Friday, May 27, 2016

credentials, careers and punctuated equilibrium

life is like a sequence of flights where there's an exciting (and unnerving) takeoff (often preceded by stressful and boring waits) followed by the moment you break through the clouds, and the plane levels off in the light, and coasts. the metaphor seems to fit school, college, job changes, partners, kids, deaths/bereavements in family, etc

so purely from a work perspective, this applies to some research projects i've done.....

most the 1980s, we were building/measuring/optimising the basic internet (both on paper, similation, and real code and networks) - culminated in multicast, tcp congestion control, satellite access (in 1988), which smarter people at the other end of the net wanted to test, so we were happy to be on this end of those tests....

then in the 1990s we were doing multicast - both applications (games, vr, and most interesting, Reuters realtime share trading network), and realtime multimedia (Internet TV - what became the main way AT&T, Telefonica and Virgin/NTL built their TV streaming service; and internet telephony/conferencing-  with video, audio, shared whiteboards - etc - what became skype, webex, etc).

then in the 2000s, we were doing opportunistic networking (community mesh, also) + cloud + social media analytics....how well does a kickstarter campaign work? how do people find or follow unbiased news on twitter etc.

now what? I guess its either data science (inferencing latent variables and models) or internet of things, or both, or neither....

one underpinning theme is decentralization - the early internet was, and cloud was meant to be - so now we're revisiting both the wireless net and the cloud to see if we can make them work better without centralization and loss of privacy. See this talk for why&how

Oh yes, why "punctuated equilibrium"? because basically that's another metaphor for what happens in evolution, applied to ideas - change of environment, leads to specation. selection/crossover leads to new ideas and refinement. next....

Wednesday, May 18, 2016

Every Day Data Science Challenges

1 Guitar Strings

Different strings break at different rates. You can buy them singly or in sets of 6 (occasionally with a spare top E) - really what you want is just in time delivery of a new set wtih a distribution of strings (EBGDAE) that matches the wear/tear rate for you, your guitar (classical, flamenco, acoustic, electric etc) and tone/newnewss you like - this could be crowdsources by instrumenting tuning apps on phones which would notice when you tune from way below (e.g more than a 5th below the right note for that string, probably indicates a new string being put on) -

The statistics could be aggregated, and classes of users found, and then companies (like my fave ) could build orders for you -

2 Bicycle Wheel Spokes

I've lost 4 spokes over the last 5 months cycling in Cambridge - probably, they went on the appalling potholes on station road, or the tree roots across burrel's walk - wouldn't it be nice to know where these occcurred so I could report them to the council (and get money:-)

This could easily be done with accelerometers in smart phones....and GPS - look for rapid up/down movement - then afterwards (when a spoke has gone) you should be able to find the periodic wave of the bike as the wheel is now eliptical....

Thursday, April 07, 2016

Miro's Law


To his excellency, High Admiral, 1st Fleet, Third Arm Galaxy 74434
From Captain Moore, First Contact Team, outer quadrant 2,
planet three, yellow star 17.

Your Excellency,

I am writing to report on the results of the strange mission we have undertaken exploring the deserted planet full of wonders known by its former inhabitants, as far as we can tell, as Silt or perhaps Clay - our translators are working flat out to improve on our understanding as there is so much potentially to be gained from their technology and civilization.

We have uncovered a most exciting cache of documents which may finally explain the departure of the beings who constructed these wonderful buildings and devices. Everywhere we look there are suitable perches on tall polls, connected by long nesting strings. Marching across the countryside between what we believe to be their latrine sites, are long flat landing strips where competition for suitability for breeding stock amongst our warriors would be idea. Enough of the marvels. Back to the documents, which appear to be from a savant, desperate to solve some crisis that has struck their ecosystem....he writes

"I am sending you this letter to ask for your advice. As I travel often to far away lands, and present my work at conferences, I am inevitably showered with gifts, and amongst these is always at least one ball point pen. Since we developed the fishnet" (we're not sure if that is the right term) " I have had almost no use for these gadgets, and have steadily been accumulating them in killing jars" (again, not clear, but it seems that the 'jar' is something to preserve things in at least we can tell that). "Now, I am out of jars, and am unable to store sufficient foods for the winter" (now you see why we are fairly sure of our translation).

"Hence I am writing to all my fellow savants, to ask if they have any idea how we can solve this problem. The number of ball points is growing hyper-exponentially, and threatens the whole of the Fellowship of the Royal Society, and so we realise that we have to reach out to our cousins across the seas for help

I remain yrs, etc etc

p.s. I enclose a pen for your use in response"


Your excellency, there are many responses, but most echo the concern, and dare I say despair at the situation. Finally, however, after much work, it seems that one amongst these giants of intellect proposes a possible solution, for it is the last letter, and in it are many strange symbols which resemble our own formalism for hyperspace drive, and yet appear to arrive at a simpler solution....the letter concludes

"and so we suddenly understood that if we could figure out how to channel the gravity waves just right, the spaghettification phenomenon will allow even the largest of our fellow humans to fit down the inter-dimensional tunnel formed from the tubular casing of the ballpoint through the frames, and into the landscapes that miro draw, it seems from true life, rather than, as critics of the day said, his dreams. the rest can easily be worked out from this sketch...

I leave now, as you know, however, I enclose your last pen, which you will find sufficiently charged to allow you to join us in Blue II should you wish, although as you are of hungarian origin, you may resonate with the richer Mikrokosmos..."

So, your excellency,
It seems that the "humen" of "mud" were finally able to lose enough weight through some fantastic new plan, to soar to other dimensions.....we have yet to complete the proof from the sketch mentioned above, but I hope that we can report to you on this soon,

I remain, as ever, your nest-issue of the fourth degree, captain Moore...

captain etc

p.s. I enclose a pristine unused biro pen for your perusal, and who knows, perhaps use....

Sunday, February 28, 2016

Opening up the Billion Sided Market for our IoT data.

In the HAT project, we came up with the idea for  starting a data exchange for all of us to exploit our data for fun and profit.

There are several important innovations we are bringing to the IoT world:

  • Multi-sided market - we are all now used to the two-sided markets of the smart phone & the cloud - we get apps and services for "free", in reality, trading data about our selves (wishes from searches, preferences from likes,  places from location checkins, etc etc). However, the market is heavily tipped in favour of the large cloud providers, and the user has little knowledge or control over her data, and in particular, very little view of its use and value. The HAT changes all that by providing a hub for each user with storage processing and interfaces for access by other parties, but with visibility, control and above all, valuation for the data.
  • Democratised data - HAT providers store the data and provide access, so we need a marketplace for the valuation - an exchange, where bidders can establish openly a price. This could be at a fine or coarse grain - for example, usage of utilities (power, water etc) typically is interesting for service providers, but typically, aside from billing, fine grain use is only really interesting to the actual consumer in their home or office. Alternatively, monetizing usage information about retail goods could be traded directly with retailers or even wholesalers for discounts, loyalty points, or money, and can include preferences for really accurately targeted advertisements in exchange for further discounts or e-cash. 
  • Freedom - freedom to switch hub, to choose aggregators who have a better deal, or provide stronger service guarantees, is a given  - the large number of HATs is trivially deployed and scaled out in today's cloud based world. This encourages innovation in HAT technology itself. The symmetry of the business relationships allows this dynamic, in contrast to the asymmetric power wielded by the centralised services of the last fifteen years.
  • Silo Busting - the IoT world is notoriously not an Internet of Things, but a hodge podge of many different services, overlayed on the internet and the cloud, but not in any way connected to each other. The HAT changes that by creating a collection of places where data from multiple worlds can be integrated by new applications and new customers from any of the millions of sides of the new market. We are strongly technology agnostic when it comes to IoT at the "lower level" - of course there are good reasons for different systems to work in different ways. We break open the silos by allowing user-centered integration of data. Its about you, so you control it, whatever it is. Cosmetics, entertainment, clothes, energy, well-being, you name it. Think of the value being missed by existing isolated systems when they cannot put 1+1+1 together, but can only see how single values (kilowat hours, litres, meters) increase over time, instead of being able to combine together information with meaning! A space for a million apps for combining your data - more innovation, driven by new value made out of new joins across the seams of the legacy disjointed IoT world.
  • Privacy Protection - We really care about our privacy. The legacy cloud systems today (your social media, web mail, search, travel portal usage) currently do a half baked job on this. When we take far more personal information into the HAT, it is essential we offer much much stronger assurances, applying the very best practice in technology and also written in to the terms & conditions in plain language. If one HAT doesn't get it right, it is easy to move to another. This enables an eco-system with constantly improving, transparent, control over data visibility - once again, another dimension on which to innovate.

Monday, February 15, 2016

Zika App idea

Back in the day, during the H1/N1 epidemic, we did this Flu Phone App to track people's encounters (via phone proximity using say bluetooth (could also use GPS tracking on phone, or even call data records with cell phone company cooperation, if you want less accuracy). The idea was to extract events when people self reported with symptoms, and then (in a privacy preserving manner) extracet the encounters between that individual and others (infected or not) in the population, and then to work out from this various epidemic parameters (susceptibility of different members of population, infectiousness, recovery rate, asymptomatic carriers/herd immunity levels in segments of population, etc etc), as well as possibly nailing elements of the vector....

So with the current Zika virus, it is pretty clear that it is spread by a particular mosquito type (the same as spreads Dengue Fever).

So we could take the app described above (and its reporting infrastructure) and
add one very simple thing - if the phone app turns on the mike, you can tell from sound whether there is one of these little beasties near you- wing sounds have characteristic frequency which is in audio range and sensitivity of human ear and certainly of the (usually better) microphone/audio system on a phone - more info about the Aedis Agypti sound of female mosquito which is the one you care about being not bitten by in terms of Zika.

If there were several people running such an app in the same location, you might even tll roughly where the mosquito was and avoid it (though that's a bit fanciful).

At least, however, you'd be able to look at the incidents of people being co-locaed with mosquitos of the right type, and the infection rate. ANd possibly (over time) look at the spread caused by an uninfected mosquito biting an infected person....thus
mosquito -> person -> mosquito ->person

of course, the same app might possibly also tell you of cases of person->person where there's no mosquito detected...which would also be useful data for epidemiologists

A thought.

Tuesday, February 09, 2016

panic, moi?

So there's this great new report from the Berkman about the worries various governments have that the technology we are starting finally to make use of to protect our privacy may also mean that "bad guys" can get away without being caught.

It is deeply ironic that there's precious little evidence that having untramelled access to everyone's Internet data for the last 20 years has done a single thing to prevent one terrorist death. It is also ironic that when there was access to encrypted data, during WWII, from Station X (Bletchley, breaking the code, the Enigma and its variations etc etc), it was not used to prevent Atlantic shipping from being sunk by U-boats as that would have given away the fact the allies knew where the subs were (i.e. had likely broken all the codes). It was finally "used" to know that the germans did not know about where the D-Day landings were to be. This was to prove useful (although not necessarily decisive) in winning/ending the second world war.

However, note interestingly that spotter planes could often see U-Boats surface, and it was the location of the sub when it sent an encrypted report (aka "meta-data") that let the Turing folks break the code the 2nd time. There's no evidence that the NSA have known about Al Quaeda before 9/11 or that the Spanish, UK and French had any idea about the Madrid, London or Paris terrorists ahead of time. If they did, and didn't say because it would "reveal" their capability, in a post Snowden era, this is just plain stupid, actually criminal. Given several events have happened after Snowden, and there's precious little evidence the bad guys used much more than basic comms (SMS, instant messaging) then, it is evidence that the security apparatus is not fit-for-purpose.

Thus, the report above is right about meta-data (what's sometimes called communications data, as opposed to content, or "control" as opposed to "data").

Interestingly, was talking to some lay folks recently about what the police do if they find someone unconscious (or worse) with no id, but a smart phone, and that smart phone is locked (and, in modern iphone or android, encrypted). So
1/ If you have an ICE ("In Case of Emergency") configured, it can be called from a locked screen on an iPhone, and you can configure android the same if you want.
2/ The phone company can workout what the IMEI and number of the phone is from the location, and from that, could give the police a list of caller and callee IDs so they could try a few til they get someone...plus the account information would likely give name/address/bank info.
3/ If the phone is backed up in the iCloud, its quite likely the back up isn't encrypted

All of this could also be done with someone "of interest" who is perfectly conscious, but unaware:-)

So there. Fire the NSA and GCHQ and get someone in who has a clue.

Monday, January 25, 2016

blockchain for gun control

so distributed ledger technology is a new technology that is all the rage in some government circles. while Bitcoin as the exemplar of the use of the technology for an electronic replacement for cash and credit cards, has its detractors (and they are mostly not wrong), the underlying system allows one to track transaction history associated with a physical object  - one of the UK government's use cases in the report linked above, is the idea of being able to avoid buying "blood diamonds".

so how  about we propose using this for arms control (everything from nukes, to hand guns, and ammo) ? there are ways even without putting "smarts" in the gun (ballistics can often match gun/ammo to each other in any case, and one can move to more careful signatures easily)...

then one could start to look at liability. i.e. people that own weappns would have to take responsibility for a change.

Thursday, January 07, 2016

investigatory ploughsharing bill - srambling for safety

for a thorough report on today's scrambling for safety 2016 debate, its hard to beat George Danezis blog - one thing I was going to ask about was the really broken part of the bill, which prevents any discussion between a service provider and the agency that serves a warrant on them for intercepoton (whether a standard surveillance or a bulk one, or interference on a device or a broad spectrum of devices).

I realize that some level of stealth is, by definition, needed during the surveilance - however the world is rapidly evolving, and it is clear that operators and service providers are at the bleading edge and are able to offer (and do, in practice under today's laws in the UK)  on a request  (e.g. no, you don't want that IP address, you want this URL prefix, as that's a load balancer/VM, NATed device that changes etc etc) - in my example question (no., you don't want to run interference on that device as it isn't just a routine users ipad, its their tesla dashboard, and if you weaken the random number generator in the OS on that device, you open it up to hackers who will crash the car), not only is it obvious the security and police agencies don't have expertise yet in the area, we need to have a cooperatively evolveable law - latching the law (the first in 500 years to admit that agencies need these powers, but under legal controls) we need to make sure it isn't the last law made in the area either - just as the "Internet Connection Record" is meaningless in the world today, so the interference model is extremely dangerous in the IoT space, where there are currently more devices that are not end-users comms gadget (==phone/skype) than are - pretty soon, there will be 100s or 1000s of devices - monitoring these is mostly a waste of resources (more haystacks to not find needles in) - interfering with these devices (e.g. pacemakers, car brakes, traffic lights) is incredibly dangerous - [footnote...]

proportionality requires risk assessment - "collateral damage" that is a death because of interference on a device which causes a car crash or a heart failure, is not assessable today. it may be one day, but I posit that it is not an acceptable risk level for gleaning a little bit more sigint, that probably wont be acted on anyhow. Basically, this blows out of the water any fig leaf of proportionality, unless there is a wholly different way to manage (transparently) the codes of practice, in a way that future proofs (actually makes fit for purpose for today's internet) this dodgy draft bill.

footnote - let not forget algorithmic lawyers - when the music biz wanted to chill the p2p file sharing world, they started getting s.w that generated letters to threaten disconnecting users from their ISP - one fabulous case ended up with a tech guy defending himself in court, because the IP address the lawyers s/w detected allegedly uploading music in breach of copyright from. was his HP laster printer. doh. if they can get that wrong, then the spooks software can and will confuse a crims phone with an innocent ("collateral damage") bystander's  auto-defibrillator or internet enabled insulin pump.

Tuesday, January 05, 2016

Will we ever fix that last s/w (h/w) security vulnerability?

A recent talk bu Johanna Rutkowska sparked a discussion about whether the number of vulnerabilities is potentially infinte, or whether the cost and/or value of exploiting and/or fixing them them is slowly increasing (or decreasing) or (thanks to Markus Kuhn and others) it is cyclic, as phases of technological innovation wash up and down the shores of human society....

so my take - we spend ages in the OS community trying (as
per the talk) to nail down the smallest piece of the trusted tiny
center of the kernel (and talk to the hardware people about it very
closely - even modifying their designs), so that the attack surface is
minimized - including, as you say, improved tools and techniques 9type
safe software fuzzers, verifiers etc etc...

then some skunk works thing from the h/w comes along and changes the
whole game (in terms of complexity to start with, but also in terms of
massively opening up the attack space) _ usually its coz of some
geniuine user demand for something faster/cleverer (as per the talk,
add in GPUs, add in smarer NICs with offloading, add in multicore, add
in more instructions for graphics, even for security itself!)

another example of this can be seen on the net  - since well before
current scandels (back in 1990s) we've been trying to batten down the
hatches everywhere  with DNS, BGP and end-to-end crypto (and now
betterer DNSSEC, better certificate ideas, better router-router
systemic ways to prevent problems, better e2e crypto (c.f. tcpcrypt)
etc

and then some bozo comes along and re-jogs the entire mobile phone net
to be IP based (but with lots of little, devilish little changes)

then some mega-bozo comes and puts a rspi in every thing that has a
moving part, and connects that to the interweb (and builds a new stack
with COAP and IPv6 and lowpan/zigbee so we have no idea what new
sneaky things there are in there)...

then some dolt comes and builds million core data centers and modifies
the entire stack and routing system coz it doesn't scale to their
needs....so we don't know what new corner cases have now appeared on
the masive geodesic (no longer nice shiny smooth, hard  thing)

and we have to start a l l   o v e r   a g a i n
thrice.

It's like you build defences around your big city with walled gardens
and gated communities, and someone comes and builds a massive shanty
town right outside, a favella, which you need, coz, after all, someone
has to come and clean the floors and make your tea and take out the
trash...oops


Sunday, December 20, 2015

Disasters bring out the best and the worst in people


I've been reading about disasters for a few years now.
As a result of friends struggling to let all their families know they were ok in the Tsunami in South East Asia a few years back, we embarked on the Haggle opportunistic networking
project, and more recently, partly fuelled by other problem in society including the current massive movement of refugees from the middle east, we instigated n4d, the networking for development lab, in cambridge, with many partners around the world, and leverage via the Internet Research Task Force's Global Access to the Internet for All (GAIA) activity.

Back at the beginning, I read this fine book about how people behave remarkably altruistically during disasters, that is until the first responders arrive (typically, 72 hours later) -- this made me quite optimistic about our efforts:
A Paradise built in Hell

However, more recently I've read this account of the neo-liberal industrial-military complex way of engaging, which makes for much more depressing prognostication:

Disaster Capitalism

(Contrast Haiti with Cuba just for a moment, but closer to home, the description of private security forces ("we're not mercenaries" and "we're only here for the money" occur multiple times in the same irony-free breath), look at the imposition of austerity on Greece,  where much European refugee money goes to non-greek security firms to run camps for Syrians and others arriving there, before moving on to Germany (the place that needs them for cheap menial labour but imposes restrictions on what the Greek government can do that stop employment for greek nationals picking up again. Grrrrr....

I'm not sure how to regain my optimism (or even sanity) but am tempted to re-target Mao's slogan Combat (Neo-)Liberalism sometime soon. Oddly enough, today someone pointed me at this excellent blog on insurrectionist civics in an age of mistrust which might help

Saturday, November 07, 2015

Review of "The tools and techniques of the adversarial reviewer"

This is my review of the paper
"How to review a paper \\ The tools and Techniques of the adversarial reviewer"
by Graham Cormode.

This paper appeared in the SIGMOD Record in December of 2008, but appears not to have gone through proper peer review. The paper suffers from at least three major problems

Motive  - is it really an interesting problem that reviewers are adversarial? Surely if reviewers colluded with the authors, we'd end up accepting all kinds of rubbish,  swamping our already bursting filing cabinets and cloud storage resources further, and taking cycles away from us just when we could be updating our blog or commenting on someone's Facebook status.
Is the fact that a reviewer doesn't like a paper a problem? Do we know that objective knowledge and reasoning based on the actual facts are the best way to evaluate scholarly work? Has anyone tried random paper selection to see if it is better or worse?

Means - the paper doesn't provide evidence to support its own argument While there is much anecdote, there are no data. The synthetic extracts from fictional reviewers are not evaluated quantitatively - e.g. to see which are more likely to lead to a paper rejection -- for example, it is not even shown that perhaps accepted papers may have more adversarial reviews than rejected papers, which may attract mere "meh" commentary.

Missed Opportunity - the paper could have a great opportunity to publish the names of the allegedly adversarial reviewers together with examples of their adverse reviews, to support the argumentation, and to allow other researchers to see if the results are reproducable, repeatable, and even useful.
For example, multiple programme committees could be constituted in parallel, and equipped with versions of reviewing software that modify reviews to include more or less adversarial comments. The outcomes of PC meetings could generate multiple conference events, and the quality of the different events compared. If particular outcomes can be determined to be superior, then the review process could subsequently be fully automated. It is only a small step from there to improving the automatic authoring of the papers themselves, and then the academic community will be relieved of a whole slew of irksome labour, and can get on with its real job.

Sunday, October 25, 2015

the thing is...

part un ..with the form factor of a hand, the thing can control any legacy actuator - possessed of several simple electromechanical motors, a set of fiber optics in the finger tips, leading back to a camera in the raspberry pi controller at the wrist, and a light, to look at stuff in the dark (extra-sensory perspective), the thing can run around your house and turn stuff on and off - it might be a bit scary (especially if you have several of them, and you see them going up stairs, or hanging off the old thermotat controller or VHS video or microwave) but through online legacy device manuals, these are the new universal remote control  - instead of getting a remote for each device, even devices which have no digital/IR/WiFi/Bluetooth/Zigbee/Audio interface can now be managed via an app on your phone which talks to your family of things...

this is cheaper, more deployable than expensive new tech, more secure (modulo any recurrences of early "hands of orlac" bugs), and can deal with tricky situations (e.g. get spider out of bath, unblock toilet) that most IoT engineers blanche at the thought of (which).

these things can turn your old dial phone into a cellular like device (indeed allow you to dial remotely using your cell phone) can take readings from utility meters and scan, OCR and email them to you, and then let you turn down the heating or turn up the gas as you can afford, without leaving the comfort of your internet cafe.

no cloud needed. no nudges or winks from a psychology/marketing department, just plain old wrist action and common sense.

its true, there may be a re-guard legal fight with the estate of charles addams, but we expect that to be handled easily

part deux - lust as actuators should be made visible agents, sensors too -- every thing that contains a sensor  should have a face - for example, any sensor should show a picture of the people currentlly looking at the output of the sensor - this is the moral equivalent of the facebook "show me as others see me" interface or the statistics on google's search dashboard...

this would give us the inverted panopticon (aka sousveillance) - this is not hard to do - indeed, a similar idea was applied for logging in to public wifi hotspots  where the router has a camera and display which yo ucan use from your laptop in a cafe, to make sure (or at least, improve your confidence that) you are using the real router, not some hacker sitting near by

this is also psychological. so using information flow control, and tracing, one could easily implement this - given the total number of people who should be able to see sensors' output is small, this should actually be scalable too

it could also e a service offered by HATDeX :-)

Friday, October 02, 2015

driverless cars uninsurable?

so some of the push to get autonomous vehicles out there appears to have support from the automotive insurance business.

this seems odd, in the long run for this kind of obvious reason.

driverless cars reduce the risk of accidents. when all vehicles are driverless, the risk (of accident, or "taking&driving away" theft) is zero. so why would you want or need insurance?

of course, there's the other thing - why would _you_ want a car either? the goal will be to maximise the use of  all vehicles so you'll just call up one via uber-uber-zip-zip

oh, and poor taxi drivers - bad enough to get ubered- but this will make them complete toast.

maybe a few chauffeur limo businesses will remain as "bespoke handicraft" signs of conspicuous consumption?


Sunday, August 30, 2015

technology embedding ethics

Having tried to confront ethics in internet experiments at a conference a couple of weeks ago, I'm trying to think about the way technologies like the internet embed ethics and how this challenges us both in every day life and as researchers into communications, but also for developers creating new technologies.

One obvious place where this shows up repeatedly is in the tension between free speech and hate crimes, as well as between privacy and accountability. but it also shows up in the power imbalance between large organisations and the individual. Taking these in the reverse order, then:

1/ The cloud is run by a small number of very big trans-national companies, for profit - original technical reasons for centralising resources (compared with the world wide web of the 1990s, or even early 2000s) was economic - scale gets price/performance advantages for servers, as management and control are run in one place for a lot of people. prevention of various attacks (e.g. denial of service on small sites) goes away as a problem, since few bad guys have the resource to launch a big attack on today's giant data centres (outside a couple of government agencies:)

However, once all that information is concentrated in one place, it affords opportunities which didn't make sense when it was decentralised. A for profit company has no choice: It has to maximise the shareholder value. This isn't mission creep, its just capitalism.

Of course, putting all your eggs in one basket does have a downside when there is a successful hack (viz the ever increasing list of Cablegates, Sony's, Ashley Maddison's)

2/ Privacy is not assured in a network. when you communicate, at least one other party now knows what you said. In a computer network, your privacy is now in their hands, since everything you "send" to them is a copy. They now have a copy. It can be copied again. While the parties to your original communication may be accounted for (you think/hope), further copies are not accounted for. This is a consequence also of the near-zero cost of copying. In days of illuminated manuscripts, only people with a monastery full of monks could copy stuff again. Nowadays, as downloaders know, anyone can re-upload. As YouTube demonstrated, you can even legitimise file sharing if you have enough power (see 1/:)

However, privacy is not dead. There are social norms which prevent us repeating all secrets to all and sundry. There are also legal situations where confidentiality is required (patient/doctor or client/lawyer, or just gf/bf but only if at least one of them is a celeb:)

What isn't clear because of the way technology has made copying easy, is when you are trespassing on those social norms - the technology could be less neutral - it is fairly easy now to provide tools that look (locally, on your device) at the information you have and make suggestions about reasonable use of it (delete now for ever, do not copy, etc) - in organisations that care about security (defense agencies) classification provides rules about where data can go - we could help every day people by building better support for remembering what you should and should not do.

3/ Many systems provide platforms for public utterances - blogs, have-your-say, comment-is-free, etc etc - but also just being able to get a throw away e-mail account at the drop of a hat.

Many are geared to ease of use, so don't need accountable sign-on, and don't check what is said or who it is said to.

Such systems allow trolling and other offence.

The problem is that the policing of what people can say, to whom, and where is generally regarded as a form of censorship, and in some countries, strongly opposed.
This conflates two things
a) anonymity (which has its place for whistleblowers, or people in countries where free speech is anathema anyhow)
with
b) free speech.

In general, if you think you have a right to say something, you should be able to stand by what you say, hence being anonymous is not only not a requirement, it is actually a really weird thing to require. Experiments on requiring true names, or at least accountable identities, on some sites have resulted in visible reduction in abuse.

So what I'm trying to say here is that we have built an internet, web, cloud, which to a large degree is not fit for human purpose.

  • It is good for corporations to make money at your expense
  • It is excellent for us to live in a panopticon
  • It is a fine public space for people to shout abuse at others while wearing a mask.
Time to fix this.

Thursday, August 20, 2015

lost and not not forgotten

social scientists studying the right to be forgotten have forgotten why

Tuesday, July 21, 2015

sharing and hiding - e-books and crypto comms

two ideas for the day:
1/ when you're reading an ebook, people around you don't have the pleasure of seeing what you're reading as they do by seeing the cover of a paper book....

so e-books have wireless for download - why not (up to you to turn on/off) use a whispernet style ad hoc meassage to broadcast to people nearby what you currenty are lookin at....?

2/ when you type an email that has a word like "attachment" in it, the mailer notices if there isn't an attachment often, & asks you if you meant to have one
how about the mail app (or browser) could also look at the email and make a guess "this looks private, don't you want to use the recipient's public key"?

j

Saturday, July 18, 2015

democracy and debate - what's wrong with vanguards etc

just listening to lots of talks by social scientists - when people talk about politics, they've spent a lot of time reading, digesting, thinking, synthesising and so on. so then they report their results back. what's the problem?

well, basically, TL;DR

the process has to be a process for al potential involved parties - this is why syndicalist anarchism is the way forward - direct democracy has to engage, so the naive extension of representative democracy into direct democracy just burdens people with too many irrelevant discussions, so is alienating in a worse way.

Friday, June 26, 2015

towards an antisocial contract

Towards an Anti-Social Contract

I've read the David Kaye's report, which I very much like (clarity and precision, but also happen to agree).
What is missing? A clear way to measure proportionality, and a social/legal framework to implement judgement of what is a (currently on hold) proposals to replace the European Human Rights proportional way to suspend crypto rights. So for example, the UK's where decisions are made, and replace them with politicians - with a UK Bill of Rights threatened to remove judges as the place Anderson's report makes it plain this is unacceptable (not just and proportional scheme to carryout lawful intercept, the advent of ethically, given conflict of interest, but constitutionally).
However, there's a very real threat that without a transparent, fair, intercept. Government agencies need to be persuaded to reduce their really good perfect forward secrecy mechanisms, and better key  management in general, will basically mean there will be no feasible (child porn , terrorism organisation, money laundering etc) would mission creep (similar to commercial agencies abuse of personal data) as that would mean legitimate policing of really bad uses of the net simply go completely unchecked.

There's a secondary threat, which is that wholesale monitoring by too: If citizens feel confident that monitoring is only done for good reason, and without weakening out crypto-systems, they may not feel the need to adopt unbreakable systems. Many agencies will result in a massive breach of privacy when should never have had access to 2 Million documents - modern cloud (inevitably) one of those agencies accidentally leaks a collection of monitoring data. This is the other lesson from Snowden (the NSA's internal security procedures were incompetent, in that one person providers do not let their system administrators have such privilege.
This is the balancing act that needs to be created, in my view. and nor should a security agency, and what better way to enforce this, than only to collect necessary and sufficient data in the first place - the needle, not the whole haystack.
A sort of Anti-Social Contract c.f. always on
So maybe we need a new arbiter organisation - a distributed citizenship v. government tie-breaker - not the police, business or the press or current national judiciary - a sort of 7th estate. It should, like the Internet itself, admit of no kings, just working codes of practice. It could manage rights to be forgotten too. It might need to employ some very smart social machines to cope with ddos, edit war, troll, bot farms etc etc

Friday, June 19, 2015

science and policy #101

Three recent pieces of work in Cambridge came to light

1. scientists have been working on the basis for randomized trials, and realized that, of course, we must have some non-randomized trials, to check if the very basis for randomization as part of scientific empirical method is sound.
In a bold inter-disciplinary move, the scientists collaborated with the department of history and analyzed a number of UK and other policies for economics and military action, to see if one could find random (e.g. the 100 years) and non-random (e.g. the 1st world) wars, as well as economics (e.g. monetarism, and austerity). The results will be published very soon, but are currently under embargo, in case they disturb a current experiment with Greece.

2. Engineers in Cambridge have long wanted to build a railway to replace the ageing bus and taxi system. Working from earlier chinese experiments with mono-rails, and the guided by the guided bus success, the proposal is not to take the modern electric line from Royston to King's Lynn, where customers are already used to the trains splitting at Cambridge, with one half going forward, for example, to Ely, and the other half, soon, to the Science Park. From next year, they hope to split the train laterally, with the left half going around the pieces (Christs, Parkers) and Commons (Midsummer etc), and the right half going in a long overhead loop, to Ely, allowing the Eels much easier migration along their breeding paths in the fens. If the duo-mono-rail is a success, the engineers propose to extend the routes to Paris and Brussels, where onward mono-mono routes could serve ski-resorts and some of the Belgian mountain regions where the finer beers are produced.

3. For some time now, a very ambitious project in CRASSH has been working on Consipiracy Theory. This work has involved linguists, computer scientists, taxi drivers and publicans, and has recently yielded a breakthrough. A new tool has been built that can detect consipiracy theories with a false positive rate of 2% and a false negative rate of 3%. The method is based on a mix of Bayes and various NLP clustering algorithms. Currently the tool is part of a possible startup and venture capitalists are clamouring to fund the work. The business case is unclear as yet, and there have been some suggestions that at least one major journalism organisation may have prior art, although scientists suggest that their conspiracy generator is based on different technology (followers of Chomsky will understand that recognition and generation are quite different linguistic machines). At least one government agency claims that they had build a system exactly like this in 1961, and that it correctly identified Cuba and Suez, but they could not reveal the technology for fear of showing potential national enemies how much more advanced the UK was than them. Security analysts have asked them to "put up or shut up" as this is not the first time that they have claimed to have approaches to their work that would save time and money, but have not deployed because they would have, err, saved time and money and lives and red faces.

Meanwhile, CRASSH were not available for comment.

Monday, June 01, 2015

intent with meaning - future network control

there's a lot of chat about intent-oriented networking e.g. Nemo, - latest fad - seems to be a little bit like predicate routing - or declarative networking - where you way, in a very high-level way (e.g. legalease, c.f. recent microsoft paper on compliance) what you want to happen. Hopefully, this is 11 layers higher than open flow, and employs P4 at a minimum, as most of the intents that aren't just 5-tuple flowspec based, must necessarily employ DPI and application based content patterns.

however, where are the semantics? this seems to me to be a massive missing mole of an elephant in the room

Who (subject/object) wants What (packet, router, link, user) to be Where (in a jurisdiction, or not) When (before T, after T etc), and Why (profit, loss, legal link, fun) - the WWWWW (High 5 ?) of networking - it shouldn't be too hard to do a bit of deontic logic and denotational sugar to get this right...a suitable job for computer science, and possibly, the NaaS project, but possibly not...

Blog Archive

About Me

My photo
misery me, there is a floccipaucinihilipilification (*) of chronsynclastic infundibuli in these parts and I must therefore refer you to frank zappa instead, and go home