Stuxnet, Flame and security

First of all, I’d like to thank all my readers, I’ve had over 10,000 views in my first year of blogging. That’s amazing and is so many more views than I expected to ever have. Thank you for making it well worth my time to blog!

Recently a friend of my asked me to comment about the latest cyber attack, Flame, uncovered by Kaspersky, a Russian security firm. It’s still not entirely certain who unleashed the attack, but at the time I argued that it could have been Israel acting alone as they have a very capable tech sector. They put out high quality software, they have security experts and they have some serious R&D from US companies like MS and Intel.

Flame targeted Iranian computer systems, very much like Stuxnet did. At the time, it was unclear who released Stuxnet, which attacked Iranian centrifuges. It could have very easily been Israel acting alone or with some help from the US. Being a realist I fully expected the US to be involved, however I did not expect Obama to have issued the order himself. Based on history it is equally likely that Flame was initiated by the US as well.

Flame targeted data being sent over the internet such as PDF, Office and AutoCAD data and did not actively attack anything like Stuxnet did, according to Kaspersky. However, this doesn’t mean that it’s not being used by a spy agency. It’s also interesting to note that the infected computers are all outside of the US, which indicates that it could very easily be a US spy agency as they are not usually allowed to spy on US citizens.

These two programs leave me with a great deal of concern, because “the Pentagon has concluded that computer sabotage coming from another country can constitute an act of war, a finding that for the first time opens the door for the U.S. to respond using traditional military force.” Does this mean that if Iran responded with military force that our own Pentagon would argue that they were justified? I don’t think they would, but essentially they already have.

Aside from the risks of war it also gives greater leverage for a regime like Iran’s to argue for a more suppressed internet. They can now without any worry claim that they are doing it for national security. They are doing it for that reason, their centrifuges have been attacked (Stuxnet) and their people are being spied on (Flame). In addition other repressive regimes will likely use Flame as justification as a crack down on the internet. There may also be repercussions for Microsoft as Flame exploited a weakness within their auto update.

This also raises other concerns about what other types of cyber programs Obama has given the OK to. As he is the most technically savvy president we’ve had since the rise of the Internet, I think he fully understands the choices he is making. With Bush it may have been argued that he didn’t really understand as well what he was approving as he doesn’t have an in depth knowledge of how people use the internet and how systems interact with technology. He also wouldn’t have a good understanding of how viruses like this could turn against their creators. In this case Obama should. He should know that once in the wild a worm can mutate in a way that could turn against the people that released it and that we could destroy ourselves.

I think that these actions will weaken our position in any negotiations with Iran and possibly other countries that we have pushed for a more open internet. They could, rightly perhaps, argue that we only want the internet open, so it’s easier for us to infiltrate.

I don’t believe that’s the reason. I believe that the internet is the an amazing tool that has improved people’s condition to at least some extent. It has allowed for freer flowing of knowledge, but it can be used for wrong just as easily as any other media or communication tool.

Facebook, IPO and valuing a company

This week we’ve been hearing about the debacle that was the Facebook IPO.Which has revealed that some of the underwriters for the IPO were doing shady things. Matt Taibbi believes that this indicates that there are essentially two markets. One for the insiders and one for the schumcks, the every day investors.

Why is this important? Well, based on the discussions I’ve read online, there’s a lot of concern of the validity of the whole IPO process, the valuation methods of companies and how investors think of companies. The valuation of Facebook had a great deal of discussion before the final IPO price of $38/share, this was partially driven by two articles that came out. In the first one it was mentioned that GM was pulling it’s account because “Facebook ads don’t work.” The other article of note relates that researchers found that 44% of Facebook users will NEVER click an ad. This research is important because some of the valuation is based on the conversion rates of ad views to ad clicks. On average Facebook was only able to earn around $4.34 per user. The valuation of $100 billion puts the life time earning potential per user at $100 (at 1 billion users). This is pretty low, but at the same time, if only 560 million users ever click ad, that pushes means the people that do click ads need to be earning Facebook roughly $200.

MIT Technology Review discusses how this is an unsustainable growth model for Facebook. Essentially, Facebook will begin to drive down the cost per view for their advertisers to try to increase their total revenue. This falls into the race to the bottom mentality that crushes industries. Advertisers will be able to say to any website, why should we pay you x amount per ad when we only pay Facebook y there is no way that you can get me more views than Facebook. The only way that a site could get more revenue if they can show data for a higher click through and conversion rates than Facebook. That might be tough. The Review article argues that this will eventually kill Facebook and a lot of the ad driven website business models.

The other aspect of the IPO is a difference in the way that business and technology media are reporting on Facebook. Things have shifted from all the non-business related activities to focusing solely on this aspect of Facebook. This will likely shift over time, but I believe that these considerations will be discussed in any article related to Facebook. If Facebook wants to remain a haven for activists it will be difficult if there are potential suits over people being activists. There will be an increase of risk aversion within the “owners” of the company as there will be influence from investors.

Zuckerberg has said that he plans on doing what is best for the long term and try to ignore the demands of investors. He might be able to do that because he still owns 57% of the voting rights for the company. However, it will be difficult for him to avoid the influence of the discourse of media outlets. Even if he gets all his news from his friends on Facebook, there will likely be articles posted that will give him news about the company and things that he probably won’t want to read.

Essentially, discussions will shift from being about the risk of privacy for users to how changes to Facebook will impact investors bottom line. I don’t think this is healthy for businesses, consumers of Facebook or the general public. There are other things companies do that are unrelated to investors that are important for society as a whole. The Facebook coverage really indicates that we don’t look at businesses in a long term sustainable manner. We need to change this if we want to save capitalism.

Religion, Morality and political stances

This morning on KUT (local NPR station) there was a local interview between the KUT host and an author of a book that discussed how religion has been playing a larger role in the public forum in the United States and that people are basing their political stances more and more on religion. I am skeptical of this for several reasons. First, the morality these stances are based on are sometimes dubious at best even within the religious context. Secondly, some of these moral stances aren’t actually based on teachings in the specific religion, but are much more cultural in origin than religious.

Let’s look at the first issue. There are many issues that we can examine to see if the validity of the moral stance. How about the death penalty. Many Christians (not all) strongly support the death penalty. This stance clearly violates one of the Ten Commandments (thou shall not kill). Supporting this type of policy is not congruent with this belief. In addition, it conflicts with the belief that all life is sacred, which is the argument against abortion. I personally don’t agree with either stand, I’m against the death penalty and pro-choice (by which I mean I support the woman’s right to choose if she wants to be pregnant or not).

I arrived at these moral stances outside of the Christian frame work. I find that life is sacred since we only have one. Ending a person’s life for whatever reason is a horrible thing. It destroys everything that they are and could be, it destroys their potential. Now some people may think that this is ok in the case of people that are beyond help, but who defines “help”? Or perhaps it’s ok to kill people that are more committing horrible crimes against other people and they can never be reformed. Well, first there’s a lot of things we need to look at as to the why they were doing what they were doing. We should investigate what changes we can do and what sort of environment we want them to be living in after the we’ve given up on them.

In terms of abortion, it’s a trickier matter than the death penalty. However, women should have control over their on bodies and when/if they ever want to have children. Sure killing a fetus is killing a possibility, but every time a person has sex there are thousands of possibilities that are destroyed by a condom or other birth control. It’s just a matter of time and why you chose to stop the pregnancy. In some case the baby can destroy the potential of the mother or could end up being a huge drain on society. These can cause larger issues than if the fetus was aborted when the woman wanted it to be aborted.

Issues of morality may not be easy, but there are also moral issues that happen to conform to a specific outlook on life. In the case of gay marriage, this is more of a cultural issue than a religious issue. The very book that proponents quote as the reason for denying this right is ignored on a routine basis (eating shellfish is a killable offense). Marriage has long been something sanctioned by the state and has a level of cultural normalcy that has moved it from the realm of religion alone. In some states it’s possible to be married through time spent living together and getting it approved by a Justice of the Peace. Marriage is a way that cements a relationship in your own mind, the mind of your community and with the state. A civil union doesn’t have the feeling of importance and smacks of differences in rights and demotes a person to a second class citizen.

There are definitely some policy stances that could easily be seen to be rooted in religious beliefs such as supporting welfare, turning the other cheek, being a pacifist and giving your money to the poor and needy. However, there are many people that are against abortion and against welfare. These wildly different stances  for a Christian smacks of a cultural belief structure driving many of these policy stances rather than their religious beliefs themselves. This doesn’t mean you aren’t a Christian or that have to be against abortion and for welfare, but it means you should be honest about the source of your morality in regard to your policy stances. You need to look inward and really investigate why you stand for something and why you’re against something. Look close enough and you may find that it’s due to your social and cultural influences rather than your religious beliefs.

Is Scientism the problem?

I just finished reading an article in The New Republic which argues that history and the humanities are knowledge too. At times it felt like the author was yelling at his brother begging to be noticed. Personally, I feel that in general the author is correct, that history and humanities do plan an important role and can be considered as knowledge. However, the author makes one glaring mistake, he is equating the unified theories of everything in physics with everything, where it typically means a combination of all physical laws within physics both particle and cosmic, which would then move into chemistry and likely into biology. However, this type of theory of everything would stop there. It couldn’t really combine natural selection as functions of chemicals in a specific manager do not necessarily mean a truer understanding of evolution. It would be able to explain how phenotypes are changed with genotypes, but not why one genotype/phenotype pair was selected over another without an understanding of the specifics of the environments at a time. A true theory of everything at that level would essentially be a simulation of the universe. It would be impossible to model in a series of equations beyond the fundamental laws of physics.

For the evolution of biological systems you have to understand the natural history of the world that the organisms develop and evolve. This is why when you read Sagan, Dawkins or any other biologists or cosmologist they argue that if you rewound the tape of history you’d get a different present day. Some things may have happened just slightly different enough and you’d have no humans. The understanding of the history of our world allows us to understand where the future of it is going.

In the same way, history does matter. There are branches of economics, such as evolutionary economics that use complexity models and work to ensure that the history of events are included in their models. What the major difference between typical theories of history and psychology and newer models of economics and complex systems of physics, is that we’re able to test them using simulations. It is likely that in the future we’ll be able to do the same thing with history. This will give us a deeper understanding of why our societies have developed as they have. One heavily contested aspect of evolution, which is mentioned in the article, is cultural inheritance, which is where the theory of memes came from. This approach doesn’t suggest one type of people is better than another or one lifestyle is better than another, it simply says that in the environment that the culture resides it’s more capable of surviving than others. This can go down deeper to smaller niches within the culture and how well they adapt to their environment.

Other aspects the author argues discusses is the differences in the acceptability (or perhaps the perception) of radical paradigm shifts in science compared to the humanities and history. He mentioned specifically Freud in psychology and Galileo in physics. He argues that Galileo was able to make changes in physics because he tackled an “easy” problem that had minimal level of complexity. He went after the theory of gravity and how objects fall at the same rate while Freud went after the entirety of the human psyche. I agree there is a difference of complexity, however the key differences between Galileo and Freud is that he was better able to explain the state of the world and when new scientific theories were produced they continued to explain what Galileo found but with more accuracy and expanded on them. When Freud was discredited it was more like discrediting Alchemy than going from Newtonian physics to Relativistic physics.

The key difference between many theories in humanities and in the rest of science is the lack of continuum between two major theories. Yes, Relativistic physics completely obliterated the value of Newtonian physics and created a new world (universe) view, but it solved the same problems or proved that many of the old problems were only problems because the theory wasn’t complete enough.

The key that needs to be remembered in either science or humanities is that all models are wrong, but some are useful. Freud was wrong in how he looked at the human psyche, but his models allowed other theories to be tested and used and likely spawned Neuroscience and the bridging between neuroscience and many of psychological problems.

A bit remiss

Sorry dear readrs, I’ve been very bad about writing any blogs lately. I’ve had some pretty big changes in the past two months as you all know. I’ve moved back from the Netherlands to the US, did some consulting work and I just started a job at AMD. Consequently, I’ve not been able to post as much as I have in the past. Big changes have been happening in my life.

Because of these changes I wasn’t able to pay enough attention to the CISPA fiasco that just occurred in the US. This law is a terrible step in the direction of data tyranny. I’m even being hyperbolic about this either. I wrote about the risks of having a voluntary data sharing program and in my review of Consent of the Networked I discussed the different data and Government regimes out in the “wild.” These concerns are valid. We need to be aware of what’s going on. Now, I have to say we pretty much blew our collective internet protest load with the SOPA/PIPA protests. Which is actually a problem. I would hazard that in many ways CISPA is as bad or worse than SOPA, however I didn’t see as much chatter about CISPA on reddit, twitter, Google+ or Facebook about CISPA as I did about SOPA.

I think there are a few reasons for this actually. First, the majority of the people were able to clearly understand the risks associated with SOPA. These risks are pretty straight forward and understandable. These risks affect us tomorrow not in some future time period. In many ways SOPA like acts can already happen today. This makes it extremely obvious why SOPA/PIPA are terrible laws and should be opposed at many levels. Second, with CISPA coming so quickly after the SOPA/PIPA protests there was likely something of a protest overload or disbelief that another law could come through so quickly that is as bad or worse than SOPA. Especially with the language that was being used at the time of SOPA. It would have broken the Internet, how could anything be worse than that? Third, there was more support by large companies for this law than for SOPA. Apparently that actually matters more than we realized. We were able to push Wikipedia, Facebook, and other large companies to protest this law. However in this case Facebook and Microsoft supported the law while Google sat on the sideline saying nothing about the law.

I think from this stand point, people that weren’t happy with CISPA but didn’t understand the importance likely didn’t do anything about it. However, whenever a fantastic website like Wikipedia blacks out in protest for a law it will get people who are only on the fence about the law to actually do something about the law.

CISPA and SOPA are both bad but in very different ways. CISPA is something of an abstraction of risk. Losing your privacy when so many people already voluntarily give up so much information about themselves on Facebook and Twitter might not seem like as big of a deal. The secondary abstraction is a lack of understanding of the impact of the data sharing. It’s unclear of what exactly the Feds would do with the data once they have it. It’s unclear how data sharing would occur within the government. However, it is likely that the data would be shared throughout the government including the military. Which many privacy experts are say essentially legalizes military spying on US civilians. The third problem is that many people also feel that if you aren’t doing something wrong you don’t have anything to worry about. However, this is a fallacy as even people who are doing things that aren’t wrong can get in trouble. I’ve discussed the cases where people are fired for posting drunken pictures on Facebook. Additionally, this type of law represents the biggest of the big government that we can imagine. There’s no reason why the government needs to know what we’re doing in this level of detail.

It’s going to be a long and difficult fight to keep our internet free. However, it’s something that we must do and I believe we can do it. We will just need to keep vigilant and work together to ensure that our internet stays our internet.