Technology

Tech, Vigilance, and the Title of Liberty: What Captain Moroni Teaches Us About Mass Surveillance

If you read the Book of Mormon through a civic or strategic lens, one figure stands out above the rest when it comes to the intersection of defense, intelligence, and individual liberty: Captain Moroni.

Moroni was an operational genius. He overhauled military defensive structures, pioneered early-warning scout networks, and anticipated threats before they reached city walls. But more than a military leader, Moroni was a fierce guardian of individual agency and civil rights. He famously tore his coat to raise the Title of Liberty, rallying citizens to defend their religion, freedom, peace, and families against internal overreach and external threats.

Which begs a modern question for those of us who care deeply about both public safety and privacy: What would Captain Moroni make of automated license plate readers (ALPRs) like Flock safety cameras?

At first glance, a technologist might argue Moroni would love ALPRs… after all, he built watchtowers and relied on scouts. But a deeper look at his principles reveals a clear, vital distinction between defensive threat monitoring and domestic dragnet surveillance.

1. Tactical Intelligence vs. Mass Surveillance

Moroni was a pioneer in tactical intelligence. He posted scouts along borders, monitored troop movements, and used geographical high ground to protect non-combatants (Alma 43:23–24).

  • The Defensive Mandate: Moroni wouldn’t oppose a local community knowing if a stolen vehicle or a fleeing violent offender crossed a specific threshold. He valued actionable, targeted early warning systems.

  • The Dragnet Problem: There is a fundamental difference between placing a scout on a border wall to watch for an invading army and placing a scout outside every citizen’s home to record when they leave for work, church, or the doctor.

A system that continuously logs, stores, and profiles the legal movements of every law-abiding driver into a centralized, searchable database moves past “scouting” into passive domestic tracking. Moroni’s primary mandate was preserving the agency and rights of the “freemen” a system that assumes guilt until proven innocent through perpetual tracking would trigger his deep suspicion.

2. Raising the Title of Liberty for Transparency

When internal political factions attempted to quietly centralize power and strip away local governance, Moroni didn’t sit back. He made the issue public, clear, and unassailable. He demanded that leaders take explicit oaths to protect the foundational rights of the people.

If Moroni were evaluating modern ALPR networks, he would push for immediate, unyielding transparency:

  • No Secret Deployments: Publicly questioning private-public camera partnerships installed without explicit community consultation or public debate.

  • Binding Guardrails: Insisting that local officials and law enforcement take clear, accountable stands on data ownership, retention periods, and third-party access.

  • Community Vigilance: Encouraging citizens to actively map, audit, and understand the surveillance footprint around them. In Moroni’s view, the people have a duty to keep the watchers accountable.

3. Strict Rules of Engagement and Power Limits

Moroni was famously cautious with power. In his scathing letter to Pahoran, he made his core motivation clear:

“I do not seek for power, but to pull it down. I do not seek for the honor of the world, but for the glory of my God, and the freedom and welfare of my country.”

Alma 60:36

He fought strictly to preserve life and liberty, laying down his command the moment peace was secured. Applied to modern camera networks, Moroni would demand strict technological and legal boundary lines:

  • Zero Dragnet Retention: Erasing location logs of law-abiding citizens immediately, rather than archiving 30 days (or more) of movement patterns “just in case.”

  • Warrant-Backed Access: Requiring specific, localized probable cause rather than open-ended network searches across regional databases.

  • Decentralized Control: Resisting corporate monopolies over public movement data, ensuring control remains local and directly answerable to the neighborhood.

The Takeaway

Captain Moroni wouldn’t advocate for abandoning defense or ignoring technology. Instead, he would recognize ALPR networks as a classic double-edged sword.

While watchtowers have their place on the perimeter, unchecked mass tracking of free citizens presents a direct threat to the very liberty defense is supposed to protect. The lesson Moroni leaves us with is simple: use technology to protect freedom, but never let technology-or the promise of safety-convince you to trade away your agency.

Tech, Vigilance, and the Title of Liberty: What Captain Moroni Teaches Us About Mass Surveillance Read Post »

Two Weeks with Google Fiber

For years I used Spectrum Internet. Off-promotion pricing ran about $80/month for 500 Mbps down and 20 Mbps up, or $100/month for 1 Gbps down and 35 Mbps up. I used my own modem and router, which kept things consistent.

Two weeks ago I switched to Google Fiber. For $100/month I now have the 3 Gbps × 3 Gbps plan. They provided a Google Router and two mesh access points, and right out of the box it was blazing fast, easily more than enough for the average household.

But my household isn’t average. I run a home server for file backups, media, and our blog. While the Google Router works well for general use, it was lacking when it came to port forwarding. To solve that, I purchased a wired router capable of handling the traffic, connected my server directly through it, and then routed the Google hardware through that router. This setup gives my server its own LAN, logically and physically separated from the rest of the network.

On top of that, I configured the Google Fiber router’s Guest Wi-Fi as the network for all IoT devices. Since it can operate on its own VLAN, those devices are also isolated from my personal computers. From a cybersecurity perspective, this is a much more secure and efficient division of traffic.

Now that my advanced setup is in place, I couldn’t be happier. I get the full 3 Gbps on wired connections and the maximum possible speeds on wireless devices. For both everyday users and power users like me, Google Fiber delivers excellent performance and flexibility. Highly recommended.

Two Weeks with Google Fiber Read Post »

Voice and SMS insecure by design

In an era dominated by digital communication, the convenience of voice calls and SMS (Short Message Service) often overshadows their glaring security vulnerabilities. Despite their widespread use, these traditional communication methods were never designed with modern security challenges in mind. As cyber threats and surveillance intensify, the need for secure alternatives like Signal and other encrypted messaging platforms has become increasingly evident.

Why Voice and SMS Are Insecure

  1. Lack of Encryption: SMS messages and standard voice calls operate over protocols that lack end-to-end encryption. This means that your communications can be intercepted and read by third parties, such as hackers, malicious insiders, or even network operators. In contrast, encrypted platforms use advanced protocols to ensure that only the intended recipient can access the content.
  2. Susceptibility to Interception: SMS messages are transmitted in plain text, making them vulnerable to interception via sophisticated tools or techniques like SS7 (Signaling System No. 7) exploitation. SS7, a protocol used by telecom providers to route calls and texts, has well-documented security flaws that attackers can exploit to eavesdrop on calls or intercept text messages.
  3. Reliance on Phone Numbers: Both SMS and voice calls rely on phone numbers, which can easily be spoofed or hijacked. SIM swapping, a common attack, enables fraudsters to take control of a victim’s phone number, granting them access to sensitive information like two-factor authentication (2FA) codes.
  4. Data Retention by Providers: Telecom companies often store records of SMS messages and call metadata, such as timestamps and participants, for extended periods. These records can be accessed by unauthorized entities, whether through hacking, legal demands, or internal misuse.
  5. Incompatibility with Modern Security Practices: Traditional phone systems lack advanced features like forward secrecy, which ensures that past communications remain secure even if encryption keys are compromised in the future. This shortfall leaves voice and SMS communications inherently vulnerable to retrospective attacks.

The Case for Encrypted Messaging

Encrypted messaging platforms, such as Signal, WhatsApp, and Telegram (when using secret chats), offer robust security features designed to protect user communications in the modern digital landscape. Here’s why these platforms are superior:

  1. End-to-End Encryption: With end-to-end encryption, only the sender and recipient can access the communication content. Even the service provider cannot read messages or listen to calls.
  2. Minimized Metadata: Platforms like Signal prioritize user privacy by minimizing the collection of metadata—the data about your communication, such as who you contact and when. This reduces the risk of surveillance and profiling.
  3. Enhanced Authentication: Encrypted messaging apps often provide additional security features, such as safety numbers or QR code verifications, to ensure that you are communicating with the intended recipient and not an imposter.
  4. Resistance to SIM Swapping: These platforms decouple identity from phone numbers by using unique identifiers or alternative authentication methods, reducing the risk of SIM swap attacks.
  5. Open-Source Code: Many secure messaging apps, including Signal, are open source. This transparency allows security experts to audit the code for vulnerabilities, ensuring robust protection against emerging threats.

While voice calls and SMS may seem convenient, their inherent vulnerabilities make them ill-suited for secure communication in today’s threat landscape. By adopting encrypted messaging platforms like Signal, individuals can safeguard their personal information and maintain privacy in an increasingly connected world. Making the switch is not just a step toward better security; it is an essential measure to protect our fundamental right to private communication.

Voice and SMS insecure by design Read Post »

Ban TP-Link or shed a light on all router vulnerabilities?

Recent discussions around a proposal to ban TP-Link routers due to security concerns have ignited debates about the safety of internet-connected devices. While the scrutiny of TP-Link may be warranted, focusing solely on one vendor obscures a larger and more systemic issue: the pervasive vulnerabilities of routers and other connected devices due to inadequate security practices and lack of regular updates.

Understanding the TP-Link Ban Proposal

The proposal to ban TP-Link routers stems from concerns about security flaws that could potentially expose users to cyberattacks. Critics argue that TP-Link devices may be particularly susceptible to exploits due to insufficient firmware updates, weak default settings, or vulnerabilities in design. Such issues can lead to unauthorized access, data theft, or the integration of compromised devices into larger botnet networks used for malicious purposes.

However, TP-Link is not alone in facing such accusations. Numerous vendors across the industry grapple with similar challenges, raising the question: Are we addressing the root of the problem by singling out one company?

A Broader Look at Router Vulnerabilities

Routers are a cornerstone of modern internet infrastructure, yet they are often overlooked when it comes to security. Many routers are:

  1. Shipped with outdated firmware: Devices often come with pre-installed software that may contain vulnerabilities.
  2. Rarely updated by users: Unlike smartphones or computers, routers typically lack automated update systems, and users may not even be aware updates are available.
  3. Configured with weak defaults: Default usernames, passwords, and settings are frequently exploited by attackers.
  4. Unsupported after a few years: Vendors frequently discontinue updates for older models, leaving them open to exploitation.

These issues are compounded by a lack of user awareness and minimal oversight. When these vulnerabilities are exploited, the consequences extend beyond individual users, affecting broader networks and even critical infrastructure.

The Need for Comprehensive Action

Rather than isolating TP-Link as a singular offender, policymakers, industry leaders, and consumers should recognize that the entire ecosystem of internet-connected devices is at risk. Addressing these vulnerabilities requires a multi-pronged approach:

  1. Mandatory Security Standards: Industry bodies should enforce baseline security standards for all internet-connected devices. These should include strong default settings, encrypted communication, and regular security audits.
  2. Automatic Updates: Vendors should implement automatic firmware updates to ensure devices remain secure without requiring user intervention.
  3. Extended Support Commitments: Manufacturers must provide security updates for a minimum number of years after a device’s release, ensuring older devices are not abandoned.
  4. User Education: Consumers should be informed about the importance of regular updates, strong passwords, and proper router configuration.
  5. Incentivizing Secure Design: Governments could provide certifications for vendors that prioritize security in their product design and lifecycle management.

Moving Beyond Reactive Measures

The TP-Link ban proposal is a wake-up call but risks being a band-aid solution if it does not lead to broader systemic changes. As our homes and workplaces become increasingly connected, the security of every device in the network matters. Addressing vulnerabilities at the source, ensuring long-term support, and fostering a culture of proactive security are essential steps toward safeguarding our digital future.

The discussion should not stop at TP-Link. Instead, it should expand to encompass the broader vulnerabilities inherent in internet-connected devices, with collaborative efforts aimed at raising the bar for security across the industry. Only then can we ensure a safer and more resilient digital ecosystem for everyone.

Ban TP-Link or shed a light on all router vulnerabilities? Read Post »