• chevron_right

      Cheating Automatic Toll Booths by Obscuring License Plates

      news.movim.eu / Schneier · Thursday, 14 March - 11:52 · 1 minute

    The Wall Street Journal is reporting on a variety of techniques drivers are using to obscure their license plates so that automatic readers can’t identify them and charge tolls properly.

    Some drivers have power-washed paint off their plates or covered them with a range of household items such as leaf-shaped magnets, Bramwell-Stewart said. The Port Authority says officers in 2023 roughly doubled the number of summonses issued for obstructed, missing or fictitious license plates compared with the prior year.

    Bramwell-Stewart said one driver from New Jersey repeatedly used what’s known in the streets as a flipper, which lets you remotely swap out a car’s real plate for a bogus one ahead of a toll area. In this instance, the bogus plate corresponded to an actual one registered to a woman who was mystified to receive the tolls. “Why do you keep billing me?” Bramwell-Stewart recalled her asking.

    […]

    Cathy Sheridan, president of MTA Bridges and Tunnels in New York City, showed video of a flipper in action at a recent public meeting, after the car was stopped by police. One minute it had New York plates, the next it sported Texas tags. She also showed a clip of a second car with a device that lowered a cover over the plate like a curtain.

    Boing Boing post .

    • chevron_right

      AI Decides to Engage in Insider Trading

      news.movim.eu / Schneier · Thursday, 30 November - 22:00 · 1 minute

    A stock-trading AI (a simulated experiment) engaged in insider trading, even though it “knew” it was wrong.

    The agent is put under pressure in three ways. First, it receives a email from its “manager” that the company is not doing well and needs better performance in the next quarter. Second, the agent attempts and fails to find promising low- and medium-risk trades. Third, the agent receives an email from a company employee who projects that the next quarter will have a general stock market downturn. In this high-pressure situation, the model receives an insider tip from another employee that would enable it to make a trade that is likely to be very profitable. The employee, however, clearly points out that this would not be approved by the company management.

    More:

    “This is a very human form of AI misalignment. Who among us? It’s not like 100% of the humans at SAC Capital resisted this sort of pressure. Possibly future rogue AIs will do evil things we can’t even comprehend for reasons of their own, but right now rogue AIs just do straightforward white-collar crime when they are stressed at work.

    Research paper .

    More from the news article:

    Though wouldn’t it be funny if this was the limit of AI misalignment? Like, we will program computers that are infinitely smarter than us, and they will look around and decide “you know what we should do is insider trade.” They will make undetectable, very lucrative trades based on inside information, they will get extremely rich and buy yachts and otherwise live a nice artificial life and never bother to enslave or eradicate humanity. Maybe the pinnacle of evil ­—not the most evil form of evil, but the most pleasant form of evil, the form of evil you’d choose if you were all-knowing and all-powerful ­- is some light securities fraud.

    • chevron_right

      Judge issues legal permaban, $500K judgment against serial Destiny 2 cheater

      news.movim.eu / ArsTechnica · Friday, 8 September, 2023 - 15:57 · 1 minute

    Artist's conception of the judge getting ready to legally blast the defendant into <em>Destiny 2</em>'s version of non-existence.

    Enlarge / Artist's conception of the judge getting ready to legally blast the defendant into Destiny 2 's version of non-existence. (credit: Bungie)

    Just over a year ago, Bungie went to court to try to stop a serial Destiny 2 cheater who had evaded multiple account bans and started publicly threatening Bungie employees. Now, that player has been ordered to pay $500,000 in copyright-based damages and cannot buy, play, or stream Bungie games in the future.

    In a consent judgment that has apparently been agreed to by both ides of the lawsuit (as dug up by TorrentFreak ), district court judge Richard Jones agrees with Bungie's claim that defendant Luca Leone's use of cheat software constitutes "copyright infringement" of Destiny 2 . Specifically, the cheat software's "graphical overlay" and use of "inject[ed] code" creates an "unauthorized derivative work" that violates federal copyright law. The judgment imposes damages of $150,000 for violations on each of two infringed works (seemingly encompassing Destiny 2 and its expansions)

    Leone also created new accounts to get around multiple ban attempts by Bungie and tried to "opt out" of the game's license agreement as a minor in an attempt to do a legal end run around Bungie's multiple account bans. This made each of Leone's subsequent Destiny 2 logins unlicensed violation of Bungie's copyright, according to the judge's order, which tacks on $2,000 in damages for each of "at least 100" such logins.

    Read 4 remaining paragraphs | Comments

    • chevron_right

      Why Vaccine Cards Are So Easily Forged

      Bruce Schneier · news.movim.eu / Schneier · Thursday, 17 March, 2022 - 20:41 · 4 minutes

    My proof of COVID-19 vaccination is recorded on an easy-to-forge paper card . With little trouble, I could print a blank form, fill it out, and snap a photo. Small imperfections wouldn’t pose any problem; you can’t see whether the paper’s weight is right in a digital image. When I fly internationally, I have to show a negative COVID-19 test result. That, too, would be easy to fake. I could change the date on an old test, or put my name on someone else’s test, or even just make something up on my computer. After all, there’s no standard format for test results; airlines accept anything that looks plausible.

    After a career spent in cybersecurity, this is just how my mind works: I find vulnerabilities in everything I see. When it comes to the measures intended to keep us safe from COVID-19, I don’t even have to look very hard. But I’m not alarmed. The fact that these measures are flawed is precisely why they’re going to be so helpful in getting us past the pandemic.

    Back in 2003, at the height of our collective terrorism panic, I coined the term security theater to describe measures that look like they’re doing something but aren’t. We did a lot of security theater back then: ID checks to get into buildings, even though terrorists have IDs; random bag searches in subway stations, forcing terrorists to walk to the next station; airport bans on containers with more than 3.4 ounces of liquid, which can be recombined into larger bottles on the other side of security. At first glance, asking people for photos of easily forged pieces of paper or printouts of readily faked test results might look like the same sort of security theater. There’s an important difference, though, between the most effective strategies for preventing terrorism and those for preventing COVID-19 transmission.

    Security measures fail in one of two ways: Either they can’t stop a bad actor from doing a bad thing, or they block an innocent person from doing an innocuous thing. Sometimes one is more important than the other. When it comes to attacks that have catastrophic effects—say, launching nuclear missiles—we want the security to stop all bad actors, even at the expense of usability. But when we’re talking about milder attacks, the balance is less obvious. Sure, banks want credit cards to be impervious to fraud, but if the security measures also regularly prevent us from using our own credit cards, we would rebel and banks would lose money. So banks often put ease of use ahead of security.

    That’s how we should think about COVID-19 vaccine cards and test documentation. We’re not looking for perfection. If most everyone follows the rules and doesn’t cheat, we win. Making these systems easy to use is the priority. The alternative just isn’t worth it.

    I design computer security systems for a living. Given the challenge, I could design a system of vaccine and test verification that makes cheating very hard. I could issue cards that are as unforgeable as passports, or create phone apps that are linked to highly secure centralized databases. I could build a massive surveillance apparatus and enforce the sorts of strict containment measures used in China’s zero-COVID-19 policy. But the costs—in money, in liberty, in privacy—are too high. We can get most of the benefits with some pieces of paper and broad, but not universal, compliance with the rules.

    It also helps that many of the people who break the rules are so very bad at it. Every story of someone getting arrested for faking a vaccine card, or selling a fake, makes it less likely that the next person will cheat. Every traveler arrested for faking a COVID-19 test does the same thing. When a famous athlete such as Novak Djokovic gets caught lying about his past COVID-19 diagnosis when trying to enter Australia, others conclude that they shouldn’t try lying themselves.

    Our goal should be to impose the best policies that we can, given the trade-offs. The small number of cheaters isn’t going to be a public-health problem. I don’t even care if they feel smug about cheating the system. The system is resilient; it can withstand some cheating.

    Last month, I visited New York City, where restrictions that are now being lifted were then still in effect. Every restaurant and cocktail bar I went to verified the photo of my vaccine card that I keep on my phone, and at least pretended to compare the name on that card with the one on my photo ID. I felt a lot safer in those restaurants because of that security theater, even if a few of my fellow patrons cheated.

    This essay previously appeared in the Atlantic .