<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://cyber.harvard.edu/cyberlaw_winter10/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Jharrow</id>
	<title>Cyberlaw: Difficult Issues Winter 2010 - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="https://cyber.harvard.edu/cyberlaw_winter10/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Jharrow"/>
	<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cyberlaw_winter10/Special:Contributions/Jharrow"/>
	<updated>2026-09-26T18:43:07Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.43.6</generator>
	<entry>
		<id>https://cyber.harvard.edu/cyberlaw_winter10/?title=Cybersecurity_Project&amp;diff=1096</id>
		<title>Cybersecurity Project</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cyberlaw_winter10/?title=Cybersecurity_Project&amp;diff=1096"/>
		<updated>2010-01-29T21:33:45Z</updated>

		<summary type="html">&lt;p&gt;Jharrow: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&#039;&#039;Topic Owners: Mike, Jason, Ramesh, and Sheel&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Saying that cybersecurity is a &amp;quot;difficult problem&amp;quot; is like saying that reversing global warming is a difficult problem: it&#039;s true, but it doesn&#039;t quite capture how devilishly complicated and multifaceted the problem really is. There&#039;s no single reason why creating a more secure global network is so difficult; it in part has to do with the radically-distributed architecture of the Net, in part with some deep flaws computer software for both consumers and businesses, and in part from the network&#039;s sheer size and importance to our daily lives. (For more on this, see the nice [[Cybersecurity]] backgrounder.)&lt;br /&gt;
&lt;br /&gt;
Our group approached the problem not with the goal of inventing a panacea that would make all credit card transactions magically secure and make it impossible for hackers to [http://googleblog.blogspot.com/2010/01/new-approach-to-china.html compromise Gmail&#039;s security]. Instead, we wanted to offer suggestions with minimal implementation headaches and maximal benefit to users, from novices to experts. &lt;br /&gt;
&lt;br /&gt;
The final &amp;quot;product&amp;quot; of our month-long thinking on this issue begins with a reasonably short video overview of our ideas [http://www.vimeo.com/9036735 here,] (or see below), explains some of the details of our proposal, and also has an alpha-release Firefox plugin that you can download and try out (thanks to [http://www.elance.com/ Elance] for making the plugin possible, by the way).&lt;br /&gt;
&lt;br /&gt;
==Overview==&lt;br /&gt;
&lt;br /&gt;
We discussed this topic at length in an in-class presentation on January 19. [http://www.vimeo.com/9036735 This] 9-minute video summarizes and extends the presentation we gave that day. The details on this page elaborate on the proposals mentioned in the video.&lt;br /&gt;
&lt;br /&gt;
==Specific Proposals==&lt;br /&gt;
&lt;br /&gt;
===Public Service Announcement===&lt;br /&gt;
&lt;br /&gt;
We created a Public Service Announcement for generating public awareness for the cybersecurity problem, and showed it in class on January 19. It&#039;s online [http://vimeo.com/8937782 here] but is password-protected. Please email us if you were in the class and would like the password. &lt;br /&gt;
&lt;br /&gt;
The upshot of the video is that we don&#039;t think a direct public awareness campaign will be very effective. We believe it would be more productive to nudge users and change their behavior by altering the way browsers and websites work, not by scolding people in 30-second TV ads.&lt;br /&gt;
&lt;br /&gt;
===SafeWord===&lt;br /&gt;
&lt;br /&gt;
====What is SafeWord?====&lt;br /&gt;
&lt;br /&gt;
SafeWord is a real, working FireFox plugin designed to nudge users into keeping safer and more unique passwords, though it&#039;s too unstable and unrefined to be considered anything buy alpha software at this point. It&#039;s available for download [http://www.jasonharrow.com/safeword-1.0.0-fx.xpi here]. To install, save that file to your disk, select File --&amp;gt; Open in Firefox 3.5 or above, and install it. You will need to restart Firefox before it takes effect. Thanks to Elance for helping with the coding on very short notice.&lt;br /&gt;
&lt;br /&gt;
We have created a video demonstration of one of the key features of SafeWord [http://vimeo.com/9031865 here].&lt;br /&gt;
&lt;br /&gt;
====What Are The Goals of SafeWord?====&lt;br /&gt;
&lt;br /&gt;
SafeWord begins with a simple proposition: online passwords should be both strong and also different across different sites, and your browser should help you achieve that goal. Studies continue to show that most people use very simple passwords; see, for instance, [http://www.nytimes.com/2010/01/21/technology/21password.html this] &#039;&#039;New York Times&#039;&#039; article that gets right to the point. &amp;quot;If your password is 123456,&amp;quot; reads the headline, &amp;quot;just make it HackMe.&amp;quot; Moreover, most users also fall into the &amp;quot;dirty habit&amp;quot; of using the same password across multiple online accounts, which can lead to a disaster if only one of the accounts is able to be compromised. An extremely detailed analysis of a 2009 attack that used this principle to compromise many online accounts of Twitter employee is [http://www.techcrunch.com/2009/07/19/the-anatomy-of-the-twitter-attack/ here].&lt;br /&gt;
&lt;br /&gt;
====More on The Unique Password Feature====&lt;br /&gt;
&lt;br /&gt;
=====A Scary Story, and A Word About Annoyance=====&lt;br /&gt;
&lt;br /&gt;
Even readers who are all for stronger password security in general may nonetheless be skeptical of what can happen to &amp;quot;regular people&amp;quot; who can&#039;t be bothered to remember so many passwords. But here&#039;s a very scary story - which is taken directly from the [http://www.techcrunch.com/2009/07/19/the-anatomy-of-the-twitter-attack/ Twitter attack analysis] cited above - of what can happen if users employ the same password at multiple important sites:&lt;br /&gt;
&lt;br /&gt;
# HC [the hacker&#039;s alias] accessed Gmail for a Twitter employee by using the password recovery feature that sends a reset link to a secondary email. In this case the secondary email was an expired Hotmail account, he simply registered it, clicked the link and reset the password. Gmail was then owned.&lt;br /&gt;
# HC then read emails to guess what the original Gmail password was successfully and reset the password so the Twitter employee would not notice the account had changed.&lt;br /&gt;
# HC then used the same password to access the employeeâs Twitter email on Google Apps for your domain, getting access to a gold mine of sensitive company information from emails and, particularly, email attachments.&lt;br /&gt;
# HC then used this information along with additional password guesses and resets to take control of other Twitter employee personal and work emails.&lt;br /&gt;
# HC then used the same username/password combinations and password reset features to access AT&amp;amp;T, MobileMe, Amazon and iTunes, among other services. A security hole in iTunes gave HC access to full credit card information in clear text. HC now also had control of Twitterâs domain names at GoDaddy.&lt;br /&gt;
# Even at this point, Twitter had absolutely no idea they had been compromised.&lt;br /&gt;
&lt;br /&gt;
That&#039;s the danger, and it ain&#039;t pretty.&lt;br /&gt;
&lt;br /&gt;
On the other hand, we admit from installing SafeWord on our computer that the aspect of the program that requires you to use a different password for each new login is, well, pretty damn annoying. Complying with its demands to keep generating unique passwords might even require some old-fashioned tricks, like the creation of some sort of heuristic for generating memorable but unique passwords or keeping a card in your wallet to keep track of your various logins (and maybe even separating out parts of &#039;&#039;that&#039;&#039; list or keeping it encoded somehow). Still, we think that the cost/benefit analysis weighs in favor of life being just a little more annoying in this area, because as our scary story illustrates, there are &#039;&#039;&#039;lots&#039;&#039;&#039; of points-of-entry to our various accounts, and &#039;&#039;&#039;lots&#039;&#039;&#039; of random people out there who would love to hack those accounts for financial gain or to get their kicks.&lt;br /&gt;
&lt;br /&gt;
=====Why Do It This Way?=====&lt;br /&gt;
&lt;br /&gt;
There are other solutions out there that automatically generate secure, unique passwords for each site you visit; [https://lastpass.com/features_free.php LastPass] is a particularly nifty one. But they all share several key points of failure: they rely on a master password, and they store your passwords in the cloud. Relying on a master password is particularly problematic, because a compromise of that password can lead to the same disastrous chain of events that we are trying to prevent. The only way to truly reduce the risk of this type of threat is to decentralize everything. And if that takes encouraging people to work a little harder, we at least want to make people aware that this just might be worth the hassle. Similarly, there are problems with storing passwords in the cloud, including intruder problems and problems if the company goes out of business or the cloud becomes inaccessible.&lt;br /&gt;
&lt;br /&gt;
=====Extension v. Built-in Feature=====&lt;br /&gt;
&lt;br /&gt;
Initially, we hoped to build this extension to make a pitch to Mozilla that they should think about building this kind of functionality into the browser. But as we have used a now-working copy of SafeWord in our browsers - admittedly, it&#039;s an alpha copy that&#039;s not even close to ready for prime-time - at least one of us (i.e. jharrow) sees that it&#039;s just too intrusive for mainstream users. If the average, busy user gets a pop-up every time he comes across a new website and tries to use an old password, he will get angry at the browser. If this happens a few times, he will probably switch from Firefox to another browser. So right now, the idea works best as an extension for people who really believe in password security and want a little nudge when they are thinking of giving in to the instinct to just use the password they used last time. It will be supremely difficult to think of a solution in this area that can truly capture the masses and not be insufferably annoying.&lt;br /&gt;
&lt;br /&gt;
====More on the Stronger Password Feature====&lt;br /&gt;
&lt;br /&gt;
On the other hand, the idea of adding a feature that helps users create more secure passwords - even if they are reused across multiple accounts - is a simple fix that should enhance the browsing experience for most users.&lt;br /&gt;
&lt;br /&gt;
Increasingly, many websites are giving users some guidelines on password security. For instance, Yahoo!&#039;s sign-up page looks like this:&lt;br /&gt;
&lt;br /&gt;
[[Image:Yahoo.png]]&lt;br /&gt;
&lt;br /&gt;
We think that&#039;s great. But not all sites have that feature. For instance, you get no visual feedback if you sign-up for an Amazon account with a weak password:&lt;br /&gt;
&lt;br /&gt;
[[Image:Amazon1.png]]&lt;br /&gt;
&lt;br /&gt;
Your browser can change this state-of-affairs easily. Here&#039;s the new view, with a SafeWord bar underneath the password field reminding you that your password is weak:&lt;br /&gt;
&lt;br /&gt;
[[Image:Amazon2.png]]&lt;br /&gt;
&lt;br /&gt;
SafeWord even lets you customize the password strength options:&lt;br /&gt;
&lt;br /&gt;
[[Image:Amazon3.png]]&lt;br /&gt;
&lt;br /&gt;
We think something like this really could be built into the browser, and would both add to the user experience and increase security.&lt;br /&gt;
&lt;br /&gt;
===&amp;quot;Amber Alert&amp;quot; For The Internet===&lt;br /&gt;
&lt;br /&gt;
Even if websites invest a lot of time and effort into securing their servers and user data, few sites take a more systematic approach to cybersecurity and view the massive numbers of compromised user machines as as &amp;quot;their&amp;quot; problem; they don&#039;t have any ownership over the fact that so many computers are running nasty malware and are thus compromised in important ways that can cause systemic harm to the Internet (like, say, when a site is taken offline in a Distributed Denial-of-Service attack; a partial list of such incidents is [http://en.wikipedia.org/wiki/Denial-of-service_attack#Incidents here]). However, there are some promising signs [http://bits.blogs.nytimes.com/2010/01/13/facebook-joins-with-mcafee-to-clean-up-malware-on-site/ this] may be [http://stopbadware.org/home/pr_01252010 changing].&lt;br /&gt;
&lt;br /&gt;
Perhaps these initiatives can go even further. What if a coalition of leading Internet sites were willing to share certain information about security threats with a third party organization (like [http://stopbadware.org/home/index StopBadware]), and the third-party would vet the information and then issue certain &amp;quot;Amber Alerts&amp;quot; that all the sites would be willing to publicize in some way? When there&#039;s a particularly egregious security hole in an [http://en.wikipedia.org/wiki/Internet_Explorer_6 old browser], for instance, if all the leading websites actively encouraged its users to patch it, that has the potential to do a lot of good.&lt;br /&gt;
&lt;br /&gt;
We initially proposed this solution as a unilateral move that individual sites could make - Google, say, could warn its users about the vulnerabilities of Internet Explorer 6. But we&#039;ve realize that if the recommendations are filtered through a reliable third-party, perhaps the companies won&#039;t be threatened by the embarrassment of having an &amp;quot;Amber Alert&amp;quot; put out. Sure, there would be negative consequences for a company, just as a company who undertakes a product recall generates bad publicity. But ultimate the hope is that companies will realize the net positive value of this transaction, and that consumers will look kindly on companies promoting a new level of honesty and transparency.&lt;br /&gt;
&lt;br /&gt;
====Good Cyber-Samaritans====&lt;br /&gt;
&lt;br /&gt;
An idea we discussed on January 19 that was related to the &amp;quot;Amber Alert&amp;quot; system for websites involves empowering educated users to help out their less computer-savvy friends and neighbors with computer security problems just...because. Perhaps there could be a network of young people who think security is important and who don&#039;t mind hanging around their local library for a few hours helping people update software and patching security holes. This solution becomes ever-more feasible as a greater proportion of users switches to laptop computers and as projects showing that people are willing to assist strangers for the sheer fun and satisfaction of the experience - from building an [http://www.wikipedia.org encyclopedia] to giving them a [http://www.couchsurfing.org couch to crash on] for free - flourish. Relying on people&#039;s good natures could be a new way to make progress on this problem.&lt;/div&gt;</summary>
		<author><name>Jharrow</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cyberlaw_winter10/?title=Cybersecurity_Project&amp;diff=1095</id>
		<title>Cybersecurity Project</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cyberlaw_winter10/?title=Cybersecurity_Project&amp;diff=1095"/>
		<updated>2010-01-29T21:13:09Z</updated>

		<summary type="html">&lt;p&gt;Jharrow: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&#039;&#039;Topic Owners: Mike, Jason, Ramesh, and Sheel&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Saying that cybersecurity is a &amp;quot;difficult problem&amp;quot; is like saying that reversing global warming is a difficult problem: it&#039;s true, but it doesn&#039;t quite capture how devilishly complicated and multifaceted the problems really are. There&#039;s no single reason why creating a more secure global network is so difficult; it in part has to do with the radically-distributed architecture of the Net, in part with some deep flaws computer software, and in part just from its sheer size and importance to our daily lives. (For more on this, see the nice [[Cybersecurity]] backgrounder.)&lt;br /&gt;
&lt;br /&gt;
So we came in not with the goal of providing a magical elixir that would make all credit card transactions magically secure and make it impossible for hackers to [http://googleblog.blogspot.com/2010/01/new-approach-to-china.html compromise Gmail&#039;s security]. Instead, we wanted to offer suggestions with minimal implementation headaches and maximal benefit to users, from novices to experts. This page has a short video overview of the ideas, explains some of the details of our proposal, and even has an alpha-release Firefox plugin that you can download and try out (thanks to [http://www.elance.com/ Elance] for this, by the way).&lt;br /&gt;
&lt;br /&gt;
==Overview==&lt;br /&gt;
&lt;br /&gt;
We discussed this topic at length in an in-class presentation on January 19. [http://www.vimeo.com/9036735 This] 9-minute video summarizes and extends the presentation we gave that day.&lt;br /&gt;
&lt;br /&gt;
==Specific Proposals==&lt;br /&gt;
&lt;br /&gt;
===Public Service Announcement===&lt;br /&gt;
&lt;br /&gt;
We created a Public Service Announcement for generating public awareness for the cybersecurity problem, and showed in class on January 19. It&#039;s online [http://vimeo.com/8937782 here] but is password-protected. Please email us if you were in the class and would like the password. In sum, we don&#039;t think a direct public awareness campaign will be very effective. We want to nudge users and change their behavior by changing the way browsers and websites work, not by scolding people.&lt;br /&gt;
&lt;br /&gt;
===SafeWord===&lt;br /&gt;
&lt;br /&gt;
====What is SafeWord?====&lt;br /&gt;
&lt;br /&gt;
SafeWord is a real, working FireFox plugin designed to nudge users into keeping safer and more unique passwords, though it&#039;s too unstable and unrefined to be considered anything buy alpha software. It&#039;s available for download [http://www.jasonharrow.com/safeword-1.0.0-fx.xpi here]. To install, save that file to your disk, select File --&amp;gt; Open in Firefox 3.5 or above, and install it. You will need to restart Firefox before it takes effect. Thanks to Elance for helping with the coding on very short notice.&lt;br /&gt;
&lt;br /&gt;
We have created a video demonstration of one of the key features of SafeWord [http://vimeo.com/9031865 here].&lt;br /&gt;
&lt;br /&gt;
====What Are The Goals of SafeWord?====&lt;br /&gt;
&lt;br /&gt;
SafeWord begins with a simple proposition: online passwords should be strong and different for different sites, and your browser should help you acheie that goal. Studies continue to show that most users use very simple passwords; see, for instance, [http://www.nytimes.com/2010/01/21/technology/21password.html this] &#039;&#039;New York Times&#039;&#039; that gets right to the point. &amp;quot;If your password is 123456,&amp;quot; reads the headline, &amp;quot;just make it HackMe.&amp;quot; Moreover, most users also fall into the &amp;quot;dirty habit&amp;quot; of using the same password across multiple online accounts, which can lead to a disaster if only one of the accounts is able to be compromised. An extremely detailed analysis of a 2009 attack that compromised many online accounts of Twitter employees is [http://www.techcrunch.com/2009/07/19/the-anatomy-of-the-twitter-attack/ here].&lt;br /&gt;
&lt;br /&gt;
====More on The Unique Password Feature====&lt;br /&gt;
&lt;br /&gt;
=====A Scary Story, and A Word About Annoyance=====&lt;br /&gt;
&lt;br /&gt;
Even readers who are all for stronger passwords in general may nonetheless be skeptical of what can happen to &amp;quot;regular people&amp;quot; who can&#039;t be bothered to remember so many passwords, here&#039;s a very scary story - which is taken directly from the [http://www.techcrunch.com/2009/07/19/the-anatomy-of-the-twitter-attack/ Twitter attack analysis] cited above - of what can happen if users employ the same password at multiple important sites:&lt;br /&gt;
&lt;br /&gt;
# HC [the hacker&#039;s alias] accessed Gmail for a Twitter employee by using the password recovery feature that sends a reset link to a secondary email. In this case the secondary email was an expired Hotmail account, he simply registered it, clicked the link and reset the password. Gmail was then owned.&lt;br /&gt;
# HC then read emails to guess what the original Gmail password was successfully and reset the password so the Twitter employee would not notice the account had changed.&lt;br /&gt;
# HC then used the same password to access the employeeâs Twitter email on Google Apps for your domain, getting access to a gold mine of sensitive company information from emails and, particularly, email attachments.&lt;br /&gt;
# HC then used this information along with additional password guesses and resets to take control of other Twitter employee personal and work emails.&lt;br /&gt;
# HC then used the same username/password combinations and password reset features to access AT&amp;amp;T, MobileMe, Amazon and iTunes, among other services. A security hole in iTunes gave HC access to full credit card information in clear text. HC now also had control of Twitterâs domain names at GoDaddy.&lt;br /&gt;
# Even at this point, Twitter had absolutely no idea they had been compromised.&lt;br /&gt;
&lt;br /&gt;
It ain&#039;t pretty. &lt;br /&gt;
&lt;br /&gt;
We admit from installing SafeWord on our computer that the aspect of the program that requires you to use a different password for each new login is, well, pretty damn annoying. Complying with its demands to keep generating unique passwords might even require some old-fashioned tricks, like the creation of some sort of heuristic for generating memorable but unique passwords or keeping a card in your wallet with your various logins. But we think that the cost/benefit analysis weighs in favor of life being just a little more annoying in this area, because as our scary story illustrates, there are &#039;&#039;&#039;lots&#039;&#039;&#039; of ways in to our various accounts, and &#039;&#039;&#039;lots&#039;&#039;&#039; of random people out there who would love to hack those accounts for financial gain or to get their kicks.&lt;br /&gt;
&lt;br /&gt;
=====Why Do It This Way?=====&lt;br /&gt;
&lt;br /&gt;
There are other solutions out there that automatically generate secure, unique passwords for each site you visit; [https://lastpass.com/features_free.php LastPass] is a particularly nifty one. But they all share several key points of failure: they rely on a master password, and they store your passwords in the cloud. Relying on a master password is particularly problematic, because a compromise of that password can lead to the same disastrous chain of events that we are trying to prevent. The only way to truly reduce the risk of this type of threat is to decentralize everything. And if that takes encouraging people to work a little harder, we at least want to make people aware that this just might be worth the hassle.&lt;br /&gt;
&lt;br /&gt;
=====Extension v. Built-in Feature=====&lt;br /&gt;
&lt;br /&gt;
Initially, we hoped to build this extension to make a pitch to Mozilla that they should think about building this kind of functionality into the browser. But as I have a now-working copy of SafeWord in my browser - admittedly, it&#039;s an alpha copy that&#039;s not even close to ready for prime-time - I (i.e. jharrow) see that it&#039;s just too intrusive for mainstream users. If the average, busy user gets a pop-up every time he comes across a new website and tries to use an old password, he will get angry at the browser. If this happens a few times, he will probably switch. So right now, the idea works best as an extension for people who really believe in password security and want a little nudge. It will be supremely difficult to think of a solution in this area that can truly capture the masses.&lt;br /&gt;
&lt;br /&gt;
====More on the Stronger Password Feature====&lt;br /&gt;
&lt;br /&gt;
On the other hand, the idea of adding a feature that helps users create more secure passwords is a simple fix that should enhance the browsing experience for most users.&lt;br /&gt;
&lt;br /&gt;
Increasingly, many websites are giving users some guidelines on password security. For instance, Yahoo!&#039;s sign-up page looks like this:&lt;br /&gt;
&lt;br /&gt;
[[Image:Yahoo.png]]&lt;br /&gt;
&lt;br /&gt;
We think that&#039;s great. But not all sites have that feature. For instance, you get no visual feedback if you sign-up for an Amazon account with a weak password:&lt;br /&gt;
&lt;br /&gt;
[[Image:Amazon1.png]]&lt;br /&gt;
&lt;br /&gt;
Your browser can change that easily. Here&#039;s the new view, with a SafeWord bar underneath the password field reminding you that your password is weak:&lt;br /&gt;
&lt;br /&gt;
[[Image:Amazon2.png]]&lt;br /&gt;
&lt;br /&gt;
SafeWord even lets you customize the password strength options:&lt;br /&gt;
&lt;br /&gt;
[[Image:Amazon3.png]]&lt;br /&gt;
&lt;br /&gt;
We think something like this really could be built into the browser, and would both add to the user experience and increase security.&lt;br /&gt;
&lt;br /&gt;
===&amp;quot;Amber Alert&amp;quot; For The Internet===&lt;br /&gt;
&lt;br /&gt;
Even if websites invest a lot of time and effort into securing their servers and user data, few sites take a more systematic approach to cybersecurity and view it as &amp;quot;their&amp;quot; problem that so many computers are running nasty malware and are thus compromised in important ways that can cause systemic harm to the Internet (like, say, when a site is taken offline in a Distributed Denial-of-Service attack; a partial list of such incidents is [http://en.wikipedia.org/wiki/Denial-of-service_attack#Incidents here]). There are some promising signs [http://bits.blogs.nytimes.com/2010/01/13/facebook-joins-with-mcafee-to-clean-up-malware-on-site/ this] may be [http://stopbadware.org/home/pr_01252010 changing].&lt;br /&gt;
&lt;br /&gt;
We think these are encouraging signs, and they can go even further. What if a coalition of leading Internet sites were willing to share certain information about security threats with a third party organization (like [http://stopbadware.org/home/index StopBadware]), and the third-party would vet the information and then issue certain &amp;quot;Amber Alerts&amp;quot; that all the sites would be willing to publicize in some way? When there&#039;s a particularly egregious security hole in an [http://en.wikipedia.org/wiki/Internet_Explorer_6 old browser], for instance, if all the leading websites actively encouraged its users to patch it, that has the potential to do a lot of good.&lt;br /&gt;
&lt;br /&gt;
We initially proposed this solution as a unilateral move that individual sites could make - Google, say. But we&#039;ve realize that if the recommendations are filtered through a reliable third-party, perhaps the companies won&#039;t be threatened by the embarrassment of having an &amp;quot;Amber Alert&amp;quot; put out. Sure, there would be negative consequences for a company, just as a company who undertakes a product recall generates bad publicity. But ultimate the hope is that companies will realize the net positive value of this transaction, and that consumers will look positively at a new level of honesty and transparency.&lt;br /&gt;
&lt;br /&gt;
====Good Cyber-Samaritans====&lt;br /&gt;
&lt;br /&gt;
An idea we discussed on January 19 that was related to the &amp;quot;Amber Alert&amp;quot; system for websites involves educated users helping out their less computer-savvy friends and neighbors with computer security problems just...because. Perhaps there could be a network of young people who think security is important who don&#039;t mind hanging around their local library for a few hours helping people update software and patch their security holes. This solution becomes ever-more feasible as a greater proportion of users switches to laptop computers and as projects showing that people are willing to assist strangers - from building an [http://www.wikipedia.org encyclopedia] to giving them a [http://www.couchsurfing.org couch to crash on] for free - for the sheer fun and satisfaction of the experience. Relying on people&#039;s good natures could be a new way to make progress on this problem.&lt;/div&gt;</summary>
		<author><name>Jharrow</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cyberlaw_winter10/?title=Cybersecurity_Project&amp;diff=1094</id>
		<title>Cybersecurity Project</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cyberlaw_winter10/?title=Cybersecurity_Project&amp;diff=1094"/>
		<updated>2010-01-29T03:22:03Z</updated>

		<summary type="html">&lt;p&gt;Jharrow: /* Amber Alert For The Internet */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Saying that cybersecurity is a &amp;quot;difficult problem&amp;quot; is like saying that reversing global warming is a difficult problem: it&#039;s true, but it doesn&#039;t quite capture how devilishly complicated and multifaceted the problems really are. There&#039;s no single reason why creating a more secure global network is so difficult; it in part has to do with the radically-distributed architecture of the Net, in part with some deep flaws computer software, and in part just from its sheer size and importance to our daily lives. (For more on this, see the nice [[Cybersecurity]] backgrounder.)&lt;br /&gt;
&lt;br /&gt;
So we came in not with the goal of providing a magical elixir that would make all credit card transactions magically secure and make it impossible for hackers to [http://googleblog.blogspot.com/2010/01/new-approach-to-china.html compromise Gmail&#039;s security]. Instead, we wanted to offer suggestions with minimal implementation headaches and maximal benefit to users, from novices to experts. This page has a short video overview of the ideas, explains some of the details of our proposal, and even has an alpha-release Firefox plugin that you can download and try out (thanks to [http://www.elance.com/ Elance] for this, by the way).&lt;br /&gt;
&lt;br /&gt;
==Overview==&lt;br /&gt;
&lt;br /&gt;
We discussed this topic at length in an in-class presentation on January 19. [http://www.vimeo.com/9036735 This] 9-minute video summarizes and extends the presentation we gave that day.&lt;br /&gt;
&lt;br /&gt;
==Specific Proposals==&lt;br /&gt;
&lt;br /&gt;
===Public Service Announcement===&lt;br /&gt;
&lt;br /&gt;
We created a Public Service Announcement for generating public awareness for the cybersecurity problem, and showed in class on January 19. It&#039;s online [http://vimeo.com/8937782 here] but is password-protected. Please email us if you were in the class and would like the password. In sum, we don&#039;t think a direct public awareness campaign will be very effective. We want to nudge users and change their behavior by changing the way browsers and websites work, not by scolding people.&lt;br /&gt;
&lt;br /&gt;
===SafeWord===&lt;br /&gt;
&lt;br /&gt;
====What is SafeWord?====&lt;br /&gt;
&lt;br /&gt;
SafeWord is a real, working FireFox plugin designed to nudge users into keeping safer and more unique passwords, though it&#039;s too unstable and unrefined to be considered anything buy alpha software. It&#039;s available for download [http://www.jasonharrow.com/safeword-1.0.0-fx.xpi here]. To install, save that file to your disk, select File --&amp;gt; Open in Firefox 3.5 or above, and install it. You will need to restart Firefox before it takes effect. Thanks to Elance for helping with the coding on very short notice.&lt;br /&gt;
&lt;br /&gt;
We have created a video demonstration of one of the key features of SafeWord [http://vimeo.com/9031865 here].&lt;br /&gt;
&lt;br /&gt;
====What Are The Goals of SafeWord?====&lt;br /&gt;
&lt;br /&gt;
SafeWord begins with a simple proposition: online passwords should be strong and different for different sites, and your browser should help you acheie that goal. Studies continue to show that most users use very simple passwords; see, for instance, [http://www.nytimes.com/2010/01/21/technology/21password.html this] &#039;&#039;New York Times&#039;&#039; that gets right to the point. &amp;quot;If your password is 123456,&amp;quot; reads the headline, &amp;quot;just make it HackMe.&amp;quot; Moreover, most users also fall into the &amp;quot;dirty habit&amp;quot; of using the same password across multiple online accounts, which can lead to a disaster if only one of the accounts is able to be compromised. An extremely detailed analysis of a 2009 attack that compromised many online accounts of Twitter employees is [http://www.techcrunch.com/2009/07/19/the-anatomy-of-the-twitter-attack/ here].&lt;br /&gt;
&lt;br /&gt;
====More on The Unique Password Feature====&lt;br /&gt;
&lt;br /&gt;
=====A Scary Story, and A Word About Annoyance=====&lt;br /&gt;
&lt;br /&gt;
Even readers who are all for stronger passwords in general may nonetheless be skeptical of what can happen to &amp;quot;regular people&amp;quot; who can&#039;t be bothered to remember so many passwords, here&#039;s a very scary story - which is taken directly from the [http://www.techcrunch.com/2009/07/19/the-anatomy-of-the-twitter-attack/ Twitter attack analysis] cited above - of what can happen if users employ the same password at multiple important sites:&lt;br /&gt;
&lt;br /&gt;
# HC [the hacker&#039;s alias] accessed Gmail for a Twitter employee by using the password recovery feature that sends a reset link to a secondary email. In this case the secondary email was an expired Hotmail account, he simply registered it, clicked the link and reset the password. Gmail was then owned.&lt;br /&gt;
# HC then read emails to guess what the original Gmail password was successfully and reset the password so the Twitter employee would not notice the account had changed.&lt;br /&gt;
# HC then used the same password to access the employeeâs Twitter email on Google Apps for your domain, getting access to a gold mine of sensitive company information from emails and, particularly, email attachments.&lt;br /&gt;
# HC then used this information along with additional password guesses and resets to take control of other Twitter employee personal and work emails.&lt;br /&gt;
# HC then used the same username/password combinations and password reset features to access AT&amp;amp;T, MobileMe, Amazon and iTunes, among other services. A security hole in iTunes gave HC access to full credit card information in clear text. HC now also had control of Twitterâs domain names at GoDaddy.&lt;br /&gt;
# Even at this point, Twitter had absolutely no idea they had been compromised.&lt;br /&gt;
&lt;br /&gt;
It ain&#039;t pretty. &lt;br /&gt;
&lt;br /&gt;
We admit from installing SafeWord on our computer that the aspect of the program that requires you to use a different password for each new login is, well, pretty damn annoying. Complying with its demands to keep generating unique passwords might even require some old-fashioned tricks, like the creation of some sort of heuristic for generating memorable but unique passwords or keeping a card in your wallet with your various logins. But we think that the cost/benefit analysis weighs in favor of life being just a little more annoying in this area, because as our scary story illustrates, there are &#039;&#039;&#039;lots&#039;&#039;&#039; of ways in to our various accounts, and &#039;&#039;&#039;lots&#039;&#039;&#039; of random people out there who would love to hack those accounts for financial gain or to get their kicks.&lt;br /&gt;
&lt;br /&gt;
=====Why Do It This Way?=====&lt;br /&gt;
&lt;br /&gt;
There are other solutions out there that automatically generate secure, unique passwords for each site you visit; [https://lastpass.com/features_free.php LastPass] is a particularly nifty one. But they all share several key points of failure: they rely on a master password, and they store your passwords in the cloud. Relying on a master password is particularly problematic, because a compromise of that password can lead to the same disastrous chain of events that we are trying to prevent. The only way to truly reduce the risk of this type of threat is to decentralize everything. And if that takes encouraging people to work a little harder, we at least want to make people aware that this just might be worth the hassle.&lt;br /&gt;
&lt;br /&gt;
=====Extension v. Built-in Feature=====&lt;br /&gt;
&lt;br /&gt;
Initially, we hoped to build this extension to make a pitch to Mozilla that they should think about building this kind of functionality into the browser. But as I have a now-working copy of SafeWord in my browser - admittedly, it&#039;s an alpha copy that&#039;s not even close to ready for prime-time - I (i.e. jharrow) see that it&#039;s just too intrusive for mainstream users. If the average, busy user gets a pop-up every time he comes across a new website and tries to use an old password, he will get angry at the browser. If this happens a few times, he will probably switch. So right now, the idea works best as an extension for people who really believe in password security and want a little nudge. It will be supremely difficult to think of a solution in this area that can truly capture the masses.&lt;br /&gt;
&lt;br /&gt;
====More on the Stronger Password Feature====&lt;br /&gt;
&lt;br /&gt;
On the other hand, the idea of adding a feature that helps users create more secure passwords is a simple fix that should enhance the browsing experience for most users.&lt;br /&gt;
&lt;br /&gt;
Increasingly, many websites are giving users some guidelines on password security. For instance, Yahoo!&#039;s sign-up page looks like this:&lt;br /&gt;
&lt;br /&gt;
[[Image:Yahoo.png]]&lt;br /&gt;
&lt;br /&gt;
We think that&#039;s great. But not all sites have that feature. For instance, you get no visual feedback if you sign-up for an Amazon account with a weak password:&lt;br /&gt;
&lt;br /&gt;
[[Image:Amazon1.png]]&lt;br /&gt;
&lt;br /&gt;
Your browser can change that easily. Here&#039;s the new view, with a SafeWord bar underneath the password field reminding you that your password is weak:&lt;br /&gt;
&lt;br /&gt;
[[Image:Amazon2.png]]&lt;br /&gt;
&lt;br /&gt;
SafeWord even lets you customize the password strength options:&lt;br /&gt;
&lt;br /&gt;
[[Image:Amazon3.png]]&lt;br /&gt;
&lt;br /&gt;
We think something like this really could be built into the browser, and would both add to the user experience and increase security.&lt;br /&gt;
&lt;br /&gt;
===&amp;quot;Amber Alert&amp;quot; For The Internet===&lt;br /&gt;
&lt;br /&gt;
Even if websites invest a lot of time and effort into securing their servers and user data, few sites take a more systematic approach to cybersecurity and view it as &amp;quot;their&amp;quot; problem that so many computers are running nasty malware and are thus compromised in important ways that can cause systemic harm to the Internet (like, say, when a site is taken offline in a Distributed Denial-of-Service attack; a partial list of such incidents is [http://en.wikipedia.org/wiki/Denial-of-service_attack#Incidents here]). There are some promising signs [http://bits.blogs.nytimes.com/2010/01/13/facebook-joins-with-mcafee-to-clean-up-malware-on-site/ this] may be [http://stopbadware.org/home/pr_01252010 changing].&lt;br /&gt;
&lt;br /&gt;
We think these are encouraging signs, and they can go even further. What if a coalition of leading Internet sites were willing to share certain information about security threats with a third party organization (like [http://stopbadware.org/home/index StopBadware]), and the third-party would vet the information and then issue certain &amp;quot;Amber Alerts&amp;quot; that all the sites would be willing to publicize in some way? When there&#039;s a particularly egregious security hole in an [http://en.wikipedia.org/wiki/Internet_Explorer_6 old browser], for instance, if all the leading websites actively encouraged its users to patch it, that has the potential to do a lot of good.&lt;br /&gt;
&lt;br /&gt;
We initially proposed this solution as a unilateral move that individual sites could make - Google, say. But we&#039;ve realize that if the recommendations are filtered through a reliable third-party, perhaps the companies won&#039;t be threatened by the embarrassment of having an &amp;quot;Amber Alert&amp;quot; put out. Sure, there would be negative consequences for a company, just as a company who undertakes a product recall generates bad publicity. But ultimate the hope is that companies will realize the net positive value of this transaction, and that consumers will look positively at a new level of honesty and transparency.&lt;br /&gt;
&lt;br /&gt;
====Good Cyber-Samaritans====&lt;br /&gt;
&lt;br /&gt;
An idea we discussed on January 19 that was related to the &amp;quot;Amber Alert&amp;quot; system for websites involves educated users helping out their less computer-savvy friends and neighbors with computer security problems just...because. Perhaps there could be a network of young people who think security is important who don&#039;t mind hanging around their local library for a few hours helping people update software and patch their security holes. This solution becomes ever-more feasible as a greater proportion of users switches to laptop computers and as projects showing that people are willing to assist strangers - from building an [http://www.wikipedia.org encyclopedia] to giving them a [http://www.couchsurfing.org couch to crash on] for free - for the sheer fun and satisfaction of the experience. Relying on people&#039;s good natures could be a new way to make progress on this problem.&lt;/div&gt;</summary>
		<author><name>Jharrow</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cyberlaw_winter10/?title=Cybersecurity_Project&amp;diff=1093</id>
		<title>Cybersecurity Project</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cyberlaw_winter10/?title=Cybersecurity_Project&amp;diff=1093"/>
		<updated>2010-01-29T02:51:27Z</updated>

		<summary type="html">&lt;p&gt;Jharrow: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Saying that cybersecurity is a &amp;quot;difficult problem&amp;quot; is like saying that reversing global warming is a difficult problem: it&#039;s true, but it doesn&#039;t quite capture how devilishly complicated and multifaceted the problems really are. There&#039;s no single reason why creating a more secure global network is so difficult; it in part has to do with the radically-distributed architecture of the Net, in part with some deep flaws computer software, and in part just from its sheer size and importance to our daily lives. (For more on this, see the nice [[Cybersecurity]] backgrounder.)&lt;br /&gt;
&lt;br /&gt;
So we came in not with the goal of providing a magical elixir that would make all credit card transactions magically secure and make it impossible for hackers to [http://googleblog.blogspot.com/2010/01/new-approach-to-china.html compromise Gmail&#039;s security]. Instead, we wanted to offer suggestions with minimal implementation headaches and maximal benefit to users, from novices to experts. This page has a short video overview of the ideas, explains some of the details of our proposal, and even has an alpha-release Firefox plugin that you can download and try out (thanks to [http://www.elance.com/ Elance] for this, by the way).&lt;br /&gt;
&lt;br /&gt;
==Overview==&lt;br /&gt;
&lt;br /&gt;
We discussed this topic at length in an in-class presentation on January 19. [http://www.vimeo.com/9036735 This] 9-minute video summarizes and extends the presentation we gave that day.&lt;br /&gt;
&lt;br /&gt;
==Specific Proposals==&lt;br /&gt;
&lt;br /&gt;
===Public Service Announcement===&lt;br /&gt;
&lt;br /&gt;
We created a Public Service Announcement for generating public awareness for the cybersecurity problem, and showed in class on January 19. It&#039;s online [http://vimeo.com/8937782 here] but is password-protected. Please email us if you were in the class and would like the password. In sum, we don&#039;t think a direct public awareness campaign will be very effective. We want to nudge users and change their behavior by changing the way browsers and websites work, not by scolding people.&lt;br /&gt;
&lt;br /&gt;
===SafeWord===&lt;br /&gt;
&lt;br /&gt;
====What is SafeWord?====&lt;br /&gt;
&lt;br /&gt;
SafeWord is a real, working FireFox plugin designed to nudge users into keeping safer and more unique passwords, though it&#039;s too unstable and unrefined to be considered anything buy alpha software. It&#039;s available for download [http://www.jasonharrow.com/safeword-1.0.0-fx.xpi here]. To install, save that file to your disk, select File --&amp;gt; Open in Firefox 3.5 or above, and install it. You will need to restart Firefox before it takes effect. Thanks to Elance for helping with the coding on very short notice.&lt;br /&gt;
&lt;br /&gt;
We have created a video demonstration of one of the key features of SafeWord [http://vimeo.com/9031865 here].&lt;br /&gt;
&lt;br /&gt;
====What Are The Goals of SafeWord?====&lt;br /&gt;
&lt;br /&gt;
SafeWord begins with a simple proposition: online passwords should be strong and different for different sites, and your browser should help you acheie that goal. Studies continue to show that most users use very simple passwords; see, for instance, [http://www.nytimes.com/2010/01/21/technology/21password.html this] &#039;&#039;New York Times&#039;&#039; that gets right to the point. &amp;quot;If your password is 123456,&amp;quot; reads the headline, &amp;quot;just make it HackMe.&amp;quot; Moreover, most users also fall into the &amp;quot;dirty habit&amp;quot; of using the same password across multiple online accounts, which can lead to a disaster if only one of the accounts is able to be compromised. An extremely detailed analysis of a 2009 attack that compromised many online accounts of Twitter employees is [http://www.techcrunch.com/2009/07/19/the-anatomy-of-the-twitter-attack/ here].&lt;br /&gt;
&lt;br /&gt;
====More on The Unique Password Feature====&lt;br /&gt;
&lt;br /&gt;
=====A Scary Story, and A Word About Annoyance=====&lt;br /&gt;
&lt;br /&gt;
Even readers who are all for stronger passwords in general may nonetheless be skeptical of what can happen to &amp;quot;regular people&amp;quot; who can&#039;t be bothered to remember so many passwords, here&#039;s a very scary story - which is taken directly from the [http://www.techcrunch.com/2009/07/19/the-anatomy-of-the-twitter-attack/ Twitter attack analysis] cited above - of what can happen if users employ the same password at multiple important sites:&lt;br /&gt;
&lt;br /&gt;
# HC [the hacker&#039;s alias] accessed Gmail for a Twitter employee by using the password recovery feature that sends a reset link to a secondary email. In this case the secondary email was an expired Hotmail account, he simply registered it, clicked the link and reset the password. Gmail was then owned.&lt;br /&gt;
# HC then read emails to guess what the original Gmail password was successfully and reset the password so the Twitter employee would not notice the account had changed.&lt;br /&gt;
# HC then used the same password to access the employeeâs Twitter email on Google Apps for your domain, getting access to a gold mine of sensitive company information from emails and, particularly, email attachments.&lt;br /&gt;
# HC then used this information along with additional password guesses and resets to take control of other Twitter employee personal and work emails.&lt;br /&gt;
# HC then used the same username/password combinations and password reset features to access AT&amp;amp;T, MobileMe, Amazon and iTunes, among other services. A security hole in iTunes gave HC access to full credit card information in clear text. HC now also had control of Twitterâs domain names at GoDaddy.&lt;br /&gt;
# Even at this point, Twitter had absolutely no idea they had been compromised.&lt;br /&gt;
&lt;br /&gt;
It ain&#039;t pretty. &lt;br /&gt;
&lt;br /&gt;
We admit from installing SafeWord on our computer that the aspect of the program that requires you to use a different password for each new login is, well, pretty damn annoying. Complying with its demands to keep generating unique passwords might even require some old-fashioned tricks, like the creation of some sort of heuristic for generating memorable but unique passwords or keeping a card in your wallet with your various logins. But we think that the cost/benefit analysis weighs in favor of life being just a little more annoying in this area, because as our scary story illustrates, there are &#039;&#039;&#039;lots&#039;&#039;&#039; of ways in to our various accounts, and &#039;&#039;&#039;lots&#039;&#039;&#039; of random people out there who would love to hack those accounts for financial gain or to get their kicks.&lt;br /&gt;
&lt;br /&gt;
=====Why Do It This Way?=====&lt;br /&gt;
&lt;br /&gt;
There are other solutions out there that automatically generate secure, unique passwords for each site you visit; [https://lastpass.com/features_free.php LastPass] is a particularly nifty one. But they all share several key points of failure: they rely on a master password, and they store your passwords in the cloud. Relying on a master password is particularly problematic, because a compromise of that password can lead to the same disastrous chain of events that we are trying to prevent. The only way to truly reduce the risk of this type of threat is to decentralize everything. And if that takes encouraging people to work a little harder, we at least want to make people aware that this just might be worth the hassle.&lt;br /&gt;
&lt;br /&gt;
=====Extension v. Built-in Feature=====&lt;br /&gt;
&lt;br /&gt;
Initially, we hoped to build this extension to make a pitch to Mozilla that they should think about building this kind of functionality into the browser. But as I have a now-working copy of SafeWord in my browser - admittedly, it&#039;s an alpha copy that&#039;s not even close to ready for prime-time - I (i.e. jharrow) see that it&#039;s just too intrusive for mainstream users. If the average, busy user gets a pop-up every time he comes across a new website and tries to use an old password, he will get angry at the browser. If this happens a few times, he will probably switch. So right now, the idea works best as an extension for people who really believe in password security and want a little nudge. It will be supremely difficult to think of a solution in this area that can truly capture the masses.&lt;br /&gt;
&lt;br /&gt;
====More on the Stronger Password Feature====&lt;br /&gt;
&lt;br /&gt;
On the other hand, the idea of adding a feature that helps users create more secure passwords is a simple fix that should enhance the browsing experience for most users.&lt;br /&gt;
&lt;br /&gt;
Increasingly, many websites are giving users some guidelines on password security. For instance, Yahoo!&#039;s sign-up page looks like this:&lt;br /&gt;
&lt;br /&gt;
[[Image:Yahoo.png]]&lt;br /&gt;
&lt;br /&gt;
We think that&#039;s great. But not all sites have that feature. For instance, you get no visual feedback if you sign-up for an Amazon account with a weak password:&lt;br /&gt;
&lt;br /&gt;
[[Image:Amazon1.png]]&lt;br /&gt;
&lt;br /&gt;
Your browser can change that easily. Here&#039;s the new view, with a SafeWord bar underneath the password field reminding you that your password is weak:&lt;br /&gt;
&lt;br /&gt;
[[Image:Amazon2.png]]&lt;br /&gt;
&lt;br /&gt;
SafeWord even lets you customize the password strength options:&lt;br /&gt;
&lt;br /&gt;
[[Image:Amazon3.png]]&lt;br /&gt;
&lt;br /&gt;
We think something like this really could be built into the browser, and would both add to the user experience and increase security.&lt;br /&gt;
&lt;br /&gt;
===Amber Alert For The Internet===&lt;/div&gt;</summary>
		<author><name>Jharrow</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cyberlaw_winter10/?title=Cybersecurity_Project&amp;diff=1092</id>
		<title>Cybersecurity Project</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cyberlaw_winter10/?title=Cybersecurity_Project&amp;diff=1092"/>
		<updated>2010-01-29T02:50:36Z</updated>

		<summary type="html">&lt;p&gt;Jharrow: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Saying that cybersecurity is a &amp;quot;difficult problem&amp;quot; is like saying that reversing global warming is a difficult problem: it&#039;s true, but it doesn&#039;t quite capture how devilishly complicated and multifaceted the problems really are. There&#039;s no single reason why creating a more secure global network is so difficult; it in part has to do with the radically-distributed architecture of the Net, in part with some deep flaws computer software, and in part just from its sheer size and importance to our daily lives. (For more on this, see the nice [[Cybersecurity]] backgrounder.)&lt;br /&gt;
&lt;br /&gt;
So we came in not with the goal of providing a magical elixir that would make all credit card transactions magically secure and make it impossible for hackers to [http://googleblog.blogspot.com/2010/01/new-approach-to-china.html compromise Gmail&#039;s security]. Instead, we wanted to offer suggestions with minimal implementation headaches and maximal benefit to users, from novices to experts. This page has a short video overview of the ideas, explains some of the details of our proposal, and even has an alpha-release Firefox plugin that you can download and try out (thanks to [http://www.elance.com/ Elance] for this, by the way).&lt;br /&gt;
&lt;br /&gt;
==Overview==&lt;br /&gt;
&lt;br /&gt;
We discussed this topic at length in an in-class presentation on January 19. [http://www.vimeo.com/9036735 This] 9-minute video summarizes and extends the presentation we gave that day.&lt;br /&gt;
&lt;br /&gt;
==Specific Proposals==&lt;br /&gt;
&lt;br /&gt;
===Public Service Announcement===&lt;br /&gt;
&lt;br /&gt;
We created a Public Service Announcement for generating public awareness for the cybersecurity problem, and showed in class on January 19. It&#039;s online [http://vimeo.com/8937782 here] but is password-protected. Please email us if you were in the class and would like the password. In sum, we don&#039;t think a direct public awareness campaign will be very effective. We want to nudge users and change their behavior by changing the way browsers and websites work, not by scolding people.&lt;br /&gt;
&lt;br /&gt;
===SafeWord===&lt;br /&gt;
&lt;br /&gt;
====What is SafeWord?====&lt;br /&gt;
&lt;br /&gt;
SafeWord is a real, working FireFox plugin designed to nudge users into keeping safer and more unique passwords, though it&#039;s too unstable and unrefined to be considered anything buy alpha software. It&#039;s available for download [http://www.jasonharrow.com/safeword-1.0.0-fx.xpi here]. To install, save that file to your disk, select File --&amp;gt; Open in Firefox 3.5 or above, and install it. You will need to restart Firefox before it takes effect. Thanks to Elance for helping with the coding on very short notice.&lt;br /&gt;
&lt;br /&gt;
We have created a video demonstration of one of the key features of SafeWord [http://vimeo.com/9031865 here].&lt;br /&gt;
&lt;br /&gt;
====What Are The Goals of SafeWord?====&lt;br /&gt;
&lt;br /&gt;
SafeWord begins with a simple proposition: online passwords should be strong and different for different sites, and your browser should help you acheie that goal. Studies continue to show that most users use very simple passwords; see, for instance, [http://www.nytimes.com/2010/01/21/technology/21password.html this] &#039;&#039;New York Times&#039;&#039; that gets right to the point. &amp;quot;If your password is 123456,&amp;quot; reads the headline, &amp;quot;just make it HackMe.&amp;quot; Moreover, most users also fall into the &amp;quot;dirty habit&amp;quot; of using the same password across multiple online accounts, which can lead to a disaster if only one of the accounts is able to be compromised. An extremely detailed analysis of a 2009 attack that compromised many online accounts of Twitter employees is [http://www.techcrunch.com/2009/07/19/the-anatomy-of-the-twitter-attack/ here].&lt;br /&gt;
&lt;br /&gt;
====More on The Unique Password Feature====&lt;br /&gt;
&lt;br /&gt;
=====A Scary Story, and A Word About Annoyance=====&lt;br /&gt;
&lt;br /&gt;
Even readers who are all for stronger passwords in general may nonetheless be skeptical of what can happen to &amp;quot;regular people&amp;quot; who can&#039;t be bothered to remember so many passwords, here&#039;s a very scary story - which is taken directly from the [http://www.techcrunch.com/2009/07/19/the-anatomy-of-the-twitter-attack/ Twitter attack analysis] cited above - of what can happen if users employ the same password at multiple important sites:&lt;br /&gt;
&lt;br /&gt;
# HC [the hacker&#039;s alias] accessed Gmail for a Twitter employee by using the password recovery feature that sends a reset link to a secondary email. In this case the secondary email was an expired Hotmail account, he simply registered it, clicked the link and reset the password. Gmail was then owned.&lt;br /&gt;
# HC then read emails to guess what the original Gmail password was successfully and reset the password so the Twitter employee would not notice the account had changed.&lt;br /&gt;
# HC then used the same password to access the employeeâs Twitter email on Google Apps for your domain, getting access to a gold mine of sensitive company information from emails and, particularly, email attachments.&lt;br /&gt;
# HC then used this information along with additional password guesses and resets to take control of other Twitter employee personal and work emails.&lt;br /&gt;
# HC then used the same username/password combinations and password reset features to access AT&amp;amp;T, MobileMe, Amazon and iTunes, among other services. A security hole in iTunes gave HC access to full credit card information in clear text. HC now also had control of Twitterâs domain names at GoDaddy.&lt;br /&gt;
# Even at this point, Twitter had absolutely no idea they had been compromised.&lt;br /&gt;
&lt;br /&gt;
It ain&#039;t pretty. &lt;br /&gt;
&lt;br /&gt;
We admit from installing SafeWord on our computer that the aspect of the program that requires you to use a different password for each new login is, well, pretty damn annoying. Complying with its demands to keep generating unique passwords might even require some old-fashioned tricks, like the creation of some sort of heuristic for generating memorable but unique passwords or keeping a card in your wallet with your various logins. But we think that the cost/benefit analysis weighs in favor of life being just a little more annoying in this area, because as our scary story illustrates, there are &#039;&#039;&#039;lots&#039;&#039;&#039; of ways in to our various accounts, and &#039;&#039;&#039;lots&#039;&#039;&#039; of random people out there who would love to hack those accounts for financial gain or to get their kicks.&lt;br /&gt;
&lt;br /&gt;
=====Why Do It This Way?=====&lt;br /&gt;
&lt;br /&gt;
There are other solutions out there that automatically generate secure, unique passwords for each site you visit; [https://lastpass.com/features_free.php LastPass] is a particularly nifty one. But they all share several key points of failure: they rely on a master password, and they store your passwords in the cloud. Relying on a master password is particularly problematic, because a compromise of that password can lead to the same disastrous chain of events that we are trying to prevent. The only way to truly reduce the risk of this type of threat is to decentralize everything. And if that takes encouraging people to work a little harder, we at least want to make people aware that this just might be worth the hassle.&lt;br /&gt;
&lt;br /&gt;
=====Extension v. Built-in Feature=====&lt;br /&gt;
&lt;br /&gt;
Initially, we hoped to build this extension to make a pitch to Mozilla that they should think about building this kind of functionality into the browser. But as I have a now-working copy of SafeWord in my browser - admittedly, it&#039;s an alpha copy that&#039;s not even close to ready for prime-time - I (i.e. jharrow) see that it&#039;s just too intrusive for mainstream users. If the average, busy user gets a pop-up every time he comes across a new website and tries to use an old password, he will get angry at the browser. If this happens a few times, he will probably switch. So right now, the idea works best as an extension for people who really believe in password security and want a little nudge. It will be supremely difficult to think of a solution in this area that can truly capture the masses.&lt;br /&gt;
&lt;br /&gt;
====More on the Stronger Password Feature====&lt;br /&gt;
&lt;br /&gt;
On the other hand, the idea of adding a feature that helps users create more secure passwords is a simple fix that should enhance the browsing experience for most users.&lt;br /&gt;
&lt;br /&gt;
Increasingly, many websites are giving users some guidelines on password security. For instance, Yahoo!&#039;s sign-up page looks like this:&lt;br /&gt;
&lt;br /&gt;
[[Image:Yahoo.png]]&lt;br /&gt;
&lt;br /&gt;
We think that&#039;s great. But not all sites have that feature. For instance, you get no visual feedback if you sign-up for an Amazon account with a weak password:&lt;br /&gt;
&lt;br /&gt;
[[Image:Amazon1.png]]&lt;br /&gt;
&lt;br /&gt;
Your browser can change that easily. Here&#039;s the new view, with a SafeWord bar underneath the password field reminding you that your password is weak:&lt;br /&gt;
&lt;br /&gt;
[[Image:Amazon2.png]]&lt;br /&gt;
&lt;br /&gt;
SafeWord even lets you customize the password strength options:&lt;br /&gt;
&lt;br /&gt;
[[Image:Amazon3.png]]&lt;br /&gt;
&lt;br /&gt;
We think something like this really could be built into the browser, and would both add to the user experience and increase security.&lt;/div&gt;</summary>
		<author><name>Jharrow</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cyberlaw_winter10/?title=File:Amazon3.png&amp;diff=1091</id>
		<title>File:Amazon3.png</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cyberlaw_winter10/?title=File:Amazon3.png&amp;diff=1091"/>
		<updated>2010-01-29T02:49:26Z</updated>

		<summary type="html">&lt;p&gt;Jharrow: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Jharrow</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cyberlaw_winter10/?title=File:Amazon2.png&amp;diff=1090</id>
		<title>File:Amazon2.png</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cyberlaw_winter10/?title=File:Amazon2.png&amp;diff=1090"/>
		<updated>2010-01-29T02:47:44Z</updated>

		<summary type="html">&lt;p&gt;Jharrow: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Jharrow</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cyberlaw_winter10/?title=File:Amazon1.png&amp;diff=1089</id>
		<title>File:Amazon1.png</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cyberlaw_winter10/?title=File:Amazon1.png&amp;diff=1089"/>
		<updated>2010-01-29T02:45:31Z</updated>

		<summary type="html">&lt;p&gt;Jharrow: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Jharrow</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cyberlaw_winter10/?title=Cybersecurity_Project&amp;diff=1088</id>
		<title>Cybersecurity Project</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cyberlaw_winter10/?title=Cybersecurity_Project&amp;diff=1088"/>
		<updated>2010-01-29T02:45:12Z</updated>

		<summary type="html">&lt;p&gt;Jharrow: /* More on the Stronger Password Feature */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Saying that cybersecurity is a &amp;quot;difficult problem&amp;quot; is like saying that reversing global warming is a difficult problem: it&#039;s true, but it doesn&#039;t quite capture how devilishly complicated and multifaceted the problems really are. There&#039;s no single reason why creating a more secure global network is so difficult; it in part has to do with the radically-distributed architecture of the Net, in part with some deep flaws computer software, and in part just from its sheer size and importance to our daily lives. (For more on this, see the nice [[Cybersecurity]] backgrounder.)&lt;br /&gt;
&lt;br /&gt;
So we came in not with the goal of providing a magical elixir that would make all credit card transactions magically secure and make it impossible for hackers to [http://googleblog.blogspot.com/2010/01/new-approach-to-china.html compromise Gmail&#039;s security]. Instead, we wanted to offer suggestions with minimal implementation headaches and maximal benefit to users, from novices to experts. This page has a short video overview of the ideas, explains some of the details of our proposal, and even has an alpha-release Firefox plugin that you can download and try out (thanks to [http://www.elance.com/ Elance] for this, by the way).&lt;br /&gt;
&lt;br /&gt;
==Overview==&lt;br /&gt;
&lt;br /&gt;
We discussed this topic at length in an in-class presentation on January 19. [http://www.vimeo.com/9036735 This] 9-minute video summarizes and extends the presentation we gave that day.&lt;br /&gt;
&lt;br /&gt;
==Specific Proposals==&lt;br /&gt;
&lt;br /&gt;
===Public Service Announcement===&lt;br /&gt;
&lt;br /&gt;
We created a Public Service Announcement for generating public awareness for the cybersecurity problem, and showed in class on January 19. It&#039;s online [http://vimeo.com/8937782 here] but is password-protected. Please email us if you were in the class and would like the password. In sum, we don&#039;t think a direct public awareness campaign will be very effective. We want to nudge users and change their behavior by changing the way browsers and websites work, not by scolding people.&lt;br /&gt;
&lt;br /&gt;
===SafeWord===&lt;br /&gt;
&lt;br /&gt;
====What is SafeWord?====&lt;br /&gt;
&lt;br /&gt;
SafeWord is a real, working FireFox plugin designed to nudge users into keeping safer and more unique passwords, though it&#039;s too unstable and unrefined to be considered anything buy alpha software. It&#039;s available for download [http://www.jasonharrow.com/safeword-1.0.0-fx.xpi here]. To install, save that file to your disk, select File --&amp;gt; Open in Firefox 3.5 or above, and install it. You will need to restart Firefox before it takes effect. Thanks to Elance for helping with the coding on very short notice.&lt;br /&gt;
&lt;br /&gt;
We have created a video demonstration of one of the key features of SafeWord [http://vimeo.com/9031865 here].&lt;br /&gt;
&lt;br /&gt;
====What Are The Goals of SafeWord?====&lt;br /&gt;
&lt;br /&gt;
SafeWord begins with a simple proposition: online passwords should be strong and different for different sites, and your browser should help you acheie that goal. Studies continue to show that most users use very simple passwords; see, for instance, [http://www.nytimes.com/2010/01/21/technology/21password.html this] &#039;&#039;New York Times&#039;&#039; that gets right to the point. &amp;quot;If your password is 123456,&amp;quot; reads the headline, &amp;quot;just make it HackMe.&amp;quot; Moreover, most users also fall into the &amp;quot;dirty habit&amp;quot; of using the same password across multiple online accounts, which can lead to a disaster if only one of the accounts is able to be compromised. An extremely detailed analysis of a 2009 attack that compromised many online accounts of Twitter employees is [http://www.techcrunch.com/2009/07/19/the-anatomy-of-the-twitter-attack/ here].&lt;br /&gt;
&lt;br /&gt;
====More on The Unique Password Feature====&lt;br /&gt;
&lt;br /&gt;
=====A Scary Story, and A Word About Annoyance=====&lt;br /&gt;
&lt;br /&gt;
Even readers who are all for stronger passwords in general may nonetheless be skeptical of what can happen to &amp;quot;regular people&amp;quot; who can&#039;t be bothered to remember so many passwords, here&#039;s a very scary story - which is taken directly from the [http://www.techcrunch.com/2009/07/19/the-anatomy-of-the-twitter-attack/ Twitter attack analysis] cited above - of what can happen if users employ the same password at multiple important sites:&lt;br /&gt;
&lt;br /&gt;
# HC [the hacker&#039;s alias] accessed Gmail for a Twitter employee by using the password recovery feature that sends a reset link to a secondary email. In this case the secondary email was an expired Hotmail account, he simply registered it, clicked the link and reset the password. Gmail was then owned.&lt;br /&gt;
# HC then read emails to guess what the original Gmail password was successfully and reset the password so the Twitter employee would not notice the account had changed.&lt;br /&gt;
# HC then used the same password to access the employeeâs Twitter email on Google Apps for your domain, getting access to a gold mine of sensitive company information from emails and, particularly, email attachments.&lt;br /&gt;
# HC then used this information along with additional password guesses and resets to take control of other Twitter employee personal and work emails.&lt;br /&gt;
# HC then used the same username/password combinations and password reset features to access AT&amp;amp;T, MobileMe, Amazon and iTunes, among other services. A security hole in iTunes gave HC access to full credit card information in clear text. HC now also had control of Twitterâs domain names at GoDaddy.&lt;br /&gt;
# Even at this point, Twitter had absolutely no idea they had been compromised.&lt;br /&gt;
&lt;br /&gt;
It ain&#039;t pretty. &lt;br /&gt;
&lt;br /&gt;
We admit from installing SafeWord on our computer that the aspect of the program that requires you to use a different password for each new login is, well, pretty damn annoying. Complying with its demands to keep generating unique passwords might even require some old-fashioned tricks, like the creation of some sort of heuristic for generating memorable but unique passwords or keeping a card in your wallet with your various logins. But we think that the cost/benefit analysis weighs in favor of life being just a little more annoying in this area, because as our scary story illustrates, there are &#039;&#039;&#039;lots&#039;&#039;&#039; of ways in to our various accounts, and &#039;&#039;&#039;lots&#039;&#039;&#039; of random people out there who would love to hack those accounts for financial gain or to get their kicks.&lt;br /&gt;
&lt;br /&gt;
=====Why Do It This Way?=====&lt;br /&gt;
&lt;br /&gt;
There are other solutions out there that automatically generate secure, unique passwords for each site you visit; [https://lastpass.com/features_free.php LastPass] is a particularly nifty one. But they all share several key points of failure: they rely on a master password, and they store your passwords in the cloud. Relying on a master password is particularly problematic, because a compromise of that password can lead to the same disastrous chain of events that we are trying to prevent. The only way to truly reduce the risk of this type of threat is to decentralize everything. And if that takes encouraging people to work a little harder, we at least want to make people aware that this just might be worth the hassle.&lt;br /&gt;
&lt;br /&gt;
=====Extension v. Built-in Feature=====&lt;br /&gt;
&lt;br /&gt;
Initially, we hoped to build this extension to make a pitch to Mozilla that they should think about building this kind of functionality into the browser. But as I have a now-working copy of SafeWord in my browser - admittedly, it&#039;s an alpha copy that&#039;s not even close to ready for prime-time - I (i.e. jharrow) see that it&#039;s just too intrusive for mainstream users. If the average, busy user gets a pop-up every time he comes across a new website and tries to use an old password, he will get angry at the browser. If this happens a few times, he will probably switch. So right now, the idea works best as an extension for people who really believe in password security and want a little nudge. It will be supremely difficult to think of a solution in this area that can truly capture the masses.&lt;br /&gt;
&lt;br /&gt;
====More on the Stronger Password Feature====&lt;br /&gt;
&lt;br /&gt;
On the other hand, the idea of adding a feature that helps users create more secure passwords is a simple fix that should enhance the browsing experience for most users.&lt;br /&gt;
&lt;br /&gt;
Increasingly, many websites are giving users some guidelines on password security. For instance, Yahoo!&#039;s sign-up page looks like this:&lt;br /&gt;
&lt;br /&gt;
[[Image:Yahoo.png]].&lt;br /&gt;
&lt;br /&gt;
We think that&#039;s great. But not all sites have that feature. For instance, you get no visual feedback if you sign-up for an Amazon account with a weak password:&lt;/div&gt;</summary>
		<author><name>Jharrow</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cyberlaw_winter10/?title=File:Yahoo.png&amp;diff=1087</id>
		<title>File:Yahoo.png</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cyberlaw_winter10/?title=File:Yahoo.png&amp;diff=1087"/>
		<updated>2010-01-29T02:40:43Z</updated>

		<summary type="html">&lt;p&gt;Jharrow: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Jharrow</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cyberlaw_winter10/?title=Cybersecurity_Project&amp;diff=1086</id>
		<title>Cybersecurity Project</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cyberlaw_winter10/?title=Cybersecurity_Project&amp;diff=1086"/>
		<updated>2010-01-29T02:38:34Z</updated>

		<summary type="html">&lt;p&gt;Jharrow: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Saying that cybersecurity is a &amp;quot;difficult problem&amp;quot; is like saying that reversing global warming is a difficult problem: it&#039;s true, but it doesn&#039;t quite capture how devilishly complicated and multifaceted the problems really are. There&#039;s no single reason why creating a more secure global network is so difficult; it in part has to do with the radically-distributed architecture of the Net, in part with some deep flaws computer software, and in part just from its sheer size and importance to our daily lives. (For more on this, see the nice [[Cybersecurity]] backgrounder.)&lt;br /&gt;
&lt;br /&gt;
So we came in not with the goal of providing a magical elixir that would make all credit card transactions magically secure and make it impossible for hackers to [http://googleblog.blogspot.com/2010/01/new-approach-to-china.html compromise Gmail&#039;s security]. Instead, we wanted to offer suggestions with minimal implementation headaches and maximal benefit to users, from novices to experts. This page has a short video overview of the ideas, explains some of the details of our proposal, and even has an alpha-release Firefox plugin that you can download and try out (thanks to [http://www.elance.com/ Elance] for this, by the way).&lt;br /&gt;
&lt;br /&gt;
==Overview==&lt;br /&gt;
&lt;br /&gt;
We discussed this topic at length in an in-class presentation on January 19. [http://www.vimeo.com/9036735 This] 9-minute video summarizes and extends the presentation we gave that day.&lt;br /&gt;
&lt;br /&gt;
==Specific Proposals==&lt;br /&gt;
&lt;br /&gt;
===Public Service Announcement===&lt;br /&gt;
&lt;br /&gt;
We created a Public Service Announcement for generating public awareness for the cybersecurity problem, and showed in class on January 19. It&#039;s online [http://vimeo.com/8937782 here] but is password-protected. Please email us if you were in the class and would like the password. In sum, we don&#039;t think a direct public awareness campaign will be very effective. We want to nudge users and change their behavior by changing the way browsers and websites work, not by scolding people.&lt;br /&gt;
&lt;br /&gt;
===SafeWord===&lt;br /&gt;
&lt;br /&gt;
====What is SafeWord?====&lt;br /&gt;
&lt;br /&gt;
SafeWord is a real, working FireFox plugin designed to nudge users into keeping safer and more unique passwords, though it&#039;s too unstable and unrefined to be considered anything buy alpha software. It&#039;s available for download [http://www.jasonharrow.com/safeword-1.0.0-fx.xpi here]. To install, save that file to your disk, select File --&amp;gt; Open in Firefox 3.5 or above, and install it. You will need to restart Firefox before it takes effect. Thanks to Elance for helping with the coding on very short notice.&lt;br /&gt;
&lt;br /&gt;
We have created a video demonstration of one of the key features of SafeWord [http://vimeo.com/9031865 here].&lt;br /&gt;
&lt;br /&gt;
====What Are The Goals of SafeWord?====&lt;br /&gt;
&lt;br /&gt;
SafeWord begins with a simple proposition: online passwords should be strong and different for different sites, and your browser should help you acheie that goal. Studies continue to show that most users use very simple passwords; see, for instance, [http://www.nytimes.com/2010/01/21/technology/21password.html this] &#039;&#039;New York Times&#039;&#039; that gets right to the point. &amp;quot;If your password is 123456,&amp;quot; reads the headline, &amp;quot;just make it HackMe.&amp;quot; Moreover, most users also fall into the &amp;quot;dirty habit&amp;quot; of using the same password across multiple online accounts, which can lead to a disaster if only one of the accounts is able to be compromised. An extremely detailed analysis of a 2009 attack that compromised many online accounts of Twitter employees is [http://www.techcrunch.com/2009/07/19/the-anatomy-of-the-twitter-attack/ here].&lt;br /&gt;
&lt;br /&gt;
====More on The Unique Password Feature====&lt;br /&gt;
&lt;br /&gt;
=====A Scary Story, and A Word About Annoyance=====&lt;br /&gt;
&lt;br /&gt;
Even readers who are all for stronger passwords in general may nonetheless be skeptical of what can happen to &amp;quot;regular people&amp;quot; who can&#039;t be bothered to remember so many passwords, here&#039;s a very scary story - which is taken directly from the [http://www.techcrunch.com/2009/07/19/the-anatomy-of-the-twitter-attack/ Twitter attack analysis] cited above - of what can happen if users employ the same password at multiple important sites:&lt;br /&gt;
&lt;br /&gt;
# HC [the hacker&#039;s alias] accessed Gmail for a Twitter employee by using the password recovery feature that sends a reset link to a secondary email. In this case the secondary email was an expired Hotmail account, he simply registered it, clicked the link and reset the password. Gmail was then owned.&lt;br /&gt;
# HC then read emails to guess what the original Gmail password was successfully and reset the password so the Twitter employee would not notice the account had changed.&lt;br /&gt;
# HC then used the same password to access the employeeâs Twitter email on Google Apps for your domain, getting access to a gold mine of sensitive company information from emails and, particularly, email attachments.&lt;br /&gt;
# HC then used this information along with additional password guesses and resets to take control of other Twitter employee personal and work emails.&lt;br /&gt;
# HC then used the same username/password combinations and password reset features to access AT&amp;amp;T, MobileMe, Amazon and iTunes, among other services. A security hole in iTunes gave HC access to full credit card information in clear text. HC now also had control of Twitterâs domain names at GoDaddy.&lt;br /&gt;
# Even at this point, Twitter had absolutely no idea they had been compromised.&lt;br /&gt;
&lt;br /&gt;
It ain&#039;t pretty. &lt;br /&gt;
&lt;br /&gt;
We admit from installing SafeWord on our computer that the aspect of the program that requires you to use a different password for each new login is, well, pretty damn annoying. Complying with its demands to keep generating unique passwords might even require some old-fashioned tricks, like the creation of some sort of heuristic for generating memorable but unique passwords or keeping a card in your wallet with your various logins. But we think that the cost/benefit analysis weighs in favor of life being just a little more annoying in this area, because as our scary story illustrates, there are &#039;&#039;&#039;lots&#039;&#039;&#039; of ways in to our various accounts, and &#039;&#039;&#039;lots&#039;&#039;&#039; of random people out there who would love to hack those accounts for financial gain or to get their kicks.&lt;br /&gt;
&lt;br /&gt;
=====Why Do It This Way?=====&lt;br /&gt;
&lt;br /&gt;
There are other solutions out there that automatically generate secure, unique passwords for each site you visit; [https://lastpass.com/features_free.php LastPass] is a particularly nifty one. But they all share several key points of failure: they rely on a master password, and they store your passwords in the cloud. Relying on a master password is particularly problematic, because a compromise of that password can lead to the same disastrous chain of events that we are trying to prevent. The only way to truly reduce the risk of this type of threat is to decentralize everything. And if that takes encouraging people to work a little harder, we at least want to make people aware that this just might be worth the hassle.&lt;br /&gt;
&lt;br /&gt;
=====Extension v. Built-in Feature=====&lt;br /&gt;
&lt;br /&gt;
Initially, we hoped to build this extension to make a pitch to Mozilla that they should think about building this kind of functionality into the browser. But as I have a now-working copy of SafeWord in my browser - admittedly, it&#039;s an alpha copy that&#039;s not even close to ready for prime-time - I (i.e. jharrow) see that it&#039;s just too intrusive for mainstream users. If the average, busy user gets a pop-up every time he comes across a new website and tries to use an old password, he will get angry at the browser. If this happens a few times, he will probably switch. So right now, the idea works best as an extension for people who really believe in password security and want a little nudge. It will be supremely difficult to think of a solution in this area that can truly capture the masses.&lt;br /&gt;
&lt;br /&gt;
====More on the Stronger Password Feature====&lt;br /&gt;
&lt;br /&gt;
On the other hand, the idea of adding a feature&lt;/div&gt;</summary>
		<author><name>Jharrow</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cyberlaw_winter10/?title=Main_Page&amp;diff=1085</id>
		<title>Main Page</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cyberlaw_winter10/?title=Main_Page&amp;diff=1085"/>
		<updated>2010-01-29T02:27:50Z</updated>

		<summary type="html">&lt;p&gt;Jharrow: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Welcome to Difficult Problems in Cyberlaw, a January course taught by Professor Jonathan Zittrain and Elizabeth Stark, co-hosted by Stanford Law School and Harvard Law SchooI.&lt;br /&gt;
&lt;br /&gt;
In addition to this wiki, this class maintains a [http://blogs.law.harvard.edu/difficultprobs/ blog] and [http://twitter.com/DifficultProbs twitter feed]. Check them out!&lt;br /&gt;
&lt;br /&gt;
If you are a student, please see the [[Student Responsibilities]] section and [[Course Logistics]].  For admins looking for details on field trips, please visit [http://cyber.law.harvard.edu/difficultproblems/Main_Page#Field_Trip_Logistic here].  All regular class meetings will be at &#039;&#039;&#039;Stanford Law School Classroom 280B&#039;&#039;&#039;. &lt;br /&gt;
&lt;br /&gt;
This [http://www.law.stanford.edu/contact/#maps map site] has a map of the [http://www.aaccessmaps.com/show/map/us/ca/bayarea Bay Area], [http://ucomm.stanford.edu/map/ Stanford campus], and [http://transportation.stanford.edu/images/visitor-bus.pdf visitor parking] at Stanford.&lt;br /&gt;
&lt;br /&gt;
The four main difficult problems to be addressed are: &lt;br /&gt;
*[[Global Network Initiative]] ([[GNI Brainstorming |Group Page]])&lt;br /&gt;
*[[Ubiquitous Human Computing]]  ([[Ubicomp Brainstorming |Group Page]])&lt;br /&gt;
*[[Future of Wikipedia]]&lt;br /&gt;
*[[Cybersecurity]] ([[Cybersecurity Project|Final Project]]) ([[Cybersecurity Brainstorming |Brainstorming Page]])&lt;br /&gt;
&lt;br /&gt;
Cross-cutting themes include: &lt;br /&gt;
*[[Due process on the Internet among private sheriffs]]&lt;br /&gt;
*[[The role of intermediaries]]&lt;br /&gt;
*[[Motivating good and bad actors]]&lt;br /&gt;
*[[Collaborating and relying on masses]]&lt;br /&gt;
*[[Privacy and Anonymity on the Internet]]&lt;br /&gt;
&lt;br /&gt;
Group presentation schedule:&lt;br /&gt;
*Friday, Jan. 15th: Ubiquitous Human Computing&lt;br /&gt;
*Tuesday, Jan. 19th: Cybersecurity&lt;br /&gt;
*Wednesday, Jan. 20th: Global Network Initiative&lt;br /&gt;
*Thursday, Jan. 21st: Future of Wikipedia&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==WEEK ONE: DEFINING THE PROBLEMS==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt; &#039;&#039;&#039;Monday, January 4th&#039;&#039;&#039; &amp;lt;/center&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;LUNCH&#039;&#039;&#039;: 12-2pm SLS, Room 280B&lt;br /&gt;
:Student introductions&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;CLASS&#039;&#039;&#039;: 7:20-9:20pm SLS Room 280B&lt;br /&gt;
:A brief overview of the course, its goals and expectations, including an introduction to the difficult problems and the cross-cutting themes.  &lt;br /&gt;
:A quiz on Zittrain&#039;s book, &amp;lt;span style=&amp;quot;font-variant:small-caps&amp;quot;&amp;gt;[http://yupnet.org/zittrain/ The Future of the Internet: And How to Stop It]&amp;lt;/span&amp;gt; will be given. &lt;br /&gt;
:Brief introduction to the Global Network Initiative&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Readings For Class&#039;&#039;: &lt;br /&gt;
*Read &amp;lt;span style=&amp;quot;font-variant:small-caps&amp;quot;&amp;gt;[http://yupnet.org/zittrain/ The Future of the Internet: And How to Stop It]&amp;lt;/span&amp;gt;&lt;br /&gt;
*Explore the [http://www.globalnetworkinitiative.org/ Global Network Initiative] website&lt;br /&gt;
*Read the [http://cyber.law.harvard.edu/cyberlaw_winter10/GNI GNI Wiki Primer]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Assignments&#039;&#039;: Before next class, post [[Day 2 Predictions]]. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Thoughts after class&#039;&#039;: [[Day 1 Thoughts]]&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt; &#039;&#039;&#039;Tuesday, January 5th&#039;&#039;&#039; &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;CYBERSECURITY BACKGROUND: &#039;&#039;BONUS&#039;&#039;&#039;&#039;&#039;: 2-4pm SLS Room 280B &lt;br /&gt;
: Professor Zittrain will interview Professor [http://www.law.harvard.edu/faculty/directory/index.html?id=559 Jack Goldsmith] as an overview of cybersecurity as it has evolved and as it can potentially be addressed. &lt;br /&gt;
&lt;br /&gt;
*&#039;&#039;Bonus Writing Opportunity&#039;&#039;: produce a summary of the cybersecurity event, to be used as background reading for Thursday&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;CLASS&#039;&#039;&#039;: 5:15-7:15pm SLS Room 280B&lt;br /&gt;
:Identify the first-order problems regarding corporate responsibility and free expression on the internet. Examine how GNI attempts to address these problems and then evaluate whether GNI is a success and whether better approaches could be taken. &lt;br /&gt;
:Introduction to ubiquitous human computing.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Guests:&#039;&#039; &lt;br /&gt;
*Mark Chandler, CISCO&lt;br /&gt;
*Chuck Cosson, Microsoft&lt;br /&gt;
*Dunstan Hope, BSR&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Readings:&#039;&#039; &lt;br /&gt;
*Read Rhys Blakely, &#039;&#039;[http://business.timesonline.co.uk/tol/business/industry_sectors/media/article728898.ece Yahoo in second Chinese blog Row],&#039;&#039; &amp;lt;span style=&amp;quot;font-variant:small-caps&amp;quot;&amp;gt;TimesOnline&amp;lt;/span&amp;gt;, Feb. 9, 2006. &lt;br /&gt;
*Read Colin Maclay, &amp;quot;[http://drop.io/cyberlaw_winter10/asset/maclay-access-controlled-pdf Protecting Privacy and Expression Online],&amp;quot; &#039;&#039;in&#039;&#039; &amp;lt;span style=&amp;quot;font-variant:small-caps&amp;quot;&amp;gt;Access Controlled&amp;lt;/span&amp;gt; (Ronald Diebert et al., eds., MIT Press: Cambridge, MA, 2010).&lt;br /&gt;
*Read GNI [http://www.globalnetworkinitiative.org/cms/uploads/1/GNI_-_Principles_1_.pdf Guiding Principles]&lt;br /&gt;
*Read the [http://cyber.law.harvard.edu/cyberlaw_winter10/Ubiquitous_Human_Computing UbiComp Wiki Primer]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Assignments&#039;&#039;: Before next class, post [[Day 3 Predictions]]. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Thoughts after class&#039;&#039;: [[Day 2 Thoughts]]&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt; &#039;&#039;&#039;Wednesday, January 6th&#039;&#039;&#039; &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;CLASS&#039;&#039;&#039;: 6:30-8:30pm SLS Room 280B, guests to begin arriving at 7:00pm&lt;br /&gt;
:Examine the nature of ubiquitous human computing and potential future applications of human computing and the dangers. &lt;br /&gt;
:Introduction to cybersecurity. &lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Guests&#039;&#039;: &lt;br /&gt;
*Lukas Biewald, [http://crowdflower.com/ CrowdFlower]&lt;br /&gt;
*Bjoern Hartman, see his [http://bjoern.org/projects/catbook/ Mechanical Turk Cats Book]&lt;br /&gt;
*Aaron Koblin, see his [http://www.aaronkoblin.com/work.html Ten Thousand Cents and Sheep Market projects]&lt;br /&gt;
 &lt;br /&gt;
&#039;&#039;Readings&#039;&#039;:&lt;br /&gt;
*Visit [http://www.mturk.com/ Mechanical Turk], [http://www.liveops.com/ LiveOps], [http://www.crowdflower.com CrowdFlower] or other human computing site&lt;br /&gt;
**Watch the [http://www.ustream.tv/recorded/2167086 12-minute video] of Lukas&#039; CrowdFlower presentation at TechCrunch&lt;br /&gt;
*Skim Nancy R. Mansfield, &#039;&#039;[http://www.allbusiness.com/technology/internet-technology/618188-1.html The information revolution and its impact on the employment relationship: an analysis of the cyberspace workplace]&#039;&#039;, &amp;lt;span style=&amp;quot;font-variant:small-caps&amp;quot;&amp;gt;American Business Law Journal&amp;lt;/span&amp;gt; (2003).&lt;br /&gt;
*Kate Thomas, &#039;&#039;[http://www.seiu.org/2009/12/insurers-hire-mafia-to-spam-congress.php Insurers Hire Mafia to Spam Congress]&#039;&#039;, &amp;lt;span style=&amp;quot;font-variant:small-caps&amp;quot;&amp;gt;SEIU.org Blog&amp;lt;/span&amp;gt;, Dec. 10, 2009. &lt;br /&gt;
*Read Jonathan Zittrain, &#039;&#039;[http://drop.io/cyberlaw_winter10/asset/ssrn-id1140445-pdf Ubiquitous Human Computing]&#039;&#039;, SSRN Paper No 32/2008 (July 2008). &lt;br /&gt;
*Read the [http://cyber.law.harvard.edu/cyberlaw_winter10/Cybersecurity Cybersecurity Wiki Primer]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;ASSIGNMENT: Due -- Email Admin with Problem Topic Choice&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Assignment&#039;&#039;: Before next class, post [[Day 4 Predictions]]. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Thoughts after class&#039;&#039;: [[Day 3 Thoughts]]&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt; &#039;&#039;&#039;Thursday, January 7th&#039;&#039;&#039; &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;CLASS&#039;&#039;&#039;: 11:10am-1:10pm SLS Room 280B, guests to begin arriving at 11:40am&lt;br /&gt;
:Cybersecurity has been identified as one of the greatest threats facing the United States today, but it is ill-defined and almost impossible to address. How can we frame this problem to better inspire solutions?  How should government, military, businesses, and internet/tech approach the problem from different angles and do these different approaches work together?&lt;br /&gt;
:Introduction to Future of Wikipedia&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Guests&#039;&#039;: &lt;br /&gt;
*Chuck Cosson, Microsoft&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Readings&#039;&#039;: &lt;br /&gt;
*Listen to David Clark, [http://www.ischool.berkeley.edu/newsandevents/events/sl20090304 The Internets We Did Not Build].&lt;br /&gt;
*Col. Allen &amp;amp; Lt. Col Demchak, &#039;&#039;[http://drop.io/cyberlaw_winter10 The Palestinian-Israeli Cyberwar]&#039;&#039;, &amp;lt;span style=&amp;quot;font-variant:small-caps&amp;quot;&amp;gt;Military Review&amp;lt;/span&amp;gt; (2003). &lt;br /&gt;
*Kim Zetter, &#039;&#039;[http://www.wired.com/threatlevel/2008/08/revealed-the-in/ Revealed: The Internet&#039;s Biggest Security Hole]&#039;&#039;, &amp;lt;span style=&amp;quot;font-variant:small-caps&amp;quot;&amp;gt;Wired&amp;lt;/span&amp;gt; (2008). &lt;br /&gt;
*Review &amp;lt;span style=&amp;quot;font-variant:small-caps&amp;quot;&amp;gt;Zittrain, [http://yupnet.org/zittrain/ The Future of the Internet: And How to Stop It]&amp;lt;/span&amp;gt;; Chapter 3&lt;br /&gt;
*Skim CENTRA Technology, [http://drop.io/cyberlaw_winter10 Cyber Compendium] Workshop, Nov. 2009.&lt;br /&gt;
*Skim the White House [http://www.whitehouse.gov/assets/documents/Cyberspace_Policy_Review_final.pdf Cyberspace Policy Review] (2009); focus on the introduction/overview and the Near &amp;amp; Mid-Term Action Plans.&lt;br /&gt;
*Read [http://cyber.law.harvard.edu/cyberlaw_winter10/Future_of_Wikipedia Future of Wikipedia] wiki background paper&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Assignment&#039;&#039;: Before next class, post [[Day 5 Predictions]]. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Thoughts after class&#039;&#039;: [[Day 4 Thoughts]]&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt; &#039;&#039;&#039;Friday, January 8th&#039;&#039;&#039; &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;FIELD TRIP: &#039;&#039;BONUS&#039;&#039;&#039;&#039;&#039;: 10:30 am eBay office visit (shuttle from SLS), including JZ talk and meeting with eBay lawyers and security experts&lt;br /&gt;
*If you&#039;re unable to attend, you might want to watch JZ&#039;s [http://www.youtube.com/watch?v=Dw3h-rae3uo Minds for Sale talk].&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;CLASS&#039;&#039;&#039;: 3:00-5:00pm SLS Room 280B, guests to begin arriving at 3:30pm&lt;br /&gt;
:Wikipedia has grown quickly and rapidly to become one of if not the largest online content-generating collaboration. Following the 2009 Wikimania, Wikimedia has undertaken a self-review, looking at strategies for the future of Wikipedia. Is it a sustainable model?  and if so, to what other fields is it applicable? How can its reception in academia be improved? and what are its applications for education?&lt;br /&gt;
:Brief introduction of next week&#039;s cross-cutting themes&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Guests&#039;&#039;: &lt;br /&gt;
*Stu West, [http://wikimediafoundation.org/wiki/Board_of_Trustees#Stu_West Wikimedia Foundation Board Member]&lt;br /&gt;
*Mike Godwin, Wikimedia General Counsel&lt;br /&gt;
*Phoebe Ayers, Wikimedia volunteer&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Readings&#039;&#039;: &lt;br /&gt;
*Review &amp;lt;span style=&amp;quot;font-variant:small-caps&amp;quot;&amp;gt;Zittrain, [http://yupnet.org/zittrain/ The Future of the Internet: And How to Stop It]&amp;lt;/span&amp;gt;; Chapter 6&lt;br /&gt;
*Peruse Wikipedia&#039;s [http://strategy.wikimedia.org/wiki/Main_Page Strategy Page]&lt;br /&gt;
*Strona, &#039;&#039;[http://prawo.uni.wroc.pl/~kwasnicki/EkonLit6/WikipediaSoul.pdf The Battle for Wikipedia&#039;s Soul]&#039;&#039;, &amp;lt;span style=&amp;quot;font-variant:small-caps&amp;quot;&amp;gt;The Economist&amp;lt;/span&amp;gt;, March 6, 2008. &lt;br /&gt;
*&#039;&#039;[http://www.insidehighered.com/news/2007/01/26/wiki A Stand Against Wikipedia?]&#039;&#039;, &amp;lt;span style=&amp;quot;font-variant:small-caps&amp;quot;&amp;gt;Inside Higher Ed&amp;lt;/span&amp;gt;, Jan. 26, 2007.&lt;br /&gt;
*Browse [http://www.wikipedia-watch.org/ Wikipedia Watch] and [http://en.wikipedia.org/wiki/Criticism_of_Wikipedia Criticism of Wikipedia]&lt;br /&gt;
*&#039;&#039;[http://www.resourceshelf.com/2009/11/23/wsj-volunteers-log-off-as-wikipedia-ages/ Wikipedia Volunteers Log Off as Wikipedia Ages]&#039;&#039;, &amp;lt;span style=&amp;quot;font-variant:small-caps&amp;quot;&amp;gt;Wall Street Journal&amp;lt;/span&amp;gt;.&lt;br /&gt;
*&#039;&#039;[http://infodisiac.com/blog/2009/12/new-editors-are-joining-english-wikipedia-in-droves/ New editors are joining English Wikipedia in droves?]&#039;&#039;, &amp;lt;span style=&amp;quot;font-variant:small-caps&amp;quot;&amp;gt;Infodisiac&amp;lt;/span&amp;gt;, Dec. 6, 2009.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Assignment&#039;&#039;: Before next class, post [[Day 6 Predictions]]. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Thoughts after class&#039;&#039;: [[Day 5 Thoughts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;EVENING EVENT: &#039;&#039;BONUS&#039;&#039;&#039;&#039;&#039;: Cocktails and hors d&#039;oeuvres at David Hornik&#039;s office in Palo Alto after class.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt; &#039;&#039;&#039;Saturday, January 9th&#039;&#039;&#039; &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Tour of San Francisco (Optional); details TBD. To give input and suggestions, visit [[Tour Ideas]].&lt;br /&gt;
&lt;br /&gt;
==WEEK TWO: CROSS-CUTTING THEMES==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt; &#039;&#039;&#039;Monday, January 11th&#039;&#039;&#039; &amp;lt;/center&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;CLASS&#039;&#039;&#039;: 7:20-9:20pm SLS Room 280B, guests to begin arriving at 7:50pm&lt;br /&gt;
:One potential way to address some of the problems addressed in this course is through innovations and technological solutions. Several solutions have changed the way our browsers work and thereby changed the way we interact with the internet, making life better. In what other areas could a similar approach be applied? Change the technology, save the world. &lt;br /&gt;
:Introduction to cross-cutting theme of privacy, anonymity and liability on the internet&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Guests&#039;&#039;: &lt;br /&gt;
*John M. Agosta, [http://disputefinder.cs.berkeley.edu/ DisputeFinder]&lt;br /&gt;
*Tye Rattenbury, DisputeFinder&lt;br /&gt;
*Rob Ennals, DisputeFinder&lt;br /&gt;
*Tad Hersch, DisputeFinder&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Readings&#039;&#039;: &lt;br /&gt;
*Visit [http://www.herdict.org/web/ HerdictWeb]&lt;br /&gt;
*Watch [http://www.youtube.com/watch?v=NggzBHSXdCo Video explanation of Herdict] (student suggested)&lt;br /&gt;
*Zittrain&#039;s [http://www.hyperorg.com/blogger/2009/02/10/berkman-jz-on-herdict/ Comments on Herdict] at a Berkman Center Lunch&lt;br /&gt;
*Visit [http://disputefinder.cs.berkeley.edu/ DisputeFinder] (Test it out!)&lt;br /&gt;
*Visit [https://www.new.net/ New.net]&lt;br /&gt;
**How can .church domain names exist when it does not exist? Look at the new.net domain decoder&lt;br /&gt;
**Compare with [http://en.wikipedia.org/wiki/List_of_Internet_top-level_domains List of Internet Domains]&lt;br /&gt;
*Read Introduction to Ann Bartow, &#039;&#039;[http://www.law.harvard.edu/students/orgs/jlg/vol322/383-430.pdf  Internet Defamation As Profit Center: The Monetization of Online Harrassment]&#039;&#039;, 32 &amp;lt;span style=&amp;quot;font-variant:small-caps&amp;quot;&amp;gt;Harvard Journal of Law &amp;amp; Gender&amp;lt;/span&amp;gt; 383 (2009).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Assignment&#039;&#039;: Before next class, post [[Day 7 Predictions]]. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Thoughts after class&#039;&#039;: [[Day 6 Thoughts]]&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt; &#039;&#039;&#039;Tuesday, January 12th&#039;&#039;&#039; &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;WORKSHOP: &#039;&#039;BONUS&#039;&#039;&#039;&#039;&#039;: 1-2pm Faculty Lounge, Stanford [http://public.resource.org/law.gov/ law.gov workshop]&lt;br /&gt;
Hosted by Carl Malamud &lt;br /&gt;
:Some students attend the entire workshop, 10am-3pm&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;CLASS&#039;&#039;&#039;: 5:15-7:15pm SLS Room 280B, guests to begin arriving at 5:45pm&lt;br /&gt;
:Privacy and anonymity can raise significant issues for accountability for online actions. Users often believe they are more anonymous than they truly are online - how can we better educate the public about the reality of privacy online? Consider the Drumbeat privacy project and creative commons issues. &lt;br /&gt;
:Introduction to the cross-cutting theme of due process and dispute resolution on the internet. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Guests&#039;&#039;: &lt;br /&gt;
*Ryan Calo, SLS Fellow&lt;br /&gt;
*Ebele Okobi-Harris, Yahoo! Director of Business and Human Rights&lt;br /&gt;
*Mark Surman, Mozilla&lt;br /&gt;
*Michael Fertik, Reputation Defender&lt;br /&gt;
*Carl Malamud&lt;br /&gt;
*Julie Martin, Mozilla&lt;br /&gt;
*Aza Raskin, Mozilla&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Readings&#039;&#039;: &lt;br /&gt;
*Browse [http://creativecommons.org/ Creative Commons] for discussion&lt;br /&gt;
*Review &amp;lt;span style=&amp;quot;font-variant:small-caps&amp;quot;&amp;gt;Zittrain, [http://yupnet.org/zittrain/ The Future of the Internet: And How to Stop It]&amp;lt;/span&amp;gt;; Chapter 9 on Data Genealogy&lt;br /&gt;
*Odia Kagan, &#039;&#039;[http://www.ibls.com/internet_law_news_portal_view.aspx?s=latestnews&amp;amp;id=1915 Fighting Anonymous Defamation],&#039;&#039; &amp;lt;span style=&amp;quot;font-variant:small-caps&amp;quot;&amp;gt;Int&#039;l Business Law Services&amp;lt;/span&amp;gt;, November 26, 2007. &lt;br /&gt;
*Consider commercial applications; visit [http://www.reputationdefender.com/ ReputationDefender]&lt;br /&gt;
*[https://wiki.mozilla.org/Drumbeat/Challenges/Privacy_Icons Drumbeat privacy icon challenge] backgrounder&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Additional Materials&#039;&#039; (suggested by student):&lt;br /&gt;
*Watch [http://www.youtube.com/watch?v=JCbKv9yiLiQ Message from Anonymous to the Church of Scientology];&lt;br /&gt;
*Skim [http://en.wikipedia.org/wiki/Anonymous_%28group%29 Wikipedia&#039;s article about Anonymous Group];&lt;br /&gt;
*Read about (and use!) [http://www.torproject.org/ Tor]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Assignment&#039;&#039;: Before next class, post [[Day 8 Predictions]]. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Thoughts after class&#039;&#039;: [[Day 7 Thoughts]]&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt; &#039;&#039;&#039;Wednesday, January 13th&#039;&#039;&#039; &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;CLASS&#039;&#039;&#039;: 6:30-8:30pm SLS Room 280B, guests to begin arriving at 7:00pm&lt;br /&gt;
:How do our due process concerns translate to the internet and online communities? Should due process exist on the internet? Is the internet public or private space and under what terms do we have the privilege or right to access?  &lt;br /&gt;
:Consider, for example, how much due process should be required to remove an account from Facebook, Google or Twitter. How much due process is necessary for a take-down on YouTube and what right of appeal do you have in any of these circumstances?&lt;br /&gt;
:Introduction to online collaboration and group motivation strategies&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Guests&#039;&#039;: &lt;br /&gt;
&lt;br /&gt;
* Kim Scott, Google &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Readings&#039;&#039;:&lt;br /&gt;
&lt;br /&gt;
* Skim Elizabeth Thornburg, &#039;&#039;[http://faculty.smu.edu/ethornbu/Thornburg%20Macro.doc Going Private: Technology, Due Process, and Internet Dispute Resolution]&#039;&#039;, 34 &amp;lt;span style=&amp;quot;font-variant:small-caps&amp;quot;&amp;gt;Univ. Cal. Davis&amp;lt;/span&amp;gt; 151 (2000). &lt;br /&gt;
* Read through the Facebook or Google terms of service (see the primer above)&lt;br /&gt;
* Recall Zittrain, Chapter 7, on [http://yupnet.org/zittrain/archives/18#48 Private Sheriffs]&lt;br /&gt;
* Terri Wells, &#039;&#039;[http://www.seochat.com/c/a/Search-Engine-News/Beware-the-Google-Death-Penalty/ Beware the Google &#039;Death Penalty&#039;]&#039;&#039;,&amp;lt;span style=&amp;quot;font-variant:small-caps&amp;quot;&amp;gt;Search Engine News&amp;lt;/span&amp;gt; (2006).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Assignment&#039;&#039;: Before next class, post [[Day 9 Predictions]]. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Thoughts after class&#039;&#039;: [[Day 8 Thoughts]]&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt; &#039;&#039;&#039;Thursday, January 14th&#039;&#039;&#039; &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;CLASS&#039;&#039;&#039;: 11:10am-1:10pm SLS Room 280B, guests to begin arriving at 11:40am&lt;br /&gt;
:Online collaboration projects require internet organizations to motivate and coordinate large groups of people.  This requires both motivating good actors to participate and motivating bad actors either to not participate or to conform to the rules/standards of the site.  How can website hosts face these challenges? How involved should the users of cooperatively developed sites be in their governments?&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Guests&#039;&#039;: &lt;br /&gt;
*Daniel Hoffer, [http://www.couchsurfing.org/ Couchsurfing]&lt;br /&gt;
*Micah Schaffer&lt;br /&gt;
*Dan Scholnick, [http://www.trinityventures.com/venture-capital-team/bio.php?first-name=Dan&amp;amp;last-name=Scholnick Trinity Ventures]&lt;br /&gt;
*Ben Rigby, [http://beextra.org The Extraordinaries]&lt;br /&gt;
*Stu West, [http://wikimediafoundation.org/wiki/Board_of_Trustees#Stu_West Wikimedia Foundation Board Member]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Readings&#039;&#039;: &lt;br /&gt;
*F. Gino, Jun Gu, &amp;amp; Chen-Bo Zhong, &#039;&#039;[http://drop.io/cyberlaw_winter10 Contagion or Restitution? When bad apples can motivate ethical behavior]&#039;&#039;, 45 &amp;lt;span style=&amp;quot;font-variant:small-caps&amp;quot;&amp;gt;J. Experimental Social Psychology&amp;lt;/span&amp;gt; 1299-1302 (2009).&lt;br /&gt;
*Browse [http://www.opencouchsurfing.org/ OpenCouchSurfing.org] posts and complaints&lt;br /&gt;
*Review readings from Friday, January 8th on Wikipedia and motivation of contributors&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Thoughts after class&#039;&#039;: [[Day 9 Thoughts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;CLASS SOCIAL&#039;&#039;&#039;: Bonus, evening, details TBD&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt; &#039;&#039;&#039;Friday, January 15th&#039;&#039;&#039; &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;CLASS&#039;&#039;&#039;: 1:00-3:00pm SLS Room 280B, guests to begin arriving at 1:30pm&lt;br /&gt;
:Ubiquitous Human Computing presentation (60 min)&lt;br /&gt;
:Discussion of solution&#039;s strengths and weaknesses and other approaches to consider&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Guests&#039;&#039;: &lt;br /&gt;
*Fabio Rosati, Elance&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Group Documents&#039;&#039;:&lt;br /&gt;
*[http://docs.google.com/Doc?docid=0AVl_o5lQOXEqZGMzejN4OG5fMjEzZnFyeG54ZG4&amp;amp;hl=en Best practices ]&lt;br /&gt;
*[http://docs.google.com/Doc?docid=0AVl_o5lQOXEqZGMzejN4OG5fMjE2Z3pjNWR2ZGM&amp;amp;hl=en Technological solutions ]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Thoughts about the discussed solutions&#039;&#039;: [[UHC Solutions]]&lt;br /&gt;
&lt;br /&gt;
==WEEK THREE: SOLUTIONS==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt; &#039;&#039;&#039;Monday, January 18th&#039;&#039;&#039; &amp;lt;/center&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;NO CLASS&#039;&#039;&#039;: [http://en.wikipedia.org/wiki/Martin_Luther_King,_Jr._Day Martin Luther King, Jr. Day]&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt; &#039;&#039;&#039;Tuesday, January 19th&#039;&#039;&#039; &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;FIELD TRIP: &#039;&#039;BONUS&#039;&#039;&#039;&#039;&#039;: Google, 3:30pm&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;CLASS&#039;&#039;&#039;: Held at Google during visit&lt;br /&gt;
:Cybersecurity presentation (60 min)&lt;br /&gt;
:Discussion of solution&#039;s strengths and weaknesses and other approaches to consider&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Guests&#039;&#039;: &lt;br /&gt;
*Mitchell Baker&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt; &#039;&#039;&#039;Wednesday, January 20th&#039;&#039;&#039; &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;FIELD TRIP: &#039;&#039;BONUS&#039;&#039;:&#039;&#039;&#039; Facebook, 12:30-2pm (TBC)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;CLASS&#039;&#039;&#039;: 6:30-8:30pm SLS Room 280B, guests to begin arriving at 7:00pm&lt;br /&gt;
:Global Network Initiative presentation (60 min)&lt;br /&gt;
:Discussion of solution&#039;s strengths and weaknesses and other approaches to consider&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Guests&#039;&#039;:&lt;br /&gt;
*Esther Wojcicki&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt; &#039;&#039;&#039;Thursday, January 21st&#039;&#039;&#039; &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;CLASS&#039;&#039;&#039;: 11:10am-1:10pm SLS Room 280B, guests to begin arriving at 11:40am&lt;br /&gt;
:Future of Wikipedia presentation (60 min)&lt;br /&gt;
:Discussion of solution&#039;s strengths and weaknesses and other approaches to consider&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Guests&#039;&#039;: &lt;br /&gt;
*Craig Newmark, [http://www.craigslist.org/about/craig_newmark Craigslist founder] and [http://wikimediafoundation.org/wiki/Advisory_Board#Craig_Newmark Wikimedia Foundation Advisory Board member]&lt;br /&gt;
*Edward Wes&lt;br /&gt;
*Jack Herrick, founder of [http://www.wikihow.com/Main-Page WikiHow]&lt;br /&gt;
*Stu West, [http://wikimediafoundation.org/wiki/Board_of_Trustees#Stu_West Wikimedia Foundation Board Member]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;WRAP-UP DINNER&#039;&#039;&#039;: 7:20-9:20pm SLS Student Lounge&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt; &#039;&#039;&#039;Friday, January 22nd&#039;&#039;&#039; &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;ReputationDefender visit&#039;&#039;&#039;: 2:30pm&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt; &#039;&#039;&#039;January 31st&#039;&#039;&#039; &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;FINAL PROJECTS DUE&#039;&#039;&#039;&lt;/div&gt;</summary>
		<author><name>Jharrow</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cyberlaw_winter10/?title=Main_Page&amp;diff=1084</id>
		<title>Main Page</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cyberlaw_winter10/?title=Main_Page&amp;diff=1084"/>
		<updated>2010-01-29T02:27:21Z</updated>

		<summary type="html">&lt;p&gt;Jharrow: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Welcome to Difficult Problems in Cyberlaw, a January course taught by Professor Jonathan Zittrain and Elizabeth Stark, co-hosted by Stanford Law School and Harvard Law SchooI.&lt;br /&gt;
&lt;br /&gt;
In addition to this wiki, this class maintains a [http://blogs.law.harvard.edu/difficultprobs/ blog] and [http://twitter.com/DifficultProbs twitter feed]. Check them out!&lt;br /&gt;
&lt;br /&gt;
If you are a student, please see the [[Student Responsibilities]] section and [[Course Logistics]].  For admins looking for details on field trips, please visit [http://cyber.law.harvard.edu/difficultproblems/Main_Page#Field_Trip_Logistic here].  All regular class meetings will be at &#039;&#039;&#039;Stanford Law School Classroom 280B&#039;&#039;&#039;. &lt;br /&gt;
&lt;br /&gt;
This [http://www.law.stanford.edu/contact/#maps map site] has a map of the [http://www.aaccessmaps.com/show/map/us/ca/bayarea Bay Area], [http://ucomm.stanford.edu/map/ Stanford campus], and [http://transportation.stanford.edu/images/visitor-bus.pdf visitor parking] at Stanford.&lt;br /&gt;
&lt;br /&gt;
The four main difficult problems to be addressed are: &lt;br /&gt;
*[[Global Network Initiative]] ([[GNI Brainstorming |Group Page]])&lt;br /&gt;
*[[Ubiquitous Human Computing]]  ([[Ubicomp Brainstorming |Group Page]])&lt;br /&gt;
*[[Future of Wikipedia]]&lt;br /&gt;
*[[Cybersecurity]] ([[Cybersecurity Project|Final Project]]) ([[Cybersecurity Brainstorming |Group Page]])&lt;br /&gt;
&lt;br /&gt;
Cross-cutting themes include: &lt;br /&gt;
*[[Due process on the Internet among private sheriffs]]&lt;br /&gt;
*[[The role of intermediaries]]&lt;br /&gt;
*[[Motivating good and bad actors]]&lt;br /&gt;
*[[Collaborating and relying on masses]]&lt;br /&gt;
*[[Privacy and Anonymity on the Internet]]&lt;br /&gt;
&lt;br /&gt;
Group presentation schedule:&lt;br /&gt;
*Friday, Jan. 15th: Ubiquitous Human Computing&lt;br /&gt;
*Tuesday, Jan. 19th: Cybersecurity&lt;br /&gt;
*Wednesday, Jan. 20th: Global Network Initiative&lt;br /&gt;
*Thursday, Jan. 21st: Future of Wikipedia&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==WEEK ONE: DEFINING THE PROBLEMS==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt; &#039;&#039;&#039;Monday, January 4th&#039;&#039;&#039; &amp;lt;/center&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;LUNCH&#039;&#039;&#039;: 12-2pm SLS, Room 280B&lt;br /&gt;
:Student introductions&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;CLASS&#039;&#039;&#039;: 7:20-9:20pm SLS Room 280B&lt;br /&gt;
:A brief overview of the course, its goals and expectations, including an introduction to the difficult problems and the cross-cutting themes.  &lt;br /&gt;
:A quiz on Zittrain&#039;s book, &amp;lt;span style=&amp;quot;font-variant:small-caps&amp;quot;&amp;gt;[http://yupnet.org/zittrain/ The Future of the Internet: And How to Stop It]&amp;lt;/span&amp;gt; will be given. &lt;br /&gt;
:Brief introduction to the Global Network Initiative&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Readings For Class&#039;&#039;: &lt;br /&gt;
*Read &amp;lt;span style=&amp;quot;font-variant:small-caps&amp;quot;&amp;gt;[http://yupnet.org/zittrain/ The Future of the Internet: And How to Stop It]&amp;lt;/span&amp;gt;&lt;br /&gt;
*Explore the [http://www.globalnetworkinitiative.org/ Global Network Initiative] website&lt;br /&gt;
*Read the [http://cyber.law.harvard.edu/cyberlaw_winter10/GNI GNI Wiki Primer]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Assignments&#039;&#039;: Before next class, post [[Day 2 Predictions]]. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Thoughts after class&#039;&#039;: [[Day 1 Thoughts]]&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt; &#039;&#039;&#039;Tuesday, January 5th&#039;&#039;&#039; &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;CYBERSECURITY BACKGROUND: &#039;&#039;BONUS&#039;&#039;&#039;&#039;&#039;: 2-4pm SLS Room 280B &lt;br /&gt;
: Professor Zittrain will interview Professor [http://www.law.harvard.edu/faculty/directory/index.html?id=559 Jack Goldsmith] as an overview of cybersecurity as it has evolved and as it can potentially be addressed. &lt;br /&gt;
&lt;br /&gt;
*&#039;&#039;Bonus Writing Opportunity&#039;&#039;: produce a summary of the cybersecurity event, to be used as background reading for Thursday&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;CLASS&#039;&#039;&#039;: 5:15-7:15pm SLS Room 280B&lt;br /&gt;
:Identify the first-order problems regarding corporate responsibility and free expression on the internet. Examine how GNI attempts to address these problems and then evaluate whether GNI is a success and whether better approaches could be taken. &lt;br /&gt;
:Introduction to ubiquitous human computing.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Guests:&#039;&#039; &lt;br /&gt;
*Mark Chandler, CISCO&lt;br /&gt;
*Chuck Cosson, Microsoft&lt;br /&gt;
*Dunstan Hope, BSR&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Readings:&#039;&#039; &lt;br /&gt;
*Read Rhys Blakely, &#039;&#039;[http://business.timesonline.co.uk/tol/business/industry_sectors/media/article728898.ece Yahoo in second Chinese blog Row],&#039;&#039; &amp;lt;span style=&amp;quot;font-variant:small-caps&amp;quot;&amp;gt;TimesOnline&amp;lt;/span&amp;gt;, Feb. 9, 2006. &lt;br /&gt;
*Read Colin Maclay, &amp;quot;[http://drop.io/cyberlaw_winter10/asset/maclay-access-controlled-pdf Protecting Privacy and Expression Online],&amp;quot; &#039;&#039;in&#039;&#039; &amp;lt;span style=&amp;quot;font-variant:small-caps&amp;quot;&amp;gt;Access Controlled&amp;lt;/span&amp;gt; (Ronald Diebert et al., eds., MIT Press: Cambridge, MA, 2010).&lt;br /&gt;
*Read GNI [http://www.globalnetworkinitiative.org/cms/uploads/1/GNI_-_Principles_1_.pdf Guiding Principles]&lt;br /&gt;
*Read the [http://cyber.law.harvard.edu/cyberlaw_winter10/Ubiquitous_Human_Computing UbiComp Wiki Primer]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Assignments&#039;&#039;: Before next class, post [[Day 3 Predictions]]. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Thoughts after class&#039;&#039;: [[Day 2 Thoughts]]&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt; &#039;&#039;&#039;Wednesday, January 6th&#039;&#039;&#039; &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;CLASS&#039;&#039;&#039;: 6:30-8:30pm SLS Room 280B, guests to begin arriving at 7:00pm&lt;br /&gt;
:Examine the nature of ubiquitous human computing and potential future applications of human computing and the dangers. &lt;br /&gt;
:Introduction to cybersecurity. &lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Guests&#039;&#039;: &lt;br /&gt;
*Lukas Biewald, [http://crowdflower.com/ CrowdFlower]&lt;br /&gt;
*Bjoern Hartman, see his [http://bjoern.org/projects/catbook/ Mechanical Turk Cats Book]&lt;br /&gt;
*Aaron Koblin, see his [http://www.aaronkoblin.com/work.html Ten Thousand Cents and Sheep Market projects]&lt;br /&gt;
 &lt;br /&gt;
&#039;&#039;Readings&#039;&#039;:&lt;br /&gt;
*Visit [http://www.mturk.com/ Mechanical Turk], [http://www.liveops.com/ LiveOps], [http://www.crowdflower.com CrowdFlower] or other human computing site&lt;br /&gt;
**Watch the [http://www.ustream.tv/recorded/2167086 12-minute video] of Lukas&#039; CrowdFlower presentation at TechCrunch&lt;br /&gt;
*Skim Nancy R. Mansfield, &#039;&#039;[http://www.allbusiness.com/technology/internet-technology/618188-1.html The information revolution and its impact on the employment relationship: an analysis of the cyberspace workplace]&#039;&#039;, &amp;lt;span style=&amp;quot;font-variant:small-caps&amp;quot;&amp;gt;American Business Law Journal&amp;lt;/span&amp;gt; (2003).&lt;br /&gt;
*Kate Thomas, &#039;&#039;[http://www.seiu.org/2009/12/insurers-hire-mafia-to-spam-congress.php Insurers Hire Mafia to Spam Congress]&#039;&#039;, &amp;lt;span style=&amp;quot;font-variant:small-caps&amp;quot;&amp;gt;SEIU.org Blog&amp;lt;/span&amp;gt;, Dec. 10, 2009. &lt;br /&gt;
*Read Jonathan Zittrain, &#039;&#039;[http://drop.io/cyberlaw_winter10/asset/ssrn-id1140445-pdf Ubiquitous Human Computing]&#039;&#039;, SSRN Paper No 32/2008 (July 2008). &lt;br /&gt;
*Read the [http://cyber.law.harvard.edu/cyberlaw_winter10/Cybersecurity Cybersecurity Wiki Primer]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;ASSIGNMENT: Due -- Email Admin with Problem Topic Choice&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Assignment&#039;&#039;: Before next class, post [[Day 4 Predictions]]. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Thoughts after class&#039;&#039;: [[Day 3 Thoughts]]&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt; &#039;&#039;&#039;Thursday, January 7th&#039;&#039;&#039; &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;CLASS&#039;&#039;&#039;: 11:10am-1:10pm SLS Room 280B, guests to begin arriving at 11:40am&lt;br /&gt;
:Cybersecurity has been identified as one of the greatest threats facing the United States today, but it is ill-defined and almost impossible to address. How can we frame this problem to better inspire solutions?  How should government, military, businesses, and internet/tech approach the problem from different angles and do these different approaches work together?&lt;br /&gt;
:Introduction to Future of Wikipedia&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Guests&#039;&#039;: &lt;br /&gt;
*Chuck Cosson, Microsoft&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Readings&#039;&#039;: &lt;br /&gt;
*Listen to David Clark, [http://www.ischool.berkeley.edu/newsandevents/events/sl20090304 The Internets We Did Not Build].&lt;br /&gt;
*Col. Allen &amp;amp; Lt. Col Demchak, &#039;&#039;[http://drop.io/cyberlaw_winter10 The Palestinian-Israeli Cyberwar]&#039;&#039;, &amp;lt;span style=&amp;quot;font-variant:small-caps&amp;quot;&amp;gt;Military Review&amp;lt;/span&amp;gt; (2003). &lt;br /&gt;
*Kim Zetter, &#039;&#039;[http://www.wired.com/threatlevel/2008/08/revealed-the-in/ Revealed: The Internet&#039;s Biggest Security Hole]&#039;&#039;, &amp;lt;span style=&amp;quot;font-variant:small-caps&amp;quot;&amp;gt;Wired&amp;lt;/span&amp;gt; (2008). &lt;br /&gt;
*Review &amp;lt;span style=&amp;quot;font-variant:small-caps&amp;quot;&amp;gt;Zittrain, [http://yupnet.org/zittrain/ The Future of the Internet: And How to Stop It]&amp;lt;/span&amp;gt;; Chapter 3&lt;br /&gt;
*Skim CENTRA Technology, [http://drop.io/cyberlaw_winter10 Cyber Compendium] Workshop, Nov. 2009.&lt;br /&gt;
*Skim the White House [http://www.whitehouse.gov/assets/documents/Cyberspace_Policy_Review_final.pdf Cyberspace Policy Review] (2009); focus on the introduction/overview and the Near &amp;amp; Mid-Term Action Plans.&lt;br /&gt;
*Read [http://cyber.law.harvard.edu/cyberlaw_winter10/Future_of_Wikipedia Future of Wikipedia] wiki background paper&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Assignment&#039;&#039;: Before next class, post [[Day 5 Predictions]]. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Thoughts after class&#039;&#039;: [[Day 4 Thoughts]]&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt; &#039;&#039;&#039;Friday, January 8th&#039;&#039;&#039; &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;FIELD TRIP: &#039;&#039;BONUS&#039;&#039;&#039;&#039;&#039;: 10:30 am eBay office visit (shuttle from SLS), including JZ talk and meeting with eBay lawyers and security experts&lt;br /&gt;
*If you&#039;re unable to attend, you might want to watch JZ&#039;s [http://www.youtube.com/watch?v=Dw3h-rae3uo Minds for Sale talk].&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;CLASS&#039;&#039;&#039;: 3:00-5:00pm SLS Room 280B, guests to begin arriving at 3:30pm&lt;br /&gt;
:Wikipedia has grown quickly and rapidly to become one of if not the largest online content-generating collaboration. Following the 2009 Wikimania, Wikimedia has undertaken a self-review, looking at strategies for the future of Wikipedia. Is it a sustainable model?  and if so, to what other fields is it applicable? How can its reception in academia be improved? and what are its applications for education?&lt;br /&gt;
:Brief introduction of next week&#039;s cross-cutting themes&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Guests&#039;&#039;: &lt;br /&gt;
*Stu West, [http://wikimediafoundation.org/wiki/Board_of_Trustees#Stu_West Wikimedia Foundation Board Member]&lt;br /&gt;
*Mike Godwin, Wikimedia General Counsel&lt;br /&gt;
*Phoebe Ayers, Wikimedia volunteer&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Readings&#039;&#039;: &lt;br /&gt;
*Review &amp;lt;span style=&amp;quot;font-variant:small-caps&amp;quot;&amp;gt;Zittrain, [http://yupnet.org/zittrain/ The Future of the Internet: And How to Stop It]&amp;lt;/span&amp;gt;; Chapter 6&lt;br /&gt;
*Peruse Wikipedia&#039;s [http://strategy.wikimedia.org/wiki/Main_Page Strategy Page]&lt;br /&gt;
*Strona, &#039;&#039;[http://prawo.uni.wroc.pl/~kwasnicki/EkonLit6/WikipediaSoul.pdf The Battle for Wikipedia&#039;s Soul]&#039;&#039;, &amp;lt;span style=&amp;quot;font-variant:small-caps&amp;quot;&amp;gt;The Economist&amp;lt;/span&amp;gt;, March 6, 2008. &lt;br /&gt;
*&#039;&#039;[http://www.insidehighered.com/news/2007/01/26/wiki A Stand Against Wikipedia?]&#039;&#039;, &amp;lt;span style=&amp;quot;font-variant:small-caps&amp;quot;&amp;gt;Inside Higher Ed&amp;lt;/span&amp;gt;, Jan. 26, 2007.&lt;br /&gt;
*Browse [http://www.wikipedia-watch.org/ Wikipedia Watch] and [http://en.wikipedia.org/wiki/Criticism_of_Wikipedia Criticism of Wikipedia]&lt;br /&gt;
*&#039;&#039;[http://www.resourceshelf.com/2009/11/23/wsj-volunteers-log-off-as-wikipedia-ages/ Wikipedia Volunteers Log Off as Wikipedia Ages]&#039;&#039;, &amp;lt;span style=&amp;quot;font-variant:small-caps&amp;quot;&amp;gt;Wall Street Journal&amp;lt;/span&amp;gt;.&lt;br /&gt;
*&#039;&#039;[http://infodisiac.com/blog/2009/12/new-editors-are-joining-english-wikipedia-in-droves/ New editors are joining English Wikipedia in droves?]&#039;&#039;, &amp;lt;span style=&amp;quot;font-variant:small-caps&amp;quot;&amp;gt;Infodisiac&amp;lt;/span&amp;gt;, Dec. 6, 2009.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Assignment&#039;&#039;: Before next class, post [[Day 6 Predictions]]. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Thoughts after class&#039;&#039;: [[Day 5 Thoughts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;EVENING EVENT: &#039;&#039;BONUS&#039;&#039;&#039;&#039;&#039;: Cocktails and hors d&#039;oeuvres at David Hornik&#039;s office in Palo Alto after class.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt; &#039;&#039;&#039;Saturday, January 9th&#039;&#039;&#039; &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Tour of San Francisco (Optional); details TBD. To give input and suggestions, visit [[Tour Ideas]].&lt;br /&gt;
&lt;br /&gt;
==WEEK TWO: CROSS-CUTTING THEMES==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt; &#039;&#039;&#039;Monday, January 11th&#039;&#039;&#039; &amp;lt;/center&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;CLASS&#039;&#039;&#039;: 7:20-9:20pm SLS Room 280B, guests to begin arriving at 7:50pm&lt;br /&gt;
:One potential way to address some of the problems addressed in this course is through innovations and technological solutions. Several solutions have changed the way our browsers work and thereby changed the way we interact with the internet, making life better. In what other areas could a similar approach be applied? Change the technology, save the world. &lt;br /&gt;
:Introduction to cross-cutting theme of privacy, anonymity and liability on the internet&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Guests&#039;&#039;: &lt;br /&gt;
*John M. Agosta, [http://disputefinder.cs.berkeley.edu/ DisputeFinder]&lt;br /&gt;
*Tye Rattenbury, DisputeFinder&lt;br /&gt;
*Rob Ennals, DisputeFinder&lt;br /&gt;
*Tad Hersch, DisputeFinder&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Readings&#039;&#039;: &lt;br /&gt;
*Visit [http://www.herdict.org/web/ HerdictWeb]&lt;br /&gt;
*Watch [http://www.youtube.com/watch?v=NggzBHSXdCo Video explanation of Herdict] (student suggested)&lt;br /&gt;
*Zittrain&#039;s [http://www.hyperorg.com/blogger/2009/02/10/berkman-jz-on-herdict/ Comments on Herdict] at a Berkman Center Lunch&lt;br /&gt;
*Visit [http://disputefinder.cs.berkeley.edu/ DisputeFinder] (Test it out!)&lt;br /&gt;
*Visit [https://www.new.net/ New.net]&lt;br /&gt;
**How can .church domain names exist when it does not exist? Look at the new.net domain decoder&lt;br /&gt;
**Compare with [http://en.wikipedia.org/wiki/List_of_Internet_top-level_domains List of Internet Domains]&lt;br /&gt;
*Read Introduction to Ann Bartow, &#039;&#039;[http://www.law.harvard.edu/students/orgs/jlg/vol322/383-430.pdf  Internet Defamation As Profit Center: The Monetization of Online Harrassment]&#039;&#039;, 32 &amp;lt;span style=&amp;quot;font-variant:small-caps&amp;quot;&amp;gt;Harvard Journal of Law &amp;amp; Gender&amp;lt;/span&amp;gt; 383 (2009).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Assignment&#039;&#039;: Before next class, post [[Day 7 Predictions]]. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Thoughts after class&#039;&#039;: [[Day 6 Thoughts]]&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt; &#039;&#039;&#039;Tuesday, January 12th&#039;&#039;&#039; &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;WORKSHOP: &#039;&#039;BONUS&#039;&#039;&#039;&#039;&#039;: 1-2pm Faculty Lounge, Stanford [http://public.resource.org/law.gov/ law.gov workshop]&lt;br /&gt;
Hosted by Carl Malamud &lt;br /&gt;
:Some students attend the entire workshop, 10am-3pm&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;CLASS&#039;&#039;&#039;: 5:15-7:15pm SLS Room 280B, guests to begin arriving at 5:45pm&lt;br /&gt;
:Privacy and anonymity can raise significant issues for accountability for online actions. Users often believe they are more anonymous than they truly are online - how can we better educate the public about the reality of privacy online? Consider the Drumbeat privacy project and creative commons issues. &lt;br /&gt;
:Introduction to the cross-cutting theme of due process and dispute resolution on the internet. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Guests&#039;&#039;: &lt;br /&gt;
*Ryan Calo, SLS Fellow&lt;br /&gt;
*Ebele Okobi-Harris, Yahoo! Director of Business and Human Rights&lt;br /&gt;
*Mark Surman, Mozilla&lt;br /&gt;
*Michael Fertik, Reputation Defender&lt;br /&gt;
*Carl Malamud&lt;br /&gt;
*Julie Martin, Mozilla&lt;br /&gt;
*Aza Raskin, Mozilla&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Readings&#039;&#039;: &lt;br /&gt;
*Browse [http://creativecommons.org/ Creative Commons] for discussion&lt;br /&gt;
*Review &amp;lt;span style=&amp;quot;font-variant:small-caps&amp;quot;&amp;gt;Zittrain, [http://yupnet.org/zittrain/ The Future of the Internet: And How to Stop It]&amp;lt;/span&amp;gt;; Chapter 9 on Data Genealogy&lt;br /&gt;
*Odia Kagan, &#039;&#039;[http://www.ibls.com/internet_law_news_portal_view.aspx?s=latestnews&amp;amp;id=1915 Fighting Anonymous Defamation],&#039;&#039; &amp;lt;span style=&amp;quot;font-variant:small-caps&amp;quot;&amp;gt;Int&#039;l Business Law Services&amp;lt;/span&amp;gt;, November 26, 2007. &lt;br /&gt;
*Consider commercial applications; visit [http://www.reputationdefender.com/ ReputationDefender]&lt;br /&gt;
*[https://wiki.mozilla.org/Drumbeat/Challenges/Privacy_Icons Drumbeat privacy icon challenge] backgrounder&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Additional Materials&#039;&#039; (suggested by student):&lt;br /&gt;
*Watch [http://www.youtube.com/watch?v=JCbKv9yiLiQ Message from Anonymous to the Church of Scientology];&lt;br /&gt;
*Skim [http://en.wikipedia.org/wiki/Anonymous_%28group%29 Wikipedia&#039;s article about Anonymous Group];&lt;br /&gt;
*Read about (and use!) [http://www.torproject.org/ Tor]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Assignment&#039;&#039;: Before next class, post [[Day 8 Predictions]]. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Thoughts after class&#039;&#039;: [[Day 7 Thoughts]]&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt; &#039;&#039;&#039;Wednesday, January 13th&#039;&#039;&#039; &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;CLASS&#039;&#039;&#039;: 6:30-8:30pm SLS Room 280B, guests to begin arriving at 7:00pm&lt;br /&gt;
:How do our due process concerns translate to the internet and online communities? Should due process exist on the internet? Is the internet public or private space and under what terms do we have the privilege or right to access?  &lt;br /&gt;
:Consider, for example, how much due process should be required to remove an account from Facebook, Google or Twitter. How much due process is necessary for a take-down on YouTube and what right of appeal do you have in any of these circumstances?&lt;br /&gt;
:Introduction to online collaboration and group motivation strategies&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Guests&#039;&#039;: &lt;br /&gt;
&lt;br /&gt;
* Kim Scott, Google &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Readings&#039;&#039;:&lt;br /&gt;
&lt;br /&gt;
* Skim Elizabeth Thornburg, &#039;&#039;[http://faculty.smu.edu/ethornbu/Thornburg%20Macro.doc Going Private: Technology, Due Process, and Internet Dispute Resolution]&#039;&#039;, 34 &amp;lt;span style=&amp;quot;font-variant:small-caps&amp;quot;&amp;gt;Univ. Cal. Davis&amp;lt;/span&amp;gt; 151 (2000). &lt;br /&gt;
* Read through the Facebook or Google terms of service (see the primer above)&lt;br /&gt;
* Recall Zittrain, Chapter 7, on [http://yupnet.org/zittrain/archives/18#48 Private Sheriffs]&lt;br /&gt;
* Terri Wells, &#039;&#039;[http://www.seochat.com/c/a/Search-Engine-News/Beware-the-Google-Death-Penalty/ Beware the Google &#039;Death Penalty&#039;]&#039;&#039;,&amp;lt;span style=&amp;quot;font-variant:small-caps&amp;quot;&amp;gt;Search Engine News&amp;lt;/span&amp;gt; (2006).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Assignment&#039;&#039;: Before next class, post [[Day 9 Predictions]]. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Thoughts after class&#039;&#039;: [[Day 8 Thoughts]]&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt; &#039;&#039;&#039;Thursday, January 14th&#039;&#039;&#039; &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;CLASS&#039;&#039;&#039;: 11:10am-1:10pm SLS Room 280B, guests to begin arriving at 11:40am&lt;br /&gt;
:Online collaboration projects require internet organizations to motivate and coordinate large groups of people.  This requires both motivating good actors to participate and motivating bad actors either to not participate or to conform to the rules/standards of the site.  How can website hosts face these challenges? How involved should the users of cooperatively developed sites be in their governments?&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Guests&#039;&#039;: &lt;br /&gt;
*Daniel Hoffer, [http://www.couchsurfing.org/ Couchsurfing]&lt;br /&gt;
*Micah Schaffer&lt;br /&gt;
*Dan Scholnick, [http://www.trinityventures.com/venture-capital-team/bio.php?first-name=Dan&amp;amp;last-name=Scholnick Trinity Ventures]&lt;br /&gt;
*Ben Rigby, [http://beextra.org The Extraordinaries]&lt;br /&gt;
*Stu West, [http://wikimediafoundation.org/wiki/Board_of_Trustees#Stu_West Wikimedia Foundation Board Member]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Readings&#039;&#039;: &lt;br /&gt;
*F. Gino, Jun Gu, &amp;amp; Chen-Bo Zhong, &#039;&#039;[http://drop.io/cyberlaw_winter10 Contagion or Restitution? When bad apples can motivate ethical behavior]&#039;&#039;, 45 &amp;lt;span style=&amp;quot;font-variant:small-caps&amp;quot;&amp;gt;J. Experimental Social Psychology&amp;lt;/span&amp;gt; 1299-1302 (2009).&lt;br /&gt;
*Browse [http://www.opencouchsurfing.org/ OpenCouchSurfing.org] posts and complaints&lt;br /&gt;
*Review readings from Friday, January 8th on Wikipedia and motivation of contributors&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Thoughts after class&#039;&#039;: [[Day 9 Thoughts]]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;CLASS SOCIAL&#039;&#039;&#039;: Bonus, evening, details TBD&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt; &#039;&#039;&#039;Friday, January 15th&#039;&#039;&#039; &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;CLASS&#039;&#039;&#039;: 1:00-3:00pm SLS Room 280B, guests to begin arriving at 1:30pm&lt;br /&gt;
:Ubiquitous Human Computing presentation (60 min)&lt;br /&gt;
:Discussion of solution&#039;s strengths and weaknesses and other approaches to consider&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Guests&#039;&#039;: &lt;br /&gt;
*Fabio Rosati, Elance&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Group Documents&#039;&#039;:&lt;br /&gt;
*[http://docs.google.com/Doc?docid=0AVl_o5lQOXEqZGMzejN4OG5fMjEzZnFyeG54ZG4&amp;amp;hl=en Best practices ]&lt;br /&gt;
*[http://docs.google.com/Doc?docid=0AVl_o5lQOXEqZGMzejN4OG5fMjE2Z3pjNWR2ZGM&amp;amp;hl=en Technological solutions ]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Thoughts about the discussed solutions&#039;&#039;: [[UHC Solutions]]&lt;br /&gt;
&lt;br /&gt;
==WEEK THREE: SOLUTIONS==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt; &#039;&#039;&#039;Monday, January 18th&#039;&#039;&#039; &amp;lt;/center&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;NO CLASS&#039;&#039;&#039;: [http://en.wikipedia.org/wiki/Martin_Luther_King,_Jr._Day Martin Luther King, Jr. Day]&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt; &#039;&#039;&#039;Tuesday, January 19th&#039;&#039;&#039; &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;FIELD TRIP: &#039;&#039;BONUS&#039;&#039;&#039;&#039;&#039;: Google, 3:30pm&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;CLASS&#039;&#039;&#039;: Held at Google during visit&lt;br /&gt;
:Cybersecurity presentation (60 min)&lt;br /&gt;
:Discussion of solution&#039;s strengths and weaknesses and other approaches to consider&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Guests&#039;&#039;: &lt;br /&gt;
*Mitchell Baker&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt; &#039;&#039;&#039;Wednesday, January 20th&#039;&#039;&#039; &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;FIELD TRIP: &#039;&#039;BONUS&#039;&#039;:&#039;&#039;&#039; Facebook, 12:30-2pm (TBC)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;CLASS&#039;&#039;&#039;: 6:30-8:30pm SLS Room 280B, guests to begin arriving at 7:00pm&lt;br /&gt;
:Global Network Initiative presentation (60 min)&lt;br /&gt;
:Discussion of solution&#039;s strengths and weaknesses and other approaches to consider&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Guests&#039;&#039;:&lt;br /&gt;
*Esther Wojcicki&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt; &#039;&#039;&#039;Thursday, January 21st&#039;&#039;&#039; &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;CLASS&#039;&#039;&#039;: 11:10am-1:10pm SLS Room 280B, guests to begin arriving at 11:40am&lt;br /&gt;
:Future of Wikipedia presentation (60 min)&lt;br /&gt;
:Discussion of solution&#039;s strengths and weaknesses and other approaches to consider&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Guests&#039;&#039;: &lt;br /&gt;
*Craig Newmark, [http://www.craigslist.org/about/craig_newmark Craigslist founder] and [http://wikimediafoundation.org/wiki/Advisory_Board#Craig_Newmark Wikimedia Foundation Advisory Board member]&lt;br /&gt;
*Edward Wes&lt;br /&gt;
*Jack Herrick, founder of [http://www.wikihow.com/Main-Page WikiHow]&lt;br /&gt;
*Stu West, [http://wikimediafoundation.org/wiki/Board_of_Trustees#Stu_West Wikimedia Foundation Board Member]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;WRAP-UP DINNER&#039;&#039;&#039;: 7:20-9:20pm SLS Student Lounge&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt; &#039;&#039;&#039;Friday, January 22nd&#039;&#039;&#039; &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;ReputationDefender visit&#039;&#039;&#039;: 2:30pm&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt; &#039;&#039;&#039;January 31st&#039;&#039;&#039; &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;FINAL PROJECTS DUE&#039;&#039;&#039;&lt;/div&gt;</summary>
		<author><name>Jharrow</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cyberlaw_winter10/?title=Cybersecurity_Brainstorming&amp;diff=1083</id>
		<title>Cybersecurity Brainstorming</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cyberlaw_winter10/?title=Cybersecurity_Brainstorming&amp;diff=1083"/>
		<updated>2010-01-29T02:26:21Z</updated>

		<summary type="html">&lt;p&gt;Jharrow: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This page reflects the brainstorming and discussion of the cybersecurity group in [http://en.wikipedia.org/wiki/Jonathan_Zittrain Jonathan Zittrain]&#039;s Cyberlaw: Difficult Problems Class.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Note: This page was just a scratch-pad for our ideas. Our final project is [[Cybersecurity Project|here]].&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;For the Mozilla-icon-privacy project see: [[Terms of Service Brainstorming]].&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=Problems to Tackle=&lt;br /&gt;
&lt;br /&gt;
Misaligned incentives have prevented industry, users, and government from solving many of the problems of cybersecurity. We&#039;re proposing three projects that will allow (power) users to increase the security of their data, as well as improve security for other people, and maybe even for the network as a whole. We may also be interested in working on the [[Terms of Service Brainstorming | Mozilla Privacy issue]]. &lt;br /&gt;
&lt;br /&gt;
==&amp;quot;Safeword&amp;quot;==&lt;br /&gt;
*&#039;&#039;All functionality should be inserted into the browser to appear as part of the various websites.&#039;&#039;&lt;br /&gt;
(1) Shows security level of user-selected password as it&#039;s typed in (for registration)&lt;br /&gt;
(2) If user chooses weak password, auto-fill will be turned off. User must manually type in all weak passwords &lt;br /&gt;
:Safeword will look for keystrokes and won&#039;t send the password to the website if it doesn&#039;t sense the appropriate keystrokes&lt;br /&gt;
(3) Refuse password if it&#039;s been used before (for a major/important/security-sensitive site)&lt;br /&gt;
:for security reasons, Safeword would only save the first 4 characters of each password (not the whole thing)&lt;br /&gt;
(4) Periodically prompt user to change password&lt;br /&gt;
:this would be a suggestion, not a requirement and users could set how often it should prompt&lt;br /&gt;
&lt;br /&gt;
Other Ideas:&lt;br /&gt;
*encrypted password storage within browser&lt;br /&gt;
*using recaptcha or pictures (esp game), etc as dual key for all passwords&lt;br /&gt;
*perhaps regulation requiring financial institutions to only accept strong or dual-key passwords&lt;br /&gt;
&lt;br /&gt;
NYT article on bad password security: http://www.nytimes.com/2010/01/21/technology/21password.html?hp&lt;br /&gt;
&lt;br /&gt;
==Mesh Network Vaccination==&lt;br /&gt;
Firefox plug-in used by the 5% of power users that can help patch the problems created by the larger base of security-ignorant or security-apathetic users. I made the analogy to tower defense at some point. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;For your edification, see [http://en.wikipedia.org/wiki/Tower_defense Tower Defense].&#039;&#039; &#039;&#039;[[User:Mfeld|Mfeld]] 05:18, 13 January 2010 (UTC)&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
==Stop Badware==&lt;br /&gt;
We propose a Firefox plug-in that would incorporate an improved Stop Badware database and automatically warn users when they attempt to access websites that are suspected of including malware or have been known to do so recently.  We also propose this is included in search engines.  While Firefox 3 and Google have recently implemented similar ideas, we would like to display more granular data (i.e., 99% of visitors to this site report no problems, 90% of visitors to that site), with better timing information, and automatically build in reporting of malware to the database.&lt;br /&gt;
&lt;br /&gt;
StopBadware goes independent: http://news.cnet.com/8301-27080_3-10440210-245.html&lt;br /&gt;
&lt;br /&gt;
==Distress Password==&lt;br /&gt;
Have 2 passwords -- &lt;br /&gt;
:(1) secure password -- shows all emails, all data&lt;br /&gt;
:(2) distress password -- shows limited data (like limited profile), only showing safe data&lt;br /&gt;
&lt;br /&gt;
==Password Picture==&lt;br /&gt;
Have a dual key mode of authentication for various web services: one would be the typical password, and the second would be a series of pictures.  For example, when creating an account on a website for the first time, you would choose a password and choose keywords for pictures, like &amp;quot;animal&amp;quot; or &amp;quot;tree&amp;quot;.  Logging in would require you to enter a password as well as, from a series of pictures, choose your 1, 2, or 3 pictures that show your keyword.  This would prevent robots from being able to try and guess your password, and would also prevent keystroke detectors from being fully functional.&lt;br /&gt;
&lt;br /&gt;
=Presentational ideas=&lt;br /&gt;
*&amp;quot;This is your internet, this is your internet on botnet&amp;quot;&lt;br /&gt;
*Ham Sandwich metaphor acted out in reality&lt;br /&gt;
*Voiceover puppets a la JZ&#039;s [http://www.youtube.com/watch?v=NggzBHSXdCo video explanation of Herdict]&lt;br /&gt;
*PSA Announcement featuring Internationally Recognized Magician Michael Feldman&lt;br /&gt;
*Lessig-style keynote presentation (as part)&lt;br /&gt;
&lt;br /&gt;
Spot 1: Ham Sandwich (Live).&lt;br /&gt;
&lt;br /&gt;
Magic Michael is happily doing a magic trick. Suddenly, he makes a ham sandwich appear out of nowhere. He asks an audience member, &amp;quot;And now, who would like to eat this ham sandwich?&amp;quot; People in the audience (kids?) react angrily. One says, &amp;quot;But, where did that ham sandwich come from?&amp;quot;&lt;br /&gt;
&lt;br /&gt;
CUT TO Magic Michael, now sitting on a stool, talking to the camera: Everyone knows not to eat a mysterious ham sandwich that I make appear out of nowhere. But why do some people install software when they don&#039;t know where it came from? Hi, I&#039;m internationally-recognized magician Michael Feldman, and I&#039;m here to remind you how important it is to keep your computer safe. When in doubt about whether or not you should download and install a piece of software, just follow the ham sandwich rule; if it came from a stranger and you&#039;re not sure when or where it was made, don&#039;t install it - or eat it!&lt;br /&gt;
&lt;br /&gt;
(looks great -- I just want some more magic puns, like &amp;quot;if it were a rabbit sandwich, maybe that&#039;s ok&amp;quot; or &amp;quot;installing random programs isn&#039;t magic. it&#039;s stupid.&amp;quot;)&lt;br /&gt;
&lt;br /&gt;
End with &amp;quot;The More You Know&amp;quot; music and logo? (like at the end of this stupid clip: http://www.youtube.com/watch?v=3eazYHO3Hsg&amp;amp;feature=related).&lt;br /&gt;
&lt;br /&gt;
Spot 2: &lt;br /&gt;
Magic Michael is seated, looking directly at the camera. &amp;quot;Hi, i&#039;m internationally-recognized (and renowned) magician Michael Feldman. I can make many things disappear (hand gesture, and poorly patched together video making something disappear). But there&#039;s one thing that even I can&#039;t make disappear: the cybersecurity problem. (Michael attempts to make something symbolizing cybersecurity disappears, but fails). Remember, kids, installing random programs isn&#039;t magic. It&#039;s stupid.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Image:CyberSec1.jpg|thumb|120px|alt=Whiteboard Notes Part 1|Mesh Network Vaccination / Password Protection Ideas]]&lt;br /&gt;
[[Image:CyberSec2.jpg|thumb|120px|alt=Whiteboard Notes Part 2|Ideas for Incentivizing]]&lt;br /&gt;
[[Image:CyberSec3.jpg|thumb|120px|alt=Whiteboard Notes Part 3|Stop Badware Ideas]]&lt;br /&gt;
[[Image:Problems Solved.jpg|thumb|120px|alt=Whiteboard Notes Part 4|Problems Solved by &amp;quot;Safeword&amp;quot;]]&lt;br /&gt;
[[Image:Safeword Functionality.jpg|thumb|120px|alt=Whiteboard Notes Part 4|Functionality for &amp;quot;Safeword&amp;quot;]]&lt;/div&gt;</summary>
		<author><name>Jharrow</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cyberlaw_winter10/?title=Cybersecurity_Project&amp;diff=1081</id>
		<title>Cybersecurity Project</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cyberlaw_winter10/?title=Cybersecurity_Project&amp;diff=1081"/>
		<updated>2010-01-29T02:21:19Z</updated>

		<summary type="html">&lt;p&gt;Jharrow: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Saying that cybersecurity is a &amp;quot;difficult problem&amp;quot; is like saying that reversing global warming is a difficult problem: it&#039;s true, but it doesn&#039;t quite capture how devilishly complicated and multifaceted the problems really are. There&#039;s no single reason why creating a more secure global network is so difficult; it in part has to do with the radically-distributed architecture of the Net, in part with some deep flaws computer software, and in part just from its sheer size and importance to our daily lives. (For more on this, see the nice [[Cybersecurity]] backgrounder.)&lt;br /&gt;
&lt;br /&gt;
So we came in not with the goal of providing a magical elixir that would make all credit card transactions magically secure and make it impossible for hackers to [http://googleblog.blogspot.com/2010/01/new-approach-to-china.html compromise Gmail&#039;s security]. Instead, we wanted to offer suggestions with minimal implementation headaches and maximal benefit to users, from novices to experts. This page has a short video overview of the ideas, explains some of the details of our proposal, and even has an alpha-release Firefox plugin that you can download and try out (thanks to [http://www.elance.com/ Elance] for this, by the way).&lt;br /&gt;
&lt;br /&gt;
==Overview==&lt;br /&gt;
&lt;br /&gt;
We discussed this topic at length in an in-class presentation on January 19. [http://www.vimeo.com/9036735 This] 9-minute video summarizes and extends the presentation we gave that day.&lt;br /&gt;
&lt;br /&gt;
==Specific Proposals==&lt;br /&gt;
&lt;br /&gt;
===Public Service Announcement===&lt;br /&gt;
&lt;br /&gt;
We created a Public Service Announcement for generating public awareness for the cybersecurity problem, and showed in class on January 19. It&#039;s online [http://vimeo.com/8937782 here] but is password-protected. Please email us if you were in the class and would like the password. In sum, we don&#039;t think a direct public awareness campaign will be very effective. We want to nudge users and change their behavior by changing the way browsers and websites work, not by scolding people.&lt;br /&gt;
&lt;br /&gt;
===SafeWord===&lt;br /&gt;
&lt;br /&gt;
====What is SafeWord?====&lt;br /&gt;
&lt;br /&gt;
SafeWord is a real, working FireFox plugin designed to nudge users into keeping safer and more unique passwords, though it&#039;s too unstable and unrefined to be considered anything buy alpha software. It&#039;s available for download [http://www.jasonharrow.com/safeword-1.0.0-fx.xpi here]. To install, save that file to your disk, select File --&amp;gt; Open in Firefox 3.5 or above, and install it. You will need to restart Firefox before it takes effect. Thanks to Elance for helping with the coding on very short notice.&lt;br /&gt;
&lt;br /&gt;
We have created a video demonstration of one of the key features of SafeWord [http://vimeo.com/9031865 here].&lt;br /&gt;
&lt;br /&gt;
====What Are The Goals of SafeWord?====&lt;br /&gt;
&lt;br /&gt;
SafeWord begins with a simple proposition: online passwords should be strong and different for different sites, and your browser should help you acheie that goal. Studies continue to show that most users use very simple passwords; see, for instance, [http://www.nytimes.com/2010/01/21/technology/21password.html this] &#039;&#039;New York Times&#039;&#039; that gets right to the point. &amp;quot;If your password is 123456,&amp;quot; reads the headline, &amp;quot;just make it HackMe.&amp;quot; Moreover, most users also fall into the &amp;quot;dirty habit&amp;quot; of using the same password across multiple online accounts, which can lead to a disaster if only one of the accounts is able to be compromised. An extremely detailed analysis of a 2009 attack that compromised many online accounts of Twitter employees is [http://www.techcrunch.com/2009/07/19/the-anatomy-of-the-twitter-attack/ here].&lt;br /&gt;
&lt;br /&gt;
====A Scary Story, and A Word About Annoyance====&lt;br /&gt;
&lt;br /&gt;
Even readers who are all for stronger passwords in general may nonetheless be skeptical of what can happen to &amp;quot;regular people&amp;quot; who can&#039;t be bothered to remember so many passwords, here&#039;s a very scary story - which is taken directly from the [http://www.techcrunch.com/2009/07/19/the-anatomy-of-the-twitter-attack/ Twitter attack analysis] cited above - of what can happen if users employ the same password at multiple important sites:&lt;br /&gt;
&lt;br /&gt;
# HC [the hacker&#039;s alias] accessed Gmail for a Twitter employee by using the password recovery feature that sends a reset link to a secondary email. In this case the secondary email was an expired Hotmail account, he simply registered it, clicked the link and reset the password. Gmail was then owned.&lt;br /&gt;
# HC then read emails to guess what the original Gmail password was successfully and reset the password so the Twitter employee would not notice the account had changed.&lt;br /&gt;
# HC then used the same password to access the employeeâs Twitter email on Google Apps for your domain, getting access to a gold mine of sensitive company information from emails and, particularly, email attachments.&lt;br /&gt;
# HC then used this information along with additional password guesses and resets to take control of other Twitter employee personal and work emails.&lt;br /&gt;
# HC then used the same username/password combinations and password reset features to access AT&amp;amp;T, MobileMe, Amazon and iTunes, among other services. A security hole in iTunes gave HC access to full credit card information in clear text. HC now also had control of Twitterâs domain names at GoDaddy.&lt;br /&gt;
# Even at this point, Twitter had absolutely no idea they had been compromised.&lt;br /&gt;
&lt;br /&gt;
It ain&#039;t pretty. &lt;br /&gt;
&lt;br /&gt;
We admit from installing SafeWord on our computer that the aspect of the program that requires you to use a different password for each new login is, well, pretty damn annoying. Complying with its demands to keep generating unique passwords might even require some old-fashioned tricks, like the creation of some sort of heuristic for generating memorable but unique passwords or keeping a card in your wallet with your various logins. But we think that the cost/benefit analysis weighs in favor of life being just a little more annoying in this area, because as our scary story illustrates, there are &#039;&#039;&#039;lots&#039;&#039;&#039; of ways in to our various accounts, and &#039;&#039;&#039;lots&#039;&#039;&#039; of random people out there who would love to hack those accounts for financial gain or to get their kicks.&lt;br /&gt;
&lt;br /&gt;
====Why Do It This Way?====&lt;br /&gt;
&lt;br /&gt;
There are other solutions out there that automatically generate secure, unique passwords for each site you visit; [https://lastpass.com/features_free.php LastPass] is a particularly nifty one. But they all share several key points of failure: they rely on a master password, and they store your passwords in the cloud. Relying on a master password is particularly problematic.&lt;/div&gt;</summary>
		<author><name>Jharrow</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cyberlaw_winter10/?title=Cybersecurity_Project&amp;diff=1080</id>
		<title>Cybersecurity Project</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cyberlaw_winter10/?title=Cybersecurity_Project&amp;diff=1080"/>
		<updated>2010-01-29T02:12:12Z</updated>

		<summary type="html">&lt;p&gt;Jharrow: /* What Are The Goals of SafeWord? */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Saying that cybersecurity is a &amp;quot;difficult problem&amp;quot; is like saying that reversing global warming is a difficult problem: it&#039;s true, but it doesn&#039;t quite capture how devilishly complicated and multifaceted the problems really are. There&#039;s no single reason why creating a more secure global network is so difficult; it in part has to do with the radically-distributed architecture of the Net, in part with some deep flaws computer software, and in part just from its sheer size and importance to our daily lives. (For more on this, see the nice [[Cybersecurity]] backgrounder.)&lt;br /&gt;
&lt;br /&gt;
So we came in not with the goal of providing a magical elixir that would make all credit card transactions magically secure and make it impossible for hackers to [http://googleblog.blogspot.com/2010/01/new-approach-to-china.html compromise Gmail&#039;s security]. Instead, we wanted to offer suggestions with minimal implementation headaches and maximal benefit to users, from novices to experts. This page has a short video overview of the ideas, explains some of the details of our proposal, and even has an alpha-release Firefox plugin that you can download and try out (thanks to [http://www.elance.com/ Elance] for this, by the way).&lt;br /&gt;
&lt;br /&gt;
==Overview==&lt;br /&gt;
&lt;br /&gt;
We discussed this topic at length in an in-class presentation on January 19. [http://www.vimeo.com/9036735 This] 9-minute video summarizes and extends the presentation we gave that day.&lt;br /&gt;
&lt;br /&gt;
==Specific Proposals==&lt;br /&gt;
&lt;br /&gt;
===Public Service Announcement===&lt;br /&gt;
&lt;br /&gt;
We created a Public Service Announcement for generating public awareness for the cybersecurity problem, and showed in class on January 19. It&#039;s online [http://vimeo.com/8937782 here] but is password-protected. Please email us if you were in the class and would like the password. In sum, we don&#039;t think a direct public awareness campaign will be very effective. We want to nudge users and change their behavior by changing the way browsers and websites work, not by scolding people.&lt;br /&gt;
&lt;br /&gt;
===SafeWord===&lt;br /&gt;
&lt;br /&gt;
====What is SafeWord?====&lt;br /&gt;
&lt;br /&gt;
SafeWord is a real, working FireFox plugin designed to nudge users into keeping safer and more unique passwords, though it&#039;s too unstable and unrefined to be considered anything buy alpha software. It&#039;s available for download [http://www.jasonharrow.com/safeword-1.0.0-fx.xpi here]. To install, save that file to your disk, select File --&amp;gt; Open in Firefox 3.5 or above, and install it. You will need to restart Firefox before it takes effect. Thanks to Elance for helping with the coding on very short notice.&lt;br /&gt;
&lt;br /&gt;
We have created a video demonstration of one of the key features of SafeWord [http://vimeo.com/9031865 here].&lt;br /&gt;
&lt;br /&gt;
====What Are The Goals of SafeWord?====&lt;br /&gt;
&lt;br /&gt;
SafeWord begins with a simple proposition: online passwords should be strong and different for different sites, and your browser should help you acheie that goal. Studies continue to show that most users use very simple passwords; see, for instance, [http://www.nytimes.com/2010/01/21/technology/21password.html this] &#039;&#039;New York Times&#039;&#039; that gets right to the point. &amp;quot;If your password is 123456,&amp;quot; reads the headline, &amp;quot;just make it HackMe.&amp;quot; Moreover, most users also fall into the &amp;quot;dirty habit&amp;quot; of using the same password across multiple online accounts, which can lead to a disaster if only one of the accounts is able to be compromised. An extremely detailed analysis of a 2009 attack that compromised many online accounts of Twitter employees is [http://www.techcrunch.com/2009/07/19/the-anatomy-of-the-twitter-attack/ here].&lt;br /&gt;
&lt;br /&gt;
====A Scary Story, and A Word About Annoyance====&lt;br /&gt;
&lt;br /&gt;
Even readers who are all for stronger passwords in general may nonetheless be skeptical of what can happen to &amp;quot;regular people&amp;quot; who can&#039;t be bothered to remember so many passwords, here&#039;s a very scary story - which is taken directly from the [http://www.techcrunch.com/2009/07/19/the-anatomy-of-the-twitter-attack/ Twitter attack analysis] cited above - of what can happen if users employ the same password at multiple important sites:&lt;br /&gt;
&lt;br /&gt;
# HC [the hacker&#039;s alias] accessed Gmail for a Twitter employee by using the password recovery feature that sends a reset link to a secondary email. In this case the secondary email was an expired Hotmail account, he simply registered it, clicked the link and reset the password. Gmail was then owned.&lt;br /&gt;
# HC then read emails to guess what the original Gmail password was successfully and reset the password so the Twitter employee would not notice the account had changed.&lt;br /&gt;
# HC then used the same password to access the employeeâs Twitter email on Google Apps for your domain, getting access to a gold mine of sensitive company information from emails and, particularly, email attachments.&lt;br /&gt;
# HC then used this information along with additional password guesses and resets to take control of other Twitter employee personal and work emails.&lt;br /&gt;
# HC then used the same username/password combinations and password reset features to access AT&amp;amp;T, MobileMe, Amazon and iTunes, among other services. A security hole in iTunes gave HC access to full credit card information in clear text. HC now also had control of Twitterâs domain names at GoDaddy.&lt;br /&gt;
# Even at this point, Twitter had absolutely no idea they had been compromised.&lt;br /&gt;
&lt;br /&gt;
It ain&#039;t pretty. &lt;br /&gt;
&lt;br /&gt;
We admit from installing SafeWord on our computer that the aspect of the program that requires you to use a different password for each new login is, well, pretty damn annoying. Complying with its demands to keep generating unique passwords might even require some old-fashioned tricks, like the creation of some sort of heuristic for generating memorable but unique passwords or keeping a card in your wallet with your various logins. But we think that the cost/benefit analysis weighs in favor of life being just a little more annoying in this area, because as our scary story illustrates, there are &#039;&#039;&#039;lots&#039;&#039;&#039; of ways in to our various accounts, and &#039;&#039;&#039;lots&#039;&#039;&#039; of random people out there who would love to hack those accounts for financial gain or to get their kicks.&lt;/div&gt;</summary>
		<author><name>Jharrow</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cyberlaw_winter10/?title=Cybersecurity_Project&amp;diff=1079</id>
		<title>Cybersecurity Project</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cyberlaw_winter10/?title=Cybersecurity_Project&amp;diff=1079"/>
		<updated>2010-01-29T02:02:05Z</updated>

		<summary type="html">&lt;p&gt;Jharrow: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Saying that cybersecurity is a &amp;quot;difficult problem&amp;quot; is like saying that reversing global warming is a difficult problem: it&#039;s true, but it doesn&#039;t quite capture how devilishly complicated and multifaceted the problems really are. There&#039;s no single reason why creating a more secure global network is so difficult; it in part has to do with the radically-distributed architecture of the Net, in part with some deep flaws computer software, and in part just from its sheer size and importance to our daily lives. (For more on this, see the nice [[Cybersecurity]] backgrounder.)&lt;br /&gt;
&lt;br /&gt;
So we came in not with the goal of providing a magical elixir that would make all credit card transactions magically secure and make it impossible for hackers to [http://googleblog.blogspot.com/2010/01/new-approach-to-china.html compromise Gmail&#039;s security]. Instead, we wanted to offer suggestions with minimal implementation headaches and maximal benefit to users, from novices to experts. This page has a short video overview of the ideas, explains some of the details of our proposal, and even has an alpha-release Firefox plugin that you can download and try out (thanks to [http://www.elance.com/ Elance] for this, by the way).&lt;br /&gt;
&lt;br /&gt;
==Overview==&lt;br /&gt;
&lt;br /&gt;
We discussed this topic at length in an in-class presentation on January 19. [http://www.vimeo.com/9036735 This] 9-minute video summarizes and extends the presentation we gave that day.&lt;br /&gt;
&lt;br /&gt;
==Specific Proposals==&lt;br /&gt;
&lt;br /&gt;
===Public Service Announcement===&lt;br /&gt;
&lt;br /&gt;
We created a Public Service Announcement for generating public awareness for the cybersecurity problem, and showed in class on January 19. It&#039;s online [http://vimeo.com/8937782 here] but is password-protected. Please email us if you were in the class and would like the password. In sum, we don&#039;t think a direct public awareness campaign will be very effective. We want to nudge users and change their behavior by changing the way browsers and websites work, not by scolding people.&lt;br /&gt;
&lt;br /&gt;
===SafeWord===&lt;br /&gt;
&lt;br /&gt;
====What is SafeWord?====&lt;br /&gt;
&lt;br /&gt;
SafeWord is a real, working FireFox plugin designed to nudge users into keeping safer and more unique passwords, though it&#039;s too unstable and unrefined to be considered anything buy alpha software. It&#039;s available for download [http://www.jasonharrow.com/safeword-1.0.0-fx.xpi here]. To install, save that file to your disk, select File --&amp;gt; Open in Firefox 3.5 or above, and install it. You will need to restart Firefox before it takes effect. Thanks to Elance for helping with the coding on very short notice.&lt;br /&gt;
&lt;br /&gt;
We have created a video demonstration of one of the key features of SafeWord [http://vimeo.com/9031865 here].&lt;br /&gt;
&lt;br /&gt;
====What Are The Goals of SafeWord?====&lt;br /&gt;
&lt;br /&gt;
SafeWord begins with a simple proposition: online passwords should be strong and different for different sites, and your browser should help you acheie that goal. Studies continue to show that most users use very simple passwords; see, for instance, [http://www.nytimes.com/2010/01/21/technology/21password.html this] &#039;&#039;New York Times&#039;&#039; that gets right to the point. &amp;quot;If your password is 123456,&amp;quot; reads the headline, &amp;quot;just make it HackMe.&amp;quot; Moreover, most users also fall into the &amp;quot;dirty habit&amp;quot; of using the same password across multiple online accounts, which can lead to a disaster if only one of the accounts is able to be compromised. An extremely detailed analysis of a 2009 attack that compromised many online accounts of Twitter employees is [http://www.techcrunch.com/2009/07/19/the-anatomy-of-the-twitter-attack/ here], but here&#039;s a fairly scary summary of what can happen if users use the same password at multiple important sites:&lt;br /&gt;
&lt;br /&gt;
# HC [the hacker&#039;s alias] accessed Gmail for a Twitter employee by using the password recovery feature that sends a reset link to a secondary email. In this case the secondary email was an expired Hotmail account, he simply registered it, clicked the link and reset the password. Gmail was then owned.&lt;br /&gt;
# HC then read emails to guess what the original Gmail password was successfully and reset the password so the Twitter employee would not notice the account had changed.&lt;br /&gt;
# HC then used the same password to access the employeeâs Twitter email on Google Apps for your domain, getting access to a gold mine of sensitive company information from emails and, particularly, email attachments.&lt;br /&gt;
# HC then used this information along with additional password guesses and resets to take control of other Twitter employee personal and work emails.&lt;br /&gt;
# HC then used the same username/password combinations and password reset features to access AT&amp;amp;T, MobileMe, Amazon and iTunes, among other services. A security hole in iTunes gave HC access to full credit card information in clear text. HC now also had control of Twitterâs domain names at GoDaddy.&lt;br /&gt;
# Even at this point, Twitter had absolutely no idea they had been compromised.&lt;/div&gt;</summary>
		<author><name>Jharrow</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cyberlaw_winter10/?title=Cybersecurity_Project&amp;diff=1078</id>
		<title>Cybersecurity Project</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cyberlaw_winter10/?title=Cybersecurity_Project&amp;diff=1078"/>
		<updated>2010-01-29T01:58:19Z</updated>

		<summary type="html">&lt;p&gt;Jharrow: /* SafeWord */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Saying that cybersecurity is a &amp;quot;difficult problem&amp;quot; is like saying that reversing global warming is a difficult problem: it&#039;s true, but it doesn&#039;t quite capture how devilishly complicated and multifaceted the problems really are. There&#039;s no single reason why creating a more secure global network is so difficult; it in part has to do with the radically-distributed architecture of the Net, in part with some deep flaws computer software, and in part just from its sheer size and importance to our daily lives. (For more on this, see the nice [[Cybersecurity]] backgrounder.)&lt;br /&gt;
&lt;br /&gt;
So we came in not with the goal of providing a magical elixir that would make all credit card transactions magically secure and make it impossible for hackers to [http://googleblog.blogspot.com/2010/01/new-approach-to-china.html compromise Gmail&#039;s security]. Instead, we wanted to offer suggestions with minimal implementation headaches and maximal benefit to users, from novices to experts. This page has a short video overview of the ideas, explains some of the details of our proposal, and even has an alpha-release Firefox plugin that you can download and try out (thanks to [http://www.elance.com/ Elance] for this, by the way).&lt;br /&gt;
&lt;br /&gt;
==Overview==&lt;br /&gt;
&lt;br /&gt;
We discussed this topic at length in an in-class presentation on January 19. [http://www.vimeo.com/9036735 This] 9-minute video summarizes and extends the presentation we gave that day.&lt;br /&gt;
&lt;br /&gt;
==Specific Proposals==&lt;br /&gt;
&lt;br /&gt;
===Public Service Announcement===&lt;br /&gt;
&lt;br /&gt;
We created a Public Service Announcement for generating public awareness for the cybersecurity problem, and showed in class on January 19. It&#039;s online [http://vimeo.com/8937782 here] but is password-protected. Please email us if you were in the class and would like the password. In sum, we don&#039;t think a direct public awareness campaign will be very effective. We want to nudge users and change their behavior by changing the way browsers and websites work, not by scolding people.&lt;br /&gt;
&lt;br /&gt;
===SafeWord===&lt;br /&gt;
&lt;br /&gt;
====What is SafeWord?====&lt;br /&gt;
&lt;br /&gt;
SafeWord is a real, working FireFox plugin designed to nudge users into keeping safer and more unique passwords, though it&#039;s too unstable and unrefined to be considered anything buy alpha software. It&#039;s available for download [http://www.jasonharrow.com/safeword-1.0.0-fx.xpi here]. To install, save that file to your disk, select File --&amp;gt; Open in Firefox 3.5 or above, and install it. You will need to restart Firefox before it takes effect. Thanks to Elance for helping with the coding on very short notice.&lt;br /&gt;
&lt;br /&gt;
We have created a video demonstration of one of the key features of SafeWord [http://vimeo.com/9031865 here].&lt;br /&gt;
&lt;br /&gt;
====What Are The Goals of SafeWord?====&lt;br /&gt;
&lt;br /&gt;
SafeWord begins with a simple proposition: online passwords should be strong and different for different sites, and your browser should help you acheie that goal. Studies continue to show that most users use very simple passwords; see, for instance, [http://www.nytimes.com/2010/01/21/technology/21password.html this] &#039;&#039;New York Times&#039;&#039; that gets right to the point. &amp;quot;If your password is 123456,&amp;quot; reads the headline, &amp;quot;just make it HackMe.&amp;quot; Moreover, most users also fall into the &amp;quot;dirty habit&amp;quot; of using the same password across multiple online accounts, which can lead to a disaster if only one of the accounts is able to be compromised. An extremely detailed analysis of a 2009 attack that compromised many online accounts of Twitter employees is [http://www.techcrunch.com/2009/07/19/the-anatomy-of-the-twitter-attack/ here], but here&#039;s a fairly scary summary of what can happen if users use the same password at multiple important sites:&lt;br /&gt;
&lt;br /&gt;
   1. HC accessed Gmail for a Twitter employee by using the password recovery feature that sends a reset link to a secondary email. In this case the secondary email was an expired Hotmail account, he simply registered it, clicked the link and reset the password. Gmail was then owned.&lt;br /&gt;
   2. HC then read emails to guess what the original Gmail password was successfully and reset the password so the Twitter employee would not notice the account had changed.&lt;br /&gt;
   3. HC then used the same password to access the employeeâs Twitter email on Google Apps for your domain, getting access to a gold mine of sensitive company information from emails and, particularly, email attachments.&lt;br /&gt;
   4. HC then used this information along with additional password guesses and resets to take control of other Twitter employee personal and work emails.&lt;br /&gt;
   5. HC then used the same username/password combinations and password reset features to access AT&amp;amp;T, MobileMe, Amazon and iTunes, among other services. A security hole in iTunes gave HC access to full credit card information in clear text. HC now also had control of Twitterâs domain names at GoDaddy.&lt;br /&gt;
   6. Even at this point, Twitter had absolutely no idea they had been compromised.&lt;/div&gt;</summary>
		<author><name>Jharrow</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cyberlaw_winter10/?title=Cybersecurity_Project&amp;diff=1076</id>
		<title>Cybersecurity Project</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cyberlaw_winter10/?title=Cybersecurity_Project&amp;diff=1076"/>
		<updated>2010-01-28T05:29:53Z</updated>

		<summary type="html">&lt;p&gt;Jharrow: /* SafeWord */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Saying that cybersecurity is a &amp;quot;difficult problem&amp;quot; is like saying that reversing global warming is a difficult problem: it&#039;s true, but it doesn&#039;t quite capture how devilishly complicated and multifaceted the problems really are. There&#039;s no single reason why creating a more secure global network is so difficult; it in part has to do with the radically-distributed architecture of the Net, in part with some deep flaws computer software, and in part just from its sheer size and importance to our daily lives. (For more on this, see the nice [[Cybersecurity]] backgrounder.)&lt;br /&gt;
&lt;br /&gt;
So we came in not with the goal of providing a magical elixir that would make all credit card transactions magically secure and make it impossible for hackers to [http://googleblog.blogspot.com/2010/01/new-approach-to-china.html compromise Gmail&#039;s security]. Instead, we wanted to offer suggestions with minimal implementation headaches and maximal benefit to users, from novices to experts. This page has a short video overview of the ideas, explains some of the details of our proposal, and even has an alpha-release Firefox plugin that you can download and try out (thanks to [http://www.elance.com/ Elance] for this, by the way).&lt;br /&gt;
&lt;br /&gt;
==Overview==&lt;br /&gt;
&lt;br /&gt;
We discussed this topic at length in class on January 19. [http://www.vimeo.com/9036735 This] 9-minute video summarizes and extends the presentation we gave that day.&lt;br /&gt;
&lt;br /&gt;
==Specific Proposals==&lt;br /&gt;
&lt;br /&gt;
===Public Service Announcement===&lt;br /&gt;
&lt;br /&gt;
We created a Public Service Announcement for generating public awareness for the cybersecurity problem, and showed in class on January 19. It&#039;s online [http://vimeo.com/8937782 here] but is password-protected. Please email us if you were in the class and would like the password. In sum, we don&#039;t think a direct public awareness campaign will be very effective. We want to nudge users and change their behavior by changing the way browsers and websites work, not by scolding people.&lt;br /&gt;
&lt;br /&gt;
===SafeWord===&lt;br /&gt;
&lt;br /&gt;
SafeWord is a real, working FireFox plugin designed to nudge users into keeping safer and more unique passwords, though it&#039;s too unstable and unrefined to be considered anything buy alpha software. It&#039;s available for download [http://www.jasonharrow.com/safeword-1.0.0-fx.xpi here]. To install, save that file to your disk, select File --&amp;gt; Open in Firefox 3.5 or above, and install it. You will need to restart Firefox before it takes effect. Thanks to Elance for helping with the coding on very short notice.&lt;br /&gt;
&lt;br /&gt;
We have a video demo of one of the key features of SafeWord [http://vimeo.com/9031865 here].&lt;/div&gt;</summary>
		<author><name>Jharrow</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cyberlaw_winter10/?title=Cybersecurity_Project&amp;diff=1075</id>
		<title>Cybersecurity Project</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cyberlaw_winter10/?title=Cybersecurity_Project&amp;diff=1075"/>
		<updated>2010-01-28T05:20:05Z</updated>

		<summary type="html">&lt;p&gt;Jharrow: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Saying that cybersecurity is a &amp;quot;difficult problem&amp;quot; is like saying that reversing global warming is a difficult problem: it&#039;s true, but it doesn&#039;t quite capture how devilishly complicated and multifaceted the problems really are. There&#039;s no single reason why creating a more secure global network is so difficult; it in part has to do with the radically-distributed architecture of the Net, in part with some deep flaws computer software, and in part just from its sheer size and importance to our daily lives. (For more on this, see the nice [[Cybersecurity]] backgrounder.)&lt;br /&gt;
&lt;br /&gt;
So we came in not with the goal of providing a magical elixir that would make all credit card transactions magically secure and make it impossible for hackers to [http://googleblog.blogspot.com/2010/01/new-approach-to-china.html compromise Gmail&#039;s security]. Instead, we wanted to offer suggestions with minimal implementation headaches and maximal benefit to users, from novices to experts. This page has a short video overview of the ideas, explains some of the details of our proposal, and even has an alpha-release Firefox plugin that you can download and try out (thanks to [http://www.elance.com/ Elance] for this, by the way).&lt;br /&gt;
&lt;br /&gt;
==Overview==&lt;br /&gt;
&lt;br /&gt;
We discussed this topic at length in class on January 19. [http://www.vimeo.com/9036735 This] 9-minute video summarizes and extends the presentation we gave that day.&lt;br /&gt;
&lt;br /&gt;
==Specific Proposals==&lt;br /&gt;
&lt;br /&gt;
===Public Service Announcement===&lt;br /&gt;
&lt;br /&gt;
We created a Public Service Announcement for generating public awareness for the cybersecurity problem, and showed in class on January 19. It&#039;s online [http://vimeo.com/8937782 here] but is password-protected. Please email us if you were in the class and would like the password. In sum, we don&#039;t think a direct public awareness campaign will be very effective. We want to nudge users and change their behavior by changing the way browsers and websites work, not by scolding people.&lt;br /&gt;
&lt;br /&gt;
===SafeWord===&lt;br /&gt;
&lt;br /&gt;
SafeWord is a real, working FireFox plugin designed to nudge users into keeping safer and more unique passwords, though it&#039;s too unstable and unrefined to be considered anything buy alpha software. It&#039;s available for download here, and thanks to Elance for helping with the coding on very short notice.&lt;br /&gt;
&lt;br /&gt;
We have a video demo of one of the key features of SafeWord [http://vimeo.com/9031865 here].&lt;/div&gt;</summary>
		<author><name>Jharrow</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cyberlaw_winter10/?title=Cybersecurity_Project&amp;diff=1074</id>
		<title>Cybersecurity Project</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cyberlaw_winter10/?title=Cybersecurity_Project&amp;diff=1074"/>
		<updated>2010-01-28T00:09:53Z</updated>

		<summary type="html">&lt;p&gt;Jharrow: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Saying that cybersecurity is a &amp;quot;difficult problem&amp;quot; is like saying that reversing global warming is a difficult problem: it&#039;s true, but it doesn&#039;t quite capture how devilishly complicated and multifaceted the problems really are. There&#039;s no single reason why creating a more secure global network is so difficult; it in part has to do with the radically-distributed architecture of the Net, in part with some deep flaws computer software, and in part just from its sheer size and importance to our daily lives. (For more on this, see the nice [[Cybersecurity]] backgrounder.)&lt;br /&gt;
&lt;br /&gt;
So we came in not with the goal of providing a magical elixir that would make all credit card transactions magically secure and make it impossible for hackers to [http://googleblog.blogspot.com/2010/01/new-approach-to-china.html compromise Gmail&#039;s security]. Instead, we wanted to offer suggestions with minimal implementation headaches and maximal benefit to users, from novices to experts. This page has a short video overview of the ideas, explains some of the details of our proposal, and even has an alpha-release Firefox plugin that you can download and try out (thanks to [http://www.elance.com/ Elance] for this, by the way).&lt;/div&gt;</summary>
		<author><name>Jharrow</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cyberlaw_winter10/?title=Cybersecurity_Project&amp;diff=1073</id>
		<title>Cybersecurity Project</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cyberlaw_winter10/?title=Cybersecurity_Project&amp;diff=1073"/>
		<updated>2010-01-28T00:05:13Z</updated>

		<summary type="html">&lt;p&gt;Jharrow: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Saying that cybersecurity is a &amp;quot;difficult problem&amp;quot; is like saying that reversing global warming is a difficult problem: it&#039;s true, but it doesn&#039;t quite capture just how really hard the problem is. There&#039;s no single reason why creating a more secure global network is so difficult; it in part has to do with the radically-distributed architecture of the Net, in part with some deep flaws computer software, and in part just from its sheer size and importance to our daily lives. (For more on this, see the nice [[Cybersecurity]] backgrounder.)&lt;br /&gt;
&lt;br /&gt;
So we came in not with the goal of providing a magical elixir that would make all credit card transactions magically secure and make it impossible for hackers to [http://googleblog.blogspot.com/2010/01/new-approach-to-china.html compromise Gmail&#039;s security]. Instead, we wanted to offer suggestions with minimal implementation headaches and maximal benefit to users, from novices to experts. This page has a short video overview of the ideas, explains some of the details of our proposal, and even has an alpha-release Firefox plugin that you can download and try out (thanks to [http://www.elance.com/ Elance] for this, by the way).&lt;/div&gt;</summary>
		<author><name>Jharrow</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cyberlaw_winter10/?title=Cybersecurity_Project&amp;diff=1072</id>
		<title>Cybersecurity Project</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cyberlaw_winter10/?title=Cybersecurity_Project&amp;diff=1072"/>
		<updated>2010-01-27T23:58:38Z</updated>

		<summary type="html">&lt;p&gt;Jharrow: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Saying that cybersecurity is a &amp;quot;difficult problem&amp;quot; is like saying that reversing global warming is a difficult problem: it&#039;s true, but it doesn&#039;t quite capture just how really hard the problem is. There&#039;s no single reason why creating a more secure global network is so difficult; it in part has to do with the radically-distributed architecture of the Net, in part with some deep flaws computer software, and in part just from its sheer size and importance to our daily lives. (For more on this, see the [[Cybersecurity]] backgrounder.)&lt;/div&gt;</summary>
		<author><name>Jharrow</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cyberlaw_winter10/?title=Cybersecurity_Project&amp;diff=1071</id>
		<title>Cybersecurity Project</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cyberlaw_winter10/?title=Cybersecurity_Project&amp;diff=1071"/>
		<updated>2010-01-27T23:58:03Z</updated>

		<summary type="html">&lt;p&gt;Jharrow: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Saying that cybersecurity is a &amp;quot;difficult problem&amp;quot; is like saying that reversing global warming is a difficult problem: it&#039;s true, but it doesn&#039;t quite capture just how really hard the problem is. There&#039;s no single reason why creating a more secure global network is so difficult; it in part has to do with the radically-distributed architecture of the Net, in part with some deep flaws computer software, and in part just from its sheer size and importance to our daily lives. (For more on this, see the Cybersecurity backgrounder [http://cyber.law.harvard.edu/cyberlaw_winter10/Cybersecurity here]).&lt;/div&gt;</summary>
		<author><name>Jharrow</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cyberlaw_winter10/?title=Cybersecurity_Project&amp;diff=1070</id>
		<title>Cybersecurity Project</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cyberlaw_winter10/?title=Cybersecurity_Project&amp;diff=1070"/>
		<updated>2010-01-27T23:48:45Z</updated>

		<summary type="html">&lt;p&gt;Jharrow: New page: Our Final Project goes here.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Our Final Project goes here.&lt;/div&gt;</summary>
		<author><name>Jharrow</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_9_Predictions&amp;diff=789</id>
		<title>Day 9 Predictions</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_9_Predictions&amp;diff=789"/>
		<updated>2010-01-14T17:52:19Z</updated>

		<summary type="html">&lt;p&gt;Jharrow: /* Motivations and Community */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Online Trust and Identity==&lt;br /&gt;
&lt;br /&gt;
It&#039;s kind of puzzling that a service like couchsurfing works despite the fact that it relies on people&#039;s ability to trust complete strangers. If now people can rely on reviews made by other users, it would be interesting to know how the site dealt with that issue in the beginning.&lt;br /&gt;
&lt;br /&gt;
We&#039;d be also interested in hearing about the identity verification system that Daniel mentioned at approx. 23:30 in the YouTube video mentioned bellow.  How are they getting access to passport numbers and credit card numbers?  If it is that much better at identifying people, why hasn&#039;t eBay implemented something like this?&lt;br /&gt;
&lt;br /&gt;
==Motivations and Community==&lt;br /&gt;
&lt;br /&gt;
It&#039;s interesting how the Extraordinaries (great name, reminded me of the Pixar movie The Incredibles) is for-profit, while Couchsurfing is non-profit. Will the Extraordinaries be able to build a Couchsurfing or Wikipedia-type community even though it&#039;s for-profit? Alternately, we might discuss how the non-profit of CS may have given rise to such a strong community of dissenters. If CS were a so-called [http://www.bcorporation.net/ B-Corp], as the Extraordinaries apparently aspires to be, would be people as angry at the supposed &amp;quot;betrayal&amp;quot; of the core values of the organization?&lt;br /&gt;
&lt;br /&gt;
We were struck by the fissures within the couchsurfing movement. It seems inevitable in these bottom-up, free internet communities that there will be intense fights over the direction of the project. What keeps communities like Wikipedia and Couchsurfing from still providing useful services despite all the chatter? Could that balance be reversed? How do we keep the community motivated enough to keep contributing?&lt;br /&gt;
&lt;br /&gt;
===Bad Apples in An Online Community===&lt;br /&gt;
&lt;br /&gt;
The OCS site leveled several general criticisms at CS and its governance structure, but other eye-catching rebukes involved the actions of a few &amp;quot;bad apples&amp;quot;. It would be interesting to see the CS people consider whether their structure of vouching and verification truly offer the best protection against such isolated incidents, and whether the partially-open nature of the organization can lend enough critical eyes to &amp;quot;guilt&amp;quot; (using Gino et al&#039;s word choice) everyone into better behavior. Perhaps the existence of Open Couchsurfing itself provides some outsider review--what changes has Couchsurfing considered or actually implemented since these contrarian voices began their loose campaign?&lt;br /&gt;
&lt;br /&gt;
==Additional Info==&lt;br /&gt;
&lt;br /&gt;
Here is a related youtube video, [http://www.youtube.com/watch?v=6IDNKhAIOww CouchSurfing: What one website reveals about the future of the net].&lt;/div&gt;</summary>
		<author><name>Jharrow</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_8_Predictions&amp;diff=722</id>
		<title>Day 8 Predictions</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_8_Predictions&amp;diff=722"/>
		<updated>2010-01-14T00:17:03Z</updated>

		<summary type="html">&lt;p&gt;Jharrow: /* Should there be Due Process Online */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;For those who aren&#039;t familiar, here are [http://creativecommons.org/dmca/ Creative Commons&#039;] and [http://www.google.com/dmca.html Google&#039;s] explanations of DMCA Notice and Takedown Procedures, one example of Due Process online&lt;br /&gt;
&lt;br /&gt;
==Should there be Due Process Online==&lt;br /&gt;
It seems like there should be, though I can&#039;t predict where the folks from Google believe it should come from. On the one hand, you might think that Google is &amp;quot;just&amp;quot; a company, and their due process obligations are not greater than those of any other private entity who effects your life: i.e. send a letter to the complaint department and pray. At the entire other end of the spectrum, you might think that Google is such a critical point-of-control online that the government should have no problem regulating them in areas from copyright to even their handling of search results and their imposition of the death penalty. My guess is that Google believes itself to be in the former, &amp;quot;leave-us-alone&amp;quot; pile.&lt;br /&gt;
&lt;br /&gt;
It&#039;s great how the website with the article on the Google death penalty was filled with mostly internal links, which I&#039;m guessing are intended to raise its Google rank.&lt;br /&gt;
&lt;br /&gt;
==Due Process Defaults==&lt;br /&gt;
&lt;br /&gt;
There are at least two default possibilities for due process of takedowns on the internet: (1) Due process afforded before takedown (default on), and (2) take down immediately upon request and afford due process to restore the content (default off). Google will probably take the stance that (2), default off, is a more appropriate standard for internet due process. Since internet content can do a great deal of harm in a very short period of time, it makes sense to take it down immediately (after someone has complained that it might be harmful information) and create a process by which the uploaded can ask that it be restored. That way the damage of offensive content is mitigated, but could not be unilaterally censored. (also, this process probably does the best job of limiting the liability of companies like Google, YouTube, etc). I think one of the biggest problem companies such as Google face is however that after summary proceedings, which in Europe can take more than 3 months after the lawsuit was filed, the procedure on the merits can take years and years (up to 6 or even more years), so it takes too much time until the case comes to an end (unless parties are willing to settle). Another problem are the huge damages (imposed on a daily basis in case of non-compliance) that are imposed very easily and run up very quickly. I would like to hear the thoughts of the guests on this.&lt;br /&gt;
&lt;br /&gt;
:The counter argument to the above is that this cripples the generatively of the internet. If anyone can request that content be taken down which web companies must comply with, it would be possible for anyone to (at least temporarily) gag the production of new content. A better compromise might be to require that the requester make some showing of who they are and how they will be harmed (at something resembling a probable cause standard) before web companies must comply with such a complaint.&lt;br /&gt;
:Due process is needed for the protection of the party against which actions to be taken, and in the interest of public notice. According to Facebook terms of service, an account will be disabled if it is found to repeatedly infringe other people&#039;s intellectual property rights. Here a due process is needed to disable an account on Facebook. How many times does &amp;quot;repeatedly&amp;quot; refer to? Who have the final say on this &amp;quot;infringement&amp;quot; of other people&#039;s intellectual property rights? Hope to hear more from our guest on their practice to deal with this, and how they balance between the alleged owner of the right and the one against whom the action to be taken. &lt;br /&gt;
&lt;br /&gt;
==Google and China==&lt;br /&gt;
Although today&#039;s class isn&#039;t about this topic, it&#039;s hard to believe it won&#039;t come up. It will be interesting to hear whether the Google guest will have a response to Jason&#039;s concern that Google disengaging with China will allow unscrupulous actors to dominate the world&#039;s biggest internet market, and that Google, even if it had to make compromises, could do more good than evil by working inside China.&lt;br /&gt;
:Yes, The voice of &amp;quot;Google in China&amp;quot; not &amp;quot;Google China&amp;quot; is around for a while. It will be interesting to hear how Google will do business in China if it finally decided to pull out. This will have a huge impact on not only the internet users in China, but also the resellers and strategic partners of Google China.&lt;br /&gt;
&lt;br /&gt;
:I think there is some connection between the Google-China news and today&#039;s topic.  From a macro perspective, what kind of due process should be given to Google (or any other type of Internet service provider) before the decision is made to force them to withdraw?  Today&#039;s speaker should have some good insights into Google&#039;s experiences with Turkey to might help us understand what the coming fight with China may look like.&lt;/div&gt;</summary>
		<author><name>Jharrow</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_8_Predictions&amp;diff=721</id>
		<title>Day 8 Predictions</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_8_Predictions&amp;diff=721"/>
		<updated>2010-01-14T00:16:38Z</updated>

		<summary type="html">&lt;p&gt;Jharrow: /* Should there be Due Process Online */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;For those who aren&#039;t familiar, here are [http://creativecommons.org/dmca/ Creative Commons&#039;] and [http://www.google.com/dmca.html Google&#039;s] explanations of DMCA Notice and Takedown Procedures, one example of Due Process online&lt;br /&gt;
&lt;br /&gt;
==Should there be Due Process Online==&lt;br /&gt;
It seems like there should be, though I can&#039;t predict where the folks from Google believe it should come from. On the one hand, you might think that Google is &amp;quot;just&amp;quot; a company, and their due process obligations are not greater than those of any other private entity who effects your life: i.e. send a letter to the complaint department and pray. At the entire other end of the spectrum, you might think that Google is such a critical point-of-control online that the government should have no problem regulating them in areas from copyright to even their handling of search results and their imposition of the death penalty. My guess is that Google believes itself to be in the former, &amp;quot;leave-us-alone&amp;quot; pile. [[User:Jharrow|Jharrow]] 00:16, 14 January 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
It&#039;s great how the website with the article on the Google death penalty was filled with mostly internal links, which I&#039;m guessing are intended to raise its Google rank.&lt;br /&gt;
&lt;br /&gt;
==Due Process Defaults==&lt;br /&gt;
&lt;br /&gt;
There are at least two default possibilities for due process of takedowns on the internet: (1) Due process afforded before takedown (default on), and (2) take down immediately upon request and afford due process to restore the content (default off). Google will probably take the stance that (2), default off, is a more appropriate standard for internet due process. Since internet content can do a great deal of harm in a very short period of time, it makes sense to take it down immediately (after someone has complained that it might be harmful information) and create a process by which the uploaded can ask that it be restored. That way the damage of offensive content is mitigated, but could not be unilaterally censored. (also, this process probably does the best job of limiting the liability of companies like Google, YouTube, etc). I think one of the biggest problem companies such as Google face is however that after summary proceedings, which in Europe can take more than 3 months after the lawsuit was filed, the procedure on the merits can take years and years (up to 6 or even more years), so it takes too much time until the case comes to an end (unless parties are willing to settle). Another problem are the huge damages (imposed on a daily basis in case of non-compliance) that are imposed very easily and run up very quickly. I would like to hear the thoughts of the guests on this.&lt;br /&gt;
&lt;br /&gt;
:The counter argument to the above is that this cripples the generatively of the internet. If anyone can request that content be taken down which web companies must comply with, it would be possible for anyone to (at least temporarily) gag the production of new content. A better compromise might be to require that the requester make some showing of who they are and how they will be harmed (at something resembling a probable cause standard) before web companies must comply with such a complaint.&lt;br /&gt;
:Due process is needed for the protection of the party against which actions to be taken, and in the interest of public notice. According to Facebook terms of service, an account will be disabled if it is found to repeatedly infringe other people&#039;s intellectual property rights. Here a due process is needed to disable an account on Facebook. How many times does &amp;quot;repeatedly&amp;quot; refer to? Who have the final say on this &amp;quot;infringement&amp;quot; of other people&#039;s intellectual property rights? Hope to hear more from our guest on their practice to deal with this, and how they balance between the alleged owner of the right and the one against whom the action to be taken. &lt;br /&gt;
&lt;br /&gt;
==Google and China==&lt;br /&gt;
Although today&#039;s class isn&#039;t about this topic, it&#039;s hard to believe it won&#039;t come up. It will be interesting to hear whether the Google guest will have a response to Jason&#039;s concern that Google disengaging with China will allow unscrupulous actors to dominate the world&#039;s biggest internet market, and that Google, even if it had to make compromises, could do more good than evil by working inside China.&lt;br /&gt;
:Yes, The voice of &amp;quot;Google in China&amp;quot; not &amp;quot;Google China&amp;quot; is around for a while. It will be interesting to hear how Google will do business in China if it finally decided to pull out. This will have a huge impact on not only the internet users in China, but also the resellers and strategic partners of Google China.&lt;br /&gt;
&lt;br /&gt;
:I think there is some connection between the Google-China news and today&#039;s topic.  From a macro perspective, what kind of due process should be given to Google (or any other type of Internet service provider) before the decision is made to force them to withdraw?  Today&#039;s speaker should have some good insights into Google&#039;s experiences with Turkey to might help us understand what the coming fight with China may look like.&lt;/div&gt;</summary>
		<author><name>Jharrow</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_8_Predictions&amp;diff=719</id>
		<title>Day 8 Predictions</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_8_Predictions&amp;diff=719"/>
		<updated>2010-01-14T00:16:23Z</updated>

		<summary type="html">&lt;p&gt;Jharrow: /* Should there be Due Process Online */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;For those who aren&#039;t familiar, here are [http://creativecommons.org/dmca/ Creative Commons&#039;] and [http://www.google.com/dmca.html Google&#039;s] explanations of DMCA Notice and Takedown Procedures, one example of Due Process online&lt;br /&gt;
&lt;br /&gt;
==Should there be Due Process Online==&lt;br /&gt;
It seems like there should be, though I can&#039;t predict where the folks from Google believe it should come from. On the one hand, you might think that Google is &amp;quot;just&amp;quot; a company, and their due process obligations are not greater than those of any other private entity who effects your life: i.e. send a letter to the complaint department and pray. At the entire other end of the spectrum, you might think that Google is such a critical point-of-control online that the government should have no problem regulating them in areas from copyright to even their handling of search results and their imposition of the death penalty. My guess is that Google believes itself to be in the former, &amp;quot;leave-us-alone&amp;quot; pile.&lt;br /&gt;
&lt;br /&gt;
It&#039;s great how the website with the article on the Google death penalty was filled with mostly internal links, which I&#039;m guessing are intended to raise its Google rank.&lt;br /&gt;
&lt;br /&gt;
==Due Process Defaults==&lt;br /&gt;
&lt;br /&gt;
There are at least two default possibilities for due process of takedowns on the internet: (1) Due process afforded before takedown (default on), and (2) take down immediately upon request and afford due process to restore the content (default off). Google will probably take the stance that (2), default off, is a more appropriate standard for internet due process. Since internet content can do a great deal of harm in a very short period of time, it makes sense to take it down immediately (after someone has complained that it might be harmful information) and create a process by which the uploaded can ask that it be restored. That way the damage of offensive content is mitigated, but could not be unilaterally censored. (also, this process probably does the best job of limiting the liability of companies like Google, YouTube, etc). I think one of the biggest problem companies such as Google face is however that after summary proceedings, which in Europe can take more than 3 months after the lawsuit was filed, the procedure on the merits can take years and years (up to 6 or even more years), so it takes too much time until the case comes to an end (unless parties are willing to settle). Another problem are the huge damages (imposed on a daily basis in case of non-compliance) that are imposed very easily and run up very quickly. I would like to hear the thoughts of the guests on this.&lt;br /&gt;
&lt;br /&gt;
:The counter argument to the above is that this cripples the generatively of the internet. If anyone can request that content be taken down which web companies must comply with, it would be possible for anyone to (at least temporarily) gag the production of new content. A better compromise might be to require that the requester make some showing of who they are and how they will be harmed (at something resembling a probable cause standard) before web companies must comply with such a complaint.&lt;br /&gt;
:Due process is needed for the protection of the party against which actions to be taken, and in the interest of public notice. According to Facebook terms of service, an account will be disabled if it is found to repeatedly infringe other people&#039;s intellectual property rights. Here a due process is needed to disable an account on Facebook. How many times does &amp;quot;repeatedly&amp;quot; refer to? Who have the final say on this &amp;quot;infringement&amp;quot; of other people&#039;s intellectual property rights? Hope to hear more from our guest on their practice to deal with this, and how they balance between the alleged owner of the right and the one against whom the action to be taken. &lt;br /&gt;
&lt;br /&gt;
==Google and China==&lt;br /&gt;
Although today&#039;s class isn&#039;t about this topic, it&#039;s hard to believe it won&#039;t come up. It will be interesting to hear whether the Google guest will have a response to Jason&#039;s concern that Google disengaging with China will allow unscrupulous actors to dominate the world&#039;s biggest internet market, and that Google, even if it had to make compromises, could do more good than evil by working inside China.&lt;br /&gt;
:Yes, The voice of &amp;quot;Google in China&amp;quot; not &amp;quot;Google China&amp;quot; is around for a while. It will be interesting to hear how Google will do business in China if it finally decided to pull out. This will have a huge impact on not only the internet users in China, but also the resellers and strategic partners of Google China.&lt;br /&gt;
:I think there is some connection between the Google-China news and today&#039;s topic.  From a macro perspective, what kind of due process should be given to Google (or any other type of Internet service provider) before the decision is made to force them to withdraw?  Today&#039;s speaker should have some good insights into Google&#039;s experiences with Turkey to might help us understand what the coming fight with China may look like.&lt;/div&gt;</summary>
		<author><name>Jharrow</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_7_Predictions&amp;diff=614</id>
		<title>Day 7 Predictions</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_7_Predictions&amp;diff=614"/>
		<updated>2010-01-13T00:37:31Z</updated>

		<summary type="html">&lt;p&gt;Jharrow: /* Anonymity */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;In the spirit of today&#039;s issues, our collective &amp;quot;anonymous&amp;quot; predictions are set out below:&lt;br /&gt;
&lt;br /&gt;
== Reputation Defender ==&lt;br /&gt;
&lt;br /&gt;
First of all, congratulations to Reputation Defender for [http://www.techcrunch.com/2010/01/12/reputationdefender-kleiner-bessemer-8-65-million/ raising $8.65 million last year] (announced today, January 12, 2010).  &lt;br /&gt;
&lt;br /&gt;
Mr. Fertik will probably try to persuade us that Reputation Defender offers great advantages to improve our reputation (even promoted by Dr. Phil?!), and the service obviously has a lot of merit--assuming you have the ability to pay for it.  It gives people a great way to remove defamatory, or potentially defamatory, content in a way where it harms nobody and helps those who it should.   However, we hope that the students and guests will discuss the problems raised by this kind of business:&lt;br /&gt;
:â¢Is Reputation Defender a tool to defend or artificially improve one&#039;s reputation?  (And does it matter?)  &lt;br /&gt;
:â¢Does Reputation Defender&#039;s incentive to &#039;&#039;hide&#039;&#039; the methods they use to get content removed (sometimes as simple as a DMCA takedown) actually &#039;&#039;slow&#039;&#039; the evolution of civility on the Net? &lt;br /&gt;
&lt;br /&gt;
:We&#039;d also like to hear about the tactics Reputation Defender uses to increase Google page ranks (MyEdge) in a way that makes sure it doesn&#039;t get the Google Death Penalty, as well as what technological or legal tools Reputation Defender would add if it could.&lt;br /&gt;
&lt;br /&gt;
Really interesting point taken from the Tech Crunch blog linked above: &amp;quot;It is still early days and there is a lot of work ahead. Perhaps ReputationDefenderâs biggest weakness is that it does not have a full view into Facebook, where only public comments or photos show up. If somebody is going to badmouth you online, chances are it will be on Facebook.&amp;quot;  Would be interested how they are planning to deal with this. On a related note, how would this itself be a privacy violation? Are individuals entitled to talk about each other in a social networking setting?&lt;br /&gt;
&lt;br /&gt;
Another apparent weakness of ReputationDefender is that while they are one company with a limited amount of employed people working for them, they might have to fight against a legion of anonymous people - which sometimes amounts to over 9,000 participants - that can be easily mobilized in certain image boards and forums. It would be also interesting to know how they would deal with this.&lt;br /&gt;
&lt;br /&gt;
Reputation Defender will probably also emphasize how its product is &amp;quot;family-friendly&amp;quot; -- its website must have more mentions of protecting your family and children than the all of the other websites we&#039;ve looked at in the class, combined. Is Reputation Defender profiting from a generational gap with regard to privacy? Parents may be horrified by what their children post online, and assume it will doom their career prospects, but by the time the children are adults, it may be normal to have that information freely available.&lt;br /&gt;
&lt;br /&gt;
Additionally, we would be very interested to hear anecdotes from our guests about the most compelling use cases for ReputationDefender - where does the majority of their business come from? What are some surprising use cases they have seen with the product? How do they plan to expand with this new infusion of cash?&lt;br /&gt;
&lt;br /&gt;
== Anonymity ==&lt;br /&gt;
&lt;br /&gt;
We hope our guests will not be too narrowly focused on the need to ensure accountability through identification and attribution.  The democratic benefits of leaving an option open for anonymous contribution is important also, to help encourage frank speech and content.  It seems to us that this would be particularly relevant in the US jurisdiction, where strong First Amendment principles are unlike what we see pretty much anywhere else in the world (which also raises the discrete sub-issue of how we can reconcile different international views of what an appropriate level of privacy protection might be).  Like Dispute Finder discussed yesterday - their emphasis is not to resolve an issue in dispute, but to highlight for the public that there is a conflict, which cannot exist without vocalization of many different points of view, no matter how unpopular.&lt;br /&gt;
&lt;br /&gt;
In terms of anonymity on the Internet in the user&#039;s control, we think services such as Tor do quite a good job. We may also discuss whether it would be good or bad to allow less skilled Internet users to get access to these tools, and, if it would be a good thing, how these technologies could be built-in to the browser or bundled with the OS. There still are weaknesses associated with the exit nodes of Tor allowing hackers to access user names and passwords due to the lack of encryption technologies available. Our guests may also speak to what drawbacks are associated with anonymizing services like Tor or [http://www.domainsbyproxy.com/ DomainsbyProxy] which simultaneously maintain privacy for certain users, but are specifically designed to thwart disclosure requirements where they still exist. &lt;br /&gt;
&lt;br /&gt;
In light of the well-publicized events surrounding Shi Tao and Wang Xiaoning, Ebele may express Yahoo&#039;s recent concerns with anonymity and its sometimes drastic importance outside the U.S., and the difficulties of working with governments with completely different expectations that do not match with our First Amendement concerns. We would be interested to hear our guests&#039; opinion about Google&#039;s dramatic announcement today about China, and wonder if it will have any effect on Mozilla.&lt;br /&gt;
&lt;br /&gt;
== Mozilla and Privacy ==&lt;br /&gt;
&lt;br /&gt;
We expect Ryan and the people of Mozilla will show the great advantages of understandable privacy policies in the form of icons. This might encourage people to actually check whether a website upholds certain privacy standards. Even more importantly, it would allow users, in an easy way, to realize the diverse range of privacy policies (and the amount of information released to third parties) that various add-ons have (the Location Aware feature of Firefox version 3.5, for example, can tap into a wide range of information). The advantages of easy-to-understand privacy icons are straightforward, although we might wonder whether users will have a collective voice strong enough to cause change, or whether users will really stop visiting nytimes.com if it has certain unpleasant policies.  The people from Mozilla will probably express the difficulty in creating icons that are simple enough to be understood at a glance and useable by a wide range of users when there is such wide variety in privacy policies. Beyond that question, the guests likely to justify why modifications to the browsers that we use are a necessary or desired way to implement them.&lt;br /&gt;
&lt;br /&gt;
As we discussed yesterday, the people at the Mozilla foundation can take any idea to improve the internet from a fanciful theory to a concrete reality very quickly.  It seems likely, then, that they are deluged with causes to adopt and browser functionality to build in.  It would be interesting to hear how they decided what to focus on, and why privacy rose to the top of the list. Mozilla has, in effect, the ability to bundle any plug-in that it desires with Firefox by making it core browser functionality. The guests are likely to address whether there is a happy medium between bundling functionality with Firefox and relying entirely on users tracking down and installing plug-ins (like DisputeFinder requires). Is there a possibility of a central plug-in repository that can allow useful plug-ins to take off more easily? Can the decision of which plug-ins/concepts could be &amp;quot;promoted&amp;quot; to core browser functionality be crowdsourced somehow?&lt;/div&gt;</summary>
		<author><name>Jharrow</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_6_Thoughts&amp;diff=600</id>
		<title>Day 6 Thoughts</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_6_Thoughts&amp;diff=600"/>
		<updated>2010-01-12T23:28:21Z</updated>

		<summary type="html">&lt;p&gt;Jharrow: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Quickie thought: how effective can Firefox plugins really be for many projects - especially those that require a large non-geek percentage? And what if IE were to allow easy compatibility with plugins? Consider the following back of the envelope calculations:&lt;br /&gt;
&lt;br /&gt;
-25% of Internet users use Firefox. [http://www.downloadsquad.com/2009/05/05/how-many-firefox-users-are-there-mozilla-estimates-270-million/ Estimates] are that this is about 270 million users.&lt;br /&gt;
&lt;br /&gt;
-The latest [https://addons.mozilla.org/en-US/statistics statistics] from Mozilla show that there are about 200 million add-ons in use total. But that&#039;s clearly not evenly distributed. I can&#039;t find the number, so let&#039;s wildly ballpark it and say that the average add-on user is using four add-ons (the Stanford computer in Room 280B is clearly using way more...), which means there are 50 million people that really use add-ons.&lt;br /&gt;
&lt;br /&gt;
That means that if we take the roughly billion people who are estimated to be on the Net (based on the marketshare above of Firefox), about 5% even have the capacity to change their user experience with a Firefox extension.&lt;br /&gt;
&lt;br /&gt;
I don&#039;t know what the implications of this are - anyone else have a deep thought? - but I think it&#039;s worth remembering that those who desire to change their Internet experiences this way are a small minority of users. If IE decided to open up to extensions, though - and if there was some way to translate existing Firefox extensions over to that platform - we might have a whole new ballgame... [[User:Jharrow|Jharrow]] 23:28, 12 January 2010 (UTC)&lt;/div&gt;</summary>
		<author><name>Jharrow</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_6_Thoughts&amp;diff=599</id>
		<title>Day 6 Thoughts</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_6_Thoughts&amp;diff=599"/>
		<updated>2010-01-12T23:26:35Z</updated>

		<summary type="html">&lt;p&gt;Jharrow: New page: Quickie thought: how effective can Firefox plugins really be for many projects - especially those that require a large non-geek percentage? And what if IE were to allow easy compatibility ...&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Quickie thought: how effective can Firefox plugins really be for many projects - especially those that require a large non-geek percentage? And what if IE were to allow easy compatibility with plugins? Consider the following back of the envelope calculations:&lt;br /&gt;
&lt;br /&gt;
-25% of Internet users use Firefox. [http://www.downloadsquad.com/2009/05/05/how-many-firefox-users-are-there-mozilla-estimates-270-million/ Estimates] are that this is about 270 million users.&lt;br /&gt;
&lt;br /&gt;
-The latest [https://addons.mozilla.org/en-US/statistics statistics] from Mozilla show that there are about 200,000,000 add-ons in use total. But that&#039;s clearly not evenly distributed. I can&#039;t find the number, so let&#039;s wildly ballpark it and say that the average add-on user is using four add-ons (the Stanford computer in Room 280B is clearly using way more...), which means there are 50,000,000 people that really use add-ons.&lt;br /&gt;
&lt;br /&gt;
That means that if we take the roughly billion people who are estimated to be on the Net (based on the marketshare above of Firefox), about 5% even have the capacity to change their user experience with a Firefox extension.&lt;br /&gt;
&lt;br /&gt;
I don&#039;t know what the implications of this are - anyone else have a deep thought? - but I think it&#039;s worth remembering that those who desire to change their Internet experiences this way are a small minority of users. If IE decided to open up to extensions, though - and if there was some way to translate existing Firefox extensions over to that platform - we might have a whole new ballgame... [[User:Jharrow|Jharrow]] 23:26, 12 January 2010 (UTC)&lt;/div&gt;</summary>
		<author><name>Jharrow</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_6_Predictions&amp;diff=509</id>
		<title>Day 6 Predictions</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_6_Predictions&amp;diff=509"/>
		<updated>2010-01-11T18:22:52Z</updated>

		<summary type="html">&lt;p&gt;Jharrow: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Daniel: Our guests will probably discuss at length the challenges that Dispute Finder and most web-based cooperative tools bump into while attempting to harness input from virtual crowds. I guess they will talk about Dispute Finderâs design difficulties, such as costs and trade-offs (between precision and recall, between user-friendliness and number / quality of features, etc). Theyâll most likely also summon stories from the interviews discussed in the document we received, perhaps to illustrate content-layer problems with measurement of &amp;quot;information sources reliability&amp;quot;; usersâ misunderstandings / trouble with logic operations; and group biases.&lt;br /&gt;
I would love to hear their views on the [http://courses.ischool.berkeley.edu/i256/f09/lectures/RobEnnalsGuestLecture.ppt proposed use of Turks] to improve the database of disputed claims and arguments, as well as on the current biases of the disputed facts / arguments presently listed by the software.&lt;br /&gt;
&lt;br /&gt;
:Jason: I predict that there will be a good deal of discussion of what Daniel calls the &amp;quot;user-friendliness&amp;quot; aspect of these tools - and I hope there is, because it&#039;s critical. Specifically, what is the necessary ratio between DisputeFinder or Herdict &amp;quot;passive users&amp;quot; and &amp;quot;active reporters&amp;quot; to make a project successful? I say this because both Herdict and DisputeFinder look somewhat sparsely-populated for them to be maximally-useful right now. For example, Herdict is [http://www.herdict.org/web/explore/country/CN;jsessionid=4A2D95D3EB7A8F96B073DE77D3654D53 reporting] that 2 Chinese users have reported YouTube as inaccessible. How do I interpret that? What percent of people who might know about and like Herdict in China are reporting back to Herdict? We know that Wikipedia is successful in spite of the fact that only a very small portion of readers become really regular editors - but Wikipedia is also one of the most visited sites in the world. I hope we discuss what strategies these organizations are employing to build participation for these more niche offerings. [[User:Jharrow|Jharrow]] 18:20, 11 January 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
Emily: &lt;br /&gt;
Dispute Finder bears an inherent flaw: individuals, not algorithms, decide whom and what to trust for information. Consider the watch on your wrist. If your watch starts to get the time wrong, you might try to fix the watch. You hope and pray your watch starts giving you accurate, dependable information because you like your watch. You might even love your watch. But, if it continues to betray your trust, and the people in your trusted circle insist your watch is wrong, you give up. You decide to trust a new watch, but your new watch will probably be reminiscent of your old watch with respect to personal taste, experience, and preferences. Most people are intuitive enough (though they donât necessarily convert insights into complex conclusions about source x versus source y) to know that 120 seconds of live, relatively unedited sound on Fox News Live or MSNBC Dayside is less likely to contain factually accurate information â even if relatively unimportant, like the location of a fire, or the total number of casualties in a mass shootingâ than a compulsively edited, fact-checked tome in the Sunday NY Times magazine, the Economist, or the New Yorker. &lt;br /&gt;
&lt;br /&gt;
Article 3.5 of the Dispute Finder document, âDetermining Trustworthy Sources,â seems a bit absurd. It actually acknowledges the marketability challenges of its own software: âUnfortunatelyâ¦the sites people actually trust are often those that share the personâs own point of view.â So, again, what is this software and what, really, is the point? Segway into âCross-cutting themes.â Save the world. How? Is Dispute Finder intended to help people sue other people for libel? Richard Jewel (now deceased) had a reasonably compelling case. Thatâs probably why he successfully sued (for libel) every organization, from CNN, to NBC, to the NY Post. All settled. He collected from each of them. But Richard Jewel didnât need help from Dispute Finder. Richard Jewel had a case. &lt;br /&gt;
&lt;br /&gt;
Cross-cutting themes: âChange the technology, save the world.â Okay, why not? Isnât there something else smart people at Intel and UC Berkeley could be doing to make the world better? Last November, the New York Times produced an alarming story [http://www.nytimes.com/2009/11/29/us/29foodstamps.html] about the food stamp program in America(ânow expanding at a pace of about 20,000 people a day.â) Also no shortage of children in custody. Last December, the New York Times obtained â and reported on [http://www.nytimes.com/2009/12/14/nyregion/14juvenile.html?_r=1&amp;amp;scp=1&amp;amp;sq=new%20york%20family%20court%20juvenile%20department%20of%20justice%20youth&amp;amp;st=cse]â a âconfidential draft reportâ prepared by a task force appointed by NY gov David Paterson: âNew York Stateâs current approach fails the young people who are drawn into the system, the public whose safety it is intended to protect, and the principles of good governance that demand effective use of scarce state resources.â Story also says the situation was so bad that the DOJ, at one point, was threatening to âtake over.â &lt;br /&gt;
&lt;br /&gt;
So, if Intel is interested in contributing, how about addressing real problemsâhelping real peopleâ that could affect real, collective societal change and improvement? Children and education seem like obvious places to start. Basics like hardware and mentors could go a long way. Children in poverty struggle with range of issues, including asthma, low self-esteem, obesity, and depression. Consider children in places like the South Bronx (Jonathan Kozolâs children [http://www.amazon.com/Amazing-Grace-Children-Conscience-Nation/dp/0060976977]): allocation of resources in places like this (and/or lower-middle class communities), especially from companies like Intel, could change lives; give voices to people from whom we do not often hear. &lt;br /&gt;
&lt;br /&gt;
Interested to hear thoughts on Internet privacy, though I&#039;m not sure adults have an expectation of privacy anywhere [http://gawker.com/5444885/facebooks-mark-zuckerberg-on-your-erased-privacy-these-are-the-social-norms-now] on the Internet. If you want privacy, don&#039;t put yourself on the Internet. Finally, on the subject of online harassment, if we accept that the Internet is a public place, to what extent is it acceptable to regulate online communication, including but not limited to comments deemed &#039;offensive&#039; on blogs?&lt;br /&gt;
&lt;br /&gt;
Predictions. Guests will be nice. Class will be nice. Hope to hear more about Dispute Finder&#039;s business model.&lt;/div&gt;</summary>
		<author><name>Jharrow</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_6_Predictions&amp;diff=508</id>
		<title>Day 6 Predictions</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_6_Predictions&amp;diff=508"/>
		<updated>2010-01-11T18:22:17Z</updated>

		<summary type="html">&lt;p&gt;Jharrow: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Daniel: Our guests will probably discuss at length the challenges that Dispute Finder and most web-based cooperative tools bump into while attempting to harness input from virtual crowds. I guess they will talk about Dispute Finderâs design difficulties, such as costs and trade-offs (between precision and recall, between user-friendliness and number / quality of features, etc). Theyâll most likely also summon stories from the interviews discussed in the document we received, perhaps to illustrate content-layer problems with measurement of &amp;quot;information sources reliability&amp;quot;; usersâ misunderstandings / trouble with logic operations; and group biases.&lt;br /&gt;
I would love to hear their views on the [http://courses.ischool.berkeley.edu/i256/f09/lectures/RobEnnalsGuestLecture.ppt proposed use of Turks] to improve the database of disputed claims and arguments, as well as on the current biases of the disputed facts / arguments presently listed by the software.&lt;br /&gt;
&lt;br /&gt;
:Jason: I predict that there will be a good deal of discussion of what Daniel calls the &amp;quot;user-friendliness&amp;quot; aspect of these tools - and I hope there is, because it&#039;s critical. Specifically, what is the necessary ratio between DisputeFinder or Herdict &amp;quot;passive users&amp;quot; and &amp;quot;active reporters&amp;quot; to make a project successful? I say this because both Herdict and DisputeFinder look somewhat sparsely-populated for them to be maximally-useful right now. For example, Herdict is [reporting http://www.herdict.org/web/explore/country/CN;jsessionid=4A2D95D3EB7A8F96B073DE77D3654D53] that 2 Chinese users have reported YouTube as inaccessible. How do I interpret that? What percent of people who might know about and like Herdict in China are reporting back to Herdict? We know that Wikipedia is successful in spite of the fact that only a very small portion of readers become really regular editors - but Wikipedia is also one of the most visited sites in the world. I hope we discuss what strategies these organizations are employing to build participation for these more niche offerings. [[User:Jharrow|Jharrow]] 18:20, 11 January 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
Emily: &lt;br /&gt;
Dispute Finder bears an inherent flaw: individuals, not algorithms, decide whom and what to trust for information. Consider the watch on your wrist. If your watch starts to get the time wrong, you might try to fix the watch. You hope and pray your watch starts giving you accurate, dependable information because you like your watch. You might even love your watch. But, if it continues to betray your trust, and the people in your trusted circle insist your watch is wrong, you give up. You decide to trust a new watch, but your new watch will probably be reminiscent of your old watch with respect to personal taste, experience, and preferences. Most people are intuitive enough (though they donât necessarily convert insights into complex conclusions about source x versus source y) to know that 120 seconds of live, relatively unedited sound on Fox News Live or MSNBC Dayside is less likely to contain factually accurate information â even if relatively unimportant, like the location of a fire, or the total number of casualties in a mass shootingâ than a compulsively edited, fact-checked tome in the Sunday NY Times magazine, the Economist, or the New Yorker. &lt;br /&gt;
&lt;br /&gt;
Article 3.5 of the Dispute Finder document, âDetermining Trustworthy Sources,â seems a bit absurd. It actually acknowledges the marketability challenges of its own software: âUnfortunatelyâ¦the sites people actually trust are often those that share the personâs own point of view.â So, again, what is this software and what, really, is the point? Segway into âCross-cutting themes.â Save the world. How? Is Dispute Finder intended to help people sue other people for libel? Richard Jewel (now deceased) had a reasonably compelling case. Thatâs probably why he successfully sued (for libel) every organization, from CNN, to NBC, to the NY Post. All settled. He collected from each of them. But Richard Jewel didnât need help from Dispute Finder. Richard Jewel had a case. &lt;br /&gt;
&lt;br /&gt;
Cross-cutting themes: âChange the technology, save the world.â Okay, why not? Isnât there something else smart people at Intel and UC Berkeley could be doing to make the world better? Last November, the New York Times produced an alarming story [http://www.nytimes.com/2009/11/29/us/29foodstamps.html] about the food stamp program in America(ânow expanding at a pace of about 20,000 people a day.â) Also no shortage of children in custody. Last December, the New York Times obtained â and reported on [http://www.nytimes.com/2009/12/14/nyregion/14juvenile.html?_r=1&amp;amp;scp=1&amp;amp;sq=new%20york%20family%20court%20juvenile%20department%20of%20justice%20youth&amp;amp;st=cse]â a âconfidential draft reportâ prepared by a task force appointed by NY gov David Paterson: âNew York Stateâs current approach fails the young people who are drawn into the system, the public whose safety it is intended to protect, and the principles of good governance that demand effective use of scarce state resources.â Story also says the situation was so bad that the DOJ, at one point, was threatening to âtake over.â &lt;br /&gt;
&lt;br /&gt;
So, if Intel is interested in contributing, how about addressing real problemsâhelping real peopleâ that could affect real, collective societal change and improvement? Children and education seem like obvious places to start. Basics like hardware and mentors could go a long way. Children in poverty struggle with range of issues, including asthma, low self-esteem, obesity, and depression. Consider children in places like the South Bronx (Jonathan Kozolâs children [http://www.amazon.com/Amazing-Grace-Children-Conscience-Nation/dp/0060976977]): allocation of resources in places like this (and/or lower-middle class communities), especially from companies like Intel, could change lives; give voices to people from whom we do not often hear. &lt;br /&gt;
&lt;br /&gt;
Interested to hear thoughts on Internet privacy, though I&#039;m not sure adults have an expectation of privacy anywhere [http://gawker.com/5444885/facebooks-mark-zuckerberg-on-your-erased-privacy-these-are-the-social-norms-now] on the Internet. If you want privacy, don&#039;t put yourself on the Internet. Finally, on the subject of online harassment, if we accept that the Internet is a public place, to what extent is it acceptable to regulate online communication, including but not limited to comments deemed &#039;offensive&#039; on blogs?&lt;br /&gt;
&lt;br /&gt;
Predictions. Guests will be nice. Class will be nice. Hope to hear more about Dispute Finder&#039;s business model.&lt;/div&gt;</summary>
		<author><name>Jharrow</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_6_Predictions&amp;diff=507</id>
		<title>Day 6 Predictions</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_6_Predictions&amp;diff=507"/>
		<updated>2010-01-11T18:20:57Z</updated>

		<summary type="html">&lt;p&gt;Jharrow: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Daniel: Our guests will probably discuss at length the challenges that Dispute Finder and most web-based cooperative tools bump into while attempting to harness input from virtual crowds. I guess they will talk about Dispute Finderâs design difficulties, such as costs and trade-offs (between precision and recall, between user-friendliness and number / quality of features, etc). Theyâll most likely also summon stories from the interviews discussed in the document we received, perhaps to illustrate content-layer problems with measurement of &amp;quot;information sources reliability&amp;quot;; usersâ misunderstandings / trouble with logic operations; and group biases.&lt;br /&gt;
I would love to hear their views on the [http://courses.ischool.berkeley.edu/i256/f09/lectures/RobEnnalsGuestLecture.ppt proposed use of Turks] to improve the database of disputed claims and arguments, as well as on the current biases of the disputed facts / arguments presently listed by the software.&lt;br /&gt;
&lt;br /&gt;
:Jason: I predict that there will be a good deal of discussion of what Daniel calls the &amp;quot;user-friendliness&amp;quot; aspect of these tools - and I hope there is, because it&#039;s critical. Specifically, what is the necessary ratio between DisputeFinder or Herdict &amp;quot;passive users&amp;quot; and &amp;quot;active reporters&amp;quot; to make a project successful? I say this because both Herdict and DisputeFinder look just a little bit sparsely-populated for them to be maximally-useful right now. For example, Herdict is [http://www.herdict.org/web/explore/country/CN;jsessionid=4A2D95D3EB7A8F96B073DE77D3654D53] reporting that 2 Chinese users have reported YouTube as inaccessible. How do I interpret that? What percent of people who might know about and like Herdict in China are reporting back to Herdict? We know that Wikipedia is successful in spite of the fact that only a very small portion of readers become really regular editors - but Wikipedia is also one of the most visited sites in the world. I hope we discuss what strategies these organizations are employing to build participation for these more niche offerings. [[User:Jharrow|Jharrow]] 18:20, 11 January 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
Emily: &lt;br /&gt;
Dispute Finder bears an inherent flaw: individuals, not algorithms, decide whom and what to trust for information. Consider the watch on your wrist. If your watch starts to get the time wrong, you might try to fix the watch. You hope and pray your watch starts giving you accurate, dependable information because you like your watch. You might even love your watch. But, if it continues to betray your trust, and the people in your trusted circle insist your watch is wrong, you give up. You decide to trust a new watch, but your new watch will probably be reminiscent of your old watch with respect to personal taste, experience, and preferences. Most people are intuitive enough (though they donât necessarily convert insights into complex conclusions about source x versus source y) to know that 120 seconds of live, relatively unedited sound on Fox News Live or MSNBC Dayside is less likely to contain factually accurate information â even if relatively unimportant, like the location of a fire, or the total number of casualties in a mass shootingâ than a compulsively edited, fact-checked tome in the Sunday NY Times magazine, the Economist, or the New Yorker. &lt;br /&gt;
&lt;br /&gt;
Article 3.5 of the Dispute Finder document, âDetermining Trustworthy Sources,â seems a bit absurd. It actually acknowledges the marketability challenges of its own software: âUnfortunatelyâ¦the sites people actually trust are often those that share the personâs own point of view.â So, again, what is this software and what, really, is the point? Segway into âCross-cutting themes.â Save the world. How? Is Dispute Finder intended to help people sue other people for libel? Richard Jewel (now deceased) had a reasonably compelling case. Thatâs probably why he successfully sued (for libel) every organization, from CNN, to NBC, to the NY Post. All settled. He collected from each of them. But Richard Jewel didnât need help from Dispute Finder. Richard Jewel had a case. &lt;br /&gt;
&lt;br /&gt;
Cross-cutting themes: âChange the technology, save the world.â Okay, why not? Isnât there something else smart people at Intel and UC Berkeley could be doing to make the world better? Last November, the New York Times produced an alarming story [http://www.nytimes.com/2009/11/29/us/29foodstamps.html] about the food stamp program in America(ânow expanding at a pace of about 20,000 people a day.â) Also no shortage of children in custody. Last December, the New York Times obtained â and reported on [http://www.nytimes.com/2009/12/14/nyregion/14juvenile.html?_r=1&amp;amp;scp=1&amp;amp;sq=new%20york%20family%20court%20juvenile%20department%20of%20justice%20youth&amp;amp;st=cse]â a âconfidential draft reportâ prepared by a task force appointed by NY gov David Paterson: âNew York Stateâs current approach fails the young people who are drawn into the system, the public whose safety it is intended to protect, and the principles of good governance that demand effective use of scarce state resources.â Story also says the situation was so bad that the DOJ, at one point, was threatening to âtake over.â &lt;br /&gt;
&lt;br /&gt;
So, if Intel is interested in contributing, how about addressing real problemsâhelping real peopleâ that could affect real, collective societal change and improvement? Children and education seem like obvious places to start. Basics like hardware and mentors could go a long way. Children in poverty struggle with range of issues, including asthma, low self-esteem, obesity, and depression. Consider children in places like the South Bronx (Jonathan Kozolâs children [http://www.amazon.com/Amazing-Grace-Children-Conscience-Nation/dp/0060976977]): allocation of resources in places like this (and/or lower-middle class communities), especially from companies like Intel, could change lives; give voices to people from whom we do not often hear. &lt;br /&gt;
&lt;br /&gt;
Interested to hear thoughts on Internet privacy, though I&#039;m not sure adults have an expectation of privacy anywhere [http://gawker.com/5444885/facebooks-mark-zuckerberg-on-your-erased-privacy-these-are-the-social-norms-now] on the Internet. If you want privacy, don&#039;t put yourself on the Internet. Finally, on the subject of online harassment, if we accept that the Internet is a public place, to what extent is it acceptable to regulate online communication, including but not limited to comments deemed &#039;offensive&#039; on blogs?&lt;br /&gt;
&lt;br /&gt;
Predictions. Guests will be nice. Class will be nice. Hope to hear more about Dispute Finder&#039;s business model.&lt;/div&gt;</summary>
		<author><name>Jharrow</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_6_Predictions&amp;diff=506</id>
		<title>Day 6 Predictions</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_6_Predictions&amp;diff=506"/>
		<updated>2010-01-11T18:20:02Z</updated>

		<summary type="html">&lt;p&gt;Jharrow: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Daniel: Our guests will probably discuss at length the challenges that Dispute Finder and most web-based cooperative tools bump into while attempting to harness input from virtual crowds. I guess they will talk about Dispute Finderâs design difficulties, such as costs and trade-offs (between precision and recall, between user-friendliness and number / quality of features, etc). Theyâll most likely also summon stories from the interviews discussed in the document we received, perhaps to illustrate content-layer problems with measurement of &amp;quot;information sources reliability&amp;quot;; usersâ misunderstandings / trouble with logic operations; and group biases.&lt;br /&gt;
I would love to hear their views on the [http://courses.ischool.berkeley.edu/i256/f09/lectures/RobEnnalsGuestLecture.ppt proposed use of Turks] to improve the database of disputed claims and arguments, as well as on the current biases of the disputed facts / arguments presently listed by the software.&lt;br /&gt;
&lt;br /&gt;
:Jason: I predict - and hope - there will be a lot of discussion on Daniel calls the &amp;quot;user-friendliness&amp;quot; aspect of these tools. Specifically, what is the necessary ratio between DisputeFinder or Herdict &amp;quot;passive users&amp;quot; and &amp;quot;active reporters&amp;quot; to make a project successful? I say this because both Herdict and DisputeFinder look just a little bit sparsely-populated for them to be maximally-useful right now. For example, Herdict is [http://www.herdict.org/web/explore/country/CN;jsessionid=4A2D95D3EB7A8F96B073DE77D3654D53] reporting that 2 Chinese users have reported YouTube as inaccessible. How do I interpret that? What percent of people who might know about and like Herdict in China are reporting back to Herdict? We know that Wikipedia is successful in spite of the fact that only a very small portion of readers become really regular editors - but Wikipedia is also one of the most visited sites in the world. I hope we discuss what strategies these organizations are employing to build participation for these more niche offerings. [[User:Jharrow|Jharrow]] 18:20, 11 January 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
Emily: &lt;br /&gt;
Dispute Finder bears an inherent flaw: individuals, not algorithms, decide whom and what to trust for information. Consider the watch on your wrist. If your watch starts to get the time wrong, you might try to fix the watch. You hope and pray your watch starts giving you accurate, dependable information because you like your watch. You might even love your watch. But, if it continues to betray your trust, and the people in your trusted circle insist your watch is wrong, you give up. You decide to trust a new watch, but your new watch will probably be reminiscent of your old watch with respect to personal taste, experience, and preferences. Most people are intuitive enough (though they donât necessarily convert insights into complex conclusions about source x versus source y) to know that 120 seconds of live, relatively unedited sound on Fox News Live or MSNBC Dayside is less likely to contain factually accurate information â even if relatively unimportant, like the location of a fire, or the total number of casualties in a mass shootingâ than a compulsively edited, fact-checked tome in the Sunday NY Times magazine, the Economist, or the New Yorker. &lt;br /&gt;
&lt;br /&gt;
Article 3.5 of the Dispute Finder document, âDetermining Trustworthy Sources,â seems a bit absurd. It actually acknowledges the marketability challenges of its own software: âUnfortunatelyâ¦the sites people actually trust are often those that share the personâs own point of view.â So, again, what is this software and what, really, is the point? Segway into âCross-cutting themes.â Save the world. How? Is Dispute Finder intended to help people sue other people for libel? Richard Jewel (now deceased) had a reasonably compelling case. Thatâs probably why he successfully sued (for libel) every organization, from CNN, to NBC, to the NY Post. All settled. He collected from each of them. But Richard Jewel didnât need help from Dispute Finder. Richard Jewel had a case. &lt;br /&gt;
&lt;br /&gt;
Cross-cutting themes: âChange the technology, save the world.â Okay, why not? Isnât there something else smart people at Intel and UC Berkeley could be doing to make the world better? Last November, the New York Times produced an alarming story [http://www.nytimes.com/2009/11/29/us/29foodstamps.html] about the food stamp program in America(ânow expanding at a pace of about 20,000 people a day.â) Also no shortage of children in custody. Last December, the New York Times obtained â and reported on [http://www.nytimes.com/2009/12/14/nyregion/14juvenile.html?_r=1&amp;amp;scp=1&amp;amp;sq=new%20york%20family%20court%20juvenile%20department%20of%20justice%20youth&amp;amp;st=cse]â a âconfidential draft reportâ prepared by a task force appointed by NY gov David Paterson: âNew York Stateâs current approach fails the young people who are drawn into the system, the public whose safety it is intended to protect, and the principles of good governance that demand effective use of scarce state resources.â Story also says the situation was so bad that the DOJ, at one point, was threatening to âtake over.â &lt;br /&gt;
&lt;br /&gt;
So, if Intel is interested in contributing, how about addressing real problemsâhelping real peopleâ that could affect real, collective societal change and improvement? Children and education seem like obvious places to start. Basics like hardware and mentors could go a long way. Children in poverty struggle with range of issues, including asthma, low self-esteem, obesity, and depression. Consider children in places like the South Bronx (Jonathan Kozolâs children [http://www.amazon.com/Amazing-Grace-Children-Conscience-Nation/dp/0060976977]): allocation of resources in places like this (and/or lower-middle class communities), especially from companies like Intel, could change lives; give voices to people from whom we do not often hear. &lt;br /&gt;
&lt;br /&gt;
Interested to hear thoughts on Internet privacy, though I&#039;m not sure adults have an expectation of privacy anywhere [http://gawker.com/5444885/facebooks-mark-zuckerberg-on-your-erased-privacy-these-are-the-social-norms-now] on the Internet. If you want privacy, don&#039;t put yourself on the Internet. Finally, on the subject of online harassment, if we accept that the Internet is a public place, to what extent is it acceptable to regulate online communication, including but not limited to comments deemed &#039;offensive&#039; on blogs?&lt;br /&gt;
&lt;br /&gt;
Predictions. Guests will be nice. Class will be nice. Hope to hear more about Dispute Finder&#039;s business model.&lt;/div&gt;</summary>
		<author><name>Jharrow</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_5_Predictions&amp;diff=411</id>
		<title>Day 5 Predictions</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_5_Predictions&amp;diff=411"/>
		<updated>2010-01-08T16:59:34Z</updated>

		<summary type="html">&lt;p&gt;Jharrow: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Victoria: My prediction is that the speakers are going to be extolling the virtues of Wikipedia and explaining that although the site has gone under some transformations it is still a vibrant force. I would concede that I think it is. Most people I know still immediately turn to Wikipedia for a quick run down of a topic or an answer to a quick question. However, as time moves on the site is becoming less innovative and more standard. I would like to ask them about their understanding and personal experiences in trying to keep Wikipedia young. Moreover, having read that 85% of the contributors to Wikipedia are male I&#039;d specifically love to ask Phoebe whether she feels that the articles are written from the male gaze and lack the other gender&#039;s perspective.&lt;br /&gt;
&lt;br /&gt;
:: Sharona: Like Vickie, I was also struck by the statistics on the demographic breakdown, and I would love to hear their thoughts on whether they feel wikipedia really does represent a wide range of views, or more specifically (especially in the US) that of a white male. Another thing I think they will likely discuss - and probably not have a good answer for - is the question of privacy and defamation on wikipedia and other wikimedia projects. Can, or should, the website and/or its users or editors be held accountable if allegedly defamatory posts are not removed? Who makes that call? And what standards are used? It seems to me that there&#039;s no easy answer to this: while they may not run into strictly legal issues, it could definitely affect reader&#039;s trust in the information or fear that they too are vulnerable. &lt;br /&gt;
&lt;br /&gt;
Bruno: I expect our guests to focus their comments on the strategies Wikipedia is adopting to address two of what seems to be the main problems of the project: (i) quality/accuracy of its articles, and (ii) issues concerning vandalism. After reading the materials, I was struck by the fact that Wikipedia doesn&#039;t seem to be worried about increasing its user base. The increasing amount of rules, the hostility of veteran users to newbies and the efforts to attract more scientists to participate in the project suggest that in fact they would be interested in less, but more qualified participation. Just like the attitude of our guest from CrowdFlower, perhaps a sort of procrastination to address a problem that is not yet so concrete might be operating here: with over 40 thousand contributors it&#039;s not clear when more means actually less.&lt;br /&gt;
&lt;br /&gt;
:: Sheel: I&#039;d be interested in hearing Wikimedia&#039;s reaction to this: what if people started using CrowdFlower or MechanicalTurk, if they don&#039;t already, to pay people 10 cents or so to go edit Wikipedia pages?  I know they weren&#039;t okay with MyWikiBiz, but this is much more under the radar.  Finally, I&#039;d like to hear where the debate is on inclusionists v. exclusionists (meaning those who want to produce the &#039;integrity&#039; of the encyclopedia and shy away from what may be deemed as frivolous by some portion of editors).  My guess is that there is still no concrete answer---if enough editors are passionate about editing/creating a new page, then it&#039;ll stay.&lt;br /&gt;
&lt;br /&gt;
Daniel: In addition to the topics above, I expect a discussion about the possible increase in vulnerability Wikipedia faces at the content layer, on par with a less dynamic environment. Since most pages are already done, at least in the English version, editors may feel less motivated to monitor existing, but seldom edited pages which are not on the &amp;quot;watch list&amp;quot;. As a consequence, they can be more easily twisted by outsiders. In connection with that issue, I guess that our guests will raise the question &amp;quot;how does it feel to be a Wikipedian?&amp;quot; - and try to describe the community feeling from the perspective of insiders, and the challenges to bring more people in.&lt;br /&gt;
&lt;br /&gt;
Franny:  Main problems within the wikipedia bubble are summarized well above - I think that we also need to examine the problem of how to improve/encourage the transfer of wikipedia&#039;s benefits (e.g. generativity and sense of community) outside of the wikipedia microcosm.  To that end, I hope that our guests will discuss their experiences with similar applications and initiatives (e.g. citizendium, etc.), and provide their views of the successes or weaknesses.&lt;br /&gt;
&lt;br /&gt;
:Jason: Great point by Franny; I too hope they address how Wikipedia&#039;s success can to other initiatives. After all, I&#039;ve been struck by just how &#039;&#039;sui generis&#039;&#039; Wikipedia seems to be, and now that we are in 2010, I think we need to start asking whether Wikipedia is an outlier or whether its principles of both creation and governance can really generalize to other projects. Of course, as I write that, I find myself wondering whether free and open source software is another example of the Wikipedia model. Further, I wonder what they think of as other really good candidates for adopting Wikipedia&#039;s new form of participatory self-government. For instance, some of us have been laughing about Stanford&#039;s new, fairly permissive policies when it comes to handing in papers at the end of the semester (you can still pass the . Could these new policies have been created by the Stanford community via wiki? What would the outcome have been?&lt;br /&gt;
&lt;br /&gt;
Juan: I would like to hear their opinions on&lt;br /&gt;
1. How to deal with vandalism and spams while keeping the generativity of Wikipedia as much as possible. Now they&#039;ve created several restrictions to lower of the possibility of attacks by vandals and spams, such as blocking IP addresses of repeat offenders, using full protection and semi-protection functions to restrict editing of certain pages. However, these restrictions limits free editability and thus seems jeopardize its generativity. &lt;br /&gt;
2. The prospect of wikipedia in China. How will it compete with its local counterpart Hudong. Unlike wikipedia, Hudong rewards top contributors with gifts ranging from post cards to MP3 players, and offers some features that complies with Chinese users&#039; habits. Recently, it even launched it partnership with some popular overseas Chinese website, making its first steps to expand into overseas Chinese market. What is wikipedia&#039;s strategy facing this situation? Is there any possibility to establish some cooperation or strategic partnership between these two on-line encyclopedias? &lt;br /&gt;
3. Sustainable problem. Dedicated editor may leave because of life cycle change, motivation by other UGC websites, tire of anti-threat work, and etc. How will wikipedia attract new editors and keep them?&lt;/div&gt;</summary>
		<author><name>Jharrow</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_4_Predictions&amp;diff=366</id>
		<title>Day 4 Predictions</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_4_Predictions&amp;diff=366"/>
		<updated>2010-01-07T18:25:21Z</updated>

		<summary type="html">&lt;p&gt;Jharrow: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Amanda: I am very interested to hear Chuck&#039;s take on the relationship between the government, large corporations like Microsoft, and the defcon-attending hacker community (like the L0pht group mentioned in the Wired article). Is the government receptive to both groups? I imagine the relationship specifically between the hacker community and the government can become tense because the interests of both groups is not exactly aligned and is sometimes conflicting. Have they been able to successfully work together around a common threat like cybersecurity? While I imagine the government often tries to recruit from the hacker community, and I&#039;m interested to hear where they draw the lines legally as far as subversive behavior within the hacker community (ie do they bend the rules for the sake of potential advances in cybersecurity?).&lt;br /&gt;
:Of course there are great advances yet to be made in the relationship between white-hat hackers and corporations like Microsoft.  Skepticism abounds from both sides for obvious reasons, as well as entrenched interests and preconceptions based on past interactions (&amp;quot;Hackers are simply criminals&amp;quot;, or on the other side &amp;quot;Microsoft is The Man&amp;quot;).&lt;br /&gt;
&lt;br /&gt;
Vickie: I&#039;m going to dovetail from Amanda&#039;s comment and say that I think Chuck is going to speak more specifically about the ID program he was talking about the other day as a possible solution to cybersecurity. Just as in the Wired article - identification solves a large percent of the problem, mostly through accountability. However, this seems too Orwellian for my blood. Unlike a passport that is shown in person - a computer ID is never going to be checked person to person. The computer will always be the intermediary. Moreover, this type of program may deter people from doing things on the Internet that they normally would do - if it wasn&#039;t anonymous. Visit certain political sites, fetish sites etc. etc. At what point is our fear balanced by our need for an Internet that is not being surveyed.&lt;br /&gt;
&lt;br /&gt;
:Ramesh: I wonder what Chuck would say are the benefits to anonymity on the internet, and whether they are outweighed by the security risks. It seems like there could be a creditable argument saying just that. Also, I wonder about problems in scaling up ID programs -- one would assume that many countries would not participate, but if desirable content could only be accessed by an ID, perhaps consumers would then demand their nations also issue internet IDs.&lt;br /&gt;
&lt;br /&gt;
Hector: Some of Chuck&#039;s points from his remarks on Tuesday that stuck with me most were the strengthening of internet identification and alternative networks that use something else than TCP. I hope that he elaborates on the possible applications of the latter.&lt;br /&gt;
&lt;br /&gt;
Lien: I&#039;m very interested to hear (i) what Chuck thinks the biggest cybersecurity risk is that Microsoft and other simular major private companies face and (ii) how the company is prepared for attack on its system and will react on it. I however predict he&#039;s not gonna answer that question...&lt;br /&gt;
&lt;br /&gt;
Reuben: On Tuesday we spent a great deal of time on the attribution problem of cybersecurity which is related to deterrence and retaliation.  I&#039;d like to hear more about that, but I&#039;d also like to hear about how we shore up our own defenses and incentivize security.  I&#039;ll be interested to hear who Chuck thinks should be responsible for security.  There is a dilemma for a company like Microsoft that may not want to have the burden of cybersecurity thrust upon them, but may also resist government mandates and control.  I think Chuck will probably recognize that both public and private sector have a role to play, but he will emphasize the need for government to provide more leadership in the area.&lt;br /&gt;
&lt;br /&gt;
Jason: Especially since we have already had some discussion on the security issue, I think the class will be able to offer some interesting solutions for problems that exist pretty high-up in the stack, like user behavior, software, ID schemes, and other things that happen at the end node. But I predict that we&#039;ll be somewhat flummoxed about what&#039;s going on and what to do about the fundamental nature of the network, like the implications of the stuff that Clark was talking about in [http://www.ischool.berkeley.edu/newsandevents/events/sl20090304 his talk] that we listened to. I certainly am - though hopefully we&#039;ll make a bit of headway in class.&lt;/div&gt;</summary>
		<author><name>Jharrow</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_4_Predictions&amp;diff=365</id>
		<title>Day 4 Predictions</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_4_Predictions&amp;diff=365"/>
		<updated>2010-01-07T18:25:00Z</updated>

		<summary type="html">&lt;p&gt;Jharrow: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Amanda: I am very interested to hear Chuck&#039;s take on the relationship between the government, large corporations like Microsoft, and the defcon-attending hacker community (like the L0pht group mentioned in the Wired article). Is the government receptive to both groups? I imagine the relationship specifically between the hacker community and the government can become tense because the interests of both groups is not exactly aligned and is sometimes conflicting. Have they been able to successfully work together around a common threat like cybersecurity? While I imagine the government often tries to recruit from the hacker community, and I&#039;m interested to hear where they draw the lines legally as far as subversive behavior within the hacker community (ie do they bend the rules for the sake of potential advances in cybersecurity?).&lt;br /&gt;
:Of course there are great advances yet to be made in the relationship between white-hat hackers and corporations like Microsoft.  Skepticism abounds from both sides for obvious reasons, as well as entrenched interests and preconceptions based on past interactions (&amp;quot;Hackers are simply criminals&amp;quot;, or on the other side &amp;quot;Microsoft is The Man&amp;quot;).&lt;br /&gt;
&lt;br /&gt;
Vickie: I&#039;m going to dovetail from Amanda&#039;s comment and say that I think Chuck is going to speak more specifically about the ID program he was talking about the other day as a possible solution to cybersecurity. Just as in the Wired article - identification solves a large percent of the problem, mostly through accountability. However, this seems too Orwellian for my blood. Unlike a passport that is shown in person - a computer ID is never going to be checked person to person. The computer will always be the intermediary. Moreover, this type of program may deter people from doing things on the Internet that they normally would do - if it wasn&#039;t anonymous. Visit certain political sites, fetish sites etc. etc. At what point is our fear balanced by our need for an Internet that is not being surveyed.&lt;br /&gt;
&lt;br /&gt;
:Ramesh: I wonder what Chuck would say are the benefits to anonymity on the internet, and whether they are outweighed by the security risks. It seems like there could be a creditable argument saying just that. Also, I wonder about problems in scaling up ID programs -- one would assume that many countries would not participate, but if desirable content could only be accessed by an ID, perhaps consumers would then demand their nations also issue internet IDs.&lt;br /&gt;
&lt;br /&gt;
Hector: Some of Chuck&#039;s points from his remarks on Tuesday that stuck with me most were the strengthening of internet identification and alternative networks that use something else than TCP. I hope that he elaborates on the possible applications of the latter.&lt;br /&gt;
&lt;br /&gt;
Lien: I&#039;m very interested to hear (i) what Chuck thinks the biggest cybersecurity risk is that Microsoft and other simular major private companies face and (ii) how the company is prepared for attack on its system and will react on it. I however predict he&#039;s not gonna answer that question...&lt;br /&gt;
&lt;br /&gt;
Reuben: On Tuesday we spent a great deal of time on the attribution problem of cybersecurity which is related to deterrence and retaliation.  I&#039;d like to hear more about that, but I&#039;d also like to hear about how we shore up our own defenses and incentivize security.  I&#039;ll be interested to hear who Chuck thinks should be responsible for security.  There is a dilemma for a company like Microsoft that may not want to have the burden of cybersecurity thrust upon them, but may also resist government mandates and control.  I think Chuck will probably recognize that both public and private sector have a role to play, but he will emphasize the need for government to provide more leadership in the area.&lt;br /&gt;
&lt;br /&gt;
Jason: Especially since we have already had some discussion on the security issue, I think the class will be able to offer some interesting solutions for problems that exist pretty high-up in the stack, like user behavior, software, ID schemes, and other things that happen at the end node. But I predict that we&#039;ll be somewhat flummoxed about what&#039;s going on and what to do about the fundamental nature of the network, like the implications of the stuff that Clark was talking about in [http://www.ischool.berkeley.edu/newsandevents/events/sl20090304 his talk] that we listened to. I certainly am - at least for now.&lt;/div&gt;</summary>
		<author><name>Jharrow</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_4_Predictions&amp;diff=364</id>
		<title>Day 4 Predictions</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_4_Predictions&amp;diff=364"/>
		<updated>2010-01-07T18:24:21Z</updated>

		<summary type="html">&lt;p&gt;Jharrow: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Amanda: I am very interested to hear Chuck&#039;s take on the relationship between the government, large corporations like Microsoft, and the defcon-attending hacker community (like the L0pht group mentioned in the Wired article). Is the government receptive to both groups? I imagine the relationship specifically between the hacker community and the government can become tense because the interests of both groups is not exactly aligned and is sometimes conflicting. Have they been able to successfully work together around a common threat like cybersecurity? While I imagine the government often tries to recruit from the hacker community, and I&#039;m interested to hear where they draw the lines legally as far as subversive behavior within the hacker community (ie do they bend the rules for the sake of potential advances in cybersecurity?).&lt;br /&gt;
:Of course there are great advances yet to be made in the relationship between white-hat hackers and corporations like Microsoft.  Skepticism abounds from both sides for obvious reasons, as well as entrenched interests and preconceptions based on past interactions (&amp;quot;Hackers are simply criminals&amp;quot;, or on the other side &amp;quot;Microsoft is The Man&amp;quot;).&lt;br /&gt;
&lt;br /&gt;
Vickie: I&#039;m going to dovetail from Amanda&#039;s comment and say that I think Chuck is going to speak more specifically about the ID program he was talking about the other day as a possible solution to cybersecurity. Just as in the Wired article - identification solves a large percent of the problem, mostly through accountability. However, this seems too Orwellian for my blood. Unlike a passport that is shown in person - a computer ID is never going to be checked person to person. The computer will always be the intermediary. Moreover, this type of program may deter people from doing things on the Internet that they normally would do - if it wasn&#039;t anonymous. Visit certain political sites, fetish sites etc. etc. At what point is our fear balanced by our need for an Internet that is not being surveyed.&lt;br /&gt;
&lt;br /&gt;
:Ramesh: I wonder what Chuck would say are the benefits to anonymity on the internet, and whether they are outweighed by the security risks. It seems like there could be a creditable argument saying just that. Also, I wonder about problems in scaling up ID programs -- one would assume that many countries would not participate, but if desirable content could only be accessed by an ID, perhaps consumers would then demand their nations also issue internet IDs.&lt;br /&gt;
&lt;br /&gt;
Hector: Some of Chuck&#039;s points from his remarks on Tuesday that stuck with me most were the strengthening of internet identification and alternative networks that use something else than TCP. I hope that he elaborates on the possible applications of the latter.&lt;br /&gt;
&lt;br /&gt;
Lien: I&#039;m very interested to hear (i) what Chuck thinks the biggest cybersecurity risk is that Microsoft and other simular major private companies face and (ii) how the company is prepared for attack on its system and will react on it. I however predict he&#039;s not gonna answer that question...&lt;br /&gt;
&lt;br /&gt;
Reuben: On Tuesday we spent a great deal of time on the attribution problem of cybersecurity which is related to deterrence and retaliation.  I&#039;d like to hear more about that, but I&#039;d also like to hear about how we shore up our own defenses and incentivize security.  I&#039;ll be interested to hear who Chuck thinks should be responsible for security.  There is a dilemma for a company like Microsoft that may not want to have the burden of cybersecurity thrust upon them, but may also resist government mandates and control.  I think Chuck will probably recognize that both public and private sector have a role to play, but he will emphasize the need for government to provide more leadership in the area.&lt;br /&gt;
&lt;br /&gt;
Jason: Especially since we have already had some discussion on the security issue, I think the class will be able to offer some interesting solutions, especially high-up in the stack, like user behavior, software, ID schemes, and other things that happen at the end node. But I predict that we&#039;ll be somewhat flummoxed about what&#039;s going on and what to do about the fundamental nature of the network, like the implications of the stuff that Clark was talking about in [http://www.ischool.berkeley.edu/newsandevents/events/sl20090304 his talk] that we listened to. I certainly am - at least for now.&lt;/div&gt;</summary>
		<author><name>Jharrow</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_3_Thoughts&amp;diff=363</id>
		<title>Day 3 Thoughts</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_3_Thoughts&amp;diff=363"/>
		<updated>2010-01-07T18:17:08Z</updated>

		<summary type="html">&lt;p&gt;Jharrow: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Tyler: I am wondering if the terms in AMT&#039;s conditions of use that works prepared by turkers are to be considered works for hire would be considered valid. My initial instinct is that it would not necessarily be so.&lt;br /&gt;
&lt;br /&gt;
: To paraphrase, the Copyright Act defines a work for hire as (17 U.S.C. 101):&lt;br /&gt;
&lt;br /&gt;
* 1) a work prepared by an employee within the scope of his or her employment&lt;br /&gt;
** The factors to make determination were listed in the CCNV v Reid case (790 U.S. 730, 1989)&lt;br /&gt;
*** The two most important factors are provision of employee benefits and tax treatment (from Aymes v. Bonelli, 980 F.2d 857, 1992)&lt;br /&gt;
* OR 2) a work specially ordered or commissioned for use as a contribution to a collective work if:&lt;br /&gt;
** 1. category: is one of:&lt;br /&gt;
*** part of a motion picture or other audiovisual work&lt;br /&gt;
*** a translation&lt;br /&gt;
*** a supplementary work â adjunct to a work made by another author&lt;br /&gt;
*** a compilation&lt;br /&gt;
*** an instructional text â systematic instructional activities&lt;br /&gt;
*** a test&lt;br /&gt;
*** answer material for a test&lt;br /&gt;
*** an atlas&lt;br /&gt;
** 2. intent: if the parties expressly agree in a written instrument signed by them that the work shall be considered a work made for hire&lt;br /&gt;
must fit into one of the 8 categories to be a contracted work made for hire (p132)&lt;br /&gt;
Most work produced for HITs would not seem to fall into either of these categories.&lt;br /&gt;
&lt;br /&gt;
::Michael: I think many works produced through HITs are going to be considered compilations or collective works. Certainly David&#039;s Sheep or 100 Dollar Bill are compilations so long as they are taken as a whole. Even in any attempt to monetize the individual elements, the Turk Participation Agreement states that any works which cannot be considered works for hire are assigned to the requester. (full text copied below)&lt;br /&gt;
&lt;br /&gt;
::Section 3(a): &amp;quot;As a Provider, the Requester for whom you provide Services is your client, and as such, you agree that the work product of any Services you perform is deemed a &amp;quot;work made for hire&amp;quot; for the benefit of the Requester, and all ownership rights, including worldwide intellectual property rights, will vest with the Requester immediately upon your performance of the Service. To the extent any such rights do not vest in Requester under applicable law, you hereby assign or exclusively grant (without the right to any compensation) all right, title and interest, including all intellectual property rights, to such work product to Requester.&amp;quot; [https://www.mturk.com/mturk/conditionsofuse The full policy can be found here.]&lt;br /&gt;
&lt;br /&gt;
::Jason: Michael just sort of stole my mojo - I was about to say a similar thing - but Tyler, I guess I too don&#039;t see why you think HITs are not works-for-hire under test 2. Take the book about cats: it seems to me that Bjoern specifically ordered those stories for his compilation, which would fall under the rule. I guess there could be a problem of asymmetry if both parties need to know that they work is being commissioned, since in many cases only the commissioner might know what it&#039;s being used for. But given the Mechanical Turk terms of service that Michael reproduces above - which probably constitutes a &amp;quot;written instrument&amp;quot; - I think the Turker would be hard-pressed to argue that he had zero notice, even if he didn&#039;t know specifically what his work would be used for.&lt;br /&gt;
&lt;br /&gt;
:::Andrew: I think there&#039;s certainly enough wiggle room in the words &amp;quot;specially ordered or commissioned&amp;quot; to support a claim that the AMT contract does not effect WMFH status, at least in some cases. Take the cats book: When it was ordered, Bjorn himself didn&#039;t know what he was going to do with the cats when he got them. How could he argue that he had &amp;quot;specially ordered or commissioned&amp;quot; them for that compilation at the time of the contract? More generally, I think the &#039;meeting of the minds&#039; aspect is more important than Jason suggests, given that it&#039;s the basis of so much doctrine in contract interpretation. That is, I think it&#039;s an open question whether a task which the performer does not know to have a certain purpose can be said to be &amp;quot;specially ordered or commissioned&amp;quot; for that purpose with regard to the written instrument. &lt;br /&gt;
&lt;br /&gt;
::Sharona: While I agree with Jason and Michael that this is probably a work made for hire, do you think this may run into contracts of adhesion problems? Or, do you think if the average turker was aware of what his &amp;quot;original&amp;quot; (after all, to be copyrightable, it must be original) work would be used for, he would have agreed to the Participation Agreement? Does it matter?&lt;br /&gt;
&lt;br /&gt;
::Tyler: To follow up on my original thought, I agree that an argument could be made for HITs to be WMFH, but I see big problems with the &amp;quot;specially ordered or commissioned&amp;quot; language as Andrew mentioned. Also, I&#039;m not sure mention in the terms of service would qualify as a written instrument signed by both parties.&lt;br /&gt;
&lt;br /&gt;
:::Jason: Hmmm, that&#039;s interesting. After doing a bit more reading, I agree that the WMFH requirements are a bit stricter than I thought they were, so I do see your point, even though I stand by the view that the cat book contributions likely qualify as works made for hire. Maybe we need to find a HIT that becomes a creative work and then sue the compiler for copyright violation to find out? Sure, it&#039;d be an ironic copyright suit coming from this group, but we can work around that.&lt;br /&gt;
&lt;br /&gt;
Victoria: I think what bothers me most about Ub. Hum. Comp. through tools like Mechanical Turk and re-Captcha is the lack of transparency. I think a lot of the fear about these programs - that lead to the Iranian hypo stem from a lack of transparency. The task master is not required to say what the micro task is for. However, what I found to be a fascinating comment last night in response to this came from Bjoern. After publishing the cat book he said he asked a test group if it was OK to publish the book without asking first. Bjoern reported that the Turkers seemed to be OK with it. I wonder if it is just the non-Turkers (like myself) that have a problem with the lack of transparency and dream up these dystopic problems. &lt;br /&gt;
&lt;br /&gt;
Secondly in addition to transparency I have a problem with the micro-tasking. Although Aaron&#039;s artwork is completely beautiful - Crowdflower kind of makes me feel uneasy at times - especially when thinking that it could eventually be tapped into on an IPhone app during a person&#039;s idle time and that a security guard is doing it while he is supposed to be engaged in surveillance. By making the tasks so short and small Turk infuses money-making into every aspect of life. It makes everything a cost-benefit analysis. Should I go to the beach and read a Magazine or make money. Should I stand in line and think about what I have to cook later or make money? Should I spend time with my family or make money?&lt;/div&gt;</summary>
		<author><name>Jharrow</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_3_Thoughts&amp;diff=348</id>
		<title>Day 3 Thoughts</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_3_Thoughts&amp;diff=348"/>
		<updated>2010-01-07T07:51:31Z</updated>

		<summary type="html">&lt;p&gt;Jharrow: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Tyler: I am wondering if the terms in AMT&#039;s conditions of use that works prepared by turkers are to be considered works for hire would be considered valid. My initial instinct is that it would not necessarily be so.&lt;br /&gt;
&lt;br /&gt;
: To paraphrase, the Copyright Act defines a work for hire as (17 U.S.C. 101):&lt;br /&gt;
&lt;br /&gt;
* 1) a work prepared by an employee within the scope of his or her employment&lt;br /&gt;
** The factors to make determination were listed in the CCNV v Reid case (790 U.S. 730, 1989)&lt;br /&gt;
*** The two most important factors are provision of employee benefits and tax treatment (from Aymes v. Bonelli, 980 F.2d 857, 1992)&lt;br /&gt;
* OR 2) a work specially ordered or commissioned for use as a contribution to a collective work if:&lt;br /&gt;
** 1. category: is one of:&lt;br /&gt;
*** part of a motion picture or other audiovisual work&lt;br /&gt;
*** a translation&lt;br /&gt;
*** a supplementary work â adjunct to a work made by another author&lt;br /&gt;
*** a compilation&lt;br /&gt;
*** an instructional text â systematic instructional activities&lt;br /&gt;
*** a test&lt;br /&gt;
*** answer material for a test&lt;br /&gt;
*** an atlas&lt;br /&gt;
** 2. intent: if the parties expressly agree in a written instrument signed by them that the work shall be considered a work made for hire&lt;br /&gt;
must fit into one of the 8 categories to be a contracted work made for hire (p132)&lt;br /&gt;
Most work produced for HITs would not seem to fall into either of these categories.&lt;br /&gt;
&lt;br /&gt;
::Michael: I think many works produced through HITs are going to be considered compilations or collective works. Certainly David&#039;s Sheep or 100 Dollar Bill are compilations so long as they are taken as a whole. Even in any attempt to monetize the individual elements, the Turk Participation Agreement states that any works which cannot be considered works for hire are assigned to the requester. (full text copied below)&lt;br /&gt;
&lt;br /&gt;
::Section 3(a): &amp;quot;As a Provider, the Requester for whom you provide Services is your client, and as such, you agree that the work product of any Services you perform is deemed a &amp;quot;work made for hire&amp;quot; for the benefit of the Requester, and all ownership rights, including worldwide intellectual property rights, will vest with the Requester immediately upon your performance of the Service. To the extent any such rights do not vest in Requester under applicable law, you hereby assign or exclusively grant (without the right to any compensation) all right, title and interest, including all intellectual property rights, to such work product to Requester.&amp;quot; [https://www.mturk.com/mturk/conditionsofuse The full policy can be found here.]&lt;br /&gt;
&lt;br /&gt;
::Jason: Michael just sort of stole my mojo - I was about to say a similar thing - but Tyler, I guess I too don&#039;t see why you think HITs are not works-for-hire under test 2. Take the book about cats: it seems to me that Bjoern specifically ordered those stories for his compilation, which would fall under the rule. I guess there could be a problem of asymmetry if both parties need to know that they work is being commissioned, since in many cases only the commissioner might know what it&#039;s being used for. But given the Mechanical Turk terms of service that Michael reproduces above - which probably constitutes a &amp;quot;written instrument&amp;quot; - I think the Turker would be hard-pressed to argue that he had zero notice, even if he didn&#039;t know specifically what his work would be used for.&lt;/div&gt;</summary>
		<author><name>Jharrow</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_3_Thoughts&amp;diff=347</id>
		<title>Day 3 Thoughts</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_3_Thoughts&amp;diff=347"/>
		<updated>2010-01-07T07:50:49Z</updated>

		<summary type="html">&lt;p&gt;Jharrow: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Tyler: I am wondering if the terms in AMT&#039;s conditions of use that works prepared by turkers are to be considered works for hire would be considered valid. My initial instinct is that it would not necessarily be so.&lt;br /&gt;
&lt;br /&gt;
: To paraphrase, the Copyright Act defines a work for hire as (17 U.S.C. 101):&lt;br /&gt;
&lt;br /&gt;
* 1) a work prepared by an employee within the scope of his or her employment&lt;br /&gt;
** The factors to make determination were listed in the CCNV v Reid case (790 U.S. 730, 1989)&lt;br /&gt;
*** The two most important factors are provision of employee benefits and tax treatment (from Aymes v. Bonelli, 980 F.2d 857, 1992)&lt;br /&gt;
* OR 2) a work specially ordered or commissioned for use as a contribution to a collective work if:&lt;br /&gt;
** 1. category: is one of:&lt;br /&gt;
*** part of a motion picture or other audiovisual work&lt;br /&gt;
*** a translation&lt;br /&gt;
*** a supplementary work â adjunct to a work made by another author&lt;br /&gt;
*** a compilation&lt;br /&gt;
*** an instructional text â systematic instructional activities&lt;br /&gt;
*** a test&lt;br /&gt;
*** answer material for a test&lt;br /&gt;
*** an atlas&lt;br /&gt;
** 2. intent: if the parties expressly agree in a written instrument signed by them that the work shall be considered a work made for hire&lt;br /&gt;
must fit into one of the 8 categories to be a contracted work made for hire (p132)&lt;br /&gt;
Most work produced for HITs would not seem to fall into either of these categories.&lt;br /&gt;
&lt;br /&gt;
::Michael: I think many works produced through HITs are going to be considered compilations or collective works. Certainly David&#039;s Sheep or 100 Dollar Bill are compilations so long as they are taken as a whole. Even in any attempt to monetize the individual elements, the Turk Participation Agreement states that any works which cannot be considered works for hire are assigned to the requester. (full text copied below)&lt;br /&gt;
&lt;br /&gt;
::Section 3(a): &amp;quot;As a Provider, the Requester for whom you provide Services is your client, and as such, you agree that the work product of any Services you perform is deemed a &amp;quot;work made for hire&amp;quot; for the benefit of the Requester, and all ownership rights, including worldwide intellectual property rights, will vest with the Requester immediately upon your performance of the Service. To the extent any such rights do not vest in Requester under applicable law, you hereby assign or exclusively grant (without the right to any compensation) all right, title and interest, including all intellectual property rights, to such work product to Requester.&amp;quot; [https://www.mturk.com/mturk/conditionsofuse The full policy can be found here.]&lt;br /&gt;
&lt;br /&gt;
::Jason: Tyler, Michael just sort of stole my thunder - I was about to say a similar thing - but I guess I too don&#039;t see why you think HITs are not works-for-hire under test 2. Take the book about cats: it seems to me that Bjoern specifically ordered those stories for his compilation, which would fall under the rule. I guess there could be a problem of asymmetry if both parties need to know that they work is being commissioned, since in many cases only the commissioner might know what it&#039;s being used for. But given the Mechanical Turk terms of service that Michael reproduces above - which probably constitutes a &amp;quot;written instrument&amp;quot; - I think the Turker would be hard-pressed to argue that he had zero notice, even if he didn&#039;t know specifically what his work would be used for.&lt;/div&gt;</summary>
		<author><name>Jharrow</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_3_Predictions&amp;diff=311</id>
		<title>Day 3 Predictions</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_3_Predictions&amp;diff=311"/>
		<updated>2010-01-06T20:49:39Z</updated>

		<summary type="html">&lt;p&gt;Jharrow: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Daniel: My guess is that three issues will be focused:&lt;br /&gt;
&lt;br /&gt;
1- &#039;&#039;labor rights&#039;&#039; â workers in UHC are not attached to a safe work environment, do not receive any fringe benefits, health care, etc., and as of yet there are no unions for Turks and the like. It is quite easy to see homeworkers as nonworkers, and to build [http://www.missconceptions.net/downloads/mturk-pca09-web.pdf digital sweatshops].&lt;br /&gt;
&lt;br /&gt;
2- workersâ new &#039;&#039;expectation of complete anonymity&#039;&#039;, that go way beyond privacy demands in regular work environments. Hopefully ethical issues concerning this faceless workforce will be discussed, as well as its potential identity and community feelings (taking into account that, unlike bearers of [http://www.iab.net/about_the_iab/recent_press_releases/press_release_archive/press_release/pr-061009-value formal jobs], UHC workers have shifting numbers, not social security ones). Still on this topic, I expect debates about people willing to perform otherwise shameful tasks, and about the opportunities for children, sick or unfit workers in general to work / be worked. &lt;br /&gt;
&lt;br /&gt;
3- the &#039;&#039;use of UHC for complex, creative tasks&#039;&#039;, analyzed in conjunction with a look at the economics of commoditized labor pools. Resulting discussions could examine quality control and its costs, and [http://portal.acm.org/citation.cfm?id=1357054.1357127 proper design], necessary to unleash [http://www.youtube.com/watch?v=rQ3Q6Y6Ylqo creativity] and demand more than repetitive, boring tasks from fellow anonymous humans. On that note, it is nice to see that, as scientific experiments with Mechanical Turks [http://experimentalturk.wordpress.com/ become more popular], academic attention is drawn towards the problematic incentives in the platformâs most common setting (low payment + repetitive tasks), which encourages Turks to finish HITs as fast as they can, [http://experimentalphilosophy.typepad.com/experimental_philosophy/2010/01/looking-for-subjects-amazons-mechanical-turk.html at the expense of proper comprehension of the tasks].&lt;br /&gt;
: Andrew: Since at least some of our guests tonight are &amp;quot;creatives&amp;quot;, I hope to hear some discussion about the relationship between full-time freelancers and websites that crowdsource complex, creative tasks (e.g. Worth1000, [http://www.istockphoto.com/index.php iStockPhoto]). At a Berkman lunch last spring, [http://crowdsourcing.typepad.com/ Jeff Howe] cited a [http://papers.ssrn.com/sol3/papers.cfm?abstract_id=1122462 study] that showed only 4% of iStockPhoto sellers derived their primary income from the site. As the site and its peers begin to dominate the market for stock photography, what happens to the livelihoods of those who depended on stock photography for a living? Protectionist worries like this parallel those about outsourcing more generally and are vulnerable to the same counters about progress and efficient markets; I hope some of those arguments play out tonight. &lt;br /&gt;
&lt;br /&gt;
My wish list for the session: discussions of solutions / tools such as [http://turkopticon.differenceengines.com/ Turkopticon], a Firefox application designed to identify and expose âshady employersâ.&lt;br /&gt;
&lt;br /&gt;
Ramesh: I predict that the founders of human computing websites will be more focused on the technology and potential of the websites and may have a blind spot for the legal issues that may be raised by UHC (applicability of minimum wage and other laws) while as law students, we may naturally focus on the legal issues implicated.&lt;br /&gt;
&lt;br /&gt;
Alternatively, perhaps the founders of UHC websites will see them simply as a continuation of current trends, especially the increasing numbers of contractors in the labor force of large companies and governments and the outsourcing of call-center (and increasingly higher-skilled) jobs overseas. Does UHC present any problems that are different from the current trends? What role can employment and labor law play in a world where increasing numbers of workers are &amp;quot;independent contractors&amp;quot; or even Mechanical Turks? Will technology re-enact Lochner?&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Franny:&lt;br /&gt;
&lt;br /&gt;
Given the guest list, I diplomatically disagree with Daniel (and agree with Ramesh) and would expect these guests to address the positive potential and advantages of human computing applications into business, arts and culture, as well as the benefits available through this new type of labour force with built-in autonomy.  As libertarian as I may be in my views, I agree with Daniel that there is a real possibility that UHC can develop into a last resort for unskilled workers to earn income in order to survive.  I just don&#039;t think that the negative aspects will be the focus of today&#039;s session.&lt;br /&gt;
&lt;br /&gt;
I would also be interested to hear our guests&#039; thoughts on whether UHC can be applied to tasks in which sensitive information is involved, and if so, how could private content be protected?&lt;br /&gt;
&lt;br /&gt;
:Jason: Totally agree with Franny here. I was at first somewhat surprised that in the talk that Lukas gave at TechCruch 50 there was zero discussion of any of the legal aspects of this (no one asked, &amp;quot;Um, do you have to withhold taxes from the workers?&amp;quot; or &amp;quot;What if it turned out that someone was a child?&amp;quot; or &amp;quot;Won&#039;t your business model be ruined if it turns out you have to pay taxes for not providing health insurance to these people?&amp;quot; or anything along those lines) - but, of course, I forgot that I&#039;m a law student and that&#039;s not the lens through which they are viewing this technology. Faced with a room of (mostly) lawyers, these questions will obviously come more the fore than they were there, but I suspect that the considerable advantages and potential of this type of work will dominate the discussion.&lt;br /&gt;
&lt;br /&gt;
Juan: &lt;br /&gt;
&lt;br /&gt;
By doing quality control and tracking the quality history of workers, Crowdflower moves one step closer to a real employer. How will it and other human computing websites deal with labor law issues, such as employment relationship, jurisdiction conflict, non-compete agreement, anti-discrimination, disability, leave time, wage and hour requirements, and etc. Also, building up workers&#039; career path, balancing between monitoring and privacy intrusion, disclosing information for workers to evaluate the moral value and giving them the opportunity to opt out, shall be new problems in the cyberspace. Besides, this paid work on-line may have an impact on those contributions without payments. How will we address this issue to make sure people will have incentives to embark on free works. &lt;br /&gt;
&lt;br /&gt;
Another thing I want to hear is whether UHC will develop verticals like the traditional industries. How will it develop those verticals not suitable for on-line outsourcing per its nature?&lt;br /&gt;
&lt;br /&gt;
Sharona: I agree with Franny and Ramesh - I think the speakers will generally focus more on the positive contributions these types of sites can offer - the innovation from crowd sourcing, the efficiency, the specialization - and less concern over the legal issues. One thing I would like to hear is whether they think these tasks will continue to be performed by US residents, or how quickly they will also be outsourced to English speaking (or non-English speaking) people across the world looking for menial labor especially. Another thing to consider is how or if people could actually make a career out of doing tasks online, or whether it is just something to supplement another job. How will things like health benefits or insurance policies come into play for these kinds of workers?&lt;/div&gt;</summary>
		<author><name>Jharrow</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_3_Predictions&amp;diff=310</id>
		<title>Day 3 Predictions</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_3_Predictions&amp;diff=310"/>
		<updated>2010-01-06T20:48:34Z</updated>

		<summary type="html">&lt;p&gt;Jharrow: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Daniel: My guess is that three issues will be focused:&lt;br /&gt;
&lt;br /&gt;
1- &#039;&#039;labor rights&#039;&#039; â workers in UHC are not attached to a safe work environment, do not receive any fringe benefits, health care, etc., and as of yet there are no unions for Turks and the like. It is quite easy to see homeworkers as nonworkers, and to build [http://www.missconceptions.net/downloads/mturk-pca09-web.pdf digital sweatshops].&lt;br /&gt;
&lt;br /&gt;
2- workersâ new &#039;&#039;expectation of complete anonymity&#039;&#039;, that go way beyond privacy demands in regular work environments. Hopefully ethical issues concerning this faceless workforce will be discussed, as well as its potential identity and community feelings (taking into account that, unlike bearers of [http://www.iab.net/about_the_iab/recent_press_releases/press_release_archive/press_release/pr-061009-value formal jobs], UHC workers have shifting numbers, not social security ones). Still on this topic, I expect debates about people willing to perform otherwise shameful tasks, and about the opportunities for children, sick or unfit workers in general to work / be worked. &lt;br /&gt;
&lt;br /&gt;
3- the &#039;&#039;use of UHC for complex, creative tasks&#039;&#039;, analyzed in conjunction with a look at the economics of commoditized labor pools. Resulting discussions could examine quality control and its costs, and [http://portal.acm.org/citation.cfm?id=1357054.1357127 proper design], necessary to unleash [http://www.youtube.com/watch?v=rQ3Q6Y6Ylqo creativity] and demand more than repetitive, boring tasks from fellow anonymous humans. On that note, it is nice to see that, as scientific experiments with Mechanical Turks [http://experimentalturk.wordpress.com/ become more popular], academic attention is drawn towards the problematic incentives in the platformâs most common setting (low payment + repetitive tasks), which encourages Turks to finish HITs as fast as they can, [http://experimentalphilosophy.typepad.com/experimental_philosophy/2010/01/looking-for-subjects-amazons-mechanical-turk.html at the expense of proper comprehension of the tasks].&lt;br /&gt;
: Andrew: Since at least some of our guests tonight are &amp;quot;creatives&amp;quot;, I hope to hear some discussion about the relationship between full-time freelancers and websites that crowdsource complex, creative tasks (e.g. Worth1000, [http://www.istockphoto.com/index.php iStockPhoto]). At a Berkman lunch last spring, [http://crowdsourcing.typepad.com/ Jeff Howe] cited a [http://papers.ssrn.com/sol3/papers.cfm?abstract_id=1122462 study] that showed only 4% of iStockPhoto sellers derived their primary income from the site. As the site and its peers begin to dominate the market for stock photography, what happens to the livelihoods of those who depended on stock photography for a living? Protectionist worries like this parallel those about outsourcing more generally and are vulnerable to the same counters about progress and efficient markets; I hope some of those arguments play out tonight. &lt;br /&gt;
&lt;br /&gt;
My wish list for the session: discussions of solutions / tools such as [http://turkopticon.differenceengines.com/ Turkopticon], a Firefox application designed to identify and expose âshady employersâ.&lt;br /&gt;
&lt;br /&gt;
Ramesh: I predict that the founders of human computing websites will be more focused on the technology and potential of the websites and may have a blind spot for the legal issues that may be raised by UHC (applicability of minimum wage and other laws) while as law students, we may naturally focus on the legal issues implicated.&lt;br /&gt;
&lt;br /&gt;
Alternatively, perhaps the founders of UHC websites will see them simply as a continuation of current trends, especially the increasing numbers of contractors in the labor force of large companies and governments and the outsourcing of call-center (and increasingly higher-skilled) jobs overseas. Does UHC present any problems that are different from the current trends? What role can employment and labor law play in a world where increasing numbers of workers are &amp;quot;independent contractors&amp;quot; or even Mechanical Turks? Will technology re-enact Lochner?&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Franny:&lt;br /&gt;
&lt;br /&gt;
Given the guest list, I diplomatically disagree with Daniel (and agree with Ramesh) and would expect these guests to address the positive potential and advantages of human computing applications into business, arts and culture, as well as the benefits available through this new type of labour force with built-in autonomy.  As libertarian as I may be in my views, I agree with Daniel that there is a real possibility that UHC can develop into a last resort for unskilled workers to earn income in order to survive.  I just don&#039;t think that the negative aspects will be the focus of today&#039;s session.&lt;br /&gt;
&lt;br /&gt;
I would also be interested to hear our guests&#039; thoughts on whether UHC can be applied to tasks in which sensitive information is involved, and if so, how could private content be protected?&lt;br /&gt;
&lt;br /&gt;
:Jason: Totally agree with Franny here. I was at first somewhat surprised that in the talk that Lukas gave at TechCruch 50 there was zero discussion of any of the legal aspects of this (no one asked, &amp;quot;Um, do you have to withhold taxes from the workers?&amp;quot; or &amp;quot;What if it turned out that someone was a child?&amp;quot; or &amp;quot;Won&#039;t your business model be ruined if it turns out you have to pay taxes for not providing health insurance to these people&amp;quot; or anything along those lines) - but, of course, I forgot that I&#039;m a law student and that&#039;s not the lens through which they are viewing this technology. Faced with a room of (mostly) lawyers, these questions will obviously come more the fore than they were there, but I suspect that the considerable advantages and potential of this type of work will dominate the discussion.&lt;br /&gt;
&lt;br /&gt;
Juan: &lt;br /&gt;
&lt;br /&gt;
By doing quality control and tracking the quality history of workers, Crowdflower moves one step closer to a real employer. How will it and other human computing websites deal with labor law issues, such as employment relationship, jurisdiction conflict, non-compete agreement, anti-discrimination, disability, leave time, wage and hour requirements, and etc. Also, building up workers&#039; career path, balancing between monitoring and privacy intrusion, disclosing information for workers to evaluate the moral value and giving them the opportunity to opt out, shall be new problems in the cyberspace. Besides, this paid work on-line may have an impact on those contributions without payments. How will we address this issue to make sure people will have incentives to embark on free works. &lt;br /&gt;
&lt;br /&gt;
Another thing I want to hear is whether UHC will develop verticals like the traditional industries. How will it develop those verticals not suitable for on-line outsourcing per its nature?&lt;br /&gt;
&lt;br /&gt;
Sharona: I agree with Franny and Ramesh - I think the speakers will generally focus more on the positive contributions these types of sites can offer - the innovation from crowd sourcing, the efficiency, the specialization - and less concern over the legal issues. One thing I would like to hear is whether they think these tasks will continue to be performed by US residents, or how quickly they will also be outsourced to English speaking (or non-English speaking) people across the world looking for menial labor especially. Another thing to consider is how or if people could actually make a career out of doing tasks online, or whether it is just something to supplement another job. How will things like health benefits or insurance policies come into play for these kinds of workers?&lt;/div&gt;</summary>
		<author><name>Jharrow</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_2_Thoughts&amp;diff=299</id>
		<title>Day 2 Thoughts</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_2_Thoughts&amp;diff=299"/>
		<updated>2010-01-06T19:45:11Z</updated>

		<summary type="html">&lt;p&gt;Jharrow: /* Cybersecurity */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Cybersecurity ==&lt;br /&gt;
&lt;br /&gt;
Daniel: the idea of a &amp;quot;digital driver&#039;s license&amp;quot; has been around for [http://www.youtube.com/watch?v=RrpajcAgR1E some time now]. Effective and simple [http://en.wikipedia.org/wiki/Digital_signature digital signature] schemes, outside corporate or governmental control, sound much more promising to me.&lt;br /&gt;
&lt;br /&gt;
Jason: This was a great discussion. To borrow a taxonomy from the [http://consc.net/papers/facing.html philosophy of mind], I particularly liked that we were trying to identify the &amp;quot;hard&amp;quot; problems and the &amp;quot;easy&amp;quot; problems of cybersecurity - even if we didn&#039;t always agree about what they are. In theory, though, we might identify a class of easy problems because they seem to have incremental solutions. If your drone transmissions are getting intercepted, use encryption! If you&#039;re worried about data loss, generate lots of backups to the cloud or to a mesh network! If you&#039;re worried about your credit card being stolen when you buy on Amazon, how about a government-generated user ID system? Or (somewhat more controversially), if your Air Traffic Control system is vulnerable, spend some money and update it - maybe making it more appliancized, maybe adding more points of human control.&lt;br /&gt;
&lt;br /&gt;
But that still leaves the hard problems that seem to need quantum solutions. How can we solve the attribution problem when the global network was fundamentally designed to be pretty  anonymous? How do we rectify the fact that the Internet carries both regular civilian communications and government transmissions? And how can we guarantee that hardware is secure when the only way to verify that it was built to spec is to take it apart? I&#039;m looking forward to talking more about both kinds of problems, and both kinds of solutions.&lt;br /&gt;
&lt;br /&gt;
== GNI ==&lt;br /&gt;
&lt;br /&gt;
Reuben: I think we should all congratulate ourselves on our prognostication skills.  A lot of our predictions were right on the money.  After reviewing my notes, I came away with a few main points.  It seems the GNI has had two main benefits for those involved.  First, it has helped companies establish processes for how they will handle sticky situations that arise in fields of free expression and privacy where previously those concerns went unrepresented or were dealt with an ad hoc scramble.  Secondly, GNI has facilitated relationships between companies and human rights organizations that allow the two sides to work together collaboratively to map out strategies and get more effective results.  &lt;br /&gt;
&lt;br /&gt;
While the panelists recognized the effectiveness of the GNI in at least certain situations, I was a bit surprised by the degree to which at least some participants seemed to welcome government involvement in order to force more attention on the activities of smaller companies who don&#039;t stand out the same way a Microsoft, Google, Yahoo, or CISCO might.&lt;br /&gt;
&lt;br /&gt;
Jason: I think that the discussion took a bit of steam out of the &amp;quot;Difficult&amp;quot; part of the &amp;quot;Difficult Problems&amp;quot; equation - at least with regard to why Cisco is not participating in GNI and how they make decisions that implicate human rights issues. Mark&#039;s explanation of Cisco&#039;s position was exceedingly compelling: to my mind, he left little doubt that they really do have a different sort of impact on human rights than companies higher up in the stack; that they face a vastly different competitive landscape and client base than other ICT companies; and that they have well-developed standards and principles going forward. From where I sit, they would be completely crazy to join the GNI - it&#039;d be all potential downside with no upside that I can tell, for either the company or for human rights. (Sadly, Cisco did not pay me to say all that, even if I just completely toed the company line.)&lt;/div&gt;</summary>
		<author><name>Jharrow</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_2_Thoughts&amp;diff=293</id>
		<title>Day 2 Thoughts</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_2_Thoughts&amp;diff=293"/>
		<updated>2010-01-06T19:23:47Z</updated>

		<summary type="html">&lt;p&gt;Jharrow: /* GNI */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
== Cybersecurity ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== GNI ==&lt;br /&gt;
&lt;br /&gt;
Reuben: I think we should all congratulate ourselves on our prognostication skills.  A lot of our predictions were right on the money.  After reviewing my notes, I came away with a few main points.  It seems the GNI has had two main benefits for those involved.  First, it has helped companies establish processes for how they will handle sticky situations that arise in fields of free expression and privacy where previously those concerns went unrepresented or were dealt with an ad hoc scramble.  Secondly, GNI has facilitated relationships between companies and human rights organizations that allow the two sides to work together collaboratively to map out strategies and get more effective results.  &lt;br /&gt;
&lt;br /&gt;
While the panelists recognized the effectiveness of the GNI in at least certain situations, I was a bit surprised by the degree to which at least some participants seemed to welcome government involvement in order to force more attention on the activities of smaller companies who don&#039;t stand out the same way a Microsoft, Google, Yahoo, or CISCO might.&lt;br /&gt;
&lt;br /&gt;
Jason: I think that the discussion took a bit of steam out of the &amp;quot;Difficult&amp;quot; part of the &amp;quot;Difficult Problems&amp;quot; equation - at least with regard to why Cisco is not participating in GNI and how they make decisions that implicate human rights issues. Mark&#039;s explanation of Cisco&#039;s position was exceedingly compelling: to my mind, he left little doubt that they really do have a different sort of impact on human rights than companies higher up in the stack; that they face a vastly different competitive landscape and client base than other ICT companies; and that they have well-developed standards and principles going forward. From where I sit, they would be completely crazy to join the GNI - it&#039;d be all potential downside with no upside that I can tell, for either the company or for human rights. (Sadly, Cisco did not pay me to say all that, even if I just completely toed the company line.)&lt;/div&gt;</summary>
		<author><name>Jharrow</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_1_Thoughts&amp;diff=290</id>
		<title>Day 1 Thoughts</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_1_Thoughts&amp;diff=290"/>
		<updated>2010-01-06T18:14:10Z</updated>

		<summary type="html">&lt;p&gt;Jharrow: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Tyler: I thought JZ&#039;s point about &amp;quot;half-assed&amp;quot; censorship was quite interesting. For example, I like the idea that Google created google.cn, while retaining an easy way for people in China to use a Chinese-language, uncensored google.com instead, as a way of convincing the Chinese government that it had taken steps to censor content that it had been ordered to censor but without actually preventing access to anything. A similar example of Microsoft censoring the titles of blogs but not their content was also given that I found interesting. I wonder if there are other, more subtle, behaviors that have been built into products that allow for the appearance of censorship without actually fully implementing the censorship?&lt;br /&gt;
: Jason: But notice that how effective this all is depends on what you think about how powerfully the &amp;quot;Principle of Bovinity&amp;quot; operates (amazingly, there appears to be no Wikipedia article on this topic - someone get on that! - but you can check out [http://www.cato-unbound.org/2009/05/11/lawrence-lessig/continuing-the-work-of-code/ this Lessig article] and scroll down to the second block quote). By this, I mean that if 99% of all users use Baidu or Google.cn without checking Google.com, isn&#039;t that more than enough control for the whole censorship project to accomplish its goal? Isn&#039;t &amp;quot;good enough&amp;quot; censorship really all the government is looking for? Those who believe in the strong operation of this principle might be highly skeptical of &amp;quot;work-around&amp;quot; solutions, even if they seem really easy to people like us. Here&#039;s Lessig in &#039;&#039;Code&#039;&#039; (quoted in that Cato link): &amp;quot;I think it is as likely that the majority of people would resist these small but efficient regulators of the Net as it is that cows would resist wire fences. This is who we are, and this is why these regulations work.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
Also interesting is the distinction between the two types of countries that may want to filter online content. The first type, like Saudi Arabia, can filter content as it comes into the country because its network topology is small and simple enough that each incoming server can be configured to support the government-ordered censorship. The second type, like China, has too large of a network to rely on an approach that is working in Saudi Arabia and must rely more heavily on the content servers/providers doing the filtering themselves. Are there steps, such as encrypting URLs to make keyword filtering more difficult, that could make filtering more difficult in either of the types of countries?&lt;/div&gt;</summary>
		<author><name>Jharrow</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cyberlaw_winter10/?title=User:Jharrow&amp;diff=254</id>
		<title>User:Jharrow</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cyberlaw_winter10/?title=User:Jharrow&amp;diff=254"/>
		<updated>2010-01-05T19:26:55Z</updated>

		<summary type="html">&lt;p&gt;Jharrow: New page: I&amp;#039;m a 2L at Harvard Law School, though I am reconsidering the wisdom of that decision with every day I spend in sunny California. You can follow me on twitter [http://twitter.com/jharrow21...&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;I&#039;m a 2L at Harvard Law School, though I am reconsidering the wisdom of that decision with every day I spend in sunny California. You can follow me on twitter [http://twitter.com/jharrow216 @jharrow216].&lt;/div&gt;</summary>
		<author><name>Jharrow</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_2_Predictions&amp;diff=252</id>
		<title>Day 2 Predictions</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cyberlaw_winter10/?title=Day_2_Predictions&amp;diff=252"/>
		<updated>2010-01-05T19:23:39Z</updated>

		<summary type="html">&lt;p&gt;Jharrow: /* Mark */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Mark =&lt;br /&gt;
&lt;br /&gt;
Sheel: Cisco, with its involvement in China&#039;s Golden Shield Project and $16 Billion investment (http://www.socialfunds.com/news/article.cgi/2825.html), doesn&#039;t want to have to deal with issues of human rights that might diminish ROI. Notable quote from article and 2008 testimony: Chandler said, &amp;quot;Cisco does not customize, or develop specialized or unique filtering capabilities, in order to enable different regimes to block access to information.&amp;quot; My guess: Mark Chandler will affirm this statement tomorrow, but the real reason is that following the GNI principles would be a poor business decision and CISCO isn&#039;t willing to make any sacrifice.&lt;br /&gt;
: Elisabeth: we might push back on the idea that this would be a poor business decision, and solicit Cosson and Hope&#039;s opinions.  Yahoo and Google have faced real backlash for their actions, and GNI serves as something of a safety net against that backlash.  We could also ask Chandler if he can imagine how GNI could be structured such that it would be worthwhile for Cisco to join--it would be interesting to see if what he says matches up with what Cosson says GNI needs to do to recruit new members.&lt;br /&gt;
:: Andrew: I doubt Chandler would be cynical (frank?) enough to respond this way, but Cisco may be shielded from the kind of &amp;quot;PR risks&amp;quot; that Yahoo/Google/Microsoft face, since their products and services reside below the content layer and are less intuitively understandable to the general public. Along these lines, I hope to hear some discussion about the sources of contention between stakeholders at different architectural layers. How do differences in the type of actions governments request from these companies translate to materially different policy preferences, given the extreme broadness of the principles at issue? &lt;br /&gt;
:: Hector: I agree with Andrew and wonder whether Cisco will go to lengths to emphasize the hardware-side of its products/services. This may be a more palatable version of JZ&#039;s &amp;quot;gun&#039;s don&#039;t kill people&amp;quot; framing: &amp;quot;Look, we provide hardware and the software interfaces that are infinitely customizable.&amp;quot; Such an argument works only to the extent that the products/services are general-use (generative?) and the extent that CISCO is &#039;&#039;&#039;truly&#039;&#039;&#039; removed from any immoral end-use.&lt;br /&gt;
: Jason: I doubt that he will emphasize ROI and the need to make money to a group like ours - or, at least he won&#039;t explicitly mention his company&#039;s desire to make billions of dollars. Instead, I suspect that Mark will emphasize the need for more Internet infrastructure in developing countries, and the uncertain effect of the GNI in terms of continuing to do business everywhere. He would be right about that need - see, for instance, the Internet density map [http://www.chrisharrison.net/projects/InternetMap/medium/worlddotblack.jpg here]. So he can ask us rhetorically, &amp;quot;What is Cisco supposed to do? Don&#039;t you cyberlaw students want people in China and Southeast Asia and the Middle East and Africa to get online, too? If so, those countries need our hardware - and we can&#039;t choose who runs their governments!&amp;quot; And you know what? If he says this, he will have a very, very good point.&lt;br /&gt;
&lt;br /&gt;
Daniel: I believe Chandler will provide his professional - and hopefully personal - account on the role CISCO plays in [facilitating / enabling / providing neutral tools] to allow for &amp;quot;different regimes&amp;quot; to control their nationals&#039; internet experience. Cosson and Hope will probably dedicate more time to in depth discussion of two issues: involvement of industry actors other than the GNI founding members and the types of incentives that are needed for that, including legal alternatives and public exposure of &amp;quot;do some evil&amp;quot; firms. Also, given that we will not have representatives from Google and Yahoo, these companies are likely to figure prominently in the examples of events, actions and concessions to be avoided.&lt;br /&gt;
&lt;br /&gt;
Sanford Lewis: I predict that Mr. Chandler will not discuss  in very much depth the extent to which external stakeholder and stockholder pressure has shaped company policy, unless he is prompted by student questions to  discuss this.&lt;br /&gt;
&lt;br /&gt;
Lien: The GNI principles are so general and an &amp;quot;implementation / repetition&amp;quot; of international standards. If a certain company (for whatever reason) does not want to join the GNI, this company still has to comply with these standards. To play the devil&#039;s advocate, does joining the GNI change anything in reality or is it just a good thing to join because of the company&#039;s image and reputation? Furthermore, the concept of the GNI (sort of self- regulation) is a very American concept. European companies are not very familiar with the kind of approach. The GNI might be a good starting point for a company to obey the certain principles. However, the privacy principles are so broadly written, that if a company would obey to these principles, it would still not be comply with European Privacy legislation. Why would a European company then join the initiative and do all the efforts (e.g. audit, ...), knowing that it would still not comply with European legislation?&lt;br /&gt;
: Elisabeth:  I also wonder how true it is that these are &amp;quot;international&amp;quot; standards, rather than American or American/European standards.&lt;br /&gt;
&lt;br /&gt;
= Dunstan =&lt;br /&gt;
Tyler: I believe Dunstan will try and draw a distinction between situations involving two types of countries. The first type is countries with laws in accordance with GNI principles but that are not enforced or poorly enforced. The second type is countries with laws that on their face are violative of GNI principles. I hope Dunstan will discuss strategies that corporations should use for situations that arise involving both types of countries and the different approaches that GNI stakeholders can collectively take to preemptively forestall problems in each of the two types of countries.&lt;br /&gt;
: Daniel: It would be great if we further explored the (blurring) division between these two country-types. Was Google&#039;s first move in the negotiation with Turkey - accepting to block videos insulting AtatÃ¼rk, but only within the country&#039;s limits - OK under the GNI principles? How much can a country legitimately curb freedom of speech, according to the GNI framework? IMO, its diplomatic language allows for an &amp;quot;American&amp;quot; interpretation, but also for an &amp;quot;European&amp;quot; one and perhaps others even more restrictive.&lt;br /&gt;
&lt;br /&gt;
= Chuck =&lt;br /&gt;
&lt;br /&gt;
Tyler: I expect Chuck to express frustration that more corporations have not signed up for GNI and identify some specific reasons why he thinks GNI has so far been unable to recruit any additional corporations from the initial roster of three (Yahoo!, Google, Microsoft). I also hope that Chuck discusses what preparations Microsoft has made to allow GNI auditors access the sensitive Microsoft information.&lt;/div&gt;</summary>
		<author><name>Jharrow</name></author>
	</entry>
</feed>