Categories
Links

Lessig Blog, v2: Prosecutor as bully

lessig:

Boston Wiki Meetup

(Some will say this is not the time. I disagree. This is the time when every mixed emotion needs to find voice.)

Since his arrest in January, 2011, I have known more about the events that began this spiral than I have wanted to know. Aaron consulted me as a friend and lawyer. He shared with me what went down and why, and I worked with him to get help. When my obligations to Harvard created a conflict that made it impossible for me to continue as a lawyer, I continued as a friend. Not a good enough friend, no doubt, but nothing was going to draw that friendship into doubt.

The billions of snippets of sadness and bewilderment spinning across the Net confirm who this amazing boy was to all of us. But as I’ve read these aches, there’s one strain I wish we could resist:

Please don’t pathologize this story.

No doubt it is a certain crazy that brings a person as loved as Aaron was loved (and he was surrounded in NY by people who loved him) to do what Aaron did. It angers me that he did what he did. But if we’re going to learn from this, we can’t let slide what brought him here.

First, of course, Aaron brought Aaron here. As I said when I wrote about the case(when obligations required I say something publicly), if what the government alleged was true — and I say “if” because I am not revealing what Aaron said to me then — then what he did was wrong. And if not legally wrong, then at least morally wrong. The causes that Aaron fought for are my causes too. But as much as I respect those who disagree with me about this, these means are not mine.

But all this shows is that if the government proved its case, some punishment was appropriate. So what was that appropriate punishment? Was Aaron a terrorist? Or a cracker trying to profit from stolen goods? Or was this something completely different?

Early on, and to its great credit, JSTOR figured “appropriate” out: They declined to pursue their own action against Aaron, and they asked the government to drop its. MIT, to its great shame, was not as clear, and so the prosecutor had the excuse he needed to continue his war against the “criminal” who we who loved him knew as Aaron.

Here is where we need a better sense of justice, and shame. For the outrageousness in this story is not just Aaron. It is also the absurdity of the prosecutor’s behavior. From the beginning, the government worked as hard as it could to characterize what Aaron did in the most extreme and absurd way. The “property” Aaron had “stolen,” we were told, was worth “millions of dollars” — with the hint, and then the suggestion, that his aim must have been to profit from his crime. But anyone who says that there is money to be made in a stash ofACADEMIC ARTICLES is either an idiot or a liar. It was clear what this was not, yet our government continued to push as if it had caught the 9/11 terrorists red-handed.

Aaron had literally done nothing in his life “to make money.” He was fortunate Reddit turned out as it did, but from his work building the RSS standard, to his work architecting Creative Commons, to his work liberating public records, to his work building a free public library, to his work supporting Change Congress/FixCongressFirst/Rootstrikers, and then Demand Progress, Aaron was always and only working for (at least his conception of) the public good. He was brilliant, and funny. A kid genius. A soul, a conscience, the source of a question I have asked myself a million times: What would Aaron think? That person is gone today, driven to the edge by what a decent society would only call bullying. I get wrong. But I also get proportionality. And if you don’t get both, you don’t deserve to have the power of the United States government behind you.

For remember, we live in a world where the architects of the financial crisis regularly dine at the White House — and where even those brought to “justice” never even have to admit any wrongdoing, let alone be labeled “felons.”

In that world, the question this government needs to answer is why it was so necessary that Aaron Swartz be labeled a “felon.” For in the 18 months of negotiations, that was what he was not willing to accept, and so that was the reason he was facing a million dollar trial in April — his wealth bled dry, yet unable to appeal openly to us for the financial help he needed to fund his defense, at least without risking the ire of a district court judge. And so as wrong and misguided and fucking sad as this is, I get how the prospect of this fight, defenseless, made it make sense to this brilliant but troubled boy to end it.

Fifty years in jail, charges our government. Somehow, we need to get beyond the “I’m right so I’m right to nuke you” ethics that dominates our time. That begins with one word: Shame.

One word, and endless tears.

 

Categories
Links

Advice on Browsing the Web Safely

Global Voices has a series of good suggestions on how to browse the web safely. Many users may not need to take the more extreme precautions – such as browsing from a USB-drive mounted operating system – but other pieces of information are helpful. Well worth the (quick) read.

Categories
Links

Turning IT Into a Profit Centre

Jeffrey Carr has some amusing thoughts on transforming IT in corporate businesses from a cost to a profit centre. Just a taste of the humour:

The good news, or at least potential good news since no one is doing this yet, is that the undiscovered malware lurking on corporate networks potentially represent tens or hundreds of thousands of dollars in income for the corporation. And since it resides on the corporate network, it becomes the property of that corporation. All of a sudden, something that you’ve viewed only as a threat and an expense has become a valuable commodity thanks to the trend in selling offensive malware to government agencies.

One can easily imagine how his article, slightly reworked, would have made an excellent April fool’s column.

Categories
Links

How foreign firms tried to sell spy gear to Iran

Steve Stecklow is one of the few reporters that has continued to write about Iran’s acquisition of surveillance equipment for the past several years. At this point he has a good grasp of how the technology gets into the country, what’s done with it, and why and how vendors are evading sanctions. His article earlier this year provides a good look at how Huawei and ZTE alike have sold ‘lawful intercept’ equipment to the Iranian government. I’d highly recommend taking a look at what he’s written.

Categories
Links

Incredibly Detailed Outing of Android UI Problems

Ron Amadeo has a terrific and comprehensive post on all the various Android UI issues. Well worth the read if UI and UX is something you pay attention to.

Categories
Links

The issue here is that data reduced to paper form loses much of its usefulness. The effect is to take power away from the recipient of the data (and by extension in this case from you as a citizen) and conserve it in a government institution as much as possible. Unless the user is bloody-minded enough to re-enter it manually, which of course is only possible at a certain scale.

On the topic of Canadian FOI responses; read the blog post here
Categories
Links

Feudalism 2.0

Bruce Schneier has a clever piece discussing the contemporary model of ‘feudal security’, where user have committed themselves to differing lords of the Internet. As a taste:

Some of us have pledged our allegiance to Google: We have Gmail accounts, we use Google Calendar and Google Docs, and we have Android phones. Others have pledged allegiance to Apple: We have Macintosh laptops, iPhones, and iPads; and we let iCloud automatically synchronize and back up everything. Still others of us let Microsoft do it all. Or we buy our music and e-books from Amazon, which keeps records of what we own and allows downloading to a Kindle, computer, or phone. Some of us have pretty much abandoned e-mail altogether … for Facebook.

These vendors are becoming our feudal lords, and we are becoming their vassals. We might refuse to pledge allegiance to all of them – or to a particular one we don’t like. Or we can spread our allegiance around. But either way, it’s becoming increasingly difficult to not pledge allegiance to at least one of them.

Feudalism provides security. Classical medieval feudalism depended on overlapping, complex, hierarchical relationships. There were oaths and obligations: a series of rights and privileges. A critical aspect of this system was protection: vassals would pledge their allegiance to a lord, and in return, that lord would protect them from harm.

Of course, I’m romanticizing here; European history was never this simple, and the description is based on stories of that time, but that’s the general model.

And it’s this model that’s starting to permeate computer security today.

The rest of the piece is clever; highly recommend taking a read.

Categories
Links

Municipality of Saanich Does the Right Thing on Police Surveillance

Kudos to the mayor of Saanich for, you know, obeying BC law with regards to ubiquitous license plate surveillance technologies that have been found to violate BC law. As the mayer says,

“Certainly [Saanich police] are finding it a useful tool, but because this thing is hosted by the RCMP, who isn’t subject to this oversight, there’s a glitch there,” Leonard said.

“Until it gets sorted out, we just voluntarily suspended use.”

It’s good to see ‘voluntary’ decisions to not violate BC law. Guess now we wait and see whether the other mayors of BC take similarly strong stances.

Categories
Links Writing

Belkin #Fails At Password Creation

WPA2-PSK is recognized as a pretty reasonable way for most consumer to secure their wifi access point. That said, this mechanism falls pretty flat on its face when router manufacturers screw up, and it looks like Belkin has screwed up badly. From a Register article we see that:

Each of the eight characters of the default passphrase are created by substituting a corresponding hex-digit of the WAN MAC address using a static substitution table. Since the WAN MAC address is the WLAN MAC address + one or two (depending on the model), a wireless attacker can easily guess the wan mac address of the device and thus calculate the default WPA2 passphrase.

This is just really poor mechanism to calculate the password. At least the manufacturer has been totally silent on the issue, and unwilling to disclose how they intend to defray potential attacks; this gives the possibility that Belkin’ll fix things instead of just abandoning consumers (which seems to be, sadly, a pretty default vendor response when their errors undermine users’ privacy and security). Here’s hoping that Belkin decides to not be like most router vendors…

Categories
Links

The Rationale for Retaining Passwords

Alec Muffett has a terrific piece that clearly articulates why, exactly, passwords are beneficial elements of a broader security apparatus. He also notes core ‘risks’ associated with passwords, and how many of these risks can be defrayed (spoiler alert: just use a strong password management system).