Showing posts with label Technology amp; Internet. Show all posts
Showing posts with label Technology amp; Internet. Show all posts

Friday, February 8, 2013

Bitcasa: Unlimited storage, version history & sync

bitcasa-sBitcasa has just emerged from “skunkworks” mode. The cloud storage startup made waves in 2011 as finalist at TechCrunch Disrupt and runner up at Startup Battlefield. They were Kickstarter financed and then went silent. Throughout 2012, there were no public bulletins, but some analysts noted that they filed for 20 patents--a few are really slick! Now, during Feb 2013, they have unveiled a cloud service with an edge over all others (SkyDrive, iDrive, Dropbox, Sugarsync, etc). In my opinion, only Symform and SpaceMonkey come close to the model that I described 3 years ago (search for ‘Ellery’ and ‘RDDC’).

Bitcasa gives every user folder sync, a timeline for version recovery, and cloud storage without limits. And, I really mean limitless! By the end of next month, I may be using petabytes, as in millions of gigabytes! The space available to me shows exabytes are still available.  That’s more than all the grains of sand on the world’s beaches and all the stars in the heavens. How much does this cost? Just $99 a year, or $49 if you sign up early this month. (Promo Code: BETATHANKS). WildDucks can help this Blog by using our referral link. It tacks a free month onto your editor’s subscription.

I can’t guarantee that Bitcasa will be around next year. After all, most startups fail. But in this case, I crafted a substantially identical network architecture years ago. I understand the business model. Even with a high fraction of data hogs, the venture can profitably service users for the long haul. If an understanding of the secret sauce isn’t sufficient to assuage hesitation, this interview with CEO Tony Gauda will floor you. He combines the technical and marketing genius of Steve Jobs with the showmanship of Siegfried and Roy, and the smile of Barak Obama

http://www.youtube.com/watch?v=3ImZWVxAQ_Q

Damon Michaels, a WildDuck contributor wrote:
Seems like a virtual drive. I need automatic backup of
my important data. I use Carbonite for this right now.

The folder-sync defaults to all drives in their entirety—even external drives and network attached storage! If you accept the default, it always backs up everything. But more importantly, Bitcasa reverses the model. As connectivity becomes more ubiquitous and speedy, they want you to use the cloud as your primary active storage. Eventually, it will even host your live EXE files (your apps) and your “bootable” OS. The synchronized copy on your PC will be the backup – as well as the one that is used when you cannot connect.

I proposed the fundamental principles used in Bitcasa architecture in this Blog, and 3 years ago in other articles. I called it a “Reverse Distributed Data Cloud” (RDDC). My spec adds distributed, P2P storage to the model. This reduces cost, creates redundancy, and makes a far more robust system. Not only does it get rid of the data center completely. With my model, it is unnecessary for the service provider to perform any backups. In effect, the live cloud is a RAID 10,000 constellation.

One architectural trade-off is the desire for massive de-duplication –vs– the compelling need for end-to-end encryption, in which only the individual users have the keys. These two features are incompatible. DropBox and Bitcasa claim that files are encrypted at the sender and that private keys are never given to the service. While technically true, that claim covers up a nasty little detail. They use a method called Convergent Encryption in which encryption keys are derived from a character string within the encrypted file. Although the service cannot decrypt a unique file (for example, your income taxes), they could compare a hash of your file to one provided by a government or alleged rights owner, thus proving that you have stored a copy of contested media. They could block access to movies and music that you have stored or even block your original upload. The good news is that with a full RDDC implementation, the need for de-duplication is greatly reduced or even eliminated. Therefore, a properly implemented RDDC can truly empower its uses with strong, end-to-end encryption.

I'll report more about Bitcasa after a few months of use. For now, I feel ratified to see my dream taking shape at several American ventures. If you find this field as fascinating as me, check out Symform, SpaceMonkey and Digital Lifeboat. That last venture is floundering, and may be bankrupt by the time you read this. But they have some very compelling technology for p2p, distributed storage.

Sunday, September 9, 2012

$1 Billion kick-starts Facial Recognition of Everyone

For access to a home or automobile, most people use a key. Access to accounts or transactions on the Internet usually requires a password. In the language of security specialists, these authentication schemes are referred to as using something that you have (a key) or something that you know (a password).

In some industries, a third method of identification is becoming more common: Using something that you are. This area of security and access is called ‘biometrics’. The word is derived from bio = body or biology and metrics = measurement.

The data center that houses computer servers for AWildDuck also houses valuable equipment and data for other organizations. When I visit to install a new router or tinker with my servers, I must first pass through a door that unlocks in the presence of my fob (a small radio-frequency ID tag on my key chain). But before I can get to the equipment cage that houses my servers, I must also identify myself by placing the palm of my hand on a scanner and speaking a code word into a microphone. I don’t know if my voice is identified as a biometric, but the use of a fob, a code word and a hand-scan demonstrates that the facility uses all three methods of identify me: Something that I have, something that I know and something that I am.

If you work with technology that is dangerous, secret, or that has investor involvement, then biometric identification or access seems reasonable. After all, something-that-you-are is harder to forge than something that you have. Because this technique is tied to part of your body, it also discourages the loaning of credentials to a spouse, friend, or blackmailer.

But up until now, biometric identification required the advance consent of the individuals identified. After all, before you can be admitted to a secure facility based on your hand print, you had to allow your hand to be scanned at some time in the past. This also suggests that you understood the legitimate goals of those needing your identification in the future.

Few Americans have been compelled to surrender their biometrics without advance consent. There are exceptions, of course. Rapists and individuals applying to live in the United States are routinely fingerprinted. Two very different demographics, and yet both are compelled to surrender a direct link to their genetic makeup. But until now, we have never seen a non-consenting and unsuspecting population subjected to wholesale cataloging of personal biometrics. Who wants all of this data? What could they do with it?

Here at AWildDuck, we have written about the dogged persistence of conservatives in the American government to seek a state of Total Information Awareness. But now, Uncle Sam is raising the stakes to a new low: The Dick Cheneys and Karl Roves aren't satisfied with compiling and mining data from that which is online, such as phone books, Facebook data, company web sites, etc. They want access to as much personal and corporate data as they can get their hands on: Bank records, credit card receipts, tax returns, library borrowing records, personal email, entire phone conversations & fax images, and the GPS history logged by your mobile phone.

Perhaps even more creepy, is the recent authorization for the use of high altitude drones for domestic law enforcement. But wait! That development pales in comparison with a minor news bulletin today. The FBI has just funded a program of facial recognition. We’re not talking about identifying a repeat bank robber, a missing felon or an unauthorized entry across our borders. We are talking about scanning and parsing the entire population into a biometric fingerprint database. The project aims to cull and track facial images – and identify each one – from every Flickr account, every ATM machine, every 7-11...in fact, every single camera everywhere.

If you have a driver’s license, a Facebook account, or if you ever appeared in a college yearbook, it’s a certainty that you will soon surrender identifiable biometrics, just like a rapist or a registered alien. By 2014, we may arrive at 1984.

The one billion dollars set aside by the FBI for the facial recognition component of Project Über Awareness belies the truly invasive scope of body-cavity probing that the Yanks want to administer. The massively funded effort includes a data archival project buried within a Utah hill that is brain-seizing in size and scope. Forget about Tera, Peta and Exabytes. Think instead of Yotta, Zeta and Haliburtabytes.

Engadget is a popular web site that reviews and discusses high tech markets, media & gadgets. Below, they discuss the facial recognition component and its privacy implications. Just as with our past articles on this topic, Engadget begins with a still image from the ABC television series Person of Interest. The show depicts the same technology and it’s all encompassing power. Whomever controls it has the power to manipulate life. But unlike Mr. Finch, a fictional champion of stalked heroines, the Big Brother version is not compelled by a concern for individual safety and security. Instead, the US government is using the specter of terrorism and public safety to bring the entire world one giant leap closer to a police state.

Do we really want our government – any government – to know every detail about our daily lives? Does the goal of securing public safety mean that we must surrender our individual freedoms and privacy completely? Are individuals who don’t care about privacy absolutely certain that they will trust their governments for all time and under all circumstances? Do they expect that the data will never be breached or used for purposes that were not originally sanctioned or intended? Is anyone that naïve?

________________________________________________________________________

FBI rolls out $1 billion public face recognition system in 2014.
Big Brother will be on to your evildoing everywhere

Reprint: Engadget.com — By , posted Sep 9th 2012


DNP FBI to roll out $1 billion public facial recognition system in 2014, will be on to your evildoing

Thursday, August 16, 2012

Can USA Assert Jurisdiction Over Assange?

Most Wild Ducks are aware that WikiLeaks is a rogue distributor of classified and secret documents from anonymous news sources, news leaks and whistle blowers. At the helm is the very charming self-promoter, Julian Assange. This man attracts controversy like honey attracts flies. Dozens of governments, banks and NGOs would gladly substitute honey with “horse manure” in that simile.

In the past 2 years, WikiLeaks has threatened—and then followed through—on the release of information troves containing copious numbers of memos, orders, private communications, and tactical analyses by governments, banks, charities, NGOs, and what-have-you. To generate buzz and prevent sabotage while they vet and compile controversial disclosures, WikiLeaks occasionally pre-releases an encrypted stash of secret documents that they call an “insurance file” or, more accurately, an information bomb. Once out there, it can never be defused—The contents can be remotely detonated by anyone with an encryption key. (This can be a short phrase that is easy to remember).

During the past 2 years, WikiLeaks has been doing exactly what it has threatened (or promised, depending upon your perspective). They have disseminated enormous troves of sensitive and sometimes embarrassing documents, phone calls, faxes, emails, and other private communications without permission from those who were party to the data. Among the infringed parties (think of this as the data ‘owner’ or originator) are the US Government, Bank of America and just about anyone else that claims domain over sensitive material. WikiLeaks justifies its acts as a 21st century watchdog agency with a calling higher than any government. Their PR spin conveys an ethical rudder that pushes for transparency in all affairs. The United States points out that outted documents sometimes reveal the name of spies, and that release endangers their lives of government agents and their families. Other documents reveal the number and location of weapon systems. And still others, reveal what one country believes to be the capacity and range of another country's weapons. But that’s not all...

For WikiLeaks, it doesn’t matter that a telephone transcript reveals personal information unrelated to the government or business affairs targeted for disclosure. For example, parties arranging a phone call reveal that a premier is delayed because he is with a young mistress or a Deputy of State can’t take a call, because she is in the midst of a fierce hangover. In effect, WikiLeaks says “Hey! These are public officials supported by their subjects or constituents. Transparency is always better than secrecy, no matter what’s in the pudding. Just throw it all out there and let the chips fall as they may.”

Of course, the US Government, it’s allies, and many public and private organizations don’t see it that way! Just because a disgruntled employee or consultant has access to sensitive documents shouldn’t mean that a 3rd party organization can air on the bathroom wall. And so, Julian Assange is a wanted man.

For the past two month, Assange has been holed up at the Ecuadorian embassy in Great Britain. I mention “Great Britain” as a geographic footnote and not to imply ownership or jurisdiction. An embassy of Ecuador is sovereign Ecuadorian territory no matter whose land surrounds it. Right?

...Well, not according to the British.

Today, Ecuador’s foreign minister announced that the country is granting asylum to WikiLeaks founder Julian Assange. Of course, Assange is wanted  defying threats by the British government to storm the Ecuadorian Embassy and extradite Assange to Sweden, where he is wanted for questioning in cases of alleged rape and sexual molestation.

The US government seeks Julian Assange for trial in a US court on charges related to his role in the massive WikiLeaks disclosure of confidential documents and communications. Of course, the US considers these documents to be sensitive and they are each labeled at various levels of “Secret”. The US has laws that govern access, copying and disclosure. It’s safe to assume that the charge would be treason, conspiracy, theft, aiding the enemy, or something related to willful interference with process.

US Jurisdiction: How Can it be Asserted?

I understand all of that. But I have never seen an explanation as to how the US could assert jurisdiction or request extradition. Assange is a foreigner and his acts related to WikiLeaks took place in foreign countries. Does the US assert that anything labeled as “secret” by its military is automatically secret everywhere on Earth? That would be a tough argument, because it would require a bilateral reciprocation agreement. Assange has lived in Nairobi since 2007. Does the US protect documents and extradite individuals over everything that the Nairobi government considers to be a secret?

Of course, the United States is pursuing enablers within or serving in uniform, but Assange is not among them. His actions may have harmed US interests (this is certainly debatable)—but how can the US claim that it has domain over the legality of his acts or his capture and punishment? Having an extradition agreement doesn't mean that you can demand any individual that you seek. There has got to be a reasonable basis for the extradition. Doesn’t a bench warrant need a viable basis in law?



Swedes:
We Just Want to Try Him for Rape


The Swedes interest in Assange is ostensibly to charge him with a sex crime. That certainly sounds like a legitimate interest that is unrelated to the beef with Uncle Sam. But the Swedish government refuses to guaranty safe passage to a region that is not party to a US extradition treaty. They claim that they are bound by law to turn Assange over to the US. The solution to this quagmire is not simple, but it is achievable. Assange claims that he is willing to face that charge. Why not try him in Ecuador (or the country that becomes his safe harbor from American extradition). If he refuses, he could be tried in abstention by a Swedish court and the court sentence could be negotiated with authorities in the safe harbor country.

WikiLeaks: Is the Wholesale Release of
                   Secret Communiques Ethical?

What about the 900 pound elephant in the room? Can WikiLeaks claim that its mission is moral or ethical (carried out in the current fashion) morality of what Assange has done vis-à-vis WikiLeaks. My own readers at awildduck.com have pressed for an editorial opinion on the whole affair. Has Assange harmed US interests? Does it matter outside of the US? Did he break an “international” law? Should he be held accountable?  Should he be turned over to American authorities to stand trial?

I won’t weigh in on these issues here. The purpose of this posting is to question US jurisdiction and earnestly seek information & opinions on the basis for extradition. If you have knowledge of the law, the basis or the justification for that request, I invite your analysis and comment.

Could the Brits Really “Storm an Embassy”?

I certainly can’t imagine that the Brits would “storm the Ecuadorian embassy”. Good God, man! Regardless of treaties and acts, it is a sovereign country. In fact, I would think that the Ecuadorian could, at their discretion, grant Assange citizenship and then confer diplomatic status. This would compel a host country to guaranty safe passage to the Airport. Isn’t that the whole idea of ambassadors and the exchange of territory? Storming an embassy would place the UK in the unenviable and undistinguished company of Egypt (2011) and Iran (1979~1981). Who can forget the hostage taking? That event spawned a nightly TV show in the US and the career of Ted Koppel.

         Ellery Davies clarifies the intersection of Technology, Law and Public
         Policy. He is a contributor to Yahoo, CNet, ABC News, PCWorld and
         The Wall Street Journal. He is also Chief Editor of A Wild Duck.

Photo Mural—Sam Spratt, Gizmodo

Monday, August 13, 2012

Ineffective JFK airport anti-terrorism security

Check out this video, courtesy of Yahoo! and ABC News:

  • A man horsing around on a Jet Ski in Jamaica Bay has a technical problem.
    It may be related to his drinking a few too many beers...

  • He ditches his water craft. Friends aren’t responding to his calls. It’s night
    and the sky is dark.

  • He swims toward the only thing he sees: runway lights at JFK airport.

  • He climbs out of water, over a fence, walks across 2 runways, past
    motion detectors, cameras and security guards. Still dripping wet and
    wearing a bright yellow life vest, he wanders into a back maintenance
    door of the Delta terminal—all without being detected.




I don’t find it hard to believe that a $100 million security system is flawed. But I would have thought that the weakness would be “social engineering”. That’s where an operative probes for individuals who can be fooled into weakening the perimeter, revealing passwords or even deactivating security systems.

During the past year, we have endured a lot of boasting about protective measures built into the travel process by Homeland Security, TSA, NYPD and the New York Port Authority. These organizations want us to believe that our money is well spent. And yet, without even trying, a 31 year old, tipsy water sport enthusiast waltzes past counterterrorism barriers of a brand new $100 million Airport security system.

If JFK truly has the latest technology, wouldn’t there be some kind of RFID/NFC badge on every authorized individual? I would think that each individual moving on the tarmac would be tracked and identified on an alarm console  just like planes in the sky.

I suppose that we can’t expect the latest, high-tech measures at every airport, but considering the boast of a 0.1 billion dollar, state-of-the-art security system, it seems reasonable that a slightly inebriated swimmer shouldn’t be able to get this far!

Incidentally,  Daniel Casillo, 31, was arrested for trespassing into a ‘secure area’. Obviously, he did no such thing! Wild Duck’s say: Give this guy a gold medal and pray that we learn from his swim lesson. Let’s also pray that Jihadists don’t use Jet Skis in Jamaica Bay.

Thursday, June 28, 2012

Texas students hijack drone aircraft

Credit: Post based on writing for Geek.com

[caption id="attachment_1457" align="alignleft" width="300"] Missile launch is triggered from Sam’s iPhone[/caption]

Look! Up in the sky…Is it a bird? a plane? No! It’s an unmanned Predator drone, hijacked by students! That’s right. Whiz kids from University of Texas at Austin took control of an aerial drone by altering its course.

The task was shockingly simple. Instead of hacking the primary control firmware, they fed its GPS mechanism a false signal, tricking the flying Al Qaeda hunter into heading wherever they wished, perhaps into the 3rd floor showers of the sorority. This was no fly-by-night operation (pardon the pun). The Department of Homeland asked students to try hacking the drone and gaining control. Was it expensive? It required only $1000 worth of equipment to seize control of a multi-million dollar piece of technology used by the US military and CIA.

The government became concerned about the vulnerability of drone aircraft after it became apparent that Iran had most likely taken control of a US drone and crashed it in Iranian territory several months ago. The Austin students, led by professor Todd Humphreys, used the GPS equipment to spoof the GPS signal being sent to the drone. Spoofing the signal means the students were able to trick the drone into mistaking their signal for the real one, allowing them to lead the drone astray. The aircraft being used employs the same unencrypted GPS signals used by government vehicles.

This hack presents a serious problem for proponents of using domestic drones. If any kid with $1000 and a little know-how can crash a drone into things or perhaps drop a payload!), well–that’s just not cricket. It is currently illegal to use drone aircraft in US airspace without special clearance from the FAA, and now it might take a little longer than expected for that to change.

RT via Popular Science

ICANN gTLD Plan Begins to Unravel

Oh ICANN, Dear ICANN. Please say it ain’t so!

The Internet Corporation for Assigned Names and Numbers (ICANN) is the bureaucracy that oversees the Internet. This committee of intellectuals coordinates IP address space, assigns address blocks, governs standards, administers root DNS architecture, develops internationalization, arbitrates disputes, and perhaps – most ignobly – it sets policy over Top Level Domains.

They do this all under a US government contract which evolved as the Internet grew from academic and military roots to become an all-encompassing network of global public highways. But over the years and throughout the shifting winds of politics and technology, one thing has remained constant: ICANN’s fundamental Raison d'être is to ensure the stable and secure operation of the Internet. Obviously, they cannot ensure the stability and ready access of every web server. The operation, maintenance and connection of equipment is the responsibility of the millions of server owners across the globe. Each GoDaddy, each Google, and each individual user is a node in a vast network that gradually creeps—some pundits suspect—toward consciousness.

Since ICANN manages a public resource, there will always be political components to the organization structure and funding. After all, it is difficult to imagine their responsibilities fulfilled by an entity subject to pure, free market mechanisms. But because they are international in scope, setting standards & policy that affect billions of people in every nook and cranny of our world, they should be depoliticized to the extent possible. Every opportunity should be exploited to move each department and each function toward free market mechanisms.

Unfortunately, in the post-Esther Dyson era, ICANN has turned into a money grubbing hodgepodge of special interests. It certainly appears that they are extorting wads of cash from the public by raising fears of trademark infringement. It’s the only reasonable explanation for their insane and malfeasant decision to create unlimited global Top Level Domains (gTLDs).

If you already operate as Coca-Cola.com, why on earth should you be pushed into buying .Coca-Cola? Simple. Because ICANN will sell it to someone else if you don’t.

In the middle of 2011, ICANN cooked up a cockamamie idea to unleash an infinite number of random top level domains on the world. I tried hard to dissuade ICANN from proliferating gTLDs when it was proposed in June 2011. (I wrote about it here at AWildDuck, when the Blog was created in August). I have a few friends at ICANN, though I suspect I am losing them fast. And so, here is my mea culpa: I told you so...

No—The plan has not yet been fully implemented. It’s slated to go online in 2013. But it’s already beginning to unravel. Today, ICANN announced that due to public dissent and gross technical problems (they called it “unexpected results”), they are scrapping a new system designed to prioritize TLD applications. This is big news to the few thousand applicants who hope to own custom top level domains such as .google, .dance-with-the-stars, or .i_are_an_idiot! After all, they put up US $185,000 each to corner the market for snake oil. They see it as a potentially valuable piece of web real estate.

Dear applicants: It is not. It is smoke up your derriere—an illusion.

Listen up, ICANN: Stop duping the public. Stop profiteering. It’s not in your charter. Go back to square one. In fact, Go a few steps behind square one. you are solving a problem that does not exist. There are already too many gTLDs (.com and .gov and perhaps .org are the only ones that are useful). Everything else clouds the water and invites squatters and profiteers. They only serve to fatten your wallets or stir up trade name disputes.

A better idea: Get rid of all TLDs. Every one of them! Let current .com users own the naked term and stop forcing little guys to repurchase their names. Please ICANN. The current debacle is just the first embarrassment. Run back. Admit the error. Give it up!

Wednesday, June 20, 2012

Apple’s Trade Embargo. Is it “racial” discrimination?

I generally shy away from trendy stories of the day. They are covered elsewhere and the wonks are predictable. Columnists and bloggers add spin of their own camp, either liberal or conservative. My take on these stories would be similarly predictable. That’s why I hold out for something with meat on the bone—something to which I can lend a Wild Duck insight. After all, I want the ‘wild’ part to mean something.

But today, a story making news misses a very critical fact. One that changes the conclusion. Let me explain...

Sahar Sabet is a typical America teen. Although she comes from Iran, she is a US citizen. She looks, speaks, dresses and grooms like a typical, white, suburban girl. Of course, even if she looked, dressed or behaved as a foreigner or an immigrant (an absurd determination for a country filled with immigrants), you would expect that in a shopping mall, she would be treated like any other shopper.

This weekend, Sahar and her uncle browsed an Apple store at North Pointe Mall in Alpharetta Georgia. Choosing an iPad, the salesman overheard the couple speaking in Farsi. When Sahar explained that it is the language of Iran–also known as Persia–the salesman prohibited the sale, explaining “Our countries do not have good relations”. He stated that Apple enforces a trade embargo against Iran and several other countries and showed the would be customers a written Apple policy which, itself, cites US trade restrictions.

For consumers of mainstream media, the Apple salesman seemed racist or, at the very least, ignorant. What do trade relations have to do with a retail sale? And how could he miss the fact that Sahar is a citizen of the same county as himself and the late Steve Jobs?

Sitting outside her home and talking to a television reporter, Sahar explains that she left the store in tears. Zack Jafarzadeh had the same experience at the nearby Perimeter Mall. Perhaps more bizarre, he is born in Virginia of Iranian ancestry. In the video clip below, he states that the policy smacks of ethnic profiling. Of course, the Council on American-Islamic Relations (CAIR) protested the incident immediately.*


You will find a great many news stories about Sahar’s trip to the mall this week. But a few stories, like this firsthand account from an Atlanta television station include a fact that is critical and yet overlooked in the commentary. It makes all the difference in the world:

“The iPad was to be a gift for her cousin who lives in Iran.”


Wohah!...That changes everything! The US trade embargo law specifically mandates that the store shall not sell embargoed technology if they know that the product will be exported, transferred or re-exported to Iran. It’s not clear if the salesman was made aware of the intention to export the iPad, or if he was a closet racist, or perhaps he was expressing his own post-911 anxiety. But either way, this is valid trade law, and Apple would get into a lot of trouble if they violate this law.

Zack was born in Virginia. Both he and Sahar are as American as apple pie. So naturally, news reports slam the Apple salesman for profiling immigrants. They also question the role of a private company in enforcing a federal trade embargo at the point of sale. But again, they miss the point. To illustrate, consider this bump in the success story of Digital Equipment Corporation, the Massachusetts minicomputer manufacturer that rivaled IBM in the 1970s and 80s...

In the early 1980s, Digital’s flagship minicomputer, the VAX 780, had the distinction of being on the original list of embargo technology. Naturally, during the Cold War, sales of fast computers to the Soviet Union were restricted.

[caption id="attachment_1432" align="alignright" width="281"] During the Cold War, selling fast computers to Soviets was illegal, even if transferred through an intermediary or neutral country.[/caption]

Sellers of large, expensive computers generally know their buyers. Even if a deal is not initiated by the sales team, sellers defend price and competitive position. Engineers at buyer and builder talk nuts & bolts. This was no exception. But because Digital could not openly sell to Russians, they transferred the machine to an American shill organization, because an intermediary is more likely to fly under the radar while transferring the computer to the Soviets.

Bad move, Digital! The deal was discovered and the company faced an inquiry and stiff penalties. Most importantly, they were disgraced in the press.

Regarding the Apple iPad, one could question the law as it applies to a popular consumer item, one that is available in many other countries. But the law and its clear focus on export awareness by sellers restricted lends a different spin to the Apple salesman’s actions.

Just as with Miss Sabet, Mr. Jafarzadeh was purchasing the iPad for an Iranian friend who accompanied him to the store. He was in the United States on a student visa. If this fact were apparent to the salesman, then he would be compelled to deny the sale.

Incidentally, Sabet’s mother was able to purchase the iPad on a subsequent visit and an Apple spokesperson told reporters that it could also be purchased online to circumvent the policy (or at least the enforcement of the policy). While this may be the case, it might still violate US trade law. The law is clear. Certain products, services, technology and components are prohibited from being sold, directly or indirectly, if they are slated to be exported, transferred or re-exported to countries on a technology embargo list that includes Iran, Cuba, North Korea and Syria.

_____________
* Despite the warm-fuzzy title, CAIR is a widely acknowledged front for terrorists, still operating, openly, within the United States. The group’s actions speak volumes about their agenda, posing as an NGO of tolerance and cultural bridges while seeking to use our western tradition of inclusion, tolerance and accommodation to make Islamic Sharia Law palatable in America. But I digress. We can cover that story in another post.

Monday, June 4, 2012

Kids and Facebook (revisited)

My friend, Damon, wrote an insanely popular post to his own blog. Shortly after viewing a suggestive Facebook photo by his daughter’s online acquaintance (another 12 year old girl), he solicited readers to opine about preteens who post swimsuit “fashion” photos, pose suggestively, and then comment on each other’s “hotness”. He worries that it may invite unwarranted or even dangerous attention.

Of course, in no time at all, Moms & Dads were falling all over each other in their response. The feedback generally fell into these categories:

  • “My little Alice would never do anything like that!”

  • “I don’t allow Betty to use Facebook”

  • “Why doesn’t someone demand that Facebook police the age of users?”


Related: Filter a child from online porn? Stop worrying!




[caption id="attachment_1350" align="alignright" width="109"] Damon[/caption]

A feature in today’s Wall Street Journal discusses Facebook policy towards children. Depending upon on the news source, they are either thinking of granting access to kids under 13 – or not. Forbes says that access for preteens might make them safer. Of course, the truth is that Facebook has no way to tell the age of its users—nor should they care, except for purposes of marketing demographics. Policing an online audience achieves nothing and opens up the gatekeepers to all sorts of liability.

This might be a good time to review the stats: Nearly 40% of kids between 9 and 12 already have their own Facebook accounts. In fact, more than 5 million of these kids are under 10. The numbers will grow regardless of the ‘rules’, but the good news: This is a good thing. Kids and Facebook aren’t the problem. But parents are often a problem.

Ellery’s thoughts can be summarized in a pithy string of words: Parenting, closed circles, and reading the unredacted news together. And, oh yes...Did I mention, ‘parenting’?

[caption id="attachment_1361" align="alignleft" width="188"] Avoiding online predators[/caption]

It’s easy to jump on the bandwagons of filters, censorship and parental controls. But restricting kids to online kiddie activities is rarely in order. Prohibitions rarely have the intended effect. Kids get what they want while parents encourage deceit and risk. Web savvy kids don’t need a Facebook account to post raunchy photos. Any eight year old with internet access can do it with ease.

A more practical solution begins like this: Keep PCs in an open and busy area of your living room or kitchen. Spend time with your kids. Talk about these things. Get them to close their circles (friends only). Know their friends and (depending upon age and responsibility) Friend them yourself (the one rule that I accept). But ultimately, trust them to do the right thing. If you lead by example—giving children a chance to be safe & responsible—you will be amazed at how responsible they can be.

Damon wondered Why Facebook doesn’t do a better job policing the age of its users.
Editor’s Note: Damon polled readers about a photo and comments posted
to Facebook by an early teen. Damon and some of his readers feel that
the posting is risky or inappropriate. But he did not 
advocate that it
is incumbent upon Facebook to police the age of its users. (I jumped
to that conclusion about his position)
. His poll 
was intended to spark
discussion. In fact, he agrees with my perspective below.

While it is tempting to blame web services for lax oversight, I really don’t think that it is realistic to expect them to police electronic traffic. It smacks of a Nanny state and it opens up every Blogger and hosting service to unwarranted liability. Facebook can no more be responsible for activity on your child’s page than the phone company can be responsible for foul language or bullying.

Imagine the maker of steak knives enforcing an “age policy”. With a sense of purpose and a massive effort, they have almost no influence over the individual family members that grab their utensil from kitchen drawers across the world. It is ludicrous to assume that Facebook could, would or even should police the age of users. That’s a job for parents! My pre-teen daughter has had a Facebook account since she could type. I accept it. It is a tool of the times. (Actually, it is an insanely useless and ill-crafted tool, but that’s beside the point). We talk frequently about appropriate use. I am included in her circles (and therefore, invited to monitor), and I continuously re-evaluate activities & venues as she matures. Facebook is many things: a Blog, a social gathering spot, a gaming site, an academic tool, and much more. Although I feel that the service has little benefit and lax standards, it is easy to monitor and it supports closed communities.

[caption id="attachment_1355" align="alignleft" width="174"] Facebook is popular with kids & soccer moms, but a lousy social network[/caption]

But let’s face it, Bucko! It’s a social network and not a baby sitter. Gossip and even occasional raunch among close friends is to be expected. It’s much more important to talk with your kids, test your trust, and constantly reassess if your progeny is living up to your expectations.

You know the drill, ducks. So Sayeth Ellery. Tell me what you think.

Saturday, May 26, 2012

New York & Hawaii: Frightening bedfellows lacking perspective

New York and Hawaii are bookends to 50 American states. Although separated by 8,000 km, each is rich in heritage, and with a very different political and cultural perspective. Yet, despite the distance and political differences, they are embarking on an identical and ruinous path. Bills introduced in both states suggest that legislators lack fundamental knowledge of history, democracy, economics and, especially, the nature of the Internet. More importantly, they care not a whit of personal freedoms, privacy and individual rights.

[caption id="attachment_1314" align="alignleft" width="147"] NY & HI senate: Lacking historical perspective[/caption]

I should end here with my favorite tag line, “So Sayeth Ellery”, but that would deny readers chilling facts. Facts that ought to shock the senses of every New Yorker and Hawaiian, and humiliate by association. Let’s cut to the chase: Lawmakers in the Aloha state want to criminalize anonymous internet posting while senators in the Empire State plan to create a database of every web site visited by each resident. Yes! They plan to track & archive your internet surfing history. I am not making this up!

[caption id="attachment_1262" align="alignright" width="200"] A government dB of everyone’s web surfing... Now, Isn’t that just special?![/caption]

With regrets to Dana Carvey, Isn’t that just special? After all, an individual concerned about being carded at the door is an individual with something to hide—most likely, guilty of a crime. Who else would object to registering a DNA sample before speaking on topics of the day? A law-abiding citizen doesn’t fear a government that tracks thought, medical history, private communication, bedroom fantasy, or corporate negotiation. Just what are those people afraid of?

Dear Wild Ducks: We are all those people. I am too blinded by disappointment and pity to name names or plow through the facts. (N.B. Names of the proponents are in the tags below this article). So, I offer links to well written summaries. Read along with me and weep. The US is already constructing the world’s biggest database of everything that you say, do and think. Perhaps New York and Hawaii feel left out. Or perhaps legislators in those states skipped out on high school history. More likely, they are decent individuals with good intentions, but simply poor stewards of liberty in an era of ecommerce, the Drudge Report, AWildDuck.

Does anyone not find this frightening? Forget about “confidential sources”. Want to comment on a breastfeeding blog? Sure. But first, register your fingerprints with an ISP and web host! I can think of three reasons that this won’t fly. More importantly, I am concerned that our legislators don’t see this:

Reasons to avoid suppressing a privacy technology




  • If a government bans free expression, the business of internet hosting & access simply migrates to jurisdictions that understand democracy. It’s the nature of any fungible medium.

  • Political restrictions on existing technologies or platforms create incentives for the rapid deployment of methods that circumvent or thwart the restrictions. This has the unintended effect of causing even more interference with legitimate investigations and forensic tools.

  • History demonstrates the dangers of surrendering free, anonymous speech to a government, no matter how ethical the current leaders. Governments are transient, though they try hard to be self-preserving. They do their best work when prodded by free and democratic constituents.


So sayeth Ellery.

Ellery Davies is not generally known as a liberal commentator.
But he is a political wonk, privacy advocate and editor of AWildDuck.

Thursday, May 10, 2012

Enhancing Privacy: Blind Signaling and Response

Welcome Engadget & TechCrunch Readers


This primer describes a privacy enhancement that is transparent to users, yet allows Google and other online services to provably shield personal data from prying eyes—even from themselves. The data is meaningful for only a clearly defined purpose and without trackback or correlation to individual users.


It is not yet built into major online services. But as it crosses development and test milestones, it is attracting attention and community scrutiny.


Takeaway #1: Blind Signaling and Response encrypts and anonymizes personal data while supporting a marketing backchannel (what Google marketing partners pay for).


Takeaway #2: I am an inventor. I seek to build a career in Privacy technology centered around the development and roll out of Blind Signaling and Response. If you influence companies that gather personal user data, contact me today. Your organization, its clients, and your users will benefit. Your advertising revenue model will be preserved.


In the article directly beneath this one, I claimed that Google can protect individual user data and privacy without detriment to their revenue model. In fact, it would be a great stride in the user perception of trust and a commitment to privacy. I also claimed that Google could modify their services in such a way that would prevent any leak of personal information, even if compelled to turn over data by totalitarian governments around the world.

That posting has become popular. Readers have asked me to peel back the cover and I have even been approached by Google. (Perhaps it will lead to an affiliation. I admire Google, and would love to work with the company).

The magic behind my claims is a method of collecting and storing data that prevents anyone but the intended party from making sense of what is stored. It’s not based on just data encryption, but rather a clever outgrowth of encryption technology that I call blind signaling and response.

Before we can understand Blind Signaling and Response, it helps to understand classic signaling.

When someone has a need, he can search for a solution. When an individual is aware of their needs and problems, that’s typically the first step in marrying a problem to a solution. But in a marketing model, a solution (sometimes, one that a user might not even realize he would desire) reaches out to individuals.

Of course the problem with unsolicited marketing is that the solution being hawked may be directed at recipients who have no matching needs. Good marketing is a result of careful targeting. The message is sent or advertised only to a perfect audience, filled with Individuals who are glad that the marketer found them. Poor marketing blasts messages at inappropriate lists or posts advertisements in the wrong venue. For the marketer (or Spam email sender), it is a waste of resources and sometimes a crime. For the recipient of untargeted ads and emails, it is a source of irritation and an involuntary waste of resources, especially of the recipient’s attention.

Consider a hypothetical example of a signal and its response:

Pixar animators consume enormous computing resources creating each minute of animation. Pixar founder, John Lasseter, has many CGI tools at his disposal, most of them designed at Pixar. As John plans a budget for Pixar’s next big film, suppose that he learns of a radical new animation theory called Liquid Flow-Motion. It streamlines the most complex and costly processes. His team has yet to build or find a practical application that benefits animators, but John is determined to search everywhere.

Method #1: A consumer in need searches & signals

Despite a lack of public news on the nascent technique, John is convinced that there must be some workable code in a private lab, a university, or even at a competitor. And so, he creates a web page and uses SEO techniques to attract attention.

The web page is a signal. It broadcasts to the world (and hopefully to relevant parties) that Pixar is receptive to contact from anyone engaged in Liquid Flow-Motion research. With Google’s phenomenal search engine and the internet’s reach, this method of signaling may work, but a successful match involves a bit of luck. Individuals engaged in the new art may not be searching for outsiders. In fact, they may not be aware that their early stage of development would be useful to anyone.

Method #2: Google helps marketers target relevant consumers

Let’s discuss how Google facilitates market-driven signaling and a relevant marketing response today and let us also determine the best avenue for improvement...

At various times in the past few weeks, John had Googled the phrase “Liquid Flow-Motion” and some of the antecedents that the technology builds upon. John also signed up for a conference in which there was a lecture unit on the topic (the lecture was not too useful. It was given by his own employee and covered familiar ground). He also mentioned the technology in a few emails.

Google’s profile for John made connections between his browser, his email and his searches. It may even have factored in location data from John’s Android phone. In Czechoslovakia, a grad student studying Flow-Motion has created the first useful tool. Although he doesn’t know anything about Google Ad Words, the university owns 75% of the rights to his research. They incorporate key words from research projects and buy up the Google Ad Words “Liquid Flow-Motion”.

Almost immediately, John Lasseter notices very relevant advertising on the web pages that he visits. During his next visit to eBay, he notices a home page photo of a product that embodies the technique. The product was created in Israel for a very different application. Yet it is very relevant to Pixar’s next film. John reaches out to both companies–or more precisely, they reached out in response to his signal, without even knowing to whom they were replying.

Neat, eh? What is wrong with this model?

For many users, the gradual revelation that an abundance of very personal or sensitive data is being amassed by Google and the fact that it is being marketed to unknown parties is troubling. Part of the problem is perception. In the case described above and most other cases in which the Google is arbiter, the result is almost always to the user’s advantage. But this fact, alone, doesn’t change the perception.

But consider Google’s process from input to output: the collection of user data from a vast array of free user services and the resulting routing of ads from marketing partners. What if data collection, storage and manipulation could be tweaked so that all personal data–including the participation of any user–were completely anonymized? Sounds crazy, right? If the data is anonymized, it’s not useful.

Wrong.

Method #3: Incorporate blind signaling & response into AdWords
— and across the board

A signaling and response system can be constructed on blind credentials. The science is an offshoot of public key cryptography and is the basis of digital cash (at least, the anonymous form). It enables a buyer to satisfy a standard of evidence (the value of their digital cash) and also demonstrate that a fee has been paid, all without identifying the buyer or even the bank that guarantees cash value. The science of blind credentials is the brainchild of David Chaum, cryptographer and founder of DigiCash, a Dutch venture that made it possible to guaranty financial transactions without any party (including the bank) knowing any of the other parties.

The takeaway from DigiCash and the pioneering work of David Chaum is that information can be precisely targeted–even with a back channel–without storing or transmitting any data that aids in identifying the source or target. (Disclosure: I designed the back channel mechanism, which is not a design requirement of Chaum’s DigiCash implementation. As of June 2012, I am working toward a patent). Even more interesting is that the information that facilitates replying to a signal can be structured in a way that is useless to both outsiders and even to the database owner (in this case, Google).

The benefits aren’t restricted to Internet search providers. Choose the boogeyman: The government, your employer, someone taking a survey, your grandmother. In each case, the interloper can (if they wish) provably demonstrate to that meaningful use of private data is restricted-by-design to a stated purpose.

It’s reasonable to assume that privacy doesn’t exist in the Internet age. After all, unlike a meeting at your dining table, the path from whisper to ear passes through a public network. Although encryption and IP re-routing ensure privacy for P2P conversations, it seems implausible to maintain privacy in everyday searches, navigation, and online email services, especially when services are provided at no cost to the user. Individuals voluntarily disgorge personal information in exchange for services, especially, if the goal is to keep the service provider incented to offer the service. For this reason, winning converts to Blind Signaling and Response requires a thoughtful presentation.

Suppose that you travel to another country and walk into a bar. You are not a criminal, nor a particularly famous or newsworthy person. You ask another patron if he knows where to find a good Cuban cigar. When you return to your country, your interest in cigars will probably remain private and so will the fact that you met with this particular individual or even walked into that bar.

Gradually, the internet is facilitating at a distance the privileges and empowerment that we take for granted in a personal meeting. With end-to-end encryption, it has already become possible to conduct a private conversation at a distance. With a TOR proxy and swarm routing, it is also possible to keep the identities of the parties private. But today, Google holds an incredible corpus of data that reveals much of what you buy, think, and fantasize about. To many, it seems that this is part of the Faustian bargain:

  • If you want the benefits of Google services, you must surrender personal data

  • Even if you don’t want to be the target of marketing,* it’s the price that you pay for using the Google service (Search, Gmail, Drive, Navigate, Translate, Picasa, etc).


Of course, Google stores and act on the data that it gathers from your web habits. But both statements above are false!

a)  If Google incorporates Blind signaling technology into its services, you will get all the benefits of each Google service without anyone discovering a useful piece of personal data. Moreover, Google will still benefit your use of their services just as they do now.

b)  Surrendering personal data in a way that does not anonymize particulates it is not “the price that you pay for Google services”. First, Google is paid by the marketer and not individual end users. But more importantly, the marketers can still get the full advantage of sending you relevant, targeted messages while Google protects your privacy en toto! They can take steps to make the data useless to any other party and for any other purpose. Google and their marketing partners will continue to benefit exactly as they do now.

Article in process...


* This is also a matter of perception. You really do want targeted messaging. Even if you hate spam and, like me, prefer to search for a solution instead of have marketers push a solution to you. In a future article, I will demonstrate that every individual is pleased by relevant messaging, even if it is unsolicited, commercial or sent in bulk.

Saturday, March 10, 2012

Will Google “Do No Evil”?

Google captures and keeps a vast amount of personal information about its users. What do they do with all that data? Despite some very persistent misconceptions, the answer is “Nothing bad”. But they could do a much better job ensuring that no one can ever do anything bad with that data—ever. Here is a rather simple but accurate description of what they do with what is gleaned from searches, email, browsing, documents, travel, photos, and more than 3 dozen other ways that they learn about you:

  • Increase the personal relevance of advertising as you surf the web

  • Earn advertising dollars–not because they sell information about you–but
    because they use that data to match and direct relevant traffic toward you


These aren’t bad things, even to a privacy zealot. With or without Google, we all see advertising wherever we surf. Google is the reason that so many of the ads appeal to our individual interests.

But what about all that personal data? Is it safe on Google’s servers? Can they be trusted? More importantly, can it someday be misused in ways that even Google had not intended?

I value privacy above everything else. And I have always detested marketing, especially the unsolicited variety. I don’t need unsolicited ‘solutions’ knocking on my door or popping up in web surfing. When I have needs, I will research my own solutions—thank you very much.

It took me years to come to terms with this apparent oxymoron, but the personalization brought about by information exchange bargains are actually a very good bargain for all parties concerned, and if handled properly, it needn’t risk privacy at all! In fact, the things that Google does with our personal history and predilections really benefits us, but...

This is a pro-Google posting. Well, it’s ‘pro-Google’ if they “do no evil” (Yes—it’s the Google mantra!). First the good news: Google can thwart evil by adding a fortress of privacy around the vast corpus of personal data that they collect and process without weakening user services or the value exchange with their marketing partners. The not-so-good news is that I have urged Google to do this for over two years and so far, they have failed to act. What they need is a little urging from users and marketing partners. Doing no evil benefits everyone and sets an industry precedent that will permeate online businesses everywhere.

The CBS prime time television series, Person of Interest, pairs a freelance ‘James Bond’ with a computer geek. The geek, Mr. Finch, is the ultimate privacy hack. He correlates all manner of disparate data in seconds, including parking lot cameras, government records, high school yearbook photos and even the Facebook pages of third parties.

[caption id="" align="alignleft" width="300"] Mr. Finch & Eric Schmidt: Separated at birth?[/caption]

It’s an eerie coincidence that Google Chairman, Eric Schmidt, looks like Mr. Finch. After all, they both have the same job! They find a gold mine of actionable data in the personal dealings of everyone.

Viewers accept the TV character. After all, Finch is fictional, he is one of the good guys, and his snooping ability (especially the piecing together of far-flung data) is probably an exaggeration of reality. Right?!

Of course, Eric Schmidt & Google CEO Larry Page are not fictional. They run the largest data gathering engine on earth. I may be in the minority. I believe that Google is “one of the good guys”. But let’s first explore the last assumption about Mr. Finch: Can any organization correlate and “mine” meaningful data from a wholesale sweep of a massive eavesdropping machine and somehow piece together a reasonable profile of your interests, behavior, purchasing history and proclivities? Not only are there organizations that do this today, but many of them act with our explicit consent and with a disclosed value exchange for all that personal data.

Data gathering organizations fall into three categories, which I classify based on the exchange of value with web surfers and, more importantly, whether the user is even aware of their role in collecting data. In this classification, Google has moved from the 2nd category to the first, and this is a good thing:

  1. Organizations that you are aware of–at least peripherally–and for which there is a value exchange (preferably, one that is disclosed). Google comes to mind, of course. Another organization with informed access to your online behavior is your internet service provider. If they wanted to compile a dossier of your interests, market your web surfing history to others, or comply with 3rd party demands to review your activities, it would be trivial to do so.

  2. Organizations with massive access to personal and individualized data, but manage to “fly beneath the Radar”. Example: Akamai Technologies operates a global network of servers that accelerate the web by caching pages close to users and optimizing the route of page requests. They are contracted by almost any company with a significant online presence. It’s safe to say that their servers and routers are inserted into almost every click of your keyboard and massively distributed throughout the world. Although Akamai’s customer relationship is not with end users, they provide an indirect service by speeding up the web experience. But because Internet users are not actively engaged with them (and are typically unaware of their role in caching data across the Internet), there are few checks and on what they do with the click history of users, with whom they share data, and if–or how–individualized is data is retained, anonymized or marketed.

  3. National governments. There is almost never disclosure or a personal value exchange. Most often, the activity involves compulsory assistance from organizations that are forbidden from disclosing the privacy breach or their own role in acts of domestic spying.


[caption id="attachment_1193" align="alignright" width="200"]The NSA is preparing to massively vacuum data from everyone, everywhere, at all times The US is preparing to spy on everyone, everywhere, at all times. The massive & intrusive project stuns scientists involved.[/caption]

I have written about domestic spying before. In the US, It has become alarmingly broad, arbitrary and covert. The über secretive NSA is now building the world’s biggest data gathering site. It will gulp down everything about everyone. The misguided justification of their minions is alternatively “anti-terrorism” or an even more evasive “911”.

Regarding, category #2, I have never had reason to suspect Akamai or Verizon of unfair or unscrupulous data mining. (As with Google, these companies could gain a serious ethical and market advantage by taking heed of today’s column.) But today, we focus on data gathering organizations in category #1—the ones with which we have a relationship and with whom we voluntarily share personal data.

Google is at the heart of most internet searches and they are partnered with practically every major organization on earth. Forty eight free services contain code that many malware labs consider to be a stealth payload. These doohickeys give Google access to a mountain of data regarding clicks, searches, visitors, purchases, and just about anything else that makes a user tick.

It’s not just searching the web that phones home. Think of Google's 48 services as a marketer’s bonanza. Browser plug-ins phone home with every click and build a profile of user behavior, location and idiosyncrasies. Google Analytics, a web traffic reporting tool used by a great many web sites, reveals a mountain of data about both the web site and every single visitor. (Analytics is market-speak for assigning identity or demographics to web visits). Don’t forget Gmail, Navigate, Picassa, Drive, Google Docs, Google+, Translate, and 3 dozen other projects that collect, compare and analyze user data. And what about Google’s project to scan everything that has ever been written? Do you suppose that Google knows who views these documents, and can correlate it with an astounding number of additional facts? You can bet Grandma Estelle’s cherry pie that they do!

How many of us ever wonder why all of these services are free to internet users everywhere? That’s an awful lot of free service! One might think that the company is very generous, very foolish, or very unprofitable. One would be wrong on all counts!

Google has mastered the art of marketing your interests, income stats, lifestyle, habits, and even your idiosyncrasies. Hell, they wrote the book on it!

But with great access to personal intelligence comes great responsibility. Does Google go the extra mile to protect user data from off-label use? Do they really care? Is it even reasonable to expect privacy when the bargain calls for data sharing with market interests?

At the end of 2009, Google Chairman, Eric Schmidt made a major gaffe in a televised interview on CNBC. In fact, I was so convinced that his statement was toxic, that I predicted a grave and swift consumer backlash. Referring to the Billions of individuals using Google search engine, investigative anchor, Maria Bartiromo, asked Schmidt why it is that users enter their most private thoughts and fantasies. She wondered if they are aware of Google’s role in correlating, storing & sharing data—and in the implicit role of identifying users and correlating their identities with their interests.

Schmidt seemed to share Bartiromo’s surprise. He suggested that internet users were naive to trust Google, because their business model is not driven by privacy and because they are subject to oversight by the Patriot Act. He said:
If you have something that you don't want anyone to know, maybe you shouldn't be doing it in the first place. If you really need that kind of privacy, the reality is that search engines -- including Google -- do retain this information for some time and it's important, for example, that we are all subject in the United States to the Patriot Act and it is possible that all that information could be made available to the authorities.

At the time, I criticized the statements as naive, but I have since become more sanguine. Mr. Schmidt is smarter than me. I recognize that he was caught off guard. But clearly, his response had the potential to damage Google’s reputation. Several Google partners jumped ship and realigned with Bing, Microsoft’s newer search engine. Schmidt’s response became a lightning rod–albeit brief–for both the EFF (Electronic Freedom Foundation) and the CDT (Center for Democracy & Technology). The CDT announced a front-page campaign, Take Back Your Privacy.

But wait...It needn’t be a train wreck! Properly designed, Google can ensure individual privacy, while still meeting the needs of their marketing partners - and having nothing of interest for government snoops, even with a proper subpoena.

I agree with the EFF that they undermine Google’s mission. Despite his high position, Schmidt may not fully recognize to that Google's marketing objectives can coexist with an ironclad guarantee of personal privacy – even in the face of the Patriot Act.

Schmidt could have had salvaged the gaffe quickly. I urged him to quickly demonstrate that he understands and defends user privacy. But I overestimated consumer awareness and expectations for reasonable privacy. Moreover, consumers may feel that the benefits of Google’s various services inherently trade privacy for productivity (email, taste in restaurants, individualized marketing, etc).

Regarding a damning consumer backlash for whitewashing personal privacy with their public, I was off by a few years, but in the end, my warnings will be vindicated. Public awareness of privacy and especially of internet data sharing and data mining has increased. Some are wondering if the bargain is worthwhile, while others are learning that data can be anonymized and used in ways that still facilitate user benefits and even the vendor’s marketing needs.

With massive access to public data and the mechanisms to gather it (often without the knowledge and consent of users), comes massive responsibility. (His interview contradicts that message). Google must rapidly demonstrate a policy of “default protection and a very high bar for sharing data. In fact, Google can achieve all its goals while fully protecting individual privacy.

Google’s data gathering and archiving mechanism needs a redesign (it’s not so big a task as it seems): Sharing data and cross-pollination should be virtually impossible – beyond a specified exchange between users and intended marketers. Even this exchange must be internally anonymous, useful only in aggregate, and self expiring – without recourse for revival. Most importantly, it must be impossible for anyone – even a Google staffer – to make a personal connection between individual identities and search terms, Gmail users, ad clickers, voice searchers or navigating drivers!

I modestly suggest that Google create a board position, and give it authority with a visible and high-profile individual. (Disclosure, I have made a “ballsy” bid to fill such a position. There are plenty of higher profile individuals that I could recommend).

Schmidt’s statements have echoed for more than 2 years now. Have they faded at all? If so, it is because Google’s services are certainly useful and because the public has become somewhat inured to the creeping loss of privacy. But wouldn’t it be marvelous if Google seized the moment and reversed that trend. Wouldn’t it be awesome if someone at Google discovered that protecting privacy needn’t cripple the value of information that they gather. Google’s market activity is not at odds with protecting their user’s personal data from abuse. What’s more, the solution does not involve legislation or even public trust. There is a better model!

They are difficult to contain or spin. As Asa Dotzler at FireFox wrote in his blog, the Google CEO simply doesn’t understand privacy. Here in USA, Schmidt’s statements have become a lightning rod for both the EFF and CDT (Center for Democracy & Technology). The CDT has even launched a front page campaign to “Take Back Your Privacy”.

Google’s not the only one situated at a data Nexus. Other organizations fly below the radar, either because few understand their tools or because of Government involvement. For example, Akamai probably has more access to web traffic data than Google. The US government has even more access because of an intricate web of programs that often force communications companies to plant data sniffing tools at the junction points of massive international data conduits. We’ve discussed this in other articles, and I certainly don’t advocate that Wild Ducks be privacy zealots and conspiracy alarmists. But the truth is, the zealots have a leg to stand on and the alarmists are very sane.

Saturday, December 31, 2011

What’s with Verizon Billing & Customer Service?

Feb 2012 UPDATE:
Verizon billing misfeasance—just keeps getting worse
At the end of 2011, Verizon announced a ‘bill-paying’ fee that would be charged even if payment was made on time and online. They did this to discourage payment of individual monthly invoices, and push users, instead, to authorize direct debit from credit card and checking accounts. To avoid the new fee, users must allow Verizon to dip into the till without any involvement of the user.

Although the proposal was not a ‘trial balloon’ (Verizon actually believed users wouldn’t mind paying for the privilege of paying!),  they were met with overwhelming publicity and a scathing consumer reaction. The plan was scrapped within 48 hours.

But since the article appeared, many Wild Ducks were less concerned about Verizon’s fee schedule and more interested in the billing & support problems that plague Verizon TV and Internet, especially the wholesale inability to honor FIOS bundle promotions.

Billing integrity is abhorrent. I suspect an audit of 100 customer accounts would reveal errors in the invoices or ACH debits of every one. In my own account, Verizon made scores of credit adjustments, but only after hundreds of calls & complaints. Jump directly to the relevant section.

When I launched A Wild Duck, I promised myself that this humble soap box would never be used for a personal gripe or vendetta. So let me get this out up front: This is a personal gripe. It’s not about the Verizon decision to charge customers a fee to pay their bills (a decision that they announced and then retracted after just 48 hours). Well, it’s tangentially related, but at least it’s not specifically about that loony announcement.

The ISP and wireless behemoth that Americans just love to hate is technically superior in every sector they serve. The best cell phone network in North America. The best Internet Service in the world (many of us enjoy 100Mbps FIOS service in our homes). Incredible television choices at reasonable prices. All this technology and superb technicians when there is a problem. But wait!...

They keep gushing out fodder. This time, Verizon announced a $2 fee for any customer who pays their bill. Yes! A fee to pay bills by mail or even online – unless the customer consents to pre-authorized automatic debit.

The plan lasted for about 2 days. They retracted the goofy anti-customer measure when the Federal Trade Commission announced an investigation (Hey guys. It’s stupid, but it probably isn’t illegal) and when a grass roots backlash began from every corner of the country. In fact, during the waning hours of 2011, it was more like a tidal wave.

I won’t comment further on the idea of charging customers to pay bills. It’s so whacky that it defies comment. But let me explain why users might not wish to allow Verizon to transfer payments in the absence of active client participation..


What’s up with Verizon's Billing & Support?


  • Even after 4 years—Verizon has difficulty honoring offers & incentives

  • Renewal leads to endless billing errors & deplorable customer service

  • Verizon continues billing errors, even after agents identify the problem

  • Hundreds of calls, dozens of letters, constant apologies; Errors persist


Verizon should be permanently barred from interacting with any bank account. The amounts they debit have absolutely no bearing on the service package contracted by their clients! At least if you require them to mail invoices, you have a chance to demand corrections before payment. (But good luck. It can take literally hundreds of calls and complaints).

To make matters worse, Verizon sacked their customer support staff years ago. The remaining peons have been stripped of authority and tools. They simply cannot solve problems, no matter how egregious! (This has been acknowledged to me by numerous telephone support specialists who wish that they had mechanisms to solve serious and blatantly obvious snafus. They can’t even elevate serious billing problems).

Case Study:  Me!

I am an early adopter of direct debit payment (ACH & EFT). Since the 1980s, I have allowed a few vendors to debit my checking account for monthly services. This is how I pay for my mortgage, electric & gas bills, UPS package delivery, and other monthly services. I used to allow Verizon the same access to sweep their monthly service fee from my checking account. "Why not?" you ask. After all, It saves time, avoids late fees, and – as a diversified conglomerate – they can certainly keep their records straight. Right? Not on your life! For the past three years, I have blocked Verizon from dipping into my bank account. Instead, I use single payments for a practical reason...

Verizon has cut back on customer service to such an extent that they debit the wrong amount more frequently than the correct amount (no exaggeration!). In fact, in just 40 months, they have made more than 120 corrections to my bill and issued almost a dozen apologies. The problem is biggest with their FIOS and One Bill program (which folds in your VZ Wireless bill). They also have trouble with accurate billing for their "triple-play" bundles, especially if you choose a plan that aggregates your wireless phones.

I feel sorry for the Verizon customer who fails to regularly check their bank statement for EFT/ACH debits. With an almost complete lack of customer support, it sometimes takes legal threats (or waiting for service to be cut off) before getting Verizon to correct a litany of errors.

Why put up with such negligent customer service? It transcends misfeasance! One reason: Without question, Verizon serves up the best TV, Internet and wireless service in every market they serve. I freely acknowledge a terrific product suite. Cable TV companies and satellite services don’t even come close. Verizon never has a blackout or glitch, they replace equipment on demand, they don't over-compress the TV signal and their FIOS speeds don’t degrade as neighbors jump on the bandwagon. In short, their "product-service" is terrific. But what about customer service?...

After 120 credits (and more than 150 phone calls to get them corrected), I finally had it! I called to disconnect service. Guess what? They lowered the price to keep my business. At first, I said “No.” I was really, really, really fed up. They didn't just lower it once, but three times on the same call—a discount of more than $50 each month, a free DVR and a bump up to unlimited data on my smart phone. Even more surprising, they threw more senior and more professional resources at saving my business than ever offered in the past. They bent over backwards to retain my good will, and in the end, I capitulated... I accepted an outrageously grand offer.

And what happened after they created a new bundle price for me (confirmed in writing). You guessed it! The discount never stuck. Each month thereafter, I was billed the wrong amount. Did I complain? Yes. Every single month. I got profuse apologies (“up the Gazoo” as they say). Eventually, a telephone representative told me that there is simply no mechanism to automatically apply special “customer retention” offers. So she offered to apply the discount each month a few days after the regular invoice is generated. Mind you, a separate representative was manually crediting a “Triple Play” bundle discount because the company had no process for honoring a nationally advertised service packages that included wireless services.

On top of all this, their unified One Bill program was a month behind in showing credits and payments, so I never knew what to pay!

Does this method of manual intervention work? Sort of...about 1/3 of the time. The rest of the time, I must call (it takes 3 or 4 calls) and persuade the first few representatives that I am the beneficiary of a “customer retention” offer. Then, these jokers need to find the representative who made the rebate offer. Then, my call is mysteriously dropped, or – get this – a tin plated, middle manager picks up the line and tells me that the original employee acted without authority. Whoahh?! I reprint transcripts of everything and resend a few legal demand notices (8 times last year!). Eventually, the original rep calls me back. Another apology, retroactive credit, and another promise, and...

Does this sound like a company that has its act together? Is this a vendor to be trusted with the keys to your bank account? I think not, Toto! Against the advice of my own family, I have still remained a Verizon customer. Alas, it is difficult to give up terrific products (Wireless phones, TV, Internet and tethering) and of course, very significant concessions to keep my business. But I certainly wouldn’t put up with this, if it weren’t for a massive incentive: about $600 off of their discount bundle and that’s on top of advertised incentives.

Note to Verizon Stock Holders: Imagine how much more your company would earn if they didn’t have to give so much back to disgruntled customers. If I held equity in Verizon or Vodafone, I would demand an accounting of post-facto givebacks. I bet that you will find a universe of lost revenue.

SOPA: Barricading the Information Superhighway

If you haven’t heard about SOPA — the Stop Online Piracy Act — you will soon. The bill aimed at halting digital piracy is being debated in a Judiciary Committee of the US House of Representatives. It is expected to pass both the House and Senate.

Despite the likelihood of ratification, it is almost comical how former supporters are defecting and trying to distance themselves from it as a vote approaches. Most notably, GoDaddy, the giant of Internet hosting and domain registration. They pulled their support as they became the target of a grass roots boycott

Will it pass? Perhaps. Can it be enforced? Of course not! Will it change anything. No. This leads to an obvious question: Why bother? The answer is typical of Washington politics: SOPA is supported inside the beltway because law makers are out of touch, because Hollywood and the music industry have effective lobbyists, and because it makes for good politics. [continued below]...



But what about the underlying issue? Is digital piracy wrong? Is it reasonable and just to at least try to stem the tide? The cause is just but the proposed mechanism of enforcement is not. In fact, almost any effort to stop digital piracy is futile. The problem must be addressed by rethinking the very purpose and nature of copyright law.

I have mixed feelings about casual consumer piracy of copyright content (music, movies, books and software). My brother will not watch a movie streamed from my home server, because he questions the legality of the original source or rip. Yet he allows his children to use my Netflix account even though it is not authorized for access from his home TV. (He rationalizes that at least someone has licensed the content!). I get it. I realize that some of my music and movies were copied without permission, but I actually own most of the originals. It was simply easier to grab it from Napster or Bit Torrent than to locate and RIP my own CD, DVD or Blu-Ray. Without trying too hard to get into the philosophical argument (is it theft? is it fair? is it enforceable?), SOPA goes too far. It doesn’t criminalize behavior (digital pirates are already breaking the law). Rather, it makes a snitch out of the carrier and then requires the carrier to actively participate in blocking the transmission.

This is feel good politics at its worst. What’s wrong with it?...

  • It can’t work. The economics of free content combined with improving mechanisms of anonymity guarantee that digitized works will spring eternal through other channels. Political restrictions only undermine the growth and influence of the Internet, but not it’s distributed and empowering nature.

  • It leads to a police state – and a very slippery slope!

  • It shifts the burden of protecting content & policing users to the wrong parties

  • It defies the principles that make the internet robust, open & productive. While this may sound like a cop out, I honestly believe that we should not cripple the medium. There are other ways to skin this cat.


By now, Wild Ducks know the drill: So sayeth Ellery!

Tuesday, December 6, 2011

Verizon Wireless: Trouble with honesty & fairness

In the market for mobile phones, a time span of 7 years represents a different era altogether. At least 4 generations of hardware feature phones have come and gone. Seven years ago, there was no iPhone and no Android. Palm was king of PDAs, a class that was still separate from phones and browsers. Feature phones offered Symbian at best. (Who remembers Windows CE?).

Way back in 2004, Verizon crippled Bluetooth in the Motorola v710, the first mobile phone to support short range wireless technology. The carrier supported Bluetooth for connecting a headset and for voice dialing, but they blocked Bluetooth from transferring photos and music between a phone and the user’s own PC. More alarmingly, they displayed a Bluetooth logo on the outside of custom Verizon packaging, even though the logo licensing stipulated that all logical and resident Bluetooth “profiles” are supported.

(Disclosure: I was a plaintiff in a class action that resulted in free phones for users affected by the deception. I am not a ‘Verizon basher’. I have been a faithful client since early cell phones and I recently defended Verizon’s right to charge for off-device tethering.)

[caption id="attachment_800" align="alignright" width="212"] Can you hear me now?[/caption]

Why would Verizon cripple a popular feature that helps to differentiate and sell equipment? That’s an easy one. It forced users to transfer photos and music over the carrier network rather than exchange files directly with a PC. The carrier sells more minutes or costly data plans.

With the same motive, Verizon restricted feature phone apps to their Get it Now store, limiting music, games and ringtones to their own pipeline. Heck--Why not? It’s their ball park! Users can take their business to other carriers. Right? Well perhaps—but mobile service is built upon licensed spectrum, a regulated and limited commodity. Although carriers are not a monopoly in the strict sense (there are three or four carriers in populated regions), they are licensed stewards of an effective market duopoly.

Perhaps the longest lived vestige of Verizon's stodgy funk (and the most depressing) was their insistence on stripping pre-smart phones of the manufacturer’s user GUI and foisting users to navigate a bland set of carrier-centric screens and commands. Often, I would sit next to someone on an international flight who had the same model Motorola, Samsung or Nokia phone. And guess what? His carrier didn’t interfere with fascinating user features. Why did Verizon force their own screens on unsuspecting Americans? It meant that I could not set my phone to vibrate first and then ring with increasing volume over the next few seconds. What a great feature on my Moto i810! But it was stripped from subsequent models, because it wasn’t spec’d by the boys in Verizon’s “retrofit and bastardize” lab.

With the exception of the class action on the Bluetooth features, no legislation was needed to get Verizon to unlock phone features. Eventually a free market mechanism forced them to rethink their ivory tower greed. With AT&Ts market success selling iPhones, Verizon eventually capitulated so that they could become the Android market leader. The new strategy worked for both consumers and for Verizon. Even before they began selling iPhones in 2011, Verizon reasserted their position as the carrier of choice and fully justified their cost premium through excellent coverage and quality service.

[caption id="attachment_801" align="alignleft" width="300"] Hey, Verizon! Can you hear us now?![/caption]

But now, the company that I have learned to hate, love, and then curse, is at it again! They are about to introduce the Samsung Galaxy Nexus. It is only the 2nd Google branded Android (you can’t get closer to a pure Android experience!). But wait! News Flash: They are going to cripple a native Android feature. Just as with the Bluetooth debacle, Verizon claims that it is for the protection and safety of their own users. (Stop me, Mommy! I’m about to access a 3rd party service!).

Why doesn’t Verizon get it? Why can’t they see value in being the #1 carrier and base profit strategy on exceptional build out and service? Sure, I support their right to offer apps, music, ringtones, photo sharing, navigation, child tracking, mobile television, and even home control. These are great niches that can boost revenue. But remember that you are first and foremost a carrier. Just because you plan to enter one of these markets is no reason to cut off your own users from content and service options.

Think of this issue as your subscribers see it: Cutting off users from the Android wallet, because you plan to offer a payment mechanism of your own is no different than a phone service blocking calls to Bank of America because they are tied in with Citibank. If that metaphor doesn’t cut it, how about a simple truth? It’s been 22 years since Judge Harold Greene deregulated the telecommunications monopoly. Your company is both legacy and chief beneficiary of that landmark decision. But success is transient to those who use market penetration to restrict choice. And this time, it won't require anti-monopoly legislation. The market will push back hard and share recovery will be slow.

[caption id="attachment_806" align="alignright" width="265"] I'm taking my phone and going home![/caption]

Android is open. Get it? You have flourished recently, because you chose to embrace an open system that builds on its own popularity. You have contributed to its swift ascent, and likewise, Google and your users who like Android have contributed to your success. Why spit on your users now? What did we do to deserve this?

C’mon Verizon. Stop seizing your ball and threatening to close the ball park. We love you. Get it right for once and stop dicking with us. Our patience is wearing thin!