Showing posts with label Privacy. Show all posts
Showing posts with label Privacy. Show all posts

Thursday, July 30, 2009

Tell me, what do you see?

So Adam Man Tium sent me a most interesting article yesterday.  The New York Times has posted that a bit of a stink has been thrown up about the publication of common answers to Rorschach tests. It is a really good article, filled with all sorts of juicy little morsels for our brains to feast upon.

First, there is the issue of the release jeopardising the validity of a famous psychological test. While I can see why the clinical psychs are a bit cranky, I don't particularly see any objection to such a move. I mean, other fields that deal with people encounter this all the time. Hell, psychologists have to deal with the fact that people learn. That they can learn faster now just means that new scales will have to be designed. The fact that there are apparently tens of thousands of papers written trying to link behaviours and results on the tests doesn't seem to matter. I mean, for research psychs - shouldn't you guys be happy? You now have more work. Get over it. As to the wringing of hands about posterity, that's a touch weak as far as I'm concerned. if the cryptographers cried every time someone on the internet cracked a code, the world would be awash with their tears and broken dreams.  My experiences with people who are in the business of fooling psychs is that if someone wants to fool a psych, faking a Rorschach isn't going to be the only trick up their sleeves.

What is more interesting is the concern that leaking psychological diagnostic tests may lead amateurs to wrongly diagnose people they know.  More importantly, this is seen (it seems) as a violation of the psychological professional code of conduct.  Now, my own internal jury is still out on whether this in the Rorschach case has sufficient empirical grunt to follow through, but I actually think this kind of argument is quite a pressing one.  There is already a growing worry about self-diagnosis and subsequent prescription of medical treatments.  Of course, it hasn't stopped a whole swag of individuals jumping on the home-medicine bandwagon, and considering the US health problems of the day maybe this is justified.  Nonetheless, there is a reason that people train as long as they do in health-related disciplines.  The harms potentially caused by misdiagnosis and malpractice (as liability premiums for medical practitioners show) can be quite catastrophic.  Again, if you are only doing it for yourself, maybe that's okay.  But anecdotally, if someone thinks they know how to cure your particular brand of sniffles, they are going to go around telling everyone they can.  Noone just keeps their home-medicine to themselves.  That's how medicine evolved.  Unfortunately, in our society, the risks are that much greater, and there are weighty ethical concerns that accompany the trial-and-error way of the home doctor.

What is startling about this article is that the above concerns about harms and professional responsibility is actually shown nicely by the very person who is the staunchest defender of the postings, Dr. James Heilman. Before I do that, I'm going to take the chance to e-ridicule him:

Heilman, the man who originally posted the material, compared removing the plates to the Chinese government’s attempt to control information about the Tiananmen massacre. That is, it is mainly a dispute about control, he said.
IDIOT. You think this is in anyway like the cover up of Tienanmen, because of control? So by your logic, the protection of patient details, or the identity of rape victims, or any other form of control of information based on the risk of considerable harm caused is like Communist repression. I mean, come on people! The mere attempt to exert control over something doesn't make you any [insert favourite political scapegoat of the day]. Heilman obviously hasn't been engaging with the arguments on any substantive level, because otherwise he'd be focusing on actual argument, rather than meaningless hyperbole.

To cap it off, we have his own personal coup de gras:
To illustrate his point, Dr. Heilman used the Snellen eye chart, which begins with a big letter E and is readily available on the Wikipedia site. 
“If someone had previous knowledge of the eye chart,” he said, “you can go to the car people, and you could recount the chart from memory. You could get into an accident. Should we take it down from Wikipedia?” 


And, Dr. Heilman added, “My dad fooled the doctor that way.”

So doc, what you are saying is that you let your dad endanger the lives of other people by faking a really quite justified intervention into people's right to drive their cars around (i.e. whether or not they can see), and this is somehow meant to act as a rebuttal to those psychologists who are worried about harms caused by misuse of their diagnostic materials?  Yeah, that's totally coherent.  In fact, I would be tempted to say YES.  Yes we should.  Not only have you shown that leaving the loaded gun on the kitchen table risks kids shooting each other with it, but you've got video footage of little Jimmy running off with it to play cops and robbers with his friends.  You've proved their point!  Hell, all they need now is a little push in the empirical direction to show its not only you and your dad who are menaces to everyone around them, and there's a case for regulation right there!  I mean, right to freedom of expression is one thing.  Right to cheat on your driving eye-test is quite another.

I mean, there is a better solution to the eye thing - just randomise the letters.  But I'm not in the biz, so I don't know if that is feasible or jeopardises the reliability of the test.  It probably does. Still, an interesting article all in all, filled with equal amounts of the good, the bad, and the stupid.

Thursday, September 4, 2008

U.S. Federal Election

I am sure that some of our loyal and devoted fan base (consisting of millions, no doubt) have been following the recent developments in the U.S. Federal Election.
First off, we have Obama as the first 'non-white' major party candidate, then McCain names Sarah Palin as his running mate/potential Vice President. She is young (mid fourties) conservative, and she is female. She also has five children, one of them 17, pregnant and - shock horror - unwed. As the dirt diggers fire up their engines, and rumours and scuttlebut abound, I am become more and more fascinated by this election. Obviously the outcome wil be interesting, but to see what happens during the process leading to the outcome will be really really interesting.

Just to add a little slacademic fuel to this fire, this is a quote from our girl Sarah P from today's Australian: She is expected to highlight her focus on ethics issues in Alaska and other accomplishments...

Hmmm, I wonder if she takes an irrealist or a non-descriptive cognitivist approach, or whether she is a full blown realist. Methinks the last.

Wednesday, June 11, 2008

Stupidity in legislation

A new trade agreement is being proposed at the G8 in July, the Anti-Counterfeiting Trade Agreement, that will essentially allow any border guard to confiscate any electronic device and inspect it for possible copyright-law-infringing material.

Here is an article on it, and here is the document on wikileaks (a site I highly recommend!).

This is an insane act. I have no words for just how insanely stupid it is. The US has just gone crazy with its straw-grasping in order to placate an amazingly backward entertainment industry that is mired in 50 year old business plans.

Anything we can do to make sure Australia doesn't enter into this will be fan-freaking-tastic.

Tuesday, April 15, 2008

Follow-up to employee email snooping article

So the water becomes a little muddier here -- turns out the Attorney-General's office is quite well renowned for attempting to bring in crazy authoritarian initiatives to restrict Australians under the guise of anti-terrorism solutions.

According to Crikey today (subscription possibly required), some of the A-G's secretary's recent efforts include attempting to silence criticism of ASIO after they wrongly detained Izhar ul-Haque (rejected by the commission), others in the office helped Howard with his infamous "children overboard" mess and providing the false allegations of weapons of mass destruction that dragged Australia into war. Apparently it seems that this lot quite enjoy close relations with the private sector.

Bernard Keane writes in the above article:


The private sector, across areas such as transport, communications, IT and energy, is a willing participant in the process of establishing a system for monitoring and protecting their facilities and the public infrastructure they use, all in the name of preventing or effectively responding to terrorism. After all, the process allows companies access to government funding for the maintenance and upgrading of monitoring and information-collection systems they would otherwise have to invest in themselves, enables – in the name of greater security – the development of new regulatory requirements that raise the barriers to entry for possible competitors, and transfers an element of operational risk to taxpayers.


Still think this is all about keeping Australians safe?

P.S. for some fun acronym bureaucracy in the world of Critical Infrastructure Security (CIS), this is a good read.

Monday, April 14, 2008

Is losing employee consent the price to be paid for cyber-terrorism safety?

I read with some initial horror this morning that the Federal Attorney-General, Robert McClelland, has proposed amendments to the Telecommunications (Interceptions) Act among other legislature to be introduced in order to combat cyber-terrorism. These amendments apparently (I can't find the original documents for all the searching I have done so far today after trawling the parliament website, all I could find is a proposed amendment from February that just expands warrant powers) allow companies and others who run critical infrastructure (apparently the financial system, stock exchange, electricity grid, transport system, etc.) to monitor employee use of the internet including email and other communications without their consent. The Act so far only allows those working in security agencies to be monitored without consent.

McClelland and Julia Gillard have spoken out to say that these amendments will help in securing Australia's infrastructure against cyber-terrorism, because a terrorist attack on critical infrastructure would "reap far greater economic damage than would be the case of a physical attack", according to McClelland, which Gillard backed up soon after.

Why do the A-G and Julia Gillard suppose that cyber-terrorists are likely to be working from within an infrastructure company? McClelland used the example of the Estonian hackers which used a bot-net of thousands of external zombie computers to take down the system. This isn't something that will be fixed by monitoring, all it requires is decent Distributed Denial of Service (DDoS) attack prevention mechanisms, which are available. And even if they still think that insider jobs facilitate terrorist attacks, why do they think that cyber-terrorists that may happen to be inside the company are likely to be stupid enough to communicate through company channels?


I'm also interested in what sort of mechanisms they are putting in place to avoid situations where employers with a grudge could use this law to poke into private affairs of their employees who are in no way a danger to the company or Australia's infrastructure, and how they are proposing that employers effectively monitor their employees for terrorist activity. What sort of delegation of these powers would there need to be to, say, someone employed by the company to monitor other employees? What sort of checks and balances are there for this? It seems like it would be detrimental to Australia's security if employers could act as if they were security experts and identify likely threats from innocuous emails.

Another thing that needs to be asked is why consent needs to be taken away. Consent can be construed as a waiver of normative expectations, according to Neil Manson and Onora O'Neill (and my upcoming thesis on informed consent in ICT will explain why I think this is a reasonable model to apply to ICT). It seems here that by legislating consent out of a workplace agreement that the government here is almost attempting to make workplace surveillance the norm. This surprises me coming from a supposedly liberal government! Why is not having an employee's consent important to this bill? Surely we can have a bill that allows for all the other parts with explicit knowledge of the employee. Many companies already have internet use policy agreements with their employees, which involve degrees of surveillance. Legislating this sort of thing is fine, but surely, like collecting tax file information or as part of a standard contract for employment, the legislation could include some sort of policy for detailing the surveillance and obtaining consent from the employee?

McClelland has said that information from these communications could be used in "for instance, disciplinary matters regarding the employees' conduct or any other privacy issues. In other words, you're not interested in communications from employees' friends, their children, other family members." I fail to understand why this sort of thing isn't already covered by the existing legislation though, or why it is necessary to remove consent from the equation, or put employers (and/or the person delegated to deal with these matters) in charge of judging the relevance of personal communication.

I agree that infrastructure is a juicy target for potential cyber-terrorist attack, but this set of laws is not the way to protect infrastructure. Infrastructure needs good solid protection through careful construction and management and contingency plans, not the ability for employers to be able to monitor their employees' internet use. If that's not what this is about, then terrorism needs to be fully disconnected from the discourse about this law. Otherwise, it's just fear-mongering, something more suited to the dim dark past of Australian government history.

New Policy Proposes That Work Emails Be Screened For Threats

Our friends of the Governmentmental variety are proposing new legislation to access personal work emails in order to prevent attacks on vital infrastructure.
http://www.theage.com.au/news/national/gillard-backs-workplace-snoop-law/2008/04/14/1208025033663.html

Now many of you paranoid types may see this as an infringement on privacy or some other such things. Some of you may even go so far as to devote years of your life writing thaecis on such things.
Anyway, my reason for posting is not to rant about this, but the hope that if people are interested in this, that they post new info and or links about this policy, if it becomes enacted etc.

That is all.