Two thirds of the way through the talk, they broaden the context to talk about the role of American companies in the war waged against privacy and free speech -- SmartFilter (now an Intel subsidiary, and a company that has a long history of censoring Boing Boing) is providing support for Iran's censorship efforts, for example. They talked about how Blue Coat and Cisco produce tools that aren't just used to censor, but to spy (all censorware also acts as surveillance technology) and how the spying directly leads to murder and rape and torture.
Then, they talked about the relationship between corporate networks and human rights abuses. Iran, China, and Syria, they say, lack the resources to run their own censorship and surveillance R&D projects, and on their own, they don't present enough of a market to prompt Cisco to spend millions to develop such a thing. But when a big company like Boeing decides to pay Cisco millions and millions of dollars to develop censorware to help it spy on its employees, the world's repressive governments get their R&D subsidized, and Cisco gets a product it can sell to them.
They concluded by talking about how Western governments' insistence on "lawful interception" back-doors in network equipment means that all the off-the-shelf network gear is readymade for spying, so, again, the Syrian secret police and the Iranian telcoms spies don't need to order custom technology that lets them spy on their people, because an American law, CALEA, made it mandatory that this technology be included in all the gear sold in the USA.
Here is the video of the talk which Doctorow attended given by Tor technologists:
It is depressing that US politicians pass laws that set up the basis for the spyware and then US corporations do the multi-million dollar R&D to develop the spyware that is then deployed by repressive regimes worldwide (plus the US government and big US corporations). We live in a "big brother" world. Orwell thought he was writing a cautionary tale with his book Nineteen Eighty-Four, but he was documenting the hellish future we now all live in.
The privacy bargain we make with tech companies usually involves giving up some personal data in return for a free service, as with Facebook or many mobile applications.
Doctorow argues it’s hard for people to assign a value to personal data. When the full consequences of giving up that data are still unknown, how do you determine whether the privacy bargain is a fair one?
“It’s hard to get worked up about things where the failure and the deed are separated by a long way,” said Doctorow. “It’s the same reason that people start smoking.”
He insists data-driven companies such as Facebook actively exploit users to solicit as much data as possible. “Facebook trains you to undervalue your privacy. These companies are choca with social scientists now and those people have read their Skinner (an American behaviorist), have read their Adler (founder of the school of the school of individual psychology) and they understand intermittent reinforcement.” In exchange for posting status updates, photos and other information, Facebook users are intermittently rewarded with attention from people they care about. This mechanism can have addictive qualities similar to gambling.
...
Tech companies often do not offer clear or easy privacy choices to users. Facebook constantly changes its privacy settings to push the default towards more public data, and its Byzantine custom privacy settings are bewildering for a new user. “Complexifying a proposition is usually there to stop you from finding out whether the deal is good,” comments Doctorow.
With mobile applications, the choice is often between giving the application all the data it requests or not installing at all.
...
One of the reasons that we undervalue out personal data seems to be that the threat is not visceral and concrete. “In technology we often have this core problem of taking a fairly abstract social harm and rendering it concrete,” concludes Doctorow. “I think science fiction is rubbish at predicting the future, but it can create narratives that become part of our discourse. Imagine it’s 1947 and Orwell hasn’t written 1984 yet, and you’re trying to explain to someone why you don’t want to be electronically surveiled.”
In other words, we are like those naive animals that don't understand that cars kill and wander out on the road at night only to be flattened one day as our past comes back to bite us in the ass.
My complaint about the tech companies is that they require you to contractually sign off of a lot of legal mumbo-jumbo which is (a) long and boring, (b) mostly unintelligible, and (c) puts liabilities on you while ensuring that the service provider has no liabilities. That clause (c) is the real killer because under the legal system it is effect "forever". You could have just given away rights to your first born and not know it. That kind of legal system is insane.
I find it odd that Americans celebrate their "love of liberty" but have been one of the fastest peoples on the face of the earth to give up basic freedoms and personal dignity in the name of "security". It is tragic and laughable.
Elderly woman asked to remove adult diaper during TSA search
Jean Weber of Destin filed a complaint with the Department of Homeland Security after her 95-year-old mother was detained and extensively searched last Saturday while trying to board a plane to fly to Michigan to be with family members during the final stages of her battle with leukemia.
Her mother, who was in a wheelchair, was asked to remove an adult diaper in order to complete a pat-down search.
“It’s something I couldn’t imagine happening on American soil,” Weber said Friday. “Here is my mother, 95 years old, 105 pounds, barely able to stand, and then this.”
Sari Koshetz, a spokeswoman for the Transportation Security Administration in Miami, said she could not comment on specific cases to protect the privacy of those involved.
...
She said her mother was first pulled aside into a glass-partitioned area and patted down. Then she was taken to another room to protect her privacy during a more extensive search, Weber said.
Weber said she sat outside the room during the search.
She said security personnel then came out and told her they would need for her mother to remove her Depends diaper because it was soiled and was impeding their search.
Weber wheeled her mother into a bathroom, removed her diaper and returned. Her mother did not have another clean diaper with her, Weber said.
Weber said she wished there were less invasive search methods for an elderly person who is unable to walk through security gates.
“I don’t understand why they have to put them through that kind of procedure,” she said.
Koshetz said the procedures are the same for everyone to ensure national security.
I always find it hysterically funny with bureaucrats cover their ass with a claim that they can't talk about an issue because "they are concerned about the privacy of those involved". But they weren't concerned enough to not impose this indignity on a dying 95 year old woman. Who are they kidding with their "concern".
By the way, it is the very same government which says that dying 95 year olds must be brutalized for "security" which also decided that an Al Qaeda double agent, Balawi, didn't need any "pat down" when he met with high CIA agents and killed 7 of them with a suicide vest (more in the UK's Guardian newspaper). On the one hand you have American "security" policy degrading a 95 year old dying woman "because of security policy" but you have the leading lights of the "war on terrorism" deciding they didn't need to pat down a known terrorist who they thought they had "turned" against Al Qaeda and were "surprised" when he blew them to kingdom come because of their stupid gullibility. This is madness.
What this shows it that Americans would rather have a police state with all the trappings of "security theatre" rather than have a society in which the dignity and freedom of individuals are upheld.
I find it funny that it is the Republican party that waves the flag most vigorously over "freedom" and "family values" but it was specifically the Republican party under George Bush who threw aside all rights and allow an intrusive police state to grow and swell into its current behemoth state. The US is spending $664 billion on its military and a poorly disclosed amount of spying and intelligence. This is over $2000/person in order to have 95 year old terminally ill women forced to get out of wheelchairs and strip off their adult diaper in public so that a bureaucrat can run his hands over her body to assure "safety" to the American people. What a joke!
A truly "freedom-loving people" does not live on its knees with security goons feeling them up while ordering them around. The American people needs to open its eyes and realize they made a pact with the devil when they bought the "war on terror" sold to them by Bush and continued by Obama. Since there will always be "terror", this is a proscription for eternally living on their knees while mumbling about the "love of liberty".
Update 2011jun27: I don't buy into Rand Paul's crazy right wing politics, but I fully agree with his tongue-lashing of the TSA for their failure to respect the rigths of Americans and their absolutely idiotic "security theatre" pat downs...
Rand Paul asks the right questions about the kind of investigative background and risk assessment that should be done and the need to target the searching to real suspects. It is mind-boggling that Americans put up with the complete destruction of "life, liberty, and the pursuit of happiness" on the part of the TSA bureaucracy. This TSA "testimony" is absolute idiocy.
The right wing Rand Paul politics I don't buy into: turning over security to "private enterprise" is idiotic. There is nothing about a private company that implies that it can be more intelligent in providing security. In fact, there are good arguments that private companies by their very nature, i.e. primary goal is profit-seeking, owners can be world-wide, limited liability means they can walk away if something absolutely reprehensible is done, cannot provide the same kind of honest, diligent security that a government agency can provide. So I don't go for the right wing Kool-aid that Paul is selling. But his points about TSA being brain dead and wasting resources of "security theatre" are right on the mark.
Twenty years ago, when I was writing Accidental Empires, my book about the PC industry, I included near the beginning a little rant about how good engineers were incapable of lying, because their work relied on Terminal A being positive and not negative and if they lied about such things then nothing would ever work. That was before I learned much about data security, where apparently lying is part of the game. Well, based on recent events at RSA, Lockheed Martin, and other places, I think lying should not be part of the game.
Was there a break-in? Was data stolen? Was there an unencrypted database of SecureID seeds and serial numbers? All we can say at best is that we don’t really know. And in some quarters that is supposed to make us feel more secure because it means the bad guys are equally clueless. Except they aren’t, because they broke-in, they stole data, they knew what the data was good for while we — including SecureID customers it seems — are still mainly in the dark.
A lot of this is marketing — a combination of “we are invincible” and “be afraid, be very afraid.” But a lot of it is intended also to keep us locked-in to certain technologies. To this point most data security systems have been proprietary and secret. If an algorithm appears in public it escaped, was stolen, or reverse-engineered. Why should such architectural secrecy even be required if those 1024- or 2048-bit codes really would take a thousand years to crack? Isn’t the encryption, combined with a hard limit on login attempts, good enough?
Good question.
Alas, the answer is “no.” There are several reasons for this but the largest by far is that the U.S. government does not want us to have really secure networks. The government is more interested in snooping in on the rest of the world’s insecure networks. The U.S. consumer can take the occasional security hit, our spy chiefs rationalize, if it means our government can snoop global traffic.
This is National Security, remember, which means ethical and common sense rules are suspended without question.
RSA, Cisco, Microsoft and many other companies have allowed the U.S. government to breach their designs. Don’t blame the companies, though: if they didn’t play along in the U.S. they would go to jail. Build a really good 4096-bit AES key service and watch the Justice Department introduce themselves to you, too.
The feds are so comfortable in this ethically-challenged landscape in large part because they are also the largest single employer… on both sides. One in four U.S. hackers is an FBI informer, according to The Guardian. The FBI and Secret Service have used the threat of prison to create an army of informers among online criminals.
While security dudes tend to speak in terms of black or white hats, it seems to me that nearly all hats are in varying shades of gray.
We’ve created a culture of self-perpetuating paranoia in military-industrial data security by building systems that are deliberately compromised then arguing that draconian measures are required to defend these holes we’ve made ourselves. This helps the unquestioned three-letter agencies maintain political power, doing little or nothing to increase national security, while at the same time compromising personal security for all of us.
The joke is that national governments have the deep pockets to keep their secrets secret. As Cringely points out, having "leaky" security is of benefit only to allow government to spy on individuals (at least the ones not technologically sophisticated enough to protect themselves). Be assured, organized crime and terrorist can afford the necessary level of security (even if Osama Bin Laden appears to have ignored the need of it in his Pakistani-protected hideout).
I was in Los Angeles last Friday for TV meetings and lost my iPhone 4. It was on my belt and suddenly it wasn’t. Then in one of those deja vu experiences I noticed that I was only steps from an Apple Store, so I went inside to trace my iPhone using the Where is my iPhone? app. But my iPhone was nowhere.
Understand it was fully-charged and I had been using it less than 10 minutes before. My phone was nowhere to be found.
Sadly the kids at the Apple Store knew far too well what had happened because they hear the story every day. My phone was most likely stolen straight from its clip on my belt by a professional iPhone 4 thief. The moment it was grabbed from my belt the thief handed it to an accomplice. Within a minute the phone was powered-off and untraceable. They didn’t want my data, just my iPhone.
An iPhone 4 can go for $300 in China. They replace the SIM card, spoof the MAC address or sell it for use on a network that doesn’t care. The street price in L. A. for my phone is $100. An industrious criminal can grab several phones per day.
My friend Bill, hearing my story, said it is even worse in New York where thieves will steal the iPhone 4 right out of your hand, running off into the inevitable crowd of pedestrians. That will teach us not to use our mobile smart phones when, well, mobile.
I have had a hand-held phone continuously since 1993 and while I have broken phones a variety of ways including dropping one in a toilet, this is the first phone I’ve had stolen in 18 years. It’s not that I felt naked without the phone, I felt violated.
So what do you do? Go back to the Apple Store and pay full price ($599) for a replacement iPhone 4 because AT&T didn’t offer insurance and you didn’t think to buy a policy from a third-party provider
Nope. I bought for a quarter that price an iPhone 3GS which nobody wants to steal.
It’s good enough for me.
Combine that with the current fury over the fact that iPhones maintain a file on the phone that lets your every movement be tracked, and you get some major unhappiness with Apple. This feeds my glee at the idea that Apple which has rocketed up with success after success is now due for some major hiccups and product problems.
"By passively logging your location without your permission, Apple have made it possible for anyone from a jealous spouse to a private investigator to get a detailed picture of your movements."
And according to this article at MSNBC, Senator Al Franken has 9 questions for Apple about this secret tracking:
Here's what Sen. Franken wants to know:
Why does Apple collect and compile this location data? Why did Apple choose to initiate tracking this data in its iOS 4 operating system?
Does Apple collect and compile this location data for laptops?
How is this data generated? (GPS, cell tower triangulation, Wi-Fi triangulation, etc.)
How frequently is a user's location recorded? What triggers the creation of a record of someone's location?
How precise is this location data? Can it track the users location to 50m, 100m, etc.?
Why is this data not encrypted? What steps will Apple take to encrypt the data?
Why were Apple consumers never affirmatively informed of the collection and retention of their location data in this manner? Why did Apple not seek affirmative consent before doing so?
Does Apple believe that this conduct is permissible under the terms of its privacy policy?
To whom, if anyone, including Apple, has this data been disclosed? When and why were these disclosures made?
I'm thinking these "problems" will take some of the shine off the Apple, and a lot of people will make decisions like Cringely and buy other products that meet their needs.
The lesson to be learned? If you want to be left alone, unplug from the Internet, do only cash transactions, don't give anybody your name or phone number... wait a second... get rid of that phone! You can successfully keep your info "private". It just requires that you live in a cave in the hills in an "undisclosed location".
In another exchange leaked to Silicon Alley Insider, Zuckerberg explained to a friend that his control of Facebook gave him access to any information he wanted on any Harvard student:
ZUCK: yea so if you ever need info about anyone at harvard ZUCK: just ask ZUCK: i have over 4000 emails, pictures, addresses, sns FRIEND: what!? how’d you manage that one? ZUCK: people just submitted it ZUCK: i don’t know why ZUCK: they “trust me” ZUCK: dumb fucks
To get an insight into the character of the man, read this bit from the article:
Zuckerberg had a knack for creating simple, addictive software. In his first week as a sophomore, he built CourseMatch, a program that enabled users to figure out which classes to take based on the choices of other students. Soon afterward, he came up with Facemash, where users looked at photographs of two people and clicked a button to note who they thought was hotter, a kind of sexual-playoff system. It was quickly shut down by the school’s administration. Afterward, three upperclassmen—an applied-math major from Queens, Divya Narendra, and twins from Greenwich, Connecticut, Cameron and Tyler Winklevoss—approached Zuckerberg for assistance with a site that they had been working on, called Harvard Connection.
Zuckerberg helped Narendra and the Winklevoss twins, but he soon abandoned their project in order to build his own site, which he eventually labelled Facebook. The site was an immediate hit, and, at the end of his sophomore year, Zuckerberg dropped out of Harvard to run it.
As he tells the story, the ideas behind the two social networks were totally different. Their site, he says, emphasized dating, while his emphasized networking. The way the Winklevoss twins tell it, Zuckerberg stole their idea and deliberately kept them from launching their site. Tall, wide-shouldered, and gregarious, the twins were champion rowers who competed in the Beijing Olympics; they recently earned M.B.A.s from Oxford. “He stole the moment, he stole the idea, and he stole the execution,” Cameron told me recently. The dispute has been in court almost since Facebook was launched, six years ago. Facebook eventually reached a settlement, reportedly worth sixty-five million dollars, with the Winklevosses and Narendra, but they are now appealing for more, claiming that Facebook misled them about the value of the stock they would receive.
To prepare for litigation against the Winklevosses and Narendra, Facebook’s legal team searched Zuckerberg’s computer and came across Instant Messages he sent while he was at Harvard. Although the IMs did not offer any evidence to support the claim of theft, according to sources who have seen many of the messages, the IMs portray Zuckerberg as backstabbing, conniving, and insensitive.
Zuckerberg is out to make big money with Facebook and he will do that by boring inside people and exposing everything about them to the commercial market:
For this plan to work optimally, people have to be willing to give up more and more personal information to Facebook and its partners. Perhaps to accelerate the process, in December, 2009, Facebook made changes to its privacy policies. Unless you wrestled with a set of complicated settings, vastly more of your information—possibly including your name, your gender, your photograph, your list of friends—would be made public by default. The following month, Zuckerberg declared that privacy was an evolving “social norm.”
The backlash came swiftly. The American Civil Liberties Union and the Electronic Privacy Information Center cried foul. Users revolted, claiming that Facebook had violated the social compact upon which the company is based. What followed was a tug-of-war about what it means to be a private person with a public identity. In the spring, Zuckerberg announced a simplified version of the privacy settings.
...
Zuckerberg’s critics argue that his interpretation and understanding of transparency and openness are simplistic, if not downright naïve. “If you are twenty-six years old, you’ve been a golden child, you’ve been wealthy all your life, you’ve been privileged all your life, you’ve been successful your whole life, of course you don’t think anybody would ever have anything to hide,” Anil Dash, a blogging pioneer who was the first employee of Six Apart, the maker of Movable Type, said. Danah Boyd, a social-media researcher at Microsoft Research New England, added, “This is a philosophical battle. Zuckerberg thinks the world would be a better place—and more honest, you’ll hear that word over and over again—if people were more open and transparent. My feeling is, it’s not worth the cost for a lot of individuals.”
Update 2010sep18: Here is a preview of the new film about Zuckerberg: