Categories
Aside Quotations

Hyper-Regulated Mass Surveillance

The difficult project of establishing meaningful oversight would be aided by a deeper appreciation by all sides of the surveillance debates that their adversaries are generally acting in good faith. Too often it seems that we occupy parallel universes. In the first, the U.S. intelligence community operates in a framework so regulated and constrained that it should be the envy of the world, not the target of its scorn. No intelligence agency in the world can match our respect for rules and laws. In the second, the U.S. surveillance state has outgrown legal restraints and allowed its surveillance activities to be driven by technological capabilities. It developed and deployed a global system of mass surveillance without the knowledge or consent of the public, and it is sitting on massive databases of private information that constitute a genuine threat to free societies.

We should acknowledge the possibility that both of these pictures are largely accurate. The intelligence community is staffed by honorable public servants who have an abiding respect for the Constitution. And history gives us reason to be concerned that information collected for one purpose will likely be put to other purposes, particularly in the aftermath of a terrorist attack or other national trauma. We might even elect a president who has no regard for the rule of law.

–Ben Wizner, ACLU

The question of how to draft a system of secret rules while simultaneously ensuring that the actors solely operate within the realm of the rules continues to vex policymakers, academics, politicians, and lawyers. What definitely seems to not work is maintaining a veil of secrecy over the baseline set of rules themselves, to say nothing of cloaking the interpretations of those rules in their own layers of secrecy.

Categories
Links

Making Game of Thrones Sensible

M.G. Siegler had a terrific suggestion for making Littlefinger’s death more meaningful and interesting:

In the scene itself, as Sansa calls out Littlefinger as the conspirator, rather than having him grovel as he does before dying, I would have had him play his one final card: he knows that Jon Snow is not a Stark. As Arya draws the blade, he could let slip that “Jon is not your brother” to not only Sansa and Arya (who still do not know this) but also to all the lords in Winterfell who are present to overhear. This plants a seed in the head of the girls, but more importantly it calls into question the leadership of The North.

Littlefinger’s demise was particularly pathetic: it made little sense as to why the Stark women acted as they did, nor was it apparent how Littlefinger managed to lose everything so quickly given his own planning and resiliency. Had he at least inserted a final barb as he died, the viewer would have the pleasure of watching the effects in the final season. Unfortunately that’s a lost pleasure so we’re just left with are dragons, the dead, and (almost certainly) betrayal and mayhem.

Categories
Links Writing

The Role of Link Posts

One of the things that I’ve thought a lot about over the past few years are link posts. I’ve tried numerous different platforms and ways of sharing and commenting on links. And something that I’ve always appreciated are blogs that combine different forms of content (including link posts) along with something else to give them some unique perspective on the content of interest to their authors.

Gabe Weatherhead has recently written that:

It’s far too easy to grab a story headline streaming by and create a link post.

…

The reason I’ve walled off Macdrifter link articles behind Hobo Signs was because I wanted to clearly show that they weren’t my work. They are source materials. There is no guarantee I’ve reviewed them or even thought much about them. Sometimes I provide commentary but often they are just links.

I like link articles as much as the next person. But I felt disingenuous mixing those on a site that also provided commentary and opinion. It blurred lines I didn’t want to blur at a time when regurgitation looks like the successor to original content on the web. I don’t wonder why indie blogs are dying any more. Link posts are killing them.

I don’t think that link posts are necessarily killing indie blogs. I think that the problem is that indie blogs are often so replete with them that there isn’t a clear voice, narrative, or expertise associated with the comments on the links.

But link posts also raise the question about who blogging is for, and what we mean to do when blogging. Twitter and Facebook are fluid publication spaces: it can be impossible to see what you wrote on those platforms, about different topics, whereas its comparatively easy to retroactively see what you’ve written about on (most) structured blogging platforms. You can build a body of work that includes a shifting, or development, of thoughts and ideas over time. At the very least, you can turn Google search onto a blog and dredge up the various posts related to your search query to try to divine how your thoughts have changed over time. That’s next to impossible on more transient social media.

While commercial (or commercially-motivated) indie blogs might suffer from link posts I’m not convinced that such posts are kryptonite to personal blogs. And even for those which are commercially-oriented it’s not self-evident that link posts are bad: for the big indie blogs, the authors operate as tastemakers and news curators. They can quickly indicate their pleasure or displeasure where a fully review is unnecessary, or surface news of interest to them and their readers without requiring a detailed analysis of the issue at hand. Admittedly breaking news or entirely novel products may be ill served by such hot takes, but fast and short posts are routinely useful to their readership. The trick is to have a sufficiently interesting and authoritative voice that someone wants to read the author’s work in the first place. And that’s a space where most authors routinely struggle, indie writers or not.

Categories
Writing

WhatsApp Profits

Facebook’s purchase of WhatsApp made sense in terms to buying a potential competitor before it got too large to threaten Facebook’s understanding of social relationships. The decision to secure communications between WhatsApp users only solidified Facebook’s position that it was less interested in mining the content of communications than on understanding the relationships between each user.

However, as businesses turn to WhatsApp to communicate with their customers a new revenue opportunity has opened for Facebook: compelling businesses to pay some kind of a fee to continue using the service for commercial communications.

WhatsApp will eventually charge companies to use some future features in the two free business tools it started testing this summer, WhatsApp’s chief operating officer, Matt Idema, said in an interview.

The new tools, which help businesses from local bakeries to global airlines talk to customers over the app, reflect a different approach to monetization than other Facebook products, which rely on advertising.

This is Facebook flipping who ‘pays’ for using WhatsApp. Whereas in the past customers paid a small yearly fee, now customers will get it free and businesses will be charged to use it. It remains to be seen, however, whether WhatsApp is ‘sticky’ enough for consumers to genuinely expect businesses to use it for customer communications. Further, Facebook’s payment model will also stand as a contrast between WhatsApp and its Asian competitors, such as LINE and WeChat, which have transformed their messaging platforms into whole social networks that can also be used for robust commercial transactions. Is this the beginning of an equivalent pivot on Facebook’s part or are they, instead, trying out an entirely separate business model in the hopes of not canibalizing Facebook itself?

Categories
Links

Plant Memories

Europeans citizens and their settlers have long treated the natural world as mere ‘stuff’ that can be manipulated to achieve our human-centric ends. It wasn’t that long ago that animals were regarded as dumb beasts without the ability to genuinely feel pain or have thoughts or memories. It turns out that our presumptions of plants are similarly undergoing radical reevaluations by some in the scientific community.

After training the plants, Gagliano withheld the light. When she next turned on the fans, she had switched them to the opposite branch of the Y shape. She wanted to see if the plants had learned to associate airflow with light, or its absence, strongly enough to react to the breeze, even if it was coming from a different direction, with no light as a signal. It worked. The plants that had been trained to associate the two stimuli grew toward the fan; the plants that had been taught to separate them grew away from the airflow.

“In that context, memory is actually not the interesting bit—of course you have memory, otherwise you wouldn’t be able to do the trick,” she says. “Memory is part of the learning process. But—who is doing the learning? What is actually happening? Who is it that is actually making the association between fan and light?”

It’s telling that Gagliano uses the word “who,” which many people would be unlikely to apply to plants. Even though they’re alive, we tend to think of plants as objects rather than dynamic, breathing, growing beings. We see them as mechanistic things that react to simple stimuli. But to some extent, that’s true of every type of life on Earth. Everything that lives is a bundle of chemicals and electrical signals in dialogue with the environment in which it exists. A memory, such as of the heat of summer on last year’s beach vacation, is a biochemical marker registered from a set of external inputs. A plant’s epigenetic memory, of the cold of winter months, on a fundamental level, is not so different.

It’s absolutely amazing to learn how much we do not know, and similarly striking that so many people actively work to prevent scientists from learning more about the natural world.

Categories
Links Photography

National Geographic Photos of the Year

These are absolutely amazing shots; I have to admit my preference for the People’s Awards is definitely ‘Colourful Markets’. The vibrancy of the image combined with the elevated angle of the shot is really magical.

Categories
RPG

See the Sketches J.R.R. Tolkien Used to Build Middle-Earth

Many of these are amazing, in that they show how one of the most adored fantasy world’s maps began just as those used in most homebrew D&D games.

Categories
Links

Cider Profiles

 AV Club:

English ciders, for example, tend to be still, dry, and higher in alcohol than most ciders. (English ciders are often considered the red wine of the cider world.) Spanish ciders are more often compared to sour beers, with a funkier taste. French ciders are the most approachable of European ciders, as they have a champagne-like sparkle and are lower in alcohol content. Terroir isn’t all that differentiates European ciders from American ones, however, as their use of wild yeasts results in a bolder, more offbeat flavor profile.

American ciders are harder to pin down, as the unique processes brewers have been applying to craft beer—barrel-aging, hopping, the addition of spices and other fruits—are also being used by cider makers, resulting in a variety of different tastes. What most American ciders have in common, however, is lightness, crispness, and an easy-going approachability.

As someone who appreciates well-crafted beers and liquors, and has recently tried to get into cider, this is really helpful in orienting myself. Thus far I think my preferred kind of cider tends to be semi-experimental (I had a truly delightful gin barrel-aged dry cider earlier this summer) but knowing what to look for in flavour profiles is definitely helpful going forward.

Categories
Writing

Thoughts on 1Password ‘Home’ Edition

People are worried that someone’s going to steal their data or secretly access their personal devices. Border agents are accessing devices with worrying regularity. Travellers are being separated from their devices and electronic when they fly. Devices are stolen with depressing regularity. And then there’s the ongoing concern that jealous spouses, partners, or family members will try to see with whom their partner’s been emailing, Snapchatting, or Whatsapping.

Few people are well positioned to defend against all of these kinds of intrusions. Some might put a password on their device. Others might be provided by updates for their devices (and even install the updates!). But few consumers are well situated to determine which software is better or worse in terms of providing security and user privacy, or make informed decisions about how much a security product is actually worth.

Consider a longstanding question that plagues regular consumers: which version of Windows is ‘the most secure’? Security experts often advise consumers to encrypt their devices to prevent many of the issues linked to theft. Unfortunately, only the professional or enterprise versions of Windows offer BitLocker, which provides strong full disk encryption.1 These professional versions are rarely provided by-default to consumers when they buy their laptops or desktops — they get the ‘Home’ editions instead — because why would everyday folks want to encrypt their data at rest using the best security available? (See above list for reasons.)

Consumers ask the same security-related questions about different applications they use. Consider:

  • Which messaging software gives you good functionality and protects your chats from snoops?
  • Which cloud services is it safe to store my data in?
  • Which VoIP system encrypts my data securely, so no one else can listen in?
  • And so on…

Enter the Password Managers

Password managers all generally offer the same kind of security promises: use the manager, generate unique passwords, and thus reduce the likelihood that one website’s security failure will result in all of a person’s accounts being victimized. ‘Security people’ have been pushing regular consumers to adopt these managers for a long time. It’s generally an uphill fight because trusting a service with all your passwords is scary. It’s also a hill that got a little steeper following an announcement by AgileBits this week.

AgileBits sells a password manager called ‘1Password’. The company has recognized that people are worried about their devices being seized at borders or about border agents compelling people to log into their various services and devices. Such services could include the 1Password, which is pitched as a safe place to hold your logins, credit card information, identity information, and very private notes. Recognizing the the company has encouraged people to store super sensitive information in one place, and thus create a goldmine for border agents, AgileBits has released a cool travel mode for 1Password to reduce the likelihood that a border agent will get access to that stash of private and secret data.

1Password Home Edition

But that cool travel mode that’s now integrated into 1Password? It’s only available to people who pay a monthly subscription for the software. So all those people who were already skeptical of password managers and who it was very hard to convince them to use a manger in the first place but who we finally got to use 1Password or similar service? Or those people who resist monthly payments for things and would rather just buy their software once and be done with it? Yeah, they’re unlikely to subscribe to AgileBit’s monthly service. And so those users who’ve been taught to store all their stuff in 1Password are effectively building up a prime private information goldmine for border agents and AgileBits is willing to sell them out to the feds because they’re not paying up.

People who already sunk money into 1Password to buy the software are, now, users the 1Password Home version. Or to be blunt: they get the segregated kinds of security that Microsoft is well known for. It’s disappointing that in AgileBits’ efforts to ‘convert’ people to ongoing payments that the company has decided to penalize some of its existing user base. But I guess it’s great for border agents!

I’m sure AgileBits and 1Password will survive, just as Microsoft does, but it’s certainly is a sad day when some users get more security than others. And it’s especially sad when a company that is predicated on aggregating sensitive data in one location decides it would rather exploit that vulnerability for its own profit instead of trying to protect all of its users equally.

NOTE: This was first published on Medium on May 24, 2017.


  1. 1 Windows 8 and 10 do offer ‘Device Encryption’ but not all devices support this kind of encryption. Moreover, it relies on signing into Windows with a Microsoft Account and uploads the recovery key to Microsoft’s servers, meaning the user isn’t in full control of their own security. Unauthorized parties can, potentially, access the recovery key and subsequently decrypt computers secured with Device Encryption. ↩︎
Categories
Writing

When ‘Contact Us’ Forms Becomes Life Threatening

Journalists targeted by security services can write about relatively banal subjects. They might report on the amount and quality of food available in markets. They might write about the slow construction of roads. They might write about dismal housing conditions. They might even just include comments about a politician that are seen as unfavourable, such as the politician wiped sweat from their brow before answering a question. Risky reporting from extremely hostile environments needn’t involve writing about government surveillance, policing, or corruption: far, far less ‘sensitive’ reporting can be enough for a government to cast a reporter as an enemy of the state.

The rationale for such hyper-vigilance on the part of dictatorships and authoritarian countries is that such governments regularly depend on international relief funds or the international community’s decision to not harshly impede the country’s access to global markets. Negative press coverage could cut off relief funds or monies from international organizations following a realization that the country lacks the ‘freedoms’ and ‘progress’ the government and most media publicly report on. If the international community realizes that the country in question is grossly violating human rights it might also limit the country’s access to capital markets. In either situation, limiting funds available to the government can endanger the reigning government or hinder leaders from stockpiling stolen wealth.

Calling for Help

Reaching out to international journalism protection organizations, or to foreign governments that might offer asylum, can raise serious negative publicity concerns for dictatorial or authoritarian governments. If a country’s journalists are fleeing because they believe they are in danger, and that fact rises to public attention, it could negatively affect a leader’s public image and the government’s access to funds. On this basis governments may place particular journalists under surveillance and punish them should they do anything to threaten the public image of the leader or country. Such surveillance is also utilized when reporters who are in a country are covering, and writing about, facts that stand in contravention to government propaganda.

The potential for electronic surveillance is particularly high, and serious, when the major telecommunications providers in a country tend to fully comply with, or willingly provide assistance to, state security and intelligence services. This degree of surveillance makes contacting international organizations that assist journalists risky; when a foreign organization does not encrypt communications sent to it, the organization’ security practices may further endanger a journalist calling for help. One of the many journalists covered in Bad News: Last Journalists in a Dictatorship who feared his life was in danger by the Rwandan government stated,

[h]e had written to the Committee to Protect Journalists, in New York, but someone in the president’s office had then shown him the application that he had filled out online. He didn’t trust people living abroad any longer.” (Bad News: Last Journalists in a Dictatorship, 83-4)

Such surveillance could have taken place in a few different ways: the local network or computer the journalist used to prepare and send the application might have been compromised. Alternately, the national network might have been subject to surveillance for ‘sensitive’ materials. Though the former case is a prevalent problem (e.g., Internet cafes being compromised by state actors) it’s not one that international journalist organizations are well suited to fix. The latter situation, however, where the national network itself is hostile, is something that media organizations can address.

Network inspection technologies can be configured to look for particular pieces of metadata and content that are of interest to government monitors. By sorting for certain kinds of metadata, such as websites visited, content selection can be applied relatively efficiently and automated analysis of that content subsequently be employed. That content analysis, however, depends on the government in question having access to plaintext communications.

Many journalism organizations historically have had ‘contact us’ pages on their websites, and many continue to have and use these pages. Some organizations secure their contact forms by using SSL encryption. But many organizations do not, including organizations that actively assert they will provide assistance to international journalists in need. These latter organizations make it trivial for states that are hostile to journalists to monitor in-country journalists who are making requests or issuing claims using these insecure contact forms.

Mitigating Threats

One way that journalism protection organizations can somewhat mitigate the risk of government surveillance is to implement SSL on their websites, which encrypts communications sent to the organization’s web server. It is still apparent to network monitors what website was visited but not which pages. And if the journalist sends a message using a ‘contact us’ form the data communicated will be encrypted, thus preventing network snoops from figuring out what is being said.

SSL isn’t a bulletproof solution to stopping governments from monitoring messages sent using contact forms. But it raises the difficulty of intercepting, decrypting, and analyzing the calls for help sent by at-risk journalists. And adding such security is relatively trivial to implement with the advent of free SSL encryption projects like ‘Let’s Encrypt’.

Ideally journalism organizations would either add SSL to their websites — to inhibit adversarial states from reading messages sent to these organizations — or only provide alternate means of communicating with them. That might mandate email, and list hosts that provide service-to-service encryption (i.e. those that have implemented STARTSSL), messaging applications that provide sufficient security to evade most state actors (everything from WhatsApp or Signal, to even Hangouts if the US Government and NSA aren’t the actors you’re hiding from), or any other kind of secure communications channel that should be secure from non-Five Eyes surveillance countries.

No organization wants to be responsible for putting people at risk, especially when those people are just trying to find help in dangerous situations. Organizations that exist to, in part, protect journalists thus need to do the bare minimum and ensure their baseline contact forms are secured. Doing anything else is just enabling state surveillance of at-risk journalists, and stands as antithetical to the organizations’ missions.

NOTE: This post was previously published on Medium.