Network lock-in

At The Overspill this week, veteran UK technology journalist Charles Arthur highlighted a blog posting at the venture capital firm A16Z by cyberethnographer and NYU adjunct professor Ruby Thelot claiming that “enshittification isn’t real”.

Thelot’s main argument: “Simply put, more people use Instagram every year, they use it on average longer every day, year over year and, finally, their reported satisfaction has also grown over time, indicating no decrease in overall satisfaction, stated or revealed.” I immediately imagined a survey like this about the London railway node Clapham Junction.

Thelot uses Instagram as an exemplar. No matter how much users complain, he says, surveys show they continue to spend more time on the site and indicate greater satisfaction. To him, swapping out chronological feeds for algorithms is just part of natural evolution as platform adapt to their evolving user base. Enshittification, he concludes, provides “absolution” for “platform narcissists” who need to forgive themselves for remaining on the platforms. They’re not *really* trapped.

Some of this is fair. People *don’t* like change, particularly when it removes or alters features they’re used to. It’s also true that the generation who began our online lives pre-Internet and embraced email and the open web early on are often the most loudly disaffected with the current state of things.

Thelot is also undoubtedly correct that tech moguls have learned they can ignore complaints because people will go on using their products. This is a lesson they learned years ago, when they growing explosively – and differently designed. Today, the oligopoly of competitors all behave roughly the same to promote engagement. The courts continue to repeatedly agree that these companies are abusive.

He also ignores the various forms of lock-in and network effects. These are not just individual choices. People want to be where their friends are, and it’s non-trivial to persuade all those school groups, clubs, and communities of interest to move. In fact, research from the University of New South Wales in April shows that platforms don’t have to “addict” users; they merely have to raise the cost of leaving, measured in the loss of their connections and businesses.

But Doctorow was not just talking about social media or just about users. Amazon is a great example; its product search has become broken. So is Google, a three-time monopolist whose change in behavior Doctorow blames on tech workers’ loss of power.

Enshittification is about power and its abuse. Saying it isn’t real rejects the widespread decades-old understanding that, “If you’re not paying for it, you are the product”, generally attributed to Andrew Lewis. As every business tries to expand its revenue streams, sometimes now you’re the product even when you *are* paying – which is exactly what enshittifies the customer experience. Just this week, Uber said it will start playing ads during Uber journeys even while drivers in multiple countries are suing it over using its algorithms to squeeze every last penny out of both riders and drivers. TV manufacturers are showing their own advertising, and Hyundai will charge extra for the “instrument cluster” that provides detail about what your car is doing. Whichof these moves doesn’t make life objectively worse (and/or less safe) for customers?

Enshittification became the word of the year in 2024 because it resonates with so many frustrated, angry people. Pretending they don’t really care is denial.

***

Concern over the US’s pole position in Internet governance – as in the recent case of a Texas county court ordering ICANN to lock a domain worldwide – continues to grow. Last month, the Trump administration placed Austici/Inventati on a terrorism watchlist, as Matthew Petti reports at Reason. This is an Italian provider of free encrypted email and web hosting to about 20,000 activist organizations around the world. The consequence has been to crippling. Not only does the designation put the use of US-based payment systems such as PayPal, Mastercard, and Visa out of reach immediately, but it has also losr its website worldwide, since the registry for its domain – austici.org – is also US-based.

Legacy design means that a lot of other Internet infrastructure is also US-based, such as Let’s Encrypt, used to secure connections to more than 700 million websites worldwide (says Wikipedia), more than 23 million of them in Europe.

Blocking via payment systems is not new. In 2010, the US government told PayPal, Mastercard, and Visa that Wikileaks’ activities were illegal in the US, choking donations until the organization could find alternative routes. That kind of blockade still happens; a friend pointed at the story of a Cuban sandwich shop in Belfast. which can’t get paid by Deliveroo because the latter’s bank is American and won’t pay anyone or anything associated with Cuba.

But implementing sanctions via US-based Internet governance nodes is relatively new – see last year’s sanctions against the International Criminal Court and other examples – and is harder to counter. Whatever the rights or wrongs of any one particular site or service, that one country’s leader can selectively shut down any organization in the world any time they like is alarming.

What used to be soft power is an attack vector.

Illustrations: Clapham Junction railway station, in 2002 (via Wikimedia.)

Wendy M. Grossman is an award-winning journalist. Her Web site has an extensive archive of her books, articles, and music, and an archive of earlier columns in this series. She is a contributing editor for the Plutopia News Network podcast. Follow on Mastodon or Bluesky.

Bedroom eyes

We’ve long known that much of today’s “AI” is humans all the way down. This week underlines this: in an investigation, Svenska Dagbladet and Göteborgs-Posten learn that Meta’s Ray-Ban smart glasses are capturing intimate details of people’s lives and sending them to Nairobi, Kenya. There, employees at Meta subcontractor Sama label and annotate the data for use in training models. Brings a new meaning to “bedroom eyes”.

This sort of violation is easily imposed on other people without their knowledge or consent. We worry about the police using live facial recognition, but what about being captured by random people on the street? In January’s episode of the TechGrumps podcast, we called the news of Meta’s new product “Return of the Glasshole“.

Two 2018 books, Mary L. Gray and Siddharth Suri’s Ghost Work and Sarah T. Roberts’ Behind the Screen made it clear that “machine learning” and “AI” depend on poorly-paid unseen laborers. Dataveillance is a stowaway in every “smart” device. But this is a whole new level: the Kenyans report glimpses of bank cards, bedroom intimacy, even bathroom visits. The journalists were able to establish that the glasses’ AI requires a connection to Meta’s servers to answer questions, and there’s no opt out.

The UK’s Information Commissioner’s Office is investigating, and at Ars Technica Sarah Perez reports that a US lawsuit has been filed.

As the original Swedish report goes on to say, the EU has no adequacy agreement with Kenya. More disturbing is the fact that probably hundreds of people within Meta worked on this without seeing a problem.

In 1974, the Watergate-related revelation that US president Richard Nixon had recorded everything taking place in his office inspired folksinger Bill Steele to write the song The Walls Have Ears (MP3). What struck him particularly was that everyone saw it as unremarkable. “Unfortunately still current,” he commented in his 1977 liner notes. Nearly 50 years later, ditto.

***

A lot of (especially younger) people don’t remember that before 9/11 you could walk into most buildings without showing ID. Many authorities – the EU in particular – have long been unhappy with anonymity online, and one conspiratorial theory about age gating and the digital ID infrastructure being built in many places is that the goal is complete and pervasive identification. In the UK, requiring ID for all Internet access has occasionally popped up as a child safety idea, even though security experts recommend lying about birth dates and other personal data in the interests of self-protection against identity theft.

Now we have generative AI, and along comes a new paper that finds that large language models can be used to deanonymize people online at large scale by analyzing profiles and conversations. In one exercise, they matched Hacker News posts to LinkedIn profiles. In another, they linked users across subReddit communities. In a third, they split Reddit profiles to mimic the use of pseudonymous posting. Pseudonymity doesn’t offer meaningful protection (though I’m not sure how much it ever did), and preventing this type of attack is difficult. They also suggest platforms should reconsider their data access policies in line with their findings.

It’s hard to imagine most platforms will care much; users have long been expected to assess their own risk. Even smaller communities with a more concerned administration will not be in a position to know how many other services their users access, what they post there, or how it can be cross-linked. The difficulty of remaining anonymous online has been growing ever since 2000, when Latanya Sweeney showed it was possible to identify 87% of the population recorded in census data given just Zip code, date of birth, and gender. As psychics know, most people don’t really remember what they’ve said and how it can be linked and exploited by someone who’s paying attention. The paper concludes: we need a new threat model for privacy online.

***

The Internet, famously, was designed to support communications in the face of a bomb outage.

Building it required physical links – undersea cables, fiber connections, data centers, routers. For younger folks who have grown up with wifi and mobile phone connections, that physical layer may be invisible. But it matters no less than it did twenty-five years ago, when experts agreed that ten backhoes (among other things) could do more effective damage than bombs.

This week’s horrible, spreading war in the Middle East has seen the closure of the Strait of Hormuz and the Red see to commercial traffic. Indranil Ghosh reports at Rest of World that that 17 undersea cables pass through the Red Sea alone, and billions, soon trillions, of dollars in US technology investment depends on fiber optic cables running through war zones. There’s been reporting before now about the links between various Middle Eastern countries and Silicon Valley (see for example the recent book Gilded Rage, by Jacob Silverman), but until now much less about the technological interdependence put in jeopardy by the conflict. Ghosh also reports that drones have struck two Amazon Web Services data centers in UAE and one in Bahrein.

The issue is not so much direct damage to the cables as the impossibility of repairing them as long as access is closed. The Internet, designed with war in mind, is a product of peace.

Illustrations: Monument to Anonymous, by Meredith Bergmann.

Also this week: At the Plutopia podcast, we interview Kate Devlin, who studies human-AI interaction.

Wendy M. Grossman is an award-winning journalist. Her Web site has an extensive archive of her books, articles, and music, and an archive of earlier columns in this series. She is a contributing editor for the Plutopia News Network podcast. Follow on Mastodon or Bluesky.