GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by Wolfie Christl (wchr@mastodon.social)

  1. Embed this notice
    Wolfie Christl (wchr@mastodon.social)'s status on Sunday, 09-Mar-2025 06:19:48 JST Wolfie Christl Wolfie Christl

    So, after trying to bankrupt Hondoras by suing the country for $11 billion because of their extraterritorial private city project, Thiel and other oligarchs now want the Trump/Musk regime to create tax-exempt 'freedom cities' in the US where "clinical trials, nuclear reactor startups [etc] can proceed without having to get prior approval from agencies like the Food and Drug Administration, the Nuclear Regulatory Commission, and the Environmental Protection Agency":
    https://www.wired.com/story/startup-nations-donald-trump-legislation/

    In conversation about 2 months ago from mastodon.social permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: media.wired.com
      ‘Startup Nation’ Groups Say They’re Meeting Trump Officials to Push for Deregulated ‘Freedom Cities’
      from Caroline Haskins,Vittoria Elliott
      The architects of projects like Próspera are drafting legislation to create US cities that would be free from federal regulations.
  2. Embed this notice
    Wolfie Christl (wchr@mastodon.social)'s status on Monday, 30-Dec-2024 06:26:01 JST Wolfie Christl Wolfie Christl
    • Flüpke
    • Michael Kreil

    Volkswagen left an unprotected database with up to two years of sensitive personal data on 800k networked VW, Seat, Audi and Skoda cars accessible online, including names, user IDs, sensor and geolocation data.

    CCC talk by @fluepke and @michaelkreil (in German):
    https://streaming.media.ccc.de/38c3/relive/598

    Spiegel article:
    https://www.spiegel.de/netzwelt/web/volkswagen-konzern-datenleck-wir-wissen-wo-dein-auto-steht-a-e12d33d0-97bc-493c-96d1-aa5892861027

    In conversation about 5 months ago from mastodon.social permalink

    Attachments


    1. https://files.mastodon.social/media_attachments/files/113/732/986/855/040/256/original/5efffc762842f724.png

    2. https://files.mastodon.social/media_attachments/files/113/732/987/461/153/640/original/688672904efa1952.png

    3. https://files.mastodon.social/media_attachments/files/113/732/988/156/182/083/original/a110c43355a94808.png

    4. https://files.mastodon.social/media_attachments/files/113/732/988/814/872/651/original/851a40cbf6a1a3eb.png

    5. Domain not in remote thumbnail source whitelist: cdn.prod.www.spiegel.de
      Volkswagen-Konzern - Datenleck: Wir wissen, wo dein Auto steht
      from @derspiegel
      VW hat mit einer neuen Blamage zu kämpfen. Bewegungsdaten von 800.000 E-Autos sowie Kontaktinformationen zu den Besitzern standen ungeschützt im Netz. Sichtbar war, wer wann zu Hause parkt, beim BND oder vor dem Bordell. Die SPIEGEL-Recherche.
  3. Embed this notice
    Wolfie Christl (wchr@mastodon.social)'s status on Wednesday, 27-Nov-2024 01:31:18 JST Wolfie Christl Wolfie Christl

    The network technology giant Cisco offers to turn Wi-Fi access points installed in offices and other buildings into a system that tracks the location of employees, customers, smartphones, laptops and other devices for a wide range of purposes #workersurveillance

    I took a deep dive ⬇️ [thread]

    In conversation about 6 months ago from mastodon.social permalink

    Attachments


    1. https://files.mastodon.social/media_attachments/files/113/549/542/775/231/046/original/68d9c11d133954e3.png
  4. Embed this notice
    Wolfie Christl (wchr@mastodon.social)'s status on Wednesday, 28-Aug-2024 06:13:09 JST Wolfie Christl Wolfie Christl
    in reply to

    The system uses 'behavioral risk models' to assess whether employees are in financial distress, show 'decreased productivity' or intend to leave the job, how they communicate with colleagues and whether they access 'obscene' content or show 'negative sentiment' in their communications.

    Here's a list of built-in risk models, see p. 16 in my report:
    https://crackedlabs.org/dl/CrackedLabs_Christl_SecurityRiskProfiling.pdf

    In conversation about 9 months ago from mastodon.social permalink

    Attachments


    1. https://files.mastodon.social/media_attachments/files/113/036/004/168/435/717/original/6c5cdcf386402d7a.png

  5. Embed this notice
    Wolfie Christl (wchr@mastodon.social)'s status on Wednesday, 28-Aug-2024 06:13:09 JST Wolfie Christl Wolfie Christl
    in reply to

    Based on behavioral profiling, Forcepoint's technology continuously calculates risk scores for employees, singles out those who are assessed as suspicious, ranks them by risk and raises alerts.

    To identify 'anomalous' behavior, it can analyze behavioral data on many or all employees, which is recommended by Forcepoint.

    In conversation about 9 months ago from mastodon.social permalink

    Attachments


    1. https://files.mastodon.social/media_attachments/files/113/035/999/256/226/928/original/599e5b7c0154909e.png
    2. No result found on File_thumbnail lookup.
      TipAlerts
  6. Embed this notice
    Wolfie Christl (wchr@mastodon.social)'s status on Wednesday, 28-Aug-2024 06:13:09 JST Wolfie Christl Wolfie Christl
    in reply to

    Forcepoint's systems can analyze:

    - data from employee computers/devices, e.g. file, web, app, clipboard, keyboard, screen activity
    - employee communication contents, e.g. email, chat, voice calls
    - networking data, e.g. firewall, proxy
    - performance reviews from HR systems
    - data on physical access to buildings and rooms via badging systems
    - activity log data from many other software systems, e.g. Microsoft, Salesforce, SAP, Cisco
    - external data, e.g. criminal history, financial distress

    In conversation about 9 months ago from mastodon.social permalink

    Attachments


    1. https://files.mastodon.social/media_attachments/files/113/035/981/526/912/855/original/db6a6d9cb6ef4cc1.png

    2. https://files.mastodon.social/media_attachments/files/113/035/982/007/014/494/original/c40d163b548ad268.png

    3. https://files.mastodon.social/media_attachments/files/113/035/982/981/996/891/original/51a66a37c8262a71.png

    4. https://files.mastodon.social/media_attachments/files/113/035/983/544/088/431/original/8b5c9469e0acbf19.png
  7. Embed this notice
    Wolfie Christl (wchr@mastodon.social)'s status on Wednesday, 28-Aug-2024 06:13:09 JST Wolfie Christl Wolfie Christl
    in reply to

    First, the report investigates insider risk and behavioral monitoring technology offered by Forcepoint, a major US cybersecurity vendor that is affiliated with the defense/intelligence sector.

    Forcepoint promises to help organizations identify cyberattacks and employees who are considered a risk, whether by carelessness, negligence or intention.

    Potential threats include “disgruntled employees” who had a “huge fight with the boss” and “internal activists” who leak information to journalists.

    In conversation about 9 months ago from mastodon.social permalink

    Attachments


    1. https://files.mastodon.social/media_attachments/files/113/035/930/065/202/984/original/2e8b85904c0f6d98.png
  8. Embed this notice
    Wolfie Christl (wchr@mastodon.social)'s status on Wednesday, 28-Aug-2024 06:13:09 JST Wolfie Christl Wolfie Christl
    in reply to
    • Thomas Claburn

    The report is part of a larger project which examines how employers (mis)use worker data, funded by Austrian Arbeiterkammer:
    https://crackedlabs.org/en/data-work

    To illustrate wider practices, the report investigates software for cybersecurity and risk profiling from two major vendors including Microsoft. While employers can use these systems for legitimate purposes, the report focuses on potential implications for employees.

    The Register's @thomasclaburn wrote about my research:
    https://www.theregister.com/2024/08/27/microsoft_workplace_surveillance/

    In conversation about 9 months ago from mastodon.social permalink

    Attachments


    1. Domain not in remote thumbnail source whitelist: regmedia.co.uk
      Microsoft security tools probed for workplace surveillance
      Cracked Labs examines how workplace surveillance turns workers into suspects
  9. Embed this notice
    Wolfie Christl (wchr@mastodon.social)'s status on Wednesday, 28-Aug-2024 06:13:08 JST Wolfie Christl Wolfie Christl
    in reply to

    Forcepoint was until recently owned by defense giant Raytheon. Its behavioral surveillance tech was initially funded by the CIA's venture capital firm In-Q-Tel.

    A co-founder of RedOwl which later became Forcepoint Behavioral Analytics is a former US army intelligence and NSA officer who was previously the CEO of Berico, which was involved in a large-scale plan to discredit labor unions in the US.

    Overall, Forcepoint claims to analyze 5 billion activity records per day from 900 million devices.

    In conversation about 9 months ago from mastodon.social permalink
  10. Embed this notice
    Wolfie Christl (wchr@mastodon.social)'s status on Wednesday, 28-Aug-2024 06:12:28 JST Wolfie Christl Wolfie Christl

    I published a new report that shows how today's cybersecurity and risk profiling systems are turning into employee mass surveillance and predictive policing tools.

    Based on log, device and network data,
    they let companies monitor almost everything employees do or say.

    We need a serious debate about what is necessary and proportionate for what purpose and about safeguards that prevent misuse.

    My 76-page report focusing on software from Forcepoint/Everfox and Microsoft:
    https://crackedlabs.org/en/data-work/publications/securityriskprofiling

    In conversation about 9 months ago from mastodon.social permalink

    Attachments


    1. https://files.mastodon.social/media_attachments/files/113/035/877/977/327/598/original/65e82c7a2f77ac8d.png

    2. Domain not in remote thumbnail source whitelist: crackedlabs.org
      Employees as Risks
      from @WolfieChristl
      A case study on intrusive surveillance and behavioral profiling for cybersecurity, insider risk detection and 'compliance'
  11. Embed this notice
    Wolfie Christl (wchr@mastodon.social)'s status on Saturday, 27-Apr-2024 05:09:52 JST Wolfie Christl Wolfie Christl

    "A data broker is offering sensitive passport data of thousands of people for sale – and publishing some of it openly online. Our investigation leads to an airline as a possible source. Data protection authorities are alarmed"

    "netzpolitik.org was able to identify several people on the list. They live in Bavaria or Lower Saxony and confirm that their data and ID numbers are genuine. Some were shocked to learn their data was public"

    Passport numbers for sale in the EU: https://netzpolitik.org/2024/european-data-broker-sensitive-passport-data-of-germans-published-online/

    In conversation about a year ago from mastodon.social permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: cdn.netzpolitik.org
      start
    2. Domain not in remote thumbnail source whitelist: cdn.netzpolitik.org
      Sensitive passport data of Germans published online
      from Chris Köver
      A data broker is offering sensitive passport data of thousands of people for sale – and publishing some of it openly online. Our investigation leads to an airline as a possible source. Data protection authorities are alarmed.
  12. Embed this notice
    Wolfie Christl (wchr@mastodon.social)'s status on Saturday, 02-Mar-2024 00:14:23 JST Wolfie Christl Wolfie Christl

    LiveRamp, formerly known as Acxiom, sits at the core of much of today's opaque personal data sharing for marketing purposes and maintains comprehensive identity records about everyone in many countries, including in Europe and the UK.

    We examined LiveRamp's identity surveillance system, which facilitates digital tracking and profiling across many companies.

    New 60-page report published today:
    https://crackedlabs.org/en/identity-surveillance

    In conversation about a year ago from mastodon.social permalink

    Attachments


    1. https://files.mastodon.social/media_attachments/files/112/010/210/305/289/536/original/d46a12c73534fe76.png
    2. Domain not in remote thumbnail source whitelist: crackedlabs.org
      Pervasive identity surveillance for marketing purposes
      from @WolfieChristl
      A technical report on personal data processing for LiveRamp’s RampID identity graph system based on an analysis of software documentation
  13. Embed this notice
    Wolfie Christl (wchr@mastodon.social)'s status on Monday, 22-Jan-2024 23:19:14 JST Wolfie Christl Wolfie Christl

    "Each Facebook user is monitored by thousands of companies ... Using a panel of 709 volunteers who shared archives of their Facebook data, Consumer Reports found that a total of 186,892 companies sent data about them to the social network. On average, each participant in the study had their data sent to Facebook by 2,230 companies"
    https://themarkup.org/privacy/2024/01/17/each-facebook-user-is-monitored-by-thousands-of-companies-study-indicates

    In conversation about a year ago from mastodon.social permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: mrkp-static-production.themarkup.org
      Each Facebook User is Monitored by Thousands of Companies – The Markup
      from @themarkup
      A new study looks at who is sending information about your online activity to Facebook
  14. Embed this notice
    Wolfie Christl (wchr@mastodon.social)'s status on Thursday, 23-Nov-2023 08:02:15 JST Wolfie Christl Wolfie Christl

    The video includes a demo of the Patternz system. An archived version should be soon available here:
    https://web.archive.org/web/20231122160629/https://www.youtube.com/watch?v=P6EZF0vdzYw

    The video seems to be a sales pitch to a Peruvian cybersecurity firm and the government of Peru for covid tracking purposes, but it also explains that Patternz was originally 'designed and built' as a 'homeland security platform', for 'anti-riots and protesting'.

    Weird that this is publicly available. Uploaded in January 2023, but it might actually be older, 2020/21/22?

    In conversation Thursday, 23-Nov-2023 08:02:15 JST from mastodon.social permalink

    Attachments


    1. https://files.mastodon.social/media_attachments/files/111/456/665/702/298/742/original/ed8a909781c48e5b.png
    2. Domain not in remote thumbnail source whitelist: web.archive.org
      Patternz
      from FS Ciberseguridad
      Presentacion de PatternzInteligencia Israel - FS
  15. Embed this notice
    Wolfie Christl (wchr@mastodon.social)'s status on Thursday, 23-Nov-2023 08:02:15 JST Wolfie Christl Wolfie Christl
    in reply to

    Xandr/Microsoft also lists Nuviad as a "partner which may receive Platform Data":
    https://docs.xandr.com/bundle/service-policies/page/third-party-providers.html

    Here's Nuviad boasting about '2.5 billion user profiles' and 'analyzing over 700k ad opportunities every second'. From an Amazon AWS event in 2018:
    https://de.slideshare.net/AmazonWebServices/success-has-many-query-engines-tel-aviv-summit-2018

    In conversation Thursday, 23-Nov-2023 08:02:15 JST from mastodon.social permalink

    Attachments


    1. https://files.mastodon.social/media_attachments/files/111/420/098/611/682/349/original/4b245c9717025471.png
    2. No result found on File_thumbnail lookup.
      Xandr Documentation Center
    3. Domain not in remote thumbnail source whitelist: cdn.slidesharecdn.com
      Success has Many Query Engines- Tel Aviv Summit 2018
      Success has Many Query Engines- Tel Aviv Summit 2018 - Als PDF herunterladen oder kostenlos online ansehen
  16. Embed this notice
    Wolfie Christl (wchr@mastodon.social)'s status on Thursday, 23-Nov-2023 08:01:39 JST Wolfie Christl Wolfie Christl
    in reply to

    The commercial data industry is complicit. Google, the IAB, adtech firms, data brokers, publishers and advertisers are complicit.

    Whenever someone visits a website or uses a mobile app that displays digital ads, profile data is broadcasted to dozens or hundreds of companies and other entities in uncontrolled ways.

    This occurs billions and billions of times a day. Billions of people are affected globally, hundreds of millions in Europe.

    (see our report: https://www.iccl.ie/wp-content/uploads/2023/11/Europes-hidden-security-crisis.pdf)

    In conversation Thursday, 23-Nov-2023 08:01:39 JST from mastodon.social permalink

    Attachments



    1. https://files.mastodon.social/media_attachments/files/111/410/832/704/445/665/original/6d5261497b5dd616.png
  17. Embed this notice
    Wolfie Christl (wchr@mastodon.social)'s status on Thursday, 23-Nov-2023 08:01:39 JST Wolfie Christl Wolfie Christl
    in reply to

    Although we cannot verify their claims, the docs and web sources suggest that Patternz turns the intrusive global surveillance infrastructure that has been built for digital advertising into a system for mass and targeted surveillance for national security agencies, and perhaps also other actors.

    It's now the best-documented example of how personal data that is routinely processed to provide consumer services and digital advertising can be exploited for completely unrelated purposes at scale.

    In conversation Thursday, 23-Nov-2023 08:01:39 JST from mastodon.social permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      actors.it
      This domain may be for sale!
  18. Embed this notice
    Wolfie Christl (wchr@mastodon.social)'s status on Thursday, 23-Nov-2023 08:01:38 JST Wolfie Christl Wolfie Christl
    in reply to

    To my knowledge, this 2020 Forbes article provided evidence for the first time that a firm who sells surveillance tech to governments was running its own DSP to harvest personal data from RTB bid requests in digital advertising. There was not a lot of detail, but it has been a known issue for years:
    https://www.forbes.com/sites/thomasbrewster/2020/12/11/exclusive-israeli-surveillance-companies-are-siphoning-masses-of-location-data-from-smartphone-apps/

    Of course, it's ridiculous to believe that only 'Western' state actors would access RTB bidstream data. I'm sure several state and malicious actors do.

    In conversation Thursday, 23-Nov-2023 08:01:38 JST from mastodon.social permalink

    Attachments


  19. Embed this notice
    Wolfie Christl (wchr@mastodon.social)'s status on Thursday, 23-Nov-2023 08:01:38 JST Wolfie Christl Wolfie Christl
    in reply to

    It was a deliberate decision to create the RTB advertising system in this bad way, and even worse, the data industry has since then been fighting hard to keep it running, for years, at any cost, from lobbying policymakers to trying to delay GDPR enforcement.

    Anyway, thousands of adtech firms and a much larger number of publishers and advertisers have NO CONTROL over who they share personal data with.

    Which means they cannot have a legal basis to do so under the GDPR. Which means it's illegal.

    In conversation Thursday, 23-Nov-2023 08:01:38 JST from mastodon.social permalink
  20. Embed this notice
    Wolfie Christl (wchr@mastodon.social)'s status on Thursday, 23-Nov-2023 08:01:37 JST Wolfie Christl Wolfie Christl
    in reply to

    RTB undermines the privacy and data rights of billions of people, and it undermines trust into digital technology at large.

    RTB is also a national security threat, because of course the data sharing doesn't stop for political leaders, sensitive personnel, military staff and their families.

    In our report published today we call for the European Commission, ENISA and EEAS to take action:
    https://www.iccl.ie/wp-content/uploads/2023/11/Europes-hidden-security-crisis.pdf

    We also call for the US FTC and Congress to take action:
    https://www.iccl.ie/wp-content/uploads/2023/11/Americas-hidden-security-crisis.pdf

    In conversation Thursday, 23-Nov-2023 08:01:37 JST from mastodon.social permalink

    Attachments



    1. https://files.mastodon.social/media_attachments/files/111/410/995/864/776/613/original/6cddf1846f9d8881.png

    2. https://files.mastodon.social/media_attachments/files/111/410/996/464/136/353/original/1512351b9bd2108b.png


  • Before

User actions

    Wolfie Christl

    Wolfie Christl

    Public-interest researcher https://crackedlabs.org | Tech and society. Tracking, surveillance, consumer data, platform power, algorithmic decisions, datafication of work.https://wolfie.crackedlabs.org/en

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          176373
          Member since
          22 Sep 2023
          Notices
          36
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.