/ / News


OpenSSL maintainer and Google cryptographer Ben Laurie and I collaborated on an article for Nature magazine on technical systems for finding untrustworthy Certificate Authorities. We focused on Certificate Transparency, the solution that will shortly be integrated into Chrome, and also discuss Sovereign Keys, a related proposal from the Electronic Frontier Foundation. Both make clever use of cryptographic hashes, arranged in Merkle trees, to produce “untrusted, provable logs.”

In 2011, a fake Adobe Flash updater was discovered on the Internet. To any user it looked authentic. The software’s crypto­graphic certificates, which securely verify
the authenticity and integrity of Internet connections, bore an authorized signature. Internet users who thought they were applying a legitimate patch unwittingly turned their computers into spies. An unknown master had access to all of their data. The keys used to sign the certificates had been stolen from a ‘certificate authority’ (CA), a trusted body (in this case, the Malaysian Agricultural Research and Development Institute) whose encrypted signature on a website or piece of software tells a browser program that the destination is bona fide. Until the breach was found and the certificate revoked, the keys could be used to impersonate virtually any site on the Internet.

Secure the Internet (PDF)

/ / Pirate Cinema

I did an interview with The Geek’s Guide to the Galaxy, which they’ve published in both text and MP3 form. We talked about Pirate Cinema, Rapture of the Nerds, the Humble Ebook Bundle, the future of publishing, the Disney/Star Wars merger, and lots more:


Wired: Do you ever get letters from kids who have been inspired by your books to become hacker anarchists?

Doctorow: Yeah, all the time — at least to become hackers, and political activists. My first young-adult novel Little Brother had an afterword with a bibliography for kids who want to get involved in learning how security works, learning how computers work, learning how to program them, learning how to take them apart, learning how to solve their problems with technology as well as with politics. And the number of kids who have written to me and said that they became programmers after reading that, I couldn’t even count them. I’ve had similar responses to my second young-adult novel, For the Win, and I’ve also heard from kids who’ve read Pirate Cinema. In fact, we published an editorial by one of them on Boing Boing — an anonymous reader who makes her own movies out of Japanese anime, and who talked about what drives her and how the book resonated with her.


With Pirate Cinema, Cory Doctorow Grows His Young Hacker Army

/ / News, Podcast

Here’s a recording of a debate I participated in on Monday at Denmark’s Fagfestival (yes, really — Danish has weird English cognates) 2012, the largest gathering of journalists in the country. I debated Peter Schønning, a prominent Danish copyright lawyer, in an event hosted by Henrik Føhns.

MP3 link

/ / Articles, Podcast

I did an interview with The Geek’s Guide to the Galaxy, which they’ve published in both text and MP3 form. We talked about Pirate Cinema, Rapture of the Nerds, the Humble Ebook Bundle, the future of publishing, the Disney/Star Wars merger, and lots more:


Wired: Do you ever get letters from kids who have been inspired by your books to become hacker anarchists?

Doctorow: Yeah, all the time — at least to become hackers, and political activists. My first young-adult novel Little Brother had an afterword with a bibliography for kids who want to get involved in learning how security works, learning how computers work, learning how to program them, learning how to take them apart, learning how to solve their problems with technology as well as with politics. And the number of kids who have written to me and said that they became programmers after reading that, I couldn’t even count them. I’ve had similar responses to my second young-adult novel, For the Win, and I’ve also heard from kids who’ve read Pirate Cinema. In fact, we published an editorial by one of them on Boing Boing — an anonymous reader who makes her own movies out of Japanese anime, and who talked about what drives her and how the book resonated with her.


With Pirate Cinema, Cory Doctorow Grows His Young Hacker Army

/ / News

My latest Guardian column is “There’s no way to stop children viewing porn in Starbucks,” a postmortem analysis of the terrible debate in the Lords last week over a proposed mandatory opt-out pornography censorship system for the UK’s Internet service providers.

In order to filter out adult content on the internet, a company has to either look at all the pages on the internet and find the bad ones, or write a piece of software that can examine a page on the wire and decide, algorithmically, whether it is inappropriate for children.

Neither of these strategies are even remotely feasible. To filter content automatically and accurately would require software capable of making human judgments – working artificial intelligence, the province of science fiction.

As for human filtering: there simply aren’t enough people of sound judgment in all the world to examine all the web pages that have been created and continue to be created around the clock, and determine whether they are good pages or bad pages. Even if you could marshal such a vast army of censors, they would have to attain an inhuman degree of precision and accuracy, or would be responsible for a system of censorship on a scale never before seen in the world, because they would be sitting in judgment on a medium whose scale was beyond any in human history.

Think, for a moment, of what it means to have a 99% accuracy rate when it comes to judging a medium that carries billions of publications.

Consider a hypothetical internet of a mere 20bn documents that is comprised one half “adult” content, and one half “child-safe” content. A 1% misclassification rate applied to 20bn documents means 200m documents will be misclassified. That’s 100m legitimate documents that would be blocked by the government because of human error, and 100m adult documents that the filter does not touch and that any schoolkid can find.


There’s no way to stop children viewing porn in Starbucks

/ / News, Podcast

Here’s a podcast of my recent Guardian column, Automated calls, fraud and the banks: a mismatch made in hell:

The banks are now outsourcing their fraud prevention to computers that can make dozens of calls all at once, around the clock, fishing (or phishing) for someone who just happened to have made an unusual purchase and is thus willing to spill all his details down the phone to get it approved. Note that most of the categories of purchase that trigger false positives from fraud detection systems are also the sort of thing that customers are anxious to see go off without a hitch. The unusual and the urgent often travel together.

MoneyBox took up the question of robo-calls on 22 September, with a series of finance industry executives explaining their position on robo-call anti-fraud systems. As Money Box pointed out, customers don’t know what automated fraud prevention calls are supposed to sound like, or which questions are supposed to be asked. They missed that even if this were common knowledge, it would be trivial to make a homemade robo-caller that perfectly mimicked the calls, and set it loose to call around the clock, to many victims at once.

Santander’s statement was that the system allows it to “reach more customers, more quickly, all at the same time”. It didn’t mention that it’s a lot cheaper than paying humans to make those calls, of course. On the other hand, it invited its customers to opt out of the service. But a customer that doesn’t even know the service exists won’t opt out of it – and if a customer’s first experience with a robo-caller is with a fraudulent one, they won’t have had a chance to opt out until it’s too late.

Mastering by John Taylor Williams: wryneckstudio@gmail.com

John Taylor Williams is a audiovisual and multimedia producer based in Washington, DC and the co-host of the Living Proof Brew Cast. Hear him wax poetic over a pint or two of beer by visiting livingproofbrewcast.com. In his free time he makes “Beer Jewelry” and “Odd Musical Furniture.” He often “meditates while reading cookbooks.”

MP3 link