// COMPLETE THREAD

Re: (eternity) Eternity as a secure filesystem/backup medium (fwd)

4 expanded posts ยท every known parent and child

NODE 553b483bRe: (eternity) Eternity as a secure filesystem/backup medium (fwd)
Forwarded message:

> Date: Sun, 18 Jan 1998 12:02:34 -0800
> From: Kent Crispin <kent@songbird.com>
> Subject: Re: (eternity) Eternity as a secure filesystem/backup medium (fwd)

> There are alternative ways of paying for the service that do not in
> any way depend on ecash, and after thinking about it a bit, they seem
> more robust, as well. 
> 
> The basic idea is as follows:  The fundamental eternity service is 
> free to readers, and is financed entirely by writers.  The writers 
> supply the disk space, the network bandwidth, and possibly pay for 
> the software to support all this.

It is clear that there are two diametricaly opposed models of payment
mechanisms and who those costs should fall on; producers or consumers.
I personaly have no faith in systems where the producers bear the burden of
the costs since they have no clear mechanism to obtain the funds to finance
the enterprise in the first place.

Imagine for a moment that a couple of persons come into possession of a set
of documents which would cause considerable political embarassment and legal
difficulties for a head of the local government.

Why should these two individuals pay to have their data dissiminated to
anyone who wants it? It certainly isn't going to improve their social,
political, or professional standing since the server will anonymize the
data. They then have two options, release it themselves and hope for the
best (and hence reap the benefit of any economic benefits that might acrue)
or do nothing with it.

How about information to build man portable atomic bombs? It doesn't make
sense to take all those chances and the data haven operators to take the
chances when they will get at most the monetary input from a *single* party.
It is clear that these resources are clearly inferior to many parties paying
to get the data.

I guess the question boils down to why the individual operator in running
the server in the first place. I assume a priori that the goal of both the
submitter and the operator is to make a reliable income from the users of
the service since there are clearly many more consumers of information than
producers of it.


    ____________________________________________________________________
   |                                                                    |
   |       The most powerful passion in life is not love or hate,       |
   |       but the desire to edit somebody elses words.                 |
   |                                                                    |
   |                                  Sign in Ed Barsis' office         |
   |                                                                    | 
   |            _____                             The Armadillo Group   |
   |         ,::////;::-.                           Austin, Tx. USA     |
   |        /:'///// ``::>/|/                     http://www.ssz.com/   |
   |      .',  ||||    `/( e\                                           |
   |  -====~~mm-'`-```-mm --'-                         Jim Choate       |
   |                                                 ravage@ssz.com     |
   |                                                  512-451-7087      |
   |____________________________________________________________________|
NODE 0d75a240eternity economics (Re: (eternity) Eternity as a secure filesystem/backup medium
Jim Choate <ravage@ssz.com> writes:
> Kent Crispin <kent@songbird.com> writes:
> > Subject: Re: (eternity) Eternity as a secure filesystem/backup medium (fwd)
> 
> > There are alternative ways of paying for the service that do not in
> > any way depend on ecash, and after thinking about it a bit, they seem
> > more robust, as well. 
> > 
> > The basic idea is as follows:  The fundamental eternity service is 
> > free to readers, and is financed entirely by writers.  The writers 
> > supply the disk space, the network bandwidth, and possibly pay for 
> > the software to support all this.
> 
> It is clear that there are two diametricaly opposed models of payment
> mechanisms and who those costs should fall on; producers or consumers.
> I personaly have no faith in systems where the producers bear the burden of
> the costs since they have no clear mechanism to obtain the funds to finance
> the enterprise in the first place.
> 
> Imagine for a moment that a couple of persons come into possession of a set
> of documents which would cause considerable political embarassment and legal
> difficulties for a head of the local government.
> 
> Why should these two individuals pay to have their data dissiminated to
> anyone who wants it? It certainly isn't going to improve their social,
> political, or professional standing since the server will anonymize the
> data. 

If the would be disseminater was happy to have their name associated
with the document, they could put it on their own web page.  The
problems may be that:

- they do not want to suffer the legal and extra-legal reprisals for
  posting, 

- they have little faith in the data remaining available for long on
  their web page, once well resourced determined attackers try to remove
  it.

Eternity helps here in that it obscures the poster's identity, and
reduces their exposure in that they personally don't have to send as
many messages.  Eternity also helps ensure continued availability, at
least while somebody is funding that availability.

> They then have two options, release it themselves and hope for the
> best (and hence reap the benefit of any economic benefits that might
> acrue) or do nothing with it.

Releasing the data themselves is problematic.  They may not wish to
accept the risk.  Eternity provides a way to pay someone else to take
the risks in ensuring availability.

> How about information to build man portable atomic bombs? It doesn't
> make sense to take all those chances and the data haven operators to
> take the chances when they will get at most the monetary input from
> a *single* party.  It is clear that these resources are clearly
> inferior to many parties paying to get the data.

The users is getting value for money from the eternity servers -- the
eternity server is providing the service of risk taking.

It is true that someone could pay for accessing the data, and resubmit
it to eternity with themselves as the beneficiary.  They would likely
want to undercut the price charged by the initial poster.  This
suggests a recursive auction market with prices falling over time.
The eternity server operators win in that they are being paid for
their services.

The original poster possibly doesn't make that much money, but the
operator could counter by reducing their prices over time to undercut
other copies also.

There are other ways where the submitter could get higher prices.  He
could for example post the data in encrypted form, and send the
decryption key to a high reputation third party to verify the
authenticity of the data.  He could then demand $10,000 for the key.

Bids would be placed by users interested in obtaining the data.  When
the bid price is reached the data is posted.  Bids would be held in
escrow by the third party.  In the event that the requested price is
not met the ecash could be returned to the bidders.


The market will discover the value of the risk taking services
provided by the eternity servers in that if the servers over-charge,
users will take their own risks, by starting their own servers.  If a
given server under-charges, other servers will sub contract to that
server.  

There is a risk here that the NSA may offer eternity services at
prices undercutting everyone else.  This risk suggests that users
would not necessarily select the cheapest services.  If this pattern
of usage emerges, it also suggests that the NSA would better optimise
their efficacy by not offering the cheapest prices.

The problem of preventing eternity servers sub-contracting all their
work to the cheapest eternity-server (the NSA operated servers)
suggests that it may be desirable to design a system so that the
poster, or some third party auditing agent is able to verify where
data resides.

I can not see how this can generally be achieved, because it seems
difficult to verify whether a server is sub-contracting or not.

So in conclusion the safest strategy seems to be to select random
servers regardless of price.  This results in a flat demand curve, and
no incentive for servers to offer cheap service.

The model is more complex that this in that there are different risk
documents and this risk would affect the price a submitter is willing
to pay.

Adam
NODE 9f7f5143Re: (eternity) Eternity as a secure filesystem/backup medium (fwd)
On Sun, Jan 18, 1998 at 02:53:54PM -0600, Jim Choate wrote:
> Forwarded message:
> 
> > Date: Sun, 18 Jan 1998 12:02:34 -0800
> > From: Kent Crispin <kent@songbird.com>
> > Subject: Re: (eternity) Eternity as a secure filesystem/backup medium (fwd)
> 
> > There are alternative ways of paying for the service that do not in
> > any way depend on ecash, and after thinking about it a bit, they seem
> > more robust, as well. 
> > 
> > The basic idea is as follows:  The fundamental eternity service is 
> > free to readers, and is financed entirely by writers.  The writers 
> > supply the disk space, the network bandwidth, and possibly pay for 
> > the software to support all this.
> 
> It is clear that there are two diametricaly opposed models of payment
> mechanisms and who those costs should fall on; producers or consumers.
> I personaly have no faith in systems where the producers bear the burden of
> the costs since they have no clear mechanism to obtain the funds to finance
> the enterprise in the first place.

You must find the advertising business completely mystifying, then.

> Imagine for a moment that a couple of persons come into possession of a set
> of documents which would cause considerable political embarassment and legal
> difficulties for a head of the local government.
> 
> Why should these two individuals pay to have their data dissiminated to
> anyone who wants it? It certainly isn't going to improve their social,
> political, or professional standing since the server will anonymize the
> data. They then have two options, release it themselves and hope for the
> best (and hence reap the benefit of any economic benefits that might acrue)
> or do nothing with it.

You pay to have your data disseminated in a form that you can be later
paid -- for example, leave the juciest part of the data in encrypted
form, along with a public key through which payment options can be
negotiated. 

[...]
> I guess the question boils down to why the individual operator in running
> the server in the first place. I assume a priori that the goal of both the
> submitter and the operator is to make a reliable income from the users of
> the service since there are clearly many more consumers of information than
> producers of it.

Why on earth do you try to be an ISP, then?  You pay for disk drives 
for other people to store their data, and make it available to the 
world.  The eternity service is actually very similar.

Given a protocol such as I described, you could move to Data Haven
Island, and charge up front to supply pornographers with an entrance
to the eternity service, while John Young could wallow in righteous
ego gratification as he provides space for morally important documents
by donating his disk space to eternity.  You do it for the money, he
does it for the buzz -- there are all kinds of ways to get paid. 

-- 
Kent Crispin, PAB Chair			"No reason to get excited",
kent@songbird.com			the thief he kindly spoke...
PGP fingerprint:   B1 8B 72 ED 55 21 5E 44  61 F4 58 0F 72 10 65 55
http://songbird.com/kent/pgp_key.html
NODE a6accf25Re: (eternity) Eternity as a secure filesystem/backup medium (fwd)
>> The basic idea is as follows:  The fundamental eternity service is 
>> free to readers, and is financed entirely by writers.  The writers 
>> supply the disk space, the network bandwidth, and possibly pay for 
>> the software to support all this.
>
>It is clear that there are two diametricaly opposed models of payment
>mechanisms and who those costs should fall on; producers or consumers.
>I personaly have no faith in systems where the producers bear the burden of
>the costs since they have no clear mechanism to obtain the funds to finance
>the enterprise in the first place.

Assume the existence of a for-profit service provider.
The service provider needs to cover the costs of the service,
plus enough profit to make the effort interesting.
The prices charged need to reflect the costs (or be higher)
or the service provider can't make money and goes out of business.
So what are the costs, and who can be talked into paying for them?

1) Storage of information - Storage currently costs < $1/MB for raw disk, 
and getting cheaper by the minute, but sysadmins, lawyers, etc.
cost money and they're not getting cheaper as fast.
The costs of the equipment for permanent storage are probably about
10-50% more than the costs for storing for 5 years;
the costs of administration (assuming inflation is limited to
some small number) can be covered by an annuity.
Every technology upgrade or two you need to copy the archives to 
new storage media, and data that doesn't get accessed often may
get migrated out to slower or perhaps even offline media;
storage contracts need to reflect that retrieving data that hasn't
been accessed in a while may involve some delay.

2) Transmission of information - Roughly proportional to MB/time -
unlike storage, this one's not predictable, unless the provider and
author agree in advance (e.g. N free accesses per year, per password.)
So the provider could charge the reader for access, or use advertising
banners to fund retrieval costs (if that remains a valid model
for financing the web over the next N years, especially if the
readers retrieve data through anonymizers.)

3) Legal defense - This one's harder to predict :-)  
The current US climate is that service providers are relatively immune 
as long as they cooperate with subpoenas and court orders,
discourage copyright violators, and avoid having legal knowledge of
the contents of their sites, but that could change.

>Why should these two individuals pay to have their data dissiminated to
>anyone who wants it?  It certainly isn't going to improve their social,
>political, or professional standing since the server will anonymize the

If they want their names known, they can include them in the contents
of the data that readers retrieve, independent of what the server does.
(Of course, they can forge other peoples' names as well :-)
And they can use pseudonyms, with or without digital signatures,
and accumulate reputation capital under those nyms.
If they want to collect money from the readers, that's independent -
they may be able to include advertising, or may sell the decryption
keys to the data for digicash or information using some contact mechanism,
or they may just be publishing their manifestos for The True Cause.
				Thanks! 
					Bill
Bill Stewart, bill.stewart@pobox.com
PGP Fingerprint D454 E202 CBC8 40BF  3C85 B884 0ABE 4639