Category: Newsletter

  • Keeping Privacy and Knowledge In Balance

    Keeping Privacy and Knowledge In Balance

    I’ve decided to try changing up the format to the newsletter on a more regular basis. I want to try new things with the layout and the conversational tone of the newsletter. If you love or hate my new format experiments, let me know!

    Knight Crane Convergence Lab via flickr
    Knight Crane Convergence Lab via flickr

    It’s really hard to care about privacy. Do you even take the effort?

    Do you care about your privacy? It’s pretty easy to say that you have nothing to hide so you don’t care, but let’s be honest here: there’s really nothing that you care about keeping to yourself? Maybe you think that your data is already being gathered and used. If you’re like most college students, as long as it’s being used to help you, that’s considered ok.

    The issue is in part that you don’t always know who has access to your private data, or who they can share it with or how they can use it. Again, maybe you don’t care about the anonymity of Bitcoin being a myth.

    There are some things that you just shouldn’t have to spend time worrying about, but isn’t it nice to know if stores and ads are tracking you through your phone and ultrasonic sounds, or how to block them? Or that advertisers have access to information like your race, which they can use to exclude ads from being shown to you, which would be pretty illegal if they had any federal oversight.

    When knowledge is power, who should own that information?

    I spend a lot of my time in the WordPress world and like any close community, the turmoil and commotion can offer an interesting distraction from the work. Last weekend we dealt with a discussion around the leaders of two huge companies, Automattic and Wix, trading blog posts about the latter’s use of the former’s GPL code in a closed source app. Both had some valid points, and it was pretty easy for fans or foes of either company to take sides. The crux of their arguments wasn’t about money (despite the potential for large exchanges of money here), but the value and nature of open source code and the free exchange of knowledge.

    This extends beyond the usage rights of code, but the way that code can be used as a tool to hamper free trade and sharing of knowledge. Cory Doctorow has a great piece in Locus Mag this week about DRM, intellectual property rights, and the EFF’s fight for sane standards and laws around both. The EFF also fights for the knowledge to maintain system security, even when that fight is with the government over code exploits used to hack and track users of Playpen, a child pornography website that was busted, but kept running and even given performance improvements (besides the upgrade of infecting visitors with malware to trace them) which led to an increase in usage of the site before it was finally shut down.

    As an example of how detailing exploits can be useful, Google tells Microsoft about a security flaw in the Windows kernel. Microsoft does not patch or inform users of this flaw. Google publicly reveals the existence of the vulnerability – which is actively being used – to help expedite the patching process.

    New and shiny things to keep an eye on.

    You may have heard of Magic Leap by now, and the five-year-old company is slowly leaking more information about its secretive mixed-reality glasses project, which could potentially be released within 18 months. Will it really change everything about computing displays? It’s nice to think that we’re moving into a ‘Ready Player One‘ world (minus the dystopic future wealth disparity part). Still, it’s pretty easy to see how the anticipation for seamless augmented and enhanced reality glasses can get smashed upon arrival in the real world.

    Have you noticed Youtube comments getting nicer? It’s an old joke by now to call the space below a Youtube video the worst wasteland on the internet, which is why I make it a point (and highly encourage all of you!) to leave a positive comment on videos that I enjoy. Now it’s a bit nicer there, with new tools to patrol comments rolled out to the Google-owned video platform. Wired, which has been on a righteous crusade to clean up the vitriol of the internet, is celebrating this fact while calling out Twitter yet again, as the platform is becoming the lone holdout in a battle to make social media just a bit nicer.

    Do you love Furby? Of course you don’t, but your young child does. There’s a new one out, and the Furby Connect is just as annoying as the old ones were.

  • This Week in Web #43

    This Week in Web #43

    If Diamonds Are Forever, Your Data Could Be, Too

    Joanna Klein, NYT

    There’s a lot of discussion about archiving the web, and the problems that arise from link-rot. Maybe diamonds are the answer? Scientists have been experimenting with storing data in diamonds, and are currently able to store about 100 DVDs worth of information into a synthetic diamond half the size of a grain of rice. Soon, they say, they’ll be able to store even more into a smaller space, while making diamonds even cheaper.


    Iceland Pirate Party leaders photographed in 2014. Via Day Donaldson
    Iceland Pirate Party leaders photographed in 2014. Via Day Donaldson


    Iceland election could propel radical Pirate party into power

    Jon Henley and Luke Harding, The Guardian

    Moving to Iceland is looking like a better proposition by the day. This weekend they hold their first parliamentary election after the resignation of former Prime Minister Sigmundur Davið Gunnlaugsson earlier this year, after his ties to offshore bank accounts were revealed in the Panama Papers. Polls are showing it as not that far-fetched that the Pirate Party could win a plurality of seats, allowing them to lead the charge to form a new government. Protection for whistleblowers, a commitment to transparency, voter-backed referendums? Yes please.


    Web devs want to make the Internet of S**t worse. Much worse

    Richard Chirgwin, The Register

    The Register has made it clear what they think of The Internet of Things, often calling it The Internet of Shit in their articles. The W3C Web Bluetooth API is currently in their crosshairs, as it’s understandable that allowing websites and browsers to manage Bluetooth devices is totally not a terrible idea in general.


    Important News about Vine

    Vine, Medium

    Vine is shutting down. Twitter isn’t having any problems at all with their main service, and it’s only the The site will stay up indefinitely, so you can still watch some of your favorite vines, but you can also download yours to ensure that they aren’t deleted. Or you can read an analysis of one of the greatest Vines of all time.

    Don’t fret too much. It looks like the founders of Vine are ready to hype their next project, a way to broadcast video on the internet (like Fine?), Hype.


    Dan Kaminsky calls for a few good hackers to secure the web

    Iain Thomson, The Register

    With all of the hacks going on, the work of Dan Kaminsky and his coworkers at White Ops is welcome and overdue. Check out Dan’s Github page to see what is being worked on and how people can jump in and help.

  • This Week in Web #42

    This Week in Web #42

    From liberal beacon to a prop for Trump: what has happened to WikiLeaks?

    david Smith, The Guardian

    WikiLeaks has been publishing dump after dump of private emails from Hillary Clinton, her campaign chairman John Podes, and others who have emailed them. The newsworthiness of some of the emails is undeniable, just as the non-newsworthiness of others is undeniable. For this or some other reason, the Ecuadorean embassy that Julian Assange has been living in for the past four years in London has cut off his internet access.

    It’s believed that Russia supplied leaks to Assange’s whistleblower service, most likely through a Gmail Phishing scheme, which we’re all more susceptible to than comfortable admitting.

    Maybe the four years of confinement have hardened the WikiLeaks’ founder’s views. Maybe he is stir-crazy, worried for his future at the embassy or abroad when Ecuador elects a new president next year. Maybe he’s trying to side with a candidate on the gamble that a win would provide lenience and allow him to avoid extradition to the US after extradition to Sweden. Maybe this is all a poorly timed coincidence with a high-profile scapegoat. Either way, we’ve got 18 days until the woman who (jokingly?) questioned the efficacy of drone attacks against is elected president, and Assange’s future is unknown.


    Gangnam Style Galaxy Note 7 via Know Your Meme
    Gangnam Style Galaxy Note 7 via Know Your Meme

    DOT Bans All Samsung Galaxy Note7 Phones from Airplanes

    Transportation.gov

    The saga of the fiery Samsung Galaxy Note 7’s continues. As of 15 October, the phones are banned from air travel to, from, and within the US. This includes checked bags. If you’ve got one of these explosive devices, send it back and get a new phone with your refund.

    Enjoy the jokes that have come at the $17Bn expense of Samsung while feeling sorry for them. Fire extinguishers behind a Note 7 display. A Gangnam Style ad. Using the explosive phone as an improvised grenade in GTAV. Just don’t let Samsung sue you if they submit a takedown request to your playthrough with the explosive phone mod.


    Attackers Hiding Stolen Credit Card Numbers in Images

    Chris Brook, Threat Post

    What’s a good way to get stolen credit card information from an eCommerce site? Well after you’ve exploited the site, how about embedding that information in product images on the site? Then you can visit later (or direct a buyer to a link) as you please as if you are just browsing deals.

    Sucuri discovered this attack running on some Magento sites due to a separate flaw that allowed attackers to gain access to the site and implant malicious code.

    This article was suggested by @lmelegari. If you’ve got any cool story ideas, shoot them over to david@thisweekinweb.com or suggest them here!


    Big-Data Algorithms Are Manipulating Us All

    Cathy O’Neil, Wired

    O’Neil, a former hedge fund quant, details some of the ways that big data is used to determine things about your future. Things like insurance rates, the likelihood of college acceptance, credit rankings and creditworthiness, and more.

    The danger of allowing algorithms to make decisions for us about monumental life milestones is the lack of transparency in the process of selection. You don’t know why you got passed over in favor of someone else, or what the outcome of that personality test that you took at your last job was. But companies that gather your data and match you against trends, detemrining the maximum value that they can wring from you do. They don’t have to tell you what they choose or how, and you have little to no recourse from the decisions made.

  • This Week in Web #41

    This Week in Web #41

    samsung_galaxy_tab_and_apple_ipad

    The U.S. Supreme Court will weigh in on the value of design patents in the Apple-Samsung hearing Tuesday

    Ina Fried, Recode

    Samsung has already had a trying few months, what with Galaxy Note 7’s being replaced after battery meltdowns, Then those replacement phones also catching fire, and finally the company being forced to recall both batches in super flame-retardant return boxes, killing the flagship phone entirely.

    Another issue over the past five years has been an escalating lawsuit between Samsung and Apple over design patents the latter holds. The $399M of the $1.05B award against Samsung related to the design patent is what’s being argued at the Supreme Court this week. I am of the opinion that it shouldn’t hold up in part because the design patents are broad and not what I would consider novel concepts. While Chief Justice Roberts probably doesn’t agree with me on that, he does seem to think that the outside design does not affect the guts of the phone and the profits earned by them.


    This Twitter bot is tracking dictators’ flights in and out of Geneva

    Amar Toor, The Verge

    A Twitter bot was created earlier this year (with open source code to boot) that tracks planes belonging to dictatorial governments flying in and out of Geneva. The journalist who created the tool wanted to shed some light on the shadowy workings of Swiss banks. If we can’t get transparency, we can at least try to keep tabs!


    https://www.youtube.com/watch?v=63RtppQU32Y

    Do You Have The Right To Privacy?

    Gearbrain Editorial Team

    A panel moderated by Gearbrain discussed how to maintain businesses while respecting the privacy of clients. The discussion centers in part around Internet of Things devices, which are gathering more and more information from users with elss and less oversight.

    If the argument exists that you can’t have both security and privacy, or perhaps can’t have security without privacy, can we at least agree that you shouldn’t have to have neither? CDN company Akamai has shown that some SSH vulnerabilities in IOT devices have existed for years, potentially decades. Moreover, they’re not getting patched even after they become publicly known for the same reason that common security protocol was not followed in the first place: the rush to get to market makes important tasks like customer security and privacy less important as deadlines loom.

    For now the devices may not even be worth it. If you can spend 11 frustrating hours trying to boil a kettle of tea with a connected device, is it worth it?


    Even the US military is looking at blockchain technology—to secure nuclear weapons

    Joon Ian Wong, Quartz

    The lasting legacy of Bitcoin may not be the volatile currency itself, but the normalization of the concept of digital currency in general, and the blockchain, the powerful ledger that drives this and other secure transactions. DARPA is working on a use case for blockchain to maintain tighter control over the inventory of nuclear arms and parts that the government commands. At the very least, it can make it harder to lose track of nukes or fly them around by accident, costing military jobs.

  • This Week in Web #40

    This Week in Web #40

    As I’m writing this week’s newsletter, WordCamp Orlando has been cancelled, which threw off a lot of planning by a dedicated team. Hurricane Matthew is bearing down, and I’m planning for some time without internet. If anything big happens in the world, be sure to let me know when I’m back.


    Yahoo Hacks, courtesy Premshee Pillai via Flickr
    Yahoo Hacks you, not the other way around. Courtesy Premshee Pillai via Flickr

    Exclusive: Yahoo secretly scanned customer emails for U.S. intelligence – sources

    Joseph Menn, Reuters

    Even better than searching stored or sent email? How about searching all incoming email? I can choose to not have a Yahoo email account (which is probably a good idea already with their massive breach). It’s harder for me to choose not to email anyone with a Yahoo account. If I do though, now I know that that email was also scanned by the US government.

    If the reports that Reuters has received are true, this would be the first known case of a US corporation complying with a government request to scan all incoming mail, removing privacy protection from them and everyone that has contacted them. Apparently, the departure of Yahoo’s CISO Alex Stamos in 2015 was over the compliance with this government demand.

    Thanks to FISA, Yahoo may also have felt legally obligated to hide the fact that they were complying as well, under a gag order on that activity. The NSA is ok with this though, suggesting that email providers “have the power to encrypt it all, and with that comes added responsibility to do some of the work that had been done by the intelligence agencies.”


    N.S.A. Contractor Arrested in Possible New Theft of Secrets

    Jo Becker, Adam Goldman, Michael S. Schmidt, and Matt Apuzzo, New York Times

    The NSA has reduced the number of employees with access to classified information in recent years, but they continue to employee third party contractors. One of the consequences of this is more opportunities for a leakage of data.

    Harold T Martin III is not Edward Snowden. For one thing, his focus was more on software and hacking tools, though it’s unclear if he has any connection to the Shadow Brokers, who released some NSA hacking tools earlier this year.


    The Internet Finally Belongs to Everyone

    Klint Finley, Wired

    Following up on a recent newsletter, the rider in the federal budget requiring a pause of IANA transfer to ICANN ownership was removed before the budget was passed. This means that on 1 October the transition process was set in motion, and ICANN (which already was under control of a consortium of countries) has control over the Internet Assigned Numbers Authority, which has been colloquially referred to as the address book of the internet.

    There has been a lot of misguided fear over the past few months by Republican lawmakers and presidential candidates over what this means. It basically means nothing beyond a symbolic gesture saying that yes, other countries do get a say in this international network, not just the US.


    screenshot-2016-10-06-22-37-46

    Right-wingers and ‘free speech’ trolls devise secret internet language to dodge online censorship

    Jasper Hamill, The Sun

    In a totally stupid move, a really simple code for racism was leaked from the white-supremacist movement that is trying to rebrand itself as “alt-right”. The idea is that referring to other races as “Googles, Yahoos, and Skypes” would allow them to freely congregate in public and avoid censorship, since Google wouldn’t ban the word Google. Turns out that the AI work that the Jigsaw team can figure out context while banning hate speech, and figure out this code that would be laughable if not so terrible.


    Love that new Mac smell? Now you can buy a candle that smells like a freshly-opened Apple product

    Jeff Benjamin, 9 To 5 Mac

    TwelveSouth already makes some fancy mac accessories. Now they’ll help keep your senses in mac world with their candle that smells like a fresh Apple product. Incredibly they’re already sold out at $24 each, so people must really love that smell.

  • This Week in Web #39

    This Week in Web #39

    Software and Terms of Service Control Ownership

    You don’t own the things that you pay for if those things are based around software. Nowadays, that is describing more and more things.

    HP has caused a minor uproar with a new update for their Office Jet line of printers, which included a DRM lock which is intended to block third party ink cartridges from working. Customers were not happy. HP backtracked on this particular update, but they didn’t explain exactly how they were going to implement it or how they would avoid doing the same in a future update.

    When you purchase something you should be free to do what you want with it. HP is losing market share on printers, and forcing you to buy their ink (probably the most expensive liquid you’ll ever buy) is a desperate gambit to maintain that revenue. The ability to use whatever ink you purchase should be obvious. The ability to do what you want with your ebooks should also be obvious, even if a Quartz poll (on terms of service no less!) shows that most readers don’t understand that.

    You can choose not to install updates to firmware, and hope that your device still works. But what if you miss out on an important security update? One that allows someone to gain control of your device for use in a botnet, or to remotely set your printer on fire.

    What about wanting to use your device after the manufacturer no longer supports it? In the past week I’ve been unable to find firmware updates for a bluetooth controller that came from Kickstarter a few years ago and was sold in major retailers. The website simply no longer exists, and a mirror for the firmware and instructions is hard to find, if it exists at all. Narrative, the life logging camera that also came out of Kickstarter shut down on Monday, though their website doesn’t even acknowledge this yet, instead saying that cameras can’t be purchased because demand is too high.

    I waited over a year to get my camera after purchase, yet a few months later it is effectively an expensive puck, until they release their promised photo retrieval tool. Which they have no obligation or timeline to actually do. If they do release a tool it could arguably improve my usage over being tied into their system. If they don’t, the DMCA and other laws could legally halt others from creating free, open source tools to get back usage of your camera.

    If you want to be able to use whatever ink you want in your printer, or think that this is an important first step into affirming your rights over the things that you pay for, the EFF has an open letter that you can sign to the CEO of HP, which has garnered over 11,000 signatures so far.


    Pepe is the Alt-Right Poster Child. Image courtesy CommanderCorson
    Pepe is the Alt-Right Poster Child. Image courtesy CommanderCorson

    Anti-Defamation League Declares Pepe the Frog a Hate Symbol

    Sarah Begley, Time

    The life cycle of any meme is strange. They can transcend the internet and enter popular culture. They can become newsworthy items on their own. Or they can completely eclipse their original meaning. Some even gain additional life and find a way to reach more people positively, as the creator of the Equity vs. Equality meme describes in the second life of his presentation slide.

    Pepe the frog did not get this positive treatment. It moved from a webcomic character into a symbol of the new breed of white supremacists who hide their terribleness behind the name “alt-right”.


    Can you abuse technology? It certaintly works the other way around!

    Frank Buytendijk, Gartner

    Techno-anger, the new rage affliction? All of us yell at our devices every once in a while. Some parents are making their kids say please and thank you to Siri and Alexa. Someone thanking Google becomes a news story. Research by Dr. Sheryl Brahnam suggests that anti-social behavior with computer agents is both common and something that should be avoided if possible.


    Neiman Marcus and Vogue blame fashion’s woes on bloggers: “You are heralding the death of style”

    Marc Bain, Quartz

    Vogue and Neiman Marcus are mad at bloggers. In the world of fashion capitalism maybe some of their points are valid. Or maybe they are making less money while paradoxically having to pay less for advertising of new fashion.

    The gatekeepers of old industries are losing their grasp, and they don’t like it. Anyone has the ability to make a change online and anyone can find a voice given an internet connection and effort. The complaints of these gatekeepers will get louder and more frequent as their power over PR is eclipsed by the voices of their fans.

  • This Week in Web #38

    This Week in Web #38

    nexus2cee_google-allo-sticker-packs-julio-bull-1

    Allo, allo. What’s all this chatter about then?

    Look, if I can use a chat app and immediately start sending gif stickers of a twerking bull to someone, I will. If that isn’t entertaining enough, I can send beans wearing condoms, entreating you to “Rubber Up!”, or some kind of… pig monster maybe? asking you to send pics with his Simmons-like tongue sticking out.

    But now let’s get down to the core app. Is it worth using? I’m generally a Google kind of guy, and I’m eagerly awaiting their connected home device so I can give up Alexa for something that knows me a bit better, what with most of my email, calendar, chats, and more coming through the internet giant. That said, there are certain times where the magical moments brought up by the company that knows you better than anyone are overshadowed by just how much it knows.

    Privacy researchers have been urging users not to turn to Allo, as even though it offers Signal’s end to end encryption protocol in the app, the default is for your conversations to be stored on Google servers indefinitely, to furnish data for their AI in order to improve that magical feeling. This means that anyone who can access Google’s servers (which we know to have happened before) can access those conversations. That’s probably why Ed Snowden also suggested not using apps like Allo for communication.

    Add to this the fact that users complain about the glut of chat apps and the fracturing of that market (very true in my experience), as well as the fact that it currently just does not work that well, and Allo is looking less like the perfect new thing that I was waiting for, and a flawed, untrustworthy and not very useful assistant. Given that this is Google, it could go the way of it’s many shelved or otherwise underdeveloped tools, or it could get renewed vigor with live users giving it a go. Considering recent purchases by the search behemoth, including the acquisition of api.ai, they just might be making a go of this as hard as their competitors are.


    Verizon issued a pretty stunning statement concerning the Yahoo breach

    Jason Abbruzzese, Mashable

    Yahoo stakeholders are in a bit of a bind right now. Verizon issued a statement on Thursday, claiming that they only found out about a leak of approximately half a billion accounts and personal details of Yahoo customers two days prior. That is well after the two months ago that they agreed to purchase the beleaguered Yahoo’s web division for almost $5billion.

    The breach occurred in 2014, but the data has been for sale since at least August of this year, and no word yet on who has it. The indications given so far are that, like some recently high profile hacking cases, the attack resulting in the breach may have been undertaken by a state actor, rather than individual hackers.

    This is bad news for Yahoo, as the deal hasn’t finalized and presumably Verizon has a reason now to alter the terms of the deal, if not cancel it entirely. Even if Verizon continues with the acquisition, there’s no reason that the final value could be lower if the Yahoo stock drops heavily over the news

    This story was suggested by @lmelegari. Do you have a story that you think would be good for the newsletter? Please suggest it!


    Ted Cruz is wrong about how free speech is censored on the Internet

    Tim Berners-Lee and Daniel Weitzner, The Washington Post

    When the creator of the World Wide Web talks about the internet, it’s worth a listen. In an editorial in the Washington Post this week, Sir Tim Berners-Lee fights back against a huge backlash in recent weeks of Conservative lawmakers calling plans to cede national control of ICANN an affront on free speech. As Berners-Lee rightly notes, ICANN has nothing to do with free speech or speech of any sort, and does not control what people post online. ICANN is an address book of sorts, pointing you to domains based on a mutual trust between service providers the world over. If a repressive government wants to block a website or shut down internet to their entire country, there is nothing that ICANN can do to stop or help them.


    California Supreme Court to hear Yelp free-speech case

    Carolyn Said, SFGate

    I talked about a legal dispute involving Yelp as a third party between a lawyer in California and a dissatisfied client in the newsletter about a month ago. Yelp challenged a ruling by a lower court that ordered them to scrub a defamatory review from their site, despite them not having been involved in the original dispute, and the DMCA safe harbor protections that they ostensibly get.

    That safe harbor has been slowly evaporating, as lawmakers have found it more enticing to remove one of the few positive policies from a law that at times has been quite stifling. Thankfully, the California State Supreme Court has decided to hear out Yelp’s case, after an amicus brief filed by other high-profile tech companies drew attention to the suit. The reason for the added support is that this could be a test case for future rulings against companies that host content that some visitors find distasteful. The reason that they definitely should hear the case out is that Yelp wasn’t in the original dispute, and therefore did not have a chance to be heard.


    1.0.0

    Mike McQuaid, Homebrew

    If you love having a package manager for your apps and use a mac, celebrate that Homebrew has hit a stable release of 1.0.0 this week! If only every app developer built in support for packages, allowing me to update everything at once.


    Inside Google’s Internet Justice League and Its AI-Powered War on Trolls

    Andy Greenberg, Wired

    Another recent story was on Jigsaw, a division of Google. With an AI system that they’ve open sourced and trained on New York Times comments and Wikipedia articles, the company is claiming a 92% success rate (which Greenberg disputes) in recognizing and acting upon abusive comments online. The question is if Conversation AI can grow and adapt as quickly as those who regularly find ways to bypass content censors.

  • This Week in Web #37

    Ed Snowden’s Chance for Clemency is Closing

    Edward Snowden has taken refuge in Russia for over three years, ever since leaking millions of documents worth of proof of illegal activity on part of the US Government. He has stated his wish to return to the United States if he

    The Oliver Stone biopic, ‘Snowden’, hits theaters today, and his legal team is hoping that it can help turn public opinion enough to help convince President Obama to pardon the whistleblower. Immediately before leaving office is generally the time that most noteworthy presidential pardons are given. Both major party nominees have indicated that they would most likely not grant leniency to Snowden, even if Bernie Sanders publicly supports the idea.

    The President will need quite a bit of convincing. He has made it clear that he does not condone Snowden’s actions in anyway whatsoever, and already has demonstrated his dislike of whistleblowers, prosecuting them under the Espionage Act more than all past presidents combined. This is the same law that is under review again for being potentially unconstitutional, and which has been used to silence other whistleblowers, as they are not allowed to make a case based on public good of their leaks.

    The NSA leaks, part of a broader picture of surveillance culture, mass leaks, and the increasing interconnectedness of our world, have definitely had an impact felt worldwide. Here in the United States, we’ve had a conversation about the role of surveillance in our society, new bills intended to curb abuses of surveillance power, and court rulings that have declared several NSA activities, including the bulk collection of phone records and metadata. Corporations have become emboldened as well, building encryption directly into their products to avoid some surveillance, and standing up to the government to draw a line and say that they will not bend to unreasonable demands.

    From early reviews, the film takes some liberties with its source material. The most good that it can do is to raise awareness of the man, who has already been featured in an Academy Award winning documentary, ‘Citizenfour’, which does a good job of explaining who he is and what he did for us. His interview with John Oliver last year, while showing a depressing number of people who even knew who Snowden was (see awareness issue above), was also a good primer on personal security, and a humorous look at a man who has been taken so serious for the past three years.

    The Feds Will Soon Be Able to Legally Hack Almost Anyone

    Senator Ron Wyden, Matt Blaze and Susan Landau, Wired

    Sometimes the government is more transparent in how they surveil. Currently, Expansions to Rule 41 of the Federal Rule of Criminal Procedure are under consideration in Congress. The fallout of this could very well allow the government to legally do what it’s already doing, and hack computers of criminals, their victims, and unrelated third parties in the millions with a single warrant. Beyond the privacy implications, security is something that isn’t really taken into account here. Well, it is if you are oblivious enough to think that the government can crack your devices but no one else would be able to take advantage of those cracks.

    A better bill to support would be the Stop Mass Hacking Act, which Senator Wyden introduced with Senator Rand Paul in May.


    The state of the Octoverse 2016

    Github

    Github is the most widely used public code repository in the world, so it is also the def facto place to see trends in code. JavaScript and Java both had huge gains in popularity in the past year, though newer languages like Go, Swift, and TypeScript are also seeing growth. Microsoft has overtaken Facebook and Google for the most open source contributions on the platform.

    See all this and more, like the issue message that got the most reactions (it might sound awfully familiar to NASA buffs), with an infographic of stats on the code repository network that came out in conjunction with the Github Universe conference this week.


    YouTube Is Building Community—And It’s Not Just About Video

    Harry McCracken, FastCompany

    This is a long read, but if you’re more inclined to video, the YouTube channel The Know stated it succinctly: Facebook is becoming YouTube, while YouTube is becoming Facebook.


    How WIRED Completely Encrypted Itself

    Zack Tollman, Wired

    Zack Tollman is a smart guy. He can teach most anyone the basics of security and encryption, even me. When Wired moved to encrypting their entire network of sites, covering 23 years worth of publishing, there was a lot to do. Their hope is that a post about the problems that they faced and how they overcame them will be useful to other publishers. I’m also glad to have something to point to so I can say “yeah, this isn’t always as easy as it looks, and sometimes it looks hard.”


    Twitter’s new, longer tweets are coming September 19th

    Chris Welch, The Verge

    This and other articles about the change in tweet character counts have been a bit clickbaity, but it’s still a change that I eagerly await. Following announcements earlier this year that things like usernames, links, and media attachments would no longer count toward character limits in tweets, it appears that we’re almost there. I personally can’t wait to quote people and tag people and spam links everywhere with impunity. Follow me on Twitter if you dare😝

  • This Week in Web #36

    This Week in Web #36

    Google’s Clever Plan to Stop Aspiring ISIS Recruits

    Andy Greenberg, Wired

    Google is finding another way to use it’s powerful and omnipresent search system for good. Chat services have been outright banning people who post in support of ISIS, even if they are the most popular YouTuber. Now Jigsaw, a team formerly known as Google Ideas, is directing search terms identified as common to potential ISIS recruits to videos and content curated from the web that is believed to be effective in turning people away from the cult.

    If you want to know some other ways that one of our presidential nominees would handle ISIS on the web, try to parse some of these statements.


    Dennis Cooper’s blog re-launched after Google censorship criticisms

    Mazin Sidahmed, The Guardian

    Dennis Cooper, who is an author and artist, has been running his blog for about 14 years, with updates almost every day of the week. Several months ago, Google took down his long-running Blogspot hosted site, after a report from a user on a ten-year-old post, despite that post’s content being hidden behind an adult content notice. An agreement with Google was finally reached where they would provide him data from his site, as well as his Gmail account, which was also disabled, removing a decade of correspondence and a novel that he was working on.

    His new site is built with WordPress, and is a good reminder that it’s always best to own your own data.


    Chrome is stepping up its war on the unencrypted web

    Russell Brandom, The Verge

    Chrome is doing more to push sites to move to using basic encryption standards by changing to SSL and HTTPS. This is getting much easier, as well as free, with services like Let’s Encrypt, and the number of sites offering this level of protection has dramatically risen over the past year.

    Starting in January for all forms of Chrome (earlier for incognito mode), a notification in the address bar will be displayed on websites with login forms that are not protected with SSL. The goal is to raise awareness for users, and to an extent shame websites into becoming more secure for their visitors.


    The Harambe Trolley Problem
    The Harambe Trolley Problem

    How Harambe Became the Perfect Meme

    Venkatesh Rao, The Atlantic

    I am very much over Harambe as an anything, and as a meme is the top of that list. In a similar way that “Jet Fuel Can’t Melt Steel Beams” became a lazy shorthand to faux-insiderism, every mention of Harambe has moved away from being about the gorilla and controversy surrounding his death. The image and name is now devoid of meaning, with the ability to stand in for almost any message.

    Rao’s take is an interesting one: in a world where only things out of the ordinary can gain any traction at all, Harambe is an example of how meaning can be applied to


    Stupid Patent of the Month: Elsevier Patents Online Peer Review

    Elliot Harmon and Daniel Nazer, EFF

    The future of publicly funded science research should be what is being promised by the EU: free and open access to research and papers if any public money is used. The future of science research should not be patents on online peer review systems, with the intent of tightening a stranglehold of ownership of academic research. This is why websites like sci-hub.cc exist.

  • This Week in Web #35

    Facebook fires human editors, algorithm immediately posts fake news

    Annalee Newitz, ArsTechnica

    Facebook took heed of the critics who said that their human editors brought bias to the trending newsfeed. Last week they replaced all of their human editors with an algorithm that sorts based on the most discussed stories on the platform.

    Big surprise, a lot of the stories posted are not real stories. It seems that people are more apt to share outrageous headlines that aren’t based in reality. That’ll show us to let computers take our jobs!


    Here’s What You Need to Know About the #YouTubeIsOverParty Uproar

    Mathew Ingram, Fortune

    YouTube was under fire yesterday for the notifications sent out to many highly subscribed channels that their videos would be de-monetized. The videos in question apparently violate the “advertiser friendly” terms, though not all of them are very obvious.

    The official Youtube team Twitter account responded that no change of rules around content has changed, there’s just a notification system process now to send those messages to users. That hasn’t sat very well with many famous Youtubers that are loudly wondering how many of their videos in the past have been de-monetized without them knowing it.


    Open Internet Advocates Claim Victory in Europe Net Neutrality Fight

    Sam Gustin, Motherboard

    In a victory that at this point I’d not have guessed at all, the European Union has followed suit with the US and upheld net neutrality. A new ruling upholds that internet users “have the right to access and distribute information and content, use and provide applications and services, and use terminal equipment of their choice, irrespective of the end-user’s or provider’s location or the location, origin or destination of the information, content, application or service, via their internet access service.” A PDF of the full BEREC guidelines can be found here.


    The Dropbox hack is real

    Troy Hunt

    Troy Hunt followed up on a Motherboard story confirming a rumor that Dropbox had been hacked back in 2012 and the service has now discovered this and has forced password resets for affected users. He does more than the standard shock news story however and did some analysis on how he determined that the dump was real, as well as some instructions on how to verify for yourself.

    If you’re worried about any accounts of yours, check Have I Been Pwned? to see if your email address is associated with any known leaks over the past few years.


    Facebook Just Proved It Isn’t Hooli From Silicon Valley

    Cade Metz, Wired

    Google has Brotli (which I covered in one of the first newsletters), and now Facebook has ZStandard. The major players in compression know that the only way for them to find new revolutions in compression (and AI, and hardware design, and even the foundation of their site’s software) is to make it open to third party innovation.


    Who Killed YTMND?

    Bryan Menegus, Gizmodo

    We know who killed Gizmodo parent, Gawker, but Gizmodo wants to know who killed YTMND. The answer to that question appears to be the site itself. You’re The Man Now Dog was a staple of internet culture in the early 2000’s, but the site was never made for such a wide user base. Advertisers were hard to come by with the kind of content posted to the site, and the social connections made it easier for abuse to pile on. An interview with the creator of the site described how hard it was to run a community of over 300,000 users with only one employee, as well as his reluctance to expand the site in the first place.


  • This Week in Web #34

    This Week in Web #34

    Internet Queens by WadeM via Flickr
    Internet Queens by WadeM via Flickr

    Happy Birthday Internet! Happy Birthday Web!

    Several Notable birthdays occurred this week. The World Wide Web celebrated its 25th anniversary on Tuesday. Yesterday marked the 25th birthday of the Linux Foundation as well. The first test of wireless networking and protocols from ARPAnet that would become the Internet were conducted 40 years ago tomorrow.

    The Internet was a revelation, and the WWW began the flourishing of a whole new world that more than half of humanity has participated in to some extent. It was hard to imagine any of the technological advancements of 2016 back in 1976, just as it’s hard to imagine where we’d be now if not for those audacious experiments in connection decades ago.

    It hasn’t all been pretty. Wired celebrated the birth of the web with an open letter to the Internet itself, reminding us that we’re all responsible for the sorry state of discourse online. Buzzfeed reminds us that hacks are inevitable when cybersecurity itself is broken. And how much does the web still matter if everything is moving into walled gardens like Facebook and phone apps?

    Also, the National Park Service celebrated it’s 100th anniversary yesterday. Get outside, you internet nerds! Just kidding, I prefer my screen to the swamps of the Everglades.


    Of Course Everyone’s Already Using the Leaked NSA Exploits

    Lily Hay Newman, Wired

    There’s a reason that it’s important for security vulnerabilities to be responsibly disclosed to the developers of software and hardware. Not doing so can open those applications up to exploitation. Even if you think that you’ve found a vulnerability that no one else will, there’s nothing stopping you from getting hacked yourself and having those exploits stolen. Even if you are the NSA.

    Recently a hacking group known as Shadow Brokers announced the acquisition of material from NSA affiliated spies that included a variety of programs, zero days, and other exploits for common pieces of software. As a taste of their wares, they released some of these exploits which have been confirmed as working, do not have patches from the previously unaware victim companies, and are currently being used by hackers with almost no skill required to use following step-by-step instructions.

    It’s now a race against time for affected systems to be hardened, and for software makers to patch their programs. Not only will these tools then be rendered moot in their current incarnation for NSA intrusion use, but real damage can be done in the interim, with all of us paying the price for a lack of responsible disclosure.


    Word Games: What the NSA Means by “Targeted” Surveillance Under Section 702

    Cindy Cohn, EFF

    Another bad habit of the NSA? Using confusing verbiage and changing the meaning of existing words internally to claim to follow the letter of the law, if not in spirit. What does targeted mean when the loosely connected people swept up in a targeted account amounts to billions of US communications for millions of citizens each year?


    French official threatens lawsuit over widely shared burkini ban photos

    Marcus Gilmer, Mashable

    I cannot claim to have excellent legal knowledge of public photography rights in France, and assuming that what I’m familiar with in the US will translate would not be wise. Still, I’m not discussing the act of photography and jurisdictions here, but of sharing photos. The president of the French administrative region that Nice is a part of has sent letters threatening lawsuit to individuals who shared photos of a woman being forced to remove a burkini by metro police.

    The internet is built on sharing and is fueled by sharing, whether you like it or not. Like the lawyer story below, trying to suppress these images is pointless, as there’s no way to reliably strip any content from the many disparate networks that comprise the shared internet.


    The Streisand Estate. Copyright 2002 Kenneth & Gabrielle Adelman, California Coastal Records Project, www.californiacoastline.org
    The Streisand Estate. Copyright 2002 Kenneth & Gabrielle Adelman, California Coastal Records Project, www.californiacoastline.org

    Major internet companies support Yelp in case that threatens online reviews

    Greg Sterling, Marketing Land

    Are you familiar with the Streisand Effect? Named after the singer, it’s the phenomenon of drawing more attention to information that someone tries to keep secret due to the fact that they try to censor it in the first place. Basically, if Streisand didn’t sue a photographer over pictures of her home, almost no one would have seen the pictures, but now they’re available all over the web.

    A former client of a California lawyer was sued over a negative Yelp review, and as it wasn’t challenged, the court ordered Yelp to remove the review. Yelp refused as they were never part of the legal proceedings, and wide range of legal scholars and fellow tech companies have submitted letters backing Yelp up for their actions.

    Safe Harbor is already under attack. The concept, part of the Digital Millenium Copyright Act, ensures growth on the web by protecting site owners from content posted by their users if they responded to legal requests for content removal in a timely manner. The difference here is that the company, Yelp, was not even involved in the altercation, but was commanded to take action on something that wasn’t proven to be libelous at all.

    Honestly the only question that I have in this case is why a dentist’s reviews are trashed with blatant lies due to socially unacceptable behavior entirely unrelated to his practice, but how the page of a lawyer embroiled in a frivolous lawsuit has not been likewise attacked.

  • This Week in Web #33

    This Week in Web #33

    "GCHQ ! Delete my data!" via Frerk Meyer on Flickr
    “GCHQ ! Delete my data!” via Frerk Meyer on Flickr

    We Need to Make Digital Data That Dies Like Us

    Michael Byrne, Motherboard

    There are a lot of services that cater to those who want to have a final say in their digital lives. Is deleting that data on demand the best option? It’s a task that is sudden and abrupt, final and absolute. This is not how most people treat death, and some time thinking about how we treat our digital lives is in order.

    Florida’s state senate approved a bill in February that would allow people to appoint data custodians for after their death. Facebook, Google, and other major platforms already have death policies, but this is meant to codify that. Digital death is on the minds of a lot of lawmakers lately.


    You Won’t Believe What Facebook Is Giving Away for Free Now

    Klint Finley, Wired

    Clickbait title? Exactly. Facebook is open sourcing some artificial intelligence software that classifies texts that it sees. This would allow people using the software to determine the meaning of content programmatically, and to filter spam and clickbait more easily.


    Joseph Gordon-Levitt – The Privacy Debate is On

    Connie Guglielmo, CNet

    I’ve already seen the movie about Edward Snowden. ‘Citizenfour’ came out two years ago and won best documentary at the 2015 Academy Awards. Similar to the dramatized version of ‘Man on a Wire’ that came out earlier this year, Joseph Gordon-Levitt is turning a best-doc into his shot at best actor.

    The nice thing about reading interviews with JGL is that he sounds like he’s both interested in the ideals of the person who he’s portraying (easy to believe for the transparency and open collaboration part with his long-running HitRecord production company), as well as committed to getting it as right as possible in a confusing situation.


    A Gary Johnson Super PAC Spent $30,000 on “Internet Web Memes”

    Hudson Hongo, Gawker

    The internet has been a driver of politics for the past decade and is only becoming more important. A Super PAC for libertarian candidate Gary Johnson is being clear in tax filings exactly where that money is going. We don’t know what $30k in memes is (none of their ads have aired/displayed yet), but I hope it’s not things that were old five years ago.

🌙 ☀️