Over the past two months, I've been writing a series of posts on the intersection of politics and technology. The series consists of two bookend posts, with a number of focused topic discussions between them; this is the second bookend post.
Programmers are incredibly good at finding stuff to get worked up about. What's your favorite text editor? Vim? emacs? Maybe (god help you) Notepad? gedit? kate? nano? Or maybe you don't use an editor -- ok, then what's your favorite IDE? Eclipse? Visual Studio? NetBeans? Something obscure and language-specific?
Speaking of, what's your favorite language? Python? C? Java? C++? C#? Javascript? Lisp? Haskell?
Astute readers may have picked up on a theme here: Unless you're getting ready to draft a specification or set up a group workflow, none of these questions matter at all. And yet, we're all expected to have strong opinions on them. Conversations like these cement computer science's male-dominated reputation, because they are all about unabashed dick-wavery.
I wouldn't mind this so much if it weren't for the fact that it distracts a lot of smart people from things that actually matter. If you're making the case that easter eggs like "M-x tetris" proves yours is the editor of the gods, you're not making the case that, say, fair use provisions are critical to the future of internet culture. If you're arguing ad nauseam that Eclipse is so bloated as to be all but unusable, you're not wrong, but you're also not learning anything. If you're arguing that modal editors like vim are better because the lack of chording means you're less likely to get carpal tunnel, that's nice, but also kind of weirdly specific.
There are thousands of these silly little issues. My goal with this series was to try to find software-related issues that actually, in some broader sense, matter. With that almost comically lofty goal in mind, let's take a lightning tour of the topics visited.
We started out with a discussion of boot security, where we tried to wrap our heads around the question of how to detect (or maybe even prevent) hardware attacks. The political angle: the recently adopted UEFI standard claims to solve this problem, but in fact makes it worse in a way that
Next, we took a look at the still-emergent "sharing economy", and explored the good and the bad which lurk therein. One takeaway was that while change can be very good, "disruption for disruption's sake" is an absolutely absurd (and absurdly pervasive) guiding principle. Another takeaway: as services get decentralized, it gets really hard really fast to regulate them in any meaningful way, and this can lead to some really bad situations.
The sharing economy post momentarily brushed up against the issue of online platforms serving as facilitators for harassment and abuse. The next installment dealt with this issue head-on. It's incredible that there are large groups of people to whom which this post's title, "Ignoring Abuse On Your Social Platform Is Not a Neutral Stance", is actually a controversial claim.
The final "body" post, "You Can't Legislate Reality", took on a somewhat broader scope, looking at ways that the legislature has gotten tech completely wrong in mind-boggling and often dangerous ways. In particular, that post saves some heated language for a discussion of the TPP.
Now that we've reached the end, there's only one thing left to do. I've heard it said that all that's needed for the triumph of evil is that the good do nothing. Now, that's not entirely wrong, but it's not entirely right either. It's good to be educated about the issues facing your domain of expertise. But that alone is not enough.
A friend once asked me to help fix his computer, and he refused to believe me when I told him I couldn't. "But you're a computer science major!" Yeah, I replied -- so I can give you a really detailed walkthrough of why it's broken! But that doesn't get us any closer to finding the fix. This is the difference between diagnosis and cure.
Tens of thousands of computer hobbyists sitting in tens of thousands of homes or offices could all independently educate themselves about the issues facing their field, all get tremendously incensed about something like the locking-down of router firmware or the government-mandated corruption of digital maps, and all independently decide that Something Must Be Done... but it wouldn't make one iota of difference unless they decide, given that knowledge, to do something.
The fact is, being able to explain exactly how and why the world is getting worse does nothing by itself to forestall this worsening. The people worsening your world for their own interests could not care less how well or poorly you understand what they're doing, as long as you don't try to get in their way. But how do we get in their way?
It's not easy: Most of these issues are national in scope, and very few of us have standing invitations to that particular big-kids table. But that's a bit of a silly complaint coming from people in a field where median incomes are almost all six figures. We've got money to burn, and there are groups who've been fighting the good fight for decades, and they accept donations.
Foremost among these groups is the EFF, a non-profit that relies largely on donations for its funding. We all owe them a debt of gratitude for the work that they've done towards our community's ends. As with any organization, donations are critical to retaining that focus. Once you land that sweet job and start making more money than you know what to do with, maybe think about starting to pay that debt back.
Friday, February 26, 2016
Friday, February 19, 2016
You Can't Legislate Reality
For thousands of years, geometers tried in vain to square the circle -- a task which, in 1882, was mathematically proven to be impossible. A result like this isn't really something you get to debate the specifics of. They call it "proof" for a reason.
That's part of what made the 1897 proceedings of the Indiana General Assembly so bizarre -- because it was there that lawmakers tried to pass a law declaring the problem solved. The bill might well have been passed by the senate, were it not for the intervention of a visiting professor.
This incident is one instance of a theme which recurs whenever legislature collides with math or technology. The legal system just can't seem to wrap its head around how science works. Many are inclined to see malice in this tendency -- a sort of deliberate commitment to backwardness, a gleeful embracement of that which is known to be wrong. Tempting as this is, it's a good rule of thumb never to attribute to malice that which is adequately explained by stupidity.
What that rule of thumb fails to capture, though, is that many cases have plenty of room for stupidity and malice.
In the instance of Indiana's Pi law, the ignorance of certain groups within the legislature was maliciously exploited to feed the egotism of the bill's author, an amateur mathematician trying to make his reputation "solving" impossible problems.
In the instance of the Scopes trial, the scientific illiteracy of certain parties involved was exploited to the benefit of evangelical religious fundamentalists with a well-established track record of using legislation in legally dubious ways.
And in the instance of many recent legal cases concerning copyright, patent law, digital rights management (DRM), intellectual property, cryptography, and hardware design, the ignorance of the legislative and judicial systems on technical matters has been (and continues to be) exploited by avaricious and sometimes malicious vested interests in both government and industry, who use their leverage to advance profoundly antisocial ends.
Cory Doctorow argues compellingly in his recent book, Information Doesn't Want to be Free, that modern attempts at digital rights management (which he refers to using a more general term, "digital locks") are not only futile but also harmful to everyone involved. The essential problem (and here I do Doctorow a great disservice by trying to briefly summarize some of his main points; really, his treatment of the topic is second to none and I can't recommend that book highly enough) is this: What digital rights management schemes try to do is to provide a user with access to a technology, but only for certain purposes -- which, to put it bluntly, is just not possible.
Computers are copying machines. They are very good at copying data, and they can do it at virtually no cost. If you can watch a movie on screen, what's to stop you from telling your display to quietly, in the background, record everything it's displaying? Likewise for audio: once this data is in the user's hands, the users can do what they want with it. This shouldn't be a surprise: Computers are general-purpose, so this sort of flexibility is in their very nature.
All sorts of "solutions" have been proposed. Many devices now ship with purpose-built hardware meant to take control of a computer away from its user for the sake of giving manufacturers and content distributors stronger DRM controls.
Sony, never one to favor such above-the-board approaches, for some time had a standard practice of installing a backdoor rootkit on literally every computer that played one of their CDs, just so they could regularly check up on the user and make sure you hadn't violated copyright. Read up on how that thing worked -- it's seriously evil.
Not that we're going to get into it here, but if you care about encryption and you haven't heard of the clipper chip, that's a history lesson you might want to give yourself. Focus your attention on the "criticisms" section, and then maybe read the case made by Bruce Schneier, who has more credentials here than almost anybody. He also made a short post not to long ago about how the Clipper debacle relates to the issues we face today.
It might be hard to believe the situation has worsened in the last decade, but in some ways it has. The much-maligned Trans-Pacific Partnership (TPP) has been negotiated largely in secret, so that until November of 2015 nobody except for government and big business interests even knew what it entailed. Now that a full draft has been released, we can confirm that the situation is even worse than originally thought. The EFF has a good discussion of the main points that deal directly with technology law. This EFF article hits the major issues. Of particular note, the language is designed to stifle things like conducting security research, fixing your own software and hardware, or talking about whether it's even possible to break DRM. And if you've ever pirated an album, may god have mercy on your soul. (Edited to add: Less than an hour after I published this post, Doctorow shared on his blog another simple breakdown written in conjunction with the EFF, which is well worth a read)
These are all things they want, and things they've been trying to implement, but software solutions to these things aren't possible, and so they've turned to legislating reality instead. If they can't outright stop you from copying a copyrighted file, and they can't justify undermining the designs of hardware (including the hardware they use!) in the process of trying to stop you, they can at least try to pass international laws letting them break into your home, confiscate your computer hardware, potentially destroy any or all of it, seize any domains you own, and throw you in jail, if they even suspect you've ever broken copyright. Yes, really. Go read the documents if you don't believe me -- it's all in there.
At what point are we going to recognize how fucked up it is that these are the priorities driving the world's major governments? When is enough enough? If this isn't enough to push us to that point, what will be? Will anything? Do we really have so little spine, so little self-respect? Is there no limit to the abuse we will tolerate?
At what point are we going to recognize how fucked up it is that these are the priorities driving the world's major governments? When is enough enough? If this isn't enough to push us to that point, what will be? Will anything? Do we really have so little spine, so little self-respect? Is there no limit to the abuse we will tolerate?
Friday, February 12, 2016
Ignoring Abuse On Your Social Platform Is Not a Neutral Stance
There are some pretty big problems with social media right now. Or, it might be more accurate to say there's one big problem -- but it's really big. The problem is how, in this age, we deal with abuse and harassment online.
It borders on impossible to express the scope of online abuse and harassment. Probably the most famous example is Gamergate, which we're not going to get into here, because I'd rather eat glass than even do that shitstorm the dignity of a summary. Look it up in another tab if you really don't know.
The point is, there are a number of well-known cases where specific individuals have been targeted by huge crowds for harassment and abuse. But there are orders upon orders of magnitude more cases that have not become even remotely as well-known, but which nevertheless have caused very real harm in people's lives.
In 2014, the Pew research center conducted a study on harassment, with some striking findings. The worst forms of abusive harassment targeted women disproportionately more than men. This may not come as a surprise, but the sheer numbers involved are staggering: 26% of women aged 18-24 reported stalking, 25% reported sexual harassment, and 18% reported sustained harassment. The corresponding figures for men were 7%, 13%, and 16%, respectively.
The takeaway is this: If we sincerely care about fostering diversity in online communities -- and we all should -- then the first step is to recognize how abusive harassment disproportionately targets some demographics over others. Otherwise, it is impossible to put together a coherent picture of how these behaviors take place on whatever platform you might be dealing with.
It goes beyond harassment, in fact: A recent study suggests that women's contributions to open-source projects on Github tend to be accepted more often than men's -- unless the reviewer knows that the code was submitted by a woman, in which case the acceptance rate plummets. Why is the gender distribution of core developers for major open-source projects so lopsided? Gosh, I wonder.
But I've managed to sidetrack myself again. The real point I want to be getting to here near the end of the post is about how institutions handle abuse, or how they fail to. I'm mostly going to pick on Twitter, because if I focused on Reddit et al. instead we'd be here all fucking night. It's mind-bogglingly bad. Ellen Pao tried to take some small, common-sense steps to improve things, and look how that went.
That reminds me: There's one thing we have to get out of the way right now. Let me put it this way. I adore freedom of speech -- it's an absolute, unconditional prerequisite to any broader freedoms -- but that fondness does not extend to most of its most vocal invokers. You know, the people who, soon as they start to sense resistance, start bellowing that you can't do this! I have freedom of speech!
There are so many things wrong with this. First off, not everyone lives in the United States, which is almost never even acknowledged here. Like, come on. Second -- iamnotalawyer -- the first amendment grants you the right to free speech, not the right to be listened to. Third, there are notable exceptions to free speech, like for fighting words or specific kinds of hate speech. Fourth, if someone points out that what you're doing is actively harmful, and your best response is "yeah, but you can't make me stop", that really should prompt some serious introspection. Free speech is great, but having nothing on your side except free speech? Slightly less great.
With that out of the way, here's a couple notes on Twitter in particular. Twitter gets a kick out of pretending they take a neutral stance towards content shared on their platform. They've called themselves 'the free speech wing of the free speech party'. This blind enthusiasm might remind you of a discussion we just had. The issue is, serious harassment restricts ordinary people's willingness to exercise their freedom of speech, both due to emotional fatigue and, in many cases, the fear of personal harm. Refusing to take action against this form of harassment is, unavoidably, an implicit endorsement of its consequences.
So make no mistake: Freedom of speech is still restricted under this "pro-free-speech" platform. It's just that instead of restricting the speech of vitriolic spewmongers who devote countless hours to tormenting their fellow human beings, the platform restricts the speech of their targets. This is not a neutral stance, it is a pro-vitriol stance. I don't think it's an exaggeration to say that this stance is, in fact, anti-compassion. And, of course, it should almost go without saying that this stance is also implicitly every bit as sexist, racist, and otherwise bigoted as the abusers it enables are. How is anyone okay with this?
Motherboard has an interesting timeline outlining how Twitter's rules have changed over its lifespan, along with the cultural shifts that accompanied these changes. It's an interesting story. One big takeaway is that, while Twitter has made some good changes in the past couple of years, its changes have not been universally positive, and we still haven't yet reached a good place. One anecdote in particular comes to mind. Just the other week, a parody account mocking Twitter support and particularly support's reluctance to suspend or otherwise take action against abusers and harassers...
...was itself, for a time, suspended. At least it's good to know the account suspension feature still works, I suppose.
It borders on impossible to express the scope of online abuse and harassment. Probably the most famous example is Gamergate, which we're not going to get into here, because I'd rather eat glass than even do that shitstorm the dignity of a summary. Look it up in another tab if you really don't know.
The point is, there are a number of well-known cases where specific individuals have been targeted by huge crowds for harassment and abuse. But there are orders upon orders of magnitude more cases that have not become even remotely as well-known, but which nevertheless have caused very real harm in people's lives.
In 2014, the Pew research center conducted a study on harassment, with some striking findings. The worst forms of abusive harassment targeted women disproportionately more than men. This may not come as a surprise, but the sheer numbers involved are staggering: 26% of women aged 18-24 reported stalking, 25% reported sexual harassment, and 18% reported sustained harassment. The corresponding figures for men were 7%, 13%, and 16%, respectively.
The takeaway is this: If we sincerely care about fostering diversity in online communities -- and we all should -- then the first step is to recognize how abusive harassment disproportionately targets some demographics over others. Otherwise, it is impossible to put together a coherent picture of how these behaviors take place on whatever platform you might be dealing with.
It goes beyond harassment, in fact: A recent study suggests that women's contributions to open-source projects on Github tend to be accepted more often than men's -- unless the reviewer knows that the code was submitted by a woman, in which case the acceptance rate plummets. Why is the gender distribution of core developers for major open-source projects so lopsided? Gosh, I wonder.
But I've managed to sidetrack myself again. The real point I want to be getting to here near the end of the post is about how institutions handle abuse, or how they fail to. I'm mostly going to pick on Twitter, because if I focused on Reddit et al. instead we'd be here all fucking night. It's mind-bogglingly bad. Ellen Pao tried to take some small, common-sense steps to improve things, and look how that went.
That reminds me: There's one thing we have to get out of the way right now. Let me put it this way. I adore freedom of speech -- it's an absolute, unconditional prerequisite to any broader freedoms -- but that fondness does not extend to most of its most vocal invokers. You know, the people who, soon as they start to sense resistance, start bellowing that you can't do this! I have freedom of speech!
There are so many things wrong with this. First off, not everyone lives in the United States, which is almost never even acknowledged here. Like, come on. Second -- iamnotalawyer -- the first amendment grants you the right to free speech, not the right to be listened to. Third, there are notable exceptions to free speech, like for fighting words or specific kinds of hate speech. Fourth, if someone points out that what you're doing is actively harmful, and your best response is "yeah, but you can't make me stop", that really should prompt some serious introspection. Free speech is great, but having nothing on your side except free speech? Slightly less great.
With that out of the way, here's a couple notes on Twitter in particular. Twitter gets a kick out of pretending they take a neutral stance towards content shared on their platform. They've called themselves 'the free speech wing of the free speech party'. This blind enthusiasm might remind you of a discussion we just had. The issue is, serious harassment restricts ordinary people's willingness to exercise their freedom of speech, both due to emotional fatigue and, in many cases, the fear of personal harm. Refusing to take action against this form of harassment is, unavoidably, an implicit endorsement of its consequences.
So make no mistake: Freedom of speech is still restricted under this "pro-free-speech" platform. It's just that instead of restricting the speech of vitriolic spewmongers who devote countless hours to tormenting their fellow human beings, the platform restricts the speech of their targets. This is not a neutral stance, it is a pro-vitriol stance. I don't think it's an exaggeration to say that this stance is, in fact, anti-compassion. And, of course, it should almost go without saying that this stance is also implicitly every bit as sexist, racist, and otherwise bigoted as the abusers it enables are. How is anyone okay with this?
Motherboard has an interesting timeline outlining how Twitter's rules have changed over its lifespan, along with the cultural shifts that accompanied these changes. It's an interesting story. One big takeaway is that, while Twitter has made some good changes in the past couple of years, its changes have not been universally positive, and we still haven't yet reached a good place. One anecdote in particular comes to mind. Just the other week, a parody account mocking Twitter support and particularly support's reluctance to suspend or otherwise take action against abusers and harassers...
Today we're excited to announce a faster way to report abuse.— Trusty Support (@TrustySupport) February 2, 2016
1. Download this image
2. Email it to yourself pic.twitter.com/SZMGMnd112
...was itself, for a time, suspended. At least it's good to know the account suspension feature still works, I suppose.
Friday, January 29, 2016
Sharing Economy Apps and the New Bottle-Wavers
For better or for worse, the modern age has ushered in new 'disruptive' technologies the like of which we have never before seen. The classic example of this is what some people have taken to calling the sharing economy.
The sharing economy, in a nutshell, is based on the idea that while traditionally people have bought good or services from specialized third parties (taxi rides from taxi companies, hotel rooms from hotel companies), people totally would buy these things from each other if there existed a reliable channel to mediate those transactions. What's more, lots of people have services to offer, but no good way to offer them. If you're going out of town for a week, your apartment is just sitting there empty, and empty living space has an inherent value which you are not capitalizing on. Catchphrases like "unused value is wasted value" get thrown around a lot when describing this sort of situation.
Enter "sharing economy" apps. Uber, Lyft, et al., let you play taxi using your very own car. Airbnb lets you play hotel with your own property. The apps are a mediated channel for connecting consumers with providers, and (hopefully) giving each a reasonable level of assurance about the other. Basically, they give you a way to easily rent out things you already own, on your schedule. Stated in the abstract this way, it probably sounds nice. And a lot of the time, it is. But it also has its share of failures, and most people seem to turn a blind eye to them, drunk as we are on its successes.
Let's start with the name: "the sharing economy". This is a masterpiece of euphemism and marketing. Sharing is letting someone crash on your couch. Sharing is carpooling. The second you attach a price to something, the second you offer your services on a market instead of as a favor, what you're doing stops being sharing. But of course, sharing is such a nice word that people are reluctant to stop using it, even though very cogent arguments have been put forward about how misleading the name is, and other names have been suggested, most notably "access economy".
The next problem is that price aside, the generous-individuals-sharing-hospitality-because-we're-all-such-good-buddies narrative still isn't really true. Power players, both individual and corporate, have emerged, trying in essence to be the hotel and taxi companies (so to speak) of the sharing economy. The more successful they are, the more resources they have to put towards furthering their success, because that's how capitalism works. Of course, many die-hard capitalists would say that if this is the will of the market, then so be it. But it doesn't sit well -- aren't these exactly the sort of entities the sharing economy promised to move us away from?
Then there's the issue of regulation. And make no mistake: this is a big issue. Uber, for instance, has had no end of legal troubles in virtually every country where it operates. Its failure to fit the business models around which extant legal regulations are built means that it can in many cases dodge or muscle past regulations meant to apply to businesses offering the service it provides. Uber's ability to sidestep laws meant to hold it to ethical standards means that it has been able to engage time and again in startlingly unethical practices.
How unethical, you ask? I'll let you judge that for yourself. All I'm saying is, it's not a pretty picture. And it doesn't stop with Uber's own practices -- they also have a track record of enabling and defending drivers' ethically questionable conduct.
And it's not just Uber: Related companies like Lyft have also been taking all kinds of questionable liberties with their workforce, provoking high-profile lawsuits and setting controversial legal precedent. The question of whether these companies' workers, some of whom are full-time drivers who make their living off of Uber, should even be allowed to organize is still under active discussion, somehow.
It's not just quasi-taxi services, either. San Francisco has gotten pretty tired of Airbnb, seemingly for good reason. Plus, it seems like for every one of the service's funny stories ("boutique igloo"!), there's a horror story to balance it out, and while the blame in these stories rarely rests on one party alone, it's also rare to find one in which the facilitating service is not at least partly at fault.
What this situation reminds me of, somehow, is this little story that showed up in a longer novel, told to one character by another. The story is about the term "bottle-waver", which I think the author coined. It might have been Neal Stephenson, but I'm not sure. But in any case, the story as I remember it goes that there's this tiny island, and there's a tribe living on the island, and they've never made contact with the outside world. They all live peaceful lives, unconcerned with what might lie beyond their shores... until one day, an empty glass bottle washes onto the beach.
This bottle just blows their minds -- they've never even seen glass before, bear in mind, and now suddenly here's this, and they don't have the slightest idea what to make of it. The villagers are equally awed and terrified and so, seeking answers, they take it to the village shaman. The shaman immediately recognizes this glass bottle to be an object of great magical power, but also has no idea how to use it. To save face, the shaman grabs a stick, puts the bottle on the end of the stick, and waves the stick overhead declaring Its power is mine! The villagers, seeing this, are all forced to agree, and everything returns to the way it was.
The bottle-waver, then, is someone who claims as their own that which they don't even understand, seemingly hoping that by recognizing the power of that which they have claimed, they will themselves acquire its power. Actually understanding the power in question is unnecessary, maybe even detrimental -- all you have to do is look, to the less informed, as if you understand it. This reminds me very much of the attitude these companies take towards their collective innovation, the 'sharing economy'. It's unclear whether any of them truly understand or even care about their technologies' ramifications on the marketplace, or on the cultures in which they operate. They've hit upon something nobody's ever seen before -- their glass bottle -- and as soon as they found it, they all lunged for their sticks, to see who could wave it the highest. Now Silicon Valley watches, enthralled, as everyone in the crowd wishes nothing more than to take the bottle's power for themselves. Suggestion after suggestion gets thrown out -- "Uber but for x," "Uber but for y" -- but as of yet, they're all too enthralled to suggest the one thing that might actually help: That we all catch our breath, take the bottle down off the stick, and take a moment to try to figure out what bottles are actually good for.
The sharing economy, in a nutshell, is based on the idea that while traditionally people have bought good or services from specialized third parties (taxi rides from taxi companies, hotel rooms from hotel companies), people totally would buy these things from each other if there existed a reliable channel to mediate those transactions. What's more, lots of people have services to offer, but no good way to offer them. If you're going out of town for a week, your apartment is just sitting there empty, and empty living space has an inherent value which you are not capitalizing on. Catchphrases like "unused value is wasted value" get thrown around a lot when describing this sort of situation.
Enter "sharing economy" apps. Uber, Lyft, et al., let you play taxi using your very own car. Airbnb lets you play hotel with your own property. The apps are a mediated channel for connecting consumers with providers, and (hopefully) giving each a reasonable level of assurance about the other. Basically, they give you a way to easily rent out things you already own, on your schedule. Stated in the abstract this way, it probably sounds nice. And a lot of the time, it is. But it also has its share of failures, and most people seem to turn a blind eye to them, drunk as we are on its successes.
Let's start with the name: "the sharing economy". This is a masterpiece of euphemism and marketing. Sharing is letting someone crash on your couch. Sharing is carpooling. The second you attach a price to something, the second you offer your services on a market instead of as a favor, what you're doing stops being sharing. But of course, sharing is such a nice word that people are reluctant to stop using it, even though very cogent arguments have been put forward about how misleading the name is, and other names have been suggested, most notably "access economy".
The next problem is that price aside, the generous-individuals-sharing-hospitality-because-we're-all-such-good-buddies narrative still isn't really true. Power players, both individual and corporate, have emerged, trying in essence to be the hotel and taxi companies (so to speak) of the sharing economy. The more successful they are, the more resources they have to put towards furthering their success, because that's how capitalism works. Of course, many die-hard capitalists would say that if this is the will of the market, then so be it. But it doesn't sit well -- aren't these exactly the sort of entities the sharing economy promised to move us away from?
Then there's the issue of regulation. And make no mistake: this is a big issue. Uber, for instance, has had no end of legal troubles in virtually every country where it operates. Its failure to fit the business models around which extant legal regulations are built means that it can in many cases dodge or muscle past regulations meant to apply to businesses offering the service it provides. Uber's ability to sidestep laws meant to hold it to ethical standards means that it has been able to engage time and again in startlingly unethical practices.
How unethical, you ask? I'll let you judge that for yourself. All I'm saying is, it's not a pretty picture. And it doesn't stop with Uber's own practices -- they also have a track record of enabling and defending drivers' ethically questionable conduct.
And it's not just Uber: Related companies like Lyft have also been taking all kinds of questionable liberties with their workforce, provoking high-profile lawsuits and setting controversial legal precedent. The question of whether these companies' workers, some of whom are full-time drivers who make their living off of Uber, should even be allowed to organize is still under active discussion, somehow.
It's not just quasi-taxi services, either. San Francisco has gotten pretty tired of Airbnb, seemingly for good reason. Plus, it seems like for every one of the service's funny stories ("boutique igloo"!), there's a horror story to balance it out, and while the blame in these stories rarely rests on one party alone, it's also rare to find one in which the facilitating service is not at least partly at fault.
What this situation reminds me of, somehow, is this little story that showed up in a longer novel, told to one character by another. The story is about the term "bottle-waver", which I think the author coined. It might have been Neal Stephenson, but I'm not sure. But in any case, the story as I remember it goes that there's this tiny island, and there's a tribe living on the island, and they've never made contact with the outside world. They all live peaceful lives, unconcerned with what might lie beyond their shores... until one day, an empty glass bottle washes onto the beach.
This bottle just blows their minds -- they've never even seen glass before, bear in mind, and now suddenly here's this, and they don't have the slightest idea what to make of it. The villagers are equally awed and terrified and so, seeking answers, they take it to the village shaman. The shaman immediately recognizes this glass bottle to be an object of great magical power, but also has no idea how to use it. To save face, the shaman grabs a stick, puts the bottle on the end of the stick, and waves the stick overhead declaring Its power is mine! The villagers, seeing this, are all forced to agree, and everything returns to the way it was.
The bottle-waver, then, is someone who claims as their own that which they don't even understand, seemingly hoping that by recognizing the power of that which they have claimed, they will themselves acquire its power. Actually understanding the power in question is unnecessary, maybe even detrimental -- all you have to do is look, to the less informed, as if you understand it. This reminds me very much of the attitude these companies take towards their collective innovation, the 'sharing economy'. It's unclear whether any of them truly understand or even care about their technologies' ramifications on the marketplace, or on the cultures in which they operate. They've hit upon something nobody's ever seen before -- their glass bottle -- and as soon as they found it, they all lunged for their sticks, to see who could wave it the highest. Now Silicon Valley watches, enthralled, as everyone in the crowd wishes nothing more than to take the bottle's power for themselves. Suggestion after suggestion gets thrown out -- "Uber but for x," "Uber but for y" -- but as of yet, they're all too enthralled to suggest the one thing that might actually help: That we all catch our breath, take the bottle down off the stick, and take a moment to try to figure out what bottles are actually good for.
Wednesday, January 20, 2016
Does UEFI Secure Boot Actually Help Security?
You know, BIOS gets a bad rap. Most people only know it by the splash screen they see when they first boot up, and if they ever have to actually interact with it, what they find is often downright jarring. Flat colors? Keyboard-only navigation? Didn't we leave all this behind decades ago?
Maybe we did in higher-level systems, but not here. And if we're being honest, I've always had a soft spot for those tacky, old-school ASCII menus. They're kind of cute. And UEFI, the successor to BIOS, is so user-friendly it creeps me out a little bit -- you can even use a mouse in it! What kind of low-level interface is that?
I do have to admit, though, that UEFI fixes some important problems. It can boot from multiple-terabyte hard drives, which apparently people need these days. It has networking capabilities that BIOS couldn't dream of. UEFI is more broadly portable across different processors, which helps with security and stability.
That's the good. There's also lots of bad. We could talk about UEFI's negligence towards long-standing device driver issues, but that's nothing next to Microsoft's darling, the UEFI "Secure Boot" feature. Secure Boot is borderline functional for Windows users and an unmitigated disaster for everyone else.
The problem Secure Boot was meant to solve is a classic security issue called the "Evil Maid Attack". As Bruce Schneier explains it:
Secure Boot tries to prevent this using what're called crypographic signatures or digital signatures. Just like signing your name is something that (supposedly) only you know how to do, a cryptographic signature is something only you (with the help of your computer, which has a big personal secret number saved on it) can generate.
You can cryptographically sign any piece of data, and that signature can serve as your personal seal of approval. Anyone can check that your signature on a file is valid, but they can't forge your signature. And if the file changes, your signature won't match it any more, so it's hard to get tricked into signing the wrong thing. As you can probably imagine, these signatures are really useful. For example, all major flavors of Linux use signatures when installing software to make sure their downloads weren't corrupted or tampered with in transit.
So, what if we get the people who wrote our bootloader to cryptographically sign it, and we make UEFI check the signature and sound the alarm if it doesn't match? If your Windows bootloader is signed by Microsoft, you know you can trust it not to steal your password (well, that's not entirely true, but only because Microsoft is creepy). If someone overwrites that bootloader, the signature won't match, and UEFI can warn you of shenanigans and bail out.
This might seem like a fine idea, but it has some bad consequences. Microsoft is vehement about manufacturers enabling Secure Boot and setting it to only accept Microsoft's signature if they want to ship Windows on their hardware. That prevents the computer from loading anything except Microsoft-signed code, meaning that with secure boot enabled, those computers would only be able to run Windows. Regardless of Microsoft's claims to the contrary, this is a blatant attempt at promoting lock-in. The open-source community was, and is, less than thrilled.
"So", you might ask, "why not just set UEFI to accept Linux developers' signatures instead?" The answer is that, more often than not, you can't. Most if not all hardware manufacturers' UEFI implementations don't provide that option. "Why not have manufacturers bake the developers' keys in, then?" Well, in favor of that we have open-source geeks, and opposed to it we have Microsoft. One of these groups holds more influence than the other.
There do exist workarounds, but they're inconvenient and far from universal. More than that, the need for a workaround rather than the presence of a solution represents a toxic shift away from openness. This is why some have advocated renaming Secure Boot as "Restricted Boot".
Microsoft's official stance is that people who don't like Secure Boot being limited to Microsoft signatures can just disable the feature. This makes about as much sense as forcing a subletter to use a room lock whose key you've copied and telling them that if they aren't comfortable with that, they could always just not use a lock at all.
And astoundingly, most of the big players in this debacle have completely ignored the fact that there are better defenses against Evil Maid -- for example, this approach that Joanna Rutkowska outlined five years ago.
This situation has been developing since before UEFI even hit the market. Boot security still sucks, but it's marginally improving. For that, we have organizations like the Free Software Foundation and dedicated developers like Matthew Garrett (who wrote the workaround linked above -- and who turns out to be just as much of a righteous dude in non-UEFI matters) to thank. Microsoft doesn't seem to be coming to its senses any time soon, but hopefully boot security will continue to improve in spite of their influence.
Maybe we did in higher-level systems, but not here. And if we're being honest, I've always had a soft spot for those tacky, old-school ASCII menus. They're kind of cute. And UEFI, the successor to BIOS, is so user-friendly it creeps me out a little bit -- you can even use a mouse in it! What kind of low-level interface is that?
I do have to admit, though, that UEFI fixes some important problems. It can boot from multiple-terabyte hard drives, which apparently people need these days. It has networking capabilities that BIOS couldn't dream of. UEFI is more broadly portable across different processors, which helps with security and stability.
That's the good. There's also lots of bad. We could talk about UEFI's negligence towards long-standing device driver issues, but that's nothing next to Microsoft's darling, the UEFI "Secure Boot" feature. Secure Boot is borderline functional for Windows users and an unmitigated disaster for everyone else.
The problem Secure Boot was meant to solve is a classic security issue called the "Evil Maid Attack". As Bruce Schneier explains it:
Step 1: Attacker gains access to your shut-down computer and boots it from a separate volume. The attacker writes a hacked bootloader onto your system, then shuts it down.In essence, if you encrypt your hard drives with a password only you know, an attacker couldn't access those drives -- but that doesn't stop them from rewriting the piece of code that asks you for the password! If you don't notice realize what's going on until after you've unlocked the drive, that's game over.
Step 2: You boot your computer using the attacker's hacked bootloader, entering your encryption key. Once the disk is unlocked, the hacked bootloader does its mischief. It might install malware to capture the key and send it over the Internet somewhere, or store it in some location on the disk to be retrieved later, or whatever.
Secure Boot tries to prevent this using what're called crypographic signatures or digital signatures. Just like signing your name is something that (supposedly) only you know how to do, a cryptographic signature is something only you (with the help of your computer, which has a big personal secret number saved on it) can generate.
You can cryptographically sign any piece of data, and that signature can serve as your personal seal of approval. Anyone can check that your signature on a file is valid, but they can't forge your signature. And if the file changes, your signature won't match it any more, so it's hard to get tricked into signing the wrong thing. As you can probably imagine, these signatures are really useful. For example, all major flavors of Linux use signatures when installing software to make sure their downloads weren't corrupted or tampered with in transit.
So, what if we get the people who wrote our bootloader to cryptographically sign it, and we make UEFI check the signature and sound the alarm if it doesn't match? If your Windows bootloader is signed by Microsoft, you know you can trust it not to steal your password (well, that's not entirely true, but only because Microsoft is creepy). If someone overwrites that bootloader, the signature won't match, and UEFI can warn you of shenanigans and bail out.
This might seem like a fine idea, but it has some bad consequences. Microsoft is vehement about manufacturers enabling Secure Boot and setting it to only accept Microsoft's signature if they want to ship Windows on their hardware. That prevents the computer from loading anything except Microsoft-signed code, meaning that with secure boot enabled, those computers would only be able to run Windows. Regardless of Microsoft's claims to the contrary, this is a blatant attempt at promoting lock-in. The open-source community was, and is, less than thrilled.
"So", you might ask, "why not just set UEFI to accept Linux developers' signatures instead?" The answer is that, more often than not, you can't. Most if not all hardware manufacturers' UEFI implementations don't provide that option. "Why not have manufacturers bake the developers' keys in, then?" Well, in favor of that we have open-source geeks, and opposed to it we have Microsoft. One of these groups holds more influence than the other.
There do exist workarounds, but they're inconvenient and far from universal. More than that, the need for a workaround rather than the presence of a solution represents a toxic shift away from openness. This is why some have advocated renaming Secure Boot as "Restricted Boot".
Microsoft's official stance is that people who don't like Secure Boot being limited to Microsoft signatures can just disable the feature. This makes about as much sense as forcing a subletter to use a room lock whose key you've copied and telling them that if they aren't comfortable with that, they could always just not use a lock at all.
And astoundingly, most of the big players in this debacle have completely ignored the fact that there are better defenses against Evil Maid -- for example, this approach that Joanna Rutkowska outlined five years ago.
This situation has been developing since before UEFI even hit the market. Boot security still sucks, but it's marginally improving. For that, we have organizations like the Free Software Foundation and dedicated developers like Matthew Garrett (who wrote the workaround linked above -- and who turns out to be just as much of a righteous dude in non-UEFI matters) to thank. Microsoft doesn't seem to be coming to its senses any time soon, but hopefully boot security will continue to improve in spite of their influence.
Friday, January 15, 2016
Politics in Software
This is the start of a two-month series of posts on the intersection of politics and technology. The series consists of two bookend posts, with a number of focused topic discussions in between; this is the first bookend post. Now that the series is concluded, this post has been lightly edited to add links to the later posts.
Near my family's house in Seattle are two major construction projects. The first is building a new, refurbished waste transfer station; the second, a new corporate headquarters. In spite of the differences in these buildings' purposes, I'm willing to bet that the labor crews for each have pretty similar feelings towards their work. What difference does it make, being a bricklayer for the state or a bricklayer for private industry? Perhaps not much. It's understandable how most people tend to view their work as apolitical.
And yet, in building something that other people are going to use, you are in some sense helping those people, and so perhaps we should give serious thought to who it is we help. In some domains it might not matter much -- certainly there's no shortage of people who can lay down bricks -- but in other domains, very real political shifts can take place without anyone caring or even noticing.
This probably sounds pretty abstract. The goal of the series I'm writing here is to bring this discussion down to earth. I'm going to try to illustrate, through concrete examples, the real and serious political consequences of the choices people make on what projects to support and what projects to ignore.
I'm focusing on software issues. There's a reason for this. A lot of people see software development as "digital bricklaying", and not without good reason: both have the potential to be menial, repetitive, borderline rote tasks with little reward aside from wages. It would be a mistake, though, to let this comparison lead us to assume that software is no more political than other menial crafts. As soon as we get into social issues, the comparison breaks down.
There can be deep political ramifications to software design decisions. Most people turn a blind eye here, or take only a superficial interest, caring about the politics just long enough to let someone convince them they're on the right side, then wandering off in a happy haze to implement some new half-baked idea. Half a year later, that idea is raining down all sorts of unintended consequences. This is the sort of thing we would call naïveté, if it were harmless. But when it impacts people's lives, we don't have the luxury of being so kind.
It's not all bad. Yes, we have lots of people out there with vested interests in ensuring copyright law continues to lag behind the digital age because they profit by abusing its archaisms. But we also have Cory Doctorow and Parker Higgins and Sarah Jeong and many more like them, people sincerely committed to tracking the issues, fighting the good fight, and making sure the rest of us can keep up with them, too.
Yes, we have the NSA and its allies actively working to undermine the technologies that keep us all safe and secure online, and recruiting as much talent as they can into their closed ecosystems, indirectly hamstringing public-domain research into technologies that grow more important with each passing month. But we also have the likes of Bruce Schneier and Phil Rogaway, the latter of whose linked paper is far and away one of the best publications in recent memory. These people are at the forefront of the modern issues in security and cryptography, and seem to be doing everything in their power to help advance the public good.
With so many intelligent, articulate, well-educated, well-connected, and well-respected voices on these issues, it almost feels arrogant or presumptuous to add my own. What do I have to say that our current luminaries haven't already said better?
I don't have a good answer to that question. The fact is, in order to pass my major's senior sequence I need to write a seven-part series of blog posts connected by some central theme, and I couldn't find any other theme that sat as well with me as this one.
I strongly encourage the reader to spend whatever time they can on the works of the people I listed above, and others like them. But just in case you decide to spend some time with me as well, here's a bird's-eye view of the topics I'm going to be taking on in the next installments.
Near my family's house in Seattle are two major construction projects. The first is building a new, refurbished waste transfer station; the second, a new corporate headquarters. In spite of the differences in these buildings' purposes, I'm willing to bet that the labor crews for each have pretty similar feelings towards their work. What difference does it make, being a bricklayer for the state or a bricklayer for private industry? Perhaps not much. It's understandable how most people tend to view their work as apolitical.
And yet, in building something that other people are going to use, you are in some sense helping those people, and so perhaps we should give serious thought to who it is we help. In some domains it might not matter much -- certainly there's no shortage of people who can lay down bricks -- but in other domains, very real political shifts can take place without anyone caring or even noticing.
This probably sounds pretty abstract. The goal of the series I'm writing here is to bring this discussion down to earth. I'm going to try to illustrate, through concrete examples, the real and serious political consequences of the choices people make on what projects to support and what projects to ignore.
I'm focusing on software issues. There's a reason for this. A lot of people see software development as "digital bricklaying", and not without good reason: both have the potential to be menial, repetitive, borderline rote tasks with little reward aside from wages. It would be a mistake, though, to let this comparison lead us to assume that software is no more political than other menial crafts. As soon as we get into social issues, the comparison breaks down.
There can be deep political ramifications to software design decisions. Most people turn a blind eye here, or take only a superficial interest, caring about the politics just long enough to let someone convince them they're on the right side, then wandering off in a happy haze to implement some new half-baked idea. Half a year later, that idea is raining down all sorts of unintended consequences. This is the sort of thing we would call naïveté, if it were harmless. But when it impacts people's lives, we don't have the luxury of being so kind.
It's not all bad. Yes, we have lots of people out there with vested interests in ensuring copyright law continues to lag behind the digital age because they profit by abusing its archaisms. But we also have Cory Doctorow and Parker Higgins and Sarah Jeong and many more like them, people sincerely committed to tracking the issues, fighting the good fight, and making sure the rest of us can keep up with them, too.
Yes, we have the NSA and its allies actively working to undermine the technologies that keep us all safe and secure online, and recruiting as much talent as they can into their closed ecosystems, indirectly hamstringing public-domain research into technologies that grow more important with each passing month. But we also have the likes of Bruce Schneier and Phil Rogaway, the latter of whose linked paper is far and away one of the best publications in recent memory. These people are at the forefront of the modern issues in security and cryptography, and seem to be doing everything in their power to help advance the public good.
With so many intelligent, articulate, well-educated, well-connected, and well-respected voices on these issues, it almost feels arrogant or presumptuous to add my own. What do I have to say that our current luminaries haven't already said better?
I don't have a good answer to that question. The fact is, in order to pass my major's senior sequence I need to write a seven-part series of blog posts connected by some central theme, and I couldn't find any other theme that sat as well with me as this one.
I strongly encourage the reader to spend whatever time they can on the works of the people I listed above, and others like them. But just in case you decide to spend some time with me as well, here's a bird's-eye view of the topics I'm going to be taking on in the next installments.
- UEFI "Secure Boot", its consequences for open source, and the dangers of letting moneyed interests write the standards we're all going to use. (link)
- The sharing economy, how it's cool in some ways, and how in other ways it's really not. Due to the economic and regulatory angles, this is one of the most rich and nuanced examples of technology's political dimension. (link)
- The problem with media platforms refusing to pick sides in issues involving harassment. It is commonly believed that non-involvement is a neutral stance. This could not be more wrong. (link)
- The trend towards, and ramifications of, trying to legislate reality, where lawmakers demand technologies that simply do not -- and often cannot -- exist. (link)
These topics may move around a bit as I realize how much or how little I may have to say on the different points here. The first one should be up some time next week!
Monday, December 28, 2015
Making a Raspberry Pi Cluster's Rack
It's hard to play with a Raspberry Pi and not wonder what a bunch of them wired together could do. We're talking about $40 computers with 1GB RAM, a quad-core 900MHz processor, and a GPU, all on a credit card-sized board. They're not too far off, specs-wise, from the ThinkPad X60 I'm typing this post on. All that with a $40 price tag -- how could you not want as many as possible?
It probably wouldn't surprise anyone who knows me to learn that I've been working on doing exactly this: wiring a bunch of Raspberry Pis into a cluster for distributed computing. I've now collected enough of the hardware that the big priority is building a rack to keep it all organized. There are a bunch of cool Pi cluster rack designs out there. One 3D-printed design stands out in particular, both for the idea behind it and the implementation. I considered a few different designs, but none were a perfect match for my goals. In the end, it seemed like the best option was to roll my own rack.
Every design is tuned to the resources available to its designer. Being at my family's house for a week over winter break, I had a seven-day window of access to my dad's wood shop, his CNC machine, and his help. Naturally, I was inclined to take full advantage of all three. First of all, though, came deciding what exactly it was we would make.
Design
A few different design constraints are involved here. I wanted every Pis easy to access or remove. I wanted the finished product to look nice. I wanted to keep the footprint small, because this thing is probably going to live on my desk. It was also important to make sure the design wouldn't restrict airflow, because this cluster will be running some long jobs without any heat sinking. Lastly, budget dictated an eight-board setup.
I decided to power over USB, because my understanding is that the Pi has a protective self-resetting fuse in line with the USB power input. This fuse keeps power supply malfunctions from permanently destroying your board, but powering over GPIO seems to bypass this protection. I didn't put too much time into verifying this info, since I heard it from a trusted source, and in any case powering the boards over USB from a couple externally powered hubs is also nice and simple. If I ever decide to overclock these boards (and, let's be real, that's happening sooner or later), I'll probably enlist some help and make a custom power supply to deal with the increased power demands at that point. Maybe mount some heat sinks, too.
These parameters together with the tools available led me to the design you saw above. It's a vertical rack of five trays: on the bottom, a tray for USB hubs and an 8-port Ethernet switch; above it, four trays, all set up to mount two Pis each. Each Pi mount point also has an elliptical hole to promote airflow. It seemed important not to neglect either side of the boards ventilation-wise, since both sides of the Pi 2 have important chips on them (CPU and GPU on top, RAM on bottom). The Pis are rotated 180 degrees from each other, so that both have their Ethernet port and USB power input exposed.
![]() |
| The final design. |
Assembly
It was only in hindsight that I realized how simple this process really is. The vast majority of our time was spent not on woodworking but on trying to troubleshoot the CNC machine toolchain. There don't seem to be nearly enough mature open-source projects in this domain. This is an area where a few dedicated programmers could make a respectable impact. The process of setting up a working toolchain was so painful that I'm not going to say another word about it, except to note for posterity that when we did get things working it was using the proprietary tools provided by the manufacturer (Shapeoko) start-to-finish. One wishes that there could be a better way.
![]() |
| The CNC machine, hard at work cutting a tray. Not pictured: hours and hours of troubleshooting. |
The sides were easy enough to build: just take the relevant cut-to-size pieces (after sanding them reasonably smooth!), measure out whatever ground clearance you might want, glop some wood glue onto the points of contact, press everything together, slap on some clamps, and let it sit for a good long while.
![]() |
| Letting it sit. |
Cutting the slots is easy, too, if there's a tablesaw around: just measure & mark the slot locations, lower the blade so it extends from the table by however deep you want the slots to be, and gouge away. I opted to be sort of generous with the cut depth (after all, better too wide than too narrow), but what I've come to realize is that the tolerance used here has a surprisingly big impact on how cleanly the trays slide in. It pays to be as accurate as possible.
Once the slots are cut, it's time to glue up the other four crosspieces and bring the whole frame together. This step was a bit tricky, since all four beams have to be left to set at roughly the same time in order to keep everything nicely aligned, which turns out to be easier said than done. The problem is that once two pieces are in and clamped down, the remaining ones get progressively harder to wedge in without losing most or all of their wood glue. I really don't have any better advice than to use generous amounts of glue (remember that spillover can always be cut/scraped/sanded off) and to have two pairs of hands involved: one person gently pulling the soon-to-be contact points apart, and another person to put the new beam in and get it lined up just right.
Once this glue cures, the frame's complete except for backstops. These really could not be easier to attach, especially compared to what came before them.
After that, all that's left to do is sand this puppy damn smooth and slap on some finish. This wood took the finish well, each coat drying pretty quickly. We put on ballpark four or five coats (who counts?), continuing until it looked good, then sanded it down and added a final layer.
Oh -- there is one more thing left to do, and that's to mount the Pis on their trays. As you can see, we hit a slight gotcha here:
If you think it looks like those boards are missing half their standoffs, you're absolutely right. Here's what happened. We drew up our parts list for screws, standoffs, nuts, and washers, and rolled on down to the local hardware store (Stone Way Hardware, great place). Tracking down the 2.5mm hardware took a while, since just about nobody except computer & electronics hobbyists use this stuff... arguably for good reason. Turns out the stock was pretty sparse. We asked if they might have more "in the back". No such luck. The clerk commented, after hearing the amounts we were looking for, that we wanted as many of these components as they sold in about two years. He didn't seem particularly moved by the chance to get two years ahead of quota, and so we had to make due with half of everything.
Fortunately, it only really takes two screws & standoffs to do a "good enough" job of mounting a Pi if you install them diagonally from each other. It's not pretty, but it works. The boards are mounted and stable now, but I definitely plan to get the rest of the hardware at some point down the road. It'd probably be better for the boards, and it'd just look better besides. Maybe I'll check back in at Stone Way in a couple years.
![]() |
| The rack, with a network switch in its tray and 6 out of 8 Pis mounted |
Subscribe to:
Posts (Atom)







