Earlier quoted context omitted.
Any estimate on EC2 costs using this moderately?
You would be better of putting it on a Digital Ocean and then create / destroy a droplet when you need it. It is what I do and my cost is like $1.50 per month (as opposed to $5).
VPNs are not the solution to a policy problem
211–220 of 228 posts
Re: VPNs are not the solution to a policy problem
#212https://news.ycombinator.com/item?id=13982966
* False dichotomy: that the solution lies in only one sphere. (Lessig, Code). This is lightly moderated, but resurfaces at several later points in the argument.
* Personal responsibility. Check. Never mind that the source article states concisely and specifically why this doesn't work or scale.
* Hybrid system. Or as I prefer, the worst of both worlds. In the healthcare example, a guarantee of emergency room services is posited as a sufficient mitigation for mandating individual responsibility in all other areas. Disregarding the fact beneficial health outcomes comes from public or preventive measures, not acute (read: late, expensive, heroic measures) interventions:
"In all, 86 per cent of the increased life expectancy was due to decreases in infectious diseases. And the bulk of the decline in infectious disease deaths occurred prior to the age of antibiotics. Less than 4 per cent of the total improvement in life expectancy since 1700s can be credited to twentieth-century advances in medical care."
― Laurie Garrett, Betrayal of Trust: The Collapse of Global Public Health
* As with all good Techno-Libertarians, nikcub "personally believe[s] in user responsibility". Despite some 50+ years of experience that user responsibility for security simply does not work or scale.
Nikcub continues with specifics:
* Universality of policy. Which seems to boil down to "since every jurisdiction cannot offer the same high levels of protection, no jurisdiction should". What ever happened to the concept of a competitive marketplace for ideas, including legal and moral frameworks? Isn't the very idea of liberal democracy that its principles, premises, and protections are so manifestly self evident that all people everywhere would want them? (And hence: why it's such a major pain in the ass of tinpot despots everywhere.)
* Some governments are bad ... so no governments can be trusted. Again: a slope so slippery nikcub loses his footing instantly. We can apply the same argument to ... anything. Including his proposed technological solutions: Software is a major party in privacy violations and is conflicted (and buggy), so it cannot be expected to behave in the interest of users. In government as with software, the proper response to buggy implementations is to fix the bugs, not burn the house down and abandon the domain completely.
* Government trust. Where do I even start (the concept and questions of trust are ... a whole 'nother essay). If liberal democratic government, the agent and agency* of The People, cannot be trusted, then what can?* Private, self-interested business? Which, I'll hasten to add, has landed us in the present kettle of fish? If you're finding that your government (or parts of it) aren't trustworthy, then you have two problems. But the one doesn't invalidate proper approaches to the other, and fixing the problem of government trust gives you an exceptionally powerful tool to apply in remedying privacy and other policy failures. Say, such as single-payer, universal, socialised medicine.
* Tech solutions that are universal ... are called policy. And, to add to that, a primary reason for approaching such policies through government is that governments have the clout and scale to make policies stick. Keep in mind that this need not be at national or international scales. Policies at the sub-national scale -- say, Northern Ireland or Scotland within the UK, or California or New York within the United States, could have major impacts. Given the option of adopting multiple and conflicting regulatory standards, or a unified and coordinated standard, companies will often prefer the latter. The case of US EPA and California EPA emissions standards would be an excellent study in same.
* Good policy is hard work. Yes, well, hard problems are hard. This doesn't make them not worth pursuing. And remedying the specific problems highlighted would be a key goal of any privacy regulatory overhaul.
* Penalties are small. Well, duh: embiggen them. I thought yuuuuge!!! was in now, anyways....
* On information disclosure: yes, it's very hard to un-leak data. On the other hand, comprehensive and pervasive regulations against the storing or transmission of personal data, stiff penalties for doing so, and sufficient rewards for reporting on such violations, will tremendously decrease the incentives for doing so. Given that the value of vast troves of personal information to firms such as Facebook is ... roughly $12/year per person, those penalties need not be tremendous, though they do need to be sufficient given scales of detection. This isn't dissimilar to present approaches against counterfeiting of money or goods: the fundamental capability to violate norms exists, but with appropriate penalties, and incentives, against transacting in such money or goods, it can generally be tamped down to an acceptable level. The more so if technology and other means are applied in concert with policy.
The argument continues spewing the additional canards of perfect worlds (no policy world is perfect, at best it is sufficient), sole reliance, and of mis-casting the argument as warning people away from VPNs (it doesn't, it merely points out that VPNs alone are grossly insufficient).
And for the capper, we have free-market it harder. As if it wasn't free-market interests, and failures, which haven't landed us precisely in the present situation.
Re: VPNs are not the solution to a policy problem
#213Earlier quoted context omitted.
Well, pastebinning communication of a politician (or better - their kid) seems like such an effective idea, I wonder why this doesn't seem to happen? Is there a strong roadblock somewhere there? It's not like most politicians and their staff know much about Internet security.
Let's leave their kids out of this.
Re: VPNs are not the solution to a policy problem
#214Earlier quoted context omitted.
Data you release can never be recovered. Even if we were to chuck out the entire House and reverse this change in 2018, VPNs would still be a key part of the solution. It would only take one medical search sold to insurers (as a random example) to seriously affect you, so I agree that downplaying technical defenses is unreasonable.
You can make holding and using that data highly intractable. If there are blisteringly strong penalties to holding and trading in personal data, the incentives to do so will largely disappear. Unfortunately, statutory regimes, particularly in the United States, seem to be going in the opposite direction. With the ability to seek out and purge disclosed data, at least some of the damage can be mitigated. Considering t…
At least when thinking about individual defenses, I tend to treat the regulatory landscape as a lost cause - currently I'm just hoping that privacy tools won't be actively outlawed.
Re: VPNs are not the solution to a policy problem
#215Earlier quoted context omitted.
We live in a world where breaking and entering is possible, and the police may only come after the fact, and might not come at all — it is everyone's personal responsibility to defend his home. Likewise, we live in a world where violating one's privacy is possible, which means it is probable, and thus it is everyone's personal responsibility to defend his privacy.
What do you think would have more of an impact on the security of your home: repealing the laws against breaking & entering, or removing the lock from your door? It's naive to think of oneself as strong enough to self-protecting. I know there's a certain appeal in the lone wolf myth that speaks to the (mostly male) psyche. But never in the history of mankind has it been the winning strategy to be strong and independe…
Honestly, the latter. I don't believe laws prevent thieves from breaking in, nor do they keep honest people honest. I don't really buy the deterrent theory of law in general, anyway: law exists to punish in a civil and orderly fashion, not to deter.
Re: VPNs are not the solution to a policy problem
#216Earlier quoted context omitted.
I really don't understand this line of logic on fundamental rights. If you're referring to the UDHR, it's a piece of paper put together by Eleanor Roosevelt a little over half a century ago. It's a human document of arbitrary concepts put together by people who believed enforcing those would improve the world in aggregate. The idea of basing our sense of right on what is law, rather than basing the laws we write on o…
Re your final sentence, there's a possible third option (though your second has merits): coming up with both rules (law) and guidance (rights, ethics, morality) based on what improves the overall common weal. Another archaic concept, I fear, most days.
In my mind:
ethics = definition of what improves the common weal
law (should)= enforcement of said ethics
Re: VPNs are not the solution to a policy problem
#217Earlier quoted context omitted.
You can make holding and using that data highly intractable. If there are blisteringly strong penalties to holding and trading in personal data, the incentives to do so will largely disappear. Unfortunately, statutory regimes, particularly in the United States, seem to be going in the opposite direction. With the ability to seek out and purge disclosed data, at least some of the damage can be mitigated. Considering t…
All fair points, though I specifically had individual defense in mind. I don't know any good way for an individual to restrain accurate data once it's released, so poisoning is the only option I see to dilute the value of it. At least when thinking about individual defenses, I tend to treat the regulatory landscape as a lost cause - currently I'm just hoping that privacy tools won't be actively outlawed.
Whether it's concern of your data going out, or bad genetics patterns coming in, your best bet is to cut off the routes of transmission.
In a plague-infested land, it's practicing exceedingly good hygiene which is in your best interest. If that means walling yourself off from the rest of society for a few years (as one royal household in Europe did), so be it.
Keep in mind that the Black Death even eventually reached Iceland, though some years after it scorched over the rest of Europe (4-5 years as I recall).
There are domains of problems which are intrinsically personal. Though rather more which manifestly are not.
(Though you've also got me thinking about what equivalents to own information spreading out there are, epidemiologically.)
Re: VPNs are not the solution to a policy problem
#218Earlier quoted context omitted.
So true and I could not agree more. When did technical problems start requiring political solutions? I think it's a Trojan horse from politicians to start legislating where nobody needs legislation. The net will still route around censorship, but it's becoming increasingly harder in a world where a high percentage of global bandwidth transits through a small number of large deployments by centralized corporations. Th…
> When did technical problems start requiring political solutions? When the technical solutions became criminalized. End-to-end encryption is only now becoming common, and English MPs are already talking eagerly about outlawing it. The need for political fights isn't exactly new - think of the Clipper chip in the 90s - but it hasn't abated either. I see lots of suggestions that we can solve this with keeping tech ahe…
Re: VPNs are not the solution to a policy problem
#219It's strange to see the evolution of the technology versus policy debate. We started out with "the Internet views censorship as damage and routes around it." A little later we had Lessig saying "code is law." And now the refrain is "VPNs are not the solution to a policy problem." I miss the idealism and optimism of the past. The only hopeful thing I can find in the new "quote" is that it seems that the tech world is…
You're misrepresenting Lessig's point. His was not that code replaces statutory law, but that code is one of the four forms of law: Law, Norms, Market, Architecture (including code). Which is captured in his title, "Code and Other Laws of Cyberspace". (Emphasis added.) The problem in this case is that morality (Norms) has gone AWOL, architecture is insufficient, and market incentives are buying statutory cover to pur…
Re: VPNs are not the solution to a policy problem
#220Earlier quoted context omitted.
You're misrepresenting Lessig's point. His was not that code replaces statutory law, but that code is one of the four forms of law: Law, Norms, Market, Architecture (including code). Which is captured in his title, "Code and Other Laws of Cyberspace". (Emphasis added.) The problem in this case is that morality (Norms) has gone AWOL, architecture is insufficient, and market incentives are buying statutory cover to pur…
No. I never said that "code replaces statutory law." I said it was strange to see the evolution from one extreme where code trumps law to the other extreme where technology can't solve policy problems. Lessig was mentioned in between those two extremes.
If you meant to convey a different meaning, you might have clarified. I stand by my statement that that appears to misrepresent Lessig's argument, which is a good one.
As for the range of opinions ... from John Gillmore to Staticsafe ... views differ. It's helpful to keep in mind that Gillmore, Lessig, and Staticsafe are all presenting arguments as challenges to conventional wisdom. To that end, presenting any of them as indicative of the CW is also ... misleading.
Unless you meant another argument.
Again: I'm not trying to tell you what you meant, but I'm telling you what I'm reading from that. And ... between exposition, clarity, and/or argument, it could be better.
Cheers.