Tuesday, April 21, 2015

Draft Final - Institutional Loyalty



Institutional Loyalty

In 2011 Aaron Swartz, was arrested for downloading nearly five million files from JSTOR, a digital library of mass academic journals, by infiltrating a network on the Massachusetts Institute of Technology campus. Swartz was caught on camera by MIT when he was re-entering the network closet to replace the storage devices he was using at the time to hold the downloaded information. Swartz believed that information should not be wholesaled, especially when the research for the journals were funded by tax dollars. He believed that the information should have been open source, and available to anyone interested for free. Although he only downloaded these journals and did not release them MIT saw this as criminal activity. Due to the lack of institutional leadership and loyalty, the MIT Police quickly concluded that this bulk downloading was theft before any other possibility. The prosecutors on this case pushed for the firmest penalties, which could have included a 35 year prison sentence for Swartz, and MIT stood silently by and watched. This and further troubles led to Swartz taking his own life in 2013. 

MIT has a long standing tradition of encouraging its colleagues to follow their curiosity wherever it may lead them, even if that’s somewhere they are not authorized. The nation’s leading University adopts a culture of openness. MIT main lobby doors are always unlocked, and the computer networks are set up for easy guest access. The concept of sharing information and the hacker’s ethic was born in their computer labs in the 1950’s and 60’s, and is still very alive today. Due to this many say that MIT has Swartz’s blood on its hands. Swartz’s defenders would later argue that he had guest access to MIT’s network, and that charges to this extent, or at all could have been avoided. MIT could have asked for the charges to be dropped just like JSTOR did. Instead, the university chose to remain neutral, and in doing so contradicted its adopted culture that encourages openness.

How could a university that boasts about its community of hackers and hackers abilities turn around and let a member of that community be prosecuted? Every year MIT holds a self-declared hackathon type event where students and affiliates are asked to show off their talents and abilities, the results are then posted on MIT’s site and can be read here. This begs the question of where MIT’s obligation and/or loyalty reside. Is it with their self-produced hacker community, or with obsolete and unjust laws?  This institution relies on the computer prodigy’s and the hacker community and should remain loyal to them. They should not contradictorily prosecute them for their success. Philosopher Josiah Royce argued that as a member of a group, we share the standards of that group. MIT is the leader of that group, and should set equal standards for all while reaming loyal to that culture. Royce also argued that loyalty gives security, and offers ready-made standards. This holds very true to this case. MIT should have remained loyal to Swartz and his quest, and recognized him as a member of their own hacker community and protected him from prosecution. Another philosopher, W.E.B. DuBois also argued that values are bound up with social group identity. We are members of a nation first, then of a culture, and then a subculture, and we may adopt values consistent with loyalty to those groups. The group in question here is the hacker community. With being a “hacker” there is a hacker ethic or philosophy that is adopted. The vital topics within this ethic are access, freedom of information, and improvement to quality of life. This is what Swartz was striving for, and MIT put a stop to. 


In 2013, MIT hinted that they could have handled the case better and is now considering internal reforms. The institute is changing how they handle network infractions, and plan on handling the issues internally. John Riser was a philosopher that took a stance on obligation to society and loyalty to community. He argued that obligation is displayed toward rules or requirements of formalized roles stemming from a membership in society. I believe that MIT should have been obligated to take a stance in the Swartz case to protect the community it creates. Instead they remained silent and in the process of doing so, the community tragically lost a valuable member.  Now, MIT is obligated to change course to remain a respectable, working member in that community.




Sources:




Social Engineering Challenge I Don't Know What Number: I Just Couldn't Do It

My mission for this week was to get a fellow player to send me their homework so I could copy it or cheat.

Unfortunately, the mission ended there. Academic integrity is extremely important to me, and I just couldn't do it. I've worked very hard for the grades I've received, and I could see myself doing nothing else but continuing to work hard. I'm a first-generation college student (and soon graduate) in my family. This might just be community college, but it means a lot to me, and I couldn't put that aside for a few points on the leaderboard.

That is all.

- The Admiral

Monday, April 20, 2015

DRAFT: What's All the Buzz About?

            Hacking isn’t all about little guys and questionable governments. Hacking can be, and is also done by large companies, many of which we freely give troves of personal information. Take Google, for instance. Do you have a Gmail account? If so, think about all the information that has passed through that account. Google now has a copy of it. Surely they wouldn’t do anything nefarious with it, right? Well, they did with Google Buzz. While the idea of consent shouldn’t be a fuzzy gray area, it often is, and Google used that to their advantage.

            So what happened? In 2010, Google casually dropped an email in every Gmail user’s inbox. They were promoting a new service called Buzz. The email was light on details, and prompted interested users to click a link to learn more. That seems innocent enough, until one realizes that link is an opt-in button for the service. One click and Buzz was enabled. Once activated, Buzz analyzed the user’s Google account, including their entire email history. Some information was made public by default, like who the user interacts with often (with full names and email addresses). Did users really consent to this? I would argue that they did not.

            We’re all very familiar with the EULA – End User License Agreement. They can be dozens or hundreds of pages long, and few users ever read even the first line. Those who do are met with endless legalese that makes little to no sense for the average person. Sound familiar? The same thing happened a few years ago before the housing bubble burst. Thousands of families, who by all proper standards were not fit to have a mortgage, were pushed into signing cryptic documents on the premise of a mortgage. Many later discovered hidden fees and steep penalties lurking in those documents, and hundreds went into foreclosure because of them. The problem? They didn’t really understand to what they were agreeing. The same is true for Google’s user agreement. Nobody truly understands what we’re giving Google “permission” to do.

            In this case, consent to Google’s user agreement could be called tacit. That is, we all check the box saying we’ve read and agreed, but don’t actually take the time to figure out what we’re agreeing to. In addition, a majority of users (in most cases) won’t take any action if they discover Google is doing naughty things with their information. A. John Simmons notes tacit consent is “given by remaining silent and inactive; …it is expressed by the failure to do certain things.” By continuing to use Google’s services, even those not connected to Buzz, users tacitly consented to Buzz’s practices. Apathy can be dangerous, as seen with Buzz. Without taking any action, troves of personal information remained available with no protections. Was this right for Google to do? Absolutely not, and they received strong backlash for it. Tacit consent only worked as long as users remained ignorant of what was happening. With Buzz, that changed quickly.

            On the idea of ownership (as it applies to consent), Google puts users in a predicament. In order to use Google’s services as advertised, and to their full capability, users must provide some amount of personal information. By actively providing this information, users are exercising explicit consent, in that the information is provided willingly. What’s interesting to consider is that at that point, who owns the data? Does it still belong to the user, or does Google take ownership once it’s on their servers? While John Doe still owns the rights to his own name, Google’s user agreement grants them the rights to do whatever they please with their copy of John Doe, and any other information connected to him. John wanted to use Google services, so he had to provide some of his information. In a sense, he entered into a social contract with Google, to which John Rawls notes, “unjust social arrangements are themselves a kind of extortion, … and consent to them does not bind.” To reiterate, Google required information in order to use their services. The only alternative option is to not use the service, and we all secretly judge people who don’t have an @gmail.com email address. Enough said on that.

            Like the newer Google+, the grand idea behind Buzz was to create a new social network—one that users would welcome into their private lives with open arms. Google’s aim was likely to collect information for marketing purposes, and provide ultra-targeted advertising and content suggestions based on email conversations and frequent contacts. Some people just don’t want that. Personally, I block all ads. If one slips through my filters, I block it manually. I don’t care what Google wants me to see; I care what I want to see. I consent to Google’s data mining to a very small extent, and I control my settings tightly. If they try to pull some shady business, I speak out (as should everyone). Advertising can be a cash cow, so Buzz was a great business idea. Google just took it way too far.


- The Admiral

Social Engineer Challenge 9: Gym Session

My task this week was to get a fellow member to do an activity with me outside of campus.

I once bumped into CaptainBlack X31 at our neighborhood gym sometime last year and I haven’t seen him there since. So after class I asked him why hasn’t he been at the gym and he said that he’s been busy with work and homework assignments. I told him I’ve been busy too, but with summer around the corner, I’ve been going lately. I told him that he should too and that he should show me some workouts. He seemed a little skeptic at first but later agreed. So we made plans to meet the next day around 5pm. Gym was a success. He showed me a lot of different workouts and pushed me to lift more than my usual. Mission accomplished.

My strategy of targeting the closest fellow player that lived next to me was pretty effective because he already had a membership at the same gym.

The moral stake is listening to your gut feelings. Everything in this class could and will be another player’s task since I never bothered asking him to go to the gym before.

There is nothing I can do with having him go to the gym with me unless I didn’t know where he lived before and decided to get him to go somewhere so I can stalk him back.


CaptainBlack X31 and I made a handshake that we were both not going to target each other for our tasks, but I see we both lied. I actually felt bad doing this but knowing everybody had their guard up, there was no way I would have been able to meet outside of campus with any other fellow player. 

Mission #9



This week my mission was to collaborate with a fellow player to complete a mission of my choice. I immediately got to work on this and first tried to solicit the professors as a fellow player to complete my mission, but was denied. My strategy quickly turned to an all-out search for my collaborator. I threw out every line I could, hoping to get a bite. I started with the people closest to me, but no one trusted me and thought they were being tricked. I then hit the social media streets and started messaging and emailing any fellow player that I saw checking their phones, or email. I reached out to AgentBlueRaven and BAM, we were on to the mission. We decided the mission would be to get the Professor to read a joke out loud to the class. We wrote back and forth in class plotting our mission, and decided to print the joke out via the classroom computers connected to the class printer.  Then she would deliver it to the Professor off the printer and hope for the best. 

One “cheesy” joke later and Mission Complete! The joke was read out loud with no hesitation and with full cooperation. Perfect. 

During this mission I went for an all or nothing strategy and it worked. I sent a message to almost everyone in class, waiting for a reply. I didn’t expect certain players to answer out of fear of being tricked, but knew someone would eventually join me. I was about to throw a paper ball at AgentBlueRaven for her to open her email when she replied to me via messenger. 

There was no moral issue with this mission, unless I was tricking them into helping me as part of a mission, and I was not. This mission’s difficulty was getting a fellow player to join in my shenanigans. The mission was fun, and I learned that the Professor will play along and read jokes out loud to the class when prompted, which may come in handy for a future mission. 

Til next week!