Brainstorm!
Feb. 10th, 2009 08:33 pm![[personal profile]](https://www.dreamwidth.org/img/silk/identity/user.png)
Prompted by a discussion with
bunnykitteh, who's good at prompting these kinds of things:
Imagine a Facebook and/or MySpace application aimed at organising flash mobs for political action (e.g., the kind of thing Anonymous might use to quickly notify members of imminent $cientology activity in a particular location). What features should it have? (Twitter gateway?)
(Note that with Facebook, especially, there are all kinds of interesting concerns with respect to privacy...)
![[livejournal.com profile]](https://www.dreamwidth.org/img/external/lj-userinfo.gif)
Imagine a Facebook and/or MySpace application aimed at organising flash mobs for political action (e.g., the kind of thing Anonymous might use to quickly notify members of imminent $cientology activity in a particular location). What features should it have? (Twitter gateway?)
(Note that with Facebook, especially, there are all kinds of interesting concerns with respect to privacy...)
(no subject)
Date: 2009-02-10 08:44 pm (UTC)I think strong encryption with PGP keys would be more of a necessity!
(no subject)
Date: 2009-02-10 08:50 pm (UTC)Oh, now that's a neat idea -- though, hrm, the first question that pops to mind is how to go about generating keys for folks who don't have 'em and don't know how to do so. Client-side implementation (e.g. in Javascript) that saves the private half of the keypair in a cookie or a text file? What about people who use more than one machine?
I suspect there's some primitive that would be more useful here than PGP proper; perhaps
(no subject)
Date: 2009-02-10 09:13 pm (UTC)What is it that the crypto is supposed to provide?
Depending on the answers you'll want completely different solutions:
- is it keeping eavesdroppers out before the flashmob happens? Short timespan, go for some sort of session key handling and AES or something like that.
- is it keeping eavesdroppers out afterwards as well? This will get tricky, depending on your paranoia levels and the timespans involved.
- is it verifying identities? Now we're talking the entire trustweb infrastructure. And here the Javascript key-generation will not do any good.
(no subject)
Date: 2009-02-10 09:20 pm (UTC)(no subject)
Date: 2009-02-11 12:53 am (UTC)Which, upon reflection, seems to be about 80% social engineering and less network security. The problem is, how do you identify who's a legitimate user?
(no subject)
Date: 2009-02-12 01:16 pm (UTC)Maybe a two layer system where you can consume information with a nominal login if any (keeps you and your devise Anon and not identified for prosecution) and a posting layer with much higher security?
(no subject)
Date: 2009-02-12 03:36 pm (UTC)Also got pointed earlier today at Heydt-Benjamin/Serjantov/Defend, "Nonesuch: a Mix Network with Sender Unobservability", WPES 2006, which I need to read more thoroughly but also looks promising.
(no subject)
Date: 2009-02-11 03:50 am (UTC)(no subject)
Date: 2009-02-11 03:57 am (UTC)Besides - if people are being tortured to divulge their Facebook passwords - what prevents The Authorities to request their secret keys while they're at it?
(no subject)
Date: 2009-02-11 04:09 am (UTC)And I think our coder in question is focused more on American protests where torture is (somewhat?) less of a concern.
I can haz securitee?
(no subject)
Date: 2009-02-11 04:13 am (UTC)(software engineering lesson #1: figure out what the project requirements are first!)
(no subject)
Date: 2009-02-11 04:24 am (UTC)(no subject)
Date: 2009-02-11 04:32 am (UTC)(no subject)
Date: 2009-02-11 04:38 am (UTC)(no subject)
Date: 2009-02-11 12:56 am (UTC)I have no idea how to do that.
(no subject)
Date: 2009-02-11 01:48 am (UTC)(no subject)
Date: 2009-02-11 03:58 am (UTC)(no subject)
Date: 2009-02-11 04:09 am (UTC)(You have an excuse, you're a topologist. I came at security from formal language theory, that's my problem.)
(no subject)
Date: 2009-02-11 04:14 am (UTC)(no subject)
Date: 2009-02-11 04:16 am (UTC)(no subject)
Date: 2009-02-12 12:48 am (UTC)That is: there's a whole thread here which seems to be suggesting that there will be privacy guarantees and possibly identity verification measures...but nothing specific.
(Which is fine, this started out as you asking for possible features; I'm just suggesting that we may want to back up a bit.)
(no subject)
Date: 2009-02-12 12:40 am (UTC)(I'm not being snarky, really. Actually I suspect that once we define "legitimate" we may be most of the way to a solution.)
(no subject)
Date: 2009-02-10 08:59 pm (UTC)(no subject)
Date: 2009-02-10 09:18 pm (UTC)(no subject)
Date: 2009-02-10 09:10 pm (UTC)(no subject)
Date: 2009-02-10 09:28 pm (UTC)How do you want to contact people? Email, SMS, IM, phone, nearby hackable electronic billboard *grin*...the more options you provide the better your coverage. (Some of us use SMS only as a last resort.)
Geo-based filtering might be useful so that a call to arms for a protest in Podunk doesn't annoy the activists in Artemisia.
Give people an easy way to invite others along who haven't signed up for your alerts.
(no subject)
Date: 2009-02-11 04:15 am (UTC)(no subject)
Date: 2009-02-10 10:53 pm (UTC)(no subject)
Date: 2009-02-11 12:55 am (UTC)And each event could be assigned a unique name to use in tagging, so that folks who register their blog with the app get posts tagged with that tag auto-syndicated (perhaps pending mod approval).
(no subject)
Date: 2009-02-11 12:43 am (UTC)I've been kicking around for several years an idea (specific to the Bear community, because of the name) to start a project called "Bearly Involved" that would highlight very easy steps that people could follow to actively do something helpful for the environment. Post one "challenge" each quarter-year, have people write in their accomplishment on the postcard and bring it to a Bear event. The postcards are collected and then a winner is randomly drawn to receive a prize. I think it would be a great way to entice/introduce people to "scary eco-activist" ideas but in a grounded and practical way. I would focus on the plight of the poor polar bear, just to begin, but branch out from there. From barely involved to bearly involved.
(no subject)
Date: 2009-02-11 12:58 am (UTC)(no subject)
Date: 2009-02-11 04:08 am (UTC)