About four decades ago, some folks in our community formed a community association. It isn’t a powerful Home Owners’ Association where a committee decides what color begonias you can plant along your front walkway. It’s much more a loose-knit group that fosters communication among the people who live around here and helps us organize and advocate for our common interests. The voluntary dues are a whopping $20 annually and I believe the total membership is under 100 families, so you get an idea of the kind of clout we have with state and local governments. Nonetheless, our local representatives do come to some of our community functions and seem to take our concerns seriously, and our issues often seem get addressed at the county and even state level.
Small-town politics at its finest, I suppose.
This week, the GMRS radio group was discussing if and how we should publish a directory of people who have the radios. The idea is to give folks who don’t have radios a way to find someone who does in an emergency. Some participants — one of whom is a psychotherapist (I can relate) — were quite concerned about being listed in a directory even if very little other information was included. The problem in a nutshell is that it could lead to someone showing up at your door under the belief that you had made a commitment to offer help. We pretty much feel that we’re all (7 of us) happy to help, but that we want the personal agency to decide when and how that happens. We decided that, instead of a central directory, we would rely on making community connections within our own small neighborhoods and let people know, mostly one-on-one, that they can turn to us for help. That way each of us, with our individual needs and boundaries, would have some degree of control over the extent of our commitment to the project.
That caused me to re-examine the whole way small organizations function in the middle of the 21
Forty years ago, having that information collected all in one place likely presented little real risk. It would have started out as a notebook kept by the association president or treasurer. Perhaps some xerographic copies got passed around amongst the board members.
As that evolved, it likely got moved to a computer. Then that computer got networked. Still, pretty low risk. Then it got moved to the cloud. Now the risk is growing. Next comes widespread cybersecurity incidents, where cloud data is routinely breached and circulated on shady online forums. Now the risk is becoming more than theoretical. But, really, who would put the time into finding and contextualizing that data just to attack an organization of dozens of people even if it has a vast treasury of thousands (thousands!) of dollars?
But now we have large language models (LLMs), that people currently refer to as AI. Those models aren’t intelligent in any meaningful sense of the word, but one thing they are very, very good at is analyzing and contextualizing large troves of data, finding needles in haystacks that can be exploited. There is a real risk that our tiny organization’s membership list could be exploited in very profitable ways. I’m not going to provide a recipe for doing so, but it isn’t hard to imagine, particularly given that AI companies are currently providing access to their LLMs for a tiny fraction of the actual costs of running them.
I spent decades (as many as our association has been around) protecting computer data. I can assure you that very few if any people in an organization like ours has the expertise necessary to really provide an appropriate level of protection for our cloud-stored data. Microsoft and Google might have the necessary expertise, but evidence strongly suggests that they do not apply it effectively to their consumer products.
I think it’s time we step back to storing records only locally, and possibly only on paper.
—2p