Blockchain technology has been heralded as the cure for all that ails us, but is it really? In this frank discussion, we'll look at what the Internet of Information has managed to get right and wrong as it evolved into ubiquitous substrate for big business and human connectivity, and why we might need to approach things differently to build an Internet of Value - inclusive of both cryptocurrency and distributed data - that supports tomorrow's global economies, sovereign governments, and individual human rights.
Decentralized, Private, Open, Secure: Building a More Ethical Internet






















































Auto-generated transcript - may contain errors. Tap a timestamp to jump the video.
Hi. How are you? How was lunch? Good? Okay. Yay. Great. So I am going to talk, I guess, about an Internet of Value, but more as a derivative kind of a thing. When I was talking to Brian about what we should discuss, I kept coming back around to this idea of what does a next generation Internet look like, and why do we care?
So I'm not really pitching what Clover does today. I'm sure you can Google it if you care. But I'm talking a little bit about why I care about this space, and why we should be looking at some of the challenges that we have with the existing internet.
So let's hope that the PDF actually advances, because it is a PDF. Okay, oh, hey, that's me. So, that's me in front of a computer. If you can recognize the hardware, then you're dating yourself, or the acid wash shorts, I guess. But the point is, I've been on the internet for some period of time and caring about these things.
And I think that I've always known that our technical choices have human impact, and I don't really understand why we spend so little time talking about those things. So this diagram is actually from a site called Indi, I n d dot I e, and I've just, I kind of fell in love with the diagram a couple years ago.
They have an ethical design manifesto, and it's about how to build ethical applications, and those are applications that support human rights, human effort, and human experience. And if you read the description down there of decentralized, private, open, interoperable, accessible, secure, and sustainable as a foundation for these kind of applications, well, it starts to sound a lot like a blockchain.
And I did challenge myself on Twitter to not say that B word more than three times in this entire presentation. So you can count, otherwise I have to video record myself doing shots for Twitter. So, okay. So, let's see what we can do.
So, decentralized. Let's talk about some of these words. So, decentralized simply means lack of a central administrative authority. I'm not sure why these days, decentralized somehow means angelic and pure. It's not. It's simply the lack of a central authority. Distributed systems, from which a lot of today's cryptocurrency networks are derived, can be centralized.
You can have a centralized distributed database. That's fine. It simply means you have a central order maker within the network. So if you use something like Google Sheets, for example, that is distributed data, it's a distributed application, but it has a centralized entity that tells you what happened before what and whose edit reigns supreme, being Google.
Something that is private is free from intrusion into confidential matters. It doesn't necessarily mean that no one can ever see it, it means that the ability to see it should be consensual. When we talk about radical transparency, radical transparency works for a very, very small percentage of the people on this planet, and they're generally the people that are already in power.
So, if you look at who wants you to kind of give up your privacy, you can often identify who has power within a system. And as a corollary to that, anonymous systems. A lot of us don't have an expectation of anonymity, and somehow this has become this dirty word of, Oh, you want to be anonymous, you must be doing something wrong.
But in general, we are used to having a sense of anonymity within a crowd, And more and more these days, that is kind of a disappearing concept. Whether you're talking about walking down the street and having your face be recognized out of a crowd, or that every single thing you do is being tracked by some sort of fingerprint, probably through a cookie back to Facebook, but also through literal actual fingerprinting of various devices that are connecting to each other that, without your consent or without your knowledge,
are de anonymizing you in your daily activities. And systems that are open, and we're talking about both open access and open source. So that means that there's a low barrier to entry. People often talk about cryptocurrency systems being open access, you can download the software and it's free to join, and no one can stop you.
Which is true, as long as you have a home computer that has a certain amount of GPU power if you want to be mining, and that you're capable of downloading the software and extracting it and running it, and all of a sudden you realize that there are a whole number of barriers to entry for these systems that are both monetary and technical, and generally that you live somewhere where other people are telling you that this is a thing you should be doing with your time.
Secure, this was the best definition I could come up with, resistant to undesired outcomes. Security is very important, and often at the opposite end, or as a counterpoint to something that's usable. So if you take your computer and you pull it offline, and you put it in a box in a safe, it's completely secure.
But you can no longer do anything with it. Historically, people have always chosen this kind of convenience over the security, and we're starting to, or we have been reaping the benefits, or lack thereof, of that for some time. So how does this come together in these sorts of systems?
As we start to see things like autonomous vehicles that clearly have the ability to save people but also cause harm, I think that people are scrambling to build a system of ethics. So, this is a quote from Joey Ito, who I had the pleasure of meeting at MIT a couple years ago, but I kind of took issue with the way that the New York Times presented the quote within an article about artificial intelligence, as though all of a sudden people are realizing that perhaps we should have some sort of ethics around our
technical systems, that we don't need to wait for the robot overlords, This is in some distant future where someday our choices will matter. The choices that we make today matter. So, for example, data collection. You should ask yourself, if you're an application designer, why are you actually collecting that GPS data?
And are you just kind of hoovering up data to have it, to hope that you might be able to do something useful with it later? As GDPR affects people here, people in the US are starting to think about that more, but what used to be kind of considered digital gold in data is now starting to look a lot more like oil, and you need to be very, very careful with how you're using it.
And then everything around that data that you've collected, how are you managing it? So what's the user experience? For example, when someone signs up to your website, are you asking them what their gender is? If so, what choices are you offering, and what are you going to do to the user experience that actually incorporates that data?
For default settings, if you're changing the the way that privacy operates within your application, do you notify people? Do you make them opt in? Do they opt out? Ninety nine percent of people don't change defaults. Are you actually using that because you hope they don't change the default?
And if so, is that an ethical choice that you're making as an application designer? Alright, show of hands, who in here has had some sort of formalized computer science training at some point? Let the record show that's almost everybody. Okay, no, put your hands back up. Okay.
Now, keep your hands up if you ever had some sort of explicit training that mentioned any of those things that I said as being technical ethics that you should consider when you are doing application development. Okay, so that's six people. Okay, thank you.
So why is that? How did we get here? So that's ARPANET in nineteen sixty nine. This is where the internet came from. I'm sure you all kind of remember this from your computer history days, right? So ARPANET, being the advanced research projects from the DOD in the US, the Department of Defense, now part of DARPA, which continues to do cyber grand challenges and other kind of internet research, this was created out of funding from the missile defense budget.
So here's ARPANET in nineteen seventy. So even the early networked computers were not actually created so we could share pictures of cats, right? These were actually defense systems. There's nineteen seventy three, you can see more things coming online. The first international connection out to Norsair, that was the Norwegian Geological Research Institute.
It's not because we cared so much about the weather, it's because we were trying to determine whether or not there had been nuclear detonations around the world. There's ARPANET in nineteen eighty two. This is more things coming online between 'eighty two and 'eighty four, switched over to TCPIP, you can call that the birth of the actual internet as that protocol became standardized.
And then here's an example of Usenet traffic in nineteen ninety three, And, you know, is it decentralized? Is it magically pure because we didn't have a whole lot of ISPs yet? Well, it seems to be kind of centralized around people who hold similar political beliefs.
We really take for granted that a lot of the Internet as we know it was created in the West, and now as a lot of these decentralized cryptocurrency kind of systems come around, we have those same questions re coming up, and it seems kind of like there's this new generation that hasn't necessarily heard of the crypto wars of the '90s, and doesn't necessarily understand that there's really a lot of precedent for these systems being used as literally a theater of war, and the choices that we are making,
and the reasons that Russia, Venezuela, and China are the three countries that have released their own cryptocurrencies is not actually a coincidence. So, ninety four, you had internet backbone privatization, and, you know, here we are. So, who's actually hearing the sound of a dial up modem in the back of their head right now?
Okay. So, this is probably the way that most people got on line, initially, if you weren't, say, a computer nerd. This was the mass adoption phase. Why? Because it was usable. It's entirely a usability based argument as a product, but it was a massive centralizing force.
You probably remember joking around with people that said, My dad thinks that the internet is AOL. And it's not. You have to actually get outside the AOL walled garden to go out to the real internet, where all the fun things are happening. God, I'm so glad that we learned from that and would never ever do that again.
Now we have Facebook, which everyone thinks is the Internet, right? And so we're like, here, it's so easy to share, come on over here. And now, here we are. So we're with these kind of walled gardens of content, and there's been a push, for example, as Google, retired Google Reader, we've seen a shift away from RSS feeds as being this very open way to share things, to content providers like Google and Facebook vastly monopolizing the kind of distribution.
Interestingly, the shift to mobile first design, which is supposed to be a leap frog technology for people that didn't have desktop computers, has made native application development for mobile a move away from using open internet standards. So XMPP that you used to be able to use to hook together various chat clients, you can't really use for mobile push notifications, and now what do you have on your phone?
Well, I have well, I don't have Facebook Messenger, but people do. Signal, you have Telegram, you have WhatsApp, you have Twitter DMs, you've got all of these different things, and it's not actually able to be aggregated in an open way. And so, where are we?
This is from an incognito window, right? So this is not my personal search profile. This is what normal people get if you search. So I don't know why Google knows you're pregnant is up there, but that's terrifying. Okay. And of course, the privacy reminder from Google, helpfully at the bottom for me to just let me know what's happening there.
So, privacy is easy. Just use a bunch of all of these things in connection, accurately, across all of your various devices, all of the time, and you'll be completely fine. Then, you know, you can have a private browsing experience. How many people here use at least one of these things?
I would hope it's a lot of people. Okay, how many use more than two of them? Okay, We're down to like six hands again. Okay. So I would say though that if you're not familiar with Let's Encrypt, everybody in the room uses that.
And you use it because it happens in the back end, it's like a server side thing, that helps bring a large portion of the internet over to using HTTPS, so that you have encrypted traffic places. And Let's Encrypt is a fantastic example of a security first kind of design change that happened for free in the background that helps people that don't know that it exists.
So as application designers especially, you can think about what kind of changes you can make that will flow through good decisions and good processes and good workflows to people that don't necessarily know that they're losing something if you were to do it a different way.
Or as my mom used to define ethics, ethics are what you would do even if you know in a million years you wouldn't get caught if you did something else. Thanks, mom. So there are actually a lot of people that care about the open Internet and digital freedom, and I hope that you support a lot of them.
But so, sure, it sounds like freedom is ethical. These are all the good guys, right? So obviously, why aren't we all doing this? Everyone must agree. But maybe not so much. So go back to thinking about the kind of ARPANET example, and that this is actually a defense network.
So as our internet traffic is being bounced around a lot, some of it is encrypted, some of it is not, now we have devices. If you have an iPhone, you have a secure enclave, so we're having hardware based security now as well. If you didn't hear about this last year, this cartoon came out after there was a shooting in San Bernardino, California, and the iPhone, the criminal's iPhone, shooter's iPhone, was found after the fact, and the FBI went to Apple and said, cool, can you unlock this for us?
And Apple said, no, we don't actually have a backdoor into that. We don't have a way to subvert the user's privacy. We don't have their private keys. And FBI said, Well, but you could, so why don't you issue a patch and fix that?
And that is something that crops up over and over and has since the '90s, is the mandate or the possibility of a mandate at the state level to use intentionally weakened cryptography. But that has vast implications for everyone who's completely going to continue to use the strong cryptography elsewhere, but is actually the bad guys.
So you probably don't want to be the only one in the room who is using weak cryptography, but politicians don't really seem to grasp that. They think that if you can't backdoor something, that there's no other way to get it. Where in practice, this is one of my favorite XKCDs here, so this is the nerd saying, oh, but I've encrypted everything, and you can still whack someone overhead and then get them to give you your private keys.
I would say that the cryptocurrency or distributed ledger analogy of this is like the land titles thing. You might have heard that putting all the land titles on, I'll say blockchain, that's my second use, on a blockchain is the way to solve when a hostile regime comes in and takes over and says, You don't own this land anymore, and you say, But I have my paper that says I own the land title, and you say, Well, we just don't recognize that.
That if you had put all this on the blockchain, then we'll say it's the same use. That therefore one use case that it would have already been traceable, right? However, I would postulate that it's actually the people with the tanks that come and sit them on the land that will tell you what the truth of that situation is.
So we need to be careful when trying to design technical solutions to these kinds of human problems. So, other problem. Sometimes important stuff disappears from the web. This might be a great reason that you want to use some sort of immutable, decentralized system to store all the information in the world.
And yeah, sometimes stuff disappears, and it's stuff that you're like, Oh, I really wanted to read that blog post again. Or maybe it's something where, say, a news agency is sued into oblivion, and everything they've ever written disappears from the web, as happened with Gothamist last year in the US.
Or maybe it's something that was government documents, like, for example, when our administration changed, and all of a sudden, EPA from Environmental Protection Agency research started disappearing from the web. So, how do you keep information from disappearing? Well, uh-oh, it turns out the exact same things that you might use to create a censorship resistant system to keep information from disappearing has the unlikely side effect, or unfortunate side effect, of keeping a bunch of other stuff you really wish would disappear from the internet, like, say, revenge porn,
from ever going away. And so you get a constant tension between people who say, How am I supposed to be able to remove this? With people who say, But from a justice standpoint, maybe we need this other stuff to not be removable. And so, when you look at legislation, which is always trailing technology, but GDPR specifically, sounds like you can go to a centralized entity who controls all the content in the world and say, You should be able to remove this.
If you're a technologist, you realize all of this could already be mirrored five thousand times, and therefore you can never truly remove something from the internet, but the idea that someone is culpable and that there is this ultimate source of ownership kind of persists.
So, here's another challenge. Information wants to be free, right? We all want to be able to learn everything. Hopefully here we mean free like free speech and not like free beer, right? But privacy is a human right. So, do all of our tax returns deserve to be free?
Do our medical records deserve to be free? Maybe not. So there's good arguments on both sides. Here, I am trying to kind of call out or define a little bit about what does centralization mean to you. So is centralization good or bad, or maybe just a concept?
So Bank of America, obviously, is a centralized financial institution. The diagram over here, this is as of two days ago, the location of all of the Bitcoin nodes that were live. Now, again, it's kind of centralized around people who believe the same things politically, or have access to computers, because forty years ago, people who believed the same thing politically funded a bunch of defence mechanisms.
But these people all believe that they're completely independent, and making their own choices, and that anyone that wants to participate in a cryptocurrency network can. So, also, I think it looks besides it being surprisingly centralized geographically, there's actually just not as much of it as one would think.
I think there's this prevailing myth that these cryptocurrency systems are decentralized in that they're all over the world and spread equally, and there are millions and millions of participants, but there's less than ten thousand nodes there. So, back when I was designing distributed ledger networks for corporations, I would say that any kind of sufficiently adopted, permissioned distributed ledger network will eventually start to inherit all of the security principles of a public blockchain.
That was my third one. The reason for that is that a supply chain might have a million participants in it. So if you have tons and tons of these nodes coming together, at some point, the trust between the actors there that you started with, this is a trusted distributed corporate network, is going to degrade, and that we've been building corporate to corporate kind of generation systems over here, and we're building consumer to consumer cryptocurrency networks over here, and then imagining some sort of new generation Internet of
value that's going to help people is going to come out of that, Seems like a bit of a pipe dream. Here's another one. So centralization from the last slide, bad. Okay, so here's some guns. So obviously, I'm American, so there's guns involved in my presentation.
So over here we have a gun store, which is a centralized place which we attempt to do a background check before guns are sold to people, handguns. Over here on the right, you have a three d printed gun. Now that is not what the actual three d printed guns look like, That's a computer rendering of a three d printed gun.
But Defense Distributed is an actual organization that wants to make sure that everyone around the world has access to the schematics to be able to hook up a MakerBot to three d print parts to put together a gun. Becomes a decentralized thing. So I'm not saying that either one of these things is necessarily good or bad, I'm asking you what your ethical reaction is to these things.
If you believe in free speech and you believe in dissemination of sorts of computer schematics as a free speech right, how do you feel about the dissemination of this kind of information? I don't know. Well, it turns out, to go back to that kind of earlier defense systems things, that we've actually confronted a lot of these things before.
Now handguns might be different because they are not regulated under Did I put ITAR up here? Oh yeah, okay. So those are the arms restrictions controls on military weapons, which handguns are not necessarily considered. But under the Vassner agreement over there in the middle, this is an agreement that controls dual use technologies, so something like nuclear energy versus nuclear weapons, or chemical science versus chemical weapons.
Well, was a period in the 90s and in the 2000s when strong cryptography was considered a munition, was not allowed to be exported. That's why there was RSA, that's an RSA algorithm actually printed on a shirt that says this t shirt is munitions and controlled, cannot leave the United States.
It was very popular at hacker conferences fifteen or twenty years ago. So we've seen these things before, and we need to consider, as we look at things like three d printed guns, which are something because people can put it in their hands, they have a different kind of ethical reaction than they do to something like, say, a cryptographic algorithm, but these are the things that underpin the sorts of networks that we're building here.
So, when you look at a system like Bitcoin or like Ethereum, and they use specific types of cryptography, and that cryptography is open, and it was developed in the West, whether you're talking about Bernstein crypto or Sec256 PK1, whatever, all of these, these are things that are open source and that are known.
If you look at RSA or NIST suite, those were developed in the West. If you look at something like Ghost Protocols that were not, or if you look at the Chinese Russian, or if you look at the Chinese cryptographic suites, these things do not interoperate with each other.
And so when you get countries that want to go and do, say, sovereign identity programs, which we just talked about on the panel for a second, for free, where they will go and they'll go into an emerging economy, and they'll say, You know what, why don't I just build your identity systems for you?
We're going to put ten million dollars into this philanthropic project, and we're going to help you come online and use our distributed system that's built using our cryptographic suite, which may or may not be backdoored by our government, and each of those three believes that the other has backdoored each of those things.
So it's all equal there. What is the downstream implication to the security and the privacy of those people that really don't have a say in what technology they use. So, this is a quote from one of my favorite folk singers. So, essentially, every tool is a weapon if you hold it right.
It's not necessarily the corollary that if all you have is a hammer, every problem looks like a nail. It's more that all of these things become dual use. Dual use is a very kind of it sounds like a very neutral term, but that's the point.
These things technology is neutral. It is not necessarily possible for us to create a network that enforces an ethical standard. Certainly, if a lot of these systems were not developed in a somewhat individualistic, capitalist society that promotes some sort of democracy and liberty as fundamentals, but in a society that maybe believes that the social collective is more important, or that privacy is not something that people necessarily need to care about.
The systems that you create might be different, but neither is particularly ethical or unethical. There are simply tools that allow you to do something or to not do something. And so historically, we seem to have found that by advocating for the most open version of those things allows you to make a choice later on, and to fall back, and to change your mind, and to People can choose what your application that you design does, but if you, say, force every bit of your application to phone home all
the time and give everybody's GPS data to one central organisation, you've taken away the choice of informed consent from your user base. And those kind of micro choices are made thousands of times by every application, and collectively, we end up where we are today with this kind of surveillance capitalism.
So, these are trade offs. I stole this list from a series of tweets by Alex Stamos, who's the CISO of Facebook now. They're kind of arguing on Twitter yesterday, and so I grabbed these. So these are the trade offs that, not just at Facebook, but at any kind of social networking platform is concerned with.
And it's not just social networking even, but do you let people maintain their privacy, and if so, how do you kick off bad actors, or how do you disincentivize hate speech, for example? If you want people to be anonymous, for example, real name policies really tend to hurt marginalized populations, people whose identity in their daily life does not match their legal identity for any number of reasons.
How do you not enforce a real name policy, but still prevent anonymous sock puppet sort of abuse? The trade off between content owners or owners of platforms being responsible for the content there. So we just had a ruling in the US called Fosta Sesta that now makes platforms responsible for any posts which advocate or allow for sex work on their platform in an effort to prevent human trafficking, they say.
But what happens? Well, Craigslist ads shut down, Backpages shut down, and because of that, now it's actually harder to find trafficked victims, and you're seeing legitimate sex workers pushed back into less good relationships that they had previously. And on and on and down it goes, right?
So there's a trade off on each of these sides. So, here are some promising tools, though. Every one of them can be used for good, for bad. I wouldn't say it's good or bad in that it's so black and white, but here are some things which people are saying might change the balance of the game we have today.
So mesh networking, if you heard James Turing talking earlier about how to bring internet to populations on the African continent right now, being able to connect mobile devices without the need for satellites, which are very, very expensive, but rather creating very headless mesh networked organizations across phones could be super cool.
This is a real technology people are actually using. The idea of mesh networking has been around for a long time, but it's just now becoming scalable and usable across mobile devices. And not just for bringing those populations online, but also for disaster recovery.
You can use it if they're, like, let's say there's a hurricane and the network gets knocked out, you can all talk to each other. So that's one piece of the pie, and you can run different kinds of applications on top of it. Zero knowledge proofs.
Has anybody here ever heard of zero knowledge proofs? Okay. Again, smattering of hands. Okay. So this is some really cool cryptographic research as to how you can have something where both parties can agree that something really happened, but neither of them have to disclose the inputs to that in a very brand new way.
We don't have time to talk about it, because there's a ton of math there. One example might be that you could say, Go get a car, by saying, I'm going to tell you what my income was, but you just need to know if my income was over sixty thousand dollars You don't need to know how much over it was.
You can create a proof that discloses minimal information. So enforcing this principle of least privilege, or principle of least authority, which is a principle from computer science kind of systems design, we could bring that more into how we design applications. And then, let's say that you're building or buying and selling CryptoKitties, which is what you do these days, that's what the kids are doing, I hear.
They're like digital Pokemon, whatever. So you could disclose one trait from your CryptoKitty genome without disclosing another, and then buy and sell these things. You could also do that with financial products. Interesting, new classes of financial products. Selective disclosure is a tool that especially zero knowledge proofs might allow you to do.
So you can choose what you're disclosing, again, that idea of consent, an informed consent. So you might have many, many pieces of your identity on a key chain that you carry with you, and you can then say, I need to tell you, because I'm going to rent an apartment from you, here's what my name is, and you can see that this is cryptographically verified from a source that you trust, and you can see that my income is over x range, and you can see that I have a real job from a top tier institution,
but I don't need to tell you what institution that is. That could be really cool. Does that let's talk about the weaponized side. Does that mean that when I buy a movie ticket, that all of a sudden someone needs to know if my birthday came from an actual citizenship document?
We don't know. Does that mean that you can now turn very neutral kind of everyday occurrences into checkpoints or border controls? Maybe. So we don't have any standards right now as ways to enforce that, and we need to have people that are working on these kinds of things.
So maybe that's you. Self sovereign identity, that's the kind of identity on a key chain right now. So if you had everything about you, this kind of detritus of your life as you go through, like let's say your diploma is there, your marriage certificate is there, your Uber driver score is there, you can now you can essentially monetize that data over time.
And I know that it sounds crazy, but people who are already, say, monetizing their Instagram feed will probably figure out how to make this work. So if you've got your human genome and you want to rent it out instead of giving it away for free to 23andMe, there's no reason that you shouldn't be able to license that information.
Cryptoeconomics, so there you go. This is an important piece of how we can interoperate or interact with each other in a way where you don't have to sign a fancy legal agreement and get the bank involved every time you wanna do one of these things.
So having this next generation sharing economy that has a lot of agency on you requires that you can kind of be your own bank, but not necessarily take it to the degree of having to truly be your own bank all the time for all of your funds and all of your life.
Maybe having just a little piece of these micro transactions would be enough. Oh, most ICOs are stupid. Okay. And I'm essentially gonna be out of time, so just to wrap up, these are all the things that we've talked about, and this is why everybody says that blockchains, I think that was my third, maybe my fourth time, we'll give Twitter one shot.
Okay, so that's why people think that this is the answer to everything, but it's not. It's just something that you need to know about all those things to effectively use that thing. That is the opposite of it being useful for all of these kinds of things.
So decentralized applications, we can skip past. And finally, this is the last tool in your toolbox. Compassion. So here's a quote from Enron, right? Demanding our employees prove that they were smarter than everyone else inadvertently contributed to a narcissistic culture where employees were both incredibly smug and driven by deep insecurity to keep showing it off.
Sounds a lot like tech. I just was really struck by this. So, there is no such thing as an ethical technical system. People have ethics. And so, it's our choices that will have impact the other way around, and therefore, it's your responsibility. Thank you.