<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://cyber.harvard.edu/cyberlaw_winter10/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Style</id>
	<title>Cyberlaw: Difficult Issues Winter 2010 - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="https://cyber.harvard.edu/cyberlaw_winter10/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Style"/>
	<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cyberlaw_winter10/Special:Contributions/Style"/>
	<updated>2026-10-04T05:13:08Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.43.6</generator>
	<entry>
		<id>https://cyber.harvard.edu/cyberlaw_winter10/?title=Cybersecurity_Project&amp;diff=1099</id>
		<title>Cybersecurity Project</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cyberlaw_winter10/?title=Cybersecurity_Project&amp;diff=1099"/>
		<updated>2010-01-30T20:53:09Z</updated>

		<summary type="html">&lt;p&gt;Style: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&#039;&#039;Topic Owners: Mike, Jason, Ramesh, and Sheel&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Saying that cybersecurity is a &amp;quot;difficult problem&amp;quot; is like saying that reversing global warming is a difficult problem: it&#039;s true, but it doesn&#039;t quite capture how devilishly complicated and multifaceted the problem really is. There&#039;s no single reason why creating a more secure global network is so difficult; it in part has to do with the radically-distributed architecture of the Net, in part with some deep flaws computer software for both consumers and businesses, and in part from the network&#039;s sheer size and importance to our daily lives. (For more on this, see the nice [[Cybersecurity]] backgrounder.)&lt;br /&gt;
&lt;br /&gt;
Our group approached the problem not with the goal of inventing a panacea that would make all credit card transactions magically secure and make it impossible for hackers to [http://googleblog.blogspot.com/2010/01/new-approach-to-china.html compromise Gmail&#039;s security]. Instead, we wanted to offer suggestions with minimal implementation headaches and maximal benefit to users, from novices to experts. &lt;br /&gt;
&lt;br /&gt;
The final &amp;quot;product&amp;quot; of our month-long thinking on this issue begins with a reasonably short video overview of our ideas [http://www.vimeo.com/9036735 here,] (or see below), explains some of the details of our proposal, and also has an alpha-release Firefox plugin that you can download and try out (thanks to [http://www.elance.com/ Elance] for making the plugin possible, by the way).&lt;br /&gt;
&lt;br /&gt;
==Overview==&lt;br /&gt;
&lt;br /&gt;
We discussed this topic at length in an in-class presentation on January 19. [http://www.vimeo.com/9036735 This] 9-minute video summarizes and extends the presentation we gave that day. The details on this page elaborate on the proposals mentioned in the video.&lt;br /&gt;
&lt;br /&gt;
==Guiding Principles==&lt;br /&gt;
&lt;br /&gt;
Before turning to the specific proposals we&#039;ve made to improve cybersecurity, it&#039;s helpful to discuss some of the guiding principles that have informed our work. We applaud the [http://www.whitehouse.gov/assets/documents/Cyberspace_Policy_Review_final.pdf government&#039;s] attempts to improve cybersecurity, but don&#039;t believe that a top-down, regulatory or legislative solution is a panacea.&lt;br /&gt;
&lt;br /&gt;
====Empowering Users====&lt;br /&gt;
Cybersecurity is a huge, complicated problem, conceivably including everything from keeping the electrical grid from going down to garden-variety phishing spam. We consciously left the [http://www.sandia.gov/scada/history.htm SCADA] problem to those in government and industry, and focused on problems that face ordinary users. &lt;br /&gt;
&lt;br /&gt;
We suggest tools that rely both on the power users who have contributed much to the internet&#039;s development as well as the ordinary users who are the overwhelming share of people online today. Bottom-up solutions seem improbable when they begin; Wikipedia and Firefox, to take just two examples, were thought to face extremely long odds. We believe that giving users the tools they need to take control of their own security can improve users&#039; experiences on the net, as well as convincing major market players to adopt similar solutions that will help everyone, including those users who haven&#039;t taken affirmative steps to protect their security.&lt;br /&gt;
&lt;br /&gt;
====Nudging Users====&lt;br /&gt;
The mind sciences and behavioral economics have demonstrated the tinkering with default settings and gently [http://www.nudges.org/ nudging] people in a direction can cause dramatic changes in behavior. We apply that insight to cybersecurity. If it&#039;s a little harder to reuse or create weak passwords, or a little easier to find out what malware has infected your computer, security may greatly improve. &lt;br /&gt;
&lt;br /&gt;
====Code is Law====&lt;br /&gt;
[http://en.wikipedia.org/wiki/Lawrence_Lessig Lawrence Lessig&#039;s] 1999 insight that [http://www.code-is-law.org/ code is law] is still crucial to understand cybersecurity more than ten years later. Most fundamentally, the major browsers and websites can improve (or worsen) security for users, perhaps much more than the government can. Key browsers and websites, by coding our proposals or other security fixes, can make a major impact on security.&lt;br /&gt;
&lt;br /&gt;
====No big thing, many little things====&lt;br /&gt;
Finally, we consider ourselves [http://berlin.wolf.ox.ac.uk/published_works/rt/HF.pdf foxes, rather than hedgehogs,] and believe that there&#039;s no one big thing, or top-down solution, by the government or the private sector, that could solve the cybersecurity problem overnight. Cybersecurity has so many dimensions that it must be improved on all levels, by the government, by industry, by non-profits, and by users. Even if the net suddenly became more secure, in a few months or years new vulnerabilities would be exposed and take the place of the old. As long as the Net remains open, cybersecurity will be a never-ending arms race, and we believe that empowering users, nudging them to better security practices, and remembering that code can be law can give the good guys the upper hand.&lt;br /&gt;
&lt;br /&gt;
==Specific Proposals==&lt;br /&gt;
&lt;br /&gt;
===Public Service Announcement===&lt;br /&gt;
&lt;br /&gt;
We created a Public Service Announcement for generating public awareness for the cybersecurity problem, and showed it in class on January 19. It&#039;s online [http://vimeo.com/8937782 here] but is password-protected. Please email us if you were in the class and would like the password. &lt;br /&gt;
&lt;br /&gt;
The upshot of the video is that we don&#039;t think a direct public awareness campaign will be very effective. We believe it would be more productive to nudge users and change their behavior by altering the way browsers and websites work, not by scolding people in 30-second TV ads.&lt;br /&gt;
&lt;br /&gt;
===SafeWord===&lt;br /&gt;
&lt;br /&gt;
====What is SafeWord?====&lt;br /&gt;
&lt;br /&gt;
SafeWord is a real, working FireFox plugin designed to nudge users into keeping safer and more unique passwords, though it&#039;s too unstable and unrefined to be considered anything but alpha software at this point. It&#039;s available for download [http://www.jasonharrow.com/safeword-1.0.0-fx.xpi here]. To install, save that file to your disk, select File --&amp;gt; Open in Firefox 3.5 or above, and install it. You will need to restart Firefox before it takes effect. Thanks to Elance for helping with the coding on very short notice.&lt;br /&gt;
&lt;br /&gt;
We have created a video demonstration of one of the key features of SafeWord [http://vimeo.com/9031865 here].&lt;br /&gt;
&lt;br /&gt;
====What Are The Goals of SafeWord?====&lt;br /&gt;
&lt;br /&gt;
SafeWord begins with a simple proposition: online passwords should be both strong and also different across different sites, and your browser should help you achieve that goal. Studies continue to show that most people use very simple passwords; see, for instance, [http://www.nytimes.com/2010/01/21/technology/21password.html this] &#039;&#039;New York Times&#039;&#039; article that gets right to the point. &amp;quot;If your password is 123456,&amp;quot; reads the headline, &amp;quot;just make it HackMe.&amp;quot; Moreover, most users also fall into the &amp;quot;dirty habit&amp;quot; of using the same password across multiple online accounts, which can lead to a disaster if only one of the accounts is able to be compromised. An extremely detailed analysis of a 2009 attack that used this principle to compromise many online accounts of Twitter employee is [http://www.techcrunch.com/2009/07/19/the-anatomy-of-the-twitter-attack/ here].&lt;br /&gt;
&lt;br /&gt;
====More on The Unique Password Feature====&lt;br /&gt;
&lt;br /&gt;
=====A Scary Story, and A Word About Annoyance=====&lt;br /&gt;
&lt;br /&gt;
Even readers who are all for stronger password security in general may nonetheless be skeptical of what can happen to &amp;quot;regular people&amp;quot; who can&#039;t be bothered to remember so many passwords. But here&#039;s a very scary story - which is taken directly from the [http://www.techcrunch.com/2009/07/19/the-anatomy-of-the-twitter-attack/ Twitter attack analysis] cited above - of what can happen if users employ the same password at multiple important sites:&lt;br /&gt;
&lt;br /&gt;
# HC [the hacker&#039;s alias] accessed Gmail for a Twitter employee by using the password recovery feature that sends a reset link to a secondary email. In this case the secondary email was an expired Hotmail account, he simply registered it, clicked the link and reset the password, giving him control of the Gmail account.&lt;br /&gt;
# HC then read emails to guess what the original Gmail password was successfully and reset the password so the Twitter employee would not notice the account had changed.&lt;br /&gt;
# HC then used the same password to access the employeeâs Twitter email on Google Apps, getting access to a gold mine of sensitive company information from emails and, particularly, email attachments.&lt;br /&gt;
# HC then used this information along with additional password guesses and resets to take control of other Twitter employees&#039; personal and work emails.&lt;br /&gt;
# HC then used the same username/password combinations and password reset features to access AT&amp;amp;T, MobileMe, Amazon and iTunes, among other services. A security hole in iTunes gave HC access to full credit card information in clear text. HC now also had control of Twitterâs domain names at GoDaddy.&lt;br /&gt;
# Even at this point, Twitter had absolutely no idea they had been compromised.&lt;br /&gt;
&lt;br /&gt;
That&#039;s the danger, and it ain&#039;t pretty.&lt;br /&gt;
&lt;br /&gt;
On the other hand, as SafeWord users, we admit that the aspect of the program that requires you to use a different password for each new login is, well, pretty damn annoying. Complying with its demands to keep generating unique passwords might even require some old-fashioned tricks, like the creation of a heuristic for generating memorable but unique passwords or keeping a card in your wallet to keep track of your various logins (and maybe even separating out parts of &#039;&#039;that&#039;&#039; list or keeping it encoded somehow). Still, we think that the cost/benefit analysis weighs in favor of life being just a little more annoying in this area, because as our scary story illustrates, there are &#039;&#039;&#039;lots&#039;&#039;&#039; of points-of-entry to our various accounts, and &#039;&#039;&#039;lots&#039;&#039;&#039; of random people out there who would love to hack those accounts for financial gain or to get their kicks.&lt;br /&gt;
&lt;br /&gt;
=====Why Do It This Way?=====&lt;br /&gt;
&lt;br /&gt;
There are other solutions out there that automatically generate secure, unique passwords for each site you visit; [https://lastpass.com/features_free.php LastPass] is a particularly nifty one. But they all share several key points of failure: they rely on a master password, and they store your passwords in the cloud. Relying on a master password is particularly problematic, because a compromise of that password can lead to the same disastrous chain of events that we are trying to prevent. The only way to truly reduce the risk of this type of threat is to decentralize everything. And if that takes encouraging people to work a little harder, we at least want to make people aware that this just might be worth the hassle. Similarly, there are problems with storing passwords in the cloud, including intruder problems and problems if the company goes out of business or the cloud becomes inaccessible.&lt;br /&gt;
&lt;br /&gt;
=====Extension v. Built-in Feature=====&lt;br /&gt;
&lt;br /&gt;
Initially, we hoped to build this extension to make a pitch to Mozilla that they should think about building this kind of functionality into the browser. But as we have used a now-working copy of SafeWord in our browsers - admittedly, it&#039;s an alpha copy that&#039;s not even close to ready for prime-time - at least two of us (i.e. jharrow and rnagarajan) see that it&#039;s just too intrusive for mainstream users. If the average, busy user gets a pop-up every time he comes across a new website and tries to use an old password, he will get angry at the browser. If this happens a few times, he will probably switch from Firefox to another browser. So right now, the idea works best as an extension for people who really believe in password security and want a little nudge when they are thinking of giving in to the instinct to just use the password they used last time. But if SafeWord could work only with websites that store important personal information -- email providers, financial institutions, retailers with your credit card information -- and ignore the local newspaper&#039;s website, perhaps the balance between security and frustration would be a little closer to the former.&lt;br /&gt;
&lt;br /&gt;
====More on the Stronger Password Feature====&lt;br /&gt;
&lt;br /&gt;
On the other hand, the idea of adding a feature that helps users create more secure passwords - even if they are reused across multiple accounts - is a simple fix that should enhance the browsing experience for most users.&lt;br /&gt;
&lt;br /&gt;
Increasingly, many websites are giving users some guidelines on password security. For instance, Yahoo!&#039;s sign-up page looks like this:&lt;br /&gt;
&lt;br /&gt;
[[Image:Yahoo.png]]&lt;br /&gt;
&lt;br /&gt;
We think that&#039;s great. But not all sites have that feature. For instance, you get no visual feedback if you sign-up for an Amazon account with a weak password:&lt;br /&gt;
&lt;br /&gt;
[[Image:Amazon1.png]]&lt;br /&gt;
&lt;br /&gt;
Your browser can change this state-of-affairs easily. Here&#039;s the new view, with a SafeWord bar underneath the password field reminding you that your password is weak:&lt;br /&gt;
&lt;br /&gt;
[[Image:Amazon2.png]]&lt;br /&gt;
&lt;br /&gt;
SafeWord even lets you customize the password strength options:&lt;br /&gt;
&lt;br /&gt;
[[Image:Amazon3.png]]&lt;br /&gt;
&lt;br /&gt;
We think something like this really could be built into the browser, and would both add to the user experience and increase security.&lt;br /&gt;
&lt;br /&gt;
===&amp;quot;Amber Alert&amp;quot; For The Internet===&lt;br /&gt;
&lt;br /&gt;
Even if websites invest a lot of time and effort into securing their servers and user data, few sites take a more systematic approach to cybersecurity and view the massive numbers of compromised user machines as as &amp;quot;their&amp;quot; problem; they don&#039;t have any ownership over the fact that so many computers are running nasty malware and are thus compromised in important ways that can cause systemic harm to the Internet (like, say, when a site is taken offline in a Distributed Denial-of-Service attack; a partial list of such incidents is [http://en.wikipedia.org/wiki/Denial-of-service_attack#Incidents here]). However, there are some promising signs [http://bits.blogs.nytimes.com/2010/01/13/facebook-joins-with-mcafee-to-clean-up-malware-on-site/ this] may be [http://stopbadware.org/home/pr_01252010 changing].&lt;br /&gt;
&lt;br /&gt;
Perhaps these initiatives can go even further. What if a coalition of leading Internet sites were willing to share certain information about security threats with a third party organization (like [http://stopbadware.org/home/index StopBadware]), and the third-party would vet the information and then issue certain &amp;quot;Amber Alerts&amp;quot; that all the sites would be willing to publicize in some way? When there&#039;s a particularly egregious security hole in an [http://en.wikipedia.org/wiki/Internet_Explorer_6 old browser], for instance, if all the leading websites actively encouraged its users to patch it, that has the potential to do a lot of good.&lt;br /&gt;
&lt;br /&gt;
We initially proposed this solution as a unilateral move that individual sites could make - Google, say, could warn its users about the vulnerabilities of Internet Explorer 6. But we&#039;ve realize that if the recommendations are filtered through a reliable third-party, perhaps the companies won&#039;t be threatened by the embarrassment of having an &amp;quot;Amber Alert&amp;quot; put out. Sure, there would be negative consequences for a company, just as a company who undertakes a product recall generates bad publicity. But ultimate the hope is that companies will realize the net positive value of this transaction, and that consumers will look kindly on companies promoting a new level of honesty and transparency.&lt;br /&gt;
&lt;br /&gt;
====Good Cyber-Samaritans====&lt;br /&gt;
&lt;br /&gt;
An idea we discussed on January 19 that was related to the &amp;quot;Amber Alert&amp;quot; system for websites involves empowering educated users to help out their less computer-savvy friends and neighbors with computer security problems just...because. Perhaps there could be a network of young people who think security is important and who don&#039;t mind hanging around their local library for a few hours helping people update software and patching security holes. This solution becomes ever-more feasible as a greater proportion of users switches to laptop computers and as projects showing that people are willing to assist strangers for the sheer fun and satisfaction of the experience - from building an [http://www.wikipedia.org encyclopedia] to giving them a [http://www.couchsurfing.org couch to crash on] for free - flourish. Relying on people&#039;s good natures could be a new way to make progress on this problem.&lt;br /&gt;
&lt;br /&gt;
===Distress Password===&lt;br /&gt;
&lt;br /&gt;
This was an idea originally discussed at the Liberation Technologies Seminar in the Fall of 2009 and was expanded upon by the team.  Imagine you have confidential information in your email (as most of us do) and you are captured by a hostile terrorist organization.  They demand your Facebook and Gmail passwords.  As of now, we only have one password: the real one.  But, what if we had a distress password that, if entered could:&lt;br /&gt;
&lt;br /&gt;
a) delete the account, or say it was &#039;temporarily suspended&#039;&lt;br /&gt;
b) show the email account, but only emails that you had marked as safe (or, in other words, only those which you hadn&#039;t filtered as &#039;private&#039;)&lt;br /&gt;
c) require to you call customer service due to &#039;unauthorized activity&#039;&lt;br /&gt;
&lt;br /&gt;
This could easily be implemented by any email service provider.  &lt;br /&gt;
&lt;br /&gt;
===Password Picture===&lt;br /&gt;
&lt;br /&gt;
The purpose of the password picture idea is to prevent against keystroke detectors on public computers gaining access to passwords.  This dual authentication system would require the typical typed-in password, as well as the user to select, from a series of pictures, the picture or pictures that match the category given at the time of signup (perhaps updated every 3 months).  It would work like this:&lt;br /&gt;
&lt;br /&gt;
Say, when creating an account on Gmail, Gmail gave me the category &#039;tree&#039; and &#039;car&#039;.  Here is what would happen when I went to log in:&lt;br /&gt;
&lt;br /&gt;
1) I&#039;d have to type my password&lt;br /&gt;
2) Then, from a series of 20 pictures, I would have to pick the one that is a tree.&lt;br /&gt;
3) Then, from a series of 20 pictures, I would have to pick the one that is a car. &lt;br /&gt;
&lt;br /&gt;
I&#039;m in!&lt;/div&gt;</summary>
		<author><name>Style</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cyberlaw_winter10/?title=Cybersecurity_Project&amp;diff=1098</id>
		<title>Cybersecurity Project</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cyberlaw_winter10/?title=Cybersecurity_Project&amp;diff=1098"/>
		<updated>2010-01-30T20:50:22Z</updated>

		<summary type="html">&lt;p&gt;Style: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&#039;&#039;Topic Owners: Mike, Jason, Ramesh, and Sheel&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Saying that cybersecurity is a &amp;quot;difficult problem&amp;quot; is like saying that reversing global warming is a difficult problem: it&#039;s true, but it doesn&#039;t quite capture how devilishly complicated and multifaceted the problem really is. There&#039;s no single reason why creating a more secure global network is so difficult; it in part has to do with the radically-distributed architecture of the Net, in part with some deep flaws computer software for both consumers and businesses, and in part from the network&#039;s sheer size and importance to our daily lives. (For more on this, see the nice [[Cybersecurity]] backgrounder.)&lt;br /&gt;
&lt;br /&gt;
Our group approached the problem not with the goal of inventing a panacea that would make all credit card transactions magically secure and make it impossible for hackers to [http://googleblog.blogspot.com/2010/01/new-approach-to-china.html compromise Gmail&#039;s security]. Instead, we wanted to offer suggestions with minimal implementation headaches and maximal benefit to users, from novices to experts. &lt;br /&gt;
&lt;br /&gt;
The final &amp;quot;product&amp;quot; of our month-long thinking on this issue begins with a reasonably short video overview of our ideas [http://www.vimeo.com/9036735 here,] (or see below), explains some of the details of our proposal, and also has an alpha-release Firefox plugin that you can download and try out (thanks to [http://www.elance.com/ Elance] for making the plugin possible, by the way).&lt;br /&gt;
&lt;br /&gt;
==Overview==&lt;br /&gt;
&lt;br /&gt;
We discussed this topic at length in an in-class presentation on January 19. [http://www.vimeo.com/9036735 This] 9-minute video summarizes and extends the presentation we gave that day. The details on this page elaborate on the proposals mentioned in the video.&lt;br /&gt;
&lt;br /&gt;
==Guiding Principles==&lt;br /&gt;
&lt;br /&gt;
Before turning to the specific proposals we&#039;ve made to improve cybersecurity, it&#039;s helpful to discuss some of the guiding principles that have informed our work. We applaud the [http://www.whitehouse.gov/assets/documents/Cyberspace_Policy_Review_final.pdf government&#039;s] attempts to improve cybersecurity, but don&#039;t believe that a top-down, regulatory or legislative solution is a panacea.&lt;br /&gt;
&lt;br /&gt;
====Empowering Users====&lt;br /&gt;
Cybersecurity is a huge, complicated problem, conceivably including everything from keeping the electrical grid from going down to garden-variety phishing spam. We consciously left the [http://www.sandia.gov/scada/history.htm SCADA] problem to those in government and industry, and focused on problems that face ordinary users. &lt;br /&gt;
&lt;br /&gt;
We suggest tools that rely both on the power users who have contributed much to the internet&#039;s development as well as the ordinary users who are the overwhelming share of people online today. Bottom-up solutions seem improbable when they begin; Wikipedia and Firefox, to take just two examples, were thought to face extremely long odds. We believe that giving users the tools they need to take control of their own security can improve users&#039; experiences on the net, as well as convincing major market players to adopt similar solutions that will help everyone, including those users who haven&#039;t taken affirmative steps to protect their security.&lt;br /&gt;
&lt;br /&gt;
====Nudging Users====&lt;br /&gt;
The mind sciences and behavioral economics have demonstrated the tinkering with default settings and gently [http://www.nudges.org/ nudging] people in a direction can cause dramatic changes in behavior. We apply that insight to cybersecurity. If it&#039;s a little harder to reuse or create weak passwords, or a little easier to find out what malware has infected your computer, security may greatly improve. &lt;br /&gt;
&lt;br /&gt;
====Code is Law====&lt;br /&gt;
[http://en.wikipedia.org/wiki/Lawrence_Lessig Lawrence Lessig&#039;s] 1999 insight that [http://www.code-is-law.org/ code is law] is still crucial to understand cybersecurity more than ten years later. Most fundamentally, the major browsers and websites can improve (or worsen) security for users, perhaps much more than the government can. Key browsers and websites, by coding our proposals or other security fixes, can make a major impact on security.&lt;br /&gt;
&lt;br /&gt;
====No big thing, many little things====&lt;br /&gt;
Finally, we consider ourselves [http://berlin.wolf.ox.ac.uk/published_works/rt/HF.pdf foxes, rather than hedgehogs,] and believe that there&#039;s no one big thing, or top-down solution, by the government or the private sector, that could solve the cybersecurity problem overnight. Cybersecurity has so many dimensions that it must be improved on all levels, by the government, by industry, by non-profits, and by users. Even if the net suddenly became more secure, in a few months or years new vulnerabilities would be exposed and take the place of the old. As long as the Net remains open, cybersecurity will be a never-ending arms race, and we believe that empowering users, nudging them to better security practices, and remembering that code can be law can give the good guys the upper hand.&lt;br /&gt;
&lt;br /&gt;
==Specific Proposals==&lt;br /&gt;
&lt;br /&gt;
===Public Service Announcement===&lt;br /&gt;
&lt;br /&gt;
We created a Public Service Announcement for generating public awareness for the cybersecurity problem, and showed it in class on January 19. It&#039;s online [http://vimeo.com/8937782 here] but is password-protected. Please email us if you were in the class and would like the password. &lt;br /&gt;
&lt;br /&gt;
The upshot of the video is that we don&#039;t think a direct public awareness campaign will be very effective. We believe it would be more productive to nudge users and change their behavior by altering the way browsers and websites work, not by scolding people in 30-second TV ads.&lt;br /&gt;
&lt;br /&gt;
===SafeWord===&lt;br /&gt;
&lt;br /&gt;
====What is SafeWord?====&lt;br /&gt;
&lt;br /&gt;
SafeWord is a real, working FireFox plugin designed to nudge users into keeping safer and more unique passwords, though it&#039;s too unstable and unrefined to be considered anything but alpha software at this point. It&#039;s available for download [http://www.jasonharrow.com/safeword-1.0.0-fx.xpi here]. To install, save that file to your disk, select File --&amp;gt; Open in Firefox 3.5 or above, and install it. You will need to restart Firefox before it takes effect. Thanks to Elance for helping with the coding on very short notice.&lt;br /&gt;
&lt;br /&gt;
We have created a video demonstration of one of the key features of SafeWord [http://vimeo.com/9031865 here].&lt;br /&gt;
&lt;br /&gt;
====What Are The Goals of SafeWord?====&lt;br /&gt;
&lt;br /&gt;
SafeWord begins with a simple proposition: online passwords should be both strong and also different across different sites, and your browser should help you achieve that goal. Studies continue to show that most people use very simple passwords; see, for instance, [http://www.nytimes.com/2010/01/21/technology/21password.html this] &#039;&#039;New York Times&#039;&#039; article that gets right to the point. &amp;quot;If your password is 123456,&amp;quot; reads the headline, &amp;quot;just make it HackMe.&amp;quot; Moreover, most users also fall into the &amp;quot;dirty habit&amp;quot; of using the same password across multiple online accounts, which can lead to a disaster if only one of the accounts is able to be compromised. An extremely detailed analysis of a 2009 attack that used this principle to compromise many online accounts of Twitter employee is [http://www.techcrunch.com/2009/07/19/the-anatomy-of-the-twitter-attack/ here].&lt;br /&gt;
&lt;br /&gt;
====More on The Unique Password Feature====&lt;br /&gt;
&lt;br /&gt;
=====A Scary Story, and A Word About Annoyance=====&lt;br /&gt;
&lt;br /&gt;
Even readers who are all for stronger password security in general may nonetheless be skeptical of what can happen to &amp;quot;regular people&amp;quot; who can&#039;t be bothered to remember so many passwords. But here&#039;s a very scary story - which is taken directly from the [http://www.techcrunch.com/2009/07/19/the-anatomy-of-the-twitter-attack/ Twitter attack analysis] cited above - of what can happen if users employ the same password at multiple important sites:&lt;br /&gt;
&lt;br /&gt;
# HC [the hacker&#039;s alias] accessed Gmail for a Twitter employee by using the password recovery feature that sends a reset link to a secondary email. In this case the secondary email was an expired Hotmail account, he simply registered it, clicked the link and reset the password, giving him control of the Gmail account.&lt;br /&gt;
# HC then read emails to guess what the original Gmail password was successfully and reset the password so the Twitter employee would not notice the account had changed.&lt;br /&gt;
# HC then used the same password to access the employeeâs Twitter email on Google Apps, getting access to a gold mine of sensitive company information from emails and, particularly, email attachments.&lt;br /&gt;
# HC then used this information along with additional password guesses and resets to take control of other Twitter employees&#039; personal and work emails.&lt;br /&gt;
# HC then used the same username/password combinations and password reset features to access AT&amp;amp;T, MobileMe, Amazon and iTunes, among other services. A security hole in iTunes gave HC access to full credit card information in clear text. HC now also had control of Twitterâs domain names at GoDaddy.&lt;br /&gt;
# Even at this point, Twitter had absolutely no idea they had been compromised.&lt;br /&gt;
&lt;br /&gt;
That&#039;s the danger, and it ain&#039;t pretty.&lt;br /&gt;
&lt;br /&gt;
On the other hand, as SafeWord users, we admit that the aspect of the program that requires you to use a different password for each new login is, well, pretty damn annoying. Complying with its demands to keep generating unique passwords might even require some old-fashioned tricks, like the creation of a heuristic for generating memorable but unique passwords or keeping a card in your wallet to keep track of your various logins (and maybe even separating out parts of &#039;&#039;that&#039;&#039; list or keeping it encoded somehow). Still, we think that the cost/benefit analysis weighs in favor of life being just a little more annoying in this area, because as our scary story illustrates, there are &#039;&#039;&#039;lots&#039;&#039;&#039; of points-of-entry to our various accounts, and &#039;&#039;&#039;lots&#039;&#039;&#039; of random people out there who would love to hack those accounts for financial gain or to get their kicks.&lt;br /&gt;
&lt;br /&gt;
=====Why Do It This Way?=====&lt;br /&gt;
&lt;br /&gt;
There are other solutions out there that automatically generate secure, unique passwords for each site you visit; [https://lastpass.com/features_free.php LastPass] is a particularly nifty one. But they all share several key points of failure: they rely on a master password, and they store your passwords in the cloud. Relying on a master password is particularly problematic, because a compromise of that password can lead to the same disastrous chain of events that we are trying to prevent. The only way to truly reduce the risk of this type of threat is to decentralize everything. And if that takes encouraging people to work a little harder, we at least want to make people aware that this just might be worth the hassle. Similarly, there are problems with storing passwords in the cloud, including intruder problems and problems if the company goes out of business or the cloud becomes inaccessible.&lt;br /&gt;
&lt;br /&gt;
=====Extension v. Built-in Feature=====&lt;br /&gt;
&lt;br /&gt;
Initially, we hoped to build this extension to make a pitch to Mozilla that they should think about building this kind of functionality into the browser. But as we have used a now-working copy of SafeWord in our browsers - admittedly, it&#039;s an alpha copy that&#039;s not even close to ready for prime-time - at least two of us (i.e. jharrow and rnagarajan) see that it&#039;s just too intrusive for mainstream users. If the average, busy user gets a pop-up every time he comes across a new website and tries to use an old password, he will get angry at the browser. If this happens a few times, he will probably switch from Firefox to another browser. So right now, the idea works best as an extension for people who really believe in password security and want a little nudge when they are thinking of giving in to the instinct to just use the password they used last time. But if SafeWord could work only with websites that store important personal information -- email providers, financial institutions, retailers with your credit card information -- and ignore the local newspaper&#039;s website, perhaps the balance between security and frustration would be a little closer to the former.&lt;br /&gt;
&lt;br /&gt;
====More on the Stronger Password Feature====&lt;br /&gt;
&lt;br /&gt;
On the other hand, the idea of adding a feature that helps users create more secure passwords - even if they are reused across multiple accounts - is a simple fix that should enhance the browsing experience for most users.&lt;br /&gt;
&lt;br /&gt;
Increasingly, many websites are giving users some guidelines on password security. For instance, Yahoo!&#039;s sign-up page looks like this:&lt;br /&gt;
&lt;br /&gt;
[[Image:Yahoo.png]]&lt;br /&gt;
&lt;br /&gt;
We think that&#039;s great. But not all sites have that feature. For instance, you get no visual feedback if you sign-up for an Amazon account with a weak password:&lt;br /&gt;
&lt;br /&gt;
[[Image:Amazon1.png]]&lt;br /&gt;
&lt;br /&gt;
Your browser can change this state-of-affairs easily. Here&#039;s the new view, with a SafeWord bar underneath the password field reminding you that your password is weak:&lt;br /&gt;
&lt;br /&gt;
[[Image:Amazon2.png]]&lt;br /&gt;
&lt;br /&gt;
SafeWord even lets you customize the password strength options:&lt;br /&gt;
&lt;br /&gt;
[[Image:Amazon3.png]]&lt;br /&gt;
&lt;br /&gt;
We think something like this really could be built into the browser, and would both add to the user experience and increase security.&lt;br /&gt;
&lt;br /&gt;
===&amp;quot;Amber Alert&amp;quot; For The Internet===&lt;br /&gt;
&lt;br /&gt;
Even if websites invest a lot of time and effort into securing their servers and user data, few sites take a more systematic approach to cybersecurity and view the massive numbers of compromised user machines as as &amp;quot;their&amp;quot; problem; they don&#039;t have any ownership over the fact that so many computers are running nasty malware and are thus compromised in important ways that can cause systemic harm to the Internet (like, say, when a site is taken offline in a Distributed Denial-of-Service attack; a partial list of such incidents is [http://en.wikipedia.org/wiki/Denial-of-service_attack#Incidents here]). However, there are some promising signs [http://bits.blogs.nytimes.com/2010/01/13/facebook-joins-with-mcafee-to-clean-up-malware-on-site/ this] may be [http://stopbadware.org/home/pr_01252010 changing].&lt;br /&gt;
&lt;br /&gt;
Perhaps these initiatives can go even further. What if a coalition of leading Internet sites were willing to share certain information about security threats with a third party organization (like [http://stopbadware.org/home/index StopBadware]), and the third-party would vet the information and then issue certain &amp;quot;Amber Alerts&amp;quot; that all the sites would be willing to publicize in some way? When there&#039;s a particularly egregious security hole in an [http://en.wikipedia.org/wiki/Internet_Explorer_6 old browser], for instance, if all the leading websites actively encouraged its users to patch it, that has the potential to do a lot of good.&lt;br /&gt;
&lt;br /&gt;
We initially proposed this solution as a unilateral move that individual sites could make - Google, say, could warn its users about the vulnerabilities of Internet Explorer 6. But we&#039;ve realize that if the recommendations are filtered through a reliable third-party, perhaps the companies won&#039;t be threatened by the embarrassment of having an &amp;quot;Amber Alert&amp;quot; put out. Sure, there would be negative consequences for a company, just as a company who undertakes a product recall generates bad publicity. But ultimate the hope is that companies will realize the net positive value of this transaction, and that consumers will look kindly on companies promoting a new level of honesty and transparency.&lt;br /&gt;
&lt;br /&gt;
====Good Cyber-Samaritans====&lt;br /&gt;
&lt;br /&gt;
An idea we discussed on January 19 that was related to the &amp;quot;Amber Alert&amp;quot; system for websites involves empowering educated users to help out their less computer-savvy friends and neighbors with computer security problems just...because. Perhaps there could be a network of young people who think security is important and who don&#039;t mind hanging around their local library for a few hours helping people update software and patching security holes. This solution becomes ever-more feasible as a greater proportion of users switches to laptop computers and as projects showing that people are willing to assist strangers for the sheer fun and satisfaction of the experience - from building an [http://www.wikipedia.org encyclopedia] to giving them a [http://www.couchsurfing.org couch to crash on] for free - flourish. Relying on people&#039;s good natures could be a new way to make progress on this problem.&lt;br /&gt;
&lt;br /&gt;
===Distress Password===&lt;br /&gt;
&lt;br /&gt;
This was an idea originally discussed at the Liberation Technologies Seminar in the Fall of 2009 and was expanded upon by the team.  Imagine if you have confidential information in your email (as most of us do) and you are captured by a hostile terrorist organization.  They demand your Facebook and Gmail passwords.  As of now, we only have one password: the real one.  But, what if we had a distress password that, if entered could:&lt;br /&gt;
&lt;br /&gt;
a) delete the account, or say it was &#039;temporarily suspended&#039;&lt;br /&gt;
b) show the email account, but only emails that you had marked as safe (or, in other words, only those which you hadn&#039;t filtered as &#039;private&#039;)&lt;br /&gt;
c) require to you call customer service due to &#039;unauthorized activity&#039;&lt;br /&gt;
&lt;br /&gt;
This could easily be implemented by any email service provider.  &lt;br /&gt;
&lt;br /&gt;
===Password Picture===&lt;br /&gt;
&lt;br /&gt;
The purpose of the password picture idea is to prevent against keystroke detectors on public computers gaining access to passwords.  This dual authentication system would require the typical typed-in password, as well as the user to select, from a series of pictures, the picture or pictures that match the category given at the time of signup (perhaps updated every 3 months).  It would work like this:&lt;br /&gt;
&lt;br /&gt;
Say, when creating an account on Gmail, Gmail gave me the category &#039;tree&#039; and &#039;car&#039;.  Here is what would happen when I went to log in:&lt;br /&gt;
&lt;br /&gt;
1) I&#039;d have to type my password&lt;br /&gt;
2) Then, from a series of 20 pictures, I would have to pick the one that is a tree.&lt;br /&gt;
3) Then, from a series of 20 pictures, I would have to pick the one that is a car. &lt;br /&gt;
&lt;br /&gt;
I&#039;m in!&lt;/div&gt;</summary>
		<author><name>Style</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cyberlaw_winter10/?title=Cybersecurity_Brainstorming&amp;diff=833</id>
		<title>Cybersecurity Brainstorming</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cyberlaw_winter10/?title=Cybersecurity_Brainstorming&amp;diff=833"/>
		<updated>2010-01-16T00:26:41Z</updated>

		<summary type="html">&lt;p&gt;Style: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This page reflects the brainstorming and discussion of the cybersecurity group in [http://en.wikipedia.org/wiki/Jonathan_Zittrain Jonathan Zittrain]&#039;s Cyberlaw: Difficult Problems Class.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;For the Mozilla-icon-privacy project see: [[Terms of Service Brainstorming]].&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=Problems to Tackle=&lt;br /&gt;
&lt;br /&gt;
Misaligned incentives have prevented industry, users, and government from solving many of the problems of cybersecurity. We&#039;re proposing three projects that will allow (power) users to increase the security of their data, as well as improve security for other people, and maybe even for the network as a whole. We may also be interested in working on the [[Terms of Service Brainstorming | Mozilla Privacy issue]]. &lt;br /&gt;
&lt;br /&gt;
==&amp;quot;Safeword&amp;quot;==&lt;br /&gt;
*&#039;&#039;All functionality should be inserted into the browser to appear as part of the various websites.&#039;&#039;&lt;br /&gt;
(1) Shows security level of user-selected password as it&#039;s typed in (for registration)&lt;br /&gt;
(2) If user chooses weak password, auto-fill will be turned off. User must manually type in all weak passwords &lt;br /&gt;
:Safeword will look for keystrokes and won&#039;t send the password to the website if it doesn&#039;t sense the appropriate keystrokes&lt;br /&gt;
(3) Refuse password if it&#039;s been used before (for a major/important/security-sensitive site)&lt;br /&gt;
:for security reasons, Safeword would only save the first 4 characters of each password (not the whole thing)&lt;br /&gt;
(4) Periodically prompt user to change password&lt;br /&gt;
:this would be a suggestion, not a requirement and users could set how often it should prompt&lt;br /&gt;
&lt;br /&gt;
Other Ideas:&lt;br /&gt;
*encrypted password storage within browser&lt;br /&gt;
*using recaptcha or pictures (esp game), etc as dual key for all passwords&lt;br /&gt;
*perhaps regulation requiring financial institutions to only accept strong or dual-key passwords&lt;br /&gt;
&lt;br /&gt;
==Mesh Network Vaccination==&lt;br /&gt;
Firefox plug-in used by the 5% of power users that can help patch the problems created by the larger base of security-ignorant or security-apathetic users. I made the analogy to tower defense at some point. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;For your edification, see [http://en.wikipedia.org/wiki/Tower_defense Tower Defense].&#039;&#039; &#039;&#039;[[User:Mfeld|Mfeld]] 05:18, 13 January 2010 (UTC)&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
==Stop Badware==&lt;br /&gt;
We propose a Firefox plug-in that would incorporate an improved Stop Badware database and automatically warn users when they attempt to access websites that are suspected of including malware or have been known to do so recently.  We also propose this is included in search engines.  While Firefox 3 and Google have recently implemented similar ideas, we would like to display more granular data (i.e., 99% of visitors to this site report no problems, 90% of visitors to that site), with better timing information, and automatically build in reporting of malware to the database.&lt;br /&gt;
&lt;br /&gt;
==Distress Password==&lt;br /&gt;
Have 2 passwords -- &lt;br /&gt;
:(1) secure password -- shows all emails, all data&lt;br /&gt;
:(2) distress password -- shows limited data (like limited profile), only showing safe data&lt;br /&gt;
&lt;br /&gt;
==Password Picture==&lt;br /&gt;
Have a dual key mode of authentication for various web services: one would be the typical password, and the second would be a series of pictures.  For example, when creating an account on a website for the first time, you would choose a password and choose keywords for pictures, like &amp;quot;animal&amp;quot; or &amp;quot;tree&amp;quot;.  Logging in would require you to enter a password as well as, from a series of pictures, choose your 1, 2, or 3 pictures that show your keyword.  This would prevent robots from being able to try and guess your password, and would also prevent keystroke detectors from being fully functional.&lt;br /&gt;
&lt;br /&gt;
=Presentational ideas=&lt;br /&gt;
*&amp;quot;This is your internet, this is your internet on botnet&amp;quot;&lt;br /&gt;
*Ham Sandwich metaphor acted out in reality&lt;br /&gt;
*Voiceover puppets a la JZ&#039;s [http://www.youtube.com/watch?v=NggzBHSXdCo video explanation of Herdict]&lt;br /&gt;
*PSA Announcement featuring Internationally Recognized Magician Michael Feldman&lt;br /&gt;
*Lessig-style keynote presentation (as part)&lt;br /&gt;
&lt;br /&gt;
Spot 1: Ham Sandwich (Live).&lt;br /&gt;
&lt;br /&gt;
Magic Michael is happily doing a magic trick. Suddenly, he makes a ham sandwich appear out of nowhere. He asks an audience member, &amp;quot;And now, who would like to eat this ham sandwich?&amp;quot; People in the audience (kids?) react angrily. One says, &amp;quot;But, where did that ham sandwich come from?&amp;quot;&lt;br /&gt;
&lt;br /&gt;
CUT TO Magic Michael, now sitting on a stool, talking to the camera: Everyone knows not to eat a mysterious ham sandwich that I make appear out of nowhere. But why do some people install software when they don&#039;t know where it came from? Hi, I&#039;m internationally-recognized magician Michael Feldman, and I&#039;m here to remind you how important it is to keep your computer safe. When in doubt about whether or not you should download and install a piece of software, just follow the ham sandwich rule; if it came from a stranger and you&#039;re not sure when or where it was made, don&#039;t install it - or eat it!&lt;br /&gt;
&lt;br /&gt;
(looks great -- I just want some more magic puns, like &amp;quot;if it were a rabbit sandwich, maybe that&#039;s ok&amp;quot; or &amp;quot;installing random programs isn&#039;t magic. it&#039;s stupid.&amp;quot;)&lt;br /&gt;
&lt;br /&gt;
End with &amp;quot;The More You Know&amp;quot; music and logo? (like at the end of this stupid clip: http://www.youtube.com/watch?v=3eazYHO3Hsg&amp;amp;feature=related).&lt;br /&gt;
&lt;br /&gt;
Spot 2: &lt;br /&gt;
Magic Michael is seated, looking directly at the camera. &amp;quot;Hi, i&#039;m internationally-recognized (and renowned) magician Michael Feldman. I can make many things disappear (hand gesture, and poorly patched together video making something disappear). But there&#039;s one thing that even I can&#039;t make disappear: the cybersecurity problem. (Michael attempts to make something symbolizing cybersecurity disappears, but fails). Remember, kids, installing random programs isn&#039;t magic. It&#039;s stupid.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Image:CyberSec1.jpg|thumb|120px|alt=Whiteboard Notes Part 1|Mesh Network Vaccination / Password Protection Ideas]]&lt;br /&gt;
[[Image:CyberSec2.jpg|thumb|120px|alt=Whiteboard Notes Part 2|Ideas for Incentivizing]]&lt;br /&gt;
[[Image:CyberSec3.jpg|thumb|120px|alt=Whiteboard Notes Part 3|Stop Badware Ideas]]&lt;br /&gt;
[[Image:Problems Solved.jpg|thumb|120px|alt=Whiteboard Notes Part 4|Problems Solved by &amp;quot;Safeword&amp;quot;]]&lt;br /&gt;
[[Image:Safeword Functionality.jpg|thumb|120px|alt=Whiteboard Notes Part 4|Functionality for &amp;quot;Safeword&amp;quot;]]&lt;/div&gt;</summary>
		<author><name>Style</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_9_Predictions&amp;diff=774</id>
		<title>Day 9 Predictions</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_9_Predictions&amp;diff=774"/>
		<updated>2010-01-14T07:43:38Z</updated>

		<summary type="html">&lt;p&gt;Style: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Here is a related youtube video, [http://www.youtube.com/watch?v=6IDNKhAIOww CouchSurfing: What one website reveals about the future of the net]. [[User:Yosuke|Yosuke]]&lt;br /&gt;
&lt;br /&gt;
I&#039;m interested in hearing about the identity verification system that Daniel mentioned at approx. 23:30 in the YouTube video.  How are they getting access to passport numbers and credit card numbers?  If it is that much better at identifying people, why hasn&#039;t eBay implemented something like this?&lt;/div&gt;</summary>
		<author><name>Style</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_8_Predictions&amp;diff=734</id>
		<title>Day 8 Predictions</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_8_Predictions&amp;diff=734"/>
		<updated>2010-01-14T01:27:46Z</updated>

		<summary type="html">&lt;p&gt;Style: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;For those who aren&#039;t familiar, here are [http://creativecommons.org/dmca/ Creative Commons&#039;] and [http://www.google.com/dmca.html Google&#039;s] explanations of DMCA Notice and Takedown Procedures, one example of Due Process online&lt;br /&gt;
&lt;br /&gt;
==Should there be Due Process Online==&lt;br /&gt;
It seems like there should be, though we can&#039;t predict where the folks from Google believe it should come from. On the one hand, you might think that Google is &amp;quot;just&amp;quot; a company, and their due process obligations are not greater than those of any other private entity who effects your life: i.e. send a letter to the complaint department and pray. At the entire other end of the spectrum, you might think that Google is such a critical point-of-control online that the government should have no problem regulating them in areas from copyright to even their handling of search results and their imposition of the death penalty. My guess is that Google believes itself to be in the former, &amp;quot;leave-us-alone&amp;quot; pile.&lt;br /&gt;
&lt;br /&gt;
It&#039;s great how the website with the article on the Google death penalty was filled with mostly internal links, which seems to be intended to raise its Google rank.&lt;br /&gt;
&lt;br /&gt;
As it is, Google and other service providers like facebook are a black box.  In the Death Penalty article it seemed that a site could be given the death penalty without even knowing it had done something wrong; theoretically a company could set up spam that attempts to increase the page rank of a competitor with the intention it gets the Google Death Penalty. Clearer guidelines are needed and more open and transparent procedures for resolving cases. Our guest is unlikely to be receptive to imposing additional procedure and transparency, given the extra burdens that would place on Google, but maybe an appeal to the &amp;quot;Don&#039;t be evil&amp;quot; side of the company would help?&lt;br /&gt;
&lt;br /&gt;
==Due Process Defaults==&lt;br /&gt;
&lt;br /&gt;
There are at least two default possibilities for due process of takedowns on the internet: (1) Due process afforded before takedown (default on), and (2) take down immediately upon request and afford due process to restore the content (default off). Google will probably take the stance that (2), default off, is a more appropriate standard for internet due process. Since internet content can do a great deal of harm in a very short period of time, it makes sense to take it down immediately (after someone has complained that it might be harmful information) and create a process by which the uploaded can ask that it be restored. That way the damage of offensive content is mitigated, but could not be unilaterally censored. (also, this process probably does the best job of limiting the liability of companies like Google, YouTube, etc). I think one of the biggest problem companies such as Google face is however that after summary proceedings, which in Europe can take more than 3 months after the lawsuit was filed, the procedure on the merits can take years and years (up to 6 or even more years), so it takes too much time until the case comes to an end (unless parties are willing to settle). Another problem are the huge damages (imposed on a daily basis in case of non-compliance) that are imposed very easily and run up very quickly. I would like to hear the thoughts of the guests on this.&lt;br /&gt;
&lt;br /&gt;
:The counter argument to the above is that this cripples the generatively of the internet. If anyone can request that content be taken down which web companies must comply with, it would be possible for anyone to (at least temporarily) gag the production of new content. A better compromise might be to require that the requester make some showing of who they are and how they will be harmed (at something resembling a probable cause standard) before web companies must comply with such a complaint.&lt;br /&gt;
:Due process is needed for the protection of the party against which actions to be taken, and in the interest of public notice. According to Facebook terms of service, an account will be disabled if it is found to repeatedly infringe other people&#039;s intellectual property rights. Here a due process is needed to disable an account on Facebook. How many times does &amp;quot;repeatedly&amp;quot; refer to? Who have the final say on this &amp;quot;infringement&amp;quot; of other people&#039;s intellectual property rights? Hope to hear more from our guest on their practice to deal with this, and how they balance between the alleged owner of the right and the one against whom the action to be taken.&lt;br /&gt;
&lt;br /&gt;
It would also be interesting to hear how different companies have complained and whether any of them have slayed the Giant - known as Google. Have any ever threatened back or been able to have some worthy leverage against Google?&lt;br /&gt;
&lt;br /&gt;
==Google and China==&lt;br /&gt;
Although today&#039;s class isn&#039;t about this topic, it&#039;s hard to believe it won&#039;t come up. It will be interesting to hear whether the Google guest will have a response to Jason&#039;s concern that Google disengaging with China will allow unscrupulous actors to dominate the world&#039;s biggest internet market, and that Google, even if it had to make compromises, could do more good than evil by working inside China.&lt;br /&gt;
:Yes, The voice of &amp;quot;Google in China&amp;quot; not &amp;quot;Google China&amp;quot; is around for a while. It will be interesting to hear how Google will do business in China if it finally decided to pull out. This will have a huge impact on not only the internet users in China, but also the resellers and strategic partners of Google China.&lt;br /&gt;
&lt;br /&gt;
:I think there is some connection between the Google-China news and today&#039;s topic.  From a macro perspective, what kind of due process should be given to Google (or any other type of Internet service provider) before the decision is made to force them to withdraw?  Today&#039;s speaker should have some good insights into Google&#039;s experiences with Turkey to might help us understand what the coming fight with China may look like. Another thing to consider with regard to today&#039;s topic is whether there should be (if any) due process afforded to China itself - by releasing the publicity statement, Google is essentially making wide allegations against (presumably) the Chinese Government - does this raise due process concerns? Was this the best or only way to handle it? It certainly got the world&#039;s attention, and I do find it doubtful that China would have responded in any other way.&lt;/div&gt;</summary>
		<author><name>Style</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_7_Thoughts&amp;diff=730</id>
		<title>Day 7 Thoughts</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_7_Thoughts&amp;diff=730"/>
		<updated>2010-01-14T01:10:42Z</updated>

		<summary type="html">&lt;p&gt;Style: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==ReputationDefender==&lt;br /&gt;
While I think some of the things ReputationDefender has done are admirable, I was troubled by the disclosure that the company has signed revenue-share agreements with information aggregators.  These companies are often quite controversial (see http://en.wikipedia.org/wiki/Intelius for example).  It seems like these revenue share deals could potentially set up the wrong incentives (even if signed with the best intentions), where ReputationDefender&#039;s profits are now aligned with profits of information aggregators.  I could envision a future where everyone needs to pay &amp;quot;protection money&amp;quot; to companies like Intelius (or intermediaries, like ReputationDefender) in order to preserve their privacy, and that seems like the wrong state to be in.  I can&#039;t help but wonder whether the solution here is more stringent regulation of information aggregators (mainly just requiring free and easy one-stop opt-out).  Consumers don&#039;t need to pay to sign up for the national do not call registry, and one could imagine a similar opt-out process for information aggregators.  It seems kind of perverse if people feel compelled to *pay* to opt out of things that they did not sign up for to begin with.&lt;br /&gt;
:I also wonder how sustainable this is as a business model. Reputation Defender can aggregate money from its clients and share that revenue with information aggregators, but wouldn&#039;t insurance companies be able to out spend them? It seems as if the primary purchasers of such information aggregation may be in better financial positions than any aggregator of individual concern about such things. Is it possible that ReputationDefender&#039;s market will one day compete with insurance companies and the like for annual revenue?  Or, what if a big player like Google (or a Google spin off) decides to enter this space and crush ReputationDefender before it even gets off the runway?  &lt;br /&gt;
&lt;br /&gt;
:I agree with the distaste with having to pay protection money, but it seems better to have the option than not to.  Regulation would be ideal, but would likely run up against powerful commercial interests.  See the power of the insurance industry in the health care debate.  Add advertisers and you&#039;re looking for trouble.&lt;br /&gt;
&lt;br /&gt;
==Lifelock==&lt;br /&gt;
&lt;br /&gt;
LifeLock is another consumer &amp;quot;reputation protection&amp;quot; company (more focused on identity fraud) with a pretty interesting business/marketing model.  http://en.wikipedia.org/wiki/LifeLock&lt;br /&gt;
: However LifeLock has had many many problems, discussed in this article from [http://www.wired.com/politics/security/commentary/securitymatters/2008/06/securitymatters_0612 Wired Magazine] including one of the [http://phoenix.bizjournals.com/phoenix/stories/2007/06/11/daily15.html co-founders] having been an identity thief himself, the CEO&#039;s identity has been stolen successfully a [http://www.google.com/search?sourceid=chrome&amp;amp;ie=UTF-8&amp;amp;q=lifelock+suit number of times], and there is currently a [http://www.forbes.com/2008/02/21/experian-lifelock-update-markets-equity-cx_md_0221-markets32.html pending suit] against the company claiming its business model isn&#039;t legal.&lt;br /&gt;
&lt;br /&gt;
: Yeah, LifeLock is definitely controversial.  Didn&#039;t mean to imply that it was &amp;quot;good&amp;quot;, just &amp;quot;interesting&amp;quot; :)&lt;br /&gt;
&lt;br /&gt;
==Opt-Out Programs==&lt;br /&gt;
&lt;br /&gt;
Incidentally I believe that CAN-SPAM requires that opt-out has to be free to the user.  CAN-SPAM failed for a lot of reasons, whereas the do-not-call registry has comparatively succeeded--would be interesting to discuss why.&lt;br /&gt;
&lt;br /&gt;
==Transfer of Ownership==&lt;br /&gt;
&lt;br /&gt;
What happens when formerly trustworthy companies get sold?  Should the data submitted by users be transferred?  This is a very real threat--Friendster and Spock were recently acquired (the latter by Intelius--see http://www.techcrunch.com/2009/04/29/spock-and-intelius-uh-oh/).  Mint.com was also acquired by Intuit, but imagine if they had been acquired by a telemarketing firmâ¦&lt;br /&gt;
&lt;br /&gt;
==Mozilla Privacy Icons==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;We have created an internal page on this wiki for [[Terms of Service Brainstorming|Brainstorming Ideas]] for this project&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
I&#039;m still not convinced that there is an actual problem here to solve (or rather, whether the problem is so severe as to require the hammer of a browser icon convention).  In some ways I feel like people have already voted with their widespread usage of sites like MySpace, Twitter, Facebook, and Google despite the lack of a privacy icon.&lt;br /&gt;
&lt;br /&gt;
It is worth noting that the icon-in-the-browser-to-signal-privacy already exists in one form today--the &amp;quot;lock&amp;quot; you see when performing credit card transactions over SSL.  It&#039;d be interesting to examine the origin of this convention.  I&#039;d argue that in this case there *was* an actual problem to solve (and that users probably would not submit credit card information without the lock, so that users and businesses had a strong incentive to come up with a convention--adding the lock increases conversion rates).&lt;/div&gt;</summary>
		<author><name>Style</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_7_Predictions&amp;diff=593</id>
		<title>Day 7 Predictions</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_7_Predictions&amp;diff=593"/>
		<updated>2010-01-12T22:49:03Z</updated>

		<summary type="html">&lt;p&gt;Style: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;In the spirit of today&#039;s issues, our collective &amp;quot;anonymous&amp;quot; predictions are set out below:&lt;br /&gt;
&lt;br /&gt;
== Reputation Defender ==&lt;br /&gt;
&lt;br /&gt;
First of all, congratulations to Reputation Defender for raising $8.65 million last year (announced today): &lt;br /&gt;
&lt;br /&gt;
http://www.techcrunch.com/2010/01/12/reputationdefender-kleiner-bessemer-8-65-million/&lt;br /&gt;
&lt;br /&gt;
Probably, Mr. Fertik will try to persuade us that Reputation Defender offers great advantages to improve our reputation (even promoted by Dr. Phil?!), and the service obviously has a lot of merit--assuming you have the ability to pay for it.  It gives people a great way to remove defamatory, or potentially defamatory, content in a way where it harms nobody and helps those who it should.   However, we hope that the students and guests will discuss whether these kinds of initiatives are just one bridge too far; is Reputation Defender a tool to defend or artificially improve one&#039;s reputation?  (And does it matter?)  &lt;br /&gt;
&lt;br /&gt;
:We&#039;d also like to hear about the tactics Reputation Defender uses to increase Google page ranks (MyEdge) in a way that makes sure it doesn&#039;t get the Google Death Penalty, as well as what technological or legal tools Reputation Defender would add if it could.&lt;br /&gt;
&lt;br /&gt;
Really interesting point taken from the Tech Crunch blog linked above: &amp;quot;It is still early days and there is a lot of work ahead. Perhaps ReputationDefenderâs biggest weakness is that it does not have a full view into Facebook, where only public comments or photos show up. If somebody is going to badmouth you online, chances are it will be on Facebook.&amp;quot;  Would be interested how they are planning to deal with this.  &lt;br /&gt;
&lt;br /&gt;
== Anonymity ==&lt;br /&gt;
&lt;br /&gt;
We hope our guests will not be too narrowly focused on the need to ensure accountability through identification and attribution.  The democratic benefits of leaving an option open for anonymous contribution is important also, to help encourage frank speech and content.  It seems to me that this would be particularly relevant in the US jurisdiction, where strong First Amendment principles are unlike what we see pretty much anywhere else in the world (which also raises the discrete sub-issue of how we can reconcile different international views of what an appropriate level of privacy protection might be).  Like Dispute Finder discussed yesterday - their emphasis is not to resolve an issue in dispute, but to highlight for the public that there is a conflict, which cannot exist without vocalization of many different points of view, no matter how unpopular.&lt;br /&gt;
&lt;br /&gt;
In terms of anonymity on the Internet in the user&#039;s control, I think services such as Tor do quite a good job.  There still are weaknesses associated with the exit nodes of Tor allowing hackers to access user names and passwords due to the lack of encryption technologies available.&lt;br /&gt;
&lt;br /&gt;
In light of the well-publicized events surrounding Shi Tao and Wang Xiaoning, Ebele may express Yahoo&#039;s recent concerns with anonymity and its sometimes drastic importance outside the U.S., and the difficulties of working with governments with completely different expectations that do not match with our First Amendement concerns.&lt;br /&gt;
&lt;br /&gt;
== Mozilla and Privacy ==&lt;br /&gt;
&lt;br /&gt;
Besides this, Ryan and the people of Mozilla will show the great advantages of understandable privacy policies in the form of icons. This might encourage people to actually check whether the website uphold certain privacy standards.  Even more importantly, it would allow users, in an easy way, to realize the diverse range of privacy policies (and amount of information released to third parties) that various add-ons have (the Location Aware feature of Firefox version 3.5, for example, can tap into a wide range of information). The advantages of easy-to-understand privacy icons are straightforward, although we might wonder whether users will have a collective voice strong enough to cause change, or whether users will really stop visiting nytimes.com if it has certain unpleasant policies.  Beyond that question, the guests likely to justify why modifications to the browsers that we use are a necessary or desired way to implement them.&lt;br /&gt;
&lt;br /&gt;
As we discussed yesterday, the people at the Mozilla foundation can take any idea to improve the internet from a fanciful theory to a  concrete reality very quickly.  It seems likely, then, that they are deluged with causes to adopt and browser functionality to build in.  It would be interesting to hear how they decided what to focus on, and why privacy rose to the top of the list. Mozilla has, in effect, the ability to bundle any plug-in that its desire with Firefox by making it core browser functionality. The guests are likely to address whether there is a happy medium between bundling functionality with Firefox and relying entirely on users tracking down and installing plug-ins (like DisputeFinder requires). Is there a possibility of a central plug-in repository that can allow useful plug-ins to take off more easily? Can the decision of which plug-ins/concepts could be &amp;quot;promoted&amp;quot; to core browser functionality be crowdsourced somehow?&lt;/div&gt;</summary>
		<author><name>Style</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_7_Predictions&amp;diff=591</id>
		<title>Day 7 Predictions</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_7_Predictions&amp;diff=591"/>
		<updated>2010-01-12T22:45:29Z</updated>

		<summary type="html">&lt;p&gt;Style: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;In the spirit of today&#039;s issues, our collective anonymous predictions are set out below:&lt;br /&gt;
&lt;br /&gt;
== Reputation Defender ==&lt;br /&gt;
&lt;br /&gt;
First of all, congratulations to Reputation Defender for raising $8.65 million last year (announced today): &lt;br /&gt;
&lt;br /&gt;
http://www.techcrunch.com/2010/01/12/reputationdefender-kleiner-bessemer-8-65-million/&lt;br /&gt;
&lt;br /&gt;
Probably, Mr. Fertik will try to persuade us that Reputation Defender offers great advantages to improve our reputation (even promoted by Dr. Phil?!), and the service obviously has a lot of merit--assuming you have the ability to pay for it.  It gives people a great way to remove defamatory, or potentially defamatory, content in a way where it harms nobody and helps those who it should.   However, we hope that the students and guests will discuss whether these kinds of initiatives are just one bridge too far; is Reputation Defender a tool to defend or artificially improve one&#039;s reputation?  (And does it matter?)  &lt;br /&gt;
&lt;br /&gt;
:We&#039;d also like to hear about the tactics Reputation Defender uses to increase Google page ranks (MyEdge) in a way that makes sure it doesn&#039;t get the Google Death Penalty, as well as what technological or legal tools Reputation Defender would add if it could.&lt;br /&gt;
&lt;br /&gt;
== Anonymity ==&lt;br /&gt;
&lt;br /&gt;
We hope our guests will not be too narrowly focused on the need to ensure accountability through identification and attribution.  The democratic benefits of leaving an option open for anonymous contribution is important also, to help encourage frank speech and content.  It seems to me that this would be particularly relevant in the US jurisdiction, where strong First Amendment principles are unlike what we see pretty much anywhere else in the world (which also raises the discrete sub-issue of how we can reconcile different international views of what an appropriate level of privacy protection might be).  Like Dispute Finder discussed yesterday - their emphasis is not to resolve an issue in dispute, but to highlight for the public that there is a conflict, which cannot exist without vocalization of many different points of view, no matter how unpopular.&lt;br /&gt;
&lt;br /&gt;
In terms of anonymity on the Internet in the user&#039;s control, I think services such as Tor do quite a good job.  There still are weaknesses associated with the exit nodes of Tor allowing hackers to access user names and passwords due to the lack of encryption technologies available.&lt;br /&gt;
&lt;br /&gt;
In light of the well-publicized events surrounding Shi Tao and Wang Xiaoning, Ebele may express Yahoo&#039;s recent concerns with anonymity and its sometimes drastic importance outside the U.S., and the difficulties of working with governments with completely different expectations that do not match with our First Amendement concerns.&lt;br /&gt;
&lt;br /&gt;
== Mozilla and Privacy ==&lt;br /&gt;
&lt;br /&gt;
Besides this, Ryan and the people of Mozilla will show the great advantages of understandable privacy policies in the form of icons. This might encourage people to actually check whether the website uphold certain privacy standards.  Even more importantly, it would allow users, in an easy way, to realize the diverse range of privacy policies (and amount of information released to third parties) that various add-ons have (the Location Aware feature of Firefox version 3.5, for example, can tap into a wide range of information). The advantages of easy-to-understand privacy icons are straightforward, although we might wonder whether users will have a collective voice strong enough to cause change, or whether users will really stop visiting nytimes.com if it has certain unpleasant policies.  Beyond that question, the guests likely to justify why modifications to the browsers that we use are a necessary or desired way to implement them.&lt;br /&gt;
&lt;br /&gt;
As we discussed yesterday, the people at the Mozilla foundation can take any idea to improve the internet from a fanciful theory to a  concrete reality very quickly.  It seems likely, then, that they are deluged with causes to adopt and browser functionality to build in.  It would be interesting to hear how they decided what to focus on, and why privacy rose to the top of the list. Mozilla has, in effect, the ability to bundle any plug-in that its desire with Firefox by making it core browser functionality. The guests are likely to address whether there is a happy medium between bundling functionality with Firefox and relying entirely on users tracking down and installing plug-ins (like DisputeFinder requires). Is there a possibility of a central plug-in repository that can allow useful plug-ins to take off more easily? Can the decision of which plug-ins/concepts could be &amp;quot;promoted&amp;quot; to core browser functionality be crowdsourced somehow?&lt;/div&gt;</summary>
		<author><name>Style</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_7_Predictions&amp;diff=578</id>
		<title>Day 7 Predictions</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_7_Predictions&amp;diff=578"/>
		<updated>2010-01-12T22:09:48Z</updated>

		<summary type="html">&lt;p&gt;Style: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;In the spirit of today&#039;s issues, our collective anonymous predictions are set out below:&lt;br /&gt;
&lt;br /&gt;
On the issue of online defamation, I hope our guests will not be too narrowly focused on the need to ensure accountability through identification and attribution.  The democratic benefits of leaving an option open for anonymous contribution is important also, to help encourage frank speech and content.  It seems to me that this would be particularly relevant in the US jurisdiction, where strong First Amendment principles are unlike what we see pretty much anywhere else in the world (which also raises the discrete sub-issue of how we can reconcile different international views of what an appropriate level of privacy protection might be).  Like Dispute Finder discussed yesterday - their emphasis is not to resolve an issue in dispute, but to highlight for the public that there is a conflict, which cannot exist without vocalization of many different points of view, no matter how unpopular.&lt;br /&gt;
&lt;br /&gt;
Probably, Mr. Fertik will try to persuade us that Reputation Defender offers great advantages to improve our reputation (even promoted by Dr. Phil?!). However, I hope that the students and guests will discuss that these kinds of initiatives are just one bridge too far. Is reputation defender a tool to defend or artificially improve your reputation?&lt;br /&gt;
&lt;br /&gt;
There are, however, a lot of merits behind services like Reputation Defender.  Many people believe that Reputation Defender is one of the best things that has happened to the Internet (assuming, of course, you have the ability to pay for it).  It gives people a great way to remove defamatory, or potentially defamatory, content in a way where it harms nobody and helps those who it should.  I&#039;m really interested in the tactics Reputation Defender uses to increase Google page ranks (MyEdge) in a way that makes sure it doesn&#039;t get the Google Death Penalty.  &lt;br /&gt;
&lt;br /&gt;
In terms of anonymity on the Internet in the user&#039;s control, I think services such as Tor do quite a good job.  There still are weaknesses associated with the exit nodes of Tor allowing hackers to access user names and passwords due to the lack of encryption technologies available.    &lt;br /&gt;
&lt;br /&gt;
Besides this, Ryan and the people of Mozilla will show the great advantages of understandable privacy policies in the form of icons. This might encourage people to actually check whether the website uphold certain privacy standards.  Even more importantly, it would allow users, in an easy way, to realize the diverse range of privacy policies (and amount of information released to third parties) that various add-ons have (the Location Aware feature of Firefox version 3.5, for example, can tap into a wide range of information).  &lt;br /&gt;
&lt;br /&gt;
As we discussed yesterday, the people at the Mozilla foundation can take any idea to improve the internet from a fanciful theory to a  concrete reality very quickly.  It seems likely, then, that they are deluged with causes to adopt and browser functionality to build in.  It would be interesting to hear how they decided what to focus on, and why privacy rose to the top of the list.&lt;/div&gt;</summary>
		<author><name>Style</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_6_Predictions&amp;diff=547</id>
		<title>Day 6 Predictions</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_6_Predictions&amp;diff=547"/>
		<updated>2010-01-12T02:35:13Z</updated>

		<summary type="html">&lt;p&gt;Style: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Daniel: Our guests will probably discuss at length the challenges that Dispute Finder and most web-based cooperative tools bump into while attempting to harness input from virtual crowds. I guess they will talk about Dispute Finderâs design difficulties, such as costs and trade-offs (between precision and recall, between user-friendliness and number / quality of features, etc). Theyâll most likely also summon stories from the interviews discussed in the document we received, perhaps to illustrate content-layer problems with measurement of &amp;quot;information sources reliability&amp;quot;; usersâ misunderstandings / trouble with logic operations; and group biases.&lt;br /&gt;
I would love to hear their views on the [http://courses.ischool.berkeley.edu/i256/f09/lectures/RobEnnalsGuestLecture.ppt proposed use of Turks] to improve the database of disputed claims and arguments, as well as on the current biases of the disputed facts / arguments presently listed by the software.&lt;br /&gt;
&lt;br /&gt;
:Jason: I predict that there will be a good deal of discussion of what Daniel calls the &amp;quot;user-friendliness&amp;quot; aspect of these tools - and I hope there is, because it&#039;s critical. Specifically, what is the necessary ratio between DisputeFinder or Herdict &amp;quot;passive users&amp;quot; and &amp;quot;active reporters&amp;quot; to make a project successful? I say this because both Herdict and DisputeFinder look somewhat sparsely-populated for them to be maximally-useful right now. For example, Herdict is [http://www.herdict.org/web/explore/country/CN;jsessionid=4A2D95D3EB7A8F96B073DE77D3654D53 reporting] that 2 Chinese users have reported YouTube as inaccessible. How do I interpret that? What percent of people who might know about and like Herdict in China are reporting back to Herdict? We know that Wikipedia is successful in spite of the fact that only a very small portion of readers become really regular editors - but Wikipedia is also one of the most visited sites in the world. I hope we discuss what strategies these organizations are employing to build participation for these more niche offerings. [[User:Jharrow|Jharrow]] 18:20, 11 January 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
:Reuben: When Daniel talks about the challenges of web-based cooperative tools, my first thought is about the challenge of a achieving a critical mass.  I poked around with Dispute Finder for just over an hour this morning and during the entirety of my browsing the New York Times, Washington Post, Miami Herald, and Slate I only came across one disputed claim.  No offense to America&#039;s news media, but my guess is that what I read is more disputed than that, but that there just aren&#039;t enough people trolling the news sites and adding claims to the dispute finder database for the service to actually be that helpful yet.  Jason&#039;s point about passive users versus active reporters is important.  I too would like to hear about how to reach a critical mass and how many active users are needed in order to have a useful service.  I&#039;d also like to hear about the potential for users to participate in a more passive manner - notwithstanding the privacy issues, if Herdict could just monitor my browsing and automatically send a report whenever I come across an inaccessible website, something akin to a Last.fm for my click stream, the data would seem to be much more complete than simply recording whatever I choose to report.  Never underestimate the laziness of the average person.  My prediction is that our guests acknowledge the shortcomings in their current offerings while remaining optimistic about the possibilities of community based technology. [[User:ReubRodriguez|ReubRodriguez]] 18:49, 11 January 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
::Ramesh: I agree with Reuben on the usefulness of Dispute Finder and Herdict. While Wikipedia (and Yelp, and a few other sites) show that sometimes, you can get useful content for free, that&#039;s not always the case. DisputeFinder didn&#039;t find many disputes when I did my regular scan of news websites, even when reading articles on topics like medical marijuana and same-sex marriage. It seems like applications like DisputeFinder and Herdict would be better if they were more automated -- if DisputeFinder automatically attached itself to controversial terms, and especially, as Reuben suggested, if Herdict was not based on self-reporting. &lt;br /&gt;
&lt;br /&gt;
:: Franny: I agree that a threshold level of dedicated trusted users (see Vicki&#039;s comments below) resolves many problems.  I hope our guests will discuss the strategies used by DisputeFinder, or any other website initiatives dependent on a large and broad variety of user input: (1) to attract that user base; and (2) to cope during the interim period while they continue to try to attract that user base.  For example, I wonder to what extent DisputeFinder has considered building in redundancy as a means of increasing the accuracy of its results (to borrow a strategy from CrowdFlower), or perhaps some combination of automation and redundancy.&lt;br /&gt;
&lt;br /&gt;
::Andrew: I hope the discussion of how to achieve critical mass focuses as much on instilling/spreading an ethos as it does on ways to automate the DF system. Tools don&#039;t work without the accompanying human motivation: the wiki architecture is awesome, but (see our Predictions pages) they don&#039;t necessitate anything about a page&#039;s structure, and that&#039;s where the Wikipedian ethos steps in.  No matter how passive DF/Herdict eventually allow their users to be, those users will (probably) still have to take the first step of registering, installing the plug-in etc. To do that, they have to be persuaded of the importance of the problem the tools are meant to address. Until the supposed echo chamber, &amp;quot;daily me&amp;quot; effect of Internet discourse becomes a mainstream concern, DF will not be a mainstream tool.&lt;br /&gt;
&lt;br /&gt;
::Sheel: I agree that critical mass is a huge issue, but I think validity is more of an issue; Reuben&#039;s description of his searches on the NY Times infer that many statements that most of us would claim to be disputed are simply not being caught by the program.  I think DisputeFinder, while trying to make its technology stronger, should focus on instituting some sort of citations for all the information it crawls.  In other words, whether the statement is &#039;disputed&#039; or not, the plugin should (perhaps in the form of clickable footnotes), find citations for them; these can be links to &#039;valid&#039; websites, scientific papers, press releases, etc.  I&#039;d be interested in asking whether DisputeFinder thinks it could move into the citation space and expand its scope. [[User:Style|Style]] 02:35, 12 January 2010 (UTC) &lt;br /&gt;
&lt;br /&gt;
:Tyler: I completely agree with above thoughts about Herdict and DisputeFinder needing to collect a critical mass of users before becoming useful. This seems to echo the idea that wikipedia was not useful for its first several years because it did not possess a critical mass of articles. However, I think there are some differences because individual pieces of wikipedia could become useful before wikipedia as a whole in that individual articles could become independantly useful before wikipedia became as comprehensive as it is today. I don&#039;t see that Herdict or DisputeFinder have the same capability to be useful while scaling because they require users to explicitly decide to install plugins and begin using their services before any benefit can be gained by that user. Wikipedia was able to gradually grow in prominence as users occasionally found information on wikipedia that they wanted through web searches. I am wondering if Herdict or DisputeFinder can take advantage of automated solutions to increase their seemingly as-yet sparsely populated databases? For example, could web crawling robots be used to identify at least some inaccesible sites with the expectation that this list could then be pruned by users rather than expecting it to materialize entirely by user submissions? Could DisputeFinder use a web crawling robot, in conjunction with sophisticated text parsers to begin identifying at least some topics that clearly involve dispute? I expect and hope that the guests will discuss some strategies for increasing the datasets of their projects to the point that they can obtain their critical mass of users and data more quickly. [[User:TylerLacey|TylerLacey]] 19:49, 11 January 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
::Michael: In terms of achieving critical mass for utility, herdict seems to have an additional challenge to wikipedia and DisputeFinder. When users make contributions to wikipedia or DisputeFinder, the information they provide remains useful indefinitely (for the most part). Herdict, on the other hand requires constant updating. This is entirely possible (as twitter and facebook demonstrate), but it reflects an additional challenge. I would be curious to hear if there is any data to determine what the different requirements of such different sites would be. [[User:Mfeld|Mfeld]] 23:19, 11 January 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
:: Daniel: Tyler has a great point here, so maybe we should ask if the Dispute Finder team has thought of an interesting dispute to explore well enough in terms of paraphrases / arguments, so that users could experience the full potential of the software and then be lured into becoming frequent contributors. [[User:Darbix|darbix]] 01:22, 12 January 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
Emily: &lt;br /&gt;
Dispute Finder bears an inherent flaw: individuals, not algorithms, decide whom and what to trust for information. Consider the watch on your wrist. If your watch starts to get the time wrong, you might try to fix the watch. You hope and pray your watch starts giving you accurate, dependable information because you like your watch. You might even love your watch. But, if it continues to betray your trust, and the people in your trusted circle insist your watch is wrong, you give up. You decide to trust a new watch, but your new watch will probably be reminiscent of your old watch with respect to personal taste, experience, and preferences. Most people are intuitive enough (though they donât necessarily convert insights into complex conclusions about source x versus source y) to know that 120 seconds of live, relatively unedited sound on Fox News Live or MSNBC Dayside is less likely to contain factually accurate information â even if relatively unimportant, like the location of a fire, or the total number of casualties in a mass shootingâ than a compulsively edited, fact-checked tome in the Sunday NY Times magazine, the Economist, or the New Yorker. &lt;br /&gt;
&lt;br /&gt;
Article 3.5 of the Dispute Finder document, âDetermining Trustworthy Sources,â seems a bit absurd. It actually acknowledges the marketability challenges of its own software: âUnfortunatelyâ¦the sites people actually trust are often those that share the personâs own point of view.â So, again, what is this software and what, really, is the point? Segway into âCross-cutting themes.â Save the world. How? Is Dispute Finder intended to help people sue other people for libel? Richard Jewel (now deceased) had a reasonably compelling case. Thatâs probably why he successfully sued (for libel) every organization, from CNN, to NBC, to the NY Post. All settled. He collected from each of them. But Richard Jewel didnât need help from Dispute Finder. Richard Jewel had a case. &lt;br /&gt;
&lt;br /&gt;
Cross-cutting themes: âChange the technology, save the world.â Okay, why not? Isnât there something else smart people at Intel and UC Berkeley could be doing to make the world better? Last November, the New York Times produced an alarming story [http://www.nytimes.com/2009/11/29/us/29foodstamps.html] about the food stamp program in America(ânow expanding at a pace of about 20,000 people a day.â) Also no shortage of children in custody. Last December, the New York Times obtained â and reported on [http://www.nytimes.com/2009/12/14/nyregion/14juvenile.html?_r=1&amp;amp;scp=1&amp;amp;sq=new%20york%20family%20court%20juvenile%20department%20of%20justice%20youth&amp;amp;st=cse]â a âconfidential draft reportâ prepared by a task force appointed by NY gov David Paterson: âNew York Stateâs current approach fails the young people who are drawn into the system, the public whose safety it is intended to protect, and the principles of good governance that demand effective use of scarce state resources.â Story also says the situation was so bad that the DOJ, at one point, was threatening to âtake over.â &lt;br /&gt;
&lt;br /&gt;
So, if Intel is interested in contributing, how about addressing real problemsâhelping real peopleâ that could affect real, collective societal change and improvement? Children and education seem like obvious places to start. Basics like hardware and mentors could go a long way. Children in poverty struggle with range of issues, including asthma, low self-esteem, obesity, and depression. Consider children in places like the South Bronx (Jonathan Kozolâs children [http://www.amazon.com/Amazing-Grace-Children-Conscience-Nation/dp/0060976977]): allocation of resources in places like this (and/or lower-middle class communities), especially from companies like Intel, could change lives; give voices to people from whom we do not often hear. &lt;br /&gt;
&lt;br /&gt;
Interested to hear thoughts on Internet privacy, though I&#039;m not sure adults have an expectation of privacy anywhere [http://gawker.com/5444885/facebooks-mark-zuckerberg-on-your-erased-privacy-these-are-the-social-norms-now] on the Internet. If you want privacy, don&#039;t put yourself on the Internet. Finally, on the subject of online harassment, if we accept that the Internet is a public place, to what extent is it acceptable to regulate online communication, including but not limited to comments deemed &#039;offensive&#039; on blogs?&lt;br /&gt;
&lt;br /&gt;
Predictions. Guests will be nice. Class will be nice. Hope to hear more about Dispute Finder&#039;s business model.&lt;br /&gt;
&lt;br /&gt;
Tyler: I would like an explanation for why the contributor of a disputed claim on DisputeFinder needs to provide a link to an article that illustrates the opposing point of view. If there are no article, isn&#039;t it still valuable to identify a claim as disputed, especially since this could break DisputeFinder&#039;s dataset building-process into two parts? I could enter a disputed claim without a link to another source and then another user, once alerted to the potential dispute could track down and enter the article. I see the argument that an issue is not actually in dispute if there is no contradictory reports of it, but I wonder if an entry into DisputeFinder should be enough to create a &amp;quot;dispute&amp;quot;, rather than requiring a link. I agree that even a blog post outlining the opposing point of view would be more helpful than a &amp;quot;dispute&amp;quot; without any link, but I&#039;m not sure that it should be a requirement.  Today I entered a disputed claim as &amp;quot;Works prepared by amazon mechanical turkers are considered works for hire under the United States Copyright Act&amp;quot; to see if DisputeFinder would highlight portions of our wiki (which does not currently have any disputed claims, according to DisputeFinder) but I was stalled when it asked for a link to a web location outlining this dispute. Should I have entered the page on this wiki where we discuss the issue? I hope that the guests discuss this aspect of the DisputeFinder process. [[Special:Contributions/68.65.169.179|68.65.169.179]] 20:11, 11 January 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
:Tyler: Another question that came up during my lunchtime discussion of DisputeFinder with some of our classmates: is there a practical way that DisputeFinder could leverage the existing collection of topics that wikipedia has flagged as a &amp;quot;point of view&amp;quot; or &amp;quot;non-neutral&amp;quot; to boost DisputeFinder&#039;s database of disputes?&lt;br /&gt;
&lt;br /&gt;
: Elisabeth:  Actually, I tend to think the need to cite an article is a useful safeguard.  It mirrors Wikipedia&#039;s rule that contributors can&#039;t do original research, and I think it exists for the same reason: to keep spammer-activists from simply flinging their views into these trusted systems.  It&#039;s just to easy to go around labeling hundreds of things as disputed.  Now, you could just go write a wiki on Amazon Mechanical Turk and then cite to it on dispute finder, much as anyone can publish an article on SSRN and then write a Wikipedia page, but it does provide some measure of protection (it stopped Tyler).  One alternative solution is for DisputeFinder to flag in a lighter color, or a different color, claims that are marked disputed but have no article support.&lt;br /&gt;
&lt;br /&gt;
Victoria: I completely agree with the former point that DisputeFinder&#039;s success is dependent on gaining a critical mass of end users. In addition to the need for more users, I think the platform is very trusting of the end users themselves. DisputeFinder allows for a lot of users to subjectively claim anything is disputed even when it begins to reach the absurd. One EscapistMagazine.com posted in June 2009, that the following topics were included on the disputed list &amp;quot;The 2009 Iran Presidential election was rigged,&amp;quot; &amp;quot;&amp;quot; and &amp;quot;Recycling is good for the environment,&amp;quot;  &amp;quot;2Pac is dead,&amp;quot; &amp;quot;Dick Cheney is a robot&amp;quot; and &amp;quot;Italians look good.&amp;quot; Although theoretically the idea of a marketplace of ideas works - without the appropriate robust marketplace DisputeFinder becomes a caricature of the truth-seeking function of free speech.&lt;br /&gt;
&lt;br /&gt;
:Michael: I am interested to hear the speakers from DisputeFinder describe why they believe the simple knowledge of a dispute is socially valuable. The extent to which a statement is disputed seems like it would be more valuable. I&#039;d be interested to hear if our speakers expect to include a scale of dispute to their software, such as that used in Herdict (the different colored sheep).&lt;br /&gt;
:I predict that DisputeFinder will view one of its most difficult challenges to be determining the trustworthiness of sources. Unlike CrowdFlower, DisputeFinder may not be able to simply use agreement as an accurate rubric for which user-supplied links are trustworthy and which are spam. Since the nature of the site is to highlight disagreement, it doesn&#039;t seem possible to use user agreement as the benchmark of useful data for their service. I would be interested to hear what DisputeFinder uses as its criteria for determining which data is reliable (meaning non-spam). [[User:Mfeld|Mfeld]] 23:39, 11 January 2010 (UTC)&lt;br /&gt;
:: Elisabeth: I&#039;m not sure why a crowd-voting system isn&#039;t appropriate--after all, people on both sides of a given debate can vote up sources they consider most trustworthy--but I&#039;d be interested to hear how our speakers think it has worked.  &lt;br /&gt;
&lt;br /&gt;
Juan: I&#039;m interested in hearing their thoughts on the collection of disputed claims. As the material mentioned, most people who were interviewed are interested in applying Dispute Finder to particular areas that affect them. Thus, how will they collect data for areas not that popular or useful to most people, especially there are no other incentives to encourage claim creation. I guess building up community as wikipedia or herdict did might be one solution. The question is how this community can be built up. Also, I kind of feel Dispute Finder overlaps with the search services provided by Google and other search engines. If people are interested in one topic, they can always use Google or other search services to find the corroborations or objections on it. By determining trustworthy resources, can I say Dispute Finder sort of limited the available resources to people? To me, &amp;quot;trustworthy resources&amp;quot; is more like a subjective concept, everyone can has his/her own trustworthy resources. Is there a need to have a website telling us which resource is trustworthy, especially the site itself said it is a difficult tradeoff to determine the trustworthy resources.&lt;br /&gt;
&lt;br /&gt;
Sharona: I totally agree with everyone&#039;s comments about the lack of a critical mass, and I would be curious to hear how they think they could theoretically gain one. Would people actually be drawn to this the way they are to edit wikipedia pages? Is it simply a matter of a marketing strategy? Another question I had while reading the website and the other document was regarding the phrase &amp;quot;trusted source.&amp;quot; Who defines that? The users? What if people start claiming that what DisputeFinder may deem &amp;quot;unreliable&amp;quot; is a trusted source in their view? Who will stop them, and will that be antithetical to DisputeFinder&#039;s ethos?&lt;br /&gt;
&lt;br /&gt;
Elisabeth:  looking at all of our readings together--on Dispute Finder, new.net, and Herdict--makes me think about how we&#039;re creating an increasingly atomized web, where users have remarkably different experiences in the Internet space.  It&#039;s not just that people are accessing different content.  Some people are passively consuming stories from CNN, others are carefully sculpting an information diet from RSS feeders and DisputeFinder trusted sources, and still others are contributing to all different kinds of tasks, from tracking filtering around the world to working on SETI.  Even &amp;quot;contribution&amp;quot; work can be active or passively happening in the background (Wikipedia is active; SETI is background, and DisputeFinder and Herdict are active now but could be passive if some of the tech suggestions above are implemented).  Extensions like Readability and the popularity of mobile phone browsers make the web look totally different for different users, and if new.net takes off, it won&#039;t even be interoperable between ISPs!  The question of &amp;quot;how we interact with the internet&amp;quot; thus will become even more complex as the user experience splinters even further.  And so (dragging this mediation back to class), I would like to hear how Herdict and DisputeFinder see their audiences.  Is the vision global acceptance?  Or is it a critical mass large enough to get the job done--to identify most blocked sites and most disputes claims--and specialized use only by those who are particularly interested in the topic?&lt;br /&gt;
&lt;br /&gt;
: Elisabeth: and one theme that connects all of these services is the need for active users.  How do we foster a culture in which people think they have a responsibility to contribute to the web (beyond even contributing pure content), instead of just using it?&lt;/div&gt;</summary>
		<author><name>Style</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_5_Predictions&amp;diff=401</id>
		<title>Day 5 Predictions</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_5_Predictions&amp;diff=401"/>
		<updated>2010-01-08T07:48:19Z</updated>

		<summary type="html">&lt;p&gt;Style: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Victoria: My prediction is that the speakers are going to be extolling the virtues of Wikipedia and explaining that although the site has gone under some transformations it is still a vibrant force. I would concede that I think it is. Most people I know still immediately turn to Wikipedia for a quick run down of a topic or an answer to a quick question. However, as time moves on the site is becoming less innovative and more standard. I would like to ask them about their understanding and personal experiences in trying to keep Wikipedia young. Moreover, having read that 85% of the contributors to Wikipedia are male I&#039;d specifically love to ask Phoebe whether she feels that the articles are written from the male gaze and lack the other gender&#039;s perspective.&lt;br /&gt;
&lt;br /&gt;
:: Sharona: Like Vickie, I was also struck by the statistics on the demographic breakdown, and I would love to hear their thoughts on whether they feel wikipedia really does represent a wide range of views, or more specifically (especially in the US) that of a white male. Another thing I think they will likely discuss - and probably not have a good answer for - is the question of privacy and defamation on wikipedia and other wikimedia projects. Can, or should, the website and/or its users or editors be held accountable if allegedly defamatory posts are not removed? Who makes that call? And what standards are used? It seems to me that there&#039;s no easy answer to this: while they may not run into strictly legal issues, it could definitely affect reader&#039;s trust in the information or fear that they too are vulnerable. &lt;br /&gt;
&lt;br /&gt;
Bruno: I expect our guests to focus their comments on the strategies Wikipedia is adopting to address two of what seems to be the main problems of the project: (i) quality/accuracy of its articles, and (ii) issues concerning vandalism. After reading the materials it strikes me that Wikipedia is not worried about increasing its user base. The increasing amount of rules, the hostility of veteran users to newbies and the efforts to attract more scientists to participate in the project suggest that in fact they would be interested in less, but more qualified participation. Just like the attitude of our guest from CrowdFlower, perhaps a sort of procrastination to address a problem that is not yet so concrete might be operating here: with over 40 thousand contributors it&#039;s not clear when more means actually less.&lt;br /&gt;
&lt;br /&gt;
:: Sheel: I&#039;d be interested in hearing Wikimedia&#039;s reaction to this: what if people started using CrowdFlower or MechanicalTurk, if they don&#039;t already, to pay people 10 cents or so to go edit Wikipedia pages?  I know they weren&#039;t okay with MyWikiBiz, but this is much more under the radar.  Finally, I&#039;d like to hear where the debate is on inclusionists v. exclusionists (meaning those who want to produce the &#039;integrity&#039; of the encyclopedia and shy away from what may be deemed as frivolous by some portion of editors).  My guess is that there is still no concrete answer---if enough editors are passionate about editing/creating a new page, then it&#039;ll stay.&lt;/div&gt;</summary>
		<author><name>Style</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_5_Predictions&amp;diff=400</id>
		<title>Day 5 Predictions</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_5_Predictions&amp;diff=400"/>
		<updated>2010-01-08T07:47:47Z</updated>

		<summary type="html">&lt;p&gt;Style: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Victoria: My prediction is that the speakers are going to be extolling the virtues of Wikipedia and explaining that although the site has gone under some transformations it is still a vibrant force. I would concede that I think it is. Most people I know still immediately turn to Wikipedia for a quick run down of a topic or an answer to a quick question. However, as time moves on the site is becoming less innovative and more standard. I would like to ask them about their understanding and personal experiences in trying to keep Wikipedia young. Moreover, having read that 85% of the contributors to Wikipedia are male I&#039;d specifically love to ask Phoebe whether she feels that the articles are written from the male gaze and lack the other gender&#039;s perspective.&lt;br /&gt;
&lt;br /&gt;
:: Sharona: Like Vickie, I was also struck by the statistics on the demographic breakdown, and I would love to hear their thoughts on whether they feel wikipedia really does represent a wide range of views, or more specifically (especially in the US) that of a white male. Another thing I think they will likely discuss - and probably not have a good answer for - is the question of privacy and defamation on wikipedia and other wikimedia projects. Can, or should, the website and/or its users or editors be held accountable if allegedly defamatory posts are not removed? Who makes that call? And what standards are used? It seems to me that there&#039;s no easy answer to this: while they may not run into strictly legal issues, it could definitely affect reader&#039;s trust in the information or fear that they too are vulnerable. &lt;br /&gt;
&lt;br /&gt;
Bruno: I expect our guests to focus their comments on the strategies Wikipedia is adopting to address two of what seems to be the main problems of the project: (i) quality/accuracy of its articles, and (ii) issues concerning vandalism. After reading the materials it strikes me that Wikipedia is not worried about increasing its user base. The increasing amount of rules, the hostility of veteran users to newbies and the efforts to attract more scientists to participate in the project suggest that in fact they would be interested in less, but more qualified participation. Just like the attitude of our guest from CrowdFlower, perhaps a sort of procrastination to address a problem that is not yet so concrete might be operating here: with over 40 thousand contributors it&#039;s not clear when more means actually less.&lt;br /&gt;
&lt;br /&gt;
:: Sheel: I&#039;d be interested in hearing Wikimedia&#039;s reaction to this: what if people started using CrowdFlower or MechanicalTurk, if they don&#039;t already, to pay people 10 cents or so to go edit Wikipedia pages?  I know they weren&#039;t okay with MyWikiBiz, but this is much more under the radar.  Finally, I&#039;d like to hear where the debate is on inclusionists v. exclusionists (or, at least, those who want to produce the &#039;integrity&#039; of the encyclopedia and shy away from what may be deemed as frivolous by some portion of editors).  My guess is that there is still no concrete answer---if enough editors are passionate about editing/creating a new page, then it&#039;ll stay.&lt;/div&gt;</summary>
		<author><name>Style</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_4_Thoughts&amp;diff=399</id>
		<title>Day 4 Thoughts</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_4_Thoughts&amp;diff=399"/>
		<updated>2010-01-08T06:41:24Z</updated>

		<summary type="html">&lt;p&gt;Style: New page: Sheel: The discussion on the BGP problem, although technical, was particularly interesting.  Here&amp;#039;s a question: if a full swap out of IP version 4 to 6 were to take place, could we then in...&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Sheel: The discussion on the BGP problem, although technical, was particularly interesting.  Here&#039;s a question: if a full swap out of IP version 4 to 6 were to take place, could we then institute a full Secure BGP program at the same time?  Perhaps I&#039;m trying to combine two pieces of separate technical puzzles, but the point is this: perhaps we could focus on upgrading security at the same time as switching to IPv6.&lt;/div&gt;</summary>
		<author><name>Style</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_4_Predictions&amp;diff=378</id>
		<title>Day 4 Predictions</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_4_Predictions&amp;diff=378"/>
		<updated>2010-01-07T19:21:07Z</updated>

		<summary type="html">&lt;p&gt;Style: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Amanda: I am very interested to hear Chuck&#039;s take on the relationship between the government, large corporations like Microsoft, and the defcon-attending hacker community (like the L0pht group mentioned in the Wired article). Is the government receptive to both groups? I imagine the relationship specifically between the hacker community and the government can become tense because the interests of both groups is not exactly aligned and is sometimes conflicting. Have they been able to successfully work together around a common threat like cybersecurity? While I imagine the government often tries to recruit from the hacker community, and I&#039;m interested to hear where they draw the lines legally as far as subversive behavior within the hacker community (ie do they bend the rules for the sake of potential advances in cybersecurity?).&lt;br /&gt;
:Of course there are great advances yet to be made in the relationship between white-hat hackers and corporations like Microsoft.  Skepticism abounds from both sides for obvious reasons, as well as entrenched interests and preconceptions based on past interactions (&amp;quot;Hackers are simply criminals&amp;quot;, or on the other side &amp;quot;Microsoft is The Man&amp;quot;).&lt;br /&gt;
&lt;br /&gt;
:Tyler: To follow up on the above predictions, I am interested in hearing Chuck describe what he feels is the proper balance between government and private corporations dealing with cybersecurity. This may be an actual allocation of roles, or more of a question about how much of private industry&#039;s culture of innovation and rapid change can be transplanted into the government. Professor Goldsmith painted a picture where the government is not, and is unable to, secure the cyber-interests of the United States so when we hear that 90% of US military traffic runs through private networks, are we shocked that this number is so high or that it is not closer to 100%?&lt;br /&gt;
&lt;br /&gt;
:Elisabeth: I&#039;m also interested in exploring this idea of transplanting &amp;quot;the private industry&#039;s culture of innovation and rapid change&amp;quot; into government.  When I read government documents, I&#039;m struck by how little they actually say--there&#039;s a lot of forming a vision to have a strategic plan to nurture partnerships that draw on core competencies.  On the other hand, I was impressed by the number of actual ideas that David Clark and the participants in the Centra Technology Cyber Compendium proposed.  How can the government provide the resources and permission for private companies (or actors?) to start actually trying out these ideas, instead of having everything devolve into meetings about process?  (see the Cyber compendium doc, starting on page 87, for some more musings on these questions.)&lt;br /&gt;
&lt;br /&gt;
Vickie: I&#039;m going to dovetail from Amanda&#039;s comment and say that I think Chuck is going to speak more specifically about the ID program he was talking about the other day as a possible solution to cybersecurity. Just as in the Wired article - identification solves a large percent of the problem, mostly through accountability. However, this seems too Orwellian for my blood. Unlike a passport that is shown in person - a computer ID is never going to be checked person to person. The computer will always be the intermediary. Moreover, this type of program may deter people from doing things on the Internet that they normally would do - if it wasn&#039;t anonymous. Visit certain political sites, fetish sites etc. etc. At what point is our fear balanced by our need for an Internet that is not being surveyed.&lt;br /&gt;
&lt;br /&gt;
Sheel: I&#039;m interested in hearing about the BGP/Secure BGP with ASes vulnerability mentioned in the Wired article.  This is something that Microsoft should have, and probably does have, on their radar; after all, what would happen if a bunch of Hotmail customers had their private emails routed to other ISPs, or delivered to the correct ISPs after making stops at non-secure locations.  My guess is that Chuck recognizes the problem and that Microsoft is taking action, but doesn&#039;t know what exactly is being done/could be done technically using Microsoft&#039;s clout.  &lt;br /&gt;
&lt;br /&gt;
:Ramesh: I wonder what Chuck would say are the benefits to anonymity on the internet, and whether they are outweighed by the security risks. It seems like there could be a creditable argument saying just that. Also, I wonder about problems in scaling up ID programs -- one would assume that many countries would not participate, but if desirable content could only be accessed by an ID, perhaps consumers would then demand their nations also issue internet IDs.&lt;br /&gt;
&lt;br /&gt;
:Elisabeth: easier IDing creates problems specifically in repressive political regimes, and would make GNI&#039;s work more difficult.&lt;br /&gt;
&lt;br /&gt;
Hector: Some of Chuck&#039;s points from his remarks on Tuesday that stuck with me most were the strengthening of internet identification and alternative networks that use something else than TCP. I hope that he elaborates on the possible applications of the latter.&lt;br /&gt;
&lt;br /&gt;
Lien: I&#039;m very interested to hear (i) what Chuck thinks the biggest cybersecurity risk is that Microsoft and other simular major private companies face and (ii) how the company is prepared for attack on its system and will react on it. I however predict he&#039;s not gonna answer that question...&lt;br /&gt;
&lt;br /&gt;
Reuben: On Tuesday we spent a great deal of time on the attribution problem of cybersecurity which is related to deterrence and retaliation.  I&#039;d like to hear more about that, but I&#039;d also like to hear about how we shore up our own defenses and incentivize security.  I&#039;ll be interested to hear who Chuck thinks should be responsible for security.  There is a dilemma for a company like Microsoft that may not want to have the burden of cybersecurity thrust upon them, but may also resist government mandates and control.  I think Chuck will probably recognize that both public and private sector have a role to play, but he will emphasize the need for government to provide more leadership in the area.&lt;br /&gt;
: Daniel: If Chuck details public and private strategies, I expect him to talk much more about what Microsoft has proposed to other industry players than about governmental talks. My guess is that he will also reiterate a preference for diplomatic cooperation between firms, stressing the limitations of naming and shaming (as with GNI, when nobody discussed the tainted past of the companies that were not present on Tuesday). Finally, I would bet a lesser amount on his discussing long-term solutions for users to be more aware of security risks and more reactive to perceived security flaws / reports that do not harm primarily that specific user.&lt;br /&gt;
&lt;br /&gt;
Jason: Especially since we have already had some discussion on the security issue, I think the class will be able to offer some interesting solutions for problems that exist pretty high-up in the stack, like user behavior, software, ID schemes, and other things that happen at the end node. But I predict that we&#039;ll be somewhat flummoxed about what&#039;s going on and what to do about the fundamental nature of the network, like the implications of the stuff that Clark was talking about in [http://www.ischool.berkeley.edu/newsandevents/events/sl20090304 his talk] that we listened to. I certainly am - though hopefully we&#039;ll make a bit of headway in class.&lt;br /&gt;
&lt;br /&gt;
Michael: Though not quite a prediction, I would like to hear Chuck&#039;s thoughts on whether cybersecurity issues can be solved incrementally or whether there needs to be a comprehensive scheme to take care of many problems at once. We touched on this question on during the second class, but it never really got answered. My guess is that Chuck will say comprehensive change is impractical and the internet will have to continue to rely on the procrastination principle.&lt;br /&gt;
&lt;br /&gt;
Andrew: Another leftover question from Tuesday is  JZ&#039;s Wikipedia-esque solution at the logical layer--implementation of bottom-up stuff like ad hoc mesh networking rather than top-down &amp;quot;perimeter defense&amp;quot;, and the transformation of the security problem into a question of numbers (do the people who are passionate about the network succeeding outnumber those who are passionate about its failure). (Hopefully I didn&#039;t botch the paraphrase). Neither Jack nor Chuck responded directly to these ideas; perhaps Chuck will today.&lt;br /&gt;
&lt;br /&gt;
Juan: I would like to hear what are the roles of different parties to address the problem? How can the parties work collaboratively to approach this problem? How can the hacker resources be used efficiently to solve this problem? e.g. use white-hat hackers to hunt down black-hat hackers. &lt;br /&gt;
What incentives can be given to ISPs and vulnerable site owners to create secured internet and secured websites?&lt;br /&gt;
: Daniel: How much should government / companies provide incentives to individuals joining the fight? What happens in the aftermath of white-hat / black hat hacker wars? Is [http://www.youtube.com/watch?v=3fifItoMPTw defection] to the bright side more likely to happen than defection of now-trained hackers to cybercrime?&lt;br /&gt;
&lt;br /&gt;
Franny:  Following Hector&#039;s train of thought, I think Chuck will expand on how addressing the attribution problem with &amp;quot;Internet drivers licences&amp;quot; will help ameliorate (if not resolve) many cybersecurity problems.  Of particular interest, I hope Chuck will discuss implementation strategy - would it be possible to achieve this goal through economic pressure, or is internationally harmonized government involvement necessary?&lt;/div&gt;</summary>
		<author><name>Style</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_3_Predictions&amp;diff=325</id>
		<title>Day 3 Predictions</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_3_Predictions&amp;diff=325"/>
		<updated>2010-01-07T00:03:39Z</updated>

		<summary type="html">&lt;p&gt;Style: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Daniel: My guess is that three issues will be focused:&lt;br /&gt;
&lt;br /&gt;
1- &#039;&#039;labor rights&#039;&#039; â workers in UHC are not attached to a safe work environment, do not receive any fringe benefits, health care, etc., and as of yet there are no unions for Turks and the like. It is quite easy to see homeworkers as nonworkers, and to build [http://www.missconceptions.net/downloads/mturk-pca09-web.pdf digital sweatshops].&lt;br /&gt;
&lt;br /&gt;
2- workersâ new &#039;&#039;expectation of complete anonymity&#039;&#039;, that go way beyond privacy demands in regular work environments. Hopefully ethical issues concerning this faceless workforce will be discussed, as well as its potential identity and community feelings (taking into account that, unlike bearers of [http://www.iab.net/about_the_iab/recent_press_releases/press_release_archive/press_release/pr-061009-value formal jobs], UHC workers have shifting numbers, not social security ones). Still on this topic, I expect debates about people willing to perform otherwise shameful tasks, and about the opportunities for children, sick or unfit workers in general to work / be worked. &lt;br /&gt;
&lt;br /&gt;
3- the &#039;&#039;use of UHC for complex, creative tasks&#039;&#039;, analyzed in conjunction with a look at the economics of commoditized labor pools. Resulting discussions could examine quality control and its costs, and [http://portal.acm.org/citation.cfm?id=1357054.1357127 proper design], necessary to unleash [http://www.youtube.com/watch?v=rQ3Q6Y6Ylqo creativity] and demand more than repetitive, boring tasks from fellow anonymous humans. On that note, it is nice to see that, as scientific experiments with Mechanical Turks [http://experimentalturk.wordpress.com/ become more popular], academic attention is drawn towards the problematic incentives in the platformâs most common setting (low payment + repetitive tasks), which encourages Turks to finish HITs as fast as they can, [http://experimentalphilosophy.typepad.com/experimental_philosophy/2010/01/looking-for-subjects-amazons-mechanical-turk.html at the expense of proper comprehension of the tasks].&lt;br /&gt;
: Andrew: Since at least some of our guests tonight are &amp;quot;creatives&amp;quot;, I hope to hear some discussion about the relationship between full-time freelancers and websites that crowdsource complex, creative tasks (e.g. Worth1000, [http://www.istockphoto.com/index.php iStockPhoto]). At a Berkman lunch last spring, [http://crowdsourcing.typepad.com/ Jeff Howe] cited a [http://papers.ssrn.com/sol3/papers.cfm?abstract_id=1122462 study] that showed only 4% of iStockPhoto sellers derived their primary income from the site. As the site and its peers begin to dominate the market for stock photography, what happens to the livelihoods of those who depended on stock photography for a living? Protectionist worries like this parallel those about outsourcing more generally and are vulnerable to the same counters about progress and efficient markets; I hope some of those arguments play out tonight. &lt;br /&gt;
&lt;br /&gt;
My wish list for the session: discussions of solutions / tools such as [http://turkopticon.differenceengines.com/ Turkopticon], a Firefox application designed to identify and expose âshady employersâ.&lt;br /&gt;
&lt;br /&gt;
Michael: Since two of our guests have used UHC for artistic projects, I expect one or both of them will respond to some [http://en.wikipedia.org/wiki/The_Cult_of_the_Amateur/ Cult of the Amateur]-style criticisms. I am especially interested to hear whether our speakers think UHC improves the quality of creative/design work that can be accomplished or aggregated from UHC or whether it represents a possible step backward from looking to established professionals for this kind of work. Based on the backgrounds of the speakers, I would imagine Bjoern Hartman and Aaron Koblin will argue that UHC presents the possibility for improvement over the previous paradigm of established professionals. I imagine one or more of the speakers may believe that UHC doesn&#039;t really represent a change in quality of such higher level work, but just a difference in kind. &lt;br /&gt;
&lt;br /&gt;
I don&#039;t know if any of our guests plan on discussing this topic, but I would be especially interested to hear their perspectives on UHC&#039;s effect on the morality of work done. Anonymity on the internet can sometimes remove users&#039; filters of social convention and politeness. So UHC might make it easier for users of Mechanical Turk or CrowdFlower to do work (either voluntarily or unknowingly) that would be morally dubious. There also seems to be a lot of noise in the Mechanical Turk system especially -- a lot of scams rather than true HIT tasks. A possible solution would be to use the existing Mechanical Turk or CrowdFlower functionality for users to rank the morality of the various tasks and provide marginally greater pay or benefits for tasks with higher moral/utility rankings. But I would be interested to hear to what extent our guests think this is a problem.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Ramesh: I predict that the founders of human computing websites will be more focused on the technology and potential of the websites and may have a blind spot for the legal issues that may be raised by UHC (applicability of minimum wage and other laws) while as law students, we may naturally focus on the legal issues implicated.&lt;br /&gt;
&lt;br /&gt;
Alternatively, perhaps the founders of UHC websites will see them simply as a continuation of current trends, especially the increasing numbers of contractors in the labor force of large companies and governments and the outsourcing of call-center (and increasingly higher-skilled) jobs overseas. Does UHC present any problems that are different from the current trends? What role can employment and labor law play in a world where increasing numbers of workers are &amp;quot;independent contractors&amp;quot; or even Mechanical Turks? Will technology re-enact Lochner?&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Franny:&lt;br /&gt;
Given the guest list, I diplomatically disagree with Daniel (and agree with Ramesh) and would expect these guests to address the positive potential and advantages of human computing applications into business, arts and culture, as well as the benefits available through this new type of labour force with built-in autonomy.  As libertarian as I may be in my views, I agree with Daniel that there is a real possibility that UHC can develop into a last resort for unskilled workers to earn income in order to survive.  I just don&#039;t think that the negative aspects will be the focus of today&#039;s session.&lt;br /&gt;
&lt;br /&gt;
I would also be interested to hear our guests&#039; thoughts on whether UHC can be applied to tasks in which sensitive information is involved, and if so, how could private content be protected?&lt;br /&gt;
&lt;br /&gt;
:Jason: Totally agree with Franny here. I was at first somewhat surprised that in the talk that Lukas gave at TechCruch 50 there was zero discussion of any of the legal aspects of this (no one asked, &amp;quot;Um, do you have to withhold taxes from the workers?&amp;quot; or &amp;quot;What if it turned out that someone was a child?&amp;quot; or &amp;quot;Won&#039;t your business model be ruined if it turns out you have to pay taxes for not providing health insurance to these people?&amp;quot; or anything along those lines) - but, of course, I forgot that I&#039;m a law student and that&#039;s not the lens through which they are viewing this technology. Faced with a room of (mostly) lawyers, these questions will obviously come more the fore than they were there, but I suspect that the considerable advantages and potential of this type of work will dominate the discussion.&lt;br /&gt;
&lt;br /&gt;
:Reuben: I wonder how feasible it is to actually make any real money as a mechanical turk.  All of the tasks I tried took me at least a few minutes to read the instructions and then a little bit of time to actually perform the task.  I suppose if someone did the same repetitive task over and over it would cut down on the amount of downtime and you could more quickly make some money, but at $.02 a task (which seems to be a going rate), even if you spent as little as 30 seconds on each HIT, it works out to $2.40 an hour.  You need to pay about $.07 a task to add to the basic minimum wage.  I see how the employers/taskmasters benefit, but aside from the novelty, I don&#039;t see any real benefit for the turkers.  I&#039;d love to hear from Lukas what the average worker makes doing CrowdFlower tasks.   &lt;br /&gt;
&lt;br /&gt;
Juan: &lt;br /&gt;
&lt;br /&gt;
By doing quality control and tracking the quality history of workers, Crowdflower moves one step closer to a real employer. How will it and other human computing websites deal with labor law issues, such as employment relationship, jurisdiction conflict, non-compete agreement, anti-discrimination, disability, leave time, wage and hour requirements, and etc. Also, building up workers&#039; career path, balancing between monitoring and privacy intrusion, disclosing information for workers to evaluate the moral value and giving them the opportunity to opt out, shall be new problems in the cyberspace. Besides, this paid work on-line may have an impact on those contributions without payments. How will we address this issue to make sure people will have incentives to embark on free works. &lt;br /&gt;
&lt;br /&gt;
Another thing I want to hear is whether UHC will develop verticals like the traditional industries. How will it develop those verticals not suitable for on-line outsourcing per its nature?&lt;br /&gt;
&lt;br /&gt;
Sheel: The &#039;quality history of workers&#039; that Juan alluded to is particularly interesting to me.  Crowdflower seems to integrate the &#039;reputation&#039; of workers in ways that Mechanical Turk doesn&#039;t do for its HITs.  I&#039;d like to hear Lukas&#039;s thoughts on this mechanism---how easy is it for users who have a low reputation to just start all over, taking the good (long history with website) away from the bad (similar to the online reputation possibilities that JZ mentioned in his book)?  Does CrowdFlower only track user names in this manner?  Also, would Crowdflower ever consider having tasks cost a higher amount for the vendor with the stipulation that only those with a certain reputation will be able to perform them?  &lt;br /&gt;
&lt;br /&gt;
My prediction is that the reputation system will be naturally brought about in conversation when Lukas is describing his company as his &#039;competitive advantage&#039;.  He will probably say that there isn&#039;t a need to have tasks cost a higher amount for the services of those with a good reputation (if the question is posed) because the service is inherently reliable as it can recognize spammers from truly competent workers.  &lt;br /&gt;
&lt;br /&gt;
Sharona: I agree with Franny and Ramesh - I think the speakers will generally focus more on the positive contributions these types of sites can offer - the innovation from crowd sourcing, the efficiency, the specialization - and less concern over the legal issues. One thing I would like to hear is whether they think these tasks will continue to be performed by US residents, or how quickly they will also be outsourced to English speaking (or non-English speaking) people across the world looking for menial labor especially. Another thing to consider is how or if people could actually make a career out of doing tasks online, or whether it is just something to supplement another job. How will things like health benefits or insurance policies come into play for these kinds of workers?&lt;br /&gt;
&lt;br /&gt;
Yosuke:&lt;br /&gt;
I agree with the majority opinion, I think guests will not really focus on negative aspects of ubiquitous human computing, such as potential problems of child labors in developing countries, as JZ stated in [http://yupnet.org/zittrain/archives/21#41 this paragraph in his book]. While I guess they will address some amazingly positive aspects of UHC.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Vickie: My guess here is that the &amp;quot;creative types&amp;quot; as Andrew called them are going to be psyched about the creative potential of mechanical turk but less satisfied by the &amp;quot;mundane tasks&amp;quot; that are fueled through the programs (as stated by Aaron Koblin in this video http://vimeo.com/3199933). I believe Koblin and Hartmann are not going to be happy to hear as much about CrowdFlower. Koblin, specifically said in his presentation in this video that he limited the amount of times his contributors could use HITs for his art projects. Unlike CrowdFlower Koblin isn&#039;t looking to use Turkers as steadfast blinded workers. He seems very conscious of all the Marxist qualms with the program.&lt;br /&gt;
&lt;br /&gt;
Lien: I also agree that the speakers will try to keep it positive. I&#039;m however interested to hear whether these &amp;quot;human computing companies&amp;quot; ran into law suits already because of legal issues, both in the EU and other continents. Further, did they already got (negative?) reactions from governments, human rights organisations, labor organisations, unions, etc. . Also, if a human computing company would be sued by a turk, does it involve the &amp;quot;requester&amp;quot; (as the &amp;quot;employer&amp;quot;?) in the lawsuit? Speaking to my colleagues in Europe, none of them had really heard of this mechanical turk fenomenon. However, I&#039;m sure that taking into account our very strict labor law that highly advantages employees, and strong influence of labor unions, labor regulations will become a huge issue.&lt;/div&gt;</summary>
		<author><name>Style</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_2_Thoughts&amp;diff=322</id>
		<title>Day 2 Thoughts</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_2_Thoughts&amp;diff=322"/>
		<updated>2010-01-06T23:43:39Z</updated>

		<summary type="html">&lt;p&gt;Style: /* Cybersecurity */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Cybersecurity ==&lt;br /&gt;
&lt;br /&gt;
Daniel: the idea of a &amp;quot;digital driver&#039;s license&amp;quot; has been around for [http://www.youtube.com/watch?v=RrpajcAgR1E some time now]. Effective and simple [http://en.wikipedia.org/wiki/Digital_signature digital signature] schemes, outside corporate or governmental control, sound much more promising to me.&lt;br /&gt;
&lt;br /&gt;
Jason: This was a great discussion. To borrow a taxonomy from the [http://consc.net/papers/facing.html philosophy of mind], I particularly liked that we were trying to identify the &amp;quot;hard&amp;quot; problems and the &amp;quot;easy&amp;quot; problems of cybersecurity - even if we didn&#039;t always agree about what they are. In theory, though, we might identify a class of easy problems because they seem to have incremental solutions. If your drone transmissions are getting intercepted, use encryption! If you&#039;re worried about data loss, generate lots of backups to the cloud or to a mesh network! If you&#039;re worried about your credit card being stolen when you buy on Amazon, how about a government-generated user ID system? Or (somewhat more controversially), if your Air Traffic Control system is vulnerable, spend some money and update it - maybe making it more appliancized, maybe adding more points of human control.&lt;br /&gt;
&lt;br /&gt;
But that still leaves the hard problems that seem to need quantum solutions. How can we solve the attribution problem when the global network was fundamentally designed to be pretty  anonymous? How do we rectify the fact that the Internet carries both regular civilian communications and government transmissions? And how can we guarantee that hardware is secure when the only way to verify that it was built to spec is to take it apart? I&#039;m looking forward to talking more about both kinds of problems, and both kinds of solutions.&lt;br /&gt;
&lt;br /&gt;
: Tyler: While I agree that it is a serious problem when we can&#039;t trust our hardware, I thought it was also a good point brought up in class that there is no reason why we should trust the software that runs on top of the hardware either. Is it possible to write software that we can trust even if we know or assume that it is running on malicious hardware? Are there any out of the box techniques that would allow us to use untrusted software running on untrusted hardware but still have some degree of security?&lt;br /&gt;
&lt;br /&gt;
: Sheel: Professor Goldsmith&#039;s comment showed that this is a problem that may have to be solved before law can even come into play: law depends on attribution that Jason mentioned - finding the bad actor.  What are we supposed to do if we are only 20% sure an attack came from China?  &lt;br /&gt;
&lt;br /&gt;
Sheel: First time that our military/government has critical information (not withstanding the unencrypted info that the government was sending overseas!) being sent over public networks.  Am curious to discuss either a) better methods of encrypting information over public networks or b) better ways to build private, government-only networks.  Also, the SCADA comment made by Ivan about the problem not being authentication, but old networks/platforms that have an extremely difficult time being changed, show this will require a LOT of incentives for people to be able to make the switch to more powerful networks---if that even is the answer. &lt;br /&gt;
&lt;br /&gt;
Finally, w/ regards to Prof. Zittrain&#039;s first &#039;out of the box&#039; solution on ad hoc mesh networking - I&#039;m having trouble understanding incentives for the guy with the internet on the outskirts of hurricane in the Katrina example to let others access his/her connection.  Wouldn&#039;t being &#039;kind&#039; then require a troublesome amount of security and encryption on behalf of the original users part?&lt;br /&gt;
&lt;br /&gt;
Chuck:  First of all, my thanks to Prof. Zittrain and to all of you for allowing me to participate (including on your wiki).  I hope what I offered was helpful and perhaps even thought-provoking.  Second, here are some of the links I mentioned for more on the identity/security issues:  http://www.microsoft.com/endtoendtrust and in particular the white paper under the &amp;quot;vision&amp;quot; link.  For those inclined for a geekier dive, there is Kim Cameron&#039;s excellent blog at http://www.identityblog.com/.  Finally, I&#039;d also note our blog post on one of our big projects, the US-China Internet Industry Forum and Craig Mundie&#039;s remarks in particular, which touched on these cybersecurity issues in that context. http://bit.ly/8BpJfe&lt;br /&gt;
&lt;br /&gt;
== GNI ==&lt;br /&gt;
&lt;br /&gt;
Reuben: I think we should all congratulate ourselves on our prognostication skills.  A lot of our predictions were right on the money.  After reviewing my notes, I came away with a few main points.  It seems the GNI has had two main benefits for those involved.  First, it has helped companies establish processes for how they will handle sticky situations that arise in fields of free expression and privacy where previously those concerns went unrepresented or were dealt with an ad hoc scramble.  Secondly, GNI has facilitated relationships between companies and human rights organizations that allow the two sides to work together collaboratively to map out strategies and get more effective results.  &lt;br /&gt;
&lt;br /&gt;
While the panelists recognized the effectiveness of the GNI in at least certain situations, I was a bit surprised by the degree to which at least some participants seemed to welcome government involvement in order to force more attention on the activities of smaller companies who don&#039;t stand out the same way a Microsoft, Google, Yahoo, or CISCO might.&lt;br /&gt;
&lt;br /&gt;
Jason: I think that the discussion took a bit of steam out of the &amp;quot;Difficult&amp;quot; part of the &amp;quot;Difficult Problems&amp;quot; equation - at least with regard to why Cisco is not participating in GNI and how they make decisions that implicate human rights issues. Mark&#039;s explanation of Cisco&#039;s position was exceedingly compelling: to my mind, he left little doubt that they really do have a different sort of impact on human rights than companies higher up in the stack; that they face a vastly different competitive landscape and client base than other ICT companies; and that they have well-developed standards and principles going forward. From where I sit, they would be completely crazy to join the GNI - it&#039;d be all potential downside with no upside that I can tell, for either the company or for human rights. (Sadly, Cisco did not pay me to say all that, even if I just completely toed the company line.)&lt;br /&gt;
&lt;br /&gt;
Chuck:  I am also impressed (but not surprised) by your prognostication skills.  I&#039;d only add that, in addition to the two points Reuben notes above, GNI has generated a systematic way for companies to make publically credible the steps they take.  This, I think, is where companies not in GNI are missing out.  When there are these cases (as Mark noted) of public condemnation of companies - which can at times generate more heat than light - it is very helpful to be able to point to the process that GNI creates and demonstrate that your company not only has standards and principles but that these are being followed in practice.  I also think GNI is very aware that different business sectors have different needs.  Microsoft, like Cisco, sells products and services to governments (servers are in a somewhat similar position to routers as part of network infrastructure) and we stand to benefit from guidance in those areas. Related to that, and on the point about government involvement, I&#039;d also note that the GNI principles are applicable across a company&#039;s operations, including in the US, and in that respect it&#039;s important that governments address their own practices as well as look for constructive steps to help advance user trust in other markets.  I hope that came across in the class, but if not I wanted to note it here too. Thanks again.&lt;/div&gt;</summary>
		<author><name>Style</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_3_Predictions&amp;diff=318</id>
		<title>Day 3 Predictions</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_3_Predictions&amp;diff=318"/>
		<updated>2010-01-06T23:27:22Z</updated>

		<summary type="html">&lt;p&gt;Style: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Daniel: My guess is that three issues will be focused:&lt;br /&gt;
&lt;br /&gt;
1- &#039;&#039;labor rights&#039;&#039; â workers in UHC are not attached to a safe work environment, do not receive any fringe benefits, health care, etc., and as of yet there are no unions for Turks and the like. It is quite easy to see homeworkers as nonworkers, and to build [http://www.missconceptions.net/downloads/mturk-pca09-web.pdf digital sweatshops].&lt;br /&gt;
&lt;br /&gt;
2- workersâ new &#039;&#039;expectation of complete anonymity&#039;&#039;, that go way beyond privacy demands in regular work environments. Hopefully ethical issues concerning this faceless workforce will be discussed, as well as its potential identity and community feelings (taking into account that, unlike bearers of [http://www.iab.net/about_the_iab/recent_press_releases/press_release_archive/press_release/pr-061009-value formal jobs], UHC workers have shifting numbers, not social security ones). Still on this topic, I expect debates about people willing to perform otherwise shameful tasks, and about the opportunities for children, sick or unfit workers in general to work / be worked. &lt;br /&gt;
&lt;br /&gt;
3- the &#039;&#039;use of UHC for complex, creative tasks&#039;&#039;, analyzed in conjunction with a look at the economics of commoditized labor pools. Resulting discussions could examine quality control and its costs, and [http://portal.acm.org/citation.cfm?id=1357054.1357127 proper design], necessary to unleash [http://www.youtube.com/watch?v=rQ3Q6Y6Ylqo creativity] and demand more than repetitive, boring tasks from fellow anonymous humans. On that note, it is nice to see that, as scientific experiments with Mechanical Turks [http://experimentalturk.wordpress.com/ become more popular], academic attention is drawn towards the problematic incentives in the platformâs most common setting (low payment + repetitive tasks), which encourages Turks to finish HITs as fast as they can, [http://experimentalphilosophy.typepad.com/experimental_philosophy/2010/01/looking-for-subjects-amazons-mechanical-turk.html at the expense of proper comprehension of the tasks].&lt;br /&gt;
: Andrew: Since at least some of our guests tonight are &amp;quot;creatives&amp;quot;, I hope to hear some discussion about the relationship between full-time freelancers and websites that crowdsource complex, creative tasks (e.g. Worth1000, [http://www.istockphoto.com/index.php iStockPhoto]). At a Berkman lunch last spring, [http://crowdsourcing.typepad.com/ Jeff Howe] cited a [http://papers.ssrn.com/sol3/papers.cfm?abstract_id=1122462 study] that showed only 4% of iStockPhoto sellers derived their primary income from the site. As the site and its peers begin to dominate the market for stock photography, what happens to the livelihoods of those who depended on stock photography for a living? Protectionist worries like this parallel those about outsourcing more generally and are vulnerable to the same counters about progress and efficient markets; I hope some of those arguments play out tonight. &lt;br /&gt;
&lt;br /&gt;
My wish list for the session: discussions of solutions / tools such as [http://turkopticon.differenceengines.com/ Turkopticon], a Firefox application designed to identify and expose âshady employersâ.&lt;br /&gt;
&lt;br /&gt;
Ramesh: I predict that the founders of human computing websites will be more focused on the technology and potential of the websites and may have a blind spot for the legal issues that may be raised by UHC (applicability of minimum wage and other laws) while as law students, we may naturally focus on the legal issues implicated.&lt;br /&gt;
&lt;br /&gt;
Alternatively, perhaps the founders of UHC websites will see them simply as a continuation of current trends, especially the increasing numbers of contractors in the labor force of large companies and governments and the outsourcing of call-center (and increasingly higher-skilled) jobs overseas. Does UHC present any problems that are different from the current trends? What role can employment and labor law play in a world where increasing numbers of workers are &amp;quot;independent contractors&amp;quot; or even Mechanical Turks? Will technology re-enact Lochner?&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Franny:&lt;br /&gt;
Given the guest list, I diplomatically disagree with Daniel (and agree with Ramesh) and would expect these guests to address the positive potential and advantages of human computing applications into business, arts and culture, as well as the benefits available through this new type of labour force with built-in autonomy.  As libertarian as I may be in my views, I agree with Daniel that there is a real possibility that UHC can develop into a last resort for unskilled workers to earn income in order to survive.  I just don&#039;t think that the negative aspects will be the focus of today&#039;s session.&lt;br /&gt;
&lt;br /&gt;
I would also be interested to hear our guests&#039; thoughts on whether UHC can be applied to tasks in which sensitive information is involved, and if so, how could private content be protected?&lt;br /&gt;
&lt;br /&gt;
:Jason: Totally agree with Franny here. I was at first somewhat surprised that in the talk that Lukas gave at TechCruch 50 there was zero discussion of any of the legal aspects of this (no one asked, &amp;quot;Um, do you have to withhold taxes from the workers?&amp;quot; or &amp;quot;What if it turned out that someone was a child?&amp;quot; or &amp;quot;Won&#039;t your business model be ruined if it turns out you have to pay taxes for not providing health insurance to these people?&amp;quot; or anything along those lines) - but, of course, I forgot that I&#039;m a law student and that&#039;s not the lens through which they are viewing this technology. Faced with a room of (mostly) lawyers, these questions will obviously come more the fore than they were there, but I suspect that the considerable advantages and potential of this type of work will dominate the discussion.&lt;br /&gt;
&lt;br /&gt;
Juan: &lt;br /&gt;
&lt;br /&gt;
By doing quality control and tracking the quality history of workers, Crowdflower moves one step closer to a real employer. How will it and other human computing websites deal with labor law issues, such as employment relationship, jurisdiction conflict, non-compete agreement, anti-discrimination, disability, leave time, wage and hour requirements, and etc. Also, building up workers&#039; career path, balancing between monitoring and privacy intrusion, disclosing information for workers to evaluate the moral value and giving them the opportunity to opt out, shall be new problems in the cyberspace. Besides, this paid work on-line may have an impact on those contributions without payments. How will we address this issue to make sure people will have incentives to embark on free works. &lt;br /&gt;
&lt;br /&gt;
Another thing I want to hear is whether UHC will develop verticals like the traditional industries. How will it develop those verticals not suitable for on-line outsourcing per its nature?&lt;br /&gt;
&lt;br /&gt;
Sheel: The &#039;quality history of workers&#039; that Juan alluded to is particularly interesting to me.  Crowdflower seems to integrate the &#039;reputation&#039; of workers in ways that Mechanical Turk doesn&#039;t do for its HITs.  I&#039;d like to hear Lukas&#039;s thoughts on this mechanism---how easy is it for users who have a low reputation to just start all over, taking the good (long history with website) away from the bad (similar to the online reputation possibilities that JZ mentioned in his book)?  Does CrowdFlower only track user names in this manner?  Also, would Crowdflower ever consider having tasks cost a higher amount for the vendor with the stipulation that only those with a certain reputation will be able to perform them?  &lt;br /&gt;
&lt;br /&gt;
Sharona: I agree with Franny and Ramesh - I think the speakers will generally focus more on the positive contributions these types of sites can offer - the innovation from crowd sourcing, the efficiency, the specialization - and less concern over the legal issues. One thing I would like to hear is whether they think these tasks will continue to be performed by US residents, or how quickly they will also be outsourced to English speaking (or non-English speaking) people across the world looking for menial labor especially. Another thing to consider is how or if people could actually make a career out of doing tasks online, or whether it is just something to supplement another job. How will things like health benefits or insurance policies come into play for these kinds of workers?&lt;br /&gt;
&lt;br /&gt;
Yosuke:&lt;br /&gt;
I agree with the majority opinion, I think guests will not really focus on negative aspects of ubiquitous human computing, such as potential problems of child labors in developing countries, as JZ stated in [http://yupnet.org/zittrain/archives/21#41 this paragraph in his book]. While I guess they will address some amazingly positive aspects of UHC.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Vickie: My guess here is that the &amp;quot;creative types&amp;quot; as Andrew called them are going to be psyched about the creative potential of mechanical turk but less satisfied by the &amp;quot;mundane tasks&amp;quot; that are fueled through the programs (as stated by Aaron Koblin in this video http://vimeo.com/3199933). I believe Koblin and Hartmann are not going to be happy to hear as much about CrowdFlower. Koblin, specifically said in his presentation in this video that he limited the amount of times his contributors could use HITs for his art projects. Unlike CrowdFlower Koblin isn&#039;t looking to use Turkers as steadfast blinded workers. He seems very conscious of all the Marxist qualms with the program.&lt;br /&gt;
&lt;br /&gt;
Lien: I also agree that the speakers will try to keep it positive. I&#039;m however interested to hear whether these &amp;quot;human computing companies&amp;quot; ran into law suits already because of legal issues, both in the EU and other continents. Further, did they already got (negative?) reactions from governments, human rights organisations, labor organisations, unions, etc. . Also, if a human computing company would be sued by a turk, does it involve the &amp;quot;requester&amp;quot; (as the &amp;quot;employer&amp;quot;?) in the lawsuit? Speaking to my colleagues in Europe, none of them had really heard of this mechanical turk fenomenon. However, I&#039;m sure that taking into account our very strict labor law that highly advantages employees, and strong influence of labor unions, labor regulations will become a huge issue.&lt;/div&gt;</summary>
		<author><name>Style</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_2_Predictions&amp;diff=231</id>
		<title>Day 2 Predictions</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_2_Predictions&amp;diff=231"/>
		<updated>2010-01-05T07:49:26Z</updated>

		<summary type="html">&lt;p&gt;Style: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Sheel: Cisco, with its involvement in China&#039;s Golden Shield Project and $16 Billion investment (http://www.socialfunds.com/news/article.cgi/2825.html), doesn&#039;t want to have to deal with issues of human rights that might diminish ROI. Notable quote from article and 2008 testimony: Chandler said, &amp;quot;Cisco does not customize, or develop specialized or unique filtering capabilities, in order to enable different regimes to bock access to information.&amp;quot; My guess: Mark Chandler will affirm this statement tomorrow, but the real reason is that following the GNI principles would be a poor business decision and CISCO isn&#039;t willing to make any sacrifice.&lt;/div&gt;</summary>
		<author><name>Style</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_2_Predictions&amp;diff=230</id>
		<title>Day 2 Predictions</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_2_Predictions&amp;diff=230"/>
		<updated>2010-01-05T07:48:04Z</updated>

		<summary type="html">&lt;p&gt;Style: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Sheel: Cisco, with its involvement in China&#039;s Golden Shield Project and $16 Billion investment (http://www.socialfunds.com/news/article.cgi/2825.html), doesn&#039;t want to have to deal with issues of human rights that might diminish ROI. Notable quote from article and 2008 testimony: Chandler said, &amp;quot;Cisco does not customize, or develop specialized or unique filtering capabilities, in order to enable different regimes to bock access to information.&amp;quot; My guess: Mark Chandler will affirm this statement tomorrow, but the real reason is that following the GNI principles would be a poor business decision.&lt;/div&gt;</summary>
		<author><name>Style</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_2_Predictions&amp;diff=229</id>
		<title>Day 2 Predictions</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_2_Predictions&amp;diff=229"/>
		<updated>2010-01-05T07:47:01Z</updated>

		<summary type="html">&lt;p&gt;Style: New page: Cisco, with its involvement in China&amp;#039;s Golden Shield Project and $16 Billion investment (http://www.socialfunds.com/news/article.cgi/2825.html), doesn&amp;#039;t want to have to deal with issues of...&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Cisco, with its involvement in China&#039;s Golden Shield Project and $16 Billion investment (http://www.socialfunds.com/news/article.cgi/2825.html), doesn&#039;t want to have to deal with issues of human rights that might diminish ROI. Notable quote from article and 2008 testimony: Chandler said, &amp;quot;Cisco does not customize, or develop specialized or unique filtering capabilities, in order to enable different regimes to bock access to information.&amp;quot; My guess: Mark Chandler will affirm this statement tomorrow, but the real reason is that following the GNI principles would be a poor business decision.&lt;/div&gt;</summary>
		<author><name>Style</name></author>
	</entry>
</feed>