Wednesday, April 15, 2009

Some thoughts..Winning the war is only the first step to win peace

With the LTTE terrorists (Tamil tigers) being defeated militarily, Sri Lankan government still needs to take considerable actions to restore the faith in Tamil and Tamil-speaking civilians. Terrorism in any form is not acceptable. LTTE is one of the most dangerous terrorist organizations in the world [FBI 0,1,2]. They carried out many atrocities and most of the time innocent civilians have to suffer [3]. There is no question they should be defeated and wiped out of the Sri Lankan soil. The SL government has rightly done so.

Military solution alone will not solve the problem we are currently facing; a political solution should be implemented to correct the issues including the root cause of this whole issue. IMHO, the language is the root cause. 1956 Sinhala only act was a key contributor for Tamils and Tamil-speaking civilians to feel discriminated. This was corrected later; after 1987, India-Sri Lanka accord, Tamil language was accorded the same official status as Sinhala language. Even after 20 years making both Sinhala and Tamil as official languages, we don't seem to have got it right. It is natural to feel that you are not one of them if you don't speak their language or if they don't speak your language; or you feel neglected; language divide people. I have a lot of personal experience to back up this fact. Perhaps, the issue is more visible to me as I speak both languages. So, what should be the way forward? The government has to genuinely commit itself to bridge this language gap and we, as citizens, have the responsibility to do our parts. (There have been already some measures to make both Tamil and Sinhala languages compulsory for public service positions and to add to the school curriculum; but that is not sufficient.)

It is time we, citizens, take every possible action to heal the wounds that have been around for decades. Sometimes, I feel offended by the arguments made by both parties [1]; "Sri Lanka is the homeland of Sinhalese", "(Some parts of) Sri Lanka is the homeland of Tamils". Unless we get ourselves rid of such mentality, we will continue to have divisions. Sri Lanka is the homeland of all ethnicities. One ethnicity is not superior or inferior to another. We will have the real peace in our country on the day we start to treat everyone equally and with dignity. I sincerely hope that this day is not far away.

We, as educated people, can use our ability to bridge the language gap and improve the trust between differnet ethnicities. I don't think it is too much to ask from my fellow Sinhala-speaking friends/readers to learn the basics of Tamil and my fellow Tamil-speaking friends/readers to learn the basics of Sinhalese. There's a lot in common between these two languages.

I studied in Sinhala medium, speak in Tamil at home and stared learning to write in Tamil on my own with some help from my mother a few years ago. I am glad I did that. Now, I have more reasons to polish up my writing skills. Believe me, it is not that hard and you will enjoy the feeling of getting to know/being able to understand another language - a language that is spoken by fellow Sri Lankans!

Friday, April 3, 2009

Hi-tech Exam Cheats

With technology, we naturally tend to think that there will be better ways to detect/find exam cheats and this in a way deter those who try to cheat in exams, right? But the facts seem to be otherwise [1, 2, 3, 4, 5]; recent incidents show that students are increasingly utilizing technology to their advantage to cheat.

This is similar to the current virus/malicious software development market; bad people keep on finding new ways to attack while good people (anti-virus software companies) try to defend those attacks. Another is software piracy market. (Is it OK to download copyrighted stuff from P2P file sharing networks? If so, is it OK to steal money from a book author?)

It again highlights the fact that technology alone cannot solve issues we are facing today. Further, even legal enforcements won't be able to. IMHO, this vicious cycle is never going end (in fact is going to get worse) unless we address non-technical issues such as ethical behaviors, moral issues, etc. How many of those who cheat think that cheating is a bad thing? How many think that their cheating is justified?


Some more thoughts..
Does high competition (few opportunities) lead to cheating? If so, is competition a bad thing?
When students are under pressure to perform, is it a reason for them to cheat? If so, who should be blamed for its happening?

Wednesday, April 1, 2009

Expectation of Privacy

In USA, to take legal actions, the concept of "expectation of privacy" matters. The fourth amendment (1967 I think) lays out criteria for this in order for a plaintiff to demand legal privacy protection:

1. She needs to show that she exhibited an actual "expectation" of privacy. (For example, if she leaves the data in plaintext in some public storage, she obviously has little expectation of privacy. On the other hand, if the data is encrypted, there is some level of expectation of privacy.)
2. The expectation should be one that the society is prepared to recognize as "reasonable". (This reasonableness is a subjective measure. For example, we, as a society, expect our emails to be private. However, this notion of privacy could be used by bad people for their malicious intents. For example, for terrorists to organize an attack. When there is an imminent threat, we need to give priority to societal security over personal privacy. In the interest of national security, one can argue that it is not reasonable to expect our emails are private.)

For example, Facebook (also other social networks) business model involve selling (anonymized) personal information and using it to target advertisements.

An excerpt from the Facebook privacy policy:
"Facebook may use information in your profile without identifying you as an individual to third parties. We do this for purposes such as aggregating how many people in a network like a band or movie and personalizing advertisements and promotions so that we can provide you Facebook. We believe this benefits you. You can know more about the world around you and, where there are advertisements, they're more likely to be interesting to you. For example, if you put a favorite movie in your profile, we might serve you an advertisement highlighting a screening of a similar one in your town. But we don't tell the movie company who you are."

With such statements in their privacy policies, it is questionable if a user can defend the above "expectation of privacy" as we agree to all these policies (with or without knowingly) when we sign up for the service. I am not saying social networks are bad, in fact, I do have a Facebook account and it's a great tool to connect with old colleagues and friends, and stay in touch with them. But, do we need to change our expectation of privacy to that of our service providers (Facebook in this case)? In other words, how can we show (legally) that we demonstrate sufficient expectation of privacy in case it is breached?

Here, you'll find some interesting thoughts by Bruce Schneier on this topic and he argues that "expecation of privacy" is a flawed test.

Tuesday, March 31, 2009

Medical Identity Theft

Interesting:

The soaring cost of health care is spawning a new crime: medical identity theft, in which someone uses your insurance information and health records to obtain medication or even surgery. It happens to 250,000 people each year, says the World Privacy Forum. To protect yourself, the WPF recommends that you: 1) closely review all "explanation of benefits" letters from your health insurer, 2) annually request a list of benefits paid by your insurer in your name (sometimes thieves alter billing info), and 3) check your medical file every time you visit the doctor.Google, Microsoft, and dozens of other companies will also store your personal health records (PHRs) online. While there are advantages to having a complete medical history in one convenient location, some companies have "de-identified" these records and sold them to marketers. Pam Dixon, executive director of the WPF, does not generally recommend PHRs that are not maintained by health care providers. She stresses looking for a service that is "HIPAA covered" rather than "HIPAA compliant" in order to retain confidentiality. Look for that exact wording in the privacy statement. (Electronic health records, or EHRs, are maintained exclusively by health care providers.)

To tell the truth, I hardly check any of the 3 steps mentioned above. In other words, I really don't know if someone else misuses my medical insurance.

More info: here

(Note: For those who are not familiar with medical insurance (for example, in Sri Lanka it is not required to have such insurance), some countries such as USA, require you to possess a valid medical insurance if you are under a certain visa status. It is just like automobile insurance.)

Sunday, March 29, 2009

The Availability Heuristic

When the devastating Tsunami (Indian Ocean Earthquake) happened in 2004, it was our number one fear that time as we had that feeling of happening something similar or worse again. Now we don't have the same level of concern over it, do we?

When that horrible shooting incident happened at VTech, we were more fearful at that time than now as we had that feeling of increased probability of being a victim of such an incident.

When there is a suicide bomb attack, we see extra check points and increased security measures which tend to fade off as the time pass by. Why is that we have more concern immediately after the attack? Again, we get that feeling of happing something similar or worse.

We use availability heuristic to estimate the frequency of something (good or bad) happening. Often we don't have or bother find solid evidence to base our estimation. "For example, what is the probability that the next plane you fly on will crash? The true probability of any particular plane crashing depends on a huge number of factors, most of which you're not aware of and/or don't have reliable data on. What type of plane is it? What time of day is the flight? What is the weather like? What is the safety history of this particular plane? When was the last time the plane was examined for problems? Who did the examination and how thorough was it? Who is flying the plane? How much sleep did they get last night? How old are they? Are they taking any medications? You get the idea." Our cognitive decision is based other no rationale factors!

Usually, our estimation is shaped by our recent memory. It is easier for us to recall events happened in the recent past than those in distant past.

The availability heuristic often leads people to loose sight of "real" dangers: " Psychologist Gerd Gigerenzer, for example, conducted a fascinating study that showed in the months following September 11, 2001, Americans were less likely to travel by air and more likely to instead travel by car. While it is understandable why Americans would have been fearful of air travel following the incredibly high profile attacks on New York and Washington, the unfortunate result is that Americans died on the highways at alarming rates following 9/11. This is because highway travel is far more dangerous than air travel. More than 40,000 Americans are killed every year on America's roads. Fewer than 1,000 people die in airplane accidents, and even fewer people are killed aboard commercial airlines. The bottom line is that being a passenger on a plane being flown by trained professionals who are being guided by a team of professionals (i.e., air traffic control) is much safer than driving your own car on streets surrounded by other amateur drivers who may or may not follow the rules of the road (and whose cars may or may not be fit to drive)."

Another interesting fact:
"Consider, for example, that the 2009 budget for homeland security (the folks that protect us from terrorists) will likely be about $50 billion. Don't get us wrong, we like the fact that people are trying to prevent terrorism, but even at its absolute worst, terrorists killed about 3,000 Americans in a single year. And less than 100 Americans are killed by terrorists in most years. By contrast, the budget for the National Highway Traffic Safety Administration (the folks who protect us on the road) is about $1 billion, even though more than 40,000 people will die this year on the nation's roads. In terms of dollars spent per fatality, we fund terrorism prevention at about $17,000,000/fatality (i.e., $50 billion/3,000 fatalities) and accident prevention at about $25,000/fatality (i.e., $1 billion/40,000 fatalities). This huge imbalance tells us that our priorities are seriously out of whack. (And don't even get us started on bigger killers like heart disease!)"

Is our risk assessment model flawed? IMHO it is not the model that is problematic here, but we as a society have failed in the first place (why do we have terrorists attacks? why are there mass shooting incidents?) barring the natural disasters. Why do we allocate more resources to those possible events that has a low frequency but a high impact? I argue that this is due to the true human nature; we, human beings, feel a higher impact if something happens in burst rather than gradually even if the latter is causing more damage in the long run. Can we (as citizens or as governments) change our perceptions (be a lot less afraid of recent bad incidents) and focus on the latter? I think the real problem is not the fear factor or the accrual damage caused but the fact that most of the burst incidents are caused by extremist elements and the victims have neither control nor any involvement (in other words, there are unfortunate reactions without any actions (involvement) - is this what we call "fate"?). We can make a similar argument about natural disasters.

Monday, March 23, 2009

Examples (I)

Some interesting database/security/privacy concerns through examples (taken from various papers) and this is how new ideas for some interesting papers found:

A problem with k-anonymity:

Table 1
The above table shows a list of patient records. The following table shows the 3-anonymous version of the above table.

Table 2
Disease attribute is sensitive here. If a user knows some background information, she can infer sensitive attributes of patients. Suppose Alice knows that Bob is 25 years old and lives in ZIP 47625. She knows that Bob belongs to one of the first three records in table 2. Since all of them have the same disease, Alice can deduce that Bob has heart disease. l-diversity was introduced to overcome this problem where there are at least l distinct sensitive attributes for each equivalent class. Had the table 2 had the 2-diversity property, Alice would only be able to guess Bob's illness with only 0.5 probability. (Note: even l-diversity has issues. t-closeness was introduced to address one of such issues)

Table 3

Table 4

Table 4 shows the 3-diversity version of table 3. Here both salary and disease are sensitive attributes. Notice that each equivalent class has 3 distinct sensitive attributes.

Even when the sensitive attributes are different, if they are semantically similar (low salary range, some specific types of diseases, etc.), one can perform a similarity attack. For example, if one knows that Bob is one of the first three records, one can deduce that Bob's in low income range of 3K-5K and has a stomach related disease. To account for the semantically closeness of values (i.e. to prevent similarity attacks), t-closeness was introduced. (I leave it for you to read)

A problem with replacing non-disclosed values with NULL:
(a) show a customer table with attributes ID, name, age and phone number. (Y) and (N) indicate the users' content about disclosing those attribute values. For example, Linda and Mary don't mind disclosing everything, but Nick does not want the organization to disclose his age and phone number to any third party. It is common practice to replace (N) values with NULL before executing the query.

Q1: “SELECT name, phone FROM Customer”
Q2: “SELECT name, phone FROM Customer WHERE age >= 25"
Q = Q1 - Q2

Intuitively Q should return only those records with age < 25 as in (e). But to the contrary, it returns two results as in (d). Therefore, using NULL is not a sound solution. A variable based approach was introduced to solve this problem. (I leave it for you to read)

Zero-Knowledge Proof of Knowledge (ZKPK):

Discrete Logarithm Problem is hard to solve. We can use this hardness assumption to hide a secret.
(DLP: Given a generator g of a group of order p and c (which is calculated from g^x), find the value (i.e. x) that gives c)

If you can solve the problem, you can convince another party you possess a secret. How do you actually convince the party that you know the secret without revealing the secret?

Alice: I know the value x corresponding to c. (but I don't want to tell you x)
Bob: Show me.

Alice: Chooses a random y selected from Z_p and send g^y to Bob.
Bob: Send the challenge r selected from Z_p to Alice.

Alice: Computes s = y + r.x and sends s to Bob
Bob: Checks if g^s = g^y.c^r and is convinced that Alice knows x if those are equal.

Sunday, March 22, 2009

How to differentiate a normal person from a mathematician?

Two people P and Q independently, had to babysit on a particular day. They are given the following instruction:

"If baby cries, feed it with the milk in the bottle."

Now it's P's turn. P found the baby was not crying and attended to his/her work while keeping an eye on the baby.

Then Q gets his/her turn. Q also found the was not crying..but he/she made it crying so that he/she can feed it with the milk in the bottle.

Who is the mathematician? Make a guess..

It's Q. Why?

Q found that when the baby was not crying, the action was undefined, hence an unresolved situation. Therefore, he/she made it crying so that the situation was reduced to an already solved problem. :D