Doxxing insurrectionists: Capitol riot divides online extremism researchers

The uprising has sparked a tense debate about the right way to stitch together the digital scraps of someone's life to publicly accuse them of committing a crime.

Doxxing insurrectionists: Capitol riot divides online extremism researchers

Rioters scale the U.S. Capitol walls during the insurrection.

Photo: Blink O'faneye/Flickr

Joan Donovan has a panic button in her office, just in case one of the online extremists she spends her days fighting tries to fight back.

"This is not baby shit," Donovan, who is research director of Harvard's Shorenstein Center on Media, Politics and Public Policy, said. "You do not fuck around with these people in public."

Which is why Donovan has been so worried about what she's seen happening online in the days since a violent mob overtook the U.S. Capitol. Scores of amateur sleuths are combing through terabytes of footage and openly trading tips on Twitter in hopes of piecing together the rioters' identities and bringing them to justice. To Donovan, these Twitter detectives aren't just running the risk of misidentifying innocent people; they may also unknowingly be putting themselves at risk by publicly pursuing potentially dangerous people.

Even more worrisome to Donovan: the role some prominent researchers are playing in organizing the hunt. So this week, she went on Twitter and shared some blunt words of warning. "This is one of the most dangerous uses of social media by a researcher," Donovan wrote. "Research ethics now. We must hold each other to account."

Her remarks were directed at another academic, John Scott-Railton of the University of Toronto's Citizen Lab, who has gained a following for his crowdsourced investigations of the riot, which most notably led to the successful identification of an Air Force veteran who was photographed in full tactical gear on the floor of the Senate. Two days after The New Yorker's Ronan Farrow used Scott-Railton's tip to confirm the veteran's identity and published a story with his findings, the suspect was arrested in Texas.

Scott-Railton shares Donovan's concerns — and admires her work — but says those concerns have led him to a different conclusion. He argues that in the wake of any public event caught on camera, be it a confrontation on a bike trail or the Boston Marathon bombing, there are bound to be crowds of extremely online people using digital techniques to assign blame. His goal is to harness that energy in productive ways and model appropriate behavior.

"I think the conversation has to be one that involves being very intentional in thinking about harm reduction and in trying to do one's best to always model the behavior you want to see from others," he said, noting that he has repeatedly urged his followers not to name potential suspects on Twitter and, instead, to funnel any specific names to the Federal Bureau of Investigation.

Besides, with the inauguration around the corner and the vast majority of the Capitol rioters still on the loose, Scott-Railton argues it's critically important to use the power of crowdsourcing to stop those people from committing any more violence. "There may be people who intend to do violent things around the inauguration," he said. "We urgently need to understand who they are."

The Capitol riot was a boundary-busting event in almost every way, and its impact on the digital privacy debate was no different. The insurrectionists' acts were so galling, so frightening, that suddenly, even those who might oppose digital surveillance and forensics techniques in other contexts, like, say, identifying peaceful protesters at a Black Lives Matter rally, feel justified in deploying those tools against the rioters. The shifting goalposts have sparked a tense debate among researchers of online extremism about the right way to stitch together the digital scraps of someone's life to publicly accuse them of committing a crime — or whether there is a right way at all.

Shortly after the riot, Vivian Schiller, executive director of the Aspen Institute's digital department, asked her followers a question on Twitter and stressed that it was not rhetorical: "Is there such a thing as 'ethical doxxing'?"

"Not really," replied Kate Klonick, an assistant professor of law at St. John's University, who studies online content moderation.

Others disagreed vehemently. "Yes, absolutely," wrote Sasha Costanza-Chock, an associate professor of civic media at MIT. "I would argue that in fact we have an ethical responsibility to expose people who are literal nazis and ensure there are consequences for their actions. Of course, this requires extreme care to verify so that innocents are not wrongfully accused."

Scott-Railton tends to see things that way, as does Aric Toler, a researcher with the group Bellingcat, which has been archiving vast troves of footage of the riot to help with identification. "The crowdsourcing element is obviously powerful and can go both ways, but I think it's overall more positive than not," Toler said.

The Capitol riot was virtually unprecedented in terms of the amount of digital exhaust it gave off. That's partly to do with the fact that the uprising was largely organized on social media, partly to do with the fact that some of the rioters were there explicitly to broadcast their actions on social media and partly to do with the fact that Parler, the go-to social platform of the far-right, had a bug that enabled a hacker to scrape and archive every public post and GPS coordinate before deletion.

Now, before anyone can get named and blamed, there's a virtual ton of information to sift through first. Toler sees much of the crowdsourcing work going on as a responsible way to divvy up the labor. "A lot of the work is just around sifting through ungodly amounts of photos and videos," Toler said.

Of course, a lot of it isn't. Already, a retired Chicago firefighter was wrongly accused of being involved in the riot, after Twitter detectives digitally enhanced a blurry photo of a man throwing a fire extinguisher at a cop and accused him of being "Extinguisher Man." In fact, he was back in Chicago, he said, celebrating his wife's birthday. "This story has fucked my life up," the man told a local news outlet.

Both Scott-Railton and Bellingcat had been seeking footage of that suspect on Twitter before he was misidentified. Though neither of them encouraged their followers to name names, and in some cases even actively discouraged it, the effort went sideways anyway.

That's to be expected, Donovan argues. Once you animate a crowd around a particular purpose, it's impossible to control what they'll do next, which she says is all the more reason for researchers to avoid such public investigations in the first place. "I have this overarching thesis that the internet turns us all into cops," Donovan said. "These are technologies of surveillance, and so use of them by the public to turn crowds into cops seems to me to be a very dangerous impulse."

That's to say nothing of the danger amateur investigators put themselves in, Donovan said. For all of the digital records the rioters have left behind, she stresses that the people looking into them often have their own digital trail that leaves them vulnerable to retaliation. "Say you identify some neo-Nazi militia member and think you're doing a good job, but you have your kid's birthday photos up on a Flickr account, which has the geotag of the apartment complex that you live in," Donovan said. "People don't understand how much is being revealed about them as they participate in these public campaigns."

It's not that only trained researchers or law enforcement should be able to do this work. Donovan argues there's a way to carry out crowdsourced investigations in private channels, where participants are educated about the risks they're taking and how to protect themselves. Anything less, she argues, is malpractice. "If you don't educate people before you call them into action," Donovan said, "you put them at risk."

Scott-Railton has tailored his approach somewhat in response to feedback from Donovan and others. For one thing, he's begun deleting old threads investigating people who have already been arrested to avoid leaving any misleading leads out in the open. He's also since deleted the tweet that Donovan first called him out on, in which he was seeking footage of people wearing earpieces at the riot. Donovan pointed out that such a directive could risk outing members of the media, who also regularly wear earpieces.

Perhaps, most importantly, on Thursday night, he tweeted an official notice to his now more than 100,000 followers. He told them that he was now moving to a "form-based intake model" for tips, in collaboration with Bellingcat, writing, "I feel this approach better balances the *many* reasonable concerns about a participatory & crowdsourced model done on Twitter."

Fintech

Judge Zia Faruqui is trying to teach you crypto, one ‘SNL’ reference at a time

His decisions on major cryptocurrency cases have quoted "The Big Lebowski," "SNL," and "Dr. Strangelove." That’s because he wants you — yes, you — to read them.

The ways Zia Faruqui (right) has weighed on cases that have come before him can give lawyers clues as to what legal frameworks will pass muster.

Photo: Carolyn Van Houten/The Washington Post via Getty Images

“Cryptocurrency and related software analytics tools are ‘The wave of the future, Dude. One hundred percent electronic.’”

That’s not a quote from "The Big Lebowski" — at least, not directly. It’s a quote from a Washington, D.C., district court memorandum opinion on the role cryptocurrency analytics tools can play in government investigations. The author is Magistrate Judge Zia Faruqui.

Keep Reading Show less
Veronica Irwin

Veronica Irwin (@vronirwin) is a San Francisco-based reporter at Protocol covering fintech. Previously she was at the San Francisco Examiner, covering tech from a hyper-local angle. Before that, her byline was featured in SF Weekly, The Nation, Techworker, Ms. Magazine and The Frisc.

The financial technology transformation is driving competition, creating consumer choice, and shaping the future of finance. Hear from seven fintech leaders who are reshaping the future of finance, and join the inaugural Financial Technology Association Fintech Summit to learn more.

Keep Reading Show less
FTA
The Financial Technology Association (FTA) represents industry leaders shaping the future of finance. We champion the power of technology-centered financial services and advocate for the modernization of financial regulation to support inclusion and responsible innovation.
Enterprise

AWS CEO: The cloud isn’t just about technology

As AWS preps for its annual re:Invent conference, Adam Selipsky talks product strategy, support for hybrid environments, and the value of the cloud in uncertain economic times.

Photo: Noah Berger/Getty Images for Amazon Web Services

AWS is gearing up for re:Invent, its annual cloud computing conference where announcements this year are expected to focus on its end-to-end data strategy and delivering new industry-specific services.

It will be the second re:Invent with CEO Adam Selipsky as leader of the industry’s largest cloud provider after his return last year to AWS from data visualization company Tableau Software.

Keep Reading Show less
Donna Goodison

Donna Goodison (@dgoodison) is Protocol's senior reporter focusing on enterprise infrastructure technology, from the 'Big 3' cloud computing providers to data centers. She previously covered the public cloud at CRN after 15 years as a business reporter for the Boston Herald. Based in Massachusetts, she also has worked as a Boston Globe freelancer, business reporter at the Boston Business Journal and real estate reporter at Banker & Tradesman after toiling at weekly newspapers.

Image: Protocol

We launched Protocol in February 2020 to cover the evolving power center of tech. It is with deep sadness that just under three years later, we are winding down the publication.

As of today, we will not publish any more stories. All of our newsletters, apart from our flagship, Source Code, will no longer be sent. Source Code will be published and sent for the next few weeks, but it will also close down in December.

Keep Reading Show less
Bennett Richardson

Bennett Richardson ( @bennettrich) is the president of Protocol. Prior to joining Protocol in 2019, Bennett was executive director of global strategic partnerships at POLITICO, where he led strategic growth efforts including POLITICO's European expansion in Brussels and POLITICO's creative agency POLITICO Focus during his six years with the company. Prior to POLITICO, Bennett was co-founder and CMO of Hinge, the mobile dating company recently acquired by Match Group. Bennett began his career in digital and social brand marketing working with major brands across tech, energy, and health care at leading marketing and communications agencies including Edelman and GMMB. Bennett is originally from Portland, Maine, and received his bachelor's degree from Colgate University.

Enterprise

Why large enterprises struggle to find suitable platforms for MLops

As companies expand their use of AI beyond running just a few machine learning models, and as larger enterprises go from deploying hundreds of models to thousands and even millions of models, ML practitioners say that they have yet to find what they need from prepackaged MLops systems.

As companies expand their use of AI beyond running just a few machine learning models, ML practitioners say that they have yet to find what they need from prepackaged MLops systems.

Photo: artpartner-images via Getty Images

On any given day, Lily AI runs hundreds of machine learning models using computer vision and natural language processing that are customized for its retail and ecommerce clients to make website product recommendations, forecast demand, and plan merchandising. But this spring when the company was in the market for a machine learning operations platform to manage its expanding model roster, it wasn’t easy to find a suitable off-the-shelf system that could handle such a large number of models in deployment while also meeting other criteria.

Some MLops platforms are not well-suited for maintaining even more than 10 machine learning models when it comes to keeping track of data, navigating their user interfaces, or reporting capabilities, Matthew Nokleby, machine learning manager for Lily AI’s product intelligence team, told Protocol earlier this year. “The duct tape starts to show,” he said.

Keep Reading Show less
Kate Kaye

Kate Kaye is an award-winning multimedia reporter digging deep and telling print, digital and audio stories. She covers AI and data for Protocol. Her reporting on AI and tech ethics issues has been published in OneZero, Fast Company, MIT Technology Review, CityLab, Ad Age and Digiday and heard on NPR. Kate is the creator of RedTailMedia.org and is the author of "Campaign '08: A Turning Point for Digital Media," a book about how the 2008 presidential campaigns used digital media and data.

Latest Stories
Bulletins