The ethics of the Guardian's Whisper bombshell
m.cjr.org
m.cjr.org
Everyone who had seen the stuff going on but didn't blow the whistle.
I understand the people who did the deed - according to the description "A team headed by Whisper's editor-in-chief, Neetzan Zimmerman" - they had some rather obvious profit motivation. I understand the people at The Guardian - they simply did the right thing. But everybody else at Whisper and their guests and passersby who had seen this happen - you suck. If you see your employer do slimy stuff, and put your "loyalty" as a reason to let it be, then you're as slimy and deserve to be associated with the slime and blamed for it, and I hope they're paying an appropriate price for selling your conscience.
If you see your acquaintance (or a company you're visiting or investing in) doing bad stuff, and simply do nothing, then that's not calling being a passive bystander - it's called being an accomplice, and you deserve to be treated as co-guilty.
I can very much understand why they likely chose to do a bad thing and I can't claim that given their specific circumstances I woudn't do the same in their shoes - but yes, it is still justified to claim that they did do a bad thing.
Knowing the specifics of the people I'm condemning clarifies the justification and reasons for behaving the way they did but it cannot make their conscience clean. Having good personal reasons for behavior that hurts others is an understandable mitigating circumstance, but the actions should still be condemned by the wider society.
As I've gotten older I've grown increasingly disgusted by how easily we as humans can rationalize being involved in quite a lot of obviously scammy behavior as long as:
A && (B || C)
A) we are gaining from it, monetarily
B) we can pseudo-rationalize it by saying "well, what these other people are doing or did is worse..."
C) We can shift responsibility to the people who are being scammed for not "knowing better" or making better decisionsWouldn't all of the Whisper employees be covered by the monetary motive clause (i.e. they are getting a paycheck)?
Doesn't make a lot of sense to me. Pretty sure, as always, the people who deserve the most shame are the ones who are directly responsible.
Maybe this was intended to mean that their behavior was logical, not that it was excusable.
The Guardian is a newspaper, it acted exactly how it should have.
If I knowingly invite a cop into my house and I've got a pound of cocaine on my coffee table. Is it unethical for the cop to arrest me? No. They're a fucking cop!
If you don't want people knowing shady parts of your business, don't invite people who make a living publishing stories about shady goings on!
(By the way, I apologize -- I mis-clicked when upvoting your comment, and had to upvote a few past comments to rectify the error. I posit my poor hand-eye coordination is the result of either too many espressos or not enough; I'll pull a few more shots and report back on the results.)
We'll get through this. :)
What is wrong with Guardian's reporting on Whisper's? As this article shows, nothing at all. Good for them to break open this cabal and report user's best interests, and not being worried about getting lampooned on by "new" media. Good on CJR for this write-up, I very well appreciate it. Guardian acted like journalists here.
[1] - http://www.sec.gov/litigation/complaints/comp18115b.htm [2] - http://www.sec.gov/news/press/2003-56.htm
Well i found this interesting article:- http://www.theregister.co.uk/2014/10/20/whisper_doorstepping
- They track your location regardless of stated preferences
- They store "anonymous" messages indefinitely
- They share contents of said messages with the media when it's profitable for the corporation
- They freely share data with the US, UK and Chinese governments
- They track users with a high potential for juicy posts "for life"
- They lie about all of the above (though their terms have been updated since the Guardian revelations)
Obviously they store the messages that their users submit to them. Their data retention should be spelled out in their ToS, and it's not clear if they are violating their own policies here. But take, for example, when Google a while back made a very concerted effort to ensure that deleting an email in Gmail actually meant the email would be deleted from all backups system-wide in some reasonably short timeframe (some number of days/weeks). However, prior to this, and in almost all databases worldwide, you will find that clicking 'Delete' doesn't actually remove the item from backups, and backups are kept for quite a long time / indefinitely.
An anonymous post is not necessarily a secret post, they are two different concepts entirely. I've never used Whisper, but when you post something there, I believe it is entirely public. On the face of it, there should be no more an issue sharing a tweet than sharing a whisper. To the following point, I would need to understand what private data they are sharing, not simply that they are featuring specific public posts. If they do feature a post, it makes sense for them to do some due diligence on the veracity of the claims. Honestly, I'm not sure how I feel about them using GeoIP databases as part of that diligence. If someone makes a post to Whisper without using Tor then they have certainly given their IP address away completely willingly, but I'm not sure what restrictions on use of that IP are expected by Whisper, or by any site in general which logs IPs (all of them).
Whisper, very similar to Snapchat, both promise the impossible. If you understand that technically their core feature is not actually possible, you try to understand why do people use it anyway. Either they truly thought they were getting the impossible, or there's value to the platform anyway. With Snapchat, you can see how they are trying to reframe the issue from truly secure ephemerality to simply a user interface which focuses on the present and discards the past. Similarly, Whisper is trying to reframe the issue from truly secure anonymity, to simply a user interface which doesn't include usernames / identity.
Unless you are a trained professional practicing perfect opsec, you are not anonymous on the internet. It's wrong and potentially dangerous that Whisper is making people feel like they are perfectly anonymous, but I almost wonder why anyone on HN would be surprised by any of this? As a cryptographer, I expect every piece of information I submit/leak to be used against me, so given there's literally nothing about Whisper that provides any security whatsoever, my expectation going into it would be that I am getting none. I get that my perspective is completely different from the average user on this.
If someone told me the corner grocery store was selling deadly food, I would be just as likely to believe them as someone telling me that posting on Whisper.sh keeps me securely anonymous on the internet.
If you have a rudimentary technical understanding of the internet, it's clear that the default assumption should be that you're identified unless presented with strong evidence/reasoning to the contrary. But what percentage of internet users do you think have any technical understanding of the internet? 20-30 percent, maybe? To most people it's basically magic, and they have no compelling reason to give any thought to how it works.
Regulations should be designed with the common user in mind, not the technically proficient. If a company claims that they provide anonymity, they should live up to that promise or be prosecuted for false advertising.
The closer the general response to this story is "Well, duh" I think the better.
The Guardian acted completely unethically as a business partner.
Another reason why introducing profit motives into a news organization is a recipe for trouble. Conflicts of interest like this are just too common.
http://www.theguardian.com/commentisfree/2014/jun/17/iraq-wa...
Even if your business partner is not a newspaper, if you show them something highly unethical in secret, it is not unethical for them to end the partnership by passing on what they know, whether publicly, or to regulators, or to the police.
If some other business partner was shown the same thing as Guardian but chose to disregard it due to their business relationship, then I will consider them as unethical themselves, much more so if they took any active measures to hide it, such as a manager implying to their subordinate that they should keep their mouth shut about their ethical feelings re: their partner's behavior.
Blowing the whistle on illegal behaviour is generally not considered unethical. The relationship to the other person or organisation doesn’t really matter.
(a) At all expensive to run.
(b) Funded by investors who demand a return.
(c) Has no visible means of direct revenue.
... then you REALLY need to ask the following question immediately before deciding to use it or what to entrust it with:
"How is it monetizing me?"
If you see an app or service like this, you are the product. It's either tracking you, spying on you, selling your data, somehow targeting you for advertising, or doing something else of a similar nature.
Would a majority of journalists would feel this story was damaging enough to the public that they had an obligation to publish it? Probably.
Should we feel bad for the public personas who are being taken to task for expressing an opinion that ended up on the wrong side of the issue? To some degree, yes. While these avatars did seek out the relative fame that now shames them, their mistaken logic forces the projection of humanity that twitter and blogs represent to consider both sides, and pause.
edit - for example, if a journalist is investigating a crime and you offer to give them information as long as it stays off the record and they agree, but then you tell them you committed the crime they are trying to investigate, they have no obligation whatsoever to keep what you said to them off the record.
What makes this an interesting case study in journalism ethics is that they weren't off the record, but whether you can ethically act in your capacity as a journalist in the middle of strategic business negotiations. The two are opposing interests, so to the extent I think I'm in a business meeting with The Guardian Company I'm probably also not thinking I'm the lead in their next story.
To turn it around a bit more, would it be OK for Guardian to go into Whisper under false pretenses, knowing they have no interest in a partnership, but in order to gather facts for a story? Surely they are entitled to do that form of investigative reporting, but likewise they shouldn't be surprised if that blows back on them the next time they want to form a strategic partnership with someone.
Of course there is, for instance if someone was threatening to harm you or others, it really wouldn't matter if you had agreed to keep things off the record. There is a difference between professional discretion and complicity.
edit - you described the tactics they possibly used and the potential strategic blowback, but ethically you answered your question for yourself already when you conceded that they are entitled to do that form of investigative reporting. They are a newspaper.
Apparently this is a universe where a lot of people think it's unacceptable for journalists to report on information they learned in a business meeting. I wonder what else has changed.
I understand why someone wouldn't want to burn bridges, but when their strategy for protecting access preempts any reporting ever, they cease to be performing any journalistic function. They're just hangers-on.
IF Public Interest >= Physical + Mental Damage / Reputational Damage to "source" THEN = Publish ELSE redact LOOP
Many have expressed doubt that the media reaction would be the same if Kristen Stewart's photos were leaked instead.
They had a bit of a surprise when the judge told them that there is no such thing as a public interest defence under the criminal law they were accused of.
The phone hacking law (RIPA) doesn't include that option.
But the ultimate authority in British Crown Court trials is the jury, and if a lawyer can persuade a jury that a public interest defence is valid, that will swing a trial.
Most of the phone hacking cases couldn't argue public interest because there wasn't any - it was random information gathering that could be useful in news stories and (allegedly) in other ways.
There was no equivalent of the Profumo Scandal of the 60s, which would surely have counted as a public interest case.
(Which is not to say equivalent scandals weren't found, but that if they were the press never revealed them.)