Congrats on the first strawman in the debate.
Congrats on an empty post.
Since the people telling me not to worry about how the secret services of the world spy on citizens don't even know what a Tibetan exile is, and think that the NSA has the worlds largest concentration of mathematicians and computers in order that they can
physically bust into houses like it's a Mission Impossible movie, I'm not so sure the sublter points of civil liberties, cyber risk assesment and the balance between personal privacy and the role of an intelligence agency will carry much sway.
And note, I've already said I don't consider these things a major threat to myself and I'm giving Steam a try, so the first strawman was to accuse me of paranoia. However, on a matter of
principle regarding the future of privacy, I don't like the trend of forcing people to allow unknown remote code complete access to peoples computers just because they want to use some app or other.
There are a number of covert threats from such a system:
a) Foreign or domestic government agencies. I've given the example of China's recent spying. I didn't say I was a Tibetan exile, but it is an example of how your political activities can get you red flagged and covertly observed. I won't bother linking to ghostnet again, I'm getting the impession people aren't reading it anyway. But just because nullsquared and perhaps xavier have no political positions of interest, doesn't mean everyone is so politically blank. If you aren't politically blank, this might be worth considering.
b) Corporate agencies. The purposes here can be pretty varied. Maybe they're snooping for trade secrets. Perhaps they want dirt to blackmail you to avoid some patent lawsuit. Or perhaps they want to know your bid on some contract. It's estimated that billions of dollars worth of contracts a year are affected by this kind of espionage. Here's an example:
http://www.guardian.co.uk/world/2000/mar/31/ianblack
Echelon, established during the cold war and operated by the US, Britain, Canada, Australia and New Zealand, is reportedly capable of intercepting millions of telephone, fax and email messages.
James Woolsey, who headed the CIA from 1993-95, has already admitted what to many had long seemed obvious - that the US secretly collects information on European firms.
He wrote in last week's Wall Street Journal: "That's right, my continental friends, we have spied on you because you bribe. When we have caught you at it, you might be interested, we haven't said a word to the US companies in the competition.
"Instead we go to the gov ernment you're bribing and tell its officials that we don't take kindly to such corruption."
He insisted however that it only targeted firms which violated UN sanctions or offered bribes to gain business.
Again, this doesn't especially effect me, but this doesn't mean it isn't a problem of principle to me, and it doesn't mean that isn't a real, practical concern to any number of people.
c) Hackers and organized crime. These people are constantly looking for weaknesses in systems so they can plant key loggers and steal identies and card numbers. And you never know where a hole might appear.
A recent surprising security hole was found in Quake 3 Arena after the source code was released. It turns out a flaw in the client-server download system meant that a client could be infected with any code a hacker desired just by connecting to a server setup by the hacker. The code would automatically download and launch.
http://www.securityfocus.com/advisories/2189
Impact:
This vulnerability allows an attacker to have read or write access to a
Quake3Arena user's filesystem when the user connects to a server run by the
attacker. This could allow attackers to install Trojan horse programs,
gather passwords, and read or write files.
Now, I've been playing Q3A for years, but I've been playing offline. Since nothing was forcing me to connect to any external servers I was completely safe despite this terrible security flaw. But if any of these new DRM system that force frequent internet access develop such flaws, it could cause serious and widespead damage.
(BTW, Quake 3 Arena has been patched, and provided you use the source from
http://ioquake3.org you'll be fine, since they found the flaw in the first place.)
So my concerns about these issues are both based on principle and actual practice.
No strawmen were harmed in the making of this post.
