When people think "Mafia" they think men in suits firing machine guns, but the real mafia is about making millions by establishing a pseudo-government which collects taxes in the form of bribes, corruption, over-priced rent and protection payments. Italy's mafia, Afghanistan's Taliban, and Pakistan's ISI all operate this way, and by this definition, the US has a mafia of its own, that occupies a portion of Wall Street.
The good news is some portion of US mafia went to prison. The bad news is they got right back out, seemingly due to mistakes made by the government prosecution, maybe due to bribes. More bad news: The case shows clear evidence of the convicts bribing government officials, including former New Mexico Governor Bill Richardson for $100,000, in that case in exchange for $1.5million of New Mexico's money.
There are too many schemes employed by those in the trial to cover here - see the article - but generally, someone would hire them to invest money, and they'd take a large chunk of it for themselves. To keep states hiring them, they'd bribe politicians - and by bribe I mean fund their SuperPACs, which the US defines as legal and not a bribe.
The list of things we need to change to stop this secondary government to operate is pretty long. That politicians require campaign funding (bribes) to operate is a major factor. Another is the way US states continue to award contracts worth more than $1 million to a single vendor, in a confused belief it will allow them to bid it out and get the best deal. Inevitably any large contract from a single provider leads to incredible corruption, because even a .1% kickback on that sort of contract is worth 10s of thousands of dollars, enough to get a lot of iffy people paid off.
Maybe the worst part is that everyone involved in all the schemes uncovered continue to operate banks and other parts of Wall Street - they didn't lose their jobs and once they escape prison they're often promoted or given a bonus. The author of this article is clearly frustrated when he proposes we have them all killed. But we should at least ban them from the Finance industry, politics, and lobbying.
Rolling Stone: The Scam Wall Street Learned from the Mafia
Bloomberg: Bankers Win Reversal of Convictions for Bid Rigging
Showing posts with label Politics. Show all posts
Showing posts with label Politics. Show all posts
Tuesday, February 17, 2015
Sunday, November 23, 2014
Why Conservatives often see Liberals and Scientists as Heretics
A little food for thought, on why Conservatives often see Liberals and scientists as heretics.
Two years ago, arsenic was not in the news. Today, almost every day there's a new article about dangerous arsenic levels making something poisonous and unsafe:
http://www.9news.com/story/money/personal-finance/consumer/2014/11/19/rice-arsenic/19286469/
You can hear conservatives reading this and going, "Really, liberals/scientists? You're saying rice is bad too? Why not just ban everything?" And why now, and why so suddenly - how was rice fine a year ago but TODAY it's dangerous?
So now let's walk back from the bristling irritation of reading a headline, to what happened.
The FDA and USDA have been avoiding action on arsenic for decades because the agricultural industry has been lobbying to delay it.
http://www.publicintegrity.org/2014/06/28/15000/how-politics-derailed-epa-science-arsenic-endangering-public-health
It's not that arsenic suddenly became poisonous, or suddenly appeared in people's drinking water and food - it's that it's always been in fertilizer, we've been using way too much of it, and arsenic levels have been steadily rising. Worse, the agricultural lobby has been bribing politicians and suing to delay telling the basic truth: That too much arsenic is poisonous, and it's in a lot of agricultural water because of these excessive uses of fertilizer.
OK, but aren't you, liberals and scientists, once again, anti-business? Aren't you accusing businesses of being evil? This sure sounds like some anti-corporation conspiracy theory. We're tired of that, say conservatives. Well - sort of.
Rice is cheap, so it's made cheaply: with way, way too much fertilizer, and in many cases, with waste water which contains even more arsenic from fertilizer or fracking and drilling. You'd never grow food for yourself that way, but these growers know you aren't checking on them when you buy a bag of rice, and they know you will buy that other bag of rice if they don't have the lowest price. So, they can do this to you, or go out of business.
So it's not that these businesses are evil. It's that they're slaves to our poor market forces. The Invisible Hand of Capitalism works best with a consumer that considers EVERY quality of the product before buying. But most consumers are very poorly informed about what they're purchasing, other than price - and a blind consumer hurts the market. Arsenic in drinking water, foods, and rice, is a classic case of blind buyers shaking all the goodly growers out because their prices are too high, and leaving only the ones who over-fertilize behind to dominate the market.
Of course there is SOME evil here you can't avoid: When agriculture lobbies the government to keep them from saying they're poisoning you and your children, it's hard to paint that in a good light. It's just plain evil.
http://www.scpr.org/programs/reveal/2014/07/04/38205/politics-profits-delay-action-on-arsenic-in-drinki/
So, from someone who leans left and prefers science over popular politics, if you happen to lean right, consider the case of arsenic next time you hear liberals upset over the latest thing in the news. Sometimes they really are being idiots. Sometimes they're just forcing society to finally be honest.
Two years ago, arsenic was not in the news. Today, almost every day there's a new article about dangerous arsenic levels making something poisonous and unsafe:
http://www.9news.com/story/money/personal-finance/consumer/2014/11/19/rice-arsenic/19286469/
You can hear conservatives reading this and going, "Really, liberals/scientists? You're saying rice is bad too? Why not just ban everything?" And why now, and why so suddenly - how was rice fine a year ago but TODAY it's dangerous?
So now let's walk back from the bristling irritation of reading a headline, to what happened.
The FDA and USDA have been avoiding action on arsenic for decades because the agricultural industry has been lobbying to delay it.
http://www.publicintegrity.org/2014/06/28/15000/how-politics-derailed-epa-science-arsenic-endangering-public-health
It's not that arsenic suddenly became poisonous, or suddenly appeared in people's drinking water and food - it's that it's always been in fertilizer, we've been using way too much of it, and arsenic levels have been steadily rising. Worse, the agricultural lobby has been bribing politicians and suing to delay telling the basic truth: That too much arsenic is poisonous, and it's in a lot of agricultural water because of these excessive uses of fertilizer.
OK, but aren't you, liberals and scientists, once again, anti-business? Aren't you accusing businesses of being evil? This sure sounds like some anti-corporation conspiracy theory. We're tired of that, say conservatives. Well - sort of.
Rice is cheap, so it's made cheaply: with way, way too much fertilizer, and in many cases, with waste water which contains even more arsenic from fertilizer or fracking and drilling. You'd never grow food for yourself that way, but these growers know you aren't checking on them when you buy a bag of rice, and they know you will buy that other bag of rice if they don't have the lowest price. So, they can do this to you, or go out of business.
So it's not that these businesses are evil. It's that they're slaves to our poor market forces. The Invisible Hand of Capitalism works best with a consumer that considers EVERY quality of the product before buying. But most consumers are very poorly informed about what they're purchasing, other than price - and a blind consumer hurts the market. Arsenic in drinking water, foods, and rice, is a classic case of blind buyers shaking all the goodly growers out because their prices are too high, and leaving only the ones who over-fertilize behind to dominate the market.
Of course there is SOME evil here you can't avoid: When agriculture lobbies the government to keep them from saying they're poisoning you and your children, it's hard to paint that in a good light. It's just plain evil.
http://www.scpr.org/programs/reveal/2014/07/04/38205/politics-profits-delay-action-on-arsenic-in-drinki/
So, from someone who leans left and prefers science over popular politics, if you happen to lean right, consider the case of arsenic next time you hear liberals upset over the latest thing in the news. Sometimes they really are being idiots. Sometimes they're just forcing society to finally be honest.
Sunday, October 26, 2014
Why Trader Joe's Decision to Cut Part-Time Worker's Healthcare is the Right Thing to Do
Trader Joe's is generally considered one of the best national grocers in terms of how they treat their workers. Historically if you worked just 18 hours a week there, you'd get full benefits. Under Obamacare, covering these workers is not required, and Trader Joe's has cut the health benefits of part-time workers. Normally this would be a political football for the right-wing political sphere, saying Obamacare has caused a reduction in care. But there's more to the story.
Trader Joe's is providing these workers a $500 healthcare stipend instead, and asking workers to go and get care on their own. This means not only do workers get healthcare - even if they only work a few hours, nevermind 18 - they also get it decoupled from Trader Joe's, meaning they can leave for another company, start their own business - whatever they elect to do, all with no interruption in healthcare, and more importantly, all without the scary prospect of losing their care altogether for leaving.
Depending on your income the subsidies built-in to Obamacare may get a TJs part-time worker healthcare for as low as $27/month, certainly within the $500 stipend. Obamacare has unquestionably been pivotal in this new policy.
Trader Joe's has taken an unusually generous benefits plan and made it even more generous - by making it easier for their workers to leave for that next stepping-stone.
Sunday, October 5, 2014
When Poverty Kills Children
“I just shot my daughter and shot all my grandkids. And I’ll be sitting on my steps, and when you get here, I’m going to shoot myself.” -Multiple Shooting Deaths in Gilchrist County
A grandfather calls the police, and they arrive to his killing his daughter, his grandchildren, and himself. All with a gun purchased on the black market, after he and his family tumbled for years at financial rock bottom.
So much of what's wrong in the US at play here.
The Community is Enough
The community says they all saw the suffering but no one could have seen this coming; and yet, upon further reading, they're so predictable any reasonable person would feel disgraced. The Miami Herald documented 500 children dying prematurely in the state of Florida alone in a single year under similar, desperate family circumstances.
Pull Yourself Up
There's a belief today that the poor lack work ethic, and if their life is garbage, that's deserved - it's their motivation to pull themselves up. But there's a difference between motivating people, and desperation. Leaving people to struggle desperately and bitterly turns them against the system, others, and themselves - sometimes, as terrible as it plays itself out here. Other times, as petty crimes, theft, and emergency room visits after it's too late. We do need better motivation in the system, but risk is a motivator; despair is not. We need opportunity. And we need to stop dismissing government assistance out of hand, especially when studies show programs' overall monetary cost is cheaper than proceeding without them.
Tough on Crime
Americans favor exactly one intervention for the poor, and that's prison. Multiple members of this family spent time in prison, and it lead to even more hardship, in part due to a lack of job opportunity. More significant interventions were made available by child services, like therapy and counseling, but all of them were optional. The police were called repeatedly, but cops are meant to intervene in situations of imminent harm - they aren't trained counselors. We send the wrong people to domestic violence situations, and they lack any appropriate remedies at their disposal.
Don't Let the Government Have a List of Gun Owners
There's a subculture in America that believes any gun registration will allow the government to track down every gun owner in some hellish coming act of tyranny; this leads to private, undocumented sales, and laws pushing for legalization of those sales, all wrapped in a seriously misled idea of patriotism. Today, because of this broken belief system, every state in the union has at least one way to legally buy a gun without review or documentation. One of the strangest roots of this belief system is, "Criminals will get guns anyway," a strangely self-fulfilling prophecy. It's used to dismiss the obvious harm of acting on this broken belief. This is a cultural problem first, and a legal problem second.
Sneering is No Way to Build a Stronger America
We need to end this American love for desperation and suffering, justified by a hatred for "entitlements." Hatred of the other is a great campaign slogan but there is no public benefit. We need a system that really motivates and provides people with the opportunity to work and share their talents with the world, and that means first identifying those motivators, and mitigating desperation with a helping hand. And we need to reform our punishment-only prison/rehabilitation system, with real interventions.
Multiple articles and reporters collected different portions of the facts of this story - I've linked several above to their most pertinent reports, and below are 2 more which document a bit more.
http://www.miamiherald.com/news/state/florida/article2203558.html
http://www.nbcnews.com/news/us-news/911-call-florida-murder-suicide-reveals-shooters-final-moments-n209581
Wednesday, September 17, 2014
Your Couch Is Giving You Cancer - Our Stupid World
In 1953, a company that makes flame-retardant scored a win when the US passed a law requiring it in children's pajamas. That turned out to be a bad idea when that chemical was associated with inhibited brain development and cancer, so in 1978 it was banned from children's pajamas.
Desperate to keep their business going, the company that made it then bribed their way into a California state law to require it in furniture. Unfortunately, most US furniture manufacturers responded by including it in all furniture, to avoid the fussy complication of making special California-only furniture.
A well-meaning chemist, Arlene Blum, began to fight this chemical manufacturer in the 1970s, and has been fighting for FORTY YEARS to get this stupid chemical out of the seat you're sitting on right now. At every turn the company has lobbied and bribed their way into keeping the law on the books, and the chemical has remained.
Finally, in California, a win for Arlene Blum. The chemical is no longer required. Strangely though, it is still not banned, in a partial-win for the lobbyists.
Fire-Retardants in Furniture: Manufacturers Adjust - KPCC
And they're suing to stop the law from going into effect - thankfully so far, losing:
Judge Tosses Challenge to Flame Retardant Rules - Chicago Tribune
Unfortunately that means all your furniture is probably still cancerous, including what you're sitting on right now:
Cancer-Linked Flame Retardants Eased Out of Furniture in 2014 - Scientific American
TDCPP Flame Retardant - Wiki
In the meantime you can look (hard) for furniture that explicitly contains no flame retardants. Buying such a piece of furniture was actually illegal in California until Jan 2014, but is finally legal here as well.
You can see Arlene Blum here fighting paid lobbyist dirtbags:
California Flame Retardant Law Sparks Debate - PBS
We all owe Arlene Blum a tremendous thank you. Instead of posters of athletes on their walls, kids should have posters of Arlene Blum.
Arlene Blum: Current Work - Wiki
Desperate to keep their business going, the company that made it then bribed their way into a California state law to require it in furniture. Unfortunately, most US furniture manufacturers responded by including it in all furniture, to avoid the fussy complication of making special California-only furniture.
A well-meaning chemist, Arlene Blum, began to fight this chemical manufacturer in the 1970s, and has been fighting for FORTY YEARS to get this stupid chemical out of the seat you're sitting on right now. At every turn the company has lobbied and bribed their way into keeping the law on the books, and the chemical has remained.
Finally, in California, a win for Arlene Blum. The chemical is no longer required. Strangely though, it is still not banned, in a partial-win for the lobbyists.
Fire-Retardants in Furniture: Manufacturers Adjust - KPCC
And they're suing to stop the law from going into effect - thankfully so far, losing:
Judge Tosses Challenge to Flame Retardant Rules - Chicago Tribune
Unfortunately that means all your furniture is probably still cancerous, including what you're sitting on right now:
Cancer-Linked Flame Retardants Eased Out of Furniture in 2014 - Scientific American
TDCPP Flame Retardant - Wiki
In the meantime you can look (hard) for furniture that explicitly contains no flame retardants. Buying such a piece of furniture was actually illegal in California until Jan 2014, but is finally legal here as well.
You can see Arlene Blum here fighting paid lobbyist dirtbags:
California Flame Retardant Law Sparks Debate - PBS
We all owe Arlene Blum a tremendous thank you. Instead of posters of athletes on their walls, kids should have posters of Arlene Blum.
Arlene Blum: Current Work - Wiki
Sunday, August 31, 2014
A Drug Given to Pigs Probably Causes Heart Attacks - Our Stupid World
![]() |
| Credit: farmsanctuary.org |
Ractopamine is a steroid originally designed to treat human asthma, but it's been found to increase the growth rate of some pigs. Unfortunately it also causes heart failure in many of them, though slaughterhouses just chop those pigs into pork early and off it goes to you.
Banned in 160 Nations, Why is Ractopamine in U.S. Pork?
This has become more awkward for the pork industry given that 160 countries have banned pork treated with the drug, and so, banned US pork. The pork industry is trying to force Europe to accept its drugged pork, and Europeans are protesting.
US pork producers' use of drug may derail European trade deal
The pork industry, for its part, says that Europeans aren't listening to the science - except the only human safety test of Ractopamine involved 6 men, one of whom had to drop out because his heart began racing erratically. There's no evidence to show it's safe in any dose for humans, and given how similar pigs are to us and their pattern of heart failure with the drug, it's probably not wise for us to be eating it.
Thursday, July 10, 2014
Rise of the Warrior Cop
A journalist tracks the increasing role of US police as bullies, rather than protectors. He points to some of the historical and modern causes, and to an odd stat to identify the worst departments: The number of dogs killed by cops. As cops are increasingly deployed into other people's neighborhoods, sitting isolated from people in cars built like tanks, instead of walking a beat, wearing body armor and given access to a literal armory, they're increasingly disinterested in the well-being of the community they serve.
He also notes the rise of the drug war, as federal funds are awarded for number of drug busts, and dubious-necessity military-grade weapons provided to even small-town police departments.
Cops killing dogs is an odd stat to track, but it's easy to find and calculate - and trends closely with areas where people perceive a department as failed.
Once a Town Gets a SWAT Team, You Want To Use It (salon.com)
Dogs (warning: sad):
Los Angeles, CA
Idaho
Salt Lake City, Utah
West Virginia
Self-solver - Cop literally shoots himself in the foot trying to kill someone's dog.
Small Town Police Department Questioned as to Why It Needs Two Grenade Launchers
There are a lot of good police out there, but with cops like these in some departments it's hard to trust them knowing you might just be inviting armed thugs.
He also notes the rise of the drug war, as federal funds are awarded for number of drug busts, and dubious-necessity military-grade weapons provided to even small-town police departments.
Cops killing dogs is an odd stat to track, but it's easy to find and calculate - and trends closely with areas where people perceive a department as failed.
Once a Town Gets a SWAT Team, You Want To Use It (salon.com)
Dogs (warning: sad):
Los Angeles, CA
Idaho
Salt Lake City, Utah
West Virginia
Self-solver - Cop literally shoots himself in the foot trying to kill someone's dog.
Small Town Police Department Questioned as to Why It Needs Two Grenade Launchers
There are a lot of good police out there, but with cops like these in some departments it's hard to trust them knowing you might just be inviting armed thugs.
Thursday, August 29, 2013
Restore Public Oversight of Secret Warrants
This is an attempt at forcing the US back into reasonable public oversight without having to build ironic technology solutions outside the US to enable basic Constitutional rights for its citizens. Since I'm not a lawyer, there's probably a lot wrong with it - I'd love to hear ideas for improving it. I wouldn't be terribly interested in diatribes about why it wouldn't work. The internet has hit its quota for those.
This is a follow-up to Privacy - What's Possible With the NSA Watching.
This is a follow-up to Privacy - What's Possible With the NSA Watching.
I'll try to stick to the technology side of things and openly punt on the legal ins and outs.
A brave coder could create a data service that just moves things securely in and out, that other convenient, secure services could be built on top of. Secure email, text messaging, phone calls (voice service), whatever you like. With Congress and members of the NSA etc apparently unwilling to admit that what they're doing is violating basic US rights, it may be possible to force public oversight on this process with technology despite laws and programs to the contrary.
Basic Security
First, the service itself could be secured with HTTPS PFS, described in the previous article. That takes care of connections. On the servers themselves you've got a regularly rotating key for encrypting user data you share with no one, including the government.
But there's still the sticky problem of whatever poor jerk runs this site being served a secret warrant, and no legitimate legal challenge being available because the actual person whose rights are being violated isn't allowed to know. To untangle this gross catch 22 the government's assembled, what you really need to enable here is 3 basic principles: separation, anonymity, and civil disobedience.
Separation
If the author of the code doesn't actually control the service, they just maintain the code the service uses to operate, they can provide some insulation between themselves and the service. The service could be designed to generate its own keys, keep them completely private, and expose them to no one - even the author of the service. If we assume the author of the service can't avoid being identified, the trick is to ensure they can never be compelled to expose user data. Suppose the NSA says to the author, someone on your network is a person of interest, tell no one, go get their data for us. If the author doesn't have any access to the keys that data is being stored with - if the software itself is the only entity with actual access to the keys - there's not much the author can be asked to do here. Except - they could be compelled to write code that modifies the software so it exposes those keys, or exposes what a specific person has said.
Civil Disobedience and Anonymity
So, if the service was setup so the only way it could be modified is via a public channel, like a public code repository, you would force any malicious code like the above to be exposed to the public. You could further force any modification to the code through a public review process - ideally by anonymous coders so they can't be compelled to approve malicious code - you would place a pretty strong lock and key on the code. To do this you have the software update itself periodically, by pulling the latest approved code from the public repository. You could design the software in a way that it destroys all the keys (making the data leftover garbage) if it's modified in any other way. This creates a remaining risk of the repository itself being attacked, so whoever hosts the repository would also be at risk of being compelled. Worst case you could host the repo with the rest of the service, and have the software respond to an attack by destroying the keys.
The coders that do these code reviews would have to accept a serious legal risk by participating - whatever is ensuring their anonymity could always be pulled back, so they could potentially be compelled to approve malicious code - it could get pretty ugly. That's civil disobedience. There may be other ways to protect the coders besides anonymity - for example if only a small, random subset of the coders was allowed to perform a given code review/approval, all coders gain plausible deniability as to who actually said no to a malicious code submission, and no one coder is the ideal target for threats to get them to approve malicious code.
The coders that do these code reviews would have to accept a serious legal risk by participating - whatever is ensuring their anonymity could always be pulled back, so they could potentially be compelled to approve malicious code - it could get pretty ugly. That's civil disobedience. There may be other ways to protect the coders besides anonymity - for example if only a small, random subset of the coders was allowed to perform a given code review/approval, all coders gain plausible deniability as to who actually said no to a malicious code submission, and no one coder is the ideal target for threats to get them to approve malicious code.
An Olive Branch
As I said earlier, the goal is not to build the one place actual terrorists can have a nice secure chat about blowing up a building. You do still want it to be possible for warrants to be served on real, actual criminals - you just don't want it to be outside the realm of public oversight with nothing but a "Just Trust Us" PR campaign as guarantee it's not being abused.
So, the goal is to make it possible to serve warrants into this system - basically to the software - and a group of people - a jury of your peers in a sense - get to decide whether that warrant is valid and reasonable.
- Make the only way to get access to private data in this system via an electronic warrant filing system. From a technical perspective, you could just have the system email some government email address a key periodically that they can use to validate themselves as government actors, and they can make up their own minds about how they want to gate use of the system. They've shown themselves to be plenty resourceful in screwing us so far, I'm sure they can do smart things with this as well.
- Every user of the system is a member of the jury of peers. When a secret warrant is issued, a small pool of members is selected, and sent the warrant. Since it's a secret warrant, their receipt of it is illegal - another piece of civil disobedience. But if you manage to keep step 1 air tight, you may be able to force the government into step 2. A lawyer would know better than I what would be necessary in the electronic warrant system for it to feel comfortable for NSA etc to use, and legally cover members as well as possible.
- The random pool of users decides whether the warrant should be honored. If they decide it should, the selected communications are turned over, simple as that. If they decide it should, but there's no reasonable justification for this warrant being secret, they can turn it over, but have the software publish the warrant publicly. If the warrant is completely unreasonable, they can turn nothing over and have the software publish it to remind the government of its duties. You can ensure the pool is always an odd number and a simple majority wins on both the "turn records over" and "make public" votes.
That's it - a way to put a jury of your peers and public scrutiny back into the US legal process. It's possible there are parts of this that just aren't viable inside the US - in fact, the author of the software could probably have some really terrible things happen to them regardless of where they lived, so they'd probably need to be as anonymous as possible. Go America.
Privacy - What's Possible With the NSA Watching
A number of people have reached out to me to tap my technical expertise, asking essentially — is it possible to have a private conversation anymore? Well, it is — in a few ways. The first answer will surprise you least.
If you travel to where there is no cellphone network, and no recording devices, and you’re not visible by any satellites, you should be able to have a conversation no one can hear. That’s not as impossible as it sounds given how much of the planet isn’t covered by a cell network, but for at least my lazy tech-loving life, it’s probably never going to happen. I also have to acknowledge that the warrantless wiretapping program itself is something out of the paranoid conspiracy theories of a crazy person, and yet by all accounts it’s very real — I just don’t want to propose a response any crazier than the evidence demands. So now let’s work back through all the ways the government can capture a conversation.
If you travel to where there is no cellphone network, and no recording devices, and you’re not visible by any satellites, you should be able to have a conversation no one can hear. That’s not as impossible as it sounds given how much of the planet isn’t covered by a cell network, but for at least my lazy tech-loving life, it’s probably never going to happen. I also have to acknowledge that the warrantless wiretapping program itself is something out of the paranoid conspiracy theories of a crazy person, and yet by all accounts it’s very real — I just don’t want to propose a response any crazier than the evidence demands. So now let’s work back through all the ways the government can capture a conversation.
Who’s Actually Listening
Although most articles refer to the NSA, there’s evidence that it’s actually a wide range of organizations either listening in or getting access through others. The FBI, NSA and DEA have all been shown to have their own monitoring programs. Some of them have been shown to have more than one. And the IRS and local police departments have been shown to have access to one or more of these monitoring programs. So while I’ll also be using “the NSA” as a convenience, brave reporters, journalists and whistleblowers have taken great risk to show us it’s a lot more than one program at one department of the government.Tinfoil Hat Stuff
First let’s get past the tinfoil hat stuff that sounds insane.Satellites
Technically speaking, a satellite recording you with no cloud cover should be able to get a clear enough video of you speaking, that a lip reader (or lip reading software) could capture what you’re saying.There’s also technology out there that reads the small vibrations in a large flat surface, like a pane of glass in a window, and translates that back into a crappy version of the original audio. To make it sound even more ridiculous, this technology is actually called a Laser Microphone. Yeah that’s right — go ahead and click that amazing word combination. And then go build one.
Both of these mean that if you’re in view of a satellite — basically if you’re outdoors or near a window, you could not assume your conversation is private. That said, satellites are big expensive things that must be launched up into space, and replaced by launching another one, because they fail over time — not cheap. There aren’t many, so they can’t be recording everyone at once. Even if they could, they wouldn’t have the bandwidth to send all that video or audio back to Earth where anyone could make use of it. Basically, if someone at NSA, CIA, FBI etc is watching you with a satellite, either they’re violating your privacy for fun (and with no public oversight, it’s not unfair to assume) or you did something really, really suspect worth an incredible expense. So let’s assuage the satellite fears with, “I’m not a top ten criminal, I just want my right to privacy, and I’ll avoid being outside naked.”
High Altitude Drones
Perhaps the only thing that sounds more insane than satellite monitoring is drone monitoring. Drones unfortunately are a lot cheaper than satellites, can get a much better view of you, and have a lot more opportunity for even just plain getting an actual audio recording of what you're saying - or even recording the wifi signal your cellphone is putting out. The only solace here is it appears the government doesn't have many of these. In 2011 US Customs and Border Patrol received their 9th drone - meaning they have fewer operating over the first 100 miles from the Mexican border than we have satellites orbiting earth. But, there's still obvious opportunity for abuse here, and again, no public oversight. But, they're still few enough that we'll assuage this the same way we did the satellites.Cellphones Recording While Off
Still acting like paranoid maniacs, it has been documented numerous times that various agencies have found ways to switch someone’s cellphone mic on in secret, to record audio and send it back to the FBI or NSA, while that person wasn’t making a call and thought they were in the clear. However, what has been documented suggests a couple of important things: First, you have to specifically be targeted. It may be that some of these phones have a bug in them that lets any wise hacker in to do this, but descriptions of what’s been uncovered suggest it was more about a really vicious virus getting installed on a phone, often through direct physical access.So we’ll set this one aside the same way we did with the satellites — seems like the top cops have to really want you imprisoned or dead to have this happen to you. There is one exception though, and that is a dragnet approach to infecting phones in this way.
For example, if the NSA etc worked out a deal with Samsung, HTC, etc to have this backdoor built in to every phone they made (as may have happened in the RIM/Blackberry case), it would be possible for everyday citizens to get surveilled with little way to detect it and no way to prevent it (short of leaving the modern technological world). But, even if this were so, the way cellphone networks are designed is unlikely to enable that much bandwidth usage. Basically to transmit that much information back to where it could be recorded and analyzed, every cellphone would need to be continuously transmitting data over the network — when the design of cell networks is based on the assumption that most phones spend their time idling, and in this mode they have almost zero interaction with the very limited resources at their local cell tower.
The remaining possibility is a dragnet hack into many phones, or all phones or desktops by a given manufacturer or with a given OS, and they only phone home periodically to avoid saturating networks. The only way to really catch this would be to monitor traffic - on wifi you could watch your router's traffic, and on the cell network unfortunately you'd have to do something more elaborate, like reading how much signal it's putting out when, and whether all of those times it emits a signal are expected. This is a real weakness - as usual, if your device is compromised, so are you.
The remaining possibility is a dragnet hack into many phones, or all phones or desktops by a given manufacturer or with a given OS, and they only phone home periodically to avoid saturating networks. The only way to really catch this would be to monitor traffic - on wifi you could watch your router's traffic, and on the cell network unfortunately you'd have to do something more elaborate, like reading how much signal it's putting out when, and whether all of those times it emits a signal are expected. This is a real weakness - as usual, if your device is compromised, so are you.
Your Location
Sadly the nature of cellphones is that they have to constantly check in with the cell network by their nature. They need to tell the cell network, "Hey, in case anybody calls - I'm here." Unless you pull the battery, you are constantly broadcasting your location. That location information is available to the NSA etc. The alternatives here are pretty slim: Leave the phone on and be tracked as you wander the globe, pull the battery when not in use and only be tracked sometimes, or set it to Airport Mode and hope that there isn't some passive way to still be tracked anyway (debatable), and simultaneously wonder why it is you bought a smartphone that never connects to anything.Corporations That Caved
So now let's finally get away from the paranoia stuff and on to one people like to harp on: big evil corporations. Companies like Google talk a big game about privacy, but it's now been shown they and a whole bunch of other companies did not fight the good fight when it came to secret warrants allowing dragnet data gathering on their networks, of your data. Cue There Goes My Hero by Foo Fighters. So even if you could trust the way you transmitted your data, while it's stored at Google etc unencrypted, the NSA gets to casually peruse it - or really, record every last character so they can casually peruse it later, even if you delete it. So you can't trust any company known to have caved to this dragnet, and you can't trust anything you've ever said, even the deleted stuff, over any of those companies' servers. If we're going to be really honest with ourselves, it's probably not safe to assume any company has fought back against these secret warrants issued by secret courts, unless you've seen them make a very public stink about it. So, any normal, unencrypted data on these services is out.
Secret Warrants
This may be the biggest barrier in the way of privacy. Since the various government agencies doing this do so with zero public oversight, never declassify what they've done, and use courts that are themselves secret, it's not possible to exercise your right to privacy - because the warrant your service provider is served specifically instructs them not to tell you about it. Since the person whose rights are being violated never knows, they can never challenge it in court and never enact the mechanism that calls this program what it is: Unconstitutional. Apparently the Constitution failed to include the "If a right falls in the forest and no one's there to hear it" clause.
Strictly speaking, it may not be legally possible to solve this for any service in reach of the United States - that is, either in the US itself, or in a country that either actively collaborates with the US dragnet, or caves to US pressure. Fortunately the US has plenty of enemies, but often they have warrantless wiretapping programs or worse of their own - so it's a tricky legal conundrum, and my area of expertise is technical, not legal. I'll make some technical proposals here below, but I welcome legal considerations by those who know more about that side of it.
Strictly speaking, it may not be legally possible to solve this for any service in reach of the United States - that is, either in the US itself, or in a country that either actively collaborates with the US dragnet, or caves to US pressure. Fortunately the US has plenty of enemies, but often they have warrantless wiretapping programs or worse of their own - so it's a tricky legal conundrum, and my area of expertise is technical, not legal. I'll make some technical proposals here below, but I welcome legal considerations by those who know more about that side of it.
What's Possible
With what's in the way discussed, finally what I promised: What's actually possible. First let's get non-goals out of the way.
Non-Goals
Our goal isn't to completely shut the government out. We already acknowledged the tinfoil hat stuff as being legitimately possible, so if you're dangerous enough, they may use those extreme tools, and we won't even try to interfere there. Our goal also isn't to be able to have a private conversation that's absolutely impossible to ever get into - because if we can use it, so can some big bad guy, and the Constitution provides for reasonable things like publicly inspectable warrants where justified with good reason; technology that shuts out even this legal option is likely an unwise tool to give to the world.Don't Have Any Viruses
This probably goes without saying but if you have a virus on your machine of any sort you're probably hosed. Even if the NSA didn't put it there, any virus that made it on is probably transmitting something private off the machine - maybe everything. If your machine is infected all bets are off. Not trivial advice to follow through on but that's how it is.
Pre-Shared Key
If we go back to the initial proposal where you have a conversation outside of any listening devices, there's one more option you have here: Instead of having the one private conversation, you could share a secret (encryption keys), keep it private (for example by passing it on a thumb drive - never emailing it), and have as many encrypted conversations as you like over the open internet with your friend without anyone, including the NSA, able to read what you're saying. As long as the key size was large enough, you could even be so brazen as to post your encrypted messages anywhere - public forums, Amazon product reviews, wherever - and the only person able to read them would be your friend(s). However, this doesn't facilitate much communication. You're unlikely to meet privately offline with everyone you'll ever want to communicate with, share private keys, bank that neither of you will ever get a virus, and communicate solely via these keys.
From an actual technological perspective it works like this: You could use what's called a Symmetric Key, where a single gigantic primary number is all you need to read anything written in this secret format. This approach would be easy to use with TrueCrypt, free encryption software for any computer out there. It would be a bit annoying, but each time you wanted to say something, you'd encrypt for example a text file into a .tc file, attach it to an email to as many friends as you wanted to send it to (that you've shared this key with), and they'd all open the .tc attachment to find your one text file and read it. Not super convenient for text, but about the same time as you'd spend attaching other files. For just text you can automate this kind of pre-shared key encryption with PGP or GPG (the distinction isn't super important, they do the same thing). You can tie this into Gmail, but it only works on desktops - though you could probably pair it with APG on Android and get it working on mobile as well. For IM on desktops that leverages this approach you can use Pidgin with OTR.
The vulnerability here is that for every friend you share the key with, that's one more person you have to worry will someday get a virus on their phone or computer and get that key stolen. When they do, now everyone's vulnerable, including everything they ever said with it.1 It's also pretty inconvenient as-is, although again you could write software to improve that a little.
On the flip side, this also has the no-legal-avenues problem: Two terrorists could actually use this approach to communicate securely, and thwart even a warrant (public or secret) to read what they said - because no one has the key to read it but them. If they can avoid legal avenues that would force them to divulge the key and technical avenues that would steal the key, they can communicate with total privacy - not what you want to hand to bad guys. That said, it's likely those bad guys could get that key stolen in one of the tinfoil hat scenarios, or stuff I've never heard of. Or the Bush/Obama/next administration could just kill them. That happens a lot.
The vulnerability here is that for every friend you share the key with, that's one more person you have to worry will someday get a virus on their phone or computer and get that key stolen. When they do, now everyone's vulnerable, including everything they ever said with it.1 It's also pretty inconvenient as-is, although again you could write software to improve that a little.
On the flip side, this also has the no-legal-avenues problem: Two terrorists could actually use this approach to communicate securely, and thwart even a warrant (public or secret) to read what they said - because no one has the key to read it but them. If they can avoid legal avenues that would force them to divulge the key and technical avenues that would steal the key, they can communicate with total privacy - not what you want to hand to bad guys. That said, it's likely those bad guys could get that key stolen in one of the tinfoil hat scenarios, or stuff I've never heard of. Or the Bush/Obama/next administration could just kill them. That happens a lot.
Mesh Communication
The best way to keep something from being read on the internet is to not talk about it on the internet. There are now free pieces of software, like Serval for Android, to have a conversation entirely outside of the internet, but still use those cool smartphones we like using. Of course any cloud-based anything, like google maps, fast GPS positioning, documents you don't lose when the phone is destroyed - that stuff - that's all gone without an internet connection. If the way you're talking on Serval was active enough that a large group of people were using it, there's probably also the risk that one of their devices is hacked, or some jerk is listening to everything and broadcasting it all, or whatever. But the point is, you can text, email, have phone calls, etc with anyone you can get a wifi signal to if you both have Android phones, or more broadly you could do this with anyone with the right software in place. The range on this has to fundamentally be pretty limited, since you're probably not encrypting what you're saying, so as soon as anybody listens in, you're hosed. You could add in the Pre-Shared Key stuff above via software, with all its ups and downs.
HTTPS
One of the best pieces of news is there is no published viable attack on HTTPS, the technology that secures web connections when you've got that little lock icon in your browser's Address Bar. The technology is a bit amazing given it begins with a public conversation, and someone attempting to listen in could record every single interaction back and forth - and still be unable to understand (decrypt) anything you ultimately say over the secure connection HTTPS sets up. That said, there is one attack-like strategy a bad guy could use, and the NSA has even been documented as using it: Record all those interactions, store them for years while working on breaking the original HTTPS certificate the server you were talking to, then use that to decrypt all of the recorded HTTPS traffic you left behind.
The solution to this is slightly more obscure, but still easily accessible: Perfect Forward Secrecy. Basically the service you're trusting needs to enable it, and you need to use a browser that supports it (like Chrome). HTTPS is a relatively long handshake process, and PFS adds several more back and forths to secure the connection even from this relatively exotic attack. So, any service you wanted to use privately would need to use HTTPS with PFS.
Securing the Service
So if HTTPS gets you data in and out of a service no problem, and your machine is virus free, the only remaining concern is the service itself - its servers, basically.
As mentioned in the Secret Warrants area above, one answer is to just put the service outside the reach of the United States. Lavabit, a company that attempted to provide secure email inside the US, shut down and left behind a message:
So that's a fairly sad, if you're at all patriotic, solution.
As mentioned in the Secret Warrants area above, one answer is to just put the service outside the reach of the United States. Lavabit, a company that attempted to provide secure email inside the US, shut down and left behind a message:
I have been forced to make a difficult decision: to become complicit in crimes against the American people or walk away from nearly ten years of hard work by shutting down Lavabit. After significant soul searching, I have decided to suspend operations. I wish that I could legally share with you the events that led to my decision. I cannot. I feel you deserve to know what’s going on--the first amendment is supposed to guarantee me the freedom to speak out in situations like this. Unfortunately, Congress has passed laws that say otherwise. As things currently stand, I cannot share my experiences over the last six weeks, even though I have twice made the appropriate requests.
What’s going to happen now? We’ve already started preparing the paperwork needed to continue to fight for the Constitution in the Fourth Circuit Court of Appeals. A favorable decision would allow me resurrect Lavabit as an American company.
This experience has taught me one very important lesson: without congressional action or a strong judicial precedent, I would _strongly_ recommend against anyone trusting their private data to a company with physical ties to the United States.Kolab uses this approach by putting their servers in Switzerland, which apparently has very few warrants served on its data (not clear if any are secret...).
So that's a fairly sad, if you're at all patriotic, solution.
Force All Warrants Into The Open
So the final, scraping the barrel possibility I want to propose requires more legal knowledge than I possess. I've broken it out into its own post:
Footnotes
1. PGP/GPG differ slightly from other methods described here, by being asymmetric rather than symmetric. In symmetric encryption, everyone shares a single key, which is used to both read and write whatever's being said, by all parties. In asymmetric encryption, each person has their own read ("public") and write ("private") key. As you connect with more people, you gather their individual public keys. Technically, this does change what kind of risk you're taking by using a given service, but in the end the risk is about the same: If anyone in the group gets hacked, all of the keys they have on their machine are taken as well, opening up everything you ever told them. If people quote each other in emails, what they said is largely opened up as well. The difference ends up being pretty irrelevant to an end user looking for privacy.Sunday, December 11, 2011
High-Level Media That Can't Be Bothered To Fact Check
Duty calls. http://xkcd.com/386/
Having worked at Google, people frequently ask me about some of Google's shadier dealings. There's a recurring one that comes up frequently, and here are 2 articles of many that have come up over the past 4 years:
http://techcrunch.com/2011/12/11/googles-3-top-executives-have-8-private-jets/
http://bits.blogs.nytimes.com/2008/10/23/a-new-fighter-jet-for-googles-founders/
It's important to notice that the first was written very recently (2011) and the second in 2008.
First of all, I'm not Google's biggest fan. They do stupid and evil things sometimes. But this is not one of them - in fact it's the opposite.
NASA and Google have a close relationship. First, they literally are close:
http://maps.google.com/maps?q=google+headquarters+to+moffett+field
I recall driving over Moffett Field - where NASA launches many experiments from, and even houses a dorm for budding scientists - on my commute to Google each day.
Second, they are intellectually close - they both run buildings worldwide filled with nerds dreaming of crazy things they can do with technology, that may or may not be useful or a good idea, but from time to time may turn out to be very important to humanity.
They differ in two important ways: NASA is allowed to do crazy things almost no one else can, like launch satellites, fly fighter jets, and drop astronauts out of the sky. Google has a gigantic pile of cash - $42.6 billion. NASA is short on funding as people find it and the space race less and less relevant. And this is where the insane articles people keep asking me about begin.
With NASA's lacking funds, Google loaned a private 747 - with a giant Google logo on the side - to NASA. Knee-jerk reporters took a photo and reported Google was using federal airbases to fly in style. Since then Google lent several more planes to NASA, and even helped them pay for a fighter jet that NASA used to help monitor their European equivalent's mission.
So, Google is making up for the US's lack of funding to NASA by handing some of their giant pile of cash to NASA, with no business win on Google's end unless you believe mankind's gradual progress into space is somehow in Google's business interest. To really hammer this home, these reporters for the New York Times and TechCrunch are slamming Google for doing something philanthropic.
And here's the part that makes me go XKCD on these guys: These aren't some 2-bit bloggers trying to make their name. These are established arms of the media, supposedly the 4th branch of government, meant to monitor government and industry and warn the population when they get out of line. The New York Times article was written in 2008, and updated after the fact with the same knee-jerk headline and a brief, uninvestigated note about NASA maybe owning the fighter jet.
The TechCrunch article had 3 years to figure out the facts, and regurgitated them all over again. They then go on to say that 8 jets are divided amongst 3 Google Execs: Larry Page and Sergey Brin, the founders, and Eric Schmidt, the CEO. Except Eric Schmidt stepped down as CEO, replaced by Larry Page, so he could go work for the Obama Administration. So even in their attempt to exaggerate with a "2.6 jets per executive," they failed to do basic research to maximize their claims to 4 jets per "executive" (Google has hundreds of executives that may at any time have need for a flight to a national or international office or business partner, so it's a weak number anyway).
The point being that if a company, individual, or politician can't even do something nice and get away with it - let alone be applauded for it - how is the US supposed to ever pull itself out of the hole it's in? The fourth branch is broken, and the idiots writing the linked articles are part of the problem. Shame on you, douchebags.
Having worked at Google, people frequently ask me about some of Google's shadier dealings. There's a recurring one that comes up frequently, and here are 2 articles of many that have come up over the past 4 years:
http://techcrunch.com/2011/12/11/googles-3-top-executives-have-8-private-jets/
http://bits.blogs.nytimes.com/2008/10/23/a-new-fighter-jet-for-googles-founders/
It's important to notice that the first was written very recently (2011) and the second in 2008.
First of all, I'm not Google's biggest fan. They do stupid and evil things sometimes. But this is not one of them - in fact it's the opposite.
NASA and Google have a close relationship. First, they literally are close:
http://maps.google.com/maps?q=google+headquarters+to+moffett+field
I recall driving over Moffett Field - where NASA launches many experiments from, and even houses a dorm for budding scientists - on my commute to Google each day.
Second, they are intellectually close - they both run buildings worldwide filled with nerds dreaming of crazy things they can do with technology, that may or may not be useful or a good idea, but from time to time may turn out to be very important to humanity.
They differ in two important ways: NASA is allowed to do crazy things almost no one else can, like launch satellites, fly fighter jets, and drop astronauts out of the sky. Google has a gigantic pile of cash - $42.6 billion. NASA is short on funding as people find it and the space race less and less relevant. And this is where the insane articles people keep asking me about begin.
With NASA's lacking funds, Google loaned a private 747 - with a giant Google logo on the side - to NASA. Knee-jerk reporters took a photo and reported Google was using federal airbases to fly in style. Since then Google lent several more planes to NASA, and even helped them pay for a fighter jet that NASA used to help monitor their European equivalent's mission.
So, Google is making up for the US's lack of funding to NASA by handing some of their giant pile of cash to NASA, with no business win on Google's end unless you believe mankind's gradual progress into space is somehow in Google's business interest. To really hammer this home, these reporters for the New York Times and TechCrunch are slamming Google for doing something philanthropic.
And here's the part that makes me go XKCD on these guys: These aren't some 2-bit bloggers trying to make their name. These are established arms of the media, supposedly the 4th branch of government, meant to monitor government and industry and warn the population when they get out of line. The New York Times article was written in 2008, and updated after the fact with the same knee-jerk headline and a brief, uninvestigated note about NASA maybe owning the fighter jet.
The TechCrunch article had 3 years to figure out the facts, and regurgitated them all over again. They then go on to say that 8 jets are divided amongst 3 Google Execs: Larry Page and Sergey Brin, the founders, and Eric Schmidt, the CEO. Except Eric Schmidt stepped down as CEO, replaced by Larry Page, so he could go work for the Obama Administration. So even in their attempt to exaggerate with a "2.6 jets per executive," they failed to do basic research to maximize their claims to 4 jets per "executive" (Google has hundreds of executives that may at any time have need for a flight to a national or international office or business partner, so it's a weak number anyway).
The point being that if a company, individual, or politician can't even do something nice and get away with it - let alone be applauded for it - how is the US supposed to ever pull itself out of the hole it's in? The fourth branch is broken, and the idiots writing the linked articles are part of the problem. Shame on you, douchebags.
Monday, December 5, 2011
Utopia Down Under
A point of perspective: Back home, in the US, we're considering rolling back the healthcare reform bill. It doesn't even get us universal healthcare - it just gets us slightly better chances (not 100%) that we might receive healthcare if we've paid the insurance for it.
The Australian Deal
Australia and US dollars trade at about 1:1 with minor variation. When I transferred $200 Australian here I paid? $197 US.
In Australia, here's what every citizen gets - not just their government - everyone:
The Australian Deal
Australia and US dollars trade at about 1:1 with minor variation. When I transferred $200 Australian here I paid? $197 US.
In Australia, here's what every citizen gets - not just their government - everyone:
- Healthcare. It's largely free. You get sick the government pays for the care.
- $14.73/hr minimum wage - nearly double the highest state minimum wage in the US, almost triple the lowest (if you're paid hourly rather than full-time, you make more - $15.51/hr).
- Minimum 4 weeks vacation/year.
- A retirement pension, even if you never saved any money. Retirement/"Age Pension"
- If you're unemployed you make $15761.20/year or about $7.58/hr, forever. If you never find another job, you still receive a living wage - enough to cover rent in a suburb (but almost certainly not in a city, where a studio runs $1800/mo). Unemployment/"Newstart" Rent Assistance
There are details to these where you might get paid more or less based on whether you need more (kids, single parent, renting) or less (live with your parents, ~$5/hr), but the numbers don't vary that much.
So just to be clear, if you lose your job in Australia, you'll be fine. If you come down with cancer at 21 before you ever wondered "What healthcare provider should I have?" you're covered. And if you never really make it big - enough to really save up - in retirement... you'll be fine.
Well Then It's a Disaster
So the assumption by the kind of person that votes for the kind of person that prevents the US from having any of this is, "Then the entire economy must be in tatters." Well let's check.
Unemployment. Economists say the ideal unemployment rate is 5%, meaning 95% of those wanting to work have jobs and the other 5% are available to employers needing workers. In Australia it's 5.3%. In the US it's 9%; in some parts of the US it's 15% and in some counties it's over 30%.
Non-Employment. Economists abuse the word "unemployment" to only mean people looking for work, when intuitively it means "does not have a job." They use other names for that, so what's that number? In Australia 49% of the population does not work. Those lazy bastards, much lazier than the 54% who don't work in the US.
Taxes. Well then taxes would have to be insane, right? Australia tax brackets - as a point of summary, an Australian making $80,000/year pays 22% of their total income, or $17550, in taxes. A Californian making the same pays Payroll tax (Social Security and Medicare), Income Tax, Unemployment Insurance, and State Income Tax, totaling 49% - a calculation so complicated it merits its own spreadsheet. Note that the Californian still has to pay for their healthcare after all that.
I'll update this with a bit more info and some conclusions later on. But seriously America... get your sh** together.
Updates
To compare with the US spreadsheet for $80k, I've created another that shows several income levels under the Australia tax regime. Both spreadsheets assume you rent an apartment, live alone, and have no kids, because I'm self-centered. The resources to build out a version for married with a mortgage and 3 kids are linked from this post and the spreadsheets, so if you build one, please share.
Australians point out to me that healthcare in Australia has 2 major caveats:
Updates
To compare with the US spreadsheet for $80k, I've created another that shows several income levels under the Australia tax regime. Both spreadsheets assume you rent an apartment, live alone, and have no kids, because I'm self-centered. The resources to build out a version for married with a mortgage and 3 kids are linked from this post and the spreadsheets, so if you build one, please share.
Australians point out to me that healthcare in Australia has 2 major caveats:
- There is essentially a $500 annual deductible. That is, the first $1000 worth of care in a year you pay 50%; the remainder is on the government. However, there is a debate in which they are considering eliminating this deductible.
- Many Australians fret at the long waits for doctor's appointments and go to pricier doctors instead. When they do, they exceed the limits the government will reimburse. When that occurs, the government kicks in the maximum and you pay the rest. Often these private doctors charge about double. So there is an inconvenience to free care, and occasionally an undue lack of urgency. On the other hand, these private visits are often so expensive in part because they're lavish - they involve spa treatments etc.
I need to include a comparison to MY healthcare's caveats. I called my healthcare plan and this is literally what they told me - I'm not exaggerating what they said or misreading my plan. This is the plan I pay for with Anthem Blue Cross:
- If I have a heart attack, it's my job (yes, struggling in the hospital) to gather up the relevant paperwork and submit it to them as a claim.
- If it occurs overseas, not only is it my job to do that, but also to cover the full costs of coverage myself in the meantime, and they will optionally reimburse me for what they deem as covered.
Australians have to worry about a $500 deductible that may be legislated away. I have to worry about owing $500,000, how to gather what paperwork to send to who, what lawyer to sue my healthcare company with to recoup my costs, and whether I'll live long enough to see the court case through.
Tuesday, September 6, 2011
Challenge: Get Jobs Numbers in Real Time
E. J. Dionne of the Washington Post can be a bit Keith Olbermann in his rants, so read with a step back:
The Last Labor Day?
But he makes a great point: People too often view the stock market as the real measure of the economy. He notices that the President addresses it, that many news shows hold him and Congress accountable to it, and that many news stories treat a major turn in the stock market as though it were indicative of the entire economy.
He goes on to make the obvious point that this is not the case - the fact that less than 10% of the US population capable of seriously investing in the stock market are doing better or worse on average isn't very relevant to the economy as a whole. And if you take bubbles into account, the stock market can jump up and down with no relevance to the economy - it can even say things are going well when they're really falling apart.
What matters is employment as a whole - are people working, and what are they doing?
He points out that the stock market is used instead because it's available in real-time.
It seems ridiculous but I think he may have found a simple truth. Why DO we use the stock market, and not jobs numbers, as indicators of how the economy is doing? When we get stock numbers we can all check them in real-time, whether you're a citizen, reporter or the president: finance.google.com. But getting jobs numbers is a lot murkier, never real-time, and your access to those numbers varies based on where you work.
So it's time to pose a challenge to the American public. Who among us can build a real-time indicator for employment in the US?
Giving it some thought, the first step is reporting. The most obvious approach is to ask people to report they took or lost a job, but it's not likely to succeed. On the other hand, employers already do report in with several governmental agencies when they hire a worker. There's a significant amount of paperwork that generally has to be filed within a tight timeline of when the worker is hired. So there's your source of data.
The remaining steps are accessing it in aggregate, and offering it in real-time. What's the best way? Do we ask the Obama Administration to offer their existing numbers up over an API? Is there an existing database we can ask for read access to? What's the best way to do this?
Update:
Monthly isn't real-time, but Google has monthly US Employment in millions, and with a lag time of 2 years, the US population.
If you assume the US population is now 314 million, some math for August:
140 million employed / 314 million = 44.6% employed, or put another way, 55.4% of the population of the US does not work.
There's a pointless number provided by the US Dept of Labor on the size of the Labor Force, but they don't count those not actively looking for work/those who have given up, which is ridiculous. Not a useful statistic. If you did use that number you'd get what you occasionally hear on the news: 9% unemployment, or put another way, of the <50% of the US that seeks work, 9% of those aren't finding jobs.
The Last Labor Day?
But he makes a great point: People too often view the stock market as the real measure of the economy. He notices that the President addresses it, that many news shows hold him and Congress accountable to it, and that many news stories treat a major turn in the stock market as though it were indicative of the entire economy.
He goes on to make the obvious point that this is not the case - the fact that less than 10% of the US population capable of seriously investing in the stock market are doing better or worse on average isn't very relevant to the economy as a whole. And if you take bubbles into account, the stock market can jump up and down with no relevance to the economy - it can even say things are going well when they're really falling apart.
What matters is employment as a whole - are people working, and what are they doing?
He points out that the stock market is used instead because it's available in real-time.
It seems ridiculous but I think he may have found a simple truth. Why DO we use the stock market, and not jobs numbers, as indicators of how the economy is doing? When we get stock numbers we can all check them in real-time, whether you're a citizen, reporter or the president: finance.google.com. But getting jobs numbers is a lot murkier, never real-time, and your access to those numbers varies based on where you work.
So it's time to pose a challenge to the American public. Who among us can build a real-time indicator for employment in the US?
Giving it some thought, the first step is reporting. The most obvious approach is to ask people to report they took or lost a job, but it's not likely to succeed. On the other hand, employers already do report in with several governmental agencies when they hire a worker. There's a significant amount of paperwork that generally has to be filed within a tight timeline of when the worker is hired. So there's your source of data.
The remaining steps are accessing it in aggregate, and offering it in real-time. What's the best way? Do we ask the Obama Administration to offer their existing numbers up over an API? Is there an existing database we can ask for read access to? What's the best way to do this?
Update:
Monthly isn't real-time, but Google has monthly US Employment in millions, and with a lag time of 2 years, the US population.
If you assume the US population is now 314 million, some math for August:
140 million employed / 314 million = 44.6% employed, or put another way, 55.4% of the population of the US does not work.
There's a pointless number provided by the US Dept of Labor on the size of the Labor Force, but they don't count those not actively looking for work/those who have given up, which is ridiculous. Not a useful statistic. If you did use that number you'd get what you occasionally hear on the news: 9% unemployment, or put another way, of the <50% of the US that seeks work, 9% of those aren't finding jobs.
Tuesday, August 30, 2011
Overlearning the Game
A good article on politics and corruption:
Short on proposed solutions. Here are two:
1. The Severe/Ben Franklin approach: The founding fathers were in a time of revolution, and many were quoted as expecting more revolutions to occur that would throw out our Constitution in favor of an even better one in 50 years or so. With this you also throw out all the corruption of those who have not only "overlearned the game," but also those who have invested massive amounts of wealth to change society's rules so its wealth is diverted back to them. This seemed likely to those in the midst of a revolution, but not very likely to us, and, well... what would happen to all my stuff?
2. The Gradual/Videogame Cheater approach: Game authors attempting to fight cheating fight on a naive technical front first, and later a complex behavioral front second. The technical front is like many of the basics of campaign finance laws, like "You can't pay people to vote for you." The obvious hacks. But you eventually realize you're not really trying to stop obvious hacks, you're trying to stop creative, insidious ones too. So you model good behavior, and basically treat everything outside of it as cheating. The challenge is to include modeling very strong performance in that model so you don't risk punishing it if it arises legitimately.
Google is arguably working against SEO entities who "overlearn the game" and either google bomb or push their company's result to the top. The big difference between Google/Videogame companies and law is how nimble they are. The companies acknowledge there will be cheaters and have teams to quickly respond to new workarounds for the system. The law sits idle and a big messy Congress that can be corrupted by cheaters themselves is in charge of fixing it, in a really ugly process. Arguably Congress should continue to set the broad strokes like "Prevent campaign finance abuse," but a nimble more company-like organization within the government ought to be responsible for implementing that and quickly responding to new abuses.
Wall Street actually has a limited version of this model - the SEC is not an elected body - but it's somewhat limited in scope, and impotent when for example its powers are delegated to the OMB when it comes to Collateral Debt Obligations, and down comes the world economy.
I think Congress might be suited to setting the powers more broadly and the metrics for success on these nimble organizations, but they definitely aren't suited to creating the laws that actually trap the cheaters. They're just too slow, by design.
Thursday, August 11, 2011
No Student Loans for Low-Pay Degrees
In 2015, if a private college can't show that at least 35% of graduates with a given degree can pay back their loans, students entering that major won't be eligible for student loans. Pretty smart program.
Not surprisingly, private colleges are upset about it - they want that free money to keep people entering majors they know don't lead many kids to successful careers.
It would be nice if a law went farther, and required students entering a major or considering majors to be informed of:
- Average employment rate
- Average employment rate within the chosen field
- Average salary in 1 year and 5 years
- Average time to repay
- Average delinquency rate
Saturday, March 26, 2011
Health Insurance Needs Consumer Testing Legalized
Right now, if you were to file a test claim with your insurance company to verify they'd actually fill it if you got cancer, they'd be able to sue you for a substantial amount of money - even if you gave the claim money back in say, three days, just to verify they really followed-through on their promises. That needs to change.
A mattress salesman once told me that a mattress typically sells for 3-4x what it costs, and that for the most part, none of them are very good. Often people pay extra for features they don't understand or need. Compare this to groceries at the grocery store. These goods arrive and are sold for razor thin margins - and the quality tends to be very high.
So why are mattresses expensive low-quality items, and groceries nice things you buy for very little? Frequency. You buy groceries over and over, so when you go to buy an apple or a can of beans next time, you have a strong idea of the value you're getting. You also buy them so often that each time you go to purchase them, you can go to a different vendor to look for better prices, and better quality goods. Each purchase is a chance to optimize the cost and quality of the product in your favor, and better informs you of the relative value you're getting.
Obviously a mattress is the opposite. Someone buying a mattress is unlikely to ever come back. You buy mattresses so rarely you don't really know what to look for in one mattress to the next. You also have essentially no concept of what a "good" price for a mattress is, because you have very little experience buying them. As market forces go, the value is going to tend to be low and the price high because the consumer is inexperienced at making this purchase. In summary, the frequency with which consumers buy and receive a product has a linear correlation with the value delivered for cost.
So now let's consider health insurance. Health insurance may be a perversion of this model. In some ways, health insurance is similar to groceries - many health claims pay out in small ways frequently, like covering a simple doctor's visit. But these small claims generally don't add up to enough to account for the premiums you pay in. These are not what you're actually paying for, and if you were, you'd be easily able to shop around for something a lot cheaper than the typical cost of health insurance.
What you're paying for is calamity protection. Cancer, a car accident with broken limbs, a life-threatening disease - something that puts you in the hospital. Fortunately, this happens to you infrequently. Yet unfortunately, that means the value for the money spent is also delivered to you infrequently. This means that you don't know what you're going to get. You probably don't even know how much say, a week in the hospital would cost - or 3 months of cancer treatment.
The worst case scenario for the market economy model is one where the only time the consumer's promise comes due is a time when they are at their absolute worst to demand it. It's really horrible to think about, but when an insurance company is barely scraping by and someone who has 3 months to live files for a massive claim the company can't afford, what if the insurance company just delays payment? The patient is more likely to die and both the risk of lawsuit and the risk of additional claims filed goes away. The insurance company has every economic reason to act against the consumer. How often this occurs is something I'll leave to others, but what's clear is a really awful incentive exists in this very specific scenario for this very specific product - just about as far from the grocery-buying scenario as you can get.
So what we need is to be able to get that value tested more often. You'll never be able to test health insurance as often as you verify the value of the apples at your local grocer, but we could bring market forces back into alignment if we make it legal for any journalist, or everyday citizen who wants to play the role of one, to test their insurance for calamity protection. Here's my proposal:
Any false medical insurance claim filed with the intent of testing one's insurance is not insurance fraud. If a test claim is paid in full, the payment must be returned within 3 days of the final portion of the claim payment being completed, or the claim returns to being treated as insurance fraud.
You might be saying, what if we suddenly had a deluge of fraudulent claims and people just kept the money? Well, this doesn't make it OK to keep the pay out - it makes it OK to file a claim while you're healthy and able to follow all the paperwork and hurdles before you, and then if the insurer ever pays out - give it back. Keeping it for longer than 3 days leaves you with existing law and today's existing situation - and today there is insurance fraud, but nothing so out of control that the industry can't keep up with it.
Second, you might say this risks people filing these sorts of claims in order to obtain a large 3-day loan. This is a somewhat obscure possibility, but consider that typically a medical insurance claim doesn't actually get paid to the patient - it gets paid to the medical service providers that performed the work. So to turn this into a useful 3-day loan, a medical services provider would need to convince a patient to file a test claim. It is possible that a shady doctor or hospital might do so - so let's add a clause that adds fines for such coercion:
Any medical provider who financially benefits from coercing a health insurance consumer into performing a test claim is subject to a fine triple the financial gain they accrued.
Finally, you might worry that consumers do this en masse and the number of claims filed with insurers doubles. But what's the incentive? If something is difficult, it doesn't happen very often. Coordinating an authentic-looking test claim to test the insurers is going to require a lot of coordination. A lot of fake paperwork is going to have to travel from multiple service providers to the insurance companies, and part of that coordination is that they're going to have to return their share of the payout. It's likely that only a well-organized existing group like Dateline could even put this together, but the door is left open for a very intrepid consumer who wants to test their insurance (and has quite a bit of time on their hands) can do so as well. Nonetheless, we should limit these to a reasonable level to prevent unforeseen consequences - let's add a limit clause:
Any beneficiary of test claims may not participate in more than 4 per year, paid or unpaid. Test claims in excess of this limit are fraud.
Market economies work best when the consumer can verify the value of what they buy often. Government works best when it intervenes only in case of an exception - of a dispute. This proposed law lets consumers, rather than government watchdogs, verify their own purchase's validity anytime they're willing to put in the work, and only if they keep the money or the insurer breaks their promises does the government have to get involved (via a lawsuit in either direction). So let's get a law in place that lets healthy people test their insurance - before they're too sick to fight.
Subscribe to:
Posts (Atom)



