Issues of Ethics and Responsibility with Internet Information Quality

AUTHOR
Laurie A. Smith King

ABSTRACT

Initially, the Internet connected but did not inform; the interface was insufficient to fully keep the promise of information sharing. Today, the world wide web and attendant search engine technologies offer an unprecedented ability to distribute information effectively. Increasingly people rely on the Internet as a primary source of information, and even traditional sources of information such as newspapers, journals, magazines, radio, books, and television are adding an Internet component to their distribution. But to use this information, people need to make judgements about the veracity and quality of the information they receive. How do we make these judgements about Internet information?

At present, there are very few real controls, little accountability, and the quantity of on-line information that is false or misleading is disturbing. The Internet makes it possible to broadly disseminate huge amounts of false information relatively anonymously. There are fewer ‘brand-name’ identifiers that aid the consumer of on-line information, and when traditional media go on-line, the rules are often different for their on-line counterparts. For example, the printed bestseller list of the New York Times comprises 34 books in 3 categories, whereas the on-line version consists of 370 books in 12 categories.

Email has also evolved into an information conduit in unexpected ways. Scores of ‘information viruses’ proliferate in which misinformation and hoaxes are passed on via email, often with the best of intentions. Although most would not Xerox an article and send it to dozens of their closest friends and relatives, people forward email broadly without a second thought. It is simpler than ever to reach a wide audience with information which lacks proper attribution of sources, or contains only sloppy attribution. We need to understand the level of responsibility one should take when quoting a web-source or forwarding unverified anecdotes in a piece of email. In some sense, forwarding is the same as publishing. At what point do we cross the line from free Internet speech to yelling fire on a crowded network?

Yet another issue is plagiarism based on Internet sources. For example, there is increased plagiarism among high school students downloading papers whose spelling mistakes, grammatical errors and vapid content make them virtually indistinguishable from actual papers by students likely to cheat in this way! Some teachers have reacted by modifying writing assignments to require students to submit handwritten notecards, outlines, and research notes.

Part of the attraction of the Internet is the potential for alternative cyberspace communities where prejudices based on physical appearances cannot operate because one’s identity is defined differently. Yet we are less experienced with how to safeguard digital identities. For example, identity theft consists of ‘stealing’ facts about another person, using the facts to get credit cards and run up a debt, and then shed the identity. How can we trust that people are who they claim to be on-line while at the same time respect and protect one’s identity?

Another phenomenon is that of “evaporating information” such as a reference to a web site which no longer exists. The use of URLs as references and sources for additional information in journals is becoming more common-place. How reliable and long-lived are such references compared to “hardcopy” references? In cyberspace, where is the library and who is the librarian? What responsibility does an author incur when using a URL as a reference?

This author believes that the same technology that spawned these problems, can play a part in their solution. Like a vaccine, the disease can be part of the cure. The same power harnessed to spread misinformation quickly can be used to ferret out the truth. This paper will discuss these and related issues, and the role technologists can play.

Regulating Digital Identity

AUTHOR
Richard A. Spinello

ABSTRACT

As we approach the new millenium there will be many contentious debates on the need for new Internet regulations. Proposed content controls and encryption policies have already sparked major controversies in the United States. The Internet empowers its users and provides for an immense expressive capability, but there is a tendency on the part of the state to reimpose central controls and curtail that power.

One issue that continues to come under intense scrutiny is digital identity. At present, there is no uniform system or mechanism for identifying users in cyberspace. The Internet does support architectures that make identification possible including passwords, e-mail addresses, and Internet Protocol addresses. But it is still quite possible for users to interact in cyberspace anonymously, and it can be difficult to trace the real identity of users who are deliberately trying to conceal their identity. While anonymity supports privacy rights, it also interferes with security. Hence the lack of an identifying infrastructure has been detrimental for electronic commerce and for law enforcement.

The interconnected issues of digital identity and anonymity are highly charged ones which stir deep emotions. This was evidenced by the heated response to Intel Corporation’s announcement in February, 1999 about its plan to put identification numbers in its next generation of computer chips, the Pentium III’s. The primary purpose of the embedded serial numbers is to authenticate a user’s identity in business transactions and to allow organizations to better track their equipment. While Intel capitulated to pressure and agreed to ship its products with the serial number turned off, the incident has heightened awareness about the tenuous future of electronic anonymity.

In this paper we intend to examine the various options for a digital identity system. Any system will be located on a continuum from accountability to anonymity. At one end of the spectrum (anonymity) there is no link between the data in cyberspace and its originator, and at the other end there is an indissoluble link between one’s cyberspace identity and one’s real identity, which is accomplished by mandating traceability. Mandatory traceability might be achieved by making identification a prerequisite for Internet access. In this discussion we will also review various technical architectures such as digital certificates which can be implemented to achieve the correct level of identity on this spectrum.

The state obviously has a keen interest in regulating identity to provide greater security for the Internet economy and to deter criminal acts such as fraud that are facilitated by the cloak of anonymity. These regulations could take many forms and also fall on a spectrum. They can range from a regime of laws that stiffen the penalities for fraud and identity theft to the establishment of an identity infrastructure managed by a government agency.

But should the state regulate digital identity, and, if so, how should this be done? As we grapple with this critical question we will consider the costs and benefits of various regulatory schemes. We also consider the ramifications of non-intervention by the state — the possibility that private corporations like Intel will fill the vacuum with their own identifying mechanisms for tracing the identity of end users.

In the context of this discussion on the feasibility of state regulation we must come to terms with the following questions. In what contexts in cyberspace does the state have the right to require one’s identity? Can the right to anonymous free speech be balanced with the need for identification? Can traceability be mandated in a way that preserves some degree of Internet anonymity?

An important part of this discussion will be a brief reflection on anonymity as a key element of privacy. There is pressure to differentiate privacy from anonymity, to claim that the “right to be left alone” is not the same as the right to surf the Internet in secrecy. In our estimation, those pressures should be resisted. We will make the case that real privacy requires anonymity in some circumstances and that any efforts to control digital identity must respect a user’s preference for anonymous communication.

We will also take the position that there is a modest role for the state to play in regulating digital identity, but that its involvement should take the form of creative legislation. We support a digital identity system that facilitates a user’s options: there will be times when an authenticated identity should be required in cyberspace, but there are other times when users should be allowed to communicate anonymously. We reject any solution which establishes a perfect link to one’s real identity by mandating the traceablity of all communications.

On the Moral Scrutiny of Two Kinds of Information Security Activities

AUTHOR
Mikko T. Siponen

ABSTRACT

Information security solutions have an increasing role in the information age given that security solutions technically ensure or deny access to information. Literature analysis from security research and practice suggests that certain information security activities, even when done within basic research, are morally debatable. This is true even though security personnel are often interpreted as being ‘the good guys’. The morally questionable activities that seem to occur rather widely mostly encompass the concept of lying. Database security is the first area where an important requirement, in the level of basic research, comes from a need for lying. The analysis of the aforementioned is close related to the ethics of the philosophy of technology. Are such security solutions or basic research (e.g. to maintain cover stories) wrong per se, or are they value-neutral (as scientific basic research is often interpreted to be), but used in a way which is moral, amoral or immoral?

The other issue under consideration concerns the general public in the information society. This is not a matter of basic research, but rather a problem that appears at the very end of applicatio. It concerns ‘lying’ with respect to the security of technical solutions, such as different transaction protocols. For example, that our SSL solution is 100% secure, that GSM encryption cannot be broken, and so on, are very general, albeit fallacious claims (as these techniques, for instance, can be broken in algorithm or software implementation level) presented in this respect.

The research question of this paper is to analyse the possible reasons and moral statuses of such claims and activities. In addition to the philosophy of technology generally, these issues are analysed through Kantian ethics including the impartial universality thesis advocated by Hare and Rawls and through the theory of information ethics by Floridi. Conceptual analysis is used as the primary research method to yield the results.

Could Computer Ethics Spark a New Moral Generation? – An Australian Perspective

AUTHOR
Chris R. Simpson

ABSTRACT

This paper asserts that current Higher Education students in Australia, reaching the third year of their course, have generally thought little about ethical issues, especially ethics relating to the Computing and Communications discipline. It presents initial responses made by a group of students entering a Computer Ethics subject in the third and final year of their Computer Science course. It explores why their initial outlook may be so. It goes on to compare and contrast various individual, initial views with those declared at the end of the one semester subject.

Student responses indicate frequent significant, personal changes in:

  • ethical awareness, depth of perception and ability to argue,
  • perceived relevance of the subject to one’s prospective career,
  • enthusiasm and willingness to question community values.

An appreciation is developed that eagerness, sensitivity, vision and courage are all needed to face opposition and to propose changes to entrenched outlooks in industry.

Although it has been convincingly argued [Gotterbarn, 1995; Martin, 1997; and Grodzinsky, 1998] that practical ethics can be successfully integrated into ordinary subjects of a degree course, this study suggests that there is still value in a sole, capstone subject. The value goes beyond that reported earlier [Simpson, 1996] and stems largely from the concentration of effort and depth of involvement required of students by the strategies used in this subject. Admittedly, it depends heavily upon teaching staff attitude. The nuances are developing with every semester.

Pursuing the indicated value to students of an in depth, concentrated experience obtained in this single non-technical subject in an otherwise purely technical degree course, the paper proposes that the symptoms of students entering computer technology courses are shared by those entering any other purely technological courses such as applied science and engineering, as well as those not usually thought of in this light, for example accounting, economics, business and management. All of these appear to have developed the same dearth of non-technical subjects, leaving social and ethical skills to be obtained in the workplace. Yet such skills are needed as frequently as technical skills in one’s career, from the outset [Simpson & Burmeister,1998].

Computer Ethics appears to be a pilot arena for many disciplines, by virtue of computer technology and communications applications that touch and therefore become relevant to each of these disciplines, their practice and their educational curricula. This subject could be adapted quite easily to suit almost every course in the university.

This one-subject, last ditch approach to humanising courses is only relevant whilst the current global morality persists. In this climate, economic tyranny dominates, human and environmental values count for little and a “moral cringe” has developed that dissuades moral training in schools, such that a useful and continuing ethics component in secondary and tertiary training is not forthcoming. That is the situation in Australia at present. On the other hand, there are symptoms of an awakening occurring. Perhaps we are part of that.

There has been a succession of three generations in Australia described as the Lucky Generation, the Baby Boomers and currently, the Options Generation (sometimes called the Baby Busters) [Hugh Mackay, 1997]. The last of these have been set adrift in an ever-changing world, a culture centred about the individual and limited values. These are today’s students. Yet, with a little prompting, they are quite ready to question the validity of a system that pays little heed to human and environmental sustainability and seems to be on a collision course with crisis. It is my fond hope that these are the future stimulators of a new generation, that will achieve a broadened value system, demerit greed, reintroduce human dignity and might be called the Renaissance Generation.

References

Gotterbarn D. [1995] A Tool Kit of Computer Ethics Activities for computer science classes, Proceedings of National Educational Computing Conference, Baltimore, MD.

Grodzinsky F. and Grodzinsky S [1998] Integrating Ethics into the Computer Science and Engineering Curriculum. AICE October Seminars, Swinburne University of Technology, Australia, October.

Martin C.D. [1997] The case for integrating ethical and social impact into the computer science curriculum, ITiCSE ’97 Working Group Reports and Supplemental Proceedings, ACM, Jun.

Mackay, Hugh [1997] Generations: Baby Boomers, their Parents and their Children. Pan Macmillan, Sydney.

Simpson C.R. [1996] University Courses and Ethics – Using Collaborative On-the-job Education, Proceedings, ETHICOMP96, Madrid, Nov, 427-442.

Simpson C. and Burmeister O. [1998] New Professionals, New Measures of Worth, New Ethic of Collaboration. Proceedings of ETHICOMP98, Erasmus University, The Netherlands, March, 650-661.

A common sense approach to the Corporate Contradiction (How a Local Authority manages the New Data Protection Act)

AUTHOR
Paul Simpkins

PUBLISHED IN
ETHICOMP Journal Vol 1 Issue 2

ABSTRACT

I was appointed to the post of Data Protection Compliance Officer in the summer of 1998 following a report to Council Management Board stating that there was no co-ordinated approach to Data Protection in Bradford Council and in anticipation of tougher regime with the new act. Data Protection had been under local control for ten years and there were pockets of good practice but entire wardrobes full of bad practice.

My brief was wide. Carry out a data audit, raise awareness via training, manage external liaison, work in a co-ordinating role to pull the various strands together and to be involved with policy-making especially in the area of IT legislation which for some reason seems to be the filing cabinet into which Data Protection had automatically been placed.

Data Protection is a difficult subject on which to deliver training. It’s rather dry and much of the time involves balancing the rights of individuals on the scales of competing legislation. If you hear a speaker from the Information Commissioner’s office they clearly know their onions but jump from Schedule 3 to Principle 7 without shedding a single tear. (That’s from conditions for processing sensitive vegetables to security of kitchen knives if you weren’t sure…)

I opted for a more practical approach which would involve relating the law to incidents which happen within the experience of the staff at Bradford Council. I was keen to involve both Legal and Audit as allies in this operation and I was fortunate in meeting two people who thought the same way. Between us we evolved the Bradford Way… In this paper I hope to outline the aims and objectives of a Data Protection Compliance Officer working in the public sector. I will offer an insight into the life of a Data Protection Compliance Officer. Wherever possible I will bring in examples from real life to illustrate the points and I hope to give you some indications of how this important piece of legislation will be managed in the future.

The new Act is a small step for man but is part of a whole flight of stairs for personkind in Bradford. We have to consider the Crime & Disorder Act, the Public Interest Disclosure Act and soon the Freedom of Information Act. Central Government is promoting the delivery of services by electronic means and Local Government is being encouraged into more and more partnerships with external agencies where sharing of data becomes the norm. These have to be properly managed and the rights of individuals need protecting.

Where Information Society Meets Information Economy: Some Implications of Personal Information for Market Fairness

AUTHOR
Stuart Shapiro

ABSTRACT

Viewing information strictly as a commodity limits rather than expands our understanding of the “information society” and the “information economy.” Although we must now contend with new types of information-e.g. personal genetic markers-as well as old types of information in new contexts-e.g. textual information distributed over the World Wide Web-the worldview which perceives and situates information as a commodity is as old as notions of intellectual property dating back to the Renaissance. What is needed, among other things, is a framework which takes seriously the distinctly modern interaction of personal information and market activity and its impact on economic fairness. Issues of information and fairness have received attention in the economics literature, but current developments in information and communication technology raise them to new prominence. It behooves us, then, to carefully consider how an information economy should relate to the society in which it operates.

The example discussed here is the customer loyalty programs used by many supermarkets in the United States and the United Kingdom (and perhaps in other countries as well). These programs reward shoppers with discounts and other forms of compensation in return for allowing their purchases to be tracked as well as matched against demographic profiles. From the standpoint of information as a commodity (which overlaps with the data subject/data user model underlying much privacy regulation), this is a straightforward economic transaction. However, from the perspective of economic fairness, this constitutes a significant information imbalance which can enable, among other practices, highly targeted preferential pricing schemes. Preferential pricing can be offered to identified individuals (as opposed to groups or the public in general) on the basis of information which has been collected precisely for that purpose (rather than being a necessary part of a previous transaction).

This suggests that there may well be a regulatory role for governments in situations where new information asymmetries may affect the fairness of economic transactions. There is clear precedent for such regulations, at least in the United States, in the prohibitions against “insider” stock trading. More mundane examples are consumer protection laws requiring disclosure of information such as nutritional data for packaged food. And certainly there is substantial precedent in many countries for government regulation aimed at rectifying market distortions in general. Yet, the implications for market fairness of the commodification of private information have been all but ignored. This paper suggests that treating personal information as a commodity increasingly carries with it the potential for diminished fairness in the operation of market mechanisms.