Surveillance and the Internet of Things
schneier.com
schneier.com
As Bruce says, the real issue now is not surveillance or even information, but power. Who gets to watch whom, and (of course) who watches the watchers?
I see four strategies for coping with the issue of power --
1) Default - maintain current trajectory - this is what most of us will do.
2) Withdraw - lower one's profile. This seems to be Bruce's plan.
3) Expose - bring buried secrets to light, and the watchers under surveillance. Expect harsh repercussions. The US govt has been increasingly secretive. It has been removing whistleblower protections for some years now. It has been punishing exposures of information more harshly than in the past (though I suppose the exposure of Valerie Plame might pass as an exception, unless your name is Scooter Libby.)
4) Disrupt -- frustrate the collection of information through jamming, feeding false info, deletion. But info seems to be cheap enough that bad info doesn't really hurt those using it.
I couldn't agree more.
"Fox News Reporter James Rosen’s Private Emails Given To Justice Dept. By Google"
http://apps.washingtonpost.com/g/page/local/affidavit-for-se...
1) Default - most products will (I think) continue to collect as much data as they can
2) Withdraw - I doubt most companies will withdraw from the data collection frenzy that is the current marketplace
3) Expose - There's definitely room out there for more services that expose patterns in public data, or more mechanisms for publicizing private data (the New Yorker Strongbox, for example)
4) Disrupt - One example in this space that I love are location spoofers like MediaHint, that allow users to access content that is designed to be location-locked.
It's nice because in the next update (to be released this month, v3.5), you'll be able to do things like encrypting your email and having it in two different versions of it (one for you, and one for those you don't want knowing what your actual email is). You can already do it in the current version, it's just not as user-friendly.
It will only protect data that's kept encrypted on your local drive though, so with the example of email, it doesn't protect you from the government if your email is also stored on Google's servers.
For example: we can seek to make it illegal for certain information to be tracked; we can require that any information collected be disclosed to the individual at risk of being tracked; we can expand fourth-amendment protections explicitly, forcing a warrant to be issued to collect any of the information made available through these systems, even if the data is stored on a corporate server (doing away with national security letters and administrative subpoenas, and prohibiting disclosure without a warrant); and we can impose criminal penalties on government and corporate officials that violate these rights.
And more: we can make exposure of all but the most sensitive government "secrets" mandatory by law, rather than relying on legally questionable whistle-blowing for disclosures; we can ensure that encryption technologies (and other self-protection techniques) always remain legal, and remove any requirement that backdoors be added to new communication technology; we can work to decentralize corporate power in telecom by aggressively enforcing anti-trust laws; we can improve transparency and oversight of telecom services by explicitly encouraging that high-speed data service be provided as a local public utility.
And we can reduce the incentive that exists at every level of law enforcement to undermine privacy and civil liberties (and in turn further centralize power) by making fewer things illegal--most importantly, drugs.
How are you going to get from here to there?
Start by going door to door; find people who care enough about the issue to help out; have in-person meetings and events and build connections; give people the tools--online and offline--to recruit participants and stage their own meetings; orient people towards a focused set of objectives, and ask them for money to help you broadcast those ideas with counter-propoganda; ask people to contribute time and money to candidates that support those objectives; always keep everything above board, to avoid being attacked; rinse and repeat. If enough people care, you can win; if not, then maybe "money in politics" wasn't the real hurdle to reform--maybe it's just that the voters didn't want the reform you were preaching.
Democracy today seems broken, like it doesn't work any more, but it's always been "broken," it's never "worked". The progressive movement and the labor movement of a century ago both fought an uphill battle against big money in politics. It took decades before they experienced lasting success. When voters want changes in government that cost profitable businesses money, a lot of those businesses will spend at least as much money as they stand to loose to prevent that change from happening. It was as true one hundred years ago as it is today.
The fact is, though, that absent massive violence or election fraud (which itself is only possible when the polls are tight) with all the money in the world you still need people--individual people--to vote your way. Money in US politics has influence only insofar as it can be used to convince the masses of voters to vote a certain way. The thing is that money and propaganda have limits, especially if a message of reform resonates. That's what social movements are all about--coalescing around a message of reform that makes propaganda sound unconvincing.
Only by maintaining the social stigma can we really protect ourselves.
This is, at its core, a social issue, not a technological one.
As for mandating government transparency and protecting encryption, I think those could have a lot of potential to help without unfairly limiting any person or group. And I agree, we should make fewer things illegal, which is another reason it might not be smart to make collecting consumer data illegal.
http://www.wired.com/politics/security/commentary/securityma...
It is an interesting response, although I don't think I agree with his argument. I'm not sure why they deleted it.
> Bruce, it is getting depressing to read your posts. You don't prescribe any kind of resolution such as calling your congressperson.
(I hope they were being facetious with this remark)
I know it's very cool these days in Internet-land to consider the system too broken to engage, but that seems to me to be a self-fulfilling prophecy.
Currently the only group like that I know of on technology & privacy is the EFF, but so many corporate giants have an interest in eroding your privacy that you'd need to bulk up their funding base considerably to make them able to take those giants on directly. (Or go the other direction, people-power rather than money-power, and develop a base of activists who are willing to march for privacy.)
The only way for us to protect ourselves is through political and social action.
I don't know if it is or not and I see those words spoken a lot without any sort of proof.
Maybe I'm a hermit, but I'm online every day and images associated with my name are quite scarce.
Add to that the fact that there are literally dozens of Americans who share my exact name, my privacy worries are negligle within the context proposed by the author.
That said, I do agree with the premise that surveillance is growing increasingly intrusive, thus my habits outlined above.
Though I am curious as to what that might mean - how does he use email?
The implication, at least to me, is that the only way to avoid it would be to go mountain man (I'm aware that may be a bit non-sequitor). But even that would be a wasted effort should the government, for example, decides it wants to surveil you. I've recently finished reading The Triple Agent (http://www.amazon.com/Triple-Agent-al-Qaeda-Mole-Infiltrated...) and Manhunt (http://www.amazon.com/Manhunt-Ten-Year-Search-Laden-Abbottab...). The capabilities held to detect and surveil are staggering and the abilities developed over the last decade to find and capture/kill are impressive and a bit scary.
There are plenty of things I've found worth trading my privacy for, but it's been a conscious choice every time.
Some things you really need to sign up for, like say signing up for an internet connection, but you have no choice about what happens to your data. You know almost all ISPs will roll over if any authority wants your data from them. You just have to accept it if you want the service, and often things are vital services. Its not much of a choice.
I like the way you've phrased it: not a conscious choice. I wouldn't say that ignorance is an active part in choice making. But it certainly feels less complicated.
It drags you down though. Every supermarket you go to asks for your loyalty card - which I refused to opt-in to for years, but you still are confronted with the question everytime - it gets tiresome.
I do my shopping by proxy, through a partners' loyalty card, and I've been pretty surprised at how sophisticated these systems have become.
There's a desperate battle between outlets now for custom. Loyalty cards now lead to offers (coupons) on items from the weekly shop, and our shopping basket is quite anormal I'd say. We are actually recouping some worthwhile savings, for once. Rather than being offered some promotional discount on something I have no interest in. I feel a little wrong about it, but I no longer can resist the enticement.
Ted Billson. There...use that. His email address is ted@bill.com if you get asked. ;)
Another 'fuck you money' project: a set of domains with an open SMTP server that does nothing but flip the headers around and re-send the message back to the sender.
I've been asked and politely declined probably hundreds of times by now. It's never led to any further interaction beyond my simply smiling and saying "no thank you".
The cashiers don't question it, or stare, or even miss a beat. (sometimes a 'new' person will hesitate for a second; thrown off their muscle memory pattern). But surely they hear it from more people than just me.
And I find making a shopping list beforehand, based on what I've actually used since the last trip, is more effective than coupons or loyalty cards. The coupons did start getting more properly-targeted, but they also entice purchases I hadn't previously had on my list. Which calls into question the notion of having 'saved' any money.
Similarly when I would be 'saving' money on things that are only useful when I purchase its non-special-/non-coupon-priced complements (e.g. a coupon for hotdogs leading to a purchase of regular priced buns; or a coupon for peanut butter leading to a purchase of regular-priced jelly).
(Or alternatively "abuse@localhost"? "root@127.0.0.1"? "spam@gmail.com"?)
Which means... that he's always right?
Richard Stallman is usually dismissed due to his eccentricity, but he's ALWAYS right. AL-WAYS.
I lost track on how many times I've seen the internet raging about something while I think "Richard Stallman told you so".
For example, people don't necessarily really understand basic stuff like client/server architecture and believe that their facebook profile just "is" without thinking that every time they do something on facebook a row is being added to a relational database on a computer that is somebody elses private property.
And that row will probably never be deleted regardless of how they toggle their privacy settings.
"Soon, Moore's Law will make it cheap enough to connect everything you own to the Internet - it is not a question of if, just when. All your things may or may not talk to you; but they will definitely be talking to each other about you."