Nothing says "establishment" as Vox’s attack on Trump

I keep seeing this Ezra Klein Vox article attacking Donald Trump. It’s wrong in every way something can be wrong. Trump is an easy target, but the Vox piece has almost no substance.

Yes, it’s true that Trump proposes several unreasonable policies, such as banning Muslims from coming into this country. I’ll be the first to chime in and call Trump a racist, Nazi bastard for these things.

But I’m not sure the other candidates are any better. Sure, they aren’t Nazis, but their politics are just as full of hate and impracticality. For example, Hillary wants to force Silicon Valley into censoring content, brushing aside complaints from those people overly concerned with “freedom of speech”. No candidate, not even Trump, is as radical as Bernie Sanders, who would dramatically reshape the economy. Trump hates Mexican works inside our country, Bernie hates Mexican workers in their own countries, championing punishing trade restrictions.

Most of substantive criticisms Vox gives Trump also applies to Bernie. For example, Vox says:

His view of the economy is entirely zero-sum — for Americans to win, others must lose. … His message isn’t so much that he’ll help you as he’ll hurt them… 

That’s Bernie’s view of the economy as well. He imagines that economy is a zero-sum game, and that for the 1% rich to prosper, they must take from the 99% of everyone else. Bernie’s entire message rests on punishing the 1% for the sin of being rich.

It’s the basis of all demagoguery that you find some enemy to blame. Trump’s enemies are foreigners, whereas Bernie’s enemies are those of the wrong class. Trump is one step in the direction of the horrors of the Nazi Holocaust. Bernie is one step in the direction of the horrors of old-style Soviet and Red Chinese totalitarian states.

About Trump’s dishonesty, Vox says:

He lies so constantly and so fluently that it’s hard to know if he even realizes he’s lying.

Not true. Trump just lies badly. He’s not the standard slick politician, who lie so fluently that we don’t even realize they are lying. Whether we find a politician’s lying to be objectionable isn’t based on any principle except whether that politician is on our side.

I gave $10 to all 23 presidential candidates, and get a constant stream of emails from the candidates pumping for more money. They all sound the same, regardless of political party, as if they all read the same book “How To Run A Presidential Campaign”. For example, before New Years, they all sent essentially the same message “Help us meet this important deadline!”, as if the end of the year is some important fund-raising deadline that must be met. It isn’t, that’s a lie, but such a fluent one that you can’t precisely identify it as a lie. If I were to judge candidate honesty, based on donor e-mails, Bernie would be near the top on honesty, and Hillary would be near the bottom, with Trump unexceptionally in the middle.

Vox’s biggest problem is that their attack focuses on Trump’s style more than substance. It’s a well-known logical fallacy that serious people avoid. Style is irrelevant. Trump’s substance provides us enough fodder to attack him, we don’t need to stoop to this low level. The Vox piece is great creative fiction about how nasty Trump is, missing only the standard dig about his hair, but there’s no details as to exactly why Trump’s policies are bad, such as the impractical cost of building a 2000 mile long wall between us and Mexico, or the necessity of suspending the 6th Amendment right to “due process” when deporting 20 million immigrants.

Vox’s complaint about Trump’s style is mostly that he doesn’t obey the mainstream media. All politicians misspeak. There’s no way to spend that many hours a day talking to the public without making the most egregious of mistakes. The mainstream media has a way of dealing with this, forcing the politician to grovel. They resent how Trump just ignores the problem and barrels on to the next thing. That the press can’t make his mistakes stick makes them very upset.

Imagine a situation where more than half the country believes in an idea, but nobody stands up and publicly acknowledges this. That’s a symptom of repressed speech. You’d think that the only suppressor of speech is the government, but that’s not true. The mainstream media is part of the establishment, and they regularly suppress speech they don’t like.

I point this out because half the country, both Democrats and Republicans, support Trump’s idea of preventing Muslims from coming into our country. Sure, it’s both logically stupid and evilly racist, but that doesn’t matter, half the country supports it. Yet, nobody admits supporting the idea publicly, because as soon as they do, they’ll be punished by the mass media.

Thus, the idea continues to fester, because it can’t openly be debated. People continue to believe in this bad idea because they are unpersuaded by the ad hominem that “you are such a racist”. The bedrock principle of journalism is that there are two sides to every debate. When half the country believes in a wrong idea, we have to accept that they are all probably reasonable people, and that we can change their minds if we honestly engage them in debate.

This sounds like I’m repeating the “media bias” trope, which politicians like Trump use to deflect even fair media coverage they happen not to like. But it’s not left-wing bias that is the problem here.

Instead, it’s that the media has become part of the establishment, with their own seat of power. Ezra Klein’s biggest achievement before Vox was JournoList, designed to help the established press wield their power at the top of the media hierarchy. Ezra Klein is the quintessential press insider. His post attacking Trump is just a typical example of how insiders attack outsiders who don’t conform. Yes, Trump deserves criticism, but based upon substance — not because he challenges how the press establishment has defined how politics should work in America.

Continue reading Nothing says "establishment" as Vox’s attack on Trump

Posted in Uncategorized

Lawfare thinks it can redefine π, and backdoors

There is gulf between how people believe law to work (from watching TV shows like Law and Order) and how law actually works. You lawyer people know what I’m talking about. It’s laughable.

The same is true of cyber: there’s a gulf between how people think it works and how it actually works.

This Lawfare blogpost thinks it’s come up with a clever method to get their way in the crypto-backdoor debate, by making carriers like AT&T responsible only for the what (“deliver interpretable signal in response to lawful wiretap order”) without defining the how (crypto backdoors, etc.). This pressure would come in the form of removing current liability protections they now enjoy for not being responsible for what customers transmit across their network. Or as the post paraphrases the proposal:

Don’t expect us to protect you from liability for third-party conduct if you actively design your systems to frustrate government efforts to monitor that third-party conduct.

The post is proud of its own smarts, as if they’ve figured out how to outwit mathematicians and redefine pi (π). But their solution is nonsense, based on a hopelessly naive understanding of how the Internet works. It appears all they know about the Internet is what they learned from watching CSI:Cyber.

The Internet is end-to-end. End-to-end is the technology shift that made the Internet happen, as compared to alternative directions cyberspace might have taken.

What that means is AT&T doesn’t encrypt traffic. Apple’s iPhone don’t encrypt traffic. Instead, it’s the app installed on the phone that does the encryption. Neither AT&T nor Apple can stop encryption from happening.

You think that because most people use iMessage or Snapchat, that all you have to do is turn the screws on them in order to force them to comply with backdoors. That won’t work, because the bad guys will stop using those apps and install different encrypted apps, like Signal. You imagine that it’s just a game of wack-a-mole, and eventually you’ll pressure all apps into compliance. But Signal is open-source. If it disappeared tomorrow, I’d still have a copy of the source, which I can compile into my own app I’ll call Xignal. I’ll continue making encrypted phone calls with my own app. Even if no source existed today, I could write my own source within a couple months to do this. Indeed, writing an encrypted chat app is typical homework assignment colleges might assign computer science students. (You people still haven’t come to grips with the fact that in cyberspace, we are living with the equivalent of physicists able to whip up a-bombs in their basements).

Running arbitrary software is a loose end that will defeat every solution you can come up with. It’s math. The only way forward to fix the “going dark” problem is to ban software code. But that you can’t do without destroying the economy and converting the country into a dystopic, Orwellian police state.

You think that those of us who oppose crypto backdoors are hippies with a knee-jerk rejection of any government technological mandate. That’s not true. The populists at the EFF love technological mandates in their favor, such as NetNeutrality mandates, or bans on exporting viruses to evil regimes (though they’ve recently walked back on that one).

Instead, we reject this specific technological mandate, because we know cyber. We know it won’t work. We can see that you’ll never solve your “going dark” problem, but in trying to, you’ll cause a constant erosion of both the economic utility of the Internet and our own civil liberties.

I apologize for the tone of this piece, saying you are stupid about cyber, but that’s what it always comes down to. The author of that piece has impressive Washington D.C. think-tanky credentials, but misfires on the basic end-to-end problem. And all think-tanky pieces on this debate are going to happen the same way, because as soon as they bring technologists in to consult on the problem, their desired op-eds become stillborn before anybody sees them.


Note: I get the π analogy from a tweet by @quinnorton, I don’t know who came up with analogy originally. Continue reading Lawfare thinks it can redefine π, and backdoors

Posted in Uncategorized

Is packet-sniffing illegal? (OmniCISA update)

In the news recently, Janet Napolitano (formerly head of DHS, now head of California’s university system) had packet-sniffing software installed at the UC Berkeley campus to monitor all its traffic. This brings up the age old question: is such packet-sniffing legal, or a violation of wiretap laws.

Setting aside the legality question for the moment, I should first point out that’s its perfectly normal. Almost all organizations use “packet-sniffers” to help manage their network. Almost all organizations have “intrusion detection systems” (IDS) that monitor network traffic looking for hacker attacks. Learning how to use packet-sniffers like “Wireshark” is part of every network engineer’s training.
Indeed, while the news articles describes this as some special and nefarious plot by Napolitano, the reality is that it’s probably just an upgrade of packet-sniffer systems that already exist.
Ironical, much packet-sniffing practice comes from UC Berkele. It’s famous for having created “BPF”, the eponymously named “Berkeley Packet Filter”, a standard for packet-sniffing included in most computers. Whatever packet-sniffing system Berkeley purchased to eavesdrop on its networks is almost certainly including Berkeley’s own BPF software.
Now for the legal question. Even if everyone is doing it, it doesn’t necessarily mean it’s legal. But the wiretap law does appear to contain an exception for packet-sniffing. Section 18 U.S. Code § 2511 (2) (a) (i) says:

It shall not be unlawful … to intercept … while engaged in any activity which is a necessary incident to the rendition of his service or to the protection of the rights or property of the provider of that service

In other words, you can wiretap your own network in order to keep it running and protect it against hackers. There is a lengthy academic paper that discusses this in more details: http://spot.colorado.edu/~sicker/publications/issues.pdf
 
At least, that’s the state of things before OmniCISA (“Cybersecurity Act of 2015”). Section 104 (a) (1) says:

Notwithstanding any other provision of law, a private entity may, for cybersecurity purposes, monitor … an information system of such private entity;

In other words, regardless of other laws, you may monitor your computers (including the network) for the purpose of cybersecurity.
As I read OmniCISA, I see that the intent is just this, to clarify that what organizations are already doing is in fact legal. When I read the text of the bill, and translate legalese into technology, I see that what it’s really talking about is just standard practice of monitoring log files and operating IDSs, IPSs, and firewalls. It also describes the standard practice of outsourcing security operations to a managed provider (the terms we would use, not how the bill described it). Much of what we’ve been doing is ambiguous under the law, since it’s confusing as heck, so OmniCISA clarifies this.
Thus, the argument about whether packet-sniffing was legal before is now moot: according to OmniCISA, you can now packet-sniff your networks for cybersecurity, such as using IDSs.

Continue reading Is packet-sniffing illegal? (OmniCISA update)

Posted in Uncategorized