The Twitter Hack Could Have Been Much Worse

Midday on July 15th, 2020, many high-profile Twitter accounts were compromised and began posting scams to entice users into sending them cryptocurrency (generally BTC, but also some others such as XRP for Ripple’s account). I’m not going to write about this in detail since everyone else already has, but for more information check out an article on the topic: Coindesk, TheVerge, TechCrunch, BBC, infinite others

What if instead of posting low-quality cryptocurrency scams, the attackers did something else?

Sure, they could have tried to use CEO accounts such as Musk and Bezos to make millions (or possibly billions) on the stock market by tweeting about earnings and purchasing large amounts of far-out-of-the-money near-expiration call options on the underlying stocks. But we have a lot of ways to catch people that try that, and many regulations and organizations that would make it more difficult (many more than just the SEC) to get away with (although as a side note, $TLSA’s stock+option trading volume is absurdly high, and it would be very difficult).

But, what if they had tried something else entirely, something not motivated by short-term financial gain?

What if the attackers wanted to cause chaos and violence, perhaps alongside putting certain political movements and goals forward? What if they had pre-written thousands of tweets about a topic, perhaps a fake and outrageous event occurring, paired with fake images and videos, perhaps even some higher-quality deepfakes? How many people could they get killed? Could they start a war?

You might think this sounds absurd at first glance. But remember, most of the world’s most influential people use Twitter, including the leaders of most national governments. Although a private corporation that plays by its own rules, Twitter is still the means with which many elected officials communicate with the public. Entire social movements have started and ended through the power of a single viral tweet, sometimes resulting in significant violence or many deaths. Social media platforms have been used by extremists of every type imaginable in the past, and this isn’t going to stop any time soon.

What if the next exploit affects much more than some Twitter accounts?

But, I want to go much further than talking about Twitter. What if instead of an exploit that allowed attackers to compromise Twitter accounts, it had been something much worse? What if they were able to compromise any web server, or any online Windows machine, or industrial control systems for utilities, power plants and military operations? None of these scenarios are by any means impossible. Enough software and hardware exists at enough layers of abstraction that there’s generally always 0-days lurking in critical systems, sometimes for years or decades, before they’re found. We know that 0days are found often by security researchers, private companies, governments, and others (sometimes rewarding up to $2,500,000), but also that they are less commonly exploited in obnoxious and harmful ways (generally being hoarded by government security agencies or reported in good faith).

We were unprepared for covid despite epidemics throughout all of history

It was said by many that the covid pandemic could have been predicted, in a sense (which is why it was not a true black swan event). Perhaps not the specifics of it such as the date, virus, and origin. But the general idea of “at some point in the future, something bad is going to happen like this, and we need to prepare for it.”

Another one of these “something really bad is going to happen in the future” categories involves cybersecurity, data privacy, and AI. Just one of these topics individually can be involved in a terrible catastrophe, and indeed have been before, but I think we’re coming close to a combination of all three that can lead to events much worse than we’re currently prepared for.

Security: Billions of humans live digital lives, including the most influential, famous, and dangerous. These people all have email accounts, phones, Twitter accounts, and more, all of which can be compromised, controlled, and manipulated by others.

Data Privacy: The amount of data that social media giants (among others) have on most people is massive, and in my opinion vastly underestimated both in quantity and power. The majority of human communication is now owned by private companies that store things forever. A large proportion of all human social connections, conversions, movements, opinions, and thoughts are stored in databases that not only will not forget, but that the user does not have any control or often even knowledge of.

AI: Advances in the area of content generation have been happening very quickly in the last few years. We now have GPT-3, which can write plenty of things better than humans can. We have deepfakes, which can produce believable fake images and videos. We can do the same for voices and much more. Much of this isn’t yet perfect, but it’s clear that we’re improving quickly.

So, take the three above topics of security, data privacy, and AI, and combine them all. Bonus points if you throw in some political tension, which we’re certainly not lacking right now either.

We are not prepared for a true disaster involving technology

As a society, we’re woefully under-prepared for disasters in all of these areas.

We’re not prepared for critical infrastructure, both physical and digital, to be compromised or attacked by highly-funded and competent groups, maybe even state-ran.

Not prepared for the massive campaigns of disinformation, fake news, and propaganda that lie ahead. If you thought things were bad in the last few years, just wait, because we’re on the verge of accelerating it by 10x, and fact-checking is not a solution. China’s government seems to be working very hard both on the offensive and defensive here. Is anyone else truly competing?

Not prepared for how to deal with database leaks that will contain the life history of millions of people, including their ‘private’ conversations and deepest secrets, and items so egregious that they instantly spark violence. Plenty of data breaches have led to murders and suicides already. There are still many countries where you can face imprisonment or death for being gay, being atheist, being of a certain ethnicity, or speaking out against the government (yes, we really don’t have it as bad here, huh!). Do you know what happens when these people have their private information carelessly leaked? It’s not pretty. And this is just for normal database leaks, let alone if a database leak had some information in it falsified (with the majority left intact, thus offering plausibility for the fake parts) to maximize its effect.

Not prepared for how to face that humanity is becoming increasingly controlled by viral algorithms that do not prioritize human values of happiness and love and truth, but rather nothing but outrage and in-group bias as the only bottom line. Most of us already feel powerless against this, but it may only just be beginning.

Not prepared for how anonymity is becoming a luxury only achievable by ultra-competent tech gurus, with most people having been forced to move their communication into more and more centralized ways over time, feeding all of the above issues. Not prepared for how one of the many reasons anonymity is getting much more difficult to obtain is because the easiest way to tell if someone is a bot or a human is to require verification of phone numbers, addresses, and more. And don’t let me forget to mention how many governments are eyeing up ways to ban end-to-end encryption.

I’m supposed to end on an optimistic note

How can we do a better job of addressing these problems?

  • Promote education on the importance of cybersecurity, especially at the government and corporate levels
  • Promote decentralized solutions instead of centralized social media platforms, allowing users to have control over their discourse, their platform, and their own data
  • Promote anonymity, even when it is difficult, and fight to ensure end-to-end encryption is a right for everyone forever
  • Promote better regulations around privacy and data security so that hoarding large amounts of personal data is less of an asset and more of a liability

Although a lot of this post might read as alarmist and pessimistic, I’m still (mostly) optimistic about these things in the long-long-term. The best part about terrible events like covid is that they make us stronger and better prepared for the next (similar) storm to hit us. Security used to be a second thought (or not a thought at all) for most companies, but we’ve improved significant in the last decade, and bug bounty programs and significant security spending are now common. I used to get looked at like I was insane for talking about how big of an issue the amount of tracking and data-collecting our society performs was a big problem, but even this is something that a lot of everyday people believe now as well. I just hope the stepping stones along the way to becoming prepared for the future aren’t so terrible that we don’t make it there in one piece.

Feel free to say hi on Twitter for any comments, suggestions, complaints, etc.

Fact-Checking Is Not Easy

It’s interesting how many people view fact-checking as a simple problem, where you just identify something that is not factual, then correct it. Problem solved! Misinformation has been defeated, the Internet is only full only of Truth, and now The People finally realize we were right all along!

Fact-checking is a very hard problem. A lot of people want to ignore this fact, because correcting people feels good, especially when they’re your enemies.

It takes a lot of virtuousness, of empathy, of vigor, and of rationality to decline the temptation to correct other people. We are driven insane by the fact that not only are other people wrong on the Internet, but they are wrong about basic facts! This is part of why websites like Twitter are so terrible. People cannot stand others being wrong on the Internet. They will gladly spend hours of their daily life willfully being miserable and angry just to have the chance to correct others, even if those they correct do not even change their beliefs at all, or even change them in the opposite direction.

Humor aside, this is literally what fact-checking is

Although some may think the reason why Mark Zuckerberg has come out against fact-checking politicians is so that he can reap profits and sow division while cackling maniacally, I think instead he has simply put a lot of thought into the problem, and not only realized how difficult it is, but also that it cannot work well long-term. He is much more concerned about the long-term future (decades) of Facebook than he is about some upsetting posts made by an upsetting person.

Difficulties with fact-checking

I. There’s no such thing as an unbiased fact-checker

Fact-checkers, whether humans, scripts, or AI, cannot be unbiased. Reality is always a state of incomplete information, and the ways that humans interpret statements vary from person to person. It’s possible for us to disagree on the veracity of a statement, but if we were to discuss things further with more specificity, actually agree on the state of reality. Many statements can not reasonably be interpreted as a boolean of true or false, and instead have subtle amounts of potential bias and nuance within them. Facts are constantly changing, and no single actor has perfect and unbiased information about all of them.

II. Even if there was, someone has to decide which content should be fact-checked

Even given impossibly-perfect moderation, someone has to cherry-pick the content that is to be moderated and checked in the first place, as the Internet has far too much content to police every thought and post manually. Most individuals in favor of fact-checking tend to focus on a very small subset of individuals or organizations that they think should be fact-checked, but this set itself is cherry-picked according to their preferences and attention. This is another process that inevitably introduces bias, potentially in many directions depending on the people and processes involved. Similar to how two completely opposing news networks may only report true information, but still promote entirely opposing narratives because they cherry-pick what is news and what is not news, fact-checking cannot avoid this selection problem. It’s very unlikely that any large organization can do a reasonable job at this.

III. Even given quality fact-checking, the results may not be what you seek

A lot of people do not trust certain fact-checkers, certain news networks, and especially certain social media companies. Even if you perform good fact-checking, there is little evidence that this will achieve your goal, which is not actually correcting text on the Internet, but correcting peoples’ beliefs in their own minds, which turns out to be pretty difficult. Fact-checking could sometimes have an effect similar to the Streisand effect, potentially even causing harm to one’s cause, although I can’t find recent studies on this specifically. Regardless, it should be well-known by now that many people will not instantly and flawlessly change their minds when presented with new opposing facts, especially when done so by their outgroup.

If an Internet platform undertakes significant fact-checking, it could even drive heavily-affected groups off of the platform and onto their own platform, where they would then be even more free to spread their own information in whichever way they want. Similarly, the amount of trust that is given to many companies could decrease significantly and cause greater problems further down the road that can then not be solved with fact-checking.

Long-term affects of big changes are impossible to predict, but it’s not too hard to think about a lot of unintended consequences not just for social media, but for governments, democracy, and humanity, further down the road. Most people don’t have to try too hard to imagine some pretty dystopian results and major failure modes when trillion dollar corporations and governments become arbiters of truth and information.

IV. alternative narratives are important for society

Fact-checking has been desired and attempted by those in power throughout history, often leading to disastrous results, even without considering the political extremes of events such as WWII, which entire books of tragedy are written on. Many may view the Copernician revolution as ancient history, being 500 years ago, but it was only 170 years ago when Ignaz Semmelweis’ controversial hypothesis that doctors should wash their hands and maintain cleanliness was mocked and ridiculed for decades, until it eventually became common practice and saved millions of lives.

Lest those examples still appear as ancient history, remember that during the beginning of the covid pandemic, stating that covid was spreading from person to person directly contradicted the WHO (not to mention that everyone should wear masks, among others), and correspondingly would have been censored by platforms like Youtube according to their public policy.

History is full of countless examples of individuals that went against the grain of their encompassing culture in order to accomplish amazing things and drive progress. These people often armed themselves with what may have been originally considered to be misinformation by those in power during their zeitgeist. I’m glad that we didn’t have the centralization of communication and power we have now throughout history, because many rights that you take for granted were only gained thanks to the failures of past powers to control the narrative as strictly as they wanted to.

V. The narrative cannot be controlled

Just like everyone else, I too wish that everyone that was wrong on the Internet could be corrected. I wish my favorite narratives, facts, and causes were supported and known by more people. To not attempt to correct and control the narrative is a tough bullet to bite, but it’s something that a lot of thought and consideration must be put into, requiring very long-term thinking and awareness of history.

As long as people are free, they will come up with their own narratives, causes, desires, and even facts and entire worldviews. It’s been said that we live in a post-truth world, but that has always been the case. It’s just more apparent now that you can see people from every other background and culture when you use the Internet. No single person, company, or government can control information flow and peoples’ beliefs to the extent that they wish, and any that grasp for such an unattainable level of control will find that it doesn’t work long-term. Even the countries with the strictest controls on information, reporting, and speech, historically, have never fared well after a long enough time.

Different people have different lives, different values, and even different facts that they live by. It’s possible for you to co-exist with them, but perhaps not best if you’re forced to live in the same room as them. But no matter how hard you try, it may be impossible to get them to live their life the way you want them to. I know it’s difficult, but sometimes the only option is to let others live in their own world, while you live in yours, still helping to make it the best you can. Spending your days being angry and miserable on social media will not accomplish what you want, no matter how right you are.

Although this post might not be particularly insightful and is almost too political for my taste, I hope at the least this may help some realize that fact-checking is more difficult than it appears at first glance, even if they still support it.

I’m looking for more interesting people to chat with on Twitter, especially if you have corrections, improvements, or just like to discuss topics like longevity, startups, security, and finance, and more.