Recent Posts
Archives

Posts Tagged ‘EFF’

PostHeaderIcon [PyConUS2025] Enshittification and the Path to a New Good Internet: Cory Doctorow

Lecturer

Cory Doctorow is a science fiction author, activist, journalist, and special advisor to the Electronic Frontier Foundation. He maintains the daily blog Pluralistic.net and has authored numerous works, including the recent novels Picks and Shovels and The Bezzle (sequels to Red Team Blues), the solarpunk novel The Lost Cause, and the nonfiction volume The Internet Con: How to Seize the Means of Computation. Earlier books encompass the Little Brother series, Chokepoint Capitalism, Red Team Blues, and How to Destroy Surveillance Capitalism. Doctorow co-founded the UK Open Rights Group, serves as a MIT Media Lab Research Affiliate and Visiting Professor of Computer Science at the Open University, and holds a Visiting Professorship of Practice at the University of North Carolina’s School of Library and Information Science. Born in Toronto, he resides in Los Angeles. He was inducted into the Canadian Science Fiction and Fantasy Hall of Fame in 2020, received the Sir Arthur Clarke Imagination in Service to Society Award in 2022, the Neil Postman Award for Career Achievement in Public Intellectual Activity in 2024, and honorary doctorates from York University and the Open University. His professional site is craphound.com and his X handle is @doctorow.

Abstract

Cory Doctorow examines the concept of enshittification—the progressive degradation of digital platforms—and situates it within broader economic, legal, and technological structures. Drawing on examples ranging from nursing labor apps to Google search, he argues that platform decay arises not from technological inevitability or novel forms of corporate malice but from deliberate policy choices that dismantled four traditional disciplining forces: competition, regulation, interoperability, and labor power. Doctorow contends that reversing these choices can restore a functional digital commons and enable a “new good internet” capable of supporting collective resistance to larger crises.

The Anatomy of Enshittification and the Mechanism of Twiddling

Doctorow opens by redirecting expectations away from a conventional critique of online platforms toward an unexpected domain: nursing labor. A January 2025 report from the Groundwork Collective documented the rise of three dominant “Uber for nursing” applications—ShiftKey, ShiftMed, and CareRev—that allocate shifts through opaque algorithmic pricing. Before offering a wage, these platforms purchase a nurse’s real-time financial data from brokers. Nurses carrying substantial or delinquent credit-card debt receive systematically lower offers because desperation reduces reservation wages. Doctorow presents this practice as paradigmatic of enshittification: a three-stage process in which platforms first court end users with high-quality service while locking them in, then degrade the user experience to extract value for business customers, and finally extract remaining surplus for themselves until only a minimal residual value keeps both sides attached.

He illustrates the sequence with Google. In its early years the company minimized advertising and invested heavily in engineering, producing superior search results while simultaneously purchasing default placement across browsers, operating systems, and carriers—expenditures that eventually rivaled the cost of acquiring an entire Twitter every eighteen months. Once users were locked in, Google increased the proportion of advertising and rendered ad labels ever more subtle, enriching publishers and advertisers at the expense of searchers. When growth plateaued at roughly 90 percent market share, internal documents revealed a deliberate decision to degrade result quality so that users would issue multiple queries, thereby multiplying ad impressions. Concurrently Google entered collusive arrangements such as “Jedi Blue” with Meta to rig advertising markets against publishers. The contemporary search results page—dominated by AI-generated material, barely labeled advertisements, and SEO spam—exemplifies the terminal stage of enshittification: a “homeopathic residue” of utility sufficient only to prevent mass defection.

The technical enabler of these shifts is what Doctorow terms “twiddling.” Because modern platforms rest on Turing-complete machines, they possess effectively infinite adjustable parameters. Prices, rankings, recommendations, and wages can be altered on every interaction according to real-time data. Algorithmic wage discrimination, the term coined by legal scholar Veena Dubal, is merely one instance of twiddling applied to labor markets. Uber pioneered a similar technique with drivers: initially elevated offers induce acceptance of rides; subsequent micro-adjustments gradually erode compensation below sustainable levels once drivers have incurred sunk costs such as vehicle purchases. Digitization converts what would have been prohibitively labor-intensive wage theft into an automated, low-cost process.

Doctorow rejects the popular maxim that “if you are not paying for the product, you are the product.” Payment confers no protection. Apple’s simultaneous introduction of a third-party tracking opt-out and a secret first-party advertising surveillance system demonstrates that even customers who pay a premium can be productized. In the nursing example, nurses, patients, and hospitals are all subject to extraction. Enshittification productizes anyone who can be productized; dignified treatment is not a loyalty perk exchanged for money rather than attention.

Policy Origins and the Collapse of Disciplining Forces

Platforms were not born enshittified. Early Google, the original iPhone, and early Facebook delivered genuine value. Doctorow insists that the transformation resulted from policy decisions enacted within living memory by identifiable actors who were warned of the consequences yet faced no subsequent accountability. These decisions dismantled four constraints that once moderated corporate behavior.

The first constraint is market competition. Classical antitrust, exemplified by Senator John Sherman’s 1890 legislation, sought to prevent the emergence of “autocrats of trade.” Beginning in the 1980s, Chicago-school economics inverted this logic, treating monopolies as presumptively efficient. The result was concentrated markets across pharmaceuticals, hospitals, insurance, beer, athletic shoes, and professional wrestling. Mark Zuckerberg’s internal memo that “it is better to buy than to compete,” followed by the unchallenged acquisition of Instagram, exemplifies the new orthodoxy. Hospital consolidation, itself a defensive response to pharmaceutical mergers, left nurses and patients exposed to monopsonistic power and algorithmic wage platforms.

The second constraint is regulation. Concentrated sectors readily capture their regulators. A sector of one hundred firms is a rabble; a sector of five is a cartel capable of coordinated lobbying. Doctorow cites the United Kingdom’s Competition and Markets Authority, previously an effective investigator of technology monopolies, whose leadership was replaced by a former Amazon executive. In the United States, the last comprehensive federal privacy statute dates to 1988—the Video Privacy Protection Act—leaving data brokers free to sell financial dossiers that enable wage discrimination against nurses.

The third constraint is interoperability. In the physical world, interoperability requires careful standardization; in software it is nearly free because any valid program can be executed. Ad blockers, alternative ink cartridges, and tools that reveal hidden tips for DoorDash drivers are all forms of adversarial interoperability that discipline platforms. The 1998 Digital Millennium Copyright Act’s Section 1201, however, criminalizes the circumvention of access controls, converting reverse engineering into a potential felony. Parallel anti-circumvention provisions were exported through trade agreements to Europe, Canada, and elsewhere. Consequently, apps—websites wrapped in digital rights management—became preferred over open web interfaces, and independent repair of tractors, ventilators, and automobiles became legally hazardous.

The fourth constraint is labor power. Technology workers historically enjoyed scarcity-based leverage without formal unionization. They could refuse to implement degrading features and simply change employers. Mass layoffs since 2023—half a million jobs—and simultaneous executive bonus increases have eroded that leverage. The current enthusiasm for AI coding tools is, in Doctorow’s view, driven less by productivity gains than by the prospect of replacing workers who might otherwise resist enshittification.

Pathways Out of the Enshittocene

Because enshittification is the product of specific policy choices rather than technological destiny or inevitable historical forces, those choices can be reversed. Doctorow surveys an emerging global antitrust revival that is largely bipartisan and independent of billionaire funding. The European Union’s Digital Markets Act and Digital Services Act, parallel statutes in Australia, Japan, South Korea, and even China, and coordinated enforcement actions demonstrate renewed vigor. Market studies produced by one jurisdiction are readily adapted by others, creating a multiplier effect.

Regulatory capture can be mitigated by shifting enforcement away from captured national venues (for example, moving GDPR claims out of Irish courts). Right-to-repair legislation in Europe and Canada remains partially frustrated by residual anti-circumvention rules, yet the political opportunity now exists to repeal those rules. Doctorow argues that any jurisdiction willing to legalize reverse engineering, jailbreaking, and independent app stores would instantly become a technology export powerhouse. A Canadian app store charging a three-percent transaction fee rather than thirty percent would raise authors’, musicians’, and software developers’ revenues by roughly twenty-five percent overnight. Diagnostic tools priced at one hundred dollars per month rather than ten thousand dollars per manufacturer would attract global demand. The resulting competition would simultaneously lower costs for users worldwide and attack the most profitable lines of business of the largest American technology firms.

Doctorow situates these technical and legal interventions within a larger polycrisis—climate change, authoritarianism, genocide, and xenophobia—whose perpetrators have weaponized centralized platforms. The “insidete” was purpose-built for such co-option: giant corporations willing to trade a habitable planet for modest tax advantages, default algorithmic feeds, and government-backed intellectual-property barriers to exit. Yet the architecture was chosen, not inevitable. A new good internet combining the technical self-determination of the early web with the accessibility of Web 2.0 services remains possible. Such an internet would enable coordination and mutual aid in the face of cascading crises. Doctorow closes with the injunction that the community must build it.

Links:

PostHeaderIcon [DefCon32] How to Keep IoT From Becoming An IoTrash

The proliferation of Internet of Things (IoT) devices promises connectivity but risks creating a digital wasteland of abandoned, vulnerable gadgets. Paul Roberts, Chris Wysopal, Cory Doctorow, Tarah Wheeler, and Dennis Giese, a distinguished panel from Secure Resilient Future Foundation, Electronic Frontier Foundation, Veracode, Red Queen Dynamics, and DontVacuum.me, respectively, address this crisis. Their discussion, rooted in cybersecurity and policy expertise, explores solutions to prevent IoT devices from becoming e-waste, advocating for transparency, ownership, and resilience.

The Growing Threat of Abandonware

Paul opens by highlighting the scale of the issue: end-of-life devices, from routers to medical equipment, are abandoned by manufacturers, leaving them susceptible to exploitation. Black Lotus Labs’ discovery of 40,000 compromised SOHO routers in the “Faceless” botnet underscores this danger. Cory introduces the concept of “enshittification,” where platforms and devices degrade as manufacturers prioritize profits over longevity, citing Spotify’s Car Thing, bricked without refunds after brief market presence.

Policy and Right-to-Repair Solutions

Tarah and Chris advocate for legislative reforms, such as updating the Digital Millennium Copyright Act (DMCA), to grant consumers repair rights. Google’s extension of Chromebook support to ten years saved millions in e-waste, a model Tarah suggests for broader adoption. Chris emphasizes that unmaintained devices fuel botnets, threatening critical infrastructure. Policy changes, including antitrust enforcement to curb monopolistic practices, could compel manufacturers to prioritize device longevity and security.

Cybersecurity Implications and Community Action

Dennis, known for reverse-engineering vacuum robots, stresses the cybersecurity risks of abandoned devices. Malicious actors exploit unpatched vulnerabilities, conscripting devices into botnets. He calls for community-driven efforts to document and secure IoT systems. Paul, through the Secure Resilient Future Foundation, encourages grassroots advocacy, such as contacting local representatives to support repair-friendly legislation, making it easier for individuals to contribute without navigating complex policy landscapes.

Redefining Ownership and Sustainability

Cory argues for redefining ownership in the IoT era, criticizing practices like Adobe’s Creative Cloud, where Pantone’s licensing dispute threatened to render designers’ work unusable. By designing devices to resist forced downgrades, manufacturers can empower users to maintain control. The panel collectively urges a shift toward sustainable design, where devices remain functional through community-driven updates, reducing e-waste and enhancing digital resilience.

Links:

PostHeaderIcon [DefCon32] Closing Ceremonies & Awards

As the echoes of innovation and collaboration fade from the halls of the Las Vegas Convention Center, the closing ceremonies of DEF CON 32 encapsulate the spirit of a community that thrives on engagement, resilience, and shared purpose. Hosted by Jeff Moss, known as Dark Tangent, alongside contributors like Mar Williams and representatives from various teams, the event reflects on achievements, honors trailblazers, and charts a course forward. Amid reflections on past giants and celebrations of current triumphs, the gathering underscores the hacker ethos: pushing boundaries while fostering inclusivity and growth.

Jeff opens with a tone of relief and gratitude, acknowledging the unforeseen venue shift that tested the community’s adaptability. What began as a potential setback transformed into a revitalized experience, with attendees praising the spacious layout that evoked the intimacy of earlier conventions. This backdrop sets the stage for a moment of solemnity, where participants pause to honor those who paved the way—mentors, innovators, and unsung heroes whose legacies endure in the collective memory.

The theme of “engage” permeates the proceedings, inspiring initiatives that extend the conference’s impact beyond its annual confines. Jeff highlights two new ventures aimed at channeling the community’s expertise toward societal good and personal advancement. These efforts embody a commitment to proactive involvement, bridging the gap between hacker ingenuity and real-world challenges.

Honoring the Past: A Moment of Reflection

In a poignant start, Jeff calls for silence to remember predecessors whose contributions form the foundation of today’s cybersecurity landscape. This ritual serves as a reminder that progress stems from accumulated wisdom, urging attendees to carry forward the ethos of giving back. The gesture resonates deeply, connecting generations and reinforcing the communal bonds that define DEF CON.

Transitioning to celebration, the ceremonies spotlight individuals and organizations embodying selfless dedication. Jeff presents the Uber Contributor Award to The Prophet, a figure whose decades-long involvement spans writing for 2600 magazine, educating newcomers, and organizing events like Telephreak Challenge and QueerCon. His journey from phreaker to multifaceted influencer exemplifies the transformative power of sustained engagement. The Prophet’s acceptance speech captures the magic of the community, where dreams materialize through collective effort.

Similarly, the Electronic Frontier Foundation (EFF) receives recognition for over two decades of advocacy, raising $130,000 this year alone to support speakers and defend digital rights. Their representative emphasizes EFF’s role in amplifying security research for global benefit, aligning with DEF CON’s mission to empower ethical hacking.

Embracing the Theme: Engagement in Action

The “engage” motif drives discussions on evolving the community’s role in an increasingly complex digital world. Jeff articulates how this concept prompted bold experiments, acknowledging the uncertainties but embracing potential failures as learning opportunities. This mindset reflects the hacker’s adaptability, turning challenges into catalysts for innovation.

Attendees share feedback on the new venue, noting reduced overcrowding and a more relaxed atmosphere reminiscent of DEF CON’s earlier editions. Such observations validate the rapid pivot from the previous location, a decision thrust upon organizers by an unexpected contract termination. Jeff recounts the whirlwind process with humor, crediting quick alliances and the community’s resilience for the seamless transition.

Spotlight on Creativity: The Badge Unveiled

Mar Williams takes the stage to demystify the DEF CON 32 badge, a testament to accessible design and collaborative artistry. Drawing from a concept rooted in inclusivity, Mar aimed to create something approachable for novices while offering depth for experts. Partnering with Raspberry Pi, the badge incorporates layers of interactivity—from loading custom ROMs to developing games via GB Studio.

Acknowledgments flow to the team: Bonnie Finley for 3D modeling and game art, Chris Maltby for plugins and development, Nutmeg for additional game work, Will Tuttle for narrative input, Ada Rose Cannon for character creation, Legion 303 for audio, and others like ICSN for manufacturing. Mar’s vision emphasizes community participation, with the badge’s game dedicating itself to players who engage and make an impact. Challenges like SOS signals and proximity interactions foster connections, while post-conference resources encourage ongoing tinkering.

Triumphs in Competition: Village and Challenge Winners

The ceremonies burst with energy as winners from myriad contests are announced, showcasing the breadth of skills within the community. From the AI Village Capture the Flag, where teams like AI Cyber Challenge victors demonstrate prowess in emerging tech, to the Aviation Village’s high-flying achievements, each victory highlights specialized expertise.

Notable accolades include the AppSec Village’s top performers in secure coding, the Biohacking Village’s innovative health hacks, and the Car Hacking Village’s vehicular exploits. The Cloud Village CTF crowns champions in scalable defenses, while the Crypto & Privacy Village recognizes cryptographic ingenuity. Diversity shines through in the ICS Village’s industrial control triumphs and the IoT Village’s device dissections.

Special mentions go to the Lockpick Village’s dexterity masters, the Misinformation Village’s truth-seekers, and the Packet Hacking Village’s network ninjas. The Password Cracking Contest and Physical Pentest Challenge celebrate brute force and subtle infiltration, respectively. The Policy Village engages in advocacy wins, and the Recon Village excels in intelligence gathering.

Celebrating Hands-On Innovation: More Contest Highlights

The Red Team Village’s strategic simulations yield victors in offensive operations, complemented by the RFID Village’s access control breakthroughs. Rogue Access Point contests reward wireless wizardry, while the Soldering Skills Village honors precise craftsmanship.

The Space Security Village pushes boundaries in orbital defenses, and the Tamper Evident Village masters detection of intrusions. Telecom and Telephreak challenges revive analog artistry, with the Vishing Competition testing social engineering finesse. The Voting Village exposes electoral vulnerabilities, and the WiFi Village dominates spectrum battles.

Wireless CTF and Wordle Hacking rounds out the roster, each contributing to a tapestry of technical mastery and creative problem-solving.

Organizational Gratitude: Behind-the-Scenes Heroes

Jeff extends heartfelt thanks to departments, goons, and volunteers who orchestrated the event amid upheaval. Retiring goons like GMark, Noise, Ira, Estang, Gataca, Duna, The Samorphix, Brick, Wham, Casper receive nods for their service, earning lifetime attendance. New “noons” are welcomed, injecting fresh energy.

Gold badge holders, signifying a decade of dedication, are celebrated for their enduring commitment. This segment underscores the human element sustaining DEF CON’s scale and vibrancy.

Looking Ahead: Community and Continuity

Social channels keep the conversation alive year-round, from Discord movie nights to YouTube archives and Instagram updates. The DEF CON Social Mastodon server offers a moderated space adhering to the code of conduct, providing a haven amid social media fragmentation.

A lighthearted anecdote from Jeff about the badge’s “dark chocolate” Easter egg illustrates serendipitous joy, where proximity triggers whimsical interactions. Such moments encapsulate the conference’s blend of seriousness and play.

Finally, anticipation builds for DEF CON 33, slated for August 7-10 at the same venue. Jeff reflects on the positive reception, affirming the space’s role in reducing FOMO and enhancing connections. With content continually uploaded online, the community remains engaged, ready to disengage only until the next convergence.

Links:

EN_DEFCON32MainStageTalks_007_010.md