Tuesday, May 04, 2004

This gmail bullshit has gone too far

EPIC is alleging that Google's proposed gmail service violates "wiretapping" laws. What a fucking crock of shit. This discredits EPIC in my eyes, perhaps permanently. Dammit, if you don't like the idea that a mechanical algorithm will be reading email sent to gmail purely in order to insert contextual ads, then guess what: don't sign up for a gmail account. I am frankly amazed --- flabbergasted --- at the completely bizarre, disproportionate backlash that people like EPIC and Liz Figueroa are stirring up in opposition to this mostly innocuous and completely voluntary service.

Guess what bozos: all these people who sign up for gmail could also, uh, hire a secretary to scan all their mail and clip magazine advertisements related to that mail. Holy shit, full PRIVACY RED ALERT, MAKE SECRETARIES ILLEGAL! They're wiretapping their bosses!

Reality check: All gmail does is offer massive amounts of highly reliable, highly available, backed-up mail storage to the masses, whereas before this was basically only available to rich people or employees of rich corporations. You pay with a tiny amount of attention, and (possibly) a tiny invasion of your privacy, instead of shelling out lots of hard cash. And if you don't like the deal, don't sign up (and don't send email to people at gmail accounts).

The anti-gmail squad's misdirected ire is particularly outrageous given that other entities online are way worse and nobody's raising hell about them at all. For example, online ad networks like DoubleClick store your complete web browsing behavior across all client sites, plus the referrers (which, if you clicked from a search engine, includes the search terms used to reach the site). And these ad networks don't even have users click through a terms of service agreement.

Sunday, May 02, 2004

Michael Ignatieff is an ignorant, ignorant motherfucker

Today's New York Times Magazine carries an article by Michael Ignatieff which combines astounding arrogance with astounding ignorance. Ignatieff writes with a voice of supreme superciliousness, lecturing his readers that "we need to change the way we think, to step outside the confines of our cozy conservative and liberal boxes". Meanwhile he recapitulates basically every incorrect argument, every "cozy" bit of received wisdom, that I've ever read about security and civil liberties.

The biggest unspoken assumption is that reducing civil liberties is likely to increase security. It is true that security and liberty are sometimes in conflict, but in many cases the most effective security measures do not decrease liberty at all.

The most egregious example of Ignatieff's ignorance is his support for a national ID system:

But being absolutely right on this issue doesn't make a civil liberties position right on every other issue. Consider the question of a national ID system. Instead of crying ''1984,'' the civil liberties lobby should be taking an honest look at the leaky sieve of the existing driving license ID system and admit how easy it was for the hijackers to talk their way into the ID's that got them onto the planes. Instead of defending a failed ID system, civil libertarians should be trying to think of a better one. One possibility is for Congress to establish minimum national standards for identification, using the latest biometric identifiers. Any legislation should build in a Freedom of Information requirement demanding that the government divulge the data it holds on citizens and purge data that is unsound.

Aarrrrrggghhh!!! When I read this, I literally leapt from my couch and punched the nearest chair. Civil libertarians do not merely "cry '1984'" in objection; that is a ridiculous straw man. And civil libertarians are not "defending a failed ID system" when they criticize proposals for national IDs; they are claiming that ID systems in general are open to tremendous abuse, and that therefore a heavy burden of proof falls on those who propose to extend their reach and pervasive influence in our society.

Furthermore, and more importantly, civil libertarians are not the only ones who oppose a national ID system. Mr. Ignatieff, you're a reporter, so perhaps you should, you know, interview some actual security experts before you go shooting your mouth off about security? The notion that a national ID system would increase national security has been comprehensively debunked by world-renowned security expert Bruce Schneier, several times. He points out numerous powerful objections, and most of them stem from pure security analysis:

What good would it have been to know the names of Timothy McVeigh, the Unabomber, or the DC snipers before they were arrested? Palestinian suicide bombers generally have no history of terrorism. The goal is here is to know someone's intentions, and their identity has very little to do with that.

This objection, like many others, has never been credibly countered by advocates of a national ID system. Yet writers like Ignatieff and Nicholas Kristof (what is the deal with New York Times writers and this national ID system fetish?) persist in pretending that such a system would make us safer. Free Clue for the Clueless: A reliable ID system would not have prevented the 9/11 attacks.

The idea that national IDs would increase security sounds vaguely plausible at first, until you examine the specifics, at which point you realize it's a giant steaming mound of horse shit. (And, in retrospect, I think that the only reason it sounds plausible at first is that we've become conditioned, socially, to "present our papers" in all kinds of contexts --- many hotels, for example, now require you to present ID when you check in; if you think about it, there's actually no good reason for them to do this.) Notice that Ignatieff does not actually point out any specific scenario in which hijacking might have been prevented by a national ID system. Some of the hijackers had completely clean records. Among the ones who didn't, it's not clear that the blemishes would have been significant enough to prevent them from flying. Are we going to ban all convicted felons from commercial air flights? All Middle Eastern immigrants? All rural white people? Anybody who holds radical political views? In short, does Ignatieff propose even a single realistic scenario in which knowing someone's identity helps you defeat a terrorist attack? No, he does not. Ignatieff's writing is either extremely stupid or extremely irresponsible, and he should get the fuck off his high horse in caricaturing civil libertarians and security experts as a bunch of silly crybabies.

As for the notion that the government should "purge data that is unsound", well, duh, but that's far easier said than done. If Ignatieff had even the tiniest bit of experience with managing databases, or had spoken on the phone to someone who manages databases professionally for, say, thirty seconds, then he would recognize that maintaining security, integrity, and consistency of a database of this size over time is a stupendously difficult undertaking. Schneier thinks it is actually impossible, given the current the state of the art in computer security and database management. As a computer scientist, I'm inclined to agree.

In short, with respect to security, Michael Ignatieff is an ignorant, ignorant motherfucker who should stick to stuff that he's actually good at, like writing about foreign policy.

Saturday, May 01, 2004

Dodgeball: Now playing in NYC, SF, LA, Boston, Philly

A while back I told MS that social networking sites like Friendster and Orkut were dumb because there were no applications. You type in all this information about your social network; you harass your friends to join; and in the end it's good for a couple minutes' amusement, no more. It's just inert data. There's no integration with your mail client, your address book, your instant messenger, your text messaging service, or whatever.

Well, meet Dodgeball. At last, an application:

Q: What does it do?
A: The idea is simple: tell us where you are and we'll tell you who and what is around you. We'll ping your friends with your whereabouts, let you know when friends-of-friends are within 10 blocks, allow you to broadcast content to anyone within 10 blocks of you or blast messages to your groups of friends.

Q: Give me an example.
A: Okay, so you're having drinks at Luna Lounge. Send us a text message telling us where you are and we'll send out a text message telling all your friends where you are AND send you back a message letting you know if any friends-of-friends are within 10 blocks. If you have a camera phone, we'll even send you their picture.

(Sounds like the more civilized, social cousin of toothing.)

This solves one of the problems of social networking sites. But it doesn't solve the bigger meta-problem, which is that all these sites are currently closed: their database isn't published in a form accessible to other software. As a result, you have to wait for the site owners to provide the applications. There's no possibility that some random programmer with a great idea can simply hack up an application and try it out. Result: glacially slow pace of advance in application development, and when applications do arrive they're frequently locked out of the best data (which is in the databases of Friendster etc.).

Consider the consequences of closed networks for a service like Dodgeball. I'm on Orkut and Friendster (though, as this post implies, I don't use them for anything). There's no way in hell I'm going to harass all my friends to join yet another social network. And that's just the beginning: when tomorrow's social networking site comes along with some new and compelling application, am I going to go through the whole process again? What about the multiplicity of effort required when I add someone to my network on a half-dozen sites? What about version skew between my various networks?

This isn't sustainable. In the long run, I can see three possible outcomes:

  • Social networking turns out to be a passing fad that goes totally bust.

    (Unlikely, IMO; social networks are a powerful idea, and the Internet isn't going away. Even if the current generation of networks withers, someday somebody will probably figure out how to make them compelling.)

  • Someone will figure out that sites must provide a (suitably authenticated) protocol so that people who are not the site owners can access social network data, using software of their choice. This may lead to a universe where some sites specialize in providing and aggregating the social network data itself, and third parties specialize in providing applications that operate on this data.

  • The marketplace converges on one or two social networking sites that everyone's on. Any smaller company that comes up with a cool new social network application finds itself rapidly preempted by the behemoths, who simply copy those applications and make them available on their (much larger, and hence much more compelling) social networks.

For a variety of reasons, I think that the second of these alternatives would be the best possible world. But the conventional wisdom with the current crop of sites seems to be: "The data we have is our main asset; by maintaining a stranglehold on access to that data, and thereby locking people into our web site, we increase our competitive edge." And FOAF looks too disorganized and unfocused to provide a credible alternative any time soon. So, it looks like we're headed to the last of the above alternatives.

In this scenario, if Dodgeball works, then sooner or later Friendster or one of the other big sites will copy Dodgeball, and Dodgeball will go out of business. And then, the next group of bright hackers who has some interesting idea for social networks may get discouraged, and decide not to pursue it.

Bush administration goes after salmon

D. Neiwert reports that the Bush administration is gutting environmental protections for wild salmon in the Pacific Northwest.

In related news, dog bites man.

Creationist theme parks

From today's Times:

PENSACOLA, Fla., April 29 - Robert and Schön Passmore took their children to Disney World last fall and left bitterly disappointed. As Christians who reject evolutionary theory, the family scoffed at the park's dinosaur attractions, which date the apatosaurus, brachiosaurus and the like to prehistoric times.

"My kids kept recognizing flaws in the presentation," said Mrs. Passmore, of Jackson, Ala. "You know - the whole `millions of years ago dinosaurs ruled the earth' thing."

So this week, the Passmores sought out a lower-profile Florida attraction: Dinosaur Adventure Land, a creationist theme park and museum here that beckons children to "find out the truth about dinosaurs" with games that roll science and religion into one big funfest with the message that Genesis, not science, tells the real story of the creation. Kent Hovind, the minister who opened the park in 2001, said his aim was to spread the message of creationism through a fixture of mainstream America - the theme park - instead of pleading its case at academic conferences and in courtrooms.

Mr. Hovind, a former public school science teacher with his own ministry, Creation Science Evangelism, and a hectic lecture schedule, said he had opened Dinosaur Adventure Land to counter all the science centers and natural history museums that explain the evolution of life with Darwinian theory.

Weep for America.