What's up y'all? I'm Skyler Diggins, seven-time WNBA All-Star, Olympic gold medalist, and Mom. And I'm Cassidy Hubbard, posted and reported for nearly 20 years, covering the biggest names and stories in sports. And Mom.
And this is and Mom, a community for athletes, game changers, and moms of all kinds. Dropping May 14th. Happy end with us. Hey everybody, it's Taelei from the Fresh House.
On this week's interview episode, we have Alex Stamos. He's currently the director of Stanford's internet observatory. He explains to us exactly what that means. But you might know him.
As the former chief security officer for Facebook, Alex and I talked a lot about what is going on with Facebook. He was there during the Cambridge Analytica scandal. How that coverage has preceded how it's changed Facebook. The trade-offs big platforms have to make between things like end-to-end encryption, working with law enforcement, keeping users secure from bad actors, what the threats for the platforms are, and honestly how the media doesn't really understand the trade-offs every platform constantly has to make and navigate as they operate these scales.
A super interesting conversation, extremely thought-roaching officer, very smart guy. I don't know if I agree with everything, we disagree a little bit, but I think I learned a lot. Check it out. Alex Stamos, director of the Stanford internet observatory.
Alex Stamos, welcome to the very chest. Hey, thanks anyway. You are the director of the Stanford internet observatory. What is the Stanford internet observatory?
So first off, the word observatory shows up nowhere in the Stanford academic handbook, so that's why it is named what it is, and it's great to be in that liminal space that nobody knows how to stand new. We are a research and teaching program under what is a new cyber policy center here at Stanford. Our goal is to build technology and tools and training to help all the folks outside of computer science to deal with the impact of the internet on their fields. So for example, if you're a political scientist these days and you want to understand how Twitter or Facebook or some other kind of technology is impacting your field, the activation energy for the amount of work you've got to do is really high, right?
You've got to get a grad student, have them write some Python, get access to the Twitter API. We're trying to build all of these tools and techniques one time and then to offer them to a variety of different people from across the social and political sciences to understand what's going on. So we see ourselves as both a group that will do its own research, but also really a support and engineering team to try to help academia deal with the incredible impacts the internet has had on society. And this is the thing I think we're going to come back to a number of times.
There's an element of the internet right now where just to look at it correctly and deal with what it's become, you have to either reinvent the wheel at a very high scale over and over again, or you have to find a service right where you can do it. It sounds like you're kind of like, we're going to help you look at the internet and measure it correctly so you don't have to do it yourself. Yeah, exactly. So we're not actually not an accident, right?
Astronomers have figured this out. If you're an astronomer, you don't raise $5 billion and build your own Hubble Space Telescope, right? You have a theory of what you want to study. You go rent time on the Hubble or the Air Seaboard or the very large array or something.
So we want to do the same thing, like build a set of capabilities that then are going to get used in ways that we have no idea how they'll be used. So I mean, it's a theory, right? Our thesis is if we build it, they will come. But so far we've had a lot of interest from a variety of different academic groups who have deep expertise in different areas of society or area studies, for example, but don't have the technical worth or the access to data to really do this kind of work.
I mean, for that, you're the Chief Security Officer at Yahoo. Yeah, I like boring jobs. I like to go from. Well, those are not boring moments for either company.
Obviously, I want to talk to you about Facebook a bit, but we just had Michael Bennett, Center for Colorado on the show. And he wrote a book about election security. That's obviously, when you think about Facebook, it was the center of election interference, basically like posting memes from Russians on Facebook. I'm curious, do you think we're ready for 2020 right now?
Because Bennett really did not think that we were ready. Yeah, so I've met with Senator Bennett and we've talked a lot about this kind of stuff. So we just put out a report from our group at Stanford. You can go to electionreport.stanford.edu.
If you want to see it, we have around 40 recommendations for how Congress, how tech companies, how individuals can prepare for 2020. If we look at 2016, there's actually three or four different kinds of interference by the Russians, right? So you have what you refer to, which is the online meme wars, which is mostly on Twitter and Facebook. You have the GRU Hack and Lead Campaign.
So that was the campaign of breaking into Odessa's email, breaking into the DNC, and then leaking out information in a way that changed the overall information environment to the detriment of Hillary Clinton. There's the overt propaganda campaign. So there's Russia today and Sputnik and such. And then there was the direct attacks against election infrastructure.
So I think our response to society has been different for those four different lines. So on the meme-lord stuff, I think that's actually where we've been best prepared in that the responsibility there kind of cleanly falls to the tech platforms. And they have done things. I mean, the big difference between now and 2016 is organized government propaganda was not anybody's job at the tech companies in 2016, right?
So I kind of inherited this as an issue that I got to lead the team that worked on this because we had an intelligence team whose job it was to look for governments doing bad things online. That was based upon a very traditional idea of what is government interference online, malware, account takeovers, suppression of dissidents. It did not include hot takes and eds forwarding by people pretending to be Black Lives Matter activists who are actually sitting in St. Petersburg, right?
And so a lot has changed in that. That is now an entire field of subfield of trust and safety is being invented right now at places like Google and Twitter and Facebook. And there are people whose entire job is to do that. And then the government has reacted as well.
And there are people inside the government side whose job it is to work on these issues. I think if you did a kind of a big look at 2016 as a society, we had this big blind spot because it was really nobody's job to be tracking the internet research agency and the other kinds of online propaganda outlets because it wasn't considered a traditional part of cybersecurity. Now, inside the NSA, and cyber command, there's people working on this. There's a foreign influence task force on the FBI.
There's people working on this at DHS and they're working with the folks in the company. So whether the precautions are great or not, at least this is now a field that people are focusing on. And that was not true at all this time three years ago. I mean, too, not to credit the Russians.
But it was pretty innovative technique. I don't think anybody saw it coming. They came up with it and they employed it at mass scale to what appears to be the effect that they desire. You gotta be careful ever saying nobody saw it coming.
The truth is for any bad thing that's happened on the internet, somebody called it. It's really easy to predict that something bad is gonna happen on the internet. When you're in a defensive role, you always have a finite amount of resources and there's an infinite space of possible badness. And so you do have to have some kind of evidence that something deserves you to put some finite resources on it.
And it's true that while the Russians, this is not the first time somebody invented this, this is by far the deepest use of this kind of propaganda in a international context. If we'd been paying more attention where we would have seen this in the Ukraine, right? So the truth is that the Russians, everything they did in the United States in 2016, they've done in Ukraine for a lot longer period of time. But I think even people who were paying attention saw that as something special, right?
That the Russians would treat a former Soviet state, their neighbors and that they would never use the same kind of techniques against the United States. And that just turned out to be an incorrect assumption that a lot of people made. So as you're thinking about looking at the internet now with the tools you're building in the observatory, as you're thinking about trust and safety in the 2020, the push from Facebook to become a more private platform, do you think it's gonna get harder or do you think it's gonna get easier? Yeah, it's a great question.
The move to a, for Facebook towards a more private platform, I think this really raises fascinating questions about what do we want out of social networks. So if Facebook and other social networks move towards small group messaging to less amplification, it will reduce the amount of spread you can get of propaganda and hate speech and such with a small number of people, right? So when you look at kind of the Russian model, they were looking for lots of amplification. You might have one or two people in St.
Petersburg running a persona, they would get hundreds of thousands of people to follow that persona over a multi-year period. And then if they had some truly hot, spicy thing that they wanted to post, their goal was to get millions of people to see it versus reshars, reshars, reshars. And so that kind of application becomes much less likely in a future where everything is much more like Snapchat or an Instagram story. The flip side is things become invisible to those who are watching for it, both on the outside, like us, but also to the people inside the companies.
And I think this is where this actually starts to become a hard problem. And kind of one of my bugaboos about kind of the media, especially the way they talk about tech companies, is there's a lot of kind of wanting it both ways without dealing with the fact that there's hard trade-offs here. And for a couple of years, everybody's been talking about privacy, right? The worst possible thing that's ever happened in history mankind is the Cambridge Analytica scandal.
And so if that's true, then you should love the fact that Facebook is encrypting everything and making everything private. But the truth is when you give privacy people, you also give privacy to bad guys. And so the turn about here about giving people privacy is it will greatly reduce the ability for the companies to police their own networks for bad activity and for people on the outside to spot it. So in the long run, that's good for the social networks, because they don't have to be responsible for things that people don't know are happening.
But the actual harm will contain to happen. And disinformation campaigns work great on end encryption. Like if you look at what's just happened in the Indian election, is that it turns out that both the BJP and the Congress party were running their own troll farms. But instead of getting one message seen by a million people, what they do is they get tens of thousands of people to forward the message to all their friends and family members.
And so you get just as much amplification, it just takes a little bit more work. And since it's all encrypted, it's very hard to study it. So I think for the most part that moved to privacy, there are good things. I'm pro-privacy, I'm pro-pro-end-end-encryption.
But let's not hide ourselves from the fact that this will be better for certain kinds of abuse. It's funny, just as we were talking today, last night into this morning, there was the Instagram copyright hoax that just flew over that network. And obviously, it takes that very low. It doesn't matter.
But you can't actually stop the people from posting that shit. Oh, Facebook absolutely could stop that from happening. They don't, because Facebook never uses its power to defend itself from things that criticize itself. Instagram completely has the ability to take that copy-post image to generate a perceptual hash into ban it from Instagram and Facebook.
But the company will not use that kind of power for something that is seen as criticizing them. Really? So it is an interesting thing that if that was a screenshot of the Christchurch Manifesto, it would not be spreading on Instagram like this. This is just an interesting issue in that the companies are always very careful to utilize power in a way that could be seen as doing so for proprietary purposes.
If actually, these companies were as evil as people thought, there'd be a lot more subtle manipulation of people's anti-tech and virg articles, for example, would be down-rains and stuff. But there's never any evidence that happening, because they actually never want to utilize the power and therefore attract all of the negative attention that we create. There are no anti-tech virg articles. We're just here to make it better, man.
We criticize out of love. No. I shouldn't use the virg as the evil. We use the New York Times as the organization that allows their distaste for the tech industry to override their critical thinking at some point.
This is a very rich vein of conversation. We're going to come back to that. But I want to just stick on that. The tech companies have a lot of power that is sort of on this close.
So this to me is the core of it. Can Facebook go into what's up and say we want you to stop sharing these memes that are obvious troll farms from the Congress Party and the BJP? So without breaking end encryption, there are some options. So this is actually an area that I've been working on a bit.
We're holding an event here at Stanford where we're going to have the major tech companies. So we've got Facebook, Microsoft, Google. Unfortunately, the fruit company hasn't been interested yet, but I'm going to keep on trying. We're going to have people from ACLEU EFF.
We're going to have Nick McThorren, so there's a child safety advocacy organizations. We have representatives from GCHQ and FBI, so we have government folks and we have a lot of academics. And the whole point of the conversation is that the entire end-to-end encryption conversation gets stuck on the backdoor conversation, right? That government's want to backdoor.
Companies don't want to give it to them. We don't have to have that argument. I'm anti-bacte-war. We'll just say that.
But you can spend hours and hours going around without any progress. And as a result, we don't talk about all the other options. And it is totally, there are possible ways that you can make some privacy trade-offs to push certain kinds of intelligence into the client that allow end-to-end encryption to happen, but then prevent people from doing certain things. So in theory, WhatsApp could regularly download a database of effectively a number of different kinds of compressed data structures that represent thousands of different known fake stories or rumors could do a matching on every single message that comes through.
And then without violating the privacy of the user, pop up some kind of counter messaging saying, hey, this looks like this is a disputed fact, or it's not true that these people harm these girls in the next village. Please don't afford this. And then do things like prevent forwarding that message. That would be a decision to reduce the freedom of the user, right?
Some people would call that breaking end-to-end. I think we've got to be careful in our language here. Situations in which you can reduce that freedom. But so far, the companies have been very careful not to use utilizer power to do that.
I think that's a discussion we have to have. Because I do think there are situations in which we should be providing people with privacy, but we should also blunt the damage that they can do through the incredible, the fact that now they have the ability to reach hundreds of millions, perhaps billions of people in an extremely private manner. There are downsides of that. And there are situations in which we might want to reduce the choice that people have of how they're going to use that.
That's a huge conversation, a huge debate. You're saying that you're focused on, before you ever get to send the bits off your phone, the client locally should be doing some screening of, hey, we know this is fake news. We know the pope didn't endorse Donald Trump. Why are you sending this off?
Yeah, so I'm not endorsing that exact solution. What I'm saying is that there are options both for the people receiving information and people sending information to have intelligence in the client. An easier example is there's a bunch of forms of abuse for which the victim of the abuse is part of the conversation. So let's say unwanted pictures of male genitalia is something that dominates every messaging product.
If you're a woman and people can reach out to you in an anonymous fashion, you will be sent to these images. There's no reason why you can't push the same AI Facebook currently uses on its servers to look at an image and say, this looks like male genitalia based on this machine or any models, or a reason why you can't push it into a client and have effectively clippy pop up and say, hey, somebody sending you images that are sensitive, I've blurred them out. Do you know this person? If you don't want to receive these images, you can report it now and then you could break the security of that encryption by them turning over the encryption key for that specific conversation and then allow the company to take care of it.
So I think there are a bunch of different forms of abuse where you can reduce the impact via more intelligence in the client through smooth out reporting structures through interesting crypto stuff that allows you to report specific conversations, but not all of them. But in the long run, it means the company's asking, acting in a more paternal way than they traditionally have. And I think this is where the company's about themselves in a corner here because they don't talk about all the things they do right now. And the truth is that as bad as the internet is right now, as bad as it is for women and for children and for people who don't like getting abused by Nazis online and don't like in hate speech and don't like getting images they didn't ask for, the companies are doing a huge amount of what is semi-creepy stuff with machine learning, with image recognition and such, to police their networks right now, and most of that goes away in an end and encrypted future.
And so the fact that the companies don't talk about it means that the baseline of the conversation is actually pretty bizarrely twisted. And that makes it hard to have an intelligent conversation about what should happen next. I mean, do you think Facebook is moving to the end and encrypted privacy? We're going to merge the back ends of the three services purely cynically or is that a good business decision or is it just we're going to evade the Department of Justice and a trust division?
First off, Facebook never makes a product decision without hard data backing it up. Nobody is sitting on more good data about what people want to do online than Mark Zuckerberg. He has instrumentation from Facebook, from Instagram, from WhatsApp. And so clearly there are things showing that the features of Facebook's existing social networks that protect privacy, that are small group, that are ephemeral, are more popular.
So I'm sure that is absolutely the number one goal is to, you know, Zuck has always been really, really good at seeing where the puck is going and skating there. And so I'm sure that that is the biggest one. But I do think that there is probably a cynical component to the encryption in that, effectively, the companies are being held to two standards that I can't live to, right? One is we want you to provide privacy and not know anything about these users.
And the other is we want to keep people, you to keep people completely safe. You can't have both those things, right? Like in the same week that you're a time for both criticize Facebook for not finding every bad guy. And then criticize Facebook for having too much data on people.
When you give people privacy, again, you give privacy to bad guys too. And so historically, what Facebook has done is to try to like have this kind of, if you're on a one to 10 scale, but in like the four to six range of like, let's be in intermediate on some of this stuff. And that's not working because that opens you up to be able to criticize you from the one or the 10. And so Zuckerberg is just choosing to slam all the dials over to one side.
We're going to encrypt everything. We're going to throw away all this data. Everything's a femoral. And so he is maximizing privacy with, but also then reducing the ability to do safety and especially content moderation.
I think the other reason is that Facebook has demonstrated that there is a trap you can never get out of, which is once you start moderating people's content, there is no logical end to what people ask you to what speech by other people, you will be asked to control, right? And so I think that there is no real reason to be able to do that. And so I think that's a real reason that Facebook has been to the bottom of the stuff, which is once you start moderating people's content, there is no logical end to what people ask you to what speech by other people, you will be asked to control, right? And so if you're on this slope and you're trying to deal with 97 different legal regimes for speech, then probably the only way out is to put yourself in a situation where you can do the minimal amount of content moderation.
And I think that's part of it too. The whole DOJ thing, I find that kind of silly. Like if that is Facebook's goal, that tiny things together stops anti-trust action, that's really stupid. Like the Department of Justice broke up AT&T, right?
Like the most complicated thing ever built by man at the time was the phone network. And the Department of Justice broke up AT&T probably actually caused all kinds of problems and reduced the amount of innovation that you can see out of the baby bells, but whatever. Oh, I totally disagree with you. On that point, specifically, I totally disagree with you.
Okay. Well, I've heard both things on the AT&T breakup, right? That like Bell Labs loose into like that. We lost a lot out of having it.
And then also, you know, the phone network still uses like SS7, which is the signaling system that was built by AT&T pre-breakup. Like it's the fact that everything has to go through like a standards body now in the GSM form and all that kind of stuff, maybe reduces the speed at which those companies moved. But you know, the benefit of that is that that opened the door for the internet companies. So I'm sure you can see both ways.
But whatever happened, AT&T, it's like, obviously, D.O.J. and look at AT&T and be like, it's too hard to break this up. So like, I think that's a silly calculation for Facebook to make. I don't know if you had to lost an AT&T thing because I love thinking about it, which is dangerous for podcast hosts to be like, we're going to talk about this one lucky thing from a hundred years ago that I love, but I think that DOJ was obviously at that moment much more motivated to do the thing than R.D.O.J.
is even though it seems like the drums are rising in volume, then they are to go after Facebook, right? And I think you see that over again. They try and they bounce off and they try again and they bounce off. And I think Zuckerberg is equals the services together.
It creates more of a bull work against it. Maybe. Well, so you're assuming that D.O.J. actually wants to do an action.
People in the media are all of a sudden much less cynical about the Trump administration when it comes to the Trump administration's investigations of tech companies, right? So a truly cynical read is that the President of the United States controls the Department of Justice, controls the FTC, controls the SEC, right? Control has a huge amount of power to make your life hell if you're the executive of a Fortune 500 company. And so if you are the Trump administration and you do not want Facebook and Twitter and other people enforcing their content moderation policies, if that means shutting down your supporters, then a great thing to be doing in 2019 is to be flexing your muscles and to be threatening as many investigations as possible to demonstrate that you have the ability to make Facebook and Twitter's life hell in a way that the quote-unquote liberal media will totally apply.
And so I think there's an interesting question here of how much actual anti-trust interest there is and how much there is of the Josh Hawley kind of, I'm going to make you a little bit afraid so that every time you make a difficult decision that might have a disparate impact on somebody on the right wing, you think twice about it. Yeah, and that Josh Hawley proposal is like the FTC will become the speech police. I mean, that's an outlandish proposal in terms of its scope. It's the most ridiculous thing I've seen.
It's like they should take away his Yale JD for example, something like that. Yeah, I mean, I mean, I'm a career s harbor lawyer, like maybe should be the statute, right? Like it seems like confusing and I agree with you. It's designed to chill content moderation decisions.
So I think putting it together, you just described it in a way that I don't think I've heard crystallized before. We obviously cover content moderation a lot, casey and covers like the lives of moderators. I've suggested to him that one of the defining questions of tech in this moment is what goes on the internet, like what belongs on the internet. He suggested me that there's like a sub question of like many other things.
So it's a little bit strange, but I think it's one of the most important questions of like our time in tech. And I don't think I've ever heard anybody crystallize it as, hey, I can turn all the dials to 10 and actually take this responsibility away from myself. I can devolve this responsibility if I just say everything's private. I know I'm going to have the opportunity to moderate.
Do you just see that Facebook? Do you see that elsewhere? I think you'll see it elsewhere. I mean, Facebook is on the cutting edge of dealing with these issues.
There's about 80% of the things that people write about Facebook. They're really writing about the entire sector, but Facebook happens to be the biggest. And so therefore is the first one dealing with it, right? But if it works for Facebook, then you're going to see other people follow for sure.
This is really about like, actually, if this is what case is ideas, I do see the content moderation as a sub issue. Like the big picture issue is as a society, we have not decided about a how safe should people be kept online and how much we want to control their choices to keep them safe, for what definition of safe you have, and be who does that, right? Like one of my colleagues here is Stanford, Stephanie Keller, and likes to talk about how a lot of people have an irrational exuberance for speech control that they never had in the pre-tech era, right? That we have hundreds of years of people trying to figure out what is legitimate political speech, what is hate speech, what are you allowed to say, and that what the internet and private regulation has done has allowed people to advocate for speech controls that would never have been considered acceptable for the last couple hundred years.
And so all of this built up interest in controlling the speech of others is coming out all at once, right? But that is a sub issue of like, how safe are we going to make the internet, right? Like, is it going to be a rubber room that you can't hurt yourself in? And then if so, are the rules going to be made in a democratic manner, or are they going to be made by private actors?
And so what's interesting to you about that is the government really can't make any of those rules. I mean, the first amendment exists. The American government can't, right? The American government can't.
And that's why most of the action on speech regulation is happening elsewhere. Effectively, every non-US anglophone country is currently considering some kind of ridiculous online speech control, right? The Australians move first, as is their want, but there's this kind of nutty paper by DCMS in the UK, which only talks about the downsides of online speech and never talks about the upsides or the civil liberties issues. But clearly, it's pointing in a direction that other countries are going to move more aggressively.
And so when you think about any decision Facebook's making, you actually can't think about the United States, right? Something like, I think it's less than 5% of Facebook users are Americans. You've got to consider the international ramifications first. And I expect that the giving people privacy and the flip side being less speech moderation is specifically targeted at a number of countries.
Because if you think globally, what is passing? Is it laws that say that more content moderation should happen? For the most part, no. What's happening is we see pro-privacy laws like GDPR passing.
So if you put all, there is a trade-off here between privacy and safety. And if you put all of the legal weight on one side of this equity, then the companies are eventually going to respond. And I think that's part of what's going on here, too. So we're having conversation that is complicated, right?
There's all this set of trade-offs. There is multiple legal regimes around the world that are potentially in conflict around what's allowed in the platforms. There is building this stuff, which is hard. Then there's the threat models which are increasingly sophisticated.
You tweeted a couple of days ago, one of the reasons we're putting together a Trust in Safety Engineering course for Undergrads at Stanford is that every product of the social user-generated content feature now needs a full-fledged trust and safety team. That's a lot of startups need specialists now. So I'm curious, I want to hear about that course. What does it look like?
And two, should this just get pulled out of the companies? If I'm a person and I want to start a photo sharing startup to compete with Instagram because I think the market needs more competition and that's what I'm going to do, is there a world in which Instagram spins out its trust and safety team and that becomes a resource like AWS is a resource? Do you see that as a potential solution here? Because otherwise it seems like no startup has a chance.
Yeah, so to work on the definitional issues a bit, so effectively what I learned at Yahoo is that if my goal was to maximize my positive impact on people, then I had wasted most of my career in that the vast majority of bad things happening to people online have nothing to do with all the sexy security issues that people like me love to study and work on. It's not about ODA, it's not even about malware or passive resets. The most harm that happens online is what we term abuse, which is the technically correct use of these products to cause harm. The people who deal with abuse at most companies is generally called like a trust and safety team at Facebook, they now call it integrity, but nevertheless it's a different field than traditional information security.
And one of the things we're trying to address here at Stanford is you can't learn anything about this entire field of software engineering except by going to one of these big companies and becoming an apprentice on a team. So if you want to become the world's best expert in online fraud, you go and you work at PayPal and you go work on their trust and safety team for several years. But you can't, none of that makes it back in academia. So we're building a course to do that.
I have 18 people from a number of companies, so we have Google, Microsoft, Facebook, people from Nick, Nick, and Thorn. I have some law enforcement people. I have a bunch of folks who are helping create this content and then the goal is to open source it. So a number of universities teach it, but we're going to talk about content moderation.
We're talking about hate speech. We're talking about bullying and abuse, non-consensual imagery, which is effectively revenge porn and dick picks. We're going to talk about child sexual exploitation, human trafficking, suicide and self-harm. It's a real uplifting class.
I'm looking forward to people, like my professors is a little pepper for the hot professor. I'm expecting to get the little sad face. Super depressing class. But the truth is, we've got to graduate students who understand that when you allow people to communicate online, when you create situations where images can be uploaded or any kind of interaction can happen, there are risks that are created by that and it's not acceptable in 2019 to start a company and then to be shocked that this kind of stuff happens.
So your second question, I think you're totally right. One of my overall thesis is that on truth and safety issues where we were on information security in the late 90s or early 2000s, which is in the late 90s, nobody knew how to write secure software. Nobody knew how to build security into a software development cycle, and Microsoft got all this criticism, not as the only people who built that software, but as the biggest. And they reacted by building out what has become the ways that people do product and application security now across the entire industry.
We effectively need the same revolution in trust and safety, and coming with that is not just that companies changing. It means academia reacting. It means having a mind share change of what people study and learn. And then also the creation of industry.
So in the late 90s, if you want to build secure software, there's effectively nobody you can hire to help you with that. If you have a Nazi problem today, like say you start a company and all of a sudden the Nazi takeover, so a great example of this is Discord. Discord starts as a chat for gamers and very quickly ends up with this white supremacist radical underbelly that they were not expecting to have. If you have that kind of problem, there are very few people you can call to come help you with your Nazi problem or your child safety problem or your suicide problem.
And so I think you're right that this is actually going to become an entire industry, including managed services, including cloud services, that you can't expect that every company builds all these things from scratch. And maybe that becomes actually a business line for a Facebook or an Instagram is that just like Amazon turned their experience scaling infrastructure in AWS, you could see Facebook turning their experience scaling trust and safety into an actual service they provide to all the smaller companies who can't afford to hire thousands of people themselves. So that leads to a really interesting question about size and scale, right? If Facebook is the biggest and it's hard to compete with them, who would they sell to?
There's like a trade-off here. Are we just going to have a few giant incumbents and we push them and they sort of compete on their own trust and safety metrics? Or is there going to be a wide ecosystem of companies and there are service layers that they need to become their own economies and their own ecosystems? I would love, we run a commenting platform around chorus, right?
We have our own social channels across different platforms. I would love to hire a company to come in and make sure our communities across our platforms, our own and operated in our world, are healthy. But we are not big enough market to support two or three independent companies doing that. How do you see that market developing?
Well, I think it is a lot like the cloud computing market. And that 15 years ago, if you said that even decent sized companies, it was not economical for them to build and run their own data centers, you said that's crazy, right? But that's where we are right now. That unless you are humongous, it makes very little sense for you to have your own data center operations and perhaps even kind of your server operations.
There is an interesting question here. This actually comes back to the anti-trend question, right? Because there's a number of arguments around if you break up Facebook, then the safety issues become impossible to solve. I think that's a poor argument.
I mean, it's true in the short term that the Instagram Trust and Safety Team, like the Instagram anti abuse team, is the Facebook team, right? So yes, if you broke up a Facebook over a three month period, you would have lots of problems that you couldn't backstaff. But a company of Instagram size, standing alone, should have the ability to run trust and safety. And kind of where we need to work on is the cutoff here, I think, is Twitter, right?
Like all of the companies have some kind of user-generated content. Twitter is the smallest one that is at least holding their own. They don't do everything great. But a lot of that is actually intentional or product decisions.
But they do have people that work on things like Russian disinformation, right? Below Twitter, it is a wasteland, right? Like the smaller organizations than that, like the Reddit and such. It's not their fault, but it's very difficult for them to have a capability that is scaled enough and that can touch all of the different areas of abuse well enough to run a full fledged user-generated content site.
And so I think there are, I mean, we don't think about it, but as much as people talk about Facebook and Twitter, there's this huge long tail of user-generated content, right? Of all of these different sites, all of these different discussion forums. Most of which are doing nothing in this area. And so we don't think about the possible impact.
I think that's actually one thing we're interested in trying to study in our new projects at Stanford is the impact of that long tail on disinformation operations. Especially when you look at the United States, you'll find that lots of countries have one or two products that we've never heard of in the United States that are actually quite important within that area. And so as a result, almost by definition, they don't have people who are prepared for these kinds of issues. And so I think in some of these specific areas, it's a really big deal.
But anyway, I do think it's going to develop. I think as the expectations rise about, you know, I think what Facebook is trying to do is trying to turn this into a competitive advantage, right? Of like, they're going to do all of this work on different kinds of abuse and then try to get the legal bar to be set right below wherever they are at that moment. And then hopefully for them, that bar is higher than what anybody else can do.
So if we end up with laws that actually, you know, dilute CD-A 230 or in other countries create some kinds of liability for caring content, then I think you could see a growth industry in this. I think one of the places to look is where this is first started is Germany, that Google and Facebook were able to adopt to NetstG pretty quickly, and there's a number of other companies that have had more struggles. That's a lot that prevents hate speech online, right? Yeah, exactly.
So that's like basically a German law saying that you have to enforce a German hate speech law, or you are liable, and that has been a real challenge for smaller companies. In my understanding is that they're having a couple of very specialized companies that have popped up to specifically help with enforcement in Germany. The question is if you have enough laws globally, then maybe this becomes a global enterprise that you can run. Hey, I'm AppiShel, comedian, writer, and floating head.
You may or may not have seen on your 4U page, and I'm starting a brand new podcast. Wait, wait, don't swipe away. It's called, That Sounds Like A Lot. As in, that feeling when you check your phone in the morning, you read three headlines and you immediately think, oh, that sounds like a lot.
I can't deal with all this, but guess what? I can deal with it, and I'm going to get into it every Friday. I'll break down whatever chaos is happening in the world, then I'll sit down with a comedian. You can be progressive and not be like fucking annoying.
Maybe an actor. They've got communism in zone too far. You go, why? Does the Sadie Hawkins dance happen?
Maybe a filmmaker. Since leaving that show, I'm challenged sparingly. I just got to hang out and try to do so. You're the one with a charmed line.
Could be a politician, basically anyone who responds to my cold DMs. We're recording the whole thing in a beautiful studio, so yes, you can watch it on YouTube, or you can listen wherever you get your podcast. This is not the place to get the news, but it is the place to feel a little better about it. That sounds like a lot part of the Vox Media Podcast Network.
This week on Network In Shell, I'm joined by Tang Sinatra, the meme king with over 50 million followers across Tang's good news, influencers in the wild, and his personal account. Tang is breaking down what the meme economy really is, how much a single sponsored post pays, why major brands are throwing serious money at jokes, and how meme culture, think preparation age, starter packs, and a perfectly timed screenshot is actually reshaping how we think about money and value. Get ready for a conversation that'll change the way you scroll, make you rethink what's going viral is really worth, and prove that sometimes the most serious money moves are wrapped in the silliest of jokes. Listen, wherever you get your podcasts or watch YouTube.com slash your rich BFF.
So I think we have a lot of listener and product managers who build things who start companies. Where should trust and safety live in their product film and cycle? Because I also know a lot of trust and safety people who, as you've said, they can see the problems come in my way. They just can't get in there early enough to stymie them.
So should every product manager think of themselves as a trust and safety person, should be built into the competition of a team, like it should be more diffuse than a single department? Yeah, I think where I think we're going to end up with both kind of core cybersecurity teams and then the broader trust and safety is that you will continue to have centralized teams, but that those centralized teams will be consultants, service providers, and auditors, and will not be the owners of risk. So I think at a company, a smaller company that only has one product, then trust and safety is probably part of the product organization with a offsuit over whatever customer operations team that you have to handle operational tasks. Running a team that has engineers, investigators, with people who work the midnight shift, it's actually organizationally, it's difficult to work those kinds of things in the same org chart.
So often what you have is trust and safety teams are actually split where you have engineering and product investigations as one part, and then the day to day operations is part of a larger operational team who's being managed to SLAs of effectively like a call center of the stuff that Casey writes about. So I think that's reasonable for a company that has one product. So multiple products, and I think what we'll end up having is what we probably should have in security, which is you have a central security team whose job it is to help all of the product owners judge and manage risk, but not to make the risk management decisions themselves. Like one of the problems that we've had in Silicon Valley to this point is that the SVPs and VPs who own lines of product are measured on growth.
They're measured on money. They're measured on the success of the product. They are never measured on whether or not they generated a huge amount of risk for this. And that's got to change.
And the place we can look for this, changing is the banks, right? Post 2008 crisis, the financial services industry has really reorganized its risk management. They have risk officers, but they also have all kinds of controls in place to push risk management out to the owners of different lines of business. So you can't go to Jamie Diamond and say, my division of JPMC just made $10 billion, but it's all fraudulent accounting, but I still want my bonus, right?
Like that kind of thing is not acceptable when it comes to financial risk, and we need to get the same place on kind of the general tech risk of cybersecurity plus trust and safety risk. And so that works with a big company, but if you're starting a new company, what's the proposal you have in your class on trust and safety? How do you teach a student or a startup founder to think about that risk from the jump? So part of the goal of the class is most companies, just like they don't have a CISO, most startups, they're not going to have a dedicated trust and safety resource, and that's probably fine.
What you really need is you need the people in product and engineering to understand the classes of issues that have been seen in the past so that they themselves are responsible for considering it, right? So I'm not going to argue that if you're an eight person startup that you should then, your ninth person should be a TNS engineer. What would be great is if the engineers you have already have a bit of a background, so when they're like, somebody proposes, okay, I have an idea, let's take anonymous photos and then encrypt them and send them to women without them knowing where it came from. They have in their mind, I know the kinds of things that can go wrong in that kind of scheme.
In the long run, when it's time to hire the first person, I think they absolutely have to be part of product, right? Because when it comes, this is true for security overall, but especially when it comes to trust and safety, what you end up happening is that big product decisions about how the product works is what accumulates 99% of the risk in that initial huge decision, right? So you're effectively filling up a orange home depot bucket full of risk, and then you give your trust and safety people a little spoon to go try to spoon out that risk before something happens, right? And that doesn't work.
So when the clock decision is made for hyper growth or some kind of growth hacking or because people want it, then the part of that initial decision needs to be able to have potential downside here, and we need to prepare for that downside. That doesn't mean you don't take the decision, but it means if you're looking for the downside, then you're much more quick to respond. That's the only thing about trust and safety is it's a lot harder thing to predict than traditional cybersecurity, right? We're moving towards a steady state where if somebody is building a mobile app that does this in that and it's up at AWS, you can hire a consultant to list out for you the top 12 potential things that are going to go wrong from security perspective, but the trust and safety issues are incredibly specific to exactly how the product works, and then also specific to who's using it, what society they're in, cultural issues, language issues, legal issues, and so it's a harder thing to predict.
So as a result, more of your effort is going to be on detection and response than it is on prevention. That's an okay thing, but you then have to, just because you can't predict that a risk is going to happen doesn't mean that you should not be staffed up to be ready if something bad happens. I think that's part of the thing for starters as well, as they get caught behind the ball of the first time something bad happens, they're not finding themselves, they're reading about it on the verge or in the near times or the Wall Street Journal, and if you're reading about it in the papers, the first time you knew you haven't trusted safety problem, then you're already in deep deep. Do-do.
Sorry. I don't know. Does this have an explicit label? No, we are still protected by CD8, CD3, we can do whatever we want in the platforms.
For now, until Josh Holley comes around. So those are little companies. I want to talk about big companies. You mentioned Twitter, they're like struggling along.
I just want you to evaluate. You have a position outside your working with companies. Hey, how are I want to know for a list of companies? How are they doing now?
Where do they stand and how prepared are they for the upcoming election? So let's start with Twitter. How are they doing? How prepared do you think they are for 2020?
So Twitter has a significant issue in that early product design decision was to allow pseudonymous accounts and allow people to have multiple pseudonymous accounts, right? So the policy framework under which Facebook enforces a lot of things that are related to elections is around authenticity. What does it mean to be a fake account on Twitter is really confusing. I actually gave a talk at Twitter, right?
I basically said, like, I'm an expert in this area. This is all I do. With the Twitter blue check mark means, right? So Sarah, John, who I know both of us know, right, has a blue check mark will change her name to a literal side duck.
We'll have a picture of a side duck keeps the blue check mark. What does that mean then, the check mark mean in a situation where once you're blessed, you have the ability to pretend to be whoever you want to be, and in what situations do they pull that back. So I think Twitter has some basic product design decisions that they still have not dealt with of what does authenticity mean and how are we going to signal to people? I think they have people who are working really hard on this, my experience at Facebook is that they had a team that was very open.
I have to give Twitter credit. Out of the three major companies, they are the only one who is dumping out the stuff they find. So this last week, both Facebook and Twitter, I think this last week is very indicative, right? Facebook and Twitter announced simultaneously that they were taking down a bunch of Chinese propaganda accounts.
They both gave examples and talked about it. Twitter also releases the files of all of the content, right? Facebook did not. And I think the core of this is Facebook over-legalizes this decision.
It is technically very hard around privacy laws, around FTC content-degree, GPR, ECWA, SCA. These things make it hard to dump out content that has been deleted. But I think Facebook over-legalizes it, and Twitter's decision is like, well, maybe it's legal, maybe it's not. If the Chinese want to sue us, they can go ahead.
And so they dump it out and they make the decision, which is the right decision, which is to share this content for external research. Facebook, did the announcement, did the right thing, did not release the data. Google said nothing, and has done nothing, right? And the big difference between those companies is Twitter and Facebook have no future in China.
They have both effectively given up on the Chinese market. Google's trying very, very hard to make a lot of money in China, and they have done nothing to blunt the propaganda campaign, and they have said nothing about PRC activity on YouTube. And so I think that's a microcosm of where the companies are, right? Facebook has the most resources behind this.
They are significantly larger than Twitter. I think Facebook has added more content moderators in the last year than all of Twitter's employees and contractors. So just from an amount of money spend, Facebook continues to do that. I think Facebook also just has the biggest challenge of having the biggest network and also having these three different products that have very different kind of propaganda models, right?
WhatsApp is very different than Instagram is very different than the big blue at Facebook.com. I think Google's probably done the least. And it's unfortunate, because I think Google had this opportunity to see what was happening to Facebook, starting in 2017, and to cut the corner on a bunch of these problems on YouTube. And instead, they kind of just kept their heads down.
So they have always been the least honest and open about what's going on. They will quietly clean up problems without coming out and publicly discussing them. And that has generally worked, right? Like the amount of criticism they've gone on these issues is much less than Facebook.
But I think what that has created is a backswell of criticism and the deluge will come because they have not been honest about all the things they've been doing and they haven't been as aggressive. It seems like the deluge is starting to build already. It doesn't seem that was an excellent answer to ask about. So Twitter, it seems like they're doing what they can.
They're doing well. It's specific to how do you think they're doing for 2020? I think they're doing OK. Again, the actions of these companies only affects one of those four different kinds of Russian interference.
So even if you completely eliminated all online trolling activity, we should not consider 2020 a done deal. So I just want to say that. I think Twitter's doing OK. They've cleaned things up a lot.
They've gone a lot of fake accounts. So they have a fundamental product weakness that will always leave them open that doesn't exist at Facebook. And that is a problem. And they just have staffing issues as well.
But I have to give them credit for being the most open company on data. I think they've done the right thing there. They've made it easiest for people to find and spot bad stuff on Twitter. And so that helps offset the fact that they have the least resources.
So let's go to Google. Google constantly in the news. President is attacking Google for basically bad study. And they have the two different service areas.
They have obviously the search results page and I have YouTube. What's specific is not about YouTube. How is YouTube doing? It is very unclear what YouTube is doing around disinformation.
They are acting the way Facebook acted a couple years ago. So when I was at Facebook, one of the things that really frustrated me is the company would make content moderation decisions completely knee jerk based upon the immediate press feedback. And that reduces the pain in the short term and greatly increases the pain in the long term. Because they are doing what Facebook used to do, which is signal that if you yell at us enough, we will make decisions in your favor.
And Facebook is trying to grow outside of that through more documentation of these policies of why these decisions have been made of creating kind of an external process for adjudication of the really hard decisions. Where YouTube, if you look back just a couple of months ago, took down a video, untooked down it, demonetized a guy, all of this within 48 hours without any actual intellectual scaffolding. It was clear just based upon how much feedback they're getting internally and externally, they made snap decisions. And so I think YouTube is probably the worst place because they have done the least kind of intellectual work and what it is that they want to do and what kind of information environment they want to provide.
The other challenge YouTube has is unlike Facebook or Twitter, the number one determinant, while both of those companies have algorithmic ranking of news feeds, the number one determinant of what shows up in your news feed of Twitter and Facebook is who your friends are. The number one determinant of what you see on YouTube is the algorithm itself. YouTube, while a social network is not really powered by who your following your friends are, it's based upon the recommendation engine. And so that makes them uniquely more responsible for what people are doing, I think, more than a Twitter or Facebook or any other social network that is powered by who your social graph is.
And they have not responded that great to that as we've all seen. It is still possible to start with Jordan Peterson videos and then to end up with semi-white supremacist videos that send you to GAB where you can get more highly radicalized. That is still a progression that you can do on YouTube. One thing I think is important is close.
You described a video that was up and down and demonetized. That was all around the guy who works at Vox Media College. I feel like it's important for me to disclose that was our company. We were right in the middle of it, but I agree with you.
It seemed like YouTube is making a lot of snap decisions on Twitter, which is a weird place to make big policy swings. I guess the question I have about the algorithm that you pointed out very directly is, when you describe YouTube as an information environment, that's not how any consumer sees YouTube, right? Is there a level of this where the consumer needs to get smarter about how the information environments are being presented to them or being created? Because that is very opaque for anybody who opens up one of these apps right now.
It's opaque for Netflix creators, right? Like Netflix showrunners are mad that Netflix did promote their show in the algorithm right now. And they're presumably at a much higher level of interaction and discourse with their service for other Netflix. Can we change that so that the consumer has got more power back in these moments?
Yeah, so I think the underlying thing is that the solution to these problems is going to be with individuals no matter what, right? Like, no matter what the companies do, we have gone through a revolution in the structure of the information we consume that has undone the centralization that we saw in the 20th century, right? So we have for the most of human history, the only people you can speak to are the people you are physically speaking to, right? And then you have the written word, something that, for much of your European history is controlled by one organization, the Catholic Church, which is the keeper of the history, of the things that get me copied, and a classics professor that talked about everything we know about the ancient Greeks and Romans, we should see as being filtered through the Middle Ages and what was burned or left to rot versus what was copied.
And so we have this humongous information filter, and then you have the printing press, which greatly democratizes not to everybody, but a lot of people having a lot more voice and being able to amplify their voice out to thousands. And then the 20th century you have radio and television, which give you huge implication, but also massive consolidation, right? Like only a television station was something that you can only do if you're a massive corporation. And we've just gone very, very quickly, much more quickly than those other shifts, from mass centralization to mass decentralization, that you can have just as much amplification as a television station had 30 years ago, except that can belong to one person.
Our society survived all those shifts. Every single one of them had people saying, kids these days with their new thing or whatever are destroying society, right? Like we've gone through these moral panics during every information shift, so it is natural for us to again have a moral panic about the use of the internet for communication. And this doesn't mean the company shouldn't do anything, I think they have a responsibility to help get us through this shift, but in the end, it's going to be up to individuals, right?
Like we're not going to actually end up with an internet, that is a rubber room, that all the information that you're fed is safe and trustworthy and is appropriate for you. We're always going to have, we're never going back to a world where Walter Cronkite controls the conversation again. We're never going back to a world where 30 middle-aged white men decide what is newsworthy in the United States. And it's because of the breaking of that oligopoly that you have Black Lives Matter, that you have the Me Too movement, that you have a lot of positive things because it is not a small set of non-diverse people who are deciding what is newsworthy, but the flip side is you also have Gab and H.ann and white supremacists and other people who can utilize it.
And I think no matter what, as a society, individuals are going to have to adapt that news environment. The good news in the United States is that there is some academic research that demonstrates that the especially kind of the fake news problem is mostly a baby boomer problem, right? It is a problem of people who grew up in the Walter Cronkite era who are having difficulty adjusting to the Fox News slash Facebook era. And so there is quantitative data showing that and then Brett and Nyan has done some work on this at the University of Michigan.
That is not true globally though. There are some other places where young people are just as vulnerable to spreading this kind of stuff. So it is not a societal shift that will happen evenly. But the fact that young people are less likely to share fake news or less likely to spread rumors or less likely to have Instagram posts saying, I declare by the Treaty of Rome that all my information is copyrighted, like our Secretary of Energy, the demand and charge of our nuclear stockpile posted that.
The fact that young people don't do that as much, I think is a good sign that societal shift that needs to happen hopefully will happen. The question is, is like, will we shepherd the next 20 years or so to get through this safely? This all comes back to one of the first things we talked about which is how much of a conversation are we having that's open and honest about the responsibilities of these companies to make the internet a safe place. And in particular the United States, the government just can't do it.
Like it is prevented from regulating speech on the internet in this way. So it has to fall, I mean I look at every proposal to modify 230 as like a backdoor around the first amendment. Like we're gonna hold this gun to your head of your company will go to business and we take this law away unless you do some shit we like. And fine, I mean that's the way to do things.
It's maybe the only way to do things. But it seems like the companies have to make big set of decisions around how much of a rubber room they wanna be and they haven't really been transparent about those decisions yet. They absolutely have not been transparent. This is one of the big problems, right?
Is that Facebook, Google, Twitter, these companies are quasi governments. They have powers that we generally reserve for democratically accountable elected positions. But they don't act with the accountability, they don't act with the transparency. So if they're going to make these decisions, which like you said, they're pretty much forced to in the United States, right?
You know, Facebook can not punt to the US government. Please make a decision on what is appropriate speech in the political realm. Then if they're gonna make these decisions, they have to do so in a much more transparent manner and they have to be predictable. That's one of the crazy things like when I say that YouTube is going back and forth on their decisions.
One of the real problems that creates for them and then creates for their users is that any individual YouTube creator cannot predict if what they do is gonna be bad or not, right? Like if you run a stop sign, if you get caught, you know that that is not gonna be considered an okay thing, right? No, seriously, like if you kill somebody, it is understood that that is a crime. Like there are obviously gray areas of all kinds of crimes, but for the most part we live in a rule-based society where any individual can predict whether or not the action they're taking is legal or not.
But that is completely and totally impossible on any of these platforms. And so they have to be transparent enough in their enforcement decisions so that any individual can make a video, can write a post, can do something and then know themselves whether or not they're pushing the line or not. Because if the line continuously moves, then it means nobody has respect for the companies and there'll be no respect for the process. And it's respect for the process that allows a legal system to operate, right?
If you believe that every once in a while, the courts will go your way, but sometimes they'll go for you and against you, then you're willing to be part of the process. If you believe that every single decision is completely arbitrary, then you can do everything you can to argue against those decisions to put pressure on the organizations. And it's just like a bad way to operate. The other thing I'd love to see from the companies, I'd love to see a way for all of these content moderation decisions to be reviewable externally, right?
So something like a database of, here's all the tweets that have been taken down from Twitter. Now, it would have to be accessible under NDA. There's all kinds of, again, GDPR, FTC. There's all kinds of privacy law issues.
But again, without the ability for external groups to see what decisions are being made, it's impossible to have any kind of pushback and to have any real scholarship. And so that's something that I'd love to see the companies move towards probably in a unified manner, right? If there's like one database of your all the content moderation decisions made by these folks over the last 30 days available under NDA, you can write about the decisions, but not de-anonymize people, maybe do some differential privacy stuff. I think that would be an incredible step towards establishing some trust that the companies are, if they're going to operate the government so they have some of the trappings of a real legal system.
How does that mesh with Facebook's Supreme Court of content moderation proposal, which to me seems, when you talk about these companies in governments, that's how you know that they think they're governments, right? They're studying a legal system. Do you think that's compatible with that? Or think about it with that.
It is, I mean, just like the US Supreme Court does not sit on traffic court, like the Supreme Court decides very difficult decisions that bubble all the way up. That is how this Facebook Supreme Court, which they never use that term, as you can tell I'm no longer a Facebook and that I'm willing to sit your frame in. But it's the right framing, right? The Facebook Supreme Court is going to be for the really tough ones, right?
The truth is, Facebook makes more content moderation decisions in one hour than the entire federal court system makes it a year, right? So you clearly can't have real due process for every single content moderation decision. What you can have is an ability for the tough corner cases of deciding, huh, does Alex Jones violate these three rules? That that kind of decision that will end up being a precedent that will have massive impact on the rest of the network, that that kind of thing can go to that Supreme Court and be decided in a much more open fashion.
And then the precedent that's created will be continued to be enforced mostly by robots and then with the help of the kind of content moderators that the verges we're not about. So this is my last question. I'm asking how the companies are doing. And then I have a real spicy one from Casey.
He gave it to me because he said, quote, He doesn't get to ask you if I'm not going to show up. He doesn't get to send a question. I will say the note on this question is, and I quote, he will go off. So I got to do it.
It's true. So what is that? I was facing doing how prepared are they for the election? So I think Facebook's pretty well prepared for what happened in 2016, right?
It has the broadest set of advertising transfer. So unlike Google, Facebook considers issue ads to be political ads. I think that's a really important set because under our assessment at Facebook during our investigation, something like 80 some percent of the Russian ads that they ran were not illegal actually takes a much broader definition of what is a disallowable political ad than Google does. I think Facebook has the largest team.
I think the hardest thing for Facebook is going to be to try to predict how the non-Facebook products are going to be used, right? So Instagram has some of the same problems Twitter has and that you can have a pseudo-anonymous identity on Instagram. The fact that Instagram is mostly images gives some benefit, but not a ton. As you know, the Russians did lots of the Russian troll factories have professional meme farms.
Like they have graphic designers using Illustrator all day to create memes. So Instagram ready is actually a big question. I'm guessing Instagram is well behind what's happened on Facebook.com. And then the use of WhatsApp, number one source of disinformation in Southeast Asia, will WhatsApp with its end encryption be used in the same way in the United States.
It seems unlikely in 2020, but after 2020, as people move to those platforms, I think that'll become an issue. Do you see that problem on iMessage, right? Like WhatsApp isn't used as probably United States. Apple does have an end-to-end, very popular messaging service on iMessage.
Do they have a disinformation problem in iMessage? Is it even possible to know? It's impossible to know. It's pretty well known that iMessage has a child safety problem, right?
Which is something that does not require kind of the international reach that WhatsApp has to have that as an infinite problem. I see no evidence of a disinformation problem on iMessage. Okay, all right. That's a question.
I'm actually very excited to ask you this question. I'm very excited to ask you. Okay, I made myself ready. What are we getting wrong?
What is the media getting wrong in this conversation? Oh, that's not that spicy. That's how we know. See, you get that reaction.
It's beginning. What are we getting? What are we consistently wrong? There's a couple of different issues going on here.
First, there are three groups who really screwed up in 2016, right? There's Mark Zuckerberg in the hoodie is standing next to James Comey in a suit, is standing next to a New York Times editor in a press hat. And Mark Zuckerberg is saying, man, we really screwed up in 2016. And the government guy and the media guy are saying, yeah, you really messed up, right?
Like everybody agrees that tech made mistakes in 2016. The government made serious, serious mistakes. They're the obvious, like specific operational mistakes in the Obama administration. But then just also just like in tech, we missed propaganda as a legitimate area of cybersecurity.
The government did not have anybody working on it. And that has changed a lot. So that has been great. At least the government is over there.
The media has had almost no self-reflection on its role in the Russian disinformation campaign in 2016. The most, if you, there's a number of books about this, one of the great books is by Alainian Kathleen Hall, Jameson. She's done quantitative studies of this, of all the things that the Russians in 2016, who work demonstrates that she believes it is the Hackenley campaign, the GRU, getting jump into this emails, getting the DNC emails, creating scandals around Debbie Wasserman Schultz and the like, that had the most impact. And that had the most impact, not because of Facebook or Twitter, and that the most impact because of the media, right?
The amplification for the GRU campaign was the New York Times, it was the Wall Street Journal, it was the Washington Post, it was MSNBC, it was obviously Fox, right? But it was the legitimate media, did the work of the Russians. And while the tech companies have dealt with that fact that we were used, that I made mistakes, I screwed up personally, I've never heard somebody in the media say that. And so that is one of the things I think that gets wrong, is that while you will read 3,000 words in the New York Times, about all the screw ups at Facebook, you will not read 3,000 words in the New York Times about the screw ups at the New York Times, right?
Maybe don't write about yourself. You can write about the One About The Washington Post and The Washington Post about the Times, right? But that is a serious problem. And it's a serious problem because if today, you know, somebody on Tulsi Gabbard's team, all of a sudden got access to a ton of emails sent inside the Joe Biden campaign, would the media treat it any differently, right?
Or would the amplification of the message that the Russians want to get out happen just as it did in 2016? And the answer is probably very little would change because there hasn't been any kind of self reflection. I think my bigger picture is the thing that we've been talking about, which is all of these issues are trade offs, and in other areas of public policy, those trade offs are obvious, right? Generally, you will not see the Wall Street Journal say, we both believe that the government should make more revenue and cut taxes, right?
And that people in the media who cover public policy understand the trade off between taking resources away from cops and the potential to fight crime, cutting taxes and revenue. What they don't understand is the trade off between privacy and safety. They don't understand the trade off between data protection and antitrust, right? And so you end up with the kind of the position of the media being, we believe the tech companies are too powerful and we want that power to be used to squash our enemies, which is a completely inconsistent position.
Or you see this a lot from the New York Times, especially. The Times wants there to be a dynamic social media environment where lots of people can compete against Facebook. They also never want Facebook to ever share information with anybody under any legal agreement ever, right? And that you have a series in your time articles that try to create scandals out of things like Netflix, being able to send messages, that they imply that all of a sudden Netflix can read your private Facebook messages, that is completely and totally ridiculous.
It is a complete technical misreading of the leaked documents these guys had. But it also strikes to the core point, which is if you believe that the companies need to be data orders, you're also telling them to be monopolists. And so I think that's like my biggest problem is that a lot of folks in the media don't believe they need to have a position on what the world is that they want, right? That they'll complain no matter what.
And so when you're in tech, the fact that they have to never have to take a position that could be criticized, that all they're going to do is criticize you whatever difficult decision you make really gets frustrating. I think actually the verbs have been great on this. I think you guys are much more opinionated. This is more of an issue for the other kind of big issue is that at the big media outlets like In Your Times, everybody's a tech reporter now.
So you have these really skilled people who have been in the area, who have good sources, who've been doing this work for years. So you have Bob McMillan at the Journal, you've got Sheer Frankl at The Times. There's a bunch of Joe Manet Reuters. So people who really know what they're talking about.
And so they have sources to help them out. But everybody else in the organization now sends themselves a tech reporter, even if they're working out of DC or New York. And so that kind of reduces the overall quality of the reporting because you end up with a large number of people that have access to grind and don't understand the kind of alien equities of any decision. It's funny you said we're opinionated.
I do think the verbs are opinionated. We're very forward about our values. I don't know that that would survive in a bigger place. We're very clear about the future.
We're like a hopeful organization. We think the tech company should do better and work harder. But at the end of the day, we're also like, there's a new phone, it's fucking cool. And that helps us center, OK, we have to make progress.
I just don't know that any other big media organization will ever really figure that out. I think about that a lot. It is very complicated to trade us or very nuanced. If you are telling people about Cambridge Analytica, you have to do 2,000 words of backstory just to get to what happens so you can understand it.
How do you think somebody listening to this podcast can evaluate what they see from the rest of the media? Right, because people listen to this podcast are so very into it. If they've gotten an hour and seven minutes and you and me, they're obviously invested in this subject, how can they better evaluate what they see from the big media organizations? I mean, I think this is true for not just tech reporting.
I think when you read a position from what is supposed to be a non-opinion source, but clearly they have their own opinions, you have to separate the things that they are saying are factual and that they have checked with multiple sources with their interpretation, which what's going on right now is that there's a number of media outlets like the Times that will apply the worst possible interpretation to any possible decision that was made. So like the example I like to use, Facebook Live has when it launched and you need to have a serious safety problem, right? Is that Facebook Live is used to do a bunch of bad things, right? Obviously the Christ shooting is an extreme example.
Most of the safety problem on Facebook Live is suicide. Is that you have teenagers who in a cry for help will livestream themselves. And unfortunately, if they attract the wrong people, instead of people saying don't do it, somebody loves you and reporting to Facebook, they will egg them on, right? And it creates kind of a real toxic and perhaps actually leads to them committing suicide.
The New York Times has rightly written stories about the safety issues of suicide in Facebook Live. They also wrote a story about how creepy it is that Facebook will call law enforcement when somebody's about to commit suicide in Facebook Live, right? Like if you're, you can read either one of those positions is OK. It's OK to say Facebook needs to please this product.
It is OK to say this is not good. And then in that story about policing suicides, they explicitly kind of infer and imply that the only reason that any of this happens is because Facebook wants to look good in the media or look at the politicians, which I know the people who work on that team. There's a number of people who work on that team and have bad family members who have committed suicide. I was disgusted to see the New York Times imply that these people who have worked very, very hard on a very difficult safety problem are only doing it for the bottom line of the company, right?
And so that's one thing, like if you're reading the media and they're implying that because somebody works at a tech company, that they're just kind of an evil person, that's something you can disregard, right? And look to see whether or not that same organization has had any opinions on that exact same topic. Now I talked to somebody at the Times about that. And they basically pointed out that it has over 1,000 reporters, it's quite possible that the person who wrote that story had never read the other time story on Facebook Live, right?
So you're right, like that's a problem of an organization that's large. I'd say you have all these different opinions, but I would like to see the larger media organizations start to understand that they should have a vision of the world they want to move to, and they should incentivize people to move that way instead of just complaining about whatever decision people make at that moment, right? Like that is not helpful, and it's just getting kind of old. Like it's easy to write a story saying the world's a shitty place.