<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The Future of the Internet -- And How to Stop It</title>
	<atom:link href="http://futureoftheinternet.org/feed" rel="self" type="application/rss+xml" />
	<link>http://futureoftheinternet.org</link>
	<description>Jonathan Zittrain is Professor of Law at Harvard Law School and co-founder of the Berkman Center for Internet and Society at Harvard Law School</description>
	<lastBuildDate>Thu, 29 Jul 2010 01:19:47 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Facebook&#8217;s ocean of names becomes a torrent</title>
		<link>http://futureoftheinternet.org/facebooks-ocean-of-names-becomes-a-torrent</link>
		<comments>http://futureoftheinternet.org/facebooks-ocean-of-names-becomes-a-torrent#comments</comments>
		<pubDate>Thu, 29 Jul 2010 01:02:07 +0000</pubDate>
		<dc:creator>jz</dc:creator>
				<category><![CDATA[Future of the Internet]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[privacy]]></category>

		<guid isPermaLink="false">http://futureoftheinternet.org/?p=1524</guid>
		<description><![CDATA[Nick Bilton over at the NYT Bits Blog has the story of Internet security consultant Ronald Bowes&#8217;s recent Facebook caper.  Ron noticed that Facebook has a directory of its users, just like the old Bell Telephone White Pages.  I agree with Ron&#8217;s assessment that this is a very little-noticed feature: normally one searches on Facebook [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://bits.blogs.nytimes.com/author/nick-bilton/">Nick Bilton</a> over at the NYT Bits Blog <a href="http://bits.blogs.nytimes.com/2010/07/28/100-million-facebook-ids-compiled-online/?utm_source=twitterfeed&amp;utm_medium=twitter">has the story</a> of Internet security consultant Ronald Bowes&#8217;s <a href="http://www.skullsecurity.org/blog/?p=887">recent Facebook caper</a>.  Ron noticed that Facebook has a directory of its users, just like the old Bell Telephone <a href="http://en.wikipedia.org/wiki/Telephone_directory">White Pages</a>.  I agree with Ron&#8217;s assessment that this is a very little-noticed feature: normally one searches on Facebook not by looking at a directory, but rather by typing a name into a search box.  It&#8217;s in plain sight, though, at <a href="http://www.facebook.com/directory">http://www.facebook.com/directory</a>:</p>
<p><a href="http://futureoftheinternet.org/wp-content/uploads/2010/07/fb-directory.jpg"><img class="alignnone size-medium wp-image-1525" title="facebook directory" src="http://futureoftheinternet.org/wp-content/uploads/2010/07/fb-directory-300x182.jpg" alt="" width="300" height="182" /></a></p>
<p>There are two differences that jump out between this awe-inspiring alphabetical listing of all Facebook users and a dog-eared telephone directory.  First, Facebook&#8217;s directory has a staggering <em>171 million</em> names in it.  Second, in good news for paper prices everywhere given the first difference, the directory is digital &#8212; it&#8217;s right there, online.  And if it&#8217;s online, it&#8217;s scrapable.  Ron, being of the inquisitive engineering sort who can&#8217;t help but push a button if he sees one, figured that supply creates demand, and went ahead and scraped the directory.</p>
<p>That means he produced a file on his own hard drive containing more or less the directory&#8217;s main contents: for each person listed, a name, the person&#8217;s Facebook URL (what one types in to go directly to his or her entry), and unique Facebook ID (not a secret; this is part of a person&#8217;s Facebook url).  The resulting file is only a few gigs &#8212; amazing how cheap storage has become that so much can be roughly the side of an episode of House.  Ron then placed it online as a torrent &#8212; which means anyone can download the file, and voila, a snapshot of Facebook&#8217;s membership as of July 2010.</p>
<p>So, is this a problem?  As I&#8217;m writing, news is only just breaking, so it&#8217;s like that moment when a toddler trips, falls, and then has to think about whether to cry or not.  &#8220;<em>You&#8217;re OK!</em>&#8221; is usually what the alert parent encouragingly says &#8212; and if the toddler buys it, it&#8217;s usually true.  In fact, even if the toddler doesn&#8217;t buy it, it&#8217;s still usually true.  In this case, I think I&#8217;m with the metaphorical parent.  The data that Ron grabbed is precisely what Facebook users have chosen (or perhaps more accurately, passively acquiesced) to share.  For those who lock their privacy settings to avoid having a public listing in a Facebook search, they&#8217;re not present here.  For those who have, they are &#8212; along with a click through to their respective Facebook pages however they&#8217;ve chosen to share them.</p>
<p>Ron appears a little disquieted by it because of the prospect that the snapshot can live forever more.  If you remove your Facebook account or up your privacy settings, that will be reflected in real time in the Facebook directory and search (or at least it should be!).  But the torrent file exists forever &#8212; so one&#8217;s privacy choices are locked into that moment.  This is an artifact of having a service &#8212; Facebook &#8212; converted into a product &#8212; a Facebook database &#8212; the way that universities used to not just maintain online directories, but also publish bound volumes of their alumni with addresses, for those who opted in.  (In fact, many universities <a href="http://alumni.harvard.edu/haa/alumnidirectory">still do this</a>; someone should tell them about saving the trees.)</p>
<p>There&#8217;s some privacy hit there, but there are also benefits.  By making a public directory &#8212; and a scrapable one, no less &#8212; Facebook gets more inbound links and attention as its members become easier to find.  And we benefit by having Facebook&#8217;s subscribers&#8217; public pages indexed by the likes of Google and Yahoo! search.  In fact, when searching on a person&#8217;s name in a regular search engine, quite commonly a Facebook entry is one of the top hits.  That seems to me a good thing, and once Google, Yahoo!, and Bing have it, why shouldn&#8217;t Ron and anyone else who wants it have it too?  Indeed, Ron already did some cool stuff with the data.  For example, he crunched it all and came up with a list of Facebook&#8217;s most commonly used <a href="http://www.skullsecurity.org/blogdata/facebook-firstnames-withcount.txt.bz2">first</a> and <a href="http://www.skullsecurity.org/blogdata/facebook-lastnames-withcount.txt.bz2">last</a> names, discovering &#8220;Michael&#8221; and &#8220;Smith&#8221; coming in at number 1 for each.  Congratulations, Michael Smith, you are hidden in plain sight, since a search for you turns up so many others at the same time!  (Not so much with &#8220;Jonathan Zittrain&#8221;&#8230;)</p>
<p>Anyway, that&#8217;s generativity at work: Facebook makes available a directory on free and open terms, and people do stuff with it, some of which can surprise us.  There could be bad surprises, too &#8212; Ron and others hint at undesirable data mining &#8212; but I&#8217;m glad that the gates of Facebook&#8217;s gated community have some slats in them, rather than being a solid wall.  At most, it seems to highlight the desirability of getting the defaults right: Facebook shouldn&#8217;t have people automatically publicly sharing stuff they&#8217;d not normally share, without clear markers on what&#8217;s about to happen.  As <a href="http://toolbar.google.com/prdlg.html">Google would say</a>, &#8220;Please read this carefully.   It&#8217;s not the usual yada yada.&#8221;</p>
<p>Indeed.  There have been so many Facebook privacy mini-scandals that we&#8217;re primed for the next, and the involvement of a torrent file adds an element of seeming subversiveness to the mix, given the association of p2p with contraband material.  But sometimes when the boy cries wolf it&#8217;s just a shadow.  I count 8 Yadas in the Facebook directory.  And I, along with my <a href="http://www.jeffzittrain.com">cool musician</a> brother <a href="http://en-us.facebook.com/people/Jeff-Zittrain/613281979">Jeff Zittrain</a>, fall in between <a href="http://en-us.facebook.com/people/Aron-Zittra/687235077">Aron Zittra</a> and <a href="http://en-us.facebook.com/people/Austin-Zittrauer/726749501">Austin Zittrauer</a>.  Until now, who knew?  Interesting &#8212; but not pitchfork worthy.  &#8230;JZ</p>
]]></content:encoded>
			<wfw:commentRss>http://futureoftheinternet.org/facebooks-ocean-of-names-becomes-a-torrent/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Android kill switch activated &amp; some links of the week</title>
		<link>http://futureoftheinternet.org/android-kill-switch-activated-some-links-of-the-week</link>
		<comments>http://futureoftheinternet.org/android-kill-switch-activated-some-links-of-the-week#comments</comments>
		<pubDate>Mon, 26 Jul 2010 14:01:28 +0000</pubDate>
		<dc:creator>elisabeth</dc:creator>
				<category><![CDATA[Future of the Internet]]></category>

		<guid isPermaLink="false">http://futureoftheinternet.org/?p=1481</guid>
		<description><![CDATA[Control over tethered appliances basically comes in two forms: pre-approval of apps and kill switches. As this blog has documented, Apple has had a very heavy hand in screening apps, but &#8212; as far as we know &#8212; they haven&#8217;t ever used the iPhone kill switch. I was a little surprised to find that out, [...]]]></description>
			<content:encoded><![CDATA[<p>Control over tethered appliances basically comes in two forms:  pre-approval of apps and kill switches.  As this blog has documented, Apple has had a very heavy hand in screening apps, but &#8212; as far as we know &#8212; <a href="http://www.wired.com/gadgetlab/2010/06/google-flips-remote-kill-switch-on-android-apps/">they haven&#8217;t ever used the iPhone kill switch</a>.  I was a little surprised to find that out, and I wonder why they haven&#8217;t used it.  Maybe the screening process is keeping out malicious apps, and they&#8217;re content to let users keep apps that are merely in bad taste (although they remove them from the app store).  Maybe the bad publicity from past kill switch uses &#8212; see <a href="http://futureoftheinternet.org/orwellian-indeed">Amazon and 1984</a> &#8212; has stayed their hand.  Or maybe they have removed apps and it just hasn&#8217;t been publicized.</p>
<p>Google has taken a different tack with Android:  they&#8217;ve largely surrendered the power to pre-approve apps, because Android users can always download apps from third-party sources.  But they too have a kill switch, and according to the Android developers&#8217; blog post, they <a href="http://android-developers.blogspot.com/2010/06/exercising-our-remote-application.html">decided to use it</a> a few weeks ago.  (It&#8217;s not totally clear from the blog post, but it sounds like they&#8217;ve also used it before on clearly malicious apps.)  An app that <a href="http://blogs.forbes.com/firewall/2010/06/25/google-flips-kill-switch-deletes-and-downplays-botnet-demo-android-apps/">claimed to offer Twilight photos turned out to be a demonstration</a>, done by researchers, of how easy it would be to create an app that would turn phones into a botnet.  The app didn&#8217;t actually create the botnet (and it didn&#8217;t show Twilight photos, either, so most disappointed downloaders deleted it), and the researchers presented their work at the conference.  Nonetheless, after they heard about it, the Android team decided to remotely delete remaining copies of the app as part of a <a href="http://android-developers.blogspot.com/2010/06/exercising-our-remote-application.html">&#8220;cleanup&#8221;</a> process.  Affected users received notifications.</p>
<p>I can see why they wanted to do that.  A <a href="http://android-developers.blogspot.com/2010/06/exercising-our-remote-application.html">report documenting Android vulnerabilities</a> was recently released, and it&#8217;s caused <a href="http://www.readwriteweb.com/archives/google_activates_android_kill_switch_zaps_useless_apps.php?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+readwriteweb+%28ReadWriteWeb%29">some hand-wringing</a> over Android&#8217;s security.  There&#8217;s also no sense in leaving a loaded weapon laying around.  And I&#8217;m glad they told both customers and everyone else that they&#8217;d deleted the apps.  Still, I do worry about the removal of an app that isn&#8217;t actually harming any machines.  More generally, I think that if Android is going to stick to the plan to not pre-screen apps and have an open system, they and we are going to have to think seriously &#8212; more seriously than Apple has had to &#8212; about the ethics of the kill switch.  Questions like whether there should there ever be an opt-out, whether users should get refunds, and whether it should be used in cases other than damaging viruses are all still wide open.</p>
<p>And a few quick links:</p>
<p><a href="http://tech.slashdot.org/story/10/06/28/1923221/Leaked-MS-Presentation-Shows-App-Store-Plans-For-Windows-8?from=rss&amp;utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29"> Leaked MS Presentation Shows App Store Plans For Windows 8.</a> Why all this thinking about app stores and kill switches matters:  there are already plans to transfer the app store model from phones to PCs, where the arguments about the virtues and harms of contingent generativity have even more salience.</p>
<p><a href="http://nanocr.eu/2010/06/27/googles-mismanagement-of-the-android-market/">Google’s mismanagement of the Android Market.</a> Jon Lech Johansen thinks the lack of pre-screening is hurting Google and Android.</p>
<p><a href="http://www.phonenews.com/did-apple-flip-the-ios-kill-switch-on-ndrive-11579/">Did Apple Flip the iOS Kill Switch on NDrive?</a> Wait, has Apple already used the kill switch?</p>
<p><a href="http://www.zdnet.com.au/new-zombie-code-in-effect-by-december-339303681.htm">New zombie code in effect by December.</a> Here&#8217;s a totally different option for improving security: let users keep open PCs, but if they become infected, have their ISPs quarantine them or reduce their internet speed to a crawl.  That way, users will have to get their computers fixed and can&#8217;t keep infecting others.  Internet Industry Association CEO Peter Coroneos said of the plan:  &#8220;I&#8217;m sure there are people around that resent having to put new tyres on their car when they&#8217;re unroadworthy, or have their breaks done . . . But the reality is that we have argued that internet users have a responsibility not only to themselves, but also to other users on the internet.&#8221;  The code will be made available to Australian ISPs soon.</p>
<p><a href="http://www.facebook.com/pages/One-Brown-Package-From-Seattle-to-Norway/141564892520845?v=info">One Brown Package: From Seattle to Norway.</a> Why we love the internet in the first place: unexpected avenues for fun, creativity and kindness (here, in the form of people working to get a package from Seattle to Norway).  They claim inspiration from <a href="http://www.ted.com/talks/jonathan_zittrain_the_web_is_a_random_act_of_kindness.html">JZ&#8217;s TED talk</a> on the web on random acts of kindness.  The package is currently reported as missing.</p>
<p>&#8212;By Elisabeth Oppenheimer</p>
]]></content:encoded>
			<wfw:commentRss>http://futureoftheinternet.org/android-kill-switch-activated-some-links-of-the-week/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>FOI Topics and Links of the Week</title>
		<link>http://futureoftheinternet.org/foi-topics-and-links-of-the-week-10</link>
		<comments>http://futureoftheinternet.org/foi-topics-and-links-of-the-week-10#comments</comments>
		<pubDate>Mon, 28 Jun 2010 17:21:27 +0000</pubDate>
		<dc:creator>Jennifer</dc:creator>
				<category><![CDATA[Future of the Internet]]></category>
		<category><![CDATA[news]]></category>

		<guid isPermaLink="false">http://futureoftheinternet.org/?p=1460</guid>
		<description><![CDATA[iPad security breach. Even closed systems can be vulnerable to exploitation.  A group of high-profile iPad owners, including President Obama&#8217;s Chief of Staff among 114,000 others, had their email addresses exposed by a web security group.  Although it was AT&#38;T&#8217;s network that was compromised, Apple is shouldering much of the blame, since it denies iPad [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://gawker.com/5559346/apples-worst-security-breach-114000-ipad-owners-exposed">iPad security breach.</a> Even closed systems can be vulnerable to exploitation.  A group of high-profile iPad owners, including President Obama&#8217;s Chief of Staff among 114,000 others, had their email addresses exposed by a web security group.  Although it was AT&amp;T&#8217;s network that was compromised, Apple is shouldering much of the blame, since it denies iPad customers a choice of carriers and also requires an email address to activate the device.  AT&amp;T patched the security hole, but not until after the script used to exploit it was shared with third parties.  The FBI is investigating.</p>
<p><a href="http://volokh.com/2010/06/11/the-future-of-privacy-facial-recognition-public-facts-and-300-million-little-brothers/">Facial recognition and next generation privacy.</a> David Thompson gives an update on the progress of facial recognition software and its implications for <a href="http://yupnet.org/zittrain/archives/20#46">privacy 2.0</a>.  In addition to describing the revolution in surveillance capabilities that occurs when a person can be identified on any security camera feed or in any of the more than three billion photos on Flickr, he notes that Face.com <a href="http://techcrunch.com/2010/05/03/7-billion-scanned-photos-later-face-com-opens-up-to-developers/">released an API</a> last month, allowing developers free access to its facial recognition technology and the green light to adapt it for new uses.  Here&#8217;s hoping the appropriate <a href="http://yupnet.org/zittrain/archives/20#80">norms</a> evolve in tandem.</p>
<p><a href="http://techdirt.com/articles/20100604/1307039696.shtml">Defamation liability: please fwd.</a> A bankruptcy court in Texas has ruled that forwarding an email link can be considered defamation.  The defendant in the case didn&#8217;t send a copy of the actual content, just a link to a website.  Neither had he written any of the defamatory content on the website.  It&#8217;s unlikely that the ruling will survive an appeal, since forwarding a link probably doesn&#8217;t amount to the required element of &#8220;publication&#8221; under a traditional interpretation of defamation law.  Still, it&#8217;s something to think about the next time there&#8217;s a link to a juicy tabloid story in your inbox.</p>
<p><a href="http://apple.slashdot.org/story/10/06/01/1937204/Apple-Blindsides-More-AppStore-Developers?from=rss&amp;utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29">Shifting foundations of the App Store.</a> Apple continues to indulge its discretion when it comes to approving iOS apps.  This time it pulled an app for being &#8220;widget-like,&#8221; despite approving three previous versions.  The frustrated developer asks &#8220;<em>How can a company be prepared to invest into a platform that can  change at any time<em>?</em>&#8220;</em></p>
<p><a href="http://www.thebigmoney.com/blogs/app-economy/2010/06/11/it-gets-worse-apple-censored-oscar-wilde-comic-featuring-two-men-kissin">It Gets Worse: Apple Censors a Gay Kiss in Oscar Wilde Comic.</a> In another Apple censorship story, the company appeared to block out a kiss in a comic book because two men were doing the kissing.  To be fair, it&#8217;s not entirely clear to me from the pictures in the article whether the same-sex kiss was the cause of the blackout, but the author claims that similar opposite-sex scenes have gone unchanged in other comic books.  As he says, &#8220;the more examples I see of Apple&#8217;s capricious censoring, the less funny it is.&#8221;</p>
<p><a href="http://news.cnet.com/8301-13860_3-20006526-56.html?tag=newsLeadStoriesArea.1">Steve Jobs at D8: Post-PC era is nigh.</a> In the introduction of the book, JZ <a href="http://yupnet.org/zittrain/archives/6">predicted</a> that Steve Jobs, having launched the PC era, was about to usher it out.  Now, Jobs <a href="http://news.cnet.com/8301-13860_3-20006526-56.html?tag=newsLeadStoriesArea.1">says the same thing</a>.  According to him, &#8220;PCs are going to be like trucks &#8230; they are still going to be around,&#8221; but &#8220;one out of x people will need them.&#8221;</p>
<p><a href="http://techdirt.com/articles/20100608/1521449744.shtml">TiVo&#8217;s &#8216;Big Win&#8217; Over Dish On Patents Looking Less And Less Solid, As Patent Office Rejects Patent Claims.</a> Update in <a href="http://futureoftheinternet.org/the-end-draws-nearer-for-echostar-dvrs">the TiVo-EchoStar battle</a>: we may never find out if EchoStar will actually have to remotely kill already-purchased DVRs, because the Federal Circuit is rehearing the original patent claims en banc.</p>
<p>&#8212;By Jennifer Halbleib and Elisabeth Oppenheimer</p>
]]></content:encoded>
			<wfw:commentRss>http://futureoftheinternet.org/foi-topics-and-links-of-the-week-10/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>The Internet’s Fort Knox Problem</title>
		<link>http://futureoftheinternet.org/fort-knox-problem</link>
		<comments>http://futureoftheinternet.org/fort-knox-problem#comments</comments>
		<pubDate>Thu, 03 Jun 2010 19:52:12 +0000</pubDate>
		<dc:creator>jz</dc:creator>
				<category><![CDATA[Future of the Internet]]></category>

		<guid isPermaLink="false">http://futureoftheinternet.org/?p=1456</guid>
		<description><![CDATA[A few weeks ago Internet security firm McAfee released an update to its Windows PC customers designed to protect them against a newly detected virus threat.  Instead, for some, the update destroyed a legitimate, and crucial, system file.  Uncountable numbers of PCs – likely hundreds of thousands, even millions – were rendered unusable.  The University [...]]]></description>
			<content:encoded><![CDATA[<p>A few weeks ago Internet security firm McAfee released an update to its Windows PC customers designed to protect them against a newly detected virus threat.  Instead, for some, the update destroyed a legitimate, and crucial, system file.  Uncountable numbers of PCs – likely hundreds of thousands, even millions – were rendered unusable.  The University of Michigan medical school lost the use of 8,000 of 25,000 PCs.  State troopers in Kentucky abandoned their cruisers’ mobile PCs and resorted to writing reports by hand.  Some hospitals in Rhode Island turned away non-trauma patients from their ERs.</p>
<p>The issue is larger than one firm&#8217;s unfortunate misstep.  It echoes across the entire Internet.  Call it the Fort Knox problem.</p>
<p>Fort Knox represents the ideal of security through centralization: gunships, tanks, and 30,000 soldiers surround a vault containing over $700 billion in American government gold.  It’s not a crazy idea for a nation’s bullion; after all, the sole goal is to convincingly hoard it.  But Fort Knox is an awful model for Internet security.</p>
<p>Our IT environment has traditionally been immune from many Fort Knox issues, because its architecture has encouraged decentralization.  One PC might be compromised, or Web site might fall, but others stand.  Bad guys on one side of the spectrum, and well-intentioned regulators on the other, each had to sweat to have an impact on Internet activities.</p>
<p>But the bad guys were clever and industrious.  Their digital robots came to costlessly crawl the Web looking for computers and sites to compromise, leveraging their reach.  Operators of well-financed Web sites have dealt with rising anxieties about security by spending enormous amounts of money on digital bunkers and backups for their data, while littler ones have hunkered down and simply hoped they wouldn’t be hit.</p>
<p>The public sector has been confused about how to help.  Governments know how to maintain and defend their roads and waterways, but have been stymied in cyberspace: so much of it is rightly privatized that there’s no obvious place to station a guard and no way to fill a digital pothole.  Worse, since identifying those behind intentional attacks online is exquisitely difficult, the traditional state tools of deterrence and punishment are ineffective.</p>
<p>That’s why we now see centralization under a few major corporate umbrellas under which disparate activities can be gathered.  The lures of security, interoperability and economies of scale have propelled much of the Web from a vibrant ecosystem of different, and differently managed, PCs and sites to one where a handful of private Fort Knoxes take responsibility for security.</p>
<p>But we can’t simply put our precious data into a single well-protected vault and peek in every few years.  We need to guard our PCs and data, but we also need them to be part of a worldwide network.  When we’re not masking our digital trail, we’re eagerly sharing it.  If we try to centralize its protection, it’s not a one-time transaction: rather, we need a constant gatekeeper who signs our data in and out every time we want to make use of it.  That’s a thread that runs from the McAfee debacle, where millions of people and firms turned the keys to their computers over to a third party to handle, through to cloud-based platforms like Facebook, where the company’s assent is increasingly needed to run unrelated applications on its platform or to log in to unaffiliated Web sites that no longer care to maintain their own digital borders.</p>
<p>If McAfee makes a mistake, many people pay at once.  If Facebook’s computers go down or are compromised, thousands of otherwise-independent applications and sites suddenly go down with it.  It’s not just our own data and transactions at risk, but our collective memory: the flip side of a centralized defense against bad guys is vulnerability to well-meaning good guys.  For example, if the generally laudable Google Books project is a spectacular success, we’ll see libraries give up their moldering, isolated archives of regular books in exchange for PC terminals where patrons can peer at an ephemeral digital copy drawn from Google’s central archive.  It makes sense – and no doubt Google has near-impregnable backups – but it’s also an opportunity for a government to intervene in worrisome ways.</p>
<p>For example, if one book in the system contains copyright infringing, or defamatory, or obscene material, those aggrieved can get a court order requiring the infringing pages of the book to be deleted from the central server.  This vulnerability affects every book that is distributed and maintained through a centralized platform.  Anyone who does not own a physical copy of the book – and a means to search it to verify its integrity – will now lack access to that material.  By centralizing (and to be sure, making more efficient) the storage of content, we are building a world in which, as a practical matter, all copies of once-censored books like Candide, The Call of the Wild, and Ulysses could have been permanently destroyed at the time of the censoring, and could not be studied or enjoyed even after subsequent decision-makers lifted the ban.</p>
<p>So what do we do?  We have two things going for us that the real Fort Knox doesn’t: we can make copies of our digital gold, and there are lots of us, each with our own stake in security and autonomy.</p>
<p>First, so long as there aren’t undue barriers to extracting our own data from cloud platforms or our own PCs, backups can become more seamless, and made in a variety of ways, making a McAfee misstep or anything like it less costly.  Then we have our cake and eat it too.  The same principle applies to projects like Google Books, where participating libraries can arrange to securely maintain their own gold copies of Google’s precious trove – kept to compare against others’ copies, so omissions and changes can be detected and appropriately challenged, not leaving Google with the sole burden of holding off government speech regulation.</p>
<p>Second, we need to reinvigorate the Internet’s principle of open, distributed architecture that has sparked so much growth and innovation.  Our choices for security aren’t simply among government soldiers, corporate mercenaries, or our own personal barricades – though each has a valuable role to play.  Rather, we can reinforce open, shared early warning systems to enumerate and deal with security threats, whether against PCs, Web sites, or Internet connectivity.  With a few technical tweaks, we can all further help relay data from Web sites that are under attack, stabilizing their presence.  Security shouldn’t have to be purchased like a personal bodyguard.  Far more flexible than Fort Knox are people, each with their own pocketed gold and machinery, empowered to look out for one another.</p>
<p>A version of this appeared in the <a href="http://www.ft.com/cms/s/0/c6ca96bc-6e94-11df-ad16-00144feabdc0.html">Financial Times</a> on June 3rd, 2010.</p>
]]></content:encoded>
			<wfw:commentRss>http://futureoftheinternet.org/fort-knox-problem/feed</wfw:commentRss>
		<slash:comments>10</slash:comments>
		</item>
		<item>
		<title>FOI Topics and Links</title>
		<link>http://futureoftheinternet.org/foi-topics-and-links</link>
		<comments>http://futureoftheinternet.org/foi-topics-and-links#comments</comments>
		<pubDate>Tue, 01 Jun 2010 15:00:34 +0000</pubDate>
		<dc:creator>Jennifer</dc:creator>
				<category><![CDATA[Android]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[Future of the Internet]]></category>
		<category><![CDATA[Generativity]]></category>
		<category><![CDATA[censorship]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[iphone]]></category>
		<category><![CDATA[kindle]]></category>
		<category><![CDATA[news]]></category>

		<guid isPermaLink="false">http://futureoftheinternet.org/?p=1424</guid>
		<description><![CDATA[Google launches Government Requests tool. Google is now making public information on the requests it receives from government agents to remove content from its search results or reveal private user data. The Government Requests tool currently displays the number and type of requests by country for the last six months of 2009. In a bit [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://googlepublicpolicy.blogspot.com/2010/04/greater-transparency-around-government.html">Google  launches Government Requests tool.</a> Google is now making public  information on the requests it receives from government agents to remove  content from its search results or reveal private user data. The <a href="http://www.google.com/governmentrequests/">Government Requests</a> tool currently displays the number and type of requests by country for the last  six months of 2009. In a bit of irony, last week Google disclosed that  it had <a href="http://bits.blogs.nytimes.com/2010/05/14/google-admits-to-snooping-on-personal-data/?hp">accidentally  collected fragments of private user information</a> over unencrypted  Wi-Fi networks during drive-by data collection for Google Maps.</p>
<p><a href="http://www.techflash.com/seattle/2010/05/kindle_patches_and_privacy.html">Communicating with the e-book mothership.</a> If the latest must-read on Kindle is dotted with typos or has a few pages missing, there&#8217;s a good chance Amazon offers a patch to correct the error. It&#8217;s a handy Internet-enabled functionality, although one can imagine at the extreme authors continuing to update their work ad infinitum, making it impossible for a reader to say he or she has read an e-book since content is <a href="http://yupnet.org/zittrain/archives/14#26">always subject to change</a>. Information flows in the other direction on the Kindle superhighway too, as Amazon apparently <a href="http://kindle.amazon.com/popular_highlights">keeps track</a> of what readers are highlighting. There&#8217;s some creep factor in Amazon knowing what ideas Kindle readers think are important, even if the most highlighted passages are in works as deep as The Lost Symbol.  But the information is also so interesting.</p>
<p><a href="http://games.slashdot.org/story/10/04/22/1641225/Sony-Can-Update-PS3-Firmware-Without-Permission?from=rss">The  remote control.</a> In April, Sony quietly revised the End User License  Agreement that came with the latest PS3 firmware update to allow the  company to change how an owner&#8217;s console operates in whatever way it  wants, no notice or permission required. Now the FCC, at the request of  the MPAA, has given cable and satellite providers the <a href="http://www.google.com/hostednews/ap/article/ALeqM5hjnBaJyXbAZLgX4Rsp1yzEh7N06QD9FI9U500">right  to remotely disable</a> output connections on consumers&#8217; set-top  boxes, leading consumers to ask <a href="http://yupnet.org/zittrain/archives/19#5">&#8220;What did I buy?&#8221;</a></p>
<p><a href="http://arstechnica.com/gadgets/news/2010/05/curated-computing-whats-next-for-devices-in-a-post-ipad-world.ars">Curated  Computing</a> is the new name in town for the experience provided by  the tablet non-PC. This particular term is meant to accentuate the  &#8220;less choice, more relevance&#8221; aspects of that experience. It rolls off  the tongue more smoothly than <a href="http://yupnet.org/zittrain/archives/17#1">&#8220;contingently  generative&#8221;</a> and sounds less regressive than an <a href="http://yupnet.org/zittrain/archives/17#1">&#8220;appliance,&#8221;</a> but  it connotes somewhat life aboard the <a href="http://en.wikipedia.org/wiki/WALL-E#Plot"><em>Axiom</em></a>. However, its proponents suggest that curated computing devices are meant  to exist alongside and supplement traditional PCs. Let&#8217;s call that a  worthy goal and the best of both worlds.</p>
<p><a href="http://gawker.com/5539717/">iPhone pillow talk with Steve  Jobs.</a> A ValleyWag reporter last week exchanged late-night emails  with a defiant Steve Jobs on the iPhone&#8217;s ability to give people  &#8220;freedom from&#8221; data theft, battery hogs, and porn. The emails speak  for themselves, giving a little insight into Jobs&#8217; perspective on the  benefits and aims of the iPhone. He gets a little snarky at the end,  but then again it&#8217;s 2am when he&#8217;s responding, and he never has a chance  to clarify his comments, unlike the Gawker reporter.</p>
<p><a href="http://mobile.slashdot.org/story/10/05/10/195251/Android-Sales-Surpass-iPhone-OS-Sales?from=rss&amp;utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29">Android outsells iPhone.</a> During the first quarter of 2010, phones with the Android OS grabbed 28% of the U.S. market share, surpassing iPhone&#8217;s 21% (RIM&#8217;s Blackberry is still at the top with 36%).  Although Android benefited from Verizon&#8217;s buy-one-phone-get-one-free promotion and iPhone continues to lead <a href="http://techcrunch.com/2010/05/19/iphone-android-25-percent/">worldwide</a>, it appears Google is getting closer in Apple&#8217;s rearview mirror.</p>
<p><a href="http://andreyf.tumblr.com/post/538652366/info-roundup-mcafee-kills-computers-worldwide">McAfee prevents computers from booting up in new virus-protection strategy.</a> Centralizing security software in a few big providers concentrates expertise to solve problems, while also meaning that there are only a few&#8211;albeit strong&#8211;security systems the bad guys need to breach in order to wreak widespread havoc.  But in a previously under-appreciated risk, a flawed update of widely-used antivirus software can cut out the middleman and accomplish the same havoc directly.  A McAfee software update mistakenly identified a critical file as a virus and quarantined it, causing computers around the world, many of which automatically install updates, to repeatedly attempt to boot up.  One <a href="http://gist.github.com/raw/374154/9ab3cd7bef81fd3a8bc9398fd7051403eb72160f/gistfile1.txt">source</a> estimated that 800,000 PCs were affected.</p>
<p><a href="http://news.cnet.com/8301-17852_3-20003316-71.html">Taking [re-]generativity seriously.</a> A Connecticut mayor donated her kidney to a Facebook friend last month after seeing his desperate status update.  The patient&#8217;s doctor had suggested that he try publicizing his need through social media, using an online connection to a forge a real-world bond.</p>
]]></content:encoded>
			<wfw:commentRss>http://futureoftheinternet.org/foi-topics-and-links/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Unplugging for a bit</title>
		<link>http://futureoftheinternet.org/unplugging</link>
		<comments>http://futureoftheinternet.org/unplugging#comments</comments>
		<pubDate>Sun, 25 Apr 2010 16:14:23 +0000</pubDate>
		<dc:creator>jz</dc:creator>
				<category><![CDATA[Future of the Internet]]></category>

		<guid isPermaLink="false">http://futureoftheinternet.org/?p=1421</guid>
		<description><![CDATA[I&#8217;ll be offline until about May 10.  In the meantime, um, keep it generative!  &#8230;JZ]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ll be offline until about May 10.  In the meantime, um, keep it generative!  &#8230;JZ</p>
]]></content:encoded>
			<wfw:commentRss>http://futureoftheinternet.org/unplugging/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>FOI Topics and Links of the Week</title>
		<link>http://futureoftheinternet.org/foi-topics-and-links-of-the-week-9</link>
		<comments>http://futureoftheinternet.org/foi-topics-and-links-of-the-week-9#comments</comments>
		<pubDate>Mon, 19 Apr 2010 14:03:46 +0000</pubDate>
		<dc:creator>Jennifer</dc:creator>
				<category><![CDATA[Future of the Internet]]></category>

		<guid isPermaLink="false">http://futureoftheinternet.org/?p=1361</guid>
		<description><![CDATA[Government transparency through technology. U.S. federal government agencies published their open government plans online this week.  The plans detail long-term strategies for addressing one of the three identified principles of open government&#8212;transparency, civic participation, and government collaboration with public and private sectors.  They can be accessed by appending &#8220;/open&#8221; to the department website address.  The [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://techinsider.nextgov.com/2010/04/ogov_plans_social_media_regs_out.php?oref=latest_posts">Government transparency through technology.</a> U.S. federal government agencies published their open government plans online this week.  The plans detail long-term strategies for addressing one of the three identified principles of open government&#8212;transparency, civic participation, and government collaboration with public and private sectors.  They can be accessed by appending &#8220;/open&#8221; to the department website address.  The end goal of President Obama&#8217;s initiative is to obviate requests under the <a href="http://en.wikipedia.org/wiki/Freedom_of_Information_Act_%28United_States%29">Freedom of Information Act</a>.</p>
<p><a href="http://www.nytimes.com/2010/04/12/technology/12comments.html?sudsredirect=true">Online newspapers to modify anonymous comment policies.</a> Several major online news sites are considering or implementing changes in their approach to user comments.  There has been a trend toward requiring users to register, establishing ranking systems to identify trusted users, and highlighting the comments of those willing to use their real names, all in an attempt to hold commenters accountable for their statements and discourage vitriol.  Linking identity with posted opinions facilitates a reputation system to mitigate abuses of anonymity online (other examples of such strategies, and their risks, are <a href="http://yupnet.org/zittrain/archives/20#52">discussed in the book</a>).  Here it serves both to cement a user&#8217;s responsibly for his or her comments and maintain the status of a particular news site as a respected forum for discussion.</p>
<p>In the department of really freaky things:  <a href="http://80legs.com/"> 80legs.</a> 80legs pays developers to embed a bit of code in their programs to turn the user&#8217;s computer into a bot.  But unlike all the malicious code that does the same thing, this one purports allow 80legs to use the botnet for good (for their web-crawling services), and is theoretically disclosed to the users.  I&#8217;m skeptical&#8212;especially since, as <a href="http://lifehacker.com/5336382/digsby-joins-the-dark-side-uses-your-pc-to-make-money">one example indicates</a>, the &#8220;disclosure&#8221; may be a few lines buried way down in the TOS.  And who monitors whether 80legs is in fact doing good?</p>
<p><a href="http://andrewsullivan.theatlantic.com/the_daily_dish/2010/04/crowdsourced-art.html">Crowdsourced Art.</a> On the ubicomp front, <a href="https://www.mturk.com/mturk/welcome">Amazon Mechanical Turk</a> can be used to create cool works of mass art.  If you follow the link to <a href="http://www.aaronkoblin.com/work.html">artist Aaron Koblin&#8217;s website</a> (who also kindly guested in last winter&#8217;s Stanford/HLS cyberlaw class), the Sheep Market is my favorite (although there was <a href="http://radar.oreilly.com/2006/11/the-sheep-market-thesis.html">some debate</a> about it).</p>
<p><a href="http://www.niemanlab.org/2010/04/mark-fiore-can-win-a-pulitzer-prize-but-he-cant-get-his-iphone-cartoon-app-past-apples-satire-police">Mark Fiore can win a Pulitzer Prize, but he can’t get his iPhone cartoon app past Apple’s satire police.</a> Pulitzer-prize winning <em>political cartoonist</em> has his app bounced by Apple for&#8230;mocking political figures.  Oh, come on.  One interesting thing:  this has apparently happened several times before with cartoonists; each time, there was an outcry, and Apple relented.  Fiore himself isn&#8217;t arguing with Apple&#8212;he&#8217;s just sitting back and waiting for the reversal.  Maybe this is the real App Store model: reject broadly, accept anything the public deems important enough to make a fuss about.</p>
<p>And a few links on the iPad:</p>
<p><a href="http://daringfireball.net/2010/04/kids_are_all_right">The Kids Are All Right.</a> An unusually thoughtful post on the iPad/Pod/Phone tradeoffs:  the technology isn&#8217;t as generative, but distribution can be much simpler.</p>
<p><a href="http://slate.com/id/2249872">The Apple Two.</a> Apple introduced the original generative PC, and is now doing away with that generativity with the iPad, among other devices.  Tim Wu explains that this isn&#8217;t about a change in &#8220;Apple&#8217;s&#8221; ethos:  it&#8217;s Steve Jobs&#8217; ascendancy over Steve Wozniak.</p>
<p><a href="http://www.roughtype.com/archives/2010/04/the_ipad_luddit.php">The iPad Luddites.</a> One more meditation on the iPad, generativty, and the inevitability of technological change.  Carr points out that &#8220;[i]t&#8217;s useful to remember that the earliest radios were broadcasting devices as well as listening devices and that the earliest phonographs could be used for recording as well as playback,&#8221; and that the evolution from primitive to refined devices nearly always comes with a generativity loss.  But the question is whether that loss is inevitable, whether there&#8217;s a salient difference between the PC/Internet combo and the radio, and whether we can hope for some generative and general-purpose device that tinkerers will turn to if the PC becomes more locked down.</p>
<p>&#8212;By Jennifer Halbleib and Elisabeth Oppenheimer</p>
]]></content:encoded>
			<wfw:commentRss>http://futureoftheinternet.org/foi-topics-and-links-of-the-week-9/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Quick Links on the Apple-Adobe Battle</title>
		<link>http://futureoftheinternet.org/quick-links-on-the-apple-adobe-battle</link>
		<comments>http://futureoftheinternet.org/quick-links-on-the-apple-adobe-battle#comments</comments>
		<pubDate>Fri, 16 Apr 2010 00:20:31 +0000</pubDate>
		<dc:creator>elisabeth</dc:creator>
				<category><![CDATA[Future of the Internet]]></category>
		<category><![CDATA[Generativity]]></category>
		<category><![CDATA[iphone]]></category>
		<category><![CDATA[news]]></category>

		<guid isPermaLink="false">http://futureoftheinternet.org/?p=1378</guid>
		<description><![CDATA[On April 3, an Adobe technical project manager demonstrated that Adobe&#8217;s new Air software could be used to develop across platforms&#8212;he created a Reversi game app that runs on Android, iPhone, iPad, Windows 7, Ubuntu, and OS X (see potential caveats in comments here). Cool! As JZ said, via email, &#8220;if this is really possible, [...]]]></description>
			<content:encoded><![CDATA[<p>On April 3, an Adobe technical project manager <a href="http://blogs.adobe.com/cantrell/archives/2010/04/one_application_five_screens.html">demonstrated</a> that Adobe&#8217;s new Air software could be used to develop across platforms&#8212;he created a Reversi game app that runs on Android, iPhone, iPad, Windows 7, Ubuntu, and OS X (see potential caveats in comments <a href="http://developers.slashdot.org/story/10/04/04/1627226/Multi-Platform-App-Created-Using-Single-Code-Base?from=rss&amp;utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29">here</a>).  Cool!  As JZ said, via email, &#8220;if this is really possible, I feel better about the iPad, because developers don&#8217;t have to choose among platforms to which to devote energy.&#8221;</p>
<p>Whoops:  Five days later, Steve Jobs <a href="http://www.wired.com/gadgetlab/2010/04/iphone-developer-policy/">announced</a> modified Apple developer rules banning use of &#8220;intermediary&#8221; tools such as Air&#8212;in other words, there will be no more cross-platform development.  Adobe employees:  <a href="http://theflashblog.com/?p=1888">not happy.</a></p>
<p>This is starting to sound pretty antitrust-y.  It&#8217;s hard to think of any logical reason Apple cares where an app&#8217;s code originates&#8212;unless, of course, it just wants to hurt Adobe at every turn. Unfortunately, it&#8217;s been hard to find knowledgeable people analyzing actual antitrust law&#8212;anyone know of a good blog?  (For what it&#8217;s worth, this <a href="http://www.antitrustlawblog.com/2009/11/articles/article/technology-sector-comes-under-increased-antitrust-scrutiny/">old post from the Antitrust Law Blog</a> indicates that the tech sector, including Apple, is under heavier scrutiny from the DOJ and FTC.)</p>
<p>Not surprisingly, there are rumors a <a href="http://www.telegraph.co.uk/technology/apple/7588825/Adobe-to-sue-Apple-over-Flash-row.html">lawsuit is brewing</a>.</p>
<p>As usual, there&#8217;s another chapter in this saga: <a href="http://www.readwriteweb.com/archives/ripcode_brings_streaming_flash_video_to_iphone_ipa.php">Flash translation.</a> In a related but not identical story, Apple has long been <a href="http://gizmodo.com/5460694/steve-jobs-googles-dont-be-evil-mantra-is-bulls">hostile</a> to Adobe&#8217;s Flash multimedia platform, citing stability and security concerns for refusing to offer Flash support for the iPhone and iPad.  This puts websites that use Flash in a tough spot and limits iUsers&#8217; access to content&#8212;75% of web video <a href="http://blogs.adobe.com/flashplatform/2010/01/apples_ipad_--_a_broken_link.html">according to Adobe</a>.  Enter RipCode, which has developed a server-side translator solution.  If an iPhone user attempts to access a Flash video, the &#8220;transcoder&#8221; detects the platform and translates the video into a compatible format.  Since the transcoder is run off the website&#8217;s server, it doesn&#8217;t require Apple&#8217;s approval.  Assuming it&#8217;s reliable, this is a nice example of a how the <a href="http://yupnet.org/zittrain/archives/17#10">generative</a> web allows enterprising developers to solve problems (or, depending on your point of view, do end-runs around the rules).</p>
<p>&#8212;By Jennifer Halbleib and Elisabeth Oppenheimer</p>
]]></content:encoded>
			<wfw:commentRss>http://futureoftheinternet.org/quick-links-on-the-apple-adobe-battle/feed</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Modernizing Privacy in the Internet Age</title>
		<link>http://futureoftheinternet.org/modernizing-privacy-in-the-internet-age</link>
		<comments>http://futureoftheinternet.org/modernizing-privacy-in-the-internet-age#comments</comments>
		<pubDate>Fri, 09 Apr 2010 03:20:18 +0000</pubDate>
		<dc:creator>Jennifer</dc:creator>
				<category><![CDATA[Future of the Internet]]></category>

		<guid isPermaLink="false">http://futureoftheinternet.org/?p=1349</guid>
		<description><![CDATA[A coalition of prominent netizens and watchdogs released its wishlist this week for Digital Due Process.  Google, Microsoft, AT&#38;T, the ACLU, and EFF, among others, are advocating for an update of the 1986 Electronic Communications Privacy Act.  The statute, which includes the current regulations government agencies follow to access an individual&#8217;s electronic data and communications, [...]]]></description>
			<content:encoded><![CDATA[<p>A coalition of prominent netizens and watchdogs <a href="http://www.nytimes.com/2010/03/31/technology/31privacy.html">released its wishlist</a> this week for <a href="http://www.digitaldueprocess.org/index.cfm?objectid=37940370-2551-11DF-8E02000C296BA163">Digital Due Process</a>.  Google, Microsoft, AT&amp;T, the ACLU, and EFF, among others, are advocating for an update of the 1986 <a href="http://en.wikipedia.org/wiki/Electronic_Communications_Privacy_Act">Electronic Communications Privacy Act</a>.  The statute, which includes the current regulations government agencies follow to access an individual&#8217;s electronic data and communications, was passed the year after Windows 1.0 was released and five years before the World Wide Web was publicly introduced.  Attempts to shoehorn unexpected emerging technologies into the Act&#8217;s framework has led to inconsistent application to the same type of communication across jurisdictions and within the life cycle of the communication (for example, depending on the length of time since a stored email was first read), confusing all parties&#8212;government officials seeking information, service providers receiving such requests, and users wanting to know the extent to which their data is protected&#8212;and <a href="http://yupnet.org/zittrain/archives/19#31">arguably</a> providing insufficient protection. Therefore, the coalition is lobbying Congress to amend the law to reflect modern developments of widespread reliance on email, cloud computing, social networking, and location technologies.  Their list of principles would require warrants&#8212;with an exception for emergencies&#8212;for disclosure of a communication without regard for where or how it is stored, its age, or whether the service provider itself has access to the information for business purposes.  Location information would also require a warrant.  And the government must have a court order to obtain aggregate information (e.g., data from a non-particularized set of subscribers to a social networking site).</p>
<p>While legislation embodying these principles would clarify limits and valid procedure for U.S. government agents seeking information, it does not <a href="http://yupnet.org/zittrain/archives/20#3">ultimately secure</a> user data.  Companies that request or record personal information can sell it or otherwise use it without user authorization.  Hackers can surreptitiously acquire information from sites where it has been collected or archived.  In addition, because the Internet extends across jurisdictions, foreign states have their own rules governing data seizure which may be broader or less certain than U.S. standards.  Finally, the personal information of one person is often <a href="http://yupnet.org/zittrain/archives/20#16">disclosed by others</a>, for example on blogs or in online photo repositories.</p>
<p>One way a user can address the first three of these risks and assert a measure of control how his or her data is used or disseminated is to understand what information is being collected, why it is needed, and how security measures are implemented to safeguard it.  Unfortunately, this is often difficult for the average user to assess, especially considering the plethora of apps requesting access and their technical nature.  A <a href="http://www.google.com/hostednews/ap/article/ALeqM5girxG-534If8xmwg1CYJbgouQZUwD9ER7MUO2">new online resource</a> recently launched that harnesses the power of the community to provide this information.  <a href="https://whatapp.org/">WhatApp</a> compiles a database of apps, mining both the knowledge of technical experts and the experience of users.  Experts rate the apps along dimensions of privacy, security, and openness, based on a specific set of criteria.  Users review the apps on how they work in practice.  Should WhatApp be successful, it may serve not just as a tool to comment on apps, but itself affect change within the app ecosystem.  If a user has a choice of several apps to perform a specific task and makes a decision based on WhatApp&#8217;s assessment of their relative privacy and security, app developers will have to take these concerns into account to be competitive.</p>
<p>Both Digital Due Process and WhatApp still have to gain a critical mass to sustain the movements to their completion, whether that be legislation or a comprehensive and useful database of app privacy and security.  But at least initially, they seem to be growing steadily&#8212;another promising sign that institutional and individual members of the online community are taking initiative to maintain the Internet as a safe and open environment.  However risks to Privacy 2.0 remain, in particular how to control personal information disseminated broadly by others.  These concerns will require implementing additional ameliorative mechanisms online; <a href="http://yupnet.org/zittrain/archives/20#63">JZ suggests</a> data genealogy, reputation bankruptcy, and contextualization of information.</p>
<p>&#8211;by Jennifer Halbleib</p>
]]></content:encoded>
			<wfw:commentRss>http://futureoftheinternet.org/modernizing-privacy-in-the-internet-age/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>FOI Topics and Links of the Week</title>
		<link>http://futureoftheinternet.org/foi-topics-and-links-of-the-week-8</link>
		<comments>http://futureoftheinternet.org/foi-topics-and-links-of-the-week-8#comments</comments>
		<pubDate>Mon, 05 Apr 2010 16:04:03 +0000</pubDate>
		<dc:creator>Jennifer</dc:creator>
				<category><![CDATA[Future of the Internet]]></category>

		<guid isPermaLink="false">http://futureoftheinternet.org/?p=1295</guid>
		<description><![CDATA[Internet Telephony Comes to the iPhone. Apple has approved an app intended to provide a virtual second line for business that allows consumers to make calls using Wi-Fi when available instead of AT&#38;T&#8217;s cellular network.  The Line2 app may allow iPhone users to downgrade their AT&#38;T cell plans, though contracts and lack of universal Wi-Fi [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.nytimes.com/2010/03/25/technology/personaltech/25pogue.html?src=me&amp;ref=general">Internet Telephony Comes to the iPhone.</a> Apple has approved an app intended to provide a virtual second line for business that allows consumers to make calls using Wi-Fi when available instead of AT&amp;T&#8217;s cellular network.  The Line2 app may allow iPhone users to downgrade their AT&amp;T cell plans, though contracts and lack of universal Wi-Fi coverage&#8212;including where users might need phone service most in an emergency&#8212;will likely prevent them from dropping it entirely.  But Line2 is available for the iPod Touch, potentially turning it into a part-time iPhone.  Unfortunately, almost immediately after the NYT write-up, the developer had to <a href="http://www.csmonitor.com/Innovation/Horizons/2010/0326/Line2-app-pulled-by-Toktumi-after-computer-attack">pull Line2</a> from the App Store because of a massive denial-of-service attack.</p>
<p><a href="http://www.cl.cam.ac.uk/~rja14/psysec.html">Security Theory to Practice.</a> Ross Anderson has assembled a resource with links on the myriad dimensions of psychology and security.  A sampling includes why we as users discount some risks and overestimate others, how scams ensnare us, what conditions lead us to disclose private information, and ways to make security measures usable for the average person so that they actually get used and protect the greater internet community.  Interesting and practical.</p>
<p><a href="http://www.destructoid.com/drm-we-can-back-humiliating-pirates-for-fun-and-profit-169383.phtml">Humiliating the Pirates.</a> In a digital adaptation of medieval stocks, the Japanese gaming company Overflow released a fake installer for its erotic game Cross Days online that contains malicious code to acquire the information of people who try to use the installer to pirate the game.  That information is then posted online until the transgressor accepts responsibility for stealing the game.  It&#8217;s unclear whether the humiliation stems from being victimized&#8212;do those who play the game generally consider themselves too smart to download a trojan?&#8212;or from being exposed as a player of erotic video games.  If the latter, will the website where user information is posted receive enough traffic (besides others who play the game, who presumably won&#8217;t &#8220;out&#8221; those posted to the world if it would expose their own identity as well) to serve as a public town square?  It also seems less legitimate as an anti-piracy tactic since the company itself is making the &#8220;pirated&#8221; program available online.</p>
<p><a href="http://news.cnet.com/8301-13577_3-20001338-36.html?tag=mncol">Hunch Preview.</a> Buzz-generating start-up Hunch has launched a <a href="http://hunch.com/games/twitter-predictor/">Twitter Predictor</a> tool that examines a Twitter user&#8217;s account profile&#8212;who follows and is followed&#8212;and predicts the answer to a series of questions, apparently with over 80% accuracy.  The tool is intended to publicize the utility of Hunch&#8217;s forthcoming API to provide personalized recommendations.  Another example of <a href="http://yupnet.org/zittrain/archives/20#96">evolving privacy norms</a>, we as users are willing to turn over some personal data (by filling out a &#8220;taste profile&#8221; to use the service from which Hunch&#8217;s algorithm extrapolates additional information) for greater convenience.</p>
<p><a href="http://www.wired.com/threatlevel/2010/03/hacker-bricks-cars/">Hacker Disables More Than 100 Cars Remotely.</a> Even cars can be tethered appliances!  A Cleveland-based company &#8220;encourages&#8221; people who have been habitually late with car payments to be more timely by remotely triggering incessant horn honking or disabling the car&#8217;s ignition when payments aren&#8217;t made.  This went badly amiss when a laid-off employee of the company took revenge by remotely bricking or sounding the horns of 100+ cars.</p>
<p><a href="http://rconversation.blogs.com/MacKinnonCECC_Mar1.pdf">Rebecca MacKinnon&#8217;s Testimony at the Congressional-Executive Commission on China&#8217;s hearing on &#8220;China, the Internet, and Google.&#8221;</a> In light of the fast-evolving Google-China saga, MacKinnon&#8217;s analysis of the multi-tiered problems in China and possible solutions makes for a good read.  Among other things, she claims the Chinese government has hired 280,000 people to &#8220;astroturf&#8221;&#8212;that is, support the government&#8217;s views in cyberfora.  (The specific number comes from research by David Bandurski, which is unfortunately <a href="http://www.feer.com/essays/2008/august/chinas-guerrilla-war-for-the-web">behind a pay wall</a>.)  We&#8217;ve covered <a href="http://futureoftheinternet.org/citizens-of-farmville-petition-your-real-representatives">small-scale astroturfing</a> on this blog, but nothing close to that size or coordination.</p>
<p><a href="http://www.techdirt.com/articles/20100324/1806018708.shtml">Facebook Threatens Greasemonkey Script Writer.</a> A developer came up with the bright idea of writing a Greasemonkey script (that is, one that works through the user&#8217;s Firefox browser) to remove all that useless stuff from your Facebook feed&#8212;quizzes, Mafia Wars, etc.<a href="http://steeev.site50.net/fbpurity/news.htm"> According to the developer</a>, Facebook abruptly killed the fan page, and is now rolling out code that messes up the Greasemonkey script.  If that&#8217;s true (and that&#8217;s not clear to me; we only have one side of the story) it strikes me as overreaching&#8212;Facebook can control its site, but shouldn&#8217;t be able to control your browser.</p>
<p><a href="http://volokh.com/2010/03/15/eleventh-circuit-decision-largely-eliminates-fourth-amendment-protection-in-e-mail/">Eleventh Circuit Decision Largely Eliminates Fourth Amendment Protection in E-Mail.</a> As the title of this well-done Volokh conspiracy post suggests, don&#8217;t expect to defeat a government search of your email if you live in the Eleventh Circuit.  The decision tracks the discussion in <a href="http://yupnet.org/zittrain/archives/19#29">chapter 8 of the book</a>, but comes to a harsher conclusion&#8212;even e-mail stored locally isn&#8217;t safe from government seizure once a copy of it has been delivered elsewhere.</p>
<p>Finally, there are a few new thoughts posted in the comments of the <a href="http://futureoftheinternet.org/the-end-draws-nearer-for-echostar-dvrs">EchoStar/TiVo post</a>.</p>
<p>&#8212;By Elisabeth Oppenheimer and Jennifer Halbleib</p>
]]></content:encoded>
			<wfw:commentRss>http://futureoftheinternet.org/foi-topics-and-links-of-the-week-8/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
