Σάββατο 1 Απριλίου 2017

7 Personal names on the surface may appear to be well defined and legally regulated, but in practice they show an amazing diversity (especially in multicultural settings) that make formalizations deeply problematic. See http://www.kalzumeus.com/2010/06/17/falsehoods-programmers-believe-about-names/ for an interesting discussion about the real-world problems of assuming anything about what a personal name “is”. 2. Inform The adage “ online medi new forms o setting of hu Online id Social networ just 25 contac but it is relati they were sho Online iden accounts an addresses, a other online Many of the of different eBay profile The Facebo reflecting di persona may known to B mation an “on the Inter ia allow a hig of identificat uman face-to dentities rk of contacts a cts, they in turn ively easy to de ot, and commen ntities are bec nd online per a Facebook o e products an ese identities online servic e, showing th ook account m ifferent aspe y be less inte Blizzard Enter nd commu net nobody k gh degree of tion, docume -face commu and contacts-of n have 4442 co educe much p nts made on va coming incre rsonas. For or Google+ a nd services, s are interlinke ces. A PayPa e transaction might serve t cts of her li egrated with rtainment; an unication knows you ar anonymity a entation and unications and f-contacts of on ntacts. Within ersonal inform arious topics. easingly impo example, an account, an iT uch as the m ed. An email al account wi n history of th to tie togethe fe – hobbies an individua nd the gaming technolog re a dog” has and the possi tracking. No d private/pub ne of the autho this forum ide mation from the ortant. Man n individual Tunes accou massive multip l address may will be linked he user and t er many diffe s, sports, frie al’s offline id g persona ma gies s always been ibility to set u ormal intuitio blic environm ors on the phot entity is mostly e content of th ny people in might have unt, an eBay player online y be used as a to a bank ac he reputation erent commun ends, family, entity, but is ay itself have n of doubtful up alternate i ns about ide ments, are unr to-sharing site y defined by sh he images, loca today have a PayPal acc account, and roleplaying g a username o count, and it n she has acq nities of whic and work. at least tied e various disti l veracity. W identities, th entity, honed nreliable onlin e Flickr. While hared photogra ation and time a variety of count, a cou d subscription game World or password f t might also quired as a bu ch a person i The World d to the custo tinguishable i 10 While modern ey also allow in the social ne. the author has aphic interests, data of where distinct user uple of email ns to various of Warcraft. for a number be tied to an uyer or seller. is a member, of Warcraft omer identity dentities as a 0 n w l s , e r l s . r n . , t y a 11 participant in guilds and other friendships within the game.Some identities are deliberately fragmented. People regularly try to separate their work email account from their private account, often extending this to phone numbers and other ways of gaining access. Parents often instruct their children to never reveal their real names and addresses online. Online game characters or forum identities may be ways of ‘letting off steam’, and hence may require keeping them distant from the main social identities of their creator. This is in many ways a natural extension of our existing separate social personas, projected into online media. Maintaining this kind of separation requires not only the right technology but also some social and mental discipline, keeping the personas distinct. With the proliferation of identities – online as well as offline – growing demands are being placed on identity management systems and on the skills of the citizen. Identity management systems are the software (and institutional) systems that create and keep track of digital identities, as well as connect them to the attributes of their identity (such as resources they can access). These systems can range from simple password protections to complex systems maintaining traceability, data integrity, privacy, preferences, parental and institutional controls and interfaces to other identity management systems. However, unlike social identity management (i.e. how we act among other people) such systems are often inflexible and completely prohibit unplanned uses of identity (which often leads to users finding workarounds that might undermine security) while at the same time missing undesirable activities: they are ‘brittle’. There is little doubt that finding better forms of identity management is going to be a major research and investment area over the next decade as more and more people come online across the world and use new kinds of services. There might not just be competitive advantage in the right kind of identity management, but important social effects. For some identities, it is important that they can be tied in a verifiable way to the legal identity of a person. A PayPal account needs to be linked to a bank account, and the user must verify their identity and that they are the holder of the bank account in question. For other identities, the user might prefer that they be dissociated from their legal identity or entirely anonymous. Online anonymity can be an important component of personal privacy. For example, an individual maintaining a blog in which they expresses politically unpopular views, suffering a serious disease, or opinions that are critical of their employer may suffer grave repercussions if they lose the veil of anonymity. Hiding an identity is an aspect of privacy, but privacy is actually about controlling who can access an identity, not prevent all knowledge of it. Privacy is not absolute – there are sometimes ethical or legal reasons to limit it – but it is often highly desirable that people can control how their identity can be observed or used. Yet, from a practical standpoint enforcing privacy protection can run into the problem of getting the designers of new systems to build it in, making existing widespread systems privacy compliant, handling data that exists in a distributed but collectable form, enforcing the intended protection, avoiding making enforcement so costly that it prevents technological innovation (while Google can afford privacy compliance officers it is unlikely that a small start-up or open source hobby project can), and – perhaps most problematic – making the privacy protection fit the actual social norms of privacy. Given that actual privacy norms vary enormously between groups and develop organically it is likely that any formal system of privacy protection will be lagging social and technological change. “NightJack”: police blogger unmasked The police blog “NightJack” won the prestigious Orwell Prize for political writing 2009. The blog often expressed critical views related to the police and justice system. The author, a Lancashire detective constable, was unmasked by The Times after a landmark High Court ruling that stated that blogging was “essentially a public rather than a private activity” and that it was in the public interest to know who originated opinions and arguments. As a result, the constable was disciplined by the police force. This case illustrates the complicated relation between freedom of speech, accountability, anonymity, and risks of reprisals. 12 Trouble can also arise from inappropriate linkages between different snapshots of a single identity across time. A teenager may post pictures and make statements that later prove embarrassing – and, as recruitment officers increasingly Google job applicants, even career-hampering. In this case, a problem arises if people regard the earlier online expressions as relevant manifestations of an unchanging character. While information gleaned from researching a candidate online can often be relevant and highly useful, there is also a risk of self-fulfilling prophecies. If the person is shunned by employers because of something they have said or done, they may be unable to establish a track record to rehabilitate their reputation as a good employee. Furthermore, with the increasing persistence of identity-relevant information online, one cannot rely on the past being forgotten; it will, in some cases, instead have to be forgiven8 . These linkages also include the shadow of the future: in the future much of our present information will be available to people with vastly larger computational resources (making many current forms of encryption or security weak) and different values. While some of the uses they will put our personal information to will be neutral or positive from our perspective, others might not be so benign. Long-lived politicians today have to explain past policies that seemed to make sense at the time they were made but today appear deeply racist; in the future we might be similarly be held accountable for views or activities we currently find entirely moral. Worse, there is no guarantee that this information will not eventually be used by future governments or groups of ill intent. The claim that “if you have done nothing wrong you have nothing to worry about” presupposes that the accepted criteria for ‘wrong’ will remain the same. The response to this problem might not be to attempt to amplify privacy, but rather to recognize that the need to safeguard open societies and human rights grows with government power over individual lives. One particularly pernicious current possibility is online character assassination. The practises of libel and slander are as old the human species, but the online world offers new opportunities for their efficient implementation. It is easy to post material online anonymously, and material thus inserted may remain available for a very long time and the proficiency of the search engines will ensure that anybody who looks for information about the victim will be presented with the slanderous assertions. Even if the victim obtains a court injunction it may be difficult to remove the offending material, which might be posted on servers located in foreign jurisdictions. If the false information has spread it may even be impossible for the perpetrator to remove it from the net. There is, however, at least one important mitigating factor: just as the Internet makes it easier to disseminate slander, it also makes it easier to publish a rebuttal and to ensure that it will be seen by the relevant people. Unfortunately smears can be stickier than the truth: developing technologies and habits that help uncover slander is a major challenge for future social technology. Identity metasystems 8 The EU Commission draft framework for data protection policies famously states that people have a “right to be forgotten” (or rather, their personal data). The “Social network users’ bill of rights” http://cfp.acm.org/wordpress/?p=495 also includes “the right to withdraw”. Both documents however assume the personal data resides within the domain of some actor who can obey legal or customer demands. If personal information can be collected or inferred from the other information available online these rights may be of little use. The current legal case against Google in Spain where plaintiffs demand references to them to be removed from the search database is a case in point: even if it succeeds, it will not remove the references from other search engines, or from emerging future tools. http://news.yahoo.com/s/ap/eu_internet_right_to_be_forgotten 13 While digital identities within single systems are useful, it is common for people to wish to maintain their identities across many systems and institutions, ideally without having to authenticate themselves in countless different ways (consider the issue of password-re-use). Identity metasystems are interoperable architectures that allow users to manage collections of digital identities. Key roles within the metasystem are identity providers (issues digital identities), relying parties (entities that require identities, such as online services) and subjects (entities about whom identity claims are made, such as users, companies and organisations)9 . Existing examples are the identification systems sponsored by Microsoft (Passport), Yahoo, Facebook and Google where a single login gives access to many web services. A possible future example would be a metasystem linking a person’s legal identity, various email addresses and a bank account so that commercial and government relying parties could transact official business (e.g. paying taxes, making official requests, signing online contracts). At present few widespread identity metasystems exist. There are economic, technical and legal problems that need to be overcome. A likely scenario is that as society becomes more integrated online the demand for identity metasystems increases (due to the cumbersomeness of fragmented digital identities) and, since there are clear economies of scale, consolidation and competition leads to a few or a single metasystem. These global metasystems could very well be under the control of private foreign companies who would have unprecedented control over digital identity. Government-sponsored metasystems also pose interesting problems, as the globalisation of the digital world would mean many non-citizens would wish to join the national metasystem, essentially becoming digital subjects. However, past attempts at creating “federate authentication” have often failed, largely due to mismatched incentives between the stakeholders. In particular identity providers need to assume some liability, relying parties need to benefit from the system and users had legitimate worries about a single point of failure – if their master online identity was subverted, they would risk significant trouble10. If these issues can be solved (perhaps more a business problem than a technological one11) we might see the emergence of global metasystems; if not, online identities will continue to be fragmented. 9 While this structure was originally proposed by Kim Cameron at Microsoft Corporation (The Laws of Identity, 2005, http://msdn.microsoft.com/en-us/library/ms996456.aspx ) and is currently used in various implementations, the concepts of identity providers, relying parties and subjects is useful for our discussion regardless of their origin. 10 Ross Anderson, Can we fix the security economics of federated authentication? http://spw.stca.herts.ac.uk/2.pdf 11 J.D. Lasica, Identity in the Age of Cloud Computing: The next-generation Internet's impact on business, governance and social interaction, The Aspen Institute, 2009 Sorry, we’ve spilled your secrets The October 2007 loss of two disks containing child benefit data is just one example of how large data breaches can occur relatively easily. The discs, containing names, addresses, dates of birth of children, National insurance numbers, and bank details of approximately 25 million people in the UK, were sent by junior staff at HM Revenue and Customs to the National Audit Office as internal mail and were lost. No data fraud or identity theft appears to have occurred as a result of the loss. In January 2009 a security breach in Heartland Payment Systems (a US company) compromised up to 130 million credit cards. In this case a computer criminal was indicted for the attack, which had a clear profit motive. Other data leaks of note are the August 2006 AOL release of 20 million Internet search keywords that could be linked to particular users, the November 2008 leak of full contact details of British National Party activists and the 2010 Wikileaks “Cablegate” of 250,000 US embassy diplomatic cables. Each of these represents the loss of control over important aspects of identity (financial, interests, political views, international association), and were due to simple Identity pro personal inf identifiable involving te and as the n Identity met increasing ri Rate of repo accidentally r Control ov Press freedo propped up television ch of the Intern under press broader issu the issue o Approximat 2010, and th current pos communicat 12 India is pla http://www.t oviders have formation. B information ens of million number grows tasystems mig isks for sudde orted data los revealed. Data ver social sp om and own p by subserv hannels that a net, online m ure will be t ues of censor of the owne tely one half his number w ssessor of w tion and for t anning to issue timesonline.co a responsibil But as shown has been ac n or more pe s of online id ght if implem en, correlated sses (worldwid from http://da paces and i ership of the vient state-o are controlled media are bec tempted to r rship, which f ership of so of the UK p was rapidly g what is per the expressio e each of its 1.2 o.uk/tol/news lity for mana n in the figu ccidentally or eople are cur dentities a per mented badly d outbreaks o de) 2005-2009 atalossdb.org/ dentities e media are i wned media d by individu coming essen egulate or m fall outside th cial space, w population cu growing). T rhaps Britain on of individu 2 billion citizen /world/asia/a aging identiti ure below, th r maliciously rrently regula rson possesse amplify such of fraud or sa where person / important iss a, and some uals who are c ntial forums f manipulate th he scope of t which is no urrently uses This makes Fa n’s largest u ual identities. ns with biome article6710764 ies appropria he number of y disseminate ar occurrence es, such large h risks, limitin abotage that c nally identifyin sues for dem times also b close to the r for political d ese online fo this paper. A ow often co Facebook (th acebook, a fo unified socia etric ID, the M .ece ately, especial f reported in ed is very hig es. As larger breaches wil ng the usabili could affect a ng information mocracy. Ma by privately regime. With debate and ac orums. We Attention mu ncentrated i he UK had 2 oreign-owned al space for Multipurpose N lly when the ncidents wher igh. Even v r databases co ll become mo ity of global i a society deep n has been s any a dictator owned new h the growing ctivism. Regi will not here ust be drawn, in a few pr 26 million use d private cor r individual National Identit 14 ey are tied to re personally vast breaches ome online12 ore common. identities and ply. stolen, lost or rial regime is wspapers and g importance imes that are e discuss the , however, to rivate hands. ers as of July rporation the and public ty Card. 4 o y s 2 . d r s d e e e o . y e c Owners are of expressio or by disallo influenced: information to prevent b Many online discussion th implicit enfo to ‘safe’ top one’s online This can inc writing incr especially in precludes de Users often to cancel pla are likely to 13 Data from 14 Greg Last freedom of sp 15 http://www free to regul on and identit owing them controls ove can be linke bullying or se e games prev hreads, uploa orcement of pics without a e identity can clude control reasingly dem n cases of un eliberately an feel strongly ans to retain be contested http://www.f owka, Virtual peech in massi w.guardian.co.uk late social spa ty14. Overt e from signing er the kind o ed to what ot xually explici vent avatars a aded materia what is perce any formal (o be threatene ls on what ki manding that nusual handle onymous or y about their user data eve d, the more so facebook.com/ l Justice, Yale U ively multiple k/technology/20 Activ aces in nume exclusion of c g up) is a cru of content th ther informat it messages b and usernam l, groups or eived to be th or legally cha d by stepping inds of identi t users prov es. This is no fragmented i online identi en after they h o the greater /press/info.ph University Pre on-line role pl 009/feb/19/fac ve Facebook us erous ways, co certain peopl ude way. Th hat can be p tion. For exa by forcing com mes seen as u users can be the unstated r allengeable) r g out of line. ities users ex ve that their ot just linking identities. ities. After st had left the n the space’s im hp?timeline ess, 2010, Pete laying games, J cebook-persona sers13. ontrolling bo le or groups here are many posted, how ample, some mmunication nsuitable or deleted if th rules of the o regulation, jus xpress. Faceb screen nam g online iden trong protest network15. Ru mportance to er S. Jenkins, Journal of inte l-data oth what valu (either by mo y more subtl identities ca social spaces n through a li copyright inf hey are seen a owners. This st the chilling ook and Goo mes correspo ntities closer ts from its us ules governin o its users. The virtual w rnet law vol. 8 ue is created, oderators rem le ways the s an be expres s for kids hav imited pre-se fringing. Th as unsuitable can limit fre g effects of k ogle+ are at ond to their to legal iden sers Faceboo ng the use of world as a com 8:1, july 2004 15 and freedom moving them space can be ssed or what ve attempted t vocabulary. he threat that e also acts an ee expression knowing that this point of real names, ntities; it also k was forced social spaces
Online identities will be growing rapidly in importance and will raise a plethora of issues. They are sometimes formalizations of social identities but are fundamentally more rigid. This (and the large number of online services) leads to people using multiple identities. Linking multiple identities to a legal identity and across time and domains can cause problems, in the form of breaches of privacy, risks of identity theft, damage to reputations, and reprisals. Gathering identities into identity metasystems can solve some of these problems but at the expense of posing new challenges such as border-crossing identity systems of unclear jurisdiction, massive data breaches, and expanding the power of identity providers over the identified and their social interactions. Virtual worlds – be they online games, social spaces or teleconferencing, will grow in reach and use. Users feel strongly about their online identities and want control over them despite weak legal protections. Successful social spaces allow negotiation between users and the maintainers. As online identities become more important it is likely that formal legal protection for them will be needed, yet it will be hard to implement effective enforcement and avoiding strangling social and entrepreneurial creativity. The augmented world and exoselves: In the words of one author, the generation growing up now will “never be alone, never lost, never forget” – the constant connectivity holds together social networks regardless of location, location services makes everything findable, and life recording allows the storage of representations of a large part of life. The resulting extended memory is likely to have significant effects on personal identity: parts of identity will reside in a persistent “exoself” of information and software. Life recording will also likely to synergize with social networking into seamless “life sharing”. The limits of privacy will be pushed as a generation grows up with this technology. Even if the average person in 2025 is not using full lifelogging, many of the functions being explored today will likely exist in the background of their technology. Identity technology: Not only humans but objects are gaining persistent, traceable identities. RFID-tags and other methods will give many objects a much richer identity, allowing them to be identified not just as belonging to a category but also as individual objects, possibly without direct touch. Similarly, biometric identification and data fusion – the combination of evidence from several “senses” – will make automatic remote identification of people easier (especially since they might carry a recognizable constellation of RFID tags and a smartphone). Thanks to rich databases and new probabilistic algorithms, identity resolution (constructing a persistent identity from various records) is increasingly feasible. Such systems can allow wide-ranging transparency and accountability, but also threaten privacy and secrecy. Finding the proper regulation and social norms for a nearly totally identifiable society will be a major process over the next 15 years. Automation and robotics will have broad but diffuse impacts on various aspects of identity, mainly by gradually changing the nature of work and impacting labour markets. These effects will represent a continuation of long-term trends that have led to urbanization and to a remarkable growth of the service sectors of advanced economies. Both IT skills and people skills will be in demand on the labour market. Careers will become 5 more fluid, and it will be important for the country to have a work force that is adaptable and that can master new skills as need arises. A major breakthrough in artificial general intelligence could have extremely profound implications for society and for many aspects of identity; however, this must be regarded as a unlikely possibility within the given 15 year timeframe. Medicine and personalized health are not only about health but also about the expression of social identities. This function will become increasingly prominent as preventive, diagnostic, and enhancement medicine grow in importance. Eating healthy and exercising – or not – are choices that people make not only because of health effects but also to maintain a certain social identity. Diagnostic medicine (and genomics) will expand the medicalization of self-conception. Enhancement medicine, too, is focused very much on social identity and self-expression rather than merely on health and biological capacity narrowly construed. It is paramount to consider these identity-related dimensions of medicine if we are to understand how and why people will be consuming health care resources in the future. Life extension may lead to new forms of age identities, where people no longer identify with traditional age groups. Genomics raises many important identity-related issues; in fact, an entire report could be written on these issues alone. Some of the main issues include: (1) changes in self-conception as a result of knowledge about the personal genome and how it correlates with life outcomes; (2) general changes in conceptions of human nature and human identity as a result of better understanding genetic causation (advances in neuroscience also act in the same direction); (3) the possibility that genomics will reveal significant differences between ethnic groups (or differences that some will interpret to be significant) - this could have important implications for ethnic identity; (4) genetic privacy will become increasingly hard to safeguard, thanks to cheaper gene sequencing and methods such as PCR amplification that allow even a small sample (such as a skin flake or a hair follicle) to produce enough genetic information. This latter implication is especially worth highlighting. The medicalization of conception, embryo selection, and (over time) genetic modification will have important effects on individuals - most obviously on individuals who would not have come into existence were it not for these procedures, but also on parents whose reproductive lifespan is extended, and eventually on wider society. The more radical possibilities of genetic modification are unlikely to come into significant use within a 15-year timeframe; however, they may become extremely important over the longer term. Drug-use will continue to be a significant identity-related issue, and it may be joined by new concerns over novel pharmaceutical neuroagents. There are speculations that e.g. neuropeptides could be developed that could be distributed as aerosol and used for neurological manipulation. Invasive brain-computer interfaces are unlikely to have widespread impacts on identity within a 15-year horizon. Non-invasive interfaces, such as various brain-scanning techniques, could have important effects if reliable and practicable techniques for detecting deception were to be developed (though this appears somewhat unlikely within the given timeframe). In addition, brain scanning technologies might have effects on public perception through fears about loss of neural privacy and as a result of mistaken “neurohype”. A long lived, multigenerational society: Longer lifespans will lead to changes in how people regard their identity as aged people, as well as increased diversity in how age-related aspects of identity are managed and in cultural expectations. Intergenerational conflicts can erupt if institutions and social norms do not adapt to a generationally, culturally and technologically diverse society. New technologies may accentuate the vulnerability of certain groups: people who are outside identity systems, people who need certain forms of privacy, people unable to handle the growing complexity of identity, people who are victims of identity theft, and people with persistently ruined reputations. Developing methods for identity rehabilitation might be important in order to reduce the risk for vulnerable groups. 6 7 1. Introduction This paper reviews some of the possible impacts on identity from three broad fields of technological advancement: biotechnology; automation and robotics; and information and communications technologies. We consider a time horizon of 15 years, with the occasional glance towards development further down the road. For each of the three areas covered, we briefly review and evaluate technological advances that might plausibly be expected within the 15 year time frame. We then seek to illuminate the potential impacts that these development might have on social identity, and we identify and highlight developments that are of particular relevance for governmental policy and that present novel risks or opportunities for policymakers. Personal identity being an extremely multifaceted concept, we will not attempt here to furnish an exact definition. We will use the term “identity” to cover a number of loosely related notions, including the selfimages and reputational capital of individuals, social and formal identifications, perceptions and prejudices related to social group membership, software representations of identity, and more broadly changing views of human nature. We will accept a degree of indeterminacy in the concept of identity itself, and put the focus on presenting what seems to us the most interesting and policy-relevant insights in the general neighbourhood of the concept of social identity. The concepts of identity Identity has many meanings in different domains, and in this report the following are relevant: Much analysis of identity has been done in philosophy, in particular focusing on identity as persistence of something, as being definable, recognizable and in particular the issues surrounding personal identity. The philosophy of personal identity is a large field, but some of the key questions include whether there is a persistent identity over time, how important personal continuity is, the relation between numerical identity (being the same person) and qualitative identity (being similar to a past or future self), the links between our minds and bodies, and whether there even exists a self. In psychology personal identity is linked to our experience of being someone (a “core self”) and our sense of being a particular person with a past, future and various attributes (a “narrative self”). The narrative identity is gradually built up over the lifespan and plays an important role both in living a meaningful life and fitting into a social context. Both kinds of selves can be impaired or modified in different ways: meditation, certain drugs and the Cotard delusion2 can change the sense of core self, while amnesia and false memories can transform the narrative self. Deliberate modification of the self, using internal and external means is an important part of human life and adapts new technologies rapidly3 . In fact, it may often be a driver for new technologies – cosmetics, plastic surgery, social media etc. Psychological identity shades over into social identity. Social identity involves aspects such as the different personas (social roles) people take on in different contexts, how people identify with group identities (as well as sexual, gender, and cultural identities) and how these are used in various forms of expression and affiliation. People maintain a rich structure of social identities, often keeping them separate. Each of these identities has attributes, roles and norms within their social contexts4 . 2 A rare neuropsychiatric disorder where the victim believes that they are dead or do not exist. 3 Robert J. Weber, The Created Self, W.W. Norton & Company, 2001. 4 Helen Nissenbaum, Privacy in Context: Technology, Policy, and the Integrity of Social Life. Stanford University Press, 2009, p. 132 A particular formal rules in more than Another imp person is of fully guaran biometric p twins sharin authenticatio their freedom information Digital iden a computer that the user the online n Digital ident aspect of dig claim to be identities, a identifier. authenticatio 5 Different fa something you that for a posit J.B. Robshaw 2004, http://w 6 Kim Camero http://www.id r kind of soci s of society. n one country portant form ften taken for nteed: psycho roperties can ng DNA), an on it is also i m, making u or control o ntities are di user’s digital r can log in t name and the tities exist wi gital (and ma e 5 . This is i although typi In the term on to subject actors of authen u have, or somet tive identificatio and Scarlet Sch www.bis.gov.uk/ n, The Laws of dentityblog.com/ Digital id ial identity is An increasin y. m of identity i r granted and ological ident n sometimes d in cyberspa intrinsically li use of bodily ver the perso igital represen l identity link to the system e computer sy ithin identity any other) ide important sin ically within minology of ts, which can ntication are u thing you are” (f on at least two, hwiderski-Grosc /assets/bispartn Identity, Micro /stories/2005/0 dentities. From the legal id g number of is bodily ide d used as the tity can chan change or b ace bodies ar inked to man identity sens on. ntations of re ks a password m using the p ystem can ke y manageme entities: the a nce many of the same s “the Laws then be used sed to establish for example a pa ideally three, fa che, Identities a ners/foresight/d soft Corporatio 05/13/TheLaws m http://en.wik dentity, the c f people have entity. The as foundation f nge drasticall be confusing re not availab ny attributes sitive in many eal-world enti d, an online n password and eep track of w ent systems ability to assu f the attribut system each s of Identity d by relying h authenticity, assword, an ID actors should be and authenticati docs/cyber/iden n, 2005, sOfIdentity.pdf kipedia.org/wi concept of a e several legal ssumption th for biometric ly (e.g. fugue g (e.g. people ble. While th of the perso y application ities that link name, and ow d access the fi what activitie that keep tra ure other ent tes of digital identity nee y”6 , identity parties (enti typically expres card, or a finge e verified. For a on, Cyber Trus ntities%20and% f iki/Identity_m (natural) per l identities be hat one body c identificatio e states, som e losing their he body can b n (health, ge s because of a number of wnership of v files, other us es occur relat ack of them. tities that one l identities ca eds to have y providers ities that need ssed by the fo rprint). Security an overview of t & Crime Prev 20authenticatio management rson encomp ecause they li belongs to o on systems. Y me religious c r fingerprints be used as a enetics, drug f the possibili f attributes. F various files in sers can send ted to the dig Authentica e entity really an be shared a distinct, s supply ide d to know id ormula “someth y research has la the topic, see F vention Project on.pdf 8 passed by the ive and work one particular Yet this is not conversions), s or identical passport for use etc.) and ity of gaining For example, n such a way d messages to gital identity. ation is a key y is who they d with other recognizable entifiers and entities, such hing you know, rgely concluded Fred Piper, Matt t, UK Foresight 8 e k r t , l r d g , y o . y y r e d h , d t t 9 as online services). Many local identity management systems can work together to form an interoperable identity metasystem, allowing users to manage collections of digital identities. Although the above definitions have been developed to deal with identities in the digital world they have close ties to formal identities in the social world, e.g. the handling of names7 . As society becomes more reliant on digital processing the distinction between social and digital identities might also diminish. A key issue is whether this allows the digital identities to become as flexible as social identities, or whether there is a risk of social identities to become formal and rigid, forcing us to live in a way we might not desire. There is hence a strong public policy concern that technologies and policies that affect personal identity should allow people to maintain flexible social identities, even if it might be technologically and administratively easier to create systems that forces fixed identities.
T 1 “See someth tweets (blue). THE (2011) hing or say som . FUT ) Report, Com Facu mething: Lond TUR mmissioned b N An Future o ulty of Philoso Ox www don” by Eric F RE O by the UK’s Nick Bostrom nders Sandb of Humanity ophy & Oxfo xford Univer w.nickbostrom Fischer. A map OF ID Government m erg Institute ord Martin Sc rsity m.com p derived from DEN t Office for S chool m online photo NTIT Science ographs (orang 1 TY 1 ge) and Twitter 2 Table of Contents Executive summary ................................................................................................................................................................. 4 1. Introduction ........................................................................................................................................................................... 7 The concepts of identity ..................................................................................................................................................... 7 2. Information and communication technologies ........................................................................................................... 10 Online identities ................................................................................................................................................................ 10 Identity metasystems ................................................................................................................................................... 12 Control over social spaces and identities ................................................................................................................ 14 The globalized identity ............................................................................................................................................... 17 The virtual worlds ............................................................................................................................................................ 18 The augmented world ...................................................................................................................................................... 19 Identity technology ...................................................................................................................................................... 22 3. Automation and robotics ................................................................................................................................................. 24 Automation and robotic technology ............................................................................................................................. 25 Home automation ......................................................................................................................................................... 25 Autonomous cars.......................................................................................................................................................... 25 Unmanned aerial vehicles .......................................................................................................................................... 26 Professional obsolescence and changing nature of work ........................................................................................ 27 Fluid careers and continuing education .................................................................................................................. 28 Conclusion ..................................................................................................................................................................... 28 4. Biotechnology and medicine .......................................................................................................................................... 30 Medicine ............................................................................................................................................................................. 30 Personalised health ........................................................................................................................................................... 30 Genomics ............................................................................................................................................................................ 31 The medicalization of conception ................................................................................................................................. 33 Genetically modified humans ........................................................................................................................................ 34 Biohacking and biosecurity ............................................................................................................................................ 35 Life extension .................................................................................................................................................................... 35 Human enhancement........................................................................................................................................................ 37 Implanted identity chips ............................................................................................................................................. 39 Brain-computer interfaces and other implants ........................................................................................................... 40 Invasive BCI ................................................................................................................................................................. 40 Non-invasive BCI ........................................................................................................................................................ 43 Cognitive technology, neural privacy, and neurohype ........................................................................................ 45 5. Wildcards ........................................................................................................................................................................... 47 3 6. Some general issues ......................................................................................................................................................... 49 Generational issues ...................................................................................................................................................... 49 The vulnerable .............................................................................................................................................................. 49 The future of identity .................................................................................................................................................. 50 7. Concluding remarks ......................................................................................................................................................... 52 Personal reflections by Anders Sandberg ............................................................................................................... 52 Personal reflections by Nick Bostrom ..................................................................................................................... 52 Appendix: Potential challenges to public policy from to identity-affecting technologies (summarized from the text) .................................................................................................................................................................................... 54 4 Executive summary This paper reviews some of the possible impacts on identity from three broad fields of technological advancement: biotechnology; automation and robotics; and information and communications technologies. It considers a time horizon of 15 years. Identity is central in human activities. Having a functioning psychological and social identity is essential for wellbeing. Threats to identity are serious threats and often evoke strong reactions. Yet we have multiple, changing identities. Shifting between different social identities in different contexts (jobs, family, friends, etc.) is a necessary part of everyday life. Legal identities are essential for the functioning of modern societies. Increasingly, online identities serve not only to give us access to different resources but also to help us link our different social identities. Technologies that affect how our identities function can have important effects on the
Self-Locating Belief in Big Worlds: Cosmology’s Missing Link to Observation* Nick Bostrom Oxford University Homepage: www.nickbostrom.com [Preprint of the paper "Self-Locating Belief in Big Worlds: Cosmology's Missing Link to Observation." Journal of Philosophy. Vol. 99, No. 12 (2002).] Space is big. It is very, very big. On the currently most favored cosmological theories, we are living in an infinite world, a world that contains an infinite number of planets, stars, galaxies, and black holes. This is an implication of most “multiverse theories”, according to which our universe is just one in a vast ensemble of physically real universes. But it is also a consequence of the standard Big Bang cosmology, if combined with the assumption that our universe is open or flat, as recent evidence suggests it is. An open or flat universe – assuming the simplest topology[1] – is spatially infinite at any time and contains infinitely many planets etc.[2] Philosophical investigations relating to the vastness of the cosmos have focused on the fine-tuning of our universe. “Fine-tuning” refers to the alleged fact that the laws of physics are such that if any of several physical constants had been even slightly different, then life would not have existed. A philosophical cottage industry has arisen from the controversies surrounding issues such as whether fine-tuning is in some sense “improbable”, whether it should be regarded as surprising[3], whether it calls out for explanation (and if so whether a multiverse theory could explain it[4], whether it suggests ways in which current physics is incomplete[5], or whether it is evidence for the hypothesis that our universe was designed[6]. Here I wish instead to address a more fundamental problem: How can vast-world cosmologies have any observational consequences at all? I will show that these cosmologies imply, or give a very high probability to, the proposition that every possible observation is in fact made. This creates a challenge: if a theory is such that for any possible human observation that we specify, the theory says that that observation will be made, then how do we test the theory? What could possibly count as negative evidence? And if all theories that share this feature are equally good at predicting the data we will get, then how can empirical evidence distinguish between them? I call this a “challenge” because current cosmological theories clearly do have connections to observation. Cosmologists are constantly modifying and refining theories in light of empirical findings, and they are presumably not irrational in doing so. But it is a philosophical problem to account for how this is possible. One lesson that will emerge is that we must be careful about how we construe the evidence. We know not only that such-and-such observations are made (which we shall show is impotent as a basis for evaluating Big World theories): we also know that such-and-such observations are made by us. This indexical de se component of our evidence turns out to be crucial to cosmology, and recognizing this is the first step to the solution that I shall propose. The second step is to formulate a new methodological principle that describes the probabilistic evidential bearing of (partly) indexical information on non-indexical hypotheses. With the expanded evidence base and the new rule, we can explain how Big World theories are testable. We will also hint at how the epistemological theory we outline is useful in other areas of philosophy and scientific methodology. But first, let us study in more detail how things go wrong if we construe the evidence non-indexically, in the form “Such-and-such an observation is made”. We can be generous and take “an observation” in a broad sense to include the total phenomenological content present in the observer’s mind. We do not, however, at this stage take “observing” as success verb, implying the veracity of observations; but rather, we assume an internal reading of the evidence. This assumption will later be relaxed. I. THE CONUNDRUM Consider a random phenomenon, for instance Hawking radiation. When black holes evaporate, they do so in a random manner such that for any given physical object there is a finite (although extremely small) probability that it will be emitted by any given black hole in a given time interval. Such things as boots, computers, or ecosystems have some finite probability of popping out from a black hole. The same holds true, of course, for human bodies and human brains in particular states.[7] Assuming that mental states supervene on brain states, there is thus a finite probability that a black hole will produce a brain in a state of making any given observation. Some of the observations made by such a brains will be illusory and some will be truthful. For example, some brains produced by black holes will have the illusory of experience of reading a measurement device that does not exist. Other brains, with the same experiences, will be making veridical observations – a measurement device may materialize together with the brain and may have caused the brain to make the observation. But the point that matters here is that any observation we could make has a finite probability of being produced by any given black hole. The probability of anything macroscopic and organized appearing from a black hole is of course minuscule. The probability of a given conscious brain-state being created is tinier still. Yet even a low-probability outcome has a high probability of occurring if the random process is repeated often enough. And that is precisely what happens in our world, if the cosmos is very vast. In the limiting case where the cosmos contains an infinite number of black holes, the probability of any given observation being made is one.[8] There are good grounds for believing that our universe is open and contains an infinite number of black holes. Therefore, we have reason to think that any possible human observation is in fact instantiated in the actual world.[9] Evidence for the existence of a multiverse would only add further support to this proposition. It is not necessary to invoke black holes to make this point. Any random physical phenomenon would do. It seems we don’t even have to limit the argument to quantum fluctuations. Classical thermal fluctuations could, presumably, in principle lead to the molecules in a gas cloud containing the right elements to spontaneously bump into each other so as to form a biological structure such as a human brain. The problem is that it seems impossible to get any empirical evidence that could distinguish between various Big World theories. For any observation we make, all such theories assign a probability of one to the hypothesis that that observation is made. That means that the fact that the observation is made is no reason whatever for preferring one of these theories to the others. Experimental results appear totally irrelevant.[10] We can see this formally as follows. Let B be the proposition that we are in a Big World, defined as one that is big enough and random enough to make it highly probable that every possible human observation is made. Let T be some theory that is compatible with B, and let E be some proposition asserting that some specific observation is made. Let P be an epistemic probability function. Bayes’s theorem states that P(T|E&B) = P(E|T&B)P(T|B) / P(E|B). In order to determine whether E makes a difference to the probability of T (relative to the background assumption B), we need to compute the difference P(T|E&B) - P(T|B). By some simple algebra it is easy to see that P(T|E&B) - P(T|B)0 if and only if P(E|T&B)P(E|B). This means that E will fail to give empirical support to T (modulo B) if E is about equally probable given T&B as it is given B. We saw above that P(E|T&B)P(E|B)1. Consequently, whether E is true or false is irrelevant for whether we should believe in T, given we know B. To illustrate, let T2 be some perverse permutation of an astrophysical theory T1 that we actually embrace. T2 differs from the T1 by assigning a different value to some physical constant. To be specific, let us suppose that T1 says that the temperature of the cosmic microwave background radiation is about 2.7 Kelvin (which is the observed value) whereas T2 says it is, say, 3.1 K. Suppose furthermore that both T1 and T2 imply that we are living in a Big World. One would have thought that our experimental evidence favors T1 over T2. Yet the above argument seems to show that this view is mistaken. Our observational evidence supports T2 just as much as T1. We really have no reason to think that the background radiation is 2.7 K rather than 3.1 K. II. IT’S NOT THE OLD POINT ABOUT UNDERDETERMINATION OF THEORY BY DATA At first blush, it could seem as if this simply rehashes the lesson, made familiar by Duhem and Quine, that it is always possible to rescue a theory from falsification by modifying some auxiliary assumption, so that strictly speaking no scientific theory ever implies any observational consequences. The above argument would then merely have provided an illustration of how this general result applies to cosmological theories. However, this would be to miss the point. If the argument given above is correct, it establishes a much more radical conclusion. It purports to show that all Big World theories are not only logically compatible with any observational evidence, but they are also perfectly probabilistically compatible. They all give the same conditional probability (namely one) to every observation statement E defined as above. This entails that no such observation statement can have any bearing, whether logical or probabilistic, on whether the theory is true. If that were the case, it would not seem worthwhile to make astronomical observations if what we are interested in is determining which Big World theory to favor. The only reasons we could have for choosing between such theories would be either a priori (simplicity, elegance, etc.) or pragmatic (such as ease of calculation). Nor is the argument making the ancient statement that human epistemic faculties are fallible, that we can never be certain that we are not dreaming or are brains in a vat. No, the point here is not that such illusions could occur, but rather that we have reason to believe that they do occur, not just some of them but all possible ones. In other words, we can be fairly confident that the observations we make, along with all possible observations we could make in the future, are being made by brains in vats and by humans that have spontaneously materialized from black holes or from thermal fluctuations. The argument would entail that this abundance of observations makes it impossible to derive distinguishing observational consequences from contemporary cosmological theories. III. THE CONCLUSION IS A REDUCTIO I trust that most readers will find this conclusion unacceptable. Cosmologists certainly appear to be doing experimental work and modify their theories in light of new empirical findings. The COBE satellite, the Hubble Space Telescope, and other devices are showering us with data that have been causing something of a renaissance in the world of astrophysics in recent years. Yet the argument described above would show that the empirical import of this information could never go beyond the humble role of providing support for the hypothesis that we are living in a Big World, for instance by showing that the universe is open. Nothing apart from this one fact could be learnt from such observations. Once we have established that the universe is open and infinite, then any further work in observational astronomy would be a waste of time and money. Worse still, the leaky connection between theory and observation in cosmology spills over into other domains. Since nothing hinges on how we defined T in the derivation above, the argument can easily be extended to prove that observation does not have a bearing on any scientific question so long as we assume that we are living in a Big World.[11] This consequence is absurd, so we should look for a way to mend the methodological pipeline and restore the flow of testable observational consequences from Big World theories. How can we do that? IV. GIVING UP THE INTERNAL CONSTRUAL OF “OBSERVATION” DOESN’T SAVE US Suppose we give up the internal construal of “observation” and instead take the term as a success verb, so that observing, say, a blue table implies that there is a blue table that is causally responsible for the observation. Suppose further that we couple this with the postulation that we are entitled (and perhaps even required) to have a prior credence function that strongly favors the hypothesis that we for the most part really do observe (in the success sense) what it seems to us that we are observing. Then it might appear as if we have an exit from our predicament. (Alternatively, we could formulate this escape plan by sticking to the original internal definition of “observation” and adding the postulate that our prior credence functions should strongly favor the veridicality of our observations.) However, even setting aside foundationalist scruples, the proposed solution doesn’t get us out of the pickle. To see this, consider that observers are not the only things that have a finite probability of being generated in random systems. On the same ground that we should expect human observers in all possible states to be ejected from black holes or to form from vastly improbable thermal fluctuations, we should also expect all physically possible local environments to spring forth. So not only are there observers having all sorts of illusions (of seeing a blue table or reading a measurement apparatus) but additionally there are observers making all sorts of veridical observations (actually seeing a blue table or reading off instruments in each of their possible output states). Consequently, even if we assume our observations to be veridical, we are still left with the problem that our current best theories give probability one to the existence of all possible such observations together with their truth-making local environments. (See Figure 1). We can even press on to the conclusion that for any possible human observation, there may be habitats in which that observation is appropriately caused by the observed object and in which the observer’s perceptions in general track her surroundings.[12] A qualification is due. While small-scale environments, e.g. ones that include tables and measuring apparatuses, are on a par with human bodies, it is not clear that very large systems such as galactic superclusters could be produced by any of the random processes that we have discussed. If we stipulate that we are making veridical observations of these mega-scale entities, we could thus salvage the testability of some aspects of cosmological theories that concern these large-scale entities. Yet this would be of little avail since it would not rescue the rest of our epistemic practices, which deal with medium-sized and small things. Observations of such items would still be subject to the charge of being radically irrelevant to our theories about the world, modulo the Big World hypothesis.[13] A further shortcoming of the proposal (apart from the fact that it doesn’t work) is that it doesn’t tell us anything about the defeasibility conditions of the purported principle that you should be strongly biased in favor of the veridicality of your observations. Clearly, there are cases where it would be unreasonable to believe that one’s observations are veridical. For example, if you knew that almost all observers in your current situation (tucked in, let’s say, between the bedsheets in a detox unit with the sensation of bugs crawling under your skin) were hallucinating, then you should not believe that your current observations are veridical, unless you had additional information defeating that conclusion. A satisfactory account of the Big World case ought to have at least something to say about why the presence of lots of hallucinating and otherwise misled observers in Big Worlds does not undermine our confidence in the reliability of our own observations while the contrary holds specifically for clients in the methadone clinic and other such special situations. So if an externalist construal of the evidence is not the answer, what is? V. RESTORING THE FLOW OF TESTABLE CONSEQUENCES VIA A LIMITED INDIFFERENCE PRINCIPLE OVER DE SE STATEMENTS It may seem as if our troubles originate from the somewhat “technical” point that in a large enough cosmos, every observation will be made by some freakish observers here and there. It remains the case, however, that those observers are exceedingly rare and far between. For every observation made by a freak observer spontaneously materializing from Hawking radiation or thermal fluctuations, there are trillions upon trillions of observations made by regular observers who have evolved on planets like our own and who make veridical observations of the universe. Why can we not solve the problem, then, by saying that although all these freak observers exist and are suffering from various illusions (or are making veridical but unrepresentative observations), it is highly unlikely that we are among their numbers? Then we should think, rather, that we are very probably one of the regular observers whose observations reflect reality. We could safely ignore the freak observers and their illusions and misleading perceptions in most contexts when doing science. In my view, this response suggests the right way to proceed. Because the freak observers are in such a tiny minority, their observations can be disregarded for most purposes. It is possible that we are freak observers – we should assign to that hypothesis some finite probability, but such a tiny one that it does not make any practical difference. If we want to run with this idea, it is crucial that we construe our evidence differently than we did above. If our evidence is simply “Such and such an observation is made” then the evidence has probability one given any Big World theory – and we ram our heads straight into the problems I described. But if we construe our evidence in the more specific form “We are making such and such observations” then we have a way out. For we can then say that although Big World theories make it probable that some such observations be made, they need not make it probable that we should be the ones making them. Let us therefore define: E’ := “Such and such observations are made by us” E’ contains an indexical de se component that the original evidence-statement we considered, E, did not. E’ is logically stronger than E. The rationality requirement that one should take all relevant evidence into account dictates that in case E’ leads to different conclusions than does E, then it is E’ that determines what we ought to believe. A question that now arises is how to determine the evidential bearing that statements of the form of E’ have on cosmological theories. Using Bayes’s theorem, we can turn the question around and ask, how do we evaluate P(E’|T&B), the conditional probability that a Big World theory gives to us making certain observations? The argument in the foregoing sections showed that if we hope to be able to derive any empirical implications from Big World theories, then P(E’|T&B) should not generally be set to unity or close to unity. P(E’|T&B) must take on values that depend on the particular theory and the particular evidence that we are we are considering. Some theories T are supported by some evidence E’; for these choices P(E’|T&B) is relatively large. For other choices of E’ and T, the conditional probability will be much smaller. To be concrete, consider the two rival theories T1 and T2 about the temperature of the cosmic microwave background. Let E’ be the proposition that we have made those observations that cosmologists innocently take to support T1. E’ includes readings from radio telescopes etc. Intuitively, we want P(E’|T1&B) > P(E’|T2&B). That inequality must be the reason why cosmologists believe that the background radiation is in accordance with T1 rather than T2, since a priori there is no ground for assigning T1 a substantially greater probability than T2. A natural way to achieve this result is by postulating that we should think of ourselves as being in some sense “random” observers. Here we use the idea that the essential difference between T1 and T2 is that the fraction of observers that would be making observations in agreement with E’ is enormously greater on T1 than on T2. If we reason as if we were randomly selected samples from the set of all observers, or from some suitable subset thereof, then we can explicate the conditional probability P(E’|T&B) in terms of the expected fraction of all observers in the reference class that the conjunction of T and B says would be making the kind of observations that E’ says that we are making. As we shall see, this postulate enables us to conclude that P(E’|T1&B) > P(E’|T2&B). Let us call this postulate the Self-Sampling Assumption: (SSA) Observers should reason as if they were a random sample from the set of all observers in their reference class. The general problem of how to define the reference class is complicated, and I shall not address it here. For the purposes of this paper we can think of the reference class as consisting of all observers who will ever have existed. We can also assume a uniform sampling density over this reference class. Moreover, it simplifies things if we set aside complications arising from assigning probabilities over infinite domains by assuming that B entails that the number of observers is finite, albeit such a large finite number that the problems described above obtain. These assumptions help us focus on basic principles. Here is how SSA supplies the missing link needed to connect theories like T1 and T2 to observation. On T2, the only observers who observe an apparent temperature of the cosmic microwave background CMB2.7 K are those who either have various sorts of rare illusions (for example because their brains have been generated by black holes and are therefore not attuned to the world they are living in) or happen to be located in extremely atypical places (where e. g. a thermal fluctuation has led to a locally elevated CMB temperature). On T1, by contrast, almost every observer who makes the appropriate astronomical measurements and is not deluded will observe CMB2.7 K. A much greater fraction of the observers in the reference class observe CMB2.7 K if T1 is true than if T2 is true. By SSA, we consider ourselves as random observers; so it follows that on T1 we would be much more likely to find ourselves as one of those observers who observe CMB2.7 K than we would on T2. Therefore, P(E’|T1&B) >> P(E’| T2&B). Supposing that the prior probabilities of T1 and T2 are roughly the same, P(T1)P(T2), it is then trivial to derive via Bayes’s theorem that P(T1|E’&B) > P(T2|E’&B). This vindicates the intuitive view that we do have empirical evidence that favors T1 over T2. The job that SSA is doing in this derivation is to enable the step from a proposition about fractions of observers to propositions about corresponding probabilities. We get the propositions about fractions of observers by analyzing T1 and T2 and combining them with relevant background information B; from this we conclude that there would be an extremely small fraction of observers observing CMB2.7 K given T2 and a much larger fraction given T1. We then consider the evidence E’, which is that we are observing CMB2.7 K. SSA authorizes us to think of the “we” as a kind of random variable ranging over the class of actual observers. From this it then follows that E’ is more probable given T1 than given T2. But without assuming SSA, all we can say is that a greater fraction of observers observe CMB2.7 K if T1 is true, and at that point the argument would grind to a halt. We could not reach the conclusion that T1 is supported over T2. For this reason I propose that SSA, or something like it, be adopted as a methodological principle. It may seem mysterious how probabilities of this sort can exist – how can we possibly make sense of the idea that there was some chance that we might have been other observers than we are? However, what I am suggesting here is not the existence of some objective, or physical, chances. I am not suggesting that there is a physical randomization mechanism, a cosmic fortune wheel as it were, that assigns souls to bodies in a stochastic manner. Rather, we should think of these probabilities as epistemic. They are part of a proposal explicating the epistemic relations that hold between theories (such as T1 and T2) and evidence (such as E’) containing a de se component. We can view SSA as a kind of restricted indifference principle that applies to credences over de se propositions, or sets of centered possible worlds in the Quinean terminology. The status of SSA could also be regarded as in some respects akin to that of the David Lewis’s Principal Principle[14], which expresses a connection between physical chance and epistemic credence. Crudely put, the Principal Principle says that if you know that the objective (physical) chance of some outcome A is x%, then you should assign a credence of x% to A (unless you have additional “inadmissible” information). Analogously, SSA can be read as saying that if you know that a fraction x% of all observers in your reference class are in some type of position A, then you should assign a prior credence of x% to being in a type-A position. This prior credence must, of course, be conditionalized on any other relevant information you have in order to get the posterior credence, i.e. the degrees of belief you should actually have given all you know. Thus, after conditionalizing on the observation that CMB2.7 K, you get, trivially, a posterior function that assigns zero credence to the hypothesis that you are an observer that observes CMB3.1 K. But it is the higher conditional prior credence (according to SSA) of observing that CMB2.7 K given T1 than given T2 that renders it the case that conditionalizing on this observation preferentially supports T1. VI. AN ILLUSTRATION We can illustrate how SSA works by a simple thought experiment. Blackbeards and Whitebeards. In an otherwise empty world there are three rooms. God tosses a fair coin and creates three observers as a result, placing them in different rooms. If the coin falls heads, He creates two observers with black beards and one with a white beard. If it falls tails, it is the other way around: He creates two whitebeards and one blackbeard. All observers are aware of these conditions. There is a mirror in each room, so observers know the color of their own beard. You find yourself in one of the rooms and you see that you have a black beard. What credence should you give to the hypothesis that the coin fell heads? The situation is depicted in Figure 2. Because of the direct analogy to the cosmology case, we know that the answer must be that you should assign a greater credence to Heads than to Tails. Let us apply SSA and see how we get this result. From the setup, we know that the prior probability of Heads is 50%. This is the probability you should assign to Heads before you have looked in the mirror and thus before you know your beard color. That this probability is 50% follows from the Principal Principle together with the fact you know that the coin toss was fair. We thus have Next we consider the conditional probability of you observing that you have black beard given a specific outcome of the toss. If the coin fell heads, then two out of three observers observe themselves having a black beard. If the coin fell tails, then one out of three observe having a black beard. By SSA, you reason as if you were a randomly sampled observer, giving . Using Bayes’s theorem, we can then calculate the conditional probability of Heads given that you have a black beard: . After looking in the mirror and learning that your beard is black you should therefore assign a credence of to Heads and to Tails. This result mirrors that of the cosmology example. Because one theory (T1, Heads) entails that a greater fraction of all observers are observing what you are observing (E’, Black) than does another theory (T2, Tails), the former theory obtains preferential support from your observation. VII. SUMMARY: WE NEED A METHODOLOGY FOR EVIDENCE WITH A DE SE COMPONENT Big World theories, popular in contemporary cosmology, engender a peculiar methodological problem: because they say the world is very big and somewhat stochastic, they imply (or make it highly probable) that every possible human observation is made. The difficulty is that it is unclear how we could ever have empirical reasons for preferring one such theory to another, since they all seem to fit equally well with whatever we observe. This skeptical threat is different from and much more radical than the problem of underdetermination of theory by data associated with Duhem and Quine. And if left unfixed, the broken connection between observation and theory spills over from cosmology into other domains. We saw that the leakage cannot be stopped even by blocking all consideration given to the possibility of illusory observations, because the maverick observations made in Big Worlds include veridical ones as well as illusions. Instead, we proposed to repair methodology by means of a new epistemic principle, the Self-Sampling Assumption, which takes into account the de se component of our evidence. This principle connects Big World theories to observation in an intuitively plausible way and vindicates the practices of cosmologists who test hypotheses against experimental findings. The Self-Sampling Assumption has implications in other problem areas in science and philosophy. It can be seen as an explication of the anthropic principle, understood in the original spirit of by Brandon Carter, a theoretical physicist whose seminal work opened the door to a systematic exploration of observation selection effects.[15] Observation selection effects are a kind of bias that may be present in our data that is not due to limitations in our measurement apparatuses but to the fact that our data are preconditioned on the existence of a suitably positioned observer to “have” the data (and to build the instruments in the first place). Carter investigated the relevance of observation selection effects for attempts to evaluate the bearing of our current evidence on questions such as how improbable it is for complex life forms to evolve on a given Earth-like planet or how many critical improbable steps were involved in our evolution.[16] To illustrate, take one of the simplest points Carter made: Even if a theory says that the probability for an Earth-like planet of giving rise to intelligent life is small, the theory will still perfectly fit our observation of intelligent life having evolved on this planet provided that the total number of Earth-like planets is large enough for it to have been probable, according to the theory, that intelligent life should arise somewhere. Similar modes of reasoning are invoked in some discussions of no-collapse versions of quantum mechanics[17] and, as hinted at in the introduction, they play a central role in the debate about the significance of the apparent fine-tuning of our universe and the capacity of multiverse theories to explain it. Even an application to traffic planning has been discovered.[18] On the more theoretical side, we have game theoretic problems involving imperfect recall, such as the Absent-Minded Driver problem[19] and its philosophical, more purely epistemic analogue, the Sleeping Beauty problem[20]. What these various topics have in common is that they involve the assignment of conditional credences to statements of the form “I make such and such observations given that the world is such and such.”[21] In other words, they involve the evaluation of a de se component of our evidence: our knowledge that we are the ones making a certain observation or that we are the ones who have a certain piece of (otherwise non-indexical) evidence. Our duty to objectivity must not be misunderstood as a license to ignore de se clues. The considerations advanced in this paper impose constraints on what can count as a satisfactory methodology for fashioning knowledge out of this indexical part our epistemic raw material. Such a methodology, a general theory of observation selection effects and its various scientific and philosophical applications, is something I have attempted to set forth elsewhere.[22] Footnotes * I’m grateful for valuable comments from Craig Callender, Milan Cirkovic, Adam Elga, Colin Howson, John Leslie, Peter Milne, Don Page, Elliott Sober, Alex Vilenkin, Roger White, and three anonymous referees. [1] I.e. that space is simply connected. There is a recent burst of interest in the possibility that our universe might be multiply connected, in which case it could be both finite and hyperbolic. A multiply connected space could lead to a telltale pattern consisting of a superposition of multiple images of the night sky seen at varying distances from Earth (roughly, one image for each lap around the universe that the light has traveled). Such a pattern has not been found, although the search continues. For an introduction to multiply connected topologies in cosmology, see M. Lachièze-Rey and J.-P. Luminet, J.-P., “Cosmic Topology,” Physics Reports, 254(3) (1995): 135-214. [2] A widespread misconception is that the open universe in the standard Big Bang model becomes spatially infinite only in the temporal limit. The observable universe is finite, but only a small part of the whole is observable (by us). One fallacious intuition that might be responsible for this misconception is that the universe came into existence at some spatial point in the Big Bang. A better way of picturing things is to imagine space as an infinite rubber sheet, and gravitationally bound groupings (such as stars and galaxies) as buttons glued on to it. As we move forward in time, the sheet is stretched in all directions so that the separation between the buttons increases. Going backwards in time, we imagine the buttons coming closer together until, at “time zero”, the density of the (still spatially infinite) universe becomes infinite everywhere. See e.g. J. L. Martin, General Relativity (London: Prentice Hall, 1995). [3] E.g. J. Earman, “The SAP also Rises: A Critical Examination of the Anthropic principle,” Philosophical Quarterly, 24(4) (1987): 307-317; J. Leslie, J., Universes (London: Routledge, 1989). [4] E.g. Q. Smith, “Anthropic Explanations in Cosmology,” Australasian Journal of Philosophy 72(3) (1994): 371-382; I. Hacking, “The Inverse Gambler’s Fallacy: The Argument from Design. The Anthropic Principle Applied to Wheeler Universes,” Mind 76 (1987): 331-340. [5] E.g. E. McMullin, “Indifference Principle and Anthropic Principle in Cosmology,” Studies in History and Philosophy of Science, 24(3) (1993): 359-389. [6] E.g. R. Swinburne, “Argument from the Fine-tuning of the Universe,” in Physical Cosmology and Philosophy, ed. J. Leslie and J. Collier (New York: Macmillan, 1990): pp. 154-173. [7] See e.g. S. Hawking and W. Israel, eds., General Relativity: An Einstein Centenary Survey (Cambridge University Press, 1979): “[I]t is possible for a black hole to emit a television set or Charles Darwin” (p. 19). To avoid making a controversial claim about personal identity, Hawking and Israel ought to have weakened this to “… an exact replica of Charles Darwin”. But see also G. J. Belot et al., “The Hawking Information Loss Paradox: The Anatomy of a Controversy,” British Journal for the Philosophy of Science 50(2) (1999): 189-229. [8] In fact, there is a probability of unity that infinitely many tokens of each observation-type will appear. But one of each suffices for present purposes. [9] I restrict the assertion to human observations in order to avoid questions as to whether there may be other kinds of possible observations that perhaps could have infinite complexity or be of some alien or divine nature that does not supervene on stuff that is emitted from black holes – such stuff is physical and of finite size and energy. [10] Some cosmologists are recently becoming aware of the problematic that this paper describes (e.g. A. Vilenkin, “Unambiguous probabilities in an eternally inflating universe.” Physical Review Letters, 81 (1998): 5501-5504; A. Linde and A. Mezhlumian, “On Regularization Scheme Dependence of Predictions in Inflationary Cosmology,” Physical Review D, 53 (1996): 4267-4274. See also J. Leslie, “Time and the Anthropic Principle,” Mind 101(403) (1992): 521-540. [11] And were it really true that we have no means of testing Big World theories, then it is not even clear that the empirical support we currently have for such theories could be maintained. Such theories would seem self-undermining in that they would say of their own evidence, in effect, that it was not to be trusted. [12] I want to emphasize that the problem is not that there is some massive inconsistency of contradictory observations. To assert the existence of all possible human observations is not inconsistent, since the observations may be illusory. Moreover, even if all the observations were asserted to be veridical, it would still be no inconsistency, since the various diverse properties that are being observed may be instantiated at different places, just as a tie can be both blue and yellow (although not at the same spot at the same time). Rather, the problem is how to derive testable predictions given our inability to observationally locate ourselves in a Big World, which is rather analogous to seeing a yellow spot through a microscope and not knowing which part of the hypothesized tie we are looking at. [13] We may also note that there are some (speculative) theories according to which even the largest structures that we see are not large enough to escape the problem (e.g. M. Tegmark, “Does the universe in fact contain almost no information?” Foundations of Physics Letters, 9(1) (1996): 25-42). Moreover, there are many much less extreme theories, such as chaotic inflation theory (see e.g. A. Linde, “Inflation with variable Omega,” Physics Letters B, 351 (1995): 99-104), according to which observers are observing a wide range of different values of some physical constant and parameters, not because the observers have illusions or live in habitats that originate from black holes or the like, but because the “constants” and parameters vary over vast cosmic distances or epochs. [14] See e.g. D. Lewis, Philosophical Papers II (Oxford, 1986) and “Humean Supervenience Debugged,” Mind, 103(412) (1994): 473-490. A similar principle had earlier been introduced by Hugh Mellor in The Matter of Chance (Cambridge, 1971). [15] “Large Number Coincidences and the Anthropic Principle in Cosmology,” in Confrontation of Cosmological Theories with Data, ed. M. S. Longair (Dordrecht: Leidel, 1973): pp. 291-298; “The Anthropic Selection Principle and the Ultra-Darwinian Synthesis,” in The Anthropic Principle, eds. F. Bertola and U. Curi (Cambridge, 1989): pp. 33-63. [16] “The Anthropic Principle and its Implications for Biological Evolution,” Philosophical Transactions of the Royal Society, A 310 (1983): 347-363. [17] See e.g. D. N. Page, “Can Quantum Cosmology Give Observational Consequences of Many-Worlds Quantum Theory,” in General Relativity and Relativistic Astrophysics, Eighth Canadian Conference, Montreal, Quebeck, eds. C. P. Burgess and R. C. Myers (New York: American Institute of Physics, 1999), pp. 225-232. [18] N. Bostrom, “Cars In the Next Lane Really Do Go Faster,” PLUS, 17 (2001). [19] See e.g. M. Piccione and A. Rubinstein, “On the Interpretation of Decision Problems with Imperfect Recall,” Games and Economic Behaviour, 20 (1997): 3-24; R. J. Aumann and S. Hart et al., “The Forgetful Passenger,” Games and Economic Behaviour 20 (1997): 117-120. [20] E. g. A. Elga, “Self-locating Belief and the Sleeping-Beauty problem,” Analysis 60(266) (2001): 143-147; D. Lewis, “Sleeping Beauty: reply to Elga,” Analysis 61(271) (2001): 171-175. [21] Or in some cases, the analogous temporal construction: “I make such and such observations now given that the world is such and such.” [22] Anthropic Bias: Observation Selection Effects in Science and Philosophy (New York: Routledge, 2002). A theory of observation selection effects must walk a fine line in order to cater to legitimate scientific needs while avoiding philosophical paradoxes, of which a great number lie in ambush. Incidentally, the Self-Sampling Assumption is, in my view, a mere derivative of a more powerful principle, and it is only valid in special cases.
Here, α is the observer-moment whose subjective probability function is . is the class of all possible observer-moments about whom h is true; is the class of all possible observer-moments about whom e is true; is the class of all observer-moments that places in the same reference class as herself; is the possible world in which is located; and γ is a normalization constant Pα Ωh Ωe Ωα α wα α ∑∈Ω Ω ∩Ω = e w P w σ σ σ α σ γ | ( ) | ( ) OE can be generalized to allow for different observer-moments within the reference class having different “weights”, an option that might be of relevance for instance in the context of the many-worlds version of quantum theory. 19 6 Redelmeier and Tibshirani (1999) • “Differential surveillance can occur because drivers look forwards rather than backwards, so vehicles that are overtaken become invisible very quickly, whereas vehicles that overtake the index driver remain conspicuous for much longer;” and • “Human psychology may make being overtaken (losing) seem more salient than the corresponding gains.” The authors recommend that drivers should be educated about these effects in order to reduce the temptation to switch lanes repeatedly. This would reduce the risk of accidents, which are often caused by poor lane changes. While all these psychological illusions might indeed occur, there is a more straightforward explanation for the drivers’ persistent suspicion that cars in the next lane are moving faster. Namely, that cars in the next lane actually do go faster! One frequent cause of why a lane (or a segment of a lane) is slow is that there are too many cars in it. Even if the ultimate cause is something else (for example, road work) there is nonetheless typically a negative correlation between the speed of a lane and how densely packed the vehicles driving in it are. This implies that a disproportionate fraction of the average driver’s time is spent in slow lanes. If you think of your present observation, when you are driving on the motorway, as a random sample from all observations made by drivers, then chances are that your observation will be made from the viewpoint that most such observer-moments have, which is the viewpoint of the slowmoving lane. In other words, appearances are faithful: more often than not, for most observer-moments, the “next” lane is faster. Even when two lanes have the same average speed, it can be advantageous to switch lanes. For what is relevant to a driver who wants to reach her destination as quickly as possible is not the average speed of the lane as a whole, but rather the speed of 20 some segment extending maybe a couple of miles forward from the driver’s current position. More often than not, the next lane has a higher average speed at this scale than does the driver’s present lane. On average, there is therefore a benefit to switching lanes (which of course has to be balanced against the costs of increased levels of effort and risk). Adopting a thermodynamics perspective, it is also easy to see that (at least in the ideal case) increasing the “diffusion rate” (that is, the probability of lane-switching) will speed the approach to “equilibrium” (where there are equal velocities in both lanes), thereby increasing the road’s throughput and the number of vehicles that reach their destinations per unit time. To summarize, in understanding this problem we must not ignore its inherent observation selection effect. This resides in the fact that if we randomly select an observer-moment of a driver and ask her whether she thinks the next lane is faster, more often than not we have selected an observer-moment of a driver who is in a lane which is in fact slower. When we realize this, we see that no case has been made for recommending that drivers change lanes less frequently.7 11. Observation selection theory (also known as anthropic reasoning), which aims to help us detect, diagnose, and cure the biases of observation selection effects, is a philosophical goldmine. Few branches of philosophy are so rich in empirical implications, touch on so many 7 The above reasoning applies to a driver who is currently on the road wondering why she is in the slow lane. When considering the problem retrospectively, that is, when you are sitting at home thinking back on your experiences on the road, the situation is more complicated and requires also taking into account differential recall (psychological factor may make you more likely to remember and bring to mind certain kinds of experiences) and the fact that 21 important scientific questions, pose such intricate paradoxes, and contain such generous quantities of conceptual and methodological confusion that need to be sorted out. Working in this area is a lot of intellectual fun. The mathematics used in this field, such as conditional probabilities and Bayes’s theorem, are covered by elementary arithmetic and probability theory. The topic of observation selection effects is extremely complex, yet the difficulty lies not in the math, but in grasping and analyzing the underlying principles. References Bartha, P. and C. Hitchcock, "No One Knows the Date or the Hour: An Unorthodox Application of Rev. Bayes's Theorem," Philosophy of Science (Proceedings) 66 (1999): S329-S53. Bartha, P. and C. Hitchcock, "The Shooting-Room Paradox and Conditionalizing on Measurably Challenged Sets," Synthese 108(3) (2000): 403-37. Bostrom, N., "Investigations into the Doomsday argument." Preprint (1997). Bostrom, N., "The Doomsday argument, Adam & Eve, UN++, and Quantum Joe." Synthese 127(3) (2001): 359-87. 22 while the slow lane contains more observer-moments, it may nevertheless be true that more drivers have passed through the fast lane. Bostrom, N., Anthropic Bias: Observation Selection Effects in Science and Philosophy (New York: Routledge, 2002a). Bostrom, N., "Self-Locating Belief in Big Worlds: Cosmology's Missing Link toObservation," Journal of Philosophy 99(12) (2002 b). Dieks, D., "Doomsday - Or: the Dangers of Statistics," Philosophical Quarterly 42(166) (1992): 78-84. Hall, N., "Correcting the Guide to Objective Chance," Mind 103(412) (1994): 505-17. Leslie, J., The End of the World: The Science and Ethics of Human Extinction (London: Routledge, 1996). Lewis, D., Philosophical Papers (New York: Oxford University Press, 1986). Lewis, D., "Humean Supervenience Debugged," Mind 103(412) (1994): 473-90. Oliver, J. and K. Korb, A Bayesian analysis of the Doomsday Argument,[is this a book or article…?] Department of Computer Science, Monash University, 1997. Olum, K., "The Doomsday Argument and the Number of Possible Observers," Philosophical 23 Quarterly 52(207) (2002): 164-84. Redelmeier, D. A. and R. J. Tibshirani, "Why cars in the other lane seem to go faster," Nature 401 (1999): 35. Smith, Q., "Anthropic Explanations in Cosmology," Australasian Journal of Philosophy 72(3) (1994): 371-82. Thau, M., "Undermining and Admissibility," Mind 103(412) (1994): 491-503.
Normally, this kind of subtle change in indexical information makes no difference to our inferences, so they can therefore usually be ignored. In special cases, however, including the thought experiments considered in this paper, which rely precisely on the peculiar evidential properties of indexical information, such changes can be highly relevant. This does not yet show that your beliefs at stage (b) about the outcome of the coin toss should differ from those obtained by conditionalizing Pr(tails|I’m in cell #1). But it defeats the 15 Bayesian argument for why they should be the same. If you regard these associated epistemic changes that occur in addition to your obtaining the information that “I’m in cell #1” when you move from stage (a) to stage (b) as relevant, then you can coherently assign a 1/2 posterior credence to tails. Let α be one of your observer-moments that exist before you discover which cell you are in. Let β be one of your observer-moments that exist after you have discovered that you are in cell #1 (but before you have learned about the outcome of the coin toss). What probabilities α and β assign to various hypotheses depends on reference classes in which they place themselves. For example, α can pick a reference class consisting of the observer-moments who are ignorant about which cell they are in, while β can pick the reference class consisting of all observer-moments who know they are in cell #1. α ’s conditional credences are then the same as before: Prα (α is in cell #1| tails) = 1 100 1 Prα (α is in cell #1| heads) = . But β ’s conditional probability of being in cell #1 given heads is now identical to that given tails: Prβ (β is in cell #1| tails) = 1 Prβ (β is in cell #1| heads) = 1. From this, it follows that β ’s posterior credence of tails after conditionalizing on β being in 16 cell #1 is the same as its posterior credence of heads, namely 1/2. SSSA does not by itself imply that this should be β ’s posterior credence of tails. It just shows that it is a coherent position to take. The actual credence assignment depends on which reference classes are chosen. In the case of Incubator, it may not be obvious which choice of reference class is best. But in the Serpent’s Advice, it is clear that Eve should select a reference class that puts her observer-moments existing at the time when she is pondering the possible consequences of the sinful act in a different reference class from those later observer-moments that may come to exist as a result of her transgression. For her to do otherwise would not be incoherent, but it would yield the strongly counterintuitive consequence discussed above. By selecting the more limited reference class, she can reject this consequence. The question arises whether it is possible to find some general principle that determines what reference class an observer-moment should use. We may note that the early Eve’s choice of a reference class that contains only her own early observer-moments and excludes the observermoments of all the billions of progeny that may come to exist later is not completely arbitrary. After all, the epistemic situation that the early Eve is in is very different from the epistemic situation of these later observer-moments. Eve doesn’t know whether she will get pregnant and whether all these other people will come to exist; her progeny, by contrast, would have no doubts about these issues. Eve is confronted with a very different epistemic problem than her possible children would be. It is thus quite natural to place Eve in a different reference class from these later people, even apart from the fact that this maneuver would explain why the serpent’s recommendation should be eschewed. Constraints on what could be legitimate choices of reference class can be established, but it is an open question whether these will always suffice to single out a uniquely correct reference class for every observer-moment. My suspicion is that there might remain a subjective element 17 in the choice of reference class in some applications. Furthermore, I suspect that the degree to which various applications of anthropic reasoning are sensitive to that subjective element is inversely related to how scientifically robust those applications are. The most rigorous uses of anthropic reasoning have the property that they give the same result for almost any choice of reference class (satisfying only some very weak constraints). In passing, we may note one interesting constraint on the choice of reference class. It turns out (for reasons that we do not have the space to elaborate on here) that a reference class definition according to which only subjectively indistinguishable observer-moments are placed in the same reference class is too narrow. (Two observer-moments are subjectively indistinguishable if they don’t have any information that enables them to tell which one is which.) In other words, there are cases in which you should reason as if your current observermoment were randomly selected from a class of observer-moments that includes ones of which you know that they are not your own current observer-moment. This fact makes anthropic reasoning a less simple affair than would otherwise have been the case. The use of SSSA and the relativization of the reference class that SSSA enables thus seem to make it possible to coherently reject both the presumptuous philosopher’s and the serpent’s arguments, while at the same time one can show how to get plausible results in Dungeon and several other thought experiments as well as in various scientific applications, some of them novel. The theory can be condensed into one general formula: the Observation Equation, which specifies the probabilistic bearing on hypotheses of evidence that contains an indexical component.5 Along with various constrains on permissible choices of reference classes, 5 ∑∈Ω ∩Ω Ω ∩Ω = h e w P w P h e σ σ σ α σ α γ | ( ) | 1 ( ) ( | ) (Observation Equation) 18 this forms the core of a theory of observation selection effects. 10. As a final example, let us consider an easy application of observation selection theory to a puzzle that many drivers on the motorway may have wondered about (and cursed). Why is it that the cars in the other lane seem to be getting ahead faster than you? One might be inclined to account for phenomenon by invoking Murphy’s Law (“If anything can go wrong, it will,” discovered by Edward A. Murphy, Jr, in 1949). However, a paper in Nature by Redelmeier and Tibshirani, published a couple of years ago,6 seeks a deeper explanation. They present some evidence that drivers on Canadian roadways (where faster cars are not expected to move into more central lanes) think that the next lane is typically faster. They seek to explain the drivers’ perceptions by appealing to a variety of psychological factors. For example: • “A driver is more likely to glance at the next lane for comparison when he is relatively idle while moving slowly;”
theorem, the risk that she shall bear a child is less than one in a billion. Therefore, my dear friends, indulge your desires and worry not about the consequences!” Given the assumption that the same method of reasoning should be applied as in Incubator, and using some plausible prior probability of pregnancy given carnal embrace (say, 1/100), it is easy to verify that there is nothing wrong with the serpent’s mathematics. The question, of course, is whether the assumption should be granted. ≈ Let us review some of the differences between Incubator and Serpent’s Advice to see if any of them are relevant in the sense of providing a rational ground for treating the two cases differently. • In the Incubator experiment there was a point in time, stage (a), when the subject was actually ignorant about her position among the observers. By contrast, Eve presumably knew all along that she was the first woman. But it is not clear why that should matter. We can imagine that Eve and Adam were created on a remote island, and that they didn’t know whether there are other people on Earth, until one day they were informed that they are thus far the only ones. It is still counterintuitive to say that the couple needn’t worry about the possibility of Eve getting pregnant. • When the subject is making the inference in Dungeon, the coin has already been tossed. In the case of Eve, the relevant chance event has not yet taken place. This difference does not seem crucial either. We can modify Serpent’s Advice by supposing that the deciding chance event has already taken place. Let’s say the couple has just sinned and they are now brooding over the ramifications. Should the serpent’s argument completely reassure them that nothing bad will happen? It seems not. So the worry remains. 11 • At stage (b) in Dungeon, any observers resulting from the toss have already been created, whereas Eve’s potential progeny do not yet exist at the time when she is assessing the odds. We can consider a variant of Dungeon where each cell exists in a different century. That is, let us suppose that cell #1, along with its observer, are created in the first century, and destroyed after, say, 30 years. In each of the subsequent 99 centuries, a new cell is built, allowed to exist for 30 years, and is then destroyed. At some point in the first century a coin is tossed and, depending on how it lands, these subsequent cells will or will not contain observers. Stage (a) can now be defined to take place in the first century after the first prisoner has been created but before the coin has been tossed and before the prisoner has been allowed to come out of his cell to observe its number. At this stage (stage (a)) it seems that he should assign the same credence to tails and the same conditional credences of tails given that he is in a particular cell as he did in the original version—for precisely the same reasons. But then it follows, just as before, that his posterior credence of tails, after finding that he is in cell #1, should be much greater than the prior credence of tails. This version of Dungeon is analogous to Serpent’s Advice with respect to the non-existence of the later humans at the time when the odds are being assessed. • In Dungeon, the two hypotheses under consideration (heads and tails) have well-defined known prior probabilities (50%), whereas Eve and Adam must rely on vague subjective considerations to assess the risk of pregnancy. True, but would we want to say that if Eve’s getting pregnant were determined by some distinct microbiological process with a well-defined objective chance which Eve and Adam knew about, then they ought to accept the serpent’s advice? If anything, the knowledge of such an objective chance would make the consequence even weirder. 12 8. The mystery that we are facing here is that it seems clear that both the serpent and the presumptuous philosopher are wrong, yet it seems as if the only model that yields this double result (model 1) is incoherent. One may be tempted to blame the strength of SSA for these troubles and think that we should reject it. But that, it appears, would transfix us on another horn of the dilemma, for we would then have to reject the cogent argument about the Dungeon thought experiment presented above, and, perhaps even more seriously, we would have failed to account for a number of very well-founded scientific applications in cosmology and elsewhere (which I lack the space to fully explore in this article). There are a number of possible moves and objections that one can try at this point. But most of these maneuvers and objections rest on simple misunderstandings, or else they fail to provide a workable alternative to how to reason about the range of problems that need to be addressed. It is easy enough to come up with a method of reasoning that works in one particular case, but when one then tests it against other cases—philosophical thought experiments and legitimate scientific inferences—one usually soon discovers that it yields paradoxes or otherwise unacceptable results. Yet by seriously confronting this central conundrum of self-locating belief, we can glean important clues about what a general theory of observation selection effects must look like. 9. So where do we go from here? The full answer is complicated and difficult and cannot be fully explored in a relatively short paper like this one. But by helping myself to a fair amount of hand-waving, I can at least try to indicate the direction in which I think the solution is to be found. 13 One key to the solution is to realize that the problem with SSA is not that it is too strong but that it isn’t strong enough. SSA tells you to take into account a certain kind of indexical information—information about which observer you are. But you have more indexical information than that about who you are; you also know when you are. That is, you know which temporal segment—which “observer-moment”—of an observer that you are at the current time. We can formulate a ‘Strong Self-Sampling Assumption’ that takes this information into account: (SSSA) Each observer-moment should reason as if it were randomly sampled from its reference class. Arguments can be given for SSSA along lines parallel to those of the arguments for SSA provided above. For example, one can consider cases in which a person is unaware of what time it is and has to assign credence to different temporal possibilities. A second key to the solution is to see how the added analytical power of SSSA enables us to relativize the reference class. What this means is that different observer-moments of the same observer may use different reference classes without that observer being incoherent over time. To illustrate, let us again consider the Incubator thought experiment. Before, we rejected model 3 because it seemed to imply that the reasoner should be incoherent. But we can now construct a new model, model 4, which agrees with the answers that model 3 gave, that is, a credence of 1/2 of heads at both stage (a) and stage (b), but which modifies the reasoning that led to these answers in a such a way as to avoid incoherency. Suppose that just as before and for the same reasons, we assign, at stage (a), the credences: 2 1 Pr(tails) = Pr(I'm in cell #1| tails) = 1 14 100 1 Pr(I'm in cell #1| heads) = Now, if the only epistemic difference between stage (a) and stage (b) is that at the latter stage you have the additional piece of information that you are in cell #1, then Bayesian conditionalization of the above conditional credences entails (as in model 1) that your posterior credence must be: 101 100 Prposterior (tails) = Pr(tails | I'm in cell #1) = . However, when we take SSSA into account, we see that there are other epistemic differences between stages (a) and (b). In addition to gaining the information that you are in cell #1, you also lose information when you enter stage (b). At stage (a), you knew that you were currently an observer-moment who is ignorant about which cell you are in and who is pondering different possibilities. At stage (b), you no longer know this piece of indexical information, because it is no longer true of you that you currently are such an observer-moment. You do know that you are an observer who previously was at stage (a), but this is an indexically different piece of knowledge from knowing that you are currently at stage (a). Since your total information at stage (b) is not equal to the information you had at stage (a) conjoined with the proposition that you are in cell #1, there is therefore no requirement that your beliefs at stage (b) be obtained by conditionalizing your stage (a) credence function on the proposition that you are in cell #1.