Showing posts with label Jordan Pearson. Show all posts
Showing posts with label Jordan Pearson. Show all posts

Tuesday, 21 March 2017

GitHub Uses Broken Cryptography, But It Has a Plan

In February, Google shocked the cryptography community by effectively breaking the stalwart SHA-1 hashing algorithm, making hypothetical concerns about the security of SHA-1 concrete for the first time.

While most folks have moved on from SHA-1 already, there's one place on the web that has the algorithm at its core: GitHub, the nerve centre of every open source project from bitcoin, to government-owned elections software, to the weekend projects of most DIY-minded developers. So, yeah, not good.

Thankfully, on Monday GitHub implemented a system that automatically detects when someone is trying to use an SHA-1 hack, and rejects it.

GitHub stores user data as "objects" that all have a unique SHA-1 hash, which the site uses as ID to keep track of them. This was more or less fine, because SHA-1 is designed so that it is extremely unlikely for two hashes to ever be identical—what's known as a "collision." Google demonstrated a highly specialized method for generating an SHA-1 collision in February, opening the possibility for someone to replace innocent code on GitHub with malicious code, using an identical SHA-1 hash.

According to a company blog post, Google's method of generating an SHA-1 collision "[leaves] a pattern in the bytes" that GitHub can detect. If the alarm bells go off, then GitHub will automatically abort the operation, the blog states.

If all of this seems like a big old bandaid to you, that's because it is. But, according to the blog, GitHub is looking for a more permanent solution.

"The Git project is also developing a plan to transition away from SHA-1 to another, more secure hash algorithm, while minimizing the disruption to existing repository data," the blog states. "As that work matures, we plan to support it on GitHub."

Subscribe to pluspluspodcast , Motherboard's new show about the people and machines that are building our future.

Correction: An earlier version of this article had the headline "GitHub Uses Broken Encryption, But It Has a Plan." SHA-1 is a cryptographic algorithm, not an encryption tool. This article's headline has been updated to reflect this, and Motherboard regrets the error. 



from GitHub Uses Broken Cryptography, But It Has a Plan

Saturday, 18 March 2017

Bitcoin Exchanges Have Accepted the Inevitability of a Fork

Bitcoin just can't catch a break. Last Friday, the virtual currency community's hopes were dashed when the Securities and Exchange Commission denied an application to approve a bitcoin investment fund. Bitcoin quickly recovered its value, but just a week later, it looks like another potential disaster is on the horizon.

After two years of debate and acrimony, bitcoin might finally be about to implement a code change that would split the currency in two, with meaningful investments on both sides. This possibility has been a nightmare for many who support the status quo, and on Friday a group of major bitcoin exchanges—which in many ways make up the foundation of bitcoin's economy, since that's where coins are bought and sold—released their contingency plan.

An open letter signed by 18 bitcoin exchanges including some large players lays it out: If bitcoin is split into two, these exchanges will trade both versions as separate currencies. But there's a catch. The exchanges state that they'll only support the newer version if it can safely avoid issues that have plagued splits in other virtual currencies.

"While a contentious forking event may be inevitable, and may ultimately provide a path forward for on-chain capacity increases, we have an obligation to our customers to provide a clear and consistent plan to minimize potential confusion surrounding such an event," the open letter states.

Read More: Bitcoin's Very Important Day Has Turned Into a Shitshow

The issue at hand is increasing the capacity, and size, of the "blocks" of bitcoin transactions that get uploaded to the blockchain. Right now, these blocks are almost uniformly full of transaction information, limiting the number of transactions that can go through the bitcoin network in a reasonable amount of time. For people who want bigger blocks, the argument is that if bitcoin is ever going to be used by people around the world instead of just a niche community of enthusiasts, it needs to be fast.

Enter Bitcoin Unlimited, a version of the standard Bitcoin Core client that allows miners—the people who create the blocks—to signal to other miners if they're willing to accept bigger blocks. If enough miners agree that they will process larger blocks for long enough, then Bitcoin Unlimited forks off from the main bitcoin chain, effectively becoming its own currency with its own rules. Interest in Bitcoin Unlimited has skyrocketed in recent weeks, leading the exchanges to plan for what will happen next.

One large risk of a split like this is what's known as a "replay" bug. When bitcoin alternative Ethereum split into two versions through a software fork, this bug wreaked havoc by duplicating transactions from one chain onto the other. To offer Bitcoin Unlimited on their platforms, the exchanges wrote, its developers need to protect against this.

"Failure to do so will impede our ability to preserve [Unlimited] for customers and will either delay or outright preclude the listing of [Unlimited]," the open letter states.

It's unclear what, exactly, will transpire in the coming days and weeks. But at this pivotal time in bitcoin's history, nobody wants to take any chances.

Subscribe to pluspluspodcast , Motherboard's new show about the people and machines that are building our future.



from Bitcoin Exchanges Have Accepted the Inevitability of a Fork

Thursday, 16 March 2017

Canada's Privacy Watchdog Lacks the Teeth to Curb Phone Searches at the Border

Canada's federal privacy watchdog has officially opened an investigation into the practices of border guards searching people's devices as they attempt to cross into the US.

Vagueness around what powers border guards have when it comes to your electronics, and what citizens' rights are in these situations, has caused Canadians much anxiety in the months since Donald Trump's election in the US. So, the investigation is a welcome bit of news for many. The problem is that it will do exactly nothing to stop any activity that violates the privacy laws meant to protect Canadians at the border.

The Office of the Privacy Commissioner is remaining tight-lipped about the complaint that kicked off the investigation, or even what it will cover, but the OPC told The National Post that the audit may cover the retention of data from scanned devices. Canadian law acknowledges a lowered expectation of privacy at the border, and that Canadians may be asked for their device passwords or risk detention.

There are two key points that cripple the investigation before it's even begun: First, the details and conclusions of the report may never be shared with the public, and second, the OPC has no legal authority to do anything but make recommendations that the government is then free to follow or ignore completely.

Read More: The US Gov Can Download the Entire Contents of Your Computer at Border Crossings

"Whether information about this particular investigation is included in a future annual report will be determined by the Commissioner once the investigation is complete," OPC spokesperson Tobi Cohen wrote me in an email. "At the end of any investigation, we would provide the report of findings to the complainant and the institution that was the subject of the complaint."

Though the OPC has the power to investigate privacy complaints and can force government organizations to share information with them via a court order, that's where their authority to compel action stops. "The Privacy Commissioner does not currently have order-making powers," Cohen continued.

The limits of the OPC's powers are a long-standing thorn in the side of privacy advocates in Canada. On the one hand, it's great to have a government agency dedicated to ensuring the privacy of citizens is upheld, and they even have a fire in their bellies for that sort of thing. On the other, it sucks that they can't do anything other than investigate, create (mostly) internal reports, and make non-binding recommendations.

Ironically, it's the Privacy Act itself that so severely limits the privacy watchdog. The OPC knows this, and in a wide-ranging set of recommendations for reforming the Act, OPC notes that giving them some actual teeth would be just dandy.

"We have recommended replacing the ombudsman model for the investigation of complaints with OPC powers to issue binding orders as part of our submissions on Privacy Act reform," Cohen wrote.

But until that happens, if it ever does, an OPC investigation—while a welcome symbolic development—will never be more than essentially for show.

Subscribe to pluspluspodcast , Motherboard's new show about the people and machines that are building our future.



from Canada's Privacy Watchdog Lacks the Teeth to Curb Phone Searches at the Border

Wednesday, 15 March 2017

How the ‘Doom’ Soundtrack Was Made Will Melt Your Puny Mortal Mind

It’s Time to Force Uber to Tell the Government How It Works

Uber has pulled off a magnificent trick. It's a taxi company that's actually a technology company, its drivers are actually independent contractors, and its tightly-controlled algorithmic workforce management system is actually the freewheeling high-tech lifestyle of tomorrow. 

It's because of all these actually's that Uber and other companies in the so-called "sharing economy" have been able to slip past regulations applied to more established industries. According to Ryan Calo from the University of Washington's School of Law and Alex Rosenblat from the Data & Society research institute, in this under-regulated environment, their practices have the potential to become predatory, and may already be. 

But we can't know for sure, these researchers say, because Uber keeps its inner workings a secret. In a recent paper, Calo and Rosenblat argue that it's time for federal regulators to seriously crack down by exercising their legal authority to get Uber to share its algorithms and practices, opening up the black box. 

Calo is a prominent legal scholar on all things technology-related, and Rosenblat is a technology ethnographer who has spent significant time researching what goes on under Uber's digital hood. For example, in 2015 her work revealed that Uber uses "phantom cars" in its passenger app to fool people into thinking a ride is closer than it really is. 

Read More: Will Uber Crush These 'Ethical' Alternatives?

In their new paper, the pair lay out how Uber in particular exploits an asymmetry of information to hold power over drivers and passengers. One example is the opacity of surge pricing. The paper notes that Uber monitors your phone battery, and some have wondered if surge pricing goes up when your phone battery is low. Uber has denied that they leverage such information in this way. 

As another example of surge pricing's sketchiness, a 2015 study by computer scientists from Northeastern University in Boston found that prices were different for individuals situated in the same surge pricing region. Uber blamed this on a bug. 

"Price discrimination tries to get the people who will pay $8 for a ride, to pay $8," Calo said in an interview. "That's fine, but Uber will use what they know about you to make you pay more, and that's manipulative."

Motherboard reached out to Uber for comment but didn't receive a response by deadline.

"It becomes problematic when you start trading on people's vulnerabilities," Calo continued. "There comes a point where it becomes predatory, and we think it's up to regulators to set that point."

Uber also leverages an immense amount of data and a good deal of secrecy to manipulate drivers, Rosenblat argued. 

"Uber bills drivers as entrepreneurs and [claims] that the company offers jobs to anyone who wants one," Rosenblat said in an interview. "But when drivers are on board with the system, their choices are constrained significantly."

For example, Rosenblat said, the Uber app doesn't let drivers see where their customers want to go until they've picked them up, taking away any ability to be selective with their fares. This isn't necessarily a bad thing, but it's clear how Uber is having its cake and eating it too with its "independence" rhetoric. If you really were your own boss on Uber's platform, you could do what you wanted. 

"There comes a point where it becomes predatory, and we think it's up to regulators to set that point"

"Technology companies have managed to operate in a Wild West by being in an under-regulated ecosystem even when their practices mirror those in heavily regulated industries, and Uber is a prime example," Rosenblat said. By positioning itself primarily as a tech company—and not as a cab service—it has largely managed to avoid the strict regulations associated with the latter, she argued.

Uber does work for those drivers who extol the virtues of easy money they earn through the app. But there are many others for whom the promise of Uber translates into sleeping in a leased car and dashing off whenever their phone pings. 

So, what's to be done? For Calo and Rosenblat, it's simple: Federal regulators should force Uber to show them how the platform and its algorithms work in detail. (It's worth noting that Uber has a history of steamrolling city-level attempts to regulate it thanks to a combination of intense lobbying efforts and fiery rhetoric.) 

"The Federal Trade Commission already has the power to ask pointed questions to Uber," Calo said. "It doesn't have to throw its hands up and say it's a black box. They can get in there." The FTC has intervened with Uber before, and most recently the company settled with the commission for $20 million for exaggerating how much drivers make. 

Rosenblat agreed. "One response could just be to regulate technology companies a little more stringently," she said. 

Another option would be to incentivize researchers to look into Uber's practices without fear of legal repercussion. (After all, it was researchers who discovered that Volkswagen was gaming emissions tests on some vehicles.) For example, Calo said, the government could legislate to ensure Uber doesn't use its now-infamous "greyball" tool, which it deployed to avoid law enforcement, to target researchers. 

Customers' options are more limited. "You want to know what consumers can do?" Calo said. "They can complain to the FTC, and to their state's Attorney General, and they can get angry."

Subscribe to pluspluspodcast , Motherboard's new show about the people and machines that are building our future.



from It’s Time to Force Uber to Tell the Government How It Works

Monday, 13 March 2017

Bitcoin Is for the People, Not Wall Street

After months of hype fuelled a price rally that ended with bitcoin surpassing the price of gold, the Securities and Exchange Commission denied a proposed bitcoin investment fund led by the Winklevoss twins on Friday.

That led to an initial nosedive in value, but now the price of bitcoin is more or less back to where it was before the denial. Despite what some feared, while it's deflated a bit, bitcoin hasn't exactly imploded. Now might be a good time for the bitcoin community to take a step back and think about where to go from here.

One implication of bitcoin's price comeback is the possibility that a good chunk of the price rally didn't just come from the anticipated approval of the Winklevoss' investment fund, but from all of the other things that make bitcoin… bitcoin. 

"It's not a bad thing to have speculators as long as they're balanced out by actual use of the currency," said prominent bitcoin expert Andreas Antonopoulos in an interview. "If you remove the use of the currency, and its value is dependent entirely on speculation, then it has no intrinsic value. The intrinsic value of bitcoin is through the economic activity of users using it to buy things from each other."

Rampant speculation with bitcoin would turn it into a "highly volatile casino," Antonopoulos continued.

Read More: The Dream of Buying a Coffee With Bitcoin Is Dying, If It's Not Already Dead

And this is a crucial point: the Winklevoss investment fund would have essentially been a way for finance types to win big by gambling on the price of bitcoin going up, without doing any of the work that actually makes it increase in value. Viewed like this, it might have never made sense to place so much hope in the Winklevoss' fund as being the thing that brings bitcoin to the mainstream. 

So, after the fund's failure, where does bitcoin go from here? It might make sense to focus on all the things that helped bitcoin retain much of its value after the investment fund was denied by the SEC. That is: making bitcoin something people can use. 

This will not be an easy thing to do. For nearly two years, bitcoin has been mired in a never-ending debate—or "civil war" as some call it—about a code change that would allow bitcoin to be used by more people, more quickly, and some argue with lower transaction fees to boot. While not everyone agrees on how to address the issue, most now feel that something needs to be done. 

I've used this example before, but I think it's a good one to consider: When I buy my morning coffee with cash, I don't have to pay an extra few cents, or perhaps a dollar, for the privilege of paying for goods. With bitcoin, I do. Bitcoin evangelists should ask themselves why anyone would ever do this voluntarily. 

Another problem is that while bitcoin used to be able to tout no more than a 10-minute wait time for a transaction to be "confirmed" by the network, wait times can now be hours upon hours. This places unnecessary risk on vendors who, for convenience's sake, must then let people walk out the door with goods without the transaction being settled. 

These are serious problems with numerous proposed solutions, but nobody can agree on which to go with. 

For his part, Antonopoulos suggested that bitcoin could be most useful in developing nations without a stable banking industry (this is a popular claim, but so far hasn't borne much fruit). On the note of usability, he suggested the community could look to technologies that put less strain on the blockchain by handling individual transactions in a separate system and only interacting with the blockchain when uploading them in bulk. 

The most important thing to take away from the investment fund's denial, however, is that speculation isn't the way forward for bitcoin, Antonopoulos said. Work is. 

"The next page of this story is that bitcoin will scale," he explained, "but on its own terms and its own timescale, and without sacrificing decentralization through more innovation coming down the line."

Subscribe to pluspluspodcast , Motherboard's new show about the people and machines that are building our future.



from Bitcoin Is for the People, Not Wall Street

Friday, 10 March 2017

Bitcoin’s Very Important Day Has Turned Into a Shitshow

In February, bitcoin reached its highest value ever in the history of the currency, and earlier this month was priced higher than gold. Investors and enthusiasts were elated, but cautious. The steep rise in value was largely attributed to an anticipated ruling by the Securities and Exchange Commission on a proposed bitcoin investment fund, headed up by the Winklevoss twins. 

On Friday, the SEC denied the fund. Now, bitcoin's future seems less certain than it did just days ago, and its massive price gains hang in the balance. 

The Winklevoss Bitcoin Trust, if approved, would have held bitcoins and issued shares to investors, who would have gotten a return only if the price of bitcoin rose. According to an SEC filing explaining the department's decision on Friday, the trust was denied because the vast majority of the bitcoin ecosystem is currently unregulated. 

Simply put, the SEC's decision largely hinged on the principle that the assets underlying a fund should be resistant to price manipulation. And, the SEC filing claims, since a large number of bitcoin exchanges—where coins are traded—are unregulated and outside the US, the Winklevoss Trust can't meet this requirement. 

Bitcoin is already seeing the disastrous effects of a misfired round of speculation. While the price of a single bitcoin was trending above $1300 just hours before the SEC's decision, the price immediately plummeted to just above $1000 in the minutes after. 

All this is to say: Pray for the bitcoiners. 

Subscribe to pluspluspodcast , Motherboard's new show about the people and machines that are building our future.



from Bitcoin’s Very Important Day Has Turned Into a Shitshow

Republicans Are Dismantling the Law That Protects Your DNA From Your Boss

The Genetic Information Nondiscrimination Act, or GINA, was a unicorn in the divided climate of US politics. GINA made it illegal for employers and other groups to discriminate against people based on their genetics, and to require or even ask for genetic tests, or to hand over the results of previous tests in many contexts. Signed into law by George W. Bush in 2008, it passed with a near-unanimous vote of 414-1 in Congress. 

Now, Republicans in Congress are pushing a new bill that would gut some of GINA's strongest protections for workers, leading experts to worry that employees may be put in situations where they will have to show their boss their entire genome—or else.

One can imagine a future scenario where an employer might not want to hire someone to be an actuary because they show a genetic predisposition to developing Alzheimer's. But as any geneticist will tell you, DNA is not destiny. 

The bill, called the Preserving Employee Wellness Programs Act, says that if a workplace wellness program is in compliance with the Public Health Service Act, then it should automatically be considered to be in compliance with GINA. In practice, this clever provision would mean that protections for employees under GINA when it comes to workplace wellness programs would no longer apply. The bill passed a House committee this week with all Republicans supporting and all Democrats opposing. 

Read More: Canada's New Genetic Discrimination Law Will Prevent a 'Gattaca' Future

For workplace wellness programs, GINA requires prior consent from employees that genetic information be anonymous, and that only the employee and a medical professional actually get to see the test results. Also under GINA, genetic tests for wellness programs must be totally voluntary. But if GINA no longer applies to such programs, thanks to the Preserving Employee Wellness Programs Act, then these protections would no longer exist. 

"They're completely undermining any protections," said Derek Scholes, director of science policy for the American Society of Human Genetics, which opposes the bill. "If you call it a workplace wellness program, you can ask what you like."

There's also the non-trivial risk that rolling pack protections for people when it comes to genetic testing would have a chilling effect on real science, Scholes said. For example, former President Barack Obama's Precision Medicine Initiative to combat cancer will ask more than one million participants to submit genetic information. 

"It will be difficult to enroll people into this initiative while Congress is removing protections that GINA provided to them at the same time," said Schols. "One of the reasons for GINA was that you could participate in research without the fear that the results from that research could be used against you. 

"This bill would allow employers to mandate through a wellness program that employees divulge results from such research, or pay a penalty," he continued.

Since it's just passed a committee, the Preserving Employee Wellness Programs Act has a long way to go before it has a real chance of becoming law. But, if approved, it would put the US behind its international peers when it comes to genetic protections. 

Until this week, when it passed a genetic non-discrimination law similar to GINA, Canada was the only G7 country without strong protections for DNA. 

Soon, the US could have that dubious honour. 

Subscribe to pluspluspodcast, Motherboard's new show about the people and machines that are building our future.



from Republicans Are Dismantling the Law That Protects Your DNA From Your Boss

Thursday, 9 March 2017

Canada’s New Genetic Discrimination Law Will Prevent a ‘Gattaca’ Future

On Wednesday night, Canadian parliament bucked the Prime Minister to pass a law that makes it illegal for employers or insurance companies to discriminate against people based on their DNA.

A growing number of people are having their genomes sequenced so doctors can assess their risk for various diseases, such as breast or ovarian cancer. But insurance companies also want to get their hands on that information in order to determine who's most at risk of falling ill, and charge them accordingly. One could also imagine an employer wanting to know if an air traffic controller, for example, will risk a sudden heart attack.

However, being at higher risk of developing a certain disease is not a guarantee that'll actually happen. In the US, it's illegal to discriminate someone based on their genes, and now Canada's Genetic Non-Discrimination Act would offer similar protections, making it illegal for anyone to require genetic testing as a precondition for entering into a contract or providing goods and services.

This means that once the Governor General signs the Act into law in the coming days, it will be illegal for a potential employer or your insurance company to require that you undergo a genetic test, or hand over the results of a previous one.

Read More: Canada's Insurance Companies Want All Your Genetic Information

Genetic testing has been a contentious privacy issue in Canada for a while now, particularly when it comes to insurance companies that worry not requiring genetic tests would allow people who know they have a genetic predisposition to withhold that information from insurers, gaming the system. The Office of the Privacy Commissioner (OPC), however, has maintained that a person's genome can contain unexpected insights that individuals may not understand the implications of when they give it to insurers.

"How equal is that, in terms of information exchange? Is that really the principle of good-faith contract?" Patricia Kosseim, director general of the OPC, said at a panel on genetic testing at last year's International Association of Privacy Professionals conference in Toronto. "This 'just trust us' policy position flies in the face of the underlying concept of privacy: the autonomous control over personal information."

The Act passed in parliament thanks to a revolt by Liberal party backbenchers and the official opposition, while Prime Minister Justin Trudeau argued that aspects of the Act that touch on contract law and the insurance industry overstep federal responsibilities. Still, the law passed so that genetic testing can be done in Canada for medical purposes without patients wondering if their insurance company or employer will ask them for results.

"Unfortunately, under our current regime, Canadians often refuse to undergo a genetic test, even based on a recommendation from a doctor, because of the fear of genetic discrimination," said Liberal member of parliament Jennifer O'Connell in parliament on Tuesday night during debate.

But the government, and insurance companies, maintain that parts of the law are unconstitutional.

"The industry agrees with the federal government's position as expressed by the Prime Minister and the Minister of Justice, as well as a number of provinces, that an important element of the Bill is unconstitutional," Wendy Hope, spokesperson for the Canadian Life and Health Insurance Association, wrote Motherboard in an emailed statement.

When I reached constitutional scholar and assistant dean of the University of Ottawa's law faculty Pierre Thibault, who testified before parliament on the legality of the Act, he was adamant that in his legal opinion it is constitutional.

"It is based on the criminal power of the government, and the criminal power is the same across the country," said Thibault over the phone. "If you can legislate in one field and the encroachment is minimal in the other field, then that law is valid."

The government should prepare itself for a legal fight. The Canadian Life and Health Insurance Association is "considering its options" now that the bill has been passed, Hope wrote. Some provinces are also expected to join any legal challenge, Thibault said.

For now, at least (and once the bill receives royal assent), it looks like Canada has avoided a future where your employment prospects and your insurance premiums depend on your genetic makeup.

Subscribe to pluspluspodcast , Motherboard's new show about the people and machines that are building our future.



from Canada’s New Genetic Discrimination Law Will Prevent a ‘Gattaca’ Future

Wednesday, 8 March 2017

Cynthia Breazeal Is Building the Droid You’re Looking For

This NES Mines Bitcoin

Let's say you want to mine some bitcoins. You could go out and buy some fancy and costly hardware, like most folks do, or you could just repurpose your favourite childhood video game console. 

This is exactly what a guy who goes by the internet handle "gbg" (pronounced "garbage") did. As a challenge to himself, gbg hacked together a Nintendo Entertainment System from 1985 with some modern components and software so that it could run the necessary calculations to get some bitcoin. It's a sight to behold, in all its stupidly inefficient, 8-bit glory. 

Mining bitcoin with an NES was mostly done for fun, and not for profit, it should be noted. Bitcoin mining is essentially a race between powerful computers all over the world to solve a complex math problem. Even four years ago, when gbg pulled off this stunt, bitcoin mining was a tough game to get into due to people with real money on the line beefing up their rigs. An NES built to run Tetris doesn't stand much of a chance in that scenario. 

Read More: How the Hell does Netflix on NES Work?

So, why did gbg do this? "To see if I could," was his answer when I reached him over email, after I learned about his unholy consumer tech golem for the first time through a bitcoin trade blog. 

Fair enough. 

The whole thing took a week of effort, he told me, but it was a "cheap hobby project" because he already had most of the parts laying around. Now, I should warn you, the following description of how gbg pulled it off might break your brain. 

According to his blog, gbg's setup treats the NES as a computer for the bitcoin hashing algorithm: SHA256. The problem, gbg wrote in a blog, is that SHA256 requires 32-bit operations, but the NES is only 8-bit. To get around this, gbg used a Raspberry Pi to grab bitcoin data from the network and compile it into a ROM with the SHA256 algorithm—basically, a game file. The file was sent to the NES via another external gadget, and the console did the math. 

Next, the console had to communicate to the network when it completed a successful calculation in order to get a reward in precious bitcoins. To do this, gbg set up the NES so that when a calculation was successful, the screen displayed green. When it failed, the screen was red. Gbg pointed a PlayStation Eye camera at the screen and used some open source computer vision software so it could "recognize" the green. When this happened, the mining operation was communicated to the network as a success.

Amazingly, the Rube Goldberg machine of old and new tech worked. But how much money did it make gbg? "Zero," he wrote me in an email. "The likelihood of hitting a block is so very, very small at the hashrate that the NES worked at. So small. So very, very small."

Gbg has moved on since he retrofitted his old NES, and now runs a blog where he tears down hardware bitcoin wallets and their software. He successfully reverse-engineered the popular Trezor bitcoin wallet, and even created his own open source implementation of it, which he called "Dinosaur Hiphop."

He did consider going Dr. Bitcoin Frankenstein on another revered vintage gaming console, however: Sega Dreamcast. But he abandoned the project after drawing up some initial designs. Why?

"Time," he wrote. "I'd like to get back to it, but there's only so many hours in the day."

Subscribe to pluspluspodcast , Motherboard's new show about the people and machines that are building our future.



from This NES Mines Bitcoin

Friday, 3 March 2017

The Strange Story of an Alleged Hacker Killed by Police

A hacker, a revolutionary, a racist crusader, a father, a husband, a university student, a son, and a friend: Sam Maloney was all of these things, depending on who you ask. 

But the one person we can't ask is Maloney himself, who was shot dead by police in his home in London, Ontario, during an early morning raid to seize his computer in December of last year. He allegedly fired a crossbow at officers, who were there to investigate the defacement of a local cinema's website with a rambling, racist screed. 

Subscribe to pluspluspodcast, Motherboard's new show about the people and machines that are building our future. Available wherever you get your podcasts.

Today, Motherboard is telling Maloney's story in the first episode of a new podcast: pluspluspodcast, which will tell stories from the perspective of journalists in the field. With narration by me, Jordan Pearson, production by Katie Jensen (formerly of Canadaland), and a slappin' theme song courtesy of Toronto's Paul Chin, Maloney's story sets the tone for future installments.

I visited London in January and scoured the internet to speak with Maloney's family, friends, collaborators, as well as his common law wife's lawyer. Melissa Facciolo, Maloney's wife, is facing criminal charges due to a 10-year weapons ban that was breached by the presence of the crossbow in the house. 

Maloney's story is in turns sad, strange, and unsettling. There's no doubt that his online persona was troubled and expressed toxic views that should be condemned by every reasonably empathetic person. But questions remain about the appropriateness of a pre-dawn raid to seize a computer, and the circumstances surrounding Maloney's shooting death at the hands of police. 

The Ontario Special Investigations Unit is investigating the shooting, and the police would not comment on any aspect of this story. Disclosure from the police is expected in the coming days or weeks. 

Stay tuned for new episodes of pluspluspodcast every week for the next six weeks. 

Subscribe to pluspluspodcast, Motherboard's new show about the people and machines that are building our future.



from The Strange Story of an Alleged Hacker Killed by Police

Thursday, 2 March 2017

Don’t Talk Trash on Slack

Here's a portrait of Hell: 

It's 2018. An anonymous hacker finds a way to get access to Slack's servers and decides to make off with everyone's chat logs and private messages. Then, that person decides to put it all in a 50 gigabyte .zip file and makes it downloadable on Pastebin. Just like that—probably overnight, and without any warning—every bit of petty shit you've ever typed into Slack is now the world's business. 

On Thursday, hacker Frans Rosén found a bug that let him—as well as less well-intentioned folks—log into anybody's Slack account using a malicious web page. Slack fixed the bug within hours. Will it be handled so quickly next time?

That time you and your coworker gabbed about your boss's bad breath; the DMs you sent about picking up weed for a Friday night out; all the times you complained or boasted about traffic on your site… Everything could get out there. 

I can't say for sure that this will ever happen, but at this point it's safe to say that it's a possibility at the very least. 

There's only one thing to do, I guess: Don't talk trash on Slack. 

Get six of our favorite Motherboard stories every day by signing up for our newsletter .



from Don’t Talk Trash on Slack

Here's How to Make Canadian Phone Bills Cheaper

On Wednesday, Canada's federal telecom regulator ordered a small, affordable competitor in the country's oligarchic mobile market to shut down. 

Sugar Mobile is an Ontario-based provider owned by Ice Wireless, a company that also owns a wireless network in the North. For just $19 per month—an exceedingly low price for a mobile plan in Canada—Sugar Mobile allowed customers to call and send texts over WiFi, only using Ice Wireless' network when WiFi was unavailable. It's very similar to how Google's Project Fi works in the US. 

Like Project Fi, Sugar Mobile is what's known as an "mobile virtual network operator," or MVNO. This means that although Sugar Mobile doesn't own any of its own infrastructure, it piggybacks off of the network of a larger provider—in this case, its parent company. 

Because of a roaming agreement between Ice Wireless and Rogers, one of Canada's "big three" telecom companies, Sugar Mobile also used Rogers as its network when both WiFi and Ice Wireless weren't available. This was helpful for Ice Wireless' customers in the North, especially when travelling to cities where the provider doesn't have coverage. The order to shut down Sugar Mobile came about because Rogers complained that customers outside of the North would always be using Rogers' network, violating the roaming agreement. 

It's a big mess that could have been easily avoided if the Canadian Radio-television and Telecommunications Commission (CRTC) approved mandatory access for MVNOs.

"It's like, welcome to Canada"

In a landmark ruling in 2015, the CRTC effectively put the kibosh on MVNOs operating at scale in Canada by declining to mandate that large providers lease their networks to smaller competitors. The reasoning at the time was that mandating small companies to be able to buy network access would disincentivize building new wireless infrastructure. Some organizations pushed back, but their appeal was ultimately denied by the CRTC. 

While there's nothing stopping Canadian telecoms from approving MVNO services on their networks, without a rule making such access mandatory, they've so far elected to not play nice with competition. 

"[Being an MVNO] was part of the initial discussions, and Rogers was not open to entertaining that," said Sugar Mobile president Samer Bishay over the phone. "They said, 'We have these requests every day and we decline all of them.'"

"It's like, welcome to Canada," Bishay continued. "In the US, you have 250 MVNOs. Of course this could have been avoided, but who's going to do it?"

Rogers, when asked for comment on whether Sugar Mobile being an MVNO on the Rogers network was part of the initial negotiations, sent Motherboard an emailed statement from David Watt, Rogers' Senior Vice President of Regulatory Affairs, that did not directly respond to Bishay's allegations. 

Read More: Canada Has Some of the Most Expensive Data In the World, and That's Not OK

"We're pleased the [Canadian Radio-television and Telecommunications Commission] made the right call," Watt said in the emailed statement. "We believe in innovation and a fair, competitive market—this was about violating a roaming agreement, plain and simple."

Still, it's a familiar story. Consider the case of an MVNO based in Toronto: Ting. While Ting is rather successful in the US, working with Sprint and T-Mobile, it hasn't enjoyed the same generous reception from Canadian telecom giants. 

"Sprint and T-Mobile are our providers in the states—there's no legal requirement for them to offer service, but it makes sense for them to do that," said Andrew Moore-Crispin, Ting's head of content, in a phone interview. "Canadian carriers are disincentivized to invite competition in. We all know we're paying $80 for our single cell phone plans, so there's a disincentive to change that."

Right now, small providers have precious few options in Canada, Crispin-Moore continued. "You either build your network from scratch, and you find a backdoor and see what happens," he said. 

Sugar Mobile arguably chose the latter option, and it didn't end well. As long as the Canadian mobile market is dominated by three companies, ordering that they share their networks with smaller competitors may be the only way to ensure that companies with similar ambitions don't get burned. 

Get six of our favorite Motherboard stories every day by signing up for our newsletter .



from Here's How to Make Canadian Phone Bills Cheaper

Wednesday, 1 March 2017

How an Illegal Canadian Spy Program Sailed Through Regulatory Checks

A federal court alerted Canadians to the existence of a secret metadata analysis program last year when it ruled that the program's retention of thousands of innocent people's data was illegal. The question on everyone's mind then was: Who knew about it?

In its ruling on the Operational Data Analysis Centre (ODAC), the federal court also concluded that the Canadian Security Intelligence Service (CSIS)—the country's domestic CIA analogue—had breached its duty of candour by not fully briefing the court on the program until forced. Former ministers clamored to avoid blame for approving the program or being aware of it, and CSIS halted its metadata analysis. 

But privacy regulators were aware of the program, documents show, and CSIS even went through the proper privacy checks and balances. Rules that are ostensibly in place to ensure that government programs don't breach Canadian privacy laws did nothing to stop the security agency's illegal activity. 

CSIS created a Privacy Impact Assessment, or PIA, for the metadata centre in 2010. The 64-page document, reported on by the Canadian Press on Monday and obtained by VICE News correspondent Justin Ling via an access to information request, shows how these mandatory measures were little more than a bureaucratic check-box for CSIS. All government agencies are asked to prepare PIAs for new programs and submit them to the Office of the Privacy Commissioner (OPC). 

"Whoever did the report has fully drunk the Kool-Aid"

In response to one question in the assessment that asked, "Is all the personal information collected necessary to the operating program or activity?" CSIS simply responded, "Yes." The retention of unnecessary metadata is exactly what the federal court ruled to be illegal last year. CSIS is required by law to only retain data that it deems "strictly necessary" to an investigation. 

"Whoever did the report has fully drunk the Kool-Aid," said David Fraser, a digital privacy lawyer at law firm McInnes Cooper, in a phone interview. "It's not at all surprising that a magic wand was waved over it so that it's designated as kosher before the federal court described it as unlawful. They believed that what they were doing was legal." 

In a call with journalists after the federal court ruling on the metadata analysis program, Chief General Counsel for the Department of Justice Robert Frater stated that, "We believed we had the authority. Was it set out specifically? No, it wasn't."

An OPC spokesperson confirmed to Motherboard that CSIS provided the office with the privacy assessment, but could not provide further detail due to the fact that the file contains classified information. 

"Generally speaking, PIAs are submitted to us and we can make comments and recommendations based on the government institution's analysis of the privacy risks of a given initiative, activity or program," the spokesperson wrote in an emailed statement. "The OPC, however, does not approve those initiatives, programs or activities."

Read More: How Bureaucrats and Spies Turned Canada Into a Surveillance State

The constrained role of the OPC when it comes to law enforcement has long been a point of concern. While it's a mandatory policy that all government agencies prepare PIAs and alert the OPC to new programs, it's not a law. 

I asked Privacy Commissioner Daniel Therrien about this in an interview last year, and he said, "We can only advise on issues that we're informed on. [...] Currently, it's under a policy that this is done, and often we see that the policy is not necessarily respected."

In the case of CSIS' illegal retention of citizens' metadata, we've seen how this good-faith system can fail even when an agency files a privacy assessment, if that agency isn't forthcoming with officials. 

"A PIA is only effective if the organization conducting it engages honestly and thoughtfully in the process," Brenda McPhail, director of the Canadian Civil Liberties Association's surveillance project, wrote me in an email. "If CSIS had done the PIA assessment in the way it should have been done, it should have emerged in their own analysis that the program they proposed, including the collection and storage of information on individuals not under investigation, was unlawful."

The blame for severe breaches of Canadian privacy law shouldn't lie with the OPC, even though they were presented with a Privacy Impact Assessment on the illegal program, said Fraser. 

"I would be surprised if CSIS opened its toga to the OPC to give it all the information it needed to make a real assessment," he said. "It leads to the conclusion that the system we have, whatever it is, doesn't work."

Get six of our favorite Motherboard stories every day by signing up for our newsletter .



from How an Illegal Canadian Spy Program Sailed Through Regulatory Checks

How to Keep Our Robots, Lose Our Jobs, And Prosper

The Ontario government is getting closer to starting its planned trial of a basic income—essentially topping up the incomes of people below a particular economic threshold. Understandably, some are worried about how financially sustainable a basic income will be, and how it will actually work in practice. 

Policy experts are increasingly looking to basic income to stabilize a society where humans are being replaced by robots in the workforce. Bill Gates and some politicians have gone so far as to call for a tax on robots to slow down their adoption. 

But how about this: Let's forget about all that and make our oil companies and other resource extractors, such as companies that pump groundwater for private sale, pay for society's well-being. That way, we can keep our robots and prosper, too. 

Read More: The Future of Robot Labor Is the Future of Capitalism

The idea isn't so crazy, and was discussed on Monday by former Greek finance minister Yanis Varoufakis in an essay for Al Jazeera. Varoufakis claims that instead of a basic income and an accompanying tax on robots entering the workforce, a better way to deal with increasing automation (and fewer jobs for humans) is a national dividend. 

The core idea behind a national dividend is to give every citizen an equal cut of society's overall productivity. In Varoufakis' conception, this could involve making every corporation devote some of its shares to a public trust, making every single member of society a shareholder.

Instead of disincentivizing robotics via taxation, the national dividend would allow everyone in society to prosper even if every factory replaced its human employees with robots tomorrow. 

But Varoufakis' conception of a shareholder-based national dividend is just one of several. The basic idea is that corporations—those already owned by the government, as well as privately-owned entities that profit from natural resources—should help fund all of society's well-being. 

"The state of Alaska, even under a relatively conservative Republican government in the 1980s, with all the oil and gas coming out of the state, decided to put a good portion of the profits into the Alaska Permanent Fund," said Jim Mulvale, Dean of the Faculty of Social Work at the University of Manitoba, in an interview. "Some of the money was used to pay an annual dividend to all residents of the state of Alaska."

"There'd certainly be nothing preventing national governments from doing that kind of thing," he continued. We could even look to private companies to pay into the fund. 

"We need to rethink our whole idea of work"

While oil companies are an obvious starting point, Mulvale said, we could also require other industries to contribute to a national dividend. For example, robots and the internet only exist due to decades of publicly funded research and investment, in addition to private sector contributions, so the companies that profit off of them could be asked to give back.

"The basic idea is whether it's land, or natural resources, or hydro power, or the long social enterprise of developing robots and the internet—it's social capital," Mulvale said. 

The largest difference between basic income and a national dividend is how they relate to work and jobs. 

A basic income in a quickly automating society, despite ensuring a minimum standard of living, doesn't solve the problem of there being fewer jobs overall. So, a tax on robots is needed to slow the rollout of machine labour. But with a national dividend, even a fully automated economy would buoy everyone economically because the robots would be working for us all. 

What about the other, less tangible benefits of a having a steady job? Some fear that sloth and gluttony will overtake society without the compulsion to work, but the possibilities offered by a highly technologically developed, and more communal, society have long captured imaginations for generations through media like Star Trek. 

"This would potentially underwrite people getting involved in community work or artistic endeavours," Mulvale said. "We need to rethink our whole idea of work—valuable work isn't just what people get paid for in the labour market."

Get six of our favorite Motherboard stories every day by signing up for our newsletter.



from How to Keep Our Robots, Lose Our Jobs, And Prosper

Friday, 24 February 2017

The Price of Bitcoin Just Hit a New Record High

Late Thursday night, the price of a single bitcoin was the highest it's ever been in the history of the virtual currency: $1,172.09, according to bitcoin trade blog CoinDesk, which keeps track of bitcoin's value in real-time.

Through Friday morning the price continued to rise, hitting a high of $1,206.60 before levelling off.

For some perspective on how completely bonkers that is, consider this: Just seven years ago, in 2010, someone paid 10,000 bitcoins for two pizzas. At today's prices, that would be a $12 million meal.

The bitcoin community is over the moon, particularly those who were early adopters and have been holding on to their bitcoins in case they ever appreciated in value. Someone who bought 30 bitcoins when they were worth mere cents each can now afford to buy a new car with them.

The question now is whether or not the price will stay high. This is uncharted territory, and the last time bitcoin's price reached similar highs in 2013, a massive crash followed shortly behind. In a matter of weeks, a single bitcoin went from being worth more than $1,000 to roughly $500.

As for what's driving the price up now, the accepted narrative seems to be investor speculation due to the anticipated approval of a bitcoin investment fund owned by the Winklevoss twins. The Securities and Exchange Commission's judgement on the fund is set to come down in March.

But for now, bitcoiners have a tough choice to make: Do you get while the getting's good and cash out, or do you hold?

Get six of our favorite Motherboard stories every day by signing up for our newsletter .



from The Price of Bitcoin Just Hit a New Record High