‘Picking on’ Volkswagen: Why Follow Dieselgate?

[photo: macwagen via Flickr]

[photo: macwagen via Flickr]

One of our commenters described my attention to Dieselgate as ‘picking on’ Volkswagen. It’s not as if there haven’t been scandalous problems with other automotive industry manufacturers, like General Motors’ ignition switches or Takata’s airbag failures, right?

But Volkswagen earns greater attention here at this site because:

1) A critical mass of emptywheel readers are not familiar with the automotive industry, let alone manufacturing; they do not regularly follow automotive news. Quite a number are familiar with enterprise information security, but not car manufacturing or with passenger vehicle security. Many of the readers here are also in policy making, law enforcement, judiciary — persons who may influence outcomes at the very beginning or very end of the product manufacturing life cycle.

2) This is the first identified* multi-year incidence in which an automotive industry manufacturer using computer programming of a street-ready vehicle to defraud consumers and willfully violate multiple U.S. laws. This willfulness wholly separates the nature of this risk from other passenger vehicle vulnerabilities, ex: Fiat Chrysler’s hackable Uconnect dashboard computers or Nissan’s unprotected APIs for keyless remotes. (These latter events arose from inadequate info security awareness though responsiveness of vehicle manufacturers after notification may be in question.)

3) Volkswagen Group is the single largest passenger vehicle manufacturer in Europe. This isn’t a little deal considering half of all passenger vehicles in Europe are diesel-powered. Health and environmental damage in the U.S. from 600,000 passenger diesels has been bad enough; it’s taking lives in the tens of thousands across Europe. 75,000 premature deaths in 2012 alone were attributed to urban NO2 exposures, the source of which is diesel engines. It was testing in the U.S. against U.S. emissions standards which brought VW’s ‘cheating’ to light making it impossible for the EU to ignore any longer. The environmental damage from all Volkswagen passenger diesels combined isn’t localized; these additional non-compliant emissions exacerbate global climate change.

These are the reasons why Dieselgate deserved heightened scrutiny here to date — but the reasons why this scandal merits continued awareness have everything to do with an as-yet unrealized future.

We are on the cusp of a dramatic paradigm shift in transportation, driven in no small part by the need for reduced emissions. Development and implementation of battery-powered powertrains are tightly entwined with artificial intelligence development for self-driving cars. Pittsburgh PA is already a testing ground for a fleet of self-driving Uber vehicles; Michigan’s state senate seeks changes to the state’s vehicle code to permit self-driving cars to operate without a human driver to intervene.

All of this represents a paradigm shift in threats to the public on U.S. highways. Self-driving car makers and their AI partners claim self-driving vehicles will be safer than human-driven cars. We won’t know what the truth is for some time, whether AI will make better decisions than humans.

But new risks arise:

  • An entire line of vehicles can pose a threat if they are programmed to evade laws, ex: VW’s electronic control unit using proprietary code which could be manipulated before installation. (Intentional ‘defect’.)
  • An entire line of vehicles can be compromised if they have inherent vulnerabilities built into them, ex: Fiat Chrysler’s Uconnect dashboard computers. (Unintentional ‘defect’.)

Let’s ‘pick on’ another manufacturer for a moment: imagine every single Fiat Chrysler/Dodge/Jeep vehicle on the road in 5-10 years programmed to evade state and federal laws on emissions and diagnostic tests for road-worthiness. Imagine that same programming exploit used by criminals for other means. We’re no longer looking at a mere hundred thousand vehicles a year but millions, and the number of people at risk even greater.

The fear of robots is all hype, until one realizes some robots are on the road now, and in the very near future all vehicles will be robots. Robots are only as perfect as their makers.

An additional challenge posed by Volkswagen is its corporate culture and the deliberate use of a language barrier to frustrate fact-finding and obscure responsibility. Imagine now foreign transportation manufacturers not only using cultural barriers to hide their deliberate violation of laws, but masking the problems in their programming using the same techniques. Because of GM’s labyrinthine corporate bureaucracy, identifying the problems which contributed to the ignition switch scandal was difficult. Imagine how much more cumbersome it would be to tease out the roots if the entire corporate culture deliberately hid the source using culture, even into the coding language itself? Don’t take my word for how culture is used to this end — listen to a former VW employee who explains how VW’s management prevaricates on its ‘involvement’ in Dieselgate (video at 14:15-19:46).

Should we really wait for another five to 10 years to ‘pick on’ manufacturers of artificially intelligent vehicles — cars with the ability lie to us as much as their makers will? Or should we look very closely now at the nexus of transportation and programming where problems already occur, and create effective policy and enforcement for the road ahead?
_________
* A recent additional study suggests that Volkswagen Group is not the only passenger diesel manufacturer using emissions controls defeats.

9/11: A Story of Attacks, Horror, Victims, Heroes and Jingoistic Shame

screen-shot-2016-09-11-at-2-54-38-amSeptember 11, 2001 is now 15 years in the mirror of life. Like the two Kennedy assassinations, the Moonshot and a few other events in life, it is one of those “yeah I remember where I was when…” moments. Personally, being on west coast time, I was just waking up thinking all I had was a normal morning court calendar. When my wife, who gets up far earlier than I, shouted at me to rub out the cobwebs and watch the TV because something was seriously wrong in New York City. She was right. It was a hell of a day, one of unspeakable tragedy and indescribable heroism. It was truly all there in one compact day, unlike any other, save maybe December 7, 1941.

2,996 people lost their lives, and their families and history were forever altered in the course of hours on an otherwise clear and beautiful day in Manhattan. Most were simply innocent victims, but many were the epitome of heroes who charged into a hellscape to try to salvage any life they could. There were other heroes that altered their lives in response, and either died or were forever changed as a result. One was a friend of mine from South Tempe, Pat Tillman.

No one can speak for Pat Tillman, and, save for his family, those who claim to only prove they never met the man. All I can say is, I wish he were here today. The one thing that is certain is he would not give the prepackaged trite partisan reaches you are likely to hear today. It would be unfiltered truth. Which the US did not get from its leaders after September 11, 2001, and is still missing today.

Instead of rallying and solidifying the oneness of the American citizenry that was extant immediately after September 11, 2001, the Bush/Cheney Administration and GOP told us to go shopping and that we needed to invade Iraq, who had nothing whatsoever to do with 9/11. It was a fools, if not devil’s, errand and a move that threw away an opportunity for greatness from the country and exploited it in favor of war crimes and raw political power expansion and consolidation.

Instead of gelling the United States to make ourselves better as the “Greatest Generation” did sixty years before, America was wholesale sold a bill of goods by a determined group of unreformed and craven Neo-Con war criminals left over from the Vietnam era, and we were led down the path to a war of aggression that was an unmitigated disaster we have not only not recovered from today, but are still compounding.

The 2000’s will prove to be a decade of American shame when history is written decades from now. Not from the attacks, but from our craven response thereto. So, pardon me if I join Colin Kaepernick and choose not to join, every Sunday, just because the Madison Avenue revenue generating NFL of Roger Goodell cravenly exploits it, the jingoistic bullshit of rote dedication to a racist National Anthem. Also, too, shame on opportunistic and Constitutionally ignorant whiny police unions who scold free speech and threaten to abandon their jobs in the face of it.

powell_un_anthraxBut that is all over now surely. Taking the United States, nee the world, to a forever war on the wings of a craven lie is universally recognized, condemned and scorned, right?

No. The Neo-Cons are unrepentant and still trying to advance themselves on the lie that their once and forever war justifies more than their prosecution and conviction in The Hague. Here is a belligerent and unrepentant Dick Cheney passing the torch of evil to his spawn Liz Cheney in the august pages of the Wall Street Journal:

We are no longer interrogating terrorists in part because we are no longer capturing terrorists. Since taking office, the president has recklessly pursued his objective of closing the detention facility at Guantanamo by releasing current detainees—regardless of the likelihood they will return to the field of battle against us. Until recently, the head of recruitment for ISIS in Afghanistan and Pakistan was a former Guantanamo detainee, as is one of al Qaeda’s most senior leaders in the Arabian Peninsula.

As he released terrorists to return to the field of battle, Mr. Obama was simultaneously withdrawing American forces from Iraq and Afghanistan. He calls this policy “ending wars.” Most reasonable people recognize this approach as losing wars.

Times may change, but the bottomless pit of Cheney lies and evil do not. As Charlie Savage pointed out on Twitter, the two terrorists the Cheneys refer to were actually released back to the “field of battle” by Bush and Cheney, not Obama. Was Obama involved in the story? Yes, he would be the one who actually tracked them down and killed them.

And then there is the failure to learn the lessons of the failed torture regime Bush and Cheney instituted as the hallmark of the “War on Terror”. Our friend, and former colleague, Spencer Ackerman has a must read three part series over the last three days in The Guardian (Part One, Part Two and Part Three) detailing how the CIA rolled the Obama Administration and prevented any of the necessary exposure, accountability and reform that was desperately needed in the aftermath of the torture regime and war of aggression in Iraq. It will take a while, but read all three parts. It is exasperating and maddening. It is also journalism at its finest.

And so, as we glide through the fifteenth anniversary of September 11, what are we left with from our response to the attacks? A destabilized world, an ingraining of hideous mistakes and a domestic scene more notable for jingoism and faux patriotism than dedication to the founding principles that America should stand for.

That is not what the real heroes, not only of 9/11 but the totality of American history, died to support and protect. In fact, it is an insult to their efforts and lives. If America wants to win the “War on Terror”, we need to get our heads out of our asses, quit listening to the neocons, war mongers, and military industrial complex Dwight Eisenhower warned us about, and act intelligently. This requires a cessation of adherence to jingoistic and inane propaganda and thought, and a focus on the principles we are supposed to stand for.

Thursday: Alien Occupation

Since I missed a Monday post with a movie clip I think I’ll whip out a golden oldie for today’s post.

This movie — especially this particular scene — still gets to me 37 years after it was first released. The ‘chestburster’ as scene is commonly known is the culmination of a body horror trope in Ridley Scott’s science fiction epic, Alien. The horror arises from knowing something happened to the spacecraft Nostromo’s executive officer Kane when a ‘facehugger’ leapt from a pod in an alien ship, eating through his space helmet, leaving him unresponsive as long as the facehugger remained attached to his face. There is a brief sense of relief once the facehugger detaches and Kane returns to consciousness and normal daily functions. But something isn’t right as the subtle extra scrutiny of the science officer Ash foreshadows at the beginning of this scene.

Director Ridley Scott employed a different variant of body horror in his second contribution to the Alien franchise, this time by way of a xenomorph implanted in her mimicking pregnancy in scientist Shaw. She is sterile, and she knows whatever this is growing inside her must be removed and destroyed or it will kill both her and the remaining crew. The clip shared here and others available in YouTube actually don’t convey the complete body horror — immediately before Shaw enters this AI-operated surgical pod she is thwarted by the pod’s programming for a default male patient. In spite of her mounting panic and growing pain she must flail at the program to enter alternative commands which will remove the thing growing inside her.

I suspect the clips available in YouTube were uploaded by men, or they would understand how integral to Shaw’s body horror is the inability to simply and quickly tell this surgical pod GET THIS FUCKING THING OUT OF ME RIGHT THE FUCK NOW.

I don’t know if any man (by which I mean cis-man) can really understand this horror. Oh sure, men can realistically find themselves host to things like tapeworms and ticks and other creatures which they can have removed. But the horror of frustration, being occupied by something that isn’t right, not normal, shouldn’t continue, putting its host at mortal risk — and not being able to simply demand it should be removed, or expect resources to avoid its implantation and occupation in one’s self? No. Cis-men do not know this terror.

Now imagine the dull background terror of young women in this country who must listen to white straight male legislators demand ridiculous and offensive hurdles before they will consider funding birth control to prevent sexual transmission of Zika, or fund abortions of Zika-infected fetuses which put their mothers at risk of maternal mortality while the fetuses may not be viable or result in deformed infants who’ll live short painful lives. Imagine the horror experienced by 84 pregnant women in Florida alone who’ve tested positive for Zika and are now being monitored, who don’t know the long-term outcomes for themselves or their infants should their fetuses be affected by the virus.

Body horror, daily, due to occupation not only by infectious agents alien to a woman’s body, but occupation by patriarchy.

I expect to get pooh-poohed by men in comments to which I preemptively say fuck off. I’ve had a conversation this week about Zika risks with my 20-something daughter; she turned down an invitation this past week to vacation with friends in Miami. It’s a realistic problem for her should she accidentally get pregnant before/during/immediately following her trip there.

We also talked about one of her college-age friend’s experiences with Guillain–Barré syndrome. It’s taken that young woman nearly three years to recover and resume normal function. She didn’t acquire the syndrome from Zika, but Guillain–Barré’s a risk with Zika infections. There’s too little research yet about the magnitude of the risk — this vacation is not worth the gamble.

But imagine those who live there and can’t take adequate precautions against exposure for economic reasons — imagine the low-level dread. Imagine, too, the employment decisions people are beginning to make should job offers pop up in areas with local Zika transmission.

What’s it going to take to get through to legislators — their own experience of body horror? Movies depicting body horror don’t seem to be enough.

Wheels
Put these two stories together — the next question is, “Who at VW ordered the emissions cheat device from Bosch before 2008?”

Pretty strong incentives for Volkswagen to destroy email evidence. I wonder what Bosch did with their emails?

Self-driving electric cars are incredibly close to full commercialization based on these two stories:

  • Michigan’s state senate bill seeks approval of driverless cars (ReadWrite) — Bill would change state’s code to permit “the motor vehicle to be operated without any control or monitoring by a human operator.” Hope a final version ensures human intervention as necessary by brakes and/or steering wheel. I wonder which manufacturer or association helped write this code revision?
  • California now committed to dramatic changes in greenhouse gas emissions (Los Angeles Times) — State had already been on target to achieve serious reductions in emissions by 2020; the new law enacts an even steeper reduction by 2030 in order to slow climate change effects and improve air quality.

I don’t know if I’m ready to see these on the road in Michigan. Hope the closed test track manufacturers are using here will offer realistic snow/sleet/ice experience; if self-driving cars can’t navigate that, I don’t want to be near them. And if Michigan legislators are ready to sign off on self-driving cars, I hope like hell the NHTSAA is way ahead of them — especially since emissions reductions laws like California’s are banking heavily on self-driving electric cars.

Google-y-do

  • Google’s parent Alphabet-ting on burritos from the sky (Bloomberg) — No. No. NO. Not chocolate, not doughnuts, not wine or beer, but Alphabet subsidiary Project Wing is testing drone delivery of Chipotle burritos to Virginia Tech students? Ugh. This has fail all over it. Watch out anyhow, pizza delivery persons, your jobs could be on the bubble if hot burritos by drone succeed.
  • API company Apigee to join Google’s fold (Fortune) — This is part of a big business model shift at Google. My guess is this acquisition was driven by antitrust suits, slowing Google account growth, and fallout from Oracle’s suit against Google over Java APIs. Application programming interfaces (APIs) are discrete programming subroutines which, in a manner of speaking, act like glue between different programs, allowing programmers to obtain resources from one system for use in a different function without requiring the programmer to have more than passing understanding of the resource. An API producer would allow Google’s other systems to access or be used by non-Google systems.
  • Google to facilitate storage of Drive content at cloud service Box (PC World) — Here’s where an API is necessary: a Google Drive user selects Box instead of Drive for storage, and the API routes the Drive documents to Box instead of Drive. Next: imagine other Google services, like YouTube-created/edited videos or Google Photo-edited images, allowing storage or use by other businesses outside of Google.

Longread: Digitalization and its panopticonic effect on society
Columbia’s Edward Mendelson, Lionel Trilling Professor in Humanities and a contributor at PC Magazine, takes a non-technical look at the effect our ever-on, ever-observing, ever-connected technology has on us.

Catch you later!

Tuesday: In a Season of Crime

Ride the train, I’m far from home
In a season of crime, none need atone
I kissed your face


— excerpt, Sue (or In a Season of Crime) by David Bowie

Bowie left us an amazing parting shot with his 25th and final album, Blackstar. The cut featured here is a free jazz/jazz-rock fusion work which sounds off-kilter or out of sync, the lyric melody not tracking with rhythm — until one looks at the lyrics as a story of confusion told at the same time as a driving lyric-less and inevitable story beats on at the same time.

Seems like an unintended metaphor for our general election politics.

Back to School, Fool
Guess who’s back in town? A bunch of Congressional lame ducks back from vacation — I mean — work in their districts where they glad-handed at county fairs between bites of deep-fried Twinkies and kissing babies for campaign photo ops.

Get back to work and produce funding for Zika research AND birth control, damn it. Your continued intransigence is costing lives — short, ugly, painful, deformed lives on which you are pitiless and merciless, you fundamentalist let-them-eat-cake hacks. It’s only a matter of time before somebody in your district ends up Zika-infected and pregnant after vacation trip to someplace warm like Miami — or mosquito-bitten during during their day job like lawn care or construction or mail delivery. Researchers are working incredibly hard with the limited funding they’ve had; there’s only so much they can do with inadequate funding. And birth control MUST be available to all who need it. Planned Parenthood can and does hand out condoms, you pathetic slack-handed weasels. Fund them.

STG if I was the president, I’d look at any way possible to trim funding to unusual projects in states with GOP senators and then declare an emergency, pull that trimmed funding to pay for subsidized birth control in the same damned states. With researchers now having found Zika infection may spread by bodily fluids like semen, vaginal fluid, saliva, and tears while documented cases mount, there’s ample grounds to write an executive order during a lame duck session.

Big Oil = Big Bully

The NoDAPL project is bad all around. There’s no good reason for it to proceed.

— The economics of oil supply and demand do not support it; the cost to proceed is simply not supportable.

— The environmental cost of this project and the oil it is intended to carry are untenable; investment of resources private and public should go toward non-fossil fuels.

— The project violates the rights of Native Americans in numerous ways and no good faith effort has been made to address them during planning, let alone now as construction begins. The current and future damage to the Sioux only exacerbates hundreds of years of abuses against their sovereign nation.

— The companies investing in this project including Enbridge cannot assure the safe operation of this pipeline given the history of pipeline leaks across this country. In Enbridge’s case, this foreign-owned corporation has already proven unreliable and opaque in pipeline operations.

— NoDAPL should not proceed for the same reasons Keystone XL pipeline did not proceed: it is not in our country’s best interest.

I don’t know how anyone can look at this bulldozing of land containing buried Native Americans and not see it as a direct, deliberate effort to erase their existence. This is accursed behavior which in no way addresses the needs for alternative energy outlined in the Defense Department’s Quadrennial Review or our nation’s need to secure its people by reducing carbon dioxide output.

Odd Lots

  • Disposal wells in Oklahoma including Osage Nation shut down after earthquake (Tulsa World) — Yet another case where extractive fossil fuel business on Native American tribal lands has been highly problematic. 17 wells were shut down by the EPA after Oklahoma’s M5.6 induced earthquake this weekend; these wells are in addition to 37 other disposal wells shut down this weekend near the quake’s epicenter. Haven’t seen yet whether another earthquake of this magnitude could set off an overdue 500-year magnitude earthquake along Missouri’s New Madrid fault.
  • U.S. district judge denies federal plan to open 1 million acres of central CA public lands for fracking and drilling (IndyBay.org) — Bureau of Land Management didn’t do its homework on environmental risks from fracking, focusing too heavily on drilling instead. Sounds a lot like Army Corp of Engineers’ slap-dash disregard for externalities when it analyzed the NoDAPL, doesn’t it?
  • OK’s earthquake insurance market already under review (Tulsa World) — Insurers have only paid out on 20 percent of earthquake-related claims since 2010; the market has also undergone consolidation and 300-percent rate increases. No word yet on how much damage this weekend’s M5.6 quake or subsequent aftershocks have caused. Hope the public lights a fire under Oklahoma Insurance Commissioner John Doak about his review of the market. It’s grossly unfair the public must bear the cost of risk created by extractive industries as it is.

Longread: Lawsuit against DMCA Section 1201
Johns Hopkins University professor and cryptographer Matthew Green filed suit against the federal government in late July to strike down Section 1201 of the Digital Millennium Copyright Act. The current law prevents security researchers from adequately investigating products. Worthwhile read — this has huge repercussions on our safety and security given how much of the technology around us is copyrighted but leaky as hell and prone to hacking.

Hasta pasta!

Wednesday: If I Had a Heart

Crushed and filled with all I found
Underneath and inside
Just to come around
More, give me more, give me more


— excerpt, If I Had a Heart by Fever Ray

Today’s featured single is from Fever Ray’s eponymous debut album ‘Fever Ray’, the stage name for Swedish singer, songwriter and record producer Karin Elisabeth Dreijer Andersson. If her work sounds familiar, it may be that she and her brother Olof Dreijer also performed as The Knife. Karin’s work is reminiscent of Lykke Li’s and Bjork’s electronic/ambient works, redolent with dark rhythms and layers of deep and high-pitched vocals — very Nordic feminine.

Fever Ray has been very popular with television programmers; the cut featured here is the theme song for History Channel’s Vikings series. It’s also been used in AMC’s Breaking Bad and WB’s The Following. Other songs by Karin as Fever Ray including Keep the Streets Empty for Me have been used by CBS’ Person of Interest and Canadian TV’s Heartbeats as well as a number of films. I’m looking forward to her next work, wondering if it will be just as popular TV and film industry.

Fossil feud

  • TransCanada approval hearing delayed due to protests (Reuters) — Not just U.S. and Native Americans protesting oil pipelines right now; Canada’s National Energy Board deferred this week’s hearings due to security concerns (they say). The board is scheduled to meet again in early October about the planned pipeline from Alberta to Canada’s east coast. There may be more than security concerns holding up these hearings, though…
  • Big projects losing favor with Big Oil (WaPo-Bloomberg) — The ROI on big projects may be negative in some cases, which doesn’t service massive debt Big Oil companies have incurred. They’re looking at faster turnaround projects like shale oil projects — except that these quick-hit projects have poorly assessed externalities which will come back and bite Big Oil over the long run, not to mention the little problem of fracking’s break-even point at $65/barrel.
  • Big Insurance wants G20 to stop funding Big Fossil Fuel (Guardian) — Deadline the biggest insurers set is 2020; by then, Big Insurance wants the G20 nations to stop subsidizing and financing fossil fuels including Big Oil because subsidies and preferential financing skew the true cost of fossil fuels (hello, externalities).
  • Standing Rock Sioux continue their protest against the North Dakota Access Pipeline (Guardian) — Video of the protest at that link. Calls to the White House supporting the Sioux against the DAPL are solicited. Wonder if anybody’s pointing out fracked shale oil is a losing proposition?

Zika-de-doo-dah

  • Adult mosquitoes can transmit Zika to their offspring (American Journal of Tropical Medicine and Hygiene) — Study looked at infected Aedes aegypti and albopictus mosquitoes and found the virus in subsequent larva. My only beef with this study is that Culex species were not also studied; they aren’t efficient carriers of Zika, but they do carry other flavivirus well and there are too many cases with unexplained transmission which could have been caused by infected Culex. Clearly need to do more about pre-hatch mosquito control regardless of species.
  • Three drugs show promise in halting Zika damage in humans (Johns Hopkins Univerity Hub) — Important to note some of the same researchers who demonstrated Zika caused damage in mice brain models earlier this year have now rapidly screened existing drugs to test against mice brain models. The drugs include an anti-liver damage medication (emricasan), an anti-parasitic (niclosamide), and an experimental antivirus drug. The limitation of this research is that it can’t tell how the drugs act across placenta to fetus and whether they will work as well and safely once through the placenta on fetuses. More research (and funding!) is needed.
  • Contraception no big deal, says stupid old white male GOP senator’s staffer (Rewire) — Right. If only McConnell and his staff could experience the panic of being poor and at risk of Zika. Not everybody in Puerto Rico has ready access to the “limited number of public health departments, hospitals, and Medicaid Managed Care clinics,” let alone other states like Texas which has such awful women’s reproductive care in terms of access and funding the maternal mortality rate has doubled in two years, up 27%. Pro-life, my ass. By the way, this lack of access to contraception affects men, too, who may unknowingly be infected with Zika and tranmit it to their sexual partners.

Longread Must-read: Super court
If you haven’t already done so, you need to read this investigative report by Chris Hamby at BuzzFeed. While it answers a lot of questions about the lack of perp walks, it spawns many more.

Hasta luego, compadres!

Monday: A Different Ark

[Caution: some content in this video is NSFW] Today’s Monday Movie is a short film by Patrick Cederberg published three years ago. This short reflects the love life of a youth whose age is close to that of my two kids. A few things have changed in terms of technology used — I don’t think either Facebook or Chatroulette is as popular now with high school and college students as it was, but the speed of internet-mediated relationships is the same. It’s dizzying to keep up with kids who are drowning in information about everything including their loved ones.

Their use of social media to monitor each other’s commitment is particularly frightening; it’s too easy to misinterpret content and make a snap decision as this movie shows so well. Just as scary is the ease with which one may violate the privacy of another and simply move on.

Imagine if this youngster Noah had to make a snap decision about someone with whom they weren’t emotionally engaged. Imagine them using their lifetime of video gaming and that same shallow, too-rapid decision-making process while piloting a drone.

Boom.

Goodness knows real adults with much more life experience demonstrate bizarre and repeated lapses in judgment using technology. Why should we task youths fresh out of high school and little education in ethics and philosophy with using technology like remote surveillance and weaponized drones?

Speaking of drones, here’s an interview with GWU’s Hugh Gusterson on drone warfare including his recommendations on five of books about drones.

A, B, C, D, USB…

  • USBKiller no longer just a concept (Mashable) –$56 will buy you a USB device which can kill nearly any laptop with a burst of electricity. The only devices known to be immune: those without USB ports. The manufacturer calls this device a “testing device.” Apparently the score is Pass/Fail and mostly Fail.
  • Malware USBee jumps air-gapped computers (Ars Technica) — Same researchers at Israel’s Ben Gurion University who’ve been working on the potential to hack air-gapped computers have now written software using a USB device to obtain information from them.
  • Hydropower charger for USB devices available in 2017 (Digital Trends) — Huh. If I’m going to do a lot of off-grid camping, I guess I should consider chipping into the Kickstarter for this device which charges a built-in 6,400mAh battery. Takes 4.5 hours to charge, though — either need a steady stream of water, or that’s a lot of canoe paddling.

Hackety-hack, don’t walk back

  • Arizona and Illinois state elections systems breached (Reuters) — An anonymous official indicated the FBI was looking for evidence other states may also have been breached. The two states experienced different levels of breaches — 200K voters’ personal data had been downloaded from Illinois, while a single state employee’s computer had been compromised with malware in Arizona, according to Reuters’ report. A report by CSO Online explains the breaches as outlined in an leaked FBI memo in greater detail; the attacks may have employed a commonly-used website vulnerability testing application to identify weak spots in the states’ systems. Arizona will hold its primary election tomorrow, August 30.
  • Now-defunct Australian satellite communications provider NewSat lousy with cyber holes (Australian Broadcasting Corp) — ABC’s report said Australia’s trade commission and Defence Science Technology Group have been attacked frequently, but the worst target was NewSat. The breaches required a complete replacement of NewSat’s network at a time when it was struggling with profitability during the ramp-up to launch the Lockheed Martin Jabiru-1 Ka-band satellite. China was named as a likely suspect due to the level of skill and organization required for the numerous breaches as well as economic interest. ABC’s Four Corners investigative reporting program also covered this topic — worth watching for the entertaining quotes by former CIA Director Michael Hayden and computer security consultant/hacker Kevin Mitnick in the same video.
  • Opera software users should reset passwords due to possible breach (Threatpost) — Thought users’ passwords were encrypted or hashed, the browser manufacturer still asks users to reset passwords used to sync their Opera accounts as the sync system “showed signs of an attack.” Norwegian company Opera Software has been sold recently to a Chinese group though the sale may not yet have closed.

That’s a wrap for now, catch you tomorrow! Don’t forget your bug spray!

Thursday: Only You

Sometimes when I go exploring for music I find something I like but it’s a complete mystery how it came to be. I can’t tell you much of anything about this artist — only that he’s German, he’s repped by a company in the Netherlands, and his genre is house/electronica. And that’s it, apart from the fact he’s got more tracks you can listen to on SoundCloud. My favorites so far are this faintly retro piece embedded here (on SoundCloud at Only You) and Fade — both make fairly mellow listening. His more popular works are a little more aggressive, like Gunshots and HWAH.

Caught a late summer bug, not firing on all cylinders. Here’s some assorted odds and ends that caught my eye between much-needed naps.

  • Infosec firm approached investment firm to play short on buggy medical devices (Bloomberg) — Jeebus. Bloomberg calls this “highly unorthodox,” but it’s just grossly unethical. Why didn’t this bunch of hackers at MedSec go to the FDA and the SEC? This is a shakedown where they get the market to pay them first instead of ensuring patients are protected and shareholders of St. Jude medical device manufacturer’s stock are appropriately informed. I call bullshit here — they’re trying to game the system for profit and don’t give a shit about the patients at risk. You know when the maximum payout would be? When patient deaths occurred and were reported to the media.
  • Apple iPhone users, update your devices to iOS 9.3.5 stat: serious malware designed to spy and gain control of iPhone found (Motherboard) — Hey look, a backdoor applied after the fact by a “ghost” government spyware company. The malware has been around since iPhone 5/iOS 7; it could take control of an iPhone and allow a remote jailbreak of the device. Interesting this Israeli spyware firm received a big chunk of cash from U.S. investor(s).
  • Apple filed for patent on unauthorized user biometric data collection system (AppleInsider) — If an “unauthorized user” (read: thief) uses an iPhone equipped with this technology, the device could capture a photo and fingerprint of the user for use by law enforcement. Not exactly rocket science to understand how this might be used by law enforcement remotely to assure a particular contact (read: target) is in possession of an iPhone, either. Keep an eye on this stuff.
  • India-France submarine construction program hacked (NDTV) — The Indian Navy contracted construction of (6) Scorpene-class submarines from French shipbuilder DCNS. Tens of thousands of pages of information from this classified project were leaked; the source of the documents appears to be DCNS, not India. The French government as well as India is investigating the hack, which is believed to be a casualty in “economic war.”
  • Hacking of Ghostbusters’ star Leslie Jones under investigation (Guardian) — Jones’ website and iCloud accounts were breached; initial reports indicated the FBI was investigating the matter, but this report says Homeland Security is handlng the case. Does this mean an overseas attacker has already been identified?
  • Taiwanese White hat hacker and open government activist named to digital policy role (HKFP) — Audrey Tang, programmer and consultant for Apple, will shift gears from private to public sector now that she’s been appointed an executive councillor for digital policy by Taiwan. Tang has been part of the Sunflower Student Movement which has demanded greater transparency and accountability on Cross-Strait Service Trade Agreement with China while resisting Chinese reunification.
  • Oops! Recent Google Apps outage caused by…Google? (Google Cloud) — Change management boo-boo borked an update; apparently engineers working on an App Engine update didn’t know software updates on routers was in progress while they performed some maintenance. Not good.
  • Gyroscope made of tiny atomic chamber could replace GPS navigation (NIST.gov) — A miniature cloud of atoms held in suspension between two states of energy could be used as a highly accurate mini-gyroscope. National Institute of Standards and Technology has been working a mini-gyro for years to provide alternate navigation in case GPS is hacked or jammed.
  • Tim Berners-Lee wants to decentralize the internet (Digital Trends) — The internet has centralized into corporate-owned silos of storage and activities like Facebook, Google and eBay. Berners-Lee, who is responsible for the development of browsing hyperlinked documents over a network, wants the internet to be spread out again and your data in your own control.

That’s enough to chew on for now. Hope to check in Friday if I shake off this bug.

Monday: Build That Wall

Poor Ireland. Poor Inishturk. To be forced to consider the onslaught of refugees fleeing political upheaval should one loud-mouthed, bigoted, multi-bankrupt idiot with bad hair win the U.S. presidency. I’m amused at how the Irish in this short film mirror the U.S. albeit in a more placid way. There are some who are ardently against him, some who’d welcome the business, and the rest cover the spread between the extremes though they lean more to the left than the right.

I find it appalling, though, that Trump would install a sea wall *now* after the golf course development has already been established, rather than do his homework upfront before investing in real estate which relies on natural dune formation. This kind of thoughtlessness is completely absurd, and the disgust evident in this film is well merited.

Keep your volume control handy; hearing Trump blathering may set your teeth on edge. Mute for a moment and continue.

Schtuff happens
I couldn’t pull a cogent theme out of the stuff crossing my desk today. I’m just laying it down — you see if you can make any sense out of it.

  • Ramen can get you killed in private prisons (Guardian) — The federal government may have to do more than simply stop using private prisons for federal criminal incarceration. This report by a doctoral candidate in the University of Arizona’s school of sociology suggests states’ prisons operated by private industry may be violating prisoners’ civil rights by starving them. Ramen noodles have become a hot commodity for this reason. Not exactly a beacon of morality to the rest of the free world when incarcerated citizens must scrap for ramen noodles to make up for caloric shortfalls.
  • World Anti-Doping Agency may have been attacked by same hackers who poked holes in the DNC (Guardian) — “Fancy Bear” allegedly had a fit of pique and defaced Wada after Russian athletes were banned at Rio. This stuff just doesn’t sound the same as the hacking of NSA-front Equation Group.
  • New Mexico nuclear waste accident among most costly to date (Los Angeles Times) — Substitution of an organic kitty litter product for a mineral product two years ago set off a chemical reaction un an underground waste storage area, contaminating 35% of the surrounding space. Projected clean-up costs are $2 billion — roughly the amount spent on Three Mile Island’s meltdown.
  • Build that wall! Americans blown ashore in Canada by high winds (CBC) — Participants riding flotation devices on the St. Clair River in the annual Port Huron Float Down were pushed by high winds into Sarnia, Ontario. About 1,500 Americans had to be rescued and returned to the U.S. by Canadian police, Coast Guard, and Border Service. Just a test to see if Canada’s ready for the influx of refugees should Trump win in November, right?
  • Paternity test reveals a father’s sperm actually made him an uncle (Independent) — Upon discovering a father’s DNA only matched 10% of his child’s DNA, further genetic ancestry revealed the ‘father’ had an unborn twin whose DNA he had absorbed in the womb. His twin’s DNA matched his child’s. This is not the first time paternity testing has revealed chimerism in humans.

Commute-or-lunch-length reads

  • Walmart is a crime magnet (Bloomberg) — Holy crap. Communities should just plain refuse to permit any more Walmarts until they clean up their act. Bloomberg’s piece is a virtual how-to-fix-your-bullshit task list; Walmart has zero excuses.
  • It’s in your body, what version is it running? (Backchannel) — Before the public adopts anymore wearable or implantable medical devices, they should demand open access to the code running inside them. It’s absurd a patient can’t tell if their pacemaker’s code is jacked up.
  • Dirty laundry at Deutsche Bank (The New Yorker) — This you need to read. Parasitic banking behavior comes in many forms — in this case, Deutsche Bank laundered billions.

There, we’re well on our way this week. Catch you tomorrow!

Blame It On The Bossa Nova: Lochte and Brazilian Police

The travails of the Ryan Lochte gang of American Swimmers has been playing out for a full week now. The result has been almost universal scorn, if not hatred, for Lochte et. al, and almost complete credulous acceptance of the somewhat dubious, if extremely strident, pushback and claims of the Brazilian Police.

Frankly, neither side’s story ever sat quite right with me. But Lochte’s story, among other exaggeration/fabrication, always, from the start, indicated that the swimmers were pulled from a taxi at gun point, by people in uniform with badges, who pointed guns at them, and took money from them.

And then came the dog and pony show press conference staged by the Brazilian Police for a worldwide audience during mid-day on Thursday August 18. It was a bizarre and rambling presser, that was nearly comical in its staging during its opening portion. It did, however, make clear that there was a lot more to the full story than Lochte had told, and that some of his story was flat wrong. But, if you listened carefully, as I am wont to do with cops making self serving statements, it, along with previous statements made by the police, also pretty much confirmed the swimmers were pulled from a taxi at gun point, by people in uniform with badges, who pointed guns at them, and took money from them.

So, then the question was what “crimes” and/or “vandalism” had Lochte and the swimmers really caused? There was an early news crew, I think NBC, that went to the site and did not really find all that much damage. As the statements by both Lochte and the other swimmers, notably Gunnar Bentz, came out, it was clear that there was a real question as to what, if any, real damage was done. And a question of who engaged in exactly what criminal behavior at that gas station in the early morning of August 15.

Well, now it is starting to come out. And, as expected, the Brazilians have ginned up every bit as much “over-exaggeration” as Ryan Lochte. From today’s USA Today Investigative Team of Taylor Barnes and David Meeks, which confirms some of the work previously seen from (again, I believe) NBC. It is a pretty thorough and convincing report:

But a narrative of the night’s events – constructed by USA TODAY Sports from witness statements, official investigations, surveillance videos and media reports – supports Lochte’s later account in which he said that he thought the swimmers were being robbed when they were approached at a gas station by armed men who flashed badges, pointed guns at them and demanded money.

A Brazilian judge says police might have been hasty in determining that the security guards who drew guns on the swimmers and demanded money did not commit a robbery. A lawyer who has practiced in Brazil for 25 years says she does not think the actions of Lochte and teammate Jimmy Feigen constitute the filing of a false police report as defined under Brazilian law.

An extensive review of surveillance footage by a USA TODAY Sports videographer who also visited the gas station supports swimmer Gunnar Bentz’s claim that he did not see anyone vandalize the restroom, an allegation that in particular heightened media portrayals of the four as obnoxious Americans behaving recklessly in a foreign country. Meanwhile, Rio authorities have declined to identify the guards or offer any details beyond confirming they are members of law enforcement who were working a private security detail.

Now, we can’t compare that with everything the Brazilian police have, because they have been hiding a lot of their material and, apparently, misrepresenting substantial portions of it from the start. But everything within the USA Today piece corresponds with the various videos obtained by the various media outlets, whether Brazilian, American or international, and corresponds with Gunnar Bentz’s statement, which nobody, even, quite notably the Brazilians, including police, seems to contest in the least.

In short, the overall picture of the incident seems to be bigger and more complex, with some outrageous conduct by not just the American swimmers, but also, and substantially, the Brazilians. Oh, and about that “bathroom trashing damage”? That appears to be vapor too:

At a news conference Thursday, Rio police chief Fernando Veloso characterized the athletes’ actions at the gas station as vandalism. He said they also had broken a soap dispenser and mirror inside the restroom. Reports quickly grew that the Americans had trashed the restroom.

A USA TODAY Sports videographer who visited the bathroom Thursday found no damage to soap dispensers and mirrors and said none of those items appeared to be new. Some media accounts suggested the men had broken down a door, which USA TODAY Sports also did not observe.

Bentz said in his statement that he believes there are surveillance videos shot from different angles that have not been released. He also said he did not see anyone damage the bathroom or even enter it.

Oh, and that much ballyhooed “sign” supposedly damaged? Reports are that it was a minor crack in a cheap plastic cover and that the swimmers were made to pay out somewhere between $100 to $400 to cover what appears to be mostly ginned up nonsense. Additionally, irrespective of what the “security guards” extracted from the swimmers at gunpoint, swimmer James Feigan was made to pay the amount of $11,000 as a “donation” simply in order to leave the country and return home. That is not a “donation”, that is a flat out outrageous extortion demand and payment extracted by Brazilian authorities.

I wonder what bloviating sports columnists so full of righteous outrage and apologia will say now? Brazil is to be commended for putting on a great Olympics, and doing so under difficult constraints and conditions. But for the green pools (that affected nothing in the long run), they really pulled off a fantastic, admirable and beautiful show. Even the rain did not phase or slow down the glorious closing ceremonies Sunday night.

But one point on which Brazilian authorities “over-exaggerated”, overreacted, and failed to acquit themselves well on was in relation to the randy American swimmers. According to the USA Today report, even judges in Rio are wondering if they were hoodwinked in the rush of outrage by the authorities.

The distress of the Brazilian authorities over the emerging story from the swimmers is perfectly understandable given the dynamics. But, if an international scandal was created by this incident, it appears as if it is every bit as much the fault of the Brazilan police and authorities as it is the American swimmers.

It took two for this little tango.

Friday: Smells Like

With the lights out, it’s less dangerous
Here we are now, entertain us
I feel stupid and contagious
Here we are now, entertain us
A mulatto, an Albino
A mosquito, my libido, yeah


— excerpt, Smells Like Teen Spirit by Nirvana

Been a rough week so I’m indulging myself with some double bass — and because it’s Friday, it’s jazz. This is 2009 Thelonious Monk Competition winner Ben Williams whose ‘Teen Spirit’ is both spirited and minimalist. Check out this set with Home and Dawn Of A New Day, the first embued with a hip-hoppy beatmaking rhythm.

More Shadows on the wall
While Marcy has some questions about the recent alleged Shadow Brokers’ hack of NSA-front Equation Group and malware staging servers, I have a different one.

Why is Cisco, a network equipment company whose equipment appears to have been backdoored by the NSA, laying off 20% of its workforce right now? Yeah, yeah, I hear there’s a downturn in networking hardware sales due to Brexit and the Chinese are fierce competitors and businesses are moving from back-end IT to the cloud, but I see other data that says 50-60% of ALL internet traffic flows through Cisco equipment and there are other forecasts anticipating internet traffic growth to double between now and 2020, thanks in part to more video streaming and mobile telecom growth replacing PCs. Sure, software improvements will mediate some of that traffic’s pressure on hardware, but still…there’s got to be both ongoing replacement of aging equipment and upgrades (ex: Southwest Airlines’ router-fail outage), let alone new sales, and moving the cloud only means network equipment is consolidated, not distributed. Speaking of new sales and that internet traffic growth, there must be some anticipation related to increased use of WiFi-enabled Internet of Things stuff (technical term, that — you know, like Philips’ Hue lighting and Google Nest thermostats and Amazon Echo/Alexa-driven services).

Something doesn’t add up. Or maybe something rolls up. I dunno’. There are comments out on the internet suggesting competitor Huawei is hiring — that’s convenient, huh?

AI and Spy

  • Data security firm working on self-tweeting AI (MIT Review) — The software can generate tweets more likely to illicit response from humans than the average phishing/spearphishing attempt. Seems a little strange that a data security company is working on a tool which could make humans and networks less secure, doesn’t it?
  • Toyota sinks a bunch of cash into AI project at U of Michigan (ReadWrite) — $22 million the automaker pledged to development of self-driving cars, stair-climbing wheelchairs and other mobility projects. Toyota has already invested in similar AI development programs at Stanford in Palo Alto, CA and MIT in Cambridge, MA. Funding academic research appears to be a means to avoid a bigger hit to the corporation’s bottom line if the technologies do not yield commercially viable technology.
  • Steganography developed to mask content inside dance music (MIT Review) — Warsaw University of Technology researcher co-opted the rhythm specific to Ibiza trance music genre. The embedded Morse code buried in rhythm could not be audibly detected by casual listeners as long as it did not distort the tempo by more than 2%.

Sci-like-Fi

  • New theory suggests fifth force of nature possible (Los Angeles Times) — The search for a “dark photon” may have led to a new theory explaining the existence and action of dark energy and dark matter, which together make up 95% of the universe. I admit I need to hunt down a better article on this; this one doesn’t make all the pieces snap into place for me. If you’ve seen a better one, please share in comments.
  • Sound wave-based black hole model may show Hawking radiation at work (Scientific American) — Can’t actually create a real black hole in the lab, but a model like this one created by an Israeli scientist using phonons (not photons) may prove Stephen Hawking was right about information leakage from black holes. The work focuses on the actions of quantum-entangled particle pairs which are separated on either side of the event horizon. Beyond adding to our understanding of the universe, how this work will be used isn’t quite clear. But use of quantum entanglement in cryptography is an important and growing field; I wouldn’t be surprised to see this finding shapes cryptographic development.
  • Pregnant women’s immune system response may affect fetus’ neurological system (MedicalXpress via Phys.org) — While an expectant mother’s immune system may prevent a virus from attacking her fetus, the protective process may still affect the fetus long term. Research suggests that some neurological disorders like schizophrenia and autism may be associated with maternal infections pre-birth.

Late adder: Travel Advisory issued for pregnant women to avoid Miami Beach area according to CDC — Five more cases of Zika have been identified and appeared to have originated in the newly identified second Zika zone, this one east of Biscayne Bay in the Miami Beach area. The initial Zika zone was on the west side of Biscayne Bay. The CDC also discouraged pregnant women and their sex partners from traveling to Miami-Dade County as a whole; the county has now had a total of 36 cases of Zika.

In the video in the report linked above, FL Gov. Rick Scott pokes at the White House about additional Zika assistance, but Scott previously reduced spending on mosquito control by 40%. Now he’s ready to pay private firms to tackle mosquito spraying. Way to go, Republican dirtbag. Penny wise, pound foolish, and now it’s somebody else’s job to bat cleanup.

Longread: Stampede at JFK
A firsthand account of the public’s stampede-like reaction to a non-shooting at New York’s JFK International Airport. To paraphrase an old adage, if all you have is a gun, everything looks and sounds like a shooting.

Let go of your fear and let the weekend begin.