
Everest: the highest mountain, but not the furthest you can get from the Earth’s centre. CC-licensed photo by Jerome Bon on Flickr.
You can sign up to receive each day’s Start Up post by email. You’ll need to click a confirmation link, so no spam.
A selection of 14 links for you. Neither inflammable nor flammable. I’m @charlesarthur on Twitter. Observations and links welcome.
Everything on Amazon is Amazon! • The New York Times
»
There are vanishingly few types of consumer goods that you can’t buy, in some form, on Amazon. But it is missing plenty of brands. In 2009, the company started selling products under its own name. It soon moved beyond the first AmazonBasics — items including budget electronics and batteries — to a wider range of Amazon-branded products. This was followed by an explosion of company-owned brands, including dozens with Amazon-free names.
Lark & Ro sells women’s wear, Buttoned Down sells men’s dress shirts; Pike Street sells linens; Strathwood sells furniture. These brands are intended to stand on their own, sort of. They are associated with Amazon, and listed on the site’s dozens of different contexts as “Our Brand” or “by Amazon” or “An Amazon Brand.” (Some new brands are undercover but then blow their cover, as in “Amazon Brand – Solimo Pasta, Thin Spaghetti, 16oz.”)
A lot of these brands — most explicitly the Basics products and various household staples — appear to be straightforward margin plays. Others, clothing brands in particular, fill gaps left by companies that have steered clear of the platform altogether. Others, well, who’s to say?
«
What is the highest point on Earth as measured from Earth’s center? • NOAA
»
Mount Everest, located in Nepal and Tibet, is usually said to be the highest mountain on Earth. Reaching 29,029 feet at its summit, Everest is indeed the highest point above global mean sea level—the average level for the ocean surface from which elevations are measured. But the summit of Mt. Everest is not the farthest point from Earth’s center.
«
You’ll have to read on to find out. You’ve probably never heard of the mountain whose summit is the one. Remembering that the Earth is an oblate spheroid. And no, it’s not Kilimanjaro.
link to this extract
A leaky database of SMS text messages exposed password resets and two-factor codes • TechCrunch
»
A security lapse has exposed a massive database containing tens of millions of text messages, including password reset links, two-factor codes, shipping notifications and more.
The exposed server belongs to Voxox (formerly Telcentris), a San Diego, Calif.-based communications company. The server wasn’t protected with a password, allowing anyone who knew where to look to peek in and snoop on a near-real-time stream of text messages.
For Sébastien Kaul, a Berlin-based security researcher, it didn’t take long to find.
Although Kaul found the exposed server on Shodan, a search engine for publicly available devices and databases, it was also attached to to one of Voxox’s own subdomains. Worse, the database — running on Amazon’s Elasticsearch — was configured with a Kibana front-end, making the data within easily readable, browsable and searchable for names, cell numbers and the contents of the text messages themselves.
«
Everyone gets hacked. Sometimes, they just do it to themselves.
link to this extract
Facebook, Google, Amazon, and the collapse of the tech mythology • The Atlantic
»
Where does this almost unbelievably bad news cycle end for these companies? And what if the news stays bad, but the people using their products can’t extract themselves from the platforms tech has built?
A historical analog for this fall from grace does exist. There was a time when Americans loved and talked about the transcontinental railroads the way we loved and talked about the internet. The steel lines spanning the nation were, as the Stanford historian Richard White put it, “the epitome of modernity.” “[Americans] were in love with railroads because railroads defined the age. The claims made for railroads by men who wrote about them were always extravagant,” White wrote in Railroaded: The Transcontinentals and the Making of Modern America. “The kind of hyperbole recently lavished on the Internet was once the mark of railroad talk.”
Then the public turned on the transcontinental railroads. “The innovations entrepreneurs brought to the railroads—financial mechanisms, pricing innovations, and political techniques—were as harmful to the public, to the republic, and even to the corporation as they were profitable to many of the innovators,” White continued.
The railroads became some of the most despised institutions in the country and a core reason why monopoly became such a terrible word. When the railroad mythology collapsed, it helped create an entire political ideology: the progressivism of the late 19th and early 20th centuries.
«
SEC settles enforcement actions over two initial coin offerings – WSJ
»
both settlements require the companies to file audited financial statements and other disclosures about their businesses, providing the information that investors typically need to decide if a stock is a good investment.
Paragon and CarrierEQ, which conducted unregistered coin offerings, each agreed to pay $250,000 in civil penalties and to notify investors they are eligible for refunds if they still own the token or can show they sold it at a loss. Paragon sold to 8,300 investors, while CarrierEQ’s coin offering reached 2,500 buyers, the SEC said.
Paragon, founded by Russian internet entrepreneur Egor Lavrov and former model Jessica VerSteeg, staged a widely noticed coin sale in August 2017 that raised about $12 million, according to the SEC. The company said it would fuse blockchain, the technology underpinning virtual currencies, with the marijuana industry.
The startup launched at a time when many initial coin offerings used athletes and other celebrities to generate buzz. Paragon enlisted The Game, a rapper, to tout its coin. The company said it could control the supply of its token in order to stabilize or raise its price, the SEC said in a settlement order.
Paragon was one of hundreds of coin issuers identified by The Wall Street Journal in May as displaying signs of possible fraud. The Journal’s analysis reviewed the companies’ marketing documents and identified red flags such as plagiarized language, promises of guaranteed returns and missing or fake executive teams.
«
First two of scores. The ICO joyride is over.
link to this extract
‘Nothing on this page is real’: How lies become truth in online America – The Washington Post
»
The only light in the house came from the glow of three computer monitors, and Christopher Blair, 46, sat down at a keyboard and started to type. His wife had left for work and his children were on their way to school, but waiting online was his other community, an unreality where nothing was exactly as it seemed. He logged onto his website and began to invent his first news story of the day.
“BREAKING,” he wrote, pecking out each letter with his index fingers as he considered the possibilities. Maybe he would announce that Hillary Clinton had died during a secret overseas mission to smuggle more refugees into America. Maybe he would award President Trump the Nobel Peace Prize for his courage in denying climate change.
A new message popped onto Blair’s screen from a friend who helped with his website. “What viral insanity should we spread this morning?” the friend asked.
“The more extreme we become, the more people believe it,” Blair replied.
He had launched his new website on Facebook during the 2016 presidential campaign as a practical joke among friends — a political satire site started by Blair and a few other liberal bloggers who wanted to make fun of what they considered to be extremist ideas spreading throughout the far right. In the last two years on his page, America’s Last Line of Defense, Blair had made up stories about California instituting sharia, former president Bill Clinton becoming a serial killer, undocumented immigrants defacing Mount Rushmore, and former president Barack Obama dodging the Vietnam draft when he was 9. “Share if you’re outraged!” his posts often read, and thousands of people on Facebook had clicked “like” and then “share,” most of whom did not recognize his posts as satire. Instead, Blair’s page had become one of the most popular on Facebook among Trump-supporting conservatives over 55.
«
Blair is himself astonished by peoples’ credulousness. He’s a Democrat, and earning thousands per month from it.
And then Saslow finds someone who does believe it. And then it all rolls around.
link to this extract
The wartime spies who used knitting as an espionage tool • Atlas Obscura
»
During World War 1, A grandmother in Belgium knitted at her window, watching the passing trains. As one train chugged by, she made a bumpy stitch in the fabric with her two needles. Another passed, and she dropped a stitch from the fabric, making an intentional hole. Later, she would risk her life by handing the fabric to a soldier—a fellow spy in the Belgian resistance, working to defeat the occupying German force.
Whether women knitted codes into fabric or used stereotypes of knitting women as a cover, there’s a history between knitting and espionage. “Spies have been known to work code messages into knitting, embroidery, hooked rugs, etc,” according to the 1942 book A Guide to Codes and Signals. During wartime, where there were knitters, there were often spies; a pair of eyes, watching between the click of two needles.
When knitters used knitting to encode messages, the message was a form of steganography, a way to hide a message physically (which includes, for example, hiding morse code somewhere on a postcard, or digitally disguising one image within another). If the message must be low-tech, knitting is great for this; every knitted garment is made of different combinations of just two stitches: a knit stitch, which is smooth and looks like a “v”, and a purl stitch, which looks like a horizontal line or a little bump. By making a specific combination of knits and purls in a predetermined pattern, spies could pass on a custom piece of fabric and read the secret message, buried in the innocent warmth of a scarf or hat.
«
And lots more examples; you can see why a male-oriented armed forces would completely overlook such communication. (Via Graham Cluley.)
link to this extract
Apple’s new map: has Apple closed the gap with Google’s map? • Justin O’Beirne
O’Beirne does periodic, incredibly detailed (and fascinating) updates comparing Apple’s maps with Google’s. This is no exception, looking at the space where Apple has introduced new maps in California, which turns out to have some gotchas in tiny towns:
»
It’s surprising that Apple mislabels the general store because TechCrunch said that Apple’s vans were capturing addresses and points of interest along the roads:
“After the downstream data has been cleaned up of license plates and faces, it gets run through a bunch of computer vision programming to pull out addresses, street signs and other points of interest.”
But what’s even stranger is that “Markleeville General Store” is written on both the front and the side of the building—and according to TechCrunch:
“The computer vision system Apple is using can absolutely recognize storefronts and business names.”
Yet the businesses that Apple is missing—but that Google has—all have signs along the road.
This suggests that Apple isn’t algorithmically extracting businesses and other places out of the imagery its vans are collecting.
Instead, all of the businesses shown on Apple’s Markleeville map seem to be coming from Yelp, Apple’s primary place data provider…
«
It seems that while Google uses algorithms on visual data, Apple is using a lot of low-cost humans. Both have their advantages.
link to this extract
It’s easy to fact check Trump’s lies: he tells the same ones all the time • Washington Post
Daniel Dale is the Toronto Star’s correspondent in Washington, and fact-checks Trump all the time:
»
Even the best of Trump’s interviewers seldom challenge him when he lies to their faces — despite the fact that almost all of the lies have been fact-checked before.
Trump regularly makes 20 to 30 false claims in his rally speeches. But if you watched a network news segment, read an Associated Press article or glanced at the front page of the newspaper in the city that hosted him, you’d typically have no idea that he was so wholly inaccurate.
If a car salesman told you 36 untrue things in 75 minutes, that would probably be the first thing you told your friends about your trip to the dealership. It should have been the first thing we all told our readers about Trump’s August rally in Wilkes-Barre, Pa.
This issue is so urgent because Trump is getting worse and worse. In 2017, he averaged three false claims per day. In 2018, it is about nine per day. In the month leading up to the midterms: a staggering 26 per day. By my count, he’s now at 3,749 false claims since his inauguration. The Post, which tracks both false and misleading claims, has tallied up to 6,420.
Meanwhile, the press continues to blast out the lies unnoted. Two weeks ago, Axios and the AP uncritically tweeted his nonsense about the United States being the only nation to grant birthright citizenship. (They updated after they were criticized.) It happened again Monday, when Trump earned credulous tweets and headlines from ABC, NBC and others for his groundless assertion about “massively infected” ballots in Florida.
There’s nothing especially strategic about much of Trump’s lying; he does it because that is what he has always done. But the president also knows the lies will be broadcast unfiltered to tens of millions of people — by some of the very outlets he disparages as “fake news.”
«
As he says, it’s important that people know *on what topics* Trump is being misleading – though it generally boils down to “all of them”.
link to this extract
Trump’s Iran oil export sanctions aren’t living up to the hype • Bloomberg
»
These were billed as the “strongest sanctions in history,” intended to prevent the Persian Gulf country from exporting any oil at all. But the reality hasn’t quite lived up to the hype: In the six months before they fully took effect, the impact of the Trump sanctions looks remarkably similar to those of his predecessor in 2012.
With the November deadline looming, it became clear that buyers which agreed to reduce their purchases of Iranian oil might be able secure waivers from the sanctions. Back in August, Trump’s national security adviser, John Bolton, said these would be “few and far between.” This week, it emerged that the US has agreed to let eight countries keep buying Iranian oil.
Details of the deal are sketchy, although Secretary of State Michael Pompeo has promised they will be revealed on Monday. The eight include China and India, the biggest buyers of Iran’s oil, as well as other key U.S. allies in Asia, Japan and South Korea. Turkey will also be permitted to continue buying, but the softening doesn’t extend to Europe. It isn’t yet clear how frequently the waivers will need to be re-validated, or by how much buyers will need to reduce their purchases to avoid penalties.
«
If China can still buy Iranian oil, the “sanctions” aren’t really going to hurt it much.
link to this extract
Never mind the iPad — where are the full-time Android tablet users? • Medium
I wrote a thing over at Medium:
»
It is absolutely true that Android-powered tablets sell in greater numbers than iPads. You can see that in this graph, sourced from IDC and Strategy Analytics (IDC for the total tablet numbers, Strategy Analytics for the Windows tablet figures):
If you go strictly on the number of tablets sold, then Androids have sold plenty more than iPads or Windows tablets (same sources as before):
They also tend to be cheaper than iPads (though that’s not necessarily true since Apple cut the price on the entry-level iPad earlier this year).
So given all that, here’s my question: why aren’t we talking about full-time Android tablet users, rather than discussing whether the iPad Pro can replace/supplant your laptop? After all, Android tablets have pretty much the same apps as iOS, and you can even access a file system if you want.
«
I also asked the folks over at Android Police for their input – which is in the piece too. It’s quite surprising.
link to this extract
Facebook and the age of manipulation • New Yorker
»
The most disturbing revelation is that Facebook employed Definers Public Affairs, a conservative Washington-based consultant, to promote negative stories about Facebook’s competitors by pushing them on the NTK Network, which calls itself “a unique news website that brings together data points from all platforms to tell the whole story.” NTK is not, in fact, a news Web site; it shares offices and staff with Definers. As the Times reported, “Many NTK Network stories are written by staff members at Definers or America Rising, the company’s political opposition-research arm, to attack their clients’ enemies. While the NTK Network does not have a large audience of its own, its content is frequently picked up by popular conservative outlets, including Breitbart.” In other words, Facebook employed a political P.R. firm that circulated exactly the kind of pseudo-news that Facebook has, in its announcements, sought to prevent from eroding Americans’ confidence in fact versus fiction.
On another front, Definers also sought to discredit Freedom from Facebook, a nonprofit opposition group, by encouraging reporters to write about its ties to George Soros, the liberal financier who is a subject of obsessive, often conspiratorial attention in conservative circles. On Thursday, Sarah Miller, a spokesperson for Freedom from Facebook, told me, “Congress and the Federal Trade Commission should come to terms with the fact that Facebook will never change, unless they force it to—and they should, without delay, to protect our democracy.” (On Thursday, as the report of the P.R. firm’s activities stirred criticism, Facebook said that it had ended its relationship. The company said that it had not asked the firm to circulate false stories.)
«
Alphabet Verily stops Smart Lens, glucose-measuring contact lens • CNBC
»
Verily, Alphabet’s life sciences arm, has paused work on its so-called “smart lens” program, which was aiming to put tiny sensors on contact lenses to measure blood sugar levels in tears.
If it worked, the lenses could help diabetics track their glucose levels in real time and in less invasive ways than the traditional meters that require piercing the skin. But in a blog post on Friday, Verily said that after four years of research it has determined that detecting blood sugar in tears is a massive — and potentially insurmountable — technical and scientific undertaking.
“Our clinical work on the glucose-sensing lens demonstrated that there was insufficient consistency in our measurements of the correlation between tear glucose and blood glucose concentrations to support the requirements of a medical device,” the company said.
«
This is a project with a long, long heritage going back to 2004 and which has gone from the University of Waterloo to Microsoft Research and on to Google (and hence to Verily). Another big PR scheme bites the dust.
link to this extract
Bitcoin giveaway scams are flourishing on Twitter. They’re probably coming from Russia • Buzzfeed News
»
A BuzzFeed News analysis of the Target and G Suite account hacks suggest the perpetrators may have been the same ones responsible for similar schemes back in March. BuzzFeed News examined the websites touted in the Target and G Suite promoted tweet scams and determined they share a web server that also hosts sites like btc-back.net, elonmusk.gift, and eth-giving.com.
While domain registration information for those scam sites is hidden, other sites hosted the server are registered to Russian names with associated emails, and Russian addresses. A QR posted in one of the tweets was hosted on a Russian domain. The server currently hosts 600 Russian and English-language websites for illegal pharmacies, escort services, and a business that promises to improve the levels of World of Warcraft characters. Many of them appear to be based in Russia.
“The phrasing of the tweet themselves seem to suggest a Russian or Ukrainian language actor,” Kalember said. The researcher has also examined phishing emails sent by scammers to marketing and social media managers, which ultimately help them post from verified accounts like @Target. According to Kalember, those emails also show strong connections to Eastern European actors.
Twitter declined a request for technical details on the promoted scam ads.
«
Errata, corrigenda and ai no corrida: none notified



















/






