On Wall Street, a high-ranking few still avoid email
reuters.com
reuters.com
> RS: One of the unintended consequences is the opposite effect, which is what we've seen with the Department of Defense, and even the State Department, here in the U.S., of trying to make secrets more impenetrable rather than less and trying to take precautions against what has happened from happening again in the future. How do you regard that?
> JA: Well, I think that's very positive. Since 2006, we have been working along this philosophy that organizations which are abusive and need to be [in] the public eye. If their behavior is revealed to the public, they have one of two choices: one is to reform in such a way that they can be proud of their endeavors, and proud to display them to the public. Or the other is to lock down internally and to balkanize, and as a result, of course, cease to be as efficient as they were. To me, that is a very good outcome, because organizations can either be efficient, open and honest, or they can be closed, conspiratorial and inefficient.
1: http://content.time.com/time/world/article/0,8599,2034040,00...
After all, don't they believe in full transparency?
They don't have much of a moral hill to stand on - unless they subscribe to the morality of "The ends justify the means." (Which most people do.)
How many people are going to avoid leaked material because Wikileaks are hypocrites?
[1] https://en.wikipedia.org/wiki/Censorship_of_images_in_the_So...
They've backed and associated with various privacy groups and suggested that individuals and groups not in the public interest deserve privacy. Assange has complicated that a little by releasing personal, unredacted emails, but it's been their stated intent at least.
Give that transcript another read: "organizations which are abusive and need to be [in] the public eye". That's not decrying privacy, its decrying use of privacy to hide abusive behaviors. I haven't seen Wikileaks accused of that; the usual accusation is that their public behaviors are politically motivated, which is very different than alleging internal corruption.
Being politically motivated can very much be a form of abuse. When you have the ability to significantly hinder or tear down public organizations through leaking, I think the public deserves to know how Wikileaks decided what to leak, how they are funded, and what interests they represent.
Simple hypothetical scenario: Wikileaks gets compromising information about a left-leaning and a right-leaning organization, but they only decide to make public one of those leaks because they're biased. Or they receive some damaging info, and use it to trade for political or personal favors in return for suppressing the leak.
Given that there are so many ways that Wikileaks could abuse the public's trust, their 'transparency' rhetoric very much should apply to themselves.
That's some pretty intense equivocation from where we started. Acting in the public interest does not make you "a public interest". The details of Chelsea Manning's gender identity don't influence the ethical status of her leaks.
Assange's claim (which is not my claim) seems to be that groups with structural power and objective control over people's lives should be forced into transparency or inefficient secrecy. That's largely governments, and agencies like the DNC that shape them. It's also militaries, powerful investment banks, and other groups like utilities which can control access to credit or basic needs.
None of that is representative of Wikileaks. Their influence all happens at one remove, by doing things which the public reacts to. If their disclosures on X are accurate and the public gets mad about X, that can be a direct conversation between X and the public that need not involve them. "Abusive" here seems to mean groups that can take direct financial/legally/physical action on people.
Having said all of that, I understand how selective enforcement works. If you know that a disclosure will harm a person, and take that act to achieve your interests, it's a cop-out to blame "the public" if you're choosing what to disclose. But it's relevant that Assange has made it quite clear that he's disclosing to hurt Clinton; his political motivation is already public knowledge.
There's really no good answer here. You can explain how you make your decisions, but "not leaking a document" is inherently a secretive act. No one can be sure your choice was honest and public-spirited unless you do reveal the document, so all that's left is faith. That's part of why Snowden and other leakers have gone through respected news orgs, because if someone's judgement is the deciding factor you might as well choose well-regarded judgement.
I don't have much of that faith in Assange at this point. I think his leaks are probably selective and politically motivated. It would be interesting to know who funds them and what they say internally, but that couldn't possibly clear up the whole question. After all, if Assange reads one paper about Clinton and one about Trump, and says "the one about Clinton is worth leaking, but the one about Trump isn't in the public interest", how could you possibly evaluate that claim without both leaks?
But none of that means Wikileaks is equivalent to the groups he's demanding disclosure for. Ethical questions on our part do not amount to hypocrisy on his part, and it's still a distinction worth drawing.
At that point Wikileaks needs to be auditable to find out who decided that would be a good thing to do and why.
I was speaking the to larger claim that Wikileaks owes us transparency to avoid being hypocritical, which I still don't accept. But at this point, they might well owe some transparency not as a public establishment but as some people who screwed up badly with the power they were given.
This is exactly the rationale behind why reporters frequently wish to keep their own sources private, even while they are busy publishing things that other organizations wish they wouldn't.
Corruption is still corruption, no matter if it is made public by a "good" organization or another corrupt organization. The corrupt organization does not get a free pass just because their competitors might be even more corrupt (and wikileaks might know that and hold back that information).
Wikileaks' core activity forces it to walk a very very thin moral and ethical line. I think we the public have obligation to make sure they don't cross it, especially if we benefit from the leaks.
I'll note that in another context, it was for a long time not alright for prosecutors to use illegally obtained evidence, in order to discourage prosecutors and police from breaking the law, even at the cost of potentially letting criminals go free. Why doesn't that logic apply here?
Being politically motivated can very much be a form of abuse.
When you have the ability to significantly hinder or tear down public organizations through leaking [...]
If there is no (major) wrongdoing, you cannot just tear them down. The organization needs to be corrupt in the first place. it's whether we should inspect Wikileaks itself,
given that its position gives it strong incentives to do shady things
without any transparency.
I don't see anything suggesting strong incentives to do shady things, can you elaborate please?I see the opposite, however, they got strong incentives NOT to do shady things, because if they are caught even once doing shady things, their reputation is in the gutter and nobody will ever listen to them again. That is not to say that they got no political bias and even political bias. When the emails you obtained contained Hillary asking why they cannout just "drone him" (aka Assange), you might take that a bit personally too. But political bias and personal bias is in no way evidence for "shady things" and wrongdoing.
But yes, wikileaks too should be scrutinized, and I think it is, by pretty much everybody, the government, it's agencies, the media. Still, so far, after a decade of operation, there is no proof wikileaks did anything sinister, and the best attempts so far to discredit wikileaks was coming for their leader with rape charges instead of discrediting what the organization is doing.
And yes again, we the public should not stop to be vigilant and continue to scrutinize wikileaks.
I'm not so sure that's true. As the size of an organization grows, the probability that someone in it will write an e-mail that looks incredibly damning when leaked approaches 1. That's true regardless of whether there is any actual corrupt behavior, but the political damage is done regardless. IMO, the public is generally not great at teasing apart real misconduct from stupid private e-mails, because the public either lacks or chooses to ignore context.
I know in this day and age it's not very popular to say that things should be kept from the public, but I'd like to point out the example of the legal system. Judge often decide that evidence should not be shown to juries because the evidence is inflammatory and will cause bias. Sometimes showing more evidence leads to less truth, not more. Obviously, Wikileaks is not a court, but it does choose who gets to see what, and they have some idea of how the public will react to what is revealed. But we have no real idea how they internally make that decision.
> I don't see anything suggesting strong incentives to do shady things, can you elaborate please?
Sure -- this is an organization that often gets illegally obtained information from perhaps anonymous sources. Because the sources are by definition secret or inaccessible, and yet the information can be very damaging, there's always the temptation for illicit dealings. Here are some possibilities:
- Someone in Wikileaks uses the information to blackmail the target of a leak
- The target of a leak gets wind of it and tries to buy off Wikileaks
- Outside actors (e.g. the Russian government) effectively use Wikileaks as a 'neutral' channel to cloak their interference in the political affairs of another country. This may in fact be what is happening today, but we can't be sure because again -- Wikileaks is not transparent.
- A Wikileaks staffer is arrested or otherwise threatened by a government to do their bidding
Contrast this how major news organizations handle sources and leaks: journalists form a professional body with their own journalistic code of ethics and conduct. Leaks are evaluated for their newsworthiness and sources are scrutinized.
Obviously, traditional media organizations aren't perfect either, but they are far more open and transparent than Wikileaks is, because there are institutional norms developed over decades that constrain their behavior.
In a perfect world, Wikileaks would be open and transparent in their process of how they evaluate and pass on leaks, so we can be sure that they're not being unduly influenced or using it to advance a hidden agenda.
All your examples apply to traditional journalists as well, by the way.
Wikileaks has their own code of conduct and ethics. I fail to see how their self-imposed code is any less valid than the self-imposed code of traditional journalists.
wikileaks claims it evaluates and scrutinizes their sources. So far it seems they actually did that, and did not fall for any hoax. Traditional journalists also claim they evaluate their sources, and most of them did not fall for any hoax. Both don't do so transparently, in fact journalists went to jail for not being transparent and disclosing their sources, so I fail to see how traditional journalists are any better or worse than wikileaks. The lack of transparency when it comes to sources is a feature and not a failure, protecting said sources, for both wikileaks and traditional journalism.
It's a bold claim to state that traditional journalists are more open and trustworthy simply because they have been around longer (the organizations, not the individuals of course).
Regular news organizations reported the Iraq had WMDs because the government sources said so, without any actual evidence. Or published fake Hitler Diaries. Meaning it's not all that rosy and checked and ethical as you make it out to be.
I don't see the "contrast" you claim exists. If anything, wikileaks has a better track record than a lot of traditional media organizations when it comes to publishing verified information, so far.
PS: The likes of Murdoch and Bezos prove outside influence in journalism is a real thing to worry about.
Quite the opposite happens even in this thread. Are you aware of [1] and [2] and [3]? Do you think that incident sent their reputation to the gutter?
(edit: added one more link)
[1]: http://www.dailydot.com/layer8/wikileaks-syria-files-syria-r...
[2]: http://www.theverge.com/2016/9/9/12864328/wikileaks-threat-r...
[3]: http://www.dailykos.com/story/2016/7/26/1552616/-Russian-Hac...
> The question is not whether we should give corrupt organizations a pass (we shouldn't)
The majority of the criticism I've seen absolutely misses this step. It treats "Wikileaks is shady" or even "Assange might be a sex criminal" as a rebuttal to "this thing in this email you sent is incredibly unethical". Time and again, the discussion of Wikileaks ethics comes up only when they embarrass someone, as a defense for the person embarrassed.
I'm not sure what to do about that. Ideally, I think we'd do it the opposite way - the published emails that weren't ethical embarrassments are a way bigger violation of privacy. I'd like to see Wikileaks held to account for publishing harmless and personal messages, while seeing the leak subjects held to account where the things they did were actually bad.
I'm being flip, but there's real substance here. A government, bank, utility, or military has direct power over people. They can cut people off from money, property, or freedom without any offering any recourse or external accountability, and that makes them potentially abusive to the public.
A private citizen, hobby group, or business with strong competitors is generally not at risk of abusing the public. They don't have the power, or couldn't sustain it while behaving badly.
So there is a narrative where we can decline "full transparency" while demanding transparency from public actors. The role of media (and Wikileaks) here is complicated, because they lack direct power but can still have predictable influences on the world; even so, we don't have to grant privacy as a totally symmetric right.
But that's not a distinction that Assange makes in his rhetoric, and I'm doubtful it's one he will make in practice either. Would Wikileaks really hold off on publishing if it came across a damaging leak about a news organization?
I feel Assange and his supporters do a great disservice to the public debate by oversimplifying things. Sometimes secrets are necessary for the proper functioning of our governments.
The problem is he's describing exactly the modus operandi of some bad actors on wall street. Cozy relationships, exploiting advantages (gained through unethical, or illegal means), and general obfuscation of how they're able to extract fortunes from the financial system. If you create more of this, that's not a remedy, it creates more opportunities for bad actors.
Of course I don't have any substantial evidence but just looking at it, it seems like a contrived apparatus with a James Bond like villain at the top, branding that looks like it came out of a B rated movie and 'leaks' that seem serious enough to get the media up in a frenzy and attract anyone with any real leaks.
I wouldn't be surprised to read about its conception by some mid-level CIA agent in 30-40 years.
Many of these highly eyebrow raising emails are CC'd to gmail accounts, for example. If it was fake, you could ask Google for the logs to prove at least it wasn't received.
And if there are DKIM headers, then that's certainly strong evidence that the header and body are legit.
The whole problem with this sort of thing is that there's no chain of custody.
If the people don't deny it, then it should be assumed to be true.
US government takes security very seriously. A real organization like wikileaks would not even see the light of day.
That big tax cheating leak that mostly leaked famous non-usa figures....particularly Russian and Chinese.
Their claim is that technology allows governments to conspire. Not in an Alex Jones kind of way but simply that technology allow governments and people in power to exchange information effectively enough to coordinate various plans.
Some of these are good some of them are bad, but ultimately the idea that the governments can conspire is bad and so Wikileaks want to make it so impractical to use technology to communicate that they are forced to use other less effective means.
You can't only understand wiki-leaks if you only understand them as a political organization. You have to understand them as an techno-activist organization using information to destroy the way information is used by those in power.
Slow it down not hindering it completely.
How noble.
(It's not like this problem hasn't been solved by the intelligence agencies already.)
So will legitimate internal members of the organization.
Haven't you ever had to wade through your company's intranet wiki trying to figure out which documents were are actually useful versus the giant piles of things that are outdated, wrong, superceded, etc?
> That won't work because you'll be adding noise to
> your own data.
What does "noise" mean in this context?This seems like a false dichotomy.
Wish I had more time to go in to why I think that. One counter example might be The Manhattan Project.
And I don't think necessarily the people on the project would think what they are working on as 'abusive' per say. Compared to killing civilians from a helicopter, being corrupt, dodging taxes or spying on the entire world like the gestapo, the manhattan project probably had a different feeling to it.
I mean, come on. Everyone uses email. Having said that, everyone also knows there are things you put in email and things you only discuss face to face, or over the phone.
And the dividing line doesn't necessarily have anything to do about breaking the law.
Everyone on wall street has had an email they typed up get into the hands of someone who they wish it wouldn't.
Whether its shitting all over an analyst for not being good at their job that got back to the analyst or doing something similar to a CEO, these things can harm your future relationship with these people who you may need to do business with again.
You rant over the phone, you issue actionable orders via email for the same reason. One has no trace, the other has a record you can point to.
If you're a big enough target, having lots of conversations is much worse than having none, because you will make a mistake, or something will be misinterpreted, either accidentally or willfully.
Specific content aside, it would downright miraculous for 60k emails to not include something embarrassing to someone, and setting an expectation for that just commits us to lying or condemning anyone who uses email.
Sadly, this is not true.
I get many emails from people with URGENT in the subject that require an immediate reply, as if they expect I will see it in minutes.
I have gotten emails about outages from clients, even after telling then "outages are always a phone call".
Some people assume that everyone lives in email, like they do, and has push notifications setup on their phone, etc.
A lot of people don't know this. One of my favorite classes in business school was "Business Communications." a lot of the stuff seemed really basic, but I'm amazed how much of it is disregarded in the wild.
Email wasn't a worry, nobody had it then. I think they had an internal system of some sort but the line staff consultants didn't have access.
If it is a service that is paid for by the company, then it is most likely a trove of data that is discoverable...
Not actually. I've been a consultant for a few years now, and have worked with executives who have their assistants print out their email for them in order to review. It isn't limited to Wall Street.
Though it's probably something we'll see less and less of as the years go by.
As per https://www.quora.com/What-is-it-like-to-be-Knuths-secretary, the secretary role has changed a couple of times in the last couple of years.
Sadly, no. I often have to remind co-workers not to discuss things like patents or license issues in email, IRC, etc. These are seasoned developers who absolutely should know better - we do take training in this every year - but it still keeps happening.
What everyone on Wall Street appreciates is that your emails are a permanent record and should be treated accordingly. When there's a real risk that your emails will later turn up in court, you are gonna be a lot more careful about what you say. Even things that seem innocuous when you write them may not look good if they come under the spotlight later (something like "Hey John, the code in that repo looks messy..." may come back to bite you if it turns up in court). So I was taught to always keep to facts in emails rather than opinions ("this data set has 246 invalid phone numbers and 20 fake email addresses" is a fact... "this data looks messy" is an opinion subject to all sorts of interpretation later).
You might think that there's nothing that you have to hide. If that's true, then by all means, say what you want in your _personal_ email. But when you are using your company email, remember that you don't have many rights to privacy there and so treat it accordingly.
I once dated a lady who did data recovery and "e-discovery" for the legal department of a large corporation. A large part of her job involved grabbing disk images of people's hard drives, and then digging through them and people's email, looking for any information relevant to lawsuits, internal investigations, subpeonas, etc..
As far as I know it was never at random, though.
A desire to filter out noise and apply their attention in a selective manner is probably the biggest motivation to avoid email. At this level, I imagine people would like to receive a concise written or spoken summary, think about the content, discuss it with the relevant people and then make a decision. Since they control their own time, and have staff to respond to "tactical emergencies," they're free to organize their schedule and staff in order to optimize the decision-making process.
I can easily believe that major figures with a public email address receive far more mail than they can deal with in person.
good advice for everyone, not just bankers and politicians.
"There's a real danger when you're really famous. I can have a drink or two at night; I don't need to have an apparatus that, in a drunken joke, even, I could say something, go to sleep, and wake up in the morning and my career be over."
http://fusion.net/video/136579/george-clooney-doesnt-underst...
I suspect baby boomer led management think memorizing passphrases and using encryption is "too hard" and are calling the shots right now and we're all paying the price for it. We should be teaching each other and the younger generation that email encryption should be seen the same way we look at https now. Not too long ago https was regarded as for just 'credit card stuff only' because it 'cost time and resources.'
Its sad that something as critical as email doesn't have end to end encryption.
It's not just baby boomers, it's most people outside HN unfortunately.
mydog'snameisAliceandsheiscute
to
P@ssw0rd
The latter is harder to memorize (what letters did I substitute with symbols again?) and far easier to crack.
I suspect until regulators make people use encrypted email we'll keep using plain-text.
Since a pw manager can be cracked, for important sites (financial , email, etc), I make up a sentence that describes my feelings about the site. These I keep memorized. As a bonus, as my feelings about the site change, it's a great prompt to update my password.
I'd like to throw a layer of physical security into the mix (eg one of those usb keys), but it seems like there still aren't universally accepted options. Anyone have suggestions for this?
It's not that they have anything to hide -- but at the same time, corporate espionage is a real thing and you have to protect trade secrets and you know the government receives a copy of every e-mail and document that you do.
A great story I heard from a former employer was a lawsuit around a new sleeping pill. One person taking the drug ended up killing his wife while on it (in combination with a ton of alcohol and other drugs). The drug manufacturer was sued and decided to vigorously defend the safety of the drug.
Well, some low-level lawyer in the company decided to spout about the science of drug development (have no actual education around it) and said in an email "maybe the dose is too high?".
Slam dunk. That statement looked incriminating. The company quickly settled after that email was found. Just not worth the time or money to fight it. A settlement was the cheapest way out.
If you don't have a personal relationship with someone, questions aren't even honest questions, they are signals of liability transfer.
The cc: line is a kind of blackmail where assholes list the people they are performing for, or threatening to scandalize you to.
Everything about e-mail is abnormal.
It's a performance. The only way to win is not to play. Hence executives eschew it.
I don't doubt that this toxic environment exists, but I'm fortunate not to have worked in one yet and I'd like to keep it that way.
When people say they work for a company that is collaborative and non-hierarchical, I've found it either means they are a manipulative and delusional tyrant or they are the sucker at the table.
It's absolutely hierarchical from a macro level, but engineers live in pretty collaborative 5-10 person leaf nodes and we don't need to interact across the tree very often.
What you describe might exist for senior management, but they generally take cross-team dependencies to be a bug in the way the tree was partitioned, and fix it at the next re-org.
Of course the nature of email makes it difficult to make sure the policy has been enforced.
The standard enforcement protocol is to block all non-company webmail (and other messaging systems) and SMTP so everything runs through corporate Exchange or IM configured with the appropriate retention policy.
I expect that as creating and dealing with wiretap recordings gets easier, we'll see email retention policies extended to voice communications. Currently that only exists for certain highly sensitive positions that interact with the public, AFAIK.
That's not true for banks; they have specific reporting laws to comply with for anything that gets emailed.
> Every member, broker and dealer [...] shall preserve for a period of not less than three years, [...] Originals of all communications received and copies of all communications sent [...] (including inter-office memoranda and communications) [...]
I wonder if these people are the last (or some of the last) people that don't use email to communicate.
1: http://www.nytimes.com/2015/03/12/us/politics/storing-emails...
What's your source for this? I can easily believe they delete emails. But I would expect them to be subject to various laws about email retention, and those laws typically require companies to hold on to emails for years.
A colleague who was at a fairly known investment company told me of a senior exec whose PA left printed emails and left them on his desk. He would then write replies on the paper version and the PA would type and send them.
Nothing to do with secrecy. He was just older and never adapted to computers. I feel this logic fits occam's razor nicely rather than being over conspiratorial. It's not like you can't use email for efficiency, and do the 'lets take this offline' response when going somewhere sensitive/secretive.
I've got a feeling Tim Cook doesn't use a computer, maybe just an iPad with a carefully curated list of messages and financial reports for him to browse.
i know at least one candidate for President of US who right now is very very sorry for not following such best practice while at her last gov job, and who has basically become the showcase of "Trying to dodge discovery the Wrong Way".