Showing posts with label technology. Show all posts
Showing posts with label technology. Show all posts

Thursday, September 13, 2007

Life in the Slow Lane

Greetings, road warriors.
Hold infinity in the palm of your hand
And eternity in an hour.
-- William Blake, Auguries of Innocence

This post is about commuting; specifically why I refuse to do long commutes. I don't really understand why people put up with long commuting. Some of my coworkers get up at 4 AM to get to work on time (8 AM), twice a day wasting in traffic more time than it takes to travel by train from Rome to Naples. Where do I start with the problems here? That kind of squandering of human life is so egregious that I don't even know where to start to try to attack it: res ipsa loquitor! If that res still isn't very loquacious, read on!

In an earlier post, I quantified how much you pay labor-saving machines for each hour of chores they save you; here I'm going to figure out how much you're paying yourself to live in a cheap neighborhood and commute to a good job.

Tinned Nation

On average last year, Americans spent 50 minutes per work day commuting to and from their jobs; mostly in a sitting position within oversized metallic cans on wheels. However, like the aforementioned coworkers, over 3.4 million Americans spent more than three hours per day commuting to work. If these extreme commuters value their time at $25/hour and work 20 days per month, they're spending $1500 of their time every month for the privilege of living where it's cheap. Unless housing is drastically more expensive where they work, it's just not worth their time.

Leisure sucker

Commuting is more than just a monetary problem, however: the less free time you have the more precious it becomes. If you're awake 16 hours a day, work 8 hours and spend 2 hours keeping the household together that leaves just 6 hours of discretionary free time per day. If three hours is sucked up in commuting, you have half the time to pursue self-development.

Greeks to the Rescue?

Aristotle thought the best division of waking hours was to spend 6 hours working, 6 hours resting and 6 hours pursuing some leisured activity: being creative and exercising parts of your body and intellect for the shear joy of it. The 8-hour work day already overbalances this ancient ideal; why tip it further into job-is-everything territory?

Personally I'm dismayed with the fact that the remainder of peoples' time usually has to go towards wakeful resting (like watching the tube), and not the active creation of interesting life, tradition and culture. I want life to be more participatory: we should be having a good time with the freeboard that going to work gives, if the work itself isn't fun (a harsh reality I'm trying to avoid).

Staying Un-Canned


What are some ways to keep our commuting hours down? How about the following for a start;
leave comments if you have more ideas.

  • Arrange to spend one day a week telecommuting (if possible)
  • Use a home office
  • Rent an apartment close to your job (and price out the time cost of your commute if you live far from your job - you might consider moving then)
  • Live/work arrangements are also great
I hope I'm going to be able to dodge nasty commutes. We'll have to see if that's going to be possible.

Take care, and stay out those cars as much as possible!

LeDopore

Friday, August 31, 2007

Heating with Flops

Greetings, fellow old-world primates.

Today I'm going to flesh out an idea a dear friend of mine had: that waste heat from high-performance computer facilities could be used to heat cold regions of the world.

We humans evolved our big brains in Africa, where it's nice and warm. For better or for worse, these big brains have allowed us to develop means of keeping our bodies at African temperatures even at polar latitudes, allowing us to conquer the planet.

Technology (be it fire or clothing) has always been a factor in allowing our spread into frozen zones; today I'm going to look into something a little higher-end.

Computing in Vegas

A friend of mine works for Cafe Press, an online clothing-designing company which recently moved their main data centers to Nevada. The reason for this move was an unusual one: proximity to the Hoover Dam means cheap power to run the site's computational muscle.

In fact, data centers can generate an enormous amount of heat. A thousand processors working at 100 W each consume 100 kW of electricity: about 50 households' worth. With electricity costing 15¢ per kWh, that's over $130 000 per year in electricity costs alone, and that's before factoring in cooling costs.

Computing in Siberia


Suppose instead that data centers were built where you want to generate a lot of heat anyway. that same 100 kW data center could potentially provide heat most of the required heat to a shopping mall. How economically feasible is this? Let's look into two possible scenarios. For the sake of simplicity I'm going to assume enough people will soon do the Cafe Press trick that electricity costs even out globally around 15¢/kWh.

Scenario A: 1 fixed data center in a place cold in winters.

Here, you'd build a 1000-CPU data center for $500 000, and half of the year you'd be able to use 80% of the waste heat from the data center to heat a mall. Together, you and the mall would save $52 560 in heating costs per year of operation; more if you can use some waste heat more than half the year. Even in the summer, data centers could be used to provide hot water.

Scenario B: 1 data center in a shipping container, moving from pole to pole

Sun Microsystems' "Project Blackbox" will build you a data center in a shipping container already. Imagine having a deal with two different malls, one in each hemisphere, so that the waste heat of the data center could be used always. You'd have two extra expenses: container shipping expenses (about $10 000 for the round trip) and four weeks annually of down-time, but you'd save $100 000 in heating costs. Overall, you'd have to spend 8% more (or $40 000 as a one-time expense) on your computer hardware to compensate for the downtime, but that should be just-about recouped after the first year of operation.

Three Moore's Laws

Technologically, the use of waste heat is only going to make more sense in the future. There are three relevant Moore's laws here: performance/watt, performance/$ and bandwidth/$.

The most familiar Moore's law statement is that computing power doubles every 18-24 months, but one should also look at power efficiency and bandwidth trends. Power efficiency has been climbing slower than computing efficiency, so today's $1500 PC uses more energy than a $1500 PC from a decade ago. Conversely, bandwidths have been doubling more frequently than CPU speeds. Therefore, in the future, bandwidth (especially on the backbone of the Internet) will be too cheap to matter, and the ratio of power expenditure to computer hardware expenditure is only going to increase.

Therefore re-using computer waste heat is only going to become increasingly lucrative in the future, so it's a technology that should be on the up-and-up.

Conclusions

It's already cheaper to operate data centers where power is cheap. I think now it's also cheaper to coöperate with public buildings (which tend to be big enough to act as thermal flywheels to smooth out diurnal heat supply needs) to supply waste heat from data centers. I haven't worked in the added costs of the data center's floorspace, so it's not yet a complete no-brainer to use computers instead of /along side of traditional furnaces, but future trends certainly seem to be pointing in that direction.

Yoursfor a Greener Cyberspace,

LeDopore

PS This post printed with 100% recycled electrons

Monday, August 27, 2007

How Much do You Pay Your Machines?

Greetings, Robot Lords.

The Pitch

How much do you value your free time? In Stephen King's The Stand, the Walkin' Dude comes by Mother Abigail's place in the guise of a vacuum cleaner salesman, making the pitch that he's not actually selling her labor-saving vacuum cleaners. Instead, he's selling her cool lemonade sipped in the shade on a hot day, time to lazily read a novel, or time to do essentially whatever Mother Abigail likes best. The premise is simple and appealing: we buy (or make) machines which save us drudgery, and then allegedly have more free time.

The Catch


In reality, our time-savers often end up owning us instead. It takes a lot of time, energy and money to maintain every piece of equipment we buy. On the other hand, I have a lot more free time than any subsistence farmer I've heard about, so there must be a good side to this tech too. How do we know if a given piece of labor-saving tech is worthwhile?

The Players' Salaries


One interesting analysis is to figure out what effective wage you're paying your labor saving device for your extra free time. Everything doesn't always boil down to money: it's not as if chores are equally onerous (I enjoy gardening more than cleaning the bathroom), but quantifying the hourly rate of free-time-saving makes for an interesting analysis nonetheless. Here's a summary table, then I'm going to talk a little more about some entries. Here "machine wage" isn't how much you pay per hour of operation - it's how much you pay per every hour of labor it saves you. I've ordered this list in descending order of utility.

ItemPriceCost/yLifetime (y)Hours saved/weekHours savedTotal CostMachine Wage







Dishwasher 500
5 3 780 500 0.64
Non-stick fry pan 100
20 0.05 52 100 1.92
Lawnmower (electric)
4001 10 0.25 130 410 3.15
Newer computer 1500
2 1 104 1500 14.42
Kitchen Mixer200 1 20 0.0096 10 220 22
Melon baller 10
10 0.00064 0.33 10 30
Car 5000 2000 5 1 260 15000 57.69

  • I'm a dishwasher evangelist. I've been responsible for (or at least influential in) the decisions of no fewer than 5 households I know to acquire a dishwasher by hook or by crook. (If you're renting, look into portable dishwashers - that's what I own.) Until today I just always had a hunch that dishwashers were good time-savers, but the hard numbers really nail it for me. Operating a dishwasher (in hot water and dish soap) costs about the same as washing by hand, and by my analysis my $500 dishwasher will save me 780 hours of scrubbing. Since I value my free time more than 64¢/hour, owning a dishwasher is a no-brainer.
  • I just bought a $100 super-high-quality frying pan, with (I kid you not) embedded diamonds as the non-stick coating. So far I have no complaints performance-wise: I get an even heat and the food has been scrumptious every time. As a side effect, I estimate that I spend about 3 minutes per week less cleaning, since now I can use this pan instead of my older stainless steel pan (which was a pain to scrub). Those 3 minutes per week over the 20 years the pan should last amount to 52 total hours saved, so I'm "paying" this machine $1.92/hour for the privilege of not washing dishes.
  • If I were to buy a new computer (something I dream about way too often) I might spend about 1 hour less per week waiting for my numbers to crunch (I'm a "power user": I run intensive numerical operations on a regular basis; for word-processing I doubt a newer computer would save more than a minute or two per week). If the new computer I'd keep for about 2 years, then it would save me about 104 total hours, so upgrading now (for $1500) would be like paying the machine $14.42 for every hour I save not waiting for that progress bar to end.
  • I broke down and bought one of those designer kitchen mix machines the other year. We barely use it, truth be told. If it were to save 15 minutes twice a year, this $200 machine would save us 10 hours of work over its 20-year lifetime. (Inside, I doubt it will save that much time, but the truth hurts sometimes.) It really sucks power too, so I guess its lifetime cost (price + power) will be $220; meaning we're paying it $22 per hour that it saves us. (Note: this mixer brings an invaluable quantity of ancillary joy to my better half merely by gracing our kitchen - which is precisely why this kind of analysis didn't have the last word.)
  • We also own a melon baller! If it saves us 2 minutes a year (we hardly use it), we're paying it $30/hour for the privilege. Maybe single-purpose kitchen gadgets should be contraband.
  • Last (but not least) we don't own a car. I can get to and from work without one (and, considering the parking around where I work, biking is faster), even though it makes doing errands a little more tricky. I estimate I spend about 1 hour more per week doing errands because I can't just hop into a rust bucket. (Aside: if I were to offset time I don't have to spend in the gym because I bike, this 1-hour figure could very well be negative!) In any case, were I to buy a car, over 5 years it could well cost $15,000 in insurance, depreciation, maintenance, parking and fuel. For each of the 260 hours it would save me, I'd be paying it $57.69: a pretty lousy deal. I guess I won't be buying a car until my lifestyle requires one.
The Last Inning

On that note, let me hand it over to you. The numbers I've presented are highly personalized and might not apply to you. I do a lot of serious computing, and even for me a new computer only barely makes sense. I live close to work, so biking is a great option. We do a lot of entertaining, and thus a dishwasher is pretty much essential. If you truly need a car, or if you don't entertain or run scientific computing experiments your personal table is likely to be quite different. Still, I encourage you to do the same sorts of analyses before listenening to the Walkin' Dude.

Rule your 'bots with an iron fist!

LeDopore

Friday, May 11, 2007

Liberty and Bandwidth for All

Greetings, YouTubers*.

In my last post I outlined how our current system of private Internet Service Providers (ISPs) companies is economically wasteful. Although in general the private sector is better than the public sector at providing higher-quality services at a lower cost, with ISPs the product (Internet bandwidth) is a factor of 1000 times cheaper than what ISPs charge. Almost all the ISPs' operational costs come from advertising, distributing and charging for this cheap-as-dirt Internet backbone bandwidth. In other words IPSs are intrinsically so wasteful that publicly-owned networks make sense. This post is going to tackle how I think we should implement municipal data networks.

Letting Demand Drive Expansion

Internet technology changes so fast that it would be unwieldy for a council to try to have a sane policy of technology roll-out which took advantage of the latest and greatest. It would also be hard to periodically gauge the service levels residents truly want. It's much better to make technology policy future-proof, meaning that no new laws or regulations will be required to implement better technology where it's wanted as soon as it's developed.

Here's an example of a future-proof network-building scheme. Have residents pledge (with holds on their credit cards) that they would be willing to pay X dollars for Y service. As soon as a private company notices that enough residents in a neighborhood have pledged enough money to make granting the service worthwhile, they can install whatever hardware they choose which is able to meet or exceed the bandwidth demands Y of all the people who pledged X dollars. The money from the credit card holds would then go into a trust which would pay the hardware companies annuities for as long as the service works (or maybe the trust should be invested with low risk, and 25% of the total equity should be paid to the hardware builder/maintainer each year; since Internet technology becomes obsolescent so much faster than roads it makes sense to make the payment schedule accelerated).

The city would provide all of the (essentially free) backbone bandwidth in exchange for the fact that all Internet services using that bandwidth must be broadcast over authentication-free wireless Internet or users must be able to plug in wired connections for free in publicly-accessible points. (Perhaps encryption could be optional to prevent people from spying, but it shouldn't be mandatory, and passwords must not be secret. With good crypto you can have every user use a different session key, so that even if they know each others' passwords they can't snoop on each other.)

Miscellaneous Points

Here are a few guidelines for details of the policy which might help:
  • The quality of service could be specified by three numbers: bandwidth, reliability and latency-to-backbone; that way users can communicate what's most important for them to the free market.
  • Perhaps users should pay on a sliding scale, with payments tied to the quality of service received, so that there is always an explicit incentive to provide better Internet service.
  • Assuming only 25% of residents who want a given service would pledge for it, maybe the city should match pledges paid out of property tax.
  • Since optical fiber is cheap but expensive to lay, it's a common practice to lay cables with many more fibers than will be needed in the near future. These "dark" fibers can later be cheaply lit if needed. Policies should probably specify that some percentage (like 95%) of the fiber laid to make a network must be dark.
  • Depending on political will, it might make sense to pay for city-wide phone-level coverage off the bat through taxes, and let people pledge for upgrades as desired.
Conclusions

In the Chicago example of last post we saw that the entire city could have a free data network for a one-time cost of under $15 per person. People are probably willing to pay a lot more for much faster connections; the plan outlined in this post shows a way in which a publicly-owned network can deliver services the public wants as soon as their feasible to deliver without wasting money on advertising and accounting.

This plan isn't anti-business either. The local companies which would spring up to supply the network services asked for by the people would have a leg up spreading to other municipalities where this same incentive policy gets implemented. (I am fairly confident that other municipalities would want to emulate the digital utopias which would come from this type of municipal Internet service.)

With some organization, the people can have cake and eat it too: they can pay a pittance in extra tax in exchange for hassle-free, state-of-the-art Internet connectivity. Everybody wins except old-school ISP shareholders. (Sell!)

*Web 2.0 couch potatoes?

Wednesday, May 9, 2007

The Answer is Blowin' in the Windy City

Greetings, chatterboxes.

Today I'm going to outline why I think municipal wireless networks are a good idea. We depend more and more on Internet connectivity for our everyday lives; it's no longer the case that bandwidth is a luxury item only a small niche desires. However, the way we typically pay for bandwidth (through private Internet Service Providers, or ISPs) is tremendously inefficient. I'm going to outline an estimate of how inefficient privately-owned ISPs are, then in the next few posts I'll talk about a way in which publicly-owned networks can be financially and technologically sustainable.

Getting Hosed by ISPs

Bandwidth at Internet backbones is ridiculously cheap: about $1 per terabyte (TB) and falling fast. (Based on estimates of web-hosting costs which allow 3 TB of transfer per month for $5 per month - the $1 per TB might not be accurate to within more than an order of magnitude. I don't specifically endorse the web hosting company I linked to - it's just an example of how cheap backbone bandwidth can be.) A heavy home user might transfer about 20 GB of bandwidth per month, costing their ISPs no more than a few pennies per customer per month.

However, the rates which ISPs charge their customers is three orders of magnitude higher: $20 per month is considered a good deal. That's a markup factor of at least 1000.

There are at least three main expenses other than backbone bandwidth which contribute to the costs of running ISPs:
  1. The "last mile" connectivity between multiple homes and a backbone connection point
  2. Advertising and promotion
  3. Billing customers
Going Public

If a publicly-operated free (as in beer) municipal Internet network existed, there would be no need for costs # 2 and 3, and I postulate that #1 could take a big hit too by allowing better technology to be used. I think that one of the major reasons private ISPs are scared to deploy city-wide mesh wireless networks is that if users shared their passwords with friends, they could lose customers. Instead they've opted for wired networks (through DSL or cable) which are probably a lot more expensive than wireless mesh networks so they can be sure you don't share your account with friends.

Why do I think mesh networks are cheaper? The City of Chicago plans to roll out a city-wide wireless mesh network for only $18.5 million. A city-wide network would supplant not only ISP communication, but if a few Asterisk servers were part of the setup you could replace aging telephone lines and cellphones with voice over IP (VoIP), obviating the need for phone companies, whose costs are also dominated by the three numbered items above.

Savings

How much do Chicago's 3 million residents currently pay for phone, Internet and cell phones? If we assume one ISP line (at $20/mo.) and one land line (also at $20/mo.) for every 4 residents and one cellphone (at $30/mo.) for every two residents, we'd estimate that Chicago spends $900 million per year on combined data services. Even assuming Chicago's network costs double the estimate with a one-time cost of $40 million, a municipally-funded wireless network is an exceedingly good deal.

If the backbone bandwidth cost were approximately one penny per resident per month it would not be worth the city's while to try to charge people for their individual bandwidth usage, just as we don't try to charge people who use streetlights more for their fair share of electricity costs to the city.

Conclusions

Even if implemented poorly, a publicly-owned data network would give astronomical cost savings over the current arrangement. There are still the potential pitfalls that a publicly-owned network might be terribly cost-inefficient, or that it might not give the quality of service expected by the residents. However, in my next post I will unveil a plan which addresses both of these woes.

Until then!

LeDopore

Saturday, May 5, 2007

Keeping Your Autograph Yours

Greetings, John Hancock.

In today's post I'm going to talk a little about digital signatures and hashes. I'm going to talk about hashes and their use in cryptosystems, and then I'm going to give some crypto “recommendations” for how to stay one step ahead of potential digital signature forgers.

I'm not really sure why, but I just love to learn about security mechanisms, how they can be beat, and how you can really foil intruders. If you don't share my passions for math and security, maybe this post won't hold your attention; I promise I'll post something more sensational soon. If, on the other hand, you read Cryptonomicon and were starved for the numerical details behind the characters' plots, read on, and be satisfied!

Hype Warning

Let me get one thing clear before we start. Current digital cryptography is secure enough for you to rest easy – your weakest link is not going to be that somebody spends thousands of CPU hours to do a direct attack on your data. If somebody wants to steal your information it's much easier to use a “side channel attack,” in other words it's easier for a data thief to push malicious key-logging software onto your Windows computer, infiltrate your organization, or record the sound of your keyboard to get sensitive information than it is to do a brute-force attack on even a relatively weak cryptosystem.

However, I think cryptology is fun, so today I'll talk about a security practice which will keep your digitally-signed documents über-safe. If that appeals, read on!

Digital Signatures


The Internet provides a remarkable degree of anonymity to its users, which can be both a blessing and a curse. (LeDopore isn't my real name, by the way. I enjoy being able to post unfiltered opinions that will never be tied to C.V.-related Google searches. I can prepare a face to meet the faces that [I] meet and have only a select few be able to link my masks.)

The Internet would be much less useful if we couldn't establish the authenticity of any particular source. Because of its decentralized nature (which is one of the reasons it's so robust - 0 seconds downtime since the 1970s is pretty impressive), there's no way to have a trusted path between source and sender; we must let the message itself testify to its authenticity.

Public Key Cryptology

When a message is digitally signed with public key (asymmetric) encryption, you can quickly verify that only a particular sender (actually, a sender with access to the key's corresponding private key) could have sent it. We say "asymmetric" and "public" because for every secure channel, there's one public (in other words, you want everyone to know it) and one private (secret) key; these keys are different (hence "asymmetric").

Let me give a hallway analogy to explain what public key encryption can do. Imagine an apartment building hallway with rows of doors with mail slots, and with glassed-in locked message boards beside every door. You can slip a message into anybody's slot without anyone else being able to read it, and you can post anything you like in your locked message board so that anybody can see it an know you sent it. Slipping a message into others' slots is equivalent to encrypting it with their public key: they need their private key to read it. Posting behind glass is equivalent to encrypting it with your private key: if you need your public key to decrypt it, it's impossible that the message was generated with anything but your unique private key.

For a fully-secure connection, you can encrypt a message first with your private key and then with the receiver's public key; then only they will be able to receive it, and they can be sure that the message came from you. (The hallway metaphor breaks down, since with public key cryptology you can do the equivalent of slipping a message board of yours into someone else's mail slot.) Thus people who have never met can exchange fully private information, which is why you can buy things with your credit card online. (A mixed blessing?)

One of the big potential holes in public key cryptography is that you have to be sure you know what public key to use when sending a message to somebody. The only way around this conundrum is to go through a security broker like VeriSign, whose job it is to physically go to companies to sign hand-delivered public keys with their master VeriSign private key, which your computers are pre-programmed to trust. (Man, talk about a single point-of-failure; if anybody managed to factor VeriSign's product-of-primes it would be "game over" for lots of digital security. If you don't like VeriSign's game, you can always physically share symmetric keys through a trusted, i.e. non-Internet, connection first. That's how I've set up my ssh into work; not that I don't trust VeriSign, but you never know...)

The RSA Algorithm

Signatures typically work through the RSA public key algorithm, which gains its cryptologic strength from the fact that it's easy to check if a number is prime, easy to do modular exponentiation (which I'm not even going to define here), but difficult to factor the product of two large prime numbers. (If you're interested in the math behind RSA, try chapter 1, page 42 of Algorithms, by S. Dasgupta, C. H. Papadimitriou, and U. V. Vazirani, freely available online and very well written).

The Need for Hashes

Theoretically it would be possible to sign entire documents with RSA, and to conduct whole conversations by passing messages through public-key cryptosystems. However, although using RSA with the proper keys is orders of magnitude faster than cracking it (which, as far as I know, hasn't been done ever with long enough keys), it still takes quite a few clock cycles. Typically then you don't send your secret info directly through RSA, but you use a block cypher like AES (Advanced Encryption Standard).

Aside: AES

AES takes a secret 128-bit shared number and generates a bitstream of random-looking data. Both the sender and receiver share the same random 128-bit key through a secure method like RSA, then they use AES on the 128-bit key to make a stream of random-looking bits. Since both sender and receiver have the same key, AES is a type of symmetric key encryption.

AES is in many ways like a random-number generator on steroids: the 128-bit number is the random seed, and from it you can generate as long a random-looking bitstream as you like. The sender of messages ("Alice:" in cryptology it's always Alice who has some interesting secret message) then takes her digital message and the random bitstream and performs the exclusive OR operation between them. (I.e., if the random bit in the bitstream is 1, flip the message bit from 1 to 0 or vice versa, but if the random bit is 0 do nothing.) The result is a totally unintelligible to everyone but Bob (the ever-listening, trusted confidant of Alice), with whom Alice has shared the 128-bit key. Since Bob can use AES to make exactly the same bitstream as Alice, he knows which bits have been flipped, and thus can recover the original message by flipping the bits back.

Aside Over

Back to digital signatures. Just as it's impractical to sign everything with RSA directly, it would take a lot of CPU cycles to sign your documents with RSA. Instead, usually you'll sign a hash of the document you want to verify came from you. In the hallway analogy, think of it as distributing a book you liked to everyone, and then slipping the title page into your secure glassed-in message board so that everyone can see that you endorsed it.

Making a Good Hash Function

There's an immediate problem with the title-page strategy: other people could write a different book with the same title page. If the new interloping book contained inflammatory remarks, you could get into a heap of trouble. Ideally, what we want is some digest, or hash, of your book (other than just ripping out the title page) which had the following properties:

  1. Relatively fast to calculate
  2. Sensitive to the entire document, not just one page of it
  3. Small enough to fit into a message box
  4. Nearly impossible to reverse, i.e. find another book with the same hash
If you have a hash function which satisfies all of the above properties, you can speedily sign documents by distributing the bulk of the document through insecure channels, and then making a hash of the entire document and signing just the hash with your private key. Then receivers wanting to check the authenticity of your document can take the insecure copy of the document, hash it in exactly the same way you hashed it (there are publicly available hash algorithms like MD5, SHA-1, and WHIRLPOOL), and then compare the hash the digitally-signed hash you just made (by passing your signed hash through your public key).

Let's go over why each of the four above points is important. #1: if it takes a long time to calculate the hash, you waste time. (That's why we don't sign whole messages with RSA, right?) #2: every bit of the hash must depend on every bit of the original document in a unique way. (This way changing even a single character in the document produces a completely different hash, making forgery difficult.) #3: hashes are typically only a few bytes long. (MD5 is 128 bits long, SHA-1 is 160 bits and WHIRLPOOL is 512 bits - all small enough that signing them is no big deal.) #4 the hashes should be computationally easy only in one direction: so it's hard to make a message with a specified hash. When I say "hard," I mean that ideally it would take about 2^(hash length) tries to find a message which would have a specified hash.

This last point is vital: when you make a digital signature, you're claiming authorship for every message which has that hash, since the hash is the only thing you sign. (If somebody distributed a forged document withe same hash as a document you signed, they could claimed you signed the forgery.)

Hashes are also used to protect passwords. You want programs to be able to identify if a password was correct, but for security reasons it's a bad idea to store the password itself on your disk. To get around this problem, most software stores only a hash of your password on your disk. To check that subsequent entered passwords are correct, programs do a hash of the entered text and compare it to the stored hash. As long as the has has good crypto strength, people with read-only access to the file containing the passwords will not be able to guess the password from the hash. (Aside: Windows by default uses an infamously insecure algorithm for storing password hashes, the LM hash, which requires only about 2^36 operations to crack. Even a general-purpose modern computer can brute-force Windows passwords in a few hours, and you can speed that up to a few minutes by using pre-computed rainbow tables. Insane!)

Potential Pitfall: Birthday Attacks

SHA-1 (Secure Hash Algorithm) is used industry-wide as a purportedly secure hash algorithm (i.e. one that satisfies #4 above). It's still pretty good, but it's starting to show its age. One of the best ways to attack the signed hash cryptosystem is to use what's called a birthday attack, named after the birthday paradox (which says if you have more than about 25 people in a room, chances are that two people will share the same birthday - the trick works because the number of possible birthday collisions is 25 * (25 -1)/2 = 300 - the number of potential pairs goes as the square of the number of people).

To do a birthday attack, the villain chooses a message you'd be happy to sign (A, which could be some innocuous legal document to be signed by a lawyer) and an evil message he wants you to sign (B which can be anything). He then looks for strings of invisible fluff (c and d) which he can append to A and B such that the hash of Ac will be the same as the hash of Bd. (The invisible fluff can be a string of mixed spaces and non-breaking spaces, or comments in an .html document, or tons of other things which won't affect the appearance of A and B but will change their hashes.)

Here's the bad news: although for a good 160-bit hash you'd have to make 2^159 guesses of d such that A and Bd would have the same hash, for a birthday attack the villain generates only about 2^80 fluff strings c and d. Chances are that for one of the 2^160 pairs of c'd and d's, the hash of Ac will be the same as the hash of Bd.

Real World Implications

Already there have been successful birthday attacks against MD5 (the 128-bit hash I mentioned), and SHA-1, which is an industry standard, is starting to show cracks as well. In 2005, Xiaoyun Wang, Andrew Yao and Frances Yao have found a shortcut to do birthday attacks on SHA-1 such that only about 2^63 computations are needed. (If SHA-1 were a better hash function, no attack faster than brute force would be possible, and that would take 2^80 operations). Even today, 2^63 operations is feasible with the right hardware: if a teraflop specialty purpose machine (like the Geforce 8800) costs about $500, then to make a malicious pair of messages Ac and Bd in a year you'd need about a billion dollars in computer resources.

Computers are going to get faster, and cryptanalysts (maybe) are going to find faster-than-2^63 attacks on SHA-1. My prediction is that birthday attacks against SHA-1 are going to become widespread some time within the next 20 years.

Staying One Step Ahead


Replacements for SHA-1 are in the works. There are hashes with longer digests which are already public standards: SHA-256, SHA-512 and WHIRLPOOL (with 256, 512 and 512 bit digest lengths), but they haven't been as widely scrutinized as SHA-1. (I bet they're all pretty good though, but I'm not a pro cryptanalyst.) If you're a programmer, consider coding software in a modular-enough way that you can drop in different hash functions into your code easily, and that different hash lengths don't mess up your program.

Until better software comes along, I'd recommend that people working on big, secret important stuff adopt the following two policies:
  1. Always edit a document sent to you before signing it in some unpredictable way.
  2. Always keep a copy of the document you actually do sign.
Point 1 will protect you from birthday attacks. If you change Ac even slightly, the billion-dollar crack attempt made by the villain will be completely worthless, since he has a Bd which hashes to the unmodified Ac. Point 2 will make sure that even if your signature gets broken and somebody claims you signed Bd, you can whip out the document you actually did sign and show that somebody made a pair of hash-colliding documents. (You won't be able to prove if it was you or the villain, but at least there would be reasonable doubt.)

Back to the Real World

Of course, these day's it's much cheaper to hire a spy to infiltrate your organization than to generate a billion-dollar hash-colliding document pair and hope it's signed without modification. I'm a silly crypto-hobbyist for suggesting you should worry about anything but a side channel attack. And even then, I've found that the vast majority of folks are too concerned with their own business to try to hack yours. I routinely accidentally leave my door not just unlocked but wide open, and I have yet to be stolen from at home. The world's a safe place; you don't need to worry about digital security. I just have a little-kid-in-treehouse mentality when it comes to fancy computational methods for making rock-solid crypto. How about you? Do any of my readers think crypto is fun? Should I blog more about it?

Wednesday, April 18, 2007

Local Produce vs. International Peace

Greetings, Macaroni Munchers.

A lot of my friends are concerned about buying food from too far away, in the interests of both helping out the local economy and of reducing fossil fuel consumption. It's a scary thought about how much our food supply depends on non-renewable resources like transportation fuel, and it's appealing to have the visceral connection to what you eat that you can get only from being able to visit the place where your food grows.

Agriculture and the Developing World


The unfortunate consequence of favoring domestic produce, however, is that you deprive the developing world of the much-needed foreign exchange which comes from agricultural exports. In fact, in non-industrialized areas of the third world, pretty much the only thing they produce that we consume is food.

A typical Nicaraguan farm worker earns about $.25 an hour (a quarter the minimum wage of neighboring Costa Rica). The cost of living there may be quite low, but still I'm disgusted by the fact that they could pick coffee for 8 hours and not earn enough money for a singe espresso shot in an American café.

By insisting on buying domestic food, we're just driving developing-world wages down farther. There are plenty of options for Americans: they don't all need agricultural work to stave off extreme poverty. Giving meaningful work to developing nations promotes the sense of coöperation which leads to good feelings and peace.

Dependence on developing nations for food can also lead to peace-making policy. You're less likely to invade another country if you need the food they produce to survive.

Aside: I'm being overly-dramatic. Americans consume on average 3790 calories per day (although some of that is spoilage), so losing even a third of food imports wouldn't spell widespread famine. At the same time, you're less likely to go to war with an entrenched trading partner; the European Union may have ushered in an age of post-historicism, now that individual countries are so economically entwined that it would be sillier than ever to go to war.

Fuel Costs by Sea and Land

Trade and peace aside, many of my friends want to consume as little fossil fuel as possible in getting their food delivered, so they're careful to buy only from locally-grown produce. However, raw distance-from-home is a poor tracker of fuel consumed, since freight by sea is so much more efficient than by land. Let's figure out just how much more efficient it is to ship a container one mile by sea than by land.

By land, a typical mileage rating for a semi truck carrying a 53-foot trailer is about 6 miles per gallon. Page 5 of this document has all of the relevant information: an ultra-sized container ship traveling at 22.5 knots burns 180 tonnes of fuel per day, and carries 10 000 twenty foot-equivalent units of cargo. After a little math, we find the ship transports the same 53-ft container at 44 miles per gallon.

A ship coming to the United States from Chile burns about the same amount of fuel per container as a semi truck traveling about 700 miles, and if people drive 8 miles to the grocery store to buy 50 lbs of groceries in a car rated at 30 miles per gallon, they burn as much fuel per grocery item as that container ship from Chile.

Conclusions

Before jumping on the "local food" bandwagon, please consider the impact of shunning the developing world. Also, consider biking, busing or walking to the grocery store when possible if you're really interested in reducing fossil fuel consumption.

Bon Appetit!

Sunday, April 15, 2007

Killer Cellphones?

"Pronto? MoshiMoshi? Hello?"

I was reading Digg today, which pointed me to an article speculating that cellphones are causing "colony collapse disorder," the name for an alarming phenomenon whereby the majority of honeybees in every colony are mysteriously disappearing. (By the way, this isn't jsut about the honey bees produce. The value of their crop pollination is in the billions per year; would anyone like to post a comment with a more exact figure?) The article sounded interesting until they went off the deep end by vilifying cellphones with a few cherry-picked debunked claims:

Evidence of dangers to people from mobile phones is increasing. But proof is still lacking, largely because many of the biggest perils, such as cancer, take decades to show up.

Most research on cancer has so far proved inconclusive. But an official Finnish study found that people who used the phones for more than 10 years were 40 per cent more likely to get a brain tumour on the same side as they held the handset.

Equally alarming, blue-chip Swedish research revealed that radiation from mobile phones killed off brain cells, suggesting that today's teenagers could go senile in the prime of their lives.

Chilling. Let's go into an account of how much damage a cellphone can do, and let me cite a few studies of my own.

Traffic Dangers


We have lots of evidence that cellphones impair driving ability. A University of Utah study found that cellphone conversations impair about as much as a .08% blood alcohol content, the threshold for the legal drunk-driving limit in many North American states. The World Health Organization says talking on a cellphone while driving increases your risk of accidents by a factor of 3 to 4. Taking a 100-mile drive decreases your life expectancy on average by about one hour, i.e., it has and LED of one hour (see posts with the tags LED and EDD for more, or this one which introduces them). Talking on your cellphone bumps the LED up to three or four hours, meaning that the driving-related risk starts to overcome the old-age-related risk you'd incur anyways if you call people while driving.

Other than impairing driving ability (and repetitive stress injuries from thumb-typing), cellphones aren't going to hurt you. Let's take a look first at the physics of cellphones (which will show them to be benign) and then take a look at the epidemiology of cancer among cellphone users, citing the most thorough study ever done, which happens to be Danish (Long Live Fear-Dispelling Vikings!).

The Physics of Cellphones

Cellphones communicate by broadcasting microwaves to cell towers. They use one of two frequency ranges: either about 850 MHz (the PCS band) or about 1900 MHz (the cell band). The peak power of a cellphone's transmission is about 2 Watts, so the amount it broadcasts into your head isn't more than about 1 Watt.

There are three potential concerns which make cellphones potential health risks: heat, chemical damage, and brain interference. Let's assess each potential risk.

Of Cellphones and Sunbeams

It turns out many of you non-hat wearers heat your head with electromagnetic radiation on a daily basis. A fusion-powered blob of gases over 100 million km away bakes your melon with an intensity of over 1000 Watts per square meter on a cloudless day. If the cross-sectional area of your head is about 3% of a square meter, that means the sun warms your head with over 30 times the power intensity of a cellphone. If cellphone-related heat can cause damage, so can the sun.

Mutagenic Conversations?

The next most commonly-feared etiology of cellphone-related cancer is through the photons in the microwaves causing genetic damage by affecting our DNA. However, the energy in even the highest-energy cellphone photons is far too low: a 1900 MHz photon has an energy of less than 8 microelectronvolts: about 100 000 times less energetic than the kind of photon needed to make any chemical change. At body temperature, random thermal fluctuations give every molecule constant kicks of over 25 millielectron volts: over 1000 times as powerful as a cellphone photon. No cellphone is going to turn you into a toxic avenger.

Nokia Mind Control?

I've seen one more way in which fear-mongers propose that cellphones could harm you:. They think it's possible that the pulses of electromagnetic energy could interfere with brain functions. It's true that neuroscientists use pulses of transcranial magnetic energy to temporarily (and, we hope, reversibly) poke an area of gray matter to try to figure out what it does. Could cellphones be doing the same?

Again, the relative magnitudes are way off: neuroscientists use field strengths around 10 Tesla, while cellphones typically have much smaller magnetic field strengths: around 50 Gauss or 5 mTesla (1 Tesla = 10 000 Gauss: one of those Metric System anomalies). Once again there's a yawning, factor-of-1000 gulf between the strength of a cellphone and the effect size needed to make worrying sane. It's even worse when you take into account the fact that the energy associated with a magnetic field goes as the square of the field strength, so it's more like a factor-of-1-million difference between what a cellphone is and what we'd worry about.

Epidemiology

By now, it shouldn't surprise you to find that the most extensive study done on cellphones (the Danish one I alluded to) "found no evidence for an association between tumor risk and cellular telephone use among either short-term or long-term users." The study followed 420 095 persons for up to 21 years each, and saw that cancer rates were not higher than among the population in general. Breath a sigh of relief, and don't believe the fear-mongers who say cellphones are risky.

What about studies which show a correlation between cancer and cellphone use? There's a dirty little secret in science called publication bias. In a nutshell, it's precisely those stories which seem to defy common thinking which seem most newsworthy, get the most press, and get published. In cases where there's a lot of public interest and attention, it's a good policy to disregard studies with small sample sizes, since there are probably 20 unpublished small studies with null results for every 1 study with a stunning effect that's significant at the 5% level.

Conclusions

I don't know that much about bees, but cellphones are safe to humans, provided that their attention isn't needed elsewhere and that it doesn't over-stress them to have a cellphone. It's not totally outrageous to guess bees might be confused by cellphones, since the Earth's magnetic field is only about 0.3 Gauss. I'm not an expert of bee navigation, but it shouldn't be to hard to experimentally verify the connection between active cellphones and bee death. In the meantime, color me skeptical, especially considering that the article repeats loony fears.

Saturday, April 14, 2007

Upfront Cost Disclosure

Greetings, homeowners.

If you're a regular reader, you'll already know that I have both an environmental and a capitalist streak in me. I don't think these two need be in eternal conflict; in fact today's post is going to outline a way in which we can encourage the adoption of green technologies without messing around with the marketplace.

Good Policy Assumes Laziness

First of all, let me fire a diffuse attack at all of the legislated incentives to get people to adopt new green technology. While legislated incentives can be better than nothing, often the incentives are not proportional to the environmental good done (e.g. giving a fixed tax rebate to cars purchased with better than a certain mileage - there's just a threshold and no proportionality), and almost always these bills can't and shouldn't be passed when the technology has only limited applicability. However, I think that there are potentially many diverse opportunities for incremental improvements that just can't be addressed by legislated incentives. Good policy should automatically reward where it should; good policy is lazy and future-proof.

Virtue should be Its Own Reward

In this post I'm going to outline a way to promote environmental benefits in a natural, non-legislative way. Specifically, we should require that the advertised price of goods reflect the total cost of ownership, and not just the sale price. For example, when buying a house, the only price you would be allowed to advertise should be the sum of the sale price and the forecast cost of 20 years of utilities in the house. This way, houses with the same listed price would be equally affordable, and there would be incentives to build houses that were greener. Let me slow down a bit to unpack all of these comments so that they make a little more sense.

I'm Lazy Too

How many of you have bought a house or rented an apartment without first calculating the expected utility bills? I have never requested past utility statements for any property I've rented, and I certainly haven't done any thorough analysis of properties I'm only marginally interested in. I think I'm pretty typical in my laziness too: while I might try to factor in energy efficiency, I don't have a clear idea as to how much a given setup will affect my bottom line.

Modern economists acknowledge that humans make decision (and big ones too) with imperfect information, which results in less-than-optimal buying decisions. The most common numeric piece of information people take into account when looking to buy a house or rent an apartment is its price; my idea is to fold utility costs into the price from the outset so that people can make a lazy but correct decision as to how much they would like to spend on a heated domicile.

Implementation

If I ruled the world, the list price for all houses would have to be the sale price plus 20 years of expected utilities costs, based on prior use records. (Aside: 20 years is a round figure on the order of the inflation-adjusted doubling time of money at prime rates, so if you were to invest this sum at the time of sale its simple interest could pay utilities from the interest essentially for ever. Perhaps 20 years is a little on the short side.) The sale price would be allowed to be advertised only as a line item in conjunction with the utilities cost and the total list price. Lying would be considered fraud.

Guessing the efficiency of a new building might be difficult, but it should be possible to use statistics to fine any construction company which consistently lowball's the heating estimates of the buildings they make.

The same idea could be applied to automobiles: add the cost of driving 50 000 city and 50 000 highway miles before getting the list price. (Aside: this will come out to around $10 000: enough to perhaps convince many people to buy newer, more fuel-efficient cars. Who would want a clunker when the list price is $11 200? We might be able to persuade car manufacturers to lobby for this idea since it would boost new car sales.)

Perhaps major appliances and computers should have a similar addition to advertised price, maybe also including the mean time until failure. At some point gizmos become too small for these advertising restrictions cease to make sense, but I don't know if this transition happens at the "toaster" level or the "microwave" level.

Lazily Greener Incentives

Consider the implications of my idea on builders and house maintainers. If you build a house that's more energy-efficient, its value to the seller will automatically be higher, since it competes with houses of the same list price. The 20-year cost of heating a poorly-insulated house in a cold climate can top $100 000*, so energy-efficient designs and materials could give a significant edge on the open market.

Moreover, if home buyers were to display a fraction of the eco-chic that Prius-cravers show, perhaps small 20-year heating cost stats would carry the same caché as slim cellphones. In any case, energy efficiency could be reducible to a dollar value, which is great for putting things into perspective.

Conclusions

Let me recap a few of the reasons why I think we should add use cost to sale price to determine the list price of automobiles, houses etc.
  • It's the duty of the government to protect consumers from false advertising.
  • Markets are more efficient when more information is used.
  • It's easier to perform cost analyses once per item sold than once per potential sale.
  • Green policy should provide continuous incentives to make better products, and these incentives should be proportional to the environmental good done.
  • Legislated incentives are rigid, slow-to-implement, and fiscally inefficient.
In summary, let's get our policy into the adaptive 21st century by making the cost advertised closer to what the consumer is really going to pay.

*Friends of mine in Toronto rented a house with typical winter heating bills of $2000 per month, even though some of them opted to turn the heat down and sleep in arctic sleeping bags. I'm sure that if this heating were advertised in the listed rent they would have rented elsewhere. The 20-year heating cost for this Victorian behemoth would have been over a quarter-million bucks: a significant warning to any prospective home-buyer, and a burning incentive for the current owner to insulate better to protect the house's retail and rental value.

Tuesday, March 13, 2007

ExChange in the Weather

Greetings, rain-dodgers.

A few posts ago, I made a case for future-proof policy; that is policy which automatically keeps up with the best that today's technology has to offer. I've advocated the use of results-based prizes for rewarding the discovery of useful medical treatments, since they tend to align public and private interests. Today I'm going to talk about another way we could make our policy future-proof by harnessing the free market: have our government meteorological systems switch over to prediction market-based weather prediction.

The Status Quo


Today, typically large institutions or governments hire meteorologists whose full-time job it is to interpret computer models based (largely) on publicly-available data. It takes a relatively long time for new weather-prediction models to gain acceptance: each one must be academically-verified and promoted, and the uptake of better weather-prediction techniques seems to be a patchwork affair.

At the same time, there are hundreds of math and physics geeks with computer power to spare who like to try their hand at predicting just about anything. Even the private sector has been unable to tap this latent talent pool, as is evidenced by the fact that the Netflix prize has been claimed.

Netflix Prize Exhibits Geek Talent

The Netflix Prize rewards people for discovering new ways of predicting the ratings people give their movies based on which other movies they liked. The contest started on October 2nd, 2006, and by October 15th one team had already beaten Netflix's predictions enough to claim a prize. If even a private-sector firm is unable to efficiently harness the best numerical prediction methods out there, what hope does a government agency have of keeping cutting-edge?

Prediction Markets for Weather Prediction

Imagine instead that any math nerd with a computer and an Internet connection could instantaneously profit by predicting weather better than rivals without having to apply for meteorology jobs. There are already small-scale weather prediction contests (like the WxChallenge), but these are still mostly for bragging rights, not for general-purpose weather and climate prediction.

Prediction markets are like stock markets. You can already buy and sell shares in, for example, Hillary Clinton becoming the Democratic nominee, in an online prediction market. The shares are worth $1 if the event takes place, and nothing if it doesn't. The fact that Hillary's shares trade at about 40¢ means there's a market consensus that there's a 40% chance Hillary will be nominated. Prices fluctuate with every factor that may influence her nomination probability.

If we did the same for weather (and maybe even sweetened the pot a bit to provide incentives for high-volume trading and good predictions) we could find the geeks' market consensus over the chances of it raining tomorrow. Other predictions could be made too, like the total rainfall in a season, or any other season-related information which might be economically, socially or environmentally relevant. Storm warnings could be automatically posted through regular weather channels when the price of storm stocks rose above some (low) threshold, like 20¢.

Probably what would happen is that a few centralized weather servers would emerge which would make predictions about weather at many different locations, while local "old salts" who have a sense for the weather could also make a quick buck while letting the world in on their secret, quasi-instinctual privileged weather-sense.

Conclusions

There is no method as efficient as the anarchy of the market to predict the value of a commodity. If we commoditize knowledge about the weather, we will automatically harness all the disparate knowledges about our turbulent atmosphere to reward the weather-seers and keep the rest of us dry under umbrellas when appropriate.

Stay dry!

LeDopore

PS I have to add a final caveat: if some foreign power (like a government) had deep enough pockets and had a desire to manipulate the market (by, for instance, ruining 4th of July plans by buying shares in it raining everywhere), they could do so as long as they were prepared to sustain a virtually unlimited financial loss. Perhaps a good safeguard in the system would be to include automatic "bizarreness detectors" which would sound an alarm if some fishy market activity starts.

Wednesday, March 7, 2007

Consuming to Curb Consumption: the Case for a new Prius

Greetings, fellow humans.

Today's post is by request. One of my readers who is interested in minimizing his environmental impact asked about whether the energy costs of manufacturing a new car outweigh the energy costs of running an older, less fuel-efficient vehicle. The reader in question bikes to his law firm in all weather but snow, so he's already taken the cheapest (and probably most significant) step towards reducing his transportation-related energy consumption. However, many of us need cars at least once in a while, so it will be fun figuring out how many miles of driving you'd have to do to make buying a new car worthwhile.

Manufacturing a New Car

The Internet's too powerful these days. I thought I'd have to sift through details about modern steel-making techniques to get an estimate of how much energy goes into making a new car. It turns out that Google Answers beat me to it though: the average energy consumption associated with making a new car is 73 Gigajoules. Given that a liter of gas has about 32 Megajoules of energy, that means the energy content of manufacturing a new car is equal to the energy content of about 610 US gallons of gas. Since fossil-fuel-burning power plants are only about 40% efficient, the energy cost of making a new car is equivalent to that of burning about 1500 gallons of gas. (Aside: making cars from recycled steel reduces this energy cost by about 20%.)

Comparing Manufacturing Energy to Use Energy


Now that we know how much energy it takes to make a car, let's see how much you would have to drive a new, fuel-efficient car to make up for the extra energy used in producing it. Suppose that your new car gets about 45 miles per gallon while the old one got only 30. Then, for every 90 miles you travel, you'd save one gallon of gas from the fact that you bought a new car. Since making the new car consumed the equivalent of 1500 gallons of gas, you'd have to drive 135 000 miles to get to the break-even point, energy-wise.

Adding Emissions to the Mix

One thing I haven't factored into my account is the fact that power plants tend to have lower emissions than vehicles, since some power plants are zero-emission and others may have scrubbers (i.e., they may clean their exhaust of the worst polluting chemicals before dumping it into the air). In summary, this report says that 68% of the CO2 emissions from the life cycle of a typical car come from fuel consumption, 21% come from fuel processing and only 11% come from vehicle manufacturing, based on a vehicle lifetime of 120 000 miles. That means that, from an emissions standpoint, you have to drive your new hybrid only about 15 000 miles to reduce your net CO2 output.

Conclusions

I guessed that the energy cost of operating an old vehicle would be much greater than the cost of making a new, fuel-efficient one. The marketing behind new, hybrid cars is slick: it had me thinking about ditching old clunkers in the name of environmental responsibility. It's almost as if there's no corporate muscle behind the message "don't buy a new car while your old one still works." I guess that commercial culture will never miss a chance to tell us to buy something new, even when hiding behind the message "consume less!"

It's true that many new cars will probably make it beyond the 135 000 mile mark, meaning that you could ditch your old car for a new hybrid and rest assured that probably your net energy usage would go down eventually. It's also true that if you're worried about emissions as well as consumption, you would have to drive only about 15 000 miles to break even. Still, the environmental impact of buying additional vehicles, even if they're hybrids, is not insignificant, and should be factored into any decision over "going green" by ditching an old but still usable car.

Tuesday, February 27, 2007

Beam Me Up to Heaven?

Greetings, friends.

You've heard a lot about risk evaluation so far from me, like why drinking a 2L bottle of soda is millions of times more dangerous than getting your head blown off while twisting the pressurized cap. Today I'm going to tackle an interesting problem in (soon-to-be-)practical philosophy: the ethics of teleportation. If I've done my job right, at the end of this post you will either fear death and teleportation, just teleportation, or neither of them.

What is Teleportation?

First, let me be specific as to what I mean by teleportation. The (now) hypothetical teleportation machine I'm going to talk about would work like this. You walk into a room, and your body is deconstructed while it's scanned, such that the position and composition of every molecule in you body is recorded. (I think that a fair amount of lossy compression would still have the subject live on the other side. Imagine a world with different transport ticket classes: First Class teleportation introducing relatively little distortion by using a full Yottabyte to store your body's information, but Coach using less bandwidth but leaving you feeling not quite right - like a low-bitrate MP3.) On the other side of the world, or years in the future (if you trust the data medium you're recorded on) your body is reconstructed, and you walk away fresh as a daisy.

Teleportation vs. Death

Here's the catch. How confident are you that walking into a room and getting taken apart molecule-by-molecule would feel any better because a suitable (even a perfect) copy of you walks out the door of a machine somewhere else? Suppose other people start teleporting and claim they didn't feel a thing wrong. Is that really any consolation? A perfect copy of my friend would behave just like a friend that didn't feel anything wrong. But how do I know that my actual friend didn't just subjectively die in the scanning room?

Most of my friends consider my reluctance about teleporting a little on the quirky side. They use it as evidence that I believe in a soul, which wouldn't get passed on to the copy stepping out of the teleport receiver. Even some of my friends who declare to believe in souls wouldn't mind being teleported as long as people did it all the time without any obvious side effects. (Maybe that makes sense. If souls don't have physical locations, why would it matter if the physical location of the block of matter "in contact with" the soul were to change locations?) Still, I think that getting my molecules ripped apart would feel pretty much the same regardless of the quality of the clone of me which stepped out into another time and place.

Death as Teleportation

"All mankind is of one author, and is one volume; when one man dies, one chapter is not torn out of the book, but translated into a better language; and every chapter must be so translated; God employs several translators; some pieces are translated by age, some by sickness, some by war, some by justice [....]"
-- John Donne, Meditation XVII
"Soon, some by teleportation. The 'better language' has me in Costa Rica right now."
-- Me

If you agree with pretty much everyone I've talked to, you'd say I'd be kooky to eschew teleportation because of its potential metaphysical consequences. If so, you shouldn't be afraid of dying either. Here's why: parallel universes are very likely. Check out the Wikipedia entry on "scientific" multiverses. There are tons of reasons to think that the sum total of reality is much bigger than the observable universe. Here are some reasons to suspect "reality" has more than what we could ever possibly observe:

  1. Space is big. We don't really know how big it is - but if it's at least 10^10^29 units big (What really kills me is that when you do orders of magnitude of orders of magnitude, the "units" could be 1 femptometer or 13.7 billion light years, and it wouldn't make a difference to the "29" part! If you use units 10^80 times bigger, you'd change the exponent from 10^29 to (10^29) + 80: insignificant.), then it's likely that there's an exact copy of you somewhere out there, given the number of possible arrangements of atoms in a universe 13.7 billion light-years across (which is all you can see at this point, so the seperate universes would be effectively identical). Because of quantum fluctuations these universes would diverge, but if space is at least 10^10^29 big, there would always be some universe out there identical to ours in every way.
  2. Baby universes might exist. If universes typically aren't that big, you might still have copies. Some physicists think that some universes constantly spawn children universes (here "universe" means contiguous volume of space), resulting in an exponential growth in the total possibilities explored by reality. In this case, you're guaranteed to have an exponentially-increasing number of exact copies of yourself elsewhere. You might not be able to reach these copies even in principal, but they would still exist.
  3. The "Many-Worlds" interpretation of Quantum Mechanics might be correct. You might have heard that making a measurement of a particle changes that particle in a fundamental way. Quantum computers are hard to make because to make a big one, you have to carefully avoid measuring anything while the computations are running. In this case, "measuring" doesn't mean "recording the measurement," it just means letting some information about the quantum computer's state influence the outside world. But, what counts as "outside" and "inside"? Nature doesn't draw a boundary around the quantum computational mechanism, saying "OK, you particles can interact with all particles in the quantum computer, but as soon as you interact with those particles in the computer case, the show's over." If you assume there's only one reality, you have to conclude that there's something special about our minds that collapses possibilities: whenever information about the state of a quantum computer leaks out into the world which could potentially be observed by a mind, the quantum possibilities collapse, and you're left with a classically-behaving system. (Alternatively, some physicists propose that large enough quantum systems spontaneously de-cohere with no mind needed, but it's not clear how "large enough" should be so defined yet. Every experiment done so far has the definition of "large enough" coincide exactly with "big enough to contain a mind.") If you find it hard to swallow that the atoms making up your mind have special "waveform-collapsing" powers, an appealing alternative is the "many worlds" interpretation of Quantum Mechanics, which suggests that possibilities never collapse, they just multiply. In this case, reality always branches whenever a particle makes a quantum decision. Reality always branches so that what you observe is consistent with the branch you took, which is why it appears that you collapse possibilities through observation: you're just forced to go along with a single outcome. So, if a particle in a superposition state decides to be spin-up or spin-down and you interact with it, you will be split into two and exist in two different non-interacting worlds: one where you observed the particle to be spin-down and one spin-up. Since quantum interactions happen all the time, the "many" in "many worlds" in like the "big" in "big bang": a serious understatement. There are so many exact copies of you floating around, it's ridiculous.
Personally, I think reasons #1 and #2 are possibilities we shouldn't discount, and that #3 is really quite likely. How about you guys?

Copies and Immortality
Death be not proud, though some have called thee
Mighty and dreadfull, for, thou art not so,
For, those, whom thou think'st, thou dost overthrow,
Die not, poore death, nor yet canst thou kill me.
[....]
One short sleepe past, wee wake eternally,
And death shall be no more; death, thou shalt die.
--John Donne, Holy Sonnet X

It's extremely likely that not only do perfect copies of you exist somewhere, but also that every reasonable permutation of matter exists, including ones where you have e.g. different social status. If you're not squeamish about teleportation and you bought my arguments about the plurality of possible existences, then you have to believe that even if "Fate, Chance, kings, and desperate men" disassemble you as thoroughly as a teleporter scanner would, "One short sleepe past" you'd wake in a reality where everything was the same, except some ridiculous circumstance would conspire to make you actually survive.

If the "many worlds" theory is correct, you wouldn't even have to be physically transported to another place as part of the immortality process. Check out the thought behind quantum immortality if you're interested in more on this.

Practical Issue: Subjectivity/Objectivity Mismatch

I'm more skeptical about my subjectivity being transported with my copy than I am about the plurality of the universe. Luckily, if multiverse #3 holds, I don't have to worry about the teleporter/subjectivity problem at all.

As long as the "many worlds" idea is correct, I think I'd be able to experimentally verify my reluctance to teleport myself, but only subjectively. That's because if I tried to teleport myself, no matter how hard I tried, my subjectivity would be forced down the quantum branches in the universe into realities where I wasn't able to be destructively scanned due to a freak occurrence. This will happed subjectively to everyone, but all of your friends will be able to teleport just fine from your point of view, just like it's possible for your friends to die in your world even though you might subjectively be immortal.

You May Be the Only Person Who Cannot Teleport in the Future
If you can trust yourself when all men doubt you,
But make allowance for their doubting too:
-- Rudyard Kipling, If -

Therefore, let me warn every one of you: there's a chance we're living in a multiverse where nobody will ever be able to teleport subjectively, because every time they try their subjectivity will be forced down some bizarre path where they didn't actually get killed. If you find yourself unable to teleport in the future even after having teleported many times before, it will mean "you" were born a clone from a teleportation machine, and your subjectivity won't be able to fit through a teleportation machine any more easily than a teleportation virgin's.

Conclusions

Be prepared for a future where all your friends can teleport without issues, but you are never able to. Be prepared for finding that teleportation doesn't work for you even if it has in the past: this just means your subjectivity started when you stepped out of a teleport receiver.

In either case, you will have evidence of the "many worlds" interpretation of Quantum Mechanics, but you'll never be able to objectively prove it. My advice: keep quiet about it, or they'll think you're crazy. Maybe if you turn Amish you'll be able to hide your existential conundrum.

I'll give a closing note to financial houses. I'm interested in buying a "solipsism fund:" a financial instrument where lots of us (like, millions of us) pay into a pot, and the people surviving split the interest on this cash every year they live. If we are all subjectively immortal, there's no better investment. And no, I don't want a fixed stipend for the rest of my life - I want to be filthy rich if I have to live to be as old as the Wandering Jew. PS - please keep the recipient list anonymous until only I am left, so that others don't have an incentive to do away with me early.

Sunday, February 11, 2007

Making Future-Proof Policy

Greetings, fellow nerds.

Today I'm going to address an emerging problem for policy-makers: how to exploit all the latest tech without getting bogged down in implementation details. I'm going to make the case that governments should adopt an adjudicating rather than a micro-managing role in some kinds of service provision.

Today's Tech is a Moving Target


Ours is an age of innovation. The rate of innovation has never been so fast. There's a yawning gap between the cutting edge of (especially) information technology and typical technology usage. As tech speeds up, I see this problem getting worse, not better. Do we want to perpetually wait around for bright ideas to crawl their way through the legislature? Or, do we want an adaptive system where better solutions to public problems can be implemented and rewarded instantaneously? How would such an unregulated system work?

Examples: Road Construction and Power Distribution

I've already given an outline on how we could get the private sector to automatically implement any useful tech in terms of road durability and safety in the form of bonds which annually pay the holder an amount proportional to the good that was done to the community. See my 21st century capitalism post at the bottom for more details.

I'm going to argue that we should trade in our monopsony/monopoly electrical power distribution system for a free market system with fluctuating prices for the same reason. As soon as a new gizmo which does things better gets invented, you should be able to just plug the sucker in and start making cash.

Case in Point: Cold Dutch Ideas

Recently, a Dutch research agency suggested that refrigeration warehouses should turn off their refrigerators during the day (nature article and ZDNet summary) in an idea called "night wind". Excess wind power is generated at night and might get wasted if nobody used it. Since it's OK for some refrigerated goods to vary in temperature a couple of degrees, you would let your warehouse warm up a bit during the day, but get cooled right off at night using green power through a grid that didn't happen to be at peak.

Let's review some of the steps you'd need to go through to put this idea into practice given the current power system.
  1. Some researcher thinks it up.
  2. Political will is mustered to look into the study.
  3. The specifics of which warehouses could use no diurnal refrigeration (possibly season-dependent) are compiled by a central authority.
  4. New regulations have to be developed and approved.
  5. Businesses are notified of discounts (or worse yet - income tax incentives) available for night-only refrigeration.
  6. Enforcers patrol the warehouses which signed up to make sure they don't use their refrigerators at night.
Keep It Simple!

I think letting the price of power float is a much better idea, so long as any approved entity can buy or sell energy to the grid. We already have "time of use" power meters which record the time of day each kWh of energy was used. Usually, energy at peak hours costs a high fixed rate while energy at off-peak hours is much less expensive - often less than half as costly.

Suppose we took the time-of-day concept one step farther and let electrical power be traded like any other commodity. Then, the steps needed to get warehouses to take advantage of extra power would be:
  1. Somebody notices power is more expensive in the day, so she turns off the refrigerators during the day.
  2. Profit!!!
Once people realize that power's cheaper at night, all sorts of things might get switched over to night-only, such as domestic air conditioning (possibly with a heat reserve), industrial processes, electric car charging, winter heating, etc. I can imagine thermostats which take in two variables: the current temperature and the current cost of electricity, to decide whether to turn on. It would be easy to transmit a few bits of information relaying the current price of electricity along power lines at some frequency other than 60 Hz (probably higher, so the signal would die out over a short range, and so local prices could vary somewhat). Then every appliance from fridge to light bulb could (in principal) decide for itself whether to turn on.

Free Market Benefits

There are six benefits to this system:
  1. Consumers would have financial incentives to cut back electricity usage when it's most scarce.
  2. The market would be able to decide exactly when price-dependent operation is worthwhile. Personally, I would say "no" to lightbulbs which dim when power is expensive, but "yes" to a fridge which works most when power is cheap, and "definitely" to a plug-in hybrid car which guzzled late-night 2¢-per-kWh hydro power. No extra laws needed!
  3. Power generation systems would be rewarded for producing electricity when it's most needed (potentially making solar power more financially-feasible in hot and sunny areas - solar needs all the financial help it can get).
  4. If somebody developed a large battery for leveling out peak usage, they would be able to make a quick buck right away. No need for proving the thing first: just buy low and sell high. No public investment risk would be involved, and peak prices would go down as peak supply increased, as if by magic.
  5. The financial incentives for long-distance power cables (such as HVDC) would be immediately apparent, and if they were economical, would be built quickly by profit-seeking companies.
  6. There would finally be some elasticity in demand for power. Trying to match generation with consumption is one of the biggest causes of damage to power equipment causing blackouts. If systems become over-stressed, prices would go up and everyone who had a smart air conditioner would instantaneously decrease the load on the critically-stressed system.
As I see it, the biggest disadvantage of changing to a market-based system is that it would be a change. New hardware would be needed - that's about it.

Conclusions

A market-based power-distribution system has the advantage of instantaneously adding incentives exactly where they would be with an ideal policy system. There would be no lumbering lag between technological innovation and implementation: if it will make money, do it.

Ensuring that financial incentives are aligned with the good of humanity is what 21st century capitalism is all about. Policies where every party has the same goals makes us work together to the benefit of all, harnessing our uniquely human gift of capitalism to do good.

Wednesday, February 7, 2007

Why Biometrics Scare Me

Greetings, fellow nerds.

I am a lover of technology. I love my Mac. I love the Internet. I love my doubly-shock-absorbing bicycle. I even once had a dream in code. Yet today I'm going to tame my technotropic tendencies to warn you against the threat of widespread biometric identification.

There are few technologies less viscerally appealing to tech nerds than biometrics: imagine a world where machines recognize you for the rich, influential 1337 h4xx0or you are just by scanning your body. Nothing short of tech porn.

In some limited circumstances, biometrics might be appropriate. For instance, if a security guard monitors the process of you putting your finger/retina/receding hairline on a scanner as an extra security layer, that's fine. However, biometrics; when substituting keys, credit cards or passwords; have three serious flaws:
  1. Biometrics give thieves an incentive to chop off parts of your body.
  2. You give out your biometric data all the time, whether you intend to or not.
  3. If you get your biometric identity stolen, you're screwed forever (unless you believe in reincarnation).
Don't Give People an Incentive to Cut You Up

Issue #1 means that not only would I personally refuse to use biometrics, but also that I have an incentive to make nobody use biometrics for identification. I don't want to have my hand chopped off only for thieves only for them to discover I didn't have a fingerprint-enabled bank account like most normal people.

Do you think it's far-fetched for criminals to chop off parts of the body for their biometric payload? It's already happened. Even though biometric identification is rare, we're starting to see the criminal reaction to it. I'd rather give up my cards and keys, thank-you-very-much. I'm horrified to see that the ICICI bank in India is also planning on opening widespread fingerprint-based ATMs for rural farmers who might find carrying cards to be too much of a trouble. I suppose a fingerprint-and-pin solution might somewhat discourage finger-theft, but your average robber might take fingers just in case, the same way a North American mugger wouldn't leave their marks' bank cards behind.

Don't Leave Credit Card Copies Everywhere

Issue #2 is pretty straightforward: getting someone's fingerprint is usually not very hard. Moreover, fooling a scanner with a print lifted from a glass is surprisingly straightforward. Even though expert techniques haven't yet been developed for getting a scanner to accept a print lifted off a glass (at least I'm not familiar with these cloak-and-dagger techniques), some first-try methods have a success rate of 80%. Some scanners can even be fooled by fogging them up by blowing on them to reveal the print of the last person to use them. Unless you'd be OK with leaving copies of your credit card on every smooth surface you touch, you shouldn't use your fingerprints as card substitutes either.

Getting Replacement Fingers and Eyes is Hard

Issue #3 illustrates the importance of disposable layers of security. I've had my credit card info stolen, and it was no big deal. VISA* called me one night to confirm some unusual charges which had gone through my account. When I said I hadn't made these charges, they sent me a replacement card and an affidavit to sign two days later (I guess it's in their best interest to keep me buying), and my old VISA card was sloughed off painlessly. I didn't pay a dime. (My story is not uncommon; identity theft happens to about 9 million Americans a year.)

The point is that fingerprints and retinal patterns are not things you want to have to slough off, ever. I like it that getting a new credit card didn't involve surgery. It's a feature (not a bug) that you can dispose of a credit card if its information gets compromised. Let's not take a step backwards in functionality for the sake of some flashy tech porn.

Conclusions: Now is the Time to Rant

Even though biometrics aren't widespread, the time to rant against their replacing credit cards is now. It's easier to nip a bad technology in the bud than it is to defeat it once it gets serious backing. How are we going to execute the said nip? By talking. That's all. I hope the scenarios I've laid out are sufficiently grizzly to spread through pool halls and cocktail parties; if they spread widely enough we will have done our job.

Take care; go do something amazing with your fingers while you still have them.

*I swear they didn't pay me to write this; I think it's important to get the word out if you feel like a company has done you right.