Berkman Klein Center for Internet & Society Scholarly Articles
Permanent URI for this collectionhttps://dash.harvard.edu/handle/1/13015057
Browse
Publication 2007 Circumvention Landscape Report: Methods, Uses, and Tools
(Berkman Center for Internet and Society, 2009) Palfrey, John; Roberts, Harold; Zuckerman, EthanAs the Internet has exploded over the past fifteen years, recently reaching over a billion users, dozens of national governments from China to Saudi Arabia have tried to control the network by filtering out content objectionable to the countries for any of a number of reasons. A large variety of different projects have developed tools that can be used to circumvent this filtering, allowing people in filtered countries access to otherwise filtered content. In this report, we describe the mechanisms of filtering and circumvention and evaluate ten projects that develop tools that can be used to circumvent filtering: Anonymizer, Ultrareach, DynaWeb Freegate, Circumventor/CGIProxy, Psiphon, Tor, JAP, Coral, and Hamachi. We evaluated these tools in 2007 -- using both tests from within filtered countries and tests within a lab environment -- for their utility, usability, security, promotion, sustainability, and openness. We find that all of the tools use the same basic mechanisms of proxying and encryption but that they differ in their models of hosting proxies. Some tools use proxies that are centrally hosted, others use proxies that are peer hosted, and others use re-routing methods that use a combination of the two. We find that, in general, the tools work in the sense that they allow users to access pages that are otherwise blocked by filtering countries but that performance of the tools is generally poor and that many tools have significant, unreported security vulnerabilities.
The report was completed in 2007 and released to a group of private sponsors. Many of the findings of the report are now out of date, but we present them now, as is, because we think that the broad conclusions of the report about these tools remain valid and because we hope that other researchers will benefit from access to the methods used to test the tools.
Responses from developers of the tools in question are included in the report.
Publication Accountability and Transparency at ICANN: An Independent Review
(2010) Gasser, Urs; Burkert, Herbert; Palfrey, John; Zittrain, JonathanPublication Accountability of AI Under the Law: The Role of Explanation
(Berkman Klein Center for Internet & Society, 2017) Doshi-Velez, Finale; Kortz, MasonPublication AGTech Forum Briefing Book: State Attorneys General and Artificial Intelligence
(Berkman Klein Center for Internet & Society, 2018) Hessekiel, Kira; Kim, Eliot; Tierney, James; Yang, Jonathan; Bavitz, ChristopherArtificial intelligence is already starting to change our lives. Over the coming decades, these new technologies will shape many of our daily interactions and drive dramatic economic growth. As AI becomes a core element of our society and economy, its impact will be felt across many of the traditional spheres of AG jurisdiction. Members of AG offices will need an understanding of the AI tools and applications they will increasingly encounter in consumer devices, state-procured systems, the court system, criminal forensics, and others areas that touch on traditional AG issues like consumer privacy, criminal justice, and representing state governments.
The modest goal of this primer is to help state AGs orient their thinking by providing both a broad overview of the impact of AI on AG portfolios, and a selection of resources for further learning regarding specific topics. As with any next technology, it is impossible to predict exactly where AI will have its most significant on matters of AG jurisdiction. Yet AGs can better prepare themselves for this future by maintaining a broad understanding of how AI works, how it can be used, and how it can impact our economy and society. In success, AGs can play a key constructive role in preventing misconduct, shaping guidelines, and ultimately maximizing the positive impact of these exciting new technologies. We intend for this briefing book to serve as a jumping-off point in that preparation, setting a baseline of understanding for the AGTech Forum and providing resources for specific learning beyond our workshop.
Publication Analyzing Accessibility of Wikipedia Projects Around the World
(Berkman Klein Center for Internet & Society, 2017) Clark, Justin; Faris, Robert; Jones, RebekahThis study, conducted by the Internet Monitor project at the Berkman Klein Center for Internet & Society, analyzes the scope of government-sponsored censorship of Wikimedia sites around the world. The study finds that, as of June 2016, China was likely censoring the Chinese language Wikipedia project, and Thailand and Uzbekistan were likely interfering intermittently with specific language projects of Wikipedia as well.
However, considering the widespread use of filtering technologies and the vast coverage of Wikipedia, our study finds that, as of June 2016, there was relatively little censorship of Wikipedia globally. In fact, our study finds there was less censorship in June 2016 than before Wikipedia’s transition to HTTPS-only content delivery in June 2015. HTTPS prevents censors from seeing which page a user is viewing, which means censors must choose between blocking the entire site and allowing access to all articles. This finding suggests that the shift to HTTPS has been a good one in terms of ensuring accessibility to knowledge.
The study identifies and documents the blocking of Wikipedia content using two complementary data collection and analysis strategies: a client-side system that collects data from the perspective of users around the globe and a server-side tool to analyze traffic coming in to Wikipedia servers. Both client- and server-side methods detected events that we consider likely related to censorship, in addition to a large number of suspicious events that remain unexplained. The report features results of our data analysis and insights into the state of access to Wikipedia content in 15 select countries.
Publication Anatomy of a Museum Twitter Bot
(2017-04-26) Fitzpatrick, Lauren KellyIn a group of eight Twitter bots distributing content from eight museum digital collections, none are affiliated with the collections they harvest from.
From this group of Twitter bots distributing content sourced from museum digital collections, we can take a closer look at who they are and how they’re changing the discoverability of digital collection content.
Publication Artificial Intelligence & Human Rights: Opportunities & Risks
(Berkman Klein Center for Internet & Society, 2018-09-25) Raso, Filippo; Hilligoss, Hannah; Krishnamurthy, Vivek; Bavitz, Christopher; Levin, KimberlyPublication Assessing the Assessments: Lessons From Early State Experiences in the Procurement and Implementation of Risk Assessment Tools
(Berkman Klein Center for Internet & Society, 2018) Bavitz, Christopher; Bookman, Sam; Eubank, Jonathan; Hessekiel, Kira; Krishnamurthy, VivekFor state and local officials, considering the development, procurement, implementation, and use of Risk Assessment (RA) tools can be a daunting endeavor.
This report provides context for those making these decisions, beginning with brief case studies of four states (Kentucky, Wisconsin, California, and Pennsylvania) that have adopted (or attempted to adopt) such tools early on and describes their experiences.
It then draws lessons from these case studies and suggests some questions that procurement officials should ask of themselves, their colleagues who call for the acquisition and implementation of tools, and the developers who create them.
This report concludes by examining existing frameworks for technological and algorithmic fairness.
The authors offer a framework of four questions that government procurers should be asking at the point of adopting RA tools. That framework draws from the experiences of the states we study and offers a way to think about accuracy (i.e., the RA tool’s ability to accurately predict recidivism), fairness (i.e., the extent to which an RA tool treats all defendants fairly, without exhibiting racial bias or discrimination), interpretability (the extent to which an RA tool can be interpreted by criminal justice officials and stakeholders, including judges, lawyers, and defendants), and operability (the extent to which an RA tool can be administered by officers within police, pretrial services, and corrections).
Publication Between Openness and Privacy in Genomics
(Public Library of Science (PLoS), 2016) Vayena, Effy; Gasser, UrsPublication Beyond the Wall: Mapping Twitter in China
(The Berkman Klein Center for Internet & Society, 2015) Song, Sonya; Faris, Robert; Kelly, JohnIn this paper, we map and analyze the structure and content found on Twitter centered around users in mainland China. This study offers a rare look at the activity of Chinese Internet users on a platform that is largely unregulated by the state and only reachable through the use of tools that circumvent state-mandated Internet filters. For Internet users that reside in mainland China, Twitter offers access to news from around the world and a wealth of ideas and perspectives that might otherwise be unavailable there, as well as a platform for building online communities that is not under direct control of the government. This study of Chinese Twitter — to our knowledge the first such study — offers a unique window into the online activities and global connections of Chinese Internet users who actively circumvent content restrictions. Based on a mixed-methods approach, combining social network analysis and a qualitative review of the content and activity of Chinese Twitter, we are able to map and provide detailed accounts of the topically based clusters that form among these networks. We identify 36 clusters that focus primarily on three areas: politics, technology, and entertainment. From one perspective, the discourse in the politically engaged portions of Chinese Twitter suggests that Twitter serves an alternative public sphere. The political group is formed of journalists, lawyers, human rights activists, and scholars, who are free to discuss topics typically not permitted in China, such as the Tiananmen Square protests, Tibetan and Uyghur issues, political scandals, and pollution. Yet China’s Internet repression is clearly succeeding. Chinese Twitter falls well short of supporting a broadly accessible networked public sphere. The proportion of the Chinese populace with direct access to the debates, communities, and shared resources on Twitter is relatively small, and the avenues by which such discourse might find its way into mainstream political discussion are severely constrained. The firewall between Twitter and the much larger social media platforms in China remains a formidable barrier.
Publication Breaking Down Digital Barriers: How and When ICT Interoperability Drives Innovation
(2007) Gasser, Urs; Palfrey, JohnPublication Bridging the Gap between Computer Science and Legal Approaches to Privacy
(Harvard Law School, 2018) Nissim, Kobbi; Bembenek, Aaron; Wood, Alexandra; Bun, Mark Mar; Gaboardi, Marco; Gasser, Urs; O'Brien, David; Vadhan, Salil; Steinke, ThomasThe analysis and release of statistical data about individuals and groups of individuals carries inherent privacy risks, and these risks have been conceptualized in different ways within the fields of law and computer science. For instance, many information privacy laws adopt notions of privacy risk that are sector- or context-specific, such as in the case of laws that protect from disclosure certain types of information contained within health, educational, or financial records. In addition, many privacy laws refer to specific techniques, such as deidentification, that are designed to address a subset of possible attacks on privacy. In doing so, many legal standards for privacy protection rely on individual organizations to make case-by-case determinations regarding concepts such as the identifiability of the types of information they hold. These regulatory approaches are intended to be flexible, allowing organizations to (1) implement a variety of specific privacy measures that are appropriate given their varying institutional policies and needs, (2) adapt to evolving best practices, and (3) address a range of privacy-related harms. However, in the absence of clear thresholds and detailed guidance on making case-specific determinations, flexibility in the interpretation and application of such standards also creates uncertainty for practitioners and often results in ad hoc, heuristic processes. This uncertainty may pose a barrier to the adoption of new technologies that depend on unambiguous privacy requirements. It can also lead organizations to implement measures that fall short of protecting against the full range of data privacy risks.
Publication Case Study: DRM-protected Music Interoperability and e-Innovation
(The Berkman Center for Internet & Society, 2007) Gasser, Urs; Palfrey, JohnThis report – representing one of three case studies that are part of a transatlantic research project aimed at exploring the potential relation between ICT Interoperability and eInnovation – examines issues surrounding DRM interoperability within the context of music content. Recognizing that interoperability will likely be defined differently by different stakeholders, we begin by establishing a rough, holistic working definition of interoperability and then assess the implementation of DRM in the music content market and associated problems with regard to interoperability. We then go on to explore the technological, market, and legal environments in their relation to and impact upon the achievement of interoperable DRM systems. In part 2, we analyze potential benefits and drawbacks of an interoperable DRM environment for the music content market. We then evaluate both private and public-initiated approaches towards the accomplishment of interoperability using a series of qualitative benchmarks. Lastly, we conclude by summing up the merits and demerits of the various approaches. Our findings lead us to surmise that normative considerations weigh in favor of greater interoperability in general. The challenge of determining the optimal level of interoperability and the best approach for attaining it, however, points toward consideration of a number of complex factors. We conclude that the best way to determine the optimal level of interoperability and means of accomplishing it is to rely upon economic-based assessments on a case-by-case basis.
Publication Case Study: Mashups Interoperability and eInnovation
(2009-03-24T17:56:30Z) Palfrey, John; Gasser, UrsPublication Catch-as-Catch-Can: A Case Note on Grokster
(2005) Gasser, Urs; Palfrey, JohnIn summer 2005, the United States Supreme Court issued a decision which is surely destined to play a significant role in the interrelation between law and technology in the coming years. The case, Metro-Goldwyn-Mayer Studios Inc., et al. v. Grokster, Ltd., et al., pitted copyright holders against the operators of certain peer-to-peer online file-sharing services and was awaited by many in both the legal and technology communities as a referendum on the landmark legal precedent set in the Sony-Betamax case. The Sony case came to represent the legal standard for determining when manufacturers of dual-use technology - technology capable of both legally noninfringing and infringing uses - should be given a safe harbor from liability for acts on the part of their consumers which violated copyright law.
Surprisingly, the Supreme Court's decision did not center around an affirmation or rejection of the Sony ruling; rather the Court based their opinion on a common law principle which, they held, was not preempted by the holding in Sony. The inducement to infringe copyright, although not a completely novel cause of action, has been perceived by some commentators to introduce a change in the legal landscape of secondary liability for copyright infringement. In this article, we provide an extensive exposition of the Court's decision and discuss the disposition of the decision including the implication of the two concurring opinions. We also speculate on the impact that the Court's decision will have on the technology sector and on technological innovation in particular. Ultimately, we grapple with new questions which the decision has presented for industry and the continued existence of peer-to-peer file-sharing.
Publication Challenges & Opportunities Concerning Corporate Formation, Nonprofit Status, & Governance for Open Source Projects
(Berkman Klein Center for Internet & Society, 2017) Ritvo, Dalia; Hessekiel, Kira; Bavitz, ChristopherPublication Children’s rights and digital technologies: Introduction to the discourse and some meta-observations
(Taylor and Francis, 2017) Gasser, Urs; Cortesi, SandraPublication Citizens Take Charge: Concord, Massachusetts, Builds a Fiber Network
(The Municipal Fiber Project. Berkman Klein Center for Internet & Society, 2017) Talbot, David; Warner, Waide; Crawford, Susan; White, JacobThis report describes a multi-year effort by the town of Concord, Massachusetts, to establish a robust and versatile communications infrastructure to better serve its citizens. The town’s municipal utility, Concord Municipal Light Plant, or CMLP, built a 100-mile fiber optic network as a backbone for a smart grid, and then used the network to deliver high-speed Internet access to homes and businesses, competing with Comcast. With the fiber installed, the town realized significant savings on municipal communications costs and generated new fiber-leasing revenue. CMLP recently launched a strategic planning effort to use the smart grid network and the data it generates to reduce peak power demand and costs, and to reduce systemwide greenhouse gas emissions. CMLP may earn additional revenue by allowing the New England transmission system to use parts of CMLP’s smart grid to balance regional electricity loads. And Concord now has the potential to expand its Internet access business beyond town boundaries, starting in neighboring Acton.
Publication Cloudy with a Conflict of Laws
(Berkman Klein Center for Internet & Society, 2016) Krishnamurthy, VivekAs more and more of our lives are lived online, so too are those who live lives of crime. Like everyone else, criminals of all stripes are increasingly using online services of all kinds to plan and commit their wrongful acts. Evidence of crime that not so long ago was on-the-ground and physical is now increasingly in-the-cloud and digital. All this has thrown the law parcelling the authority to search and seize among different jurisdictions into confusion, as clouds of data — like those in the sky — are everywhere and nowhere at once. Unless some clarity is brought to this situation and soon, the future of cloud computing as a unified global phenomenon may be hazy indeed.
This paper describes how the fractal complexity of cloud computing’s physical geography has fractured the system of Mutual Legal Assistance Treaties (MLATs) that arose during the jet age to help shuttle evidence of crime across borders. It explains why the territorially-based MLAT system fundamentally doesn’t work with the physical, technological, and corporate structures that are used to deliver cloud-based services, and how the resulting problems threaten their continued global nature. It highlights the role played by US laws, companies, and government institutions in exacerbating these difficulties that, ironically, have now been visited on the US government itself in the Microsoft Ireland case. It then finally sketches some elements of a potential solution based on principled US leadership that recognizes the legitimate interests of other governments.
Publication Coming in from the Cold: A Safe Harbor from the CFAA and the DMCA §1201 for Security Researchers
(Berkman Klein Center for Internet & Society, 2018) Etcovitch, Daniel; van der Merwe, ThylaIn our paper, we propose a statutory safe harbor from the CFAA and DMCA §1201 for security research activities. Based on a responsible disclosure model in which a researcher and vendor engage in a carefully constructed communication process and vulnerability classification system, our solution would enable security researchers to have a greater degree of control over the vulnerability research publication timeline, allowing for publication regardless of whether or not the vendor in question has effectuated a patch. Any researcher would be guaranteed safety from legal consequences if they comply with the proposed safe harbor process.