<<

viewpoints

VDOI:10.1145/3325287 Peter J. Denning The Profession of IT An Interview with David Brin on Resiliency Many risks of catastrophic failures of critical infrastructures can be significantly reduced by relatively simple measures to increase resiliency.

ANY PEOPLE TODAY are concerned about critical infrastructures such as the electrical network, wa- ter supplies, telephones, Mtransportation, and the Internet. These nerve and bloodlines for society depend on reliable computing, communications, and electrical supply. What would happen if a massive cyber attack or an electromag- netic pulse, or other failure mode took down the electric grid in a way that re- quires many months or even years for re- pair? What about a natural disaster such as hurricane, wildfire, or earthquake that disabled all cellphone communications for an extended period? David Brin, physicist and author, has been worrying about these issues for a long time and consults regularly with companies and federal agen- cies. He says there are many relatively straightforward measures that might greatly increase our resiliency—our ability to bounce back from disaster. I spoke with him about this.

Q: What is the difference between resil- ience and anticipation? anticipation makes it hard for protec- Q: Let’s see what anticipation and re- BRIN: Our prefrontal lobes help us tors to appreciate how we cope when silience look like for a common threat, envision possible futures, anticipat- our best-laid plans fail, which they do, disruptive electrical outages. They can ing threats and opportunities. Plan- sooner or later. be caused by storms, birds, squirrels, ners and responders augment these Resilience is how we cope with un- power grid overload, or even preventive organs with predictive models, intel- expected contingencies. It enables reduction of wildfire risk. Without pow- gathering, and big data, all in search us to roll with any blow and come up er, we cannot use our computers or ac- of dangers to anticipate and counter fighting, keeping a surprise from be- cess our files stored in the Internet. Even in advance. Citizens know little about ing lethal. It’s what worked on 9/11, our best disaster planning cannot fix the how many bad things these protectors when all anticipatory protective mea- disruption if infrastructure damage is

have averted. But this specialization in sures failed. severe. Yet, communication is essential BRIGHAM CHERYL BY PHOTO

28 COMMUNICATIONS OF THE ACM | JUNE 2019 | VOL. 62 | NO. 6 viewpoints viewpoints

for recovery. What can we do to preserve Q: What about solar on the southward our ability to communicate? walls of buildings to power the build- On 9/11, passengers aboard flight Alas, our comm ings? Some cities are already doing this. UA93 demonstrated remarkable resil- systems are fragile Sure, south-facing walls are anoth- ience when they self-organized to stop er place for photovoltaics. But there’s the terrorist plot to use that plane as to failure in competition for that valuable real a weapon against their country. If we any natural or estate—urban agriculture. Technolo- want that kind of resilience to work on unnatural calamity. gies are cresting toward where future V a large scale, we need resilient commu- cities may require new buildings to nications. Alas, our comm systems are recycle their organic waste through fragile to failure in any natural or un- vertical farms that purify water while natural calamity. One step toward resil- generating either industrial algae or ience would be a backup peer-to-peer else much of the food needed by a me- (P2P) text-passing capability for when business solar system when the electri- tropolis. With so much of the world’s phones can’t link to a cellular tower. cal utility has blacked out. The purpose population going urban, no technol- Texts would get passed from phone to is to prevent spurious home-generat- ogy could make a bigger difference. phone via well-understood methods of ed voltages from endangering repair The pieces are coming together. packet switching until they encounter linemen. This is a lame excuse for an What’s lacking is a sense of urgency. a working node and get dropped into insane situation. Simply replace that Pilot programs and tax incentives the network. Qualcomm already has cutoff switch with one that would still should encourage new tall buildings this capability built into their chips! block backflow into the grid, but that to utilize their southward faces, nur- But cellular providers refuse to turn it feeds from the solar inverter to just two turing this stabilizing trend during on. That’s shortsighted, since it would or three outlets inside the home, run- the coming decade. be good business too, expanding text ning the fridge, some rechargers, and coverage zones and opening new rev- possibly satellite coms. Just changing Q: You’ve also spoken about apps sys- enue streams. Even in the worst na- over to that switch would generate ar- tems that turn your smartphone into tional disaster, we’d have a 1940s-level chipelagos of autonomous, resilient an intelligent sensor. Can you say how telegraphy system all across the nation, civilization spread across every neigh- this supports resiliency? and pretty much around the world. borhood in America, even in the very Cellphones already have powerful All it would take to fix this is a small worst case. A new rule requiring such cameras, many with infrared capabil- change of regulation. Five sentences switches, and fostering retrofitting, ity. Soon will come spectrum-analysis requiring the cell-cos to turn this on would fit on less than a page. apps, letting citizens do local spot whenever a phone doesn’t sense a Across the next decade, more solar checks on chemical spills or environ- tower. (And charge a small fee for P2P systems will come with battery storage. mental problems, and feeding the texts.) Doing so might let us restore But this reform would help us bridge results to governments or NGOs for communications within an hour rather the next 10 years. modeling in real time. The Tricorder X than months. Prize showed how just a few add-on de- Many efforts have been made to Q: What about protection against elec- vices can turn a phone into a medical empower folks with ad hoc mesh net- tromagnetic pulse disruption? appraisal device, like Dr. McCoy had in works, via Bluetooth, Wi-Fi webs, and Much has been written about danger “.” Almost anyone could use so on. None of these enticed more than from EMP—either attacks by hostile such apparatus in the field with little a tiny user base—nothing like what’s powers or else the sort of natural disas- training. Take a few measurements, needed for national resilience. ter we might experience if the Sun ever and a distant system advises you on struck us head-on with a coronal mass corrective actions. Q: It appears that solar power for ejection, commonly called a solar flare. Infrared sensors, accelerometers, and homes and offices is at a tipping point These CMEs happen often, peaking chemical sensors could provide a full as more people find it cheaper than every 11 years. We’ve been lucky as the array of environmental awareness sys- the power grid. Localized solar power worst ones have missed Earth. But some tems by turning citizen cellphones into should also bring new benefits such as space probes have been taken out by di- nodes of an instant awareness network. ability to maintain minimum electrical rect hits and a bulls-eye is inevitable. (I describe this in my novel Existence.) function at home during a blackout. Is The EMP threat was recognized over Such a mesh is already of interest to independence from the electrical grid 30 years ago. We could have incentiv- national authorities. But the empha- good for resilience? ized gradual development of shielded sis has been hierarchical—authori- It would be. One can envision a mil- and breakered chipsets, including ties send public reports down to citi- lion solar-roofed homes and business- those in civilian electronics. Adoption zens after gathering and interpreting es serving as islands of light for their could have been stimulated with a tax data flowing upward. The hierarchical neighborhoods, in any emergency. But of a penny per non-compliant device, mind-set comes naturally when you there’s a catch. Under current regula- with foreseen ramp-up. By now we’d are an authority with protective duties. tions, almost all U.S. solar roofs have be EMP resilient, instead of fragile hos- But this can blind even sincere public a switch that shuts down the home or tages either to enemies or to fate. servants to one of our great strengths—

JUNE 2019 | VOL. 62 | NO. 6 | COMMUNICATIONS OF THE ACM 29 viewpoints

the ability of average citizens to self-or- 5,000 amateurs’ backyards, spread hoods in SUVs stealing stuff and espe- ganize laterally. around the world. As Earth rotates, cially food, with no police to stop them. Use your imagination. The great- these backyard stations would sweep I well-understand this worry! I’ve est long-term advantage of our kind of the sky in overlapping swathes, sift- written collapse-of-civilization tales. society is that lateral citizen networks, ing for anomalous signals, but also (One of them, , was filmed while occasionally inconvenient to detecting almost anything interesting by .) Hollywood pres- public servants, aren’t any kind of mac- that happens up there. Argus failed ents so many apocalyptic scenarios, ro-threat, but will make civilization earlier because of the complexity we tend to assume we live on a fragile perform better. This is in contrast to and expense of racks of equipment. edge of collapse. But Rebecca Solnit’s despotic regimes, for whom such citi- Today—with a small up-front invest- book, A Paradise Built In Hell, shows zen empowerment would be lethal. ment by some mere-millionaire—we decisively that average citizens— could offer a small box for a couple of whether liberal or conservative—are Q: Some of your proposals are less fa- hundred bucks that could be latched actually pretty tough and dynamic. miliar. You have spoken of “all sky to an old TV dish-antenna, then Wi- They quickly self-organize to help awareness.” What is that and how does Fi linked via the owner’s home. The their neighbors. A quarter or more of it improve resiliency? dish—plus a small optical detector— citizens will almost always run toward Defense and intelligence folks could report detections in real time whatever the problem is. Take citizen know we need better 24/7 omni-aware- and any pair or trio that correlate response on 9/11, or when disasters ness of land, sea, and air. Major efforts would then trigger a look by higher- hit their neighborhoods. involve protective services and space level, aimable devices. If “affluent neighborhoods” want to assets. When the Large Synoptic Tele- Sure, most of the participants be safe, there’s one method that works scope comes online in Chile, we’ll would think of their backyard SETI over the long run … don’t alienate the find 100 times as many asteroids that stations as helping sift the sky for poor and middle class and ensure that could threaten our planet, or like the aliens. So? As a side benefit, we’d the vast majority identify as members one that broke 10,000 windows in Che- become hundreds of times better at of the same overall tribe. As neighbors, lyabinsk. Closer to home, dangerous detecting almost any transient phe- we’ll come to your defense. space debris should be tracked round nomenon overhead, improving both the globe. anticipation and resilience. Q: Anything to mitigate cyber attacks, Similar technology could improve I can go on with a much longer list including phishing and massive iden- air safety and impede smugglers by of unconventional and generally very tity theft? tracking both legal and illicit air traf- inexpensive ways that very simple regu- Sincere people across the spectrum fic. For example, the cell networks I latory or incentive actions might trans- are right to worry about companies mentioned earlier could detect and form national resilience, making soci- and governments collecting massive triangulate aircraft engine sounds ety more robust to withstand shocks amounts of personal data on citizens: for comparison to an ongoing data- across the decades ahead. from the ways they use their smart- base, especially at low altitudes where phones, to always-on mics at home and drug smugglers and human traffick- Q: What about civil unrest or lawless- office (for example, Alexa). Phishing is ers operate, or where terrorists might ness if the disaster takes out or over- another example where crooks use al- attempt an attack, or detecting the whelms local law enforcement? Easy to ready open knowledge about you to lure path of airliners that stray, like Ma- see gangs roaming affluent neighbor- you into fatal online mistakes. We all laysian Air flight 370. Imagine those fret about disparities of power that may in peripheries like Canada, Alaska, or lead to the “telescreen” in George Or- nearby waters automatically report- Sincere people well’s Nineteen Eighty-Four. From facial ing sonic booms. Among myriad more recognition to video fakery to brainwave mundane uses, these might perhaps across the spectrum interpretation and lie detectors, if these localize incoming hypersonic weap- are right to worry techs are monopolized by one elite or ons, of the kind announced recently another, we may get Big Brother forever. by Russian President Vladimir Putin. about companies There are forces in the world who are Sound implausible? In Decem- and governments eager for this. China’s “social credit” ber 2018, a loose network of amateur system aims to the masses to enforce ‘plane-spotters’ managed to track Air collecting massive conformity on one another. Force One visually, during President amounts of personal In the West, most people are right to Trump’s top-secret Christmas dash to find this prospect terrifying. The reflex a U.S. air base in Iraq. A U.K. photogra- data on citizens. in response is to say: “let’s ban or re- pher used these clues to snap the un- strict this new kind of light.” And that mistakable, blue-and-white 747 jetting is the worst possible prescription. The far overhead. elites we fear will only gain great power Another method: revive the SETI if they can operate in secret, enhanc- League’s Project Argus, aiming to es- ing that disparity, because we won’t be tablish radio and optical detectors in able to look back.

30 COMMUNICATIONS OF THE ACM | JUNE 2019 | VOL. 62 | NO. 6 viewpoints

Consider. It matters much less slowly woven into civilian electronics what elites of all kinds know about for decades. And here’s a thought— you than what they can do to you. And In an era of high tech maybe it has been! After all, if we had the only thing that deters the latter is and lightning reaction truly savvy leaders, they would want to what we know about them. Denying slide this protection into place as qui- elites the power to see has never hap- times, we must etly as possible. Why? Because there pened (for long) anywhere in the his- rely on a highly is a critical vulnerability window, tory of the world. But denying them during which those who are thinking the ability to harm citizens is some- professional cadre about hitting us might strike if they thing we’ve (imperfectly) accom- of protectors. see the chance slipping away. History plished for 200 years. We’ve done it shows that such transitions can be by insisting that we get to see, too. If dangerous, as revealed by John F. Ken- not as individuals, then via the NGOs nedy in While England Slept. we hire to look for us. Some bright folks are paying at- As I appraise in The Transparent So- tention. Elon Musk told me he would ciety, the answer is more light, not less, fix the solar cutoff problem with his for common citizens to be empowered about losing. Not by hiding but by as- Power Wall storage system, and that by technology to take up much of the sertively demanding to see. What I do is the answer … in a decade. A $200 burden of supervising and arguing ask is that you squint and look ahead switch would still be worthwhile, till and applying accountability. The more 50 or 100, and ask what is our baseline then. Another zillionaire expressed we can see the less the bad groups can victory condition? interest in the all-sky awareness proj- hide. If we do this, we’ll not only be re- Every enemy of this enlighten- ect, but more for its contribution to silient, we’ll never have Big Brother. ment, individualist, open-society SETI than national or world security. The answer to phishing, ID theft, experiment—every lethal foe—is Membership in CERT—Community etc., is the same as always—to catch mortally allergic to light. They suffer Emergency Response Teams—rises and deter villains, by ending most when their plans, methods, agents, every year. And so it goes. Just way too shadows for roaches to hide in. and resources are revealed. In con- slowly. trast, we are at worst inconvenienced What truly matters is the very con- Q: We don’t know how to do this be- and—as shown by the Snowden and cept of resilience, which worked so cause the Internet itself is baked in a WikiLeaks affairs—even prodded to well on 9/11 and at every turn of Ameri- cloak of anonymity. We are not going improve a bit. If, say in 50 years, there can history. The U.S. Army, till just one to redesign the Internet protocols any- is worldwide transparency of owner- generation ago, always based its plan- time soon. We need more than light. ship and power and action, then we ning on vast pools of talented, healthy Isn’t the solution good locks on our win. We—a humanity that is inquisi- volunteers rushing in to fill the thin databases? tive, confident, individualistic, and blue line. Sure, in an era of high tech Sorry, show me one time when free—simply win. and lightning reaction times, we must “good locks” worked for very long. Ev- rely on a highly professional cadre of ery week, some previously “for sure” Q: These resiliency proposals all sound protectors. But the worst thing they database is raided or leaks. All that so reasonable. Why have they not been could do is to declare “Count on us … needs happen is for any lock to fail implemented? and only on us.” once, at all, via code-breaking or hack- A cynic would answer that there’s No. We love you and thank you for ing or phishing or human error, and not much economic-constituency be- your service. But a time will come when the information is loose, infinitely hind resilience. No big-ticket orders. you will fail. And when that happens, it copyable. If you base your sense of How much money is to be made from will be our turn—citizens—to step up. safety on secrecy, it will be impossible a slightly costlier home-solar cutoff Help us to prepare, and we won’t let to verify what others don’t know. switch that would feed rooftop en- you down. Look, I’m not saying that there ergy to three outlets in a million U.S. should be no secrets or privacy! Our homes? I spoke about backup peer- David Brin (http://www.davidbrin.com ) is an astrophysicist whose international best-selling novels include skilled protectors need tactical secrecy to-peer texting at a defense industry The Postman, Earth, and Existence. He serves on advisory boards (for example, NASA’s Innovative and Advanced to do their jobs. But smaller volumes conference where a Verizon vice- Concepts program or NIAC) and speaks or consults on and perimeters are easier to defend president in attendance went abso- a wide range of topics including AI, SETI, privacy, and national security. His nonfiction book about the information and seal. It has always been U.S. policy lutely livid. Qualcomm tried subse- age—The Transparent Society—won the Freedom of Speech that secrecy should bear some burden quently to get them—and AT&T—to Award of the American Library Association. of justification and—eventually—a try some regional experiments; Peter J. Denning ([email protected]) is Distinguished Professor of Computer Science and Director of the time limit. might P2P texting might actually Cebrowski Institute for information innovation at the This isn’t the time or place to ar- turn a profit? Alas, no one wants to Naval Postgraduate School in Monterey, CA, is Editor of ACM Ubiquity, and is a past president of ACM. The gue the point. Alas, the reflex to seek risk disruption, even though this author’s views expressed here are not necessarily those of safety in shadows is so strong that one function could knit our entire his employer or the U.S. federal government. folks forget how we got the very free- continent together, in a crisis. doms, wealth, and justice we worry EMP resistance should have been Copyright held by authors.

JUNE 2019 | VOL. 62 | NO. 6 | COMMUNICATIONS OF THE ACM 31