Showing posts with label NSA. Show all posts
Showing posts with label NSA. Show all posts

Friday, August 19, 2016

This post is not about politics

This post is not about politics. 

But it is about the election, and it’s important. Let me state it bluntly: the increasing computerization of our electoral process is putting our democracy at risk. The process as it exists now is broken and we need to bring back a foolproof paper balloting system that everyone can understand and trust.

Look at two of the many story lines of this year’s election. On the one hand, we have a candidate who has repeatedly claimed that the political system and the election is “rigged”. He’s already predicting that if he loses it will be because the other side cheated. Put aside your opinion of the validity of this claim: the fact is that he may, and probably will, seek to delegitimize the likely result of the election, an idea that will undoubtedly resonate with many of his supporters. An election mistrusted by a large portion of an angry electorate does not bode well for good and peaceful governance of our nation after election day.

Now consider the second story line: the very disturbing extent to which many of our government systems have been penetrated by America’s adversaries. Whether it was the Russians, or WikiLeaks, or another intermediary, the fact is that some very important systems that were (or should have been) well-guarded were compromised and hacked. This includes the most protected servers of the NSA. These stories do nothing to instill confidence in America’s systems amongst the general public. Anyone paying attention would conclude that no system is hack-proof to a determined, skilled and well-funded adversary. I agree that this is true, don’t you?

Now look at the way elections are conducted across America. It’s a vast patchwork of locally-managed, often shoestring operations incorporating various degrees of computer and software tools. Some touchscreens here, some Windows 2000 operating systems there, you name it, it’s out there. Security? Maybe. World-class IT security? Don’t bet on it. The men in black at the NSA (who can’t even guarantee the security of their own systems) are not managing the security at the local polling place. The systems out there are vulnerable and we don’t even know how bad it is.

We have been waiting many years for the election process to mature into a secure, stable, uniform process that takes advantage of computerized tools; one that would be secure, easy to use, fast and auditable. And above all, trustworthy.

It has not happened. It has only gotten worse. I have followed this subject for a long time as part of my course in IT Ethics at Immaculata University. The systems continue to age, break down and expose their flaws, while vendors and local electoral officials fight a losing rearguard action to keep up. The systems have proven to be hackable and failure prone over and over. In many cases, the lack of auditable paper trails have resulted in votes being lost again and again. This is not speculation, but reported fact. And now we face the prospect of foreign adversaries with an interest in meddling in our election, coupled with an angry faction ready to believe that the whole process is crooked.

A recent op-ed piece in the New York Times by Zeynep Tufekci, called Bring Back Paper Ballots, makes a strong case against our broken system and urges us to return to a paper balloting system that is impossible to hack, fully capable of being audited and re-verified, baby-simple to use and worthy of our trust. Among the quotes in the piece is this one from Matthew Green, a specialist in cryptology and cybersecurity at Johns Hopkins University (no Luddite he): “There is only one way to protect the voting systems from a nation-state funded cyberattack: Use paper.”

I have been convinced by Tufekci’s argument and I agree that our electoral process is one place where computerization will work not to our benefit but to our detriment. As an IT guy it’s hard for me to admit that, but as a citizen, it’s a no-brainer.

Paper based systems need not be primitive or cumbersome. My county (Chester County, PA) uses an Optical Mark Recognition (OMR) system, often called “fill in the bubble”. It’s simple and scanable, results are computable quickly, it’s hard to tamper with and, best of all, the paper can be saved and recounted if there’s a dispute. I think this should become the electoral standard everywhere.

We cannot allow the results of our next election, and many after that, to be put at risk and tainted by doubt and denial. We must have a process that every citizen can trust and no one can tamper with. Let’s go back to a good paper balloting process.


Sunday, January 5, 2014

The IT Ethics story of the year


You’ve probably seen some of the end of year tech wrap-up stories. The struggles of the web site HealthCare.gov certainly trained a big bright spotlight on web development projects, so much so that the president had to apologize for the troubled project. The other big story of 2013 had to be the revelations of the NSA surveillance programs by Edward Snowden. As the Obamacare web site slowly rights itself, I think it’s clear that the NSA revelations will turn out to have the more lasting impact.

I have not blogged about this story until now, partly because my opinions were complex and still evolving. And frankly, I've been surprised at how my assessment of Snowden himself has changed over the past half year.

Let’s level-set the story briefly. Edward Snowden was a contracted system administrator with the NSA for four years, and over that time, was troubled by what he learned of the agency’s worldwide secret spying operations – troubled enough to amass a large treasure trove of confidential documents that show what the agency was up to. In May of 2013, he left the country (he had been based in Hawaii) and began releasing the documents through several mainstream media sources around the world. The US government is determined to prosecute Snowden under the 1917 Espionage Act; they have filed charges that could amount to sentences that total at least 30 years in prison. After spending some time on the run, Snowden has won temporary asylum in Russia, which so far has refused to extradite him to the US.

The NY Times recently summed up the highpoints of what Snowden has revealed about the NSA programs:

  • The NSA broke privacy laws or exceeded its authority thousands of times per year, according to its own internal auditor. Presumably, this was as judged by even their own permissive standards of behavior. 

  • They broke into communications facilities and data centers both in the US and around the world, without the knowledge or consent of the targets.

  • They undermined internet encryption and scooped up massive amounts of data indiscriminately, including health and banking data that is protected by federal law.

  • The NSA was rebuked by the FISA court (its nominal oversight body) for misleading it repeatedly about its surveillance practices.

  • And finally, the director of national intelligence, James Clapper Jr., lied to congress under oath last year in denying that the agency was doing what is now proved that it did do.

Snowden has been criticized for an indiscriminate data dump of his own; in attempting to uncover wrongdoing, he has (the criticism goes) jeopardized legitimate covert operations and put US friends and operatives at risk to the enemy. Although the Times stated that no real examples of this have been revealed since the disclosures, it’s hard not to agree that the possibility exists and that Snowden either should have realized this or was wrong to have disregarded it.

However, the positive consequences of the Snowden’s revelations are equally hard to deny. The public debate that he intended to spark has indeed been ignited. Outrage has been equally furious on both ends of the political spectrum (getting them to agree on anything at all is quite a feat in itself) and I believe that outrage is justified. The revelations have been well covered in the press, who now have plenty of their own investigative journalists on the case. And legal challenges have begun their paths through the courts; two federal judges have already ruled against the program (a third has ruled in favor) and undoubtedly the Supreme Court will be asked to decide.

As an IT guy, I’m in awe of the technology that the NSA built and deployed to carry out this mission. I would not have thought that the ability to overcome so many barriers, to acquire, store and analyze such a volume of data, and to do it all secretly, was within the capabilities of any government agency; I was wrong. But as an IT ethicist and concerned American citizen, I am appalled in even greater measure by the audacity of the undertaking and the complete disregard of law and the constitution with which it was carried out. Even now, President Obama seems oblivious to – or uninterested in – the magnitude of the issues at stake here; as someone who once taught a course in constitutional law, you would think he’d know better.

The tradeoff between security and civil freedom is something that cannot be done in secret by bureaucrats alone; it must be subject to a national debate, no matter how fractured the process of our political discourse has become in recent years.

On January 1, the New York Times wrote an editorial saying that Snowden may have broken the law but nevertheless he has done his country a great service, and they called on President Obama to work towards a reduced sentence or even clemency so that Snowden could return home. There is growing support for this approach, from many in media and in government, including several prominent US Senators.

Earlier in the year I was conflicted in my opinions of Snowden the man and his actions. I clearly disliked what I learned about the NSA, but I tended to doubt just how far they could have gone, given what I thought the technical limitations might be. Snowden himself I saw as a naive opportunist who was already on the run from facing responsibility for blowing the whistle as he did. But as revelation followed revelation, and the magnitude of the spying grew (and even now continues to grow) my opinion of Snowden has changed. I see him now as a courageous individual who was right to reveal what he did. He proved to me that I was the one who was naive.

The American people and the world do indeed need to know what is going on. The downside effects are still with us and have to be admitted, but for the greater good, I think the benefits – of giving the American people the oversight of their government that they have a right to have and on which the nation was founded – far outweigh the negatives. It is for that reason that I would name Edward Snowden this blog’s 2013 Man of the Year.

(Snowden and his actions are controversial and opinions of him are bound to be strong. Whatever side your views are on, I'd love to hear them.)