The Dangers of Data
The following is from a talk given by Frank van den Heuvel and Alan Epstein to a Regional Reference Persons’ meeting in March of this year.
FRANK VAN DEN HEUVEL: The Internet was founded on the idea of connecting all people and the assumption that free access to information would make all people free. It’s an understandable wish.
Access to information gives people power. We need to have free access, and transparency, so that we can keep an eye on governments and companies.
However, the wish for a free, interconnected humanity also created a problem. Lessons learned from the past were not considered when the Internet was designed. We built the Internet as if manipulation and abuse of information hadn’t previously existed. In fact, manipulation of information, and spying, have existed for at least seven thousand years.
News, intelligence, propaganda, and marketing—all have been influenced by culture and distresses, when they’ve been created and when they’ve been consumed. What’s new is that it’s become extremely easy to collect, keep, and analyze data from people’s moves—whether they’re moving a mouse, posting a text, opening a website, or passing a camera. Such things are linked together, and it becomes possible to guess what people are thinking, believing, and vulnerable to and to manipulate that. Google may forecast what you will do tomorrow at 3:00 pm. And that forecast, whether accurate or not, can be used for marketing.
The huge data collections are increasingly being used for forensics, predictive policing, anti-terrorism, micro-targeting, fake news, political influencing, polarizing, incriminating, and more. All this disrupts families, communities, and countries and causes wars.
In the Internet age, it’s become easier to micro-fabricate news. Small groups of people get their own limited and distorted version of reality. And they don’t know that their neighbors have different views or experiences. This can erase the exchange of ideas and learning that can come from engaging with each other’s intelligence. And there can be huge upsets when something crosses the boundaries of one’s own little bubble. People feel their feelings, and “dramatize” and proliferate them.
The technologies are used to destabilize communities, too. Governments create fake news for this purpose. Also, the algorithms built on the data that’s collected in an oppressive society automatically amplify the oppression—all kinds of oppression. People are trying to fix this within technology, within governments, and with activism. However, it probably cannot be fixed without changing the system. We would need to change the fabric of all the data collected so far, which might mean ditching [getting rid of] everything that’s been collected.
All of these things are driven by the data we unawarely leave on the Internet or put in the hands of big tech.
Big tech has become too large for governments to handle, so huge battles are being fought to legally constrain data surveillance. General Data Protection Regulation (GDPR) in the European Union is one result. But it won’t be enough. The companies break laws if they can get away with it [not get caught]. And they know from the data they collect how to addict people to their products and exhaust the activists who are fighting to defend privacy and security.
The cultural dominance of the Western world, especially the United States, in big tech makes it especially hard for people in Western countries to give up their technical privileges. It also makes it hard for them to acknowledge that tech is not going to solve the problems created by capitalism.
Tech is part of the fabric of capitalism. That doesn’t make it useless, but it’s just a tool—like a screwdriver that can be used for both peaceful purposes and to build weapons of war. Western dominance also determines who has access to the tools of tech—to stable and fast Internet, to big screens, to more than one device, and so on.
(Interestingly, we may face a situation in which people who have less access to the Internet are actually better organized and more prepared for the crises to come. If the Internet collapses, or energy delivery fails, people whose lives don’t depend on Internet services will have an advantage in recreating society.)
Big tech has huge amounts of money to use for lobbying and political financing, so governments end up defending the interests of big tech. The mechanisms for this may vary in different places, but the corruption is similar and has existed at least since the Romans occupied Europe.
In RC we are dealing with two major problems:
1. Attacks—leaking data can provide the means or “reasons” for attacking RC Community members, our leadership, and organizations that we are a part of
2. Disruption—fake news targeted at certain parts of our Communities can disrupt the Communities
Of course we can talk about how to work more securely, which Alan will address in his following comments. But we also need to build awareness, organize discharge, and support Internet activism.
ALAN EPSTEIN: I will add two more problems to those discussed by Frank:
3. Service disruptions—the operations of Re-evaluation Counseling Community Resources (RCCR) and Rational Island Publishers could be stopped or damaged
4. Financial theft—this could take many forms
We need to think about these problems, so we can protect our organization and its members.
During the attacks on RC last year in Boston (Massachusetts, USA), some of our internal discussions became part of the attacks in the Boston Globe newspaper.
What would you do differently if you were certain that the content of your Co-Counseling sessions or e-mails would be freely available or broadcast widely?
How would your RC teaching and leading be affected if your students were influenced by credible-sounding fake news?
What if the constituency data of a member of your Community was leaked and it caused them to lose their job or housing or exposed them to other problems? (I expect a similar concern led to our use of pseudonyms.)
Although no techniques can protect us completely, there are steps we can take to be less vulnerable and slow attacks down.
Some people will ask, “Why take any action if we cannot stop the U.S. National Security Agency from hacking us? They already know everything about us!”
Groups like the National Security Agency (NSA) have the capacity to surveil us and collect unprecedented amounts and kinds of data. However, the NSA does not target everyone, and other threats are not as sophisticated and can be stopped or slowed. In addition, some useful laws exist—for example, the European Union’s General Data Protection Regulation (GDPR) and the California (USA) Consumer Privacy Act (CCPA). And if threat actors (data collectors) already had enough data, they wouldn’t continue to devise new ways to collect it.
The above two laws can guide us in how we protect the data we collect. There are four main ideas:
1. Minimize the types of data we collect.
2. Allow access to that data only to those who have a real need for it.
3. Avoid transmitting the data over insecure channels, like e-mail.
4. Destroy the data as soon as is practical after the need for it has ended.
We can also do the following:
1. We can avoid, or use with awareness, abusive and unprotected systems and software—for example, Google, WhatsApp, Facebook, and unencrypted e-mail.
2. We can lean toward using tools that protect privacy. Some of these are free, and some are not. We may need to discharge to consider paying for more secure systems when “free” alternatives, like Google apps, are available. Here are some examples of tools that protect privacy:
- Signal and Telegram messaging apps—for texting, calling, and video calls
- Protonmail and Tutanova—for encrypted e-mail
- Cryptpad—to replace Google apps
- Jitsi—to replace Zoom
- Duckduckgo—for a search engine instead of Google search
- Firefox—for a browser
- Ublock Origin—a browser extension to block ad trackers
3. We can use the secure RC website for collecting workshop registration data and creating mailing lists.
4. We can use different tools at different times, to evade trackers.
5. We can stop assuming that e-mail (except when encrypted) is private.
6. We can secure our passwords! The password used by the largest number of people in the world is “123456.” You could all become successful computer hackers knowing just that one fact! It is best to use long and obscure passwords. It is best to avoid reusing passwords. It is good to store passwords in a password manager.
Finally, there should be tech leaders in every RC Region who can think well about protecting privacy and the tools that can best serve the Communities and their constituencies.
Met vriendelijke groet, With kind regards,
Watertown, Massachusetts, USA
(Present Time 208, July 2022)