AOL user identified by searches, plans to cancel account

The AOL user identified as 4417749 in the recently released three months of AOL search data has been found by the New York Times. She’s Thelma Arnold, a 62-year-old widow in Georgia who has often done searches about medical conditions for her friends, as well as about such things as how to deal with her dog’s urination problem. The article includes a photo of her diaper-wearing dog, Dudley. The article points out both how the search results can be used to identify the real-world user as well as how they can be misleading. She says at the end of the article that she plans to cancel her account.

August 10, 2006 · 1 min

AOL releases user search data, tied to individual users

AOL has published logs showing web activity data for 650,000 users–it’s 20 million searches in about 800MB. Although the AOL screen names were converted to random numbers, the numbers are consistent across an individual user’s activity and in many cases is no doubt sufficient to identify the individual based on ego surfing and other activity. As Tech Crunch points out: The most serious problem is the fact that many people often search on their own name, or those of their friends and family, to see what information is available about them on the net. Combine these ego searches with porn queries and you have a serious embarrassment. Combine them with “buy ecstasy” and you have evidence of a crime. Combine it with an address, social security number, etc., and you have an identity theft waiting to happen. The possibilities are endless.The Paradigm Shift blog notes an instance of an AOL user who appears to be plotting to kill his wife (though there are, of course, possible innocent explanations). Commenters note that over 100 users used search terms which included references to child porn. There is no doubt that this will be used to argue for greater release of data to the government with fewer safeguards against misuse; commenters have already made the claim that “if you don’t do anything wrong, then you have nothing to be afraid of - even if people can view your search history.” Commenter Robert follows up with a good response: Do you ever search for your SSN#, phone number and/or name on line to see if it was posted without your consent? Do you ever worry your day care provider might be a child molester so you search for child molestation and the care takers name or their business name? Do you ever want to find ways to explain sex to your teen age daughter? Gee I wonder what those search terms might look like? Are you famous? Imagine if you type in the name of restaurant you want to go to and the word paparazzi to see if they are known to hang there. Let’s hope they do not see that? Oh, do you have a rare disease or maybe you are pregnant and are looking for clinic in your area so you type in your zip code? In a rural areas that might leave oh 1-30 people it could be? Oh, maybe you think your son is gay? I wonder what you would search for then? Do you have any fetishes or other unusual hobby that might be embarrassing for people to know about but is not illegal. Remember that rural issue again? Getting it yet, because I could go on and on. This is an personal invasion at its most basic level. Not only does it expose personal details of peoples lives, but it is open to wild misinterpretations. Take the wife killing search. Has anyone thought they were simply looking for news they had heard of on the topic, looking for a good book they had heard about with that topic whose title they could not remember, were a wife worried their husband was thinking about this, or maybe that it was exactly what they were looking for but it was only a private fantasy that let them cool off one day after an angry argument? Without context any term can seem scandalous or even criminal. Finally, there is the greater issue. When you start taking away more and more privacy. Each time you chip away at the greater fundamental concept that you deserve this right at all.Releasing this data to the general public was sheer idiocy on AOL’s part (and apparently a mistake), and demonstrates that an AOL account is not a good idea even when it’s free. The data has been downloaded hundreds of times and is now being redistributed on other websites. UPDATE August 8, 2006: AOL has admitted and apologized for its mistake. News.com has an article which gives some more examples of the kind of information that can be gleaned from the search records. ...

August 7, 2006 · 4 min

VoIP quality degradation shows need for prioritization

A study by Brix Networks, which runs TestYourVoip.com, shows that the quality of VoIP calls has degraded over the last 18 months. Their tests of VoIP connections show that 20 percent of calls have unacceptable quality, up from 15% 18 months ago. Brix’s CTO says that the cause is competition for network resources–i.e., congestion. The solution is, of course, prioritization–putting voice and other latency and jitter-sensitive traffic in a higher class of service with QoS (quality of service). Thanks to Matt Sherman for the link. Further comments on the subject may be found at Richard Bennett’s Original Blog and by James Gattuso at the Technology Liberation Front.

July 27, 2006 · 1 min

Visual representation of global data

This is a very interesting presentation at Google by the folks at Gapminder, a Swedish nonprofit that is trying to provide better, visual ways of representing information about the state of the world. These are the same people who put together this set of excellent animated interactive presentations on human development trends (income levels, life expectancy, etc.) for the United Nations Development Program. (Via Patri Friedman at Catallarchy.) Historical Comments Einzige (2006-12-09): Fascinating! ...

July 21, 2006 · 1 min

Anti-Astroturfing Wiki

Seth Godin has pointed out a new Anti-Astroturfing Wiki, for exposing those who are creating fake grassroots efforts by actions like coordinating letters to the editor or blog comment posts which don’t mention the coordinating body–a practice engaged in by both advocates for and against net neutrality regulations. The current Wikipedia definition: “In American politics and advertising, the term astroturfing describes formal public relations projects which deliberately seek to engineer the impression of spontaneous, grassroots behavior. The goal is the appearance of independent public reaction to a politician, political group, product, service, event, or similar entities by centrally orchestrating the behavior of many diverse and geographically distributed individuals." The Anti-Astroturfing Wiki and campaign has been set up as part of TheNewPR Wiki by Paull Young and Trevor Cook in response to the PR Institute of Australia’s promotion of a “how-to” seminar on astroturfing even though the practice violates the PRIA Code of Ethics. Young has issued an anti-astroturfing statement: ...

July 19, 2006 · 2 min

Telecom regulation around the world

Paul Kouroupas has written an interesting series of posts about the state of telecommunications regulation around the world. He postulates a hypothetical company, CoolCo, that is an ISP that wants to sell Internet access, voice over IP, email, instant messaging, and web hosting to residential customers, while not owning any of its own transmission facilities. CoolCo wants to expand its services to include dedicated circuits for business customers, and is majority owned by U.S. investors with a Thai investor who owns 15% of the company. Kouroupas then looks at how CoolCo would fare in Europe, Latin America, Asia, and the United States with respect to licensing requirements, license fees and other fees, foreign ownership restrictions, tariff, contract and pricing rules, interconnection rights and obligations, and the efficiency and effectiveness of the regulatory process. He begins with Europe–licensing requirements are nonexistent; operators must simply “register and abide by a set of basic consumer protection obligations and regulations.” License fees are nominal and consistent across the entire EU. There are no universal service fees or foreign ownership restrictions. There are no tariff requirements, no contract requirements beyond “conformity to basic legal precedence,” no pricing rules “other than basic non-discrimination requirements.” No regulator approval is required to set prices. Interconnection is mandatory, some states require unbundling of services by the incumbents. The regulatory process is relatively efficient and does not consume the bulk of CoolCo’s resources. In Latin America, Kouroupas looks at Argentina, Brazil, Chile, Mexico, Panama, Peru, and Venezuela, the countries where Global Crossing operates, and shows that there is a large amount of variation between countries, with Argentina, Brazil, and Chile being more open and adaptable, and Mexico, Panama, Peru, and Venezuela having more heavy-handed regulation. All have licensing requirements, with the less-regulated three and Peru requiring only a single license for CoolCo’s offerings, while Mexico, Panama, and Venezuela require separate licenses for each service offered. All have license fees as a percentage of revenue, ranging from 0.5% to 3%. Universal service fees fall in the same range. Only Mexico has foreign ownership restrictions. Mexico, Peru, and Venezuela heavily regulate prices, tariffs, and form of contracts. Most countries require some form of interconnection, but in Mexico the incumbent (Carlos Slim’s Telmex, which was privatized in the worst possible way) has been the recipient of multiple complaints for taking steps to avoid or delay the implementation of interconnection. In most countries the incumbent telco is the largest employer in the country and has considerable influence over the regulatory process, which often fails to complete by the legal time limits, leaving competitive telcos in legal limbo for months or years. Kouroupas then turns to Asia, looking specifically at Australia, Hong Kong, Japan, Singapore, South Korea, and Taiwan, with a brief look also at China and India. The former countries, unsurprisingly, are more open than the latter two, though the level of bureaucracy is also high in Japan and Taiwan. China, India, and South Korea have foreign ownership restrictions, at least for facilities-based operators. Finally, he looks at the United States, which is hampered by a lack of consistency and coherent regulations, especially with respect to VoIP. Licenses are not required at the moment, but the FCC appears to have opened the door for it, and there are some specific requirements that now apply such as CALEA and E911. VoIP providers will have to contribute to the universal service fund by assuming that 64.9% of their traffic is interstate, which means paying 10.5% of 64.9% of their revenue. Foreign ownership restrictions exist, but CoolCo should not hit them at the moment due to its foreign ownership of less than 25% and its not requiring licensing, but this could change. There are no tariff, contract, or pricing rules that apply. For VoIP there are currently no interconnection rights and unbundling is limited. The regulatory process exists at both the federal (FCC) and state (public utility commissions) level. At the federal level, regulation is incredibly inefficient; at the state level it varies considerably from state to state but is generally more efficient than at the federal level and has promoted competition. The overall picture is one of uncertainty about the future. I’ve only touched on the highlights of the detail in Kouroupas’ posts, but it’s clear that CoolCo will find Europe to be the easiest region to establish business in today. Check them out.

July 19, 2006 · 4 min

NY Times and SWIFT

Ed Brayton calls out both the NY Times and those accusing the Times of treason for reporting that the U.S. government is data mining in financial data from SWIFT. He points out that the Times is criticizing the U.S. government for doing what the Times itself editorialized in favor of the government doing, and also points out that it hasn’t really revealed anything of significance that the Bush administration hadn’t already publicly said it was doing. Further, the only actually new thing reported–that the government is accessing large amounts of data with broad subpoenas, rather than specific transactions–was also reported by the Wall Street Journal, but without it being hit with the same criticisms as the Times. This is a significant outbreak of inconsistency.

July 2, 2006 · 1 min

Back from Boston

Kat and I are back from a short trip to Boston, a mix of business and pleasure. I participated in a panel discussion Wednesday at the Silicon Valley Bank in Newton on carrier IP security and met with a customer on Thursday, but most of the rest of the time was available for sightseeing. The photos are from the Museum of Science and the Charlestown Navy Yard (where the U.S.S. Constitution is docked), respectively. We walked the Freedom Trail, saw numerous art cows, and spent some time with friends. We came back before the big Boston Pops concert/fireworks show on the Charles River, but we did get to see the fully-loaded fireworks barge being pushed into place.

July 1, 2006 · 1 min

A version of net neutrality I can endorse

In an attempt to offer something constructive, here’s a version of network neutrality–let’s call it Lippard Network Neutrality–that seems to me to be reasonable, providing me with what I want as a consumer of Internet services and what I would want if I were managing security for the provider of those services: 1. Nondiscrimination Companies that provide facilities-based wireline broadband (i.e., those who own the last-mile wires) to residences must provide unrestricted Internet access to their customers who wish to purchase Internet access, allowing the use of any Internet service or application that does not violate any laws or cause degradation or disruption to the service or other customers. The provider may engage in filtering for consumer-grade service in order to prevent the spread of malware and the sending of spam, including (for example) SMTP filtering or redirection to the provider’s mail services, but must allow the purchase of business-grade service under which customers may operate their own mail servers. The provider retains the right to suspend service or quarantine users that send spam, become compromised with malware, or engage in illegal activity or activity that disrupts the service. 2. Unbundling Providers must unbundle Internet access from other services sold over the same connection, so that a customer may use the entire capacity of the circuit for Internet access. These two requirements would give me what I want as a customer, as well as give the provider the ability to recover their costs, provide services that use QoS, provide additional filtering to protect their network and the rest of their customer base from malware, and so on. I think it’s quite reasonable for a basic consumer Internet service to do port 25 filtering, force the use of the provider’s mail servers, and to do network-based filtering of malware–but I would like the ability to pay extra for completely unfiltered Internet service and take steps to protect myself. And in fact, that’s what I’m currently paying Cox for today–I pay for business-grade service to my home in order to run my own servers here, though I could put those servers into a colo facility and get the same effect, which is what I would do if Cox decided to discontinue offering business-class service to residences. Because that option exists, it would not be necessary to mandate that providers must provide business class service as I described above, but I’d still want to be able to ensure that I could access my remotely hosted services from home. How this differs from what many network neutrality advocates are arguing for: 1. I don’t prohibit QoS or tiering, as that is a genuinely useful network feature where I expect to see future innovation of services that depend on it. 2. The nondiscrimination provision is written to allow some kind of less-than-full-Internet walled garden service at low cost–so long as customers can still purchase real Internet service. (I think such a service would be under competitive pressure to allow access to the full Internet, for the same reason AOL ended up allowing full Internet access–otherwise the service wouldn’t attract enough users to be a successful product offering.) 3. I don’t prohibit differential pricing for different services and classes of service. 4. I don’t set any restrictions on contractual arrangements (apart from these two restrictions), including interconnection agreements or who pays. I think that should be left to private negotiation and competition. 5. I don’t extend these requirements to other types of Internet providers such as backbone providers or those providing business services, as those are areas with plenty of competition. 6. I don’t extend these requirements to wireless providers, because I think that with sensible market-based allocation of spectrum, there could be plenty of independent competition with much less capital expenditure than for wireline deployment. I could possibly be persuaded that there is a place for common carriage requirements, especially for access circuits to businesses, which is where the last-mile providers could really engage in anti-competitive behavior against backbone providers that don’t own a lot of last-mile wires (e.g., Level 3, Global Crossing, Sprint), now that the major telco last-mile providers have each merged with a major backbone provider themselves (Qwest/U.S. West, AT&T/SBC/BellSouth, Verizon/MCI). This requirement currently exists in the law for telcos, and unlike the common carriage requirement for DSL, is not planned to go away next year. I would not put the above into the purview of the FCC, at least not with their current dispute resolution procedures which favor the telcos. Paul Kouroupas at Global Crossing (also my employer) has been arguing for “baseball-style” or final arbitration dispute resolution, where each side submits their best and final offer to an arbitrator, who chooses the best. This provides incentive for each side to try to reach the best agreement up front, as well as a process that can proceed quickly, without any government involvement or expense. This suggestion is the second point of Global Crossing’s proposed REFORM legislative agenda. (Unbundling and common carriage of bottlenecks such as last-mile access circuits are the sixth point.) Comments, criticisms? I should add that I believe what I’ve spelled out above is pretty close to what I’ve heard is in Sen. Stevens’ telecom reform bill, though I haven’t read it and I suspect he applies the nondiscrimination and unbundling requirements more widely than to residential broadband. ...

June 22, 2006 · 11 min

Broadcast and audio flags, learn from history

The recording and movie industries want to force a “broadcast flag” and “audio flag” into TV and radio transmissions, and require all electronic manufacturers to enforce these flags to prohibit unauthorized copying and redistribution of such content. These flags have been entered into Sen. Stevens’ telecom reform bill, and Sen. Sununu has a proposed amendment to take them out. This issue is being discussed in committee today, so if you’ve got a Senator on this list, call them today and ask them to support the Sununu amendment to remove both flags from the bill (there’s a separate Sununu amendment that only removes the audio flag): Chairman Ted Stevens (AK), (202) 224-3004 John McCain (AZ), (202) 224-2235 Conrad Burns (MT), Main: 202-224-2644 Trent Lott (MS), (202) 224-6253 Kay Bailey Hutchison (TX), (202) 224-5922 Gordon H. Smith (OR), (202) 224 3753 John Ensign (NV), (202) 224-6244 George Allen (VA), (202) 224-4024 John E. Sununu (NH), (202) 224-2841 Jim DeMint (SC), (202) 224-6121 David Vitter (LA),(202) 224-4623 Co-Chairman Daniel K. Inouye (HI), (202) 224-3934 John D. Rockefeller (WV), (202) 224-6472 John F. Kerry (MA), (202) 224-2742 Barbara Boxer (CA), (202) 224-3553 Bill Nelson (FL), (202) 224-5274 Maria Cantwell (WA), (202) 224-3441 Frank R. Lautenberg (NJ), (202) 224-3224 E. Benjamin Nelson (NE), (202) 224-6551 Mark Pryor (AR), (202) 224-2353The Consumer Electronics Association has a new advertisement out that shows the lunacy of the arguments for these flags based on the past record of these industries crying wolf about the dangers of new technology: “I forsee a marked deterioration in American music…and a host of other injuries to music in its artistic manifestations, by virtue—or rather by vice—of the multiplication of the various music-reproducing machines…” -John Philip Sousa on the Player Piano (1906)“The public will not buy songs that it can hear almost at will by a brief manipulation of the radio dials.” -Record Label Executive on FM Radio (1925) ...

June 22, 2006 · 2 min
Mastodon Verification