Bonum Certa Men Certa

Technology: rights or responsibilities? - Part III

posted by Rianne Schestowitz on Oct 09, 2024

By Dr. Andy Farnell

Back to Part I

Back to Part II

Rights and security

Whereas cybersecurity has traditionally been limited to businesses and organisations, what I call "civic cybersecurity" is concerned with obtaining and keeping a safe and fair digital world for everyone. So let's venture the idea that "digital rights" is something that makes sense when we broaden the purview of cybersecurity to include ordinary and everyday living.

In the media, civic cybersecurity tends to focus on the dramatic, on stopping planes being hacked to fall from the sky and power grids from melting down. The latest offering in the UK is the very entertaining Nightsleeper, a kind of British "Mr. Robot".

Though I teach in an area where we consider nasty and disturbing stuff from drone swarms terrorising stadiums to autonomous vehicles carrying bombs, these sorts of worst-case fantasies rarely happen for pragmatic psychological reasons rather than questions of possibility. Elaborate kinetic violence requires extraordinary levels of organisation, long term commitment and fanatical malice. Most of the civilian horror we see is more spontaneous and makes use of commonplace weapons like knives and vehicles. Stuxnet style terror stunts, like hackjacking the London Eye and centrifuging tourists into low Earth orbit requires Tom and Jerry levels of improbability.

For defenders, constantly worrying about marginal "what-ifs?" is sapping and distracts from the everyday attacks that are already commonplace. Ironically some of these less dramatic attack surfaces are less obvious to those with over-active imaginations.

imaginations

Most of what we deal with in civil cybersecurity is teenagers getting cyberbullied into a suicidal state, or old people who've been robbed of their life savings. These crimes are almost always outside the practical capacity of the police and so are seldom dealt with. Their root lies in awful software and systems designed to put profit, spying and domination ahead of safety and human values. It's not just that code is insecure, but that the design, protocols and features of the applications are hostile to users.

life savings

For a long time a "techlash" has been brewing against the handful of massive companies and unelected power centres that presume to tell us how to live our lives, causing harm to individuals and society in their own self-interest. Head of US Cybersecurity and Infrastructure Security Agency (CISA) Jen Easterly recently called-out BigTech for their criminally defective products and entitled "techno exceptionalism". The reality is that the accumulated negative impact of BigTech in its effects on health, wealth and happiness outweighs anything terrorists ever achieved on US or British soil - except indirectly by creating the money-pit of state surveillance and media circus of fear.

Let's take an seemingly innocuous example of being unable to obtain healthcare because your hospital only accepts Gmail addresses. This is a catastrophic failure of social security that has roots in bad technology and also insane policy. It is evil in it's sheer mundanity.

healthcare

email addresses

Or consider the betrayal of selling patient medical records to research companies (despite repeated opting-out) such that people no longer have confidence in their GP and avoid visits. These actions certainly cause deaths. Yet on the surface they seem inconsequential.

Or attacking the use of cash money and local economies so that small businesses and the rural poor are disadvantaged. This constant low-level technological violence is against the invisible fabric of society, not our visible symbols. It is the subversive craft that Yuri Bezmenov outlined following his defection in the 1970s. The cruel twist is to get our own people doing the dirty work so that Moscow and Beijing don't need to lift a finger. The truly poetic masterstroke is to have us dismantle our own society in the belief we are "building a better, more efficient world". I think our international enemies cheer every time our governments give a little more power to Microsoft, Amazon or Google.

These acts of social sabotage use technology which makes ordinary malice easy and convenient. Ordinary moral weakness, ignorance, greed and neglect, met by "convenient solutions", enable a witless many to have more impact than any dramatic spectacles perpetrated by a militant few. Planes flying into buildings are news, but hundreds of thousands of road deaths due to texting-and-driving is nothing to see or care about. What we confuse are "terror" and "sabotage". Whereas the terrorist likes to put on a show, the saboteur is happy if his corrosive work goes unnoticed.

Whatever uneducated and dishonest rationales might be offered, behind them is a devious policy decision in obvious contempt of basic rights. Surely each citizen has a right to be secure from capricious impositions? But who will champion and enforce such rights?

There is a clear conflict of interests around the idea that Microsoft, Amazon. Oracle or Meta can offer security to people whose very exploitation is their business model. BigTech cannot offer cybersecurity because BigTech is the cybersecurity problem. Who will protect people against the companies that want to take over their lives? Will we see organisations like CISA and the UK NCSC position themselves openly against BigTech? Will we ever see a (much needed) government warning against using Microsoft products?

But expensive open conflict is not a long-term solution. These problems need sorting out in law. So as a basis it seems much clearer if we re-frame such violations as a failure of responsibility. In the above case of a health provider it is a failure to ensure equality and universal healthcare. Unless of course their claim is that everybody is equally abused by technology and anyone who objects is free to choose dignity rather than life.

long-term solution

Shaming the NHS - who we cheered in weekly rituals banging pots and pans through the pandemic - for its betrayal of patient confidentiality, dignity and ancient Hippocratic Oaths suddenly doesn't feel so wrong or ungrateful. They should not be magically above the data protection laws that everybody else must observe. Now, instead of arguing over rights we should be able invoke the law. Can't deal with my email address? …get fined, go to jail and be forced to fix your system! Surely that's fairer than leaving the outliers to die?

So, framing problems around "responsibility" weighs heavier than any talk about "rights". Consider our responsibility to use cash money for the sake of societal bonds, to switch-off our phones when driving to protect pedestrians and other drivers, have the patience and social skills to speak to a human rather than a machine, take the stairs instead of the lift, use a stronger password, use paper and pencil instead of an "app"… these are all little things that add up to a better technological society with more long term security and resilience.

resilience

But not everybody can…

An objection sometimes levelled against a philosophy of humane responsibility is that it is "ableist". We hear; What about people who have discalcula and can't use money? What about those without legs to climb the stairs? Or people who have social anxiety and prefer robots to other people? What about folks who cannot remember a six digit number and were never taught to write with a pen?

Against this objection is the rather cruel and cavalier retort that society should not design itself around the needs of the lowest common factor. I won't make that, but what I personally hear from less-abled people is surprising agreement, that they experience being used as proxy justification insulting. Indeed I've heard anger when impositions ostensibly about accessibility are made in their name. This was identified many decades ago by disabilities groups as the "Does he take sugar?" phenomenon, and is now subject to a backlash against patronising UX in design. Technology that's inclusive must attend to both least and most able users, and put neither group in conflict with the other.

But perhaps more concerning is the irony that "convenient" technology causes debilitating human conditions. Technologically mediated isolation is a cause of social anxiety. Inactivity and easy motor transport is a cause of poor mobility. Calculators cause discalcula, etc. Being waited on hand and foot by computers and robots makes us scatterbrained and helpless. In its worst formulation this becomes an argument that; yes, technology is a crutch with which we must "limp before the lame", so as to become lame too.

Calculators

In reality almost the complete opposite is true. Digital technology harms the least able disproportionately more. I am exhausted hearing from older people how they cannot use their banking apps and just want to see a real human - but they shut the branch down and now it's a 10 mile drive in to the next town. People with poor education and learning difficulties are bewildered by the inhuman impositions of techno-bureaucracy. Sometimes they require a full-time helper/mentor just to navigate life and the social care system. People with poor eyesight and attention who are forced to use phone apps just give up. Systems are designed with dark patterns to confuse folks so they don't collect benefits or pay more for services than they should. These disproportionately harm poorer people with less education or additional needs.

poor education

Algorithms tuned for "efficiency" make this happen even if there is no direct human malice. Therefore the malice is deploying these algorithms in the first place. As coders we must question deeply what we are working on and refuse to participate in projects that raise controversial ethical questions.

And I say this coming from the UK where we actually have one of the best government web presences in the world, with high accessibility, bullet-proof availability, and plain English content. It is heartbreaking to see so much dedicated engineering go into something that underneath rests on a morally bankrupt ideology of gushing neophilia.

Our injury can often be traced to a failure of Law. The legal world has never really understood or kept pace with technology - which is praise not a criticism since Laws should be stable, steady and throughtful. However, most "cyberlaw" seems to have been written to protect those who are now the aggressors. For example the UK Computer Misuse Act 1990 (that now seems so naive and woolly as to be a crime in itself) defines misuse only in terms of "authorisation". Computers are misused in thousands of insidious ways to visit harms on peaceful, law-abiding citizens who just want to mind their own business.

failure of Law

As zero trust becomes the vogue security fad, explicit authorisation is practically dead as a concept in 2024. When was the last time you "authorised" BigTech to steal your personal information from your phone? As written, the 1990 Act is a charter for the powerful to abuse the helpless. It remains in place because of course there is a need to prevent violations of computing perimeters, but it now looks woefully inadequate, a speck in the landscape of digital harms that have evolved since that time. If reformed it will likely add nothing to redress the victims of daily corporate intrusion.

As we look around the world today we see that the unilateral imposition of digital technology on terms dictated by corporations and governments has led to a significant loss of basic rights, freedoms and psychological safety for the majority. That is not to say digital technology hasn't brought immense benefits, but one is not excused from inflicting injury by bundling it a priori with compensation (especially where there is no mutuality and the harms were unnecessary in the first place if you'd just been a little bit smarter).

inflicting injury

Much discussion of technology and security today is about balancing the needs of governments and business. Conspicuously missing from that discussion is any talk of "the people", the public, the hoi polloi. So "digital rights" might be a way of talking about the huge gap in that landscape, where ordinary folk are victims of " Police and thieves in the street", and whose voices are ignored.

ignored

So we must accept that not everyone can join in the "technological society". Not everybody should. Not everybody wants to even if they could, therefore any system that does not recognise those voices neither has nor deserves a future. "Responsibility" then is a much more complex tool than it first appears and does not easily fall to the ableist objection.

Responsibility

Other Recent Techrights' Posts

Congrats to Linux.org for Adopting or Getting Back to IRC
This is the way the Net ought to work and was originally designed to work [...] IRC as a protocol turns 38 this month
 
The Tragedy of Software Developers Making Up Narratives and Making Excuses for Plagiarism (of Their Own Work, Too)
one lingering issue is that many who vote in Debian GRs receive money from slop companies
Evri Makes Us Optimistic About the Collapse of the Slop Pyramid Scheme (Bubble)
Do not be seduced by false promises of "automation" or "intelligence" where only automation may exist but no intelligence at all
Links 24/08/2026: "Journalism Can Help Expose Bad Science And Trigger Real-World Change"; Further Suppression and Censorship in China/HK
Links for the day
Gemini Links 24/08/2026: Soul Mentality, Words to Live by, Mozz.us Gemlog Resumes, Smol Conversations
Links for the day
Today The Register MS Published Greenwashing Spam for the Slop Pyramid Scheme, It Mentions "AI" 29 Times
More people need to talk about the role of the media in this pyramid scheme
Slop Plagiarism and Chatbots Are Killing Evri (They Infuriate and Insult Clients)
Slop destroys companies and leads to misery (miserable clients, time-wasting)
Links 24/08/2026: Re-defining the IndieWeb and "Data Center Backlash Bursts Into the Midterms"
Links for the day
The Issue With Omarchy is the Slop, the Politics Are a Side Issue
Those corporations do not oppose slop, they participate in it
In South Korea, Steady Increases for GNU/Linux
authorities said they would migrate to GNU/Linux or consider moving in that direction
SLAPP Censorship - Part 160 Out of 200: In Astounding Repetition of Last Year, Brett Wilson LLP Deliberately Ignores Holidays of People It is Attacking and Crushes Principles of Access to Justice
Disconnected from the law
Links 24/08/2026: Vision and Skill, Doing Good, Chiperia Project
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, August 23, 2026
IRC logs for Sunday, August 23, 2026
Gemini Links 23/08/2026: Turning 60, PineTime, and Simulation Hypothesis
Links for the day
Will Your "Modern" New Car Still be on the Road in 2060?
Are people now expected to change a car as often as they replace a mobile phone and, if so, how fast would costs add up?
The Sniff Test
Be sceptical of "CoCs"
Cloudflare Sees a Quarter of Requests in China Coming From GNU/Linux Today
Will 23% ever be the average for GNU/Linux rather than a mere peak?
You Can Lose Some Battles and Still Win the War
Winning or losing isn't something for a scoreboard
GNU/Linux Usage Measured at 23% in Russia Today
the average was almost 10%
Things Not to Fear Missing Out on
Life is too short to pay attention to social control media
Gemini Links 23/08/2026: Exercising Again, Tackling Phone Addiction, and Putting Graal Online Back Online
Links for the day
Northern Africa: GNU/Linux Measured at Around 5%
by Clownflare
PIPs and Lawsuits: On the Future of IBM Trying to Spit Out Its Own Staff at Minimal Cost
"I'd rather be laid off than be put on a PIP"
France: GNU/Linux Averaging at 7%, Peaked at 14% Today
When will 14% be the average?
Links 23/08/2026: Water Crises, Illegal Tariffs, and Carney Confronts US Over Patent Imperialism
Links for the day
Links 23/08/2026: Slop "Children's Stories Contain Bizarre Patterns" and "Butterflies at the One Garden"
Links for the day
SLAPP Censorship - Part 159 Out of 200: Telling Courts False Information and Spoon-feeding Them Insults, Hoping or Expecting Them to Repeat These Insults
When lawyers trick courts into repeating something false
Microsoft is in Double Trouble in Singapore
Android+GNU/Linux+ChromeOS are near 20%
The Slop Industry Bribed the Media to Pretend It Has Something New and Revolutionary. Now It Bribes Politicians Too. Anything to Avoid Scrutiny and Regulation.
borrowed money has long been used to bribe the media
"AGI" is Decades Old and It Never Found a Viable Business Model or Real, Actually Useful Use Cases
I keep reminding people of local firms (right here in Manchester) doing the same thing the media now calls "AGI"...
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, August 22, 2026
IRC logs for Saturday, August 22, 2026
Microsoft to Its Workers in April-May: You're Too Old, Go Away. Microsoft in August: Young People, Go Away.
What does this company even sell anymore?
Clownflare Data US-Centric
We are assuming that for national security reasons not many sites in Chinese (or based in China) outsource their traffic to Clownflare
Gemini Links 22/08/2026: Broken Car, Devuan, and Thundermail
Links for the day
Links 22/08/2026: Prince Harry, Elton John and Others Pay High Price for Frivolous Litigation in the UK
Links for the day
'Voluntary' Mass Layoffs at IBM/Red Hat
IBM does not want people to notice what truly goes on there
Another Round of GAFAM Layoffs, This Time Apple
Now Apple "is shutting down an entire Vision Pro team focused on developing gaming features for the mixed-reality headset."
Gemini Links 22/08/2026: The Bodyguard (1992), Minimalism, Backups, and IPFS
Links for the day
SLAPP Censorship - Part 158 Out of 200: Making Alliances With Men Arrested for Strangling Women Was Always a Terrible Strategy
They work for American slop companies
Links 22/08/2026: TikTok Settles With Feds, Harms Caused by Social Control Media Gaining Attention
Links for the day
New Data Shows Microsoft's XBox is Really Dying
XBox is a "burning platform"
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, August 21, 2026
IRC logs for Friday, August 21, 2026