Joe Bloggs

[Dave Birch] Having just come from a meeting about the management of multiple identities and the potential commercial structure of a proposition based on pseudonyms, I found myself reading some excellent and thought-provoking comment on the issue of anonymity vs. pseudonymity vs. absonymity starting with a US perspective over at Public Citizen.

The First Amendment protects the right to speak anonymously, and if the bar to such discovery is set too low, much citizen and consumer discussion about the important issues of our day, including the doings of corporations and politicians, will be chilled and hence lost to the marketplace of ideas. If it is set too high, valid claims may be lost. We at Public Citizen have litigated many cases devoted to setting this balance correctly.

[From CL&P Blog: Two new cases on Internet Anonymity]

I can’t say I understood everything (or, indeed, anything) in the legal argument, but I think I agree with the conclusion (applied by the US courts in the examples given) that “commercial” speech is not the same as “political” speech. Companies bashing each others’ products via “astroturf” blogs are not (and should not) be subject to the same privileges as political opponents questioning policies. But, naturally, it is a very fuzzy boundary, and one of the key issues is anonymity. If you are allowed to post anonymously, then it’s hard to

If you read through both stories you see that judges basically seem to be making it up as they go along as to what standards to use in deciding whether or not online anonymity is protectable

[From More Mixed Rulings On The Right To Be Anonymous Online | Techdirt]

Now, I would have thought that one of the reasons why we have judges is precisely so that they can make things up as they go along. If the law was written by people like me, it would be in XML and given the facts of the case as a set of propositions would be capable of delivering justice through an algorithm that would decide the outcome in polynomial time. But it isn’t, so we need judges. Sometimes they come up with odd rulings — look at the fuss about the UK judge who recently ruled that it’s not against the law to smash stuff up if it belongs to people you really don’t like — but, generally speaking, they combine law and common sense.

Unfortunately, as I have constantly complained, common sense is a bad guide to what to do about identity.

We don’t want paedophiles and nazis to be able to groom unsuspecting, innocent children online. Who could disagree with that? In the UK, this “common sense” drove a furore about Facebook that has led to an completely pointless resolution (along the lines of “something must be done, this is something, so let’s do it”).

how can the police help with every teen who is struggling with the wide range of bullying implied, from teasing to harassment? Even if every teen in the UK were to seriously add this and take it seriously, there’s no way that the UK police have a fraction of the resources to help teens manage challenging social dynamics. As a result, what false promises are getting made?

[From danah boyd | apophenia » Facebook’s Panic Button: Who’s panicking? And who’s listening?]

I would be utterly shocked if the presence of this button makes even the slightest difference. The kids who are smart enough to press it when they are approached are presumably smart enough to know that they are being approached, if you see what I mean, and the kids who press it because they are being bullied by their peers in some way are not going to get any help, so what’s the point? The “Facebook murder” that Danah refers to might just as well have been called the “Ford Mondeo” murder, since both technologies were crucial to the crime, and as she points out having this button would not have averted the tragedy.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Spot the looney

[Dave Birch] I happened to be chatting to our friend Tony Poulos from the Telecommunications Manager’s Forum about new service possibilities for mobile operators facing commoditisation and declining ARPUs, and one of the areas he got me to brainstorm was identity services.

One of the world’s leading experts in this field, David Birch, spent some time with me explaining how mobile operators, in particular, could actually become ‘smart pipes’ with financial transactions. The ‘secret sauce’ according to Birch, lies in the ability for operators to provide secure identification linked to the SIM providing private and public keys for multiple providers.

[From The 'secret sauce'? | Poulos Ponderings]

The mobile phone is the obvious “remote control” for identity, and I’m surprised that operators haven’t moved into this space more aggressively (there are some exceptions, of course, such as Turkcell). This led me to think, again, about the nature of the value-added identity infrastructure that might be built.

One thing, I think, is clear: the goal shouldn’t be to build a virtual version of the current identity “system”. At the moment, the online world has a dynsfunctional identity layer: it’s not really anonymous but it’s not really absonymous either.

Implementing an Internet without anonymity is very difficult, and causes its own problems. In order to have perfect attribution, we’d need agencies — real-world organizations — to provide Internet identity credentials based on other identification systems: passports, national identity cards, driver’s licenses, whatever. Sloppier identification systems, based on things such as credit cards, are simply too easy to subvert.

[From Schneier on Security: Anonymity and the Internet]

Bruce goes on to note that in the real world, half-baked identity management schemes actually make matters worse, not better. You can’t argue that having people sort-of-identified is better than having them not identified at all. It isn’t.

We have nothing that comes close to this global identification infrastructure. Moreover, centralizing information like this actually hurts security because it makes identity theft that much more profitable a crime.

[From Schneier on Security: Anonymity and the Internet]

This is why I am naturally somewhat suspicious of attempts to slap identity on the ends of the network rather than having identity management as a value-added service that is part of the network infrastructure and quite distinct from the issue of which identities will be managed (in other words, the web server has PKI built in, but it doesn’t provide the identities, it facilitates identity providers to do so). Simple solutions to this difficult problem — along the lines of the Chinese attempts to have “real-name registration” of Internet access by decreeing that everyone has to present their ID number when connecting — don’t work.

Mundie and other experts have said there is a growing need to police the internet to clampdown on fraud, espionage and the spread of viruses. “People don’t understand the scale of criminal activity on the internet. Whether criminal, individual or nation states, the community is growing more sophisticated,” the Microsoft executive said… He also called for a “driver’s license” for internet users. “If you want to drive a car you have to have a license to say that you are capable of driving a car, the car has to pass a test to say it is fit to drive and you have to have insurance.”

[From UN agency calls for global cyberwarfare treaty, ‘driver’s license’ for Web users | Raw Story]

It’s a bad analogy for a start, because cars are covered by product liability laws and Microsoft’s software isn’t, but the law on driving licences doesn’t stop cars from being stolen, used in crimes and being in accidents. If there were an Internet driver’s license, the 419 scammer wouldn’t apply for one, he’d make a fraudulent one just as he would in the physical world, and then use it to open bank accounts and so forth.

Many of the forgeries are “know your customer” documents such as utility bills and driving licences, which are then used to open bank accounts under false names.

[From Police war on fake ID factories as fraudsters net millions | News]

Ah, you might say, but in the Internet world we can use cryptography and similar geek tools to stop people from forging licences. In which case, the scammers will still get their licences.

An Irvington, N.J., man who operated a driving school pleaded guilty yesterday in federal court to bribing Pennsylvania driver’s license examiners to obtain phony licenses for his customers… Authorities said Lominy began paying bribes to a PennDOT driver’s license examiner, Alexander Steele, in early 2009 in exchange for Steele issuing licenses to his customers even though they weren’t Pennsylvania residents and hadn’t passed a written test or driving exam.

[From He admits bribing PennDOT examiners to issue fake licenses | Philadelphia Daily News | 04/02/2010]

I see reports of people being convicted for taking other people’s tests for them for money in the UK from time to time as well. So, an Internet driving licence? I don’t think this is a way to improve security. I might go further and say that compared to this, the Monster Raving Looney Party’s manifesto commitment to ban envelopes and force everyone to communicate via postcards looks more practical.

All sealed private letters to be banned – we propose that all letters must be written on postcards, and emails to be routed through police stations. (After all honest citizens have nothing to hide)

[From Official Monster Raving Loony Party - manifesto proposals]

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

In a bit of a State

[Dave Birch] If you build a stable door, then one day you will inevitable find yourself locking it while your horse disappears over the horizon. There's been no better illustration of this in recent times than the recent hulabaloo about Google in China. Apparently, Chinese "hackers" were found it rather easy to break into the e-mail accounts of human rights activists and so forth, because Google had been forced to build a system to do precisely that.

That's because they apparently were able to access a system used to help Google comply with search warrants by providing data on Google users, said a source familiar with the situation, who spoke on condition of anonymity because he was not authorized to speak with the press. "Right before Christmas, it was, 'Holy s***, this malware is accessing the internal intercept [systems],'" he said.

[From Google attack part of widespread spying effort]

So companies are forced to build a stable door, and then when the inevitable happens, people appear shocked. The root problem is, naturally, that there is no underlying strategy: we fight using the technology of the next war but the tactics of the last one, as someone once said but I couldn't find out who by googling. If you want proof of this, you only need consider the US government's official response to the incident in a speech by the Secretary of State, Mrs. Clinton, that cofnirmed one of my most basic criticisms of government policy in this cyber age:

The speech made it obvious that State Department officials do not have a coherent view on online anonymity. On the one hand, they want to crack down on intellectual property theft and terrorists; on the other hand, they want to protect Iranian and the Chinese dissidents. Well, let me break the hard news: You can't have it both ways and the sooner you get on with "anonymity for everyone" rhetoric, the more you'll accomplish.

[From Is Hillary Clinton launching a cyber Cold War? | Net Effect]

In fact, US (and other governments') policy in this area isn't just confused and pointless, it's actually dangerous. While I was googling for references, I discovered that the always sensible security expert Bruce Schneier had used this story to make the same point.

The news here isn't that Chinese hackers engage in these activities or that their attempts are technically sophisticated — we knew that already — it's that the U.S. government inadvertently aided the hackers.

[From U.S. enables Chinese hacking of Google - CNN.com]

You can't have privacy without security, as the relatively old saying goes. Ah, you might object, but there's a greater good argument: security without privacy is the only way society can fight the bad guys. We must be able to read people's Google mail accounts because we need to track down criminals and terrorists. And, indeed, this is sort of true. If you know that Osama bin Laden is sending me e-mail, then you might want to investigate me a little further. And I imagine that obtaining the contents of all of my e-mails, from Google, might be a convenient way to do it (although, of course, if I am a terrorist and I know that government is able to read my mail, then I will send misleading e-mail and use an alternative secure channel to conference my confederates). Anyway, you think I'm a bad guy so you want to be able to go to Google and get all my mail. This already happens, in fact.

Prosecutors obtained a CD-ROM disk from Google Inc. this week of Mr. Tannin’s e-mail messages from Nov. 20, 2006, through Aug. 12, 2007. The two funds collapsed in June 2007. Mr. Cioffi, 53, and Mr. Tannin, 48, were indicted for fraud, and Mr. Cioffi also was charged with insider trading, the first managers accused of criminal charges from a company that collapsed in the financial crisis. The hedge funds’ failure cost investors $1.4 billion.

[From E-mail Shows Fear of ‘Blow-Up Risk’ at Bear Fund - DealBook Blog - NYTimes.com]

To be honest, I'm not sure what the fuss is about. If you send something in an e-mail, then as far as I am concerned you have no reasonable expectation of privacy. If you wouldn't put it on a postcard, then you shouldn't put in an e-mail (was it Phil Zimmerman of PGP who first said that?). If these hedge fund guys really wanted to send secret messages to each other then they could have used anonymous comments on an obscure blog, rolling IM accounts changing in a pattern known only to them or, ahem, encryption. Havent't they ever watched the world's best TV drama, "The Wire"?

So I'm not saying that prosecutors shouldn't try to go and get these e-mails. But should they get them from Google? I have a book on my shelf somewhere — the title won't come to mind — which says that, essentially, the government doesn't regulate books because it can't and it does regulate TV because it can (this was a few years ago). Surely this is what is going on here. It might be harder to nail those guys without a copy of their Google e-mail, but is it plausible that without the Google e-mail they will get off? Well, in this case they got off because of the e-mails, as far as I can see.

the prosecution blew it — on two counts. First, in devising the original indictment for conspiracy and securities fraud against the two defendants, Ralph Cioffi and Matthew Tannin, it relied on damning snippets of lengthy e-mail messages that when viewed in their entirety proved to be highly ambiguous. Second, the prosecution made a reductionist opening argument claiming the men were nothing more than out-and-out liars, needlessly raising the bar in terms of what it had to prove to jurors

[From Bear Stearns Trial: How the Scapegoats Escaped - DealBook Blog - NYTimes.com]

Suppose you are a policeman. If Osama bin Laden is sending me e-mail every day, but you can't get the contents of those e-mails from Google or BT, is that worse for society than Osama bin Laden being able to read all of your e-mails? The mere fact that I'm getting e-mail, text message or care packages from a cave in Afghanistan is enough for you to put me under surveillance and from then on other methods can take over. Look, I don't know what the answer is either, but I do know that there is a question, and therefore understand that there is a danger

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Jorge Krug, Banrisul

[Dave Birch] Jorge F. Krug is the head officer of the IT Security Division of Banrisul, State Bank of Rio Grande do Sul, Brazil, and has a seat in a number of IT associations and committees, including Brazilian Bank Association (FEBRABAN)’s Digital Certification Committee, Sucesu-RS (Society of Computer Science and Telecom Users of the Rio Grande do Sul State), ASBACE (Brazilian Association of State and Regional Banks). Mr. Krug is also the head of AC-RS (Rio Grande do Sul State Digital Certification Authority). In this podcast he talks about the introduction of the Banrisul EMV card with PKI on board, a project previously discussed in detail on this blog.

Listen here in either [Podcast MPEG4] or [Sound-only MP3] format.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Trans-mission

[Dave Birch] Should people be allowed to have “anonymous” prepaid mobile phones (well, SIMs) or not? It’s a simple question, but a complicated subject. And it’s worth exploring because it helps us to have a real, focused discussion about practical privacy and security issues. The subject came up because of one of the current hot topics in the UK, which is the government’s proposed “crackdown” (although “crackup” might be a better description) on the authorised copying of copyright material. Once the government has disconnected most broadband users in Britain through the “three accusations and you’re out” policy, many desperate internet addicts will be driven to using mobile connections to continue online banking, reading about “I’m a celebrity get me out of here” behind the Murdoch paywall and playing World of Warcraft. At which point, the mobile operators will come under pressure to start disconnecting people as well. But as the always spot-on mobile industry analyst and Forum friend Dean Bubley notes

“On one hand, the government’s trying to encourage internet connectivity — bridging the digital divide — but a lot of people in lower socioeconomic groups are on prepay, and the vast majority are anonymous,” Bubley said

[From Mobile industry 'cannot identify pirates' - ZDNet.co.uk]

So the mobile operator won’t be able to turn over the name and address of the supposed copyright pyrate. When the letter from Apple Corporation arrives at Vodafone asking them to turn over the name and address of the person who downloaded “Love Me Do”, Vodafone won’t be able to tell them (so presumably Vodafone will then be found in contempt of court or something and their internet access will be turned off).

So what to do? Well, one approach (followed in many countries) is simply to force all prepaid phones to be registered with the authorities. In the UK, the government might use its splendid new national identity register, for example, to ensure that all prepaid phones have a passport or national identity card connected to them them. And, as in Spain, take immediate action against those terrorists, money launderers, child pornographers and criminals who refuse to do so.

Spanish mobile operators last night cut off an estimated three to four million pre-pay mobile phones whose owners had not followed government instructions to register their devices.

[From Spain cuts off 3m pre-pay mobiles • The Register]

I can see exactly why law enforcement and government agencies object so strongly to anonymous mobile phones (although they still allow people to post letters anonymously) but I think they are wrong to react in this way. The truth is, the criminals will just use other peoples’ phones and will be even harder to track and trace than they were before.

Consider the most prosaic of examples. Where I live, in a deprived part of Europe called “Surrey”, a window in the house opposite to ours was smashed by a gang of feral youths. Sadly, we didn’t see this happen so we unable to assist the local constabulary. But suppose I had seen it happen? I have, currently, four prepaid mobile phones about my person (they are used for various demos and experiments for work) so I would have just picked up one of these phones and called the police with the details of the incident and a description of the yobs.

But now suppose that my prepaid phones were now connected to me through the national identity register? Now there’s no chance that I will pick up one of them and report the crime, because I’d be worried that my name and address would get (via the police or the database) to the gang in question.

This may be a silly example, but from battered women to corporate whistleblowers there are plenty of good reasons for allowing anonymity. We need this to be part of the infrastructure.

All this does prove, though, that there is a legitimate place for digital anonymity, and I hope that any identity management system required by the US government and others will allow anonymity and not prevent it.

[From Tech and Law: Technology, domestic violence, anonymity]

Note the important qualification here: there is a legitimate place for “digital anonymity”. I would go further than that and say that without digital anonymity, we are creating the wrong kind of infrastructure for a successful and prosperous society. Now, your web site may choose to allow or decline access by digitally known, pseudonymous or anonymous identities. If you are a web site discussing Iranian democracy, you may well insist on the latter. If you are government department, you may insisit on the former. The infrastructure must cope with both.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Verily

[Dave Birch] I enjoyed Scott Silverman's talk about privacy and security at ID World. Scott (the devil, according to CASPIAN) is the CEO of Verichip, the company that developed the first FDA-approved RFID chip for human implantation. (It's just a passive RFID chip containing a 16-bit identification number). Apparently, they had had some 900 emergency rooms across the US signed up for the service before the "privacy backlash" started. Opponents of the system told the newspapers that the chips caused cancer, and that was that.

Now, to be honest, I'm very sympathetic to Scott. A couple of years ago, I contacted Verichip because I thought it would be fun to have a Verichip implanted in my arm ready for the Digital Identity Forum, but they said no (spoilsports). My cat has one, and I'm jealous.

Anyway, the point is that the privacy backlash was so great that the stock price collapsed and the company — which was reduced to a shell — has now been restructured as PositiveID with Scott as the majority shareholder. They have a number of initiatives, one of them being "PatientID" which will link high-risk patients (eg, Alzheimer patients) to their medical records. Now, as far as I can see (and I'm speaking from the point of view of someone with an Alzheimer's sufferer in the family) this is a splendid idea. I'm pretty privacy sensitive, but this is an application that makes absolute sense to me. If I had Alzheimer's, I'd want a chip so that if I get lost or confused, a doctor can instantly find out who I am and what my conditions and medications are. You could do it by fingerprinting me, or iris scanning or whatever. But it appears to quick and simple to use the chip instead.

Scott also mentioned their "HealthID" initiative that will link sensors to the chip: so, for example, you could have a glucose-sensing chip for some types of diabetes so that when the chip is read to identify the patient it will also report glucose levels. If I had diabetes, I would much rather have one of these than prick my finger and test drops of blood. I wouldn't want everyone to be able to read it though, and this is where the problem comes: we need to have some form of standard privacy-enhancing infrastructure that sits above the "chip layer" to make this all work properly.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Out of control, up to a point

[Dave Birch] I re-read an excellent post over at Emergent Chaos. It reflected an important discussion between two people, both of whom I take very seriously. To paraphrase and simplify horribly, Bob thinks that the social structures maintain privacy, Adam thinks that technological structures maintain privacy.

In a world where some people say “I’ve got nothing to hide” and others pay for post office boxes, I don’t know how we can settle on a single societal norm. And in a world in which cheesy-looking web sites get more personal data — no really, listen to Alessandro Acquisti, or read the summary of “Online Data Present a Privacy Minefield” on All Things Considered… — I’m not sure the social frame will save us.

[From Emergent Chaos: Bob Blakley Gets Future Shock Dead Wrong]

The lack of a “norm” is a good point here, and I have to say it made me think. We should be developing tools that allow people to construct their norms (within boundaries, obviously) but not setting out a norm so that the tools can only implement one model. For this reason, amongst others, I tend to come down on the more technological side of this argument, which is why I’m so keen to see privacy as part of customer propositions and privacy-enhancing technologies as part of the systems being built in both public and private sectors.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Close enough for jazz

[Dave Birch] I had a typical fascinating and productive discussion with Hazel Lacohee and Piotr Cofta when we last got together. We were kicking around some ideas for finding practical ways to improve privacy, security and other good stuff while simultaneously worrying about the government's approach to the interweb, broadband and ID cards. With the right combination of technology and vision we can take an entirely different view of the "identity problem" and how to solve it. In a decentralised fashion we can see identity develop as an emergent property of trust networks, shaped by evolution to be fit for purpose or, as Piotr Cofta puts it, "good enough identity". Good enough identity (GEI). I love it.

I'm certain that there is merit in this approach. There is a real difference between between trying to create a kind of "gold standard" identity that delivers the highest possible levels of authentication and identification in all circumstances and trying to create an identity that is useful (defined by: reduces total transaction costs and, in my world, aligns social costs with private costs). Therefore, a utilitarian approach of trying to do something, anything to make the identity situation improve for individuals and organisations, we might be better off starting with some simple building blocks and building up rather than by starting with a national ID card (I mean, a 21st-century national ID card of the psychic ID kind, not electronic cardboard) and driving that down. Go from the personal to the enterprise, from the enterprise to government.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

What a cunning stunt

[Dave Birch] I am, very literally, green with envy. I count myself as a reasonably good speaker, and I try to use narrative and historical examples to explain key principles. But nothing beats a good demo, and I saw an excellent one today, one that I wish I'd thought of!

At the Intellect conference on Identity & Information in London today, Edgar Whitely from the LSE gave a terrific presentation. He was pointing out that the principle of data minimisation in identity systems is important, but he did it in a particularly arresting way.

Here's what he did.

He showed this recent newspaper photograph of the British Home Secretary, Alan Johnson, showing off his new ID card and holding it up to the camera. This version comes from The Guardian….

Alan Johnson reveals the design of the British national identity card

Alan Johnson reveals the design of the British national identity card. Photograph: Stefan Rousseau/PA

As you can see in the picture, for reasons that will be not fully explained in a moment, the UK ID card has the holder's full name, date of birth and place of birth on it. These three data points are sufficient to uniquely identify the overwhelming majority of the population. So Edgar went to the Identity & Passport Service birth certificate ordering service and put in the details from the Home Secretary's card. He then paid his £10 and… with a suitably theatrical flourish, Edgar produced the copy of the Home Secretary's birth certificate that he had been sent in the post. Note that Edgar hadn't done anything wrong. As James Hall, the head of IPS who was on the same panel, pointed out, in the UK anyone can order a copy of anyone's birth certificate. He said that if you are a celebrity then hundreds of people will order copies of your birth certificate every year, which had never occurred to me. I'm sure James is right, but it does seem a little odd that people who want to commit identity theft will simply have to look at their mark's ID card to get started.

Edgar hadn't used the birth certificate to open a bank account or get a driving licence or anything, he was just making the point that if we don't adopt the right principles (eg, data minimisation) for identity systems, then we run the risk of making identity theft worse. It was a great presentation and a super stunt. Well done.

Anyone familiar with my deranged rantings about psychic ID (ie, virtually nobody) will be familiar with the general point: a characteristic of a 21st-century ID scheme is that it should only give up information necessary to enable a transactions, nothing more or less. So, if you are authorised to ask my ID card whether I am over 18 or not, that's all it should tell you. Not my name, not my address, not my age or date of birth. Just whether I am over 18 or not and that's it.

The current ID card scheme does not have this key characteristic, not for any functional reason but because the ID card and passport were jumbled up for a political purpose — the purpose being, as far as I know, to make it harder for an incoming administration to scrap the scheme — that constrains the design and implementation. Since the government wants the ID card to be used as a travel document within in the EU, it has to have certain human-readable information on it. That's why it gives away the key data points that make it tempting for criminals to kick-start their identity theft antics.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The DNS of the industrial bourgeoisie

[Dave Birch] I have a vague memory — which five minutes googling cannot substantiate and I'm too lazy to go and find the book in the other room — that somewhere in the Gulag Archipeligo by Aleksandr Isaevich Solzhenitsyn there is mention of Stalin's desire to have a more revolutionary telephone system where all calls had to go through a central exchange and be encrypted so that Stalin could listen to everyone else's calls but his would be encrypted to remain secret. The prisoners with relevant skills were supposed to be designing this while in the gulag. It never worked, of course, and the Soviet Union had appalling telecommunications infrastructure as a consequence because the communications revolution was halted by the dictatorship of the proletariat: there's some deep incompatibility between innovation and centralisation. I couldn't help thinking of this when I read about the calls by Eugene Kaspersky to have a more Stalinist internet:

The CEO of Russia's No. 1 anti-virus package has said that the internet's biggest security vulnerability is anonymity, calling for mandatory internet passports that would work much like driver licenses do in the offline world.

[From Security boss calls for end to net anonymity • The Register]

What he means by this is that he wants a technologically complicated and expensive solution to be implemented so that ordinary people are inconvenienced to the maximum while criminals can roam free (which is what would happen). Creating such an asymmetric solution is not the way forwards: for one thing, who would decide what to censor?

A little local controversy involving the Church of Scientology and its critics could lead to curbs on the right to anonymity of anyone using the web.

[From Scientology seeks to squash anonymity • The Register]

We already have experience of this "solution" in the UK. Laws giving a wide variety of bodies the ability to monitor CCTV, the internet, phone calls and everything else which were supposed to save us from international terrorism are used by local councils to stop people from trying to get their children into better schools and to check that people are recycling enough of their rubbish. I'm sorry, but creating a world in which anyone can read anyone else's e-mail, track anyone else's web browsing, see what anyone is reading is not the way stop Russian virus writers from taking over everyone's PCs. We need an identity infrastructure.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.