Showing posts with label privacy. Show all posts
Showing posts with label privacy. Show all posts

Sunday, May 4, 2025

AI Users Bill of Rights

[A person sitting comfortably in an easy chair, protected by a force field that is holding numerous helpful robots from delivering food and other services.]

We are surrounded by too much helpful AI trying to insinuate itself into our lives. I would like the option of leaving “AI” tech turned off and invisible, though that's getting harder and harder.

I've drafted a draft version 1 of a bill of rights for humans who want the option to stay in control. Text in green is not part of the proposal. It is instead rationale or other metadata.

AI Users Bill of Rights
DRAFT, Version 1

  1. All use of “AI” features must be opt-in. No operating system or application may be delivered with “AI” defaultly enabled. Users must be allowed to select the option if they want it, but not penalized if they do not.

    Rationale:

    1. Part of human dignity is being allowed freedom of choice. An opt-out system is paternalistic.
    2. Some “AI” systems are not privacy friendly. If such systems are on by default until disabled, the privacy damage may be done by the time of opt-out.
    3. If the system is on by default, it's possible to claim that everyone has at least tried it and hence to over-hype the size of a user base, even to the point of fraudulently claiming users that are not real users.
  2. Enabling an “AI” requires a confirmation step. The options must be a simple “yes” or “no”.

    Rationale:

    1. It's easy to hit a button by accident that one does not understand, or to typo a command sequence. Asking explicitly means no user ends up in this new mode without realizing what has happened.
    2. It follows that the “no” may not be something like “not now” or any other variation that might seem to invite later system-initiated inquiry. Answering “no” should put the system or application back into the state of awaiting a user-initiated request.
  3. Giving permission to use an AI is not the same as giving permission to share the conversation or use it as training data. Each of these requires separate, affirmative, opt-in permissions.

    Rationale:

    1. If the metaphor is one of a private conversation among friends, one is entitled to exactly that—privacy and behavior on the part of the other party that is not exploitative.
    2. Not all “AI” agents in fact do violate privacy. By making these approvals explicit, there is a user-facing reminder for the ones that are more extractive that more use will be made of data than one may want.
  4. All buttons or command-sequences to enable “AI” must themselve be possible to disable or remove.

    Rationale:

    1. It may be possible for someone to enable “AI” without realizing it.
    2. It is too easy to enable “AI” as a typo. Providers of “AI” might even be tempted to place controls in places that encourage such typos.
  5. No application or system may put “AI” on the path to basic functionality. This is intended to be a layer above functionality that allows easier access to functionality in order to automate or speed up certain functions that might be slow or tedious to do manually.

    Rationale:

    1. Building this in to the basic functionality makes it hard to remove.
    2. Integrating it with basic functionality makes the basic functionality hard to test.
    3. If an “AI” is running erratically, it should be possible to isolate it for the purposes of debugging or testing.
    4. When analyzing situations forensically, this allows crisper attribution of blame.

With this, I hope those of us who choose to live in the ordinary human way, holding “AI” at bay, can do so comfortably.

 


Author's Notes:

If you got value from this post, please “Share” it.

The graphic was created at Abacus.ai using Claude Sonnet 3.7 and Flux 1.1 Ultra Pro, then cropped and scaled using Gimp.

Monday, March 18, 2024

Impersonal Politics

For years, corporate and political marketeers have been committing a predictable and painful set of offenses under the fraudulent banner of “personalization”. After uncountably many tons of direct mail heaped upon me over the years, it's time to direct a few remarks back at them. The “you” I'm addressing here are the people committing these unbearable acts, especially in political mailings, not the myriad others of us who endure them.

It's easy to throw a lot of smart tech at things and think you've done something wondrous to cultivate a relationship with mass numbers of people. You have not. There is nothing personal about mass mailings. You may be hoping AI will soon fix that. It won't. Let's just say that right up front by making that point number one in the list of points I have to make:

  1. Knowing something personal about me like email or that I gave you money or that I didn't give money recently is abuse of privacy, not personalization. You'll know when you have personal information or a personal relationship because I will have been personally involved in establishing it.

    And, no, you calling me on the phone and getting me to answer personally is not me establishing it. It's just you making unauthorized second-hand use of a phone number I almost certainly gave you (or more likely someone else that I mistakenly thought I could trust) for a very different purpose. Doing this does not make us friends. It makes me instantly unlikely to trust you and it makes me regret trusting whoever I gave the phone number to originally. That they saw selling my personal data as a revenue source makes them absolutely no friend of mine.

    Having a bot, instead of a person, call me on the phone with a rude and impersonal agenda will not improve that. Technology is not a fix for social problems, only a force multiplier.

  2. Interest is opt-in. Making it opt-out breeds strong antipathy.

    Ask yourself how you'd feel by if someone just started using the trash cans outside your house for disposing of their trash and left you a “helpful” note on the cans telling you that if you didn't like it, you were welcome to drive across town and stop by their office to ask them not to. That isn't in fact helpful, puts a large burden on the person being taken advantage of, and would not be well-received. But it's basically the same kind of thing as people are doing when they fill your mailbox with unwanted mail that you haven't asked for.

  3. People donating small bucks are not pledging undying interest. Read what your own call for donations says. It almost surely requested help “at this critical moment” not “now and forever after.”

    Notice further that I was probably offered a box saying “one-time contribution” and checked that in preference to even a “monthly” contribution. Ask yourself then whether it's really likely that if I didn't want monthly, it was because I wanted to give more money the same day, or the next day, or any time within that month.

    Now also look at the address you probably harvested with the donation. Is it out-of-state? Ask yourself whether that makes it more likely or less likely that I am serious about the “one-time” thing and whether my mailbox should have anything in it but a thank you for at least a month, if not for the entire election cycle. Seriously. I know where to find you if I need to donate more.

  4. Speaking of people who are contributing from out of state: In most cases these are not your constituents. Shouldn't you speak to them differently than the people you actually represent? If you don't realize this, you're not as much my best pal as you imagine.

    Make a template that's different for non-constituents/out-of-staters, one that reminds people who in the world you are, and one that gets used far less often—preferrably only in true emergencies. Just the process of putting yourself in this other frame of mind, of realizing these are different people with different goals, should be instructive to you.

  5. Message fatigue is a serious risk. It can't be a crisis every day without becoming just normal. No one can sustain a crisis mentality. If you're not going to be honest about what is and is not a real crisis, no one will believe you forever after. Is that in fact what you want?

    Did you never read The Boy Who Cried Wolf in school? It's supposed to be a really basic aspect of the socialization of human beings everywhere. We are asked to learn at a young age to be respectful of others' need for you to prioritize your requests and concerns so as not to overwhelm them. Do you think yourself exempt?

  6. Have you done the math? If I only gave you a one-time donation of $10, do you really think I have $3650 secretly allocated to help you and just need to be manually poked with a stick each and every day to pony up the next $10 installment for 365 days a year???

    Extra Credit: How many of your donors have $3650 in surplus cash at all for anything, much less for your one political race. (Hint: If the answer is a large number, you are not listening to ordinary voters at all.)

  7. Some people use email addresses where they can receive mail but from which they cannot initiate mail. If your unsubscribe needs me to send from the unsubscribe address and I have given you such an address, it may be that I can never unsubscribe. Do you think that, locked in that unstoppable flood of unwanted mail, I will ever think well of you again?

  8. Mailed out surveys, whether by email or physical mail, are a dead concept.

    With 98% likelihood, if I fill out a survey, it will be ignored and all you'll care about is the money you ask for on the last page.

    You, political marketeers, have killed surveys for any useful purpose ever because only those planning to donate will fill them out, so you have no representative sample.

    If you tout survey results as meaningful, you are misleading people either stupidly or willfully.

  9. We recipients of excess political email are a tragedy of the commons, completely worn out by overuse. You are hurting not just yourself, but the hopes of others.

This is probably not a complete list. But these issues matter a lot.


If you got value from this post, please “Share” it.

This post is a slightly modified version of a rant I wrote Thursday (March 14, 2024) on Mastodon. I have, as they say, revised and extended my remarks. But it started from there.

Saturday, May 15, 2021

Children of the Information Era

[Image of a sign that says 'You must be at least this tall to lose your privacy.']

“Now you see it … Now You don't.”

Probably most people know, because so many web sites ask about it when you register, that there is special protection on the web for US children under the age of 13. Quoting the FTC's explainer page on the Children's Online Privacy Protection Rule ("COPPA"):

“COPPA imposes certain requirements on operators of websites or online services directed to children under 13 years of age, and on operators of other websites or online services that have actual knowledge that they are collecting personal information online from a child under 13 years of age.”

So we in the US have a sort of right to privacy on the web. OK, not a right, exactly, but at least a strong law. But there's just one small hitch: it expires as we get older. What is that about?

Why should it be OK for that right to go away as we get older. Whose interest does that serve? Certainly not mine. What kind of values are encoded here? What message does that send?

I'm sure this was sold to Congress, and then to the American people, under the tried and true “for the children” banner and that lawmakers didn't stop to think very hard about how much many of us adults would have loved to have at least the option of similar protection.

But it was not to be.

Why?

Ethics and Technology

People like me who've watched and rewatched Star Trek for decades are regularly reminded, as one of its common themes, that technology and wisdom need to move hand in hand. When technology gets ahead of wisdom, bad things happen. But Star Trek mostly takes place in the 23rd and 24th centuries.

Ethics has had a very hard time in our 20th and now 21st century technological society. Really there's very little ethics built into anything technological. There's an explanation for that and it comes in two steps.

Early on, technologists anxious to explore a topic insist it would “hold back progress” to weigh them down with ethical concerns, as if the worst thing in the world would be having to think about the impact of technology on society.

Later, if you try to apply ethics to a more mature technology, the punch line of the joke on us is trotted out: It's too late. “It would be disruptive to the market” to impose ethics—now that the market is used to doing to us whatever it's doing that profits someone.

Growing Up in the Information Era

Of course there's another possible explanation for why this privacy “right” goes poof and vanishes at age 13: By that age we have “grown up.”

We'll ignore for the moment that 13 is not the ordinary line between childhood and adulthood. But probably some business somewhere stood to lose too much money if we drew the line between childhood and adulthood in the right place. Though I'm sure the official party line was that kids needed time to swim in the deep end while there were still adults around to help them. Or something like that.

I'm not buying any such sophistry, though.

After all, what is adulthood? Why do we even make a distinction in society between how we treat children and how we treat adults?

Wikipedia suggests this about adulthood:

“In contrast to a ‘minor’, a legal adult is a person who has attained the age of majority and is therefore regarded as independent, self-sufficient, and responsible.”

Implicit in this is the notion that there are people—often but not necessarily parents, but usually at least other adults—training one for this role of independence, of self-sufficiency, of responsibility. And why? Well, because they've been around awhile. They're native guides familiar with how adulthood plays out. They can tell children what to watch out for because they've lived in the adult world for a whlie and have seen the pitfalls.

And that's the problem. This theory might work OK for learning to drive a car. Cars change a little each year, but mostly driving a car is the same today as it was decades ago, hopefully a little safer. Adults know what to teach kids about driving a car because they've done it awhile. They know the landscape.

But the information landscape is just different. You may give up a piece of information, like your location, and think it quite benign. It's never caused you a problem before. But there are people whose job it is to infer new information all the time from old information. That data is a treasure chest for companies to mine, so the implications of giving it away are not known to your parents. They maybe, if they're really paying attention, know what a given piece of information was used for in the past, but every day there are new things being inferred. Not just new ways to track us in the future, but new ways to understand data already obtained.

I'll say it this way to be most clear: There are no adults in the information society. There is no one who can take their lifetime, or even their last 20 years, and tell you what the next 20 years will feel like. Society has always changed from generation to generation, but it's happening faster and faster, to the point that we are really all just children, bumbling our way through the implications of the world that is being re-made before us. There are not a lot of adults with worked experience in the information age they can share with their children, not really. Not in the sense that there are adults who can help kids learn to cook dinner or play a piano or drive.

We are all children in the rapid-paced world of information that dominates today. There are effectively no adults who have lived this life before and are competent to prepare the next generation for that role. The informational life that any previous generation lived is a life that has already vanished by the time the next generation comes along.

The right to informational privacy should not expire as we grow up because there's no sense in which we can usefully reach “informational maturity” until we change the aspect of society in which we're willing to let technology far outpace wisdom, with ethics left far behind, lost in the dust.

Given that we are all really just children in this information era, adulthood not an easily attainable concept, we all deserve the protections that we today afford only to those under age 13. Our right to privacy should not suddenly expire.

Control at some point should pass from parent to child, but it should not just pass to the market. We should demand to hold it ourselves for our entire lifetime.

 


Author's Notes:

If you got value from this post, please “Share” it.

The graphic image was produced using a couple of images I made with abacus.ai using RouteLLM and FLUX 1.1 [pro] Ultra, then post-processed fairly substantially in Gimp.

With apologies to little people, it refers to height rather than age in the image not because I'm confused about the fact that height doesn't always indicate age, but because it is common in theme parks for a sign measuring height to be offered as the criterion, so I thought the graphic would be most familiar. But also, and importantly, the whole point of this article is that it's a completely arbitrary and inappropriate thing that privacy disappears with age, rather than by some other more rational criterion, such as personal choice to either be private or not. Age is a terrible indicator. So, in a sense, the arbitrariness of this choice in the image matches the arbitrariness of the topic. It's my hope that this doesn't offend anyone. Art makes complex choices sometimes.

Saturday, February 12, 2011

Using Real Names has Real Consequences

I post under my own name, but I do it with a consciousness of the risk.

I've been on the net (it was the ARPANET then) since 1977. At that time, we actually had user profiles with a place to supply your social security number, and people often complied because there was no reason to suppose it was dangerous. Those were certainly different times. People today are often horrified as they look back at the practices of those days, but everyone's sensibilities were different then. At some point we noticed that there was danger in having such information out in the open, so the data was erased and the ability to attach it was removed. But initially we were more trusting.

I had an unofficial administrative position on one of these machines as member of a group called “user-accounts” that oversaw guest usage of the machine. Guest users were called “tourists.” They were tolerated on the system as long as they didn't interfere with real work, but sometimes we had to disable an existing account or deny an application for an account if we suspected a potential for problems.

Having their accounts turned off didn't always make people happy. The first time I ever found myself quoted by someone on a web page in the early web, it was a remark quoted out of context from my time as a user-accounts member, where I'd once said in email, “[It] would have taken hours to be fair and we're not employed to do that sort of thing.” You can imagine that kind of attitude upsetting this or that person. In fact, in its proper context, the thing to understand is that we already went to extraordinary lengths to be fair to tourists, spending sometimes hours of unpaid time to make sure we didn't do anyone an injustice. But at some point there was just a limit where we had to just guess.

Life in the digital world is not a certainty, and an entire lab of real research at MIT depended on things operating properly. Just one act of devastation by a tourist on our largely unprotected and highly trusting system would have brought down the entire tourist program, and could have jeopardized research funding for the Lab. It was no small matter. So sometimes we just made arbitrary decisions, and tourists sometimes just had to live with them.

It happened one time, however, that someone was so annoyed by something I'd done that in retaliation he ended up performing an act that I'll describe here simply as “having a real world effect.” It really doesn't matter what the act was, and I don't want to give anyone ideas of mean things to do to someone. We'll just say it was more destructive than just sending an annoyed email, and that it involved the use of real world personal information about me in a way that was not proper. It was a sufficiently invasive act that there may well be a law against it now. Maybe there was a law then, too, but I didn't pursue it legally. My point, though, is that it made me conscious of the fact that not everyone “out on the net” was a nice person, and conscious in a personal, tangible way of the fact that sharing information, even information people have been accustomed to sharing since long before computers, isn't always harmless.

My favorite quote on privacy comes from John Gilmore's remarks to the First Conference on Computers, Freedom, and Privacy in San Francisco 1991, which I had the good fortune to attend. He said:

Society tolerates all different kinds of behaviour -- differences in religion, differences in political opinions, races, etc. But if your differences aren't accepted by the government or by other parts of society, you can still be tolerated if they simply don't know that you are different. Even a repressive government or a regressive individual can't persecute you if you look the same as everybody else. And, as George Perry said today, "Diversity is the comparative advantage of American society". I think that's what privacy is really protecting.

And that brings me to the claim that life would somehow be better if people blogged under their real name—if there were no pseudonyms. The underlying claim, not always expressed explicitly, is that eliminating pseudonyms would make people more polite and/or more accountable. I disagree that it would, even if it did, I don't think the cost is worth the value.

First, there is the question of whether you need to know who a speaker is in order to evaluate truth. I don't think you do. Maybe once in a while. Wikipedia is a monument to this because although you can find out who wrote what in there if you dig really hard, most of the truth that is in there is best verifiable by going and testing to cited references, not by going to who wrote it and by testing their character. If who said it mattered, then they might as well throw out the content after about 100 years since all of the people who've contributed will be dead and there will be no one to validate the content.

Second, the claim that having a publicly known name leads to better accountability is bogus. It's maybe okay if what we mean by “accountable” is exposed to personal whims of literally any individual on the net. But then how is that person accountable? In order to make everyone “accountable” for their speech, the claim seems to be that we should expose them to unbounded real world risk. I don't know about you, but that doesn't seem like much of a solution to me.

And while in most cases it may matter that people are accountable for what they say, consider the case where a patriot needs to speak out against an oppressive government. Before we claim that in all cases we want those willing to speak out to suffer the consequences of doing so, let's remember that rules tolerating offensive speech are not there because we like offensive speech, but rather because sometimes, especially in politics, it's subjective what is offensive. And sometimes it's necessary to make people feel uncomfortable in order to promote change. If governments or even just businesses always knew who was speaking, there might be no way to discuss certain things very critical to all of our lives.

I don't know how much of the recent activity in Egypt required some form of anonymity or pseudonymity to accomplish, but it's not a serious stretch of the imagination to think that the events that recently unfolded might not have happened without some degree of protection for those speaking out. Certainly in the case of corporate whistleblowing, anonymity can be critical. When real world corporate or political power hangs in the balance, perturbing the lives of exposed individuals is well-known to be the cheap way to “fix” the “problem.”

Still, even for those cases that do need accountability, all that matters for accountability is that someone (e.g., an OS system administrator) could contact that person. It's just not necessary that every person in the reading audience know how to contact every writer, since it's not the right or responsibility of most people reading along to be imposing judgment or punishment.

There may indeed be some forums that are more pleasant when real names are used, but the price may be that those forums cannot carry the voices of our most vulnerable or our most controversial. It's worth keeping that cost in focus. There is some risk to words, but there is greater risk to people taking up sticks and stones to make their point. I'd rather see words encouraged over sticks and stones, even if the price is tolerating highly controversial speech.

We should be encouraging people to speak and to feel safe about doing so. Sometimes that requires actual anonymity, sometimes just pseudonymity. But certainly it should not mean that “real names” are always best.

If the words of an anonymous soul appear to be causing a problem, more than likely it's an indicator that we need to learn about how to read anonymous writings, not that we need to reform the production of anonymous writings.


Author's Note: Originally published February 12, 2011 at Open Salon, where I wrote under my own name, Kent Pitman.

Tags (from Open Salon): politics, privacy, accountability, writing, authorship, psuedonyms, pseudonymity, anonymity, anonymous, pseudonymous, safety, hacking

Sunday, November 7, 2010

The Legal and Ethical Issues in Suspending Keith Olbermann

Keith Olbermann's suspension from MSNBC on Friday brought 250,000 people out of the woodwork over this one weekend to sign a petition asking that he be reinstated.

Yesterday in my blog at Open Salon I did an analysis (On the Privacy of Political Campaign Contributions) making the claim that because human contributions are limited to a modest amount ($2400), it’s not realistically possible to unduly influence an election by making them and so they ought to be a private matter, out of the reach of employers to control. I also made the claim that because corporate contributions are potentially unlimited, that disclosure is quite important. It’s not the kind of simple rule people like, but then it comes because of that stupid legal person fiction.

Today I also did a big run-down on the grab bag of other issues I thought this suspension (MSNBC Ethical Theatre 2010). This basically takes the position that MSNBC is using the situation to try to appear more ethical than Fox (who gave $1M to the Republican Governors Association), saying they are strict with their employees about what can and cannot be given. But since the contribution is legal, I assert they’re just creating theatre that makes them look ethical. Which is a little weird since I think they are pretty ethical and have nothing to prove. Commenters on my blog post seem to think there's an internal feud at MSNBC.

Oddly, in a Google search for the Olbermann petition, this shows up alongside another petition that wants him fired for being a "maniac" and has 1316 signatures. See my article The Freedom to Hear if you want a guess on where I come down on that.