GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    Wolfie Christl (wchr@mastodon.social)'s status on Wednesday, 28-Aug-2024 06:12:28 JST Wolfie Christl Wolfie Christl

    I published a new report that shows how today's cybersecurity and risk profiling systems are turning into employee mass surveillance and predictive policing tools.

    Based on log, device and network data,
    they let companies monitor almost everything employees do or say.

    We need a serious debate about what is necessary and proportionate for what purpose and about safeguards that prevent misuse.

    My 76-page report focusing on software from Forcepoint/Everfox and Microsoft:
    https://crackedlabs.org/en/data-work/publications/securityriskprofiling

    In conversation about 9 months ago from mastodon.social permalink

    Attachments


    1. https://files.mastodon.social/media_attachments/files/113/035/877/977/327/598/original/65e82c7a2f77ac8d.png

    2. Domain not in remote thumbnail source whitelist: crackedlabs.org
      Employees as Risks
      from @WolfieChristl
      A case study on intrusive surveillance and behavioral profiling for cybersecurity, insider risk detection and 'compliance'
    • Embed this notice
      Wolfie Christl (wchr@mastodon.social)'s status on Wednesday, 28-Aug-2024 06:13:08 JST Wolfie Christl Wolfie Christl
      in reply to

      Forcepoint was until recently owned by defense giant Raytheon. Its behavioral surveillance tech was initially funded by the CIA's venture capital firm In-Q-Tel.

      A co-founder of RedOwl which later became Forcepoint Behavioral Analytics is a former US army intelligence and NSA officer who was previously the CEO of Berico, which was involved in a large-scale plan to discredit labor unions in the US.

      Overall, Forcepoint claims to analyze 5 billion activity records per day from 900 million devices.

      In conversation about 9 months ago permalink
    • Embed this notice
      Wolfie Christl (wchr@mastodon.social)'s status on Wednesday, 28-Aug-2024 06:13:09 JST Wolfie Christl Wolfie Christl
      in reply to
      • Thomas Claburn

      The report is part of a larger project which examines how employers (mis)use worker data, funded by Austrian Arbeiterkammer:
      https://crackedlabs.org/en/data-work

      To illustrate wider practices, the report investigates software for cybersecurity and risk profiling from two major vendors including Microsoft. While employers can use these systems for legitimate purposes, the report focuses on potential implications for employees.

      The Register's @thomasclaburn wrote about my research:
      https://www.theregister.com/2024/08/27/microsoft_workplace_surveillance/

      In conversation about 9 months ago permalink

      Attachments


      1. Domain not in remote thumbnail source whitelist: regmedia.co.uk
        Microsoft security tools probed for workplace surveillance
        Cracked Labs examines how workplace surveillance turns workers into suspects
    • Embed this notice
      Wolfie Christl (wchr@mastodon.social)'s status on Wednesday, 28-Aug-2024 06:13:09 JST Wolfie Christl Wolfie Christl
      in reply to

      First, the report investigates insider risk and behavioral monitoring technology offered by Forcepoint, a major US cybersecurity vendor that is affiliated with the defense/intelligence sector.

      Forcepoint promises to help organizations identify cyberattacks and employees who are considered a risk, whether by carelessness, negligence or intention.

      Potential threats include “disgruntled employees” who had a “huge fight with the boss” and “internal activists” who leak information to journalists.

      In conversation about 9 months ago permalink

      Attachments


      1. https://files.mastodon.social/media_attachments/files/113/035/930/065/202/984/original/2e8b85904c0f6d98.png
    • Embed this notice
      Wolfie Christl (wchr@mastodon.social)'s status on Wednesday, 28-Aug-2024 06:13:09 JST Wolfie Christl Wolfie Christl
      in reply to

      Forcepoint's systems can analyze:

      - data from employee computers/devices, e.g. file, web, app, clipboard, keyboard, screen activity
      - employee communication contents, e.g. email, chat, voice calls
      - networking data, e.g. firewall, proxy
      - performance reviews from HR systems
      - data on physical access to buildings and rooms via badging systems
      - activity log data from many other software systems, e.g. Microsoft, Salesforce, SAP, Cisco
      - external data, e.g. criminal history, financial distress

      In conversation about 9 months ago permalink

      Attachments


      1. https://files.mastodon.social/media_attachments/files/113/035/981/526/912/855/original/db6a6d9cb6ef4cc1.png

      2. https://files.mastodon.social/media_attachments/files/113/035/982/007/014/494/original/c40d163b548ad268.png

      3. https://files.mastodon.social/media_attachments/files/113/035/982/981/996/891/original/51a66a37c8262a71.png

      4. https://files.mastodon.social/media_attachments/files/113/035/983/544/088/431/original/8b5c9469e0acbf19.png
    • Embed this notice
      Wolfie Christl (wchr@mastodon.social)'s status on Wednesday, 28-Aug-2024 06:13:09 JST Wolfie Christl Wolfie Christl
      in reply to

      Based on behavioral profiling, Forcepoint's technology continuously calculates risk scores for employees, singles out those who are assessed as suspicious, ranks them by risk and raises alerts.

      To identify 'anomalous' behavior, it can analyze behavioral data on many or all employees, which is recommended by Forcepoint.

      In conversation about 9 months ago permalink

      Attachments


      1. https://files.mastodon.social/media_attachments/files/113/035/999/256/226/928/original/599e5b7c0154909e.png
      2. No result found on File_thumbnail lookup.
        TipAlerts
    • Embed this notice
      Wolfie Christl (wchr@mastodon.social)'s status on Wednesday, 28-Aug-2024 06:13:09 JST Wolfie Christl Wolfie Christl
      in reply to

      The system uses 'behavioral risk models' to assess whether employees are in financial distress, show 'decreased productivity' or intend to leave the job, how they communicate with colleagues and whether they access 'obscene' content or show 'negative sentiment' in their communications.

      Here's a list of built-in risk models, see p. 16 in my report:
      https://crackedlabs.org/dl/CrackedLabs_Christl_SecurityRiskProfiling.pdf

      In conversation about 9 months ago permalink

      Attachments


      1. https://files.mastodon.social/media_attachments/files/113/036/004/168/435/717/original/6c5cdcf386402d7a.png

      Aral Balkan repeated this.

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.