Wednesday, September 15, 2010

Toronymous

[A short story in progess..]

The twenty teens were destructive. Constructive, really, as the saying goes, but that only came behind its ruinous wake. For just as the web's ecological structure, it's business model, as they liked to say in the day, was beginning to solidify, just when it seemed the Wild West had finally been tamed, just when click-through rates were hailed the most accurate barometer of economic activity, the rug was about to be pulled from underneath.

The dark web, as it was later called (and then forgotten), like the web before it, developed mostly in the shadows, and by the time the captains of the new [old] order could see it coming, it was already too late. It represented not just new technology but also a movement. It was embodied in a word, an electronic device, really: the Toronymous.

In 2014, the small Taiwanese router manufacturer NextHop first introduced the device. Technically, it was hardly groundbreaking: a mashup of off-the-shelf hardware, and open source software that many a hobbyist could build themself, now packaged in a smooth, reassuring, charcoal black encasing bearing an orange lizard logo--available at Walmart.

To be sure, there would have been many other similar devices on the store shelf at this time. Bundling home and business routers with extra smarts and storage capacity was already a booming growth category. These new smart routers (recall, the vernacular "smart" connoting snooty comes a few years later), not only serviced their owners inside the network, but also served users outside the network (the public): the router, in other words, was also one or more websites.  They were touted to do many things: a thermostat manufacturer, for example, provided a simple plugin that allowed the temperature be set remotely.

But more significantly, following a number of high profile divorce suits in which Facebook data were subpoenaed, people had begun to see a need to take physical possession of their digital contributions to the web. These routers now allowed their owners to host their own blogs, blurbs, and albums on a device they physically owned and could always unplug.

A number of geeky developments had set the stage. From small beginnings, W3C work on a secure, web-based, push/pull information exchange protocol had yielded a set of basic building blocks--collectively called DOSN (pronounced "Dawson")--for constructing (among other things) distributed, implementation-agonsitc, social networks. This simple, Spartan "standard" had attracted a good deal of mindshare in the community: developing DOSN-based, social networky apps was considered sexy. What was cool about doing apps this way was that different implementations now had a way to talk to one another. And these applications had now found a new home in those shiny routers sitting on the store shelf.

The movement had caught on. A dark web had emerged. From the inside, it looked very much like the ordinary web outside. Only, who could see what was now determined by you and your friends, not some central clearing house. In the dark web, you would trust certain people with certain information. To be sure, your friends could leak the information you shared with them--but that is how it had always been and would be. Now, however, using steganographic tools, it was usually possible to determine who had leaked the information by examining the version of the leaked artifact.

Facebook page views, meanwhile, for the first time in the company's history, started trending lower, and the company's stock price sank following two consecutive quarters of declining growth. The market had been caught off guard, and there were now no shortage of pundits predicting the next business model headed to the dust bin.

The growth of the ad-free, dark web, however, had thus far not come at Google's expense. Indeed, the benevolent giant was making forays into the smart router market with its own Linux-based Droid Route (DR) operating system. Google had seen no decline in overall traffic as the dark web had emerged. To the surprise of many, it turned out a great many darkies, as they liked to call themselves, were not so private after all. They still shared a great deal of information about themselves publicly--which the search engines were only too happy to index.

Google's advertising model had evolved. Broadly, its ad placements were determined from two inputs: the content the user was viewing, and "anonymized" information about that user. The content side of this equation was safe. The Personally Unidentifiable Identity (PUI, pronounced "pew-ee") end of the business, however, was increasingly under attack. Privacy groups had long bemoaned the lack of oversight in this burgeoning industry, and time and again, security experts had demonstrated how to de-anonymize supposedly anonymized information. Google, it was said, knew more about you than any other government or commercial entity on the planet. This concentration of informational power worried many, and some were even considering legislative measures and remedies that defined what, how and when personal information could be harvested.

But the browser makers had already begun chipping away at the ability of PUI outfits to harvest personal information about users. Better cookie / persona management, HTTP request header sanitization (e.g. user-agent, and referrer), ad-block mode, and a slew of other out-of-the-box improvements had made life for the PUIs more difficult. A cat and mouse game had begun--with the cat casting an ever wider net, as the mouse got better at evading it.

Still, the PUIs' ace in the hole was the user's IP address. At the end of the day, whether dynamically or statically assigned, a user's IP address was an anchor from which much information could be gleaned, cross-correlated against databases of user browsing habits, pieced and assimilated into existing "anonymized" user dossiers maintained by the PUI.

Others however saw a giant industry standing on its last leg. Take away the IP address, and they got nothing, they argued. Already a growing number hobbyists and technically savvy users were modding their smart routers to do this by installing Tor/Privoxy gateways.

What distinguished NextHop from its peers however was that it was the first to introduce this mod out-of-the-box. Toronymous was a fantastic, if short-lived, marketing success.  And the story of how Mr. Lang managed to engineer on-demand manufacturing capacity, of course, is still a subject of study for students of business. For example, instead of scaling manufacturing capacity by making more of an existing model, he would craft a new model suited to the manufacturing location at hand. (And so it was that NextHop next introduced the Toronymous X series, and as if the pun needed explaining, this branding pattern was followed by Toronymous Rex, and then simply the Toronymous Rx series.)

Mr. Lang was right to milk this brand as fast as he could, for he never even owned it. Tor, the open source project responsible for a key software component used in the device, had sent the company a cease-and-disist over their use of Toronymous . NextHop at first rebuffed the claim, but when Lang learned his trademark applications at the Patent and Trademark Office were going nowhere, he approached the group hoping to license the mark. It was not to be, but Lang somehow managed to keep the license negotiations going, all the while Toronymous sales continued.  A Chinese manufacturer, meanwhile, having caught on to NextHop's branding game, introduced the T-Rex. More copycats followed with other variations on the name.

More interesting than its etymology, however, is the movement Toronymous later came to represent. The big, established home/business router manufacturers were the last to embrace the game changing trend towards anonymous browsing. Much of the establishment in America thought anonymous browsing should be illegal, anyway. The public, however, demanded anonymous browsing, and so great was the flood of email citizens sent their representatives that a grand coalition of liberals and conservatives of many stripes in Congress aligned against any legislative measure that would make Toronymous-like devices illegal. That left the fate of Toronymous in the safe hands of the glacial court system.

Toronymity was making the transition from grassroots to mainstream. Or rather, it was the other way around. The early devices had a button which when pressed, glowed an orange icon depicting three overlapping stick figures representing "community mode". In this mode, the device was also a Tor relay. Users were advised to run their devices with the icon glowing. The basis of anonymity, the online help page explained, was safety in numbers and running the router this way helped increase both the online privacy of the owner and the community at large. For some, running in community mode was a way to thumb your nose at power; for others it felt more like pledging money to public television--sharing communal burdens, only now a lot more cheaply. Either way, pressing that button had a feel-good effect for most anyone who had bought the device. It turned consumers into activists.

The world was changing. The router was getting fatter by the day, and more and more storage and computing power was drifting to the edges, to the end user. As Facebook had demonstrated before, people spent increasingly more time on social networks than the web at large. This dark web had emerged as a tier-accessed, individuated, grassroots social network.  It lacked an all-seeing eye.  In fact, no one could see but a small part of it.

Now, to be sure, the web itself was not going dark. Far from it.  The public web was still growing as if there had never been a dark web.  But the dark web was expanding even faster, filled with photos, videos of family and friends, and other information shared discriminately across smaller circles. And as it grew, some private information, whether by intention or accident, whether leaked or released, would make the transition to the public realm. By the time the dark web was an order of magnitude larger than the public web, this constant unidirectional leakage had caused the growth rate of the two webs to converge to a same number. The dark web, in other words, was where the vast majority of web content originated.

Business wasn't quite sure what to make of this new medium: not even the porn industry had come up with a scalable business exploit for it. There were two seemingly insurmountable problems, from a business perspective, with this dark web. One, it was one-to-one: it was relationship-based, and relationships take much too long to develop. Two, it required an authentic human voice, which in turn made working these dark networks labor-intensive.

Meanwhile, a precipitous drop in the Nasdaq PUI Index signaled the coming collapse of a once legitimate industry based on trading, packaging, and selling dossiers of clandestinely gathered personal information. A commentator on a popular financial network lamented, "I don't imagine people quite realize how much this toronymity is costing them. The slide in the PUI [index] alone marks a half-trillion dollar of wealth destroyed."

Maybe. But in a sense that informational wealth had been returned back to its rightful owners. A new world order was in the making.  Or rather an old world was in the remaking. For the dark web heralded the return of the individual, the guild, and the community at the expense of that historically younger institution, the corporation.