📰 Saying the Unspeakable

Recently, I’ve been reading the news and having a bunch of unspeakable (or unpostable) thoughts. Perhaps I should explain. These are thoughts that might be unpopular with the folks that just superficially read the news, who don’t bother to think deeply about the news and consequences, or don’t understand that many issues have deeper complexities than might just be on the surface. Trying to describe these in the short-form post that is FB or other social media doesn’t work well, so I’m turning to my blog. Here are some of these potentially unpopular thoughts:

  • Not Everyone Named in the Epstein Files is a Pedophile. What prompted this thought was Lauren Gunderson. Gunderson is playwright and author; she is actually the most produced playwright of the last 3 years, with many feminist and scientific plays out there. Recently, a theatre company in Rhode Island cancelled a production of Gunderson’s play the Revolutionists (see my review of another production) because Gunderson’s name surfaced in the latest batch of publicly released Jeffrey Epstein-related files. Now, Gunderson has never met Epstein and has never had anything to do with him (as she notes in her response). However, her ex-husband knows him well; one reason (I presume) he is an “ex”. I’ve also seen memes going around saying that anyone mentioned in the Epstein files should be prosecuted and treated as guilty even without a trial.Hopefully, we all agree that pedophilia is bad. But simply being named in the files doesn’t make one guilty of that crime. I write loads of posts and emails that mention Trump; that doesn’t mean I’m guilty of the same crimes. A fundamental notion in the USA is that folks are innocent until proven guilty. The Epstein files should be analyzed, in their unredacted form, to determine those who are likely to have committed crimes. Those crimes should be then investigated to find corroborating evidence, which can then be used by the legal system to bring people to justice. But a simple mention in the files should not be viewed as proof of guilt of the same crimes as Epstein.
    .
    [ETA: There appears to be something similar happening with the boycott against Lifetouch School Photography. Snopes has a nice piece on this, noting that the connection is tenuous. They note: “These claims began because Lifetouch’s parent company is owned by private equity firm Apollo Global Management, whose ex-CEO, Leon Black, has come under scrutiny for his close financial and personal relationship to Epstein. Multiple women have accused Black of sexual assault. Although prosecutors have looked into some of these allegations, Black has never been charged with a related crime. Apollo acquired Lifetouch’s parent company, Shutterfly, when Black ran the private equity firm. Lifetouch’s president at the time, Greg Hintz, was not in the available Epstein files. Further, there’s no evidence that Lifetouch, as a company, conspired with or even corresponded with Epstein. Lifetouch’s current CEO, Ken Murphy, is not in the public Epstein files. Yet because of the actions of a FORMER co-CEO of a twice removed private equity owner (Apollo owned Shutterfly, which owned Lifetouch), schools are cancelling school photo days. This is over-zealousness reminiscent of the McCarthy Red Investigations.]
    .
    And, yes, this means that some guilty men may have finessed the system to suppress sufficient evidence to convince a jury. That’s where the civil courts come in: there’s a lower standard to sue for monetary damages. Remember that OJ was not convicted criminally for the murders of Nicole Brown Simpson and Ron Goldman; he was convicted in civil court. Further, the low moral standards that come from deep involvement with Epstein likely mean there are often other crimes for which there may be more evidence (and prison is still prison). But we must remember that our society presumes innocence, and the mere mention in the Epstein files or a passing association  therein doesn’t mean the individual is guilty of Epstein’s crimes. There needs to be more than a mere mention.
  • Our Current Election System is Suitably Strong to Prevent Non-Citizens From Voting. Recently, the SAVE Act has been in the news. On the surface, this seems like a good thing: We don’t want non-citizens voting in local, state, and Federal elections. Who could be against that? Well, I’m against this act, because it is a backdoor way of limiting the citizens that can vote, serving to disenfranchise the poor, minorities, the disabled, and women. This article explains things well. The SAVE Act requires proof of citizenship, IN PERSON, at the time one registers. The “in person” is a problem for many, especially the disabled and those who cannot travel or take time away from work. It is a problem for the military. The only acceptable proofs of citizenship are birth certificates and passports, and they must match the name on your ID. The requirement for a passport is a problem: A large percentage of Americans don’t have passports because they don’t travel internationally, or cannot afford the cost of the passport (plus the cost of the pictures and other documents). Birth certificates are also a problem, as some folks simply don’t have them due to home births, or can not obtain or afford them. Plus, if people have changed their names, they then need the extra costs of obtaining the paper trail of the name changes, which might not be acceptable (and remember, each government document will have processing costs). Lastly, all of these takes time.
    .
    More importantly, it isn’t needed. We already have laws that prevent non-citizens from voting, and states already require proof when folks register, and match up information in state databases (for example, they should be able to match up information with the Real ID information which also notes citizenship). Further, despite all the claims by the Trump administration, non-citizen voting is not a problem. Recent research has shown that noncitizen voting occasionally happens but in minuscule numbers, and not in any coordinated way. “Noncitizens are not a large threat to our election system currently,” said David Becker, the executive director of the Center for Election Innovation & Research (CEIR), which conducted the research. “Even states that are looking everywhere to try to amplify the numbers of noncitizens … when they actually look, they find a surprisingly, shockingly small number.” The fact that there is a “shockingly small number” means that it isn’t sufficient to impact an election — certainly not at the national level, which is what the SAVE Act is worried about.
    .
    In reality, the SAVE Act is just an attempt to make it harder for segments of the population that are likely to vote Democratic to be able to register. It is just a poll tax in disguise. But to speak out against requiring an ID to vote sounds like you are saying just anyone can vote, which is something very different.
  • Denying Passports Based on Non-Payment of Child Support Is Bad. Another item in the news relates to the State Department denying passports to those who don’t pay child support. On the surface, this seems like a reasonable idea. After all, non-payment of child support is a bad bad thing. But think about this in terms of the requirements of the SAVE Act, and suddenly this seems like a bad idea. After all, the goals of this idea can be met in many other ways: most notably, by simply putting the names on the TSA “no fly” list and watch lists at ground borders.
    .
    [ETA: It was pointed out to me in a FB comment that the No Fly list wouldn’t work: That limits ALL travel; passports only limit international travel. Limiting all travel could impact the ability to earn funds to pay child support through jobs across the US.]
    .
    Here’s why doing this by denying passports is bad: Given the SAVE Act, it can also serve to disenfranchise. Now, we do disenfranchise at the state level for some crimes, notably convicted felons. States could certainly choose to do this for child-support scofflaws. But it should be at the state level. If the Feds could do this by State Department fiat, think of what else they could do. Deny passports to naturalized citizens. Deny passports to people whose parents are citizens. It is just the crack in the door to more voter suppression. This proposal has its heart in the right place, but the implementation is flawed.

So, I’ve said it: Three things that on the surface sound like I’m taking the wrong position. But, when you think about them, you come to realize that the opinions of the “court of public opinion” are often not well thought out.

 

Share

Calm Down! It’s Worse Than You Think!

Folks: With the start of the term of Trmp, the FUD (Fear, Uncertainty, and Distrust) machines have been running full bore. I’d like to urge people to calm down, and encourage people to get past the hyperbole, and to learn the facts of what is actually being done. It is simultaneously not as bad as is being made out to be, and is worse than you might think. As with everything Trmp, the noise and the swirl of what he does often sucks the oxygen out of the room, and serves to hide even more nefarious and significant items.

So, let’s take a deep breath, and go through some recent items and see what is really happening. This is a distillation of a number of recent posts on FB; I’m doing it as a blog simply because I can’t stand the artificial character limits of Bksy, X, and similar services. It also collects some thoughts that have been swirling around my head.

First, let’s look at some of the hyperbole that’s swirling in the ether:

  • Male and Female. Regarding the EO about the government only recognizing Male and Female (and the fact that they wrote the EO wrong, referring to conception): Remember that a number of states once tried to legislate π to be 3. That didn’t work: You can’t legislate nature. Be authentically you, and do your best to ignore the government friction. It will eventually pass, and you are strong enough to outlast it. Always remember that Diplomacy is the art of saying “Nice, doggie” until you can find a big enough stick. They may think they have won, but nature will always win out.
  • What Do You Mean I’m Following Trmp? There’s a big furor on FB about people who suddenly discover they are following Trmp, and believe it is some form of Zuck-Conspiracy. It isn’t. It is what happens during the transfer of an administration. The old administration’s accounts are archived, new accounts are created for the new administration (POTUS, FLOTUS, VPOTUS, WH, etc.), and most importantly, the followers and friends of the old administration’s accounts are copied to the new accounts as a starting point. That’s what happened. You likely followed Biden’s POTUS account, and that transferred over. Simply unfollow, and block if you wish. BTW: If you are worried: Go to your profile. Click on Friends. Then click on Following. Review the list of who you are following, and prune appropriately.
  • Birthright Citizenship. This is an example of the excess I’ve seen on MSNBC, and here on ‘da webs: Trmp is trying to overturn the 14th Amendment. Here I urge folks to read things more carefully. The 14th says: “All persons born or naturalized in the United States, and subject to the jurisdiction thereof, are citizens of the United States and of the State wherein they reside.” Trmp is trying to reinterpret the “subject to the jurisdiction thereof”, which has normally been held to apply children of ambassadors and such, in a very different way. He’s trying to say it applies to children of undocumented folks, or folks here on tourist or short-term visas where the other parent isn’t a citizen. It also wasn’t effective immediately. That likely won’t fly with the courts, and remember that I said the courts are going to be our most effective avenue of attack. But what he is doing is more nefarious, and is not attempting to ignore the amendment completely.
  • Prescription Drug Prices. There are posts going around claiming the Trmp’s EO rescinding Biden’s EO on Prescription Drug Prices undoes the cheap insulin and medicare drug out of pocket caps. That’s not true. Those were part of the Inflation Reduction Act, and EO’s cannot override laws. Read this Reddit chain of discussion. It notes that the primary impact is to halt development of cost-reduction models to reduce drug costs. Without the implementation of new models focused on reducing costs, Medicare and Medicaid beneficiaries might continue to face high out-of-pocket expenses for prescription drugs, possibly affecting access to certain medications. But it doesn’t change the law. Snopes goes into this in more detail.

And while everyone is up in arms about the above (and don’t forget all of his attacks on immigration, which were expected), a number of significant things have been below the RADAR, but are very significant:

  • Artificial Intelligence. One of Trmp’s first EOs rescinded a bunch of Biden’s EOs — one of which was the EO that put guardrails on the use of AI. The next day, he announced a new AI initiative, which his buddy Musk is pissed about. This may be one of the most dangerous under-the-radar things, as AI can be really misused. Biden’s order required developers of AI systems that pose risks to U.S. national security, the economy, public health or safety to share the results of safety tests with the U.S. government, in line with the Defense Production Act, before they were released to the public. The order also directed agencies to set standards for that testing and address related chemical, biological, radiological, nuclear, and cybersecurity risks. Biden’s order came as U.S. lawmakers have failed to pass legislation setting guardrails for AI development.
  • Cybersecurity. Not only did Trmp pardon the founder of Silk Road, a drug and cybercrime locus, but he cleaned out the DHS Cyber Review Board. This will delay an ongoing CSRB investigation into the Salt Typhoon hacks, which involved a wide-ranging Chinese infiltration into a number of telecom providers in the U.S. and around the world. Trmp is also effectively killing the Privacy and Civil Liberties Oversight Board, which is related to privacy issues.
  • Water in California. Trmp is also overhauling water rules in California. He issued a memo that memo calls on the Secretary of Commerce and the Secretary of the Interior to develop a new plan within 90 days “to route more water from the Sacramento-San Joaquin Delta to other parts of the state for use by the people there who desperately need a reliable water supply.” Trmp apparently is asking his agencies to override the latest version of the water delivery rules, years in the making, that the Biden administration, with the support of Gov. Gavin Newsom’s administration, announced in December. Trmp thinks this would have helped in LA’s fires, even though the local reservoirs were already at capacity.
  • Aviation Safety. According to the LA Times, “Members of the Aviation Security Advisory Committee received a memo Tuesday saying that the department is eliminating the membership of all advisory committees as part of a “commitment to eliminating the misuse of resources and ensuring that DHS activities prioritize our national security.”” The aviation security committee, which was mandated by Congress after the 1988 Pan Am 103 bombing over Lockerbie, Scotland, will technically continue to exist but it won’t have any members to carry out the work of examining safety issues at airlines and airports. Before Tuesday, the group included representatives of all the key groups in the industry — including the airlines and major unions — as well as members of a group associated with the victims of the Pan Am 103 bombing. The vast majority of the group’s recommendations were adopted over the years.

Are there things to be worried about, and that are perhaps worth hyperbole? Sure. There’s the fact that Trmp stylizes himself as a King and wants the trappings and the power. The courts will help fight back on that. There are his moves to end DEI, and even more so, to set aside anything in the government that ensures there will be no discrimination (including EOs that go back to Lyndon Johnson). If we had progressed enough that those initiatives weren’t necessary, that would be one thing. But with the rise of Whte Nationalist groups, emboldened by the pardons, expressing a desire for retribution and planning to bring back their groups, there is reason for fear. There are the broader impacts his moves will have beyond the government, such as restrictions he will place on government contractors. There is the clear discrimination that his administration will bring to the marginalized members of society.

Trmp’s MO is to distract us with the meaningless outrage, preventing us from organizing and pushing back in the areas where it really matters. PAY ATTENTION. Remember that we are the fact checkers. We should be checking everything, even the outrage and memes on our side, so that we can focus our outrage, power, and funds where it matters and is most effective. It is up to us to keep our focus on the fight for the next two years, when we can build the case that we must retake Congress to check Trmp.

Share

Post-Disaster Armchair Quarterbacking

When a ship sinks, the rats come pouring out. When a disaster happens, predictably, the armchair quarterbacks come out, with all the reasons they think the disaster happened — even before the victims have time to regroup. Further, in the Trumpworld of today, these folks want someone to blame, and they want that someone to be a Democratic politician, a Democratic theory, a Democratic policy, because we all know that liberals are responsible for all the problems in this world, and if Trump and his conservative ilk were in charge, we’d live in a world of unicorns and guns, and there wouldn’t be any problems.

Geeze, and they think the liberals are smoking something.

This post is MY place to respond to these folks, all in one place. I’m going to collect links and such here so I can find them again. But there are some a key points to be considered above all: Mother Nature is a bitch, sometimes.

  • Suppose there were no water supply problems. OK, but there was still no good way to get the water on the fire. The winds were so high and the smoke was so dense that water-dropping apperatii couldn’t fly and drop, and there were areas that hand crews could not reach.
  • Suppose there were no people supply problems. Fine, but at some point, additional people do not help. There were areas of this fire that can not be reached by firefighters. Strong winds pick up those embers and ignite new fires.
  • We build our disaster response systems for the anticipated disasters, plus a little bit more. The scope of the winds and the firestorm were far more than has been seen in the last 200 years. The system was not built to anticipate that (nor to have the number of fires in the short amount of time that we have had). Further, were we to build a system for the exceptional disaster, it would sit unused and we would then complain about the cost. To put this another way: We build for an earthquake in the 6-7 range. If we got a 10.0, we would be screwed. To put it another way: No one designed the twin towers to be resistant to commercial aircraft flying into them, because that wasn’t in the threat model. Sustained winds of the strength seen Monday and Tuesday, combined with this long of a dry season (normally, we have had some rain by January), is not something we face often.

So let’s look at some of the complaints: (ETA: and, here are some useful refutations from the Governor’s office, for your reference)

  • The hydrants ran dry. This was a complaint from Rick Caruso the night of the fires — the issue was low water pressure in the upper reaches of the Palisades. There was a good fact-check on this from LAist. Yes, there was low water pressure. However, it wasn’t due to mismanagement. The states’ reservoirs were not low. Reservoir levels for state reservoirs are at or above normal for this time of year, and recent releases would not have had an impact. There are 3 over 1million gallon water tanks used to feed the Palisades, and those were full before the fires. However, there was significant draw on those tanks fighting the fire, and they could not refill in time to maintain water pressure. There was one reservoir (city) that was empty for maintenance: there was a crack in the lid, meaning the water was not suitable for drinking and thus couldn’t be used in the system. That happens, and in normal times isn’t a problem. Experts thinks it wouldn’t have made a big difference if it were online.
  • Bass Cut the Fire Department Funding. There were concerns that some recent budget cuts to the fire department impacted response. That narrative, being pushed by the owner of the LA Times, and (of course) Rick Caruso, is false. According to Politico, the city was still negotiating a new contract with the fire department during the budget cycle. Funds for the LAFD were placed in a separate reserve until the deal was finalized in November. In reality, the department’s budget increased by over $50 million compared to the previous year. The Daily News (never a friend to liberals) noted: “On Thursday, a spokesperson for L.A. City Councilmember Bob Blumenfield, who was budget chair last year, said the city increased the fire department’s overall budget by approximately $53 million in the current fiscal year. However, $76 million – intended to pay for fire department personnel – was placed in a fund separate from the fire department’s regular account when the budget was adopted because contract negotiations with department employees were still taking place at the time.” The DN added: “As a result, if you just compare the LAFD’s budget last year to this year’s, it looks like it went down $23M. But that’s because when the budget was adopted last May or June, the city was still negotiating those new contracts. The $76M that was set aside in a separate account ultimately was moved once the MOUs were finalized.” The LA Times provided more information:  “When Mayor Karen Bass unveiled her budget plan for 2024-25, she called for a 2.7% reduction in spending at the Los Angeles Fire Department. Her proposal, unveiled in April, sought $23 million in cuts to the department, with much of it focused on reduced equipment purchases. But while her citywide spending proposal was being reviewed, Bass was also in closed-door negotiations over a major boost in pay for the city’s 3,300 firefighters. Those pay hikes — four years of raises and an array of other financial incentives — were not finalized until several months after her budget went into effect. The City Council approved the firefighter raises in November, adding more than $53 million in additional salary costs. By then, the council had also signed off on $58 million for new firetrucks and other department purchases.”. But the key point came later in the article, when the City Administrative Officer noted “The fire department is authorized to deploy whatever emergency resources are necessary, and those costs will be covered — as they are every year,”. In other words: The budget issues did not impact the ability to fight this fire. It is just like with Caltrans: Emergency expenditures to cover public safety get covered.
  • Mayor Bass Was Out of Town. There seems to be this notion that (a) the mayor (or governor, or President, or …) needs to be in the area when the disaster occurs, and (b) the mayor &c’s presence will solve a lot of problems. That’s bunk. People can schedule trips when they appear to have a clear calendar, and that can include doing city business out of town. Disasters don’t look at the calendar. What’s important is whether the leader has the ability to coordinate things when they are away, and how quickly they return. Bass was on top of the situation, and returned as quickly as she could. The New York Times addressed this, noting: “When a series of dangerous, wind-driven fires broke out on Tuesday in the Los Angeles area, Mayor Karen Bass was on the other side of the globe, part of a delegation sent by President Biden to Ghana for the inauguration of its new president. Ms. Bass, a former Democratic congresswoman who became mayor in late 2022, did not return to Los Angeles until Wednesday afternoon, by which point more than 1,000 homes had burned and 100,000 people across the region had been forced to flee from their homes.”. But the NYTimes also noted that Bass took the fastest route back, and that the city was prepared. Another article noted that: Bass was “in active communication with [LAFD] Chief Crowley, Council President Harris-Dawson, and other local leaders since early [the morning of the fire] and [was] flying home right now after participating in a Presidential diplomatic mission overseas”. It was also noted that the City Council President Marqueece Harris-Dawson  was filling in for Bass as acting mayor (so there was leadership), and the Mayor’s office had outlined their plan for responding to the wind storm and potential fires in an email sent to reporters at 10:56 AM, roughly half an hour after the Palisades Fire broke out and quickly grew to 200 acres. The person behind the complaints about Bass: Again, Rick Caruso, who ran against Bass for Mayor and will likely run again (or run for governor).
  • Faucet from the North. This is one of Trump’s lines: There would have been no fire had we had a beautiful water supply from the North. But Trump doesn’t know engineering. The book Cadillac Desert goes into this. The problem is that the mountains in far Northern California, near Lake Shasta, make moving water from Washington and Oregon nearly impossible due to the cost of pumping. It could be done, but the cost per gallon would make it very expensive. The height differential and distance would make a siphon-based system, as used for the LA Aqueduct, impractical.
  • Brush Clearance. This isn’t referring to localized brush clearance, which was enforced, but a notion that the governor or mayor should have been cutting down dead trees in national forests or parklands. The National Review has a rant on this, and they note that (again) Rick Caruso is a proponent of this attack. There are environmental laws that would prevent that; in addition, these lands are protected against such actions.  The National Park Service of the Santa Monica Mountains National Recreation Area contends that controlled burns are not an effective tool in their particular ecosystem. “Prescribed burning is not effective in limiting the spread of wildfires under the conditions that burn the largest amount of land and cause the most home losses. Native shrublands are being burned too frequently because of human ignited wildfires. Prescribed fire does not fulfill any identified ecological need in chaparral or coastal sage scrub and would increase the probability of a damaging short fire interval following a prescribed burn.” I recall some articles noting that prescribed burns make things worse, as they replace slower burning trees with faster burning grasses that put out more embers, making things worse.  There are debates ongoing in this area. But the key fact is this, as KQED notes: “Even if the U.S Forest Service had continued to allow burning, it would not have prevented this week’s devastation from deadly fires that have destroyed thousands of homes. The fires we’re seeing are primarily spreading through urban neighborhoods, with the possible exception of the Eaton Fire that is burning, in part, on federal forest lands. Given the wind, weather and location of the fires, it’s unlikely a controlled burn would have stopped the disaster. The houses and surrounding vegetation are fuels in communities that were not designed for fire resilience when they were planned decades ago.”

In short, we’re seeing attempts by politicians — primarily Conservative politicians who love to cut funds for services — to use these fires to further their political ambitions. They have no concern about helping the people on the ground. They just want to increase the anger and political temperature, and fan fires of a different nature.

Share

News Chum: Just the Facts, Maybe

I haven’t done a “news chum” post in ages, but this seems strangely appropriate to do here, on my blog, as opposed to Facebook. In recent years, I’ve moved much of my comments on news and stuff over to Facebook. Today’s chum is about Facebook, and it seemed just to, well, meta, to comment about it directly on Facebook. The universe might implode, or something like that.

The news today is that Meta is getting rid of fact checking. According to the CNN article, they are “replacing them with user-generated “community notes,” similar to Elon Musk’s X”. They are doing this to supposedly address the perception of censorship (never mind that as a private organization, that term really doesn’t apply), and the feeling from the right that fact checking is used more to suppress posts from the right than from the left. [Of course, the flaw in that argument is that non-factually posts are equally distributed across the political spectrum, and that tends not to be the case: in other words, the far right has posts fact-checked more because they are posting more posts that are loose with the facts.]

I’m sure that, in response to this, folks are going to be kermit-hand-waving (think of that GIF) and stating they are going to flee FB. But are the other services better in this? I searched to see what Bluesky is doing, and they are doing the community notes as well. In general, Bluesky’s moderation seems to be community based and report based, and you choose the moderation that you want as opposed to a blanket enforcement of a policy. Is that better? Hard to say. It just looks like the appeal of services like Bluesky and Mastodon is that they aren’t owned by folks that are sucking up to Trump, as opposed to something specific in the service. But the same “better ownership” model would also apply to the post-Livejournal services such as Dreamwidth — and Dreamwidth has the advantage of being able to limit audiences and writing longer-form pieces.

I’ve never quite gotten the hang of X, Threads, or Mastodon. I’m not into the short-form posts that Twitter encouraged, and it also seems like everything is publicly shouted into the wind, hoping to find an audience (which hash-tags help with, but those aren’t working as well these days thanks to idiotic overuse). More folks I know moved over to Bluesky, but what I see there is mostly political articles and other article sharing. There’s much less sharing of what is happing with the person. The things that you might talk about between friends — what we used to have on the blogging services — is still primarily on Facebook. That’s also where the mass of people still are.

So this is a long form way of saying: Despite its flaws, the personal stuff is likely staying on Facebook, unless there is a mass exodus of my friends moving that stuff elsewhere. I’m not seeing it on Bluesky. I might return to more news chum posts, and then sharing blog posts across multiple services, as a way of finding out where those communities have moved to.

Share

🇮🇱 So, About Israel

With all the discussion about what is happening in the Middle East, and all the discussions about Israel and Palestine, I thought I should make some things clear:

  • unequivocally  support Israeli’s right to exist as a nation, and as a space where Judaism can be practiced safely. The land where Israel is located is the traditional homeland, going back to biblical days. We can quibble on the exact borders, but the current borders — which exclude Gaza and portions of the West Bank, are as reasonable as any.
  • Many — but not all — of the Arab and Palestinian groups that are involved in these battles have as a fundamental tenet that Israel does not have the right to exist. At all.  A Hamas member stated today, “Israel is a country that has no place in our land. We must remove that country because it constitutes a security, military and political catastrophe to the Arab and Islamic nation and must be finished.” You can not negotiate with organizations and nations from a position where they deny your right to exist. Simple as that. Were they to recognize Israel’s right to exist in some form, a solution can be achieved. While they refuse to do so, a solution is not possible. Note that Israel has recognized the right for some form of Palestinian nation to exist, by ceding the land of Gaza and portions of the West Bank. Note that other Arab nations have not provided land for the Palestinians, even though the land was part of the same British mandate.
  • Hamas is behaving much like ISIS did on 9/11: They specifically attacked civilians to create terror, and have specifically located their facilities in civilian areas because of the PR benefit they gain when their military facilities are attacked and civilians are harmed. Hamas has specifically made the decision to put their population in danger. Israel’s war is with Hamas, not the civilian population. Hamas has made it nearly impossible, however, to root out the terrorists without collateral damage.
  • That said: Support for Israel does not mean I always agree with the actions of the Israeli government. Judaism is not the same as Zionism; support for the nation of Israel is not the same as supporting their government. I love and support America; I despise Donald Trump (especially when he was President). I do not agree with all the actions taken by Netanyahu, although I do agree that Israel has the right to go against Hamas, just as America went against ISIS.
  • Israel has not always treated its Arab population well. It didn’t treat the established population of Gaza and the West Bank well when it governed those lands. That fact cannot be changed, just as America has no excuse for its abuses in the areas of slavery, or in the abuses of the internment camps, or in any other form of racism that has occurred. That can only be corrected moving forward (and is unlikely to be corrected under Netanyahu, alas); and will only be corrected once said population is not trying to wipe Israel off the map. That really is the fundamental problem.
  • There is no excuse for antisemitism.  Period. End of story. In particular, Jews throughout the world are not the individuals who have governed the Palestinian areas. That treatment is not what Judaism believes in. Dislike or even hate the current and past Israeli governments if you feel that way, but do not take it out on Jews throughout the world. The same is true, by the way, for anti-Muslim hate. Hate Hamas and these terrorist organizations. Do not hate the Palestinians or Muslims, who outside of those organizations are peaceful and kind people.

Let us all hope for the day, when each side recognizes the other’s right to exist in the Middle East, and we can work to negotiate a settlement based on that recognition, and the fact that beneath it all, we are all monotheistic siblings with a shared basis.

Share

🗯️ Thoughts on a Breach

I haven’t written a real blog post in a long time, but this one is floating around in my head and insisting to come out.

For the last few months, I’ve been following closely the breach that occurred at Lastpass. You may have heard about it. It’s been all over the technical news feeds, with lots of fear, uncertainty and distrust. It was of particular interest to me, as a long time Lastpass user. These articles make it sound like Lastpass is the most insecure password manager out there. They advise everyone that their “vaults have been stolen” (not making clear it was the encrypted vaults, and the purpose of encryption is to protect information if it does get stolen). They advise everyone to change every password. They advise people to run screaming away from Lastpass to other password managers.

Their tone strikes me as off. It reminds me of the days when everyone piled on Microsoft for what we later learned was probably no good reason, for Microsoft had been moving in the right direction. Their tone — to me — sounds like risk-adverse panic. They are scaring people away from this product because of a risk that really isn’t as bad as they make it out to be.  There are times I wonder if there is an agenda behind those articles (and my mind even wonders at some times if a competing password manager wasn’t behind the attack — after all, you don’t have to do anything with the vaults to damage the market leader — the attack is sufficient).

I’ve read the latest blog post from Lastpass closely. I suggest that you do as well. Here’s what I take away from it.

First, this wasn’t a flaw in the product. The flaw — as it is so commonly — was on the human side. Social engineering was used to attack an employee’s home computer, and that employee hadn’t adequately patched their home computer. This is quite common, and to expect perfection in how people maintain their home machines is wrong. It also seems clear that this employee — and Lastpass itself — was targeted by an adversary. That tells me this wasn’t a typical “scoop up the data and sell it”. This was a targeted spearphishing attack, likely with some specific vaults in mind. That’s evident in how the attack went down, and the fact that the data exfiltrated hasn’t shown up elsewhere. For all we know, this was a government adversary targeting a specific individual they learned had a vault.

ETA: Could the breach have been stopped with a product patch? Possibly. But remember here that the attack was on a home computer, not a work machine managed by LogMeIn. On your home computer, do you install every patch on every third-party product? Most people don’t. There’s some hygiene and education to be done here, but it isn’t a product flaw.

The takeaways from this, for me, are:

  • The product is not inherently flawed. It uses a reasonable scheme to protect the vaults, and suffers from the same risks that any product that stores stuff in the cloud faces. The vaults are protected with a strength commensurate with the user chosen master password and iteration count.
  • The nature of the attack is something that could happen at any password manager product: targeting developers at home. That’s even true for open source products: open source products may still store user data in the cloud, and that data can be compromised.
  • Corporate training may be weak, but corporate training overall is weak, and people are often the weakest part in any company.
  • This was targeted attack. If you are a high-value target, I’d be worried. If you are the run of the mill user, I’d be much less worried. It is likely not worth the adversaries effort to attempt to decrypt your vault.

Second, should you change all your passwords? I think the clear answer here is “no”, not all. If you choose to change anything, you should make your determination based on what the password is protecting. Is it a bank or something vital, such as your domain configurations or DNS? Is it your social security account? Is it your email account? Change it. But you should be changing those passwords on a regular basis anyway, and enable MFA. But is the password for something like Slice or Lands End or Disqus. I wouldn’t worry. So they order a pizza on a credit card number they can’t see. You dispute the charge, unless they delivered it to you and you enjoyed it. The risk isn’t there. I’d venture you would only need to change about 20% of your passwords, if you have as many throwaway accounts as I do.

This, of course, is presuming you follow best practices. Create a unique account for each site; don’t rely on your Google or FB login. Have strong unique passwords for every site. Enable MFA where you can. These are all best practices you should know if you’ve been trained. You’re not that weak link, are you?

But do you need to change your passwords? The answer here is: it depends on you and your comfort level. They’ve already got the encrypted vaults. At minimum, you should change your vault master password to something long and strong (I recommend using xkpasswd or the pronounceable password generator and doing further conditioning), change the number of iterations to 600,000, and if you are using MFA, change the randomization seed. Details are in the Lastpass bulletin, and simply provide additional protection going forward. Should you be worried about what was stolen? I’d worry about adversaries using the non-encrypted information for phishing, so be extra careful with texts and emails (but then again, I believe that most of the data scraping attacks are collecting information for spearphishing, as it is easier to convince you to give me the data than to attempt to brute force it. See this XKCD). If you had a really weak master password and low iterations, change your key passwords and look for indications of attack. But remember: you’re likely not the target.

The takeaways here are:

  • You don’t need to change all your passwords
  • Change your vault passwords, iterations, and MFA seed on general principles.
  • If you had a weak master password, change key passwords protecting financial institutions, major accounts (email, FB), and DNS/domain related accounts.
  • Take a deep breath.

Third, do you need to run screaming away from Lastpass? Again, that depends on your comfort level. Although their latest communication was good and detailed, they sucked on communication up to this. I attribute that partially to timing, as they were being divested away from LogMeIn and that introduces a certain chaos in corporate communications. But they were also probably holding things close to the vest until they improved processes. Reading their longer term plans, I think they are significantly improving things and so their update product will be more secure. They are certainly retraining their development team. I particularly noted “Working to encrypt URL and URL-related fields in the vault BLOBs.” That’s a good thing.

Moving away from Lastpass has certain costs. There is the friction in moving the vaults (and moving your vault does nothing to protect you from this breach, as the general user information and encrypted vault data was already stolen). Arguably, it puts your data in more places to be stolen, as it doesn’t delete data from backups and such. There are also usability issues (Lastpass is an extremely easy to use product), and with the paid product, the features of the Family plan were excellent.

The takeaways here are:

  • Lastpass sucked at communication during the process, but has now finally given good details. They lost trust due to how they handled this, which is a lesson we all should learn from.
  • The improvements they have made, and are making, are good and increases confidence in their product.
  • They could do more: increased training of employees, increased emphasis on awareness, and increased practical exercises on recognizing phishing are key. Increased restrictions on what computers can connect to them, combined with techniques to ensure those computers are configured properly. Those may be coming, or perhaps they weren’t explicitly mentioned.
  • Every user should balance their risk tolerance with their likelihood as a target and the value of the information being protected. Be realistic, and understand the frictional costs in moving platforms.

Am I going to abandon Lastpass? Probably not. But I have changed master passwords, increased iterations, and updated MFA seeds. I’ve also changed passwords on critical accounts, and enabled MFA in more places (using an authenticator app instead of SMS when I can). I’m also keeping an eye out for any anomalous activity, but then again, I always do that.

Share

👩🏼👨🏾👧🏾🧑🏼👩‍🦰 From Mistakes and Missteps Comes Learning and Realization

For some reason, the whole mess at Gimlet Media related to the Reply All Test Kitchen series and its fallout, which I wrote about in my last post, has continued to fascinate me. I’ve been reading tweet threats by those involved and related: Eric Eddings, Starlee Kine, PJ Vogt, Sruthi Pinnamaneni, Alex Goldman, the Gimlet Union, Emmanuel Dzotsi, and others. As a long time listener, I never quite understood what the Union drive at Gimlet was about. One sees a company by the image they project, and I viewed Gimlet through the eyes of the Startup Podcast and Reply All, through Science Vs and Little Known Facts. This incident has made me realize that what I saw was a facade. More importantly, looking back, it showed they didn’t listen to what they were reporting.

As I noted in my last post, at the time of the starting of Gimlet, Alex Blumberg noted that there were major problems with diversity in Gimlet’s staff. They planned to do something about it. In an episode of Reply All that I cite to this day, they explored why diversity was so important in the workplace: when you hire people from the same background and the same institution, you always get the same view and the same answers. Yet even with that reporting, the recent Test Kitchen series and the subsequent fallout made clear that Gimlet didn’t learn. They hired the team and people from other podcasts they knew: from This American Life and Planet Money and NPR — all of whom had the same views and background and cliques. Just like the Bon Appetit situation they wrote about (at least from what I’ve been reading and hearing), they didn’t give spaces for the other voices. Well, perhaps they did for a short time, but they didn’t last. It was tokenization, not representation. At least, that’s from what I’m hearing and reading. I’m a long time listener, not a podcast. Just like with live theatre: I’m an audience member, which is vital for the industry.

But what is more disappointing is that this pattern of behavior is common across the podcast industry. Helen Zaltzman and the Allusionist podcast left Radiotopia. Why? Zaltzman cited a lack of racial diversity at the Radiotopia: “I have raised this fact repeatedly, recommended existing shows or potential showmakers to approach, questioned the excuses given for why the line-up stayed very white – small capacity and limited resources and insufficient money were frequently cited. So I offered money. And now, in case it makes more space and resources available, I’m removing myself.”

The problem is real. Stephanie Foo wrote a piece in 2020 about diversity problems in public media. It was her third time having to write the article, because people were not learning.  She first wrote it in 2015. In the introduction to that article, she noted: “It’s about time that public media came to terms with the fact that it does not serve the public as a whole. More hosts and program directors realize that a market of POC exists — and if they don’t cater to it, they’ll fail to grow their audience. And I’m glad the people in charge are realizing that when it comes to attracting minorities, throwing some hip-hop beatz as a transition between stories is about as effective and transparent as Mitt Romney’s spray tan. Finally, finally, it’s becoming abundantly clear that the solution to our diversity problem is hiring producers of color, and that diversifying your business is smart from a content perspective.” But did people listen? Did they really change their workplaces? Evidently not.

Back in 2015, Wired wrote about the lack of diversity in podcast voices: “Don’t replicate the stale listenership of public radio, and offer yet another way for the same culturally dominant demographic to tell each other their ideas. Rather than build a wider network of white male voices and listeners, let’s take the momentum and support of networks to promote some podcasts featuring everyone else.” There was an article on this in 2016. This was pointed out again in 2017: “Diversity is another huge challenge faced by the podcast industry, according to the report. As of mid-2016, only a few of the top-100 iTunes podcasts — shows like “Code Switch” and “Snap Judgment” — were designed to amplify diverse voices. Most podcast hosts are also male.”

But just as with theatre: diversity in the hosts at the front is only the visible tip. Diversity needs to be throughout: from the researchers to those pitching the stories to those producing to those editing to those marketing to those … The Reply All podcast perhaps said it best back in 2016:

LESLIE says that Twitter’s lack of diversity doesn’t just affect the workplace atmosphere, but it goes straight to the heart of the product itself.

LESLIE: Obviously if you don’t have people of diverse backgrounds building your product, you’re going get a very very narrowly focused product that may do one or two things really well or just may not do anything really well. And if you look at Twitter as a product, it doesn’t a lot of the simple things. It doesn’t do direct messaging well. It doesn’t do media sharing well, right? And if you had people from diverse backgrounds, you may have been able to expand, you know, what what you thought was possible?

GOLDMAN. Let me ask you this how must of your desire to see diverse workplaces comes from the fact that it’s just morally correct to have diverse workplaces versus it will make your product much better.

LESLIE: Yes. The answer to that question is yes. It’s going to, you know, diverse teams have better outcomes, that is, there’s so much has been written on that in the last 30 years I don’t even know why we’re talking about it. And and I think, you know, I hate sounding like, you know, like a total socialist, but arising tide lifts all boats.

Looking back at this transcript, you know what stands out at me? Who did the interview. Alex Goldman. Not PJ.  And in the latest problems at RA, who was there arguing for diversity and its benefits and the union. Goldman.

As audience members — as listeners to podcasts — I’m starting to wonder if we are hearing but not listening. The problems with diversity have been there. People have been talking about them for years. They have been writing about them. But I’m not sure we have been hearing. But they have been coming to the foreground now. We are learning about the problems at Radiotopia and Gimlet. It is just like how in mid-2020, we because to learn and understand about the problems in the Broadway theatre, and that we needed the diversity throughout.

So what can we — as the audience — do. I think we need to let the podcasting companies — Spotify, Earwolf, NPR, etc. — know we want diversity throughout. Not a host here and there, but in the research, writing, producing, and technical staffs.  We need to find podcasts that exhibit those characteristics and make it know that we are going out of our way to listen to them, and that we want those diverse viewpoints. Although I’m pretty backed up on podcasts, I’m open to recommendations for podcasts that fit this mold.

I also hope that Gimlet uses this incident to do what it does best, and what it did when it started: Turn that microphone on itself. I’d like to see the remaining hosts at RA — Alex and Emmanuel — explore how diversity went wrong at Gimlet, going back to when the problem was first cited in 2015, to when RA touched on the importance of structural diversity back in 2016, exploring the diversity problem in the podcasting industry. They might even be able to salvage some of the Bon Appetit story. But most importantly, I hope they can talk about how the problem is being solved, and being solved in a permanent, long lasting way.

Share

📰 Diversity, Gimlet, and Hindsight

As you know, I listen to a lot of podcasts. Fewer, since I’ve been working from home; but still, I listen to a lot of podcasts. Today on my walk, I made a special effort to listen to an episode of Reply All from Gimlet about the mess at Bon Appetit, the first episode of “Test Kitchen”. This came about because an article in the LA Times talked about how Reply All had discontinued this podcast after episode #2 of 4. Why? Here’s a quote:

The decision comes after a former Gimlet staffer accused two members of the “Reply All” team of creating a “toxic dynamic” at the company. Eric Eddings’ allegations went viral on Twitter earlier this month and prompted the departures of host PJ Vogt and senior reporter Sruthi Pinnamaneni.

After this, one of the remaining hosts Alex Goldman posted a 2 minute message that noted:

We now understand that we should never have published the series as reported. And the fact that we did was a systemic editorial failure.

So, although I had been waiting to listen to the episode for a while, thinking it would be similar to a series from The Sporkful, I now understood this was different. And listening to it with the benefit of the additional hindsight, it took on additional meaning.  But more importantly, it made me think back to an episode of Reply All from 2016 that I loved, about the importance of diversity in the workplace. It explored diversity at Twitter. It made me think of an episode of Gimlet’s Start Up podcast that explored diversity at Gimlet, where the host noted:

If you were to walk into Gimlet HQ, there are a few things you’d probably notice right off the bat. First, it’s crowded – like a grungy dorm room. Second, the lighting… it’s not great. Not many windows. Third, it’s white. Really white. 24 of Gimlet’s 27 employees are white. In this episode, we look at diversity (or lack thereof) at Gimlet. And we try to figure out what diversity should mean for the company going forward.

It goes to show: you can talk about diversity all you want, but if you don’t learn the lesson … if you don’t make that workplace better .. you fail.

I look forward to future Reply All episodes where they address this.

Share