Sunday, November 9, 2008
Proprietary security
Just a quick note - All the security flaws described in this article are attacks against proprietary software. The argument about that open source software is fundamentally less secure than proprietary software doesn't really hold up, yet again. Any software that has a significant user base will have to deal with hacks, attacks, and trojans. Healthy FLOSS communities simply respond faster.
Technorati Tags Security,IT,FLOSS
Two Innocentive challenges for readers of this blog
Innocentive is a crowd sourcing invention network of corporate or ngo partners who post problems and a completely distributed network of folks who solve them for cash prizes. While many (most) of the challenges are of a very technical nature involving chemical engineering, bioengineering, physics, materials science etc there are, here and there, some problems which fall into the realm of public policy, architecture and design, and programmatic planning. When I see on of these projects I'll post them here to see if we can't crowd source a crowd sourced question. Thanks to Fester at Newshoggers for prompting this post and the series of posts on this issue to follow.
Chicago Public Transportation
The provided solution should accomplish the following:
- Develop a plan to increase public transportation ridership in Chicago to 1 billion rides per year, adding approximately 800,000 new riders to the system.
- Solutions should be have reasonable costs that are explicitly estimated in the proposal
- The use of innovative technologies and strategies encouraged, but should be reasonable.
The solutions should be in the form of a written document. The document should clearly answer the above questions and fulfill the above criteria. There is no absolute length limit to solutions for this Challenge, although we estimate that the winning solution will be between 2 and 15 pages. Longer, well thought out proposals will also be considered.
This Ideation type of Challenge has a guaranteed award of $5,000 that will be determined exclusively be the Seeker. If multiple solutions are deemed winners, they may be each awarded partial awards totaling $5,000.
Rainwater storage system for the developing world
Project CriteriaThe Challenge is to design a very low cost rainwater storage system that can be installed in a developing country. Designs that are modular, adaptable, salvageable or that have multipurpose function are preferred.
This requires only a written proposal.
The proposal, which will be evaluated by the Seeker on a theoretical basis, should include the following:
- Identification/Detailed Description of a rainwater storage system that can meet the technical requirements as explained above.
- Rationale as to why the Solver believes that the proposed design will work. This is important for an acceptable solution. This rationale should address each of the Technical Requirements described in the Detailed Description and should be supported with relevant examples and literature citations if applicable.
- Cost estimates of all aspects of the design as explained in the requirements above.
- Detailed drawings of your design
Technorati Tags crowd,Innocentive,sourcing
Why FOSS will not suffer from Tragedy of the Commons
Free and Open Source Software will never succumb to the tragedy of the commons. FOSS simply uses a completely different model of generation and community consumption. The tragedy of the commons argument (Wikipedia page here) is often used as an argument for government regulation of collectively held assets or for the complete privatization of all the assets.
Regulation is encouraged by some to prevent the overuse of the resource by a select few of the owners. In the typical example there is a town with a collectively held green that is used for pasturage. Every town citizen has the right to graze their cattle on the common. Assuming all the interested parties would like to own healthy cattle for more than one year, there is both a collective and individual interest to keep the grass healthy and resilient through moderating the grass consumption. Unchecked individuals may seek to one-up each other in over consumption of the commons and thus jeopardize the entire communities long term health. Those on the side of regulation say "Let's just limit how much any one person can take from the commons so as to guarantee the long term sustainability of the commons".
Privatization is supported by others to replace the collective responsibility for the health of the commons with a personal self-interest that requires an individual to think sustainably for their own survival. The idea is to split the commonly held land into parcels and give responsibility and ownership to individuals. These individuals would then internalize their need to keep the ground healthy for the next season which would induce self-moderation individually, and through a cascade of this responsibility, collectively.
The process that catalyzes and then later maintains then extends Free and Open Source Software uses the language of the commons but springs from entirely different constraints. The commons used to graze Bostonian cattle in the example above was a finite resource in which the end product was a definable physical product - the well fed cow. Because there is a physical limitation of how much grass can be grown on the common there is a competition for fungible things. The fight is for who can get the most grass into the greatest number of cows. Any grass that your cow eats means that my cow cannot eat it. It's a zero sum game, bub, and I want you to be the zero.
Free and Open Source Software doesn't deal in fungible goods - it simply packages methods of organizing thoughts through technical skill. Free and Open Source Software are commonly created ideas that have been made real. There is no zero sum in the competition for open source software. If you win, I can win too, then build off both victories to create another win-win. Free and Open Source Software, as you can see by that flawless logic, is for winners! More seriously, FOSS doesn't do anything but help you work and think faster, better, smoother. By removing copyright and ownership from the equation you, the end user, can focus on what matters; the value-added from the tool and the quickness with which the tool can be produced or refined.
As Cameron Neylon at Science in the Open alludes to in this post "It is not the object that has value, because it can be infinitely copied for near zero cost, it is the skill and expertise in putting the object together that has value." What you pay for, when you pay for anything in the Free and Open Source world, is the idea - not the object. Without an object, there's no tragedy on the commons.
Technorati Tags FLOSS
Friday, November 7, 2008
OpenEvsys
What is OpenEvys?
OpenEvys is a software suite in development that has been designed by the folks at HURIDOCS in collaboration with the guys at Respere. HURIDOCS is a human rights watchdog network based in Geneva, Switzerland that works "to ensure that human rights organisations have the tools, knowledge, skills and supporting services to use their information resources effectively." Much of HURIDOCS work is focused on helping the human rights community report abuses and interventions in some of the most dangerous areas of the world. HURIDOCS tries to help other human rights agencies and individuals by creating the tools to do their jobs more effectively(a mission after my own heart). OpenEvys will be a Sahana-based case working system designed to aid humanitarian agencies keep track of both human rights violations and the measures taken to intervene.
Why am I so excited about this announcement?
I have a few reasons, in no particular ranked order, why I"m excited about this new development.OpenEvys will be Sahana based
Sahana is a free and open source disaster management tool (Sahana site here/ My blog description here) that is currently focused on post-disaster aid and recovery coordination. The Sahana community has a very organic bottom up organization that solicits contributions from all interested parties and varying levels of technical skill. It's an egalitarian organization where anyone with a good idea will have a fair shake. Additionally, the community is just that- a community. When major disasters have hit (Leyte mudslides, China earthquake, etc) the Sahana community has mobilized its volunteer base to aid in the implementation and customization of Sahana to the locality.So far, however, Sahana has not moved much beyond in-kind donations or "logistics" for the aid coordination. This is not a knock on Sahana - FEMA has a juggernaught of personnnel and budget compared to that being funneled to Sahana and they're still lost. There is only so much the Sahana community can accomplish with the limited resources available at present.
Because OpenEvys will be Sahana based, the organic community, technical standards, and hopefully the volunteer base might be mobilized to support deployments of the software suite. The main advantage for OpenEvys adopting Sahana community standards is that it will allow for easy customization of OpenEvys for post-disaster case working.
Free and Open Source Case Management Software
What do case workers do? Case workers are the advocates for individuals affected by disasters. They help people of all incomes, races, ethnicities, religions etc... to recovery more quickly from the disasters and get back on their feet. In non-emergency situations case workers focus on helping those who fall into at-risk or vulnerable populations. Many of these people are also the most likely to be severely impacted by disasters so much of post-disater caseworking is aiding pre-existing clients with an additional set of problems created by the emergency.Case workers are often social workers or are those with a particular humanitarian bent. Technical knowledge is lacking in their training more often than not because of the overburned schedules and lack of funding that is sadly consistent regardless of the economic climate. Time is money and caseworkers never get enough of either.
An additional feature of the case management universe is that there is a multitude of disparate agencies (see the alphabet soup of agencies at the bottom of the linked page for a small sample) who have case workers on staff. None of these agencies are rolling in cash. Each would like to serve as many peple as possible while keeping within their budgets. In order to prevent duplification of benefits, reduce individual agency overhead, and provide more consistent services, the agencies would benefit from a case management software suite that adheres to open standards and is fully customizable by each of the agencies through paid or volunteer efforts.
While there are ongoing attempts to create this clearing house for case managemnet (See the Coordinated Assistance Network) the software is often too expensive to maintain in non-disaster situations and funding has been an issue.
OpenEvys will be the baseline case management software suite that has already found a champion in HURRIDOCS. Agency participation is voluntary.
Technical tools for the non-technical end user
The most important development in my opinion, is that this is another attempt to engage the non-technical in the creation of their own tools. By creating a Free and Open Source Case Management suite based on Sahana, HURIDOCS is giving the power to the social workers/case workers at the point end of the mission. The social workers get to dictate how they want to work and what their software will enable them to do. This revelation, this empowerment, of the end-user caseworker can only help the entire process.Assuming positive engagement of the case worker community, the software will make them more effective in the short term with the implementation of a community-designed software suit but also in the longer term as the implications of self-created tools empowers the end user to change their approach to how they approach their work.
Non-technical end user social workers (dirty f****ing hippies) will be able to reject off the shelf software as the mediocrity it likely is and build their own with the help of the technical community.
This future cannot come soon enough.
Dear Humanitarian-ICT group --
I'm Tom Longley, a project manager at Human Rights Information and
Documentation Systems, International (HURIDOCS). HURIDOCS is
Geneva-based, and has worked on information management for human
rights for 20 or so years. We've developed some useful tools to assist
human rights defenders in monitoring the situation in their country,
or globally. These include data standards, methodologies, controlled
vocabularies and database applications for documenting and analysing
human rights violations.
After a Request for Proposals process (RFP) run across this summer,
we've decided to use SAHANA as the underlying framework for
"OpenEvsys", anew open source human rights case management system.
SAHANA's features and capabilities clearly meet many of the requests
that organisations using our past applications have made of us over
the last year: clean, attractive interface, server-based, multi-user,
access control and permissioning, improved security, mapping and
charting.
Your colleagues at Respere (http://respere.com/) won the RFP with an
exiting, hugely persuasive vision of what could be achieved by
investing in, and re-using SAHANA in this way. OpenEvsys will be
released as free and open source software, and we are also pursuing
open methods in the product's development. Development is already
underway at Respere: we'll open the growing codebase up shortly on a
public repository, and gradually build up the ways in which people can
involve themselves in the project.
Amongst many things, we see OpenEvsys as:
- A generic case management system, tethered to Human Rights
standards, that meets the core needs of monitoring organisations but
is not costly to customise.
- An open place where technical people and others can contribute to
improving a system that is directly in use by human rights organisations.
- a starting point for service providers to work with in many
different local ICT markets and settings.
- A challenge to the sad habit in our sector of locking up vast public
international and donor resource in costly, duplicate, secret systems
that could easily benefit our community, and be strengthened by public
exposure.
We've put together a short briefing paper about OpenEvsys, which
describes what it will do, how it's being developed, when it will be
ready, and who will find it useful:
http://www.huridocs.org/tools/
(grab as PDF: http://tinyurl.com/
Happy to take any questions right here...
Regards,
Tom
Technorati Tags tech,cool,sahana,foss,humanitarian
Monday, October 27, 2008
InSTEDD Tracker
InSTEDD nails it with Tracker.
Tracker is a news and feed aggregator with a purpose. The site pulls in feeds which have a bearing on humanitarian relief. InSTEDD's mission is focused in the realm of public health (pandemics) but they're smart about how they're approaching the problem. The folks at InSTEDD have decided to fight pandemics by looking to destibilize the system that produces pandemic disease in human population.
InSTEDD's particular focus at the current moment is capacity building in Cambodia and SouthEast Asia to boost reporting and tracking capability. They believe that the best information and the quickest reporting stream is to be had from well educated people dispersed throughout the commmunity. The summary of their approach to disaster relief and public health is on this page at their site. Their work, in their own words, is focused onbuilding "a better global immune system. We know we alone can't truly stop diseases, war, poverty, or climate change, but we think we can help humanity to learn about threats faster, and so respond quicker, and so soften the impact." (italics mine)
Tracker is designed to help humanity with that last bit, otherwise known as the important part. Unlike other news aggregators, Tracker doesn't categorize and segregate the different stories that are being pulled into the feed reader. Stories about public health are right next to the newest software developments which are right next to the latest report from Human Rights Watch.
"Tracker is an aggregator with a few twists. Links are not limited to breaking news, but include research papers, in-depth analyses, blog and vlog posts, podcasts, videos, websites and even book reviews. A story on a major earthquare might be grouped with an older but still relevant research paper on predicting aftershocks and fresh-from-the-field blog post about a new software application for mapping damage using a cell phone."
The goal of the site to set the stage for accidental interindustry cross polination of good ideas. Only when we can think faster and wider, when we can synthesize (meatier link here), disparate information, can we approach any useful planned activity in the disater world.
Tracker puts many of the pieces for a new snowmobile in one place - but are they the right pieces?
For now, I don't care. It's a step in the right direction and it's making the right philosophy a practical reality.
Saturday, October 25, 2008
Straw and camels
DRAFT (updated 11/9/08)
The straw that breaks the camel's back is a phrase uttered far too often in everyday conversation. It should never be uttered in (post) disaster situations. For the rest of the post, I'm going to refer to "the straw that breaks the camel's back" as the phrase
Why do I have such a strong reaction against the phrase?
Words matter. The words that are available to us both shape and limit the ideas that we are capable of expressing. Repeated use of the phrase pushes us, even if unwillingly, toward a certain simplistic mode of thinking. This particular phrase lends itself to oversimplificiation and almost immediately to a case of the "if only's". If only the nylon strap was better constructed. If only the levees had been better constructed. If only banks ability to leverage their assets had been better regulated. If only <insert pet cause here> then <horrible disaster> would have been prevented.
But isn't the "straw that breaks the camel's back” describing the tipping point?
Well, yes, it is. But ask yourself how many people will take that into consideration when you use the phrase. Ask yourself: in your most fatigued state, do you always look for the linkages of causation within an event of are you looking for the immediate fire to put out? Or do you sometimes let yourself lapse into intellectual laziness and catch a case of the if only's?
Alternative thinking and disaster applications
Disasters occur every minute of every day. The reason you don't hear about them is the scale and the connectivity of the person affected by the disaster to your informational network. The disasters that you do hear about are the foam on the crest of the wave. There was a massive decentralized effort to get that story or wave to you in its exact form that was, to your eyes, completely behind the scenes. All you know is that the disaster showed up on the front page of the New York Times.
Disasters that you hear about are extraordinary events. While the New York Fire Deparmtment recieved 490, 767 calls in 2007 it's likely you only noticed the few big or tragicincidents that were deemed newsworthy. These are the events where numerous things go wrong in sequence and relation to each other to cascade onto the front page.
In the ideal world, we would learn everyday from our failings and incorporate those lessons into mitigation or response strategies. New York City's revised building code is a good example of this effort. The combined lessons learned from decades of international engineering successes and failures was distilled into codification. This is not, however, the end of the story.
Disasters are unique in that there are never enough of them, at least on the catastrophic scale, to allow an easy synopsis of the lessons learned that are portable to other types of disasters. Finding portable lessons learned is the tough part here. Instead of learning about New Orleans if only's and the failure of the levees, we should be learning about the command and control problems ineherent in creating a diverse coalition of competing interests. Instead of hearing about the Failure of Initiativeif only we should be hearing about ways to encourage an organizational capacity to pursue and nuture unnoficial information sources. We should be hearing about how to instigate and encourage and yes, catalyze, community based organizations who will fight government at every step for the good of the community itself. We should have heard more about how to reduce the operational friction that prevents healthy response across disasters.
What am I describing? I'm describing a world where the actors are distributed and completed by those with the organizational capacity to do so, at the level closest to the community and the end users. Preferably, the end users themselves should be organizing and responsible for their own recovery. I'm thinking of an organization where “decisions” per se are not made and handed down but where the individual actual actors make the choices and the reprocussions and reporting filters up. I'm imagining and organization that approaches the problem looking for linkages, relationships, and the potentialities for negative and positive feedback loops rather than for assignation of blame or credit. I want a collection of organizations that pursue the quickest means to follow their mission and help the widest range of people.
This ideal agency should not waste their organizational capital, budgets, or time pursuing the fix for the phrase. Fixing that one thing would only increase the likelihood of some other type of disaster. I am not suggesting that agencies not fix what they are able to fix - I am suggesting that agencies acquire an awareness that their decisions are part of a web of decisions being made all the time which may have uninented consequences.
A minor example - increasing the number of building inspections increases the likelihood of bribery and corruption.
Liveblogging transparency
In this blog I will often preach the value of transparency for individuals, companies, ngo's and government. I figure I should walk the walk as much as I write the talk. To this end, I will be liveblogging everything in this blog. You will see the post layout, initial post outlines, thoughts, and the eventual final product.
This may be messy initial as I get the hang of it and can adjust my way of thinking through the topics. I'm okay with that. I am no idiot savant. There will be failed ideas, posts, analogies, and misconceptions of other ideas. The best way for me to learn is to force my ideas to butt against those ideas and run my faulty ideas to ground as quickly as possible.
Viva l'experimentation!