Bonum Certa Men Certa

Technology: rights or responsibilities? - Part III

posted by Rianne Schestowitz on Oct 09, 2024

By Dr. Andy Farnell

Back to Part I

Back to Part II

Rights and security

Whereas cybersecurity has traditionally been limited to businesses and organisations, what I call "civic cybersecurity" is concerned with obtaining and keeping a safe and fair digital world for everyone. So let's venture the idea that "digital rights" is something that makes sense when we broaden the purview of cybersecurity to include ordinary and everyday living.

In the media, civic cybersecurity tends to focus on the dramatic, on stopping planes being hacked to fall from the sky and power grids from melting down. The latest offering in the UK is the very entertaining Nightsleeper, a kind of British "Mr. Robot".

Though I teach in an area where we consider nasty and disturbing stuff from drone swarms terrorising stadiums to autonomous vehicles carrying bombs, these sorts of worst-case fantasies rarely happen for pragmatic psychological reasons rather than questions of possibility. Elaborate kinetic violence requires extraordinary levels of organisation, long term commitment and fanatical malice. Most of the civilian horror we see is more spontaneous and makes use of commonplace weapons like knives and vehicles. Stuxnet style terror stunts, like hackjacking the London Eye and centrifuging tourists into low Earth orbit requires Tom and Jerry levels of improbability.

For defenders, constantly worrying about marginal "what-ifs?" is sapping and distracts from the everyday attacks that are already commonplace. Ironically some of these less dramatic attack surfaces are less obvious to those with over-active imaginations.

imaginations

Most of what we deal with in civil cybersecurity is teenagers getting cyberbullied into a suicidal state, or old people who've been robbed of their life savings. These crimes are almost always outside the practical capacity of the police and so are seldom dealt with. Their root lies in awful software and systems designed to put profit, spying and domination ahead of safety and human values. It's not just that code is insecure, but that the design, protocols and features of the applications are hostile to users.

life savings

For a long time a "techlash" has been brewing against the handful of massive companies and unelected power centres that presume to tell us how to live our lives, causing harm to individuals and society in their own self-interest. Head of US Cybersecurity and Infrastructure Security Agency (CISA) Jen Easterly recently called-out BigTech for their criminally defective products and entitled "techno exceptionalism". The reality is that the accumulated negative impact of BigTech in its effects on health, wealth and happiness outweighs anything terrorists ever achieved on US or British soil - except indirectly by creating the money-pit of state surveillance and media circus of fear.

Let's take an seemingly innocuous example of being unable to obtain healthcare because your hospital only accepts Gmail addresses. This is a catastrophic failure of social security that has roots in bad technology and also insane policy. It is evil in it's sheer mundanity.

healthcare

email addresses

Or consider the betrayal of selling patient medical records to research companies (despite repeated opting-out) such that people no longer have confidence in their GP and avoid visits. These actions certainly cause deaths. Yet on the surface they seem inconsequential.

Or attacking the use of cash money and local economies so that small businesses and the rural poor are disadvantaged. This constant low-level technological violence is against the invisible fabric of society, not our visible symbols. It is the subversive craft that Yuri Bezmenov outlined following his defection in the 1970s. The cruel twist is to get our own people doing the dirty work so that Moscow and Beijing don't need to lift a finger. The truly poetic masterstroke is to have us dismantle our own society in the belief we are "building a better, more efficient world". I think our international enemies cheer every time our governments give a little more power to Microsoft, Amazon or Google.

These acts of social sabotage use technology which makes ordinary malice easy and convenient. Ordinary moral weakness, ignorance, greed and neglect, met by "convenient solutions", enable a witless many to have more impact than any dramatic spectacles perpetrated by a militant few. Planes flying into buildings are news, but hundreds of thousands of road deaths due to texting-and-driving is nothing to see or care about. What we confuse are "terror" and "sabotage". Whereas the terrorist likes to put on a show, the saboteur is happy if his corrosive work goes unnoticed.

Whatever uneducated and dishonest rationales might be offered, behind them is a devious policy decision in obvious contempt of basic rights. Surely each citizen has a right to be secure from capricious impositions? But who will champion and enforce such rights?

There is a clear conflict of interests around the idea that Microsoft, Amazon. Oracle or Meta can offer security to people whose very exploitation is their business model. BigTech cannot offer cybersecurity because BigTech is the cybersecurity problem. Who will protect people against the companies that want to take over their lives? Will we see organisations like CISA and the UK NCSC position themselves openly against BigTech? Will we ever see a (much needed) government warning against using Microsoft products?

But expensive open conflict is not a long-term solution. These problems need sorting out in law. So as a basis it seems much clearer if we re-frame such violations as a failure of responsibility. In the above case of a health provider it is a failure to ensure equality and universal healthcare. Unless of course their claim is that everybody is equally abused by technology and anyone who objects is free to choose dignity rather than life.

long-term solution

Shaming the NHS - who we cheered in weekly rituals banging pots and pans through the pandemic - for its betrayal of patient confidentiality, dignity and ancient Hippocratic Oaths suddenly doesn't feel so wrong or ungrateful. They should not be magically above the data protection laws that everybody else must observe. Now, instead of arguing over rights we should be able invoke the law. Can't deal with my email address? …get fined, go to jail and be forced to fix your system! Surely that's fairer than leaving the outliers to die?

So, framing problems around "responsibility" weighs heavier than any talk about "rights". Consider our responsibility to use cash money for the sake of societal bonds, to switch-off our phones when driving to protect pedestrians and other drivers, have the patience and social skills to speak to a human rather than a machine, take the stairs instead of the lift, use a stronger password, use paper and pencil instead of an "app"… these are all little things that add up to a better technological society with more long term security and resilience.

resilience

But not everybody can…

An objection sometimes levelled against a philosophy of humane responsibility is that it is "ableist". We hear; What about people who have discalcula and can't use money? What about those without legs to climb the stairs? Or people who have social anxiety and prefer robots to other people? What about folks who cannot remember a six digit number and were never taught to write with a pen?

Against this objection is the rather cruel and cavalier retort that society should not design itself around the needs of the lowest common factor. I won't make that, but what I personally hear from less-abled people is surprising agreement, that they experience being used as proxy justification insulting. Indeed I've heard anger when impositions ostensibly about accessibility are made in their name. This was identified many decades ago by disabilities groups as the "Does he take sugar?" phenomenon, and is now subject to a backlash against patronising UX in design. Technology that's inclusive must attend to both least and most able users, and put neither group in conflict with the other.

But perhaps more concerning is the irony that "convenient" technology causes debilitating human conditions. Technologically mediated isolation is a cause of social anxiety. Inactivity and easy motor transport is a cause of poor mobility. Calculators cause discalcula, etc. Being waited on hand and foot by computers and robots makes us scatterbrained and helpless. In its worst formulation this becomes an argument that; yes, technology is a crutch with which we must "limp before the lame", so as to become lame too.

Calculators

In reality almost the complete opposite is true. Digital technology harms the least able disproportionately more. I am exhausted hearing from older people how they cannot use their banking apps and just want to see a real human - but they shut the branch down and now it's a 10 mile drive in to the next town. People with poor education and learning difficulties are bewildered by the inhuman impositions of techno-bureaucracy. Sometimes they require a full-time helper/mentor just to navigate life and the social care system. People with poor eyesight and attention who are forced to use phone apps just give up. Systems are designed with dark patterns to confuse folks so they don't collect benefits or pay more for services than they should. These disproportionately harm poorer people with less education or additional needs.

poor education

Algorithms tuned for "efficiency" make this happen even if there is no direct human malice. Therefore the malice is deploying these algorithms in the first place. As coders we must question deeply what we are working on and refuse to participate in projects that raise controversial ethical questions.

And I say this coming from the UK where we actually have one of the best government web presences in the world, with high accessibility, bullet-proof availability, and plain English content. It is heartbreaking to see so much dedicated engineering go into something that underneath rests on a morally bankrupt ideology of gushing neophilia.

Our injury can often be traced to a failure of Law. The legal world has never really understood or kept pace with technology - which is praise not a criticism since Laws should be stable, steady and throughtful. However, most "cyberlaw" seems to have been written to protect those who are now the aggressors. For example the UK Computer Misuse Act 1990 (that now seems so naive and woolly as to be a crime in itself) defines misuse only in terms of "authorisation". Computers are misused in thousands of insidious ways to visit harms on peaceful, law-abiding citizens who just want to mind their own business.

failure of Law

As zero trust becomes the vogue security fad, explicit authorisation is practically dead as a concept in 2024. When was the last time you "authorised" BigTech to steal your personal information from your phone? As written, the 1990 Act is a charter for the powerful to abuse the helpless. It remains in place because of course there is a need to prevent violations of computing perimeters, but it now looks woefully inadequate, a speck in the landscape of digital harms that have evolved since that time. If reformed it will likely add nothing to redress the victims of daily corporate intrusion.

As we look around the world today we see that the unilateral imposition of digital technology on terms dictated by corporations and governments has led to a significant loss of basic rights, freedoms and psychological safety for the majority. That is not to say digital technology hasn't brought immense benefits, but one is not excused from inflicting injury by bundling it a priori with compensation (especially where there is no mutuality and the harms were unnecessary in the first place if you'd just been a little bit smarter).

inflicting injury

Much discussion of technology and security today is about balancing the needs of governments and business. Conspicuously missing from that discussion is any talk of "the people", the public, the hoi polloi. So "digital rights" might be a way of talking about the huge gap in that landscape, where ordinary folk are victims of " Police and thieves in the street", and whose voices are ignored.

ignored

So we must accept that not everyone can join in the "technological society". Not everybody should. Not everybody wants to even if they could, therefore any system that does not recognise those voices neither has nor deserves a future. "Responsibility" then is a much more complex tool than it first appears and does not easily fall to the ableist objection.

Responsibility

Other Recent Techrights' Posts

Brittany Day Can Rest and Let Microsoft/Chatbots Write Fake 'Articles' About "Linux" This Christmas
Who said people don't work on Christmas? Chatbots or plagiarism-as-a-service work 24/7, every day of the year except during Microsoft downtimes
 
Links 25/12/2024: Fentanylware (TikTok) Scams and "Zelle Scams Lead to $870M Loss"
Links for the day
Links 25/12/2024: Windows TCO Brought to SSH, Terence Eden 'Retires'
Links for the day
Gemini Links 25/12/2024: Reality Bites and Gopher Thanks
Links for the day
Links 25/12/2024: Latest Report Front Microsoft Splinter Group, War Updates
Links for the day
Links 25/12/2024: Hong Kong Attacks Activists During Holidays, Xerox to Buy Lexmark
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, December 24, 2024
IRC logs for Tuesday, December 24, 2024
Gemini Links 25/12/2024: Open Source Social and No Search
Links for the day
Brittany Day Connects Windows Ransomware to "Linux" Using Microsoft LLMs (FUD Galore, Zero Effort, No Accountability)
FUD and misinformation made by Microsoft LLMs again?
Links 24/12/2024: Labour Strikes and TikTok Scrambling to Prop Up Radical Politicians That Would Protect TikTok
Links for the day
Where the Population is Controlled by Skinnerboxes Inside People's Pockets (or Purses)
A very small fraction of mobile users practise or exercise freedom/control over the skinnerbox
[Meme] Coin-Operated Publishers (Gaming the Message, Buying the Narrative)
Advertise (sponsor) to 'play'
Advertisers and Their Covert Impact on Publications' Output (or Writers' Topics of Choice, as Assigned or Approved by Editors)
It cannot be trivially denied that sponsorship in the form of "advertising" impacts where publishers go (or don't go, won't go)
Terrible Year for Microsoft Windows in Cyprus
down from 86% to 72% since January
[Meme] How to Kill Unions (Staff on Shoestring Budget Cannot Afford Lawyers)
What next for the EPO? "Gig economy"?
The EPO's Staff Union (SUEPO) Takes Legal Action to Rectify the Decrease in Wages (Lessening of Purchasing Power)
here is what the union published
Gemini Links 24/12/2024: Deedum Gemini Client Gets Colour Support, Advent of Code 2024
Links for the day
Microsoft Windows Slides to New Lows in Colombia
Now Windows is at an all-time low
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Monday, December 23, 2024
IRC logs for Monday, December 23, 2024
A Strong and Positive Closing for the Year's Last Week
In a lot of ways this year was a good one for Free software
Feels Too Warm for Christmas
Christmas is here, no snow in sight
Links 23/12/2024: 'Negative Time' and US Arms Taiwan Again
Links for the day
Links 23/12/2024: The Book of Uncommon Beings, Squirrels, and Slop Ruining Workplaces
Links for the day
Links 23/12/2024: North Korean Death Toll in Russia at ~1,100, Oligarch Who Illegally Migrated/Stayed (Musk) Shuts Down US Government
Links for the day
The World's 'Richest Country' Chooses GNU/Linux
This has gone on for quite some time
Richard Stallman on Love
Richard Stallman's personal website includes a section that lists three essays on the subject of love
Apple's LLM Slop Told Us Luigi Mangione Had Shot Himself, BetaNews Used LLMs to Talk About a Dead Linus Torvalds
They can blame it on some bot
Microsoft, Give Me LLM Slop About "Linux" and "Santa", I Need Some Fake Article...
BetaNews is basically an LLM slop site
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, December 22, 2024
IRC logs for Sunday, December 22, 2024