Author Archives: Michael Froomkin

How to Censor ‘A Censorship-Resistant Web’

A Censorship-Resistant Web sets out a sketch of a way to create fail-safe distributed copies of web pages (i.e. not centralized in a single point of failure like at archive.org) thought likely to suffer political risk, to authenticate them as genuinely by the original author, and to help browsers find them if the original were to vanish.

What’s nice about this system is that it gets you censorship resistance without introducing anything wildly new. There are already certificate authorities. There are already hash-to-URL servers. There are already mirrors. There’s already Tor. (There’s already tor2web.) The only really new thing specific to censorship resistance is URL-to-hash servers of the form I described, but they’re very simple and hopefully uncontroversial.

There is some work to be done stitching all of these together and improving the UI, but unlike with some other censorship-resistance systems, there’s nothing you can point to as having no good purpose except for helping bad guys. It’s all pretty basic and generally useful stuff, just put together in a new way.

(Spotted via Cory Doctorow)

I like this kind of stuff, and this seems the start of a fine effort. But it made me think, and I’m afraid that I had an evil idea.  The same techniques that allow users to navigate to the backup pages(s) also will allow the party that took down the page in the first place to find the duplicate(s), and it will rarely be hard to trace these to their respective owners.  So if this form of future-proofing becomes frequent for politically sensitive materials, I expect the cross-border aspect of the denial-to-denial-of-service-attack to be overcome by executive agreement or treaty.

The difficulty for the censor in the USA, however, is that pesky First Amendment.  I can see two ways that a determined government might try to get around it other than directly applying its scary and expansionist reading of the Espionage Act.  The first would be to argue the still-open issue regarding the supremacy of treaties over the Bill of Rights.  But that’s rather major, and would depend on the content of the hypothetical international agreement. It may also be unnecessary.

A sneakier work-around the First Amendment might go as follows:

  1. Seize the copyright of the online version.  This might be done on a claim that the text is contraband or was acquired with contraband.  Alternately, the seizure might be effected under the standard condemnation power, in which case just compensation would be due to the original owner in order to comply with the Fifth Amendment.
  2. Once the government has the copyright it then applies the DMCA to all the (domestic) copies and has them taken down.  It applies to foreign countries to do the same under the proliferating DMCA clones around the world.

There are a couple of complexities that need explanation.

First, the US government doesn’t usually claim copyright in the work product of its employees, which would make the claim that there is a copyright to seize difficult if the government was the original author of the leaked work (the WikiLeaks situation). That’s from 17 USC § 105,

Copyright protection under this title is not available for any work of the United States Government, but the United States government is not precluded from receiving and holding copyrights transferred to it by assignment, bequest, or otherwise.

But imagine that § 105 was amended, and the government did start to claim copyright in its employees’ works, or maybe just in all classified works produced by the government or its contractors and agents.  On the one hand, this would seem to avoid the need to seize the copyright, since the government would already have it and could instead go straight to the DMCA. 

On the other hand, however, the government would face a difficulty in that in order to claim copyright over the posted work, the government would have to admit that the work was authentic, something the US government has studiously avoided doing (officially) in the WikiLeaks case.

Perhaps, however, the government could invent some new procedure in which it went to District Court and proceeded in the alternative, saying it was either seizing the copyright, or not (leaving the question of just compensation for any subsequent proceeding in which someone claiming to have the copyright could come forward in the Court of Claims), but in either case now claimed entitlement to a declaration that it had the authority to apply the takedown clauses of the DMCA?

Anyway, all this is too horrible.  I hope a real copyright lawyer can come along and explain why it is nonsense. And by posting it on the day of the year when no one reads this blog, I hope I’ve both established priority in the unlikely event this both isn’t nonsense and is original, and also limited the chance of the idea taking off.

Posted in Cryptography, Law: Copyright and DMCA, Law: Free Speech, National Security | Comments Off on How to Censor ‘A Censorship-Resistant Web’

Math Doodles

This is for Benjamin:

Via Robert Krulwich’s Blog.

Posted in Science/Medicine | 1 Comment

Something Went Badly Wrong in the Late 1970s

The toy du jour is Google’s new ngram — a way to graph the frequency of words or phrases in 10% of the books published in the US.  Here’s an ngram for “due process”.

Due Process Ngram

Something went wrong in the late 1970s — shortly after Justice Rehnquist joined the Court. Or maybe it’s just after Mathews v. Eldridge, 424 U.S. 319 (1976).

Posted in Law: Administrative Law, Law: Constitutional Law | Comments Off on Something Went Badly Wrong in the Late 1970s

Emergence Explained

It’s somewhat like ignoring the vegetable drawer of your fridge for a year, then opening it to find a bunch of very grateful sentient tomatoes busily working on their third opera.

from The Post That Cannot Possibly Go Wrong.  Which is worth reading for lots of other reasons.

(found via boingboing’s Secret history of Douglas Adams’s Starship Titanic game)

Posted in Completely Different | Comments Off on Emergence Explained

How to Solve the Dreaded Firefox Sync “Error while signing in” Problem

Sync LogoSomehow, my Firefox syncs stopped syncing.  I think it had something to do with updating the plugin on one machine but not another.  Anyway, in my attempts to fix this, I got to a point where the secret key was not the same on all the machines.  But when I tried to change it, the change key button was greyed out and I couldn’t type over the (wrong) key.  As a public service, I’m reprinting the solution, found — most obscurely — on a Firefox help thread entitled The article mentions a “secret phrase” but I got a “Firefox Sync Key” instead. Is this the same thing?:

After upgrading to FF 3.6 (now at 3.6.12) , I began getting an error message “! Error while signing in. Please try again” and when I clicked on it, the explanation “Sync encountered an error while connecting: Wrong Sync Key” appeared along with a link to “Preferences” – clicking on this link took me to Sync Preferences > Manage Account. Click on the tab “Sync Key” and the key on that computer is shown – but, you can’t change the Sync Key there (except by generating a new one, which resets the entire account with a new random-generated key, which is not helpful as your other computers can’t generate the same key). How to get all three computers on the same Key? It turns out you have to print the sync key from one of your computers, then trigger the error message on each other computer having a different key. On each other computer, click on Preferences > Manage Account as before, but don’t click on the Sync Key tab; instead click on “Connect” next to your account name. Now you will receive another error message saying “Wrong Sync Key” in red – and beside that, links to “update” and “reset”. Click “update.” (“Reset” merely sends you to generate a new random key.) “Update” takes you to a text box with a blank inviting you to enter a new key: enter the one you copied from the other computer. This box is pre-configured to accept only an alpha-numeric key in blocks of 1-5-5-5-5-5 characters – you cannot enter your choice of text, only a key already generated on another computer. When finished, you should get the message “Your sync keywas successfully changed!” None of this is from FF Help; just trial and error.

Got that?  Here it is in an easier-to-read format:

  1. Print the sync key from one of your computers (or save it to your Dropbox)
  2. Trgger the error message on each other computer having a different key.
  3. On each other computer, click on Preferences > Manage Account as before, but don’t click on the Sync Key tab; instead click on “Connect” next to your account name.
  4. Now you will receive another error message saying “Wrong Sync Key” in red – and beside that, links to “update” and “reset”. Click “update.” (“Reset” merely sends you to generate a new random key.)
  5. “Update” takes you to a text box with a blank inviting you to enter a new key: enter the one you copied from the other computer.

Thank you acbar8!


UPDATE (12/25): While the above does in fact allow you to get all your computers talking to each other again, it doesn’t fully solve the problem: sync will still intermittently fail to connect after working perfectly well. And then later it will work again. This seems to be a bug relating to version 1.6 on the server end. And from the look of things, I don’t think I’m going to be out of the woods until Firefox 4.0 comes out… I advise sticking with version 1.5 on all your machines until this gets worked out. (Note that it’s fairly complex to downgrade from 1.6 to 1.5 as they use different encryption or storage methods. I think you would have to unload the plugin from all the machines, then start a new account with the 1.5 data; otherwise you will end up with a mess, either missing or duplicated bookmarks.)

Maybe it is time to go back to the dead?

Posted in Software | 5 Comments

Something is Wrong at the Washington Post

No, not what you think.   Something new — this:

I’m used to seeing certificate error mismatches here and there, but “(Error code: sec_error_revoked_certificate)” sounds more serious. I wonder what happened?

Posted in The Media | 1 Comment