Beware those Black Swans

The bestselling economist Nassim Nicholas Taleb argues that we can’t make the world financial system

After completing my book The Black Swan, I spent some time meditating on the fragility of systems with the illusion of stability. This convinced me that the banking system was the mother of all accidents waiting to happen. I explained in the book that the best teachers of wisdom are the eldest, because they may have picked up invisible tricks that are absent from our epistemic routines and which help them survive in a world more complex than the one we think we understand. So being old implies a higher degree of resistance to "Black Swans" (events with the following three attributes: they lie outside the realm of regular expectations; they carry an extreme impact; and human nature makes us concoct explanations for their occurrence after the fact).

Take Mother Nature, which is clearly a complex system, with webs of interdependence, non-linearities and a robust ecology (otherwise it would have blown up a long time ago). It is a very old person with an impeccable memory. Mother Nature does not develop Alz­heimer's - and there is evidence that even humans would not easily lose brain functions with age if they took long walks, avoided sugar, bread, white rice and stock-market investments, and refrained from taking economics classes or reading the New York Times.

Let me summarise my ideas of how Mother Nature deals with the Black Swan. First, she likes redundancies. Look at the human body. We have two eyes, two lungs, two kidneys, even two brains (with the possible exception of company executives) - and each has more capacity than is needed ordinarily. So redundan­cy equals insurance, and the apparent inefficiencies are associated with the costs of maintain­ing these spare parts and the energy needed to keep them around in spite of their idleness.

The exact opposite of redundancy is naive optimisation. The reason I tell people to avoid attending an (orthodox) economics class and argue that economics will fail us is the following: economics is largely based on notions of naive optimisation, mathematised (poorly) by Paul Samuelson - and these mathematics have contributed massively to the construction of an error-prone society. An economist would find it inefficient to carry two lungs and two kidneys - consider the costs involved in transporting these heavy items across the savannah. Such optimisation would, eventually, kill you, after the first accident, the first "outlier". Also, consider that if we gave Mother Nature to economists, it would dispense with individual kidneys - since we do not need them all the time, it would be more "efficient" if we sold ours and used a central kidney on a time-share basis. You could also lend your eyes at night, since you do not need them to dream.

Almost every major idea in conventional economics fails under the modification of some assumption, or what is called "perturbation", where you change one parameter or take a parameter henceforth assumed to be fixed and stable by the theory, and make it random. Take the notion of comparative advantage, supposedly discovered by David Ricardo, and which has oiled the wheels of globalisation. The idea is that countries should focus on "what they do best". So one country should specialise in wine, another in clothes, even though one of them might be better at both. But consider what would happen to the country if the price of wine fluctuated. A simple perturbation around this assumption leads one to reach the opposite conclusion to Ricardo. Mother Nature does not like overspecialisation, as it limits evolution and weakens the animals.

This explains why I found the current ideas on globalisation (such as those promoted by the journalist Thomas Friedman) too naive, and too dangerous for society - unless one takes into account the side effects. Globalisation might give the appearance of efficiency, but the operating leverage and the degrees of interaction between parts will cause small cracks in one spot to percolate through the entire system.

The debt taboo

The same idea applies to debt: it makes you very fragile under perturbations. We currently learn in business schools to engage in borrowing, against all historical traditions (all Mediterranean cultures developed over time a dogma against debt). "Felix qui nihil debet", goes the Roman proverb: "Happy is he who owes nothing." Grandmothers who survived the Great Depression would have advised doing the exact opposite of getting into debt: have several years of income in cash before any personal risk-taking. Had the banks done the same, and kept high cash reserves while taking more aggressive risks with a smaller portion of their port­folios, there would have been no crisis.

Documents dating back to the Babylonians show the ills of debt, and Near Eastern religions banned it. This tells me that one of the purposes of religious traditions has been to enforce prohibitions to protect people against their own epistemic arrogance. Why? Debt implies a strong statement about the future, and a high degree of reliance on forecasts. If you borrow $100 and invest in a project, you still owe $100 even if you fail in the project (but you do a lot better in case you succeed). So debt is dangerous if you are overconfident about the future and are Black Swan-blind - which we all tend to be. And forecasting is harmful since people (especially governments) borrow in response to a forecast (or use the forecast as a cognitive excuse to borrow). My "Scandal of Prediction" (bogus predictions that seem to be there to satisfy psychological needs) is compounded by the "Scandal of Debt": borrowing makes you more vulnerable to forecast error.

Just as Mother Nature likes redundancies, so she abhors anything that is too big. The largest land animal is the elephant, and there is a reason for that. If I went on a rampage and shot an elephant, I might be put in jail and get yelled at by my mother, but I would hardly disturb the ecology of Mother Nature. On the other hand, my point about banks in my book - that if you shot a large bank, I would "shiver at the consequences" and that "if one falls, they all fall" - was subsequently illustrated by events: one bank failure, Lehman Brothers, in September 2008, brought down the entire edifice.

The crisis of 2008 provides an illustration of the need for robustness. Over the past 2,500 years of recorded ideas, only fools and Platonists have believed in engineered utopias. We shouldn't think that we can correct mistakes and eliminate randomness from social and economic life. The challenge, rather, is to ensure that human mistakes and miscalculations remain confined, and to avoid them spreading through the system - just the way Mother Nature does it. Reducing randomness increases exposure to Black Swans.

My dream is to have a true "epistemocracy"; that is, a society robust against expert errors, forecasting errors and hubris, one that can be resistant to the incompetence of politicians, regulators, economists, central bankers, bank­ers, policy wonks and epidemiologists.Here are ten principles for a Black Swan-robust society.

What is fragile should break early while it's still small: Nothing should ever become too big to fail. Evolution in economic life helps those with the maximum amount of hidden risks become the biggest.

No socialisation of losses and privatisation of gains: Whatever may need to be bailed out should be nationalised; whatever does not need a bailout should be free, small and risk-bearing. We got ourselves into the worst of capitalism and socialism. In France, in the 1980s, the Socialists took over the banks. In the US in the 2000s, the banks took over the government. This is surreal.

People who drove a school bus blindfolded (and crashed it) should never be given a new bus: The economics establishment lost its legitimacy with the failure of the system in 2008. Find the smart people whose hands are clean to get us out of this mess.

Don't let someone making an "incentive" bonus manage a nuclear plant - or your financial risks: Odds are he would cut every corner on safety to show "profits" from these savings while claiming to be "conservative". Bonuses don't accommodate the hidden risks of blow-ups. It is the asymmetry of the bonus system that got us here. No incentives without disincentives.

Time to definancialise

Compensate complexity with simplicity: Complexity from globalisation and highly networked economic life needs to be countered by simplicity in financial products. Complex systems survive thanks to slack and redundancy, not debt and optimisation.

Do not give children sticks of dynamite, even if they come with a warning label: Complex financial products need to be banned because nobody understands them, and few are rational enough to know it. We need to protect citizens from themselves, from bankers selling them "hedging" products, and from gullible regulators who listen to economic theorists.

Only Ponzi schemes should depend on confidence: Governments should never need to "restore confidence". Cascading rumours are a product of complex systems. Governments cannot stop the rumours. We just need to be able to shrug off rumours, to be robust to them. Do not give an addict more drugs if he has withdrawal pains: Using leverage to cure the problems of too much leverage is not homoeopathy, it's denial. The debt crisis is not a temporary problem, it's a structural one. We need rehab.

Citizens should not depend on financial assets as a repository of value and rely on fallible "expert" advice for their retirement: Economic life should be definancialised. We should learn not to use markets as warehouses of value.

Make an omelette with the broken eggs: The crisis of 2008 was not a problem to fix with makeshift repairs. We will have to remake the system before it does so itself. Let us move voluntarily into a robust economy by helping what needs to be broken break on its own, converting debt into equity, marginalising the economics and business school establishments, banning leveraged buyouts, putting bankers where they belong, clawing back the bonuses of those who got us here and teaching people to navigate a world with fewer certainties. Then we will see an economic life closer to our biological environment: smaller firms and no leverage - a world in which entrepreneurs, not bankers, take the risks, and in which companies are born and die every day without making the news.

Extracted from the postscript to "The Black Swan: the Impact of the Highly Improbable" by Nassim Nicholas Taleb (Penguin, £9.99)
© Nassim Nicholas Taleb 2008 penguin.co.uk

This article first appeared in the 05 July 2010 issue of the New Statesman, The cult of the generals

NEAL FOX FOR NEW STATESMAN
Show Hide image

They know where you live

Imagine your house being raided by armed police. That’s what happened to Mumsnet’s Justine Roberts after she fell victim to an internet hoaxer.

At around midnight on Tuesday 11 August 2015, a man dialled 999 to report a murder. A woman had been killed in her London home, he said, before hanging up without offering his name. A second call followed. This time, the man claimed to be the killer. He told the operator that he had now taken the woman’s children hostage at the Islington address. They were locked with him inside a room in the house, he said. The police responded with reassuring speed. Fifteen minutes later, eight officers, five of them armed with automatic weapons, accompanied by saliva-flecked dogs, arrived at the scene and took up position in neighbouring front gardens. When one officer banged on the front door of the house, the team was greeted, moments later, not by a masked murderer but by a blinking and bewildered au pair.

Justine Roberts, the woman whom the caller claimed to have killed, was in fact nearly 2,000 kilometres away – in Italy, holidaying with her husband and children. After explaining this to the police, the au pair called Roberts, who assumed that the incident was an unfortunate misunderstanding, one that could be unpicked after the vacation. It was no mistake. Roberts had been the victim of “swatting”, the term given to a false emergency call designed to bait an armed unit of police officers to storm someone’s home. It wasn’t until a few days later, as the family was preparing to return to London, that Roberts discovered that she had been the target of a planned and sustained attack, not only on her household, but also on her business.

Roberts is the founder of Mumsnet, the popular British internet discussion forum on which parents share advice and information. A few days before the swatting incident, members of 8chan, a chat room that prides itself on being an open, anonymous platform for free speech, no matter how distasteful, had registered accounts on Mums­net with the aim of trolling people there. When legitimate Mumsnet users identified and then ridiculed the trolls, some retreated to 8chan to plot more serious vengeance in a thread that the police later discovered. Roberts wasn’t involved in the online skirmish but, as the public face of the site, she was chosen as the first target.

After the initial armed response, Roberts’s perception was that the police were unconcerned about the swatting attack. “We were told that there was no victim, so there was not much that could be done,” she told me. The hoax caller, however, was not finished. In the days after the incident, there was chatter on Mumsnet and Twitter about what had happened. A Mumsnet user whom I will call Jo Scott – she requested anonymity for her own safety – exchanged heated messages with a hacker who claimed responsibility for the 999 call.

“It descended into jokes and silliness, like many things do,” Scott said. “I didn’t take it seriously when the hacker said he had big surprises in store.” She doesn’t believe that what happened next was personal. “I think I was just easy to find.”

A few days after police were called to Roberts’s home, Scott was in her bedroom while her husband was sitting downstairs playing video games. At 11pm, she heard a noise outside. “I looked out of the window and saw blue flashing lights in the street,” she recalled. “I could hear shouting but I didn’t pay it much notice.” Then she heard her husband open the front door. Police rushed into the house. An armed officer shouted upstairs, asking Scott if she was hurt. When she replied that she was fine, he told her to fetch her two young children: he needed to see them. Scott shook her sons awake, explaining, so as not to alarm them, that the police had come to show the boys their cars. As the three of them went downstairs, the officers swept up through the house, repeatedly asking if there were any weapons on the property.

“I was beyond confused by this point,” Scott said. “Everyone was carrying a gun. They had little cutaway bits so you could see the bullets. My eldest asked one of the officers if he could have a go on his gun and went to touch it.”

As Scott sat with an officer downstairs, she asked what had happened to her husband. “I later found out that the noises I’d heard were the police calling for him to come outside,” she said. “He dropped the PlayStation controller as he left the room. It was only later that we realised it’s a good job he did: in the dark, the controller might have looked like a weapon.”

Outside, Scott’s husband had been surrounded and arrested. Other police ­officers were on the lookout in the front gardens of nearby properties, having warned the couple’s neighbours to stay indoors, away from their windows. “One of the officers said it was beginning to look like a hoax,” Scott said. “Then he mentioned swatting. As soon as he said that word, I twigged that I’d seen the term that day on Twitter in relation to the Mumsnet hack.”

***

The term “swatting” has been used by the FBI since 2008. “Swat” is an acronym of “Special Weapons and Tactics”, the American police squads routinely called to intervene in hostage situations. It is, in a sense, a weaponised version of a phoney order of pizza, delivered as a prank to a friend’s home, albeit one that carries the possibility of grave injury at the hands of police. For perpetrators, the appeal is the ease with which the hoax can be set in motion and the severity of the results. With a single, possibly untraceable phone call, dialled from anywhere in the world, it is possible to send an armed unit to any address, be it the home of a high-profile actor whom you want to prank or that of someone you want to scare.

In America, where swatting originated, the practice has become so widespread – targets have included Tom Cruise, Taylor Swift, Clint Eastwood and the Californian congressman Ted Lieu – that it is now classed as an act of domestic terrorism. In the UK, where Justine Roberts’s was one of the first recorded cases, swatting is classed as harassment, though that may change if these and other forms of internet vigilante attacks, such as doxxing, become increasingly commonplace.

Doxxing involves the publication of someone’s personal details – usually their home address, phone numbers, bank details and, in some cases, email address – on the internet. It is often the prelude to swatting: after all, the perpetrator of a hoax cannot direct the police to the target’s home address until this is known. (During the week of the Mumsnet attacks, one of the perpetrators attempted to locate another target using their computer’s IP address, which can identify where a person is connected to the internet, often with alarming precision. Their calculation, however, was slightly out; police were called to a neighbour’s address.)

Though doxxing has a less dramatic outcome than swatting, the psychological effects can be just as severe. For victims – usually people who are active on the internet and who have outspoken opinions or who, in the eyes of an internet mob, have committed some kind of transgression – the mere threat of having their personal information made available on the web can cause lasting trauma. A Canadian software developer whose home address, bank details, social security number and email history were published online in 2014 told me that he now keeps an axe by his front door. “I still don’t feel safe here,” he said. “It’s terrifying.”

Christos Reid, a social media manager for a software company, was doxxed last year. Reid’s information came from a website he had registered seven years earlier. “I woke up one morning to find a tweet announcing my personal details,” he told me. When he asked the Twitter account holder to take down the address, he was told to commit suicide. Reid said he was “OK for about half an hour”; but then, after he went out, he broke down in the street. “I’ve become more paranoid,” he said. He no longer gives out business cards with personal information.

Reid lives in London, but at the time of the doxx he was attending an event in Nottingham, home to the British police’s largest cybercrime division. He was impressed with the police response, even though they told him that they had not heard of the term “doxxing” before. “I was interviewed by two separate people about my experiences who then compiled everything into a case file and transferred it to the Met. When I arrived home, an officer visited me to discuss what happened and my options.”

The policeman explained harassment law to Reid, and offered advice on how to improve security at his flat and what to do if someone hostile turned up at the address. Reid shouldered the repercussions of what had happened alone; no suspects were identified. A spokesperson for the Metropolitan Police similarly said that although detectives from Islington CID have investigated the swatting attacks made on Roberts and Scott, no suspects have been identified “at this time”, even as “inquiries continue”.

Doxxing may seem to be a mild form of harassment but it carries with it an implicit threat of impending violence; the worrying message is: “We know where you live.” Unlike swatting, which is always malicious, doxxing is sometimes viewed by its perpetrators as virtuous. In November 2014, hackers claiming to be aligned with the internet group Anonymous published personal information allegedly belonging to a Ku Klux Klan member from Missouri. The hackers said that their action was a response to the KKK’s threat to use lethal force against demonstrators in the city of Ferguson, Missouri, protesting against the killing of the unarmed black teenager Michael Brown by a white police officer. In January 2015 hackers claiming to be from Isis took over US Central Command’s Twitter account and posted information about senior military officers, including phone numbers and email addresses. In each case, those carrying out the doxxing believed, however mistakenly, in the virtue of their actions and hoped that the information could be used to bring punishment or ruin to the subject.

The term “doxxing” may be new but the practice is an old one. The Hollywood blacklist revealed the political beliefs and associations of actors and directors in the late 1940s as a way to invite shame, deny employment and dissuade others from following their example. “But it has become a lot easier to find people’s private details with the help of the internet,” Jeroen Vader told me. Vader owns Pastebin, a website that allows users to upload and distribute text documents, and where much of the personal data is anonymously uploaded and shared. “People post their private information on social networks,” he said. “A lot of people aren’t aware that their information is so easily available to others.”

In Justine Roberts’s case, the perpetrator may not even have needed to look at social networks to mine her personal information. “If you’re on the electoral roll, you’re easy to find,” she said. “There’s not much you can do to stop people getting hold of your data one way or another, whether it’s for nefarious reasons or simply to better advertise to you. We live in a world that is constantly trying to gather more information about us.”

Jeroen Vader said he has noticed an “upward trend” in the number of doxxing posts uploaded to Pastebin in recent months, but insisted that when someone uses the site’s abuse report system these offending posts are removed immediately.

Across social media companies, action is more often reactive than proactive. Victoria Taylor, a former director at Reddit, one of the largest community-driven websites in the world, said that the rule against publishing other users’ personal information has been “consistently one of the site’s most basic policies” and that “any violation of this rule is taken extremely seriously by the team and community”. Still, she was only able to recommend that victims of doxxing send a message to the site’s administrators. Similarly, when asked what a person can do to remove personal details that have been published without permission, a Twitter spokesperson said: “Use our help form.”

The spokesperson added: “There has def­initely been an overall increase in doxxing since 2006, both on Twitter and on the internet more generally.” She attributed this rise to the emergence of search engines such as Intelius and Spokeo, services designed to locate personal information.

***

The surge in the number of dox­xing and swatting attacks is in part a result of the current lack of legal protection for victims. Confusion regarding the law on doxxing is pervasive; the term is even not mentioned in either US or European law. In a tutorial posted on Facebook in 2013, the writer claims: “Doxxing isn’t illegal as all the information you have obtained is public,” and adds: “But posting of the doxx might get you in a little trouble.”

Phil Lee, a partner in the privacy, security and information department of Fieldfisher based at the law firm’s office in Silicon Valley, said that differing privacy laws around the world were part of the problem. “Various countries have laws that cover illegal or unauthorised obtaining of data. Likewise, some of the consequences of releasing that data, such as defamation or stalking, cover elements of what we now term doxxing. But there is no global law covering what is a global phenomenon.” Indeed, Roberts believes that her London address was targeted from America – the 999 call was routed through a US proxy number.

One challenge to creating a law on doxxing is that the sharing of personal information without permission has already become so widespread in the digital age. “If a law was to state something like, ‘You must not post personal information about another person online without their consent,’ it wouldn’t reflect how people use the internet,” Lee said. “People post information about what their friends and family members have been doing all the time without their consent.

“Such a law could have a potentially detrimental effect on freedom of speech.”

Lee believes that a specific law is unnecessary, because its potentially harmful effects are already covered by three discrete pieces of legislation dealing with instances where a person’s private information is obtained illegally, when that information is used to carry out illegal acts and when the publication of the information is accompanied by a threat to incite hatred. However, this does not adequately account for cases in which the information is obtained legally, and then used to harass the individual in a more legally ambiguous manner, either with prank phone calls or with uninvited orders of pizza.

Susan Basko, an independent lawyer who practises in California and who has been doxxed in the course of her frequent clashes with internet trolls, believes that the onus should be on the law, rather than the public. She points out that in the US it is a crime to publicise information about a government employee such as their home address, their home and cellphone numbers, or their social security number, even if the information is already online. “This law should apply to protect all people, not just federal employees,” she said. “And websites, website-hosting companies and other ISPs should be required to uphold this law.”

Basko said that doxxing will continue to increase while police have inadequate resources to follow up cases. For now, it is up to individuals to take preventative measures. Zoë Quinn, an American game designer and public speaker who was doxxed in 2014, has launched Crash Override, a support network and assistance group for targets of online harassment, “composed entirely of experienced survivors”.

Quinn, who spoke about the problem at a congressional hearing in Washington, DC in April last year, recently posted a guide on how to reduce the likelihood of being doxxed. “If you are worried you might some day be targeted,” she wrote, “consider taking an evening to stalk yourself online, deleting and opting out of anything you’re not comfortable with.”

Both Scott and Roberts have changed their privacy habits following the attacks. Scott is more careful about interacting with strangers online, while Roberts uses scrambler software, which ensures that she never uses the same password for more than one online site or service.

For both women’s families, the effects of their encounters with armed police have also lingered. When one day recently Roberts’s husband returned home early from work, the au pair called the police, believing it was an intruder. And Scott is haunted by what happened.

“What if my husband had made a sudden move or resisted in some way? What if my eldest had grabbed the gun instead of gently reaching for it? What if people locally believed that my husband did actually have guns in the house?” she asks. “I don’t think the people making these sorts of hoax calls realise the impact.” 

This article first appeared in the 28 April 2016 issue of the New Statesman, The new fascism