Blog

  • Thoughts on (Flexible) Working From Home

    It’s been a few weeks since I started working from home for Automattic, engineering happiness for users of WordPress.com.

    Having moved from an (almost) standard 8.30-5pm, office-based working day, the switch has proven to be an interesting experience.

    Even with my youth squandered in online tech communities that operate in very similar ways to Automattic, it’s definitely a mindset shift to go from that sort of world being just something that you do, to something that actually pays the bills. Work is meant to force you into set patterns begrudgingly… right? I didn’t expect there to be too much of an overhaul, but a job with complete flexibility has definitely brought with it some interesting quirks.

    happy monday - working from home

    Here are some of my observations:

    You don’t get distracted

    One of the usual reasons that people give for ‘not being able’ to work from home is that they get distracted and can’t concentrate on what they’re meant to be doing. As far as I’m concerned, that’s nonsense. Sure, it may well depend on the person, but if you are independent and self-motivated, you shouldn’t find it a problem to set out an area and dedicate the time you need. If a Gen Y-er can do it – with our alleged ridiculously short attention spans – then so can you.

    Going to the bank isn’t the headache it used to be

    Ahh… the dreaded trip to the bank/post office/travel agent/loanshark. It was always such a torture to have to undertake any sort of task that fell during the working day. This equally applies to the receiving of parcels. Sure, you can get small things delivered to work, but what happens when you order something big? Carting it back from the office is never a fun task… even if you are lucky enough to have access to a car. Working from home sweeps all of these troubles away in one fell swoop.

    Your Neighbours Will Love You!

    If you play your cards right, that is. So long as they’ve met you (and you’ve not been weird about it), you can easily become a local everyday hero. Just make it clear that you’re usually around during the day if they have parcels getting delivered, or need an eye kept out for something. Even if they never actually ask you to do anything, you’ve won major brownie points – especially handy when you throw that 7am-finish party with all of your dubious mates.

    lunch

    Lunch is better

    The first week I worked from home, I ate nothing but bacon sandwiches – purely because I can. That can’t continue for long though, or I’ll balloon to some ridiculous size. In general though, it means you have access to your own kitchen, rather than an awful, over-priced canteen (or a microwave, if you’re lucky). I was never any good at avoiding squashing my sandwiches anyway, so this is a winner. The only real dilemma is… what to have? So much choice!

    You get to mock those who have to commute

    I’ve luckily managed to avoid travelling every day during the onset of the Scottish winter this year, which is undoubtedly one of the greatest perks about being based from wherever you choose.

    It’s pretty soul-destroying to wake up early, in the dark, to make your way into work, only to return home at night, in the dark. What has never made any sense to me though, is the preposterous notion that people should fight their way for hours through gridlocked motorways in the rain, sleet, and snow, to get to an office to do a job that they could arguably do just as well from home. I’d even go so far as to argue that it’s negligent for employers to expect people to physically come in to work on days where the police are ‘advising motorists not to travel’.

    That said, I think there are those who genuinely love this sort of daily battle, as if there is some sort of valour to be had in succeeding in such a pointless trip. Those, my friends, are those whom we should mock relentlessly.

    Electricity bills

    Uhhhm, Leave this one with me.

    You can go hours without saying a single word to anybody

    Insert your own joke about how it’s better if I keep my mouth shut here. There’s a lot of commentary about how it can be unproductive to be constantly interrupted in an open plan type office, and it’s definitely true. The flip-side is the total opposite though. Unless you live with other people, you can go entire days without uttering a single word. I’m not entirely sure whether it’s a completely zen-like experience just yet.

    Watch this space.

    The banter

    This is related to the above. Sure, there are a lot of downsides about working in close proximity with over folk – like having people hang over your shoulder, or force you to look at links on the Daily Mail website (shudders – Linda, you know who you are!), but you can’t really beat the days in work when you’re surrounded by people who are working on the same thing, having a laugh together.

    You need to make more of an effort to stay in the loop

    This could well be partly because I am refusing to pay for a TV licence, and so am missing out on the news at night, (disclaimer: I don’t own a TV, or watch it as it’s broadcast online) but more often than we think (yes, even in the age of so-called ‘new media’), news is spread by word of mouth, through the people we come in contact with every day.

    If your community is online rather than round about you, very quickly you might find that you aren’t as up to speed on local happenings as you might have been previously. It takes a real effort to keep up to date; a battle that I am currently losing, it has to be said.

    You can find your natural schedule

    I’ve never been a fan of mornings. Not that I don’t like the crisp, fresh air; the tweeting of the birds; and all that. I simply don’t function well at that time.

    Part of the problem is that due to whatever screwy Circadian rhythm I have, I don’t naturally get tired until around 2-3am. Irrespective of how early I was up at in the morning, the time I went to bed remained the same. Working from home, I’ve shifted to a 10am-6pm day (roughly), which already means if I go to sleep at 3, I’m getting 7 hours sleep, compared to 4. That’s almost double the amount, and has meant I feel 100% better during the day, with no irresistible urge to disco-nap early evening.

    Working from bed is the best thing ever

    …for a few hours anyway.

    Days seem shorter

    Even though I am working the same number of hours, and finishing up the same time I would be getting in from work if I was commuting, the days still seem to fly by. Those extra 3 hours spent getting up, getting ready, and travelling to work in the morning have been converted into sleeping hours, which is probably what they should always have been in the first place.

    life work balance

    Concepts of time become more fluid

    Weekend? What’s that? With total flexibility, there comes a blurring of the lines between the ‘working week’. When you are able to choose a schedule that fits around your life, that may not be in traditional daily blocks. Many people will shudder at the thought of the lines between work and personal life ‘blurring’, but that isn’t really what’s happening. Just because work becomes spread more diffusely, doesn’t mean that it takes over; it just allows you to integrate it more closely to what fits best for you. Working two hours in the evening or at the weekend instead of on a Monday morning doesn’t mean you are a slave to the job, it means that you are more in control of how and when you choose to give it your full attention.

    When you spend all of your time in the one place, with work spread out more than beforehand, It does mean that weekends never feel quite like they used to.

    I don’t actually think that that’s a bad thing, for what it’s worth.

    People don’t get it

    ‘But… How do they know you’re actually working?!’

  • Public Sector Can’t Do Twitter

    Let’s talk about public sector organisations using Twitter. In particular, those funded by the taxpayer.

    Many councils and arms of Government have decided (read: been told) that they need to get on board with the digital age, and seek new ways to ‘engage with the public’ through different mediums. We expect them to be there, and so it makes sense that they are. In principle, this is a good thing. Organisations with such a direct role in people’s everyday lives should definitely be aware of the shift in how we are communicating. However, their response has to be considered, with a clear purpose, and strategy. It is clear that for many of those who are currently active on social media in this sphere, they don’t actually have a clue; more a case of diving in because they feel like they should, rather than having any real conception of what approach they should be taking.

    Cardinal Sin Number One: ‘We don’t respond to messages’

    The oft-repeated mantra across many public sector accounts is something along the lines of: “we monitor messages that we receive, but do not reply to them”. That is, if you are even lucky enough to get any sort of indication that somebody is actually behind these accounts. Glasgow City Council (@GlasgowCC) is one example of a local authority that don’t even bother to warn you about their blanket disregard for questions or comments they receive. Personally, I prefer this account… at least they reply:

    Screen-Shot-2013-10-11-at-12.35.24
    Do us proud, Glasgow.

    When challenged (not over Twitter of course, because you wouldn’t get a response that way), what almost always happens is that those who are responsible for these accounts throw up their hands in faux despair, pointing to the legitimate concerns about the questions about funding in the current economic situation (ad nauseam). The benefits of using social media channels for ‘engagement’ are addressed in volume elsewhere, but we have to ask what exactly the point in an organisation investing any time in Twitter is, if they aren’t prepared to use it properly? Save the time and effort and get offline rather than building a house with sand foundations and making our towns and cities look out of touch, please.

    Cardinal Sin Number Two: Posting Utter Guff

    Imagine the most boring person you know, and multiply their drudgery tenfold. Now imagine being stuck with that same person at a party, where they spend all night randomly interjecting otherwise exhilarating conversations with banal statements that everybody already knows, and tries to ignore.

    That fairly accurately describes the existence of most British councils that are on Twitter. It’s true that we shouldn’t really expect matters so regionally specific to be any more exciting than the weekly local newspapers, but routinely they manage to sink to even lower depths. Clearly devoid of anything worthwhile to say, at all, South Ayrshire Council chose to climb up onto the world stage with great fanfare and flourish, to deliver this poignant message:

    Thank God for this reminder!
    Thank God for this reminder!

    Words actually fail me.

    Seriously though, this is one of the most ridiculous, pointless tweets I’ve ever seen – and I follow @horse_ebooks

    @horse_ebooks - beating the public sector at Twitter with one hoof
    @horse_ebooks – beating the public sector at Twitter with one hoof

    There is so much wrong with the approach highlighted in the South Ayrshire example that it’s tough to know where to begin. How is this tweet relevant… to anybody? Is your target market really the tiny number of users that might be about to park a car somewhere in South Ayrshire, who are also checking Twitter at the same time? (not to mention the illegality of using your phone whilst driving). Total nonsense. Unless, of course, the role of Twitter is to randomly remind us of illegal acts. Maybe they should say DO NOT MURDER.

    If you have time to post this sort of pish, then you have time to reply to people. No excuses.

    Cardinal Sin Number Three: Not Reading What (or who) You Tweet:

    There are a few larger organisations that actually do have a decent amount of stuff to talk about. Things that concern a lot of us; things that we might well be prepared to sacrifice a lack of correspondence to be kept up to date with. After all, plenty of people follow celebrities because they find what they say interesting (well…), not because they expect to get a personal reply.

    The trouble is, public figures tend to be fairly savvy at using the technology for their own means; they have built their careers on galvanising crowds of people, after all. Sadly, this does not seem to apply to the public sector world.

    A wonderful example comes from the Department of Work & Pensions. They are already guilty of committing Cardinal Sin Number 1 (and let’s face it, not too far from the folly of Cardinal Sin Number 2 either), but they manage to rack up a hat-trick by seemingly not even proof-reading what they post in the first place.

    One tweet from early October linked to a video featuring Clare Pelham – Chief Executive of a disability charity – about issues relating to employment. In of itself, this was a great bit of content to share. However, it all went wrong. This is the Clare Pelham that they meant to mention:

    Will the real Clare Pelham Please Stand Up?
    Will the real Clare Pelham Please Stand Up?

    …and this is the Clare that they actually ended up attributing:

    @clare in promotion shocker
    @clare in promotion shocker

    Now I’m no expert in this field, but I’m sure that @clare might also be a bit surprised to hear the UK Government talking about her recent promotion. For reference, here is the offending tweet, in all of its tainted glory:

    DWP Twitter Fail
    DWP Twitter Fail

    Derp.

    Okay, so we all make mistakes. I’ve done (and do) it regularly. That might shock some of you, given my sheer articulate brilliance, but it’s true. However, I usually spot and rectify them within 0.6 seconds of the tweet going out to the world, and hang my head in shame. Not the DWP though! This particular example stayed online for at least ten days after going out. They did manage to get it right in following iterations, so it’s bizarre that they didn’t go back and make a correction. It’s probably still there, but I am too dis-heartened to check. 

    This wasn’t a once off either. Less than a week later they were at it again, this time with rogue characters that should have been removed before posting:

    That quotation mark has no business being there
    That quotation mark has no business being there

    Please… read before you tweet. (and if you can’t, delete it and throw yourself upon the mercy of the Twittersphere)

    Cardinal Sin Number Four: Simply Not Getting It

    To close, I leave you with an insight into the behaviour of Orkney Islands Council… the behaviour of which is best left without comment:

    Screen-Shot-2013-10-11-at-12.23.59
    Routine check for… what?
  • Automattic/WordPress.com fight back against Censorship

    WordPress LogoAutomattic – the company behind WordPress.com, have taken a decisive step in the fight against bogus DMCA claims.

    Under the Digital Millennium Copyright Act, people can submit a takedown notice to web service providers where their intellectual property is being used without permission. This is the legislative attempt to protect hosts like Google, WordPress, Tumblr, etc from being held responsible for the content that their users post – provided that they swiftly restrict access.

    However, whilst this system is designed to give a balance between protection and enforcement, the reality is that many times it is abused by those who wish to silence critics, or to censor views with which they disagree. The Church of Scientology infamously issued thousands of DMCA takedown notices to stop the spread of anti-Scientology views on Youtube, for example. This tactic is highly effective, as the content is almost always restricted (at its peak moment of attention), and the process to challenge the notices (a ‘counter notice’) isn’t something that creators are, or arguably should be, familiar with. In effect, it becomes a virtual game of ping-pong, with the burden of proof shifting to the ‘author’ of the content to prove that they actually have the rights to publish. Sites themselves can take action, but with the sheer volume of notices that they receive, it is often impractical, and rarely a route that businesses want to go down.

    I’m both pleased and proud to see that WordPress are fighting back against two such bogus DMCA claims, as announced in this latest blog post, where you can find all the details of the two cases in question.

    For the full text of the original post from Oliver Hotham – one of those that fell victim to the misrepresentative DMCA, continue reading below, where it is republished with permission.

    (more…)

  • No, It’s Not Just About Porn

    No, It’s Not Just About Porn

    Glasgow Guardian NewspaperThe Glasgow Guardian is the student newspaper from the University of Glasgow, and is generally better than most of the publications of this type that I’ve come across – I’m not just saying that because they used to use my pictures.

    I was surprised to come across an article in the last issue entitled ‘The day the porn was still there‘, which spoke about the proposed Internet filtering that the Government were seeking to impose on ISPs in the UK.

    It wasn’t great. Have a read for yourself.

    I wrote a response, which has been published in the current issue, on page 11.

    For those of you that aren’t fond of viewing content online in a format suitable for print (and why would you be?) the text is below:

    I write in response to the article entitled ‘The day the porn was still there’, published on the 16th of September 2013, by Imants Latkovskis.

    In the interests of full disclosure, I am a member of the Open Rights Group Supporters’ Council – the ‘London based NGO’ whose views were criticised in the original piece. However, the purpose of this response is not to rise to defend the content of the organisation’s claims; that job is for somebody else – and not what I signed up for.

    Aside from the over-use of emotive language, and massively reductive statements (“ticking the ‘I want porn’ box is unlikely to be the start of a dystopian future.”), Latkovskis has managed to miss the point completely; the thrust of the article seeming to be that ‘illegal porn is bad, so it’s good that they want to block it’.

    Latkovskis states that in justifying the proposed filter, David Cameron was ‘referring to child pornography, which seems to be forgotten about quote after quote.’ However, he himself is guilty of confusing two quite distinct issues. This isn’t something that he should feel too bad about though, as the proposals have been deliberately designed to have this effect.

    We have to separate out whether the purpose of an on-by-default Internet filter is either to:

    1. Prevent access to illegal material, e.g. child pornography

    or

    2. Prevent people (ostensibly children) from accessing any pornography

    These are two very different aims, and require equally different approaches.

    It’s a moot point for the purposes of this article that none of these type of filtering systems actually work effectively in any regard. If you aren’t sure about that, just ask yourself when the last time was that you or a ‘friend’ used a VPN to get onto American Netflix, or a proxy to peruse certain eye-patch clad torrent websites. Never, I’m sure!

    The concern that any sort of default Internet filter will inevitably also block access to other content is not an unfounded one. Mobile operators such as Orange and T-Mobile have already blocked sites under categories headed ‘Chat’ and ‘Forums’ from their service without an explicit indication that you want to gain access – something that you often cannot obtain until you have been a customer for 6 months or longer. Nobody should have to submit their name to a database with tick-boxes against the categories of content they have chosen to view, or what information they want to exchange, and that is a realistic consequence of these proposals.

    This fundamentally isn’t about pornography, and to suggest that those who question a blanket, State-mandated Internet filter are advocating free and unfettered access to ‘material depicting rape and child abuse’ is at best disingenuous, and dangerously mis-informed.

    Yet another badly thought out, technologically incompetent piece of legislation (if ISPs are not pressured into this ‘voluntarily’) will do nothing to protect children, nothing to stop the spread of illegal material, and only serve to further squeeze the freedom to communicate and disseminate information online.

     

  • Engineering Happiness for WordPress.com

    happiness engineer
    My interpretation of a happiness engineer turned out a bit horror film-esque.

    I am more than excited to say that I’ve accepted an offer from Matt Mullenweg – founder of WordPress – to join Automattic as a full time Happiness Engineer, beginning at the end of November.

    With just a shade over 200 employees, Automattic’s network gets more monthly unique visitors than Amazon.com, eBay.com, and Yahoo.com. It’s not too far behind Facebook either… They support some of the biggest names on the web, like CNN, TechCrunch, and TED, and get about 19% of the world’s web traffic.

    ‘Based’ in San Francisco, almost everybody works remotely – from locations around the world. I’m the only employee north of Manchester, which is pretty awesome in of itself. From what I’ve seen, they have an amazing culture with some incredibly smart, and talented people. I’m pretty blown away at the chance to be part of it all.

    All that said, it’s been great working with Amor Group, – where I started out 9 years ago as a fresh-faced, terrified schoolie. They’ve been good to me over the years, and I’m particularly proud of what we’ve managed to achieve with their digital communications. I wish them all the best as they go forward as part of Lockheed Martin, but it’s time for me to bow out.

    I’ll leave you with this, the Automattic creed:

    I will never stop learning. I won’t just work on things that are assigned to me. I know there’s no such thing as a status quo. I will build our business sustainably through passionate and loyal customers. I will never pass up an opportunity to help out a colleague, and I’ll remember the days before I knew everything. I am more motivated by impact than money, and I know that Open Source is one of the most powerful ideas of our generation. I will communicate as much as possible, because it’s the oxygen of a distributed company. I am in a marathon, not a sprint, and no matter how far away the goal is, the only way to get there is by putting one foot in front of another every day. Given time, there is no problem that’s insurmountable.

  • Wave Goodbye to Anonymity on Facebook

    anonymityJust after I posted a week or so ago reflecting on my return to a more open Facebook existence, they’ve gone and announced that they are doing away with one of the privacy features that was so important to staying anonymous on the site.

    In a blog post posted yesterday, Facebook quietly announced that they were getting rid of the ability to hide your name from searches – stating that it was irrelevant since people could still click on your name in comments that you make on other people’s timelines.

    In the words of Michael Richter – Chief Privacy Officer:

    people told us that they found it confusing when they tried looking for someone who they knew personally and couldn’t find them in search results

    Well, too bad for them. If I choose to be hidden from search results, then it’s my conscious choice. Facebook shouldn’t be second guessing the reasons for users to wish to remain harder to find on the site.

    Apparently a ‘tiny’ proportion of Facebook’s billion plus users were making use of the privacy setting, which eh… still equates to a huge number of people. It shouldn’t really be any surprise, given that the settings were so unintuitive to find and use. Make something hard to configure, and you have a perfect excuse to remove it later when the adoption rate is relatively low.

    This move essentially means that there is no way to keep out of the spotlight on Facebook any longer – confirming my belief that Facebook is designed to incrementally pull you further in to the network, even when you purposefully want to remain on the outskirts. Even if you restrict all of your posts to a limited number of people, you are still going to have to contend with the fact that people will be able to find you in searches, and explain why you have decided not to ‘confirm their friendship.

    The only way to get around this will be to use a fake name and e-mail address, but that is forbidden by the site’s policies, and could see you booted for good.

    Maybe that wouldn’t be such a bad thing.

  • Observations from a Facebook exile

    A number of years ago I found myself staring at my laptop, fretting over how to best represent myself up in a single paragraph – for MySpace, none the less. It was at that point that I decided that enough was enough. One by one, I deleted my various ‘social networking’ accounts, before that was even really a word we attached too much baggage to. There wasn’t any pomp or ceremony; no feigned outrage. I simply dropped off the radar.

    It was liberating.

    More than any other network, leaving Facebook was the most satisfactory, and I wrote a blog to explain why that was after a few months of questioning. A lingering anxiety about what other people’s perceptions faded away. There was no pressure to think about what audience my comments were being directed towards; how I should present myself; or what things I could and shouldn’t say. I didn’t spend time flicking through the profiles of people to check up into what they were doing, and didn’t inevitably feel like I was being left out somehow. There wasn’t the same feeling that everybody in the world was having a massive party, and that even if you were invited, it was just to be polite.

    After a few days, the constant stream of mundane updates from people who I wasn’t even that friendly with in person gained perspective. The behaviour of those whose social interactions were wound up so tightly into the fabric of Facebook, referencing it in all sorts of situations, began to seem increasingly unusual – just as the acts and seeming communitas of those deeply embroiled in drug use are impenetrable to those who are not going through the same experience. Facebook seemed like a bizarre addiction that I was glad to be rid of.

    But there were consequences.

    drowning in data

    Whilst being removed from immediate exposure to every detail of other people’s lives was undeniably a relief, it became clear that there was very little in the way of a middle ground in this regard; many people who I was in touch with beforehand just disappeared completely. In a way, this was a great test of seeing who was interested enough in you to continue to stay in contact, but it isn’t really that simple. I discovered that I no longer knew anything about nights out organised by friends, as ‘invitations’ had been sent out online. When I challenged people about this? The response was simple: “Well you’re not on Facebook.” The default mode of communication had switched in people’s minds, and if you weren’t there too, then that was your problem.

    This carried on into other areas. When deciding to terminate my account, I was painfully aware that there were a number of people who I dearly wished to remain in touch with, but who stayed in different cities that were strewn across the globe. I dismissed this at the time by asserting confidently that if we really wanted to speak, we would do so; Facebook isn’t the only way to communicate on the web after all. Thing is, whilst that might be a nice idea in theory, trying to get other people to make the mental shift towards sending e-mails rather than what they have become used to turned out to be a fool’s errand.

    It was this that eventually led me to the position that I held up until the recent past. Upon travelling through America with no phone, and no way to contact people that I met, I decided to sign up for a Facebook account that I would keep entirely for people who I didn’t get to see in real life. I used a fake name and details; kept the privacy settings as tight as possible; and told everybody else that I simply didn’t use it anymore.

    To some extent, it worked. I was buffered from most of what I had hated about the network so much in the first place, but it brought with it its own variety of problems. What happens when friends of your friends add you? You can’t exactly explain to them that you aren’t accepting the connection because it’s for people in a different place, because… well, so are they. What do you do about people in your own city that you don’t see very often, but for legitimate reasons? Are they excluded? Then there was the difficulty of dealing with other people giving you away by tagging you in posts (which you can’t do anything about if it’s on their timeline).

    I’m back.

    facebook list

    Recently I decided that it was time to open the floodgates.

    In the time I had spent living a secret Facebook existence, there had been changes. After consistent challenges from privacy advocates – including pressure from the European Commission – Facebook introduced additional controls to allow users to filter who saw what content. This was a welcome two finger salute to Zuckerberg’s totalising vision of people only having ‘one identity’. It meant that if you only wanted to see updates from certain people, you could. If you have to accept somebody as a friend, but don’t really want them to see everything you post, then you can sort that out as well. It was far from perfect, and remains so to this day. Many people are unaware of the possibilities; the settings are complicated and spread across different parts of the site; and the format is subject to such constant change that even users who are clued up can get confused in the process. However… it was a start. If I’m going to have a connection with someone halfway across the world that I’ve met once at a party, then I may as well have the same with people that I see every weekend. At that point, whether or not their tangible friendship is any more or less authentic is largely irrelevant.

    It could well be the case that this is the inevitable result of the clever honey trap offered up by Facebook; offering more and more incrementally until you find yourself completely immersed in their network. It probably just underlines and demonstrates the hard truth that the only way to really avoid becoming sucked in is to delete your account completely. However, I don’t feel particularly bad about it anymore. I’ve put my qualms to one side. Years of working in marketing have meant that I am comfortable with the balancing act that is required, and frankly… it’s just a tool to promote the things that I am interested in. My real friends are still the ones I go drink copious amounts of whisky with; or cook with; or have long Skype conversations with. Facebook doesn’t have the same sort of hold, because the importance I place over transient relationships has diminished with time. I know who and what is important to me, so it doesn’t really matter anymore.

    Insights from the Prodigal Son

    It’s been a few weeks since I slipped back into the fold now, and it’s been interesting. Here’s what I’ve observed so far:

    • People really do post the most inane drivel. That goes without saying, but the sheer extent of it is almost unbelievable. People that I respect in real life come across as preachy, argumentative, naive, and simple-minded.
    • Despite getting bugged for years about signing up to Facebook, there was no massive rush for people to connect. Instead of actively seeking out others, people connect in a gradual way. I would say it’s organic, but it is heavily influenced by the prompts and suggestions offered by the service. Users are led in everything they do; passive rather than proactively engaged. Very few people actually use Facebook anymore with any sort of excitement or depth; it’s just something that’s become a ritual.
    • People check up on others a lot more than they post.
    • There is a severe drought of good original content. Rather than posting blogs, articles, poems, pictures, or things they’ve created, the same memes and drab political commentary is shared and re-shared without second thought.
    • The initial friend request is the only interaction I have had with almost all of those I’ve connected with since coming back onto Facebook ‘properly’.
    • People fail to respond to chat messages, despite appearing online, and actively resent any initiation to talk as some sort of intrusion. Coming from a web culture where you logged on to talk in this very manner, it boggles the mind why anybody would appear online if they have no intention to do so. This especially applies to people who have requested my friendship in the first place.
    • Even with contacts arranged into groups, there is still a strong inclination to default to the widest possible audience. That applies equally to reading, as well as publishing content. It’s difficult to resist looking through the full list to see what’s going on when you know it’s just a click away… and even though you know the lack of value.

    Let’s see what happens next.

  • A Critical Look at Facebook’s Proposed Facial Recognition Feature

    facebook facial recognition

    A couple of weeks ago I was asked by the Open Rights Group to write an article up on the latest round of changes to Facebook’s various privacy policies. One of the changes relates to the extension of the ability for Facebook to deploy facial recognition software. Whilst not currently available in the EU as the result of a previous challenge, it caused quite a stir to see this idea raising its head again.

    To be completely honest, I had very little opinion on facial recognition software on social networks at the time, and said as much. I couldn’t immediately see what the problem with it all was, and fully expected it to be just a knee-jerk reaction by those keen to jump on any changes made by Zuckerberg and co. As a result, I went into this with open eyes and an open mind, to see what I could find.

    You can read all about it over on the Open Rights Group Zine.

  • Response from John Mason MSP and Anas Sarwar MP on NSA/GCHQ Surveillance

    After the revelations last week concerning the active weakening of encryption technologies by the NSA and GCHQ, I used writetothem.com to get in touch with my local MSP John Mason, and MP Anas Sarwar.

    The message I sent to John is below, with a similar variant used for Anas Sarwar:

    Dear John Mason,

    Yesterday a number of major media outlets published revelations that GCHQ, in partnership with the American NSA, have been systematically working to defeat encryption systems used on the Internet. Despite a move many years ago to have vulnerabilities inserted into encryption software being defeated, these agencies have clandestinely used their considerable resources to do this extra-legally.

    In actively reducing the integrity of secure communications, GCHQ has also weakened the protection of consumers online. With un-named vulnerabilities being implemented into systems that we have been led to believe are safe, such as online banking, and e-commerce, these have been opened up to exploitation by third party hackers. The Internet is a more dangerous place because of these actions.

    Much is still unclear about the capabilities possessed by GCHQ and the NSA, such as what technologies that are now vulnerable. Answers need to be provided, as these agencies have far over-stepped their remit, effectively engaging in mass surveillance of their own citizens, in breach of the right to privacy afforded by the various International conventions.

    Whilst I understand that this can arguably be classed as a reserved matter, I believe that it is so important that the actions of GCHQ cannot be left un-challenged. I ask that you would publicly challenge GCHQ for details of the technologies that they have exploited; to cease the invasion of the privacy of those in Scotland; and to demand that the UK Government explains why this has been allowed to happen.

    I look forward to your response,

    Yours sincerely,

    Stephen Blythe

    secure email

    I have always found John Mason to be helpful, and determined to stand up for his constituents. His response is below:

    Dear Stephen

    Thanks for your email.

    In the first place I am happy to agree with your main points that GCHQ or whoever should not be spying on their own citizens.  You can quote me publically[sic] on that if you want.

    However, how to deal with it is more difficult.  In the first place I think there is wide public support for spying by the state on suspected terrorists and in fact when we do see terrorist acts we often have a public reaction as to why the state had not been more proactive in clamping down sooner.  The film ‘Minority Report’ (I think) raised some of these questions in how far the state goes in preventing crimes happening.

    Secondly, I believe GCHQ has the full support of the UK government/establishment.  They see it as their job to do all this kind of thing.  So asking them not to do it is a bit like asking a cat to stop being a cat.

    Thirdly, my guess is that the UK establishment is also spying on the Scottish government.

    On a personal basis, I tend to work on the assumption that my phone calls may be tapped, my emails and texts are likely tobe read by people who should not be doing so.  Can we change all this?  I’m not sure.  I would certainly likely to and am happy to support any campaign on this.  Whistle blowers are certainly part of the answer.  Unless we can get insiders to go public, I doubt we will find out much information that the establishment does not want us to have.

    I am happy to discuss any of this with you face to face if that would be easier.  I guess I am a bit sceptical but I am open to persuasion that things can be made better.

    Regards

    John Mason

    The response from Anas Sarwar is below:

    Dear Mr Blythe,

    Anas Sarwar MP has asked me to thank you for your email below regarding allegations about data collection and sharing by UK intelligence agencies.

    These are, of course, extremely serious allegations and it is vital that they are thoroughly investigated and that we ensure there is effective oversight and a clear legal framework to oversee our intelligence operations.

    Mr Sarwar appreciates that our intelligence and security services undertake vital, often unrecognised, work to protect our security and to counter the threats we face. Given the global nature of their work it is also crucial that our intelligence agencies are able to share information across international borders with our allies, including the USA.

    However, he also believes there needs to be public confidence that our intelligence agencies are themselves law-abiding and accountable, and that any intelligence information received from the USA or any other country has been obtained legally.

    These recent allegations have caused real public concern and underline once again the need for effective Parliamentary and Ministerial oversight of all three of our intelligence organisations. The Government have been asked a number of questions about these allegations in the House of Commons and by the Intelligence and Security Committee. The Committee was set up in 1994 to examine the expenditure, administration and policy of the country’s intelligence agencies, and is currently looking into the issues around GCHQ that have been raised by recent events.

    Mr Sarwar has asked me to assure you that he will continue to monitor this important issue closely and will try to raise some of the points you mentioned with Government Ministers in Parliament ducharlotte.methuen@glasgow.ac.ukring Ministerial question time. [sic]

    Thank you once again for writing to Mr Sarwar and sharing your views with him.

    Yours sincerely,

    Yassar Abbas
    Office of Anas Sarwar MP
    Deputy Leader of the Scottish Labour Party
    Member of Parliament for Glasgow Central

    Rm 221-223 Portcullis,
    House of Commons,
    Westminster,
    London,
    SW1A 0AA.

    I since have invited John Mason to come and meet with the Glasgow Open Rights Group members to discuss the issues involved.

  • The NSA, GCHQ, and Encryption. What’s Going On?

    encryptionIn the past few days, more details have emerged about the sheer extent of the surveillance being carried out by both the NSA in America, and GCHQ in the UK.

    Whilst the initial news that these intelligence agencies have been intercepting massive amounts of data was a shock, the latest round of news is perhaps the most alarming of all. PRISM had an apparent budget of $25 Million. ‘Bullrun’ has a value of closer to $250 Million.

    A surge of web users have reportedly moved to increase the amount of encryption they use on a daily basis after discovering the extent to which their unsecured communications were being monitored. Now, it turns out that that much of that encryption could well have little effect on the ability for Government bodies to snoop.

    This is a development that has massive implications for our use of, and dependency on, the Internet itself… yet because of the subject matter, has not garnered as much coverage as it should have. The articles from the Guardian et. al give an insight into what is going on, but do not go into specific details of the technologies at risk, and can be inaccessible to somebody who is not already familiar with issues relating to encryption.

    What’s the problem?

    • When encryption first was introduced online, there was a concerted effort by Governments to require systems to have in-built weaknesses to ensure they retained an ability to access it; the ultimate master key. This was defeated after a hard-fought, cross-political campaign. However, the NSA and GCHQ have gone ahead and achieved the same result, without legislation, by utilising their considerable resources.
    • The intelligence agencies have deployed multiple tactics to ensure they have access to data – whether it is encrypted or not.
    • One of the tactics includes the weakening of encryption systems by implementing vulnerabilities into their architecture. This means that even the most theoretically secure encryption services can be exploited to reveal the information.
    • Encryption is not just a tool for political activists or paranoid geeks. Every day we rely on encryption to securely log in to our bank accounts; buy things online; save usernames and passwords; and keep the likes of our Facebook accounts from interference.
    • By systematically targeting encryption to weaken its protections, the NSA and GCHQ are also undermining the integrity of all of our communications online; the basis of the global ‘information economy’.

    How can I protect myself?

    At the moment, it isn’t clear exactly what services have been manipulated, and what have not. Speculation is rife over whether actual protocols used (such as HTTPS for secure web browsing) have been compromised, or whether it is simply specific companies that have been coerced into providing covert ways into their services. SSL for example – indicated by the presence of the padlock in the address bar – has been shown to be extremely vulnerable given the way that the ‘certificate authorities’ who sign off on the transmission are susceptible to attack. As Orwell Upgraded puts it: ‘Who looks after the keys?’ Even the much lauded article by security expert Bruce Schneier on this topic seems contradictory and unclear in places. (“The NSA has huge capabilities – and if it wants in to your computer, it’s in. With that in mind, here are five ways to stay safe” – Eh?!)

    However, this technology is not available to everybody, yet. Your local police force will not have access to this technology, nor your employer, nor the opportunist hacker. It wasn’t too long ago that even Scotland Yard were reporting that the use of TrueCrypt encryption on David Miranda’s laptop rendered the data ‘extremely difficult to access’. The NSA is still reportedly deploying many of the bread-and-butter tactics used by hackers for decades, including brute-force attempts to access accounts by mathematically ‘guessing’ passwords. If they did indeed have a golden bullet to decrypt all secure material, then there would be no need for this. Edward Snowden himself, the exiled NSA contractor who leaked the documents in the first place, has confirmed that ‘properly implemented crypto systems‘ work; the issue being the lack of security that surrounds those systems in the first place.

    There are still steps that can be taken to make it more difficult for your data to be accessed. Whilst not ideal, for the everyday web user, taking a few extra steps can mean that your data is less likely to be intercepted than somebody who takes no steps at all. There’s that well-worn tale of the man who, when faced with a lion, puts on trainers. When someone points out that he’ll never be able to out-run such a powerful beast, he simply replies that he only has to out-run everybody else.

    No, we don’t know who to trust just now, but you can still take steps to improve your security:

    • Make use of high entropy passwords. Never use the same password for more than one service. LastPass is one of the best ways to manage this. Whilst stored in ‘the cloud’, it makes use of end-to-end encryption, which means only you should theoretically be able to decrypt its contents.
    • Encrypt your data with 4096 bit encryption where possible.
    • Use open source software that can be scrutinised by the online community for weaknesses. Avoid commercial, ‘closed’ software from a vendor that can be more easily manipulated. TrueCrypt is one of the most widely used and respected. Whilst we currently don’t know about its status in this whole affair, it’s one of the best bets.
    • Encrypt your Internet traffic with a VPN, or use Tor.
    • Use extensions such as HTTPS Everywhere to ensure you are always using the most secure version of a website where available.

    Make your data as difficult to access as possible. Don’t just leave the door wide open.

    What now?

    Good question.

    • People need to know about this and why it’s important, not just be blinded by the technical speak. Spread the word, explain to people, and get them to act as well. – (Share This on Twitter)
    • Sign the Electronic Frontier Foundation’s petition to demand answers to what is going on. (US link hereUK/International link here).
    • Write to your local MP and demand that they challenge the UK Government to give answers on this. Write to your MSP and do the same with the Scottish Parliament; it might be a reserved issue, but they still have the power to speak. Cause a fuss until they listen.

    This is a dark time for the Internet, but it doesn’t have to stay that way.