Hailstorm: Changing Society's Privacy Infrastructure 215
chikanamakalaka writes: "I found an article at the Seattle Times about Microsoft's upcoming "Hailstorm" service and associated privacy concerns. The story is here."
A physicist is an atom's way of knowing about atoms. -- George Wald
Re:Car accident? (Score:1)
However, a brief summary:
So you see, it's not difficult. Like they say in the article, it just requires integration between the relevant agencies.
Re:Car accident? (Score:1)
This was discussed at length in a previous Slashdot article here [orgcomments.pl], anyway. Talk about re-hashing old things!
Re:Car accident? (Score:1)
Re:Car accident? (Score:1)
I know people working on it.
Re:Dude, please listen to yourself (Score:1)
Re:Car accident? (Score:1)
Welcome to the Car Accident Wizard. This wizard helps you when you just got into a car accident. Please click Next when you are ready to continue.
Select Type of Accident. Select the kind of accident you were just involved in and click Next to continue.
I just hit a pedestrian.
I just hit another car.
I was just run over by an SUV.
(I worked hard on an ASCII picture of a GPF but the Slashdot lameness filter rejected it. Try to imagine yourself a box that says "MSCARA32.EXE has performed an illegal operation and will be shut down.")
Re:Reversing the privacy policy circle... (Score:1)
Re:Sounds like a recipe for Identity Theft... (Score:1)
Re:typical Microsoft (Score:1)
authentication how? (Score:2)
johnpaulwallington.com [johnpaulwallington.com]
George Orwell Never Predicted... (Score:2)
This article gives me the Willies. (Score:2)
reminds me of the giddy plans that ermerged during
the height of the Bubble to have your fridge
know when you run low on milk and send the order
on to the grocery store.
Unwieldy, unnecessary, and just plain dumb.
Not everything needs to be automated.
Boneheds like Gates think that everything that is
not integrated into an all encompassing networked database is an ineffieciency.
Well, mountains are ineffiecencies ( to trains and farms) as are bathroom breaks to PHB.
Lets hear it for ineffiecency and limits on human
ambition and stupidity.
"Still, having a single company in control of so much information....." is absolute madness.
The stupidest idea I ever (bar none) heard of.
Ok, maybe it's not true that everything I needed to know I learned in Kindergarten.
I guess it wasn't till Grade 3 that I heard about
not putting all my eggs in one basket.
"Eventually, the service will be able to watch and listen to computer users in their homes and offices, so it knows when they are busy and when to...."
and when to squeal to the PHB, send you an email
that you are to report to the remotivation depot.
Plainly put, fuck you , Microsoft.
Who asked you to be the Grand Repository?
And the really irritating thing is that there are
problabley several dozen different better ways of delivering many of these so called benefits, which
respect an individual's privacy and
that don't require catering to MS insatiable
need to be all controlling.
Did I say Fuck You, Microsoft?
Re:Microsoft knows that someone wants Hailstorm... (Score:1)
Momma says stupid is as stupid does.
someone@somewhere.com statistics. (Score:2)
--
Simon
Re:The issue that matters (Score:1)
Of course, it seems for most Americans, that'd be too much work. However, don't try to make me feel bad about it. It's not _my_ fault. (Though it is everyone's problem.)
_____
Re:Why this won't work (Score:1)
Also, the "average Joe" out there doesn't really understand what Microsoft did/does/is doing that's so bad. Being as non-technical as they are, they don't understand why anyone would think they're bad guys. They think that MS is trying to make the world a better place. And I suppose some people at Microsoft even believe that.
So yes, many people believe Microsoft has their best interests at heart. I don't buy it, but there are people who do.
_____
Re:Microsoft Rep. talks about HailStorm at UIUC (Score:2)
Now, when universities start selling "installing rights" contracts to software vendors, will your little group be outlawed?
sPh
Re:Boiling Frogs (Score:1)
Re:Sounds like a recipe for Identity Theft... (Score:2)
Re:If Microsoft were not involved? (Score:2)
Path of least resistence (Score:1)
Re:Bwahahaha (Score:1)
All (and I mean ALL) your datum are belong to M$ (Score:2)
Stop me if I missed anything, but Microsoft are proposing to monitor everything down to your very facial expressions, leaving George Orwell not so much awed as flabbergasted by the possibilities, and they're going to use your own hardware to do this, and it's all going through Microsoft's own centralised database, and, gee, people used to be worried about governments monitoring boring stuff like their emails, and the possibility of crackers getting copies...
They're going to know more about how you think and feel than you do yourself. Microsoft?
Think about this... the multi-billion-dollar company who can't even protect their own website against a script kiddie... the people who brought you Internet ``where did your data go today'' Explorer and the beloved ``I'm feeling lucky - let's run this'' Outlook... and I'm supposed to trust them with pictures of me, an intimate knowledge of my very thought patterns, every key I hit, every word I read?
Think about this... look interested in an image - or a competitor's product, Microsoft knows it; be angered or pleased by something, Microsoft knows it; do or say something technically illegal or embarrassing, Microsoft knows it; recieve unexpected cash income, Microsoft knows it; fart, and the camera/mike will forward your muscle patterns and noise to Microsoft; hop into the hammock with your SO and you'd better have remembered to switch off the pickups - and... will they really be off...?
You'd have to be a nutter. A goldfish in a shopping mall would have more privacy. Millions of JenniCams plus the ability to fastforward to the juicy bits. If you happen to be pretty, expect to have a lot of hopefully secret admirers. If your personal beliefs aren't mainstream, maybe they soon will be. ``And he causeth all, both small and great, rich and poor, free and bond, to receive a mark in their right hand, or in their foreheads: and that no man might buy or sell, save he that had the mark, or the name of the beast, or the number of his name. Here is wisdom. Let him that hath understanding count the number of the beast: for it is the number of a man; and his number is Six hundred threescore and six.'' - Revelation 13:16-18 - I wonder if the Passport ID has 666 coded into it somewhere? )-:
Announcing Omni Consumer Products (Score:1)
Re:Makes sense (Score:2)
That's funny - I usually use someone@somewhere.com
Re:someone@somewhere.com statistics. (Score:2)
Seriously, the fact that they get that much says to me:
a) there are a lot of people besides me who just picked that out of a hat (c'mon, could "somewhere.com" be a little more generic?), because;
b) there are a lot of people trying to avoid massive amounts of spam, because;
c) there are far too many companies selling their users' registration data and email addresses, very often, I suspect, without informing the people that they collected that data from in the first place.
Anyway, I haven't used that one lately. Mostly I register these days (when I have to) as "Heywood Jablowme", heyblowme@twococks.org
Re:someone@somewhere.com statistics. (Score:2)
Car accident? (Score:4)
How do I tell it? Are we going to wire my car with Hailstorm, too? I drive a friggin 1991 Bronco II, not exactly a tremendous technology platform. OK, maybe my WinCE Pocket PC will do it for me; hope the paramedics know how. No, better yet, I'll let them spend their time keeping me out of shock.
I'm all for "changing society's infrastructure", but c'mon.
Personally... (Score:2)
I'd be surprised -- very surprised -- if a medical records system based on a Microsoft-written OS or application could pass muster with regards to the access controls and tracking required by HIPAA. And that's not even getting into the problems related to the multitude of vulnerabilities that are built into the various versions of Windows. If I found out that my medical records were being accessed by a Microsoft computer? Well, that's about the time I'd think about becoming a Christian Scientist.
IMHO, Microsoft is years away from having a secure enough system for me to trust them with even my personal calendar let alone my family's financial and medical history.
--
Re:Evil? (Score:1)
Trading aspects of personal information in order to get a benefit is evil? You mean like using a credit card, putting a return address on an envelope, having yourself listed in the phone book (oops, this usually only applies to those of us not living with mommy)? You must either be incredibly clueless or live a pretty sad and paranoid little life. Who knows, maybe even both.
Cheers,
Dude, please listen to yourself (Score:1)
You actually act like you think you're some kind of badass by saying "Fuck you" to Microsoft. I'd like you to seriously think about it and let me know why anyone there would care about the opinion of someone like you. Calling Bill Gates a "bonehed" was pretty entertaining, too. Yeah, that's telling him! It's always hilarious to see some young screwup who has never amounted to anything in his life go after one of the most successful businessmen of all time (yep, the kiddies will squeal loudly at that one; of course, they thought Linux related stock was a good idea, too) and tell 'em that they don't know what they're talking about. You, sir, are a true genius. Since you're an AC, I can only guess at the kind of salary a man of your worth must earn. You know and I know that you've never amounted to anything in your life. Suck on that. :)
Cheers,
Re:Microsoft knows that someone wants Hailstorm... (Score:1)
So in other words, you're a luddite. Want a reward or something?
Cheers,
Re:Dude, please listen to yourself (Score:1)
I couldn't care less if he thinks Gates is an asshole. I'm sure the recipients who've received hundreds of millions of his dollars for disease prevention don't think so. I'm sure a lot of the people with whom he's butted heads in his business dealings do. The point is that when it comes to business acumen, I'll put my money on Gates' "bonehed" ideas any day of the week before I'd bet on the AC's.
And if you don't want PassPort to have any of your personal information, don't sign up for an account — it's that easy. Somehow a whole lot of people don't understand that simple fact. As for the people who think that giving up some personal information to receive benefits is some crazy, evil idea, they must have never used a credit card, signed up for a discount club, bought anything online, owned a car, had their phone numbers listed in the white pages, etc. Screw that.
Cheers,
Re:Evil? (Score:1)
Phone companies don't need to do that, the information's right there in the phone book or online databases for the lifting — your name, your number, your address, and whether or not you live in a good part of town (read: have dough to spend). To some people, giving up the personal information has a net positive effect, because it's much easier for people to get hold of them, whereas a lot of single women or people with names ripe for the pranking, decide that it's not worth the benefit, so they keep their numbers unlisted. As for return addresses, there are certain locations to which I send mail that I don't want it made clear to everyone who will be handling the mail that it's coming from me. The rest of the time, I'll give up that personal info to gain the benefit of the mail being returned to me if something goes wrong along the way.
And I totally agree with the "don't want it, don't use it" idea. Microsoft's system, and any system that anyone else comes out with, is going to be much more convenient for people to use, but it's up to the users to decide whether or not they want certain personal information available through it. Don't want that copy of Nude Midget Jugglers to show up on your credit card? Pay cash. Don't want a similar purchase to go through PassPort? Don't use the PassPort Wallet feature to buy it online. If you're really paranoid about it (of course, it's going to be on your credit card, anyway, unless you plan on sending a cashier's check), log out of PassPort first. I've yet to see one of the PassPort partners requiring you to even have a PassPort account to buy things from them.
Cheers,
Re:Dude, please listen to yourself (Score:1)
Sorry to rain on your little paranoia parade, but I haven't advocated PassPort here at all, or slammed any of its alternatives. Does trying to get an actual cogent argument against something count as FUD in your book? And trust me, all the infantile "Fuck you"s and "Bill Gates is a bonehead"s make your position look a lot worse than a whole team of Bartkos could manage. Maybe you should instead be asking if those posters know Bartko. I'd start by questioning that supposed "Linux advocate" who has a penchant for making the community look bad by running around in Obi-wan Kenobi garb. :)
Cheers,
Re:Makes sense (Score:3)
I suggest using something that sends a message. I always use no_privacy_policy@<whatever their domain is>, or unacceptable_privacy_policy@<whatever>, or simply that_info_is_private@<whatever>. That way, the email isn't just bounced without an explanation, but there's a chance that someone at the company will see the objection and maybe even note it if it happens enough. Same with meatspace places like Radio Shack. When they ask for your name/address, don't waste everyone's time (especially your own) by giving out a made-up address, tell them flat out that you don't give that information out. Go further and tell them that you don't like being asked for it, if that's how you feel. At least someone there will know, and you eventually might never get asked again.
Cheers,
Sounds like a recipe for Identity Theft... (Score:3)
Then, what if someone hijacks your account... they now have your credit card numbers, your home phone, your wife's phone, your kids school info, your bosses office number and his birthday, your automobile information, etc...
Imagine the possabilities...
Maybe it's called HailStorm because, as they say, "When it rains, it pours" implying that if someone gets your password, they get your life.
Think about it, it can be scary as hell.
Lightly OT - Personal Privacy (Score:1)
Bills. This one is not entirely privacy related, but you can see how it could lead there. I was at a friends when a lady from the electricity company came by to tell him that he hadn't paid his bill (his roommate forgot or something I guess) and that his power would be cut off at 4pm (a couple hours away) unless he paid immediately. He grumbled, said okay, and fetched his wallet. He asked how much, she said something around 50 dollars. He pulled 50 out of his wallet and said 'here you go. Sorry for the inconvenience'. She said 'Oh sir! I'm sorry. I can't accept cash, I can only accept a cheque or major credit card'.
What's that? Cash is supposed to be 'legal tender for the payment of all debts, public and private'. Hmm.
Which leads me to.. hotels. Now, I *do* have a credit card.. but I always try to check into hotels with cash only. I mean, why shouldn't I be able to? It's the only real legal tender we have in this country. Here's what I find. Usually, they get really upset at first. Then they say they won't let me use the phone or watch movies without a deposit. Usually they are really nervous about asking for a deposit as well. I told one guy 'how much? 50 bucks? 500 bucks? Just spit it out...'. You see, I don't care how much it is. But these people are unable to do business with cash! It's quite scary.
Bank machines. I don't use debit/credit/atm's everywehre I go. I carry a decent amount of cash on me most of the time.
The common theme here is cash. I put pressure on people to accept cash as payment, whether they like it or not. I'll be damned if I'm going to feel put out because I'm spending the *only legal tender I know of*.
Another thing: People asking or my name. Radio shack,pay-as-you-go cellular phones, everything else. Anytime any clerk asks for my name, I say 'Why?' and also 'Do I have to tell you?'. Usually the answer is 'no sir, you don't'. If they insist, I politely leave my purchase on the counter and walk out of the store.
Email addresses. I don't worry about this one as much, believe it or not. Once it gets out there, people have it forever.. so you might as well not fight it.
Internet. Folks, for the purposes of privacy, you shoudl always consider the Internet a public medium. Every packet you generate is going to go places you don't control. You should *not* have an expectation of privacy. Use encryption if you care. I use pgp for messages that have sensitive information in them, and otherwise, I don't send anything sensitive.
Re:Sounds like a recipe for Identity Theft... (Score:2)
-B
Re:Makes sense (Score:1)
On sites that I am reasonably certain will not use my email address for evil purposes I will use my real address when using a text-based ftp client.
Re:Makes sense (Score:1)
Re:Makes sense (Score:2)
Or they could just use fake information. I presonally know that no_one@nowhere.com is getting a lot of spam that was intended for me, had I been stupid enough to give my real email address to every web site that asks for it. I never give more information to a web site than is actually required. Does NAI actually think I am going to give them my real name and mailing address before I download PGP? Same with the New York Times.
*yawn* Another pointless "service" (Score:1)
Please stop trying to personalize everything. I'm buying computer parts, or books, or what-have-you, not "experiences". I make my own experiences.
Re:Microsoft? Violate your Privacy?! (Score:2)
Re:Makes sense (Score:2)
Microsoft isn't the only company trying to do this (Score:2)
Rest assured that there are going to be plenty of systems that are going to sprout up that will do the same things. And when you stop and think about it, a lot of it is going to be pretty cool. I really would like a competent secretary I can pay $50-100 a year for! I'm sure the next big problem is going to be the interop of all of those systems.
Re:Makes sense (Score:1)
Its sorta sad tho, messing with the personal info has become such a habit that I regularly screw it up even when the requester has a legit reason, or where you can even opt out of registering.
Re:Bottom Line: this kind of service is cool. (Score:1)
But never mind that. They'll get cracked fairly fast, and do you think the crackers will mind using you as a scapegoat for their latest defacement spree or new virus? Imagine your HailStorm account filled with enough information that you'll rot in jail? Do you think Microsoft will assist you with logs showing that your account was cracked, or do you think they'll just say its not possible to crack HailStorm, delete anything suspicious and let you take your chances?
Re:Just what I want!!! (Score:2)
Re:Car accident? (Score:1)
nmarshall
The law is that which it boldly asserted and plausibly maintained..
Re:The issue that matters (Score:2)
You don't have to switch cold-turkey to another OS, GUI, set of apps, etc. PartitionMagic is not too expensive. If you have a fair-sized HD, most of it is likely unused (a full Win2K install with Office2000, MS Project, Lotus SmartSuite, Notes, etc. only takes about 3GB - most HDs are 8GB or larger now). Set up a dual boot system with more than one OS environment. Keep Windows around for the things you need it for. Use Linux (or OS/2, or BeOS, whatever) to learn how it works, become familiar with it, build your non-MS capabilities. You'll find you use Windows less and less as you get more comfortable with any better alternative, and that it will get better and easier for you to use over time, even as Microsoft progressively makes Windows more restrictive, feature bloated, and oppressive, with "content protection" and Hailstorm coming.
At a previous employer, I had a Dell notebook set up with the firm standard Windows system on one partition, OS/2 built on a second partition, and a shared data partition for Notes databases, etc. I did almost all my work under OS/2. They did not know the difference and I didn't have to reboot several times a day or redo work lost to Windows crashes. I was much more productive that way.... Now I run both OS/2 and Linux on my firewall box, and always have one to fall back on if the other develops a weird glitch.
Before long most mainstream Win32 apps will be running under both Linux and OS/2 using Wine or Odin. Linux software has been ported to OS/2 (Xfree86 and GIMP come to mind) and more will be in the future. BeOS runs most Linux apps natively, as do the *BSD environments. Software outside Windows is becoming available everwhere.
Windows is the dead end, proprietary, high cost alternative, and lots of people are slowly realizing this. Find a way out earlier rather than later, or pay the price repeatedly.
Re:someone@somewhere.com statistics. (Score:2)
Re:Car accident? (Score:2)
Officer makes a typo in entering someone else's plate, and actually enters your license plate.
Insurance companies note that you've been in an accident, and raise your premium.
Re:Makes sense (Score:1)
Re:Makes sense (Score:2)
When I buy an RCA Television I do not have to tell RCA who I am but when you buy MS software (I certainly don't) you are going to be forced to tell them who you are, not only that but you will be tagged and additional information about you will be collected and sold as well.
they will get away with it because they sell to the meaty stupid portion of the bell curve or computer users and those lusers who can't change their default homepages will happiliy divulge whatever MS wants to them. We saw it coming when the NY times insisted that they know your name before you read their paper online while the paper version was anonymous. Those of use who are not idiots used false names or partner but the MS users of the world happily typed in their names and adresses. It never occured to them that it was an odd thing to do when they could have picked up the paper in the subway for nothing AND kept their privacy at the same time. It's a stupid tax and MS will happily collect it from their stupid users.
Re:Wouldn't be so bad if... (Score:2)
Re:The issue that matters (Score:3)
Re:Oops, they did it again. (Score:3)
Wouldn't be so bad if... (Score:3)
People could run of these for their own families, small business. Companies could deploy them for their employees.
It would also be nice if the different servers could talk to each other.
My devices would be updated by both my home server for essential personal information and my work server, for appointments and business data. This should be as seamless as receiving email from these separate people is now.
Naturally, if I wanted to I could pay someone to do this for me, and I'd have to give them my information. They could discount the service if I let them share my information for marketing.
So...anyone starting a project to this the right way ?
Re:Reversing the privacy policy circle... (Score:2)
Is that concept legal? It is an interesting idea, but doesn't some human representing the party of the second part (the company running the site) have to be at least aware of the license? The HTTP protocol is designed to ignore headers it does not recognize, and if you suddenly inject this into the stream nobody on the other end would even be aware of it. At best they might see it in their httpd logs later on. Doesn't sound like license acceptance to me at all.
-konstant
Yes! We are all individuals! I'm not!
Reversing the privacy policy circle... (Score:5)
I have come up with a system so that the user who originates the request can maintain copyright on his data and so that the receiving site has a chance to either opt-out or accept and abide by the agreement. (of course all this will be Open Source).
Basically it works with the HTTP protocol and should support any server/browser combination. Right now I have hacked Mozilla 0.8.1 to support this.
The mechanism is *very* simple. Basically it add one more HTTP header *prior* to the request being transferred. A valid request would look like:
GET http://hailstorm.microsoft.com/ HTTP/1.0
User-Agent: GNU/Linux and Mozilla
User-License: All your base are belong to us!
The goal here is that the single click licenses that Amazon/Microsoft and every other site can also be used by users:
"By responding to this HTTP request, you are accepting the practices described in this Privacy Notice. You will not give my information out to other users and you understand that I maintain copyright" (this would have to be encoded so that it is an HTTP param)
Of course the above is not Lawyer talk but I am hoping that we can get some official licenses together. If anyone knows any lawyers who are interested in contributing please give them my e-mail (burton@openprivacy.org).
The goal is that users would standardize on icenses, if sites ever violated the user policy then they would file a class action suit.
I have the code local if anyone wants a copy. It is really raw right now but I am trying to add a control panel in Mozilla so that users can nable/disable it and also set their license.
Kevin
Pretty soon there will be 2 sorts of people .... (Score:2)
Interesting quote (Score:4)
This strikes me as good and bad.
Bad because I don't want people to know when I'm looking at pr0n.
Good, because if it decides that me looking at pr0n is me being "busy", maybe it'll cut back on the damn pop-up ads.
Bwahahaha (Score:4)
It'll never work. There is no fucking way I'd trust anyone, let alone microsoft, with that sort, or quantity, of private information.
Poetic Justice makes MORE sense (Score:2)
No, no, no. Fake addresses are the wrong answer. The correct solution is to look up the site's Admin Contact address from whois [whois.net] . Let the nosy bastards spam themselves. You can also use their own phone number and snail address if needed.
Cool or not ? (Score:2)
The idea of having this type of service is cool. Yes, we all like convenience.
The implementation of it's pretty dire. M$oft ? Do you trust them to get Son-of-Passport right ? Have M$oft ever produced a crypto-complex product without making a complete disaster of it ?
Secondly, the whole myFoo idea is the wrong approach. Forgive me for stating the obvious, but good ideas for improving personal privacy don't usually start by placing the whole lot on a great big server, owned by the antichrist and operated by the people who brought you Hotmail.
I predict that the most interesting exploits won't be ripping the lid off directly, but instead by buying the SDK and spoofing the B2C services. Why steal your medical history when I can claim to be Dr Viagra's Clinic and have you give it to me ?
The most disappointing part of HailStorm is how technically backward it is. Big server-based things and single point validation ? Get real guys. I'd much rather have the sorts of proof-based selective disclosure that smarter and more innovative companies are working on (OK, so I work for HP and so I'm biased). Why should Anne & Chris communicate their trust of each other for one small fact, by being forced to tell all their secrets to Bill first ? (esp. when Bill is the blabbermouthed village idiot) It's a much better approach if they communicate directly, and we already know how to do this. Where are M$oft on topics like anonymous verification, or an anonymous ePerson ? For as long as they persist with this notion that every minor disclosure to an on-line business requires me to make a full and traceable disclosure to them, then I won't touch it.
--
Always trust content from Microsoft Corporation ?
Re:Idea vs. Implementation (Score:2)
So did Bob.
It's been tried (Score:3)
If this goes anywhere, it will be because Microsoft finds some way to cram it down everybody's throats, like building it into the Windows registration process. They'll probably make it free at first, then later change the customer agreement to take a cut on every transaction.
Re:Car accident? (Score:2)
"I just got in a car accident" wizard.
It then says, okay, you got in an accident. Pull database....your insurance agent is Grecko. Look at address book, grab spouse phone number. Use modem to send a fax message to the doctor listed in your address book to leave an generic fax message saying the hospital you are at.
Creditcard anyone? then why are you so paranoid? (Score:2)
Ever worried if a waiter in a restaurant would use your creditcard number, exp date etc for fraud? I don't think so.
Then again, why are you so paranoid when a (not 'the') service is provided by a company? you don't HAVE TO use that service. And if you do, would it be any more risky than using a creditcard and give a lot of your financial information to a creditcardcompany?
--
Accidents (Score:4)
If you are in a car accident, HailStorm could automatically send your medical history and insurance information to the hospital before the ambulance arrived. Then it could page your spouse and reschedule your appointments.
Honey, I'm in the ER bleeding like a sieve. Could you pick up the kids at soccer practice today?
Sure. No problem.
Re:Car accident? (Score:4)
- - - -
Re:oops, forgot to mention... (Score:2)
Makes sense (Score:3)
If people really wanted this to stop, all they would have to do is not divulge any personal information at all. That will not happen though, as people will think, this site wants my address, that site wants my age, the other site wants my gender, but it will not occur to the typical surfer that those sites are all on the same database and will compile an entire background, shopping history and link through-click and target them for what the companies believe they will want.
People, do not give out personal information on the 'net, in person, or anywhere else if you do not want it to become public information by default.
DanH
Cav Pilot's Reference Page [cavalrypilot.com]
They're calling it hailstorm? (Score:2)
oh, ok, maybe hailstorm isn't such a bad name after all. My bad.
---
Re:Makes sense (Score:2)
This begs the question (Score:2)
Is there a way to do this in such a way that only the people who really should have your information can get to it?
I know it sounds impossible, hell, it may be. Just making it so phenomenally difficult that you have to have, say, three or four of the smartest people in the nation (The five percent nation of Casiotone, of course) to actually make it happen might be enough. Hell, that way we could make a movie about it, sort of like Sneakers, and use that cash to finance any infrastructure needs we have. I'm not sure who to trust to run them - Probably two bastions of the Tech community who hate each other. They'll keep each other honest. RMS and Bill Gates come to mind. Think about it.
Anyway, where was I? We need a system that has seperate entities entirely for each stage of the system. Data is stored by one firm, carried by another (preferrably completely government-controlled, believe it or not) and then licensed by whoever. Only certain people should have access to certain types of information. I (sadly) don't know enough about encryption to design a scheme without unnecessary steps, but it seems to me that you could do it with the current system of cryptologically signed certificates, and public key encryption. Data would be stored encrypted, would require some sort of key and passphrase for decryption (I like physical devices for the key, something like the iButton [ibutton.com] for example) and would then be signed using the recipient's public key.
The catch is, the public key has to be signed by a third party, like (yuck) Verisign. You could always sign your own, but if it's known that you sign your keys with your own provider, most people will not choose to trust you with anything but the most insignificant data. Again, all of this should be possible with the basic software we already use today, with a few minor modifications. Why not just implement our own?
Here's the deal: Allow creation of arbitrary categories. Then allow creation of arbitrary rules. The rules will check arbitrary properties. If someone says they want a certain kind of data, then they have to meet certain criteria. Maybe the forward and reverse DNS have to match, and they have to have a certain signature; Maybe you only allow someone who encrypts their request to you, using their private key, et cetera. Some pieces of information you will want to be as closely restricted as all of those at once; That's the restriction on your medical records, maybe, and perhaps to allow someone to grab your resume, they just have to have matching A and PTRs.
Anyway, don't let microsoft do this to us! We already know that we, the internet community, can do a better job than Microsoft at damn near anything except Feeding FUD - And we're a damn close second there. We rock! And we definitely rock more than Microsoft. And tell me, do you want this shit to use SOAP? Please, stop the insanity!
--
ALL YOUR KARMA ARE BELONG TO US
The issue that matters (Score:2)
I know it's probably blasphemy here (flamebait, even!), but I don't consider linux to be a viable desktop OS choice for me. Sure, it's an alternative to windows but I'd have to sacrifice functionality to switch over (not only in terms of some of my more unusual peripherals that still lack working linux drivers, but also all the software that I actually purchased instead of "liberated"). For all intents and purposes, Microsoft has me like a dealer has a junkie. I'm too used to the desktop feel, for example, to switch to something else compeltely...
So, basically, Microsoft is the only game in town and if they want to move in a particular direction, I'm forced to follow. I may not like their point of view on how society's "infrastructure" should be changed (subscription-based software, "Hailstorm", etc..), but what practical choice do I have?
I MAY technically have a choice, but I, like most other lay-people out there, don't really see it that way... Follow the herd, follow the herd...
!NET (Not Net). Don't trust Microsoft. (Score:2)
Centralizing data is a huge problem with HailStorm but also consider the innate problems of storing data on the service. You are going to put your data into HailStorm and Microsoft is going to get a firsthand peek at whatever you put in. They encrypt and protect your information but there is nothing to stop them from giving it away to the government or selling it!
To make matters worse they are inplementing HailStorm into everything they sell including Windows XP, Office XP, the X-Box, and Hotmail. People will be able to link their Windows XP login with the HailStorm service.
A group of concerned University of Illinois [uiuc.edu] students has started an organization called !NET [notnet.org] (Not Net) to spread awareness of the problems with handing all your personal information to a company like Microsoft to be stored in a centralized datacenter. If Microsoft gets their way they will have the keys to this huge collection of information. We respectfully submit that handing control of this kind of information to one company, organization, or government is a horrible idea.
We are gathering people and ideas and coding an open source, alternative method of doing HailStorm where the user encodes their data with PGP keys and allows other users or companies access to that data only by signing their data with those companies or individuals' public keys. We have considered a variety of delivary mechanisms including peer to peer networks such as FreeNet. Peer to peer distribution would give the advantage of not consolidating everyone's data in one place and would also ensure that the person who stored the information, the rightfull keyholder, will be the only one that chooses who else can view that information, not Microsoft. More information on our at present unrefined ideas is located at our website www.notnet.org [notnet.org].
Microsoft Rep. talks about HailStorm at UIUC (Score:3)
Shortly afterwards a group of University of Illinois students formed an organization, !NET (Not Net). www.notnet.org [notnet.org]
We plan on spreading awareness about HailStorm as well as designing an open source alternative for it. It involves using SOAP and XML and encrypting data inside XML tags with PGP public keys. You choose what information you want to make available to companies by encrypting your entries with their public keys. Then your encrypted information is stored in an existing peer to peer system which is completely decentralized (possibly freenet) so the whole system can't break down or get hacked. In this way you encrypt your data and an unencrypted copy isn't even stored on your local machine.. no one organization, government or company (Microsoft) has access to your data.
Scary (Score:4)
If Microsoft is not an Evil Empire(TM), I don't think there ever was one!
-----
Re:The issue that matters [off topic] (Score:2)
Smokers are addicted to nicotine. Hicotine doesn't do anything for a healthy person, only for an addict. So the first cigarette doesn't do anything for the novice smoker. But after a while, when the nicotine starts to leave the system, they start to feel slightly bad. A tiny little bit depressed.
Another cigarette alleviates the bad feeling a bit; not completely, just a bit. But it's enough to make the smoker think, that cigarette made me feel better. Only, a while later, they are feeling just a little more depressed than the first one made them. Just an imperceptible amount, but the desire for the next cigarette is now stronger than ever before.
And so it goes on.
The thing is, all a smoker has to do to stop is:
1. Understand that cigarettes do NOTHING for you; you are not giving anything up, you are not making any sacrafice.
2. Don't smoke another cigarette
3. Relish being a non-smoker. Understand that you will quickly be healthier, fitter, more attractive, wealthier.
Quite easy really, and step 3 makes it fun.
Now, this may seem off topic, but ditching Windows in favour of Freedom is much easier than people are led to believe.
1. Understand that Windows does NOTHING for you; you are not giving anything up, you are not making any sacrafice.
2. Don't run Windows again
3. Relish being free. Understand that you will quickly be more satisfied, you will reap more reward from life, you get to go around with a smug internal grin all the time.
That's it
Re:Microsoft? Violate your Privacy?! (Score:2)
Re:Microsoft? Violate your Privacy?! (Score:2)
You'll have to watch yourself if you leave the house when .NET starts growing, but it can be done.
OR, better yet, help produce open source SOAP solutions for FreeBSD/Linux/name your OS. Fight the power if you feel like it.
Myself, I honestly don't care. If it's not Microsoft it'll be someone else, and I'm not like most nerds who cower in the corner of their dim apartments, fearing social interaction and a "violation" of some uber-innate privacy. I also happen to like and use a few Microsoft products regularly (Notably IE and Win2K. I use StarOffice for word processing, g++ and the development tools in Linux). To each his own.
Re:Microsoft knows that someone wants Hailstorm... (Score:2)
Of course, your '85 probably has that nice feature of sticking a coat hanger down the side of the window to unlock it too.
Re: (Score:2)
Re:Boiling Frogs (Score:2)
Check out the Vinny the Vampire [eplugz.com] comic strip
Re:parallel with environmental disasters (Score:2)
it might be unreal, but you got to make plans to cover the possibillities.
:)
Check out the Vinny the Vampire [eplugz.com] comic strip
Boiling Frogs (Score:5)
Now, If you just toss a frog straight into a pot of boiling water, this is not going to to anything but upset the frog and make the frog jump out of the pot. BUT, if you put the frog into the pot when tha water is cool, the frog will like it. If you then very gradually raise the temperature of the water the frog will not notice it. You can eventually raise the temperature of the water until it is boiling, and you now have one cooked frog dinner. NOTE, California bullfrogs, weighing in at about 3 or 4 pounds, have enough meat to make a decent meal.
How does this relate? Simple.
The long term strategy of MS is to slowly increment changes in the way things worked so that in the end, everything works they way they want, and they can dictate how it goes together. If they got greedy and tried to do it all in a year or so, then they would never get agreeement. But by implementing it bit and piece, they can continue to carve a large and larger section of the pie for themselves. All they have to do is think longer term than their opponents.
Actually, I am sure they have on a wall someplace their equivalent of a 5 or 10 year plan to conquer the known (software) world, subject to revision and new discoveries, etc. They likely planned killing off Windows about 3 to 5 years ago when it became obvious that the legal suites were beginning to be a real pain. They are not there yet, but they needed an escape plan. Part of the move to taking over the Internet was part of this escape plan, which is why Gates made sure it was the equivalent of a oceanliner coming to a halt and turning on a dime.
How to we handle this?
We need as far reaching an effort and long range vision as they do. A competitive Argument that resonates. Microsofts's sells to the inherently lazy streak in people, even if the PR is twisted. They sell to "we make it easier for you".
What competitive meme do we offer to fight this Microsoft meme virus?
Check out the Vinny the Vampire [eplugz.com] comic strip
Why this won't work (Score:2)
Re:Car accident? (Score:2)
Clear -Thump- Crap, must be a software glitch.
This is the first step to becoming BORG. First Hailstorm, then the implants finally a world controled by cyborg Bill Gates.
Microsoft knows that someone wants Hailstorm... (Score:5)
Microsoft's Hailstorm is another manifestation of the American "I want my mommy" society. Consider, for instance, a currently-running commercial for the Chevy Suburban, wherein some dumb cluck locks his keys in the truck whilst ruining tundra in the Rocky Mountains. He calls out on his cell phone, and Chevy unlocks his car remotely .
Holy Big Brother, Batman!
It sure makes me appreciate my 1985 4x4 Chevy Suburban; the most technologically-advanced priginal equipment feature on my truck is the electric windows. Now, I have some communication doodads onboard, and I'm adding a few other James Bond features, but I'll be damned if I want some anonymous corporate cog accessing to my doorlocks!
And Satan will be dodging snowballs in Hades before Microsoft pries the personal data from my cold, dead fingers. Just don't be surprised if Hailstorm is a success, especially among the people who desperately want to be wet-nursed through life...
--
Scott Robert Ladd
Master of Complexity
Destroyer of Order and Chaos
Craig Mundie (Score:2)
His daughter went to Colorado College, while I was working in the Computing department. He came to spread M$ propoganda to the Computing Director and other "decision makers" at the college. With a not-so-subtle tone of "if you get your students to use M$ software, I'll arrange a sweet deal for you (or make a big contribution to the college)".
Anyways, I got to sit in on a few meetings with him, and discuss some campus issues with him. He's totally arrogant and elitist and everything you'd expect from the way M$ does business. I tried really hard not to be prejudiced against him just because of where he works, but I think he's a total asshole.
I doubt this is shocking news to anyone, but I felt the need to share. Thanks for letting me vent a little hostility
K45
Why "Hailstorm"? (Score:2)
Didn't they learn from the flap over Carnivore? Hell, if they are going for truth in advertising maybe they should have called it eCancer.
-------
Re:Car accident? (Score:4)
Take good care of it. It'll have one hell of a market value when all the new cars come with Big Brother tracking devices, assuming it isn't outright banned.
This could affect my courtship. (Score:2)
The first is that privacy is sometimes an impediment. If I am trying to find a loved one, or get in contact with someone of note, then it is difficult if that person has clothed the details of their life in privacy.
For example, I am desperately in love with Heidi Wall. I cherish her sweet voice and her sonsy face as those of Athene. However, were the world a private, paranoid place, I would have no hope of ever meeting her - I would not even know that she exists.
Love is the base of the world, and all of our drives. Greater privacy destroys love, by reducing the circle of people in whom we can fall in love to just those we know personally.
I urge Microsoft to consider their actions carefully. They could be breaking peoples hearts.
I am not some stalker, like shoeboy - I am an honest Virgin, reserving his true passions for The One.
I won't let microsoft get in my way.
KTB:Lover, Poet, Artiste, Aesthete, Programmer.
a year later... (Score:2)
Re:Most Good Experiments Start Scary (Score:2)
Re:Microsoft knows that someone wants Hailstorm... (Score:2)
I think a lot of the bad taste ascribed to Americans is simply due to the lack of alternatives. Many people would like something better, but companies are not filling the need because profit maximization does not completely coincide with satisfying customer demand.
typical Microsoft (Score:4)
What Microsoft is doing is convenient: centralize it all on Microsoft servers and Microsoft standards. Forget about federation, server-to-server protocols and all that. What Microsoft is doing is also cheaper in the short run an quicker to market (which is why it will likely beat open standards). Nobody but Microsoft can deliver this, not because they have any better technology, but because they have the market position.
The loser is the consumer, who will be denied any kind of market choice again: your choice may be to buy Microsoft or not schedule any appointments with your doctor, dentist, or insurance broker.
On the bright side: there is a good chance that this will not fly. With always-on Internet connections, people can control their data themselves. Even without any privacy incentives, answering machines still sell well, despite personal voice mail offerings. Many people will probably prefer to keep their personal data in cheap, secure Internet servers in their home, no larger and no more complex than an answering machine.