Beware state surveillance of your lives – governments can change for the worse
theguardian.com
theguardian.com
Of the three with data they could abuse, I’ll take the thieves everyday of the week.
Meanwhile commercial surveillance also consists of explicitly malicious parties. LexisNexis isn't storing your data to benefit you. But when Surveillance Valley does its thing, their activities aren't even illegal. And it takes many years for the media narrative to even acknowledge the harm.
So no, I'm not terribly worried about information thieves. Most news stories that focus on them seem like simplistic distractions to focus people on the wrong threat.
I am very concerned with security holes opened by legislation such as the PSD2 in Europe - they should not exist in the first place, I want to sleep well in the notion that the project is solid -, and banks far from necessarily assume that you are the victim: very uncomfortable demands of proof may exist (up to, in a slightly different context, frequently heard absurdities such as "prove that your handheld was secure" [it is not, the service provider is the one that should provide security, not the user!!] or "prove that you did not write your PIN number somewhere in the stolen wallet containing your ATM card" [and then prove what, that one does not think of Spencer Tracy!?]).
But the matter is not (for clarity) just with the example of theft. That personal data is collected inappropriately is not just a reason for moral outrage, there may be also basic real consequences. Your personal messages, under "bad" practices, for example, may leak to more repositories: if one of them is compromised, your privacy may be exposed in ways difficult to compensate. These should not be forgotten, while keeping in mind other, very practical but not immediate for some, situations like "Ah, Mr. Jones, so we came to know you are a dissident", and the general disconcert.
And by the way, when I was re-reading the imperfect 'disconcert', the term 'discomfort' came to mind. Which makes other situations come to mind. In Europe some legislation mandates to have microphones (plus GPS and radio) in the new batches of cars (post 2018, to be used in case of car crash): some may never want to enter any such trap. If I felt uncomfortable with having my phone on I would just remove the battery, but not feeling comfortable even when one is in one's own car, that is way, way, way, way_times_by_1000 too much. Back to the article, it may not take much to have an entity decide, "let us record it". And then, for some reason (subcontractors, public-private partnerships etc.), have copies around. And then, owing to holes, having one's privacy exposed...
Which brings me back to my original point: what if not just the big-s-state or its contractors, or partners (already here we are at mind-boggling reality from a moral and good-sensical point of view), could access those intrusion devices, but just Mr. Random, owing to security holes? I do not forget that my privacy is also against Mr. Random, together with Society, Enterprise and State.
It being unchecked is exactly the point of Google having an intelligence apparatus and governments being A-OK with that.
The only secure option for maintaining the privacy of data is not to collect it in the first place. Collecting it and then saying, "I'm going to hire better hackers to secure it than the guys attacking me will hire to gain access to it!" Is a bit naive. At scale, you're almost guaranteed to lose that bet.
This is the difference to me as well.
We are relying on governments to create those needed checks.
The Taliban has reportedly seized US military biometrics equipment that could expose Afghans who helped coalition forces – since they contain identifying data like iris scans and fingerprints as well as biographical information. An unidentified Joint Special Operations Command (JSOC) official told The Intercept that the Islamist group confiscated the Handheld Interagency Identity Detection Equipment (HIIDE) devices during its offensive push last week. The report was backed up by three former US military personnel.
They told the news outlet that the portable devices could be used to access sensitive information from large, centralized military databases, but noted that it was still unclear how much of the biometric database collected on the Afghan population has been compromised.
According to a US Army Corps of Engineers presentation, HIIDE devices use the data collected to create a “portfolio” that can then be imported into Biometrics Automated Toolset (BAT) identification-processing software as a “digital dossier.” This can be scanned against official watch lists for threats.
Besides tracking insurgents, the Pentagon was also reportedly keen to use the devices to gather unique data on 80% of the Afghan population to check for terrorist and criminal activity. Unnamed sources said biometric details of locals who helped the US were also collected and used in identification cards.
“We processed thousands of locals a day, had to ID, sweep for suicide vests, weapons, intel gathering, etc. ... [HIIDE] was used as a biometric ID tool to help ID locals working for the coalition,” an American military contractor told the outlet.
More info https://www.rt.com/usa/532419-taliban-biometric-data-afghan-...
Government has a monopoly on the claim to legitimate use of force. All elements of this statement are crucial. The (usually Libertarian) objection neglects to consider "claim", "legitimate", and most aspects of "monopoly".
It seems like the problem becomes when one says something is a legitimate use of force, and another says it is an illegitimate use. I’d argue they already illegitimately use their force and we should be very careful to give them any more ability to do so.
More government surveillance could genuinely be good and we could catch more bank robbers and rapists with it maybe, but it could also be used to punish those who protest.
Imagine if we give the feds crazy surveillance powers, and nod in approval as they arrest those on the right not wearing masks while not vaccinated. We might save lives! Then Trump gets re-elected and decides to use that same surveillance to go and arrest those protesting the “legitimate” use of force against PoC.
Focusing on that for a moment:
There are companies which have visited violence on people. Often in a limited fashion, though not infrequently of an ulimited nature. Smith's Wealth of Nations discusses the companies of his times which operated their own private armies and navies. (He was Not A Fan.) There are today private armed forces, whether cast as private security, police, or mercenaries. Pretending that there's some inherent divide between governments which engage in deadly force and private industry which does not is simply false.
The worst abuses occur where governments and indsutries work hand-in-hand. That is part of the particular evil of ur-industrialism in its Fascist incarnation, where an elite industrial and financial class joins with a political group to wage genocide on its own people as well as the world. Note that Nazi Germany didn't operate without international support, and that companies including IBM provided direct, ongoing, contracted support for Nazi activities, including the Holocaust, throughout WWII. The tattoos you see on the arms of Holocaust survivors are in fact IBM-generated identification codes.
What I'm concerned about is unipolar power organised without restraint or separation of power, though constructing an effective-yet-functional separation also proves difficult. (The model inherent in the US constitution appears to function poorly in the face both of political parties and a division of the country in which no common agreement on basic facts seems possible.)
In the case of information and communications monopolies, which I've previously argued inherently give rise to censorship, propaganda, surveillance, and targeted manipulation, (See: https://joindiaspora.com/posts/7bfcf170eefc013863fa002590d8e... (HN discussion: https://news.ycombinator.com/item?id=24771470)) there is a symbiosis between state and private / corporate activities and engagement. One part of the stimulus of the development of intrusive, ubiquitous, and privately-operated social networks was the NSTIC, National Strategy for Trusted Identities in Cyberspace, described by Alex Howard of O'Reilly Media as "[A Manhattan Project for Online Identity](http://radar.oreilly.com/2011/05/nstic-analysis-identity-pri...)".
One of the inherent problems in government is in designing tools and systems which can be effective, whilst being aware that as much as they'll help your own interests whilst you have some control over them, they'll serve the goals of your political opposition when _they_ gain power. (Note that thsi problem is not limited to government, and that there are numerous companies which have evolved far from the interests of their own founders over time. This seems to happen especially in the publishing and media space, see H.L. Mencken's American Mercury or The Learning Channel.) I'm not sure how that is ultimately to be dealt with, though I also believe that any tool which is useful is also of necessity potentially harmful.
But the notion that the solution to minority or tyrannical capture in government is to eliminate government's role in a domain and assign it instead to instituations based on minority and tyrannical control, that is, privately-owned businesses unanswerable to the general public and with an unlimited scope of monopoly control ... seems to have a few flaws.
Government and politics, for all their flaws, are literally the mechanism by which a public and polity comes to a mutual and shared agreement and actions.
And misquoting and misrepresenting Weber does that fact a tremendous disservice.
Some of us in this thread that are decrying survelliance of all types are going to go back to work on the next work day at Google, Facebook, Amazon or some other company. When the boss man comes in and says "can you implement this feature" and it is about getting user analytics, you will say "yes sir/ma'am" and do it with a smile.
If a gov't wants software written, there will be somebody willing to write it.
Only checks and balances, and high transparency within the gov't can work in the long term.
And how exactly is this person supposed to pay their rent and food costs?
"Don't do the work" isn't a viable solution for a lot of people. Pressure has to be put on the decision makers AND law, not the poor dude who is just trying to feed their family.
If you have enough rent saved up for a year, you might have the luxury of being able to say no.
If you have an source of developers, where you can discard 95% without effect, could you please find me a haskell developer, sysadmin and a ee engineer woking in kicad? Salary - good in Eastern Europe. I'd prefer those that do have morals and standards. Thank you very much.
95% of developers refusing to build, won't stop PRISM or FAANG by not building. What it can do (along some explanations and reasoning), is to unrecognizably change the landscape, change availability and perception of privacy and security, and in a roundabout way, maybe even stop or at least reduce PRISM, FAANG, et al. data collation.
Currently, about 5% of websites respect their user's data? What if it was 95%?
Just because some people may not have any guiding principles doesn’t mean everyone should abandon principles.
That is another way to look at it.
Quitting work without alternatives would put many people in grave danger, including not being able to receive hospital care, or not having a place to live.
Some of these tools can be adapted to create formal models of concerns that are today relegated to "ethics" and "law", which have near-zero chance of keeping pace with software evolution. Social Network Analysis has several decades of work on graph theory applied to social systems, including knowledge work, law enforcement and intelligence, most famously applied by Palantir. There are reusable OSS libraries for SNA.
We need to get to the point where a CI/CD test or simulator failure can flag the introduction of code/policy that places positive social futures at existential risk. Then the proposed changes can be escalated for human governance review. In the meantime, we rely on policy frameworks, threat models and watchdogs from places like EFF, https://twitter.com/evacide
All government databases should have a self destruct knob in case the government falls.
Though obviously there would be no guarantee the command could be related to remote stations.
Pandora's box has been opened, and we're going to be in for some interesting times.
Easy to say, hard for many people to do.
Previously, my last 4-5 job titles have included the word "manager", yet I have never performed any managerial tasks. My current title includes the word "engineer", yet there is no engineering in my job description.
I fix bugs, implement workflows and rules, and onboard customers on a platform. I don't consider that engineering, that's operations.
"What he got was a top 10 list of best performers, but not the list of the worst performers."
I interpret this to mean either you were on the list of 10 best performers or that he received a list of performs to perhaps replace you with.
Also, my case might be more true in America where there does not appear to be many laws regarding privacy. As far as I know, the EU is leading the way in this.
I find it sad that this is seen as a reasonable statement: totally idealistic, hideously unrealistic, and it is awfully close to virtue signalling.
You might as well say that the prisoners dilemma is solved by asking everybody to not cheat.
Any solution has to be robust to the variety of engineers that exist: including the antisocial, the people doing it for the lulz or $, those that don’t give a shit about anyone but themselves, and the plain clueless that are simply unaware of the outcomes/implications of their work.
Clearly expecting engineers to just solve the problem hasn’t happened, so it won’t happen. Currently the only solutions I can see are based on legal restrictions upon our government organisations to protect ourselves from our own authorities.
[1]: https://en.wikipedia.org/wiki/Tuskegee_Syphilis_Study
[2]: https://en.wikipedia.org/wiki/Guatemala_syphilis_experiments
[3]: https://en.wikipedia.org/wiki/Unit_731
[4]: https://www.businessinsider.com/the-military-tested-bacteria...
Look how many doctors are publicly stating that mandatory vaccination and vaccine passports are a violation of human rights and medical ethics.
Not too many. And certainly not the majority.
They're out there - but they are pariahed, smeared, and even getting death threats.
It's a discussion of ethics. So...
I maintain that the fact doctors are so silent on important issues - however subjective they may be to you - shows that trusting in a code of ethics rather than _actual impartial oversight and accountability_ is daft.
And that applies equally as much to engineers and tech.
With a doctor, the patient and their family is highly motivated to ensure the doctor is doing their best to avoid harm in a high stakes and high cost transaction.
When you get doctors more removed from patients (say large commercial medical organisations or vaccines or medicines), then “doctors” can often make the same selfish decisions against the diffuse interests of those they affect.
And the implication that engineers are the only vital part in an organisation that has the agency of choice is amazing. Equivalent statements could be:
* The only way it stops is if managers start refusing
* The only way it stops is if shareholders start refusing
Those statements are clearly ludicrous, yet somehow it makes sense that engineers are responsible for choice?I do believe us engineers need to try and act responsibly, and I do think using social pressure against unethical engineers is valid. But some anarchistic belief in self-policing is totally unrealistic. Likewise ethical guidelines do not seem to really help much in other professions like accountancy, legal or journalism. Our legal, regulatory, and political systems are there to help mitigate these types of issue.
>But some anarchistic belief in self-policing is totally unrealistic.
Engineers in my country are held to ethical standards with legal backing.
https://www.peo.on.ca/public-protection/complaints-and-illeg...
I'm sure truely authoritarian societies have professional engineering societies with ethics and rules about who can call themselves what.
How does your point relate to protection against state surveillance?
I'm telling you that Canada has this. There are 12 professional engineering organizations in Canada, all are self-governing, all have legal backing to enforce sanctions against engineers that act unethically.
>truely authoritarian societies
Canada has its issues but I wouldn't call it authoritarian.
I am not advocating against regulations or the like but saying that individuals are of the hook because „I don’t matter anyway“ is a recipe for ongoing disaster.
We need all types of push back against injustice, unfairness, and plain stupidity. Making excuses doesn’t help anyone.
However, this not the behaviour of someone who is seeking to be promoted. There are those who of "us" who have taken or are taking the initiative to go beyond what the boss asks them to do in hopes of being promoted. To be persuasive as evidence for promotion, this "extra work" must support the bottom line of the company the same as "the boss's orders". Hence "us" includes more than only the employees who "show up to collect a paycheck" and dutifully follow instructions, but are otherwise opposed supporting to the bottom line of the company.
Going further, is it safe to say some of "us" have already been promoted for supporting the company's bottom line and some of "us" are in fact managers. "We" are effectively the "boss man".
This line is intriguing: "The only way it stops is if engineers ..."
This seems to imply a underlying belief that "no one/nothing can stop us". As such, only "self-regulation" will work. Am I reading this wrong.
Also bringing into scope of "us" being moved into management. While I do meant boss man to be interpreted more liberally. "Boss man" can be a direct manager/supervisor (who may be an MBA or a prior engineer him/herself), it can be the CEO or shareholders. But yes, in some case those of us become the "boss man" and ask for these features or do not get in the way when someone higher asks for them.
To answer the last line, it surely is not the "only thing" that can stop us. Regulation can work also as has been brought up. But I fail to see where years of screaming for regulation has materialized in anything meaningful, at least in the US. The quickest way would be self-regulation. Adhering to a code of ethics or principles voluntarily.
I doubt he would have envisioned the mass surveillance possible today, however.
Generally, the more authoritarian a system is, the harder is standing up for liberties, because it has more willingness and tools to violently quell any resistance.
History shows that "Papers Please" often preceded questionable policy. Today, we have both questionable policy and poorly-conceived papers/identity systems being rolled out, with enforcement and fines starting in weeks.
And the decision to require vaccination at hospitals are also made on recommendation of doctors that are as, if not more qualified than the hypothetical doctor. The doctor in question can also open their own practice if they do not want to be employed by the hospital.
Licensing systems necessitate some surveillance in the form of identification and data storage, but it's not as if these do not exist already and somehow the driving license has not caused American to spiral into dystopia nor is it even close to being the worst surveillance mechanism that the American government could choose to use if it does turn authoritarian.
Driver's licenses are not required on private property, so the driver license analogy doesn't hold when we're talking about private establishments. Requiring a license and government dictating your driving behavior on your own private property would indeed be dystopian.
The government will not let you serve alcohol at a restaurant unless you check the drinker’s age. The government will now also not let you serve diners indoors unless you check they have been vaccinated.
Good to know we've established that you're ok with folks being shut out of a diner by mandate of government, so long as the reason is something other than related to a protected class. How about we ban everyone under 40 from dining indoors -- after all age discrimination is legal as long as it's against those under 40. We can also outlaw anyone who makes their living in the information economy, they shouldn't have chosen that career if they wanted to . And I think I want to ban anyone who drives or rides in motor vehicles, because there's a public safety risk as drivers and passengers of motor vehicles are one of the most common causes of traumatic death.
>The government will not let you serve alcohol at a restaurant unless you check the drinker’s age. The government will now also not let you serve diners indoors unless you check they have been vaccinated.
So you're one of those that thinks those old enough to go to war shouldn't be able to have a drink? The drinking age is one of the weakest arguments for government control and is an excellent example of overstepping gone wrong. I seriously can't tell if you might be using that example as evidence to discredit the mandates.
Religion is a choice and is also a protected class, so those are not mutually exclusive categories.
The only difference with COVID is that 375,000 people died last year in the U.S. because of it. It is a pandemic. There are three vaccines that have been granted authorization by the FDA for COVID that have also been shown in preliminary studies to be safe and efficacious.[2]
Further, why would the hypothetical doctor, whose "natural immunity is more protective than current, non-sterilizing intramuscular vaccines" additionally need the "upcoming nasal vaccine with sterilizing immunity"?
[1] https://www.cdc.gov/phlp/publications/topic/vaccinationlaws....
https://news.ycombinator.com/item?id=28252026 & https://news.ycombinator.com/item?id=28252075
In any case, the Pfizer vaccine is expected to be fully approved within days.
https://news.yahoo.com/pfizer-covid-19-vaccine-may-031718964...
The authorization's value was in allowing voluntary vaccination by those who are willing to undergo vaccination before FDA approval. There's a big difference between being _allowed_ to be injected with a substance, versus being _forced_ to be injected with a substance under pain of losing the job that provides for housing, health insurance, and other legal mandates that you could be thrown in jail for (like child support) if you are terminated "for cause" and unable to pay.
>In any case, the Pfizer vaccine is expected to be fully approved within days.
Excellent! We should hold vaccinations to at least this standard before we force people to take them, if people must be forced.
From a recent publication by UK SAGE, https://www.gov.uk/government/publications/long-term-evoluti...
> Whilst we feel that current vaccines are excellent for reducing the risk of hospital admission and disease, we propose that research be focused on vaccines that also induce high and durable levels of mucosal immunity in order to reduce infection of and transmission from vaccinated individuals. This could also reduce the possibility of variant selection in vaccinated individuals.
A short article on nasal vaccines, https://www.statnews.com/2021/08/10/covid-intranasal-vaccine...
> Vaccines that are injected into the arm have done a spectacular job at preventing severe disease and death. But they do not generate the kind of protection in the nasal passages that would be needed to block all infection. That’s called “sterilizing immunity.” The fact that the vaccines don’t block all infections and don’t prevent vaccinated people from transmitting isn’t a big surprise, said Kathryn Edwards, a vaccine expert at Vanderbilt School of Medicine.
The MMR vaccine is sterilizing, there are no booster subscription plans required. It is unfortunate that hundreds of millions of people now have category confusion where they mistakenly equate rushed, temporary, tactical vaccines (focused on symptom and mortality reduction) with proven vaccines (like MMR) that provide long-term immunity and have many years of safety data.
https://www.mayoclinic.org/diseases-conditions/measles/exper....
Also, people do get tetanus boosters as needed and some people do have to get another round of Hep-B again. My wife who is about to enter a nursing program has to go through another regimen of Hep-B because her medical paperwork shows she doesnt have immunity. She was vaccinated. It does occur in some people that their body does not retain immunity.
Now yes, I would like to see a better COVID shot. Or atleast know the full limits of the COVID shot. We are still not 100% how long someone has immunity. Hopefully it is a long time. If it turns out to be short, well yes I think we all want longer. There is also no garuntee of protection against variants. Measles could very well morph out in the wild as something different and current MMR vaccines render useless. I would actually say it is not an if, but when. As it is common for things to evolve over time.
I guess I shouldn't be surprised, but I was foolishly hopeful back in the day.
Web3 typically runs on IPFS which is like an upgraded HTTPS where instead of just one computer hosting a file on the internet it's instead lots of different people around the world. It's pretty much impossible to censor a file on IPFS. IPFS also allows easy offline web apps and a built-in CDN.
Web3 also uses a decentralized execution and state system where instead of your data being in one companies' servers like Facebook it's instead hosted on thousands of people's copy of the database. The important state data is impossible to censor.
In Web3 the infrastructure is distributed and no one controls it. You can run an app without having to trust anyone.
So, there's one centralised portal, like with Google AMP? (Perhaps this is cynical.)
So as a piece of infrastructure for hosting content and websites, it's decentralized and as more nodes come online it becomes more and more fault tolerant.
You can create new wallet addresses, for example, when you want and sign in with those. Or your dapps can use https://magic.link/ and users can just use private email addresses if they want.
Generally, for surveillance I think the legacy systems we're all still using are much worse. Firstly because we don't always know what they're doing, and secondly because these companies can say one thing and change their mind next week. Like how Apple was supposedly a privacy champion, and now they're leading the charge for building on-device surveillance tooling.
I'm not an expert yet but I don't see why self-destructing file sharing couldn't be built in the Web 3 world. You could also build hybrid apps, where most of the app is a dapp and the sensitive feature like self-destructive file sharing are housed on proprietary systems guarded by a company with a reputation for security/privacy.
I think that if today's strongest cryptography becomes plain in 100 years, I'll be okay with that since I'll be gone and the future generations will have figured out more advanced cryptography :) Or society will have moved away from privacy because we're all linked to each other with neural laces and everyone would know everyone's deepest thoughts.
From the docs: “information about which nodes are retrieving and/or reproviding which CIDs is publicly available.”
Here are some examples if you wish to watch a presentation on the finalists from a recent hackathon.
Why will it be better?
Why won't it be subject to similar failure modes as the present Internet?
What specifically do you see it improving on? How?
What can it not fix? Why not?
https://www.nytimes.com/2005/12/16/politics/bush-lets-us-spy...
That doesn't strike me as worse than what Snowden revealed. PRISM and the rest of those programs intercepted communications of hundreds of millions of people each year.
Snowden documented that surveillance in vastly more detail than had been done before, and deserves the thanks of citizens of the US and world for doing so.
(I listed a number of pre-Snowden revelations a few months ago: https://news.ycombinator.com/item?id=27184956)
> A digital ID that proves immunity will raise serious human rights issues. And the failure of the digital ID industry to deal with the issues of exclusion, exploitation and discrimination puts the entire industry under question ... The most important message for the industry is, perhaps, that you don't have to provide a solution to every conceivable use-case for identity. This pandemic should form a check on the hubris of the digital identity industry.
2021: Linux Foundation & others launch an interoperable blockchain to unify human identity across all US states and all countries, enabling linking of phones, online wallets, driver's licenses, EU digital ID, offline activity (e.g. travel, entering buildings) and potentially future central bank digital currencies with kill switches (e.g. prevent kids from exceeding monthly quota of sweets/candy purchases, or some cross-border transactions), https://www.zdnet.com/index.php/forums/discussi.com/index.ph...
> For health passes to work globally, helping countries to restart economies and reopen borders, they need to be trusted globally. Through the Global COVID Certificate Network, Linux Foundation Public Health is working to address this challenge by bringing together a network of trusted and interoperable Trust Registries, so that the holder of a certificate can use it whenever they need and wherever they are. IBM is excited to collaborate with Linux Foundation Public Health on this important initiative at this critical time in our history.
In other news, mobile phone numbers can be used to obtain the real-time geolocation of a phone. Both T-Mobile and AT&T recently announced data breaches of customer data, including phone number and other identifying information, for millions of customers.
The US government lost the entire OPM classified database on security-cleared personnel, one of the highest-value information systems on high-value humans.
So who exactly are we going to trust to run this global blockchain of human identity? IBM? What's their historical track record on cybersecurity and governance of protecting humans? And no, many "decentralized" companies enforcing identical policy does not make the resulting system any less centralized and fragile.
We need to collect less data, not more. If the West wants a social credit system, at least have the decency of emulating China by stating explicit public policy goals and owning the societal consequences. If Western countries don't want a China-style social credit system, then new legislation may be needed to encode this societal value, or to clarify Constitutional principles. But it should be a governance and policy decision, not an accidental consequence of "tech" infrastructure.
Let's remember that "Covid Contact Tracing" via phones was not especially successful in adoption or changing of outcomes. Even when tracing data was available, some local governments made decisions which ignored the data. Yet, every phone now carries closed-source binaries to track not only the human user, but neighboring devices belonging to humans. With this track record of non-utility, what is the justification for expanding health surveillance interoperability to every aspect of online, offline and economic life?
A blockchain system makes sense for a distributed record of a web of trust. Instead of a coin and proof of stake, a proof of population based algorithm would allow nodes to join a network.
Such a network could form the basis of any government function and cryptographically protected personal data. You could add trustless age verification for porn sites, for example. Or it could allow checking the vaccination status for college entry, or so on. In the case of identity theft, it should be possible to allow law enforcement or some official entity the ability to issue a new identity key, and revert or modify any changes in private data, flagging the poisoned entries in the blockchain.
Anyway, the point is : it doesn't have to be perfect, it just has to be better than the shitshow we have now. We can eliminate SSNs and do a pretty good job of implementing cryptographically secured trustless identity. We can build a system that maintains privacy as a fundamental principle instead of trying to tack on post-hoc reactive solutions that are always too little too late.
Once these systems are deployed, how can we guarantee ongoing transparency of policy debates and citizen-tax-representative governance and admin/config/security changes?
Without ongoing feedback loops that evaluate systems against explicit democratic principles, there is risk of network effects where early policy choices become difficult or impossible to change after many parties have implemented local systems. In that scenario, early system design could become a far-reaching target for lobbyists and techno-regulatory capture.
Anti-theft and anti-abuse functionality needs to be baked in from the ground up, so that individuals have total control over their data, with governments able to maintain some absolutely minimal necessary baseline of record keeping.
For example: A health department could build a vaccination status verification system, and be provided by the local government with the ability to signa citizen's record. Participation needs to be voluntary and easily reversible. At the same time, the health department should have an ephemeral record from which an accidentally reversed or deleted signature can be recovered. If someone gets their ID stolen, they can go to their local courthouse, get a new ID key, synchronize everything up to the time right before the compromise, sign off on deactivating the old key, and continue on with life.
Not only does it have to be private and secure, it has to allow for human fallibility and malice.
A system like this could be the basis for controlling law enforcement access to biometrics. If you have no criminal record, all fingerprint and DNA and other data could be restricted without a warrant, or voluntary participation, or legally structured access. Things like this would eliminate the practice of fingerprinting children, using facial recognition or DNA dragnets without explicit judicial permissions, meaning law enforcement access has to be baked in. If done right, it could mean every piece of information could be cryptographically segregated, and a record stored within the blockchain, forcing accountability in any government access and use of private data.
Best of all, it would allow secure digital voting. Instead of an election day, you could set a voting week or even month during which every citizen has the opportunity to cast their vote, then verify their selections. People would need to use the extended time frame to ensure their vote is accurate and their keys secure, and only have to go to a polling location if they have been compromised (or simply want to use paper. )
It would need to be wargamed extensively and over the course of at least a year, but we should be leveraging the best technology has to offer. It just needs to be better than what we have, and that's an abysmally low bar.
And how about CBDC? It seems that there's a (strong?) link between Hyperledger and the WEF.[2][3]
I doubt Linus would condone such things! Oh, wait...[4]
Gah, conspiracies upon conspiracies :-) .
[0] https://linuxfoundation.org/join/members/ [1] https://www.lfph.io/ [2] https://www.weforum.org/people/brian-behlendorf [3] https://www.hyperledger.org/event/world-economic-forum [4] https://www.weforum.org/people/linus-torvalds
Is there a directory of all "WEF People", other than a web search for the URL fragment? https://duckduckgo.com/?q=site%3Aweforum.org%2Fpeople
WEF has been kind enough to release public media about their visions, e.g. last week's video envisioned people's lives being rebuilt around "neighborhood hubs" that are 15-min walking distance from their home offices, containing gym and bars, but no restaurants since those will be replaced by ghost kitchens. They envision biometric ID of each human by their heartbeat [already specified in the upcoming 2024 IEEE Wi-Fi standard that will allow consumer routers to "see through walls" with doppler imaging], https://twitter.com/wef/status/1427721919483326470
One challenge for those not shopping for what WEF is selling is the lack of institutions to champion alternative visions. E.g. until that WEF video, I had no idea the "15-min city" (smart gulag?) was endorsed by urban planners, https://www.cnu.org/publicsquare/2021/02/08/defining-15-minu.... As a point of comparison, that would be a radius of ~1km, 80% smaller than the 5km home lockdown zones in Victoria, Australia, https://www.theage.com.au/politics/victoria/what-the-new-cor...
Indeed they've been very kind with releasing their agenda. :) Schwab's "The Great Reset" book is a roadmap for the next steps, and the WEF is following up with more media-friendly content regularly.[3]
I suspect that Schwab either is a very productive author who made excellent use of his lockdown time, or the Great Reset manuscript was sitting in his ghostwriter's desk, and just got "COVID-19" prepended to its title.
Also, re: the "neighborhood hubs". Really? These already existed, they were called, eh let me think -- neighborhoods. But yeah, I like your take on it as a "smart gulag", seems to capture the whole idea nicely.
I'm squinting really hard, but can't see any non-dystopian outcome. Sure, we'll put on a smile -- even with a mask on, it's a requirement, and the WiFi routers are ubiquitous, they're looking at us,[4] and they can tell when you're not smiling,[5] so we'll have to.
(OK, perhaps I'm stretching it with SENS being able to detect smiling, though apparently it does detect gestures.)
[0] https://www.weforum.org/partners
[1] https://www.weforum.org/people/
[2] https://www.amazon.com/o/asin/2940631123
[3] https://www.weforum.org/focus/the-great-reset
[4] https://beyondstandards.ieee.org/ieee-802-11bf-aims-to-enabl...
[5] https://www.theregister.com/2021/03/31/wifi_devices_monitori...
If you haven't already seen the historical archives of IIW meetings and the Project VRM mailing list, they sometimes have in-depth discussions by recognizable names in the digital identity industry, including some with leadership roles on upcoming specs: https://cyber.harvard.edu/lists/arc/projectvrm & https://cyber.harvard.edu/projectvrm/Main_Page & https://internetidentityworkshop.com/
Governments can change for the worse, and it will suck if they change in a way that makes you the receiving end of their wrath. However, the biggest state power that can be turned against you is their monopoly on violence. Who cares if they can surveil you, if they can just threaten to execute your friends and family unless you give them what they want?
Sometimes, we computer people see everything through the lens of computers that we forget larger, non-computer consequences.
The Stasi, the East German secret police, had the same guns as officials have in free countries, the difference seemed to be the effort they put into surveillance. Technology enables so much more of that.
Yes.
The instrumentalization of western states is so good the populace might as well be a crop.
We are fucked. I am reminded of Elon Musk remarking that people in China seem very motivated and grounded compared to Americans because Americans have had it too good for too long. I have felt the same way for many years.
Americans today haven’t experienced a depression, a real war, a dictatorship or a collapse of government. They haven’t experienced anything besides being the largest, richest first-in-the-queue country and they are in for the rudest awakening in human history.
The way to deal with surveillance is counter surveillance: watch the watchers. Abusive behavior is a lot harder if you can't do so without being observed by countless others and being exposed. A lot of surveillance right now is being done by shadowy government agencies, foreign nations, some big corporations, terrorists, criminals, etc. It's very one sided. Once that stops being one sided, we can control it.
It's also an arms race. Everybody is watching each other, their own citizens/subordinates/etc. People in power are rightfully concerned about being under surveillance themselves. Because they probably are. We've had a few high profile cases of e.g. the German chancellor being under surveillance by what was supposed to be an ally.
The logical outcome of such an arms race is surveillance technology becoming a widespread commodity. Commoditization means things get a lot cheaper. So, inevitably there will be a lot more entities engaging in mutual surveillance just because they can.
Those doing the surveillance will themselves become obvious targets for surveillance. You can watch but you can't do so without risking being exposed. That changes the game. Because now abuse of surveillance technology has a price and a risk. And you can't ever be certain nobody is watching.