2013-06-13

Political banking

If you want to steer a course for disaster, there are certain strategies which are better than others. "Never get involved in a land war in Asia" is a good one, as is "Never go against a Sicilian when death is on the line," and of course "when someone assures you that a high tension cable is powered down, tell them to touch it before you go near it." Along with those, I'd add never let politicians take charge of a bank:

The surprise announcement of Hester's departure [from Royal Bank of Scotland] came after the stock market had closed. It then emerged that Osborne met the bank's chairman, Sir Philip Hampton, last week to discuss the succession planning being undertaken by the bank, which is aiming for privatisation by the end of 2014.
A certain amount of reading between the lines suggests that it had become politically expedient for both the RBS board and the UK Treasury for Hester to leave, allowing him to carry off a certain amount of blame for RBS's failure to lend sufficiently to small businesses. Of course, this failure was because RBS, being a bank, likes leaving easy money in the form of high-interest loans to good prospects on the table.

Hester has had nearly five years at RBS, parachuted in with no real prospect of earning big bucks from the bank (due to ritual public outcry). As far as I can see, he's done a solid job navigating the bank back in the general direction of future profitability, albeit assisted by the BoE keeping interest rates at rock-bottom. But now he's thrown overboard by the board, no doubt because he's a political liability, to be replaced with someone else who's suitably unknown and politically inoffensive, in preparation for an eventual privatisation and claims of "getting taxpayer money back" (even if the taxpayer would be better off with a later and slower sale).

We trust the Government with getting "our money" back from the bank, but in reality the only interest the Government has is in seeming to get something done. If we want value for money from a bank in which we have a financial interest, letting its direction be controlled by politicians may not prove that fruitful.

2013-06-11

Polly Toynbee and her posterior gaseous emissions

I do try to stay away from Polly Toynbee's CiF columns. I swear, they're so bad for my blood pressure. But her latest opus breaches the dikes of my self control:

Published this week, The Entrepreneurial State, by Professor Mariana Mazzucato of Sussex University, offers a forensic analysis of how the state is prime investor and creator of most great innovations.
Oh, this will be good. Mariana Mazzucato hasn't had a meaningful job outside academe in her entire life. So what does she say?
Not only the internet but its technologies sprang from vast state investment (such as GPS and touch screens, biotech and nanotech), where the state took the risk but others took the profit; Apple and Google rode on the back of state research;
My arse, Polly. Apple (and, let's be fair, Microsoft) took inspiration for their operating systems lock, stock and barrel from Xerox PARC. Last time I checked, Xerox was a privately owned company - that had the crown jewels of the desktop computing revolution and just gave them away, but hey. Google built on the success of search engines like Alta Vista, coming up with their PageRank algorithm independently while students at Stanford University, following an education at private schools. A claim that "the state" was involved in any significant degree in either Apple's or Google's success fails even the laugh test.

Perhaps Prof. Mazzucato should stick to economics, because even my economic blatherings have more accuracy than her ventures into matters technological. She asserts:

Thus, while entrepreneurial individuals like Steve Jobs are needed, their success is nearly impossible without their ability to ride the wave of State investments. And if Europe wants its own Googles, it needs more State action, not less.
Hmm, it seems that Europe has much more State action than the USA in general and Silicon Valley in particular. So why are all the Googles, Yahoos, Microsofts etc. popping up in Silicon Valley rather than Europe? Anyone? Bueller?

2013-06-08

Facebook through a PRISM

There's a tremendous amount of hot air being talked about the alleged US Government access to personal data from the major internet companies via the supposed PRISM system. I'm not entirely sure who to believe, though I'm defaulting to "no-one"; there's no reason to trust any Government denials, nor any better reason to put faith in the technical understanding of journalists. So let's look at how PRISM might actually work from the limited point of view of snooping on Facebook.

The size of the problem

Facebook has somewhere around 1bn users, but they're not all active - indeed, they vary greatly in levels of activity. So let's say there are 250M distinct FB users per day, and they spend an average of 10 minutes per day on it with 2 activities (read a post or instant message, view a photo, update status, make or delete a friend) per minute. That's 5bn activities per day, or 60,000 per second, that you want to record. How do you find out what they are? Bear in mind that your key requirement is to be able to know who is talking to and associating with whom, and what they are saying.

Snooping at the ISP

The easiest place to start surveillance is at the user's domestic Internet Service Provider (ISP). This is where most USA-based people will connect to the Net. The user will have a public IP (internet address) which is the point where their traffic enters and exists the Net proper, and the ISP will - or should - normally know which of their users, physical locations and bank account ties to that IP. This knowledge will be looser for entities like public wi-fi networks, but they should still have physical location info e.g. the Starbucks on the corner of 5th and Maple.

Regular (HTTP) internet traffic consists of packets - consider them as postcards - with "from" and "to" Internet addresses, plus some text content. The packets are very small, so you have to be able to aggregate a lot of them in order to build up e.g. the entire contents of an email; however they have index numbers so you know what order they are supposed to be in. The "from" address will be the user's public IP, and for our purposes we know what "to" addresses belong to Facebook, so we can require the ISP to just capture those packets for our use. Assuming that we monitor all 250M people in this way, and that each "activity" is about 4KB in size (ignoring photos and voice chat) that's an average stream of 240MB/sec, nearly 2Gbits/sec that the Government has to collect from the various ISPs and process in real time. In practice you need to double that bandwidth because usage isn't flat throughout the day - there will be a definite diurnal cycle and you need to have capacity for the daily peak.

This is a substantial processing challenge but it's not impossible - the Government just has to write its own mini-Facebook back-end that records user activity, without the need to handle photos and videos, and allows them to associate Facebook IDs with real people IDs. Then they can run their own queries over that data store. They'll be writing nearly 20TB/day to that store, so they'll need quite a few hard drives (more when you consider redundancy) but hey, it's the government, they've got the spare $ somewhere.

Of course, someone has to actually pay for the hardware and bandwidth to filter, store and forward the traffic from the ISPs - more government cash - and someone's going to have to monitor and maintain it. This has to happen in nearly all USA ISPs, without any word of it getting out. I'm sure this is completely realistic.

Problem! We're primarily interested in "bloody foreigners", and not just the ones based in the USA. If two people outside the USA are communicating, even if it's via a USA-based Facebook data center, we won't even know it's happening. How can we improve this situation?

Snooping at Facebook's edge

Here we take advantage of the fact that even foreign users end up talking to a FB data center, and many of them are in the USA. (Presumably whatever we work out here could also be done by friendly governments like Eire or the UK for data centers abroad.) Instead of monitoring at the USA users' ingress points, you look at where they egress into Facebook's network. This gives you many fewer places to monitor, though obviously much more traffic per spot so you need fewer instances of hardware but at a much higher grade. You also have fewer places for news of the additional hardware installation and operation to leak from.

The IP packets still have source addresses so you know where they came into the Internet (more or less). You'll need additional collection of data from US ISPs tying IPs to locations and people, where feasible, and you won't have this quality of source information, but you can probably manage.

So far we've seen that just for Facebook you're looking at quite a substantial volume of traffic, and we've ignored all photos and videos, but you can probably infer quite a lot from this data and it doesn't seem to be an insurmountable volume. So far PRISM seems to be not technically infeasible. But there's a wrinkle...

Encryption

So far we've been blithely assuming that we can read the plain text of what the user is sending to and receiving from Facebook - the URLs, the posted text - without any problems. Indeed, HTTP - the system by which web browsers communicate with web browsers - makes it easy to read this information. An HTTP conversation happens in plain text and looks something like this:

From the browser: asking for the page "index.html" on host "www.example.com":
GET /index.html HTTP/1.1
Host: www.example.com
From the server:
HTTP/1.1 200 OK
Date: Mon, 30 Feb 2012 20:31:00 GMT
Server: Apache/2.3.4.5 (Unix) (Red-Hat/Linux)
Last-Modified: Sun, 29 Feb 2012 01:10:25 GMT
Etag: "2e70e-7d6-5f1c883b"
Content-Type: text/html; charset=UTF-8
Content-Length: 100
Connection: close

<html>
<head>
  <title>An Example Page</title>
</head>
<body>
  Hello World
</body>
</html>
The first block is the information about the server and what it's returning, the second block is the HTML page itself.

If you've got access to the stream of data between a user and a website, you can very easily work out what they're doing. You could even change the data, e.g. modifying every instance of the word "Guardian" to "Grauniad" in the stream back to the user, so that the user browsing the eponymous website gets very confused.

Luckily, some clever chaps were aware of this vulnerability of HTTP and came up with a modification: HTTP Secure (HTTPS). This is widely used, and is the default for new Facebook users. The difference it makes for our purposes is that all an external observer can see in plain text is a conversation between the browser and the Facebook server negotiating a "shared secret" - a string that both of them know but that no other observer can know. Once this is agreed, they encrypt the rest of their conversation using that shared secret. The observer can't see what URLs are being requested, or what data is returned. All they know is that IP 192.168.100.2 is communicating with Facebook, and that (judging by the encryption negotiation) they're using Internet Explorer 9. That's not a lot of use to an eavesdropper.

There are a number of approaches to compromising HTTPS sessions, but they're generally rather CPU intensive, target specific web applications, and are progressively being prevented by upgrades to the secure protocols. Here's a little light reading of some examples for the curious. Generally, the only approach that really scales is a man-in-the-middle attack. This is where an eavesdropper intercepts the user's packets to Facebook and pretends to be Facebook itself; in turn, the eavesdropper connects to Facebook pretending to be the user and relay's the user's requests and Facebook's responses.

The way that HTTPS/SSL defeats this is via Certificate Authorities, a small number of trusted firms across the world who provide the data that can verify that when you connect to a server believed to be from Facebook that the electronic signature you receive back from that server really does belong to Facebook. The ins and outs of how this works are complex, but the net effect is that it's really rather hard for even a Government to pretend to be Facebook, and requires a substantial compromise of either Facebook's secret SSL keys (so it can sign the connection just like Facebook does) or a certificate authority (so it can claim that its fake signature really is Facebook's). Even these approaches are not foolproof, and have to be cracked for each company and updated whenever each company changes its signature. Unfortunately this can be detected by browsers; for instance, modern browsers know what the real certificates should be for major websites and can warn you if someone is trying to impersonate Facebook even if a compromised certificate authority claims that they're kosher.

There's also the not insignificant issue that such an interception approach has to be at least as reliable as the servers the user connects to, and must not introduce any detectable latency into the connection despite having to relay all the traffic both ways and filter out the text it's interested in.

The killer, though is that you have to inspect all traffic to Facebook. Unlike plain text traffic, where you can easily see that packets pertain to photos or videos and ignore them, you can't tell this for HTTPS until you've intercepted the conversation and started to man-in-the-middle the connection. You've got to continue relaying the photos or video data, even though you're not interested in it, because if you drop the connection the browser will notice and so will the user. This massively magnifies the problem - you need as much processing capacity as Facebook itself has at its front ends.

Insider access

Google, Facebook et al have strenuously and specifically denied giving PRISM-like access to user data. Let's take them at their word. Assuming they're not co-operating, how would you get the access you'd like to user data without them knowing?

The most effective approach, as noted above, is to have an insider compromise their SSL secret keys. That lets you man-in-the-middle all HTTPS traffic. Unfortunately you have a very small set of insiders who have that access - and, by definition, those insiders will be as trustworthy and hard-to-compromise as possible.

The talk swanning around about "free access to data on Facebook's servers" is rubbish. There is no way any substantial routine access to user data is going unnoticed. Facebook will be monitoring read traffic, bandwidth usage, CPU and memory load for all its critical servers. If there's unexplained traffic in any volume, it's going to show up in dozens of monitoring consoles scattered all over the firm. So many people would have to be in on the snooping that word of it would inevitably leak.

Conclusion

It's just about feasible for a government to snoop on the plain-text non-photo non-video traffic for Facebook, and the best place to do it is probably where traffic exits the Internet going to Facebook's network. You're looking at a very serious amount of hardware to snoop and store the information, but it's tractable with the budget available from a major government. When it comes to routine snooping on encrypted (HTTPS) traffic though, forget it. It would require a major systematic compromise of closely-held secret keys, a very high performance software infrastructure operating at very high reliability, and - the killer - would have to be able to deal with as much traffic as the Facebook front ends themselves do. By extension, the same is true for Google, Yahoo, Microsoft etc. The Government is going to require inconveniently large amounts of hardware placed inconveniently close to the major Facebook, Google and Microsoft data centers.

I should add that the alleged $20M/year cost of PRISM would cover the capital costs of about 15,000 servers written off over 3 years (say, $4000 per server since you have to cover associated network, power and cooling infrastructure). That's really not a lot. If you have 5 TB of storage per server, that's 75,0000 TB over 3 years; the above requirements just for Facebook basics would be about 21,000 TB over that time, and you'd have to at least double that for redundancy. This doesn't even approach all the other personnel and software development costs.

Conclusion: the scope of PRISM has almost certainly been massively exaggerated. Journalists have been taken for a ride.

2013-06-05

Emma Sinclair needs to extract her head before she suffocates

Ex-investment banker and "serial entrepreneur" Emma Sinclair writes indignantly in the Telegraph on the sexism perpetuated by the GS Elevator advice for summer interns:

I was an investment banker post university so I know what sort of stereotypes to expect and at times, they are funny.
[...]
Tip 8 says "As it relates to fellow interns, make no mistake about it - it's war: Let's be clear. It's impossible to compete with female interns. And it's not cool. So don't bother trying."
Tip 8 is actually true. Women are so painfully under-represented in front desk roles in banking that HR have decided that a) banks will hire female interns disproportionately in order to try to redress the numbers and b) said interns are essentially untouchable in peer assessments. They'll always end up out-scoring all but the top-end male interns, simply because no sane associate, VP or MD wants to be on record giving a female intern a bad score. The only exception is if the female intern in question does a Lucy Gao.

Ironically, this has precisely the opposite effect of that ostensibly desired by HR. Everyone rolls their eyes when a female intern turns up at their desk, precisely because they know that the principal factor in her hiring was her lack of Y chromosones. I invite you to consider how demeaning this is for the subset of female interns who are as able, if not more able, than their male counterparts. Incidentally, if you want to know why successful women in banking are some of the worst chauvinists, this is a major factor.

Emma is also not keen on Tip 12:

Ask the secretary for the travel schedules of the senior members of your group for the week ahead. She's dumb enough to think you are being proactive. But now you know when you can sleep in, hit the gym, or beat the traffic.
Emma takes umbrage, noting that her secretary was male. But Emma, darling, secretaries are almost universally female. They're a lot more organised than many bankers, but they're not generally as Machiavellian or plotting. A position as a secretary in an investment bank is well paid but generally not fulfilling since you have to deal with the obnoxious alpha++ personalities in detail and take the flak if anything goes wrong with their meetings or travel. The only real upside is the chance of meeting a hot MD or PMD who's not a total asshole and getting hitched. This is not a strategy with a high payoff rate for blokes.

I wonder why Emma didn't touch on Tip 9?

Don't be too good to do the coffee runs. It shows confidence. Just don't fuck it up. If you can't be trusted with coffee, how can you sell bonds or manage risk.
Yes, Emma, all interns do coffee runs, irrespective of gender. How egalitarian - why didn't you mention it? Did it undermine your narrative?

I'd love to know the details of Emma Sinclair's investment banking career. I suspect she flamed out in short order, and the fact that she could recognise Lloyd Blankfein's face indicates it may well have been at Goldman Sachs itself. It's fine to blame this on a sexist environment, and investment banking is still pretty sexist, but don't blame GS Elevator for giving interns advice that actually reflects the workplace.

2013-06-03

Free speech - we've heard of it

Clucking bell. A couple of Gwent Community Support Officers could do with some sensitivity training:

Matthew Taylor, 35, the owner of Taylor's clothes store on Emlyn Walk in the city, printed up and displayed the T-shirt with the slogan: "Obey our laws, respect our beliefs or get out of our country" after Drummer Lee Rigby, 25, was killed in near [sic] Woolwich barracks in London last week.
Following a complaint from a member of the public (I'm really curious about who this was, but I'd probably bet a fiver that they were white and an avid reader of The Guardian) the CSOs dropped by to advise Mr. Taylor that someone had found the shirt design offensive. At this point Mr. Taylor advised the CSOs in turn of his right of freedom of expression, pointed out the lack of targeting at any ethnic, racial or religious group, and the CSOs accepted his argument and departed peacefully.

Kidding! Mr. Taylor ended up removing the shirt from display:

A spokeswoman for Gwent police confirmed: "We did have a call from a member of the public. We visited the shop and asked him to remove it (the T-shirt) as it could be seen to be inciting racial hatred."
Holy little green apples. Was the spokeswoman fighting to keep a straight face when she said this? Racial hatred against whom? Indonesians? Scots? Gloucestersharians? Inuits? Criminals? If this had been the CSOs being a little over-zealous then I could almost understand this, but Gwent Heddlau backing up the action makes me despair for humankind. I can't help but feel that the late lamented Inspector Gadget was spot on here - this is what you get, and the mindset of people you end up hiring, when you create lots of comfortable REMF diversity-related jobs.

As a thought experiment, what if the shirt had said the same thing but in Welsh? What if it said "Obey our laws, stop claiming illegitimate expenses or get out of our Parliament"? Perhaps, to gather better data, Mr. Taylor should produce sample shirts with a range of variations on the theme, sit back and watch to see which ones the police make him remove. Better yet, his MP should back him up, tell him to reinstate the line at his convenience, and tell Gwent police and the local busybodies to take a running jump.

Someone who wasn't paying much attention in his "Life in the UK" test was Newport city councillor, Majid Rahman:

I believe in freedom of speech and defend his rights to say what he wants, but once it starts offending people then it's a police matter and it's up to them whether they think it's broken any laws.
Wow. Well, I'm offended by people claiming that Marmite tastes delicious. We should definitely refer the matter to the police for further consideration. I didn't realise that offending people was ipso facto grounds for a criminal complaint...

2013-06-01

Illegal car sales

Thank goodness for the American legislature protecting the consumer from evil predations of private firms. North Carolina has taken a great step forward by aiming to make it illegal to buy cars online:

In North Carolina, a bill in the works would make it illegal to sell a car online. Can you imagine that? The black clad ninjas may be headed Tesla's way – not for ripping off taxpayers by forcing them to subsidize the making of economically untenable electric cars – but for how they are sold.
You can configure your Tesla online, submit your order online, and get your car delivered to your door. No salesman involved. No need to go to a dealership. No-one trying to stick his hand into your wallet, haze you about the car buying process, trick you into bad extended financing or warranty deals. How will the car salesweasels make a profitable living from you? The National Automobile Dealers Association (NADA) has been strenuously lobbying to protect its members' livelihoods. Of course, this means that anyone in North Caroline (or Texas, or Virginia) is going to have to jump through hoops to buy a Tesla, assuming they have the $60K-$90K necessary in the first place.

Eric Peters is quite clear on the future of car buying that Tesla portends:

Imagine how neat it would be if you could go online and shop for your next new car – your next new Chevy, Honda or whatever kind of car. Pick only the options you want, on an a la carte basis – not "bundled packages" heavily marked up. The price for the car – and each option – is right there, clearly stated. No bullshit. No deliberately obfuscatory paperwork. No haggling. No hassles.
And no middlemen.
The Internet is famously great at removing the middleman from transactions. Understandably, the middlemen aren't keen on this, but it's not the job of the legislature to protect the middlemen. Not unless they want to join the car salesmen, real estate agents and HMO administrators in being hung from the nearest lamp post.

A Greek on Greeks

I was privileged to sit beside a rather interesting Greek lady on a flight the other day. Well into her 80's, she was flying back to the homeland to spend a few weeks with her family. Her sons had seen her to the airport, but she was otherwise making the multi-segment journey alone. She was a very self-possessed and chatty lady, and the otherwise tedious flight simply flew by as we talked. She made an excellent sales pitch to me for spending a vacation in the islands where she would be staying.

We got talking, and the topic of conversation turned to Greece itself. She had left the country several decades ago to live and work abroad, and had prospered there. She was in no doubt about why Greece was in its current state. "They just don't pay taxes," she explained. "There's no respect for the law." She personally knew of several people in her small Greek home town who went to the town hall each month to claim their state disability benefit for blindness, then happily drove back home. She was quite happy to pay taxes in her adopted country, and benefit from the relatively ordered society that those taxes funded, but was appalled at the mentality of consumption without contribution back in Greece.

While "anecdote" is famously distinct from "data" (except in the case of short stories about Brent Spiner) it seems that even the Greeks don't feel that the structure of current Greek society is particularly sustainable.

2013-05-26

The Apple tax bandwagon

Noted tax expert[1] Robert Reich lays into Apple's tax affairs in the Guardian:

The same disconnect is breaking out in the US. A Senate report criticises Apple for shifting billions of dollars in profits into Irish affiliates where its tax rate is less than 2%, yet a growing chorus of senators and representatives call for lower corporate taxes in order to make the US more competitive.
Nice strawman, Robbie m' boy. Apple isn't shifting profits out of the US. Apple is making profits outside the US (principally throughout Europe), registering income in its office in the low-tax environment of Eire - as explicitly provisioned in European laws - and is not moving such profits back into the USA because it doesn't want to pay 35% in tax for the privilege. It would rather keep profits abroad and look for opportunities to use them.

If the USA wants to see any tax from this money earned abroad, it will have to be repatriated into the USA in order to be taxable. Apple can't be forced to repatriate that money. In fact, Apple would rather raise $17bn of money via a debt offering than repatriate money from Eire.

Robert Reich also doesn't seem to pay much attention to his tax return:

Individual states in the US have embarked on their own races to the bottom, seeking to lure investments and jobs – often from neighbouring states – with lower taxes, higher subsidies, reduced regulation and lower real wages. Here again, the new generation of information technologies is intensifying the race.
I'd point out that Apple, Facebook, Cisco and Google are all headquartered in California - with one of the highest state tax rates in the USA. Jed Kolko from real estate firm Trulia additionally points out that the race to the bottom for taxes, such as it is, applies to people not firms. A lot of cutting edge IT firms still rise in Silicon Valley due to a combination of people for hire, VC firms and the pleasant environment. Tax competition isn't likely to change this very much.

Here comes the pitch:

Similarly, the EU could be a bargaining agent for its citizens if it were to condition access to its hugely valuable market on paying taxes in proportion to a global corporation's EU earnings, as well as making investments (including research and development, and jobs) in similar proportion.
So as well as paying sales taxes on everything you sell in the EU, you'd have to pay additional income taxes on the profits you make in the EU (which are then taxed again when and if they are repatriated to the USA to pay shareholders.) You'd have to invest in R+D in the EU, no matter whether you can find a good environment for that research. Someone in the government is going to have to decide whether what you're doing is actually R+D and whether you're contributing enough money to your EU research facilities. What could possibly go wrong?

Reich's take on the implications of this are ass-backwards to mine:

As a member of the EU, Britain would have more bargaining leverage than it would if it bargained separately. Hence, an important reason for Britain to remain in the EU: rather than a race to the bottom, the UK would thereby join in a race to the top.
On the other hand, if the EU takes this approach, and the UK makes a more congenial business environment, the UK will benefit from the additional taxes and R+D facilities because they're not burdening the businesses with additional regulation. I'm surprised that Robert Reich hasn't come across the Prisoner's Dilemma and its implications in his academic studies.

[1] Not really; professor of public policy at the University of Berkeley, California. He knows about as much about tax as I do about sewer planning. He was Labor Secretary under Clinton and lobbied for a minimum wage increase, which should calibrate one's expectations about his economic nous.

2013-05-23

CYA is SOP at the MoD

Following Wednesday's brutal killing of a soldier, the MoD is keen to slam the stable door shut:

Defence sources said the order had been given that uniform should not be worn by those travelling alone, or on public transport as a "common sense precaution" immediately after the killing
Except - and correct me if I'm wrong here - the slain soldier was not in military uniform of any kind. He was wearing a Help for Heroes T-shirt. The killers (who appear to have been acting alone) seem to have had additional information identifying him as a soldier, such as following him from the barracks.

The MoD REMFs issuing this order should be pressed to explain a) how absence of military uniform will prevent those anti-military elements from identifying soldiers in other ways and b) if these homicidal idiots were acting alone, why there is any reason to believe the current known threat to military personnel is any different from last week when they were not offering this advice. "Security" as a blanket response should be publicly derided, or at least run by a suitably cleared and independent politician to confirm that the security issue is real. Optionally, they should also explain why, if there is a significant short-term threat to personal safety of military personnel, said personnel should not be carrying personal sidearms.

I hate this kind of instinctive cover-your-arse move from the desk security weasels at the MoD. Either they have to admit that they are powerless to stop this kind of attack - in which case, what are we paying them for? - or they generate this fog of pointless and annoying restrictions solely for their own personal benefit to be seen as "doing something".

Smug fruitivists

If there's one thing that really gets on my mammary glands, it's shrill self-righteous protestors at shareholder meetings, and McDonald's recent event is a case in point. Original USA Today report here.

'Mr. Thompson, don't you want kids to be healthy so they can live a long and healthy life?' she asked during the meeting's question and answer session.
Hannah has been well schooled in healthy eating; her mother, Kia, is a children's nutritional activist and creator of 'Today I Ate a Rainbow' - a game encouraging children to eat different fruits.
Well, that was diligent research by the reporters from just the name of the girl - turning up the mother's occupation and commercial interests. I'm sure that they didn't do anything like take this information from a press release handed out by the girl's mother and not report this. Heaven forfend.

Incidentally, I'm curious to know whether Hannah is a shareholder. Her mother might be (probably a single-digit clutch of shares, purchased solely for attendance rights) but it seems unlikely, if not impossible, for Hannah to hold the shares. Anyone know?

So the McDonald's CEO took the question at face value:

"We don't sell junk food," he said. "My kids also eat McDonald's."
Thompson noted that he — like other parents — watches what his kids eat. "We cook lots of fruits and veggies at home," he said. He also noted that McDonald's sells fruits (apple slices in kids meals) and veggies (including side salads on the Dollar Menu). He also said that McDonald's recently began to sell fat-free chocolate milk.
This wasn't a bad deflection, but honestly I'd have gone further. After all, if I stood up at the shareholder meeting of a vegetarian restaurant chain and asked the CEO: "Mrs. Smith, don't you want kids to be healthy so they can live a long and healthy life? Why don't you serve food that's packed with protein and essential trace elements, like chicken and beef?" I wouldn't expect such a courteous response. The vegetarians in the audience would physically attack me. I don't fancy their chances though, as they'd be on average rather underweight on muscle and unaccustomed to the physical violence inherent in meat production and consumption. The press would pillory me for causing trouble. The CEO would throw her tofu snacks at me.

If you're looking to feed your children healthy food, you don't take them to McDonald's. This is not rocket science, for goodness' sake. Burgers and chips are not health food. Everyone knows this. It's not like selling roast asparagus secretly infused with lethal levels of pork fat (mmmmmm... sorry, got distracted). Now there may be parents who feed their kids McDonald's food five days a week - where do they find the money? - but it doesn't seem to me that this should be McDonald's problem.

I'm not blaming Hannah, who has no doubt been indoctrinated by her mother from an early age. I'm not even blaming her mother for being rampantly capitalist in using a McDonald's shareholder meeting as free publicity for her interactive nutrition game. (Kia Robinson, if you're reading this, I want 50c per page view of this article for the advertising.) I'm blaming a credulous press who are happy to bash "big corporations" without actually asking the difficult questions about who is failing to feed their children a balanced diet.