And then the men with guns tell you to do it anyway
And then the men with guns tell you to do it anyway
当持枪者命令你照做时
In early February 2011 Egypt was in the middle of a political revolution. One morning, everyone’s phones suddenly pinged with an alert. The Armed Forces asks Egypt’s honest and loyal men to confront the traitors and criminals and protect our people and honour and our precious Egypt. A series of messages arrived all ostensibly from the network provider Vodafone. All pro-regime and all with the undercurrent of violence. 2011 年 2 月初,埃及正处于政治革命之中。一天早上,所有人的手机突然发出警报声。内容写道:“武装部队呼吁埃及诚实忠诚的人们站出来对抗叛徒和罪犯,保护我们的人民、荣誉以及我们宝贵的埃及。”随后,一系列短信接踵而至,表面上都来自网络运营商沃达丰(Vodafone)。这些信息全部支持政权,且字里行间暗含暴力威胁。
Why did Vodafone send these messages? Earlier in the week, all Internet access was cut off now phones were blasting propaganda to the masses. After the network went down, Vodafone issued a statement saying: It has been clear to us that there were no legal or practical options open to Vodafone, or any of the mobile operators in Egypt, but to comply with the demands of the authorities. 沃达丰为什么要发送这些信息?就在那周早些时候,所有的互联网接入都被切断了,现在手机又成了向大众广播宣传的工具。网络中断后,沃达丰发表声明称:“我们很清楚,对于沃达丰或埃及任何移动运营商而言,除了服从当局的要求外,别无其他法律或实际选择。”
Do you have to follow orders? Do you have to obey the law even when it is unjust? Should multinational corporations instruct local executives to be loyal to their parent company or the rulers of the country they live in? 你必须服从命令吗?即使法律是不公正的,你也必须遵守吗?跨国公司应该指示当地高管效忠于母公司,还是效忠于他们所居住国家的统治者?
After the messages came in - including promises that “The Armed Forces cares for your safety and well being and will not resort to using force against this great nation” - Vodafone Global, safely ensconced in the UK, put out another statement: Under the emergency powers provisions of the Telecoms Act, the Egyptian authorities can instruct the mobile networks of Mobinil, Etisalat and Vodafone to send messages to the people of Egypt. They have used this since the start of the protests. These messages are not scripted by any of the mobile network operators and we do not have the ability to respond to the authorities on their content. Vodafone Group has protested to the authorities that the current situation regarding these messages is unacceptable. We have made clear that all messages should be transparent and clearly attributable to the originator. 在这些信息发出后——其中包括“武装部队关心你们的安全与福祉,不会对这个伟大的国家动用武力”的承诺——身处英国、安然无恙的沃达丰全球总部发表了另一份声明:“根据《电信法》的紧急权力条款,埃及当局可以指示 Mobinil、Etisalat 和沃达丰等移动网络向埃及人民发送信息。自抗议活动开始以来,他们一直都在使用这一权力。这些信息并非由任何移动网络运营商编写,我们也没有能力就其内容向当局提出异议。沃达丰集团已向当局抗议,称目前有关这些信息的情况是不可接受的。我们已明确表示,所有信息都应透明,并能清楚地追溯到发送者。”
A few years later I was at a networking event chatting to a guy. We’d both previously worked for Vodafone. Me in the UK, he in Egypt. I asked him about the incident - he talked about how they built the SMS infrastructure, what they did to secure it, how they prevented spam, and how one day armed men arrived. 几年后,我在一次社交活动中与一个人聊天。我们都曾在沃达丰工作过,我在英国,他在埃及。我问起那次事件,他谈到了他们是如何构建短信基础设施的,他们采取了哪些措施来保护它,如何防止垃圾短信,以及有一天武装人员是如何闯入的。
I suspect most of us have seen a movie where some flunky in an office refuses the baddies demands to open the safe, and then gets shot in the head. Perhaps you think that’s a noble death? He lived with honour and refused to yield! But, in every movie I’ve seen, the guy’s subordinate opens the safe anyway and gets to live. 我想我们大多数人都看过这样的电影:办公室里的某个小职员拒绝了坏人打开保险柜的要求,然后被一枪爆头。也许你认为那是一种高尚的死法?他活得有尊严,拒绝屈服!但是,在我看过的每一部电影里,那个人的下属最终还是打开了保险柜,并活了下来。
But we’re technologists, right? We can build fail safes and cryptographic proofs and simply build infrastructure that can’t be abused. And then the men with guns come and tell you what to do. 但我们是技术人员,对吧?我们可以构建故障保护装置和加密证明,简单地构建出无法被滥用的基础设施。然后,那些持枪的人就会过来告诉你该怎么做。
I’ve written before about Civic Hygiene - it’s the idea that we should be mindful of the ways that our technologies could be misused. The term was coined back in 2010 by the technologist Bruce Schneier. It’s bad civic hygiene to build technologies that could someday be used to facilitate a police state. 我之前写过关于“公民卫生”(Civic Hygiene)的文章——这个概念是指我们应该警惕技术被滥用的方式。这个术语是由技术专家布鲁斯·施奈尔(Bruce Schneier)在 2010 年提出的。构建那些有朝一日可能被用于助长警察国家的技术,就是糟糕的公民卫生。
But what do we mean by that? We don’t want backdoors in security products - lest hackers break in or evil governments get elected. But we want a way to access our beloved ones’ data after they die. It’s important that we know that photos haven’t been manipulated by propagandists and saboteurs. But we want to send funny memes about that politician we don’t like. We don’t want police stalking ex-girlfriends’ cars - but we want dangerous drivers prosecuted. We want to be alerted about imminent threats, but don’t want Governments to use that power for ill. 但我们所说的“公民卫生”到底是什么意思?我们不希望安全产品中有后门,以免黑客入侵或邪恶政府当选。但我们又希望在亲人去世后能访问他们的数据。我们认为确保照片没有被宣传家和破坏者篡改很重要,但我们又想发送关于我们不喜欢的政客的搞笑表情包。我们不希望警察跟踪前女友的汽车,但我们又希望危险驾驶者受到起诉。我们希望在迫在眉睫的威胁时收到警报,但又不希望政府将这种权力用于邪恶目的。
Way back in the early 2020s, I had a minor role in the UK Government’s adoption of Common Alerting Protocol, the technology which powers cell-broadcast emergency alerts. Even back then, one of the discussions was around whether the utility of being able to send an unavoidable push notification was worth the risk that someone would send an inappropriate message. Fresh in everyone’s minds was the false alarm saying missiles were heading to Hawaii. Too many safeguards means that a genuine alert doesn’t get sent in time. Too few safeguards and you can blame “Human Error” for any mistakes. 早在 2020 年代初,我在英国政府采用“通用警报协议”(Common Alerting Protocol,即驱动蜂窝广播紧急警报的技术)的过程中担任过一个小角色。即使在当时,讨论的焦点之一也是:能够发送不可避免的推送通知所带来的效用,是否值得冒“有人发送不当信息”的风险?当时大家对夏威夷导弹警报误报事件还记忆犹新。安全措施太多,意味着真正的警报无法及时发出;安全措施太少,一旦出错,你就可以把责任推给“人为失误”。
I don’t know which safeguards are in place for the UK’s system - and most details are exempt from Freedom of Information requests. But it is both easy and fun to speculate on how such a system might be designed. The Government generates an alert. It specifies where and when the alert should be sent. It sends that message to the network operators via a secure and private channel. Perhaps they also do some out-of-band verification like having the network operator call a pre-determined phone number to check the message’s validity. At which point, the operator can choose to send the message or not. Or can they? 我不知道英国的系统采取了哪些安全措施——而且大多数细节都免于《信息自由法》的查询。但推测这样一个系统是如何设计的,既简单又有趣。政府生成警报,指定发送地点和时间,并通过安全私密的渠道将信息发送给网络运营商。也许他们还会进行一些带外验证,比如让网络运营商拨打预设的电话号码来核实信息的有效性。此时,运营商可以选择发送或不发送该信息。或者说,他们真的有选择权吗?
In August 2026, the UK government instructed network operators to send this message: Did the networks have to send that message? If they thought it wasn’t serious enough, could they have refused? As far as I can tell, the law only talks about the fact that operators can disregard “spam” laws in order to send a mass message: 2026 年 8 月,英国政府指示网络运营商发送了这条信息:网络运营商必须发送该信息吗?如果他们认为情况不够严重,他们可以拒绝吗?据我所知,法律只提到运营商为了发送群发信息,可以无视“垃圾信息”相关法律:
“A relevant public communications provider (P) may, for the purpose of providing an emergency alert service, disregard the restrictions on the processing of data relating to users or subscribers set out in paragraph (2) if the conditions set out in paragraph (3) are met. […] (3) The conditions are— (a)P is notified by a relevant public authority that— (i)an emergency within the meaning of section 1(1) of the Civil Contingencies Act 2004 has occurred, is occurring or is about to occur;” (Statutory Instrument 2015 No. 355) “相关的公共通信提供商 (P) 为了提供紧急警报服务,如果满足第 (3) 段规定的条件,可以无视第 (2) 段中关于处理用户或订阅者数据的限制。[…] (3) 条件为——(a) P 收到相关公共当局的通知,称 (i) 2004 年《民事应急法》第 1(1) 条含义内的紧急情况已经发生、正在发生或即将发生;”(2015 年第 355 号法定文书)
I’m no expert, but I can’t see anything in the spectrum licence nor in the Wireless Telegraphy Act which compels operators to process these messages. The usual British way is to ask people to play nicely and threaten them with regulation if they don’t. Could the networks have refused to send the message about wildfires - or indeed any o… 我不是专家,但我看不出频谱许可证或《无线电报法》中有任何条款强制运营商处理这些信息。英国通常的做法是要求人们“友好行事”,如果他们不配合,就以监管进行威胁。网络运营商本可以拒绝发送关于野火的信息吗——或者事实上,拒绝发送任何其他信息吗?