Tuesday, 17 September 2019

Why we won't get online safety

 Why data breaches won't go away

Why phishing won't go away

"Those who would give up essential usability to purchase a little technical security deliver neither usability nor security."

There is no prospect of us having online safety in the foreseeable future. The diagrams above show the stories around data breaches and phishing.

The infosec world does not have the tools, resources, culture, management, or incentives to fix things. The bad actors carry on getting smarter.

The IT security world as presented to us ordinary users is confusing, inconsistent, and unpleasant.

Several things are clear:
1. The victim-blaming ("silly users with their 1234567 passwords") needs to be challenged at every opportunity. It is unhelpful in the extreme.
2. Digital literacy needs to highlight Michel de Certeau's 'Arts de Faire / Arts of Doing' - ways of reclaiming our autonomy from the panopticon and bad actors.

3. We need tools and resources to fight back / hold our own against the tide of incompetence and malevolence.

4. There is no obvious source for good advice, training, tools, and resources that will be heard above the noise and used at scale.

The Robert Graham Project says "I think the most important security precaution is to lie to computers compulsively". This includes made-up user names, multiple email addresses, fake answers to security questions, and multiple mobile phone numbers. The recent (very good) UK Government guidance gets close but not close enough.

Passwords and Usability

Usability of advice

Much advice on passwords is contradictory, confusing, and context-free. I propose a Scale for Evaluating Password Advice (SEPA)

1. Does the advice give due prominence to haveibeenpwned.com?
2. Is the advice tailored to specific users and contexts (use cases)? (as opposed
    to being generic)
If 'Yes' to question 2:
3. Are there indications that the threat priorities have been based on
4. Are there indications that the risk mitigation actions proposed are
    based on evidence?
5. Are there indications that the advice has been tested with
    representative users?

Password Managers

There are plenty of reviews of password managers. These all seem to focus on technical aspects, with little or no understanding of usability. On the basis of limited personal experience, I suggest the following criteria for password manager usability:
1. The supplier website sets out what use cases it meets, and how, and what use cases it does not support.
2. The manager has a link to haveibeenpwned.com API.
3. The manager generates user-friendly passphrases
4. The manager works without the cloud.
5. The manager helps the user cope with the vagaries of various websites e.g. no paste allowed.
6. The manager is compatible with producing paper storage system.

Use Cases

A collection of not-very-thought-through use cases is below for illustrative (rather than design)purposes:
  • A US Secretary of State who steps out of the SCIF to use her personal Blackberry.
  • A bitcoin miner whose mobile phone account is hijacked to exploit SMS 2FA.
  • A Cambridge Professor of Security Engineering who refuses to use online banking with good reason
"...if you fall victim to an online fraud the chances are you will never see your money again...one of the banks’ most extraordinary feats of recent years has been their ability to shift liability away from themselves and on to the customer – aided by a Financial Ombudsman Service (FOS) that they claim rarely challenges the banks following a fraud."
  • A journalist talking to dissidents in a dangerous country.
  •  Grandma logging into Facebook while staying with her daughter.
  •  Grandma wanting to put her online affairs in order for her estate. 
  • A student wanting to prevent his flatmates using his pr0n account when he is out. 
  • A businessman going to the toilet while doing online business with the free wi-fi in a coffee shop.
  • A Civil Servant wanting to do home banking while at the office.
  • An agency ICU nurse called in at short notice needing to look up patient records. 
  • A homeless person using a mobile phone to claim benefits and pay bills. 
  • Someone on a list entering the USA and being asked to provide their passwords.

Monday, 21 May 2018

Systems of interest for autonomous platforms

The discussion on various autonomous cars, ships, aircraft has generally been focused on the moving platform - by default, or by assumption. It would be helpful to consider the various systems of interest. A very small start has been made by distinguishing UAV and UAS, but we are still at the point where most of the systems of interest do not have names. There are a number of Technical Systems (identified as TSn) and a number of Socio-Technical Systems (identified as STSn). The systems that we need to consider appear to be as follows: 

TS1; The platform (UAV, UUV, driverless rickshaw, robot, etc.). These usually have names.
TS2; The platform plus off-platform 'cloud' (robo-cloud).
TS3; Collective of platforms. Not necessarily a 'swarm' - but a group of platforms working together.
TS4; Collective of platforms plus off-platform 'cloud'.

 STS1; Any of TS1-4 so long as specified plus an 'Operator' who can be held to account. The 'Operator' may be a pilot, Master etc. Near-Real Time situation awareness for the off-platform Operator is only possible with TS2, 4. This system has a name in the case of UAS (only, I think). It is hard to see how a 'car driver' without specialist training can be held to account. The current standard of media reporting has the "driver of a driverless car" being blamed for an accident!

STS2; Any of TS1-4 so long as specified plus Operator, Responsible Owner, Design Authority. This is the minimum system for proper accountability. It needs a name. Note that TS1-4 plus Operator, Responsible Owner has not been included in the list as it is effectively obsolete.

STS3; Any of TS1-4 so long as specified plus Operator, Responsible Owner, Design Authority, Legal Authority, Insurer, Provider of financial legitimacy, Provider of employment and training legitimacy. This is the system that provides the licence to operate. i.e. the 'blunt end' as well as the 'sharp end' in Dave Woods' terminology.

STS4; Typically, 'Cloud' platform operator, financiers.The system that manages the flow of money and information rights. If the 'values' in this system are unethical, then 'value alignment' of TS2, 4 is difficult to achieve (Milo Minderbinder UAVs anyone?). 'Platform' is often used as a shorthand name here, just to add confusion.

Wednesday, 3 January 2018

Getting started with safe internet use

This is written for members of my family who are starting out with PCs on the internet (no comments here about Apple).

Install Webroot WSA - it uses less of your computer power running in the background than other AV tools. Remember to run scans regularly - don't just rely on it working in the background.

Putting your data on a separate 'partition' of the disk to Windows etc. is a good idea and may enable you to recover your data e.g. when Windows dies. If you are new to computers, it is best to get help, even though it is straightforward. This guide seems clear (like much from Tom's Hardware). Make sure your application data (such as email) is on the new partition.

Install CCleaner - this is useful for removing crud from your computer - do regular cleaning, including cookies. It is also good for uninstalling programs, and for choosing which programs you want to run when the computer starts up. CCleaner is also available as a Portableapp (see below).
If you don't want to use CCleaner for some reason, you can set up Windows to remove crud.

This guide is a good introduction to staying safe on the internet.  Read it and then come back here.

Internet security is now so complex, that working out your personal threat profile is probably impossible. Treat security like dieting or exercise. Do the important things first and then keep working at it at a manageable pace.
Now go and read it properly, then come back.

The Robert Graham Project says "I think the most important security precaution is to lie to computers compulsively".  This includes made-up user names, multiple email addresses, fake answers to security questions, and multiple mobile phone numbers. If you think the other side is playing fair, read this (technical, I know).

Security questions are broken - more than you would think. Fake answers (that you record safely!) are becoming essential. The first school Robert Graham went to was &*O)IYHPU&G!!!.
Generating a fake identity can be helped with this.

It is worth remembering that Ross Anderson, Professor of Computer Security at Cambridge, does not use online banking because the risks are all with the customer.

Update: you might want to take the Data De-tox to remove any unwelcome public data about yourself.

1.  Re-using passwords.
Checking for data breaches is very sound advice, and not often given. Do this first and regularly.
Data breach is the main threat for most of us. This is why re-using passwords is such a bad thing.
Google, Facebook, and PayPal seem to take our security seriously. If you can use them as a login, that might reduce the risk. Minimising the number of people with your credit card details is prudent.

Don't let your browser store your passwords and fill in forms - that seems to be broken. See also here. If you have a password manager, it might be as well to disable auto-fill for forms (if it will let you).

My limited experience of a password manager (Dashlane) is mixed.  A book, and a password generator set to give you a readable password (passphrase) might be better to start with. NCSC advice is to use passphrases, 4 random dictionary words or CVC-CVC-CVC style passwords, picked for memorability. Advice from Angela Sasse: "A longer password is preferable overall, but that has its own problems,...More than 50% of passwords are now entered on touchscreen devices, and longer passphrases create a significant burden on touchscreen users.
...Passwords are rarely cracked by brute force. They are mostly captured through phishing and malware, and with those attacks it does not matter how long or complex your password is

Unfortunately, password strength meters (things that tell you if your password is weak or strong) are not good indicators of real strength.

Perhaps a Password Manager for all the unimportant sites, and something personal for the vital ones. Using Charles Dickens might (or might not)be helpful. 1Password now checks whether a password has been breached, which is definitely useful. The fact that this is new and novel shows what a way the security industry has to go as regards usability (or utility).

This advice from NCSC is not bad on password re-use.

Mark Burnett‏: "Always remember the three main authentication factors: what can be easily guessed, what can be left in a cab, and what can be chopped off."

Two Factor Authentication (2FA). Yubikey has not got the idea of usability (yet).  This guide  to it was recommended by Zeynep Tufekci. A good idea if you can get the hang of it (not on day one perhaps). Biometrics (including faceID and fingerprintID) look like being more trouble than they are worth, but if long passcodes for a fully-used smartphone are too hard, then they are probably better than nothing. Barton Gellman points out you can make this less painful with an all-numeric PIN: 11 digits or more provide strong security. Big advantage: you get the big-button number pad on the unlock screen. It has to be a truly random number. Your idea of “random” isn’t. [I am not an expert, but I suspect the randomness required and number of digits is a function of how much you are under threat from major adversaries.]

2. Locking phone
How much do you need to use your phone? Maybe it doesn't need to be a repository for your life. Android phones are not a good place to keep secure matters, whereas iPhones can be ok. Maybe you use a cheap feature phone for some / all of the time? Cheap alternative phone numbers sound a worthwhile investment.

SIM hijacking is a real and frightening thing.  My mobile provider (Three) has security questions that you can set up for when they answer the phone. Well worth doing.

4. Adblockers and browsers
Perhaps use Chrome with a particular Google ID for transactions that matter and a different browser for other matters. Your computer may not support two browsers open at once, because they are so resource-hungry. As regards Adblockers, I use Ghostery, happily. Opera has one built in. Chrome is going to get one fairly soon (from Google). Adblockers are worth it. Read Section C from DecentSecurity here.

5. Backups
Using the cloud helps but remember the cloud is short for 'someone else's computer'.  I haven't used Framasoft but it is an alternative to Silicon Valley. Sort out a device to do backups for any data that matter to you. ("you only need to clean the teeth you want to keep" - same thing with data and backups). Freefile sync will give you more capability than you need, is not too hard to learn, and is blisteringly fast. Also available as a Porteableapp. For important items such as photographs, it is worth investing in 'archival Blu-Ray' - an external Blu-Ray read/write drive is not that dear.

6. email accounts
Go and read the advice again.
Email client: You can use webmail for basic purposes just fine, but an email client means you have the emails on your machine (and can back them up). Chaos Intellect is a great client for PCs etc., it can run on a memory stick, and has a great approach to use on phones, It isn't free, but is well worth it - not least for the quality of support. If you are restricted to free, then the Opera email client might be a good choice. If you are into Chat, it can handle that as well.
You will need several email accounts. A Gmail account makes sense, as everyone has one. If your ISP offers email accounts, that is another. Then maybe Yahoo, or Zoho.  If you start to use Zoho seriously, you will need to pay a subscription, but you could do much worse.
@pogue25 recommends using disposable email addresses when you have to give an email address to a site that is bound to spam you.  This generates them.

Update: Ransomware
If you do get stung and locked out of your computer by Ransomware, then it is possible that the keys can be found here.

MS Office really likes to run macros - the major risk from dodgy email attachments. Unless you really really need it, don't install it. Use LibreOffice instead.
If you are going to be using other people's computers (or the ones at the library) to help you learn, then it may be a good idea to put applications on a memory stick. PortableApps is a bit more complicated to use than having applications installed on the computer - but only a bit - It reduces the demands on the computer and allows you to take just a stick with you. You can also install the Opera browser on a memory stick (or on your computer). It is pretty good, and then it would mean that your bookmarks travel with you easily. PortableApps include the Opera browser and email client but since these are the main applications, it might be worth installing them on the USB stick directly.

Photos on social media
The pace of facial recognition on social media is alarming. The Spartacus Hack may well be worth doing. Just put up some misleading pics and labels.

Further reading
There is good advice here and here. The do's and don't's here are for folk at higher risk than many (including break-ups and stalking), but the more you follow it, the safer you'll be. Advanced material here.

Sunday, 17 December 2017

Does Autonomous = Small?

The Clyde Puffers had a crew of 3 and capacity of about 6 TEU

Wage bills have been a factor driving for ever-larger lorries and container ships. The transport companies have successfully externalised the  knock-on costs of ever-larger ports, depots, and warehouses, and the impact on city streets. Removing the wages bill could open the way to a radical reduction in size. The perennial problems of inter-modality could perhaps also be eased. Changing the scale of logistics could open the way to better 'last mile' operations.

Using cargo bikes to replace or complement vans is an example of the scope for changing scale, and thought is being given e.g. here for the need to standardise small containers (no I'm not proposing autonomous cargo bikes for city centres). Such containers will hopefully be compatible with urban mobility platforms on the lines of M.U.L.E (not the US military MULE project).

Thanks to  @thinkdefence there is a discussion of small container standards; see the section on JMIC. These would be great for mobility platforms but are not for cargo bikes.

The huge electric autonomous trucks being investigated in the USA may have a long-haul role there, but perhaps the real market is for something much smaller.

If delivery drones are ever to gain scale, there needs to be standardised landing pads, preferably palletised and compatible with small scale standard containers e.g. biscuit tins

More speculatively, we can envisage a 21st Century replacement for the Clyde Puffer; small Autonomous Ro-Ro vessels (Damen have some starting points), some Mexeflote where local infrastructure is missing, and M.U.L.E like platforms to local depots.

Operations at this more human scale are likely to be more sustainable, and with lower knock-on costs. The trick will be getting the incentives right for it to happen, supported by timely standardisation.

Monday, 27 November 2017

Turning 'Meaningful Human Control' into practical reality

The Fake News

The ambiguity in 'Meaningful Human Control' (MHC) may have been good for generating discussion but it is no good for system design or operation. Rules Of Engagement are bad enough without adding more ambiguity. Some folk seem surprised that 'ethics' needs converting to a technical matter - how else do they think 'ethics' will be implemented at design or run time? The legal viewpoint is not the only one that matters, and expertise in design, support, operation, training, seems thin on the ground to date. This post attempts to make a start on describing the way ahead and practical issues to be faced.

Doug Wise, former Deputy Director, Defense Intelligence Agency “There are human beings that actually fly the MQ-9 drone – people are actually observing and make the decisions to either continue to observe or use whatever is the lethality that is inherent in the platform. There are human beings at every stage. Now lets assume that at some point the human beings release the platform to act on its own recognizance, which is based on the basic information on the payload that it carries and the information that it continues to be updated with. Then it is allowed to behave in a timescale to take data, process it, and make decisions and act on those decisions. As the platforms become more sophisticated, our ability to let it go will become earlier and earlier.” There will be people involved in all stages of the killer robot lifecycle.  The discussion around killer robots, like the discussion around other autonomous platforms, has an unhelpful focus on the built artefact - the robot itself. As UNIDIR has pointed out, a 'system of systems' approach is needed.

The Good News

"What assurances are there that weapon systems developed can be operated and maintained by the people who must use them?" This question, from Guidelines for Assessing Whether Human Factors Were Considered in the Weapon Systems Acquisition Process FPCD-82-5, US GAO, 1981, might be a more useful framing. Assurance requires a combination of inspecting the design, evaluating performance, and auditing processes (for design, operation etc.). Many military systems need something resembling MHC - aircraft cockpits, command centres etc. In fact it is hard to think of a system that doesn't. Not surprisingly, therefore, there is a considerable body of expertise in Human System Integration (HSI) aimed at providing assurance of operability.

Quality In Use (QIU) is defined as:The degree to which a product or system can be used by specific users to meet their needs to achieve specific goals with effectiveness, efficiency, freedom from risk and satisfaction in specific contexts of use. ISO 25010 (2011). The term is part of a well-formed body of quality and system engineering standards (civil and military) aimed at providing assurance of QIU. In practical terms, this approach is the way ahead (because it exists). Pre-Contract Award Capability Evaluation is likely to be the a useful tool in helping to build and operate systems with MHC.

The Bad News

The reason most people do not recognize an opportunity when they meet it is because it usually goes around wearing overalls and looking like Hard Work.” Henry Dodd
Reliance on coming up with a good definition of  MHC won't work for the folk at the sharp end of killer robot operation. The test of whether good intentions have translated into good deeds will be after things have gone wrong. There is a need to improve military accident investigation (with some notable exceptions). Unless there is good Dekker-compatible practice for accident investigation of smart systems and weapons, more good folk who put their lives on the line their country are going to be used as fall guys. Mock trials with realistic case material would be a good start - overdue really. Sensible investigation of the 'system of systems' is bound to find shortfalls in numerous aspects of both human and technical design and operation. Looking for clear human/machine responsibilities at the sharp end is no more than scapegoating.

It’s generally hopeless trying to clearly distinguish between automatic, automated and autonomous systems. We use those words to refer to different points along a spectrum of complexity and sophistication of systems. They mean slightly different things, but there aren’t clear dividing lines between them. One person’s “automated” system is another person’s “autonomous” system. I think it is more fruitful to think about which functions are automated/autonomous.” Paul Scharre. The critical parameter for automatic / autonomous is 'context coverage' which considers QIU in both specified contexts of use and in contexts beyond those initially explicitly identified. For autonomous vehicles, it is becoming recognised that the issue is not 'when' but 'where'. A similar situation will continue to apply to smart weapons. The safe and legal operation of smart weapons will remain context-dependent.

'Ordinary' automation is usually done badly, and has not learned the Human Factors lessons proffered since the mid-1960's. There are many unhelpful myths that continue to bring more bad automation into operation e.g. 'allocation of function', 'human error', 'cognitive bias'.  Really, MHC of ordinary automation is far from common.

HSI is practiced to a much more limited degree than it should be, so the pool of expertise is smaller than would be needed. The organisational capability to deliver or operate usable systems is very variable in both industrial and military organisations. Any sizeable switch to 'Centaur' Human-Autonomous Teamwork will hit cultural, organisational, and personnel obstacles on a grand scale.
The current killer robot exceptionalism will be unhelpful if it proves to be a deterrent to applying HSI, or if it continues to be a distraction from the wider problems of remote warfare now we have said Goodbye Uncanny Valley.

Back in the days of rule-based Knowledge Based Systems, the craft of the Knowledge Engineer involved spending 10% of the time devising an appropriate knowledge representation and 90% of the time trying to convince engineers that the human decision making approach was not flawed but contained subtleties that allowed adaptation to context, and that the proposed machine reasoning was seriously flawed. With the current fashion of GPU-powered Machine Learning (ML), this may not be possible. Further, XAI (explainable AI) is a long way from a proven remedy for the opaque nature of ML  ML can be brittle and fail in unexpected ways; The claim that the X part of the system will be able to generate an explanation under this circumstance is an extraordinary claim without extraordinary evidence.

Friday, 13 October 2017

Walkable urbanism vs. the Robocar

A developed country is not a place where the poor have cars. It's where the rich use public transportation.” - Gustavo Petro
"Planning for the automobile city focuses on saving time. Planning for the accessible city focuses on time well spent." - Robert Cervero
‏ "In the walkable city, people gather in a piazza, plaza, or square. In the automobile city, they're called...intersections." - Taras Grescoe
 Motocracy (noun, plural-cies) “Government by the motorists; a form of self-governance in which authority/powers of agency is vested in individual motorists and exercised directly by them or by their co-drivers/riders in order to uphold law and liberty on the road.”
"This bill is one of the biggest assaults on 1966 federal safety act that’s ever occurred."- Former NHTSA chief @JoanClaybrook on the AV bill.


For a technology without an obvious customer or regulator pull, robocars are seen as big business. Because of the lack of pull, this is not a sure thing, and indeed we may be seriously past 'peak car'. The temptation to Volkswagenize (cheat) may be  irresistible to the motor industry/ SV combo driving the robocar narrative. The cheat will be to control the environment to make it easier for robocars to operate. The controls on streets and pavements will make towns and cities much less friendly to humans. The controls will be sold as a 'moral imperative' to reduce deaths. Such claims lack any convincing evidence.

Robocars as autogamous technology

 "Autogamous technology; self-pollinating and self-fertilizing, responding more and more to an inner logic of development than the needs and desires of the user community". Gene I Rochlin
Robocars are mostly about money, not technology; keep the share price up in the face of Google and Tesla. "If the driverless economy is imminent, and the endgame is fleets of fully utilized robot vehicles that create radical reductions in personal vehicle ownership, why would a car company be complicit in undermining its own market? The answer is that it wouldn’t. No car company actually expects the futuristic, crash-free utopia of streets packed with Level 5 driverless vehicles to trans­pire anytime soon, nor for decades. But they do want to be taken seriously by Wall Street as well as stir up the imaginations of a public increasingly disinterested in driving. And in the meantime, they hope to sell lots of vehicles with the latest sophisticated driver-assistance technology."
Pew research has shown the lack of customer pull for robocars: "In the case of driverless vehicles, 75% of the public anticipates that this development will help the elderly and disabled live more independent lives. But a slightly larger share (81%) expects that many people who drive for a living will suffer job losses as a result. And although a plurality (39%) expects that the number of people killed or injured in traffic accidents will decrease if driverless vehicles become widespread, another 30% thinks that autonomous vehicles will make the roads less safe for humans...Nearly six-in-ten Americans say they would not want to ride in a driverless vehicle ."
MIT research has found that people don't really want robocars: "The 2017 data suggest a proportional shift away from comfort with full automation. Across all age ranges, a lower proportion of respondents were interested in full automation when compared to 2016. This trend was particularly notable for younger adults aged 16-44. A higher proportion of respondents indicated comfort with systems that actively help the driver, without requiring the driver to relinquish control." Follow the money
Big motor has its eyes on some high value income: "The worldwide auto industry took in $2.3 trillion in revenue in 2016, but revenues associated with mobility services—a term the covers everything from Uber to traditional taxis and buses—totaled $5.4 trillion."

GM has said the autonomous vehicle and mobility business could be a potential $7 trillion global market.
The "Passenger Economy" is likewise reported to be a $7 trillion market  " A recent study conducted by Strategy Analytics for Intel estimates that the "Passenger Economy" created by the advent of autonomous vehicles will swell from $800 billion in 2035 to a whopping to $7 trillion by 2050, driven by services such as robo-taxis, automated delivery of everything from pizzas to prescription drugs, and captive marketing to idle car occupants."
  There is a 'billion dollar war on maps'  where the emphasis on robocars may be to our collective detriment.

Options for the way ahead

Consider two competing narratives for the future of urban mobility.
1. Networked urbanism (see) where cities are driven by big data analytics and networks controlled in part by machines. The 'smart city' as technological solutionism, with everything connected, automated, and lots of big data. You might expect the car makers to be happy with this as a future, but the bad news is,  even here, car ownership and use may fall. Ouellette on the reinvention of urban space: "If, for example, your existing urban space reality is Rob Fordian—one where cars rule while pedestrians and cyclists serve—then that model is about to be turned on its head. Car culture as the macro force of cities is on the way out. Waiting in the wings are an ever-increasing number of smart, digital technologies working synergistically to make the auto-centric urban model obsolete."Networked urbanism can be dressed up as faster, smarter, greener, but it is still pushing the corporate panopticon into our streets and lives. Big business likes AVs but needs to make long-busted claims about V2V to assemble a case.
The life in such a world sounds like that of the 'insiders' in A Very Private Life by Michael Frayne. A life tended by the kindness of corporate automata.
2.On the smart citizen side of the street, there is walkable urbanism - the "Life Sized City". This is gaining in popularity round the world. Paris for example “journee sans voiture” . "The car-free day fits within a comprehensive strategy to improve mobility while reducing motorized traffic. Hidalgo and her predecessor, Bertrand Delanoe, have enacted bold policies to prioritize transit, bicycling, and walking on city streets, resulting in a 30 percent drop in traffic over 10 years." Change is coming to the streets of Motown - alternatives to cars are going to be right in the face of the good ol' boys, and Copenhagenize Design Co has designed the bike infra network for City of Detroit.  Cities are starting to end the dominance of the traditional car, and word of the success of Copenhagen and the Netherlands is spreading. Resources for walkable urbanism are being supplemented by resources for cyclable urbanism e.g. Velotopia.The real disruption is the bicycle not the robocar.
The benefits of urban bike infrastructure are being recognised for business here  for traffic flow here, and for health here and here. A summary of ten reasons for reducing car dependency is here. Progress down this route is non-linear: "Getting from 0 to 5% bike mode share is really hard. Getting from 5 to 15% is a piece of cake." - @copenhagenize. "There are 3 million pedelec bikes in use in Germany. 3.7% of population. Adoption about to enter hockey stick...3.3 million Ebike units will sell in 2023, Europe. (2 million in 2016, 100k in 2006).." Horace Dediu‏ @asymco.
So far, progress has been largely out of the public eye; reaching 2 million EVs met with huge publicity, but 200 million eBikes in China alone is invisible. In India,  "Today, India has over 25 million four-wheeled cars, jeeps and trucks registered to private owners, escalating by about 2 million new vehicles every year. The same data registry of 2013 by the Ministry of Road Transport also recorded more than 130 million two-wheelers plying on Indian roads. A staggering number by any measure, and greater than the number of four-wheelers by a factor of five."
 Dockless bike hire has real potential, and big money behind it.  "For all the talk of autonomous cars transforming cities it’s entirely possible that another high-tech form of transport – free-floating rental bicycles – could get there first. ...  In China, a dockless bike-share boom is reducing car use in cities and even leading to forecasts that less fossil fuel will be burned in the future. "
Walkable, cyclable urbanism might look unstoppable, but its threat to the motor industry and the big data corporates is likely to bring a response.

People are messy, and difficult for robocars to deal with

"The randomness of the environment such as children or wildlife cannot be dealt with by today’s technology" - Markus Rothoff, Director of Autonomous Driving, Volvo
Apart from Volvo's trouble with kangaroos, there are many aspects of robocar / people interaction that are difficult, see here. Robocars need to interact with e.g. pedestrians. This is difficult, expensive, and culturally alien to the nerds building the cars (Cefkin at Nissan is a rare anthropologist in the business).  In robocarland, nobody can hear you scream: It’s No Use Honking. The Robot at the Wheel Can’t Hear You "If the cars drive in a way that’s really distinct from the way that every other motorist on the road is driving, there will be in the worst case accidents and in the best case frustration," he said. "What that’s going to lead to is a lower likelihood that the public is going to accept the technology."
The cheat is: Just get rid of the people around cars, so you don't need to solve these problems. 

The cheat is coming - they are after our infrastructure

"If you doubt self-driving cars are coming, you haven’t paid attention to the rate of human ingenuity and technological progress. Conversely, if you believe more than 1% of the statements coming out of Detroit, Germany, Japan and Silicon Valley about when they’re getting here, you’re as deluded as their investors. The question isn’t when, it’s how and where." Alex Roy
"There are fourteen major car companies in the world. No one believes they can all survive, and Morgan Stanley believes only five or six will. The big ones are hedged against any delay in the adoption of self-driving cars." Alex Roy

An example of the 'moral imperative' being used to destroy walkable urbanism (and much more) is here. The slippery slope starts with 'modest changes' of course. "In summary, safe autonomous cars will require modest infrastructure changes, designs that make them easily recognized and predictable, and that pedestrians and human drivers understand how computer driven cars behave." All for benefits that are vapourware.
There are reports of dedicated infrastructure already. "In the new report, the group says this transformation will occur in three stages. First, AVs will be allowed to share HOV lanes. The study’s authors say that this phase could be implemented today and note that California law already allows self-driving cars to use carpool lanes. Step two would involve creating a lane dedicated to AVs. Step three: converting all I-5 lanes to be used exclusively by self-driving cars."
The vision of a people-free dedicated robocar environment is being set out  "For example, when all riders are focused inward and the driving is handled by a sensor network, indicators like road signs, brake lights, and lane separators become unnecessary. If there are no human drivers, we won’t have a need for these visual guides... With awareness of approaching vehicles and traffic, intersection traffic lights become less necessary. Night sensor driving reduces the need for streetlights on highways. Road signs and lanes disappear, with roadway intelligence built into vehicles. Highway lanes expand and contract automatically for high-traffic times. Autonomous-only highways allow for much higher rates of speed.."
Completely unfounded expectations of AV performance and safety being used to influence infrastructure. For example   "Currently the average safe driver leaves ‘one car length per 10 miles per hour’ between vehicles (at least they have been taught to do so) but the automated (and autonomous) systems can react much faster than humans and can therefore safely travel much closer together. As a larger and larger percentage of the vehicle fleet becomes capable of safe travel in less space, the real capacity of the roadway increases. As the demand for highway infrastructure is predicated on the safe traveling distance under human control and traffic and revenue predictions are based on these assumptions, highway capacity manual assumptions will be increasingly inadequate as autonomous features are introduced. " This article combines unfounded claims with moral blackmail "Every day that goes by without driverless cars, people die. The truth is that humans are bad drivers, and driverless cars are safer. To ensure that we reach mass adoption as soon as possible, we need to sort out these issues of trust," Since we don't have driverless cars yet (or even safety requirements for them) this claim is unfounded and is being used to sell big business and technology. Also, he hasn't got the Alex Roy message on 'trolley problem' nonsense, saying "In other words, manufacturers must choose whether to make morally utilitarian cars, or preferentially self-protective ones."

The pavements / sidewalks will not be free, either.

Do watch this video testimony about a delivery robot on a railway platform.
This Guardian article is good on delivery robots:“If there really were hundreds of little robots,” Ehrenfeucht said, “they would stop functioning as sidewalks and start functioning more as bike lanes. They would stop being spaces that are available for playing games or sitting down.” Ehrenfeucht pointed out that 130 years ago, streets were not yet divided into lanes for traffic, parked cars, pedestrians and bikes, and that the introduction of robots to the streetscape might require a reimagining of the available space, possibly with a designated lane for robots....Sidewalks are often a hotly disputed space, and conflicts are bound to arise as new uses are proposed. Many cities across the US have adopted sit/lie ordinances, which criminalize resting or sleeping on the sidewalk and are generally considered to be targeted specifically at homeless people. At the same time, urbanists have tried to promote new uses of sidewalk space with features like “parklets”. ..“We really see this as a privatization of the public right of way,” said Nicole Ferrara, executive director of pedestrian advocacy group Walk San Francisco, who wants to ban robots from the sidewalk. Ferrara argued that walking has social, health and economic benefits, while robots could pose a hazard to senior citizens and people with disabilities....“We’re not excited about the idea of engineering walking out of our lives,” she said. “People live in urban centers not because they want to sit at home in their house and have their toothbrush delivered to their door, but because they have a pharmacy around the corner that they can walk to.”
A welcome (and rare) sight was an article pointing out the risks of robocars...."there has been very little public discussion of whether selfdriving vehicles will coexist or collide with long-standing principles of accountability, transparency, and consumer protection that collectively constitute the Personal Responsibility System."
Further reading on the moves underway to rid the streets of people are here and here. A tinfoil hat may be required, but the arguments are highly plausible.


 Robocars are part of the tech utopia nobody wants, but there is money and momentum behind them. The solutionism is at work co-opting good causes to make robocars critical to their lives.
If we want walkable urbanism (and we should), we will have to make a stand.