Friday, November 19, 2010

Ubiquity

A recent article in the Wall Street Journal highlights the emergence of new internet monopolies around points of control. Strangely, they aren't emerging due to clever positioning, supplier agreements, partnerships or high market entry costs. They are emerging because monopoly is the most effective configuration for delivering user benefit.  A connective system delivers the greatest convenience and perceived benefit when it is universal. For example, the bigger and more connected the social graph, the more powerful it is. Ubiquity is inevitable. The internet operating system is emerging, not as loosely connected competing components, but as ubiquitous infrastructure.

Our power infrastructure is ubiquitous, our roads, the internet itself - all of them connective systems. There is no competition for the internet - what use would an alternative be? Its unconnected value is too low - no matter how brilliant its engineering. If we look at roads: sure, private companies build roads - but they don’t get to choose what side we drive on, what a stop sign looks like, or what the national speed limit is. The universal nature of the road infrastructure is what drives the incredible competition in the auto industry, and the user benefit is enormous. When such platforms are freely available, we reap the greatest benefit from competition. Ubiquitous infrastructure shouldn’t be what we compete for, but what we compete on. Of course, this doesn't stop companies trying to own the platform, and many succeed in doing so for long periods of time. However, without exception, the greater benefit is derived when the platform is the arena for competition, not the subject of it.

There’s an interesting conclusion to be drawn here - Facebook cannot own the social graph any more than Ford can own the road infrastructure. If Ford could control Toyota's access to the road infrastructure, you would expect a situation similar to that between Google and Facebook. Competition would be severely restricted. Facebook has 'won', but only something that will slip inevitably from its grasp. The social graph must be a platform for competition, not the target of it. Anti-competition litigation seems inevitable.

Facebook losing control of the social graph also highlights the ethereal and necessary companion of ubiquitous infrastructure - benevolent governance. Who should administer the social graph for the good of all? It's not something you're likely to get from a corporate monopoly, but something that is going to become increasingly necessary. Terry Jones observes the following when responding to Tim O’Reilly's question ‘Where is the Web 2.0 address book?’:
Relief does not lie in the direction of more applications behind more API’s. It lies instead in allowing related data to co-exist in the same place.’
A call for ubiquitous infrastructure, and the question of governance arises in the article's first comment -
‘But who owns and runs the central datastore? Why should they be trusted? Who foots the bill and how?’
A common shared database would make our lives easier - one might argue, in fact, that the social graph is simply a subset of this.

What we are seeing here is the emergence of new components that belong in the fabric of the web - things that should join HTTP and DNS and perhaps learn lessons from their governance. The social graph and the common database are just the beginning - we are witnessing the formation of the internet operating system - not as a loosely connected set of competing technologies (for that is just the chaotic state prior to equilibrium), but as an emergent, ubiquitous internet infrastructure upon which real competition can thrive. This is not a process that ends - new candidates for inclusion will appear continuously, and it may be the case that the natural emergence of monopolies highlights these candidates for us. The sooner this infrastructure is delivered as an open and level playing field, the sooner we will reap the true rewards of competition in this new age of connectivity.

Sunday, August 8, 2010

Wiring the Global Brain

We've been building a global brain for a good while now. From the moment we could grunt at each other, from the moment we could connect the global brain's neurons, we have been looking for ways of increasing and improving those connections. We consume connective opportunity like voracious beasts: cave art, semaphore, music, literature, mail, carrier pigeons, morse code, telegraph, telephone, internet. And now, we are all connected. This is the reality we face: we have formed the largest possible global brain, and strange things are afoot. No longer does it get better by getting bigger. Now it must get better by getting smarter, by getting wiser.

Internet Connectivity Map
Perhaps if we knew what we were trying to achieve - why we consume connectivity like a junkie consumes heroin - we might be able to help, or hinder, depending on our determination. What is the goal of a brain? Perhaps it is as mundane as maximising the survival chances of the host organism. Perhaps not. One thing is clear: the most awe inspiring elements of our humanity transcend the function of a single human brain. Culture. Morality. Knowledge. Each of these somewhat indistinguishable from the other, a constantly evolving result of endless feedback and filtering over time. What we hold today in our minds is a refinement of that which was held in countless minds before us - minds that have long since turned to dust. Each of us a unique component of a collective that delivers something far greater than the sum of the parts.  Perhaps we consume connectivity because we know this inherently: that each connection delivers more than the sum of the end points, and more connections delivers more than the sum of those connections.

Unlike our brains, the global brain transcends time, at least as we know it. The cells of 100 years ago aren't present today, yet there are more cells than ever before, each shaped by those that came before. Perhaps this is why we consume connectivity with so much passion: immortality. The insignificant speck of our existence has meaning in the immortal knowledge of the global brain. What drives us is exactly what the global brain needs. Or is it the other way round?

A human, we are told, will have the greatest number of brain cells at age 3. After that, they die faster than they are created. With human population growth clearly still skyrocketing, perhaps we could say the global brain, in human terms is less than 3 years old. This may not be a silly as it sounds - when we look at the nature of our global brain, the page does seem blank: the connections transient, firing off half-cocked; barely recognising right from wrong; trying to understand the nature of the environment in which they exist; trying to undertand their own nature - trying to build an operating system. Revelation is the norm, and certainty non-existent. Surely Farmville is not the pinacle of global neurological evolution. There is no doubt that as youths, there is the external perception of a blank page, that we could be anything. Yet, as time goes on, the story is written, and the possibilities diminish. Our global brain is a young, unformed child - yet, for the first time, fully connected. What will be its story? It might be said that our global brain has reached a stage where it needs to start using its wiring more effectively, and unless we plan to switch off the internet, it probably wouldn't be a bad idea to give it a hand, to deliver a few revelations, a few Eureka moments that will stand it in good stead for the future.

Easier said than done. Perhaps we can start by asking whether our global brain is the only one around.  Are we the constituents of a one-off freak? Where should we look for others? Cats? Dogs? Mice? Trees? Dolphins, whales, cephalopods? Maybe all of those places, but let's take whales and dolphins. Perhaps they have a sonar internet - a distributed, wireless communication system. Cool stuff, but different to ours - it's not directed - dedicated links to specific individuals over long distances are not possible. It's a broadcast system, and anyone can listen in. They've had theirs for much longer than us, and seem to be pretty settled as far technological advancement goes. Perhaps their global brain is more mature. We can look elsewhere: how about about birds or fish?  They're all pretty bizarre, but there's no doubt ours is uniquely human.

The next thing to consider: what's the point? What does our global brain want to be when it grows up? At this age? Probably a fireman, a doctor, or a ballerina. Certainly not a mechanical engineer, abstract sculptor or neurosurgeon. It's young: looking for some support, some guidance, some nurturing. Sadly, our brain is on its own - it must look to itself for guidance. That's us. And if we are to fill this role, then, as always, we must find the balance between authority, and freedom for the brain to experiment and forge its own path, to make its own mistakes. Man that's weird - a brain being brought up by its own cells. Which are themselves brains. Stranger things there may be, but I wouldn't bet on it.

So then, let's take a stab at it. The global brain is designed for the creation, filtering and preservation of knowledge. The end-goal no clearer than our own. We know how to create, and we know how to preserve - do we know how to filter? What passes through, what is rejected, what is distilled, and to what end?

The strangest thing is that the filter itself is constructed entirely from that which it preserves - the filter for knowledge is knowledge. An endless feedback loop - its job: to build a better filter. We don't know why - we just know how to apply the filter. The brain seeks enlightenment; perfect knowledge; truth. It has no idea what that actually means, for it seeks not only the answer, but also the question. Luckily we have an apparatus designed to solve the problem - a global brain. As Sherlock Holmes said - '...when you have eliminated the impossible, whatever remains, however improbable, must be the truth.'  The perfect filter delivers perfect knowledge, but when the filter itself is knowledge, how do you get the perfect filter? Very zen.

To this point we have seen us humans as neurons in the global brain, zealously forming connections with each other - some weak, some strong, always changing. When looking at our own brains, we have discovered the existence of neural ensembles - collections of neurons which work together:

Neuronal ensembles encode information in a way somewhat similar to the principle of Wikipedia operation - multiple edits by many participants. Neuroscientists have discovered that individual neurons are very noisy. For example, by examining the activity of only a single neuron in the visual cortex, it is very difficult to reconstruct the visual scene that the owner of the brain is looking at. Like a single Wikipedia participant, an individual neuron does not 'know' everything and is likely to make mistakes. This problem is solved by the brain having billions of neurons. Information processing by the brain is population processing, and it is also distributed - in many cases each neuron knows a little bit about everything, and the more neurons participate in a job, the more precise the information encoding. In the distributed processing scheme, individual neurons may exhibit neuronal noise, but the population as a whole averages this noise out.
An alternative to the ensemble hypothesis is the theory that there exist highly specialized neurons that serve as the mechanism of neuronal encoding. In the visual system, such cells are often referred to as grandmother cells because they would respond in very specific circumstances--such as when a person gazes at a photo of their grandmother. Neuroscientists have indeed found that some neurons provide better information than the others, and a population of such expert neurons has an improved signal to noise ratio. However, the basic principle of ensemble encoding holds: large neuronal populations do better than single neurons. [Wikpedia]

As neurons in the global brain, it would seem that our myriad social groups fill such a role - indeed, the aptness of the analogy is a little disconcerting. We form groups to improve the signal to noise ratio, and groups of experts do an even better job. Here we see another reason why we are so ardent in our connective consumption: improving the quality of the filtering process. From this we might deduce that the filter of our global brain is in fact a mass of more specific filters acting together to deliver the whole. At the finest detail, an individual neuron is a filter, and at the coarsest the entire connected mass is a filter.  A brain is a fractal knowledge filter.

Better groups is a better filter, and a better filter is a better brain. If we look at our presence online, we see a huge number of groups of all shapes and sizes, constantly strengthening and weakening their connections. It seems that if we want to help out our global brain, then improving its capacity to form groups of neurons to achieve specific goals would be high on our list, and if we could organise those groups such that they consisted of experts, the results would be significantly better. If we could organise those groups such that they worked in concert, then we're heading for the jackpot. No wonder that stack overflow works so well, and no wonder those guys are developing a process for replicating that success. The global brain likes. There's something else happening here: most of these neurons - us humans - belong to many groups,  and in many cases are specialists in multiple fields and groups. In fact, we're pretty free to espouse our expertise wherever we see fit.

So the global brain is a knowledge management machine endlessly filtering its own output to produce a better process for endlessly filtering its own output. Etcetera. If we want to improve the wiring of the global brain, then we need to facilitate better groups. Which is, of course, what we have been doing since we first grunted at the next guy.

Sunday, January 17, 2010

Who are you today?

Our current model of identity online is a poor representation of how we manage identity in the real world. As mass participation becomes ubiquitous, and the web becomes one of our primary social and political environments, we need to do better. Multiple identities, pseudonymity, anonymity and credibility are necessary aspects - a fundamental part of how we should be managing identity on the web. Most importantly, public participation in government needs a unified mechanism for managing these things. I'll propose the basis for a mechanism that supports this - one that reconciles the desire for multiple identities with the hassle of multiple logins.

Before starting, it's necessary to highlight a series of blogs about online identity by Andy Oram. He does an excellent job of assessing the landscape - the coverage is extensive and well researched. One key observation he makes is that our online identity is becoming more unified rather than fragmented. This is true, but it is happening because we are engineering identity management to achieve this - not because this unification is a natural expression of our human nature.
    Why is maintaining separate identities worthwhile?

    Andy Oram pointed to some research that highlights a main argument for maintaining multiple identities -
    [Sherry Turkle] claims that we do maintain multiple online identities, and that this is no simple game but reflects a growing tendency for us to have multiple selves. The fragmentary and divided presentation of self online reflects the truth about ourselves, more than we usually acknowledge.

    It's not a strange multiple personality disorder that we're all afflicted with - it's simple human nature. We can think of our society as a complex multi-dimensional venn diagram, where each person's perception of their identity is represented by a single circular region, and intersections between these regions represent groups.  We see this all the time in our personal relationships - there are obvious differences between how our partner, family, friends and colleagues understand us, and what information we are prepared to offer them. We maintain all of these relationships - we keep information from some people while providing it to others, and people sometimes make stuff up. It's not some nefarious deceit - it's just a fundamental part of the way humans manage relationships.

    We see regular evidence of this human behaviour online. We attempt to keep professional and social associations separate on Linked-in and Facebook. We experience discomfort when 'friended' on Facebook by people we don't consider friends. Obviously the boundaries vary greatly for each person and within each group, but that's part of the point - everybody is different, everybody creates boundaries where they are comfortable, and not everybody is a friend. The push to make us all singularly open creates weird fantasy lands - just what you would expect in the real world if we were only able to expose a single identity - the minimum intersection that is comfortable in every context.

    An unfortunate aspect of this is that our uniqueness, our creativity, our gravitas even, is often best represented by the parts of us that intersect the least. This is regularly the best expression of who we really are, what drives us, and what makes us unique individuals. We have many real world identities - subsets, intersections and mutual exclusions - all of them constantly moving. It seems utterly counter-intuitive to me that we should be engineering our online world to bring all the regional intersections of our social venn diagram into alignment. Unless we are trying to model something different to real-world identity, then we're doing it wrong.

    Tim O'Reilly noted that 'It's not a matter of perfect intelligence and perfect stupidity, its a matter of a mixture of intelligence and stupidity, of brilliance and idiocy all in the same brain, of failures of will, failures of virtue, failures of goodness, at the same time as enormous heroism, enormous accomplishment - all these things are going to be true of internet applications, just as it is true of individuals'.  We need to embrace our humanity, and recognise that the quest for our one true, homogenous and palatable internet identity is just an insidious endeavour in global groupthink.

    Multiple identities online give us new opportunities for self expression as well - providing the capability to publicly explore elements of our psyche that we would otherwise keep private. Some of that will be roughly hewn rubbish, it's true, but the key here is that the internet provides new opportunities to be comfortable with being wrong. If we are anonymous, we need not fear rejection. This is important, because the idea of 'fail fast' is one that we know to reap rewards. Allowing multiple identities gives us new opportunities to fail fast as individuals, and, on rare occasions, to succeed fast. Either way it's a win-win situation. It's not just the identity owner who benefits - if we enable more fail-fast behaviour, for individuals and groups, then society as a whole benefits enormously.

    How can we engineer support for multiple identities?

    Whether or not you agree with the argument for multiple identities, a mechanism for achieving it is reasonably obvious. If we see the internet operating system emerging, then we should need to log in once with an identity provider, and have the opportunity to switch profiles at will. Each application in the operating system sees a profile as an identity, and only the identity provider maintains the information that associates profiles. It's up to me whether I want one or many profiles. It's my responsibility to take as little or as much care as I like to keep these worlds logically separate from each other. I get to define how much information about my true identity is revealed in a particular profile. If I only want one profile, then usage would be identical to our current experience. It's fairly simple, and it's a better match for the reality of how we manage identity in the real world.

    It's understandable that we don't have this today1 - but we shouldn't kid ourselves that what we do have is a good representation of how we manage identity in the real world. Sometimes we seem to be working on the assumption that human nature should be changed rather than modelled [Mark Zuckerberg][Eric Schmidt]. Looking at the Apple Human Interface Guidelines for some perspective on this is quite helpful -
    To help you discover the mental models people associate with your product’s tasks, look at how they perform similar tasks without a computer... Design your product to reflect these things, but don’t insist on replicating each step a user might take when performing the task without a computer. Take advantage of the inherent strengths of the computing environment to make the whole process easier or more streamlined.
    Obvious stuff, and it not only highlights that we should be modelling the way people do things in the real world, but that we should be seeking improved facilitation of this behaviour.

    Additional considerations with this approach

    It might be argued that people maintaining multiple identities is a hassle for the authorities. However like most things, regulation and control is a better solution for something that people will undertake regardless of the authorities' position. A key element of the above solution is that an identity provider maintains the relationship between profiles, and can correlate this to a single login. A profile can be provided to an application with data that only the identity provider can use to perform this correlation. It's easier to regulate and control. I'm not suggesting people would cease to create multiple logins, but we would observe some separation between those who manage multiple identities for reasons of self expression, and those who do so for nefarious purposes. Of course there are many legitimate reasons why someone might not want any linking information to be stored, and I'll explore that scenario below when looking at 'true anonymity'.

    The risk of unauthorised access at the identity provider is real, as is hacker activity. These represent the greatest risk to identity management in general, but especially maintenance of separate identities. It seems clear to me, however, that as identity provision becomes standardised, and its importance better understood, the need for security and enforcement against such breaches will become more obvious and more regulated. The role of identity provider will increasingly become one which carries significant responsibility and users will choose an identity provider on the basis of how they perceive the security they offer. As we enter the world of public participation in government, many aspects of identity management will become increasingly necessary - the need for regulation, trust, verifiability and credibility will all see an increase in importance.

    Credibility

    Credibility is something that we know is necessary for online activities that require trust. No one likes a zero star seller. With the identity management solution outlined above, we get new opportunities for managing credibility - especially if this is something maintained by the identity provider. For example, e-bay could specify that their reputation is transferable between user identities - so that no matter which profile we enter e-bay with, we retain a common reputation score. Conversely, a forum might specify that reputation is not transferrable. This leads to yet another interesting possibility - the capacity to merge profiles. If you have been posting on a forum with multiple profiles, you might choose to combine them, and with such a merger deliver increased (or decreased) reputation to the new identity.

    One of the arguments against multiple identities is that it generates a lot of noise - people being antagonistic, offensive or just spouting rubbish with no requirement to own up to these contributions. Using a credibility mechanism provides an excellent tool for managing this problem. A profile with low credibility (such as one that is newly created, or often marked down) can be easily distinguished from one with high credibility. It would generally be in the user's interest to improve the credibility of the profiles that they use. Credibility metrics are a critical example of how we can achieve additional benefits in online identity management.

    Verifiability is a part of credibility, but it has some interesting additional aspects. An identity provider could offer the means for you to verify that you are you. If you provided your passport or driver's licence, then the identity provider could indicate this increased confidence in each of your profiles by increasing your credibility. In something like participation in government - the fact that you have this kind of credibility could be a requirement for participation in some forums. Something similar could be achieved for qualifications. This mechanism would also provide significant protection against online identity theft. I'm not proposing that this should be a requirement for having an online identity, but would represent a legitimate option for improving credibility.

    Plenty of other credibility management opportunities exist, particularly around endorsement by others - but the basic argument is that delivery of a mechanism for managing credibility - one that can span the entire user or individual profiles and apply both in individual applications and universally - is a basic and necessary part of participation on the web.

    What about Gov 2.0?

    Gadi Ben-Yahuda provided some good analysis of the role of anonymity in Gov 2.0, observing that there are pro's and con's. He concluded that we do need to reveal our true identity to contribute to online government, and constructed a useful scale of escalating disclosure on the basis that the more influence you have, the less private you should be. He concluded that participation in Gov 2.0 required scrutiny a little greater than we would expect when speaking at a town-hall. However, it's a one-size-fits-all observation - Gov 2.0 should enable us to participate at all the levels he identified and more in between. With the ability to maintain multiple online identities, we can achieve this relatively easily, providing the user with the means to reveal only what is required by the particular forum. This is a great application of the human interface guidelines - we can deliver a better outcome by taking advantage of the strengths of the computer environment.

    His main argument in support of anonymity is that it allows the speaker to be completely truthful - they don't need to fear personal repercussions for saying what they really think. It's important to observe that this is the primary reason why we vote anonymously. Not only that, but it's considered rude to expect someone to tell you how they voted. It's a critical example of the need for anonymity in real world government processes.

    True Anonymity

    The Electronic Frontier Foundation makes a number of good points on the role of anonymity, especially in relation to government and politics. The statement highlights the fact that we need secure anonymity. They argue that you will only say what you think if you feel confident that your anonymity can be preserved. Clearly if an identity provider maintains the relationship between your profiles, and provides trackable information to an application (even though the application itself cannot use it), then there is no such guarantee.

    For true anonymity to work, the identity provider must deliver an anonymous profile to the application - one that does not contain information to link back to the user id at the identity provider. You might maintain many anonymous profiles, and provide as much or as little information as you liked - your credibility, your country of residence, even your postcode - the key is that the application isn't given the specific identifying information needed to trace back to your account at the identity provider. Obviously if you gave up too much information in your anonymous profile, then deduction might be sufficient to identify you - but that is a risk for the user to manage. Also, there would be no way for credibility to be affected by contributions made anonymously, but providing your base credibility with the anonymous profile might be considered useful in some contexts. It is important to recognise that we can achieve 'true anonymity' while still providing information that is trustable, and might be required in a particular forum.

    Another consideration is that delivering true anonymity would need to be reconciled with the authorities' desire to track internet usage against real identities - a battle which the EFF and governments are fighting on a daily basis. It's not necessary to open this can of worms here - just to observe that there is no technical reason why true anonymity cannot be supported. Even more importantly, if we want to realise all the benefits that Gov 2.0 can offer, then we need to support it.

    Conclusions

    Andrea di Maio said we need to balance the desire of government to get closer to citizens while respecting their desire and right to privacy. It's worth highlighting that the converse is also true - we need to balance the desire of citizens to get closer to government while respecting their desire and right to privacy. Citizens shouldn't be required to reveal more than is necessary - precisely because the most important thing is knowing what people really think. Effectively managing multiple identities and anonymity is a major facilitator in lowering the barriers to participation in government.

    We are correct to strive for a one-to-one relationship between our physical self and our internet login, but mistaken to extend that to the relationship between our login and our online presence. I've offered a rough outline for a solution, and looked at some of the opportunities and risks. It's true that our current software infrastructure would struggle to realise this vision, but it's a simple argument - if people are creating multiple identities online and will continue to do so, and if the benefits are clear, then why aren't we modelling this behaviour properly with online identity? The social web must enable us, not constrain us.


    UPDATE 18/01/10: It seems I missed the Open Identity For Government initiative while researching this post. I'm not sure how I managed that, but there it is. The initiative is high profile, wide ranging, and highly relevant to this discussion. It's based around OpenID & Information Cards, and provides many of the technical elements of my suggested solution - specifically: true anonymity with verifiability, pseudonyms, limiting personal information depending on the forum, centralised management at a trusted identity provider and strong regulation at the identity provider. The system also offers the ability to maintain multiple identities, although aspects such as identity merging & portable credibility do not seem to be supported. The initiative is, however, a great basis on which to build these elements, as it represents an ideal subset of my proposal. From another perspective this post represents an independent thought stream that reached the same conclusions, and provides plenty of meat for going beyond their proposal. In any case, apologies for the research gap - at least I found it before someone pointed it out to me :) I'm really excited by the direction that the Open Identity Initiative is taking. It looks like we're doing it right after all!

    1. There is some recognition of this concept in OpenID, with a 'personas' feature allowing you to maintain different sets of information with a single OpenID. It's heading in the right direction, but it's an optional registration extension, and only implemented by a few identity providers (e.g. myOpenID). It is only utilised when registering with a service provider (application), and certainly not something the service provider needs to be aware of.  The OpenID specification itself has very few references to the concept - simply describing the feature as
    'A subset of the user's identity data. A user can have multiple personas as part of their identity. For example, a user might have a work persona and a home persona.'
    It's ineffective for maintaining multiple identities in the manner I have described for a number of reasons, but primarily because each persona is a subset of the same data set, and secondly because there is no mechanism or requirement for the service provider to recognise separate personas. One reason for this is that it would be considered too big a job to add this support to all of the applications on the internet. However I think if you saw a few major providers - Google, Facebook etc. - doing so, smaller players would begin to support it as well. Another reason might be the added complexity to users - 'I know about username and password - what's this new persona thing'? However it would be simple to hide the persona features using a default persona, and making that the standard behaviour - the usage flow would remain unchanged for those that don't use the feature. A user need not even be aware the feature exists.