William Gibson makes passing reference to the art and craft forging documents early on in Spook Country, telling about trips to second hand bookstores to buy just the right paper, and ageing credentials by carrying them around.
Nowadays, though, paper is optional. Checks can be deposited by snapping pictures of front and back and sending to the bank, and airlines scan pictures of boarding passes from your phone at the gate.
Paper credentials decentralize verification. When it's difficult to "call HQ" to check identity - which it used to be until very recently - the attestation had to stand on its own feet, carrying the full burden of authenticating not only its bearer but also itself. Nowadays a database look-up is instantaneous, and the database can not only produce the photo of the person making the identity claim, but can also track whether multiple claims are being asserted simultaneously in different places.
The locus of forgery thus moves from the edge to the middle: you don't hack the passport, you hack the passport database. With a suitably large investment in securing the center, it becomes harder for street freelancers to generate credentials as they go, "at retail". However, there is now a single point of failure, and a successful hack of the central database can generate an unlimited number of false documents. As always when moving from bricks to clicks, the upfront cost is huge, but the marginal cost is negligible.
The discretion of, and trust required in, the agent at the edge diminishes. When paper documents had to be checked, officers developed a feel for a fake by handling tens of thousands of them over years, and their instincts could tell them something was off long before the official notice came around. Not all of them were equally good, though, and a rookie might miss a dud that an old hand would see a mile off. Now the quality of authentication depends on the security and agility of the central repository; if it can be broken, or is slow to respond to an exploit, a hack that works will work everywhere, immediately.
One might therefore expect that digital spooks and their paymasters are working not only on building bit-bombs to disable infrastructure, but constructing trapdoors to facilitate the forgery of digital credentials. "Identity theft" is probably not the half of it; identity creation (and destruction) is much more valuable.
"in this world, there is one awful thing, and that is that everyone has their reasons" --- attrib. to Jean Renoir (details in the Quotes blog.)
Sunday, January 02, 2011
Wednesday, December 29, 2010
Law without Categories?
A recent New Scientist story about the descent of birds from dinosaurs (James O'Donoghue, Living dinosaurs: How birds took over the world, Section 2, Was archaeopteryx really a bird?, 08 December 2010; subscription required) contained this passage:
Jurisprudence and regulation in particular is built on categorization, defining categories that determine the response to a particular situation. At the heart of current network neutrality argument is the question of whether a company falls in "Title II" in which case a whole raft of telecommunication regulation regarding common carriage applies, or "Title I" in which case they are much more lightly regulated.
However, as the analogy to biology illustrates, most interesting categories have fuzzy boundaries, making for a delightful amount of work for lawyers and lobbyists, but not necessarily helpful outcomes.
Taxonomies are backward-looking; they attempt to fossilize a reality but are constantly open to revision. (This necessity for revision undermines the certainty which category-based rules purport to offer since categories are less robust than they appear, necessitating the case-by-case interpretation which proponents of rules contend is the weakness of the alternative approach, principles-based regulation.) They evidently work well enough, though; they're pervasive. A paper by David Bach & Jonathan Sallet about VOIP regulation (The challenges of classification: Emerging VOIP regulation in Europe and the United States, First Monday, Volume 10, Number 7, 4 July 2005) explains the situation very well:
A behavioral alternative comes to mind: the regulations that should apply do not derive from the category into which an action falls, but from its consequences; in Bach & Sallet's terms, one needs to look to the political and social outcomes, not the inputs.
The real question is, where do you draw the line between dinosaurs and birds? Ask different palaeontologists and you will get subtly different answers. That is because the distinction is basically arbitrary, says Xing Xu of the Institute of Vertebrate Paleontology and Paleoanthropology in Beijing, China, who discovered many of the Chinese fossils [of feathered dinosaurs].This is a common theme in biology: the boundaries between species are arbitrary. And yet we continue to think in terms of species, since categorization is such a strong human reflex.
Jurisprudence and regulation in particular is built on categorization, defining categories that determine the response to a particular situation. At the heart of current network neutrality argument is the question of whether a company falls in "Title II" in which case a whole raft of telecommunication regulation regarding common carriage applies, or "Title I" in which case they are much more lightly regulated.
However, as the analogy to biology illustrates, most interesting categories have fuzzy boundaries, making for a delightful amount of work for lawyers and lobbyists, but not necessarily helpful outcomes.
Taxonomies are backward-looking; they attempt to fossilize a reality but are constantly open to revision. (This necessity for revision undermines the certainty which category-based rules purport to offer since categories are less robust than they appear, necessitating the case-by-case interpretation which proponents of rules contend is the weakness of the alternative approach, principles-based regulation.) They evidently work well enough, though; they're pervasive. A paper by David Bach & Jonathan Sallet about VOIP regulation (The challenges of classification: Emerging VOIP regulation in Europe and the United States, First Monday, Volume 10, Number 7, 4 July 2005) explains the situation very well:
From a practical point of view, classification stands out because classifying different services is what regulators principally do. In an ideal world, one could just draw up rules for VOIP that address the aforementioned critical issues, keeping in mind the technology’s novelty and the substantial differences that exist between conventional circuit–switched telephony and innovative packet–switched VOIP. In the real world, however, a first step in the regulation of new technologies is usually to try to fit them into existing service categories, in part because those are the tools that regulators work with and in part because classification can provide shortcuts through complex regulatory problems. Alternatively, regulators may be inclined to ask whether VOIP service is "like" or "substitutable" for current services — an approach that may obscure technological achievement. Either way, much is at stake in these decisions.
Fitting VOIP into existing regulatory categories is not simply an administrative or technical act. Since categories are associated with distinct sets of rights and responsibilities that have distributional and market strategic implications, a large number of stakeholders have mobilized to affect the outcome. . . .
Unpacking the political economic dynamics of evolving VOIP regulation highlights a second, more analytic reason to focus on classification. The debate over how to classify VOIP represents the leading edge of the question whether regulatory classification is useful in a world of converging technologies. . . .
In the eyes of most regulators and industry observers, correctly categorizing VOIP provides a shortcut through regulatory uncertainty. Yet precisely this is the problem with classification. As policymakers almost reflexively ask how a new technology fits into existing categories, the underlying political and social objectives of regulation can get lost.
A behavioral alternative comes to mind: the regulations that should apply do not derive from the category into which an action falls, but from its consequences; in Bach & Sallet's terms, one needs to look to the political and social outcomes, not the inputs.
Thursday, December 09, 2010
Not even a metaphor
Said Industry Minister Eric Besson, describing an upcoming auction of radio licenses in France, "These frequencies are of very, very high quality." What? How can a frequency, merely an attribute of electromagnetic radiation, be of high quality?
I’ve been inveighing against the misuse of spectrum metaphors for some time, but it took this quote to make me realize that the figure of speech at issue is really metonymy, not metaphor.
Metonymy is referring to something not by its name, but by something that is intimately associated with it (Wikipedia). Some examples:
Both metaphor and metonymy substitute one term for another: metaphor by some specific similarity, and metonymy by some association. In spectrum language both are at work, for example in “Guard bands leave too many frequencies (or spectrum) lying fallow.”
I’ve been inveighing against the misuse of spectrum metaphors for some time, but it took this quote to make me realize that the figure of speech at issue is really metonymy, not metaphor.
Metonymy is referring to something not by its name, but by something that is intimately associated with it (Wikipedia). Some examples:
The designers come up with the ideas, but the suits (worn by executives) make the big bonuses.
The pen (associated with thoughts written down) is mightier than the sword (associated with military action).
Freedom of the press (associated with the journalists and what they write) is an important value.
The White House (associated with the President and his staff) stood above the fray.
He bought the best acres (associated with the land measured in acres).
Both metaphor and metonymy substitute one term for another: metaphor by some specific similarity, and metonymy by some association. In spectrum language both are at work, for example in “Guard bands leave too many frequencies (or spectrum) lying fallow.”
Metonymy: Frequencies are associated with radio licenses
Metaphor: Radio licenses are like title to property
Metonymy: Property title is associated with the land to which it relates
Metaphor: Fallow land stands for any underused asset
Saturday, December 04, 2010
Heresy as Diagnostic
Heresies, or more exactly, the arguments that lead to one perspective being labeled as orthodoxy and the other as heresy, are pulsing pointers to a religion’s sore spots, those questions of doctrine or practice that have multiple plausible but incompatible answers. Heresy seems to be a useful tool for analyzing a set of beliefs. (Any book recommendations gratefully received.)
I was drawn to the question of heresy by reading Augustine’s Confessions, and Peter Brown’s masterful biography, Augustine of Hippo (1967, 2000). For instance, comparing Augustine and Pelagius, he writes
My guess is that the choice between solutions that leads to a perspective being labeled heresy is necessary for a consistent set of beliefs, but that something is lost when the choice is made. I’m reminded of Isaiah Berlin’s approach to conflicts of values, summed up thus by John Gray in an interview with Alan Saunders on the Philosopher’s Zone (Australian Radio National, 6 June 2009)
Such differences may point to a conflict between incommensurable world views. For example, in an article about “relativity deniers”, (Einstein's sceptics: Who were the relativity deniers?, New Scientist 18 November 2010, subscription required) Milena Wazeck explains,
I would not be at all surprised if there is at least something like this at play in the argument over climate change; opponents have been all but branded as heretics, and there is religious fervor on both sides.
I was drawn to the question of heresy by reading Augustine’s Confessions, and Peter Brown’s masterful biography, Augustine of Hippo (1967, 2000). For instance, comparing Augustine and Pelagius, he writes
“The two men disagreed radically on an issue that is still relevant, and where the basic lines of division have remained the same: on the nature and sources of a fully good, creative action. How could this rare thing happen? For one person, a good action could man one that fulfilled successfully certain conditions of behavior, for another, one that marked the culmination of an inner evolution. The first view, was roughly that of Pelagius; the second, that of Augustine.”
My guess is that the choice between solutions that leads to a perspective being labeled heresy is necessary for a consistent set of beliefs, but that something is lost when the choice is made. I’m reminded of Isaiah Berlin’s approach to conflicts of values, summed up thus by John Gray in an interview with Alan Saunders on the Philosopher’s Zone (Australian Radio National, 6 June 2009)
“ . . . the idea that some fundamental concepts of human values are intractable, rationally intractable, in the sense that first of all they can't be resolved without some important loss, and secondly reason is very important in thinking about these conflicts, and then being clear about what they are, what they're between and what's at stake in them. [E]qually reasonable people can come to different judgments as to what ought to be done, so certain types of conflict of value are intractable. . . . So this idea of a kind of fundamental and intractable moral scarcity if you like in human life, such that there have been and there will always be intractable, the conflicts of values, and we can resolve them more or less intelligently in particular contexts that can be more or less skillful and intelligent and reasonable settlements of these conflicts, but they can never be overcome or left behind.”
Such differences may point to a conflict between incommensurable world views. For example, in an article about “relativity deniers”, (Einstein's sceptics: Who were the relativity deniers?, New Scientist 18 November 2010, subscription required) Milena Wazeck explains,
"Einstein's opponents were seriously concerned about the future of science. They did not simply disagree with the theory of general relativity; they opposed the new foundations of physics altogether. The increasingly mathematical approach of theoretical physics collided with the then widely held view that science is essentially simple mechanics, comprehensible to every educated layperson."
I would not be at all surprised if there is at least something like this at play in the argument over climate change; opponents have been all but branded as heretics, and there is religious fervor on both sides.
Tuesday, November 30, 2010
Better Radio Rights
Demand for wireless services is growing relentlessly, but the ambiguous definition of rights and unpredictable enforcement has led to prolonged inter-service interference disputes that impede innovation and investment.
Silicon Flatirons organized a conference on this topic in DC a couple of weeks ago. The goal was to explore how radio operating rights could best be defined, assigned and enforced in order to obtain the maximum benefit from wireless operations. The event web site has links a fascinating set of position papers prepared by the panelists. There’s also a compendium that collects them all in one place (PDF).
Kaleb Sieh and I proposed (position paper, full paper on SSRN) an approach to radio operating rights based on three principles: (1) aim regulation at maximizing concurrent operation, not minimizing harmful interference; (2) delegate management of interference to operators; (3) define, assign and enforce entitlements in a way that facilitates transactions.
We argue that radio rights should be articulated using transmission permissions and reception protections, defined probabilistically (the Three Ps): transmission permissions should be based on resulting field strength over space and frequency, rather than radiated power at a transmitter; reception protections should state the maximum electromagnetic energy an operator can expect from other operations; both are specified probabilistically. This formulation of operating rights does not require a definition of harmful interference, and does not require receiver standards.
Since any initial entitlement point is unlikely to be optimal, the regulator should facilitate the adjustment of rights by: limiting the number of parties to a negotiation should be limited by minimizing the number of recipients, and enabling direct bargaining by effective delegation; recording a complete and current description of every entitlement in a public registry; stipulating the remedy (injunctions or damages) that attaches to an operating right when it is issued; the regulator refraining from rulemaking during adjudication; leaving parameter values unchanged after an entitlement has been defined, although values may be adjusted though bilateral negotiation between operators, and the regulator may add new parameters at license renewal.
Silicon Flatirons organized a conference on this topic in DC a couple of weeks ago. The goal was to explore how radio operating rights could best be defined, assigned and enforced in order to obtain the maximum benefit from wireless operations. The event web site has links a fascinating set of position papers prepared by the panelists. There’s also a compendium that collects them all in one place (PDF).
Kaleb Sieh and I proposed (position paper, full paper on SSRN) an approach to radio operating rights based on three principles: (1) aim regulation at maximizing concurrent operation, not minimizing harmful interference; (2) delegate management of interference to operators; (3) define, assign and enforce entitlements in a way that facilitates transactions.
We argue that radio rights should be articulated using transmission permissions and reception protections, defined probabilistically (the Three Ps): transmission permissions should be based on resulting field strength over space and frequency, rather than radiated power at a transmitter; reception protections should state the maximum electromagnetic energy an operator can expect from other operations; both are specified probabilistically. This formulation of operating rights does not require a definition of harmful interference, and does not require receiver standards.
Since any initial entitlement point is unlikely to be optimal, the regulator should facilitate the adjustment of rights by: limiting the number of parties to a negotiation should be limited by minimizing the number of recipients, and enabling direct bargaining by effective delegation; recording a complete and current description of every entitlement in a public registry; stipulating the remedy (injunctions or damages) that attaches to an operating right when it is issued; the regulator refraining from rulemaking during adjudication; leaving parameter values unchanged after an entitlement has been defined, although values may be adjusted though bilateral negotiation between operators, and the regulator may add new parameters at license renewal.
Saturday, October 16, 2010
Who gets the apple? Part II: A salty problem
Here's another analogy; one that includes a nod to dispute resolution. For those who know and/or love Coasian economics, it's our old friend the pollution example, though tweaked to be radio interference in light disguise. It's also, incidentally, based on a true story I heard from someone who works for a large county's water district.
Imagine a city along a river, and a downstream farming community. Urban development results in more salt being added to the river; increased salinity can reduce crop yield. Salty water is therefore analogous to radio interference between transmitters (cities) and receivers (farms).
The harm to crops is a shared responsibility, though. For example, the city can reduce the amount of downstream salt by building a water treatment plant, and the farmers can accomodate more salty water by changing crops - spinach will be fine on water that's too salty for celery.
Let's imagine that a Federal Crops Commission (call it the FCC2) is responsible for managing this problem. It might instruct the city and farms to "coordinate" to find a solution to the problem, with a guideline that water may not be "too salty". As in the apple example, this is difficult to do without defining what counts as too salty, and who bears the responsibility for salinity.
If the FCC2 limits the salt the city can dump in the river like the FCC controls radio emissions, it would specify a ceiling of, say, 5 tons of salt per day - with a rider that the resulting water can't be "too salty". This is not very helpful to the farmers, however, since they care about the resulting salinity; seasonal variations in water volume or the salinity entering the city limits from upstream affect the resulting salinty. It doesn't help the city either, since it can't be sure how much water treatment capacity to build; 4 tons/day of salt might still turn out to be too much if the farmers downstream choose salt-intolerant crops and/or the river level is too low.
Matters are compounded when the city and the farming community fail to reach agreement, and go to the FCC2 to resolve a conflict. (They have nowhere else to go, since the courts defer to the FCC2 as an expert agency to decide what "too salty" means in a particular case.)
Neither side can predict what the outcome of the FCC2's deliberations will be, since it doesn't always decide the merits of individual cases in isolation. It has many proceedings before it at any given time; for example, the FCC2 might be pushing the farmers to get organic certification, and negotiating with the city about the rezoning of agricultural land for urban development. The solution the FCC2 negotiates between the city and the farmers might encompass all these other matters, not only making the result of the salinity dispute unpredictable, but failing to establish a precedent that others might use later.
A better approach would be for the FCC2 to regulate the resulting salinity in water leaving the city (to, say, 5 ppm), remove any mention of "too salty" from its regulations, and provide a way for contending parties to get a specific case resolved efficiently. It might give the farmers the right to stop the city water plant releasing water into the river if the salinity exceeds 5 ppm (leading to a negotiated solution, where the city might pay the farmers' coop $300,000 to raise the limit up to 10 ppm in dry months), or if there are too farmers to negotiate with individually it might choose a liability regime (leading to a court-imposed payment of say $30/acre if salinity exceeds 5 ppm and some farmers sue the city).
Imagine a city along a river, and a downstream farming community. Urban development results in more salt being added to the river; increased salinity can reduce crop yield. Salty water is therefore analogous to radio interference between transmitters (cities) and receivers (farms).
The harm to crops is a shared responsibility, though. For example, the city can reduce the amount of downstream salt by building a water treatment plant, and the farmers can accomodate more salty water by changing crops - spinach will be fine on water that's too salty for celery.
Let's imagine that a Federal Crops Commission (call it the FCC2) is responsible for managing this problem. It might instruct the city and farms to "coordinate" to find a solution to the problem, with a guideline that water may not be "too salty". As in the apple example, this is difficult to do without defining what counts as too salty, and who bears the responsibility for salinity.
If the FCC2 limits the salt the city can dump in the river like the FCC controls radio emissions, it would specify a ceiling of, say, 5 tons of salt per day - with a rider that the resulting water can't be "too salty". This is not very helpful to the farmers, however, since they care about the resulting salinity; seasonal variations in water volume or the salinity entering the city limits from upstream affect the resulting salinty. It doesn't help the city either, since it can't be sure how much water treatment capacity to build; 4 tons/day of salt might still turn out to be too much if the farmers downstream choose salt-intolerant crops and/or the river level is too low.
Matters are compounded when the city and the farming community fail to reach agreement, and go to the FCC2 to resolve a conflict. (They have nowhere else to go, since the courts defer to the FCC2 as an expert agency to decide what "too salty" means in a particular case.)
Neither side can predict what the outcome of the FCC2's deliberations will be, since it doesn't always decide the merits of individual cases in isolation. It has many proceedings before it at any given time; for example, the FCC2 might be pushing the farmers to get organic certification, and negotiating with the city about the rezoning of agricultural land for urban development. The solution the FCC2 negotiates between the city and the farmers might encompass all these other matters, not only making the result of the salinity dispute unpredictable, but failing to establish a precedent that others might use later.
A better approach would be for the FCC2 to regulate the resulting salinity in water leaving the city (to, say, 5 ppm), remove any mention of "too salty" from its regulations, and provide a way for contending parties to get a specific case resolved efficiently. It might give the farmers the right to stop the city water plant releasing water into the river if the salinity exceeds 5 ppm (leading to a negotiated solution, where the city might pay the farmers' coop $300,000 to raise the limit up to 10 ppm in dry months), or if there are too farmers to negotiate with individually it might choose a liability regime (leading to a court-imposed payment of say $30/acre if salinity exceeds 5 ppm and some farmers sue the city).
Tuesday, October 12, 2010
Who gets the apple?
I’ve been looking for a metaphor to illustrate the weaknesses I see in the FCC’s “you two just go off and coordinate” approach to solving wireless interference problems among operators.
Let's think of the responsibility to bear the cost of harmful interference as an apple.* It’s as if the FCC says to Alice and Bob, “I've got an apple, and it belongs to one of you. I’m not going to decide which of you should have the apple; you decide among yourselves.”
Now, if Alice were the owner of the apple and valued it at 80 cents, then the answer would simply depend on how much Bob valued having the apple (and rational negotiation, of course). If having an apple was worth 90 cents to him, he’d get it for some price between 80 and 90 cents; if it was worth only 60 cents to him, Alice would keep it. Problem solved.
Trouble is, the FCC doesn’t tell them who actually owns the apple, and even if it did, it doesn’t tell them whether it’s a Granny Smith or a Gala. The odds of Alice and Bob coming to an agreement without going back to the FCC is slim.
The analogy: The FCC’s rules often don’t make clear who’s responsible, in the end, for solving a mutual interference problem (i.e. who owns the apple); and it’s impossible to know short of a rule making by the FCC what amounts to harm (i.e. what kind of apple it is).
-----------------------
* There's always interference between two nearby radio operators (near in geography or frequency). While the blame is usually laid on the transmitter operator, it can just as reasonably be placed on the receiver operator for not buying better equipment that could reject the interference.
Let's think of the responsibility to bear the cost of harmful interference as an apple.* It’s as if the FCC says to Alice and Bob, “I've got an apple, and it belongs to one of you. I’m not going to decide which of you should have the apple; you decide among yourselves.”
Now, if Alice were the owner of the apple and valued it at 80 cents, then the answer would simply depend on how much Bob valued having the apple (and rational negotiation, of course). If having an apple was worth 90 cents to him, he’d get it for some price between 80 and 90 cents; if it was worth only 60 cents to him, Alice would keep it. Problem solved.
Trouble is, the FCC doesn’t tell them who actually owns the apple, and even if it did, it doesn’t tell them whether it’s a Granny Smith or a Gala. The odds of Alice and Bob coming to an agreement without going back to the FCC is slim.
The analogy: The FCC’s rules often don’t make clear who’s responsible, in the end, for solving a mutual interference problem (i.e. who owns the apple); and it’s impossible to know short of a rule making by the FCC what amounts to harm (i.e. what kind of apple it is).
-----------------------
* There's always interference between two nearby radio operators (near in geography or frequency). While the blame is usually laid on the transmitter operator, it can just as reasonably be placed on the receiver operator for not buying better equipment that could reject the interference.
Friday, July 02, 2010
Social network visualizations - an online symposium
My work on the evolution of FCC lobbying coalitions has been accepted in the JoSS (Journal of Social Structure) Visualization Symposium 2010 (link to my entry). Jim Moody of Duke has done a wonderful job collecting a dozen visualizations of social networks. Each is worth exploring; in particular, see the thoughtful comments that the JoSS staff provided to each entry in order to stimulate debate.
Monday, June 07, 2010
How I Learned to Stop Worrying and Love Interference
(With apologies to Stanley Kubrick.)
Radio policy is fixated on reducing or preventing harmful interference. Interference is seen as A Bad Thing, a sign of failure. This is a glass-half-empty view. While it is certainly a warning sign when a service that used to work suddenly fails, rules that try to prevent interference at all costs lead to over-conservative allocations that under-estimate the amount of coexistence that is possible between radio systems.
The primary goal should not be to minimize interference, but to maximize concurrent operation of multiple radio systems.
Minimizing interference and maximizing coexistence (i.e. concurrent operation) are two ends of the same rope. Imagine metering vehicles at a freeway on-ramp: if you allow just one vehicle at a time onto a section of freeway, people won’t have to worry about looking out for other drivers, but very few cars would be able to move around at one time. Conversely, allowing everybody to enter at will during rush hour will lead to gridlock. Fixating on the prevention of interference is like preventing all possible traffic problems by only allowing a few cars onto the freeway during rush hour.
Interference is nature’s way of saying that you’re not being wasteful. When there is no interference, even though there is a lot of demand, it’s time to start worrying. Rather than minimizing interference with the second-order requirement of maximizing concurrent operation, regulation should strive to maximize coexistence while providing ways for operators to allocate the burden of minimizing interference when it is harmful.
I am developing a proposal that outlines a way of doing this. Here are some of the salient points that are emerging as I draft my ISART paper:
The first principle is delegation. The political process is designed to respond carefully and deliberatively to change, and is necessarily slower than markets and technologies. Therefore, regulators should define radio operating rights in such a way that management of coexistence (or equivalently, interference) is delegated to operators. Disputes about interference are unavoidable and, in fact, a sign of productively pushing the envelope. Resolving them shouldn’t be the regulator’s function, though; parties should be given the means to resolve disputes among themselves by a clear allocation of operating rights. This works today for conflicts between operators running similar systems; most conflicts between cellular operators, say, are resolved bilaterally. It’s much harder when dissimilar operations come into conflict (see e.g. my report (PDF) on the Silicon Flatirons September 2009 summit on defining inter-channel operating rules); to solve that, we need better rights definitions.
The second principle is to think holistically in terms of transmission, reception and propagation; this is a shift away from today’s rules which simply define transmitter parameters. I think of this as the “Three P's”: probabilistic permissions and protections.
Since the radio propagation environment changes constantly, regulators and operators have to accept that operating parameters will be probabilistic; there is no certainty. The determinism of today’s rules that specify absolute transmit power is illusory; coexistence and interference only occur once the signal has propagated away from the transmitter, and most propagation mechanisms vary with time. Even though US radio regulators seem resistant to statistical approaches, some of the oldest radio rules are built on probability: the “protection contours” around television stations are defined in terms of (say) a signal level sufficiently strong to provide such a good picture at least 50% of the time, at the best 50% of receiving locations. [1]
Transmission permissions of licensee A should be defined in such a way that licensee B who wants to operate concurrently (e.g. on nearby frequencies, or close physical proximity) can determine the environment in which its receivers will have to operate. There are various ways to do this, e.g. the Australian “space-centric” approach [2] and Ofcom’s Spectrum Usage Rights [3]. These approaches implicitly or explicitly define the field strength resulting from A’s operation at all locations where receivers might be found, giving operator B the information it needs to design its system.
Receiver protections are declared explicitly during rule making, but defined indirectly in the assigned rights. When a new allocation is made, the regulator explicitly declares the field strength ceilings at receivers that it intends to result from transmissions. In aggregate, these amount to indirectly defined receiver protections. Operators of receivers are given some assurance that no future transmission permissions should exceed these limits. (Such an approach could have prevented the AWS-3 argument.) However, receivers are not directly protected, as might be the case if they are given a guaranteed “interference temperature”, nor is there a need to regulate receiver standards.
While this approach has been outlines in terms of licensed operation, it also applies to unlicensed. Individual devices are given permissions to transmit that are designed by regulator to achieve the desired aggregate permissions that would otherwise be imposed on a licensee. Comparisons of results in the field with these aggregate permissions will be used as a tripwire for changing the device rules. If it turns out that the transmission permissions are more conservative than required to achieve the needed receiver protections, they can be relaxed. Conversely, if the aggregate transmitted energy exceeds the probabilistic limits, e.g. because more devices are shipped than expected or they’re used more intensively, device permissions can be restricted going forward. This is an incentive for collective action by manufacturers to implement “politeness protocols” without regulator having to specify them.
Notes
[1] O’Connor, Robert A (1968) Understanding Television’s Grade A and Grade B Service Contours, IEEE Transactions on Broadcasting, Vol. 47, No. 3, September 2001, p. 309, http://dx.doi.org/10.1109/11.969381
[2] Whittaker, Michael (2002) Shortcut to harmonization with Australian spectrum licensing, IEEE Communications Magazine, Vol. 40, No. 1. (Jan 2002), pp. 148-155, http://dx.doi.org/10.1109/35.978062
[3] Ofcom (2007) Spectrum Usage Rights: A statement on controlling interference using Spectrum Usage Rights, 14 December 2007, http://www.ofcom.org.uk/consult/condocs/surfurtherinfo/statement/statement.pdf
Monday, May 31, 2010
Why I give service
I have just returned from working in the kitchen during a course at the Northwest Vipassana Center. During one of the breaks I had a fascinating conversation with one of the center managers, who it turns out experiences service very differently from me. She asked that I record my thoughts, and this is what I came up with.
Serving is no fun – for me, at least. Serving a course is about stress, anxiety and fatigue, with a few happy moments when I wish the meditators well as I pass them by. There’s no joy in doing the work, as there is for some, and no joyful release at the end; only relief that it’s over. It’s pretty much like sitting a course, with the difference that I’m just banging my head against a wooden wall, not a brick one.
So why do I do it?
I do it because I think it’s good for me. Working in the kitchen amplifies my weaknesses, and makes it easier to see when and where I’m being unskillful. I come face-to-face with my frailties and failings, and hopefully end the course with another sliver of wisdom.
I do it because serving is a middle ground between sitting practice and living in the real world. Like developing any skill - think about playing a musical instrument - meditation requires hours of solitary practice every day, over decades. However, that practice is only the means to an end, which is to live better with, and for, others. Serving on a course helps me try out the skills I’m learning in a realistically stressful but safe environment. Things can’t spin too far out of control; I’m back on the cushion every few hours, with an opportunity to reboot and start again. And I’m surrounded by people of good will, with direct access to teachers if I need it.
And I do it to repay, in small part, the debt I owe to all those people whose service have made it possible for me to learn this technique, and sit courses. I was able to sit because someone else was in the kitchen; now it’s my turn.
Serving is no fun – for me, at least. Serving a course is about stress, anxiety and fatigue, with a few happy moments when I wish the meditators well as I pass them by. There’s no joy in doing the work, as there is for some, and no joyful release at the end; only relief that it’s over. It’s pretty much like sitting a course, with the difference that I’m just banging my head against a wooden wall, not a brick one.
So why do I do it?
I do it because I think it’s good for me. Working in the kitchen amplifies my weaknesses, and makes it easier to see when and where I’m being unskillful. I come face-to-face with my frailties and failings, and hopefully end the course with another sliver of wisdom.
I do it because serving is a middle ground between sitting practice and living in the real world. Like developing any skill - think about playing a musical instrument - meditation requires hours of solitary practice every day, over decades. However, that practice is only the means to an end, which is to live better with, and for, others. Serving on a course helps me try out the skills I’m learning in a realistically stressful but safe environment. Things can’t spin too far out of control; I’m back on the cushion every few hours, with an opportunity to reboot and start again. And I’m surrounded by people of good will, with direct access to teachers if I need it.
And I do it to repay, in small part, the debt I owe to all those people whose service have made it possible for me to learn this technique, and sit courses. I was able to sit because someone else was in the kitchen; now it’s my turn.
Wednesday, May 12, 2010
Improving FCC filing metadata
On 10 May 2010 I filed a comment on two FCC proceedings (10-43 and 10-44, if you must know) concerning ways to improve the way it does business. I argued that transparency and rule-making efficiency could be improved by improving the metadata on documents submitted to the Electronic Comments Filing System (ECFS).
I recommended that the FCC:
I recommended that the FCC:
- Associate a unique identifier with each filer
- Require that the names of all petitioners are provided when submitting ECFS metadata
- Improve RSS feed and search functionality
- Require the posting of digital audio recordings of ex parte meetings
- Provide a machine interface for both ECFS search and submission
Opt-in for Memory
The Boucher-Stearns privacy measure tries to do many things (press release; May 3 staff discussion draft); too many, according to Daniel Castro at ITIF.
One of the issues it doesn’t tackle – and legislation may or may not be the solution – is the persistence of digital information once it has been collected.
In a NY Times context piece called Tell-All Generation Learns to Keep Things Offline, Laura Holson writes that members of the “tell-all generation” are becoming more picky about what they disclose. There’s growing mistrust of social networking sites, and young people keep a closer eye on their privacy settings than oldsters. Holson reports on a Yale junior who says he has learned not to trust any social network to keep his information private, since “If I go back and look, there are things four years ago I would not say today.”
I expect that this concern will grow beyond information collection to encompass retention. (That's already a big concern of law enforcement, of course.) Explicit posts (photos, status updates) will live forever, if for no other reason than sites like the Internet Archive. However, the linkages that people make between themselves and their friends, or themselves and items on the web, are less explicit – and probably more telling. These links are held by the social network services, and I expect that there will be growing pressure on them to forget these links after some time. Finally, there are the inferences that companies make from these links and other user behavior; their ownership is more ambiguous, since they’re the result of a third party’s observations, not the subject’s actions.
My bet is that norms will emerge (by market pressure and/or regulation) that force companies to forget what they know about us. For the three categories I noted above, it might work something like this:
One of the issues it doesn’t tackle – and legislation may or may not be the solution – is the persistence of digital information once it has been collected.
In a NY Times context piece called Tell-All Generation Learns to Keep Things Offline, Laura Holson writes that members of the “tell-all generation” are becoming more picky about what they disclose. There’s growing mistrust of social networking sites, and young people keep a closer eye on their privacy settings than oldsters. Holson reports on a Yale junior who says he has learned not to trust any social network to keep his information private, since “If I go back and look, there are things four years ago I would not say today.”
I expect that this concern will grow beyond information collection to encompass retention. (That's already a big concern of law enforcement, of course.) Explicit posts (photos, status updates) will live forever, if for no other reason than sites like the Internet Archive. However, the linkages that people make between themselves and their friends, or themselves and items on the web, are less explicit – and probably more telling. These links are held by the social network services, and I expect that there will be growing pressure on them to forget these links after some time. Finally, there are the inferences that companies make from these links and other user behavior; their ownership is more ambiguous, since they’re the result of a third party’s observations, not the subject’s actions.
My bet is that norms will emerge (by market pressure and/or regulation) that force companies to forget what they know about us. For the three categories I noted above, it might work something like this:
- Posts: Retained permanently by default. Explicit user action (i.e. an opt-out) required for it to be deleted
- Linkages: Deleted automatically after a period, say five years. User has to elect to have information be retained (opt-in).
- Inferences: Deleted after a period, say five years, if user opts out; otherwise kept. This one is tricky; I can also see good reasons to make deletion automatic with an opt-in for retention.
However these practices evolve, it’s become clear to me that neither the traditional “notice and choice” regime nor the emerging “approve use” approach are sufficient without a mechanism for forgetting.
Tuesday, May 11, 2010
New Ethics as a Second Language
In lecture 27 of the Teaching Company course on Understanding the Brain, Jeanette Norden observes that we seem to learn morality using the same mechanisms we use for learning language.
Newborns can form all the sounds used in all the languages on the planet, but with exposure to their mother tongue they become fluent in a subset. It eventually becomes almost impossible to form some of unused sounds, and the idiosyncrasies of their language seem natural and universal.
This makes me wonder about the difficulties an immigrant might have in learning the peculiarities of a new culture. I’ve definitely been confounded from time to time by unexpected variations in “the right thing to do” – and there’s really very little difference between the culture I grew up in and the ones I moved to as an adult. “Culture shock” may not just be language and customs; it probably involves morality, too, since every system of ethics is a mixture of universals and particulars.
Of course, that’s not to say that one cannot become fluent in an alternative morality. It might just be harder than a native “moralizer”, particularly one who has never had to learn "ethics as a second language”, might assume.
And traditionalists around the world who claim that wall-to-wall American media “corrupt the morals of our youth” are probably right: I'd guess young people pick up the ethical biases of American culture by watching movies and TV even more easily than they pick up English.
Newborns can form all the sounds used in all the languages on the planet, but with exposure to their mother tongue they become fluent in a subset. It eventually becomes almost impossible to form some of unused sounds, and the idiosyncrasies of their language seem natural and universal.
This makes me wonder about the difficulties an immigrant might have in learning the peculiarities of a new culture. I’ve definitely been confounded from time to time by unexpected variations in “the right thing to do” – and there’s really very little difference between the culture I grew up in and the ones I moved to as an adult. “Culture shock” may not just be language and customs; it probably involves morality, too, since every system of ethics is a mixture of universals and particulars.
Of course, that’s not to say that one cannot become fluent in an alternative morality. It might just be harder than a native “moralizer”, particularly one who has never had to learn "ethics as a second language”, might assume.
And traditionalists around the world who claim that wall-to-wall American media “corrupt the morals of our youth” are probably right: I'd guess young people pick up the ethical biases of American culture by watching movies and TV even more easily than they pick up English.
Monday, May 10, 2010
Negotiating the Price of Privacy
Kurt Opsahl at EFF’s time line of changes to Facebook’s privacy policies over the last 5 years tells me a story of a shifting power balance. (Thanks to Peter Cullen for the link.)
It’s a quick read, but in a nutshell: in 2005, the user controlled where information went. By December 2009, Facebook considered some information to be publicly available to everyone, and exempt from privacy settings.
I vaguely remember Esther Dyson describing privacy more than two decades ago as a good users would trade. That’s how I read the time line. It’s an implicit negotiation between Facebook and its users over the value of personal information (let’s call it Privacy, for short) vs. the value of the service Facebook provides (call it Service).
In the early days, the service had few users, and the network effect hadn’t kicked in. Facebook needed users more than they needed Facebook, and so Facebook had to respect privacy – it was worth more to users than the Facebook service was:
It’s a quick read, but in a nutshell: in 2005, the user controlled where information went. By December 2009, Facebook considered some information to be publicly available to everyone, and exempt from privacy settings.
I vaguely remember Esther Dyson describing privacy more than two decades ago as a good users would trade. That’s how I read the time line. It’s an implicit negotiation between Facebook and its users over the value of personal information (let’s call it Privacy, for short) vs. the value of the service Facebook provides (call it Service).
In the early days, the service had few users, and the network effect hadn’t kicked in. Facebook needed users more than they needed Facebook, and so Facebook had to respect privacy – it was worth more to users than the Facebook service was:
Service << PrivacySince the value of a social network grows exponentially as the number of members increases, the value of the service S grew rapidly as membership increased. A user’s perception of the value of privacy didn’t change much; it probably grew a little, but not exponentially. Probably sometime around 2008, the value of the service started overtaking the value of privacy:
Service ≈ PrivacyFacebook’s hard-nosed approach to privacy (or lack of it) makes clear that it now has the upper hand in the negotiation. An individual user needs Facebook more than vice versa:
Service > PrivacyOne take-away from this story is that the privacy settings users will accept are not a general social norm, but the result of an implicit negotiation between the customer and supplier. When a supplier becomes indispensable, it can raise its prices, in explicitly ($$) or implicitly (e.g. privacy conditions). Other services therefore should not assume that they can get away with Facebook’s approach. They can make virtue of necessity by offering better privacy protection – at least until the day when their service is so valuable that they, too, can change the terms.
Thursday, April 29, 2010
Non-privacy goes non-linear
I’ve never been able to “get” Privacy as a policy issue. Sure, I can see that there are plausible nightmare scenarios, but most people just don’t seem to care. What a company, or a government, knows about one just doesn’t rate as something to worry about. Perhaps the only angle that might get the pulse racing is identity theft; losing money matters. But no identity theft stories have inflamed the public’s imagination, or mine.
The recent spate of stories about privacy on social networking sites have led me to reconsider – a little. I still don’t think Joe Public cares, but the technical and policy questions of networked privacy intrigue me more than the flow of personal information from a citizen to an organization and its friends.
This mismatch is an example of the “hard intangibles” problem that I wrestled with inconclusively a few years ago: our minds can’t effectively process the complexity of the systems we’re confronted with.
Two examples: attenuation and scale.
If you find the “friends-of-my-friend’s-friend” construct hard to parse, then good: I made it on purpose. I suspect that such relationships are related to the “relational complexity” metrics defined by Graeme Halford and colleagues; Halford suggests that our brains max out at around four concurrent relationships.
I’m pretty confident that the Big Name Players all just want to do right by their users; the trouble is that the social networks they’re building for us are (of necessity?) more complicated than we can handle. It hit home when I tried to grok the short blog post Managing your contacts with Windows Live People. I think I figured it out, but (a) I’m not sure I did, and (b) I'd rather not have had to.
The recent spate of stories about privacy on social networking sites have led me to reconsider – a little. I still don’t think Joe Public cares, but the technical and policy questions of networked privacy intrigue me more than the flow of personal information from a citizen to an organization and its friends.
The trigger for the current round of privacy worries was the launch of Google Buzz. Good Morning Silicon Valley puts it in context with Google, Buzz and the Silicon Tower, and danah boyd’s keynote at SXSW 2010 reviews the lessons and implications.I think there may be a profound mismatch between the technical architectures of social networking sites, and the mental model of users.
Mathew Ingram’s post Your Mom’s Guide to Those Facebook Changes, and How to Block Them alerted me to the implications of Facebook’s “Instant Personalization” features.
Woody Leonhard’s article Hotmail's social networking busts your privacy showed that Google and Facebook aren’t the only ones who can scare users about what personal information is being broadcast about them.
This mismatch is an example of the “hard intangibles” problem that I wrestled with inconclusively a few years ago: our minds can’t effectively process the complexity of the systems we’re confronted with.
Two examples: attenuation and scale.
We assume that information about us flows more sluggishly there further it goes. My friends know me quite well, their friends might know me a little, and the friends-of-friends-of-friends are effectively ignorant. In a data network, though, perfect fidelity is maintained no matter how many times information is copied. We therefore have poor intuition about the fidelity with which information can flow away from us across social networks.My most recent personal experience was when I noticed a new (?) feature on Facebook two days ago. One of my friends had commented on the status update of one of their friends, who is not in my friend network. Not only did I see the friend-of-my-friend’s update; I saw all the comments that their friends (all strangers to me) had made. I’m pretty sure the friends-of-my-friend’s-friend had no idea that some stranger at three removes would be reading their comments.
It’s a truism that the mind cannot grasp non-linear growth; we’re always surprised by the explosion of compound interest, for example. On a social network, the number of people who are friends-of-friends-of-…-of-friends grows exponentially; but I would bet that most people think it grows only linearly, or perhaps even stays constant. Thus, we grossly underestimate the number of people to whom our activities visible.
If you find the “friends-of-my-friend’s-friend” construct hard to parse, then good: I made it on purpose. I suspect that such relationships are related to the “relational complexity” metrics defined by Graeme Halford and colleagues; Halford suggests that our brains max out at around four concurrent relationships.
I’m pretty confident that the Big Name Players all just want to do right by their users; the trouble is that the social networks they’re building for us are (of necessity?) more complicated than we can handle. It hit home when I tried to grok the short blog post Managing your contacts with Windows Live People. I think I figured it out, but (a) I’m not sure I did, and (b) I'd rather not have had to.
Subscribe to:
Posts (Atom)