Showing posts with label identity. Show all posts
Showing posts with label identity. Show all posts

Monday, October 18, 2010

Chevron do agree, just not on everything (or a Yes Men hoax puncture a campaign)

It's a common complaint that public opinion has poor ability of comprehending nuances or complex issues. Well, let's see if they can sort this out, and just how much of Chevron's marketing (a.k.a. greenwashing) budget has gone down the drain.

So, social media didn't know what to think, Chevron was saying some funky stuff and the first I saw of it (thanks to Chris) was assuming Yes Men (theyesmen.org). Well chevron-press.com and chevron-weagree.com think "Oil companies should... ":

  • ... clean up their messes
  • ... fix the problems they create
  • ... put safety first

Wow, some pretty extreme statements there, coming from a huge oil company! Way to go corporate social responsibility!

Well, turns out the press contact "Giles Vechny" has no other google hits, basically declaring him an invented (at least as a professional) identity, and most likely the page a hoax. Haha, way to go Yes Men (or copycats), you almost managed to fool the world again, that's really funny. The world smiles and declares Chevron "We agree" CSR campaign a hoax.

Well, think again, because it only partly is! press.chevron-corp.com states (I'm sorry, I sincerely hope I didn't get those URLs mixed up now):

"While such a campaign does exist, its official URL is chevron.com/weagree. The advertisements released earlier today, at chevron-weagree.com, were an elaborate subterfuge and must not be mistaken as real"

So, what Chevron and chevron.com/weagree does agree on are that "Oil companies should... ":

  • ... put their profits to good use
  • ... need to get real
  • It's time... get behind the development of renewable energy
  • ... support the communities they're a part of
  • ... think more like technology companies
  • ... should support small business

I'll leave it to the professionals to weed out exactly how accountable anyone can be held to such ideals and how watered down it is.

Now good.is writes that also the second press release is fake... well, I'm not sure anymore. Thanks to @blumenberg whom I bounced some messages early on with. Anyway it seems Chevron had a new fresh marketing campaign, trying to clear the slop off big oil, though the campaign was leaked to Yes Men (or copy cats, I haven't seen them verified yet), enabling them to perform this record-fast counter-campaign. If not heads will roll, at least it certainly was a powerful way of putting focus on big oil and their attempts at CSR.

The Yes Men have publicly described their methods, most recently in their documentary "THE YES MEN FIX THE WORLD", supposedly due to a legal conflict available for free instead of for sale. So, you can at least with their approval just go to that site, download and enjoy their guerilla marketing.

Now, feel free to start the flaming.


The Yes Men posing as Exxon executives (from wikimedia commons, credit to Tavis )


Enjoy my other posts on marketing and identity.

(Update: Turns out the story is even more intricate than described above, and not all of my conclusions above were entirely correct. I hope to remedy it shortly)

Wednesday, November 5, 2008

Remember, remember the fifth of November... when you were anonymous and free


"Remember, remember the Fifth of November
The Gunpowder Treason and plot
I see no reason why Gunpowder Treason
Should ever be forgot"

Once upon a time, when there still was an information void and not everyone could be kept under surveillance one man plotted to blow up the British Houses of Parliament. Since then, this "terrorist" has been demonized annually by protestant royalists.

However, in 2006 when the conservative protestants had finished celebrating their victory and total information awareness is finally within reach, the dust was shook of the Guy Fawkes mask and he was instead martyrized in a film by Alan Moore (seriously, download it here, "V for Vendetta" is awesome) as an icon of the true will and action of the man on the street - when he can be Anonymous, that is.

Ok, so as a symbolic action to celebrate this thought I have changed my profile pictures everywhere to the Guy Fawkes mask, and I suggest you do the same, but admittedly, the idea isn't particularly sticky. There are only a reasonably small and non-important things I currently don't feel I can say or do out loud without risking my name, but there are others who are less privileged and in my gut the principle still feels so urgently important. Anonymity is worth protecting, anonymity is for everyone and anonymity is essential for a safe society.

Want to go Anonymous?
PS. I was reminded by a reader that I seem to misuse the word "integrity", because it in Swedish has a use stemming from "personal integrity" which simply doesn't work in English, instead it's "privacy". Thanks for the reminder, I stand corrected.

PPS. Share this with friends as the simpler address tinyurl.com/remember5november

Wednesday, September 24, 2008

The farse of BankID

The Swedish Administrative Development Agency (Verva) released has released a report suggesting to expand the concepts of electronic identification in Sweden. IDG writes how your cellphone will be used for e-identification, how e-identification will look in the future, everyone will have eID within two years and how the BankID company is optimistic about the future. What bull.

"BankID is an incompatible ugly hack the Swedish banks threw together to give Persson something to brag about during the EU-chairmanship"
... I quote from a renowned bank security specialist who must remain unnamed. The Swedish BankID really is terrible technology which attempts to fill the void the national ID-card should have, and could have filled long ago. Polisen writes (my emphasis): "På id-kortet finns ett kontaktchipp som i framtiden kan bli bärare av elektronisk information, så kallade eID-tjänster, som till exempel elektronisk legitimation". ("On the ID-card there is a contact-chip which in the future may be the carrier of electronic information, so called eID-services, for example electronic identification") Not only have they got backward what eID-services are and there is no such thing as a "contact-chip" if we are to be picky about device terms (which I think we should), they seem to not have any infrastructure, technical plan or even room to create a functioning hardware electronic identification.

The BankID-service is bad primarily because it is software carried ("BankID på fil") and because it requires service providers to chip in to the business model in a way which is just unfeasible. I have been told service providers avoid providing more services through BankID because the licensing is so expensive, whereas actually everyone could benefit and save money from using it more. Great success... I just realized that clunky BankID client which never works properly probably does embed standard PKCS#12 certificates (X.509) and keys (RSA) but I have not yet to peek into exactly what they are. The fact remains BankID chose to step beside existing infrastructure for hardware, software and protocols existing in browsers and other clients. Also, unless you're communicating with a BankID licensed organization, the BankID you have been issued is worthless. It may not matter much to most people, but principally it is strange not to be able to verify identity without going through a government.

Oh, and this story about Swedish bureucracy is just hilarious, according to
epractice.eu: March 2008 - "Due to the fact that the Swedish Administrative Development Agency (Verva) has no longer been assigned to manage the national eGovernment portal and that no other Government agency was handed this task over, the portal ‘sverige.se’ closes down." Yippie kay-yay...

In contrast, the Estonian ID card implements a regular PKI smart card much like the US DoD CAC. It ties into the OpenID project and anyone can implement services based on it using standard software and the government-provided LDAP directories. Oh and we already have Mobiil-ID using cellphone SIMs (using cellphone to pay for parking is a different but also very elementary thing done in all cities by most car owners for years).

To be fair though, the Estonian ID-card drivers are sometimes also messy to install, non-Estonian language support is failing in some points, the cards are pretty expensive to issue and since two cards have failed for me (I used to sit on my wallet) I've had to experience the failing support organization behind it. Probably Estonia can be said to have benefited from being a small country, not because there are few end-users (above a million is never a small number) but a limited number of market players which are able to cooperate and without too much involvement of Statskontoret framework agreements to stand in the way of pushing sensible technology.

My eToken PRO All this is of course pretty complex things and it cannot be expected of the layman to distinguish what is good or bad technology. Myself I've gotten a proper eToken PRO through Danish it2trust on which my keys are stored, to be able to encrypt, sign and authenticate while knowing that the key can practically (as far as I know) never be stolen unless the physical token is stolen. That feels really good, and even if I don't have that sensitive information myself, at least I know how to do it, and what software is capable or not to do these things properly.

Actually I recently found myself in a war-of-blogs regarding inferior banking security where the pretty large Swedish blogger "TKJ" spreads some confusion on what is the real problem and the cause for credit card frauds persisting. I'd like to say that I don't mind TKJ contributing to the discussion, on the contrary, and he's generously complimented the expert critique he's received. In my opinion also security experts should dare to step up and discuss these things openly, or media and consumers surely won't know where to push the market. So my $0.02 are that the reason swedes are still getting skimmed is the emberassing fact that Swedish banks and payment systems still use primarily copiable magnetic strips instead of the more secure "for electronic use only" smartcards. In the competition between nations for using the greatest technology, this is one area where Sweden is definitely suffering from having to carry it's legacy and being stuck with old solutions.

Tuesday, September 23, 2008

Buy bye privacy - I have joined facebook

So finally I have given in, I have joined facebook. One friend too many mentioned collaborating through a facebook app, and considering my revised view of integrity I have finally decided to give in and join this borg. Because, on today's internet, everyone know's you're a dog and you might as well be somewhat in control of it:

My name is Carl-Johan Sveningsson, I was born in Gnosjö, Sweden on the 25th of January 1981, my email address currently is cj.sveningsson(a)gmail.com, my S/MIME fingerprint is D1:50:3A:C3:76:FD:37:95:58:4D:A4:F1:A9:1E:D4:F9:49:0C:8C:95 and my OpenID is http://cjsveningsson.myopenid.com . This is me

On the other hand, I have a fascination with sousveillance and neoism pseudonyms, have just tried out FiSH IRC encryption (bulky and works so-so), I discuss encryption with #basvrak @ EFnet and have just signed up to FRApedia.se. So I think I'll be fine anyway... I hope.

Wednesday, June 25, 2008

My public keys

It's a bit silly with all the FRA-debate, but I figured I should anyway publish my public keys / certificate properly. Do note that the corresponding private keys are just kept encrypted with passphrases on my disks, thus not as reliable as if kept in some security tokens (I will however get some soon).

My X.509 / S/MIME certificate:

$ openssl x509 -in mail.der -fingerprint
SHA1 Fingerprint=D1:50:3A:C3:76:FD:37:95:58:4D:A4:F1:A9:1E:D4:F9:49:0C:8C:95
-----BEGIN CERTIFICATE-----
MIIC6jCCAlOgAwIBAgIQfieZBy5u6tREnLuiykK/mDANBgkqhkiG9w0BAQUFADBi
MQswCQYDVQQGEwJaQTElMCMGA1UEChMcVGhhd3RlIENvbnN1bHRpbmcgKFB0eSkg
THRkLjEsMCoGA1UEAxMjVGhhd3RlIFBlcnNvbmFsIEZyZWVtYWlsIElzc3Vpbmcg
Q0EwHhcNMDgwNzMxMTMzNDU3WhcNMDkwNzMxMTMzNDU3WjBKMR8wHQYDVQQDExZU
aGF3dGUgRnJlZW1haWwgTWVtYmVyMScwJQYJKoZIhvcNAQkBFhhjai5zdmVuaW5n
c3NvbkBnbWFpbC5jb20wggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDx
VgamRU9zL7ugY+2u/LHg4JyjLJhqUqvQmpwp4zHDSW4tjAOBmn2wRmF/53/LKqWu
w2nfvHig888V+uIa8+xVFgS1AyJ6xX3jqWQ0OD7GzjCAglV2auZ7cYNd3uMO9/yg
AdyxwwKHZnTSYhlBdL85En2RKbjGHimVlZag569pkxeA3dY6Tea7n79bmRuGzlSQ
C6CdZOcbbr7SWih6a35tfxxvDBQDjPQKZs1o6ois8AhdwwwepmiTT6Fsn9S8fje9
0UuFol7nEIswbK7lE+44W375iuxk1bXJep6VzWhB8kLWPB9DRMfjFcNuzABziRkH
Ei5GeKDfRc+IAEHbfmMZAgMBAAGjNTAzMCMGA1UdEQQcMBqBGGNqLnN2ZW5pbmdz
c29uQGdtYWlsLmNvbTAMBgNVHRMBAf8EAjAAMA0GCSqGSIb3DQEBBQUAA4GBAAiG
70aW9v7pZEpYnUCABuodVaxJO29L2SLb0EFe+jhVaOJ/09i0d/hYRk+4AFDrLEXZ
a63RHDZ/quOYSHaDSsidpX35yRNtT4FSxhm4SsbZiUZfjZAMNxpnsqkooWiz+goU
ABIWtzdtjilKbVrc9WfAQsYJElTN3Qvo7T3h17IO
-----END CERTIFICATE-----

My PGP / GnuPG public key:
Key fingerprint = 0349 0021 407D 9955 A3B5 FC18 1294 5939 1766 8EFA
-----BEGIN PGP PUBLIC KEY BLOCK-----
Version: GnuPG v1.4.8 (Darwin)

mQGiBEWaw0cRBACZNwcwZDZgcYR3OepOH9rSlA/p2WwO/5SrczkQ10/J/+ASLMyp
991d628qNLqlJ1nUnjRFw7GgVxHhYgVCDabhaC9JZru3GTBDXvKet+3rxZZf+isd
328H3o41cFsYwmJRERP+YuiG+QXIljb6z2suei8+QNhy5bmRyyqb+nn64wCgswwL
Ud9cOKTI6T9LFg3Xch+IQc8D/1BW3qO0RdMhis+i53ma7VYU2h0HiVJM91mJrUlE
CrL6dn0DI91H6rqakfAgESCDNjxKqHk/KnGq8Epzgyg0vmBedddsZMoNe/fewwv4
OQizJwQi2k8e9gDPsb66VsGZ1VH9uHuryeaO0P4ePkdH5zRjVJb+T4ggwexEiiXZ
jWd3A/9477im8lWwYZGxXn+RzDg0q7GmZuKRH0SEezWKVJFSdyXDXh4EagF/n1nR
tP9J3SUtd6RMNIRVIgBae9cbbohfsPCJdfVsoH2EjbUwv7fYCN6IEQioi2e7DhZs
RgHu6TuSckXKUuwHDauEv3YGkmfq4S5nF3gmuEv1t67/5Iijs7RDQ2FybC1Kb2hh
biBTdmVuaW5nc3NvbiAocHJpdmF0ZSBhZGRyZXNzKSA8Y2ouc3ZlbmluZ3Nzb25A
Z21haWwuY29tPohkBBMRAgAkBQJFmsNHAhsDBQkB4TOABgsJCAcDAgMVAgMDFgIB
Ah4BAheAAAoJEBKUWTkXZo76vKcAoLJQHSM+G7I9SvuI1k9aPyEJpIZGAJ4iZP61
7WpugcGNLbVegR4t3RyR2YhMBBARAgAMBQJFm2UyBYMB4JGVAAoJEAlZ96CtMp7r
Qn4An3usN/tF2oChzypGv1w542wcjGUTAJ0S1Tlj1UjGWR6B+iXU6SSJpxI80Yhk
BBMRAgAkBQJFmsNHAhsDBQkB4TOABgsJCAcDAgMVAgMDFgIBAh4BAheAAAoJEBKU
WTkXZo76vKcAoI1ePQCJsdPIzSzN461LpXD7a++KAJ0eVpZEzB9npMtttReCGfXR
11j3gIhkBBMRAgAkAhsDBgsJCAcDAgMVAgMDFgIBAh4BAheABQJIYqL8BQkEqRM1
AAoJEBKUWTkXZo76dq8AoIkB2Xb+VPA3KyajMZEMRz2KD0qvAKCfRBoJXkaWjXI8
cbdH1kNfvzgWhYhMBBIRAgAMBQJIYqaDBYMB4S/5AAoJECcNz56eI7s4JSQAoLYW
4pvRmjBJenX8ft1Zh8kAmHOpAJ4sAQCQ9j6naPGLvO97M/tGDhynN7kCDQRFmsO/
EAgA9Z3mkxvWXPPAnY2vg55+KW4ZEd4zdIxXocfYHn0i9nHg256GU805uSH8KD16
jAdkUEkWDX5m1xQqR6Wr3Lfax/CPnXSBoRWT8oXnTG7Uqv0uPyADNayJk62zHYFh
x1FZjNAfnwGGAScGb9m/YQ5i9vN0rN5NYVilk5nyJi/pIAmFhR+ttYm3bj0atdoF
sgU15Z1jQOwMwO6qBncPkws1r548sftPMYf+58nZiDKmeVlFkDAiLB8TM43mr7lb
ZEqysq+WoiN0+DnqahqZIi3noAHeZPDQlD4fAgeMDl7bcdM0EspG4L3Fz8Hf9PWD
vyViVdGYcfe7W+ym5MN6cPu1cwADBgf9FpHXSuD12KJ3IkLj5dg3Mbx+ySaQDdmA
BIw59W3RGyab+bYbCs0alRoCIe9ZI36V+mSzkQV4Slkm6gn0DXtRLI0UBW7qPiNq
4miw3iQzeSpwP06ZcX4Z3NUxuBQOx/q4Xtwsb8qVfy/Qvi8y0vzNhXQ8RuR6hGh3
Z/GWJYMcJFPB+5MLJ/0dUkI6AP+B4RF4RYZuq8A7lAmUVEldKES8t+8apJZLBDoQ
nh11sUbjqJaVQroTjZO22oK0RZaoro2Y8DAeF+WiF93Ts7bDgHgJjoJP9Iz1o4iA
PXHEB7Nv6EvtrdWMiguGxT7NiXAx1V1qte/bd9bcyzBvkVHNSNmICYhPBBgRAgAP
BQJFmsO/AhsMBQkB4TOAAAoJEBKUWTkXZo76f6MAn037bNsQ+KxAUMKgj7iBAbkN
ZZTQAKCh2cufVEPN2sC4SoSznlwLeDkFzw==
=uo2X
-----END PGP PUBLIC KEY BLOCK-----

Since I got OneSwarm, my friends may go ahead and add me:
MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCFhFi8f
wtqFA1mf3LbIrVvhj2Z15hzVM0R5BWZtUhO852salZc0g
xI9vHIvD+2AInT01HcIvDTkJlQ2vebomJOhO69NqkJhHG
rVfpWYZAQLYCrM19lmu4cFAM4+uakI0sSeNh0iuzISQBS
VL2e5Al8vNTIoTfAXEnD4q+VJX/7uQIDAQAB
(Update: I had some issues with that the GnuPG key was expired, so I had to update that and get it onto a keyserver. The fingerprint is unchanged, and I will probably get myself Aladdin eToken PRO or an AET CrypToken any day now)

(Update 2: Now I have managed to securely generate and store on an Aladdin eToken PRO my X.509 / S/MIME certificate, so that's a new one now)

(Update 3: I got OneSwarm, so I added my public keys here as well)

(Update 4: I changed laptop and the server is offline currently, so changed one OneSwarm keys)