In response to Neo: Free speach, centralized control, and IIP
Hezekiah <[email protected]> Mon, 19 May 2003 23:45:57 -0400
| Newsgroups | gmane.comp.security.invisiblenet.iip.devel |
|---|---|
| Message-ID | <[email protected]> |
Hi, Neo (and everyone else on the list)! :) For the most part I agree with you. I'll go into detail on all the stuff you said below. And for the sake of it: DISCLAIMER: Whatever I say below does NOT necessarily represent the opinion or policy of the IIP development team. This is just me, Hezekiah. On Monday, May 19, 2003 18:37, Neo wrote: > On Friday 16 May 2003 06:32 pm, you wrote: > > However, because of the way (and the reasons for which) IIP is designed, > > I don't really think punitive action should be taken except for in > > extreme cases. (I think there could be a few extreme cases, but most > > would involve situations that could result in physical death in the real > > world.) > > Hezekiah, > > I respect you voicing your opinion. I would like you to clarify some > things, and give some of my opinion. > > You said: > "Because of the way (and the reasons for which) IIP is designed, I don't > really think punitive action should be taken except for in extreme cases" > > This would seem to indicate that the code is being engineered in such a way > so that 'extreme cases' (by "someones" definition") would call for bending > of the algorithms. Regarding the design and coding of IIP, my comment is only relevant for IIP 1.1. Right now there is a centralized server, and if nop knows for some reason that someone's going to die, he has the possible power to do something about it. Please note the word possible: It is not gaurenteed he will. Once we reach IIP 1.2, the question of power in a centralized location and what might happen with that power will no longer be a problem. Rest assured: The code is NOT being engineered to allow a centralized power structure. The idea behind IIP is to create just the opposite. > > Also, who would do the punishing, and what are the rules and punishments > for violating them? The only people capable of removing someone from #anonymous that I know of are nop and mids. As far as I know there are no rules and punishments. By concept, #anonymous is to be completely free. However, as much as we would like it to be so, it won't be _truly_ free until IIP is totally decentralized (i.e. we release IIP 1.2). Realistically there will always be something extreme enough that a human will bend to it's force. Let's be real for a minute and consider an example. Let's say a known terrorist is conspiring with his cohorts load and clear in #anonymous. Then an FBI agent comes knocking on nop's door (with all the correct warrents and legal stuff) and tells him to kick the guy from the channel. Let's face it: As much as nop loves free speech, that guy is going to get kicked. This is what I'm talking about when I say "extreme cases", something that is so bad that it is too much for a human with power to change it to bear. And until IIP 1.2 is released, it will be a reality we all have to deal with. Hopefully, an "extreme case" will never happen. > > IIP is not a jurisdiction, it is a codebase, and while running a > communications network. > > Coders and network/node operators of a system for anonymous / encrypted > speech should never ever get into the debate on issues of content. This is > politics. Once anyone starts talking about limits and punishments, they > immediately set themselves up as a target of control and abuse. I generally agree with you on this. The idea is to create an anonymous network with no control. Then let what happens happen. This way "good" is gaurunteed never to be squelched even though "evil" is gaurunteed the same privilege. > > All of the current wars against free speech are waged on the reason of > 'extreme cases'. Terrorism, kiddie porn, drugs, money laundering, dangerous > political or religious ideas or criticsm. > > If there is any way that *ANY* speech COULD be punished, I said "could" not > should, but could be punished, then there is a serious flaw in the codebase > and architecture. Which there is. We have a central ircd server. The freedom of speech on this network is currently only as good as the people controling it. (And don't worry. I'm not one of them. ;-) ) As I said before (and will say again many times), this is problem will be solved in IIP 1.2. > > The IIP system needs to be on the level of pure 'CARRIER' status. It cannot > be responsible for its users actions. The moment IIP starts taking > responsibility to 'police' the system, is the end of IIP. The code must > make it impossible to police the network. See comment in the paragraph above. > > Lets touch on abuse of the network. Flooding for example, or DOS attacks on > the network. If this is a problem, it is not a problem with any law or need > to take punitive action. This means there are serious architecture > shortcomings and issues with the system. Politics, lawyer speak, > punishments etc, are silly and will never solve the issue. > > The issue of flooding, DOS attacks, massive channel SPAM etc are not legal > issues. They are a pure and simple engineering problem. Pure engineering. I'm right with ya', brotha! :) ... and might I add that we [the developers] have been actively discussing methods to fix the flooding problem with Trent. (Just so no one thinks we're sitting on our hands.) > > Some of the core of the issue has been called for centuries the 'tragedy of > the commons'. This may always be an issue, as long as public 'commons' > channels like '#anonymous' give free reign to any and everyone. You're probably right. I doubt this will be the last time someone makes a big mess in #anonymous. (But at least this time the flooder was rather polite about it; and hopefully next time Trent will have a mechanism in place to protect it from 400 nick registering bots.) > > This is the magic of private property. We don't have 'free speech' in my > home, if you are in my home, and you have bad breath, I can tell you to > leave and it is my right. Free speech does not enslave me or deprive me of > the control and right to manage my personal property. This is the same case > in the #distributedcity channel. It is 'pretty much' free reign, but with > limits. You can call my limits of speech in #dc to be limits on free > speech. You are damn right. I am the caretaker of this channel with > property rights to manage it on behalf of LP. I agree with you that private property is important and that chan ops are necessary in such conditions. To have a situation that is under some level of control, some type of leadership with power is required. > > So the abuse of a channel that "IIP" says is public, and a free speech > location, is fine and dandy, but with that type of a 'commons' it will > continue to be spammed, dos'd, flooded, disrespected, and destroyed. Most likely it will. > > Remember, even though I kick or ban etc someone from my channel, does not > gag him. He can always go to #anonymous, or create his own channels. > Channel ownership, and moderation, and its users responsible use of the > channel creates value. Just like the manager of a restaurant caring for the > quality of the establishment. Even if it means throwing a loud-mouthed > drunk out on his ass in the street. I agree. Channels with ops are a key to having order (even in an anonymous network.) > > As IIP moves more toward a decentralized system, the power to control a > centralized IRCD will no longer be a policy of trust we have in Nop, but > will be in the code. This is a good thing. Amen! (No offense to nop [and I doubt he would take any], but I want to get that code out the door!) > > I tried to make the case, that Coders and IIP network operators are > different from the owners of private channels. I think you did a fine job. :) > > The coders/network operators should shift control of content to the owners > of the channels. To the best of my knowledge the control is _already_ shifted to the channel owners as much as is physically possible. The only _control_ the developers have (and not even all of them) is in the IRCD server ... which will be gone in IIP 1.2, and in the source code itself ... which is free and if we mess it up and make a dictatorship out of IIP, anyone can fix it and make a real anonymous network. > > An official IIP sanctioned #anonymous channel is a silly idea as it places > ownership of the channel in the hands of the IIP coders/network operators > giving a tendency to have these conversations about punishing people. While > claiming it is an open channel, yet at the same time, saying that they are > watching, and that violaters of certain rules will be punished. I agree that the concept isn't perfect ... but I'd also say it's better than nothing. Until IIP 1.2 is out people should realize that there are a human beings out there that has the power to make them shut up. For now, we must hope they have the restraint (and I believe they do) not to use it. > > IIP should not sanction any channel as open and free speech unless it is > going to ingore all and any of all content that is placed in it. Similar to > freenet. Freenet does not say that use is 'free open speech' 'except for > certain limits'. How does freenet do this? Via CODE. not policy. Code. And we are coding. Would you like to help? If you'd like to, then check out the "development" tag from the SourceForge CVS and ask nop or UserX what you can do. :) > > A possible way for this to happen with #anonymous in the new system, is to > create the channel, and as the owners of a channel will have the crypto > keys to the channel, thus giving them ops, then publicly distribute the > keys to this channel to all users. *THAT* would guarantee free speech, and > no liability, since there is no central control point. Unless all the people holding the keys can _also_ get ops. Then you have an #anonytest scenario, and (as anyone who's been in there can see) that can be chaotic. Yet while I am a little concerned about your method, I do agree with your concept: Having a way to maintain a truly free channel in IIP 1.2 would be a really good idea (if not an outright necessary one). > > Anyone that says 'we cannot do that, what if someone says X or Y or Z', > should not be using IIP/Freenet and should spend more time on snooping, or > key escrow systems that are meant to solve this problem. > > Either we are going to have free speech uninhibited, or we are NOT. Well, I don't think the world needs any more key escrow systems than it already has, but I agree that such people shouldn't be writting code for things like IIP and freenet. > > IIP does not need any laws, a constitution of guaranteed liberties or > limitations. We just need code. Code that will let me say anything that I > want to say, or need to say. Code that will allow me to say that there is > no God, and live, while everyone else around me is being burned alive and > slaughtered. I don't need to go into all the reasons why we need privacy or > anonymous communications. I agree. You've mentioned code yet again. Do you know ANSI C? Would you like to help? :) > > Sure there will be abuses, but when there are, IIP Coders or network > operators cannot be responsible. They can only be, when they have control. > Once they have control, it is only a matter of 'who has control'. Once its > about control, the control will be taken away from those we trust today, > and the control will be used against us tommorrow. I think you are touching a very important concept here (which you have been touching through your whole message). Centralized control (and even control in general) in an imperfect being (e.g. humans) can be _very_ dangerous. Sometimes it's necessary (e.g. governments [note: anarchists please don't scalp me for that one]), but I agree that in IIP it is best to be avoided ... and eventually removed. Also, might I point out that _some_ people would still see the developers as responsible for the network since they made it. Some of those people might be governments and judges. Please remember that developers of networks like Freenet and IIP take a certain amount of risk. If I get arrested by the US government for something that happens on IIP, and the judge doesn't see reason and convicts me, I will be in big trouble. Hopefully that will never happen. (I don't think it will). But before people go developer bashing (and I'm not saying you are at all; I think you've actually done a great job writting down your opinion; I'm just say this since some people don't think about it) they should remember that we are just human and will make mistakes. IIP comes to you from the blood, sweat, and sore fingers ;-) of developers who aren't asking anything back. So though me may make mistakes, please just point them out, pick us up and dust us off, and help us fix them. :) > > In closing, our only hope for secure private and anonymous communications > will never live because of laws, politicians, police, or opinions > controlling, giving, or limiting our speech. Our hope will only be fufilled > through engineering. Well, I'll agree that engineering is as good as we're going to get short of paradise. But I'm not sure that will always be enough. I don't believe that the battle for secure, private, and anonymous communications network will ever be won. Anything a human makes another human can break. It's only a matter of time. So as long as there are opposing sides on this issue (which will probably be forever), one final feat of engineering will never be enough. It will be an ongoing process. > > -Neo Well thanks for your opinion, Neo. It was well thought out, well written, and well presented. I appreciate your willingness to say all that. Even though I might not agree with you on every point it's still nice to have people that will maturely and knowledgeablely dissagree with you. Once again, I appreciate it. :) I hope I answered any questions you had and explained my viewpoint appropriately. As I said before, it's just my viewpoint. It doesn't necessarily represent the other developers. They can speak for themselves. :) Sincerely, (and with great respect) -- Hezekiah
signature.asc
(application/pgp-signature, 189 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.1 (GNU/Linux) iD8DBQA+yaUSeHiZTMH32ioRAmIlAJ9WoBr+2GOgddJqnEw58myPnU8wLgCeIYW2 7hq5Z9QT2NYSav44F02CmO0= =9QiP -----END PGP SIGNATURE-----