• 0 Posts
  • 329 Comments
Joined 1 year ago
cake
Cake day: June 21st, 2023

help-circle






  • Was on some United flights recently with their new seatback media systems. The user experience is much better than Delta’s, but also, they actively harvest your information at your seat to build a “profile” on you, they even ask you to choose the type of flight profile you want like “relax” or “fun” etc. and it modifies the content filters for you.

    The kicker though, was on the last flight, when the lighting was just right that I noticed they have a pinhole camera installed on the lower left of the display, along with some IR blasters to power a proximity sensor around a software button.

    Blasters likely produce enough light that the camera can see you even when the screen is off/cabin is dark. So they’re likely building passenger profiles with visual data now as well, it’d be trivial to do facial recognition of “happy, sad, sleepy, etc” on top of capturing your movement in the seat. Did you just use your phone? Did you use the seatback screen? Are you reading a book? What food did you choose?



  • And the health apps know when you’re sleeping, they know your heartrate throughout the day, your o2 sats. They can take all this mortality risk data to factor in things, advertise drugs to you, advertise foods they know you’ll eat even though it’s bad, manipulate how your insurance pays out for your next treatment because it would have been preventable if you hadn’t eaten those donuts. The phone manufacturers know you run apps, how long, what you do (yes, even Apple, especially Apple, they hide behind “privacy” so you feel ok with what they do to you) what web pages you open, how long you view them.

    They could biometrically paint a picture of your day, your movement, there’s an entire profile of data available on many humans. I wouldn’t be surprised if they aren’t already tying heart rate data to viewership of media and advertising.


  • Certs have existed a long time, are never implemented correctly, and the expiration cycle that is supposed to bolster security just causes pain as a result.

    Certs should just be redesigned to have a kill switch. CRLs were supposed to handle that, but are rarely implemented or implemented correctly.

    Certs are also used in so many places where they may not be suited to the task, but because they exist, they’ve become the de-facto standard.

    A temporal expiration system seems flawed from the beginning anyway. What, you don’t trust your system anymore just because time has passed? Time is always passing. Are we all secretly racist against clocks now?