After many years of inactivity, I’ve decided to do away with Wordpress and at least keep this blog around in static form. I’ve moved this to Hugo, as that seemed like the simplest way to export Wordpress and it seems to work. Of course I’m mainting the URLs (Cool URIs don’t change!). And who knows, maybe this helps to get some inspiration for new content?
In de eerste editie van CyberNieuwtjes.nl stond een stukje over de herkomst van “cyber”. Als HRCX vind ik dat je toch ook een publieke taak hebt om mensen uit te leggen waar “cyber” echt vandaan komt en hoe weinig het betekent. Hieronder mijn ingezonden brief naar CyberNieuwtjes. Geachte heren Bouwman, Schellevis, In uw inaugurele editie van uw nieuwsbrief dd. 27 april 2018 bespreekt u de herkomst…
Finally I’ve found some time to transition my DNSSEC setup to a new algorithm. It took a lot of research, reading and finding the right tools. It appears that still everyone is using automated setups, which means nobody knows what is going on anymore when you’re talking nitty-gritty details on DNSSEC. As an example: there is a lot of discussion of people saying that the KSK/ZSK setup is not…
Het einde van het jaar nadert en dan is het tijd om je te oriënteren op je zorgverzekering. Dat kan je doen door allerlei vergelijkingswebsites en kijken naar vergoedingen en premies. Je kunt kijken naar het salaris van de directeur en wat hij ermee doet. Maar je kunt natuurlijk ook kijken hoe serieus ze hun security en internetstandaarden nemen. Hieronder een klein overzicht van mijn bevindingen…
Dit jaar heb ik plaatsgenomen bij een stembureau in Utrecht met het idee dat ik het analoge proces van harte wil ondersteunen en graag aan anderen wil uitleggen waarom. Het trof, dit jaar werd ook net een stembureau app geïntroduceerd in Utrecht. Hieronder mijn ervaringen daarvan.
On March 3 2016 a paper was published titled “Tagging Banksy: using geographic profiling to investigate a modern art mystery” . The article describes a technique for analysing geospatial aspects of a large data set of artworks to identify the author of the graffiti. The abstract of the article already gives you an idea of where this is heading: More broadly, these results support previous…
By now we can safely say that DNSSEC as a standard is here to stay. It may not be pretty or completely practical , but it is possible to implement it relatively easily . DNSSEC provides a little bit more assurance on the integrity of the DNS query results. This extra assurance does enable some other interesting applications, to increase the integrity of other systems. This is done through the…
Al een tijdje had ik de wens om mijn eigen meter uit te kunnen lezen, zonder afhankelijk te zijn van anderen. Op alle ‘slimme’ meters zit een P1 interface die dat mogelijk maakt. De documentatie die op internet te vinden is, is flink verouderd. De output van de P1 interface is ook wat veranderd, waardoor sommige instellingen niet meer kloppen. Hieronder mijn bevindingen, zodat anderen het ook…
_I’ve written a series of blog posts for the Rathenau Institute on ethical issues in data research. In this article I show that proper anonymisation of data is no easy task. This article is a translation of the Dutch original , and is available under CC-BY . _ Introduction In 2013 Chris Whong discovered that the data of all taxi rides in New York City was available based on the FOIL (the Freedom…
Ik heb als onderzoeker en docent bij de opleiding System and Network Engineering van de Universiteit van Amsterdam een serie blogs geschreven. In deze serie belicht ik in opdracht van het Rathenau Instituut ethische vraagstukken bij data-onderzoeken. In deze bijdrage ga ik dieper in op dataverzameling door smartphone apps. Niet alleen de app zelf maar ook het feit of je telefoon op Android of…
The Internet is a complicated infrastructure, which is taking over our lives. Users should have some understanding of how this works, so that they better understand regulation or commercial impact of (new) measures. Most articles trying to explain the Internet make things very complex, and they don’t need to. There are only two concepts that you need to know to understand networking: layers and…
Ik heb als onderzoeker en docent bij de opleiding System and Network Engineering van de Universiteit van Amsterdam een serie blogs geschreven. In deze serie belicht ik in opdracht van het Rathenau Instituut ethische vraagstukken bij data-onderzoeken. In deze bijdrage beschrijf ik hoe openbare data van een dienst zoals Twitter op meer manieren kan worden hergebruikt dan gebruikers veelal voorzien.…
Ik heb als onderzoeker en docent bij de opleiding System and Network Engineering van de Universiteit van Amsterdam een serie blogs geschreven. In deze serie belicht ik in opdracht van het Rathenau Instituut ethische vraagstukken bij data-onderzoeken. In deze bijdrage beschrijf ik hoe onderzoekers in beveiligingsonderzoek privacy by design toepassen. Ook gepubliceerd op het Data denkers blog . Deze…
Ik schrijf voor het Rathenau Instituut een serie blogs over ethische vraagstukken bij data-onderzoeken. In deze bijdrage beschrijf ik hoe onderzoekers die gebruik maken van data over internetverkeer een zorgvuldige afweging moeten maken tussen het belang van hun onderzoek en privacy van hun gebruikers. Ook gepubliceerd op het Data denkers blog . Deze blogpost is beschikbaar onder CC-BY . In…
Op 3 december 2014 heb ik de uiteindelijke beslissing gekregen op mijn bezwaar. Dit besluit heeft erg lang op zich laten wachten nadat we op 10 september geprobeerd hebben het informeel op te lossen. De gemeente heeft haar besluit nu uitvoerig gedocumenteerd .
Ik schrijf voor het Rathenau Instituut een serie blogs over ethische vraagstukken bij data-onderzoeken. In deze bijdrage laat ik zien hoe er bij samenwerkingen tussen onderzoekers en bedrijven een verschil kan zijn in de ethische standaarden waarmee wordt gewerkt. Ook gepubliceerd op het Data denkers blog . Deze blogpost is beschikbaar onder CC-BY . Introductie Facebook is een bedrijf dat leeft op…
Het begon allemaal met een startknop. Niet veel later was er een dikke vinger. Na een jaar stond ik voor het eerst voor de rechter en uiteindelijk kreeg ik na veel aandringen te horen dat ik niets zou krijgen. Niet omdat het niet mocht, maar omdat er niets te halen viel. Maar daarmee kan ik wel laten zien dat de gemeente geen interesse lijkt te tonen voor de beveiliging van een belangrijke ICT…
_Ik schrijf in opdracht voor het Rathenau Instituut een serie blogs over ethische vraagstukken bij data-onderzoeken. In deze bijdrage laat ik zien dat het goed anonimiseren van open data geen eenvoudige opgave is. Ook gepubliceerd op het Data denkers blog . Deze blogpost is beschikbaar onder CC-BY . _ Introductie In 2013 kwam Chris Whong erachter dat de data van alle taxi-ritten in New York City…
In een eerdere post beschreef ik al andere registers die gebruikt worden door de Jeugdzorg in Utrecht. In deze post beschrijf ik welke gegevens voor de algemene Jeugdgezondheidszorg geregistreerd worden. Hiervan is melding gemaakt bij het CBP ( Jeugdgezondheidszorg, 1075413 ) met als doel: “ Alle kinderen in de stad Utrecht krijgen of pakken (zelf en/of hun ouders/verzorgers) optimale kansen op…
Update 5/9/14: Antwoord van de GG&GD: De RIS & ROTS systemen van de GG&GD hebben geen eigen registratie bij het CBP, omdat die vallen onder de registratie voor de Jeugdgezondheidszorg. Sinds een tijdje hebben we een Elektronisch Kind Dossier Digitaal Dossier Jeugdgezondheidszorg (DD-JGZ). Hier staan ontzettend veel gegevens in, en die worden lang opgeslagen. Dit jaar is de Wet Decentralisatie…
In an earlier post I explained the idea of DNSSEC how to generate keys and sign your DNS zone. In this post I will walk you through the rollover methods as described in RFC 6781 . You should understand the rollover process so that you can securely run your zone. This way you can replace the key in a secure manner when necessary, without service interruptions. In the earlier post I explained that…
Last year has seen some outcries over privacy breaches through NSA spying . We see more problems with pervasive monitoring and privacy through ad networks, Google tracking you, and soon possibly in your own home . This week we have seen that morality on the Internet goes beyond just privacy; there has been an outcry over the morality of Facebook manipulating news feeds for science. We need to look…
At the National Cyber Security Center One Conference last week, Chris van ‘t Hof interviewed me in his TekTok studio. We briefly talked about the Ethical Committee at the University of Amsterdam’s System and Network Engineering master, about Responsible Disclosure and why this is a bad term.
Yesterday I posted a guide to securing your nginx server with some good SSL settings. As I mentioned in that post, I am eager to get rid of RSA entirely, because it is going to be broken at some point in the not so distant future. So I spent part of the day researching the possibility of using Elliptic Curve Cryptography for my site, below are some of my findings.
This week in the Netherlands the news hit again that some secure websites where vulnerable to a downgrade attack. This attack is not new, but for the average user it is hard to detect. You have to be careful that you see the lock when you are entering your credentials. Fortunately, most new web servers and browsers have a setting for it, called HTTPs Strict Transport Security (HSTS) . With that…
TinySSH is a new small SSH server using state-of-the-art encryption using the TweetNaCL cryptographic library. It piqued my interest as it claims to be an easily configured and auditable SSH server with new cryptographic primitives and has no dependency on OpenSSL. Its development target is Debian, but since it has limited dependencies it is not hard to get it to run on other systems. This post…
Met behulp van de Privacy Inzage Machine (PIM) heb ik bij een aantal organisaties aangeschreven. Met de PIM genereer je makkelijk een brief om bedrijven te kunnen vragen wat ze precies over je weten. In principe hebben bedrijven en instanties daar vier weken voor, maar in de praktijk wil dat nog wel eens mislopen. Eind januari heb ik (bijna) willekeurig drie instanties aangeschreven: Holland…
I’ve joined Keybase this week: keybase.io/jeroenh . This is a new service which hosts a directory of public keys together with a verifiable list of usernames.
Some time ago I did some research on the effectiveness of the PirateBay website blockade. I tried to measure this by looking at the intended effect: are there less Dutch people downloading torrents published on ThePirateBay? It turned out that this is very easily measurable, and in this post I am explaining what kind of information you expose when you are downloading a torrent.
I have previously written about DNSSECs “failure” . I tried to draw attention to the absence of simple documentation for implementing DNSSEC properly using simple tools. The steps to implement it are not that difficult, but without proper tools and documentation, nobody is going to find out. My previous post became subject of heated debates, and I have also been invited by NLNetLabs to discuss how…
De overheid heeft op dit moment een internetconsultatie uit staan voor Beleidsvisie gegevensdeling en privacy in het sociaal domein . PrivacyBarometer.nl heeft al een zeer goeie samenvatting van hun reactie gegeven. Mijn eigen reactie staat hieronder. Neem vooral de tijd om je te informeren en te reageren!
Besides having critique on DNS I also try to improve things, both for DNS as well as for the Internet as a whole. Just a few weeks ago I contacted the Dnsmasq community to improve it. The new release is available now for testing and hopefully released soon.
The original specification of DNSSEC is from 1997: RFC 2065 . This means that it is now over 17 years ago since its initial appearance. Sure, it has a turbulent history, and has undergone some big changes. Even the ‘final’ specification ( RFC 4033 ) is over 9 years old. Yet I am going to argue that it has failed.
Cory Doctorow argues that security engineering should be public, like public health: I think there’s a good case to be made for security as an exercise in public health. It sounds weird at first, but the parallels are fascinating and deep and instructive. Last year, when I finished that talk in Seattle, a talk about all the ways that insecure computers put us all at risk, a woman in the audience…
Last week some news about Cryptocat caught my eye, they have just launched a new monitor . This monitor allows you to see usage numbers of Cryptocat in globally in rough areas. Like I did with the WhatsApp alternatives I immediately checked the privacy policy and was surprised with what I found.
Digitalisering is handig, want dat is efficient en zorgt voor besparing, dit is al een tijdje een dogma in de Nederlandse politiek. In de praktijk blijkt dat lang niet altijd zo te zijn, maar dat houdt de politiek niet tegen. Dit zien we aan het weinig populaire Elektronisch Patiënten Dossier, maar ook bij Jeugdgezondheidszorg wordt dit dogma al een tijdje met veel moeite toegepast.
Hackers have been an important part of the Internet since its creation. They are the ones who try to take the technology just over the edge to see what happens. This may mean that things break, or other interesting things happen. Sometimes this means new products are created, new ways of using technology becomes available to users, and sometimes things break. Many hackers feel an obligation to…
How power-hungry are various permutations of Ethernet on modern MacBook Pros? Tests performed and written up by Jeroen van der Ham and Iljitsch van Beijnum . [
In the Netherlands we have a law on net neutrality, and we’re trying to defend this in Europe as well. Our law has been in effect since 2012. About one year after that, ISOC-NL received reports that some providers were breaking net neutrality. This was discussed in the Internet Transparency WG of which I’m also a member. The group worked together with the university of Dhaka to create a mobile app…
This is an addition to my other post about WhatsApp alternatives . There are others that provide more than just messaging. Below is my personal impression about these.
**Update: **Threema support responded: traffic-data is deleted when the message is delivered, or after two weeks, whichever is earlier. The popular WhatsApp messaging service has been bought by Facebook last week. It is reassuring to see that many people are worried about this. It means Facebook can collect and combine even more data about you than they already do. They now have the posts that you…
My name is Jeroen van der Ham, I have always had an interest and concern for digital privacy and open Internet developments. After some recent studies I performed on net neutrality and censorship in the Netherlands, I found myself in ethical dilemmas. This made me realise that it is not just privacy and openness that are our concerns, but that we are currently witnessing the development of ethics…