viernes, 17 de julio de 2015

Reconciling The People's Rights to Privacy with National Security

According to Alan Davidson, former Google executive turned Commerce Department official, strong encryption and law enforcement interests are not “irreconcilable.”
That comes from https://firstlook.org/theintercept/2015/07/15/former-google-exec-turned-obama-official-wont-say-believes-magical-solution-encryption-debate/ and the next sentence is:
But he won’t speculate as to how that’s possible.
Well I can. It's not at all difficult to think up at least one reasonable way to do it. I attribute the idea to Aaron Schwartz, who said before he died that he wanted his entire e-mail archive to be made publicly available.

We can reconcile the requirements of privacy, security and transparency simply by making one single global secure Internet, using the strongest cryptography possible, available to every and all people of all nations. And we build that system in such a way that security and integrity checks apply not only to the data that is being stored and communicated, but to the records of access and update of that data.

I have no objection whatsoever to the Government of the Plurinational State of Bolivia, or those of the Russian Federation, or the United States or the UK, reading any of my communications, provided they are prepared to tell me truthfully for exactly what purpose they require that information, and provided that they can prove that this purpose is in the interests of the common good of all of Humanity for all time.

Now the problem with this idea, I suspect, is that the only government in the world that is potentially capable of providing such a proof is that of the Plurinational State of Bolivia.

I say potentially capable, because it is not, as far as I know, actually capable of doing this, yet. The problem is that we do not have any reason to believe that any computer or communications system in use in Bolivia is in fact secure. So when the government of the Plurinational State of Bolivia accesses my data, though they may be able to demonstrate that their intention is for the common good, they will not be able to demonstrate that they are the only ones accessing that data, and that it will not be accessed by other unknown parties whose interests are not those of the common good.

Of course the same objection holds for any government of any nation. So the problem we all have to solve, and solve urgently and effectively, is how to provide permanent access to verifiably secure communications and computation to every person on earth.

jueves, 16 de julio de 2015

Final Cause in Telecommunications

Here's an amusing example of final cause. In 2014, in his e-mail signature, Richard Stallman objects to Skype because it's non-free (freedom denying!) software. He says "use a telephone call" instead.

--
Dr Richard Stallman
President, Free Software Foundation
51 Franklin St
Boston MA 02110
USA
www.fsf.org www.gnu.org
Skype: No way! That's nonfree (freedom-denying) software.
Use Ekiga or an ordinary phone call.

Then 29 years earlier, Edsger W. Dijkstra points out that Stallman is functionally illiterate.
Two comments to this question. One comment is that your view of industrial programs as pointed out in the question is narrow. There are all sorts of programs that hardly have users, if you think of a telephone exchange, or digital controls in cars or airplanes. As to the programming products that are used by people, I hardly have first hand experience, my impression is that an enormous amount of user time is wasted figuring out what the system does and how to control it, which is the consequence of two sorts of happenings. First of all that the designers have failed to keep the interface of a system as simple as possible—which is a challenge; but as soon as you realize that the main challenge of computer science is how not to get lost in the complexities of their own making, it is quite clear that this is a major task. Secondly, the scene is very much burdened by the fact that a large fraction of the people involved are functionally illiterate; particularly in the United States.
Now that's obvious to us now, but perhaps it wouldn't have been if Ed hadn't pointed it out so bluntly.

That's how the future reaches back to affect the past.

The Mother of all Software Vulnerabilities

In August last year I wrote a document describing how we could secure the GNU toolchain from possible subversion, as well as make all the software a lot better,

I sent it first by e-mail to Richard Stallman, Linus Torvalds and Theo deRaadt, amongst others. Then when I received no meaningful response from any of these people, I sent it to the public guile-devel mailing list.

Stallman's response (by private e-mail to me) was rather feeble. He did not seem to understand the security problem. So I explained it more explicitly in another post to guile-devel, hoping to widen the discussion to include people who might actually provide better-considered responses to the document.

That didn't work either, so I tried to explain it yet more clearly in a blog post, where I pointed out the original publication of the problem often mis-attributed to Ken Thompson.

To my pleasant surprise Roger Schell responded shortly afterwards, referring us to a paper he had written a decade earlier, which corroborated everything I had claimed.

To make the point, I gave some details to show how easy it would be to devise an object code trap-door that would survive all but a major restructuring of the compiler source code.

Stallman's feeble response was that he did not have time to read the 100 or so lines of program code I had given which implemented a PROLOG interpreter which could search for the relevant patterns in the compiler source to identify the target source even when it's structure was altered from version to version. I responded in private that he seemed to think I had time to read over 60MB [correction: that should read 600MB] of source code that comprises the GCC compiler source distribution. He had nothing to say in response to that.

It didn't go much further than that. There was a lot of smoke on the guile-devel list from people who thought they knew what I was saying, but who made it very clear that they had actually missed the point entirely. But clearly some people did understand exactly what I was saying.

I also explained how we can solve the problem of harware subversion using similar techniques.

Then a few months later, Edward Snowden dug around his "archives" and came up with this lovely little snippet, describing how "researchers" at Sandia National Labs. had actually done exactly this, to hack Apple's XCode development toolchain, and this was the origin of the MacOS and iOS hacks described here.

It is clear then that subversion by object code trap-doors is a real, extant threat, and so probably is subversion by system initialization trap-doors, though there are very few people capable of understanding what that might be. Given the difficulty of detection of these things, we have no good reason to believe that any toolchain based on the GNU C compiler has not been effectively subverted. The same "whacking" that the little boys at Sandia gave the Apple XCode gcc compiler, will be an easy-enough port to OpenBSD, Debian Linux etc.

So I pointed out the problem, and it was subsequently confirmed to be a real extant exploit. But I also pointed out the solution, which is to formally specify programs using intensional semantics as application-specific languages, and then automate the actual generation of programs implementing those specifications.

Now there is a bit of a hoo-hah about unreliable insecure commercial and open-source software, and I wonder why no-one still has any response to my suggestions? What is the problem? Can anyone tell me what I've missed? Is there a big metaprogramming project that will soon solve all this?


miércoles, 15 de julio de 2015

Modern Economics

Here's a little riddle for the Freemasons. You'll need to learn some Geometry before you can solve this one:

You are two little men, and one of you is sucking the other's cock while he fucks you up the arse. Where is your head?

Now for the 33 degree Freemasons, here's the really hard version for which you will need to learn about both Geometry and Arithmetic (modulo n):

You are any pair (i and i+1, say) of n little men, and one of you is sucking the other's cock while he fucks you up the arse. Which of you has the most money?

Now for the 108 degree Freemasons, you will need to know Geometry, Arithmetic, Stereometry and also what a Galois Connection is.

You are one of n little men, arranged on the surface of the earth, and you are sucking one of the other's cock while you fuck another up the arse. Is the total amount of Global Wealth increasing or is it decreasing?

martes, 14 de julio de 2015

Software is Not Even a Load of Utter Crap

Below is how the Ars Technica UK Security page looks like today. The verdict is pretty clear. Software isn't an eco-system. The ecosystem is a product of Intelligent Design, and modern software is only a junk-yard full of useless garbage that won't even rot properly. Any kind of shit at all, is worth more than modern software is worth.

Now the stupidest thing to do would be to start writing the same useless crap all over again. Instead, we need to design application-specific languages and interpreters for those languages. Then instead of  boring ourselves stupid by writing a load of broken code by hand, we write the interpreters which will write the code implementing the specifications we write in those application-specific languages. Then whenever we find that we've done yet something else incredibly fucking stupid, we just change the interpreters, and regenerate all the applications, thereby fixing all the fuck-witted bugs in all the applications, all at one fell swoop.

Adobe flash isn't anything more than an horrendously badly written interpreter for an horrendously badly designed language that in fact hardly does anything at all.  So if we want to replace it we just design a decent abstraction of a few different types of processor, and a few application languages: for example, one language for specifying vector graphics, another for raster graphics and applying filters and whatever, and another for scheduling animated graphics and audio streams, another for processing real-time user input events and another for remote procedure calls over network connections.

Then we design a language for specifying raster graphic constructions at around the level at which the pixman primitives work, and another for specifying drawing at the level of bezier curves, fills, etc., around the level at which Cairo works. Then we design a language for specifying glyphs in fonts using those primitives, and we produce a FEW really good fonts by interpreting languages that were designed to specify those particular fonts. Then we define a language for specifying the abstract topology of the characters, and interpret those glyph programs into the font-specific languages, which we in turn interpret into the language for specifying raster graphics primitives. Then when someone defines a Greek capital Sigma, they just write the description of the topology and the Sigma appears in Arial, Times New Roman and Garamond No 8, all at the same time, and perfectly matching all those fonts.

Then we can interpret those raster graphics primitives as generic abstract assembler code, and then reinterpret the results as specific assembler, which we JIT compile to some specific processor model and graphics display, both of which are also formally specified using languages designed for exactly that purpose. Then when we flash that JIT compiler into the machine's BIOS ROM area, and it boots in 0.5 seconds, and functions perfectly, and only uses around 2MB of code space, and even if the machine is a 10 year old laptop wired to an old car battery, for 90% of what most people would want to do with it, it is just as fast as a brand new machine costing $2,000. And the application is not just a Flash browser, it does far more than anything anyone could ever imagine wanting to use that computer to do.

That's all you need to know, now go to it ladies. I'm sorry I can't be more help, but I told you all this a year ago, and my reward was that I got left to starve in the streets of La Paz in winter. I rarely eat more than one meal a day, and often none at all, and my health is deteriorating rapidly.

So if you need me to help you, then some of you are going to have to lift yourselves out of your self-indulgent torpor and work out how you can help me to help you. Otherwise I am going to die, and quite frankly I am looking forward to it because the less time I spend in this stupid world, run by idots and madmen, the better. If you don't want to do what I tell you you need to do to solve these silly little problems, and also you can't tell me why it is that you know that you know better than I do, then I don't want to hear anything from you at all, I just want out.

So, is there anyone, anyone at all in this whole wide world, that can come up with an intelligent response to this? Oh go on, please, please, suprise me, I've earned it!

Ian

SPECULATION RUN AMOK
  1. Attack code has already been published, all but assuring exploits will go wild.

viernes, 10 de julio de 2015

Insecurity Sells

Here's a nice story.
http://arstechnica.co.uk/security/2015/07/how-a-russian-hacker-made-45000-selling-a-zero-day-flash-exploit-to-hacking-team/ 
I have a lot of respect for Vitaliy Toropov. He's professional, and very good at his job. He clearly doesn't care too much for money either, because there are probably plenty of even less savoury organizations (run by much smarter people, too) who would have been happy to pay 5 times what he was asking for that exploit.

It's a pity someone so intelligent has to spend all their time fishing around the gutter to earn a living. He would be much better employed designing software production systems that solved all these kinds of problems. But there are any number of learned idiots around who will say "it's an imponderable" or that "people need the intermediate level representations". They're wrong. Computer programs can write better programs than any number of people could, no matter where they got their PhDs.

miércoles, 8 de julio de 2015

Automatic Translation

Current attempts to automatically translate texts are doomed to failure for the simple reason that language evolves. Therefore the semantics, in other words the meaning of a text, depends crucially on the context in  which that text appears, but the context is not evident in the text itself. Chomsky provided a famous example of the phenomenon in the sentence
Colourless green ideas sleep furiously.
Chomsky probably meant this as an example of a grammatically correct English sentence which was not in fact meaningful. But the context is everything, and it doesn't take much of a poet to imagine a context in which the above sentence is in fact meanigful; try it.

The problem is that the text is an extensional representation of some intensional semantics. The intensional semantics are the semantics the author intended the text to represent. Now there are any number of ways the author (or poet) could have chosen to express that intensional meaning, and this is but one of them. However, the intensional meaning is not explicit in any one of those extensional texts.

Rather than banging our heads against the proverbial brick wall of translating informally written texts from one language to another, we could make some real progress by concentrating our efforts on defining formal languages to express the intensional semantics of what we wish to say. Then we could interpret those formal expressions of semantics as if they were computer programs, and thereby automatically generate the extensional expressions in any context where they are needed. That context will include not only the language in which they are written, but the particular period and style of expression.

Such formal expressions of intensional semantics could in principle be translated perfectly into any known written language. Furthermore, those translations could be formally proved to be faithful representations of the intended meaning of the texts.