Blog

cyberwar digital society disinformation Israel-Palestine platform governance protests social media

  • The threat of disinformation can be worse than disinformation itself

    The threat of disinformation can be worse than disinformation itself

    This article originally appeared in Dutch for SamPol Magazine.

    As several countries have introduced new legislation to put a stop to disinformation, those laws can also be abused to silence the independent press.

    According to the World Economic Forum, “AI-generated disinformation” will be the biggest threat for 2024. For its Global Risks report, experts and policymakers are annually asked to look into their crystal ball and predict the state of the world. In the 2023 report, disinformation was still nowhere to be seen in the top ten, but this year it even surpassed “extreme weather events,” which has dangled (appropriately) in the top three for a decade.

    This incredible rise in the threat of disinformation is curious, yet not unexpected. Some 4 billion people will vote in democratic elections in 2024; citizens in the U.S., India, Indonesia, Mexico, all of Europe and, of course my country Belgium, among others, will be casting their vote. And this after a year of dizzying AI developments where ever more realistic images and texts are artificially generated, in an era where, according to the Digital News Report, there is a global record of news avoiders. It seems like a perfect storm.

    The fear of disinformation focuses most on elections because it is a moment where an opinion gains real power in the form of a vote. Influencing that opinion with lies, rumors and half-truths could lead to drastic shifts in power. However, it is difficult to measure what impact disinformation effectively has on such an opinion shift; a political vote does not simply change quickly because of a lie. Time and again, researchers find few significant correlations between fake news and election results, only that the convinced become even more convinced.

    So we should take this threat of disinformation for power shifts with a grain of salt, and certainly the AI factor. Some politicians keep sharing obvious satire or poorly photoshopped disinfo over and over again, which passes almost silently among their constituents. What does that say about where the problem really lies?

    The threat of disinformation can also have unintended consequences. Indeed, several studies show that widespread fear of disinformation actually leads to increased distrust in established media and even a reduced ability to identify disinfo. A “backfire effect” that has long been warned about when media literacy is based solely on increasing skepticism, and not on regaining trust in journalism and science.

    Moreover, the threat of disinformation can also lead to a reaction that becomes more dangerous than the actual effects of disinformation. There, too, scholars found that greater fear of disinformation leads to greater support for undemocratic interventions. Several countries have created new legislation in recent years to call a halt to disinformation. But “fake news” is often not clearly defined. As a result, these laws can also be abused to silence independent press. According to the Committee to Protect Journalists, some 39 reporters worldwide have even been imprisoned by this type of legislation.

    In Europe the Digital Services Act (DSA) entered into force on Feb. 17. This vital legislation imposes certain much-needed transparency obligations on VLOPS (euro-lingo for Very Large Online Platforms) and gives users more opportunities to appeal moderation decisions made by the platforms. However, the legislation can also be used as a blunt instrument by platforms when they are required to engage in “risk mediation”.

    This was made clear recently when Thierry Breton invoked DSA obligations around harmful content when hate speech and disinformation spread on various social media platforms following Hamas’ Oct. 7 attacks on Israel. Research by NGOs such as Human Rights Watch and the Arab Center for the Advancement of Social Media found that platforms like Meta systematically silenced voices advocating for human rights in Gaza during that period. They were lumped into the same category of “Hamas glorification”. Although the DSA has various provisions and safeguards against unilateral and political interventions, a threat of legal obligations by zealous bureaucrats can lead to the hasty removal of content by the platforms.

    Disinformation can certainly pollute debates, protests and legit criticism; it is the Achilles heel of liberal democracies that value free speech. That openness is also eagerly exploited by those who do not care about the importance of keeping the public space open. But with too narrow a restriction on freedom of speech, one can also stifle those who raise social injustice. The biggest mistake that can be made is to suppress legitimate criticism as a ‘precaution’.

    There are unpleasant conclusions to be drawn from the WEF forecast, where legitimate concerns such as the “cost of living” and the “housing crisis” drop in the rankings and are replaced by the threat of disinformation. If we really want to protect elections against undemocratic actors, it doesn’t help to attribute social unrest to an allegedly deceived public. That kind of thinking leads to simple solutions that can make complex problems worse.

    Image by jakob5200 from Pixabay


  • “Play my damn song!” Social norm conflict over Spotify’s Jam feature

    “Play my damn song!” Social norm conflict over Spotify’s Jam feature

    It had been a while since i’d been to a house party where we played music and danced. Back in the days (mostly pre-pandemic), houseparties with my predominantly Belgian friends would revolve around one laptop where people would add songs, or one phone that would get passed around. When folks would start dancing and hyperfocussing on the music, there would be several contenders for what we dubbed “DJ internet”, adding songs to the queue on Youtube and later Spotify. Certain norms started forming at our parties that only became fully clear to me last night at a new year’s eve party, as those hidden rules underlying ‘our’ party clashed with other norms. The affordances of Spotify’s new Jam function played an important shaping role.

    To set the scene: I went to a New Year’s eve party in Brussels hosted by one of my best Belgian friends and her Mexican partner with whom she was about to move in. The mix of guests was thus Belgian and Mexican, with two odd Turks.

    At a certain point past midnight, our Mexican host had shared a link to Spotify’s new collaborative party playlist.

    Previously called ‘group session’, this type of listening party was first introduced by Spotify in 2021, and transformed into ‘Spotify Jam’ in September 2023. I had missed this as I had moved away from Spotify in protest against Joe Rogan getting paid by Spotify to platform antivaxxers, but was instantly fascinated by this social function of the platform, as it creates a form of democratisation over the party playlist.

    Joining a ‘Jam’ allows all guests to add to a playlist from their own devices that gets broadcast through a single speaker – the DJing-task was thus decentralized. The ‘jam’ function afforded a level of anonymity in the physical realm, since you had to open the Spotify app to know who picked a song, reducing the potential for ‘AUXiety’. When the host enables it, all users also get control over which song gets played next. This also means they can push songs down in the queue, end a song, or even delete the queue; a host of actions that were not attributable to specific users in the Jam. Since the playlist’s locus of action is decentralized to everyone’s mobile phone and accessible to all, the Jam can be democratising but also create a hidden struggle for control.

    This new feature can therefore be a recipe for some good old norm conflict (which just so happens to be the topic of my PhD).

    You must know, my Belgian friends can get very intense about music. They have a certain sensitivity for which songs should follow each other (the vibe shift needs to ‘work’) and make no qualms of putting their song first if they feel it fits the vibe better. They also have a tipping point for when to end a song; most songs should not be played entirely, (“4minutes is long!”) but we should at least hear the chorus. When we’re many wanting to play something, cutting a song short also offers space for more songs, so these actions are not frowned upon when there’s many DJ internets. I came to realize these are some pretty established norms among this friend group, yet they are not obvious to an out-group, especially when it is not clear who is doing what. In the past when the playlist and output device had a central location in the physical space, it was also obvious who to direct grievances to and sort out disagreement. With the Jam, these actions are obscured from the physical realm.

    I had not been properly paying attention to the music, casually dropping in and out on the dancefloor, when I noticed a song was abruptly switched after 15 seconds. I asked what happened to one of my Belgian friends, whom I knew would be consumed by the playlist, and he complained that he doesn’t know who’s doing this – the queue had also disappeared a few times. He bitterly said he had a suspicion, pointing across the room. I casually went to confront our suspect, and after some chatting I found out our new Mexican friends had apparently been diligently putting their songs in the queue but kept getting other songs put above his, so theirs were never played. And when they finally were played, they felt it was cut short unfairly (“ALL 6 minutes deserve to be played!”). They weren’t really sure who was doing this, so getting frustrated, he and his friends had started skipping the songs that were put in front of his songs, almost culminating into a conflict on the dancefloor.

    Queueing is a very culturally determined practice and I’ve seen norms clash over it so often – I still remember the desperate look on my Australian friend’s face after he had been trying to get a drink for half an hour at a busy Brussels bar. The later it gets, the more these queues devolve into a ‘work your elbows in the crowd till you touch the counter’ – type of ‘queue’.

    It makes sense that there are also different normative practices around queueing songs, though there’s two elements that differ from physically waiting in line; queueing a song has an effect on more than just the person choosing the song – it’s a decision that affects the collective; and the platform architectures of Spotify’s Jam shape the visibility of queues differently than in the physical world, as the actions of skipping and changing the order are not attributable. This complicates communication on how to find a consensus among differing norms.

    In the end my curiosity on our Spotify practices (and some welcome reflections by my Turkish partner) made me capable to broker peace between the different groups (I guess 2024 will not be the year where I stop meddling!). I explained to my Mexican friends that it wasn’t a case of malice, it was just a different norm, but that I understood how it feels unfair, and I told my Belgian friends what I had learned from my Mexican friends. At first my Belgian friend said that if they really wanted to play their songs, they should switch to their song when the time is right, but I pointed out that this “right” time is not obvious for people who have not partied with them before. They reconciled and admitted that there is perhaps a clash of norms, and we managed to continue partying together with a clearer communication over the shared playlist.

    There were two more pieces worth mentioning on the social shaping of Spotify’s jam function; the role of digital literacy, and the possibility for capitalist stratification.

    I noticed that some people did not fully understand how to add things to the queue, which led to some queues accidentally being wiped and songs skipped. Again, without visibility over such actions, malice was assumed and added on top of the frustration both sides felt. Hanlon’s razor is thus best applied to Spotify’s Jam! Some were off by a lot (as one can expect at a New Year’s eve party) with the hilarious incident of my not-very-sober friend who took the whole Spotify jam off the speakers to connect her phone, as she thought we were all just one by one connecting to the speakers. She abandoned her autocratic DJing after one song, so we took the jam back online.

    We also noticed how easy it would be for Spotify to create inequality in the system. For a moment in the beginning we thought Spotify had made a tiered system where its premium users would have their songs appear at the top of the queue, but as the evening progressed this did not seem to be the case anymore. I can just imagine Spotify would not be peeved with its capitalist mindset to give more social power to their paid customers… For now Spotify seems to have resorted to an autocratic option (where the host can control the order and all other users can only add to the queue) or a fully democratic option, with the potential for chaos and norm conflict.

    In any case, I had a fun evening, seems like I can’t ever fully let go of my PhD (go check out my paper on the shaping of social norms by platform architectures if you enjoyed this) but I guess by now we all know the answer to the question whether I’m “fun at parties” :’)

    Photo by Point Normal on Unsplash


  • Why is it so hard to let Musk’s leadership sink in?

    Why is it so hard to let Musk’s leadership sink in?

    (this piece previously appeared in Dutch in Knack)

    With a kitchen sink he entered Twitter’s headquarters on Friday, making it clear to everyone that they should acquiesce to his takeover. “let that sink in”.

    Why do so many people find it hard to let it sink in that Musk is now at the head of Twitter? Alarm bells go off for many that Donald Trump is coming back, along with a bunch of other foul-mouthed tweeters. Promises to make Twitter an “everything-app” like China’s We-chat make many shudder, as well as suggestions that misinformation is just an opinion, which Musk illustrated on his second day by tweeting a conspiracy theory about the attack on Nancy Pelosi’s husband.

    To be clear, Twitter is bound by legislation that pretty clearly defines how the platform is responsible to remove hate speech. The platform has also committed to following the European code of practice against disinformation, and the just-passed European Digital Services Act will also impose additional rules on the platform. As European Commissioner Thierry Breton tweeted on Friday, the Twitter bird will have to fly by EU rules.

    At the same time, there is a lot of toxicity on the platform that is not illegal but unpleasant enough to make people’s lives miserable online, and there’s plenty of dubious information circulating on Twitter can take on a life of its own.

    My main concern for Twitter lies in its architecture as a social medium, which is among others the focus of my PhD dissertation. That is because Twitter’s architecture has a direct consequence for the role Musk will be carrying from now on. Twitter, sometimes called “the hell site” by its users, is known as a platform with a lot of bickering. Although it is the source of many memes and interesting discoveries, discussions can get incredibly toxic. That’s in part due to the way Twitter is built. Whereas profile platforms like Facebook are built more like cul-de-sacs, places where people stay in conversation with their contacts and where the occasional visitor drops by, Twitter is built more like a busy city where different types of people are constantly interacting. As such, it regularly clashes between different norms of socially acceptable behavior. Years ago, the communication scientist danah boyd gave this phenomenon the name “context collapse,” a coming together of different contexts that collapse into each other with all its consequences. It is not uncommon for this to lead to conflict and for a norm to be enforced aggressively by a few outspoken users. At such moments, there is a need for community moderators. See it as a type of social worker who intervenes in disputes and urges people to calm down or return to their own neighborhood. If necessary, virtual police can also intervene to maintain order when things get out of hand.

    The ability to intervene at Twitter falls almost entirely on the shoulders of the platform itself, and since Friday on those of the chief Twit himself; Elon Musk. Indeed, on Twitter, there is little room for community social workers. When users respond, it will rarely calm things down. On the contrary, such interactions actually elicit more algorithmic visibility due to Twitter’s architecture, which can reach even more participants from other contexts, resulting in even more clashing norms. At worst, some accounts are also picked out by tweeters with a big reach and end up in a Twitter storm. Thus, they can get the full brunt of hundreds, sometimes thousands of accounts. Such harassment need not exceed the boundaries of hate speech to make people miserable. ‘Networked harassment,’ as it is called, has impact because of its scale. The only defense users have in such cases is to put their accounts on private, which basically locks them in a silo in the virtual city, or block people, which in the case of networked harassment can feel like fighting an uphill battle. The last remedy then basically leaves users to not participate in discussions, or leave the platform.

    This is why it’s important for Elon Musk to recognize his crushing responsibility to moderate as virtual police. Not that Twitter has done this in any particularly transparent or balanced way so far, but Musk has made it very clear that he prefers to do as little content moderation as possible. He wants to limit himself only to what is established by law as illegal speech. (I won’t even go into how that means he’ll likely comply with authoritarian countries that have criminalised criticism of the government…) But he claims his minimal intervention strategy is necessary to ensure freedom of speech as much as possible.

    What he does not seem to understand is that it is not content moderation but rather the lack of content moderation that harms freedom to speak out the most. When the line of decency is very low, nuanced voices are pushed out left and right, and minority voices that are inconsistent with the most common norm are suppressed by the loudest and most dominant voices. Mckay & Tenove also warned for ‘unjustified inclusions of falsehoods’, where democracies that give space to falsehoods displace and devalue the contributions of legitimate members of the public.

    Weaker moderation policies ironically hurts free speech: The voices of real users will be drowned out by malicious users who manipulate Twitter through inauthentic accounts, bots and echo chambers. Only those with elephant skin, or mildly masochistic traits in the face of so much hostility, will stay on Twitter. Musk stated Friday that he sees a danger of social media breaking down into far-right and far-left echo chambers. Ironically, a lack of proper moderation could have this very effect on Twitter. in French there is a saying “Quand tous les dégoutés s’en vont, il n’ya que les dégoutants qui restent”.

    The average reader may wonder why this is actually such a big deal, it is estimated that only 5-10% of Belgian Internet users have an active Twitter account. Yet many politicians, scientists and “something-ists” on the platform often behave as if the whole world is watching. Since Twitter is a medium where many journalists pick up information, this is unfortunately also often the case as those voices get amplified through traditional media.

    Due to poor moderation in recent years, there has already been a drain of minority voices on the platform, which may get worse under Musk’s policies. This is unfortunate because due to that aforementioned context collapse, Twitter is also a place where interesting exchanges happen between people from many different disciplines and walks of life. When minorities and nuanced voices are systematically pushed away in a place where the media often gets the mustard for what “lives” in society, we are once again served the same sameness.

    We should give Musk the benefit of the doubt; he himself has tweeted that he does not want his 44 billion investment to become a “free-for-all hellscape. But the firing of the “trust and safety” officer on his first day shows that Musk already has his own interpretation of what a comfortable platform looks like. For some, it will be an anxious wait to see how he plans to fill his role as the guardian of this platform, and whether his leadership will not sink the entire Twitter ship.


  • Cyberdiplomacy at the EU – insights and personal efforts

    Cyberdiplomacy at the EU – insights and personal efforts

    On January 30th 2021, I ended a 2,5 year adventure working in the European Union institutions. I spent this time at the EU Institute of Security Studies, the EUISS, where I worked on the EU Cyber Direct project, providing research support to the European External Actions Service in its cyberdiplomacy endeavours. I have decided to dedicate my full time on my PhD research at the Vrije Universiteit Brussels at IMEC-SMIT and the Brussels School of Governance, where I will be part-time affiliated with the Hannah-Arendt Institute. My doctoral research will focus on platform architectures, the organic spread of misinformation and online radicalisation and the ways platforms shape the agency users have to shape social norms around content sharing.

    My time at the EU left me with many impressions and some accomplishments. At the start of the experience it felt like I had been living in Rome all these years and was suddenly summoned to work in Vatican City. The impressive architecture of institutional buildings in Brussels, which I had so often walked past as a Brussels citizen, now felt like cathedrals for democracy (and bureaucracy…). The centrality of Brussels in the European empire, even more epitomised by the inner Brussels bubble and hierarchies, its jargon and odd customs,… at times working for the EU felt similar to working for the Holy Roman Empire. These cynical feelings eventually subsided as I started understanding more about the inner workings of the greatest peace project (and experiment?) ever set up. I gained some respect for the work of the European Union, despite all its defects.

    I spent my time at the EUISS providing research support for the EU’s cyberdiplomacy efforts. The EU has many diplomatic endeavours in connecting with countries in the digital landscape, one of them is cybersecurity focused. As every country in the world is navigating its way through the digital revolution, The EU deemed it important to understand how everyone perceives their route. Mass societal connection to the information highway brings many benefits, but also exposes society to many vulnerabilities that are hard to deal with. It’s no secret that some countries have been taking advantage of these vulnerabilities. There’s strategic benefits for these countries in exploiting the digital holes that are left behind while we’re all building digital infrastructure at a breakneck speed. I learned that the EU seems to want this global occurrence to be a collective endeavour where citizens protection online is the main priority (with protection very much interpreted from a liberal-democracy perspective).

    Such a collective liberal-democratic strategy previously paid off after the European continent was ravaged by internal war. Cooperation works from the EU’s perspective. In the few years that I was working on the EU Cyber Direct project, I saw an EU trying to understand other countries and regions’ cybersecurity positions in order to adapt its cooperation ideas to the preferences of everyone participating in the global digital space. I saw how the EU and its member states have tried to broker conversations at the United Nations for peace and stability (often too careful in condemning allies) and support other countries in developing cybersecurity strategies.

    A more cynical reading of these efforts is that the EU and other global powers prefer other countries to get ready for state-sponsored cyber operations. If countries know how to prevent devastating consequences and unintentional loss of human lives caused by cyberattacks, it will allow technologically advanced countries to wage cyberwar more efficiently. Though never acknowledged as one of the EU’s policy goals, the EU’s cybersecurity capacity building was probably not only coming from a perspective of peace and love for all citizens of the world.

    While such a policy perspective is not one I endorse, I did salute the capacity building support and traveled around the world to speak about how the EU does its internal cybersecurity cooperation. Not to push a strategy for completely different regions in the world, but mainly to exchange best practices. Traveling for these conferences gave me new insights on how we think about security of the internet from different perspectives. I bundled these insights in 3 regional engagement mappings for the European External Action Services, one on Latin-America, from which I condensed my analysis of the region’s balancing act in a blog post for the Elcano Institute, one on Africa, and one on Southeast Asia. There is no right or wrong way to do cybersecurity in the end, every country and region approaches cybersecurity cooperation and awareness in ways that work for their region.

    During my time working with the EU Cyber Direct project, we connected hundreds of experts, academics and digital rights activists to EU policymakers, putting them in the same room to exchange perspectives. The COVID-19 pandemic made that aspect harder, and working on cyberdiplomacy really made me understand the value of human-to-human contact. I mentioned this importance in my opening statement that I was honoured to make at the 2019 UN multistakeholder intersessional of the Open Ended Working Group (OEWG) on Developments in the Field of ICTs in the Context of International Security. I wrote about what these UN meetings are about for a Belgian audience to create more awareness on the importance of this process.

    In the UN statement I made an analogy of human interaction to the DNS system. Human networks are connected through routing points, similar to computers. These human routing points have a role to play in connecting everyone in their directory to other parts of the world. This is for me what multistakeholderism is about. It is important that the people who are routing points in their local and regional communities are involved in such global processes on securing the internet. Their presence at fora like the OEWG is key to making sure a broad variety of actors has a say in the security and stability of the internet, so a robust human DNS must be built between them.

    The point I wanted to make in that statement, was the need to get a variety of actors involved in the cyberdiplomacy conversation. I supported the European Security and Defense College in the creation of an e-learning module on cyberdiplomacy to demystify the concept and processes for European diplomats. The e-learning is openly accessible to anyone, as the understanding of cyberdiplomacy should stretch far beyond diplomats representing their states interest.

    My time at the EUISS was not exclusively spent on cyberdiplomacy and the EU Cyber Direct project. I was grateful to also be able to contribute to the institute’s strategic foresight efforts. These allowed me to develop my insights on the security threats that stem from social media, which are not a topic of debate in cyberdiplomacy. This is also why I decided to pursue this topic further in a dedicated PhD research project.

    There are good reasons to keep social media, misinformation and other content issues out of security debates, which are at the centre of cyberdiplomacy. For one, it remains problematic to securitize content, and it plays in the hands of global actors who would prefer to gain greater sovereign control over information that circulates within their borders and reaches their citizens. It does however also negate the fact that there are security threats stemming from content that circulates on the internet. On January 6th 2021, a mix of extremists, Trump supporters and conspiracists stormed the US capitol building, supposedly to ‘take back the steal’ and protest the election loss of Donald Trump. Five people died in this riot. One year earlier, we predicted a scenario of civil unrest in the US fuelled by online misinformation and extremists organising in online groups. Our scenario was supposed to take place in 2024, but perhaps the global pandemic fermented many underlying rotting issues and stank up the place faster than I expected.

    Calling the January 6th incident the start of a civil war is hyperbolic, but it was symptomatic to the very real security issue stemming from the social web. The artificial wall held up in the international discussion between harmful code – harmful content also leaves a vacuum for those countries that are dealing with the growing pains of societal digital connection. There are many countries seeing the waves of instability stemming from the internet, but see no clear solution to avoid it from turning into conflict. Without global discussions on this issue, countries cannot support each other in finding viable, human rights-respecting solutions to this problem. This vacuum is easily filled by actors supporting more online repression and surveillance to guarantee stability. If I had more time and space at the EUISS, I would have still written a Brief about the need for global capacity building and best practice exchanges on dealing with disinformation in a rights-and-rules-respecting way. The EU and other countries making policy decisions however haven’t found the best approach themselves. There needs to be more evidence-based policy making first. Countries around the world need to experiment with rights-respecting interventions, acquire evidence together, adapt to local contexts and investigate the effectiveness and impact of certain platform regulations and interventions.

    These issues of misinformation and online hatred fester all around the world on social platforms that are ran by companies that seem unbound by any national legislation, and unbothered by their societal responsibility or lack of democratic input. In my view, most of these platforms are inherently problematic because of the business model and architectures that guide their social interactions. That is why, as part of the What If series, I wrote out my utopian ideal of a social media platform in 2024 where users could get their news as well as engage socially.

    The key importance of such an interest-based social platform are: trained moderators who are part of the community, understand the norms, context and tone and can be held accountable by their community; and a subscription/wallet based monetization.

    I see many challenges ahead for the open internet, as geopolitical interests are seeping into internet governance issues increasingly more often. One such example was the discussion on a potential ban of the Chinese social media app TikTok. I wrote a piece on our Directionsblog how the concerns with TikTok are framed as cybersecurity concerns, but they are actually more a matter of national security where states such as the US don’t want data of their citizens to fall into the hands of a country like China. If states truly want to tackle the security problems with platforms like TikTok, the solution is not to ban the platform and harm user rights that have formed communities on these platforms. The solution is to create a rights-and-rules based social media, for ALL social media platforms.

    When the mindset of a free and open internet starts taking a backseat in security discussions, the internet will start fragmenting on several layers. A lot has been written about how the internet will not fragment, especially on the DNS layer, but geopolitics can intervene in several other layers of the internet. For the last What If scenario that I made at the EUISS, I hypothesized what a fragmented internet would really look like on a Physical, Data and Application layers of the internet (loosely based on OSI & TCP/IP model).

    Image

    The global network of information has always been balancing between decentralisation and centralisation. As the balance seems to be tipping more to decentralisation, it is important to keep regions from fragmenting their internet space and cutting off or inhibiting the flows of communication.

    The EU can have an important role to play in stimulating cooperation towards protecting a rule-based free and open internet. I look forward to keep working towards these goals in the future, possibly with the European Institutions but always with a sharp and critical eye on the Union.


  • What we can learn from conspiracists on social media

    What we can learn from conspiracists on social media

    (Parts of this piece previously appeared in Dutch in Knack.)

    By relying solely on traditional media, we might not be able to create group immunity with a COVID-19 vaccine. A wave of conspiracies has washed over the information ecosystem and play into people’s deep seated fears. Science communicators can learn from conspiracy influencers how to reach people, especially on platforms like Instagram that have become conspiracy engines. How can we work together and inoculate people against conspiracies?

    When the corona vaccine arrived, it felt like the release from a terrible pandemic year, yet not everyone felt that way. Surveys around the world show that people are suspicious and do not fully trust the vaccine. While that is their right, many have become caught in anti-vaccination campaigns and doubts spread by conspiracists. People distrust the government, traditional media, and the experts who seem to be ‘selected’ to share a certain narrative. They look for answers that don’t feel spoon-fed and hereby land in the conspiracy realm. There is a whole community of antivaxxers that is having its glory days during this pandemic. While they’ve been around for a lot longer, they prey on these doubts in times of crisis, and offer answers to people with questions. Researchers found that the anti-vaccination movement on Facebook is estimated to have reached some 100 million people during the pandemic.

    The established media have been working overtime for the past year to investigate every piece of misinformation for its veracity and to refute it with correct information. This is commendable, but factchecks have a limited impact. They are often pushed out into the world without taking into account how the information ecosystem works with all its emotional and social aspects. A factcheck should be part of a conversation, not simply consumed but experienced. It should be used as a tool for people who want to engage in discussion with loved ones but don’t have enough expertise on the topic. Therefore, sharing should be made as easy and attractive as possible.

    Appreciation for the micro-influencer


    In times of social media where our main social interactions during this year have been digital, many have established themselves as “micro-influencers” in their communities. They are considered an authority within a community. Often they are the ones spreading accurate information in this infodemic that has overwhelmed many. People can engage with them and ask questions. They are the people who make others think and encourages them to spread correct information. These micro-influencers also exist in conspiracy circles of course. The main difference is that in those circles, they are adored far beyond their personal network. They are seen as beacons of light in a sea of self-proclaimed “lies”. The micro-influencers sharing accurate information are by contrast undervalued outside their network. Traditional media sees it as a self-evident point that people get informed on their own and that accurate information will just land where needed. By assuming this spread will occur naturally, there aren’t many incentives to inform loved ones on the conspiracies surrounding this pandemic, as it often fuels conflict.

    Isn’t it time we nurture, encourage and provide support for the authority figures in the microcosms of our society and helpt them disseminate accurate information and counter conspiracy myths?

    Memes on instagram

    To support the spreading of accurate information, I created an account with memes against conspiracies @anti_conspiracy_memewars (25k). I am not a medical expert so I resorted to memes. Memes are perfect “units of culture”, as Richard Dawkinks describes them, that can diffuse ideas in an accelerated fashion. Memes are bitesize, often humoristic and easily shareable, which is also why conspiracy thinkers thrive on the use of memes. The account is nothing more than a collection, a database of anti-conspiracy memes. Instagram is a huge virality motor through its stories-feature. With 500 million daily active users of the stories feature, content gets shared far more through this tool than on most social media platforms, and can spread into several different ecosystems. It is the perfect platform to spread conspiracies, but it also has some potential to debunk them.

    Make no illusions; the purpose of the account is not to directly convince conspiracists. A meme account cannot develop the needed empathetic relationship with someone suspicious of medical and political authorities. Only a loved one can counter those doubts, or someone who has garnered a huge amount of trust with people. The purpose of the meme-account is to provide users with tools of communication for prebunking. Users are encouraged to share memes in their story to expose their network to a diversity of perspectives, in the hopes that it reaches them before the misinformation reaches them.

    An example of one of these memes that simplifies a common misconception to the point of it just being understandable and relatable:

    As it is a meme, often light-hearted or tongue-in-cheeck, it is less likely to stir up conflict, but the anti-conspiracy message still passes. It becomes a form of prebunking that fits in an inoculation strategy against misinformation.

    “inoculation theory posits that pre-emptively exposing people to a weakened persuasive argument builds people’s resistance against future manipulation.”

    Jon Roozenbeek, Melisa Basol, and Sander van der Linden

    Roles and contributions

    We must all accept the current information ecology in which information spreads and work with the structures that are put in place, even if that means ‘degrading’ ourselves to memes, or showing our face in an IG Live. Preferably the information ecology would be different, but as long as these platforms offer no friction, as Renee DiResta wrote in her Wired piece, untrustworthy information will keep spreading.

    There are many things we can all do as individuals. If you are an experts with knowledge; show your face and push out the evidence and facts to counter or prebunk conspiracies. Team up with a creator to translate your content to the language of the platform. If you don’t have the facts or creativity, but have a wide platform and a lot of followers; signal boost those creators and experts and make sure their voice is heard. If you see people who should collaborate, connect the dots in the network, maybe they are not be aware of each other’s presence. If you see something trending, alert those in the field who could create content about this pre-emptively. . Every single human with a network, no matter how small, can be a micro-influencer in their community. This is how everyone can actually be part of the counter-conspiracy team in an organic way.

    We don’t have to sit by idly.

    As Claire Wardle put it so eloquently:

    Our information ecosystem is not hopelessly polluted. But we all have to work together to make a change.


  • Banning online communities; is it too late to stop radicalization?

    Banning online communities; is it too late to stop radicalization?
    “Most women who claim they were raped were rapebaiting. If they just let ugly men have sex once in a while, the world would be better for everyone. It’s just sex, they need to get over it”

    This was a post from the now banned Subreddit /r/Incels. A community of men who claim to be “involuntarily celibate” because women are evil. One of many, many online communities that revolve around hatred and scapegoating. How is the internet affecting our society and making parallel communities toxic, and what can be done to stop the hatred from festering?

    Redditland: population 234 million

    A few years ago, I wrote about Reddit’s revolt against the change in management.

    I complained about the management’s new direction of banning subreddits, which are microcommunities on one of the biggest online forums. I’ve always been amazed by Reddit’s political structure and it’s reflection of a real society, and I was fascinated how the citizens of reddit tried to reclaim their virtual streets by causing a blackout.
    I’m starting to soften on the policy the management took on banning toxic subreddits.
    I might even say: I was wrong.

    I was once saddened how the decision to ban meant that Reddit isn’t allowed to reflect a real society, including all the rotten apples and fucked up people in it. I think the disappointement came from a dark corner in me that grew up lurking on 4chan. I still can’t put my finger on what amuses me to see how people can be so fucked-up, but it did.

    I don’t think lurking in the cesspool of the internet ever affected me or my political views since I’m definitely a Libtard. The only remnant is maybe my repertoire of Dead Baby jokes (always a risky performance for a new crowd).

    However I sometimes forget that people can be susceptible to, and when exposed enough, convinced of toxic ideas.
    I’m seeing it happen more around me now, and am therefore no longer sad with Reddit’s decision to ban toxic communities online.

    Incels, The_Donald and OneTrueGod

    What finally pushed me to change my opinion was the recent ban Reddit put on /r/incels. As shown in the beginning, Incels believe they aren’t getting any sex because they are ugly and all women are superficial and basically “Nazi’s trying to exterminate the male race” by denying them sex. At a certain point they convinced themselves that “reverse rape”— not being allowed to have sex with someone—should be included in the #MeToo conversation.

    yeah.

    1510621435611-yoga-pants.png

    (a typical post on /r/incel, a collection was to be found at /r/inceltears before this sub turned hateful too)

    Not only is it one crybaby-fest of men scapegoating women for not giving any sex (newsflash: it’s mostly your ugly personality, not your ugly face), they reinforce each other in their hatred and victimhood. Vice made a great analysis on the indoctrination that was being spread in the 40.000 subscribers strong Incel community, and why ultimately a ban was probably for the best.

    Toxic ideas don’t just remain ‘harmless’ online, they infect people’s minds and have consequences in the real world. Extreme examples are shooters like Elliot Rodgers, who killed 6 people, and identified himself as an incel in his manifesto.  He was a frequent visitor of Subreddits like /r/redpill and /r/mensrights and is now being worshipped by other incels.

    47ega37cakbz

    Letting dark communities exist has consequences. This isn’t just about incels or reddit, it’s about the spread of ideas that can be toxic. A subreddit like The_Donald grew as a joke, a bunch of trolls who thought it was funny to defend a racist misogynistic narcissist. They ended up becoming Trump’s online campaign front.

    Even before Donald Trump got elected, I read too many stories of people saying they started in The_Donald for teh lulz and thought it was just funny, until they became so involved in the community that they started seriously campaigning for him.

    donald-trump-ama

    (Donald Trump even gave an AMA, Reddit’s type of Q&A session to /r/the_Donald. Obama did an AMA as well in 2012, only on the official AMA subreddit)

    I get it, in some weird way, people can get sucked into things. I’m part of a satiresubreddit /r/OnetrueGod, entirely devoted to Nicolas Cage, our lord and saviour.

    6761e3681cca5ff47527b7ffe7e82b31

    It started as a joke, until I noticed I started getting really invested in it. I took a deep long look at myself after I tried to convince my friends to go stalk the hotel Nic Cage was staying in when someone had spotted the one true God in Brussels.

    Jokes can get out of hand. and then suddenly they’re president of the “Free World”.

    Don’t Feed The Trolls

    Is there any argument for banning /r/The_Donald, which supports the legitimately elected President of the United States, except for the fact that they kind of organised their white-supremacy rally in it? If /r/Incels was banned, what makes /r/theredpill any less misogynistic? I’m still very cautious of the concept of censorship. There is the slippery slope argument that if we start here, what will be next? The argument is sometimes used as a fallacy, but we always need to think very deeply what censorship can lead to, especially considering the ban of an entire community.

    Doing nothing has proven to have damaging effects though, since the internet can be an effective breeding grounds for radicalization. There have been plenty of actors that saw the immense opportunity in a network of networks, and have used it to further a political agenda. Young muslims who were first exposed to extremist ideas online were a goldmine for ISIS’ recruiting operations. The Mexican (then elect) president Peña Nieto also used recruited trolls who were already dicks on the internet in daily life to spread lies about his opponents and distraction on his own scandals (listen to the awesome Reply ALL podcast on this story)
    The Russians have elevated the art of information operations, and use information warfare as a strategic tactic. The invasion in Crimea came with a whole disinformation campaign, and troll armies have been notoriously used to influence the Brexit vote, US elections and have been seen to also influence Czech and French elections.

    A lot of these operations recruit confused individuals (usually teenagers) and weaponize  their frustrations. But not all of the radicalization was steered from some motive, most of it just grew organically out of a certain hatred.

    Where that hatred comes from is a whole other question that we won’t delve too deep into. What I usually read is the hatred comes from isolation, lack of community and lack of exposure to a diversity of perspectives.

    internet-troll-1

    “Banning an online community will just remove the container”

    What should we do then? I’m still not sure banning or censorship is the solution to everything. I always thought people will just find the community or information somewhere else, and you’re basically ignoring the problem. I am however becoming more convinced that allowing a community to fester in its hatred out in the open is not healthy. Banning means the community gets pushed deeper into the web. While we lose oversight and transparency, the toxic ideas also become less accessible, are less normalized, and are harder to stumble upon. It reaches only the most extreme individuals in our society, instead of poisoning a whole generation.

    Where do we draw the line though? Are we prepared to give up part of our freedom and compromise on the idea of a free and open democratic society internet? As Karl Popper said in the paradox of tolerance, the only thing we should be intolerant towards, is intolerance itself.

    20915622_10155667089079510_3661270304265396527_n.jpg

    Plato also said this in The Republic, Tyranny evolves from democracy, states stop being democratic when they’ve become too democratic.

    Is banning communities the solution though?

    Studies have shown that banning subreddits has an impact, and after the first ban of /r/fatpeoplehate and /r/hamplanet in 2015 a lot of the former members of the community slowed down on their hate.
    Many didn’t though, which is why banning simply is not enough. Some people don’t just go away when their container of a community is removed, they just take it somewhere else. We need a counternarrative to challenge toxic ideas, and work against the isolation of the communities, so moral borders can be stressed by more outsiders.

    We’re finally gaining ground on islamic extremism. ISIS seems to be failing to draw as many young recruits to Syria as they used to, and our European societies seem to take steps in reinforcing community and reintegrating radicalizing youths.

    The Vilvoorde approach on dealing with youth that want to go fight with ISIS in Syria will always be my favourite example on how to tackle radicalization. Vilvoorde had the highest percentage of Syria-fighters in Europe. Since they implemented the approach, they’ve had almost none.
    The set up is simple; if people spot a jihadi recruit, they ask the city for help to gather a roundtable of people who can influence them; family, friends, school, mosque. They try to reconnect the youth with the community, and challenge some of their misinterpretations of the Quran. It’s all based on local trust and love; they invite the youth, but do not force them, to become part of a broader community again.

    We need to do this for every man and woman that we are losing to hatred. Be it hatred against women, fat people, people of a certain colour or religion, “Social Justice Warriors” but also hatred against white men, and definitely hatred against themselves. We need to learn to spot radical ideas and challenge them. it doesn’t matter if it’s “just online”, these people are as much human online as they are in the physical realm. We need to step up to offer a counternarrative. Make the borders clear, but also make them feel part of a broader community. Kill the “forever alone” trolls with kindness.

    2f7

    Community is important, but if it stays in self-reinforcing bubbles, community can be toxic. Banning microcommunities is a radical solution and a stop-gap measure to healing our society.  Let’s hope we can also find a way for the bubbles to open up and diversify the communities people surround themselves with.

    Let’s stop people like incels from thinking they’re justified in raping women because they have a right to sex. Let’s change those perspectives.

    “The most powerful weapon against the lure of radicalisation is increasing complexity in thinking and developing a critical mind-set from a young age. We have to move away from black-white thinking and try to make young people comfortable with grey”

    Lynn Davies, University of Birmingham


  • How the Russians really hacked the 2016 election

    How the Russians really hacked the 2016 election
     The Russians tried to hack the American elections. But not in the way that we’re used to. This piece treats some possible consequences for the West of the information war Russia has taken outside of its borders.

    Piece previously appeared on De Morgen on 16/12/2016

    In a disconcerting long-read of the New York Times we see all the staggering mistakes made by the Americans so that the Russians could carry out strategic hacks in the run-up to the elections.

    Both for hacking the Democratic National Committee and hacking the emails of Clinton’s advisors, there is clear evidence of Russian interference. The Russian state hacker groups Cozy Bear & Fancy Bear, also known as APT28 and APT 29, were recognized in the forensic investigation. The self-proclaimed “lone wolf” Guccifer2.0 who allegedly had committed the hack alone, also made some stupid mistakes making it clear that this was a cover-up of Russia.

    Russia’s Information War

    The tactics used by Russia here come straight from their information war handbook.

    In an information war,  information is used for psychological purposes. The goals is to confuse the population with erroneous information and causing unrest with leaked information. The confidence in the traditional sources of information drops and facts can no longer be distinguished from fiction.

    The internet is a godsend for this type of warfare, and Russia is perfecting these type of operations.

    During the elections in Ukraine and the subsequent annexation of the Crimea in 2014, their use of information operations peaked. They made strategic leaks to discredit the pro-European presidential candidate while distributed fake photographs about Ukrainian soldiers and spreading disinformation (the website Russia Lies collects many of the disinformation campaign on Ukrain)

    Russia is also known for spamming internet forums with their Russian web brigades. The Russians have a veritable troll-army whose daily task consists of posting thousands of pro-Russian comments on the web.

    Sounds familiar in the run up to the 2016 election?

    harmful code vs harmful content

    The CIA had already openly accused Russia of these tactics, but the American intelligence community was first putting its effort in an investigation on hacked voting computers.

    In the run-up to the elections, it emerged that there were many vulnerabilities in the outdated voting computers. The day before the elections, for example, security company Cyclane showed that it is possible to change the names in a voting computer if you have physical access to them.

    Investigating whether the systems had been hacked was a stop-gap measure to restore confidence in democracy and elections. If it could be proven it had not, then maybe the people could trust the election? Sowing uncertainty about the election systems was also part of the information war; making people doubt the results of the election. Such uncertainty is a different way of ‘hacking’ the system, and one that would have definitely had its effect had Trump not won (his voters would have most likely questioned the results ).

    The Russians did not have to hack into voting computers to reach their objective, the main goal was always to falter the confidence in democracy, not necessarily to get a puppet like Trump elected.

    The US is struggling to recognize that it has a problem of information security.

    This has nothing to do with America’s arrogance, but above all with a fundamentally different view of international digital security. The Western doctrine of cybersecurity revolves around protecting (digital) systems, and the information contained in them. Information is no more than a series of zeros and ones.

    While the West is only mindful of ‘malicious code’, Russia sees’ malicious content’ as a weapon as well. The psychological weapon of “information operations” as described earlier. It is no coincidence that the Russians prefer to talk about information security instead of cybersecurity. (note: the infosec community also talks about information security, only this term was politicized when explicit demand came for the UNGGE to be called the UN Group of Governmental Experts on Information Security) Influential information is dangerous in Russia’s eyes, and it is not even necessariy to attack any digital systems.

    Putin is known for blocking opposition websites and bloggers and actively disseminating lies. A list of lies on the European Union is also kept up to date in the Disinformation Review, a magazine recently set up by a task force of the EU.

    It should be no surprise that this vision is share by other authoritarian state like China, Iran, Turkey, where control of information is vital to streamline political preference and keep dissident voices in check.

    6482310_orig

    It seems that Russia’s use of an information operation was not only a way of testing the potency, but also to warn the West of the ‘danger’ of a free and open internet.

    A free and open internet: the achillesheel of the West

    Now that Putin is also executing his information war abroad; the West has a problem. Freedom of expression is a core value in an open and free society. Unfortunately, this is also the Achilles heel of the West, and the Russians have made good use of it. Not even a long time ago, WikiLeaks was the epitome of free information gathering, holding those in power accountable. In recent months, by distributing only information extracted from Russian hackers, Assange became an indirect spokesperson for Putin.

    Trump does not owe his presidency to Putin. There has been some rumbling in America’s lower abdomen for some time. But in the toxic breeding ground of filter bubbles and a post-truth society, there is an opportunity to expand Putin’s sphere of influence. Now that American confidence in democracy has fallen to a low point, the US seems ripe to join the authoritarian states.

    The Democrats know that Putin played the game like that. But if they admit that there is a problem with the free flow of information (whether or not such operations have an impact), they might also want to exercise control over all information. One might think they can only beat the Russians in the information war by putting a tighter control on the information in their own country. Following the Reflexive Control Theory, this would be exactly what Putin wants.

    The West is already slowly moving in that direction. Counternarratives against radicalisation, restricting hate speech and banning fake news. And how can you be opposed to it, when you see what kind of conspiracy theories are currently finding a platform?

    All the signs indicate that we will only go one way: that of a more controlled Internet. With someone like Trump at the wheel, it is not impossible that this control in “the land of the free” will go much further than stopping Russian influence.

    The question on my mind is what direction my native Europe will take. Are there means of arming us against the next information war without having to give up our online freedoms?

    I do not believe in it, but I sincerely hope that I am wrong.


  • The IoT Zombie army is knocking on our door, what are we going to do about this?

    The IoT Zombie army is knocking on our door, what are we going to do about this?

    (this article previously appeared on Knack-Datanews)

    October 21, the world is confronted with an unprecedented DDoS attack, mostly caused by insecured Internet of Things devices. IoT manufacturers were put under scrutiny, and we were all given a sneak peek of the consequences when we don’t include including Security by Design. Where do we go from here?

    The facts: on October 21 a Distributed Denial of Service (DDoS) attack on the DNS provider Dyn caused disturbances on the internet. Dyn is the equivalent of the internet Yellow Pages; they direct you to the right IP address when you type in the URL of a website. DDoS’ing them is therefore a simple, but effective way of making a large quantity of websites inaccessible. No Netflix and Chill, no Reddit, no Twitter. In short, people had to go outside and be productive.

    DDoS attacks are as old as the internet itself. When a server is flooded with requests, it cannot reply to other legitimate requests. This happens sometimes when a site becomes unexpectedly popular and has a surge of visitors, but a malicious DDoS attack usually uses  infected computers to spike the visitor requests.

    A lot of organisations have tried to instill measures to mitigate DDoS attacks, yet this incident was remarkable because of its size. Dyn reported that more than 10 million IP addresses were involved, the equivalent of 1,5 Terrabye per second.

    It was discovered that this was mostly possible because of the festering supply of vulnerable internet of things appliances.

    Internet of shit

    The security community has been cursing for a while now about the Internet of Things, often scorned as the #InternetOfShit. These are all the appliances and gadgets that can (often needlessly) connect to the internet, like your tv, security camera, fridge, but also your car, your toaster, your lightbulbs, your doorlock, and even your bottle of wine. It is estimated that in 2016 about 6 billion appliances are connected to the internet. A dizzying number.

    internet-of-shit

    When more appliances are connected to the internet, there are more vectors to infect, which contribute to computing power for attacks.

    This was also known by the creators of the Mirai virus, which purposefully infected IoT devices. Millions of infected IoT appliances were thus added to a botnet, creating a monster army of zombies that were used for DDoS attacks, unbeknownst to their owners.

    Zombie hideout

    A logical step if we want to prevent such attacks in the future, is cleaning up those devices. A lot of users know by now that they need to install antivirus software on their computers, but are not aware that their television or security camera can also be infected and participate in attacks. There is very little motivation for users to do something about this, since the impact of the infection is nearly unnoticeable in daily use.

    Every country thus has the responsibility to notify users that show up in the IP logs of recurring DDoS attacks. They can inform the general public, generate awareness, and use certain incentives to secure IoT devices. This way, the zombies can be deactivated and botness can lose their strength.

    An IoT that deserves our trust

    Unfortunately users cannot do much themselves if they are not even capable of securing their devices. It appeared that Xiongmai, a Chinese producer whose devices was omnipresent in the attack on Dyn, had set default passwords on its devices, that couldn’t even be modified.

    This was apparently the case with all devices sold before 2015. This kind of vulnerability is sadly recurrent in many devices. If the password cannot be modified, it most definitely can be controlled by someone else.

    Producers are still free to choose how much security they want to install. There is no international security norm for connected devices.  Since a cyber-secure connected toaster isn’t exactly a big selling point, this step is often skipped to cut costs.

    firewall toaster

    It is therefore important to call IoT producers to account, force them to have minimum security standards, and penalise those that don’t.

    Organisation like the Internet of Things Security Foundation, and volunteers of the security collective I Am The Cavalry are taking matters into their own hands by setting up security frameworks. The latter even managed to make the producers of medical devices swear a hippocratic oath to no longer sell devices that do not have built in security.

    The EU is also developing a proposition to force companies to abide to certain security standards, and to find a labelling system for secure IoT devices.

    While its certainly useful to secure European production, it lacks some impact in a globalised world. If producers are prohibited to use cheap Chinese components when they don’t abide to those standards, it will be hard to stay competitive. If there’s little knowledge of the issue, few consumers will pay more for a “secured” IoT device.

    We need international rules, although it’s not bad to start with a European label.

    Too little, too late

    When IoT devices didn’t have proper built-in security settings, it’s difficult to secure them afterwards. It’s commendable (and necessary!) that we try to force security by design right now, but it’s actually too late already.

    The IoT craze has started a while ago already, and many appliances were sold that can’t install patches remotely. Often users must make a manual firmware update, or even hand in their appliance. Since the lifespan of many of those devices, which are often household appliances, are often only replaced after 5 to 10 years but its users, it’s quite possible we’ll still be living for a while with the consequences of the IoT zombie army.

    it’s very pessimistic to say, but this is only the beginning.


  • Is our “Digibesitas” giving us Technophobia?

    Is our “Digibesitas” giving us Technophobia?

    (This article previously appeared in Dutch on Knack – Datanews)

    The tendency to curse smartphones isn’t new. But I am becoming fed up with the articles, cartoons and art that are going for the low hanging fruit of bashing new media technology.

    social media whore3

    From criticizing the display of personal life on social media and fishing for likes,

    to the insensitivity of the “sharing culture”

    to being chained to your computer and smartphone

    There are too many “wake up Sheeple” cries in popular culture these days, blaming hyperconnectivity to cause society to be anti-social, attention seeking and narcissistic.

    smartphone wall

    I’m showing a bunch of examples in this post that I’ve been collecting for a few months, since they irk me. Like the well-intentioned, but very cringy Spoken Word artist below, who rhymes about how iPhones makes us only think of the  “I”.

    Even Zenpencils, who I really respected, compares social media to a Heroin Addiction.

    thumb_IMG_1311_1024

    (and here’s another such comparison… not so original eh?)

    But also more serious voices are riding the wave, like the TED-talk of Sherry Turkle, who is convinced that the virtual connections only make us more lonely.

    The Belgian research institution iMinds even came up with a name for the “overconsumption of digital media”: Digibesitas.

    It’s starting to feel like Neo-luddism, the Unabomber’s ideology against a new industrial technological society, is back in a softer form. There’s no computer stores being bombed, instead hyperbolic cries try to convince us how society is ill because we’re spending a bigger part of our social activities online.

    Kranzberg’s 1st law says “Technology is neither good nor bad; nor is it neutral”. It all depends how it is being used.

    “we should all throw away our smartphones maaaaaan, we’re so disconnected”

    (I once heard someone say at a dinner-party, that was entirely arranged through a facebook event.)

    It would be naive to argue that our social interaction hasn’t changed. Au contraire, the digital revolutions has caused quite some earthquakes, moving all our communication to the digital spectre. As I previously wrote, our memory is even changing due to the possibility of digital storage. It would also be blind not to recognise that there isn’t a sizeable portion of fhe population addicted to social media. There have been countless reports on how algorithms are affecting and steering our behaviour.

    But there are also plenty of people who still have a healthy relationship with social media. This pathologizing social media seems to only give one alternative: throw it away.

    Some nuance is due on the impact this digital transformation has had on our communication, since there have been plenty of positive aspects of the digital social life.

    Digitally enhanced life

    Thanks to the sharing culture, we’ve got an incredible archive of testimonies during historic occassions, like the footage during the Paris attacks, the detailed accounts of the refugee crisis, … but also on an individual level, your entire family can easily watch and re-watch the first words of a new addition to the family, or you can watch and re-watch your GoPro filmed escape from a bear that suddenly surprised you in the woods,…

    And let’s not forgot movements that were mostly gained momentum through social media such as the Arab Spring or #blacklivesmatter.

    Digital communication has made it possible to work from home and take care of your children or a sick family member. There are even so many more possibilities arising to keep doing the same job from the other side of the world, an evolution welcomed by the growing population of tech nomads.

    People can stay in touch with friends from all over the world, you can become friends, or even become part of an entire community of people that you’ve never met before. The internet offers an inside look on other cultures for those who cannot afford an expensive airplane ticket.

    online_communities_small

    (online communities 10 years ago, in 2006)

    Not only has the digital life had a major positive impact on our social life, not taking it seriously can even be harmful.

    As Julianne Ross wrote in Wired, the online life is just as real for many as the Physical world. Emotions people have online are just as real as the ones they have offline. Suggesting that it is not, means people aren’t taken seriously in cases of cyberbullying or sextortion.

    These are very real problems, that can have an enormous impact on the human psyche.

    The biggest problem with the digital society in my opinion isn’t that people are staring too much at screens, but that society hasn’t accepted yet that we are all real people online, with real feelings. Not acting like it can have real consequences (Hong Kong has even noticed a peak in suicides because of cyberbullying). Maybe the presumption that kinds are becoming more narcissistic is because they forgot that every ‘like’ comes from an actual human, and they should cherish it.

    martinakis-04

    The core of my rant is this;

    Technology changes, but humans are still human, in digital form.

    Anti-social people will just use the tools to stay anti-social and ignore you, possibly retreat to another world.
    Young people will always crave attention and validation.
    Narcissistic people will always feel like nobody likes them enough, no matter how many hearts you throw at them.

    xkcd

    The Digital society has only given us new tools. Tools we use royally, that facilitate and enrich our lives. We still create society ourselves. If this means we’re retrieving more into a filter bubble, it’s maybe becauae the tools give us the possibility to follow our human nature to finding connection. What SHOULD be more central to the conversation is the need for tools that break through bubbles, tools that facilitate discovery. But that is a whole other conversation on how we should reimagine platforms.

    In short: yes, the digital life impacts our social interactions. But that doesn’t make them less real.

    thumb_IMG_1310_1024 2


  • Digital Amnesia

    Digital Amnesia

    (This article appeared earlier on Vice: The Motherboard NL)

    With all this talk about ‘digibesitas’, let’s add one more new-society disease to our vocabulary: Digital amnesia. It’s the act of forgetting certain things when you store them on you digital devices.

    I started to notice that my memory is failing me lately, and it’s was really beginning to frustrate me.

    Remembering the street that I had just looked up, or the name of that movie, with that actress, you know, who was together with that guy, but I can’t remember any of them… It seemed I had to rack my brain much more to remember the stupidest things, and I couldn’t limit myself to less than 10 internet searches a day for these stupid kind of things.

    Screen Shot 2016-01-19 at 02.29.49

    Early onset Alzheimer

    When I couldn’t even remember the pin code of our shared food-account at the digital-amnesia-FB_supermarket counter at rush hour, and had to look it up in the notes of my phone cause I knew I had put it there temporarily ‘just in case’, I went to the doctor.

    I dead-seriously asked him if Alzheimer is possible at my age and he looked at me and said “Nathalie, go to sleep earlier”.

    If he wouldn’t take me seriously, the internet would, so what did I find on one of my nightly internet-rounds? That we’re all collectively kind of worried about our memory.
    Scottish researchers diagnosed this memory loss a few years ago as the ‘Busy Lifestyle Syndrome’. According to their theory, our capability to remember isn’t decreasing, but we just have far too much to remember these days. Therefore some recollections disappear in the realms of our brain, buried by the avalanche of information.

    This is only half the truth. In order to cope with all this information piling up on us, we try to save a lot externally. Our smartphone has become our biggest ally, but it also adversely seems to be the cause of our memory loss.

    A recent study initiated by the cybersecurity company Kaspersky Lab speaks of ‘digital amnesia’. This entails the phenomenon where you will start forgetting information after you’ve entrusted it to your digital device.
    Your brain will stop putting in an effort to remember certain bits of information, since it knows those are being remembered somewhere else.
    The only knowledge it still retains is the instructions where to find said information.
    Your brain becomes a directory to where certain files can be found on your smartphone/computer/the internet.

    As if you’re asking your brain “hey buddy, can you tell me where Ann lives again?” and your brain is this lazy slob lying on the couch watching tv, yelling “she mentioned it somewhere in this facebookconversation you had a while ago. Try searching with keywords ‘party’”

    lazy-brain

    According to the Kaspersky study, more than half of its respondents will think of keywords to Google the answer, instead of thinking of what the answer might be. This is also called ‘the Google effect’.

    The joy of forgetting?

    Our cognitive processes are truly changing when the internet and smartphones are within arm’s reach, it seems. According to Maria Wimber of Birmingham University, these devices allow our brain to ‘selectively forget’ the externally saved information to make room. Forgetting is quite healthy for our brain, and when we save that info on an ‘external brain’, we feel safe and assured that forgetting won’t mean that info will be lost. We can now make space in our head’s hard drive and process more new information.

    So far the good news.

    Because what if you suddenly don’t have your external brain with you? What if you need some important information that you hadn’t remembered because you counted on that smartphone?

    Your data running out when you still needed to look up the route to your friend’s house.

    phone diedMissing your last bus when your phone has died, and not remembering a single phone number from the top of your head to help you out.

    Not remembering the name of that grey white man that is walking enthusiastically towards you at a conference, and you can’t quickly check your linkedin.

    Or even worse, when your brain accidentally deleted the directory to some information because there’s too many storage spaces. That article I was going to reference to, did I save it in my bookmarks? Did I put it in my Evernote? Did I e-mail it to myself? What keywords can I use to google it and find it again…

    2013-06-21-2506605
    (Courtesy of Doghouse Diaries)

    When the external brain disappears…

    We unknowingly put so much trust in our devices because they are so efficient and user friendly. It almost makes us forget that they can disappear in a single moment.

    You can lose your device, but also your back-up can disappear.
    Whether it’s mechanical failure or magnetic field breakdown, back-ups on hard drive will not live forever. You will need to refresh them at least once every 3 years to make sure the data stays safe. After some more years, some of the files on your hard drive might also become unreadable because of ‘bit rot‘. Vint Cerf, the ‘father of the internet’ warned us for this phenomenon. Some files are only readable by certain programs, and those would no longer be supported by newer computers. You would still have the file, but no way to open it.

    B9w0-9OCIAELslB.png(This colourful mess is all you’ll be left with)

    And the internet itself is disappearing and forgetting all the time to make space.

    I recently made the painful discovery that my unused Hotmail-account, my very first e-mail address that I had created when I was 12, was completely empty.
    Microsoft had made a big sweep of inactive accounts to create more serverspace and clean up its data storage.
    Gone were my stupid but funny teenage e-mail chains with friends. Gone were my very first digital love letters with crushes. Gone was all this information that I will never retrieve again.

    This happens all the time, since the rapid growth of the internet also means an ever expanding amount of information that occupies server space and overwrites other data. Who knows what part of the internet will stand the test of time.

    If we’re not careful, it is quite possible our collective digital legacy could go up in smoke in less than 50 years. It’s one of the reasons I donate to the Internet archive and its waybackmachine. Webpages disappear all the time when their owners stop caring about them.

    One can say we’re at a point of no return, the internet and our devices have become an extension piece to our brain. We can embrace it, continue processing new information and rely on our external devices to remember it. And accept it might one day be lost.

    We can try to fight it and try to remember everything to the point that it drives us mad. Print out all pictures and documents to keep in a box in the attic. Make 6 back-ups and store them a tin jar to protect them from solar flares and spread them over the globe.

    But it doesn’t matter what kind of wonder pills you’ll try to take. One day we’ll all forget, and be forgotten.


  • The Great 2015 Reddit revolt

    Reddit’s foundations are crumbling. Disturbances are happening within the headquarters and the leadership. The frontpage of the internet is in anarchy.

    (Addendum: 2,5 years after I wrote this post, I came back on a lot of the opinions expressed in this post. The world had changed and I had been too naive to notice. I realized the value and necessity of interference from above, and how it’s necessary to keep the community healthy by banning certain subreddits. I still stand behind what I said about how interesting the political system of Reddit is, and how impressive it was when the community carried out digital civil disobedience in the Great Reddit 2015 Blackout, but I realize now I was on the wrong side of the fence. Interference should always be scrutinized, it deserves transparancy and democratic oversight. That doesn’t mean it shouldn’t happen.

    In the years after I came back from the opinions expressed in this post, I’ve hesitated several times to keep this post up. It does not exactly put me in a good light, fighting for the wrong cause and hurts my credibility to want a healthier internet. I decided to keep it up as a time capsule, to show what reform looks like, and to also show what the sentiments were before the effects of Reddit’s mismanagement of toxic communities became visible.)

    As most of my friends know, I’m often on Reddit. that massive forum that calls itself (often rightfully) the frontpage of the internet.
    I love observing the community. I enjoy how it resembles a real society so often, how it is a digital political entity.
    It has its own rules. Its own leaders in the form of moderators. Its popular places in the form of top subreddits. Its own celebrities. Its obscure and dark corners. Its own scandals and corruption.
    Better than a real live community, It allows anyone to be anonymous. to choose where they belong, and what parts they want to belong to. To pick an identity and roll with it.

    I love how it has a certain authenticity, but also how there is uproar when said authenticity is damaged. But lately I’ve been feeling like things are about to change, and the end of Reddit as we know it is in sight.

    Change of Leadership

    There’s been a lot of turmoil with Reddit lately due to its change in leadership in the real world – Ellen Pao, an MBA with zero previous affinity has become CEO and leader in charge of Reddit. A change that is transforming this community which I’ve grown to love.

    What directly led me to write about this today is that one of Reddit’s most beloved employee was fired for reasons unknown. Victoria was the direct communication support for celebrities doing an AMA. On the wildly popular subreddit /r/iama, celebrities appear and allow redditors to “Ask me Anything” (AMA), a very down to earth Q&A that almost ‘everyone who’s anyone’ has done. Even President Obama has done a historic AMA.

    Victoria not only helps the celebrities with AMA’s, who usually have never browsed reddit before (a website which can come across as very user-unfriendly for a first time user) but she is the helpline and direct contact point within Reddit’s administration for the users. When subreddits, like /r/science or /r/books want to organize an AMA for a celebrity from their niche, Victoria would help set this up and guide the moderators of such subreddits. Victoria was highly respected in the community and very committed to her tasks.

    Victoria

    /r/iama has gone dark as a protest since it cannot function without her, and a whole bunch of other default subreddits (the most popular subreddits) have gone into private mode as well.

    Why Victoria was fired is as of yet unknown, but it is yet another sign on the wall of how reddit’s owners have stopped caring about its community, and have taken over command.

    Censorship increases

    The first legitimately concerning occasion in my opinion was when a few weeks ago a bunch of subreddits were banned for being too offensive. Previously the website had banned subreddits (rightfully so) that encouraged illegal acts, such as the spread of childpornography and revenge porn.

    But banning subreddits for being offensive is walking on a thin line, bordering on and (perhaps in this case already crossing) censorship. Those who have objected against the bans, regardless of their intentions, have been shadowbanned. Sent to Siberia.

    The community at large previously decided what is offensive by self-moderating. Inappropriate behaviour was banned to some dark subreddits, where offensive people could talk to offensive people and they could just take it out on each other.

    But now the higher command has taken over.

    The 5 subreddits banned are the rather small subreddits /r/fatpeoplehate, /r/hamplanethate /r/transfag /r/shitniggerssay and /r/neofag.

    These bans has proven to be a very arbitrary decision, seemingly based solely on personal dislikes of the CEO. I say this because other Redditors have found hundreds of small subreddits with a equally offensive message who were not banned. Among those:

    /r/BeatingTrannies/r/RapingWomen/r/PhilosophyOfRape/r/StruggleFucking/r/AbusePorn2,
    /r/AntiPOZi/r/SlutJustice/r/CoonTown/r/CuteFemaleCorpses/r/SexWithDogs/r/SexWithHorses,
    /r/CandidFashionPolice/r/GreatApes/r/NecroPorn/r/DeepThroatTears/r/Painal ,…

    You can imagine the kind of content going around in those subreddits…
    Such a decision to ban was like chopping off the hydra’s head; if you ban those 5, then there are many, many more that should also be banned.
    Now that pandora’s box is opened, they can’t close it anymore. To avoid hypocrisy, they should ban every other subreddit that is offensive (who will decide on this?) and not banning one would implicitely say that those subreddits are “alright” since they have the power to ban, but don’t.

    Other than it being a hypocrite decision, the bans seem bad for the community as a whole. Those subreddits serve as containment. Banning the sub wouldn’t get rid of the idea…it just removes the container as another redditor illustrated.

    ZQHN2gS

    Maybe the really shitty individuals who are genuinely upset that such content disappeared will now leave Reddit. But most will probably just stay and spew their hate on subreddits which were healthy.

    (addendum: a study performed 2 years after this ban showed that many former members of /r/fatpeoplehate and /r/coontown either left Reddit indeed, but many of those who stayed also slowed down significantly on their hatespeech. the subreddits that the former members migrated to did not receive much more hatespeech. In other words: Science proved me wrong!)

    It’s an tough question whether Reddit should offer a forum for shitty people. It’s kind of the same question whether we should try to rehabilitate paedophiles into society. In any healthy society you will have rotten apples. But with this decision Reddit HQ decided it does not want to reflect a real society, which deeply saddens me.

    (addendum: I no longer stand behind this flawed analogy. Studies have shown that paedophilia is a sexual preference that cannot be cured, we can only refrain pedophiles from acting upon their sexual desires. Hatred CAN be cured and should not be condoned because “it reflects society”)

    Corporate interests crushing a community

    It’s maybe insensitive to the people who feel offended by such hateful subreddits, and maybe it’s dramatic for a community to react to a website that is changing a few things, but really think of this community as an actual country, population: 36 million accounts. They don’t just see this as a website changing its policy, they see it as their internet-country shifting political direction.

    A lot of money circulates in this website thanks to this community. In the end this decision to monitor the content is there for the advertisers. It’s a corporate decision, not a social decision. Such bans will make marketeers less ashamed to be advertising on a website when hateful subreddits are deleted. Decisions made for money will always break the social bonds and are inevitably hurting the community.

    (addendum: now that I’ve come to agree that these were good decisions, I see how commercial interests are powerful incentives to intervene in a community when the community itself is not able to see its systemic errors that produce toxicity)

    The decision to fire Victoria might have been a corporate decision as well. Maybe she wasn’t complying with new guidelines the company was giving? Maybe they wanted her not to let the celebrities reply to hard-hitting questions?

    Civil Disobedience

    It is interesting to see how the community is really fighting this change. The idea to turn off the lights on the big subreddits is a striking example of civil protest against political leaders, comparable to a public service strike. They’re hitting the administration where it hurts the most: slowing down traffic and inevitably making them lose money.

    What direction the administration will go with this situation is open for debate. Likely they’ll take over control from the moderators (who are not paid, and are just simple redditors) and make sure none of the big subreddits can’t go dark anymore. To appease people, maybe they’ll restore Victoria, or replace her with someone who does the job just as well, and we’ll all “forget” this ever happened. But the scene has been set and Reddit no longer belongs to the community, so it seems.

    Some redditors feel like they’ve landed in a real dictatorship, fleeing the website as if they became refugees. They feel like political prisoners for being silenced and shadowbanned when uttering critique. Those in the leadership that disagree are exiled, or fired in this case.

    Most redditors are accepting these decisions, muttering under their breath and just telling themselves that at least a lot of the daily life is still the same, where there are still funny cat pictures and interesting factoids…


  • How the Sony hacks made the US go into a cyber war frenzy

    How the Sony hacks made the US go into a cyber war frenzy

    How the Sony hacks made the US go into a cyber war frenzy

    Is this really how we’ll deal with cyberattacks in the future?

     (this article was previously published in Dutch on Datanews)

    Whether the Interview is a good movie or not is debatable, but we can all agree that it has caused a lot of commotion. Not only did it enjoy the weirdest marketing campaign in movie history and caused a diplomatic riot, it also set some special precedents, making many think the Cyberwar has commenced.

     635532898706495971-The-INterview-poster

     The events unfolding in the past few months could have been a movie on its own. Two comics make a silly movie about assassinating the current North-Korean dictator. The actual North-Korean leader is offended. Coincidentally the film production house is met with a heavy cyber attack destroying their entire systems. Theatres are threatened to “not forget” 9/11 in case they would play the movie. The theatres and production companies cowardly withdraw, which is met with a public outcry, and the film is released anyway with alternative means. The FBI is quick to point the finger to North-Korea, sanctions the country, while the North-Korean internet ‘coincidentally’ also goes offline. Obama is called a monkey, and in between people start remembering both country also have nuclear weapons.

    We’ll have to wait for the DVD-release and the next Wikileaks to see the behind-the-scenes footage, but for now it has all been very amusing.

    While the dust is settling, it’s interesting to have a closer look at what the Interview and the ‘Sony Hack’ has set in motion.

    Playing the blame game with North-Korea

    In the entire analysis of the Sony Hack, the diplomatic aspect is the most striking.

    Already after a few days the FBI concluded the cyberattack and the threats made could be attributed to North-Korea, based on flimsy evidence.
    A lot of doubt has been cast on this attribution by several experts.

    While the FBI refuses to admit how exactly the trail of its investigation leads to North-Korea, most of the evidence it gives or would credibly be able to give, is indirect circumstantial evidence according to experts.

    While one would hope the US wouldn’t make such harsh accusations without a solid backing, we mustn’t forget the assumed Weapons of Mass Destruction in Iraq. Back then the US was also very sure of what later proved to be false accusations.

    North-Korea denied the responsibility for the attack, but the New York Times saw a half confession in North-Korea’s statement that the attacks were ‘righteous deed of supporters and sympathizers’.

    2540609

    Was North-Korea aware these attacks were being launched? And is a country also responsible when it sees evil being done and doesn’t try to stop it?

    The US turned down North-Korea’s offer to launch a joint investigation, and went in the offence. The 2nd of January it raised sanctions on the most heavily sanctioned country in the world. This was a world first, effectively being the first time the US punished a country for a cyber attack on an American company.

    Very ‘coincidentally’ the North-Korean internet also went offline.
    The US denied any role, although fingers can also be pointed to a country with suspicious motives. Such actions would be giving North-Korea just as much right to strike back covertly.

    North-Korea currently only responded furiously, with press releases like “U.S. Urged to Honestly Apologize to Mankind for Its Evil Doing before Groundlessly Pulling up Others”.

    Whether the US has proof or not, according to Allan Friedman, researcher at the George Washington University’s Cyber Security Policy Research Institute, it is a smart diplomatic strategy to be overconfident in assigning blame for the cyber attacks. To prevent precedents from being made, it’s best to discourage other states from engaging in similar behaviour by punishing North-Korea, even when lacking concrete proof.

    Is this the beginning of a Cyber War?

    A lot of talk in popular media mentions cyberwar when referring to the Sony hacks, but was the crippling of a company really an act of war?

    This lack of certainty on attribution is already vital to define this attack as an act of war. It is almost impossible to speak of a cyberwar in such a covert domain since wars are traditionally only fought between nations.

    But let’s assume for the sake of the argument the FBI is right and North-Korea was behind the hacks.

    When treating the term ‘war’ literally, we have to look at whether this was a use of force, as described in the United Nations Charter. It’s forbidden to use force, unless when used in self-defense, or when permitted through a UN Security Council resolution. If you don’t have that justification, you might have started a war.

    Based on a lot of discussions and precedents, it has sort or less been agreed what such a forbidden use of force can be; inflicting harm with such a scope, duration and intensity that it threatens the territorial integrity or political independence of a state.
    So when a lot of people die, and the national security is threatened, it’s a use of force. Makes you think twice about the impact of crippling a company that, according to Dr. Evil in Saturday Night Live ‘hasn’t been relevant since the Walkman’.

    giphy

    But even here, when it comes to war, the cyber domain is a grey zone. A difficult domain where no clear lines can be drawn about what is enough ‘damage’ to regard something an act of war. There’s no international legislation, there are no precedents and thus there are no norms telling us when we feel enough damage is done for something to be classified a use of force.
    Something Pentagon Press Secretary Rear Adm. John Kirby also repeated, with the plea to urgently set up international rules.

    A lack of such international legislation and precedents also means a country can attack another, and a country like the US can reply at will. Its permissibility depends on whether the international community condemns such actions or not, shaping the norms as a consequence.

    But it would also mean this would be where the line is drawn for future reference. The US knows better not to turn these hacks into the great ‘cyber Pearl Harbour’. As cyberwar expert Peter Singer said on the Motherboard, ‘we’re not going to war with North-Korea because Angelina Jolie is angry at some Sony Executive’.

    At the same time the US is taking the matter very seriously, treating the hack on American soil as a matter of national interest.

    Especially after threats were also made.

    Cyberterrorisme?

    threat sony

    “The World will be full of fear. Remember the 11th of September 2001. We recommend you to keep yourself distant from the places [where the movie is shown] at that time.”

    The threats made by the hackerscollective responsible for the Sony Hacks apparently left a great impression that made many speak of ‘Cyberterrorism’.

    The term terrorism is used frequent to describe any threat without a clear state actor, solving the attribution conundrum. The concept of the ‘war on terror’ is still a controversial way to circumvent the traditional paradigm of “wars are only fought between nations”. The reminder of the US’ collective trauma made the nation immediately up in arms.

    Sony added fuel to the fire by caving, and allowing the film to be withdrawn from 180.000 theatres. Allowing fear to rule and complying with threats is how to ‘let the terrorists win’. As Peter Singer also said, the way Sony handled the entire ordeal has turned into a case study on how NOT to respond to terrorist threats. Especially when these hackers have not shown any capability to carry out anything remotely physically damaging.

    Such scaremongering comes with ignorance on what damage cyber attacks can actually cause.

    Did Sony have the right to panic?

    Coming back to the use of force, there has thus far not been an overt cyber attack that could be classified as an act of war, even though the possibility exists. With the Aurora Project the US even proved how much physical damage a cyber attack can cause.

    The damage done to Sony was nowhere near comparable to such physical damage.

    100 Terabyte worth of data was stolen, as well as ‘wiper malware’ was used. This type of malware destroyed Sony’s internal systems (from production planning to human resources). This meant the company has to replace all their systems, paralyzing it for a while.

    But this type of malware was also used in the South-Korean DarkSeoul case attacking banks, and the Saoudi Aramco case attacking the oil company. Lack of international regulations made these cases also hard to classify and respond to. But while they also caused a lot of commotion, they were not considered an act of war or terrorism, nor did it result in a witch hunt.

    Important to remember is Sony also has a history of leaks and security breaches. The Playstation hack of 2011 is still fresh, where 2,2 million credit card details were stolen through the Playstation network.
    Yet Sony hit the panic button this time, when critical company details were compromised. The perceived gravitas was beneficial for Sony, where the attack seemed so sophisticated they would not have been able to prevent it. The idea of being ‘hacked by a dictator’ added to their benefit, where they could claim ‘circumstances beyond their control’ when they would be put on trial.

    2701897

    It is no secret though that Sony’s security prescriptions were flawed, with the leaks even showing one of the CEO’s having an embarrassingly simple password. The panic ruled in their favour.
    Bruce Schneier concludes that Sony wasn’t afraid of the damage the hackers would do in a terrorist attack, but feared for the commercial damage to the company.

    The leaked information is probably being sold to the highest bidder by now.

    Such a perspective makes one think about the role North-Korea played in all of this. Did they really cripple a multibillion dollar company as a sadistic move because their Supreme Leader was insulted by a movie?

    It is scary not to be able to tell whether an attack came from a small group of criminals playing a mean prank by releasing a threat, or an entire country. It’s causing big countries like the US to lose their cool.

    Not only was the damage not that significant, was the target no matter of national security, 
    but harsh accusations were made and sanctions were lifted against a country based on very flimsy evidence.

    A long term vision is necessary to protect against cyber attacks towards the future. Especially now that the Aurora target list of American critical infrastructure was leaked.

    It is highly doubtful though whether flexing some muscles and scaremongering will help to win a ‘war’ against anonymous hackers.

    Biggest digital release ever

    The conspiracy theorist would expose this entire debacle as an amazing marketing campaign for a movie.

    Sow fear, boost patriotism, create a Barbara Streisand effect where people want to see this hyped movie. Release the movie and have everyone watch it as their personal act of rebellion. ‘That’s my kind of war on terror’ was tweeted by those proudly watching the movie.

    13-intervew-afp-2

    Causing a diplomatic riot to promote a film, nothing is surprising anymore in this day and age. And whether it was deliberate or not, the film can also claim the record of the biggest digital release ever. With 15 million dollars income in the first 4 days, the movie finally catapulted the movie industry in the digital age.

    The transition from 2014 to 2015 was one of many interesting phenomena. The biggest hack on American soil, fear of cyberwar and cyberterrorism, a diplomatic riot between two nuclear countries, the biggest online movie release,… All centred around one movie: The Interview. The film is definitely one for the history books, although probably not for its content.


  • There are no girls on the internet.


    Vrouw zijn op zich is geen sinecure. Maar vrouw zijn op het internet is een zeer zware identiteit om te dragen.
    Het is best mogelijk dat de volgende feministische golf zich online zal voordoen. En dan heb ik het niet over propaganda verspreiden via het medium ‘internet’ in plaats van met borden de straat op te kruipen. Neen, ik heb het wel degelijk over de online identiteit van vrouwen.
    Want momenteel staat deze identiteit nog steeds in een korset, onder een boerka. 
    Het gaat me hier dan vooral over hoe je als vrouw in de internetgemeenschap staat. En dan gaat het niet zozeer over de veilige sociale netwerken à la facebook en twitter, waar je alleen omgaat met wie je kiest en waar meer fatsoen uit het dagelijks leven heerst, maar over de internetwereld met voornamelijk onbekenden waar de wet van de sterkste heerst, de digitale far west.
    De troef van het internet is de grote anonimiteit, waarin gender natuurlijk ook anoniem is. Dit zou nog geen slechte zaak zijn, als ‘anoniem’ niet voor het internet de facto gelijk staat aan ‘man’.
    Die internetgemeenschap is vooral het meest actief via internetfora. Er zijn er veel, maar hier heb ik het vooral over een van de grootste de publieke fora, namelijk reddit, een website die zichzelf zonder enige schroom the frontpage of the internet durft noemen. Daar meet men zich een gebruikersnaam aan waar men volledig anoniem mee is, maar kan men ook kiezen zijn of haar gender  in de gebruikersnaam kenbaar te maken.
    Nog anoniemer kan ook, bijvoorbeeld op fora als 4chan. Hier is geen enkele identificatie voor nodig, en krijgt iedereen de naam anonymous. Voor wie niet bekend is met 4chan en hun populairste imageboard /b/, het wordt algemeen ook wel omschreven als ‘the asshole of the internet’omwille van zijn controversiële inhoud en gebruikers. Veel internetcultuur en populaire memes zijn ontstaan op voorgenoemd forum, maar ook veel hackersbewegingen zijn uit 4chan gegroeid.
    Zowel op reddit als op 4chan moet je je dus expliciet als vrouw onthullen om niet als man aangesproken te worden, de de facto identiteit. 4chan is hier nog wat extremer in, en deze gaan er zelfs volledig van uit dat het niet mogelijk is dat je vrouw bent. Dit is terug te vinden in ‘rule 37: there are no girls on the internet’. (4chan heeft zelfverklaarde regels van het internet uitgevonden, een hoop slogans die herhaaldelijk terugkwamen op hun forum.)
    Probeert men op 4chan toch kenbaar te maken dat men vrouw is, en een ‘Tits or GTFO’ staat je vrij zeker te wachten, of een opmerking over de keuken, en sandwichen die gemaakt moeten worden voor mannen. Niet alleen wordt er niet geluisterd naar wat je te zeggen hebt, je bent nota bena niet welkom op dit blijkbaar-toch-niet-zo-vrije-internet.
    Op Reddit is men wat minder paranoia, maar is seksisme en misogynie ook schering en inslag. Vrouwen met een duidelijk vrouwelijke gebruikersnaam worden vaak naar de keuken verwezen als ze in een discussie participeren, of krijgen heel casual scheldwoorden en de suggestie van verkrachting naar hun hoofd geslingerd, gewoon omdat ze vrouw zijn.
    Vandaar dat veel vrouwen met een constante knagende gevoel zitten over de vraag “maak ik me kenbaar als vrouw of niet?” wanneer ze anoniem browsen.
    Doen ze het niet, dan worden ze automatisch bestempeld en behandeld als een man en wordt er naar haar verwezen met ‘hem’ of ‘hij’.
    Sommigen hebben dit aanvaard, en laten het er maar bij, met de gedachte dat men tenminste wel zal luisteren naar wat er gezegd wordt als ze de moeite niet neemt te specificeren dat men met een vrouw te maken heeft.
    Komt ze er specifiek voor uit, dan is men een aandachtzoekende, feministische dolle mina, op pad om het mannengeslacht uit te roeien (of zo wordt ze toch vaak gepercipieerd) en wordt ze volledig anders behandeld dan wanneer ze genderloos/mannelijk was.
    Het anonimiteitsvraagstuk is maar 1 probleem van het seksisme. Mensen posten op Reddit ook vaak foto’s van eigen creaties waar ze soms zelf bijstaan. Het is zeer frappant hoeveel commentaar deze genereren die niet gerelateerd zijn aan de creatie als ze door een vrouw gepost worden. Aandachtshoer en andere scheldwoorden zijn zaken die snel naar het hoofd worden gegooid,  en als vrouw is de aarzeling ook veel groter om iets te posten waarbij zijzelf in beeld moeten komen.
    Het is momenteel oproer als vrouwen dingen nageroepen worden op straat, maar vrouwen moeten niet zaniken als ze seksueel geïntimideerd worden op het internet.
    Mini-revoluties zijn wel aan de gang,
    Vrouwen die hun plekje in internetcultuur opeisen door memes te maken die specifiek op hen toepasbaar zijn. Zo is foul bachelorette frog de vrouwelijke variant van foul bachelor frog, die de vieze bekentenissen van single vrouwen even eerlijk typeert als de mannelijke variant.


    Ook op de fora laten vrouwen zich niet doen, en zijn er alsmaar meer vrouwen die mannen corrigeren als ze per ongeluk naar hen verwijzen met ‘hij’ of ‘hem’.
    Een actie die zo onbenullig lijkt en toch veel zwaarder is dan ze zou moeten zijn.
    Een kleine opstanding is aan de gang met vrouwen die willen aantonen hoe patriarchaal de internetsamenleving is door automatisch van “zij” of “haar”te spreken, in plaats van het standaard “hij” en “hem”. Opspraak en verontwaardiging onder de mannelijke internetgebruikers blijkt hier nog heel vaak. “Hoe durven ze te veronderstellen dat ik een vrouw ben? De schande!” maar het is een manier van sensibilisering om mannen er te doen bij stilstaan dat vrouwen net zozeer aanwezig zijn, en er evenveel kans is dat hij een zij zou kunnen zijn.
    Het valt dus op dat alsmaar meer vrouwen terugbijten, maar ook alsmaar vaker zijn er  mannen die hen verdedigen. Die mannen krijgen vaak wel de smalende term white knights toegeschreven, en worden ook beschuldigd andere motieven te hebben dan gewoon het fatsoen te behouden.
    Maar nu reddit de laatste tijd ontzettend hard is aan het groeien, wordt zijn gemeenschap hoe langer hoe meer een afspiegeling van de samenleving.
    Vergeleken met de beginjaren, en vergeleken met 4chan, is reddit, hoe misogyn het momenteel nog steeds is, meer geëvolueerd en gediversifieerder geworden. Het zou kunnen uitdraaien op een mooi voorbeeld van hoe een community anoniem kan blijven en toch een zekere mate van zelfcontrole binnen de gemeenschap kan installeren zonder dat die van buitenaf moet afgedwongen. Door het systeem waarbij gebruikers commentaren kunnen upvotes en downvotes geven, wordt niet toelaatbaar gedrag afgestraft door karma weg te nemen (karma is de virtuele munteenheid van Reddit). Er worden veel seksistische dingen gezegd, maar wat velen niet zien is dat er ook hoe langer hoe meer tegenwind tegen komt.
    Niettegenstaande is er nog een lange weg te gaan. Het internet kan een onvriendelijke, koude, chaotische plek zijn voor zowel mannen als voor vrouwen, maar enkel en alleen vrouw zijn is op het internet genoeg om uitgescholden te worden en niet gerespecteerd te worden.
    Daarom blijven vrouwen veelal stil, vallen veel vrouwen terug op de anonimiteit en de assumptie dat ze man zijn, of kruipen ze naar veilige plekken op het internet die specifiek voor en door vrouwen zijn gemaakt. En dat hoort niet. We zouden ons niet alleen veilig mogen voelen op fora over nagellakken en dieeten, ook vrouwen hebben humor en kunnen ook lachen met politiek incorrecte dingen.
    Een vrouw zou moeten kunnen gaan en staan waar ze wilt, en tonen dat ze vrouw is als ze dat wil zonder anders behandeld te worden.

  • Cyberinterventie in Syrië, een potentieel gevaarlijk precedent

    (voorheen verschenen in Mo*)

    Sinds enkele dagen woedt er een grotendeels geheime discussie in de Amerikaanse veiligheidsraad om Amerika’s cyberwapens in te zetten in de burgeroorlog in Syrië. Er gaan in de VS al langer stemmen op voor een humanitaire interventie in Syrië, en toen er chemische wapens gebruikt werden tegen de bevolking, stond de VS op voet van oorlog. Maar de vrees om opgeslokt te worden door alweer een oorlog, of om het leven van Amerikaanse soldaten weer op het spel te zetten overheerste tot dusver het debat. De mogelijkheid om aanvallen uit te voeren via cyberspace, waar er geen “boots on the ground” nodig zijn is daarom zeer aanlokkelijk, en het debat verdient zeker meer aandacht.

    Dat de VS sinds enkele jaren een serieuze investering in zijn offensief cyberpotentieel maakte is geen groot geheim. Een heus Cyber Command als vierde tak van Amerika’s militaire macht werd enkele jaren geleden al opgericht, en de onthullingen van Edward Snowden hebben aan het licht gebracht welk potentieel dit heeft.

    Met een presidentiele beleidsrichtlijn die toestemming geeft offensieve cyberoperaties uit te voeren uit nationaal belang, zijn er ondertussen minstens 231 offensieve cyberoperaties uitgevoerd, waarvan de meest bekende de worm Stuxnet, die een Iraanse kerncentrifuge uitschakelde. De administratie heeft deze evenwel nooit erkend en de operaties zijn aldus altijd clandestien uitgevoerd.

    De mogelijkheid bestaat om via offensieve cyberoperaties de faciliteiten voor Assad’s luchtaanvallen uit te schakelen, en de raketproductie te hinderen. De efficiëntie van deze operaties om de burgeroorlog te beeindigen is betwistbaar, maar minstens tijdelijk, en mogelijk voor langere tijd zou zulke maatregel burgerlevens redden, zonder een grote kostelijke interventie te moeten maken.

    Legaal?

    Geen grote militaire interventie, geen soldaten in Syrië, niemand die gewond zal raken EN we kunnen burgerlevens redden? Zo snel mogelijk beginnen hacken, niet? Toch zijn er enkele bedenkingen te maken bij zulk een scenario.

    Allereerst is er de onduidelijkheid over de legaliteit. Voorlopig zijn er nog geen internationale richtlijnen of verdragen getekend over wat nu wel en niet mag, en of dit soort cyberaanvallen nu dezelfde status hebben als bijvoorbeeld een raketaanval. Moet er effectief schade zijn om een aanval als een vijandige, ongelegitimeerde inmenging te zien? En wat als de systemen nu enkel tijdelijk uitgeschakeld worden maar niet onherroepelijk beschadigd zijn? En geldt dit niet als een soort van territoriale inmenging? Wie beheerst cyberspace?

    Moeilijke vragen die voorlopig enkel vaag beantwoord kunnen worden, gebaseerd op interpretaties van het internationaal recht. Omdat het cyberdomein een volledig nieuwe dimensie is, kan het gezien worden als een soort van Far West, waar er nog geen echte regels zijn opgelegd. In dit geval is het een soort van trial en error, waar landen het veld aftasten. Wat aanvaardbaar is of niet hangt dan of van hoe hoe hun acties veroordeeld of toegejuicht worden.

    Precedent

    Het gevaar ligt hierin dat als een cyberinterventie van de VS geduld wordt, het als een precedent gezien kan worden. Andere landen zouden zo hun eigen offensieve cyberoperaties kunnen legitimeren wanneer zij andere landen terecht of onterecht aanvallen en hun cyberinfrastructuur platleggen. Of de VS kan deze ‘goede’ actie gebruiken om zijn cyberindringingen in de rest van de wereld te rechtvaardigen.

    Omdat dit soort aanvallen in een grijze zone ligt van het internationale recht is het ook maar de vraag of de VS eigenlijk toestemming nodig zou hebben van de VN-Veiligheidsraad.

    Normaal gezien kan een land slechts force uitoefenen uit zelfverdediging, of met de goedkeuring van de VN-Veiligheidsraad, bijvoorbeeld in het geval van een humanitaire interventie. Aangezien het niet duidelijk is of een cyberaanval nu use of force is en er veel discussie onder academici is over dit onderwerp, zou de VS in principe niet op goedkeuring moeten wachten.

    Dit zou evenwel politiek geen verstandige keuze zijn door te intervenieren op een geniepige manier, en waarschijnlijk op een zware veroordeling van Syrië’s bondgenoten onthaald worden, alsook de landen die van het oordeel zijn dat een cyberaanval onwettig is.

    Het regime van Assad heeft zelf ook zijn eigen cyberafdeling, het beruchte Electric Frontier Foundation, en heeft bondgenoten als Rusland die zelf niet vies zijn van een portie hacking en cyberaanvallen. Er is het gezegde ‘Wie in een glazen huis woont gooit niet met stenen’. Wanneer de VS het offensief zou inzetten via cyber, mag het niet vergeten dat zijn hoogtechnologische natie zeer afhankelijk is van de informatienetwerken die dan op eenzelfde manier geviseerd zouden kunnen worden.

    Maar zelfs als de VS zou wachten op een resolutie van de veiligheidsraad om de internationale gemeenschap aan boord te krijgen om cyberaanvallen uit te voeren, is het nog maar de vraag of die er ooit zouden komen. Het voorstel zou een debat in de VN-Veiligheidsraad doen losbarsten dat veel verder gaat dan Syrië alleen en vast zou blijven steken op wat nu wettelijk is in het cyberdomein.

    Verder is het ook maar de vraag of het de mogelijke gevolgen allemaal wel waard is voor de VS.

    Nog niet klaar

    Tot dusver heeft de internationale gemeenschap zich redelijk afzijdig gehouden in de verscheurende burgeroorlog die gaande is in Syrië. Waar de VS op het punt stond luchtaanvallen in te zetten, besloot het toch te wachten op de goedkeuring van de internationale gemeenschap, die niet kwam. Aangezien de VS niets verloren heeft in Syrië, en enkel uit “humanitaire” overwegingen zou interveniëren, heeft het geen baat bij een unilaterale beslissing openlijk een cyberoffensief in te zetten.

    Waar het een innovatieve manier zou zijn om via een cyberaanval humanitair tussen te komen, is de wereld er momenteel nog niet klaar voor en schept het gevaarlijke precedenten aanezien er geen regulering bestaat.

    Ondertussen blijft Syrië wel branden.


  • Snowden leaks: de VS’s geheime Offensive Cyber Effect Operations

    Snowden leaks: de VS’s geheime Offensive Cyber Effect Operations

    Moord en brand werd er de voorbije weken wereldwijd geschreeuwd over onze privacy. De recentste onthullingen van het Cyber Command van de VS, onder leiding van de National Security Agency (NSA), laten dan ook een wrange smaak na over wat er allemaal te grijpen valt online.

    Dit waren zaken die we al in 2001 na 9/11 te weten waren gekomen, maar waar de wereld geen graten in zag door de verblindende horror van 9/11. In 2006 kwam het nogmaals bovendrijven dat de NSA ieders telefoon aan het afluisteren was en kopieën van andere communicatievormen bezat.

    Maar ondanks een kleine oproer bleef men KGB en Stasi-gewijs gewoon voortluisteren. Ergens is de huidige verontwaardiging verrassender dan het feit dat de NSA toegang heeft tot AL onze communicatie. De rechten van alle wereldburgers zijn immers ondertussen al meermaals geschonden in de naam van veiligheid. Maar goed, beter laat dan nooit zeker?

    Een iets frappanter gegeven dat veel minder aandacht kreeg sinds Edward Snowden naar buiten kwam met zijn vertrouwelijke informatie, waren de hoogst confidentiële paragrafen over de VS’s OCEO, Offensive Cyber Effect Operations. De naam zegt het zelf; een departement waar men cyberoffensieven uitvoert of is aan het voorbereiden. (gelekte beleidslijn te vinden op https://epic.org/privacy/cybersecurity/presidential-directives/presidential-policy-directive-20.pdf )

    De OCEO heeft een target list van infrastructuur die essentieel is voor bepaalde staten. De taak van deze afdeling is om de zwaktes van deze infrastructuur te ontdekken en deze allemaal binnen te dringen en al te infecteren, zodat men koude-oorlog gewijs slechts op 1 knopje moet drukken om de cyberaanval te lanceren.

    Dit soort penetraties kan toch niet legaal zijn?

    Alweer duikt de VS in het grijze gebied waar de wet ambigue is over wat mag en niet mag. En dat komt hen maar al te best uit, want waar er geen wet is, kan de VS de bestaande wetgeving op maat laten aanpassen naar hun noden en wensen, en er een wettelijke logica aan verbinden. Want ook al zijn er geen interstatelijke verdragen over wat wel en niet mag in cyberspace als het op aanvallen aankomt, de logica van conventionele oorlogen wordt hiervoor gebruikt. Alleen zit men met enkele lacunes waar de conventionele wetgeving geen antwoord op heeft. Een cyberaanval die economische schade aanricht, mag je daar defensief op reageren? En mag je zodanig preventief handelen uit zelfverdediging dat je de vijand’s infrastructuur al besmet en binnendringt, maar er niets mee doet tenzij er een dreiging komt?

    De schade die zulke cyber aanvallen kunnen aanrichten valt trouwens niet te onderschatten. Aangezien we tegenwoordig in wat in het jargon the internet of things leven, waarbij alles verbonden is aan een bepaald netwerk, is alles ook ontzettend fragiel en penetreerbaar. Zo’n cyberaanval gaat dus niet om het platleggen van enkele websites en servers, maar effectief beschadigen van materiaal. Doordat bijna alles tegenwoordig aangesloten is op IDS’en (Industrial Control Systems)  kunnen die systemen gehackt en overgenomen worden.

    IDS’en (ook gekend als SCADA-systemen) zijn netwerken van infrastructuur die het gemakkelijker en overzichtelijker maken om een systeem van op afstand te besturen. Dit kan gaan van de straat- en verkeerslichten, tot de controle over een hele dam en het besturen van geplaatste pacemakers bij patiënten. Het lijken sci-fi doemscenario’s maar niets is minder waar. In 2010 kwam bovendrijven dat een reactor in het Iraanse nucleaire kernprogramma zwaar beschadigd was door een cyberaanval. De cyberworm Stuxnet was al maanden geleden het systeem binnengedrongen en zat daar te wachten tot de beslissing genomen werd actie te ondernemen. Nadat Iran de VN-resoluties negeerde om zijn kernprogramma stop te zetten, nam men dankzij het geïnfecteerde systeem de controle over de SCADA-systemen over die de centrifuges bedienen. Men bestuurde ze zodanig dat ze zichzelf oververhitten en uiteindelijk kapot draaiden. Het bewijs van een cyberaanval met levensechte schade.

    Al was het lange tijd slechts een vermoeden dat de VS en Israel achter de aanval zaten, werd het bevestigd door de recente lekken dat de VS achter de aanval zat. Een onheilspellende voorbode van wat de rest van de wereld wacht die niet wil luisteren naar Uncle Sam.

    de Offensive Cyber Effects Operations kunnen gezien worden als een voorbereiding om snel te reageren wanneer ze in een conflict terecht komen, en mogelijk een de-escalatie voorkomen door de digitale systemen plat te leggen.

    Wie in een glazen huis woont, gooit beter geen stenen.

    De VS gelooft dat het handelt met de juiste intenties, maar zulke invasie van netwerken kan evengoed gezien worden als een dreiging van de VS uit, die het slagveld gereed maakt om ten oorlog te kunnen trekken. In die hoedanigheid kunnen de eigenaars van de geïnfecteerde netwerken net zo goed hun eigen recht uitvoeren en hetzelfde doen uit zelfverdediging. Deze acties werken alleen maar escalatie in de hand. In plaats van de andere staten op te roepen tot kalmte en reguleren, legitimiseren ze het zulke acties door er zelf aan mee te doen.

    Bij gebrek aan internationale verdragen, of een gewoonterecht dat dit soort bewegingen controleert, verkent de VS de grenzen van wat acceptabel lijkt, en heeft al nieuwe rechtvaardigingen in de maak waarom zij het recht hebben zodanig preventieve maatregelen te kunnen nemen.

    Er wordt wel eens langs de neus weg gezegd dat het niet erg zou zijn als er een cyber Pearl Harbour zou gebeuren, of een cyber 9/11, gewoon maar om de regels te kunnen vastleggen omdat het dan duidelijk zou zijn dat er een echte dreiging is die tegengehouden moet worden. Maar zolang die er niet komt blijft het bij verkennen en op gereed staan.

    De militarisering van cyberspace is geen al te best vooruitzicht, en men kan zich afvragen of we echt nog een koude oorlog nodig hebben, maar dan in cyber space.