Showing posts with label moral hazard. Show all posts
Showing posts with label moral hazard. Show all posts

Saturday, June 08, 2019

Zimmermans' relevance for discussions on human rights and ICT-security surveillance


If we look at economic and social risks of new technologies, outsiders will often immediately fall into the trap of considering this to be about the illegal use of peer-2-peer networks, applications such as bitcoin etc, for socially unwanted activities or even criminal activities. From there on it is a small step to forbid such activity, regulate it, overregulate it. But we should take a wider perspective here.

For me, Phil Zimmerman was the person who made a lasting impact, when he explained, somewhere in the late 1990s, during a speech at a digital money conference his considerations behind developing Pretty Good Privacy (see also his explainer himself: Why I Wrote PGP). His argument was mainly that the new digital society has to be built in such a way that it guarantees a situation in which a people are still able to communicate and act in way which is not invaded or controlled by government tools/techniques. Whereas the old analogue world would allow the people smart analogue ways of creating their own spaces for communicating and fooling government with fake analogue id's and such, it would be much harder to do this in a digital world. Hence the need for a peer-2-peer simple mechanism as Pretty Good Privacy.

Zimmerman outlined one very significant theme during his speech. He noted that the assumption of a continuous benevolent government is not realistic. Governments come and go, some may be more democratic than others and even strong democracies may turn into dictatorships, depending on the circumstances. It is therefore important to design society, governments and the technologies that we use to manage society, guarantee that a balance exists between the powers of government and those of the public. The public, the people should always be allowed to remain digitally out of sight of government. Such a robust structure would be important to ensure a fair treatment of the people over a long period of time.

It is clear that this requirement: to allow for and to actually create areas where the government cannot see what happens means that those areas are scary for regulators. Will they facilitate crime by doing so? Perhaps. Will they allow for huge pockets of creativity? Certainly ! But it will be the strong governments that are able to allow this. They will act from a position of strength and not be afraid. The weak governments, or the scary governments, or the ill-intending governments will seek to monitor everything and control all digital activities. This will certainly fail. But while doing so, they may instil tools that are very dangerous tools in the hand of governments when they turn from benevolent to evil. It will tilt the balance towards a situation that ill-intending governments can no longer be overturned by a social revolution.

There is no need for governments to be afraid of technological progress in the hands of the people. It is a good thing, to be cherished and to be allowed. The simple labelling of such activity as possibly criminal is the wrong frame. The reverse is also wrong: regulators with good intentions are not by definition tools in the hands of dictators. The right frame is: dictators exist just as criminals. Society should ensure that neither of these can become too powerful due to technological of legal measures and it is for this reason that we need to balance our human rights to privacy with the goal to prevent criminality.

Finding this balance is not easy but over the last weeks we have witnessed too many occasions where governments seem to go to far. German police wanting access to home devices. The FATF-ruleon surveillance for virtual assets. Ghost accounts into Whatsapp. Giving your social media handles when entering the US. We should not let ourselves be caught in this wrong direction over intrusive government behaviour.

There is a very legitimate reason to develop and create new technologies that safeguard the public and it is a pity that many policy makers in the world may not have been hearing the clear message that Phil Zimmerman sent them. They really could do with open their minds more. So for them I’m embedding this video. Just to be able to learn from history.



Friday, June 24, 2016

The DAO - Ethereum incident: if you can't stand the heat, stay out of the kitchen !

Ok, I admit: I may be a payments or banking dinosaur and an old school kind of guy. I have personally witnessed the emergence of new payment methods (POS, I-pay, VbV, purse, online-purse, Paypal, EMV, etc) as well as the failure of banks (Icesave, DSB). And I have a keen interest in the history of banking and finance.

With this background I have been intrigued by the Ethereum-DAO incident and its further follow up. What now seems to happen is that an undemocratic, interest driven community that hasn't secured or enforced proper governance and safeguards, is taking the right in their own hands when some digital assets of theirs appear to move in different places than envisaged.

Lay-out of options to solve the issue
Pondering the issues at hand was stimulated by this very good presentation by Gavin Wood last Monday at the Dutch Blockchain Conference. See below



In the presentation Gavin Wood presents 3 options:
- do nothing
- soft fork by community
- hard fork by community.

How logical the 'community' approach appears to be, I couldn't escape at noticing that the concept of community is limited to those directly involved as owners/investors in ether. All of those people were aware that they're investing in a very speculative, new technology and digital asset.

Gavin introduces the concept of moral consensus by the people, rather than the machine, to solve the issue. This consensus is not really the people, he explains, but the miners. In my view this means that the bottom line is that the interested actors take the right into their own hands to cheat the attacked back out of his possessions.

What's missing: the legal consensus
What's truly missing in the discussion is a fundamental fourth 'community' option:
- owners of 'stolen' ether  call the police (in whichever jurisdiction) so that a judge may determine whether or not this is a theft or otherwise.

Any system existing on earth, is always under some jurisdiction which allows formal legal arbitrage on differences of opinions as to whether this is theft. And lacking the proper arbitrage rules in this obviously not so smart contract, this is the domain where the Ether and DAO community should revert to.

Any other road than turning to the formal/legal mechanisms to solve this issue, constitutes a power batlle between interested parties. One party claimed to offer autonomous smart contracts without human intervention (but slides back as soon as they lose money on it) and another party took them up on the offer and fights back to keep the first party to their offer.

If you can't stand the heat, stay out of the kitchen
From a macro point of view, I don't see a reason why a response in forking by the ethereum community is justified. We're just witnessing a private, risky enterprise doing not-so-smart-things with not-so-smart contracts. This will mean that a limited remit of private investors (that know that they are risk investors) lose their assets to someone else.

As tough as it may be to see someone mess up your assets/system in front of your own eyes, it is hoewever the ultimate consequence of a philosophy in which one proclaims that is exclusively the machine that drives the asset moves.

So as this all happens, you just better buckle-up, take the hit and make sure there are no more accidents waiting around the corner. And if you're not up for it, it's time to leave the play under the motto: If you can't stand the heat, better stay out of the kitchen. When seen from a financial history perspective this whole incident is just one silly drip in the ocean of follies that has ever occured.

Up next: proof it or put in arbitrage
In a practical sense, the lesson is easy. Either have full formal proof of smart contracts, allowing you to  check all possible states of the implementation, or include an arbitration and third party mediation into the smart contract.

It's not a new concept: I've been speaking with Ian Grigg numerous times on the relevance of arbitration for smart contracts (see also his blog on this). So with this incident, the lesson will surely sink in somewhat faster, whether you're into the bitcoin blockchain or the new kid on the block.