Unknown Stats

Just as an intermission; this. QQ, QZone ..? Good to (learn to) know (them), if only to wake us up to the classic-Western-world bias some may have…

That’s all for now. Your conclusions are valid, almost as valid as mine, in the limit. This:
DSC_0176
[Oh how glorious, brilliant, radiant (… you know …); and Central
 If you wondered why the vertical warp: dunno, probably just WordPress’ error …]

#ditchcyber CSI, this was real

A quote, a post:

This is a story of a very high-tech kidnapping:

FBI court filings unsealed last week showed how Denise Huskins’ kidnappers used anonymous remailers, image sharing sites, Tor, and other people’s Wi-Fi to communicate with the police and the media, scrupulously scrubbing meta data from photos before sending. They tried to use computer spyware and a DropCam to monitor the aftermath of the abduction and had a Parrot radio-controlled drone standing by to pick up the ransom by remote control.

The story also demonstrates just how effective the FBI is tracing cell phone usage these days. They had a blocked call from the kidnappers to the victim’s cell phone. First they used an search warrant to AT&T to get the actual calling number. After learning that it was an AT&T prepaid Trakfone, they called AT&T to find out where the burner was bought, what the serial numbers were, and the location where the calls were made from.

The FBI reached out to Tracfone, which was able to tell the agents that the phone was purchased from a Target store in Pleasant Hill on March 2 at 5:39 pm. Target provided the bureau with a surveillance-cam photo of the buyer: a white male with dark hair and medium build. AT&T turned over records showing the phone had been used within 650 feet of a cell site in South Lake Tahoe.

Here’s the criminal complaint. It borders on surreal. Were it an episode of CSI:Cyber, you would never believe it.

Just to remind you; it’s not all APTs only that hit you. Here, it was ‘just’ hardcore kdnapping. And think about victims of false … [fill in your favourite of the four horsemen of computer crime and colour the picture] accusations alone: Defamation by the clueless, works at much longer terms, and maybe more effectively. Nothing progressive, innovative, disruptive about that… And:

DSC_0082
[Yes that is the First Flag – government project: (i.e.) unfinished]

A sobering thought

Actually, not one but a great many sobering thoughts, in this great piece: What They Don’t Teach You in “Thinking Like the Enemy” Class. In a high-quality series.

To which one might add … not too much. Maybe the 100%-is-infeasible line, and Schneier’s Return of the Security (is..?) Theatre trope. Oh, and the one that has still taken far too little root; the deperimetrisation-means-you-need-to-focus-on-information-not-the-fortress aspect that has been around for a decade already but still has hardly been implemented properly.

Or, we redesign the world. Somehow, we need to get into the mindsets of the global populace – that so far hasn’t been standardised to any degree; happily! for cultural diversity hence overall societal flexibility, development and progress … – to accept that after human development was pushed by physical wars for all of its existence so far, we have arrived at a new round of warfare innovation. After the man-to-man (sic) manual combat, and the ethically despicable practice of not even seeing the Other in the eye individually that gunpowder brought on – glossing over the trebuchet-and-others long-distance hurtling and archers’ reach –, we are now engaging not only in drone-led warfare (distance being even greater), but also in this: humans not being the soldiers anymore; that part being taken over by the robot. By which I don’t mean humanoid robots – why even bother – nor masses of stand-alone AI. But rather, unembodied A(S)I that operates on any platforms together, creating resilience not by numbers of clones but by moving swiftly over servers by having been virtualised at various levels of conceptuality, as they are compounded-mem complexes battling each other evolutionarily. And still aiming at humans.

…? Well, what’s the purpose, otherwise ..!?

Which is far off from where this post started. And foregoing the intermediary step I wanted to write up; where ideas cleverly capture (numb, dumb?) people and ‘ideologies’ fight each other for global dominance. With all sorts of ‘neat’ (quod non) tricks. But [w|h]ell… and this:
DSCN8626cut
[All humans removed from picture. Naturally]

You, me, and ASI; the difference

Before we forget: Why some don’t see how ASI would surpass AGI and humankind, is that humankind has not learned to work together in all the time humans have existed in groups beyond the first few Dunbar numbers (2, 8, 20, 50). Which means we humans spend the most delicate thought and most thinking energy on the operations and tactics of working together, before the ‘external’ task can be solved if at all. Where ASI would have no trouble having all human culture combined into one processing faculty already, hence think-acting at a level of all humankind in concert, or beyond. We have external response flexibility, ASI has that covered internally with an n-dimensional external surface, n possibly > 4.

Deep-think that one over. And:
DSC_0168
[Indeed, one section. Goes for all of your brain’s work, too]

Still valid; MIS is a Mirage

Somehow, some neurons fired that sublimed into a thought about John Dearden’s MIS is a Mirage, of 1972 … Turns out I’m not the only one who thinks it’s still very much valid today. As e.g., here. Oh, the insights that run in deep undercurrents throughout today’s management- and other fads…!

But, once ASI comes along … Then at last, MIS can do without the, then relative but still, stupidity of mankind. Or ..?

[No pic today. Post too short. First, you study the article at length!]

Short post: Offense on the Defense

Apart from love, here too all is fair. Hence, the offense may be pushed into defense every once in a while. Yes, think that one through.
Or, that is misinterpreting it. Offense and defense do a danse macabre while the content fights out at higher abstraction levels. Think that one through ..!

[Edited to add: this link, and this one. Others apply as well.]

OK, ’nuff for now, and this:
DSC_0705
[Not even unique, as a NY wedgie; only just (…) the prettiest]

Preventing detection

At last, there’s a resurgence of non-preventative infosec (#ditchcyber) efforts. As, e.g., here (in Duts though the orig would be Engrish ..?) and here (a decent one, almost making the right point; co-typical ..? and on second reading, a bit empty of actual actionable advice). Hinting at leaving the Prevention Imperative and refocusing on Resilience.
Because ‘deperimetrisation’ may have clouded the longer-term, more strategic failure of locking oneself in and shooing away the so grossly underestimated enemies by one’s own utterly ridiculous overestimation of … authority, power, capabilities and competences, considered-self-evident importance (quod non…). The dumb not realising how dumb they actually are…

We’ve said this before, over and over again. And we’ll say it again. Because the Laggards (hey remember yesterday’s post?) still haven’t got it, deeply enough into their veins.

But, we have a start of that at last. Why only now? Because even the most conservative (sic) can no longer hold the fort (sic) of box-shipping at all levels? Anyway:
DSC_0804
[Rebound into the heavens!]

Certified without being aware of that

Hm, how come so many organisations rely on certification – by means of electronic certificates; the other kind is mindbogglingly empty paperwork – and don’t have a clue ..?

I’d say, let them get a good checkup, e.g. via.

Deeper of course is the ‘problem’ that here we have a quite important piece of the ‘security’ (note the ”) puzzle, but one that is buried deep, very deep in technology. For most. And hence is out of view. But when there’s so much talk lately (for years, decades on end already – eras in Internettime) of (info)’security’ having to come aboard in Boards and this haven’t happened almost everywhere, we now see why (?): Infosec can, partially, be ‘solved’ way out of view. Like security around electricity. As already outlined long ago.

But, to conclude, it’s an And-And thing all the way throughout the organisation. One can dream, can’t one?
DSCN0610
[If you immediately thought of Asley Madison, that’s your dirty mind …!]

May a change *is* happening

The title is correct; finally we can see what the Mayans meant when they, errrm, their calendar, predicted the end of the previous era and the dawn of a new one. Where many simpleton minions pinned it down to some very moment at 1 Jan 2012, of course the lore was about a longer-term turnaround phase before a really new era could be said to have emerged.

Now, isn’t it since the beginning of this millennium or even more, since about 2012 that AI sentience has merged with IoT to kickdown towards the Singularity …? So that the new era isn’t one for mankind only but one in which machines take over the lead over the world’s physical as well as mental reality ..? Just saying.

Oh don’t take it all too seriously. One might even read this as if I would follow Hegel’s reasoning of a path to a final and eternal triumph of abstract Reason. Hah. And:
DSCN0623
[Torún. Famous for …, somewhat appropriately]

Why ‘cyber’s still a dud

[Oh yes @CyberTaters will warp the pings re this post. And #ditchcyber!]

For one, all (sic) of ‘cybersecurity’ (quod non) is incomprehensible to those that consider themselves ‘leaders’ in one way or another in practices where actual infosec should be top of mind. Since the (for quite too large a part) despicable mice (of this story) don’t see their own folly, these kindergarten emperors will be found to wear their new clothes well… but not ‘get’ what it takes to start developing ideas how to actually lead in the infosec field. Starting with debunking Internet myths and hype-FUD but also starting the sea changes needed to achieve something (if maybe not everything).

For another, since all the hype-FUD only leads to Technology focusing, where those that would still not have thus-focused houses on order should be fired; decades of developments would have to have been easily dealt with – though it is rocket science, it’s hence not that hard. Hey, designing and building a probe to Pluto, isn’t there an app for that?
Leaving the other 99.9% (well…) of work in the area of People (and don’t start me on Process..! see my posts over the past couple of weeks). Which, even if it would be understood what needs to be done in that field, would be known to be near impossible to pull off, let alone in the short term.

Hence by simple (?) logic, ‘cyber’whatever is a dud.

Sobering:
DSCN2508
[You know where, or not; every corner needs to be beautiful…]

Maverisk / Étoiles du Nord