Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Thursday, December 31, 2009

You can re-touch, but you can't hide

BoingBoing linked to an awesome two part article (1 - Body by Victoria, 2 - The Secret Is Out) in which a security expert uses digital forensics techniques to reverse engineer what retouching has been done to a photo of a model in a Victoria's Secret catalog. The photo first showed up on the fabulous Photoshop Disasters.


As with anything showing up on the Disasters site, there are some glaring errors, but what makes the above articles great is how the author uses the errors introduced here, along with a bunch of different filters and analysis techniques, to begin tugging at the threads of what the image has been through. When the unraveling is done, he determines that the model's skin has been lightened, teeth and eyes brightened, breasts enlarged, nipple removed, and that the dress featured isn't even the color of that in the original photograph, just to name a few things.

It's an entertaining read, and one that spurred a few thoughts:

First, what in this case was an expert applying a couple principles and a set of photoshop tools, I could easily see being a single, end-user-ready, image analysis tool. "Upload your image here and we'll highlight everything that we beleive has likely been modded".

Secondly, if people start to tear this stuff apart everywhere it appears (witness the BoingBoing Demi Moore kerfuffle), I can't imagine that the industry is going to be able to stay ahead of people's ability to uncover its secrets. It's one thing to find talented photoshop artists. Its another to say "...and are you skilled at making sure your image has consistent JPEG compression artifacting and no discontinuities in alternative color spaces" during interviews. Maybe this kind of 'out'-ing will lead toward a downfall of the fake model/body image in media?

Finally, for all industries, this is a great example of how in the Internet age, there are no secrets, especially if you are a large and prominent company.

In fact, I'd go so far as to say that the only way your secret is safe is if no one cares about it.

Sunday, July 19, 2009

Security in the Cloud

Another good read: The Anatomy of the Twitter Attack. This is the first of a two-part techcrunch post about a recent Twitter hacking, where 300 confidential docs were stolen by a hacker and sent to, among other places, TechCrunch's email inbox. This article outlines how the hacker managed to get in, the next post promises to deconstruct Twitter's reaction to the theft.


The punchline is that (a) businesses increasingly relying on a mix of cloud services for hosting their documents, and that (b) each of these web services has a moderate level of security, but when viewed in aggregate, their security is seriously compromised.

It's a facinating read, in itself, but also makes me wonder what the implications are for online games and game services. If your identity games or game service becomes linked to your identity in other more significant places, will those be back doors to identity theft or other serious crimes. Will those running such games or game services safeguard my account info as well as my online bank? Will they legally be required to? Some say those games are actually banks anyway, so they may need to be.