A Question of Credibility

Google is being sued for invasion of privacy and for what approximates false advertising.

“Google expressly represented to users of its operating system and apps that the activation of certain settings will prevent the tracking of users’ geolocations,” says Patacsil’s suit, which was filed Friday in California federal court. “This representation was false.”
“Despite users’ attempts to protect their location privacy, Google collects and stores users’ location data, thereby invading users’ reasonable expectations of privacy, counter to Google’s own representations about how users can configure Google’s products to prevent such egregious privacy violations,” the complaint says.

The plaintiffs want Google to cease and desist and to destroy all data obtained “from unlawful recording and use of the location information.”

Let’s say Google is guilty as charged, and the court orders it to “cease and desist and to destroy all data obtained ‘from unlawful recording and use of the location information.'”  The trial hasn’t begun, yet, much less reached a verdict, so Google isn’t actually guilty of anything yet.

On the premise of guilt, though, my questions are these: on what basis would we believe that Google will have stopped collecting the data, and on what basis would we believe that the heretofore collected data have been destroyed?

What mechanism would exist to confirm any of that?  What independent body—capable of the forensic analysis required, since Google has claimed it doesn’t collect the data without prior permission and so unauthorized data don’t exist in Google’s systems—would do the verification, and how deeply and broadly would it be allowed to penetrate Google’s software and hardware systems in order to carry out any verification inspection(s)?

How often would that body—or those bodies, since multiple sets of eyes are better than a single one—be allowed to conduct those inspections and with how much notice (no notice at all would be optimal)?

The Will of the People

The West Virginia House of Delegates has returned articles of impeachment against every one of the sitting Justices of the State’s Supreme Court.  One Justice, Robin Davis, has resigned her post, doing so before any of the impeachment cases proceed to the West Virginia Senate for trial.  In her resignation press conference, Davis complained

The majority members have ignored the will of the people who elected the justices of this court.  They have erased the lines of separation between the branches of government.

The will of the people in electing Supreme Court Justices is overruled, is it?  Certainly it has been—by the will of the people as expressed in their election of the Representatives who voted for (and against) the impeachment. Those elected Representatives will be subject to the will of the people again, and much sooner than the Justices would be—the one stands for election every two (Senators, who will conduct the trial, every four years); the other only every dozen years.

Beyond that, it’s a critical function of the Legislature to remove misbehaving people from government, including those of the other branches of government.  This is what impeachment and trial proceedings are for.

The will of the people is being well served.

Heads in the Sand

There is a Defcon computer security conference in progress at which a Voting Village hackers collection is busily hacking various voting machine manufacturers’ machines.  As McMillan and Volz put it in their Wall Street Journal piece about the Village,

These hacks can root out weaknesses in voting machines so that vendors will be pressured to patch flaws and states will upgrade to more secure systems, organizers say.

Sadly, many of those manufacturers are upset over it, even to the point of warning about voting software license abuse.  Even State government representatives don’t like the idea of testing this software’s and these machines’ security.  Here’s Leslie Reynolds, National Association of Secretaries of State Executive Director:

Anybody could break into anything if you put it in the middle of a floor and gave them unlimited access and unlimited time[.]

To a small extent, that’s a valid beef.  But only to a small extent: that direct access “in the middle of a floor.”  However, malicious hackers—for instance, Russian hackers, to say nothing of Iranian, People’s Republic of China’s, northern Korean’s, each of whom also have an interest in sowing doubt and causing outright disruption—have lots of time between now and our November elections, and they’ve had the last couple of years (at the least) already—a good approximation of unlimited time relative to the evolution of software and hardware.

In addition, Reynolds’ argument is a bit of a strawman.  No one is representing this hack-athon as the last word in the security investigation.  It is, though, a highly useful step in the process of locating security failures (vulnerabilities being a too-soft term) so they can be patched.

Election Systems & Software LLC, a leading manufacturer of voting equipment, was reluctant to have its systems tested at the conference. … Hackers “will absolutely access some voting systems internal components because they will have full and unfettered access to a unit without the advantage of trained poll workers, locks, tamper-evident seals, passwords, and other security measures that are in place in an actual voting situation.”

Sure.  Our stuff don’t stink, so there’s nothing to see here.  Move along.  Don’t investigate because we don’t want to know the problems.  They’d be invalid, anyway.

Jeanette Manfra, a senior cybersecurity official at DHS, actually sympathized with concerns that Village hackers could unintentionally lower Americans’ confidence in our election systems.  She’s wrong, though.  Responsible persons’ hiding their heads under their pillows, chanting, “La la la, I don’t hear you” are the ones lowering our confidence.  Pretending problems don’t exist is a thin shield, indeed, against those problems’ exploitation.

No.  The more objections there are to investigating and testing the security of our voting system, the more badly we need those investigations and tests.

An Oxymoron

Apple has chosen to conceal accesses to Infowars by removing links to it from Apple’s podcast facility because Apple thinks Infowars is too far right for Apple’s taste and because the site pushes bad speech.

This is rank censorship.

Eliminating easy access to Infowars podcasts marks a rare, prominent foray for Apple into an issue confronting many major internet companies: how to remove hateful or conspiratorial messages from their platforms without infringing on free speech.

This is an impossible task to achieve legitimately.  Our 1st Amendment is explicitly intended to protect unpopular or disgusting or hateful speech as well as “approved” speech.  The Amendment recognizes the ability of individual American citizens to think for themselves and to evaluate for themselves what speech they choose to hear, free from Government “advice.”

It’s true enough that the Amendment enjoins Government and not private enterprise.  However, the principle the Amendment protects is a universal one; it applies to all of us, individuals and enterprises alike.

Apple’s MFWIC, Tim Cook, clearly thinks he’s above all of this.  His attaboy for resisting the FBI’s demand that Apple destroy individuals’ ability to encrypt effectively their private communications has been used up.