Person: Waldo, James
Email Address
AA Acceptance Date
Birth Date
Research Projects
Organizational Units
Job Title
Last Name
First Name
Name
Search Results
Publication Technical Difficulties of Contact Tracing
(Belfer Center for Science and International Affairs, 2021-02) Robinson, Amy; Waldo, JamesIn mid-October, thousands of English and Welsh citizens received phantom alerts that they had potentially been exposed to COVID-19. A quick Twitter tour reveals the spiraling fear, frustration, and confusion that ensued. Even though National Health Service (NHS) later updated the app, built using an Exposure Notification System (ENS) developed by Apple and Google, the incident still amplified mass hysteria and confusion.
The NHS bug demonstrates the real problem of false positives in digital contact tracing. A false positive occurs if the app alerts someone of possible exposure to coronavirus when no such exposure has occurred. A high rate of false positives has two potential problems. First, it could overburden a state’s limited testing capacity, as concerned citizens flood the already overwhelmed testing sites. On the other hand, people could become numb to notifications if the app continues to ping them with possible exposure. Then, people who really have been exposed will ignore the warning and not get tested.
While not as panic-inducing, false negatives can be just as deadly. A false negative occurs when a person who was actually exposed to the coronavirus does not receive a notification. If asymptomatic and unaware of a possible infection, she will continue her daily business and further spread the virus. Medical experts have dubbed such oblivious asymptomatic transmission “the Achilles’ heel” of the pandemic, especially as social distancing restrictions are relaxed.
Therefore, a digital contact tool must sufficiently minimize false positives and false negatives to ensure it does more good than harm. This is especially true as the number of U.S. states deploying digital contact tracing apps grows. In July, Google announced that 20 states and territories were “exploring” apps based on the Apple | Google ENS, which would represent approximately 45 percent of the U.S. population. New York and New Jersey’s recent app rollouts bring the total of state public health authorities currently using the Apple | Google ENS to eleven. In order to understand if the Apple | Google ENS is up for the challenge, we must understand the accuracy of the underlying Bluetooth technology. Long story short, Bluetooth technology simply cannot provide location information that is granular or consistent enough for digital contact tracing apps to reliably function.
Publication New Risks in Ransomware: Supply Chain Attacks and Cryptocurrency
(Belfer Center for Science and International Affairs, 2022-05) Robinson, Amy; Corcoran, Casey; Waldo, JamesWith the first attack dating back to 1989, ransomware is far from a new phenomenon. However, as of late, ransomware attacks have significantly changed in nature, becoming larger, more sophisticated, and more frequent. While once a rare and petty crime, ransomware has now proliferated and quickly matured into a lucrative business with the emergence of cryptocurrencies that have facilitated large, untraceable transactions. Now, organized and often state-backed hacking groups not only perpetuate sophisticated, targeted campaigns, but also franchise the infrastructure needed to carry such campaigns and sell it as Ransomware-as-a-Service (RaaS) on the dark web.
Just as concerning as the increased pace of ransomware is the emergence of a new delivery mechanism for malware that has been used in some of the most infamous ransomware attacks. As hacker groups have become increasingly sophisticated, modern software has become increasingly vulnerable to attack. Complex software must incorporate a multitude of pre-written code components from various sources, including open source code. Hacker groups can then target less secure software components, known as a supply chain attack, in order to extort a wide swath of companies or customers. Supply chain attacks are particularly dangerous if they establish a thread of control through an update package, such as the SolarWinds attack, which then provides hackers with the highest level of access to a machine’s resources.
This paper seeks to provide an overview of the current ransomware landscape, such as the rise of RaaS and the increase of supply chain attacks, while also gesturing towards potential emerging solutions. While not an exhaustive list, promising solutions address the vulnerability of complex software reliant on outside code components, such as software bill of materials (SBOM) and vulnerability disclosure databases, or address the payout, such as stricter cryptocurrency regulations.
Publication Guns, Incels, and Algorithms: Where We Are on Managing Terrorist and Violent Extremist Content Online
(Belfer Center for Science and International Affairs, 2023-06) Armstrong-Scott, Gabrielle; Waldo, JamesTen years ago, U.S. national security agencies grew concerned about a relatively new and powerful weapon used by terrorists: the World Wide Web. What had begun as an effort to connect end users from across the world to share information and to serve as a force of human liberation, instead began to be used as a tool for destruction of life. Terrorists were exploiting technology companies’ lax content moderation policies to recruit new members, spread violent extremist ideology, and plan terrorist attacks. In 2012, Twitter’s General Manager declared the firm “the free speech wing of the Free Speech Party,” and large U.S. technology companies were broadly reticent to make changes to their content moderation policies in the early days of their development.
By 2015, a gargantuan effort to eliminate ISIS commenced – mostly driven by the U.S. government – culminating in U.S. Cyber Command’s Operation GLOWING SYMPHONY, led by General Paul Nakasone, which reportedly foiled the majority of ISIS’ online presence and networks in 2016. Technology companies became much stricter about terrorist content online, but the problem of identifying and removing such content persisted.
Today, the online terrorism landscape looks much different to a decade ago. White supremacist and “incel” (involuntary celibate) violent extremist content litters the Web. Terrorist attacks are frequently committed by hate-fuelled lone-wolf “internet warriors” who have been inspired by non-Islamic terrorist and violent extremist content and radicalizing material online. Yet, technology companies and governments have not managed to keep pace with the dynamic threat.
This is not to say that they haven’t tried. In 2019, a terrorist attack committed (and live-streamed, going viral) by an “online warrior” white supremacist at two mosques in Christchurch, New Zealand, galvanized technology companies and governments to do more to combat terrorist content beyond just Islamic terrorism, culminating in an ambitious multilateral initiative, The Christchurch Call to Eliminate Terrorist and Violent Extremist Content Online, an unprecedented diplomatic achievement and step forward in managing the problem.
Technology companies and governments have spent the past decade trying to better address the evolving threat of terrorist and violent extremist content online (TVEC). However, there are few studies examining just how effective these efforts have been, where we are today in managing the problem, and wherein lie gaps for improvement.
This paper argues that companies’ efforts to deal with TVEC have been hampered at the outset by a tendency to define TVEC extremely narrowly. Still, only a tiny proportion of content that could reasonably be categorized as TVEC is included in most definitions. An outsized focus on pre-identified Islamic extremists and terrorist groups means that other types of violent extremists and terrorists (e.g., white supremacists, incels), and those unaffiliated with a group (e.g., lone-wolf actors) are overlooked. This paper also explores the idea of ethical obligations and norms as an alternative to a legally required definition.
On the technical side, this paper finds that even if there was consensus on the legal and ethical questions surrounding TVEC, the technical tools currently available are no panacea. Trade-offs across efficiency, scalability, accuracy, and resilience are persistent. Current technical tools tend to disadvantage minority groups and non-English languages. They are also less robustly implemented across small and non-U.S./European firms, generally either because they are left out of inter-firm initiatives or because they lack resources and capability. This paper does not claim to cover every issue relevant to TVEC; however, it highlights several important gaps that could be addressed by policymakers and tech companies and identifies avenues for future research.
Publication ER22x: JusticeX: Spring 2013 Course Report
(2014) Reich, Justin; Nesterko, Sergiy O.; Seaton, Daniel Thomas; Mullaney, Tommy; Waldo, James; Chuang, Isaac; Ho, AndrewER22x was offered as a HarvardX course in Spring 2013 on edX, a platform for massive open online courses (MOOCs). It was taught by Professor Michael Sandel. The report was prepared by researchers external to the course team, based on an examination of the courseware, analyses of data collected by the edX platform, and interviews with the course faculty and team members.
Publication PH207x: Health in Numbers and PH278x: Human Health and Global Environmental Change: 2012-2013 Course Report
(2014) Reich, Justin; Nesterko, Sergiy O.; Seaton, Daniel Thomas; Mullaney, Tommy; Waldo, James; Chuang, Isaac; Ho, AndrewIn the 2012-2013 academic year, the first two Harvard School of Public Health courses were offered through HarvardX on the edX platform: PH207x: Health in Numbers and PH278x: Human Health and Global Environmental Change. They were taught by Professors Earl Francis Cook and Marcello Pagano, and Aaron Bernstein and Jack Spengler, respectively. This report describes the structure of these two courses, the demographic characteristics of registrants, and the activity of students. This report was prepared by researchers external to the course teams and is based on examination of the courseware, analyses of the data collected by the edX platform, and interviews and consultations with the course faculty and team members.
Publication HarvardX and MITx: The First Year of Open Online Courses, Fall 2012-Summer 2013
(2014) Ho, Andrew; Reich, Justin; Nesterko, Sergiy O.; Seaton, Daniel Thomas; Mullaney, Tommy; Waldo, James; Chuang, IsaacHarvardX and MITx are collaborative institutional efforts between Harvard University and MIT to enhance campus-based education, advance educational research, and increase access to online learning opportunities worldwide. Over the year from the fall of 2012 to the summer of 2013, HarvardX and MITx launched 17 courses on edX, a jointly founded platform for delivering massive open online courses (MOOCs). In that year, 43,196 registrants earned certificates of completion. Another 35,937 registrants explored half or more of course content without certification. An additional 469,702 registrants viewed less than half of the content. And 292,852 registrants never engaged with the online content. In total, there were 841,687 registrations from 597,692 unique users across the first year of HarvardX and MITx courses. This report is a joint effort by institutional units at Harvard and MIT to describe the registrant and course data provided by edX in the context of the diverse efforts and intentions of HarvardX and MITx instructor teams.
Publication Heroesx: The Ancient Greek Hero: Spring 2013 Course Report
(2014) Reich, Justin; Emanuel, Jeff; Nesterko, Sergiy O.; Seaton, Daniel Thomas; Mullaney, Tommy; Waldo, James; Chuang, Isaac; Ho, AndrewCB22x: The Ancient Greek Hero, was offered as a HarvardX course in Spring 2013 on edX, a platform for massive open online courses (MOOCs). It was taught by Professor Greg Nagy. The report was prepared by researchers external to the course team, based on examination of the courseware, analyses of the data collected by the edX platform, and interviews and consultations with the course faculty and team members.
Publication Embedded EthiCS: Integrating Ethics Broadly Across Computer Science Education
(2018) Grosz, Barbara; Grant, David Gray; Vredenburgh, Kate; Behrends, Jeffrey; Hu, Lily; Simmons, Alison; Waldo, James