You’re Welcome Here in any language—whatever your path, background, or story.

Here, you belong. We celebrate and welcome people of all sexual orientations; races, ethnicities, cultures, nationalities, ages, abilities, and neurodiversities. Whether from faith, spirituality, or no religion—seeking, building, healing, or simply exploring—you have a place here. Come as you are.

Established 1994

Craft, Strategy, Insight, and the human condition for Beginning & Professional Writers

Serving a global community of screenwriters, authors, and storytellers, from Hollywood beginners to seasoned professionals across all writing disciplines.

Welcome! • ¡Bienvenido! • Namaste! • Swaagatam! • Aapka Swagatam! • Broochim Habaim! • Baruch Haba! • 欢迎光临 • Bozho nikan • Selamat Datang! • Willkommen! • Sveiki! • Welkom! • Bienvenue! • Shalom! • ¡Bienvenida! • Dga' bsu! • Hosgeldiniz! • Bem-vindo! • HuanYing! • Benvenuto! • G'day! • Latcho Drom! • Välkommen! • Mubuhay! • Tuloy kayo! • Bonvenon! • Kööwôôkwas! • Kalosirthate! • Dobro pozalovat! • Laskavo prosymo! • Usuhoshipsiyo! • Miresevini! • Merhba! • Sambutan! • Youkoso! • Yindee tonrap! • Chào mừng! • Vítejte! • Üdvözöljük! • Hos geldiniz! • Benvingut! • Wealdià! • Croeso! • Bon biní! • Olá! • Fáilte! • Witajcie! • Hey! • Ongi etorri! • Velkommen! • Barka da zuwa! • Byenveni! • Dobro dojdovte! • Cead Mile Fáilte! • Anyong! • Assalam-o-alaikum! • Bine ati venit! • Ahlan! • Karibu! • Karibuni! • Melkam met'at'u! • Tervetuloa! • Groetjes! • Ekabo! • Aloha! • Haere mai! • Nau mai! • Keuwawata! • Ha'ándáh • Yá'át'ééh! • Aya aya! • Komeekha! • Yah aninááh! • 'Á-cim! • Myu! • Bozho! • Va'ohtama! • Ant chukoa! • Hau koda! • She:kon! • Tunngasugit! • 
Welcome! • ¡Bienvenido! • Namaste! • Swaagatam! • Aapka Swagatam! • Broochim Habaim! • Baruch Haba! • 欢迎光临 • Bozho nikan • Selamat Datang! • Willkommen! • Sveiki! • Welkom! • Bienvenue! • Shalom! • ¡Bienvenida! • Dga' bsu! • Hosgeldiniz! • Bem-vindo! • HuanYing! • Benvenuto! • G'day! • Latcho Drom! • Välkommen! • Mubuhay! • Tuloy kayo! • Bonvenon! • Kööwôôkwas! • Kalosirthate! • Dobro pozalovat! • Laskavo prosymo! • Usuhoshipsiyo! • Miresevini! • Merhba! • Sambutan! • Youkoso! • Yindee tonrap! • Chào mừng! • Vítejte! • Üdvözöljük! • Hos geldiniz! • Benvingut! • Wealdià! • Croeso! • Bon biní! • Olá! • Fáilte! • Witajcie! • Hey! • Ongi etorri! • Velkommen! • Barka da zuwa! • Byenveni! • Dobro dojdovte! • Cead Mile Fáilte! • Anyong! • Assalam-o-alaikum! • Bine ati venit! • Ahlan! • Karibu! • Karibuni! • Melkam met'at'u! • Tervetuloa! • Groetjes! • Ekabo! • Aloha! • Haere mai! • Nau mai! • Keuwawata! • Ha'ándáh • Yá'át'ééh! • Aya aya! • Komeekha! • Yah aninááh! • 'Á-cim! • Myu! • Bozho! • Va'ohtama! • Ant chukoa! • Hau koda! • She:kon! • Tunngasugit! • 
The Visual Writer Masthead
 Should the CIA Be Watching You and I Surf the Web?

Copyright Ó 1996, Dorian Scott Cole *

The CIA has typically done very little within US borders. Recently with market demand decreasing, and faced with downsizing, the CIA is looking for additional work. So a number of this elite high-tech intelligence gathering agency is taking quarters in another top secret spy group, the National Security Agency. What will they be doing at NSA? Watching the Web.

Should they? Hackers recently attacked and destroyed the CIA home page. Fortunately the CIA was smart enough to put their home page on a computer that was not connected to their vast intelligence resources. The FBI recently heightened their interest in the Web when a group of school kids were caught misusing the web for drug deals. 

Bad News

The Clinton administration, in responding to Internet related security issues, has elected to put the CIA on the Web. This is in contrast to business and other Internet users supplying their own security. Business is reluctant to show an unsecure face to the world, and Internet users don't want watched. In the mean time, financial institutions that have ventured onto the Web have lost millions of dollars, businesses and government agencies risk invasion by malicious criminals and by technology pirates, and you and I risk voyeurs compromising our privacy and stealing our credit card numbers. You can scramble financial transactions all you want for transmitting information, but no server, which stores files with this information, is considered completely secure. But is protection worth being watched by the CIA?

Fear

Suppose I want to get some health information regarding the four letter word, sex. Suppose I visit alt sites to find out what is there. I don't know which Service Provider, or site, is recording my visit. Recording visits is a common practice on the net, and you can't tell which providers and sites are recording. They can even tell where you've been. Download one little "cookie" and you may be reported. One innocent looking site might want my e-mail address so they can send me updates. That information is stored, potentially including my preferences. Suppose I stumble into sites that contain child porn. I leave immediately, but may have innocently downloaded an image, and may have my visit and selection recorded. Suppose I visit a site connected with some subversive group - like a bunch of survivalists bent on blowing up the world. (James Bond never had so many opportunities as in the US today.) I just want information about what they believe so I can write an article. Did the site server and the ISP server record my visit? Will the CIA seize his files? Will the CIA suddenly start watching me to see if I'm a subversive? Suddenly I'm afraid to explore the net for fear of being recorded. Not to worry, you say? After all, you can't even make a phone call without a record of the call being inscribed in the phone company files, and people aren't afraid to dial 900 numbers. Read on. 

I used to think that you didn't have to worry about being monitored if you didn't do anything wrong. I overlooked the McCarthy era. Senator Joseph McCarthy knew there were communists under every bed, and his personal mission became to locate them and ostracize them (if he couldn't execute them). Having and expressing a contrary political opinion could be a grave error in his day. Charlie Chaplin, an irreverent actor who could make you feel any idea without saying a word, dared to lampoon the government. It wasn't appreciated. Many Hollywood film makers were hauled before the McCarthy commission, branded communists, and effectively put out of work. A Hollywood gossip columnist branded Chaplin a communist, but McCarthy couldn't get his claws into Chaplin. Then Chaplin made a politically conciliatory film which lampooned Hitler.1 The commission immediately branded it as praising Hitler, and "hung" Chaplin. His VISA revoked while he was out of the country, he remained in self-imposed exile. 

The first half of the century was an idealistic age. Europe swarmed with idealistic hotbeds, and social experiments happened everywhere. US idealism, having triumphed politically, turned to "moralistism." The film industry, the most influential communications medium, endured years of censorship, both political and "moral," reminiscent of prohibition. Prohibition - that other great government sponsored social mandate that didn't save us either (and we're still thriving even though some of us are drunkenly oblivious to it). 

But we're beyond McCarthyism, aren't we? Well, the FBI kept files on a large number of people - both famous and unknown - who took part in potentially subversive groups in the sixties and seventies. Now many of those files have been made public, so those individual's privacy has been invaded twice. The government has a rather poor track record of restraining its agencies. Supposedly the FBI is more careful now about who it watches and what files are kept. Public pressure made them that way. The lesson is, I think, without public pressure, the danger remains. 

Is public pressure the answer? Partly. Social Security numbers are an example of the lack of public pressure. Social Security numbers were not "supposed" to be a means of identification, which was a lively issue as late as the 70's, and even today people complain about using them for identification. Today, Social Security numbers are the primary means of keeping track of you for financial records, for health, for goverment records, for drivers license identification… No one came up with a better system, so we defaulted to social security numbers. After all, just about anything you do has no effect on social security benefits, so why the fuss? On another issue, Internet censorship, public pressure worked. Public pressure has influenced legislation in many recent cases, preventing censorship. The question is, are we willing to take responsibility and keep goverment monitoring out?

Responsible?

We're not always a very responsible bunch. We've been taught by the government to let the government take care of any issue that's bigger than an individual. Especially security, which is almost synonymous with law enforcement. And law enforcement wants to be involved with Internet security. I think law enforcement types are secret computer geeks. Chances are we will let them jump in. Hype and fear dominate the press and other communications, then we let the government step in because of hysteria. Hype and fear aside, there are issues here that very possibly don't require government intervention. 

The issues, practical and philosophic

The practical issues are pretty much known. Porn and child porn vs freedom of speech. Privacy invasion by hacker vs privacy invasion by the CIA. Credit card theft vs more difficult access and law enforcement monitoring. Damaged files, records, and programs by malicious criminals vs law enforcement monitoring. Technology and secrets piracy by hackers. And serious financial theft by hackers.

The practical issues

On the practical side, is the cure worse than the disease, and what will happen if the disease continues? Will the disease, like communism, burn itself out? In the case of pornography, this has generated sexual harrassment suits in the workplace. Access restriction is available for work, home, and schools. Pornography can't grow where it is restricted, and porno at home is a privacy issue. Current public opinion and law enforcement may be adequate to the challenge. 

In the case of being monitored by voyeuristic hackers, there will probably never be a public access system that can't be monitored by a hacker, unless all communications is scrambled. In most criminal actions you have to prove there were damages, so law enforcement has no teeth in it. 

Regarding credit card theft, this is a growing problem even outside of the Internet. Individuals are usually protected from liability for fraud, even though there may be short term consequences and we all pay the price in the long run. When law enforcement is involved with cases outside the Internet, where there is a paper trail and witnesses and fingerprints, very few cases are actually resolved, while the individual whose card was stolen is bogged down with police reports. Is it worth it to have law enforcement involved? 

Corporate and government databases are sometimes invaded by voyeuristic hackers. As long as there is a challenge there, some hacker is going to conquer it. I suppose it's the rite of passage for some programmers. Are most of them bent on vandalism as well? Will arresting the programmer who is trying to prove himself end the problem, or just create another one - a hacker looking for revenge.

The previous problems I mentioned probably don't require the intervention of law enforcement. Four types of security problems clearly require prevention or intervention by Internet users or law enforcement. I label those, the Great Train Robber, the Corporate Spy, the Child Porno Pervert, and the Terrorist. The Great Train Robber invades financial institutions and transfers funds illegally. This potentially could total millions of dollars for one individual. The spy can invade corporate databases and steal technology secrets that can put a company out of business and thousands of people out of jobs. Child pornography is a sickness that we can't afford to allow to spread, because the people who traffic in it get worse, spread it to others, and involve children. The Terrorist, whether using the malicious mischief of spreading a virus, publicizing secret files, or wiping out records, achieves his goal by destroying, or by causing mayhem. The potential for major losses are great.

The philosophic issues

Philosophic issues define what type of society we want to create for ourselves. What we make, or we allow the government to create by default, we have to live with. I doubt that most of us want to live in a society where others can create chaos, rob us blind, expose our private lives, and destroy our society's records and institutions. On the other hand, neither do most of us want to live with endless rules to follow that supposedly "protect" us. Nor do we want to have big brother watching our every move, restricting our access, and intervening at the slightest suspicious move. Both a society based on chaos, and one based on rigid rules, distrust, and suspicion, are terrifying places to live. 

One issue is, "What is security?"

Security, I think, is to be able to live without your life being seriously disrupted by others. We don't live in a perfect world, and none of us would fit in one. For example, one person in four will snoop in another person's house if given the opportunity. People sometimes do things that aren't proper that affect others. We all have to be tolerant of others if we expect others to be tolerant of our own lapses. There are a lot of little things that we don't like that we can't really define as security issues. If we did, we would be condemning ourselves, making rules and consequences we wouldn't want to live with.

Another issue is, "Who is responsible for security?"

We pass off a lot of issues to our government to handle. Rightfully so, because none of us can be an expert on everything or have time to do everything. I think that's a big reason why we have a civilization. We count on each other and our government. But can every issue become a government issue just because we don't necessarily want to do it? 

Law enforcement officials are trying to discourage people from setting up their own Internet security. There is a paranoia, I think, among law enforcement people and among many of us, that doing anything related to security is a step toward becoming "vigilanties." Vigilanties are those people who take justice into their own hands. Somebody does something illegal, and vigilanties step in and hang the culprit, sometimes even before the trial. Justice is the realm of the police and court system, who catch and try people who have committed a crime in a way that matches criminal behavior with the proper penalty. Security and justice are not related. 

If someone kills you, you're dead. You can whine from the grave about the government not providing security, but you're still dead. This is an extreme example, but it shows that ultimately security is up to the individual. When someone is gunning for you, whether you hide, carry a gun, hire a body guard, or put bars on your windows, is an individual choice. You may get an occassional police patrol, but you have to take responsiblity for yourself because the police don't provide security. Standard law enforcement procedure is to become involved only after a crime has happened. It's a lot like closing the pasture gate after all the cattle have escaped to the next county. They're gone. You're robbed or dead.

Security is equated with preventing crime from happening. While the police are largely reactive regarding crime - it has to happen first before they can become involved - security is proactive, preventing crime from happening. We lock our homes to discourage most thieves. It doesn't discourage the professional thief, but it stops most theft. Same for our cars. And we put our valuables in a safe or in the bank. The police wouldn't have the time for every minor break in and petty theft, and we couldn't afford to pay for that many officers. Where the pressure to steal is intense, we install alarm systems and bars. Locking up our valuables makes sense. 

Looking at the crime rate, the overloaded justice system, the overcrowded prisons - it's obvious the police have more to do than they can do, and the price for more security will be very costly to the taxpayer. The obvious question becomes, what cost effective measures can we take to prevent electronic crime, that isn't equally as cumbersome as having a sliding stone door on our house, so that government professionals don't have to be involved? 

The Question

It's a question, I think, of how responsible we as individuals and businesses are willing to become, then allowing the government to intervene only where we can't reasonably do it. By responsible, I don't mean becoming reporters of every suspicious act we see. That's a society of distrust. But Neighborhood Watches really work to cut down the crime in the neighborhoods we live in. And the security measures we take to protect ourselves from theft or violence do work. 

TV, under some government pressure, has begun to rate programs for content. Devices are readily available to block telephone and Internet sites that contain objectionable material. Internet Services, like America OnLine, are finding ways to block incoming mass mail to protect its users. People and businesses are finding responsible ways to protect themselves.

Obstacles to solving the prolems

The obstacle faced by business is that the computer and software world is very competitive, so sharing information is not on the top of the agenda, and businesses run so lean they are short on the personnel to do things. These are givens - these aren't going to change for years, if at all.

The obstacle individuals face is that it's very hard for them to watch, except possibly as network administrators. Like communities without Neighborhood Watches, we really don't know what to look for. All we hear is the occassional warning to use passwords and not use automated log ons, and to keep passwords secret.

Directions we can go

Business needs to create a solution that protects itself, including its users, on the Internet. Businesses have worked successfully together to come up with solutions for things ranging from common protocols to national competitive strategies. Electrical engineers from companies meet and create communications standards that everyone can live with for things ranging from fax, audio, and television to Internet hardware. Businesses come up with national standards for products that have technologies that are implemented on a national basis. For example, television. (Although the recent agreement on SVHS fell apart and companies went their own way.) Companies meet with the Internet committees to establish communications protocols for the Web. It can be done. It is done.

Businesses need to adopt some standards for security related issues. For example, technology potentially could be developed that detects certain types of destructive activities and takes an appropriate action. Major financial transactions, or frequent activity that totals major transactions, could have security safeguards. Intrusion into secure areas of servers could potentially be detected. Changes to certain types of data or files could be detected. Records that would reveal patterns of intrusion potentially could be created. Decoy security programs could fool hackers into thinking they are getting inside and making progress, while they are actually either wasting the intruder's time or trapping the intruder. Security programs to do these things that were tamper proof could be created. By taking a united approach and dedicating people industry wide to developing this technology, most of the problem could probably be eliminated. Then by creating a slightly new technology on a regular basis, and installing it, you can always be one step ahead of most hackers. 

So, the potential steps to foiling the hackers who are malicious are: 1) A united approach to security, creating more solid programs with greater access security. 2) Decoy programs that waste hackers time and help track intruders. 3) Changing technology that keeps sites one step ahead of hackers 4) Better tracking that senses intruders and logs their actions. 

Education is needed. Most people don't know what to look for, and don't have the tools to see it. One thing that could come out of a meeting on software security is education and tools.

The CIA 

Is the CIA going to start watching as you and I surf the Internet? I doubt it. I suspect they are sensibly targeted at international hackers who potentially could terrorize nations and disrupt the internet when it is about to explode with financial activity. But CIA presence is government intervention on what is traditionally an open service that freely spans nations. Most people, I think, are even afraid of any record keeping related to the Internet, because it diminishes the freedom of the system. But if we want to keep it secure for ourselves, we had better learn how to keep the criminals out.

Security and responsibility related story ideas:

¤ An apartment building steadily deteoriates as gangs, drug dealers, and thieves take over. They are the very people who have been moving in. It is the third local apartment building to fall. Police action has done nothing to stop the problem - the bad guys get away quickly and the residents are afraid to name names. The local police chief decides to address the problem. He plants two new recruits in the building undercover. They are watchdogs who will report suspicious activities, and they are to organize sports activities for the youth. And he gets the apartment management to start a strict new policy - commit a crime - lose your place to live. The new guys are immediately threatened to keep quiet and quit doing things with the youth because it interferes. In three months there is no problem, and the two undercover officers have groomed two local inhabitants to take their place. (The sports activities and the crime policy are based on actual events.)

¤ ! Several members of an old-folks-home take a walk every morning around several blocks of their city. It keeps them healthy. But several incidents of vandalism (purse snatching, pickpockets) become an obstacle to their outings. Staying inside, they begin to feel imprisoned. The police say they will try to recover their possessions, but say there is little hope, and they can't follow them around in a patrol car, so it is likely to happen again. 

One man, an ex-Marine, practices karate to protect them. They go out, the vandals strike, he tries to stop them and is easily punched and kicked aside, putting him in the hospital with a broken hip. The police, instead of being helpful, are outraged that they tried to engage them. They consider carrying guns, then they decide the police are right - a few dollars cash isn't worth any of their lives.

After several more days of imprisonment, they rally to the cause again. This time they have a man tail them in a car with a video camera filming continuously. After several days the vandals strike again. This time it is all on film, and they get it on TV news. The vandals are caught within hours of the broadcast. They think it is safe, and go out the next day. The vandals are out on bail, hide in a darkened alley, and snatch them at gun-point. The man in the car tries to video-tape the event, but the light is too poor. He bravely drives into the alley, taping in the dim light, and confronts the vandals with his car. They fire at him, breaking his windshield, and run. Two of the elderly have been hurt, but they are in good spirits. Days later the vandals turned criminals have been picked up and are held without bail. 

¤ ! A large electronic financial transaction occurs from a large bank to a Swiss bank account. Within hours the money is converted to cash and withdrawn. Later that day the transaction is found and determined to be fraudulent. The amount is just under the limit that would set off an automatic review. Someone had broken into the computer system, created a bank account with a large balance, then transferred it to the Swiss bank. The same thing happens two more times in other banks around the US. 

An electronic security firm is called in. A computer programmer creates traps at several banks that potentially could be targets. While the person is hacking passwords, he traces the call. But when police arrive the hacker is gone. They expect he will try again.

The search focuses now on who potentially could do it. The programmer knows it has to be a person who works for a bank or a security firm, and he knows many of the people who are in the field. He also suspects the person probably lives reasonably near where they traced the call to. They make a list of everyone that it potentially could be. But the programmer knows of one other person - a friend of his. They relocate to that area and an FBI unit is assigned to them. The programmer has another programmer watch the network. He secretly goes to watch his friend, and follows him. 
 

* Ideas can't be copyrighted, but if you use a fully developed idea from these pages it is customary to give credit - you won't get sued if you don't, or charged if you do. This page is copyrighted - that means you can't copy the text from this page and post it anonymously or give authoring credit to another person. Fully developed ideas are marked with a !. Credit for an ideas is usually in the form: From an idea by (name).

Go to Food for thought feedback page.
Return to top of page Return to main page

1 Was Chaplin a communist? He certainly was known as a strong sympathizer. This wouldn't have been much of a leap for the man who came from impoverished origins and identified strongly with the poor working man, living in an age of idealism among many idealists who were creating movies and filled with political ideals. But idealism fades with experience and in the light of major wars. I suspect Chaplin's leanings were as lightly held as they are for most idealists, and his conciliatory political films were his struggle to come to grips with cricticism and his own conscience.

Charles Chaplin : My Autobiography, by Charlie Chaplin. Published by Plume; Publication date: April 1,1993. ISBN: 0452270782 (Available from Amazon Books.)

Charlie Chaplin : And His Times, by Kenneth S. Lynn.Published by Simon & Schuster; Publication date: March 1,1997. ISBN: 068480851X(Available from Amazon Books.)

Update June 16, 1997

Over 70 percent of consumers are more concerned about Internet privacy than about telephone or mail transactions - which is where the real problem is. (Boston Consulting Group study) This negates about $6 billion in electronic commerce by the year 2000.

In July of 1996, a consortium of businesses1 with major Internet presences formed a group to look at Internet privacy and security issues. The proposed result is, businesses can join the group at licensing costs ranging from $500 to $5,000, depending on the size of the company and the sensitivity of the information.. Listing is expected to bolster consumer confidence to the point that they will download files, or buy. 

I propose, since this is too expensive for small sites, that an independent group of small sites form to create a similar listing. Recommended formation steps:

1. Arrange a panel of small site operators to determine what security issues should be addressed, and what code should be adhered to. This could involve security of downloads (virus free), security of economic transactions, security of personal information, and security from unrestricted list distribution. It could also involve the voluntary rating with RASCi, and possible membership with a professional ethics site..

2. Give one site the responsibility for collecting site registrations and agreements, for providing a list for consumer access that lists sites which have registered, and for providing a linked image that changes daily (to help prevent fraud), and which links to the registration page for convenient checking. 

Related links and information

Better business bureau for policies on net advertising aimed at children http://www.bbb.org/advertising/nadproc.html

Electronic Privacy Information Center (lobbies against legislation) http://www.epic.org/

1eTrust http://www.truste.org/  coalition to protect privacy & promote security online.TRUSTe assures online consumers' privacy through a progressive policy of informed consent utilizing a branded system of "trustmarks" which represent a company's online information privacy policy.
Companies spanning several different industries, from retail to telecommunications, are backing TRUSTe by becoming premier members.TRUSTe's premier members include: AT&T, IBM, Oracle, Lands' End, Tandem Computers, Excite, Progressive Networks, Wired Ventures, Netscape, CyberCash, MatchLogic, National Computer Security Association.

To help ensure that TRUSTe guidelines are adhered to, Coopers & Lybrand and KPMG will conduct random on-site compliance audits and provide due diligence reporting for violations of the TRUSTe licensing agreement.

Eight companies revealed to the FTC their plans for practices and guidelines for the types of personal information that are collected and who can get it over the Internet. The companies include ChoicePoint, Database Technologies, Experian, First Data InfoSource/Donnelly Marketing, Information America, IRSC, Lexis-Nexis, Metromail, with TransUnion and Equifax saying they would use the guidelines.

While some doubt that self-regulation will work, and believe the guidelines should be enforced by law, other industry groups are working to address consumer concerns about privacy. TRUSTe, as mentioned above, believes a set of logos can be used to inform web site visitors how the site may use or resell information it collects about them. Lucent Technologies offers a web assistant program that lets visitors register at sites under an assumed identity so the site is unable to determine the person or computer's identity. 

The US Supreme Court, in another matter, in a victory for free-speech and self-regulation, threw out the new law regulating smut on the Internet. It would seem at this point that relying on individual responsibility in the form of adult judgment, and for children relying on parental supervision and tools that are currently available, no one need expose themselves to unwanted material on the Internet.

(As a provider of information some of which is intended to be informative or thought provoking for mature audiences, but isn't indecent, yet isn't for children, I really think screening controls are a much more effective measure than trying to have the government regulate it - which wouldn't even apply to files on this site. Individual files on this site that I deem "not for children" are rated to prevent access.)

Other distribution restrictions: None

Main Page
Page URL:  http://www.visualwriter.com/Ideas/CIA.htm