Showing posts with label open culture. Show all posts
Showing posts with label open culture. Show all posts

January 30, 2011

Hobson's World

Public unrest over the TSA has finally boiled over. As someone who hated the TSA long before it was fashionable, it's been nice to see the general public finally voicing some outrage. Absurd that it took naked scanners and crotch-grabbing to stir us into action, but still nice. Please, continue to be angry with the TSA, and maybe someday we'll bring that whole farcical organization down upon itself. But that's not really my job here. My job is to explain to you that there are a lot of other things to be angry about, too.

Hobson, the story goes, operated a large stable with horses available for let. One could pay to use a horse from his stable, but you were not free to select any horse you liked. You could have the horse currently up for rotation, or you could shove off. This probably worked quite well for Hobson, ensuring that his most popular horses did not become overworked. At any rate, he managed some small measure of immortality; a "Hobson's Choice" is any choice where the only options are accepting all the terms, or none at all. There's nothing inherently bad about these types of choices. But what if Hobson's stable was the only one in town? And if horses were so heavily used that access to one was no longer a luxury? And what if his rotation wasn't a fair FIFO system, but something more sinister, like giving the worst horses to those least able to complain?

Hobson, the medieval stable master, would have found himself right at home on the internet. Whether you realize it or not, every trip through cyberspace is riddled with Hobson's choices. It starts at the plug in the wall; if you want anything coming down your wires you must agree to the conditions put forward by one of a handful or fewer ISPs available to you. Then almost every website you visit has a Terms of Service (I've touched on these before). And for every service you use, even the most basic like email, you've checked off your assent to a massive User Agreement. There's almost nowhere to hang your hat that isn't fenced in with thousands of words of legalese defining exactly what you are allowed to do. You don't often think about the presence of all this contractual weight, but it's there, every time you bring up a browser.

What's really appalling about all these terms is how much they take away and how little they offer. Most ISPs, if they so chose, could give you no connection at all, for as long as they pleased, and continue to bill you for it. The provider's side of these agreements is legal ass-covering, allowing them to give as little service as they please and still be within the terms of the contract, protected from litigation.

Here's Comcast stipulating that they can install software on any device you connect to their service (i.e. your computer), and that they are not responsible for any damage they cause by doing this (emphasis mine):
Customer Equipment consists of software or services that you elect to use in connection with the Services or Comcast Equipment (the “Customer Equipment”). You agree to allow us and our agents the rights to insert cable cards and other hardware in the Customer Equipment, send software and/or “downloads” to the Customer Equipment and install, configure, maintain, inspect and upgrade the Customer Equipment and Comcast Equipment.
Comcast User Agreement, Section 5.b
Comcast has no responsibility for the operation or support, maintenance, or repair of any Customer Equipment including, but not limited to, Customer Equipment to which Comcast or a third party has sent software or “downloads.”
Comcast User Agreement, Section 6.b.1

In case that's not enough, here's Comcast indemnifying themselves against anything short of gross negligence, and claiming that even in that case you cannot be entitled to more than $500 (emphasis mine):
CUSTOMER EQUIPMENT MAY BE DAMAGED OR SUFFER SERVICE OUTAGES AS A RESULT OF THE INSTALLATION, SELF-INSTALLATION, USE, INSPECTION, MAINTENANCE, UPDATING, REPAIR, AND REMOVAL OF COMCAST EQUIPMENT, CUSTOMER EQUIPMENT AND/OR THE SERVICES. EXCEPT FOR GROSS NEGLIGENCE OR WILLFUL MISCONDUCT, NEITHER COMCAST NOR ANY OF ITS AFFILIATES, SUPPLIERS, EMPLOYEES, AGENTS, OR CONTRACTORS SHALL HAVE ANY LIABILITY WHATSOEVER FOR ANY DAMAGE, LOSS, OR DESTRUCTION TO THE CUSTOMER EQUIPMENT. IN THE EVENT OF GROSS NEGLIGENCE OR WILLFUL MISCONDUCT BY COMCAST, SUPPLIERS, EMPLOYEES, AGENTS, OR CONTRACTORS, WE SHALL PAY AT OUR SOLE DISCRETION FOR THE REPAIR OR REPLACEMENT OF THE DAMAGED CUSTOMER EQUIPMENT UP TO A MAXIMUM OF $500. THIS SHALL BE YOUR SOLE AND EXCLUSIVE REMEDY RELATING TO SUCH ACTIVITY.
Comcast User Agreement, Section 10

Meanwhile, your side of the terms may contain any number of constrictions on what you are allowed to do. Many create licensing terms that cede everything you create to the control of the company, to use however they please. Here's Facebook:
For content that is covered by intellectual property rights, like photos and videos ("IP content")... you grant us a non-exclusive, transferable, sub-licensable, royalty-free, worldwide license to use any IP content that you post on or in connection with Facebook ("IP License").
Facebook ToS, Section 1

Notice that they may license your content out to others if they wish. To Facebook's credit, they no longer claim the license to be "perpetual" and "irrevocable". They briefly added those terms in 2009, and backed off after facing considerable backlash.

Many of these documents state that the terms may change at any time, with no warning, and that your continued use of the service will be bound by these new terms. Here's Comcast again (emphasis mine):
Subject to applicable law, we have the right to change our Services, Comcast Equipment and rates or charges, at any time with or without notice. We also may rearrange, delete, add to, or otherwise change programming or features or offerings contained in the Services, including, but not limited to, content, functionality, hours of availability, customer equipment requirements, speed, and upstream and downstream rate limitations. If we do give you notice, it may be provided on your monthly bill, as a bill insert, e-mail, in a newspaper or other communication permitted under applicable law. If you find a change in the Service(s) unacceptable, you have the right to cancel your Service(s). However, if you continue to receive Service(s) after the change, this will constitute your acceptance of the change.
Comcast User Agreement, Section 4

Then, of course, are the terms that are simply absurd. When Grinnell College rolled out their new alumni network, John Stone noticed that The Loggia Terms and Conditions disallowed, among other things:
Reproducing and storing data in a retrieval system (electronic or mechanical)

From a technical standpoint, one cannot view a webpage without storing and reproducing data locally, making it impossible to actually use the service and still be in compliance with this rule.

To do even the most mundane tasks online, you are forced to relinquish a great number of rights, but in return you receive absolutely nothing except the optimistic hope that the company will provide something to you. You are signing a contract for empty air, and if you're lucky the company will choose to bestow upon you some favors. If these are legally viable is a bit of an open question. Most notably, these agreements could be considered contracts of adhesion and may be unenforceable due to the doctrine of unconscionability. Vagaries of the law aside, it should be apparent that this type of agreement, wielded without oversight, is morally wrong.

At first blush, the TSA situation seems far removed from that inflicted on us by private companies. After all, the government is the one entity that can compel us to obey certain rules, whether we choose them or not. You don't get to opt out of the legal system, even if you want none of the benefits.

But let's examine the TSA's role. Flying is, in the end, a purely voluntary activity. You cannot be compelled to endure an unconstitutional body scan or enhanced patdown if you simply choose not to travel by airplane. Another Hobson's choice. Like many of the others, this choice is a coercive force for many of us. Some people depend on air travel to perform their jobs. Others have no other way to see relatives or friends in far away places. While it's admittedly a middle-class pursuit, air travel is nearly a necessity for many of us who can afford it.

Much of TSA's power, as it turns out, stems from this choice. There has been some bluster during the recent opt-outs about levying a civil fine for leaving the airport after the screening process has begun, but it's unlikely those threats will ever be made good on. And that's a civil fine, the only kind TSA has the authority to level. This fascinating account is written by a man who refused to submit to the new policies as a condition of being allowed through customs. The best part is when actual police offers get involved, officers who have been trained on constitutional rights.
I clarify, “Well, like I said, I’ll do whatever you say is mandatory. If you tell me that you have to touch my balls—“

“—I said no such thing. You’re putting words in my mouth.”

“OK. I apologize. If you say that a pat-down is mandatory, and that as a condition of that pat-down, I may have my genitals brushed against by your hand, even though you don’t want to, I will do that. But only if you say it is mandatory.”

“I’m not going to say that.”


The TSA has no real authority. Their power stems only from the fact that they control access to a service that is nearly ubiquitous and seriously disadvantages those who refuse the terms. So they can present a Hobson's choice, safe in the knowledge that almost everyone will submit. Sound familiar? TSA is nothing more than another abusive monopoly.

Let's take one final step back. I said earlier that a government is the one entity that can compel you to obey certain rules without any agreement on your part. Enter Hobbes (a very different and much more famous man than our titular Hobson). His most enduring idea is that government is a social contract:
I authorise and give up my right of governing myself to this man, or to this assembly of men, on this condition; that thou give up, thy right to him, and authorise all his actions in like manner.
Thomas Hobbes, Leviathan
We give up some of our rights, like the right to beat other people over the head with big sticks, for the goal of living peacefully and prosperously, safe from the constant danger of being beaten over the head with a big stick. Being governed is a voluntary act (let's ignore Hobbes' autocratic leanings for the sake of simplicity), undertaken because it's to our long-term benefit.

Of course, few of us actively take part in any kind of contractual ceremony agreeing to these terms. We fall under the government's jurisdiction by the circumstance of being born where we were born, living where we live. In fact, land ownership is the source of a government's authority. You may decide to "opt out" of the laws of a country, but you should not remain on that country's land and expect to escape punishment. Conversely, if you leave a country's land, you are no longer subject to their laws. Extradition feels like an exception to this rule, but it's merely an agreement between countries. Extradition does not work when the host country refuses to play along.

So! The government controls access to a desirable resource (land). This allows them to require adherence to a stringent set of rules from anyone wishing to gain access. Even if the rules seem unfair, a choice between that or nothing at all leads almost everyone to obey. Hopefully by this point you're drawing your own parallels. That's right, I see governments as nothing more or less than the biggest corporation around, one whose services we all consume. We pay a subscription fee. We reap tangible benefits. All the elements of a contractual agreement are there.

And yet, there's one thing the government offers us that no consumer relationships do: the ability to negotiate. The system is horribly inefficient, riddled with bureaucracy, and easily derailed. But in the end, we the people do get a say in the rules that are applied to us. More importantly, we see the idea of a government that answers to the people as obvious and absolutely necessary. So why don't we apply this same expectation to corporations? Why do we insist that corporations are accountable only to their shareholders, instead of to the collective public whose lives they so deeply affect?

Looking to the future, I don't think the government will be the one to relieve us of our freedoms. Sure, there will be battles. But the Bill of Rights has survived two centuries more or less intact, and I expect it will keep on truckin'. We won't lose our rights at gunpoint. We'll lose them in bits and pieces, so slowly as to be nearly imperceptible. We'll sign them away one after another in the name of new services or free beer or just following the crowd. Technically, they won't be gone, but a right that we are not free to exercise in the most frequented arenas of public discourse isn't much of a right at all.

Epilogue


My slow blogging habits caught up to me once again. I hadn't even started putting this post into words before the furor over the TSA scanners had been totally eclipsed by the Wikileaks controversy. It's a complex affair, and I could write an incredible volume on the details of the various events surrounding Cablegate, but I think I'll leave that to others, and draw two small connections instead.

The intentions of the government towards Wikileaks, as far as we can divine them, are rather serious, and in some ways conflict with what I just said. The organization, of which our government was at least tolerant — perhaps even fond — when it was dishing out leaks from third worlds and no particular friends of ours, has become a thorn in the side of some very powerful interests. The Obama administration seems intent on finding a way to declare Wikileaks' actions illegal, though there seems to be no law that fits. There's no attack on Wikileaks as a whole that isn't a dangerous attack on free speech, and it's being perpetuated by our own government. If this comes to pass, it will be one of the battles I predicted, perhaps a very important one.

In other ways, however, the assault on Wikileaks has made plain for the first time how much power corporations wield over our speech. The threatened legal action has not materialized, and may never come to pass if those in power can't find a good story to tell about why silencing Wikileaks is no cause for concern. In the meantime, however, direct and damaging action has been flowing in from the private sector. In the space of a few days, Wikileaks experienced cutoffs by hosting services, domain name services, and at least four financial services. All of these cited vague "terms of service violations", but there's little reason to doubt that these shutdowns were incited and choreographed by political interests. As Richard Stallman opines, "It is as if we all lived in rented rooms and landlords could evict anyone at a moment's notice."

It remains to be seen whether the government's feud will be derailed by legal protections we have put in place, but there's reason to be optimistic. In the private sector, though, it's been made clear just how great of a blow can be dealt to our freedoms when they become inconvenient to the powerful. We shouldn't need a "use case" for retaining our basic freedoms. For me, idealist notions about the value of freedom for freedom's sake are enough to compel resistance to these Hobson's choices. But if you're of a more pragmatic mindset, I can't think of a better spectre than government and corporations cooperating to stifle political dissent.

March 22, 2009

Enacting my own Terms of Service

I currently have a couple web crawlers running that periodically request content from a couple websites and store it in databases. It struck me as strange that these websites deigned to stipulate certain "Terms of Service" (ToS) over my use of their content and believed that these terms formed a contractual agreement, even though there had been no negotiation over these terms, and I had never signaled my assent (I haven't clicked any little "I agree" buttons on any of these sites). So I decided to bring the art of negotiation back into the formation of these previously one-sided agreements.

So, when one of my spiders makes a request, it adds a name/value pair to the query string of the URL, like so:

http://server.contentprovider.com/requested/1234567?tos=http://static.iangreenleaf.com/TermsOfService.md
This parameter directs the content provider to my own Terms of Service for the transaction. My terms start out by making clear how a content provide may accept or decline them:

By serving the content I requested, you are agreeing to all the terms and conditions set forth in this document, without reservation. If you do not wish to agree to these terms, do not serve your content in response to this request.

They go on to detail how I may use the content I am requesting. My favorite part is this:
By serving the requested content, you agree to hereby waive any and all restrictions on use of your service that you may stipulate in your own Terms of Service, Terms of Use, or other legal document...
So if the content provider responds to my request, they have agreed to my ToS and waived any terms that they may subsequently try to stipulate on my use of their content.

Now, you might think this is stupid or absurd. You might even think that this is totally unenforceable, seeing as how all I have done is provide access to the terms I am stipulating and take continued participation as consent. And I would tend to agree with you.

However, I claim that if my terms are unenforceable, so are those stipulated by the content provider. How is my request any different than providing a tiny link to the Terms of Service way down at the bottom of the page?

Example of Terms of Service link

I have as much right to place limitations on the transaction as they do. My limitations just happen to nullify all of their limitations. They're welcome to stop serving me content if they don't want to accept my terms.

Think I'm wrong? Tell me why.

August 27, 2008

Why I sign with PGP

If you've received email from me recently, there's a good chance it's arrived with a funny-looking header and footer. At the top, it will say
-----BEGIN PGP SIGNED MESSAGE-----

Hash: SHA1
And at the bottom is something like this:
-----BEGIN PGP SIGNATURE-----

Version: GnuPG v1.4.7 (GNU/Linux)
Comment: Promote trust on the internet - Use PGP!
Comment: http://enigmail.mozdev.org

iD8DBQFIqfcGDTFvtHdOkUcRAm4JAJ4vJrcQcAM7gtzoHbI8ul3bA7EUagCcC5aO
RLpYAOHP5YS40I0xSB89pDA=
=VHP3
-----END PGP SIGNATURE-----
This all looks like nonsense. Has rage and bitterness finally won the battle for Ian's soul, leaving him banging the keyboard randomly while shouting obscenities at the Internet? No! Well, not yet anyways. This stuff around the message is a PGP signature.

If I were to send you a letter or write you a check (hypothetically of course, I hate you all and you certainly aren't getting any of my money), at the bottom there would be a little scribble vaguely resembling my name, as penned by a somewhat slow seven-year-old learning cursive for the first time. This signature is the conventional way of saying "hey, it's really me, your old pal Ian, and I did write this."

A PGP signature serves the exact same purpose for electronic communication. Of course, a string of letters proves nothing. But when I open a signed message in Thunderbird with the Enigmail extension installed, it looks something like this instead:


That's nice, innit? That green bar means that I can have confidence that these somewhat unsettling threats are, in fact, from CM Lubinski, and he has electronically signed his name to them.

Ok, so you're probably thinking that this is mildly interesting so far, kind of like a poorly-drafted version of Wikipedia, and it sure beats calculus or mopping the kitchen floor or whatever you ought to be doing, but, well, big deal. Dorks like Ian can get all excited about this PGP thing, but you're going to go trawl YouTube for some clips of a baby rabbit eating its own poo. You don't need all this signature stuff, right? Wait! That furry redigester will be there in ten minutes. First, read about...

Why You Need PGP

You need PGP. You're complacent. Things are going smoothly on the internet. Your biggest problem most of the time is the occasional piece of spam that slips through the filters and annoys us for the ten seconds it takes to read "Fr33 V1agr@" and click Delete. But the convenience of technology hides an ugly truth: email is horribly, horribly insecure.

Right now, right this instant, I could send you a message purporting to be absolutely anyone. It doesn't even take that diploma sitting on my bookshelves to do it. The Grinnell mail server and a dirty trick (which I am not going to share) is sufficient. Oh look, good old Rupert sent me something just now:


I (or someone with considerably worse intentions) can pretend to be anyone in email. To illustrate my point further, here's an email coming from a domain name that doesn't even exist (I checked):


It doesn't have to be imaginary email addresses either. I could send a message with a bunch of inappropriate jokes to your boss that looks like it's from you. I promise I'm not going to, but I, or anyone else, could. That's scary stuff. We've seen the tip of the iceberg on this with phishing emails that look like they come from accounts@ebay.com or whatever. People click those fake links by the boatloads and compromise all sorts of financial information. Even smart, internet-savvy people do. Why? Because we're complacent, and no one ever taught us to doubt that the person in the From: field actually sent that message.

Encryption

Scared yet? Here's some more food for thought: ever send private information through email? Like, say, financial information, or your company's business deals, or those emails you get when you register an account somewhere that sometimes have your new password in them. Or even just personal correspondence that you don't want to share with anyone except the recipient.

Guess what - everything you send in email winds its way across the internet in "plain text" - meaning, anyone who looks can read it. If any link in the chain of servers and data lines between you and your recipient is compromised - like someone eavesdropping at your wireless hotspot, or a mail server that's been broken into by hackers, or someone tapping an ethernet line somewhere, or a spying government aided by crony telecoms  - all your email is sitting there waiting to be poked through. Additionally, there's very little oversight of how mail servers (of which any given message may cross through quite a few) are administered, so it's quite possible that your messages will end up sitting on the server or on backup tapes for a long time - quite possibly years.

My point is this: we have no reason to be certain that everyone who gets a look at our email is trustworthy, and yet we send everything totally unprotected from prying eyes. It's like sending all of your bank deposits and love letters on postcards when some of the postmen have no credentials and didn't even pass a background check to get the job.

Luckily, PGP also provides optional encryption. It's like the electronic version of a security envelope. An encrypted messages looks like garbage, just a string of nonsensical letters. It's only when your intended recipient decrypts the message that it becomes readable again.

How PGP Works (the short version)

I want to give a brief overview of how PGP works. This isn't going to be the technical version (I'm not even qualified to give the technical version). It's also not going to be a guide to setting up your computer to use PGP. For that I simply direct you to the two plugins I use and like: Enigmail and FireGPG, and especially the quick start guide for Enigmail, which is really stellar and walks you through the steps of setting it up and using PGP for the first time.   In this article, I just want to explain the underlying concepts so you can see how PGP works, and why it's such a great idea.

To start using PGP, you create a "key pair," which consists of two parts, a public key and a private key. Your public key is something you can give to everyone - you can email it as a file, put it somewhere online, upload it to a keyserver (try searching for my name or email address), whatever. Your private key, as the name suggests, you keep to yourself - it's usually password protected as an additional layer of security. These two keys are tied mathematically. I don't pretend to understand all the details, but it's something to do with factoring primes, and the important point is that it's very quick to go one direction, but incredibly difficult to go the other. So while someone could, in theory, guess your private key using only your public key, it would take the world's fastest hardware thousands of years (yes, human years) to do so. Basically, these keys are pretty secure.

Now, when you write an email and sign it with PGP, the program uses your private key to create a string of letters that is algorithmically tied to the contents of your message. When someone receives your message and wants to verify that it came from you, they take your public key and reverse the process, checking the signature against the message. Verifying a PGP signature assures you that the message came from the owner of the key because only the person with access to the private key could have created that signature. When you want to encrypt something, you take your recipient's public key and use that to turn the message into gobbledygook. That way, only the person with access to the private half of that key (i.e. your intended recipient) will be able to decrypt and read the message.

A Brief Interlude on Trust

There's one more feature of PGP I want to touch on briefly, because I think it's pretty cool: the concept of trust.

I've been going on and on about how secure PGP is, but there's a hole in all this: how do you get other people's keys in the first place? After all, just because someone puts a key up on a public keyserver saying they're James T. Madison, you have no proof that that's actually who made that key. If you downloaded the key from that person's personal website or imported it the first time they sent you a signed message, you might trust that it's who you think it is. If they gave you the key in person, say, printed on a business card, you might trust it a whole lot more. But of course, it's not feasible to get all your keys in person - email is supposed to be convenient.

Keeping that in mind, let's do a quick thought experiment. In real life, you trust Bill because you've been friends with him for ten years and he's always been reliable and honest. Bill has a friend, Jack, who you have never met. But Bill vouches for Jack, and since you trust Bill, you trust Jack (to a certain extent).

PGP has functionality that emulates these sorts of relationships - the phrase "webs of trust" gets used a lot. When you import someone else's key, you can specify how much you trust that key. And, if you choose, you can sign other people's public keys, which is like vouching that they are who they claim to be. So suppose I have complete trust that John Stone's key is legit, because I got it from him in person. I sign Stone's public key. Now maybe CM just pulled Stone's key off a public server. He doesn't know if he should trust it or not. But say CM already trusts my key - since he trusts me and I have signed (vouched for) Stone's key, CM's PGP program knows that Stone's key is reasonably trustworthy.

The Future of Trust

Stop and think about webs of trust for a second. Isn't it a cool idea? This is the power of social bonds, realized in electronic form. Picture a world where everyone uses PGP. Imagine how hard it would become for frauds to work their way into a position to do any real damage when no one will vouch for them. Imagine the freedom to trust, really trust, people on the Internet. This is where I think PGP could take us.

One More Time, Why?

Okay, so I think PGP is important. But why am I signing all my emails with it, when next to none of my recipients are currently equipped to handle it? I have several reasons, most of which are inspired by John Stone's opinions on this topic:
  • Someone's gotta do it. If we all hang around waiting for other people to use PGP first, it will never happen. By signing my messages with PGP, the benefits are immediately available to anyone who sets it up and imports my key.
  • Advertising the functionality. Sending signed messages advertises my public key. If you want to send me an encrypted message, you know I am equipped to handle it, and you can pull my public key from the signed message to use for encrypting.
  • Proselytizing. This is probably my biggest reason for signing at the moment, and is also my reason for writing this post. I hope that some small percentage of people who receive my signed messages will, rather than being confused or just ignoring the extra stuff, be curious and look into PGP, and maybe realize what a great thing it is. I plan to link to this post in the comment section of the signature, in hopes of furthering this goal.

Final Thoughts

Go! Go install Enigmail or FireGPG! Do it! It's fifteen minutes of time now, but after that, they run quietly and unobtrusively in the background. You can do like I do and sign everything you send out, or you can just use it to verify any signatures you get and sign outgoing messages selectively (I guarantee if you send me a signed message, it will brighten my day). You're making yourself safer, and you're furthering a very worthy cause. The Internet is a cool place, people. But it belongs to us and it's our job to keep it respectable. Use PGP.