• 0 Posts
  • 191 Comments
Joined 1 year ago
cake
Cake day: June 30th, 2023

help-circle




  • The metadata is actually quite important.
    Sure, chances are it’s a “pending WhatsApp message” notification, but not the actual contents of the message.
    However, with enough metadata and by surveying traffic from WhatsApp data centers, someone could see User A accessed WhatsApps service, which generated a WhatsApp notification for User B.
    That might just be a coincidence, but with enough data and time, the probability that User A is talking to User B can be increased.
    If it also shows that Users C, D and E also get notifications at the same time, it is likely that all those users are in a group chat together.
    It’s called a timing attack.
    And perhaps it isn’t enough evidence to stand up in court, it can help build the profile of the users, and guide investigations to other possible accomplices.



  • It is a recent trend after COVID.
    Before COVID, having virtual participants or presentations, even live streams were a luxury item.

    There was one client I worked with that was an early adopter of zoom pre-pandemic, and they did a lot of multi-venue stuff with presentations happening in all venues, calling out to remote office boardrooms for presentations from that region, stuff like that.
    It was charged at a premium (because it was unknown tech, so needed a lot of supplimentary technicians and equipment to mitigate the unknown risks, as well as get the virtual aspects to the same level of production as the in-person aspects).
    Some of the more important presenters would have technicians with a bunch of studio/streaming kit sent to their location to make it feel fancier for the presenter.
    I’m sure the client saved more on flights and hotels than the extra cost of the virtual aspects of the events. But it was a premium item that not everyone could afford, or was internally set up for.

    Post pandemic, live streaming is expected, it’s pretty much a standard option tbh. Every company has their own internal platform (even if it’s just Facebook pro or whatever it’s called) and all event companies have a multi purpose platform if the client wants something different.
    Virtual participants are done with a single laptop and no backups (unless it’s a very high level event), expectations from virtual interactions are lower (before, there would have to be analysis of any dropped frames, bitrate drops, stutters etc), presenters are much more comfortable handling their own tech (some even dial in dangerously close to their time slot, making the techs sweat) and 50-75% of the conferences I do now have virtual presenters.
    It’s certainly a lot cheaper, as the tech is now known, it’s capabilities proven during lockdown, and the systems and skills to use it were developed as a standard skillset of techs.

    No, I haven’t used any 3d virtual things.
    The fanciest I did was a zoom-room to audience wall, but it all got composited into a standard stream.


  • As someone that works in the events industry.

    Conferences are about the networking and social aspects.
    This is not achievable through virtual or prerecorded aspects.
    I’ve done gigs where a few CEOs zoom/teams/whatever in to show face.
    I’ve done gigs where it’s all in 1 location with only people in the room.
    I’ve done gigs where it’s people in the room, but some satellite venues that “dial in” (even done a few of the satellite venues).
    I’ve done gigs with CSuites at multiple locations, and each site takes turns presenting some part of the conference.
    Honestly, all of this can be done via zoom or some other platform to much the same effect.

    What you can’t get is the face-to-face time, incidental conversations, random introductions, and drunken conversations that happen over lunch, coffee, bar and dinner events.
    And I see this in “happier” clients. TBH, the good clients. The ones that have interesting presentations and engaged audiences are also the ones who benefit most from these extra social interactions.
    The gigs where it’s some death-by-powerpoint should have just been a zoom meeting, or dare I say just an email or 2.

    So, I’d say it’s how invested you are in the topic.
    If it’s something you care about (or affects you directly): go in-person. You will get more from the event than is what is on the schedule.
    If it’s something you have to go to, save the planet: watch it online (or whatever is the minimum mandated by your company). You aren’t going to benefit from the social aspects, leave that to you manager.

    I am seeing the trend of team leaders and key people attending conferences, with many others watching virtually (like a 1:4 ratio).





  • Yeh, it’s crazy right?
    This is all just fancy wheels, turned around, odd shaped, made to fit together better.
    And the understanding of mathematics, geometry and mechanics makes this massive apparatus of intricately connected pieces - which are relatively easy to understand in isolation - into this thing that can point a gun to be able to hit a moving target.

    World War 2 was horrendous. But some of the tech developed is jaw-dropping.
    Since then, it’s grown exponentially. We are standing on the shoulders of giants!


  • It opens users to timing attacks.
    If there are 10000 notifications per second. And across 100 incidents user A does something to cause a notification and user B receives a notification within network latency time periods, it is likely user A is talking to user B.
    Whilst that seems like arbitrarily useless data, having this at the giga/peta scale that the US government is processing it, you can quickly build a map of users “talking” to users.
    Now, this requires the help of other parties. You need to know that user A is using WhatsApp at the time. And yeh, you don’t know what the message is, but you know that they are hitting WhatsApps servers. And you know that within 5 minutes of User B receiving a notification, they are also then contacting WhatsApp servers.
    So now you know that user A is likely talking to user B via WhatsApp.
    And also user G, I X and M are also involved in this conversation.
    And you bust user G on some random charge. And suddenly warrants are issued for more detailed examination of users A, B, I, X and M.
    Maybe they have nothing to hide and are just old college friends. Or maybe they are a drug ring, or whatever.

    It’s all the “I have nothing to hide”, phones being tied to a person, privacy and all that.
    We can’t really comprehend the data warehouse/lake/ocean level of scale required to realise what all the little pieces of meta data and tracking information being able to add up to “User A is actually this person right here right now and they bought a latte at Starbucks and got 5 loyalty points” level of tracking.

    Is it likely this bad?
    Probably.
    Theres the “Target knows I’m pregnant before told anyone” story.
    https://www.forbes.com/sites/kashmirhill/2012/02/16/how-target-figured-out-a-teen-girl-was-pregnant-before-her-father-did/

    That’s over a decade ago. It’s not let off. And you can bet that governments are operating at a level a few years beyond private industry.

    So yeh, every bit of metadata counts







  • Yeh, except the battery will provide 12v throughout. So that’s essentially just an inrush current.

    A ballast is actually the opposite. It limits the current.
    From wiki:

    A familiar and widely used example is the inductive ballast used in fluorescent lamps to limit the current through the tube, which would otherwise rise to a destructive level due to the negative differential resistance of the tube’s voltage-current characteristic.

    And later…

    In operation, an increase in current through the fluorescent tube causes a drop in voltage across it. If the tube were connected directly to the power line, the falling tube voltage would cause more and more current to flow, until it destroyed itself. To prevent this, fluorescent tubes are connected to the power line through a ballast. The ballast adds positive impedance (AC resistance) to the circuit to counteract the negative resistance of the tube, limiting the current.

    https://wikipedia.org/wiki/Electrical_ballast