Up until last Monday, I had been using my free-loader account at dyn.com to publish my personal web server at the domain name reiisi.homedns.org. They've been changing the lineup in their free product line, which is perfectly within their rights. But, right now, I can't afford to pay even the small yearly fee for basic dynamic dns, so my personal web server is now off-line.
先週の月曜日までは、 dyn.com のボクの無料アカウントを使って reiisi.homedns.org のドメイン名で自家用のサーバーを公開していました。 dyn.com の方は、オマケの製品を調節しています。その責任と権限は当然彼らのものです。しかし、ボクは、その基本動的 dns のわずかな料金にしても、今は財布から出せないのです。そのため、ボクの個人ウェブサーバーが繋がらないままです。
For various technical reasons, I had wanted to move to a paying account years ago. But I have to feed my family.
技術上のいろんな理由で有料のアカウントに変えたかったんですが、家族は皆食べないといけません。
Why do I think it's important to have my own domain name?
どうして、自分のドメイン名が大事なのでしょう?
Decentralization.
ディセントラリゼーションです。集中排除。
A decentralized network is a more robust network. (This principle needs further discussion, but not here.)
集中排除分散化ネットワークは頑丈です。(この原則を議論したいけど、ここの今ではない。)
In the original plan for the internet, every terminal computer attached to the network was supposed to have its own host (sub-domain) name. (And its own permanent IP address, but that's another topic for another day.)
インターネットの元々の計画では、ネットワークに接続する端末コンピュータは固有のホスト名(下位ドメイン名)を割り当てられているはずです。(さらに、IP アドレスも持っているはずですが、それはまた違う日の課題です。)
So, if my provider were yahoo (It isn't.), yahoo might set me up with reiisi.yahoo-f.jp, and that would be the name of my router (and perhaps a primary computer behind my router). Other computers inside my router might be named clown.reiisi.yahoo-f.jp, merciless.reiisi.yahoo-f.jp, and nohat.reiisi.yahoo-f.jp. And I could set up mail addresses of my own, say, littleguy@reiisi.yahoo-f.jp.
(ヤフーではないけど)仮にプロバイダーがヤフーだとすると、ヤフーからは reiisi.yahoo-f.jp のドメイン名を割り当ててくれるとします。それが家のルーターのアドレスになる。(またルーターのこちら側の主コンピュータのドメイン名かも知れません。)内側のほかのコンピュータは例えば clown.reiisi.yahoo-f.jp や merciless.reiisi.yahoo-f.jp 及び nohat.reiisi.yahoo-f.jp. そして自分でEメールアドレスを割り当てるのです。例えば littleguy@reiisi.yahoo-f.jp.
This solves a whole lot of security-related problems, all by itself. If, for instance, littleguy@reiisi.yahoo-f.jp becomes a spam magnet because I gave it to an unscrupulous salesman, I no longer have to ask my ISP for a new address.
これだけでいろんなセキュリティの問題を解決します。例えば、 littleguy@reiisi.yahoo-f.jp を良心の無い営業マンに渡してしまって、要求無し営利的Eメールがどっさりと入ってくる場合は、わざわざ新しいEメールアドレスを ISP に頼む必要がない。
That's just a small example of how the current centralized mode of control makes a mess of the internet.
これはただ一つの小さい例えですが、現在のインターネットが集中型管理によってどれほど管理できなくなっているかが見えてくると思います。
It's time to change.
改革の時期です。
Saturday, September 7, 2013
Tuesday, August 27, 2013
grokked
PJ, at groklaw, recently realized that the internet, in its present form, is just too tempting for the control freaks who tend to gravitate to the tops of bureaucracies. And that the technology ultimately does not change the traceability of communication.
So, rather than risk receiving a warrant from bureaucrats on out of control fishing expeditions, she has decided to shutter Groklaw, apparently on the theory that operating it is tantamount to operating a honeypot for an out the out-of-control government that the US government has become. (Reference the NSA "revelations".)
In order to avoid argument, she locked comments on her final post. So, instead, the loyal readers are commenting via the previous post.
Many of those who have participated in her forum feel that shuttering it is unavoidable.
As a Christian who believes the Revelation of John, I see the end game. Truth will cover the earth as a flood, but that kind of leaves much of what we have assumed about privacy washed away in the flood. Someday, I'd like to write something about that, but rant like my blog posts will not do.
Why am I posting this here? I'm not sure.
Freedom has never come free. I've been trying to talk directly about that on my free-is-not-free blog. But it seems like I am talking around the real problems, after all. Not directly, at all. I've mentioned some relevant issues in my defining computers blog and pages, as well. (Security is not privacy or freedom, by the way.)
My solution to PJ's conundrum would be to just add a clause in the groklaw's site policies -- that the site operators would try to avoid cooperating with the tyrants in government, but that there are no promises.
That's the most that can be promised, anyway. We have no right to demand that another should put their lives on the line in some pre-programmed way, and that's what making any more promises than that would encompass.
If PJ cannot be comfortable with that, shuttering the site may be the best part of wisdom on her part. We can't judge that.
As far as making technology that would circumvent the attempts of the various governments to use a news forum for their own spying, the only way to make that kind of thing work is to set up a irregular, large volume wash of what is essentially identical to the spam we hate so much, and use steganography to hide the posts in the flow.
And if we could, what would we have done? Nameless voices are, in the end, nameless.
Nameless is good when you are doing what Jesus called "alms". In political movements, temporary anonymity helps keep movements alive in a hostile society, but the movers have to be ready for when the anonymity is inevitably broken. This is part of freedom, the willingness to take a stand in your own name on important issues. That's what redeems Snowden's behavior most of all.
Conclusion? I have none to offer beyond this. Setting up a temporary anonymous zone so that sites like Groklaw can continue is a bit beyond our current technological context.
What the wash looks like, by the way, is essentially pushing the internet to its correct form, fully distributed, every end-user running his or her or their own local servers -- e-mail, news, editorial (blog), etc. Beyond that, I don't have time to describe now, other than pointing to steganography.
We do have to break our current dependence on centralized certification and centralized software distribution. Proprietary IP does not mix well into this. (Go away, Microsoft, Apple, Oracle, Intel, and all your ilk.) This is a technical requirement.
So, rather than risk receiving a warrant from bureaucrats on out of control fishing expeditions, she has decided to shutter Groklaw, apparently on the theory that operating it is tantamount to operating a honeypot for an out the out-of-control government that the US government has become. (Reference the NSA "revelations".)
In order to avoid argument, she locked comments on her final post. So, instead, the loyal readers are commenting via the previous post.
Many of those who have participated in her forum feel that shuttering it is unavoidable.
As a Christian who believes the Revelation of John, I see the end game. Truth will cover the earth as a flood, but that kind of leaves much of what we have assumed about privacy washed away in the flood. Someday, I'd like to write something about that, but rant like my blog posts will not do.
Why am I posting this here? I'm not sure.
Freedom has never come free. I've been trying to talk directly about that on my free-is-not-free blog. But it seems like I am talking around the real problems, after all. Not directly, at all. I've mentioned some relevant issues in my defining computers blog and pages, as well. (Security is not privacy or freedom, by the way.)
My solution to PJ's conundrum would be to just add a clause in the groklaw's site policies -- that the site operators would try to avoid cooperating with the tyrants in government, but that there are no promises.
That's the most that can be promised, anyway. We have no right to demand that another should put their lives on the line in some pre-programmed way, and that's what making any more promises than that would encompass.
If PJ cannot be comfortable with that, shuttering the site may be the best part of wisdom on her part. We can't judge that.
As far as making technology that would circumvent the attempts of the various governments to use a news forum for their own spying, the only way to make that kind of thing work is to set up a irregular, large volume wash of what is essentially identical to the spam we hate so much, and use steganography to hide the posts in the flow.
And if we could, what would we have done? Nameless voices are, in the end, nameless.
Nameless is good when you are doing what Jesus called "alms". In political movements, temporary anonymity helps keep movements alive in a hostile society, but the movers have to be ready for when the anonymity is inevitably broken. This is part of freedom, the willingness to take a stand in your own name on important issues. That's what redeems Snowden's behavior most of all.
Conclusion? I have none to offer beyond this. Setting up a temporary anonymous zone so that sites like Groklaw can continue is a bit beyond our current technological context.
What the wash looks like, by the way, is essentially pushing the internet to its correct form, fully distributed, every end-user running his or her or their own local servers -- e-mail, news, editorial (blog), etc. Beyond that, I don't have time to describe now, other than pointing to steganography.
We do have to break our current dependence on centralized certification and centralized software distribution. Proprietary IP does not mix well into this. (Go away, Microsoft, Apple, Oracle, Intel, and all your ilk.) This is a technical requirement.
Saturday, August 17, 2013
love passion power and Chicago
My wife put on her Best of Chicago album (the more recent one) again just now. She's been listening to it a lot lately, I'm not sure why.
I'm a fan of Chicago. I have several albums stored somewhere across the Pacific, about half of their albums from Chicago Transit Authority to around Chicago XI. Some are rotting on tape, unfortunately.
To me, Chicago VII was the pinnacle of their work, and I still think so. Unfortunately, they backed away from their experiments in fusion jazz after that. Mixed with their high-fructose pop output, I'd have liked them to put out some more albums with the heavy fusion influence shown in VII. (Maybe it would have been hard for them to do that without Terry Kath -- the chemistry of a group changes when a member is taken away like that.)
(I notice that Stone of Sisyphus was released around five years ago while I wasn't looking.)
So we're listening to Chicago, somewhere before the tune "Stay the Night" in the play order, and I'm thinking that Chicago, except for V and VII, is pretty much heavy metal for non-metalheads. Metal adapted to pop.
But "Stay the Night" begs analysis. It came out while I was at BYU, and I and most of my friends listened to it, even danced to it, without really thinking too deeply about the lyrics. This was about a boy's passion for a girl, that was all.
I mean, I understood the irony in Heart's "Dreamboat Annie" when I was in High School. (Love that album. And wisdom and experience tell me so many more things when I listen to it now.) But it was several years later, when I met my cousin's sometimes boyfriend that she just couldn't leave behind, before I started really facing the irony that "Stay the Night" is so representative of.
Read the lyrics sometime. It's definitely youthful passion, definitely not the higher emotions of love. Watch the video with Debby Evans. It's amusing, very juvenile, very instructive of the value of juvenile passion.
(But does he want to take the time to understand her?)
And so forth. When passion remains untempered, when nothing gets in the way, something is lost.
I still enjoy the music, and the way it underscores the melodramatic lyrics. It seems I enjoy popular music now for the irony as much as I used to for the passion.
I'm a fan of Chicago. I have several albums stored somewhere across the Pacific, about half of their albums from Chicago Transit Authority to around Chicago XI. Some are rotting on tape, unfortunately.
To me, Chicago VII was the pinnacle of their work, and I still think so. Unfortunately, they backed away from their experiments in fusion jazz after that. Mixed with their high-fructose pop output, I'd have liked them to put out some more albums with the heavy fusion influence shown in VII. (Maybe it would have been hard for them to do that without Terry Kath -- the chemistry of a group changes when a member is taken away like that.)
(I notice that Stone of Sisyphus was released around five years ago while I wasn't looking.)
So we're listening to Chicago, somewhere before the tune "Stay the Night" in the play order, and I'm thinking that Chicago, except for V and VII, is pretty much heavy metal for non-metalheads. Metal adapted to pop.
But "Stay the Night" begs analysis. It came out while I was at BYU, and I and most of my friends listened to it, even danced to it, without really thinking too deeply about the lyrics. This was about a boy's passion for a girl, that was all.
I mean, I understood the irony in Heart's "Dreamboat Annie" when I was in High School. (Love that album. And wisdom and experience tell me so many more things when I listen to it now.) But it was several years later, when I met my cousin's sometimes boyfriend that she just couldn't leave behind, before I started really facing the irony that "Stay the Night" is so representative of.
Read the lyrics sometime. It's definitely youthful passion, definitely not the higher emotions of love. Watch the video with Debby Evans. It's amusing, very juvenile, very instructive of the value of juvenile passion.
I don't want you to misunderstand me
(But does he want to take the time to understand her?)
I just want to say what's on my mind(No time? What's so much more important than understanding?)
No need to hit me with an attitude
Because I haven't got the time
And so forth. When passion remains untempered, when nothing gets in the way, something is lost.
I still enjoy the music, and the way it underscores the melodramatic lyrics. It seems I enjoy popular music now for the irony as much as I used to for the passion.
Friday, August 9, 2013
subconscious vs. unconscious vs. pre-conscious vs. ...
Went to wikipedia to look for a Japanese equivalent of the subconscious mind and was rudely reminded that the argument about the existence of the unconscious elements of the mind are not at all resolved. (I knew that, why was I surprised?)
Freud talked about the unconscious and the pre-conscious.
The unconscious is the suppressed elements of the mental processes, and the preconscious is the parts which are not yet either expressed or suppressed.
And he argues that the "subconscious" is too ambiguous a term to be meaningful.
I'll give him one on that last, but I wanted him to admit that "unconscious", "preconscious" and "conscious" are also rather ambiguous classifications, not forming a true partition.
What we suppress changes from moment to moment. So does what slides in-and-out of focus.
If I wanted to make the divisions he makes, I would do it this way:
I would make another set of classifications, cutting across the first set, dividing by the topics they cover:
But the third is not just a subset of the first two. Whether we have deliberately suppressed a topic or not, the question of focus cannot be answered reliably. This may be somewhat the class Freud was intending by pre-conscious.
Forgotten topics are not just out-of-focus. They are in cold storage.
In a computer system, the first class of topics would somewhat correspond to data in cache. (Except there are hard limits to computer cache, not so much to our minds' cache.) The second class of topics would be data in high-speed store (RAM, in current systems). The fourth would be data stored on disk (or tape, etc.) in persistent store, indexed and addressable, but it takes a while to get at it.
The third would be discarded data, results that seemed, at the time, to unnecessary or even counter to the goal of solution. If a computer system is capable of bringing the discarded data back, it is data that must be regenerated, recalculated, re-indexed, etc.
This is one of the remaining differences between human cognition and mechanical reasoning -- Humans generally can, if they have enough motivation, bring suppressed topics into memory and into focus. Computer systems generally (still) require human intervention to do so.
There are at least four more classes of thoughts that need to be considered:
Revelation, of course, is off the board when it comes to scientific discussion.
Wait. I want to refine this last list:
Internal thought processes includes the following:
Socially imposed thought processes include
By "other beneficial" I mean various forms of revelations from good sources -- words of warning and encouragement from angels, some of whom are mortal and some of whom are not. Also, scripture, and the more direct revelation from what the Christians call the Holy Spirit.
Mortal angels would include friends and family in their positive moments, some church members who influence us for good, influential teachers, and so forth. They may not be official messengers from God, but they do bring us good and helpful things to think about, and the confirmative feelings by which we generally recognize that there is something worth listening to, checking, pursuing.
I'm not going to talk about immortal angels because God will do what He will do, and there really is not much use talking about that. For the same reasons these sorts of things are not subject to scientific inquiry, they are not generally of much use except to those who receive them.
But I will say this, they are more common than we generally recognize. We have a certain blindness.
The Holy Spirit is, among other things, the primary source of our conscience. I won't say much about this either, except that if you believe there is anything true and good, it is by the power of the Holy Spirit that you believe it. I'm not saying you are a closet Christian, I'm saying that the Holy Spirit is so universal, so ubiquitous. And we often can't see the forest for the trees.
If we believe in love and truth and good, the influence that gives us the confidence to believe is what I call the Holy Spirit. If we find ourselves questioning the errors and excesses of certain religionists, partisans, politicalists, charismats, it may be the same Holy Spirit telling us that they've gone too far.
Anti-beneficial external influences? Well, yes, I did mean to talk about the adversary of our souls and those who follow him. Father of lies -- 99% truth so as to pervert it all and undo it all with that 1% lie.
But refraining from talking about the devil is a good idea, anyway. Much more beneficial to talk about good things and good influences and our relationships to them.
Freud talked about the unconscious and the pre-conscious.
The unconscious is the suppressed elements of the mental processes, and the preconscious is the parts which are not yet either expressed or suppressed.
And he argues that the "subconscious" is too ambiguous a term to be meaningful.
I'll give him one on that last, but I wanted him to admit that "unconscious", "preconscious" and "conscious" are also rather ambiguous classifications, not forming a true partition.
What we suppress changes from moment to moment. So does what slides in-and-out of focus.
If I wanted to make the divisions he makes, I would do it this way:
- deliberate thought processes
- non-deliberate thought processes
I would make another set of classifications, cutting across the first set, dividing by the topics they cover:
- topics of focus
- topics out of focus
- suppressed topics
- forgotten topics
But the third is not just a subset of the first two. Whether we have deliberately suppressed a topic or not, the question of focus cannot be answered reliably. This may be somewhat the class Freud was intending by pre-conscious.
Forgotten topics are not just out-of-focus. They are in cold storage.
In a computer system, the first class of topics would somewhat correspond to data in cache. (Except there are hard limits to computer cache, not so much to our minds' cache.) The second class of topics would be data in high-speed store (RAM, in current systems). The fourth would be data stored on disk (or tape, etc.) in persistent store, indexed and addressable, but it takes a while to get at it.
The third would be discarded data, results that seemed, at the time, to unnecessary or even counter to the goal of solution. If a computer system is capable of bringing the discarded data back, it is data that must be regenerated, recalculated, re-indexed, etc.
This is one of the remaining differences between human cognition and mechanical reasoning -- Humans generally can, if they have enough motivation, bring suppressed topics into memory and into focus. Computer systems generally (still) require human intervention to do so.
There are at least four more classes of thoughts that need to be considered:
- instinct
- social consciousness
- divine revelation
- false revelation
Revelation, of course, is off the board when it comes to scientific discussion.
Wait. I want to refine this last list:
- internal thought processes
- socially imposed thought processes
- other beneficial thought processes
- other anti-beneficial externally thought processes
Internal thought processes includes the following:
- instinct from patterns in our genetic material,
- para-instinctual patterns from our existence in the pre-birth spiritual realm,
- habitual and other patterns from our mortal lives to the present,
- and our own active thoughts, the ones we are most responsible for.
Socially imposed thought processes include
- trained patterns -- most of what we refer to as "common sense",
- lessons of social propriety -- obligation and duty, etc.,
- reactive thought processes -- analytic, semi-analytic, confirmative, etc.,
- rebellion processes,
- etc.
By "other beneficial" I mean various forms of revelations from good sources -- words of warning and encouragement from angels, some of whom are mortal and some of whom are not. Also, scripture, and the more direct revelation from what the Christians call the Holy Spirit.
Mortal angels would include friends and family in their positive moments, some church members who influence us for good, influential teachers, and so forth. They may not be official messengers from God, but they do bring us good and helpful things to think about, and the confirmative feelings by which we generally recognize that there is something worth listening to, checking, pursuing.
I'm not going to talk about immortal angels because God will do what He will do, and there really is not much use talking about that. For the same reasons these sorts of things are not subject to scientific inquiry, they are not generally of much use except to those who receive them.
But I will say this, they are more common than we generally recognize. We have a certain blindness.
The Holy Spirit is, among other things, the primary source of our conscience. I won't say much about this either, except that if you believe there is anything true and good, it is by the power of the Holy Spirit that you believe it. I'm not saying you are a closet Christian, I'm saying that the Holy Spirit is so universal, so ubiquitous. And we often can't see the forest for the trees.
If we believe in love and truth and good, the influence that gives us the confidence to believe is what I call the Holy Spirit. If we find ourselves questioning the errors and excesses of certain religionists, partisans, politicalists, charismats, it may be the same Holy Spirit telling us that they've gone too far.
Anti-beneficial external influences? Well, yes, I did mean to talk about the adversary of our souls and those who follow him. Father of lies -- 99% truth so as to pervert it all and undo it all with that 1% lie.
But refraining from talking about the devil is a good idea, anyway. Much more beneficial to talk about good things and good influences and our relationships to them.
Saturday, August 3, 2013
powerful programming languages -- php5 and suhosin
PHP5 is pretty powerful.
Powerful languages have a problem. They allow things to happen that the language designer hasn't even imagined. Some of those things sometimes allow mean-spirited sorts of people to attack servers, steal credit card numbers, and make general malicious mischief.
So PHP version 5.3 needed a band-aid, to help the naive web programmer avoid blowing him/herself away with good intentions poorly implemented. The band-aid was called "suhosin".
Unfortunately, the three German engineers who developed suhosin seem to have gotten busy doing other things, according to this post at Arch Linux. And the current suhosin doesn't match the current version of php5. [update: If you fail to follow all of the links Pierre provides, at least look at this mailing list post from one of suhosin's developers.]
I had been thinking about brushing up my php skills, so I had installed php. With the upgrade to 5.4 in Debian wheezy, suhosin doesn't load. Instead, it fills my error log files with complaints of incompatibility.
So I checked, and nothing else gets removed when I remove php5. So I removed it.
When I really need it again, I'll install it again. Maybe by that time the guys who run php will have folded all of the functionality of suhosin into the language itself.
But this is not a solution, it's a knee-jerk reaction. More first-aid fixes that don't really do the full job.
This highlights one of the problems in software architecture: The power of a powerful language is in its expressiveness. To the more expressive a language is, the fewer limits there are to the things which can be expressed in it. But security in current practice requires setting limits. We need to give the programmer power, but we need to take power away from the end user.
There is an inherent conflict here. I mean, sure, we could go the direction taken with Java, using execution policies to tune the expressiveness available in the end-user's context, but that has its own set of traps --
The answer of the US Constitution was "Use checks and balances and keep it simple." Both of these principles have been long ago set aside as legislators and special interest groups press for responsive government.
Is there something wrong here?
Can we as general members of society learn enough about systems to pare back the legal kruft that is currently overburdening (and overly burdening) society (and is a primary cause of budget problems, not to mention the bureaucratic abuses that show every sign of continuing to increase)?
Can these principles be applied to computer systems? If they can, how?
I think they can, but I'm not sure anyone reading this would understand. (I'm not intending to insult. No one has time to study every necessary subject, and this particular subject has been advertised by certain special interest groups as unnecessary.)
And it seems no surprise to me that the current trends in systems design seem to be going towards increasing complexity in the provided systems, which parallels the political atmosphere, and is exactly not the solution. Precisely what we should not be doing.
We put power in the end users' hands (quite literally with the new crop of portable information devices that match the supercomputers of a few years ago). We spend a lot of money, time, and effort putting power in the end users' hands. Then we spend a lot of money, time, and effort trying to limit that power to some definition of "right" uses. We are
We can't understand everything the end user wants to do, and we can't predict what would be "safe" or "dangerous" beyond making crude and overly broad walls. (We, as an industry, try to make straitjackets, really, but we fortunately tend to fail to get the user into the straitjackets -- Fortunately, indeed, since success would make us unable to even consider band-aids like suhosin.)
And we (the primary movers of the industry) don't want to believe that end users could really want to use our systems, any more than we want to believe that the end user could understand new and appropriate ways to use our systems.
We don't want to believe that the end users might be smarter than the system designers about what the end user wants to do with the systems.
And yet, it is the only the smart end user that can safely use the system.
Uhm, no, I don't have a happy solution to the problems yet, at least no quick, straightforward patches. The only real solution I can see is not going to be quick, not going to contribute immediately to anyone's bottom line of monetary profit, not going to be considered acceptable to any of the current crop of investors, managers, and accountants.
Powerful languages have a problem. They allow things to happen that the language designer hasn't even imagined. Some of those things sometimes allow mean-spirited sorts of people to attack servers, steal credit card numbers, and make general malicious mischief.
So PHP version 5.3 needed a band-aid, to help the naive web programmer avoid blowing him/herself away with good intentions poorly implemented. The band-aid was called "suhosin".
Unfortunately, the three German engineers who developed suhosin seem to have gotten busy doing other things, according to this post at Arch Linux. And the current suhosin doesn't match the current version of php5. [update: If you fail to follow all of the links Pierre provides, at least look at this mailing list post from one of suhosin's developers.]
I had been thinking about brushing up my php skills, so I had installed php. With the upgrade to 5.4 in Debian wheezy, suhosin doesn't load. Instead, it fills my error log files with complaints of incompatibility.
So I checked, and nothing else gets removed when I remove php5. So I removed it.
When I really need it again, I'll install it again. Maybe by that time the guys who run php will have folded all of the functionality of suhosin into the language itself.
But this is not a solution, it's a knee-jerk reaction. More first-aid fixes that don't really do the full job.
This highlights one of the problems in software architecture: The power of a powerful language is in its expressiveness. To the more expressive a language is, the fewer limits there are to the things which can be expressed in it. But security in current practice requires setting limits. We need to give the programmer power, but we need to take power away from the end user.
There is an inherent conflict here. I mean, sure, we could go the direction taken with Java, using execution policies to tune the expressiveness available in the end-user's context, but that has its own set of traps --
- Will some of the programmers remember to set up the policies?
- Do the programmers understand how the policies are used to secure the system?
- Does the policy end up preventing the end user from doing important things?
- Do legislators understand the interaction with law and regulation and the potentials for abusing the laws and regulations?
- How does the government protect the people's security without inducing more chances for treacherous abuse?
- And how can a government make the people secure without excessively limiting their freedoms?
The answer of the US Constitution was "Use checks and balances and keep it simple." Both of these principles have been long ago set aside as legislators and special interest groups press for responsive government.
Is there something wrong here?
Can we as general members of society learn enough about systems to pare back the legal kruft that is currently overburdening (and overly burdening) society (and is a primary cause of budget problems, not to mention the bureaucratic abuses that show every sign of continuing to increase)?
Can these principles be applied to computer systems? If they can, how?
I think they can, but I'm not sure anyone reading this would understand. (I'm not intending to insult. No one has time to study every necessary subject, and this particular subject has been advertised by certain special interest groups as unnecessary.)
And it seems no surprise to me that the current trends in systems design seem to be going towards increasing complexity in the provided systems, which parallels the political atmosphere, and is exactly not the solution. Precisely what we should not be doing.
We put power in the end users' hands (quite literally with the new crop of portable information devices that match the supercomputers of a few years ago). We spend a lot of money, time, and effort putting power in the end users' hands. Then we spend a lot of money, time, and effort trying to limit that power to some definition of "right" uses. We are
- Not trying to teach the end user how to use the power wisely.
- Not trying to show the end user how to get around the traps.
- Not trying to give the end user more power to do right things.
- Not really trying to give the user solutions, just things that we can sell as if they were solutions
We can't understand everything the end user wants to do, and we can't predict what would be "safe" or "dangerous" beyond making crude and overly broad walls. (We, as an industry, try to make straitjackets, really, but we fortunately tend to fail to get the user into the straitjackets -- Fortunately, indeed, since success would make us unable to even consider band-aids like suhosin.)
And we (the primary movers of the industry) don't want to believe that end users could really want to use our systems, any more than we want to believe that the end user could understand new and appropriate ways to use our systems.
We don't want to believe that the end users might be smarter than the system designers about what the end user wants to do with the systems.
And yet, it is the only the smart end user that can safely use the system.
Uhm, no, I don't have a happy solution to the problems yet, at least no quick, straightforward patches. The only real solution I can see is not going to be quick, not going to contribute immediately to anyone's bottom line of monetary profit, not going to be considered acceptable to any of the current crop of investors, managers, and accountants.
Tuesday, July 30, 2013
Optimizing all the value out of your bottom line
Money.
I have a bunch of projects I could push forward if I had money. Last time I looked at Kickstarter, I would need a US credit card to try to get them funded there. I've looked at some of the other crowdfunding sites, and I don't really care for the models they use.
It's not just money I need. Publicity on Kickstarter or somewhere similar could help me reach people who might be interesting in working with me on those projects.
It's the connections I develop while getting the money the dull way that is the real value. The portfolio I develop is also useful, but it's the human relationships and the value that people have for each other, the value we generate when we work together that is the real value. Not money.
Money is cheap.
Money.
If money is what you want, I hear it's not hard to get. (And I think I have reason to believe it.) But when you go that way, you get money without meaning.
Money saves no one. I could suppose I could win a big lottery, but then I would have to spend a lot of time every day for several months just getting the money put away where the combination of US and Japanese taxes wouldn't have me owing more than I won.
Sure, that would eventually settle down, and I would be able to focus on my projects. And, for all that I could get to work, I still wouldn't have that network of like-minded people to help. Maybe I could get such a network if I had money. But there is the other possibility of just getting people who want the money clogging up my networks.
People who just want money also clog up companies, make them (appear to be) inefficient.
Companies big and small have focused on optimizing their processes, to build their bottom line. But what do they measure that bottom line in?
Money.
How often it is that a company gets a big hit on a product and then refocuses itself around the money the hit product brings in.
Focuses on the product, in theory, but more on the money. Gotta build that bottom line.
Then they optimize the company around the bottom line -- around the product, first, but around the money most of all.
And then the product begins to lose popularity. And the company finds it has money and no meaning. And no way to survive.
And then the company goes running to the government and cries,
Well, let's back up and look at the optimization process. How does that optimization work? How does it rob the company of meaning?
Well, there are two broad facets to the optimization. Two kinds of deadwood that companies like to optimize out of their organizations. Two kinds of employees that don't appear to contribute to the bottom line.
You know the one kind, no one remembers how he got hired. He never does anything. Every time you see him, he's surfing the web. Or talking at the water cooler. Or sleeping on company time.
He comes in late, leaves early. Ask him to do something, and it's a crap-shoot whether what he does, if anything, will be useful. In fact, sometimes when you involve him in your project, he does something that so much gets in the way that you'd have preferred that he had done nothing.
Clearly deadwood. Should be fired.
Well, you have to realize that, when you put that guy on the street, unless he finds something to motivate him, he goes on welfare. Then what the company is no longer paying out in wages, it is now paying in taxes.
(One problem with using inflation -- public debt -- as a way to hide future taxes, we don't see an immediate tax burden in putting such employees on the street.)
Then there's the other type. Faded stars. Still useful. Maybe they were involved in the hit product that is the company's (current) bread-and-butter. But they seem to have lost their way. Anyway, they are going a different direction from the rest of the company. They come in when they want, do what they want, what they contribute to projects is usually hard enough to work with that you wish they had done nothing.
Clearly deadwood. Should be given the opportunity to work elsewhere.
The problem is, intellectual property is a mirage. What the mirage hides is intellectual capital. Intellectual capital is in the brains of the faded stars. Maybe it's kinder to let them go elsewhere, but when you do so, a big chunk of the company's intellectual capital goes with them. And it's that intellectual capital that the company is going to need when the hit product begins to fail.
Let me tell you a secret: These two guys are one-and-the-same. You just didn't know enough about him when I described him to you the first time.
The problem is in your vision. In fact, you should go look in the mirror when you criticize the deadwood at your company, because one of these days, the deadwood is going to be you.
It's necessary to fire people or let them move on sometimes, but we should be careful about our reasons. It's even necessary to let go of entire companies.
But if our bottom line is money, the filter is going to be set to discard all meaning and all value. And it's no surprise when the company fails with its hit product. And no surprise when the surrounding society seems to have trouble maintaining enough value to survive as companies burn brightly and then burn out.
I have a bunch of projects I could push forward if I had money. Last time I looked at Kickstarter, I would need a US credit card to try to get them funded there. I've looked at some of the other crowdfunding sites, and I don't really care for the models they use.
It's not just money I need. Publicity on Kickstarter or somewhere similar could help me reach people who might be interesting in working with me on those projects.
It's the connections I develop while getting the money the dull way that is the real value. The portfolio I develop is also useful, but it's the human relationships and the value that people have for each other, the value we generate when we work together that is the real value. Not money.
Money is cheap.
Money.
If money is what you want, I hear it's not hard to get. (And I think I have reason to believe it.) But when you go that way, you get money without meaning.
Money saves no one. I could suppose I could win a big lottery, but then I would have to spend a lot of time every day for several months just getting the money put away where the combination of US and Japanese taxes wouldn't have me owing more than I won.
Sure, that would eventually settle down, and I would be able to focus on my projects. And, for all that I could get to work, I still wouldn't have that network of like-minded people to help. Maybe I could get such a network if I had money. But there is the other possibility of just getting people who want the money clogging up my networks.
People who just want money also clog up companies, make them (appear to be) inefficient.
Companies big and small have focused on optimizing their processes, to build their bottom line. But what do they measure that bottom line in?
Money.
How often it is that a company gets a big hit on a product and then refocuses itself around the money the hit product brings in.
Focuses on the product, in theory, but more on the money. Gotta build that bottom line.
Then they optimize the company around the bottom line -- around the product, first, but around the money most of all.
And then the product begins to lose popularity. And the company finds it has money and no meaning. And no way to survive.
And then the company goes running to the government and cries,
SAVE US FROM OURSELVES!!!
Make a law that requires people to use our product!!!!
'Cause we were stupid and now we don't know anything but the product that people don't buy any more!!!
Copyright! Patent! Something has to work!!!!
We don't know how to make meaning any more!!!If only companies could really see that this is what they are saying when the run crying to the government. Then they might not optimize all the meaning out of their operations so that they have to be saved from themselves.
Well, let's back up and look at the optimization process. How does that optimization work? How does it rob the company of meaning?
Well, there are two broad facets to the optimization. Two kinds of deadwood that companies like to optimize out of their organizations. Two kinds of employees that don't appear to contribute to the bottom line.
You know the one kind, no one remembers how he got hired. He never does anything. Every time you see him, he's surfing the web. Or talking at the water cooler. Or sleeping on company time.
He comes in late, leaves early. Ask him to do something, and it's a crap-shoot whether what he does, if anything, will be useful. In fact, sometimes when you involve him in your project, he does something that so much gets in the way that you'd have preferred that he had done nothing.
Clearly deadwood. Should be fired.
Well, you have to realize that, when you put that guy on the street, unless he finds something to motivate him, he goes on welfare. Then what the company is no longer paying out in wages, it is now paying in taxes.
(One problem with using inflation -- public debt -- as a way to hide future taxes, we don't see an immediate tax burden in putting such employees on the street.)
Then there's the other type. Faded stars. Still useful. Maybe they were involved in the hit product that is the company's (current) bread-and-butter. But they seem to have lost their way. Anyway, they are going a different direction from the rest of the company. They come in when they want, do what they want, what they contribute to projects is usually hard enough to work with that you wish they had done nothing.
Clearly deadwood. Should be given the opportunity to work elsewhere.
The problem is, intellectual property is a mirage. What the mirage hides is intellectual capital. Intellectual capital is in the brains of the faded stars. Maybe it's kinder to let them go elsewhere, but when you do so, a big chunk of the company's intellectual capital goes with them. And it's that intellectual capital that the company is going to need when the hit product begins to fail.
Let me tell you a secret: These two guys are one-and-the-same. You just didn't know enough about him when I described him to you the first time.
The problem is in your vision. In fact, you should go look in the mirror when you criticize the deadwood at your company, because one of these days, the deadwood is going to be you.
It's necessary to fire people or let them move on sometimes, but we should be careful about our reasons. It's even necessary to let go of entire companies.
But if our bottom line is money, the filter is going to be set to discard all meaning and all value. And it's no surprise when the company fails with its hit product. And no surprise when the surrounding society seems to have trouble maintaining enough value to survive as companies burn brightly and then burn out.
Friday, July 5, 2013
culpability for promoting bad tech
I've been wasting time on groklaw again.
This is about weev's problem, which I blogged about several months ago.
It's not a little problem, and it's not just weev's problem.
AT&T put an open interface to their database of iPhone customers' e-mail addresses. The primary key was essentially the serial number of the phone's radio modem circuit. This was negligent, and, with the current privacy laws, it was criminally negligent. Comparing database interfaces to doors, this is like failing to put a door in the doorway. It must be expected that people will come and go at will.
They could have put a hash on the key in their interface. A simple one-to-one hash would be like a gate with a latch. In this case, the key in the database query (visible in the browser's URL bar) would not look like the modem's serial number, so they interested visitor would be required to think a bit to conclude that there might be a relationship between the key and the serial number.
A simple hash would still be subject to the problem with bumping the number and seeing someone else's e-mail address, but at least it would not be advertising the path in. Using the serial number directly was effectively advertising the path in. That's why it's like an entranceway without gate or door. (And no lock.)
A sparse hatch, where numbers before and after valid keys would be invalid keys, would be a latch with a cheap and easy combination lock. Simply incrementing the key would result in an invalid query instead of a customer's e-mail address. But a curious visitor might "check the doorknob" and even try a few combinations. In other words, might try a long enough sequence to determine that the key was sufficient to produce more valid addresses.
To avoid revealing addresses, AT&T would have to limit such tries from the same IP address.
A cryptologically strong hash, sufficiently sparse, would be like a stronger lock. It would take a lot more deliberate and sustained effort to find valid keys, and such a sustained effort would be a red flag in AT&T's logs. (If they bothered to look.)
AT&T failed to make any real technical measure to limit access.
weev's actions were discourteous. But the only criminal element to them is projected through a twisted interpretation of bad laws that were written without any reference to the technology involved.
AT&T is the criminal, and the prosecuting attorney are also culpable.
Now, in truth, what AT&T did with the database should not need to be considered a crime. Negligent, discourteous, inconsiderate, grounds for reconsidering whether we want to be their customer, yes. It should not be a crime.
Why is it a crime?
The "technology" behind e-mail is extremely simple. Simple, as in, without safety features. Simple, as in minimalistic controls. They were "best practices" in a context where most users were technically inclined and motivated to be courteous to fellow users. They are not even good practices in the current context, where users don't want to be bothered with technical details, where many want to depend on the computer like it's a substitute for God, and where some are all too willing to misuse the tech if they can make a profit thereby.
In some ways, it's simple like physical mail. It's easy to write any address you want on the envelope.
But it is not as good as physical mail because the envelope is basically see-through. Any admin on any server that the e-mail passes through can easily look inside.
And if you open the envelope and change the contents, there is no evidence of the change.
And, while there are words on the envelope and inside it, those words are not like handwritten words, or even like typewritten words. There is no evidence of who put those words there when.
If it says it's from your Aunt Sharon, it's hard to tell whether it really is unless you call her up and ask her.
You can recognize her voice on the phone. If you got a physical letter from her, you probably know what her handwriting looks like. You can sort of tell a little by the words and expressions used, but there are far fewer clues about identity in e-mail.
There is some external evidence in the form of records on servers, but that is pretty weak evidence, and not visible to the ordinary user.
If your mail service provider encrypts their storage, the envelope and the contents become opaque, but only as long as the message is stored. Once the message is transmitted, it is visible to anyone and everyone who bothers to look during transit.
There is also the problem of volume. e-mail is much easier and cheaper to generate in excessive volume than ordinary junk mail.
End user encryption can mitigate some of these disadvantages to a certain degree, but there are no current common ways to use encryption.
When Microsoft incorporated e-mail into MSWindows95's internet application suite, they were making technology for the technically inclined to people who are not interested in technical details. They put an easy user interface on it and allowed ordinary users to do themselves damage with the tech.
They have several times offered to half-fix the technology, but their offerings are woefully inadequate and invariably make critical use of technical measures that Microsoft can control through patents and other means. Their solutions are always going to cement their effective monopoly position, if we allow them to have their way.
AT&T is culpable for putting a bad database interface on the web for all their iPhone customers. Microsoft is culpable for selling us technology that is not really appropriate for ordinary users in ordinary use.
We are culpable for continuing to use it.
I have some ideas about ways to mitigate the problems with e-mail, but it's a lot easier for me to just dream about re-booting the computer industry with good basic technology. So I waste my time dreaming instead of contributing to the solution. Mea culpa.
Someday.
Someday.
This is about weev's problem, which I blogged about several months ago.
It's not a little problem, and it's not just weev's problem.
AT&T put an open interface to their database of iPhone customers' e-mail addresses. The primary key was essentially the serial number of the phone's radio modem circuit. This was negligent, and, with the current privacy laws, it was criminally negligent. Comparing database interfaces to doors, this is like failing to put a door in the doorway. It must be expected that people will come and go at will.
They could have put a hash on the key in their interface. A simple one-to-one hash would be like a gate with a latch. In this case, the key in the database query (visible in the browser's URL bar) would not look like the modem's serial number, so they interested visitor would be required to think a bit to conclude that there might be a relationship between the key and the serial number.
A simple hash would still be subject to the problem with bumping the number and seeing someone else's e-mail address, but at least it would not be advertising the path in. Using the serial number directly was effectively advertising the path in. That's why it's like an entranceway without gate or door. (And no lock.)
A sparse hatch, where numbers before and after valid keys would be invalid keys, would be a latch with a cheap and easy combination lock. Simply incrementing the key would result in an invalid query instead of a customer's e-mail address. But a curious visitor might "check the doorknob" and even try a few combinations. In other words, might try a long enough sequence to determine that the key was sufficient to produce more valid addresses.
To avoid revealing addresses, AT&T would have to limit such tries from the same IP address.
A cryptologically strong hash, sufficiently sparse, would be like a stronger lock. It would take a lot more deliberate and sustained effort to find valid keys, and such a sustained effort would be a red flag in AT&T's logs. (If they bothered to look.)
AT&T failed to make any real technical measure to limit access.
weev's actions were discourteous. But the only criminal element to them is projected through a twisted interpretation of bad laws that were written without any reference to the technology involved.
AT&T is the criminal, and the prosecuting attorney are also culpable.
Now, in truth, what AT&T did with the database should not need to be considered a crime. Negligent, discourteous, inconsiderate, grounds for reconsidering whether we want to be their customer, yes. It should not be a crime.
Why is it a crime?
The "technology" behind e-mail is extremely simple. Simple, as in, without safety features. Simple, as in minimalistic controls. They were "best practices" in a context where most users were technically inclined and motivated to be courteous to fellow users. They are not even good practices in the current context, where users don't want to be bothered with technical details, where many want to depend on the computer like it's a substitute for God, and where some are all too willing to misuse the tech if they can make a profit thereby.
In some ways, it's simple like physical mail. It's easy to write any address you want on the envelope.
But it is not as good as physical mail because the envelope is basically see-through. Any admin on any server that the e-mail passes through can easily look inside.
And if you open the envelope and change the contents, there is no evidence of the change.
And, while there are words on the envelope and inside it, those words are not like handwritten words, or even like typewritten words. There is no evidence of who put those words there when.
If it says it's from your Aunt Sharon, it's hard to tell whether it really is unless you call her up and ask her.
You can recognize her voice on the phone. If you got a physical letter from her, you probably know what her handwriting looks like. You can sort of tell a little by the words and expressions used, but there are far fewer clues about identity in e-mail.
There is some external evidence in the form of records on servers, but that is pretty weak evidence, and not visible to the ordinary user.
If your mail service provider encrypts their storage, the envelope and the contents become opaque, but only as long as the message is stored. Once the message is transmitted, it is visible to anyone and everyone who bothers to look during transit.
There is also the problem of volume. e-mail is much easier and cheaper to generate in excessive volume than ordinary junk mail.
End user encryption can mitigate some of these disadvantages to a certain degree, but there are no current common ways to use encryption.
When Microsoft incorporated e-mail into MSWindows95's internet application suite, they were making technology for the technically inclined to people who are not interested in technical details. They put an easy user interface on it and allowed ordinary users to do themselves damage with the tech.
They have several times offered to half-fix the technology, but their offerings are woefully inadequate and invariably make critical use of technical measures that Microsoft can control through patents and other means. Their solutions are always going to cement their effective monopoly position, if we allow them to have their way.
AT&T is culpable for putting a bad database interface on the web for all their iPhone customers. Microsoft is culpable for selling us technology that is not really appropriate for ordinary users in ordinary use.
We are culpable for continuing to use it.
I have some ideas about ways to mitigate the problems with e-mail, but it's a lot easier for me to just dream about re-booting the computer industry with good basic technology. So I waste my time dreaming instead of contributing to the solution. Mea culpa.
Someday.
Someday.
Subscribe to:
Posts (Atom)