Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

 



Forgot your password?
typodupeerror
×
Security Privacy Your Rights Online

Why Privacy & Security Are Not a Zero-Sum Game 131

I Don't Believe in Imaginary Property writes "Ars Technica has up a nice article on why security consultant Ed Giorgio's statement that 'privacy and security are a zero-sum game' is wrong. The author reasons that, due to Metcalfe's law, the more valuable a government network is to the good guys, the more valuable it is to the bad guys. Given the trend in government to gather all of its eggs into one database, unless more attention is paid to privacy, we'll end up with neither security nor privacy. In other words, privacy and security are a positive-sum game with precarious trade-offs — you can trade a lot of privacy away for absolutely no gain in security, but you don't have to."
This discussion has been archived. No new comments can be posted.

Why Privacy & Security Are Not a Zero-Sum Game

Comments Filter:
  • Yes, well ... (Score:5, Insightful)

    by ScrewMaster ( 602015 ) on Monday January 21, 2008 @09:22PM (#22132920)
    he's right ... but the thing is, the Federal Government isn't doing this to provide us with more security, they're doing it to provide themselves with more power, power over us. Consequently, they don't much care about our privacy, and there's no reasoning with them on that score.
    • Re:Yes, well ... (Score:5, Insightful)

      by Kazoo the Clown ( 644526 ) on Monday January 21, 2008 @09:41PM (#22133030)

      he's right ... but the thing is, the Federal Government isn't doing this to provide us with more security, they're doing it to provide themselves with more power, power over us. Consequently, they don't much care about our privacy, and there's no reasoning with them on that score.

      You're right about that-- but they also don't much care about our security, for the same reasons. As long as some "bread and circuses" rewards them political brownie points, they can pass legislation "designed to increase security" that actually decreases it, and they can still come out ahead while the rest of us lose...

      If you want either security or privacy, the absolute last place to look for it is the Federal Government-- they're much of the problem, not the solution.

      • Re: (Score:1, Interesting)

        by Anonymous Coward
        No, power is not the motive, it's profit. The "security industry" is profitable and unlike any other real industry has no motive to deliver, quite the contrary. We have a name for this, it's called a protection racket.
        • Re: (Score:3, Insightful)

          by Miseph ( 979059 )
          Don't be silly, power and profit are the exact same motive. People/corporations/governments seek more power as a means of acquiring more profit and more profit as a means of acquiring more power.

          The system is broken and nobody in the mainstream (not even that racist lunatic Dr. Paul) has any interest in actually fixing it. One side wants to speed the whole thing and squeeze as much as they can out of it before the whole thing explodes and the other wants to try and throw on a fresh coat paint and hope it ke
          • Re: (Score:2, Insightful)

            by KDR_11k ( 778916 )
            Don't be silly, power and profit are the exact same motive.

            I'd rephrase that to "power and profit are closely connected". Paul doesn't have any intent on changing that, AFAIK the libertarian idea is to make money = power by introducing the "vote with your wallet" idea to any sort of question which of course distributes voting power equal to income and strengthens the connection. No idea why people support it when it's pretty damn sure they're not the ones getting the big power from it. I assume it's some so
          • Re: (Score:3, Interesting)

            by alexgieg ( 948359 )

            . . . power and profit are the exact same motive. People/corporations/governments seek more power as a means of acquiring more profit and more profit as a means of acquiring more power.

            This isn't quite accurate. The desire to be rich and "powerful" in the economic sense isn't the same as the desire to be powerful in the proper, political-military sense.

            To be more precise, you need tough, ruthless, "comfort is for sissies" guys to tame and mostly pacify a society as a necessary, although not sufficient, cond

          • not even that racist lunatic Dr. Paul


            I don't even like the man, but give it a rest. It isn't true, according to prominent people within the very cross-section of which he is supposedly racist. If that isn't enough for you, think of it this way: You know the guy less than they; therefore, your argument is much less valid and merely hearsay.There's enough vitriol to go around. Just ignore him. Attack the rabid supporters. They're the scary ones.
          • No, the world won't end. I promise :)
    • Well, yes, but... (Score:5, Insightful)

      by caitsith01 ( 606117 ) on Monday January 21, 2008 @09:53PM (#22133092) Journal
      ...they justify it and gain popular support/acquiescence using supposedly rational arguments, so it is a worthwhile expenditure of effort to criticise and dismantle those arguments.

      So if some security expert idiot is wandering around convincing people that security "versus" privacy is a "zero sum game", then one effective counter-tactic is to explain how that is incorrect.

      You are not reasoning with "them" as in, "the Federal Government". You are reasoning with "them" as in, "your fellow citizens, whose approval or at least inaction is needed to allow these things to happen."
    • Re:Yes, well ... (Score:5, Insightful)

      by slarrg ( 931336 ) on Monday January 21, 2008 @10:09PM (#22133180)
      To prove your point, let's propose to make congress the most secure place on earth by taking all of their privacy away. If removing privacy makes them secure they should do it, however, if removing their privacy makes them less powerful....
      • Re:Yes, well ... (Score:5, Insightful)

        by h4rm0ny ( 722443 ) on Tuesday January 22, 2008 @03:48AM (#22135244) Journal

        You're modded funny, but it would make us more secure. Imagine people knowing everything that was discussed and brokered in the Government, listening to all the meetings with lobbyists. These people represent you, why shouldn't you know what they're doing?
      • by b4upoo ( 166390 )
        There is some logic in your post. After all, one definition of security is to lock down and immobilize. If congress was glued to their seats so that they could not move about they could not get mugged in the parking lot. And if we secured their phones so that they could not be picked up or used in any way maybe we could keep their laws and comments secured so that they have no effect upon society,
      • For an excellent explanation of what is going on and why, please read Ominous Parallels by Leonard Peikoff. Dr. Peikoff, an Objectivist philosopher, wrote this in the 1980's showing how America's flawed philosophical values are leading her to an end much like Germany in the 1920's and 1930's -- and for the same reasons.
    • Re:Yes, well ... (Score:5, Insightful)

      by Anonymous Coward on Monday January 21, 2008 @10:09PM (#22133182)
      All Americans suck because they'd gladly trade their privacy (without even knowing it) for the mere perception of security (without even verifying that the trade went through).

      Sufficiently general?
      • Re: (Score:3, Funny)

        by ScrewMaster ( 602015 )
        Sure ... now we wait and see if you get that +5 Insightful.
      • funny europe has done that themselves on several occasions, namely being right after world war one in the 1930's when they appeased germany every time Germany broke the treaty of Versailles.

    • (I feel obliged to ask the same question whenever this point is brought up)

      the Federal Government isn't doing this to provide us with more security, they're doing it to provide themselves with more power, power over us.

      Why? What's the point in trying to expand powers subversively, when election terms are of limited length, it doesn't produce a bigger retirement fund, and it's more difficult, costly, and risky than just electioneering, and giving the people what they want? Could it be that the Federal Govern

      • I likewise feel obliged to answer the same question whenever this point is played down.

        (I feel obliged to ask the same question whenever this point is brought up)

        the Federal Government isn't doing this to provide us with more security, they're doing it to provide themselves with more power, power over us.

        Why? What's the point in trying to expand powers subversively, when election terms are of limited length, it doesn't produce a bigger retirement fund, and it's more difficult, costly, and risky than just electioneering, and giving the people what they want? Could it be that the Federal Government is at least trying to maintain an illusion of security, if not the real thing, because that's what people want?

        There are other sources of income for corrupt ex-Senators.
        http://www.nytimes.com/2007/11/27/washington/27lott.html [nytimes.com]

        What you say is certainly true, sometimes. It is also equally certain that sometimes, it is not. Generally, especially in scenarios where the essence of the right to privacy is demanded in exchange for a temporary bit of security, I tend strongly to distrust the few, extremely noisy liars that score point

        • Hello again! Once again, you thread-jack me, and call me a liar (I assume, since you, again, didn't say it outright). But fair enough, any post on /. is fair game.

          There are other sources of income for corrupt ex-Senators.

          I tentatively guess that you mean they can get lobbying jobs through senate connections? Right, well that's not good, but not particularly relevant either. The OP was talking about security measures and how the politicians want more and more control over us. The article you linked to provid

          • Hello again! Hold on, "thread-jack"? I'm still relatively new here, so I'm keeping my flamethrower holstered -- for now.

            Hello again! Once again, you thread-jack me, and call me a liar (I assume, since you, again, didn't say it outright).

            I didn't have to pay, or pass any admissions test to get an account here. Based on that mostly, I consider these publicly-viewable discussions "open." I'm also familiar with the term 'Netiquette, though, and if I fouled, I apologize. I don't mean to "thread-jack" you. I thought one point in your argument was weak -- and the rest of it strong enough that you'd be interested in shoring up t

            • I'm also familiar with the term 'Netiquette, though, and if I fouled, I apologize. I don't mean to "thread-jack" you.

              Don't worry about it. I do it all the time ;) I was a bit more concerned about the "liar" tag though.

              To be honest, the whole argument was weak, but that wasn't the point. I just get sick and tired of people assuming the government is out to get them. (Actually, I get sick and tired of a lot of things on /.) What I'm saying is that you first need to ask those questions before pointing fingers,

              • To be honest, the whole argument was weak, but that wasn't the point. I just get sick and tired of people assuming the government is out to get them.

                OK, I won't argue against your motives, even though you chose to explain them. If I understand the intent, thanks. Or, thanks but no thanks, to be exact; you have the right to your own motives, and your choice to pursue them by persuasion is noted, admiringly.

                What I'm saying is that you first need to ask those questions before pointing fingers

                Agreed.

                ... which the OP didn't do.

                OP can address that, if it cares to do so. Not my battle.

                It may well be true, but we don't know that, and the logical evaluation of the immediate facts suggests otherwise.

                Well, "assuming the government is out to get them" is your paraphrase of somebody else. Even if it's little or no exaggeration, you are proceeding from a description, rather than a qu

                • What I'm saying is that you first need to ask those questions before pointing fingers

                  Agreed.

                  Good. That was the essence of my argument, you now know its context, you agree, great.

                  In short, whether you're "right-" or "left-" wing, whatever abuses of government power you abhor the most: other things being equal, a smaller government is less capable of committing them.

                  Sure, but I'm still not convinced that a big government is all that capable either. Sure, larger numbers help, but it also takes bigger, riskier

                  • Sure, but I'm still not convinced that a big government is all that capable either. Sure, larger numbers help, but it also takes bigger, riskier, more audacious orchestration to do anything damaging.

                    I think you're using the word "damaging" as I would use "totally autocratic."

                    So many flapping lips to shut up, y'know?

                    Yes, I think I'm beginning to know what you mean. As long as it's only a few "flapping lips" to shut up at a time, you're not calling it "damaging."

                    Sure, a smaller government makes it less likely that any such damaging abuse of power would ever occur, but the benefits probably don't match the benefits of having a larger government with decent oversight over national affairs.

                    I'm reminded of the saying, from Mussolini's Italy, "at least the trains are on time," or something to that effect.

                    Agreed, but I personally believe that there is a threshold for the amount power gained before any benefits are seen, and that the threshold is very large and difficult to reach.

                    Odd use of the word "benefits."

                    • You're blowing out of proportion everything I'm saying.

                      I think you're using the word "damaging" as I would use "totally autocratic."

                      Damaging as in curtailing essential liberties, not "totally autocratic". But at least we both consider it negative.

                      Yes, I think I'm beginning to know what you mean. As long as it's only a few "flapping lips" to shut up at a time, you're not calling it "damaging."

                      No, what I'm saying is that any plan to do any "damage" requires a large scope, with a large number of people to orch

                    • You're blowing out of proportion everything I'm saying.

                      Considering that the essence of our disagreement is on matters of proportional importance of the government's scale, I'll leave my direct rebuttal to that summary for later.

                      I think you're using the word "damaging" as I would use "totally autocratic."

                      Damaging as in curtailing essential liberties, not "totally autocratic". But at least we both consider it negative.

                      I agree, that much agreement on what is "damaging" is a good start for a constructive conversation.

                      I'm reminded of the saying, from Mussolini's Italy, "at least the trains are on time," or something to that effect.

                      That's complete bullshit. I'm not at all saying we should accept dictatorship for something as trivial as the trains, I'm saying we shouldn't be so paranoid about the astronomically low odds that a large government may pose a threat to our freedoms. Large governments allow smoother operation of public services (yes, including trains), and they don't automatically become totalitarian as soon as they reach a certain size.

                      I'm not trying to argue that large governments "automatically become totalitarian as soon as they reach a certain size." But, for any type of representative government, the danger of abuse after a poor electoral choice increases with the

                    • Do you remember "the federal government shutdown of 1995"?

                      That's a good point. I realise there is, of course, going to be a sweet spot, and it's not going to be a case of bigger is better. What I'm referring to is not shying away from administering national affairs on a national level. Having centralised national agencies for certain affairs can provide very positive effects for a minuscule loss of security (from becoming a dictatorship).

                      Actually, you just demonstrated my other point. That's a good example

                    • It's nice to see some common ground. Here's my first disagreement with that reply:

                      My worry is that if the national government gets too small, the kind of clashes of power seen in 1995 will become more frequent and even worse.

                      "More frequent and even worse" than a handful since the Constitution, & totally inconsequential? Because, that's what it was to me.

                      Fifty states, each with their own population, their own values, and their own agendas, trying to wrangle agreements between each other, trying to decide on compatibility of their standards (e.g. education).

                      United States colleges & universities have their "standards" set by regional, not federal authorities, and they all end up compatible enough for corporate work. Why shouldn't we expect that free market forces will be just as useful to primary & secondary education?

                      If they are not, why should you & I excuse them from accountability?

                      We still have to hold them accountable, it's just that we don't have to be paranoid about accountability failing to the point where we cripple our country.

                      "Cripple our countr

                    • United States colleges & universities have their "standards" set by regional, not federal authorities, and they all end up compatible enough for corporate work. Why shouldn't we expect that free market forces will be just as useful to primary & secondary education?

                      Free market tends not to work so well with primary/secondary education. With universities, the student can live separately to his/her parents, so there's a lot more competition for the students. With primary/secondary schools, the student

                    • Free market tends not to work so well with primary/secondary education.

                      Free market tends not to have been permitted in primary/secondary education. So to say it "tends not to work so well with primary/secondary education" may be factually correct, but for a reason which does not tend to support your claim of its inherent inability to work as I describe.

                      With universities, the student can live separately to his/her parents, so there's a lot more competition for the students. With primary/secondary schools, the student is lucky to have a real choice between two or three schools.

                      I have no personal experience, but I have heard of "boarding schools" for primary/secondary education. I don't suggest that every family send their kids off to boarding schools at 6; the point of mentioning them is that they a

                    • Most parents, for one reason or another, don't seem to want to sever most of their contact with their children (especially their primary-aged children). They do have a choice, but the choice is an easy one. Plus, the added cost of accommodation means higher prices, which makes them less competitive to parents looking for the best value education. I'd like to also add that once a child chooses a school, no matter how badly run it is, they tend to stay at that school after they make friends, get to know teach
                    • Schools don't tend to work very efficiently splitting local populations, so if there is any competition, the weaker is quickly eliminated.

                      ... and replaced by more capable management, when a profit margin is realizable in an unsaturated market. Really, I should not have to quote from The Wealth of Nations on Slashdot. This is kindergarten Econ. Don't make me do it. ;-)

                      The parents don't want to move just to try out other schools further away, and neither they nor the student want longer traveling time between home and school.

                      A lot of students seem not to want to go to school at all. Those are all problems to solve within, not among, families. Obviously, commutes will be more challenging for some than for others. In the suburban areas where I've lived, I have always been within easy walking distance

                    • What? What 'higher prices'?

                      Most parents, for one reason or another, don't seem to want to sever most of their contact with their children (especially their primary-aged children).

                      Indeed. I believe mammals generally are more protective of their immature offspring than other Kingdoms, and maintain assisting relationships longer, but IANAB.

                      They do have a choice, but the choice is an easy one.

                      Yes, when banks [or schools, or any other supplier of good or service] compete, consumers win [or at least, lose less]. I think you forgot a "not," but I think you also can't blame me for being opportunistic on that particular error. Haaa-ha!

                      Plus, the added cost of accommodation means higher prices, which makes them less competitive to parents looking for the best value education.

                      I'm guessing from "the added cost of accommodation" you're referring specificall

                    • What? What 'higher prices'?

                      For accommodation. What, you don't think the owners/investors will just foot the extra bill?

                      I think you forgot a "not," but I think you also can't blame me for being opportunistic on that particular error. Haaa-ha!

                      Actually, no I didn't. The choice is almost always an easy one: the easiest one to get to every day is the winner. It's competition, it's choice, but it's not much of a choice, as opposed to the boarding schools and universities.

                      Similar, but lesser, competitive forces sh

                    • And I think you're exaggerating the degree of choice that lower income brackets have over schools.

                      Compared to no choice, a little is better. From every angle so far, the best you can do is agree that it is better, but not by much. Getting back to the point that brought education into this in the first place:

                      My worry is that if the national government gets too small, the kind of clashes of power seen in 1995 will become more frequent and even worse. Fifty states, each with their own population, their own values, and their own agendas, trying to wrangle agreements between each other, trying to decide on compatibility of their standards (e.g. education). It would be a nightmare.

                      I see absolutely no reason to conclude that federal government involvement is the reason that the public primary & secondary school system partly works, except in the sense that federal meddling could very well be the reason that it only partly works. If, as you say, in a free market, parents w

    • he's right ... but the thing is, the Federal Government isn't doing this to provide us with more security, they're doing it to provide themselves with more power, power over us.
      That looser surveillance standards and growing surveillance resources have the effect of granting government more power over us is of course true. The implication that this is "somebody's" motive, without proof, is problematic.
  • As any politician will tell you "the less you know the more secure you are".
    • As any politician will not tell you "the less the people know the more secure they are".

      There you go. Fixed that for you.
    • by EEPROMS ( 889169 )
      |As any politician will tell you "the less you know the more secure you are" It's an old joke, if a minister/senator/public servant doesn't know anything about the latest disruptive bit of news then they cant be blamed. Go watch the "Need to Know" episode of Yes Minister (BBC).
  • Ars Link (Score:1, Redundant)

    by 680x0 ( 467210 )
    I think this [arstechnica.com] is the article cited in the summary.
  • by Opportunist ( 166417 ) on Monday January 21, 2008 @09:38PM (#22133010)
    But... that's not the point now.

    The current system of more and more data collecting isn't for more security. That's just how it's sold. It is, bluntly, control. Over your data and you. It is easier to pinpoint and neutralize "troublemakers" before they start gaining a lot of support.

    So I guess this very interesting point will go unheard. The ones that implement the system don't care (actually, they want it to be that way), the masses don't know (or think that zero-sum game is some sort of game show) and the little rest doesn't matter (and should they start to get too vocal, we'll invent a law against them).
    • Re: (Score:3, Interesting)

      by rtb61 ( 674572 )
      Security and privacy have always been a struggle of the common man over autocrats. That is the history of democracy, the struggle of slaves, serfs and servants to gain control over their own lives, whilst the autocrats attempted to force servitude out of them. In order to maintain that servitude those slaves, serfs and servants had to be carefully watched and monitored , as the are inherently lazy, they are of low morals, they would steal bread off their masters table, they would dare to work together to fe
    • by unlametheweak ( 1102159 ) on Monday January 21, 2008 @11:51PM (#22133784)
      Yes it is control, but people fail to realize the psychological aspects of privacy, that is from the perspective of the spy.

      Having the ability to know everything about both their friends and their foes gives them a feeling of control, however transient and imaginary that may be. It is the act of trying to control their own psychological insecurity.

      It's like a patriarch snooping through their child's belongings, or reading their diary, it gives them a sense of power. In the end it doesn't matter why they do it; they have a compulsion to do it. It is not surprising that leaders in government and industry would do this because the same psychological motivations that drove them to positions of power are the same motivations that drive them to gain control in other areas. Much like Ford or Disney wanted to have total control of their employees; the same types of people in power today have the same psychological needs. Only laws and enforcement of laws that aim at mitigating these behaviors can help stifle the worst abuses. The real problem is trying to convince these people to give up some of this power once they have it. It's not an easy task. Nobody wants to give up (power).
      • Plato was wrong about a lot of things, but he did rightly observe that the desire to hold power is evidence of one's unfitness to hold power.

        Confounding and frustrating those who want to exercise power over us is not just enjoyable, it's a survival imperative.

        Putting out the eye of the cyclops is our only choice besides being eaten.

      • Explains observations under discussion.
        Makes [at least implies] falsifiable tests.
        Seems fairly scientific so far. Predicts future observations?

        It is not surprising that leaders in government and industry would do this because the same psychological motivations that drove them to positions of power are the same motivations that drive them to gain control in other areas.

        I've recently heard "transparency" in weird context, as part of attempted "proof by repetition" from positions of power. I think you're onto something.

    • Go right ahead and assert that all you want. Some of us call it bunk. I can assert too: never attribute to malice what you can attribute to stupidity. Either they are stupid, in calls for data collection, thinking that it will improve security. Or YOU are stupid, and the data collection will actually improve security.
    • by quux4 ( 932150 )

      The current system of more and more data collecting isn't for more security. That's just how it's sold. It is, bluntly, control. Over your data and you. It is easier to pinpoint and neutralize "troublemakers" before they start gaining a lot of support.

      Who are these troublemakers being pinpointed and neutralized? What sort of trouble are they making? How is the pinpointing and neutralizing being accomplished? Ever known anyone who was pinpointed and neutralized? And why haven't they (the ominous 'they')

      • A troublemaker is anyone who questions the status quo with an impact on society itself. The key message lies in the second part.

        Everyone here (and on other boards) is lamenting the current situation. As am I. We're not troublemakers, because we simply don't do anything. But we would most likely support someone who does.

        If you read the sentence carefully again, you'll notice that the "they" refers to the troublemakers, not some nibulous THEM.
        • by quux4 ( 932150 )
          I was hoping you might be able to give examples. You know ... name a few of them.
  • by gillbates ( 106458 ) on Monday January 21, 2008 @09:48PM (#22133068) Homepage Journal

    Terrorists who get caught don't continue to plan attacks...

    The fundamental problem with the privacy-vs-security argument is that it is a false dichotomy:

    1. When someone says, "I have no problem with the government listening in on my conversations or reading my emails," I ask, "Are you a terrorist?". Inevitably, they reply in the negative. Which leads me to ask, "How then, does the government reading your emails make anyone more secure?" Often, this results in an awkward silence, and then they begin to get it.
    2. Sometimes, they'll quip, "Well, how do they know who the terrorists are if they don't read all of the emails..." To which I reply, "If a terrorist is so dumb so as to discuss their plans over the phone or email, how much damage could they do?" I'll remind them of Richard Reid, who was so dumb he didn't know plastic explosives couldn't be detonated with matches.

    The fundamental problem with eavesdropping is that it assumes that the bad guys are willing to divulge key operational details over an insecure channel. Even the dumbest of criminals knows to shut up when the cops are around. So who do the feds expect to catch? That's right - ordinary Americans like you and me. When we become a "problem" to those in power, they'll have hours of phone calls and pages of emails, in which they will find something - no matter how innocent - which, when taken out of context, sounds nefarious. The famous quote, "Give me six sentences by even the most upright man and I will find a reason to hang him..." (or similar) comes to mind.

    Rather, I think it is helpful to expose the lies used to increase the amount of political power wielded by the executive branch.

    • Re: (Score:3, Insightful)

      by Vellmont ( 569020 )

      Sometimes, they'll quip, "Well, how do they know who the terrorists are if they don't read all of the emails..." To which I reply, "If a terrorist is so dumb so as to discuss their plans over the phone or email, how much damage could they do?" I'll remind them of Richard Reid, who was so dumb he didn't know plastic explosives couldn't be detonated with matches.

      This is just a poor argument. Criminals do this all the time. They might not be dumb, they just don't think anyone is listening. Why do you think
      • by Kjella ( 173770 )

        That's not to say I approve of the "wide net" approach the Bush Administration has advocated. Far from it. My enormous problem with the approach is that it's warrantless.

        If you're a "suspected terrorist" they got all the means in the world to surveilance you, what they don't have an abundance of is suspects. You can't have warrants without suspicion, instead they use warrantless wiretaps to *find* suspects. Which is fine if you don't give a shit about the fourth amendment or the principles behind it and let the government do whatever it wants. I'm sure there's a lot of illegal things going on in houses, it doesn't mean they can search my house for no reason.

      • by KDR_11k ( 778916 )
        Wiretaps work because they are rare, the average connection doesn't have them so the assumption is that a given connection is not tapped. If every connection was tapped that presumption would disappear and people would stop saying incriminating things on the phone.
    • by jamesh ( 87723 )

      "If a terrorist is so dumb so as to discuss their plans over the phone or email, how much damage could they do?"

      Plenty.

      An idiot with a bomb he made/aquired and a reason to use it can do quite a bit of damage.

      I have no problem with the authorities listening in on people (including me), provided:
      . They have good reason to do so.
      . Another government organisation oversees such action.
      . Records are destroyed after the investigation is complete.

      The government reading my emails and tapping my phonelines _can_ make

      • by gillbates ( 106458 ) on Tuesday January 22, 2008 @12:08AM (#22133928) Homepage Journal

        The government is _not_ out to get you if you aren't breaking any laws.

        Actually, this is not true - the search and seizure laws passed as part of the War on Drugs allowed law enforcement to seize money and property from suspects without ever charging them with a crime. Having myself been deprived of property by the police in just such a situation, I would be inclined to disagree with you. You seem to believe that the power wielded by the FBI has no implications for corrupt individuals. I would argue that such power is specifically sought by corrupt individuals, and the web is full of supporting evidence. Research McCarthyism sometime. Or the civil rights struggle of the sixties.

        Or even the story of Randy Weaver, whose wife and infant were shot and killed by an FBI sniper. (And this because the Justice Department moved up his trial date without informing him. When he missed it, they issued a warrant for his arrest. And in spite of the fact that the sniper killed an innocent bystander, the sniper was given an award by the FBI. Think about that for a moment: our government issued an award to someone who killed an innocent woman and her infant child. And was later forced to pay a settlement - of taxpayer money, mind you - to her husband and children.)

        And let's not forget that Egyptian student that from which the FBI wrested a confession under duress. A confession that was later shown to be false. And no, the FBI did not compensate him for his lost time.

        But that's not the biggest problem, though. Certain laws are just plain immoral, and one cannot follow them without doing something wrong. For example, for many years in the US, racial discrimination was enshrined in law. In my state, Catholic pharmacists cannot legally practice their religion - they are forced to dispense birth control, even abortifacients, or face legal penalties. In the US, you are required to pay taxes on loan interest, even if you didn't collect any interest at all (because doing so would violate Mosaic law).

        So, if you are an advocate for any type of social change, you can be considered a disturber of the peace, and prosecuted for just about anything. The idea is not that they believe you are actually guilty, but rather, by using the government's seemingly unlimited resources against an individual, they can deny the individual the ability to effectively function as an activist. The problem with email scanning, as I see it, is that just about anyone's words can be taken out of context to mean something nefarious. Which means that - even though you, if innocent, and able to afford a lawyer - will eventually be exonerated, the process will drain you financially and take away years from your life. Sure, its better than prison, but the act of being charged in the first place is a de facto fine.

        • In the US, you are required to pay taxes on loan interest, even if you didn't collect any interest at all (because doing so would violate Mosaic law).

          This statement strikes me as being odd. If you don't collect interest, then paying taxes on interest you don't pay would be meaningless (because, tax_rate * zero_percent_interest = zero tax). Could you elaborate please.

          You also talk about Mosaic law (the law of Moses I would presume). I find it dubious that current US tax law is based on the Old Testament. At any rate, the religious freedoms you speak of are not relevant to privacy in anything but the most contrived manner. This is not a discussion about morality (religious or otherwise). I don't think anybody really wants to go there.

        • In my state, Catholic pharmacists cannot legally practice their religion - they are forced to dispense birth control, even abortifacients, or face legal penalties.

          Maybe Catholics just shouldn't practice pharmacy, if doing so in an acceptably complete and non-discriminatory way is against their religion. Just like Christians used to refrain from practicing banking (as collecting interest used to be considered a sin).

        • In my state, Catholic pharmacists cannot legally practice their religion - they are forced to dispense birth control, even abortifacients, or face legal penalties.

          Pharmacists only exist because of government interference in the free market: the only place you can buy birth control pills is a pharmacy. If it wasn't for the government making such rules, you could probably buy them from vending machines or just get them at the MegaMart.

          For pharmacists to benefit from government interference which cre

      • by Degrees ( 220395 )
        This is pretty naive. You say it would be OK, if there was oversight - but what makes you think there would be oversight?

        My dad's snail mail was being read while he was active in politics. We complained to the postmaster, who did nothing, because he was of the opposite political party. (Heck, it was probably his idea). The planning meeting for California had to be moved to a different location, because the United States Post Office was violating the privacy of snail mail for political gain.

        The impetus for

      • The government is _not_ out to get you if you aren't breaking any laws.
        But which laws? And when?
        To quote Frank Zappa: "America is a land of laws; badly written and randomly enforced."

        This is why the government's net is being cast wider and wider. This way they can find the punishment that fits the "crime" that somehow fits the "criminal."
    • i>I'll remind them of Richard Reid, who was so dumb he didn't know plastic explosives couldn't be detonated with matches.

      You do that. But you should have your facts right:

      there was nothing unsophisticated about Mr. Reid's intended weapon: a wedge of plastic explosive dyed black and concealed in the sole of his high-top suede sport shoe. An official of the Federal Bureau of Investigation has confirmed that a highly unstable component known as triacetone triperoxide, or TATP, served as the trigger. T

    • "That's right - ordinary Americans like you and me."

      Who says they are not listening to "secure" channels (there are no such thing as "secure" channel) as well? If they decided to go with you and not listen to simple insecure channels they will have to assure you about that, right? Then "insecure" channel will become a "secure", because nobody is legally listening to it.

      If you are guarding a massive metal door with 3 locks on it, you also have to guard a whole in the metal fence as well.

      I am tired of listeni
  • by Rogerborg ( 306625 ) on Monday January 21, 2008 @09:50PM (#22133076) Homepage

    It doesn't even take malicious access. In the UK, some low level government peon recently snail-mailed the financial details of 25 million people on discs that went missing [bbc.co.uk]. Since that broke, a slew of other government agencies, from health through to defence have dumped "me too" admissions into the shitstorm.

    The government's response? They'll put "new procedures" in place to ensure that it can't blah blah again blah fight them on the beaches blah.

    They're still pressing ahead with the National Database, misnamed as a National ID card (the equivelant of the USian Real ID). It's Total Information Awareness [epic.org] with a fluffier spin on it, but exactly the same goals: to know everything, about everyone, all the time, and Goddamn the consequences when (not if) the black hats get their greasy fingers on it.

    • The title comes from the article that is linked at the bottom.

      If we were talking about software, the fact that key information that are relatively easy to get had to be kept secret would be deemed very poor design and would be scorn upon by the people on slashdot. It is security/privacy by obscurity.

      It should not matter that you bank account is lost by the government on a DVD, because if the system was properly design, the only thing people could do with such information would be to give you money. Not

  • by fuzzyfuzzyfungus ( 1223518 ) on Monday January 21, 2008 @10:01PM (#22133140) Journal
    As an actual assessment of security policy "Privacy and Security are a zero-sum game" is pretty much worthless. There are obvious empirical counterarguments viz. prisons, military bases and ships, and OpenBSD. The statement manages to be both too optimistic and too pessimistic all at once. It ignores the fact that many policies end up achieving a net gain of less than zero(letting the TSA bother passengers and not even glance at cargo, for instance), even if we value security and privacy equally. It also ignores the fact that there a fair number of possible policies that achieve a positive net gain.

    As a propaganda slogan, though, it is a masterstroke. It manages to imply, while sounding like good, solid, hardheaded, professional advice, that reductions in privacy automatically provide security, that defenders of privacy are enemies of security, and that proposals for plans that protect privacy and security are a bunch of unrealistic pie-in-the-sky crap.

    It also manages to completely ignore a facet of security that the American public has been absolutely terrible at(and politicians and the media have been all too willing to help them continue to be so): Risk assessment. We suck at it. We also have a strong bias in favor of flashy interventions and against boring ones. We often end up with interventions strongly modified by various political interests and of sharply reduced effectiveness. "Privacy and Security are a zero-sum game" makes it sound like we actually have it pulled together, that the professionals are on the case; when we hardly know what game we are actually playing.
    • There are obvious empirical counterarguments viz. prisons, military bases and ships

      Prisons can be so secure that they hamper the ability of a prisoner to be rehabilitated...or worse, make the prisoner more unstable and at-risk for criminal behavior. Look at what's neatly called administrative segregation [wikipedia.org]. It used to be known as solitary confinement, but now all types of people are put in ad-seg...people who are targets of gangs (who have done nothing wrong) for example. Some countries consider solita

  • It is my belief that the government phone data mining program only logged phone numbers and not calls. If they could associate a phone number with a terrorist then they could look at the network of calls to and from that number and try to construct webs of calling. The phone company already keeps this information for billing purposes and probably the gov't asked them to hang on to it for longer periods so that they could retrospectively mine this data for linkages between numbers. Trying to keep conversat
  • by radtea ( 464814 ) on Monday January 21, 2008 @10:39PM (#22133346)
    Number of people who have been killed in the United States in the past five years by terrorism: zero.

    Number of people who have been killed by the over-zealous organs of the state in the name of "security": greater than zero.

    Ergo, increased "security" is killing people and stripping them of their privacy. So as a matter of empirical fact the things people are calling "security" are negative, and the loss of privacy is negative, so it is a lose-lose situation for ordinary law-abiding Americans. They would be SAFER with less "security", as well as having more privacy. And more of something else, too.
    • Because terrorism is the only threat.

      If it was not for terrorists,

      America would be like a nice playground full of flowers and little rabbits.
      There would be no murder, no drug trafficking, no rapes, no burglaries, ...
  • by jd ( 1658 ) <imipak@ y a hoo.com> on Monday January 21, 2008 @10:52PM (#22133404) Homepage Journal
    There is simply no correlation between the two. There is no function or relationship that can map one onto the other, in either direction. There aren't enough parameters. It might be possible to define a function f() with the parameters of security, privacy, base cost, cost per incident, ease of implementation, time of implementation, ease of use, and latency, such that the function (which will not be linear) produces a constant. I don't guarantee it, though. Individuals are too variable, between each other and even between moments for the same individual, and an 8 dimensional non-linear topology is too simple to capture that. Even the sci-fi notion of psychohistory didn't work on individuals, but security and privacy is all about interactions between individuals.
    • That there's no correlation is just not true at all. There are plenty of things people can do with enough information about you, including but not limited to scams, manipulation, and impersonation. I hope it's obvious to you that each of those causes you to lose security, and that every individual's loss of security is, in general, a loss of security for society as a whole. All individuals, obviously, cannot be disconnected from society or there would be no society to speak of. The gains may not be as c
      • by jd ( 1658 )
        A loss of privacy could indeed lead to a loss of security, but a scam can equally well have the effect of you spending time to correct things (ie: it spends your time) and costing others - such as banks - money. Your security ends up unaffected, but only as a result of a transfer of the damage to time and money. Because the numbers can (almost) always be shifted around, I would argue that there can't be a direct correlation between any two variables, because that can never capture how your actions after and
        • > Your security ends up unaffected, but only as a result of a transfer of the damage to time and money.

          But then SOMEBODY ends up affected. There's no "board" here to transfer all the losses to, so somebody has to bear them. If anything, you point out how the costs are borne by society as a whole.
          • Yes, ultimately (no matter how the costs are nominally distributed) the whole of society is affected, either directly or indirectly, every time there is an attack via the vector of either privacy and/or security. "No man is an island" cuts both ways. As noted in this thread, any society, no matter how structured, is inherently highly inter-dependent or it is not a society. This makes each person's privacy and security (and, ultimately, mental and physical health, education and ability, as these directly imp
            • My preference would be to bite the bullet, invest in better quality (and more extensive) education for a much larger percentage of society, invest in social solutions to common problems (such as universal healthcare but to an equal or superior standard to the private healthcare that currently exists), and see what people do as a result. Absolutely no sane person would ever consider giving me the authority or the resources to try this, and I can't blame them. I sure as hell wouldn't vote for me, even if my ideas would work.

              Well said! A sane person might, however, take away the authority from those who already have it but haven't done what you outlined, in order to lower everybody's taxes, "and see what people do as a result."

        • A loss of privacy could indeed lead to a loss of security, but a scam can equally well have the effect of you spending time to correct things (ie: it spends your time) and costing others - such as banks - money. Your security ends up unaffected, but only as a result of a transfer of the damage to time and money.
          What do you want to bet me, on equally likely?
  • "Giorgio warned me, 'We have a saying in this business: 'Privacy and security are a zero-sum game.'"

    This was not meant to be a hard and fast equation, folks. Just like, "you can lead a horse to water but you can't make it drink" isn't meant to be 100% true all the time. I can force that damn thing to drink if I want it to, I guarantee you. It won't be pretty. I'm not that mean though.

    Not everyone in your government is out to get you. This guy is working with the national intelligence director, you be

  • The entire debate relies on the idea that the government can be "trusted" with the practice of data mining and electronics surveillance and phone/networking tapping. A wide net traps many fishes and you have to insure the motives are always pure. Unfortunately, some of the "targets" for surveillance under the "patriot act" included a group of Quakers. See: http://thewall.civiblog.org/rsf/house_nsabrief_docs_012006.html [civiblog.org] For the record, Quakers are against all war and violence. There hasn't been any answers
  • most of the threats to your privacy don't even come from government, they come from businesses. and the businesses are just going to lobby Congress to limit their liability in case they do lose your data. because accountability is expensive. you don't think AT&T is ever going to have to account for anything, do you? of course not, they've got people. hell, even credit reporting agencies have no accountability. Congress decided that it would be your responsibility to make sure the data is accurate.
  • Hey, if privacy and security were really in a zero-sum relationship, then designing systems which diminish one would cause the other to increase.

    But we know this doesn't happen. It's easy to conceive of systems in which a decrease in privacy leads to a corresponding decrease in security. For example, take an existing bank system and decrease the privacy of administrative passwords. Does this change make the bank system more or less secure? Conversely, take an anonymous ballot system and decrease its s

  • I Don't Believe in Imaginary Property writes

    "Ars Technica has up a nice article on why security consultant Ed Giorgio's statement that 'privacy and security are a zero-sum game' is wrong.

    What the heck is "privacy" if not a belief in one's ownership of their private information — an imaginary property, which the article's prolific submitter holds in such disdain?..

    • by eyenot ( 102141 )
      All the comment I have to add to this article is that it's another fine illustration of the problems being caused on all levels of civicity by hyperrealisation, or the overapplication and overuse of a word to the point where its meaning becomes either obscure or negated. Words in question: privacy; security; liberty; etc.
  • This is why I provide no real information to any government agency. I deliberately falsify all information on every document I have ever provided.

    It is NOT because I am a criminal. It is not because I have something to hide. It is not specifically that I fear the government.

    It is that I have firsthand knowledge that our government does not take the steps necessary to protect information about me. 50$ and a license plate number can get anybody all the information they want on me. My residential address,

Beware of Programmers who carry screwdrivers. -- Leonard Brandwein

Working...