Archive for October, 2018

Quantum Computing and Cryptography

Monday, October 29th, 2018

If you google “Is Quantum Computing Dangerous”, you will find headline after headline about the imminent dangers of quantum computing. Articles instilling fear in readers through the talk of the ways that Quantum computing is a “tool of destruction”, or that it is the “end of cryptography”. Articles such as this one argue that modern cryptography will be defeated and even ends with the following statement “Should the Russian government break all of our encryption before the US develops countermeasures, stolen elections will seem like small potatoes. Welcome to the cyber-battlefield of the 21st century.” Where are these fears coming from, and are they substantiated? Should we actually fear a complete breakdown of cryptographic methods if quantum computing technology advances? Will it advance to that state?

 

First, the fears about cryptography. Many cryptographic methods and schemes, such as RSA, are built on top of the difficulty of solving one-way mathematical functions, such as prime factorization. These problems are easy to compute in one direction, but take exponential time in the other direction, so the ability to guess and break a method such as RSA are not feasible with modern computers, which at best solve problems in linear time. However, theoretically, quantum computers should be able to compute problems much faster, even problems that would normally take exponential time to solve. On the face of it, this would mean that all our current systems, i.e. banks, national security, etc. would be compromised if someone had a quantum computer that truly worked as a quantum computer (i.e. each qubit, rather than storing two possible states, 0 and 1, store three states, 0 and 1 and 0 and 1. When you multiply out the additional computing power for many hundreds of thousands of bits, then its easy to see the where the additional computing power would come from). Its easy to see the fear in this -> at face value it boils down to an arms race with a crazy powerful weapon that could break all cyper security and cryptographic schemes by solving exponential time algorithms in quadratic time.

 

But, in reality this fear seems a bit too strong. What is the current progress of quantum computers? Is it even possible to reach create a fully functional quantum computer with more than 50 qubits (the number needed for quantum supremacy, that is a quantum computer that cannot be simulated on a classical computer)? Currently, there are some serious roadblocks in the practical creation of such a machine, with IBM having the closet possibility of it. But, even if such a machine is to come, “it isn’t obvious how useful even a perfectly functioning quantum computer would be. It doesn’t simply speed up any task you throw at it; in fact, for many calculations, it would actually be slower than classical machines. Only a handful of algorithms have so far been devised where a quantum computer would clearly have an edge. And even for those, that edge might be short-lived. The most famous quantum algorithm, developed by Peter Shor at MIT, is for finding the prime factors of an integer. Many common cryptographic schemes rely on the fact that this is hard for a conventional computer to do. But cryptography could adapt, creating new kinds of codes that don’t rely on factorization.” -> https://www.technologyreview.com/s/610250/serious-quantum-computers-are-finally-here-what-are-we-going-to-do-with-them/

The truth is, there are serious difficulties ahead for the advancements of quantum computers to a useful state, and it doesn’t currently seem like there are that many practically useful efforts for quantum computers. Moreover, if a quantum computer was created, cryptography could adapt quickly to rely on a NP-Hard problem that is not easily solvable by a quantum computer (which would need some sort of quantum algorithm to solve the problem in the first place). All in all, the technology is incredibly interesting, but it does not seem like much of the current fear is merited. At least for the time being.

Psychometric Targeting in Political Campaigning: Is there an Issue?

Thursday, October 18th, 2018

Following the recent presidential election, news came out that Cambridge Analytica has used people’s private Facebook data to help the Trump campaign win the election. Based on recent articles such as this one, it seems that the data driven analysis and decisions were effective in increasing voter turnout for those who ended up voting for Trump, as there were many new, unpredicted voters in this election. However, there was also an uproar about the privacy concerns regarding this move. The data that Cambridge Analytica used was mostly accessible publicly and garnered through voluntary online quizzes/tests, and the targeting was done based on psychometric methods that predicted which way a person may vote. Initially, this may seem wrong in some ways, but what about this is any different than previous modes of political campaigning? Is it that psychometric methods are more accurate? Or is there something inherently different about targeting an individual based on interests and personality than on general demographics?

This post will focus on the question of what is the real difference between psychometric targeting for political campaigning today and regular political campaigning of the past? What made the Cambridge Analytica scandal in the recent presidential election so controversial compared to political campaigning of previous elections? Both types of campaigning targeted people in order to mobilize potentially beneficial voters to go out and vote. I will offer a few differences and walk through the plausibility of each of the potentially significant differences

  1. The psychometric targeting is more individual and specific than the demographic targeting of the past.
  2. The psychometric targeting can be done on a much larger scale than the older political campaigning.
  3. Only one side in the previous election used the effective psychometric political targeting and so may have had an advantage that pushed them over the edge.

These are just some of the different ideas I came up with for differences. It doesn’t seem like the first should be the significant difference for general concerns because political campaigns of the past did campaign in very specific methods, although locally rather than on a national scale. For example, even the founding fathers would capitalize on information that a person would vote a certain way when deciding whether or not to spend extra time encouraging that person to vote. This leads to the second potential question: the scale of data driven political campaigning. Is it really the scale that throws people off? This also doesn’t seem like the issue given that most people would agree that voter mobilization in general is good, and the goal of the data driven political campaigning using psychometrics is simply to increase voter turnout. However, the more refined goal is to increase voter turnout for one’s own supporting party. So is this the real distinction? That the psychometric targeting only mobilizes the side of the person using it? This also doesn’t seem to be an issue, because all political campaigning is entirely biased towards increasing voter turnout for the constituents that would help the candidate that you are supporting. In this case, it just so happened that a singular group decided to use this data-driven psychometric targeting, but there may not have been an issue if both sides had used it, increasing voter turnout in general.

Then what is the real difference between the two if not the three above?

  • The data used in this case should be private.
  • The method of influencing people to mobilize them to vote seems dishonest in some way.

Maybe it has to do with the data itself? Namely, that the data used in this case should be private. But, this also doesn’t seem like a possible distinction simply because public data for people in the age of social media and the internet is increasingly available to anyone. So, even if companies are within privacy guidelines, identifying data can still easily be accessed for people on a large scale. The only other possibility seems to be that the method of influencing people to mobilize them to vote seems dishonest in some way. But this is no different than previous political campaigning, where fake news has also been real (except not at the scale it exists at now). All in all, the real difference here seems just to be the (alleged) increased accuracy and effectiveness of the psychometric targeting method, and the trouble seems to come from the fact that only one party decided to use it whereas the other didn’t. Would the same reaction have come if both parties had used this method to mobilize voters? Is the issue with the method itself? If so, then the more pertinent question is simply how can we work to further people’s privacy protection in the digital age and how much of this privacy is necessary, desired, or even possible.

Algorithmic Bias: Where is the Problem?

Monday, October 15th, 2018

What is algorithmic bias? That is, how can we actually define it in a meaningful, constructive way that can help us to ultimately create a more equitable society to live in? To begin thinking about this question more deeply, we must consider a few different ideas of algorithmic bias, some clarifications, and then what benchmark we are comparing algorithms to.

When I first read the following ProPublica article about predictive policing (found here) over a year ago, I was caught off guard. I was convinced that there was some sort of problem, but had to work through what exactly the problem was and what that meant with regards to algorithms and the sort of responsibility for software engineers who come up with these algorithms. However, after reading some clarifications of the ProPublica article and some statistical studies showing that the data itself was biased (based on the data that ProPublica published -> they responsibly published all of the data that they used). Now, it’s also important here to define what I mean by bias. In this colloquial sense, I simply mean that the data shows a disparate impact against a group of people based on ethically non-essential characteristics, like race. I also believe that this is a common use of the term when speaking about bias within this context.

Following the ProPublica article, a common reaction is to be up-in-arms against the dangers of such a technology as predictive policing -> will this increase the disparity? Keep it the same such that we can’t improve it? While these fears are justified and legitimate fears to have, it is important to first acknowledge that there is a real problem that this article unearths, but then, not to jump to a conclusion about what is to blame, namely the algorithms. We should not draw conclusions about what to blame simply because of a lack of understanding or a lack of information. It is a major danger and error to jump to a conclusion based off of a lack of information, namely to blame algorithms for all bias simply because we don’t understand what the algorithm is doing. In this case, it turns out that the algorithm itself was okay, but the data was skewed because of bias in the world that already exists. The important point here is that the algorithm itself was constructed in such a manner that it did its job exactly, with no “bias” or mistakes. It just so happened that the data that the algorithm used to make predictions, in this case about which areas were more likely to have crime, was skewed based on an inherent disparity that exists in the world.

If we are comparing algorithms to a benchmark of perfection, then they will fall short. By nature of uncertainty, there will always be false positives and false negatives, although this can be limited by a very good algorithm. However, there are always false positives and false negatives when humans make important decisions too. As an example, consider the study that examined the increase in harsher rulings following the loss of a home football team (https://psmag.com/news/football-team-losses-can-impact-prison-sentences). So what sort of benchmark should we compare to? If an algorithm consistently performs better and more equitably than a human, then should we use that algorithm? It seems that the rational answer should be a clear yes, but when we really think of putting life or death decisions into the hands of a machine, many would likely say that we should not. Then, we should consider what the real difference between the two cases are and why one might be not be comfortable with choosing the algorithm. Is it a lack of transparency? (i.e. algorithmic transparency and education about the algorithm might help). Or is it a lack of an intangible humanity? Moving forward, it will be exceedingly important for us as a society to think about the different ways we can define algorithmic bias in a constructive way and consider which sort of situations the use of algorithms might be okay and why.

Universal Identity: Estonia e-residency

Saturday, October 6th, 2018

This week we discussed a case-study of a country that is actually implementing universal identification systems for citizens through the use of technology. In the first case with Estonia, the government has already, successfully by many measures, implemented an identity system wherein all citizens are given a uniquely identifying public/private key pair, generated by the government, so that citizens are able to fully identify themselves online. This opens up new opportunities for all citizens to have an official identity, and use this ensured identity to vote online, complete tax returns online, obtain and fulfill prescriptions online,  set up businesses, sign contracts, etc. (https://www.theregister.co.uk/2015/06/02/estonia/). There are clearly many benefits with a system like this, and many loosely similar systems exist at less successful and smaller scales in other countries, like social security numbers in the US, etc., but the difference in the scale and success of the Estonian operation with regards to the percent of their citizens who enroll makes the Estonian system fundamentally different than any other. Many interesting questions arise with regards to the Estonian system upon further investigation, and for the rest of this blog I’ll focus on questions of the effectiveness of certain abilities that are created by the Estonian system, namely the ability to vote online.

 

One article regarding the effectiveness of Estonia’s digital government (here), suggests that after the system was implemented to allow e-voting to occur, e-voting actually became less popular, stating that “electronic voting is less popular because Estonians value their new found freedom to choose and many dress up in order to go to their polling station.” This is very interesting because I wonder whether voter turnout as a whole increased because of the e-voting initiative, even though less people actually decide to vote online. That is, even though e-voting is less popular, more people were compelled to go out and vote after e-voting was pushed. Given the potential of this technology and social phenomena that is created through the Estonian e-government system, I am hopeful that there is a way to really increase voter turnout and other functions such as census participation. This would be an interesting social phenomena or experiment to look into. Given the paradigm shift that the Estonian government has brought into being, I feel that there is potential for many of the fundamental issues in the citizenship of a nation to be more effectively addressed through this new system.