Showing posts with label US. Show all posts
Showing posts with label US. Show all posts

Sunday, May 26, 2013

I am not my IP address

It appears that the major ISPs have decided to launch an "education campaign" about copyright violation.  If their filters determine someone using your IP address is uploading copyrighted content, you will get a series of increasingly firm warnings telling you that you may be breaking the law.  And, as some have pointed out, to let you know that your ISP is watching what you're doing and to leave a nice, visible paper trail saying "you were warned".

I say "copyrighted content", but in practice that probably means video, .mp3 files and such.  I doubt that they're trying to catch people uploading the text of The Hunger Games or whatever, even though that's just as copyrighted as, say, Thrift Shop.

Before going on, I suppose this is a good opportunity to repeat the disclaimer: I don't speak for my employer.  I speak for myself, at least on a good day.  Let's throw in the "I am not a lawyer" spiel while we're at it.

On the one hand, I'm not horrified by this.  It certainly seems like a better approach than previous attempts to crack down.  The ISPs certainly have some right to do such things.  Your agreement with your ISP is a private contract.  As much as we value free speech as a principle, when you're paying a private company to convey your speech, they get some say.  Restrictions imposed by your ISP are not laws of congress.  Not to say that there shouldn't be some sort of protection, but any first-amendment case would have to be aimed at the laws regulating ISPs, not at the ISPs themselves.   Outside the US, your mileage may vary ... hmm ... how do you say "your mileage may vary" outside the US?

Likewise, the studios and record labels have a right to protect their copyrights (that is, the copyrights they acquired from the people who actually created the content).  Whatever we may think of studios, record labels, publishers and such, there is a legitimate business to be done in financing, publicizing and selecting content.  The question is whether it's done well or badly, ethically or not-so-ethically, and in what cases it makes sense for the creator to take on that role personally or hire it out.

That said, I'm leery of the basic approach of tying activity to an IP address.  In a typical household, any of several people may be using a given address, and the person paying for the service is generally not going to be aware of what every person in the household is doing at all times.

Neither is it safe to assume that the only people using the IP address in question are living in the house to which the IP address is assigned.  There are plenty of insecure wifi routers out there.  For that matter, there are plenty of deliberately insecure routers out there.  Is a coffee shop with free wifi also liable for whatever its guests choose to upload?

Nor is it that hard for someone uploading copyrighted material to disguise that fact, or plausibly deny it -- and it's a good bet that someone who makes a habit of distributing copyrighted material illegally would positively enjoy confounding The Man.

In short, it looks very easy to get false positives (someone notified of suspicious uploading when it's not their fault) and false negatives (someone up to no good going unnoticed).  If the idea is to "stop piracy", it's unlikely to work any better than previous attempts.  On the other hand, if the idea is to remind people that copyrighted material is protected by law, or start a discussion between the person legally on the hook for the internet bill and the rest of the people using it, that could probably work.

Behind all this is the issue in the title: to what extent can an IP address be identified with a person?  A reasonable analog in the real world is the distinction between a car's license plate and a person's driver's license.  A license plate is associated with a person, and that person bears some legal responsibility for what happens with that car, but if you loan your car to a good friend and that friend gets pulled over for speeding, the points go on the friend's license, not yours.

If the friend runs a red light and gets caught by a camera, though, you'll get the notice, as registrant of the car.  What happens next is a bit unclear, particularly if your maybe-not-so-good friend doesn't feel inclined to step up.

The ISP case seems more like the camera case than the pulled-over case.  Just as (generally) only the car can be positively identified, only the IP address, and not the person, can be positively identified.  Again, if the idea is to educate people about copyright law and remind them that yes, companies take this seriously and, by the way, we can see what you're doing with your IP connection, that's probably OK.  But if it comes down to fining and arresting people, the IP address involved had better be just one piece of evidence in a stronger case.

Not that that's much comfort if you have to hire a lawyer anyway.

Thursday, April 18, 2013

Voices from the dashboard

All my life I've taken road trips, partly by natural inclination, partly by necessity.  It's a largely timeless experience.  Sure, the roads have improved (see the Grapevine Grade section of this page for a good example), the speed limits are higher, cars are faster and safer and there's not a lot of "local flavor" in most stopping points unless you actively seek it out, but for the most part road trips have been road trips since well before Kerouac.

One thing that has changed is the soundtrack, and not just because tastes in music have changed.  When I was a kid, any audio not provided by the car and its occupants came from the radio, and if you were on a long haul, it was the AM radio.  Keeping FM tuned in was and remains too much of a hassle.  An AM station, especially one of the "clear channel" stations (not to be confused with the media conglomerate) licensed to broadcast at high power, could be good for hours -- enough for a whole sports fixture, several runs through the news or all the whacked-out talk radio conspiracy theories you could eat.

The key feature here, particularly on a solo trip through, say, the desert southwest US, was the lack of choice.  You'd be doing well to have your pick of baseball, UFO speculation and the company of your own thoughts, and a hundred miles or so out of Albuquerque on a dark night with the game a blowout the UFO speculation starts sounding interesting and plausible.

By the time I was doing my own solo long hauls, cassette tape was an option, but a library of a few dozen albums can be limiting after a while -- and suppose you want to know what's going on in the world, or just let someone else handle the programming for a while?  The in-dash CD (briefly supplemented by a multi-disc changer in the trunk) increased one's options, but the same basic constraints applied.  Only with the advent of satellite radio was there little reason to tune in to local stations at all.

And now there's the web.  As long as you've got a smartphone, bars, a bit of cable and an aux input, you can listen to pretty much anything.  Stream your favorite home station.  Stream your favorite internet station.  Play your podcasts.  Dial up Pandora.  AM won't be completely disappearing anytime soon -- technologies written off as obsolete seldom do -- but the proportion of people who know or care must be steadily dwindling.  Likewise I'd rather not try to predict whether or when web audio will supplant satellite radio, but if I had to place long-term bets, I'd bet on the web.

It's hard to argue that having a huge palette of choices isn't progress of some sort, but there's something to be said for being drawn out of one's comfort zone because there's only one game in town.

Friday, March 8, 2013

Were you born mobile?


(Not to be confused with Goin' Mobile, wherein you can play the tape machine, make the toast and tea ...)

Qualcomm has received a lot of attention for its keynote at CES, and not necessarily the good kind.  Apparently, they were trying to invoke some inspirational vision of a new generation -- "Generation M", they called it -- untethered from antiquated wired connections, claiming the mobile web as their birthright.  And they, um, missed.

Verge has a typically scathing writeup (typical for coverage of this event, not necessarily for Verge), complete with Tweets from various Twitterati doing their best snark.  Overall reaction seems to run from "Hey, whizzy technology.  Kinda strange presentation, though" to "Oh ... my ... God ... what ... were ... they ... thinking?"

Disclaimer: I didn't watch the whole thing. I'm not sure I could.  I'm pretty sure I got the gist from the intro (up to Paul Jacob's "... or a CEO.") and the excerpts of the rest.  I certainly haven't come across anything saying "Never mind the cheesy intro.  It gets better."  Even if it did, Qualcomm chose its lead-in to set the tone for all that followed.  For better or worse, the face of Qualcomm for some time to come will be thisthis or this (I mean the characters here.  I don't know anything about the actors, but I do know that if I were an unknown actor and someone offered me the keynote at a major consumer electronics show, I'd jump at it.  Just maybe not so quickly now.)

Qualcomm has been around for quite a while, even if not in the limelight.  Indeed, that was one of their points.  Nor are they completely incompetent at marketing in general.  I wouldn't expect this ad for their Snapdragon processor to win any Clio awards, but it's kinda fun and gets the point across.  That ad was, in fact, part of the keynote.  Sadly, it seems to have stood out for its non-cringeworthiness.  So why did it all go so badly awry?

Off the bat:
  • If there were any real geeks on the writing staff, they must have been acting under duress.  For that matter, if there were any actual social-networking popular-types on the writing staff, they must have gone out for lattes while that part was being put together.  Who talks like those three?  Put any of them in their supposed native element and they would be driven from the room by howls of "Who is this poseur?" or whatever.  It's like watching a 70s after-school special where the dad tries to "be cool" with the kid and the child actor is thinking "Get my agent on the phone!" Or like rapping public service announcements in the 80s and 90s.  Tornado92?  Really?
  • One does not simply declare a new generation.  "Generation X" was taken from a 1991 novel title that caught on, no doubt with a little help from the association with Billy Idol's old band (who took their name from an older use of the term).  "Generation Y" came out of an Ad Age editorial, and has sort of caught on, though no one really knows when it started or whether to call it that or something else.  "Baby Boom" was a demographic term used in various contexts since the 19th century that ... caught on.  And so forth.  Besides, the whole "Generation ___" thing has been done to death already.
  • If there really is a "Born Mobile" generation or "Generation M", it's going to be younger than the actors on stage.  Looking at US statistics for example, there were essentially no wireless-only households until around 2005.  Granted, the US is not cutting-edge when it comes to mobile adoption, but even in Scandinavia, home of Nokia and Ericsson, cell phone usage doesn't really start to take off until the turn of the millennium.  Smart phones, which is what Qualcomm is really talking about, are even more recent.
  • But at the same time, this is all old news.  The time to announce a new, "Born Mobile" generation is before everyone has a cell phone.  The penetration rate in South Korea has already passed 100%, or one cell phone per person.  Suburban malls in the US don't just have cell phone stores, they have specialized kiosks hawking teen-friendly cell phone accessories.  Have had for years.  We didn't have a generation "Born Mobile".  We've got a generation born sessile that has picked up mobile technology in a considerable hurry.  Except, it's not just one generation. You don't get to 100% penetration that way.  Three generations of my family have cell phones, and that's hardly unusual.

Not that a trade show opening event is supposed to be a technical symposium, but tell me something I don't know.  I know mobile technology is important.  I'm sure your processors are fast.

But there's something else, cultural, here.  The whole show hearkens back to a long-ago time when no one knew how to sell technology.

Time was, I seem to recall, that a furry geek from another planet could stand up in front of an audience of business people and stammer something like "Um, our new system has a 6502 processor running at 1MHz, 64K of RAM expandable to one megabyte, and a BASIC interpreter in ROM, so we think it's pretty cool," and the business people would scratch their heads, mutter "what's a RAM?" and somehow figure out what to buy.

Then the professionals came in.  There was, I believe, a brief period of feeling around in the dark, of figuring out whether to say "slash" or "backslash" or to mention that you need a browser to get to a web site, to take a couple of more recent, webbier examples, but this didn't last.  Professional marketers may not have known tech at first, but they do know what works and doesn't work in marketing and will adjust accordingly.

Somewhere in that early mix was a time when no one, not even the geeks, knew what to do with these "computer" things.  There was a grasping on the part of the geeks toward "real people" ... moms and neighbors, say, and a grasping on the part of the marketing folks toward, well, markets.  For some reason, one popular thing to say about a personal computer was that you would have one in your kitchen to help you organize your recipes.  I don't think anyone really believed that, but at least it was something to grab onto.  The intro to the Qualcomm presentation has something of that feel to it, which is odd coming from a company that had had enormous success selling wireless technology for decades.

...

Toward the end of the intro, the "entrepreneur" tells you about his billion-dollar idea -- because, you know, any college graduate can come up with a billion-dollar idea these days.  Of course, he's not really going to tell you what it is, but his cover story is "funny cat videos meets Gangnam style".  Because that's as up-to-date as you could possibly get, right?

Gangnam Style long ago passed from quaint goofy-looking video from across the ocean to cultural phenomenon to "please, please, don't play that again" on its way, I'm sure, to weapon of choice for drunk and clueless wedding guests, but there's actually something to it.  I've always found that culture shock is much worse coming back to one's own country, and here is Psy, returning to his native land and creating what, on closer examination, is a sly but sharp satire of a lifestyle.  A lifestyle of young, hip, heavily debt-ridden twentysomethings whose lives are much, much less than meets the eye.

Boom.

Wednesday, February 6, 2013

Shave and a haircut: two bitcoins

Someone the other day was mentioning Bitcoin, which calls itself the first decentralized digital currency.  Regular readers of this blog, a select group to be sure, will probably not be surprised that this sent my not-so-disruptive-technology sensors into high gear.  So what's a decentralized digital currency?

Virtual worlds often have virtual currencies, which citizens can earn by doing various things in the virtual world and which they can exchange within the world.  In at least some cases these virtual currencies have leaked into the real world, or been tied to real money to begin with, not always with happy results.  One can view Bitcoin as abstracting that process and removing it from the confines of a closed, proprietary virtual world.

Bitcoin uses a modest ensemble of established crypto techniques to create a public audit trail certifying that a particular person has generated a Bitcoin, or that one person has exchanged some possibly fractional amount of Bitcoin with another (and by "person" I really mean "whatever has control of a given private key").  Generating bitcoins and certifying transactions requires a non-trivial amount of computation, much as generating money in a virtual world requires a non-trivial amount of whatever one does to earn money in that world.

There are various safeguards to ensure that each unit of Bitcoin has exactly one owner and everyone has a consistent view of who owns what.  That view can change over time.  In other words, Bitcoin meets some basic requirements for a currency: It is transferable, limited in supply and difficult to duplicate or forge.  So far, so good.


It occurs to me that there is actually already a very widely-used decentralized digital currency, namely money.

While it is still possible to exchange cash for goods and services, an awful lot of commerce gets done without it.  Instead, various banks and other entities simply increment and decrement balances in various accounts.  If I pay you, my balance goes down, yours goes up and one way or another our banks and various intermediaries get to take a cut.  This is certainly digital, and it's certainly currency.  It's also decentralized, in that there are many banks, particularly once we move into the international arena, and not even the various central banks have complete control of what happens.

However, it's not as radically decentralized as Bitcoin aims to be.  Bitcoin aims to take out all intermediaries.  If I pay you in Bitcoin, everyone in the system will be informed, reasonably soon, that I now own that much less Bitcoin and you own that much more.  All participants are an essentially equal footing.  There are no banks, clearinghouses or other such entities at all.

More precisely, everyone learns that whoever controls my private key has that much less and whoever controls yours has that much more.  Whether anyone knows who controls what keys is a separate matter.    Bitcoin uses pseudonymity -- known names tied to possibly unknown entities -- to recapture some of the anonymity of cash transactions.

The Bitcoin documentation is very careful to make the classic economical distinction between value in use and value in exchange.  The computational work done in producing Bitcoin and validating transactions is not inherently useful.  It basically consists of guessing numbers until one the right one comes up (technically, one that contains a given bit string and hashes to a particular value).  The value, if any, comes of people being willing to use Bitcoins in exchange, that is, as currency.  This is no different from printed pieces of paper or numbers in databases or, for that matter, materials like gold whose prices -- that is, their exchange rate with paper currencies -- are largely decoupled from their practical uses.



So this looks well thought through and doesn't seem wildly implausible.  Why was my spidey-sense tingling?

In trying to make sense of this I went back and reviewed the concept of currency.  Except there doesn't seem to be a nice, crisp, near-universally accepted concept of what makes currency work.  Scarcity is required, in the sense that the supply of currency must be bounded, albeit typically large.  Gold and other precious metals are hard to produce.  Coins are limited by fiat -- the king's mint will only put his face on so many coins, and woe betide the counterfeiter -- making it less important what the coin is made of.  Notes carry this one step further.  Clearly it doesn't matter much how much the paper and ink is worth, only that it's difficult to duplicate the note itself.

Numbers in databases are completely abstract, and they seem to work fine.  So why not Bitcoin?

At the end of the day, currency has to be exchangeable for something useful, for example, food.  This can only happen if the person accepting currency in exchange can be confident that they in turn will be able to exchange it for something useful to them.  Bitcoin works hard to ensure that it will behave essentially like physical cash and carefully-regulated changes in bank balances, but that still doesn't make it a currency.

And that's the crux of it.  Will people trust that Bitcoin will remain exchangeable?  What is the mechanism for maintaining confidence?  Typically, this confidence is based on confidence in a government, but other systems work as well.  Failed states may continue to circulate currency well after the government has collapsed.  Some countries are perfectly happy to use another country's currency.  Local communities have been known to create their own currencies which rely on the communal bond among members.  All of these and more can work, so why not Bitcoin?

Well, maybe it can.

The best measure I can think of for the viability of a new currency is how it converts to and from existing ones, and there are Bitcoin currency exchanges which do just that.  From what I can tell, the jury is still out, if only because Bitcoin hasn't been around that long yet.  Bitcoin is currently trading around $14, but it's been as high as twice that in the past couple of months and much, much lower not long before that [and on 28 November 2011, around $2.75, less than 10% of the all-time high ... given that the earth shook slightly when the Swiss Franc dropped from around $1.27 to around $1.16 and that Sterling's fall from 2.80DM to around 2.55 helped bring down a government, this sort of volatility does not look good ... my source for the price, mtgox.com, is now offering options and margin trading on the bitcoin, just in case anyone wants an even bigger adrenaline rush -- D.H.].  On the one hand, a non-zero value is encouraging, but on the other, that sort of volatility doesn't inspire confidence.

Personally, I don't see much reason to use Bitcoin in any significant way.  Money has worked fine so far, and if the US dollar should collapse, I'm not exactly convinced that Bitcoin would become a safe haven.

Wednesday, January 16, 2013

Banking on web security

People do care about web security.  There are highly competent full-time professionals in the field.  There are conferences on the subject on a regular basis.  You'll see them in the press -- Experts Meet to Fix Security on the Web.

And yet, in large part because the problems to be solved are hard and involve significant non-techical factors, there is no shortage of things that could stand to be fixed.
  • Authentication is a mess.  For the most part, we have passwords and security questions.  I've griped about this before, multiple times, and I'm sure I'll gripe about it again.
  • Identity is a mess.  Everyone has scads and scads of identities -- logins here, there and everywhere. They can easily get confused ("That wasn't me, that was some other David Hull!").  There's no good way to say two random identities are or aren't the same.  I've griped and speculated about this before, too, and I expect I'll have more to say on that, too.
  • Anonymity is problematic.  Everything you do on the web leaves traces, but unless you're paying extremely close attention you generally don't know exactly what kind, or whether that can be tied to your identity (whatever that is).
  • Network infrastructure is scary.  Https with certificates is widely deployed, and most people probably at least know that some sites are "secured" and some aren't, but many fewer understand (or should need to understand) details like signatures, secure hashes and certificate authorities, or what can fail and what's less likely to.  Did I mention DNS?
  • PCs are scary.  Viruses, rootkits, system crashes ... some platforms are better designed than others, but nothing's perfect.
  • The cloud has its own problems.  Who owns what you put there?  Who's liable if data is lost or compromised?  Who can see what?  Who can see who sees what?
  • Spam is a perennial problem, not helped by any of the above.
I could go on, but if it's so bad -- and it is -- how does it work at all?  People continue to be able to use credit cards both online and in person, people continue to email and text each other all sorts of sensitive information, people continue to turn to the web for all sorts of vital information.  Clearly Bad Things can happen to a person on the web, but just as clearly it's not bad enough often enough to put people off the web entirely.  Far from it.

My guess is that banks have a lot to do with it, at least in the US.  In particular
  • Banks handle liability.  If someone steals your credit or debit card, whether physically or online, you can tell your bank and generally they will make sure you don't have to pay for things you didn't buy.  That's oversimplified, and there are certainly cases where that simple process has turned into a nightmare, but it's still a vital part of getting people to do business confidently online.
  • Bank cards provide a de facto stable identity.  If you're buying something from my web site, I do care who you are (well, I would, and stores in general do seem to care what their customers are up to), but I certainly also care that your payment is going to go through.  To some extent I'm talking to you, but I'm also talking to your bank account.
On the first point, you're not responsible for keeping your bank accounts absolutely safe.  You're responsible for taking reasonable precautions, so that if someone does get hold of your account number and misuses it, they're clearly at fault (the usual "I'm not a lawyer" disclaimer applies here).  Putting the rest of the burden on the banks and legal system is a large part of what keeps the wheels turning.

On the second point, if I shop at store A and store B, it's important that my bank knows that those purchases both come out of my account, and I know that I'm the same person in both cases (at least on a good day).  It's less important that store A and store B know I'm the same person.  There may even be cases where I'd rather they didn't know.

In short, security and identity matter when money is at stake, in which case your accounts serve as your identity and you have legal protections that predate the web.

Security and identity also matter where reputation is at stake, that is in the social realm, be it email, social networks, Twitter or whatever.  The landscape is different there, but it's worth noting that most accounts and identities, including your bank accounts, don't play into that much.  If someone compromises my account at widgetco.com, they might be able to have a truckload of widgets sent to my address at my expense, but they won't be able to say embarrassing things about me on this blog.  Likewise if they compromise my bank account, though that would of course be bad for other reasons.


If you buy that, then you should make sure to use strong unique passwords and unique security questions for your bank accounts, your email accounts and your major social accounts, and use better security than that when it's available.  How much to worry about other accounts depends on how closely they're tied to the accounts that matter.  For example, if your city's online parking ticket paying site doesn't remember credit card numbers or your nefarious history of overparking, you probably don't care as much about security there.