<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>danielmiessler.com &#187; Privacy</title>
	<atom:link href="http://danielmiessler.com/categories/privacy/feed" rel="self" type="application/rss+xml" />
	<link>http://danielmiessler.com</link>
	<description>grep understanding</description>
	<lastBuildDate>Thu, 24 May 2012 04:36:14 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>Job seekers getting asked for Facebook Credentials &#124; Boston.com</title>
		<link>http://danielmiessler.com/blog/job-seekers-getting-asked-for-facebook-credentials-boston-com</link>
		<comments>http://danielmiessler.com/blog/job-seekers-getting-asked-for-facebook-credentials-boston-com#comments</comments>
		<pubDate>Mon, 26 Mar 2012 03:58:00 +0000</pubDate>
		<dc:creator>Daniel Miessler</dc:creator>
				<category><![CDATA[Jobs]]></category>
		<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://danielmiessler.com/?p=11795</guid>
		<description><![CDATA[Bassett, a New York City statistician, had just finished answering a few character questions when the interviewer turned to her computer to search for his Facebook page. But she couldn’t see his private profile. She turned back and asked him to hand over his login information.Bassett refused and withdrew his application, saying he didn’t want [...]]]></description>
			<content:encoded><![CDATA[<div class='posterous_autopost'><div class="posterous_bookmarklet_entry"> <blockquote class="posterous_long_quote"><p>Bassett, a New York City statistician, had just finished answering a few character questions when the interviewer turned to her computer to search for his Facebook page. But she couldn’t see his private profile. She turned back and asked him to hand over his login information.</p><p>Bassett refused and withdrew his application, saying he didn’t want to work for a company that would seek such personal information. But as the job market steadily improves, other job candidates are confronting the same question from prospective employers, and some of them cannot afford to say no.</p></blockquote>    <div class="posterous_quote_citation">via <a href="http://articles.boston.com/2012-03-20/business/31215793_1_social-networking-password-facebook">articles.boston.com</a></div> <p>Only a matter of time, really. I think services will soon emerge that parse peoples&#8217; Facebook profiles and report yes or no to employers, providing a layer of privacy abstraction to employees but still offering the filtering peace of mind to the employer. Probably a good idea for a startup, actually.</p></div>      <p style="font-size: 10px;">  <a href="http://posterous.com">Posted via email</a>   from <a href="http://posterous.danielmiessler.com/job-seekers-getting-asked-for-facebook-creden">danielmiessler.com | posterous</a>  </p>  </div>
<div id="crp_related"><h3>Related Content</h3><ul><li><a href="http://danielmiessler.com/blog/facebook-is-secretly-building-a-phone-techcrunch" rel="bookmark" class="crp_title">Facebook Is Secretly Building A Phone | Techcrunch</a></li><li><a href="http://danielmiessler.com/blog/how-to-display-content-from-other-services-within-facebook-automatically" rel="bookmark" class="crp_title">How to Display Content From Other Services Within Facebook Automatically</a></li><li><a href="http://danielmiessler.com/blog/facebook-hands-out-white-hat-debit-cards-to-hackers-cnet-news" rel="bookmark" class="crp_title">Facebook hands out White Hat debit cards to hackers | CNET News</a></li><li><a href="http://danielmiessler.com/blog/facebook-may-be-getting-skype-video-chatting" rel="bookmark" class="crp_title">Facebook May Be Getting Skype Video Chatting</a></li><li><a href="http://danielmiessler.com/blog/civilization-coming-to-facebook-this-summer-techcrunch" rel="bookmark" class="crp_title">Civilization Coming to Facebook This Summer | TechCrunch</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://danielmiessler.com/blog/job-seekers-getting-asked-for-facebook-credentials-boston-com/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Coming War on General Computation &#124; Cory Doctorow</title>
		<link>http://danielmiessler.com/blog/the-coming-war-on-general-computation-cory-doctorow</link>
		<comments>http://danielmiessler.com/blog/the-coming-war-on-general-computation-cory-doctorow#comments</comments>
		<pubDate>Sun, 01 Jan 2012 01:46:09 +0000</pubDate>
		<dc:creator>Daniel Miessler</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Information Technology]]></category>
		<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://danielmiessler.com/?p=11316</guid>
		<description><![CDATA[via youtube.com A must see. It only runs like 30 minutes; the rest is Q&#038;A. Posted via email from danielmiessler.com &#124; posterous Related ContentNew Headz Up App &#124; SNLA Creative SongSeriously Fast LyricsAn Intro to DubstepHow Not to Do a Presentation]]></description>
			<content:encoded><![CDATA[<div class='posterous_autopost'><div class="posterous_bookmarklet_entry"> <iframe allowfullscreen="true" src="http://www.youtube.com/embed/HUEvRyemKSg?wmode=transparent" frameborder="0" height="417" width="500"></iframe>    <div class="posterous_quote_citation">via <a href="http://www.youtube.com/watch?v=HUEvRyemKSg">youtube.com</a></div> <p>A must see. It only runs like 30 minutes; the rest is Q&#038;A.</p></div>      <p style="font-size: 10px;">  <a href="http://posterous.com">Posted via email</a>   from <a href="http://posterous.danielmiessler.com/the-coming-war-on-general-computation-cory-do">danielmiessler.com | posterous</a>  </p>  </div>
<div id="crp_related"><h3>Related Content</h3><ul><li><a href="http://danielmiessler.com/blog/new-headz-up-app-snl" rel="bookmark" class="crp_title">New Headz Up App | SNL</a></li><li><a href="http://danielmiessler.com/blog/a-creative-song" rel="bookmark" class="crp_title">A Creative Song</a></li><li><a href="http://danielmiessler.com/blog/seriously-fast-lyrics" rel="bookmark" class="crp_title">Seriously Fast Lyrics</a></li><li><a href="http://danielmiessler.com/blog/an-intro-to-dubstep" rel="bookmark" class="crp_title">An Intro to Dubstep</a></li><li><a href="http://danielmiessler.com/blog/how-not-to-do-a-presentation" rel="bookmark" class="crp_title">How Not to Do a Presentation</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://danielmiessler.com/blog/the-coming-war-on-general-computation-cory-doctorow/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Like Button Follows You &#124; Yahoo!</title>
		<link>http://danielmiessler.com/blog/the-like-button-follows-you-yahoo</link>
		<comments>http://danielmiessler.com/blog/the-like-button-follows-you-yahoo#comments</comments>
		<pubDate>Fri, 20 May 2011 15:26:21 +0000</pubDate>
		<dc:creator>Daniel Miessler</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://danielmiessler.com/blog/the-like-button-follows-you-yahoo</guid>
		<description><![CDATA[The widgets, which were created to make it easy to share content with friends and to help websites attract visitors, are a potentially powerful way to track Internet users. They could link users&#8217; browsing habits to their social-networking profile, which often contains their name.For example, Facebook or Twitter know when one of their members reads [...]]]></description>
			<content:encoded><![CDATA[<div class='posterous_autopost'><div class="posterous_bookmarklet_entry"> <blockquote class="posterous_long_quote"><p>The widgets, which were created to make it easy to share content with friends and to help websites attract visitors, are a potentially powerful way to track Internet users. They could link users&#8217; browsing habits to their social-networking profile, which often contains their name.</p><p>For example, Facebook or Twitter know when one of their members reads an article about filing for bankruptcy on MSNBC.com or goes to a blog about depression called Fighting the Darkness, even if the user doesn&#8217;t click the &#8220;Like&#8221; or &#8220;Tweet&#8221; buttons on those sites.</p><p>For this to work, a person only needs to have logged into Facebook or Twitter once in the past month. The sites will continue to collect browsing data, even if the person closes their browser or turns off their computers, until that person explicitly logs out of their Facebook or Twitter accounts, the study found.</p></blockquote>    <div class="posterous_quote_citation">via <a href="http://finance.yahoo.com/family-home/article/112769/like-button-follows-users-wsj">finance.yahoo.com</a></div> <p></p></div>      <p style="font-size: 10px;">  <a href="http://posterous.com">Posted via email</a>   from <a href="http://posterous.danielmiessler.com/the-like-button-follows-you-yahoo">danielmiessler.com | posterous</a>  </p>  </div>
<div id="crp_related"><h3>Related Content</h3><ul><li><a href="http://danielmiessler.com/blog/how-to-display-content-from-other-services-within-facebook-automatically" rel="bookmark" class="crp_title">How to Display Content From Other Services Within Facebook Automatically</a></li><li><a href="http://danielmiessler.com/blog/facebook-partners-up-with-web-of-trust-to-warn-users-about-malicious-links-techcrunch" rel="bookmark" class="crp_title">Facebook Partners Up With Web Of Trust To Warn Users About Malicious Links | TechCrunch</a></li><li><a href="http://danielmiessler.com/blog/twitter-is-now-filtering-links" rel="bookmark" class="crp_title">Twitter is Now Filtering Links</a></li><li><a href="http://danielmiessler.com/blog/facebook-could-crush-google" rel="bookmark" class="crp_title">Facebook Could Crush Google</a></li><li><a href="http://danielmiessler.com/blog/flattr-now-open-for-everyone" rel="bookmark" class="crp_title">Flattr Now Open for Everyone</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://danielmiessler.com/blog/the-like-button-follows-you-yahoo/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Assange: &#8220;Facebook is the Most Appalling Spy Machine Ever Invented.&#8221;</title>
		<link>http://danielmiessler.com/blog/wikileaks-founder-facebook-is-the-most-appalling-spy-machine-that-has-ever-been-invented-tnw-facebook</link>
		<comments>http://danielmiessler.com/blog/wikileaks-founder-facebook-is-the-most-appalling-spy-machine-that-has-ever-been-invented-tnw-facebook#comments</comments>
		<pubDate>Mon, 02 May 2011 14:17:25 +0000</pubDate>
		<dc:creator>Daniel Miessler</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://danielmiessler.com/blog/wikileaks-founder-facebook-is-the-most-appalling-spy-machine-that-has-ever-been-invented-tnw-facebook</guid>
		<description><![CDATA[It’s not a matter of serving a subpoena, they have an interface they have developed for US Intelligence to use. Now, is the case that Facebook is run by US Intelligence? No, it’s not like that. It’s simply that US Intelligence is able to bring to bear legal and political pressure to them. via thenextweb.com [...]]]></description>
			<content:encoded><![CDATA[<div class='posterous_autopost'><div class="posterous_bookmarklet_entry"> <blockquote class="posterous_medium_quote">It’s not a matter of serving a subpoena, they have an interface they have developed for US Intelligence to use. Now, is the case that Facebook is run by US Intelligence? No, it’s not like that. It’s simply that US Intelligence is able to bring to bear legal and political pressure to them.</blockquote>    <div class="posterous_quote_citation">via <a href="http://thenextweb.com/facebook/2011/05/02/wikileaks-founder-facebook-is-the-most-appalling-spy-machine-that-has-ever-been-invented/">thenextweb.com</a></div> <p>I&#8217;ve been saying this for years now. The Google/Facebook NSA conspiracy is ridiculous because the government can simply walk in the door, flash some paperwork, and make use of anything Google or Facebook has. </p><p>Them being involved at a creation phase or being in charge of these things would be exceedingly stupid. </p><p>The government absolutely has eyes into everything, but not because of some conspiracy; it&#8217;s because the government can claim national security and gain access to anything they want. </p><p>I&#8217;ve long considered everything I do online&#8211;even on private sites&#8211;to be fully transparent to the government. It doesn&#8217;t bother me too much because I know I&#8217;m not doing anything wrong, and I&#8217;ve not yet perfectly formed my security/privacy argument with regard to government. </p><p>It&#8217;s a hard conversation. I know the government should have the ability to see this data, and I&#8217;m ok with that when it&#8217;s done properly. The issue is that the tendency is toward misuse, and the repercussions of that moral entropy can be disastrous.</p></div>      <p style="font-size: 10px;">  <a href="http://posterous.com">Posted via email</a>   from <a href="http://posterous.danielmiessler.com/wikileaks-founder-facebook-is-the-most-appall">danielmiessler.com | posterous</a>  </p>  </div>
<div id="crp_related"><h3>Related Content</h3><ul><li><a href="http://danielmiessler.com/blog/facebook-is-secretly-building-a-phone-techcrunch" rel="bookmark" class="crp_title">Facebook Is Secretly Building A Phone | Techcrunch</a></li><li><a href="http://danielmiessler.com/blog/is-facebook-in-bed-with-the-government" rel="bookmark" class="crp_title">Is Facebook In Bed With The Government?</a></li><li><a href="http://danielmiessler.com/blog/the-facebook-places-differentiator-checking-in-your-friends" rel="bookmark" class="crp_title">The Facebook Places Differentiator :: Checking In Your Friends</a></li><li><a href="http://danielmiessler.com/blog/facebook-may-be-getting-skype-video-chatting" rel="bookmark" class="crp_title">Facebook May Be Getting Skype Video Chatting</a></li><li><a href="http://danielmiessler.com/blog/facebook-is-a-ponzi-scheme-joseph-perla" rel="bookmark" class="crp_title">Facebook is a Ponzi Scheme | Joseph Perla</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://danielmiessler.com/blog/wikileaks-founder-facebook-is-the-most-appalling-spy-machine-that-has-ever-been-invented-tnw-facebook/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Updated PGP Information</title>
		<link>http://danielmiessler.com/blog/updated-pgp-information</link>
		<comments>http://danielmiessler.com/blog/updated-pgp-information#comments</comments>
		<pubDate>Tue, 30 Jun 2009 04:35:22 +0000</pubDate>
		<dc:creator>Daniel Miessler</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://danielmiessler.com/blog/updated-pgp-information</guid>
		<description><![CDATA[I&#8217;ve updated my PGP information. Quick question: how many of you use PGP often? I hardly ever do, but I like having it available for those rare cases. :: Related ContentWhy Lock Technology Stagnated for DecadesVulnerability Management Without Asset Management, Isn&#8217;tMy Twitter Infosec ListUsing Git to Maintain Your WebsiteUpdated Subnetting Post]]></description>
			<content:encoded><![CDATA[<p style="text-align:center"><img width="300" height="300" src="http://danielmiessler.com/wp-content/uploaded_content/2008/09/security-lock.jpg" alt="lock" /></p>

<p>I&#8217;ve updated my <a href="http://danielmiessler.com/pgp/">PGP</a> information.</p>

<p>Quick question: how many of you use PGP often? I hardly ever do, but I like having it available for those rare cases. ::</p>
<div id="crp_related"><h3>Related Content</h3><ul><li><a href="http://danielmiessler.com/blog/why-lock-technology-stagnated-for-decades" rel="bookmark" class="crp_title">Why Lock Technology Stagnated for Decades</a></li><li><a href="http://danielmiessler.com/blog/vulnerability-management-without-asset-management-isnt" rel="bookmark" class="crp_title">Vulnerability Management Without Asset Management, Isn&#8217;t</a></li><li><a href="http://danielmiessler.com/blog/my-twitter-infosec-list" rel="bookmark" class="crp_title">My Twitter Infosec List</a></li><li><a href="http://danielmiessler.com/blog/using-git-to-maintain-your-website" rel="bookmark" class="crp_title">Using Git to Maintain Your Website</a></li><li><a href="http://danielmiessler.com/blog/updated-subnetting-post" rel="bookmark" class="crp_title">Updated Subnetting Post</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://danielmiessler.com/blog/updated-pgp-information/feed</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
		<item>
		<title>How to View Your Otherwise Invisible Flash Cookies</title>
		<link>http://danielmiessler.com/blog/how-to-view-your-otherwise-invisible-flash-cookies</link>
		<comments>http://danielmiessler.com/blog/how-to-view-your-otherwise-invisible-flash-cookies#comments</comments>
		<pubDate>Sat, 14 Feb 2009 07:44:42 +0000</pubDate>
		<dc:creator>Daniel Miessler</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://dmiessler.com/blog/how-to-view-your-otherwise-invisible-flash-cookies</guid>
		<description><![CDATA[If you have any basic computer knowledge and value your privacy you probably know how to clear your browser&#8217;s cookies and cache. It&#8217;s Internet 101. But newer web technologies like Adobe Flash, Adobe Air, and Microsoft Silverlight complicate things. Deleting &#8220;cookies&#8221; from these technologies isn&#8217;t necessarily done through your browser. As an example, if you [...]]]></description>
			<content:encoded><![CDATA[<p>If you have any basic computer knowledge and value your privacy you probably know how to clear your browser&#8217;s cookies and cache. It&#8217;s Internet 101. But newer web technologies like <a href="http://www.adobe.com/products/flashplayer/" title="Adobe Flash Player">Adobe Flash</a>, <a href="http://www.adobe.com/products/air/" title="Adobe - Adobe AIR">Adobe Air</a>, and <a href="http://www.microsoft.com/SILVERLIGHT/">Microsoft Silverlight</a> complicate things. Deleting &#8220;cookies&#8221; from these technologies isn&#8217;t necessarily done through your browser.</p>

<p>As an example, if you use Flash in a standard way you are often sending websites information about the other Flash sites you&#8217;ve been to&#8211;even if you&#8217;ve done the standard browser privacy stuff. So you can <em>think</em> you&#8217;ve covered your tracks, but in fact still be blabbing about where you&#8217;ve been to any site you visit running Flash.</p>

<p><a href="http://www.macromedia.com/support/documentation/en/flashplayer/help/settings_manager07.html"></p>

<p style="text-align:center"><img width="" height="" src="http://dmiessler.com/wp-content/uploads/2009/02/flash-manager.png" alt="flash_manager" /></p>

<p></a></p>

<p>Using <a href="http://www.macromedia.com/support/documentation/en/flashplayer/help/settings_manager07.html" title="Adobe - Flash Player : Settings Manager - Website Storage Settings panel">this application</a> shown above, you can actually see this invisible content. From there you can manage not only the Flash artifacts you currently have, but also apply settings for handling them in the future.</p>

<p>Pass it on. ::</p>

<h3>Links</h3>

<p>[ <a href="http://www.macromedia.com/support/documentation/en/flashplayer/help/settings_manager07.html" title="Adobe - Flash Player : Settings Manager - Website Storage Settings panel">Flash Cookie Manager | adobe.com</a> ]</p>
<div id="crp_related"><h3>Related Content</h3><ul><li><a href="http://danielmiessler.com/blog/adobe-buying-macromedia" rel="bookmark" class="crp_title">Adobe Buying Macromedia</a></li><li><a href="http://danielmiessler.com/blog/chrome-wins-again-now-clears-flash-cookies-natively" rel="bookmark" class="crp_title">Chrome Wins Again: Now Clears Flash Cookies Natively</a></li><li><a href="http://danielmiessler.com/blog/fear-the-evercookie" rel="bookmark" class="crp_title">Fear the Evercookie</a></li><li><a href="http://danielmiessler.com/blog/adobe-reader-updates-evil-same-thing" rel="bookmark" class="crp_title">Adobe Reader Updates, Evil &#8212; Same Thing</a></li><li><a href="http://danielmiessler.com/blog/otomata-music" rel="bookmark" class="crp_title">Otomata Music</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://danielmiessler.com/blog/how-to-view-your-otherwise-invisible-flash-cookies/feed</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>How to Find Your Personal Information Within Your iTunes Songs</title>
		<link>http://danielmiessler.com/blog/how-to-find-your-personal-information-within-your-itunes-songs</link>
		<comments>http://danielmiessler.com/blog/how-to-find-your-personal-information-within-your-itunes-songs#comments</comments>
		<pubDate>Sun, 18 Jan 2009 23:39:48 +0000</pubDate>
		<dc:creator>Daniel Miessler</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://dmiessler.com/blog/how-to-find-your-information-within-your-drm-free-itunes-songs</guid>
		<description><![CDATA[So you might have heard the news that there is some personal information in the &#8220;DRM-free&#8221; iTunes songs that Apple is now making available. I decided to see what strings (runs on Linux and OS X) could show me with a cursory glance: [bash]strings $SongName &#124; grep -i daniel[/bash] Sure enough, it gave me this: [...]]]></description>
			<content:encoded><![CDATA[<p>So you might have heard <a href="http://apple.slashdot.org/article.pl?sid=09/01/13/036211&amp;from=rss" title="Slashdot | iTunes DRM-Free Files Contain Personal Info">the news</a> that there is some personal information in the &#8220;DRM-free&#8221; iTunes songs that <a href="http://www.apple.com/pr/library/2007/04/02itunes.html" title="Apple Unveils Higher Quality DRM-Free Music on the iTunes Store">Apple is now making available</a>. I decided to see what <code><a href="http://linux.about.com/library/cmd/blcmdl1_strings.htm" title="Strings">strings</a></code> (runs on Linux and OS X) could show me with a cursory glance:</p>

<p>[bash]strings $SongName | grep -i daniel[/bash]</p>

<p>Sure enough, it gave me this:</p>

<p><img width="" height="" src="http://dmiessler.com/wp-content/uploads/2009/01/strings-itunes.png" alt="strings_itunes" /></p>

<p>So that&#8217;s:</p>

<ol>
<li>My iTunes account</li>
<li>My full name</li>
</ol>

<p>&#8230;in every song.</p>

<p>Not necessarily alarming but good to know. <strong>In short, even though these songs aren&#8217;t locked down like the previous ones, you should keep in mind that they can always be tracked back to you</strong>. ::</p>
<div id="crp_related"><h3>Related Content</h3><ul><li><a href="http://danielmiessler.com/blog/new-music-for-2009" rel="bookmark" class="crp_title">New Music for 2009</a></li><li><a href="http://danielmiessler.com/blog/starbucks-and-itunes-it-really-is-cool" rel="bookmark" class="crp_title">Starbucks and iTunes: It Really is Cool</a></li><li><a href="http://danielmiessler.com/blog/apple-and-emi-partner-to-provide-non-drmd-music" rel="bookmark" class="crp_title">Apple and EMI Partner To Provide Non-DRM&#8217;d Music</a></li><li><a href="http://danielmiessler.com/blog/starbucks-goodness" rel="bookmark" class="crp_title">Starbucks Goodness</a></li><li><a href="http://danielmiessler.com/blog/eye-phucking-toons-a-drm-story" rel="bookmark" class="crp_title">Eye Phucking Toons: A DRM Story</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://danielmiessler.com/blog/how-to-find-your-personal-information-within-your-itunes-songs/feed</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Scientists Read Images Directly Out of the Brain</title>
		<link>http://danielmiessler.com/blog/scientists-read-images-directly-out-of-the-brain</link>
		<comments>http://danielmiessler.com/blog/scientists-read-images-directly-out-of-the-brain#comments</comments>
		<pubDate>Fri, 12 Dec 2008 06:01:05 +0000</pubDate>
		<dc:creator>Daniel Miessler</dc:creator>
				<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Science]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://dmiessler.com/blog/scientists-read-images-directly-out-of-the-brain</guid>
		<description><![CDATA[Image from wired.com Holy shit. I mean, yeah, I knew this would eventually happen&#8211;maybe 5 or 10 years from now, but damn. These scientists in Japan can show people a word and then pull it back out of their brain&#8211;without even touching them (fMRI). I add that last part because it&#8217;d still be cool if [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align:center"><img width="" height="" src="http://blog.wired.com/photos/uncategorized/mind_control.gif" alt="image_brain" /><br /><span class="image_attribution">Image from wired.com</span></p>

<p>Holy shit. I mean, yeah, I knew this would eventually happen&#8211;maybe 5 or 10 years from now, but <em>damn</em>.</p>

<p>These scientists in Japan can show people a word and then pull it back out of their brain&#8211;without even touching them (fMRI). I add that last part because it&#8217;d still be cool if they needed to be jacked into their skull to do it. But no, they don&#8217;t.</p>

<p>Wicked brutal stuff. Here&#8217;s a funny quote from <a href="http://www.pinktentacle.com/2008/12/scientists-extract-images-directly-from-brain/" title="SUSPENDED">this</a> article about it:</p>

<blockquote>The researchers suggest a future version of this technology could be applied in the fields of art and design&#8230;</blockquote>

<p>Yeah, that&#8217;s the first thing I thought of, too. You can read people&#8217;s minds from a distance, and now we&#8217;ll be able to do better art. Someone needs to get out more.</p>
<div id="crp_related"><h3>Related Content</h3><ul><li><a href="http://danielmiessler.com/blog/political-views-hard-wired-into-the-brain-telegraph" rel="bookmark" class="crp_title">Political Views &#8216;Hard-wired&#8217; Into the Brain | Telegraph</a></li><li><a href="http://danielmiessler.com/blog/memory-research-getting-ever-more-scary" rel="bookmark" class="crp_title">Memory Research Getting Ever More Scary</a></li><li><a href="http://danielmiessler.com/blog/scientists-enhance-mice-brains" rel="bookmark" class="crp_title">Scientists Enhance Mice Brains</a></li><li><a href="http://danielmiessler.com/blog/good-programmers-can-turn-their-minds-off" rel="bookmark" class="crp_title">Good Programmers Can Turn Their Minds Off</a></li><li><a href="http://danielmiessler.com/blog/exercise-makes-your-brain-work-better" rel="bookmark" class="crp_title">Exercise Makes Your Brain Work Better</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://danielmiessler.com/blog/scientists-read-images-directly-out-of-the-brain/feed</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
		<item>
		<title>Lifecasting Piece Refresh</title>
		<link>http://danielmiessler.com/blog/lifecasting-piece-refresh</link>
		<comments>http://danielmiessler.com/blog/lifecasting-piece-refresh#comments</comments>
		<pubDate>Thu, 03 Jul 2008 05:47:13 +0000</pubDate>
		<dc:creator>Daniel Miessler</dc:creator>
				<category><![CDATA[Culture]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Technology]]></category>

		<guid isPermaLink="false">http://dmiessler.com/blog/lifecasting-piece-refresh</guid>
		<description><![CDATA[I refreshed my lifecasting piece if anyone&#8217;s interested in checking it out. I&#8217;m considering trying to get it published with a major magazine (Wired maybe?) and am looking for input in how I should edit it down. [ Lifecasting: What It Is and How It Will Change Society ] Related ContentMy Favorite Feature of the [...]]]></description>
			<content:encoded><![CDATA[<p>I refreshed <a href="http://dmiessler.com/blog/lifecasting-what-it-is-and-how-it-will-change-society/" title="Lifecasting: What It Is and How It Will Change Society">my lifecasting piece</a> if anyone&#8217;s interested in checking it out. I&#8217;m considering trying to get it published with a major magazine (Wired maybe?) and am looking for input in how I should edit it down.</p>

<p>[ <a href="http://dmiessler.com/blog/lifecasting-what-it-is-and-how-it-will-change-society/" title="Lifecasting: What It Is and How It Will Change Society">Lifecasting: What It Is and How It Will Change Society</a> ]</p>
<div id="crp_related"><h3>Related Content</h3><ul><li><a href="http://danielmiessler.com/blog/my-favorite-feature-of-the-new-iphone-3gs" rel="bookmark" class="crp_title">My Favorite Feature of the New iPhone 3GS</a></li><li><a href="http://danielmiessler.com/blog/looxcie-wearable-camcorder" rel="bookmark" class="crp_title">Looxcie Wearable Camcorder</a></li><li><a href="http://danielmiessler.com/blog/personal-daemons-and-wuffie" rel="bookmark" class="crp_title">Personal Daemons and Wuffie</a></li><li><a href="http://danielmiessler.com/blog/my-understanding-of-our-economy" rel="bookmark" class="crp_title">My Understanding of Our Economy</a></li><li><a href="http://danielmiessler.com/blog/leave-your-change" rel="bookmark" class="crp_title">Leave Your Change</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://danielmiessler.com/blog/lifecasting-piece-refresh/feed</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>Lifecasting: What It Is and How It Will Change Society</title>
		<link>http://danielmiessler.com/blog/lifecasting-what-it-is-and-how-it-will-change-society</link>
		<comments>http://danielmiessler.com/blog/lifecasting-what-it-is-and-how-it-will-change-society#comments</comments>
		<pubDate>Mon, 12 May 2008 03:56:30 +0000</pubDate>
		<dc:creator>Daniel Miessler</dc:creator>
				<category><![CDATA[Internet]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Technology]]></category>

		<guid isPermaLink="false">http://dmiessler.com/blog/lifecasting-what-it-is-and-how-it-will-change-society</guid>
		<description><![CDATA[Our society is about to change drastically, and not in 20 or 50 years, and not because of cybernetics or nanotechnology. It&#8217;s about to change due to lifecasting. Lifecasting in its current form is where people broadcast, usually via a mounted camera at home, a significant portion of their lives. Justin.tv is one of the [...]]]></description>
			<content:encoded><![CDATA[<p><center><img src="http://dmiessler.com/wp-content/uploaded_content/2008/05/social.jpg" alt="social" /></center></p>

<p>Our society is about to change drastically, and not in 20 or 50 years, and not because of cybernetics or nanotechnology. It&#8217;s about to change due to <a href="http://en.wikipedia.org/wiki/Lifecasting_(video_stream)" title="Lifecasting (video stream) - Wikipedia, the free encyclopedia">lifecasting</a>.</p>

<p>Lifecasting in its current form is where people broadcast, usually via a mounted camera at home, a significant portion of their lives. <a href="http://www.justin.tv/" title="Justin.tv - Live Streaming Video">Justin.tv</a> is one of the most successful examples of this form of expression. But this is just the first stage of lifecasting; the real impact to society, which is about to come, requires a particular condition to exist.</p>

<p class="centered"><strong>That tipping point will come when a significant percentage of society is broadcasting their lives, nearly continuously, from mobile devices.</strong></p>

<p>You might be thinking, &#8220;Ah, that&#8217;s just another <a href="http://en.wikipedia.org/wiki/Social_media" title="Social media - Wikipedia, the free encyclopedia">&#8220;social media&#8221;</a> trend, i.e. &#8220;something those crazy Internet kids are doing&#8221;. This is true of lifecasting in its current, infantile stage, but not in the stage it&#8217;s about to reach. Within the next 5-10 years lifecasting will change the way people interact with each other in nearly all settings. Lifecasing will redefine how the rules by which we expose ourselves to the world.</p>

<h2>More Than the Sum of the Parts</h2>

<p>The reason lifecasting is currently being overlooked is because the technologies that will power it are rather unremarkable by themselves. It&#8217;s basically composed of three pieces: 1) mobile video via mobile phone or some other highly portable camera, and 2) the ability to send that video out in real time to the Internet, and 3) the ability to quickly parse the incoming content into usable chunks. Nothing major, really. In fact, <a href="http://qik.com/">two of the three are already being done</a>.</p>

<p>The issue is scale, and that&#8217;s the part that&#8217;s about to change. How many devices can stream live video? How many mobile phone carriers support the constant upload of a video stream from their entire user-base? And finally, how many services are out there that take in these videos and tag them, make them searchable, integrate them with social networks, etc? Very few.</p>

<h2>A Visible New World</h2>

<p>Once these elements change (see iPhone/3G/4G LTE) our world will change with it. Here&#8217;s how it&#8217;s going to play out:</p>

<ol>
<li>All phone carriers will start supporting all-you-can-eat data plans, and they&#8217;ll get much cheaper.</li>
<li>The bandwidth (both download and upload) on said services will increase very rapidly, e.g. the next network upgrade after 3G is going to be scary fast (try between 100-300Mb).</li>
<li>All mobile phones are going to do video, and they will all ride these newer, faster networks.</li>
<li>Within the next ten years a significant percentage of people in first-world countries are going to be broadcasting every moment of their waking lives (and in many cases their sleeping lives as well).</li>
</ol>

<p>This is a friction point for some. Why would people want to broadcast their lives? Won&#8217;t it only be a few fringe people and not a &#8220;significant percentage&#8221;? No. It&#8217;ll be a massive number. Many forces will influence the adoption of &#8220;casting&#8221; by the masses. Here are a few:</p>

<ol>
<li><strong>Youth</strong>. The world is getting younger, and young people will naturally be drawn to the idea of sharing everything about their lives. It appeals to the sense of self-importance present in most young people.</li>
<li><strong>It makes sharing your life with loved ones infinitely more easy</strong>. In order to see what you&#8217;re doing, they don&#8217;t have to contact you for an account of what happened, or even what is happening. They just tune into your view of the world. They see what you see. They hear what you hear. There will be pressure from loved ones to continue casting in order to allow others to feel close to them.</li>
<li><strong>Financial incentives</strong>. There will be an explosion of services focused solely on harvesting interesting events from everyday lives. I&#8217;ll go into these services in detail later, but the point is simply that there will be financial benefits to participating.</li>
<li><strong>Civic reasons</strong>. The government will offer incentives to &#8220;casters&#8221; because your set of eyes will help find and apprehend criminals. More on this later.</li>
</ol>

<h2>Impact</h2>

<p>Now we get to the core of it. So what, right? Why should we care?</p>

<p>Ok, so let&#8217;s assume you&#8217;ve accepted that the numbers will be there. Let&#8217;s consider the implications. Millions of people uploading their actual life perspective with sound and video, and all of this content will be stored, tagged and made searchable by Google, Microsoft, etc. &#8212; <em>instantly</em> &#8212; as it&#8217;s coming in. Oh, and add to it the fact that most of it will be <a href="http://en.wikipedia.org/wiki/Geotagging" title="Geotagging - Wikipedia, the free encyclopedia">geotagged</a> as well. It&#8217;s staggering to even think about.</p>

<p class="centered">Consider the sheer number of things that take place during everyone&#8217;s daily lives that are lost forever. Well, no longer. As lifecasting becomes mainstream, public places will become 24/7 broadcast zones. If anything at all happens worth noting it will be discussed, propagated across the Internet and the people involved will be unable to the ramifications of the events they were a part of.</p>

<h2>The Camera is Everywhere</h2>

<p>He notion of being unable to show any sort of negativity without it being shown to the world (with your name, address, and place of business) will have a staggering effect on society. Here are a few scenarios to think about.</p>

<p>One improper comment out of your mouth can now get you fired, or even aired on CNN. A single off-color joke about wanting to &#8220;do&#8221; some woman at work, or maybe you made fun of a handicapped person as they walked by. A simple funny face would be enough. Or maybe you&#8217;re a racist who makes some mouthbreathing comment about black people while eating in a restaurant with a friend.</p>

<p>The person didn&#8217;t hear it, and nobody was offended (then), but unfortunately for you it was captured by four different people who were lifecasting near you at the time. Oh, and the guy at work that hates you caught it on the Internet and just sent the link to your VP, who is black.</p>

<p>Fail.</p>

<p>In short, everything you do will be subject to scrutiny by the entire Internet. And any undesirable behavior that is captured will be easily distributed for ill-effect. You will be able to quite literally cuss someone out while driving to dinner and have someone send you the video of you doing it (titled &#8220;This guy&#8217;s an asshole&#8221;) as you&#8217;re being seated. Who else is getting a copy of that video showing you inventing new ways to be vulgar?</p>

<p>The list of bad behavior that we all do constantly is nearly endless, but now it&#8217;ll be visible:</p>

<ul>
<li>Rudeness</li>
<li>Dirty looks</li>
<li>Bad Jokes</li>
<li>Foul language</li>
<li>Cruelty</li>
<li>Maliciousness</li>
<li>Snobbery</li>
<li>Condescension</li>
<li>Enjoying the Misfortune of Others</li>
</ul>

<h2>Everyone is a Reality Show Star About to Have a Big Break</h2>

<p>But it won&#8217;t be only bad things that are captured; the ever-present cameras will also catch the positive things:</p>

<ul>
<li>Random acts of kindness</li>
<li>Heroism (did they know they were being casted?)</li>
<li>Rescues</li>
<li>Extremely strange, unlikely events, i.e. freak occurrences</li>
<li>Humorous scenarios</li>
<li>Baby and child cuteness that would have otherwise been lost</li>
</ul>

<h2>The Concepts of Time and Location</h2>

<p>A particularly scary thing about this is the fact that any place with lots of people will be under what equates to constant surveillance. And virtually all video will include highly precise time and location metadata. Hanging out with that other guy or other girl in public will get a lot more difficult. &#8220;What the hell! Someone just sent me a cast of you at the mall with Cindy!&#8221;</p>

<p class="centered"><strong>It&#8217;ll be possible to simply type in a location and watch as various views of that place stream in and out. So the screen is black for a little bit because nobody is around, then all of a sudden you see the place from the north, and it passes quickly (someone in a car). Then you see it from the right, and it&#8217;s bobbing up and down (someone walking), plus you hear a conversation. Then the screen splits because you&#8217;re now seeing two different views of the same place. And you can even see the two people casing now, because their cameras are catching each other.</strong></p>

<h2>Customer Service Feedback?</h2>

<p>One of the things that got me thinking about this was being the recipient of abominable customer service. I&#8217;ve seen people absolutely ignore me while shouting and playing with friends in the back &#8212; while I was clearly visible, only to come to the register, not look at me, and mumble, &#8220;Watchu wuh&#8221;</p>

<p>Imagine these types of events being captured constantly, with the option to instantly upload them to a given drop-off point to be reviewed by staff for that given company. So you clip your cast and send it to the URL for McDonald&#8217;s review service. It goes into a queue and gets acted upon immediately depending on severity.</p>

<p>Or even better, how about McDonald&#8217;s having staff that simply scan lifecasts that are coming from their stores&#8217; locations. So while it&#8217;d be kind of weird to put up full-time video cameras in their stores to track employee behavior they&#8217;d be able to simply query Google for all video coming from their stores&#8217; locations. They could get paid to just sit there and watch those feeds and look for corporate policy infractions.</p>

<p>So a customer gets a dirty look, or the lines are WAY too long at a particular location. A form isn&#8217;t filled out and mailed in by some customer a week later. No. It&#8217;s seen in real-time, escalated, and two minutes later a corporate manager is calling that store manager saying, &#8220;WTF?&#8221; Instead of saying, &#8220;some customer said one of your employees was rude.&#8221;, the manager will say, &#8220;I&#8217;m looking at a video of one of your employees being rude to customers. Take them off the line and fire them immediately.&#8221;</p>

<p>As with the other types of behavior, poor customer service in this new environment will have instant ramifications.</p>

<h2>Crime Fighting / Government Surveillance</h2>

<p>This is a big one, and it&#8217;s scary too. Ok, so we already see here what all is going to be captured. Now imagine law enforcement tapping into it. So many crimes that would have gone unsolved will now be trivial to take care of. Suspect grabbed a purse at location x then ran off to the north. Ok, show me all Google lifecast video for the area he just ran to (remember, most all video will have location metadata in it).</p>

<p class="centered">Parsing lifecasts will become a regular part of crime fighting.</p>

<p>Now add the government to it. Think of the NSA walking in to Google and demanding a full feed of their data. Now imagine their face, voice and other types of recognition software being trained on the full feed of incoming casting data. It&#8217;ll be like tapping into millions of sets of eyes to look for and track somebody.</p>

<p>The order to the computer will be: &#8220;Find Daniel Miessler.&#8221; At that point the interface will be irrelevant. Whether it&#8217;s phone, a static video camera or a lifecaster &#8212; it&#8217;ll all be the same &#8212; all being fed into the same search/analysis algorithm that can find my identifier tokens, e.g. credit card numbers, phone numbers, my voice, my facial characteristics, my license plate, or even someone browsing the web the way I tend to.</p>

<h2>Castwatching as a Service</h2>

<p>An entire new profession will arise from this. Castwatchers. People watching lifecasts for various reasons. You&#8217;ll have people watching lifecasts looking for celebrities so they can report on current locations. Imagine a Google Maps mashup called Oceans 17 &#8212; it tracks all celebrities that were in the movie, i.e. Brad Pitt, George Clooney, etc. and displays constantly updated markers on a Google map.</p>

<p>Of course, you roll over the icon and get their current activity. Like, drinking coffee &#8212; and the text is a link to buy the coffee they&#8217;re drinking. Oh, and on the side you can click to view the casts that are updating the location. In other words, here&#8217;s Brad Pitt from two tables over. Here&#8217;s Brad Pitt from the perspective of the waiter.</p>

<p>Then you&#8217;ll have reporters watching for new stories they can pounce on. In fact, there will be pools of trained analysts who can spot interesting behavior. And that can be sold as a service. So people will subscribe in order to look for blackmail-able offenses. So if you see someone that looks rich acting guilty while interacting with drugs or sex, research who the person is and give me their location.</p>

<p>Think of what the tabloids will do. Find me racism. Find me suffering. Find me sex. They&#8217;ll be paying these kind of services to dig up garbage that will sell.</p>

<h2>Security and Privacy</h2>

<p>Being in information security one of the things that freaks me out is that many people, if not most, are going to keep location-tracking / metadata enabled for at least their friends and family. And many are going to keep it enabled for everyone. People who get <strong>no</strong> attention can scarcely believe the &#8220;too much attention&#8221; problem even exists, so they&#8217;ll lifecast continuously and allow anyone and everyone to know exactly where they are. What could go wrong, right?</p>

<h2>Facial Recognition</h2>

<p>This one&#8217;s a bit farther in the future, but not too far. One of the most significant applications of lifecasting will be widespread use of facial recognition technology. This point is best made with an example. Let&#8217;s say you&#8217;re sitting in a restaurant near the door, and your casting camera has a view of people as they come in. Well, your device (your personal computer), which is currently called your phone &#8212; will take a picture of the person as they come in, try and get any other angles of the person if they were just uploaded by people in the same restaurant with another angle, and then it will use both/all of those images to perform a search on Google for that person.</p>

<p>Think about this. Every person you see, and hence your device sees, will get queried against Google for a match. If it finds the person, their identity information (whatever&#8217;s available) gets sent to your device. Your device will then perform its matchup algorithm on the data pulled down vs. your data that it already has. Where are they from? What do they like to do? Etc.</p>

<p>The next and most interesting extension of this functionality will be an addition to the crime fighting piece. It&#8217;s also the most scary. Carriers will offer subsidies for your service fees if you volunteer to use facial recognition at all times and allow law enforcement access to your uploads. So in other words, everyone casting with this service turned on will be helping the police, FBI, DHS, etc. catch the people they&#8217;re looking for.</p>

<p>They&#8217;ll be able to send profiles to your device and use your device (passively) to scan for those profiles. This will either be mandatory (depending on where our society is when this happens) or it may be a service that you choose to take part in as a &#8220;good citizen&#8221;, with a reward of reduced cost for your other addons.</p>

<h2>Accidents</h2>

<p>Imagine the video that will be available of car (and other vehicle) accidents. If you thought the video on &#8220;Crazy Car Crashes&#8221; was extreme, wait till you have visibility to 100,000% more crashes.</p>

<h2>Drama</h2>

<p>We&#8217;ll start being exposed to some of the most touching and heartwrenching scenes ever witnessed. Real stuff. Imagine the scenarios that happen in the movies and on the TV shows, only real. All that stuff really happens; it happens every day, but it&#8217;s never captured. But now it will be, and many of the subjects of the &#8220;best&#8221; drama will become instantly famous.</p>

<p>&#8220;She was the one in &#8220;the breakup&#8221;. Imagine the whole Internet watching a breakup between a couple that they didn&#8217;t know was being recorded. Millions will want to know about their lives. What are they doing now? Are they dating again? Who will pay to watch the &#8220;casts&#8221; of their first dates with their new boyfriends and girlfriends?</p>

<p>Also, aside from breakups, imagine the lovers in Paris. The handholding. The sweet words. The smiles. The laughs. These precious moments that have hardly ever been captured other than in Hollywood will now be regularly brought to billions. And once again, the participants will have the option to become famous, even if only for a moment.</p>

<h2>Fights</h2>

<p>Simple. Let&#8217;s say we&#8217;re currently only capturing a millionth of a percent of all fights. Now let&#8217;s bump that up to 3%. Now add knife fights. Attempted muggings. Shootouts. One defender, multiple assailants. All this stuff that there&#8217;s very little video on will now be captured on a regular basis.</p>

<h2>Instant Celebrity</h2>

<p>People who used to be unknown will quickly be discovered. That super fat guy at Arby&#8217;s? He&#8217;s online now. 140,000 views in 5 minutes. Someone just submitted his name. Here&#8217;s where he lives. Here&#8217;s his username on eBay. Oh, another caster is walking up to him now and asking him if he knows he&#8217;s famous. That&#8217;s being casted as well. Etc.</p>

<h2>Perspecive Sharing</h2>

<p>One of the coolest consumer benefits of this kind of thing is going to be the social-networking aspect. Right now we can call our friends, text them, send them email, and that&#8217;s about it. In Japan and Europe you can do a bit of video on a mobile phone, but it&#8217;s not all that ubiquitous yet.</p>

<p>Well once this is commonplace you&#8217;ll have another option for staying close to friends and family &#8212; changing to their perspective. Basically, they share out their camera to a group of people (I&#8217;m looking at you, identity services) and if you are in the group then when you click on their contact in your mobile device you&#8217;ll have multiple options:</p>

<ol>
<li>Voice call</li>
<li>Video call</li>
<li>Text</li>
<li>Email (will merge into others soon)</li>
<li>PerView (perspective view)</li>
</ol>

<p>This gives a whole new meaning to, &#8220;Dude, check this out.&#8221; When you send that to a friend now, via voice or text, it will be a prompt to change to your perspective. And it won&#8217;t matter if you&#8217;re on the other side of the country, or the world. You&#8217;re sitting in a restaraunt and a gorgeous woman is at the next table over. You are just eating your burger but you want your buddy to see how fine she is.</p>

<p>&#8220;PerView Ping Brian&#8221;, you say to your device. Brian is sitting at work and vocally accepts the incoming PerView ping (which he has setup to automatically begin a voice call as well) and he immediately sees the woman that you&#8217;re looking at. &#8220;Damn, dude&#8230;go ask her out. I&#8217;ll watch.&#8221;</p>

<h2>Countermeasures</h2>

<p>There&#8217;s no doubt that there&#8217;ll be a total backlash against casting (lifecasting). Many places will have signs displayed: &#8220;No lifecasting allowed.&#8221; Why? Because it&#8217;ll scare away customers. People will demand establishments to become safe from the eyes of the Internet. People will get wanded for cameras (which mobile phones will have anyway) when entering certain areas. Plus, who&#8217;s going to consent to having their mobile devices taken from them at the door? People will constantly be looking for who&#8217;s watching them. For who&#8217;s recording them.</p>

<p>In fact, many organizations will not only search people (that&#8217;ll be largely ineffective) but will actively jam the frequencies of the mobile devices to keep them from lifecasting from their environments.</p>

<p>The game will become figuring out how to cast from places that don&#8217;t want you casting from them. Remember, people will be going to these places to do the things that they don&#8217;t want anyone seeing. Now factor in the people who are paid to catch those same people doing those things. And a new arms race will begin.</p>

<h2>Language</h2>

<p>So what&#8217;s the lingo that will surround this new phenomenon? Here are a few obvious/unimaginative options. I&#8217;ll rely on readers to come up with better ones. First, for lifecasting itself:</p>

<ol>
<li>Lifecasting</li>
<li>Casting</li>
<li>Shooting</li>
<li>Being &#8220;live&#8221;</li>
<li>Streaming</li>
</ol>

<p>Then for going offline, i.e. NOT lifecasting.</p>

<ol>
<li>Going Dark</li>
<li>Unplugging</li>
<li>Dropping Off</li>
<li>Deadening</li>
<li>Hibernating</li>
</ol>

<h2>Conclusion</h2>

<p>I&#8217;m only barely touching the first few layers of this thing. It&#8217;s just massive. I&#8217;m kind of overwhelmed right now and just need to post this as-is despite it being a jumbled mess of word things. I&#8217;ll continue to work on the organization of the idea and add examples as I remember/think of them. I&#8217;ll also update it with ideas from the comments.</p>

<p>I&#8217;d love to hear your thoughts on the idea, i.e. do you think it will be as big as I think it will? If not, why not? What specifically will stop this from becoming reality?</p>

<p>My answer? Nothing.</p>

<h4>Notes</h4>

<ul>
<li>Thanks to Zed for helping me think through the concept over some chicken wings.</li>
</ul>
<div id="crp_related"><h3>Related Content</h3><ul><li><a href="http://danielmiessler.com/blog/my-favorite-feature-of-the-new-iphone-3gs" rel="bookmark" class="crp_title">My Favorite Feature of the New iPhone 3GS</a></li><li><a href="http://danielmiessler.com/blog/the-steam-water-and-ice-of-modern-communication" rel="bookmark" class="crp_title">The Steam, Water, and Ice of Modern Communication</a></li><li><a href="http://danielmiessler.com/blog/a-few-thoughts-on-social-networking-tools" rel="bookmark" class="crp_title">A Few Thoughts on Social Networking Tools</a></li><li><a href="http://danielmiessler.com/blog/google-and-big-brother" rel="bookmark" class="crp_title">Google and Big Brother</a></li><li><a href="http://danielmiessler.com/blog/personal-daemons-and-wuffie" rel="bookmark" class="crp_title">Personal Daemons and Wuffie</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://danielmiessler.com/blog/lifecasting-what-it-is-and-how-it-will-change-society/feed</wfw:commentRss>
		<slash:comments>41</slash:comments>
		</item>
		<item>
		<title>Why You Should Encrypt *All* of Your Google Activities [POC]</title>
		<link>http://danielmiessler.com/blog/why-you-should-encrypt-all-of-your-google-activities-poc</link>
		<comments>http://danielmiessler.com/blog/why-you-should-encrypt-all-of-your-google-activities-poc#comments</comments>
		<pubDate>Thu, 09 Aug 2007 15:54:57 +0000</pubDate>
		<dc:creator>Daniel Miessler</dc:creator>
				<category><![CDATA[Encryption]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://dmiessler.com/blogarchive/howto-encrypt-all-your-google-activities</guid>
		<description><![CDATA[Everyone loves Google. They want to be everything to everyone, and they&#8217;re getting pretty damn good at it. Once you start using their services it gets easier and easier to migrate more of your life to them. But there&#8217;s a slight problem. Google, like most other similar services, encrypts login traffic but not your content. [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: center"><img src="http://www.google.com/intl/en_ALL/images/logo.gif" title="google" alt="google" height="110" width="276" /></p>

<p>Everyone loves <a href="https://google.com/">Google</a>. They want to be everything to everyone, and they&#8217;re getting pretty damn good at it. Once you start using their services it gets easier and easier to migrate more of your life to them.<em> But there&#8217;s a slight problem.</em></p>

<p class="offset">Google, like most other similar services, encrypts login traffic <em>but not your content</em>. <strong>So the moment you&#8217;re signed in they switch to plain-text communications and send everything to you in the open.</strong></p>

<p>This means your mail, the news sources you read, your calendar events &#8212; are all able to be read by someone with access to any part of the network between you and Google. This could be your employer at work, the wireless network at your local coffee shop, whatever. This isn&#8217;t good.</p>

<p>Here&#8217;s an email I just sent myself over the default (unencrypted) connection:</p>

<p><center><img src="http://dmiessler.com/images/googleemail.png" title="googleemail" alt="googleemail" height="196" width="428" /></center>And here&#8217;s what I captured via <a href="http://dmiessler.com/study/tcpdump/"><code>tcpdump</code></a>.</p>

<p><center><img src="http://dmiessler.com/images/googlesubject.png" title="googlesubject" alt="googlesubject" height="98" width="408" /></center> <center><img src="http://dmiessler.com/images/thisisasecret.png" title="thisisasecret" alt="thisisasecret" height="42" width="403" /></center>That&#8217;s the whole email there for anyone to see. Luckily it&#8217;s easy to fix&#8230;</p>

<ol>
    <li><strong>Use Bookmarks for Your Google Services</strong>
Create bookmarks (or modify them if you already have them) for <a href="https://mail.google.com/mail/">Gmail</a>, <a href="https://www.google.com/calendar/">Google Calendar</a>, <a href="https://www.google.com/reader/">Google Reader</a>, and <a href="https://www.google.com/ig?hl=en">iGoogle</a> (your Google homepage) using <em><strong>https</strong></em> instead of <strong><em>http</em>, </strong>like so:<a href="https://mail.google.com/mail/"> https://mail.google.com/mail/.</a> Do this for <em>every</em> service that you use at Google.</li>
    <li><strong>Don&#8217;t Click on Links Within Google to Take You to Your Services</strong>
If you use <em>their</em> links Google will often take you to the unencrypted version because it&#8217;s easier on their servers. Use your links instead to ensure that your sessions are encrypted</li>
</ol>

<p>The more we depend on Google (or any other monolithic service) the more we need to safeguard the information they have of ours. One way we can help is by demanding (via secure bookmarks and other methods) that they send us our mail, news feeds, calendars, and other information over a secure connection.:</p>

<p class="post_update">[ <strong>Note</strong>: This is not a Google-specific problem. Most other services work in exactly the same way. The difference is that Google is so prolific and is becoming very successfully at getting people to use not only their email service but also their calendaring, news reader, instant messaging, their search (with history), etc. It's the all-in-one dynamic that makes it especially important to protect Google traffic. ]</p>
<div id="crp_related"><h3>Related Content</h3><ul><li><a href="http://danielmiessler.com/blog/this-is-why-you-should-be-encrypting-your-communications-with-google-traffic-included" rel="bookmark" class="crp_title">This is Why You Should Be Encrypting Your Communications with Google [Traffic Included]</a></li><li><a href="http://danielmiessler.com/blog/some-thoughts-on-googles-bookmarking-and-linkrolling-strategy" rel="bookmark" class="crp_title">Some Thoughts on Google&#8217;s Bookmarking and Linkrolling Strategy</a></li><li><a href="http://danielmiessler.com/blog/decision-2008-google-apps-vs-apples-mobileme" rel="bookmark" class="crp_title">Decision 2008: Google Apps vs. Apple&#8217;s MobileMe</a></li><li><a href="http://danielmiessler.com/blog/how-to-migrate-your-custom-domains-email-to-google-and-maintain-your-addresses" rel="bookmark" class="crp_title">How to Migrate Your Custom Domain&#8217;s Email to Google (And Maintain Your Addresses)</a></li><li><a href="http://danielmiessler.com/blog/7-essential-firefox-quicksearches" rel="bookmark" class="crp_title">7 Essential Firefox Quicksearches</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://danielmiessler.com/blog/why-you-should-encrypt-all-of-your-google-activities-poc/feed</wfw:commentRss>
		<slash:comments>192</slash:comments>
		</item>
		<item>
		<title>Is Facebook In Bed With The Government?</title>
		<link>http://danielmiessler.com/blog/is-facebook-in-bed-with-the-government</link>
		<comments>http://danielmiessler.com/blog/is-facebook-in-bed-with-the-government#comments</comments>
		<pubDate>Sat, 07 Apr 2007 00:49:33 +0000</pubDate>
		<dc:creator>Daniel Miessler</dc:creator>
				<category><![CDATA[Data Mining]]></category>
		<category><![CDATA[Government]]></category>
		<category><![CDATA[Politics]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://dmiessler.com/archives/1270</guid>
		<description><![CDATA[[ Video: Facebook Privacy Issues ] Related ContentAssange: &#8220;Facebook is the Most Appalling Spy Machine Ever Invented.&#8221;Facebook May Be Getting Skype Video ChattingFacebook Is Secretly Building A Phone &#124; TechcrunchI&#8217;m Waiting for Google&#8217;s Version of FacebookFaceBook vs. MySpace &#8212; A Matter of Class?]]></description>
			<content:encoded><![CDATA[<p>[ Video: <a href="http://albumoftheday.com/facebook/">Facebook Privacy Issues</a> ]</p>
<div id="crp_related"><h3>Related Content</h3><ul><li><a href="http://danielmiessler.com/blog/wikileaks-founder-facebook-is-the-most-appalling-spy-machine-that-has-ever-been-invented-tnw-facebook" rel="bookmark" class="crp_title">Assange: &#8220;Facebook is the Most Appalling Spy Machine Ever Invented.&#8221;</a></li><li><a href="http://danielmiessler.com/blog/facebook-may-be-getting-skype-video-chatting" rel="bookmark" class="crp_title">Facebook May Be Getting Skype Video Chatting</a></li><li><a href="http://danielmiessler.com/blog/facebook-is-secretly-building-a-phone-techcrunch" rel="bookmark" class="crp_title">Facebook Is Secretly Building A Phone | Techcrunch</a></li><li><a href="http://danielmiessler.com/blog/im-waiting-for-googles-version-of-facebook" rel="bookmark" class="crp_title">I&#8217;m Waiting for Google&#8217;s Version of Facebook</a></li><li><a href="http://danielmiessler.com/blog/facebook-vs-myspace-a-matter-of-class" rel="bookmark" class="crp_title">FaceBook vs. MySpace &#8212; A Matter of Class?</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://danielmiessler.com/blog/is-facebook-in-bed-with-the-government/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>A Poor Geek&#8217;s Copyright</title>
		<link>http://danielmiessler.com/blog/a-poor-geeks-copyright</link>
		<comments>http://danielmiessler.com/blog/a-poor-geeks-copyright#comments</comments>
		<pubDate>Tue, 13 Mar 2007 04:24:02 +0000</pubDate>
		<dc:creator>Daniel Miessler</dc:creator>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[Copyright]]></category>
		<category><![CDATA[Geek]]></category>
		<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://dmiessler.com/archives/1198</guid>
		<description><![CDATA[Fellow geeks, if you would, do me a huge favor and copy this text and put it in a safe place&#8230; &#8212;&#8211;BEGIN PGP MESSAGE&#8212;&#8211; Version: GnuPG v1.4.5 (Darwin) hQQOA11AgtNhPwrtEBAAzaEnUxjIz8sK4o//mROU59VrueX4+NkO58w3JgytYBdm paHwG7ZwE8JNJsOSxRFaGML+gC954ivV7j0fiRfMUnyziYM+KX8DIXWTls2Dq80i wE7WBz1Inr1gwS4s8uEfMiXHRxldAu2iaFx4AyqFI58vKkh6UsQF2UxMaoc+SuQS aDQioG00SDsc1JJPJwScolpp55CYBwYvGzFUklstgydjkM7AoBXdva4ZYZCg/vCN HzwH4yO6Uorw1tJkciyBv25ja23SDzpt8RCUI0vZqMUymvASgnxJO93tHVcX1Ecz 8wRyd04OMCecqvhR2KOwiVsNsVC9e/+99DC+x5c+WKH1pES5lMA+gScrSGaucrF0 ozyL2n/+roX2c5D4BF2U7iPpePvb2IjojSELmyQYgYGuPDEJawWdbjuy1w1xnGww 2n8Ihh6q67vhsuRJuE4cMhCFA1A+Rz/ecDx3o2CKRMAfzz5dQ+3N3bRhiDpfwfdO 8HeREJRaaEH3BwC3easpxZQPVgQ7C8g4bHq/3jgHK0Ru0As8QMMG1uT3dqTh7jlt hgZy0k9oIdQdg0IzzeQO1qnaA1PcjDdqoBl1EmB+C5HGsrJVKeyvydJkU/1kCgtv 36wsFztb2dOCowHmzaXKjkv8/+H8UHq79OZSt26G3TCzOAUVyBLoyqPrVYWEyFcP /2yisgsRvV4AI9E++I5JSUZS3KF2e7ATemivURKAa9dqehEpkgw4/LE6mLqWMe7Y UfpOP5WufDoNf8odAylWlBZk/vBiI7cD12Llzs05CObxpTZGBL2HqBDvZu1rTeH8 QEIldTBphCit4WACqtOxYc+7absg/X71c+8tlDjCXz0Vl9O1GLKrtDuT6wBXnIdk +Dr+1uFCLpjAVU8SIGd3REhV6S+lpf+ZcB+IG5EjfjFKEKm2p1KTkDxj1IwH6yt7 k8Pq04Ef5RV0Q9SgfvHoFD1LJvZGRmZj2thWeXclxG6v//Vue76Rmfd40mNdkoKs BaAHhalockopsIWGmVwS68cTjZzmCMl3EJwwS32R3TyYYhrqnlUmHPgNzlG0Juqo piNsEvk0zqmhySET6BeLe2zJSEKszUsYvV2kaur7MlBSWMTcSkxgOpRmDmDeYXZ5 dgTlJsgmrNeNs4iEjt21DtHnAywksSSuzSJZFmWnqSea3jjnw0cA1ccQYbXn+9yZ Ay7BNDfjqB8Qs82w1TfboepAdHMK5v4FyNdKlyt1XCwpIcQN6PjtUDvkv67k7SJT +bNjdXtALKC2h+Y4owAnM+48CgaVnv2E4mnp818VmE4CXuLG/Cmgipm5GQgVttJ5 q0O434hilfLyAem3hcaMpK3U+ltJH6uDFezDTh7G/+QR0ukBfW+MPwqt+ApACj2b GEGG1oB0U7K5nuett2xjsKbE+0V7Vv/6Sk2VKds/IRwYb+ER8wLJKEULzTKM2ADe a9cs7wLApN3az0t+ueBzCVC+EefzlQX+H7V9uWmrV95XehFNpJX0+hFFgd+uWEBZ mgFMrwZbB9xaL8EFp4cKxCBOWdqZnc/Zc39fMfISZIFGp+w3sU0q1Lp1KILubWbK Mw4YIhklj539e6uFKZHJvY/0PzRp1D08a9AzvLRnwb7tDHgd9qbPA8+YrUx083yV d8bu2uOxB4wMOnpr88OBYNpsF8QF4b4jp3XWm6/7nnexVTsx6KVxdLQQXZYmC2ZC [...]]]></description>
			<content:encoded><![CDATA[<p>Fellow geeks, if you would, do me a huge favor and copy this text and put it in a safe place&#8230;</p>

<p><codeblock>&#8212;&#8211;BEGIN PGP MESSAGE&#8212;&#8211;
Version: GnuPG v1.4.5 (Darwin)</codeblock></p>

<p>hQQOA11AgtNhPwrtEBAAzaEnUxjIz8sK4o//mROU59VrueX4+NkO58w3JgytYBdm
paHwG7ZwE8JNJsOSxRFaGML+gC954ivV7j0fiRfMUnyziYM+KX8DIXWTls2Dq80i
wE7WBz1Inr1gwS4s8uEfMiXHRxldAu2iaFx4AyqFI58vKkh6UsQF2UxMaoc+SuQS
aDQioG00SDsc1JJPJwScolpp55CYBwYvGzFUklstgydjkM7AoBXdva4ZYZCg/vCN
HzwH4yO6Uorw1tJkciyBv25ja23SDzpt8RCUI0vZqMUymvASgnxJO93tHVcX1Ecz
8wRyd04OMCecqvhR2KOwiVsNsVC9e/+99DC+x5c+WKH1pES5lMA+gScrSGaucrF0
ozyL2n/+roX2c5D4BF2U7iPpePvb2IjojSELmyQYgYGuPDEJawWdbjuy1w1xnGww
2n8Ihh6q67vhsuRJuE4cMhCFA1A+Rz/ecDx3o2CKRMAfzz5dQ+3N3bRhiDpfwfdO
8HeREJRaaEH3BwC3easpxZQPVgQ7C8g4bHq/3jgHK0Ru0As8QMMG1uT3dqTh7jlt
hgZy0k9oIdQdg0IzzeQO1qnaA1PcjDdqoBl1EmB+C5HGsrJVKeyvydJkU/1kCgtv
36wsFztb2dOCowHmzaXKjkv8/+H8UHq79OZSt26G3TCzOAUVyBLoyqPrVYWEyFcP
/2yisgsRvV4AI9E++I5JSUZS3KF2e7ATemivURKAa9dqehEpkgw4/LE6mLqWMe7Y
UfpOP5WufDoNf8odAylWlBZk/vBiI7cD12Llzs05CObxpTZGBL2HqBDvZu1rTeH8
QEIldTBphCit4WACqtOxYc+7absg/X71c+8tlDjCXz0Vl9O1GLKrtDuT6wBXnIdk
+Dr+1uFCLpjAVU8SIGd3REhV6S+lpf+ZcB+IG5EjfjFKEKm2p1KTkDxj1IwH6yt7
k8Pq04Ef5RV0Q9SgfvHoFD1LJvZGRmZj2thWeXclxG6v//Vue76Rmfd40mNdkoKs
BaAHhalockopsIWGmVwS68cTjZzmCMl3EJwwS32R3TyYYhrqnlUmHPgNzlG0Juqo
piNsEvk0zqmhySET6BeLe2zJSEKszUsYvV2kaur7MlBSWMTcSkxgOpRmDmDeYXZ5
dgTlJsgmrNeNs4iEjt21DtHnAywksSSuzSJZFmWnqSea3jjnw0cA1ccQYbXn+9yZ
Ay7BNDfjqB8Qs82w1TfboepAdHMK5v4FyNdKlyt1XCwpIcQN6PjtUDvkv67k7SJT
+bNjdXtALKC2h+Y4owAnM+48CgaVnv2E4mnp818VmE4CXuLG/Cmgipm5GQgVttJ5
q0O434hilfLyAem3hcaMpK3U+ltJH6uDFezDTh7G/+QR0ukBfW+MPwqt+ApACj2b
GEGG1oB0U7K5nuett2xjsKbE+0V7Vv/6Sk2VKds/IRwYb+ER8wLJKEULzTKM2ADe
a9cs7wLApN3az0t+ueBzCVC+EefzlQX+H7V9uWmrV95XehFNpJX0+hFFgd+uWEBZ
mgFMrwZbB9xaL8EFp4cKxCBOWdqZnc/Zc39fMfISZIFGp+w3sU0q1Lp1KILubWbK
Mw4YIhklj539e6uFKZHJvY/0PzRp1D08a9AzvLRnwb7tDHgd9qbPA8+YrUx083yV
d8bu2uOxB4wMOnpr88OBYNpsF8QF4b4jp3XWm6/7nnexVTsx6KVxdLQQXZYmC2ZC
mY9EI1oaC9niOu4IicsJEMWY3PaPfEnjh+mifvIunN92jMOtOHkF+0Aeymf2n0Rt
K25Xr6kFksjQRFhyvrT+BJd41FiJSANc7XC1b+/pVLufmlGPA+ZwWksoBvyw7kCi
IHjEk7gg9VkduRa1F2sXLmU1MgKCCFT+ptl/C+nXBFa3RwCE3xB4uzbd33kzLJbd
HT1qOVo2JZWTZ3MgzBpglv9NSKliPE7A1Ms9lhZL6IAk11U2RNypwTRCp8MkIHLI
JsGm8m9cC61T/XDmRPZ9R7iLNPf/fc7iEdL6w5sX+OzCkcPUHTUyC4Aoxe3hQXnX
X+KQ/bACGgwxmcvYhmxqjw+sHcDuxlCohq1VeUPbW8fq8oSV0trGeudZU7UBGCy9
hncZiBbNJGzbBHmMfVOsKw9cH+nVobbEJp5pSYGwLLXtdfqV59kdE95LEaHpol1r
BRqDSZq9KSLtUnIwTl9qV+Cg1bGhZpOd0hIAQPQzxDfoBH3oUJlfHREalgg5d0/Q
WwKR1bcAEuahwOwQbL5U6rFLLVtkyEtapCjM3D3kuMuMqhNwXio+GVT5w+ZdAafF
GDIIDyPnypZfunBfGK5nj5e4sbBhE2IdZiA77yoTUp2hqSldjO+2+fuYITS+5RDi
EKNC2Thj8avhl+x57o49IOYIDfSyaghVhtCHD/dgFroA0FXBTs9NKptpx6jslCp4
XuTpciLFuFP0uT9UZHeOuBhIzQe4TyOyMpZ734PlZQbE2AuIRBN0sXUJ0ENeJZTg
tjifhgpNo6TJrHn1DMgaKMrMxTDrRJn77+iB6YBdY2WLZD/lk9lQ+QtHo/IBTOI+
NZIyqFG9z6E/tMDdGJPTjY+ltLFZEAEvLEVgxazd81nMJwr8aOKSMSQB4IYGE7bx
4DyAbs/uVjt1ERnTAib6PNAvUQ==
=wftQ
&#8212;&#8211;END PGP MESSAGE&#8212;&#8211;</p>
<div id="crp_related"><h3>Related Content</h3><ul><li><a href="http://danielmiessler.com/blog/poor-geeks-copyright-version-2-patent-information" rel="bookmark" class="crp_title">Poor Geek&#8217;s Copyright (Version 2 : Patent Information)</a></li><li><a href="http://danielmiessler.com/blog/communicating-optimally-in-email" rel="bookmark" class="crp_title">Communicating Optimally in Email</a></li><li><a href="http://danielmiessler.com/blog/why-i-love-ruby" rel="bookmark" class="crp_title">Why I Love Ruby</a></li><li><a href="http://danielmiessler.com/blog/unix-geek-humor-3" rel="bookmark" class="crp_title">Unix Geek Humor</a></li><li><a href="http://danielmiessler.com/blog/iphone-nmap-results" rel="bookmark" class="crp_title">iPhone Nmap Results</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://danielmiessler.com/blog/a-poor-geeks-copyright/feed</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Hiding Your IP Address</title>
		<link>http://danielmiessler.com/blog/hiding-your-ip-address</link>
		<comments>http://danielmiessler.com/blog/hiding-your-ip-address#comments</comments>
		<pubDate>Wed, 28 Feb 2007 04:57:06 +0000</pubDate>
		<dc:creator>Daniel Miessler</dc:creator>
				<category><![CDATA[Learning]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://dmiessler.com/archives/1175</guid>
		<description><![CDATA[A short beginner&#8217;s explanation of why you can&#8217;t truly &#8220;hide your IP address&#8221;. Hiding Your IP Address Related ContentHow To Use Python To Get Your External IPThe Best Throwaway AddressThe Mailinator (Say it like Arnold)Study Finds Weaknesses in Single Sign-on Systems &#124; Network WorldProductivity: The Power Of Firefox Quicksearches]]></description>
			<content:encoded><![CDATA[<p>A short beginner&#8217;s explanation of why you can&#8217;t truly &#8220;hide your IP address&#8221;.</p>

<p><a href="http://dmiessler.com/study/hide_ip">Hiding Your IP Address</a></p>
<div id="crp_related"><h3>Related Content</h3><ul><li><a href="http://danielmiessler.com/blog/how-to-use-python-to-get-your-external-ip" rel="bookmark" class="crp_title">How To Use Python To Get Your External IP</a></li><li><a href="http://danielmiessler.com/blog/the-best-throwaway-address" rel="bookmark" class="crp_title">The Best Throwaway Address</a></li><li><a href="http://danielmiessler.com/blog/the-mailinator-say-it-like-arnold" rel="bookmark" class="crp_title">The Mailinator (Say it like Arnold)</a></li><li><a href="http://danielmiessler.com/blog/study-finds-weaknesses-in-single-sign-on-systems-network-world" rel="bookmark" class="crp_title">Study Finds Weaknesses in Single Sign-on Systems | Network World</a></li><li><a href="http://danielmiessler.com/blog/the-power-of-firefox-quicksearches" rel="bookmark" class="crp_title">Productivity: The Power Of Firefox Quicksearches</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://danielmiessler.com/blog/hiding-your-ip-address/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Security: Implementing A Secure And Usable Internet Password Scheme</title>
		<link>http://danielmiessler.com/blog/security-implementing-a-secure-and-usable-internet-password-scheme</link>
		<comments>http://danielmiessler.com/blog/security-implementing-a-secure-and-usable-internet-password-scheme#comments</comments>
		<pubDate>Tue, 13 Feb 2007 16:34:23 +0000</pubDate>
		<dc:creator>Daniel Miessler</dc:creator>
				<category><![CDATA[Internet]]></category>
		<category><![CDATA[Passwords]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Sysadmin]]></category>
		<category><![CDATA[Technology]]></category>

		<guid isPermaLink="false">http://dmiessler.com/archives/1136</guid>
		<description><![CDATA[Being an information security consultant I am often asked how to balance the need for online passwords that are both hard to guess and easy to remember. There are a number of solutions out there for dealing with the problem, but the system that I&#8217;m about to outline below is an elegant hybrid of simplicity [...]]]></description>
			<content:encoded><![CDATA[<p>Being an information security consultant I am often asked how to balance the need for online passwords that are both hard to guess and easy to remember. There are a number of solutions out there for dealing with the problem, but the system that I&#8217;m about to outline below is an elegant hybrid of simplicity and security. It works for me, and I think it can work for you as well.</p>

<p style="text-align: center"><img src="http://dmiessler.com/images/padlock.jpeg" title="Padlock" alt="Padlock" height="100" width="100" /></p>

<h4>The Problem</h4>

<p>The main issue we&#8217;re all grappling with is the number and complexity of the passwords we need to remember. Ideally, we would never share a password between any two sites. They would all be different and at the same time highly complex. Unfortunately, this doesn&#8217;t mesh well with reality. The human brain just isn&#8217;t up to the task.</p>

<h4>Simplification Through Classification</h4>

<p>The way we get around this limitation is to classify our online accounts according to risk. In other words, we&#8217;re going to determine how important each of our accounts are, and then put them into one of three (3) groups. For the purposes of this article we&#8217;ll use the military classifications.</p>

<ol>
    <li>Top Secret</li>
    <li>Secret</li>
    <li>Confidential</li>
</ol>

<p>Next we&#8217;ll simply group your Internet account types into each of these categories:</p>

<ul>
    <li><strong>Top Secret</strong>
Banking, brokerages, financially or identity-oriented sites. Think about your social security number and other sensitive personal data. Any accounts of this nature you want to protect with your strongest layer of security.</li>
    <li><strong>Secret</strong>
Personal email, blogging sites, important forums, etc. These are your main accounts that you use on a day-to-day basis. They aren&#8217;t ultra-sensitive, but they a huge part of your life and need to be secure.</li>
    <li> <strong>Confidential</strong>
Product forums, mailing lists, etc. These are your low-risk accounts, meaning that if one were to be compromised it would be annoying but not a major problem. We&#8217;re still going to have relatively strong passwords here, but they&#8217;re going to be simple in comparison to the two higher levels.</li>
<small>** Also keep in mind whether or not a site supports encrypted logins or not when assigning your accounts to these groups. Never put an account into the top two groups (Top Secret or Secret) if that site doesn&#8217;t support encryption. We don&#8217;t want someone possibly intercepting one of your upper-level passwords.</small></ul>

<h4>Designing Our Password Schemes</h4>

<p>Ok, now that you have your accounts grouped properly it&#8217;s time to design our three password systems. We&#8217;ll start with the Top Secret:</p>

<p><font color="red"><strong>Level 1 &#8212; Top Secret:
</strong></font>
For this level we&#8217;re going to use a combination of upper-case, lower-case, numbers, and special characters. We&#8217;re also going to make the password at least 12 characters in length. You will be writing these passwords down on a card in your wallet or purse, so it doesn&#8217;t matter if you can&#8217;t remember the password at first. After you use it a few times it&#8217;ll become second nature regardless of how complex it is. Try something like this:</p>

<p><font color="red" size="3"><strong>    5PF.c9a8&gt;12!</strong></font></p>

<p>It looks pretty scary, but you&#8217;d be surprised how easy it is to remember once you type it a few times over a number of days. The point is that it&#8217;s <em>not</em> going to be guessed, and it&#8217;s not going to be tied to another account. If you absolutely have to, you can use a sentence algorithm to build the password, like so:</p>

<p><em>My Online Bank Password Is Not Simple To Guess At All, Julie.</em></p>

<p><font color="red" size="3"><strong>    M0bP1n5tGAAJ.</strong></font></p>

<p>You will be writing these passwords down on a card in your wallet or purse, so it doesn&#8217;t matter if you can&#8217;t remember the password at first. After you use it a few times it&#8217;ll become second nature regardless of how complex it is.</p>

<blockquote>One point on writing down passwords: Many people think this is a bad idea, but that fully depends on how you secure them once their written down. Sticky note on monitor? Bad. Wallet? Good. You have to balance the risk of strong passwords in your wallet vs. weak ones in your brain.</blockquote>

<p>Regardless of the scheme you use to create your passwords, you want them to be a) pseudo-random/highly complex, b) over 10 characters in length, and d) <em>absolutely unique</em>. In short, we don&#8217;t want someone with your brokerage account password to be able to log into your bank with the same credentials.</p>

<p><font color="blue"><strong>Level 2 &#8212; Secret:</strong></font></p>

<p>With the secret level accounts we&#8217;re going to introduce an aspect of simplicity/usability. We&#8217;ll do this by creating an algorithm for creating and varying passwords for various sites while still maintaining the appearance of randomness within each individual password.</p>

<blockquote>In short, all level 2 (Secret) passwords will be generated by the same algorithm. As such, they&#8217;ll look very similar to you, but will look like random garbage when viewed independently by an outsider.</blockquote>

<p>So let&#8217;s build your Level-2 (Secret) algorithm; we&#8217;ll use a Gmail account as a template:</p>

<p><small>[This is just a <em>sample</em> algorithm; you should make your own.]</small></p>

<ol>
    <li>First two letters + last letter of the account.
GML</li>
    <li>Add the three letters up and subtract your birthday.
G (7) + M (13) + L (12) = 32 &#8211; 15 (if you&#8217;re born on the 15th) = 17
<em>GML17</em></li>
    <li>Add the two numbers you made to create a third number.
17 = 1 + 7 = 8
<em>GML178</em></li>
    <li>Add a word for length. Use character substitution for complexity if you want.
<em>GML178H0lid4y</em></li>
    <li>Add special characters.
<em>!GML178H0lid4y#</em></li>
    <li>Scramble as desired.<font color="blue" size="3"><strong> </strong></font><font color="blue" size="3"><strong> </strong></font><font color="blue" size="3"><strong> </strong></font><font color="blue" size="3"><strong>

!H0lid4y#GML178#</strong></font></li>
</ol>

<p>You now have a very solid password for your Gmail account. But it gets much better than that. You&#8217;re using the same algorithm for all your level 2 accounts. So do the same for your Hotmail account and you&#8217;ll end up with:</p>

<p><font color="blue" size="3"><strong>!H0lid4y#HOL358#</strong></font></p>

<p><font color="green"><strong>Level 3 &#8212; Confidential:</strong></font></p>

<p>For our lowest security level (3) we&#8217;re going to use an algorithm similar to the secret level (2), only it&#8217;s going to be completely different and much simpler. Remember, these are your unimportant accounts; you wouldn&#8217;t want them to be compromised, of course, but if they were then it wouldn&#8217;t be that big of a deal.</p>

<p>Let&#8217;s make a level 3 algorithm for a site called cars.com:</p>

<ol>
    <li>Last letter then first letter of the site (cars).
<em>SC</em></li>
    <li>A word to be used for all your low level accounts. Add a single character of number substitution (i to 1)
<em>SCPubl1c</em></li>
    <li>Use a special character.
<em>SCPubl1c$</em></li>
    <li>Scramble as desired.<font color="green" size="3"><strong> </strong></font><font color="green" size="3"><strong> </strong></font><font color="green" size="3"><strong> </strong></font><font color="green" size="3"><strong>

$Publ1cSC</strong></font></li>
</ol>

<p>Again, you now have a decent password that&#8217;s not easy to guess and will give a bit of difficulty if someone gets one and tries to guess others. Of course, if they get one of these level 3 passwords and try to break your Secret (2) or Top Secret (1) passwords, they&#8217;ll be unsuccessful.</p>

<h4>Conclusion</h4>

<p>Using this system can increase both security and usability when working with multiple accounts online. Here are a few additional guidelines about this technique and passwords in general:</p>

<ul>
    <li>Vary your algorithm for level 2 and 3 accounts regularly (I recommend at least once a year)</li>
    <li>Memorize your algorithm and write down your <em>passwords</em> on a card in your wallet. Don&#8217;t write down the algorithm itself. Just seeing a password created with it should jar your memory.</li>
    <li>For an extra layer of security you can consider leaving out or modifying a crucial part of the passwords you write down. This way, even someone with the card will not be able to use it. Be warned that if you forget what you changed, however, you&#8217;ll be very upset.</li>
    <li>Change your level 1 passwords often as well. With the strength that we&#8217;re using in this article I&#8217;d advocate once every 6-months.</li>
    <li>Many also use what&#8217;s effectively a level 4 account, i.e. a throw-away password that is used for accounts even lower in importance than level 3. Usually this is a static password. Just be sure to be very selective about where you use such a password, and make it as complex and long as possible while retaining its benefit of simplicity.</li>
    <li>An <a href="http://www.schneier.com/passsafe.html">encrypted database</a> is another option for managing passwords. I advocate this method over that one due to issues with losing or damaging the portable storage that the DB is stored on, in addition to not being comfortable with using such a system on a foreign computer (where necessarily you open ALL of your passwords to the system being used). It&#8217;s really a matter of personal preference, however, as both systems have their strengths and weaknesses.</li>
</ul>

<p>I hope this has been useful. For any questions or comments, please feel free to <a href="http://dmiessler.com/contact/">contact me</a> directly.:</p>
<div id="crp_related"><h3>Related Content</h3><ul><li><a href="http://danielmiessler.com/blog/the-list-of-shame-websites-that-dont-allow-special-characters-in-their-passwords" rel="bookmark" class="crp_title">The List Of Shame: Websites That Don&#8217;t Allow Special Characters In Their Passwords</a></li><li><a href="http://danielmiessler.com/blog/password-reset-mechanisms-the-online-security-threat-nobodys-talking-about" rel="bookmark" class="crp_title">Password Reset Mechanisms: The Online Security Threat Nobody&#8217;s Talking About</a></li><li><a href="http://danielmiessler.com/blog/lame-online-password-logic" rel="bookmark" class="crp_title">Lame Online Password Logic</a></li><li><a href="http://danielmiessler.com/blog/new-project-passwordstandardscom" rel="bookmark" class="crp_title">New Project: PasswordStandards.com</a></li><li><a href="http://danielmiessler.com/blog/never-argue-again-about-the-pronunciation-of-os-x-proof-included" rel="bookmark" class="crp_title">Never Argue Again About The Pronunciation Of &#8220;OS X&#8221; (Proof Included)</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://danielmiessler.com/blog/security-implementing-a-secure-and-usable-internet-password-scheme/feed</wfw:commentRss>
		<slash:comments>9</slash:comments>
		</item>
		<item>
		<title>Understanding The Diffie-Hellman Protocol</title>
		<link>http://danielmiessler.com/blog/understanding-the-diffie-hellman-protocol</link>
		<comments>http://danielmiessler.com/blog/understanding-the-diffie-hellman-protocol#comments</comments>
		<pubDate>Fri, 01 Dec 2006 16:13:30 +0000</pubDate>
		<dc:creator>Daniel Miessler</dc:creator>
				<category><![CDATA[Encryption]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://dmiessler.com/archives/1025</guid>
		<description><![CDATA[For anyone interested, I just completed a short write-up on the Diffie-Hellman protocol.: Understanding The Diffie-Hellman Protocol Related ContentThe Beauty of the Diffie-Hellman ProtocolDiffie-HellmanProtocols: Diffie-Hellman Explaineddanielmiessler.com/study/subnettingThe Pubsubhubub Protocol]]></description>
			<content:encoded><![CDATA[<p>For anyone interested, I just completed a short write-up on the Diffie-Hellman protocol.:</p>

<p><a href="http://dmiessler.com/study/diffiehellman">Understanding The Diffie-Hellman Protocol</a></p>
<div id="crp_related"><h3>Related Content</h3><ul><li><a href="http://danielmiessler.com/blog/the-beauty-of-the-diffie-hellman-protocol" rel="bookmark" class="crp_title">The Beauty of the Diffie-Hellman Protocol</a></li><li><a href="http://danielmiessler.com/blog/diffie-hellman" rel="bookmark" class="crp_title">Diffie-Hellman</a></li><li><a href="http://danielmiessler.com/blog/protocols-diffie-hellman-explained" rel="bookmark" class="crp_title">Protocols: Diffie-Hellman Explained</a></li><li><a href="http://danielmiessler.com/blog/dmiesslercomstudysubnetting" rel="bookmark" class="crp_title">danielmiessler.com/study/subnetting</a></li><li><a href="http://danielmiessler.com/blog/the-pubsubhubub-protocol" rel="bookmark" class="crp_title">The Pubsubhubub Protocol</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://danielmiessler.com/blog/understanding-the-diffie-hellman-protocol/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Malware Using Tor?</title>
		<link>http://danielmiessler.com/blog/malware-using-tor</link>
		<comments>http://danielmiessler.com/blog/malware-using-tor#comments</comments>
		<pubDate>Thu, 13 Jul 2006 03:24:59 +0000</pubDate>
		<dc:creator>Daniel Miessler</dc:creator>
				<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://dmiessler.com/archives/811</guid>
		<description><![CDATA[So it seems there are some reports of malware using Tor now. Inevitable perhaps, but no less scary. Related ContentDistributed WordPress Admin Account Cracking &#124; isc.sans.orgMcAfee: Nearly All New Mobile Malware In Q3 Targeted At Android Phones &#124; TechCrunchDown the RogueAV and Blackhat SEO Rabbit Hole &#124; SANSSnort IDS Sensor with Sguil Framework ISO &#124; [...]]]></description>
			<content:encoded><![CDATA[<p>So it seems <a href="http://isc.sans.org/diary.php?storyid=1477&#038;rss">there are some reports</a> of malware using <a href="http://tor.eff.org">Tor</a> now. Inevitable perhaps, but no less scary.</p>
<div id="crp_related"><h3>Related Content</h3><ul><li><a href="http://danielmiessler.com/blog/distributed-wordpress-admin-account-cracking" rel="bookmark" class="crp_title">Distributed WordPress Admin Account Cracking | isc.sans.org</a></li><li><a href="http://danielmiessler.com/blog/mcafee-nearly-all-new-mobile-malware-in-q3-targeted-at-android-phones-techcrunch" rel="bookmark" class="crp_title">McAfee: Nearly All New Mobile Malware In Q3 Targeted At Android Phones | TechCrunch</a></li><li><a href="http://danielmiessler.com/blog/down-the-rogueav-and-blackhat-seo-rabbit-hole-sans" rel="bookmark" class="crp_title">Down the RogueAV and Blackhat SEO Rabbit Hole | SANS</a></li><li><a href="http://danielmiessler.com/blog/snort-ids-sensor-with-sguil-framework-iso-sans-isc" rel="bookmark" class="crp_title">Snort IDS Sensor with Sguil Framework ISO | SANS ISC</a></li><li><a href="http://danielmiessler.com/blog/new-malware-protection-using-big-data-analytics-from-sourcefire" rel="bookmark" class="crp_title">New Malware Protection Using Big Data Analytics From Sourcefire</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://danielmiessler.com/blog/malware-using-tor/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Help Reform The Patriot Act</title>
		<link>http://danielmiessler.com/blog/help-reform-the-patriot-act</link>
		<comments>http://danielmiessler.com/blog/help-reform-the-patriot-act#comments</comments>
		<pubDate>Sat, 18 Feb 2006 16:30:19 +0000</pubDate>
		<dc:creator>Daniel Miessler</dc:creator>
				<category><![CDATA[Government]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Politics]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://dmiessler.com/archives/707</guid>
		<description><![CDATA[The current Patriot Act is desperately in need of reform, and if we as citizens don&#8217;t make ourselves heard, nothing is going to be done about it. Rather than go into the details myself, here are a few paragraphs from Sentator Russ Feingold&#8217;s speech to the Senate. It&#8217;s long, but this is the future of [...]]]></description>
			<content:encoded><![CDATA[<p>The current Patriot Act is desperately in need of reform, and if we as citizens don&#8217;t make ourselves heard, nothing is going to be done about it. Rather than go into the details myself, here are a few paragraphs from <a href="http://feingold.senate.gov/~feingold/statements/06/02/2006215.html">Sentator Russ Feingold&#8217;s speech to the Senate</a>. It&#8217;s long, but this is the future of our country&#8217;s freedoms we&#8217;re talking about. If you are moved by what the Senator has said here, I implore you to <a href="http://www.theorator.com/senate.html">write or call your representatives</a> and let them know you support Senator Feingold&#8217;s position.</p>

<p>The thing is, we literally forfeit our right to complain about our rights being taken away if we are too lazy to take 10 minutes out of a single day to make a couple phone calls or send a couple emails. If you care about this country at all, please read the text below and act on it via the link above.</p>

<blockquote>I want to remind my colleagues of the serious problems with the Patriot            Act that we have been discussing for several years. Let me start with            Section 215, the so-called “library” provision, which has            received so much public attention. I remember when the former Attorney            General of the United States called the librarians who were expressing            disagreement with this provision “hysterical.” What a revelation            it was when the Chairman of the Judiciary Committee, the Senator from            Pennsylvania, opened his questioning of the current Attorney General            during his confirmation hearing by expressing concern about this provision            of the Patriot Act. He got the Attorney General to concede that yes,            in fact, this provision probably went a bit too far and could be improved            and clarified. That was an extraordinary moment.

It was a moment that was very slow in coming, and long overdue. And            I give credit to the Senator from Pennsylvania because it allowed us            to start having a real debate on the Patriot Act. But credit also has            to go to the American people who stood up, despite the dismissive and            derisive comments of government officials, and said with loud voices            – the Patriot Act needs to be changed.

These voices came from the left and the right, from big cities and            small towns all across the country. So far, more than 400 state and            local government bodies have passed resolutions calling for revisions            to the Patriot Act. I plan to read some of those resolutions on the            floor during this debate. There are a lot of them. And nearly every            one mentions Section 215. Section 215 is at the center of this debate            over the Patriot Act. It is also one of the provisions that I tried            unsuccessfully to amend here on this floor in October 2001. So it makes            sense to start my discussion of the specific problems I have with the            conference report with the infamous “library” provision.

Section 215 of the Patriot Act allows the government to obtain secret            court orders in domestic intelligence investigations to get all kinds            of business records about people, including not just library records,            but also medical records and various other types of business records.            The Patriot Act allowed the government to obtain these records as long            as they were “sought for” a terrorism investigation. That’s            a very low standard. It didn’t require that the records concern            someone who was suspected of being a terrorist or spy, or even suspected            of being connected to a terrorist or spy. It didn’t require any            demonstration of how the records would be useful in the investigation.            Under Section 215, if the government simply said it wanted records for            a terrorism investigation the secret FISA court was required to issue            the order &#8212; period. To make matters worse, recipients of these orders            are also subject to an automatic gag order. They cannot tell anyone            that they have been asked for records.

Now some in the Administration, and even in this body, took the position            that people shouldn’t be able to criticize these provisions until            they could come up with a specific example of “abuse.” The            Attorney General has repeatedly made that same argument, and he did            so again in December in an op-ed in the Washington Post when he dismissed            concerns about the Patriot Act by saying that “[t]here have been            no verified civil liberties abuses in the four years of the act’s            existence.” First of all, that has always struck me as a strange            argument since 215 orders are issued by a secret court and people who            receive them are prohibited by law from discussing them. In other words,            the law is designed so that it’s almost impossible to know if            abuses have occurred.

But even more importantly, the claim about lack of abuses just isn’t            credible given what we now know about how this Administration views            the surveillance laws that this body writes. We now know that for the            past four-plus years, the government has been wiretapping the international            communications of Americans inside the United States, without obtaining            the wiretap orders required by statute. You want to talk about abuses?            I can’t imagine a more shocking example of an abuse of power,            than to violate the law by eavesdropping on American citizens without            first getting a court order based on some evidence that they are possibly            criminals, terrorists or spies. So I don’t want to hear again            from the Attorney General or anyone on this floor that this government            has shown it can be trusted to use the power we give it with restraint            and care.

The government should not have the kind of broad, intrusive powers            in Section 215 – not this government, not any government. And            the American people shouldn’t have to live with a poorly drafted            provision that clearly allows for the records of innocent Americans            to be searched and just hope that the government uses it with restraint.            A government of laws doesn’t require its citizens to rely on the            good will and good faith of those who have these powers – especially            when adequate safeguards can be written into the laws without compromising            their usefulness as a law enforcement tool.</blockquote>
<div id="crp_related"><h3>Related Content</h3><ul><li><a href="http://danielmiessler.com/blog/anti-government-reddit-nugget" rel="bookmark" class="crp_title">Anti-Government Reddit Nugget</a></li><li><a href="http://danielmiessler.com/blog/a-real-solution-to-the-israelipalestinian-conflict" rel="bookmark" class="crp_title">A Real Solution To The Israeli/Palestinian Conflict</a></li><li><a href="http://danielmiessler.com/blog/joe-biden-voted-for-the-war" rel="bookmark" class="crp_title">Joe Biden Voted FOR the War</a></li><li><a href="http://danielmiessler.com/blog/obamas-new-plan" rel="bookmark" class="crp_title">Obama&#8217;s New Plan?</a></li><li><a href="http://danielmiessler.com/blog/the-logical-solution-to-the-civil-union-vs-marriage-debate" rel="bookmark" class="crp_title">The Logical Solution to the Civil Union vs. Marriage Debate</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://danielmiessler.com/blog/help-reform-the-patriot-act/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Why Don&#8217;t We Clean Up The PGP Key Servers?</title>
		<link>http://danielmiessler.com/blog/why-dont-we-clean-up-the-pgp-key-servers</link>
		<comments>http://danielmiessler.com/blog/why-dont-we-clean-up-the-pgp-key-servers#comments</comments>
		<pubDate>Thu, 16 Feb 2006 07:05:30 +0000</pubDate>
		<dc:creator>Daniel Miessler</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Infosec]]></category>
		<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://dmiessler.com/archives/706</guid>
		<description><![CDATA[I think the InfoSec community needs to make a push to purge the PGP key servers. I think it&#8217;d be nice to start off with a clean slate, you know? Virtually everyone I know has at least one public key up on a server that they no longer have the secret key for. It&#8217;s a [...]]]></description>
			<content:encoded><![CDATA[<p>I think the InfoSec community needs to make a push to purge the <a href="http://www.google.com/search?q=pgp%20key%20servers">PGP key servers</a>. I think it&#8217;d be nice to start off with a clean slate, you know? Virtually everyone I know has at least one public key up on a server that they no longer have the secret key for. It&#8217;s a cluster to the n<sup>th</sup> degree.</p>

<p>I just think it&#8217;d be nice to start fresh. Everyone who manages keyservers could send a series of notification emails to the addresses listed in their key database, and after like a year (or whatever agreed upon amount of time), the deletions would begin.</p>

<p>Worst case scenario is that some people need to re-upload their public keys. I think it&#8217;s a small price to pay given the resulting &#8220;fresh&#8221; feeling. I for one can&#8217;t stand looking at all those redundant, orphaned keys &#8212; it&#8217;s the <acronym title="Obsessive Compulsive">OC</acronym> in me I suppose.</p>

<p>Thoughts? Anyone agree?</p>
<div id="crp_related"><h3>Related Content</h3><ul><li><a href="http://danielmiessler.com/blog/basic-gpg-commands" rel="bookmark" class="crp_title">Basic GPG Commands</a></li><li><a href="http://danielmiessler.com/blog/database-an-overdue-project" rel="bookmark" class="crp_title">Database &#8212; An Overdue Project</a></li><li><a href="http://danielmiessler.com/blog/under-fire" rel="bookmark" class="crp_title">Under Fire</a></li><li><a href="http://danielmiessler.com/blog/a-list-of-googles-dns-servers" rel="bookmark" class="crp_title">A List of Google&#8217;s DNS Servers</a></li><li><a href="http://danielmiessler.com/blog/voip-security" rel="bookmark" class="crp_title">VOIP Security</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://danielmiessler.com/blog/why-dont-we-clean-up-the-pgp-key-servers/feed</wfw:commentRss>
		<slash:comments>17</slash:comments>
		</item>
		<item>
		<title>Google&#8217;s Inevitable Betrayal</title>
		<link>http://danielmiessler.com/blog/googles-inevitable-betrayal</link>
		<comments>http://danielmiessler.com/blog/googles-inevitable-betrayal#comments</comments>
		<pubDate>Wed, 15 Feb 2006 16:20:24 +0000</pubDate>
		<dc:creator>Daniel Miessler</dc:creator>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[Philosophy]]></category>
		<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://dmiessler.com/archives/703</guid>
		<description><![CDATA[Tons of people all over the Internets are shedding all vestiges of sanity over how much information Google has access to. They&#8217;re especially rabid over the fact that Google is now archiving all chats. Many view this as proof that the company is heading down a dark path &#8212; a path that will eventually lead [...]]]></description>
			<content:encoded><![CDATA[<p>Tons of people all over the Internets are shedding all vestiges of sanity over how much  information Google has access to. They&#8217;re especially rabid over the fact that <a href="http://news.com.com/Google+merges+Gmail+with+chat/2100-1032_3-6035898.html">Google is now archiving all chats</a>.</p>

<p>Many view this as proof that the company is heading down a dark path &#8212; a path that will eventually lead to them knowing virtually everything about their account holders.</p>

<p><em>I disbelieve.</em></p>

<p>I have seen nothing but honesty from the company since I began using their search engine in 1999. I have a high level of confidence that they are using my information for the reasons they claim, and not for some hidden, malicious purpose.</p>

<p><strong>However &#8212; and this is a big one &#8212; this is all contingent on their current management structure.</strong></p>

<p>This debate really needs to focus on the people in charge more than anything else. They are the ones who control the &#8220;morality&#8221; of the company&#8217;s culture. As I said, I&#8217;m relatively comfortable with them right now due to how they&#8217;ve conducted themselves over the years, but that could change in one night. One bad meeting, one change in the personal life of a key decision-maker &#8212; any number of catalysts could send the company over the edge.</p>

<p><em>Imagine a room full of highly explosive gas, and then imagine a giant match. Well, the room full of gas is Google, only it&#8217;s a room the size of 10,000 football stadiums, and it&#8217;s growing every day. So the issue isn&#8217;t so much whether or not the current management staff is the match, the issue instead is the fact that there will inevitably be one at some point.</em></p>

<p>So the question then becomes &#8212; how much of your information do you want Google to have of yours when they <strong>do</strong> have that management change and open their doors to the government (and God knows who else)? This, by the way, is the match.
If you think about it, it&#8217;s actually quite easy to see. I believe the current heads of Google are decent, honest people, but do you want to bank your life&#8217;s information on the fact that they will always be there? Can you be sure they will always be successful at keeping those who want their infomation at bay?</p>

<p>Think about how much profit potential Google represents to someone willing to take advantage of it for business purposes, or how much intelligence information it holds about account holders. It&#8217;s seriously mind-boggling, and to believe that a few good people will be able to perpetually defend this massive gold mine is an exercise in naivity.</p>

<p><em>My point is simple &#8212; don&#8217;t overreact and label Google as the great Satan or some variant thereof; that&#8217;s just being a little silly at this point. But at the same time we need to stay aware of what could, and arguably <em>will</em>, happen in the future.</em></p>

<p>As for me, I&#8217;m going to continue using Google; they&#8217;re an exciting company that continues to bring out some awesome products. But I won&#8217;t be using it as a primary system for personal correspondence. I prefer having all my mail under my control, i.e. on a <acronym title="Linux Apache Mysql PHP">LAMP</acronym> server that I admnister. So I may use the mail forwarding from time to time, or Analytics, or whatever other cool stuff they come up with as time goes on, but I&#8217;m not going to drink the punch.:</p>
<div id="crp_related"><h3>Related Content</h3><ul><li><a href="http://danielmiessler.com/blog/how-to-migrate-your-custom-domains-email-to-google-and-maintain-your-addresses" rel="bookmark" class="crp_title">How to Migrate Your Custom Domain&#8217;s Email to Google (And Maintain Your Addresses)</a></li><li><a href="http://danielmiessler.com/blog/filtering-non-gmail-email-with-gmail" rel="bookmark" class="crp_title">Filtering Non-Gmail Email With Gmail</a></li><li><a href="http://danielmiessler.com/blog/why-you-should-encrypt-all-of-your-google-activities-poc" rel="bookmark" class="crp_title">Why You Should Encrypt *All* of Your Google Activities [POC]</a></li><li><a href="http://danielmiessler.com/blog/google-instead-of-local-applications" rel="bookmark" class="crp_title">Google Instead Of Local Applications?</a></li><li><a href="http://danielmiessler.com/blog/this-is-why-you-should-be-encrypting-your-communications-with-google-traffic-included" rel="bookmark" class="crp_title">This is Why You Should Be Encrypting Your Communications with Google [Traffic Included]</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://danielmiessler.com/blog/googles-inevitable-betrayal/feed</wfw:commentRss>
		<slash:comments>10</slash:comments>
		</item>
	</channel>
</rss>

