Showing posts with label Telecom Privacy. Show all posts
Showing posts with label Telecom Privacy. Show all posts

Thursday, October 13, 2011

A Near Privacy Sweep in California…With One BIG Exception

It was a near legislative sweep for privacy advocates this year as Governor Brown signed all but one of the key privacy bills that reached his desk. These include: 

SB 602 (Yee) will ensure that government and third parties cannot access private reading records without proper justification. This is no small victory being that digital books will store data that can include books browsed, how long a page is viewed, and even the electronic notes written in the margins. It's not hard to see the detailed portrait of your life such information could paint.


AB 22 (Mendoza) will prohibit a prospective employer from using consumer credit reports in the hiring process unless it’s directly related to the job. This bill was one of our top priorities this year for a number of reasons, including: credit reports do not have predictive value in determining a worker’s ability to perform job duties, while a bad credit report might unfairly influence a hiring employer’s attitude toward a job applicant; a significant percentage of credit reports are inaccurate, and correcting such information in a credit report is a tedious, time consuming affair; and millions of peoples credit scores have been decimated by a Great Recession that was no fault of their own, but in fact due to the actions of some of the very interests that then arbitrarily determine ones credit rating. For all of those reasons and more this legislation was a victory for both privacy and economic justice.

SB 24 (Simitian) will provide an important upgrade to California's landmark breach notification law. It spells out which key details must be included in that notification letter, and would make sure the Attorney General hears about the breach. SB 24 will help consumers make sense of these notices, and help arm us to stop identity theft. Sony, Citibank, and the Bay Area Rapid Transit District are recent examples of businesses and government agencies whose customers’ records were stolen by hackers.

And just a few weeks ago it was revealed that 300,000 Californians’ intimate medical records, along with their social security numbers, were viewable for months to anyone with an internet connection, owing to an insurance processing business’ failure to safeguard its electronic data files. This massive medical records data breach leads us to another privacy related legislative victory: SB 850 (Leno), which will expand the Confidentiality of Medical Information Act to both written and electronic health records.

Also of note, but not a high priority for CFC this year, was the signing of SB 208 (Alquist), which will authorize restitution to an identity theft victim for expenses to monitor a credit report and for the costs to repair a credit rating, and SB 636 (Corbett), which will provide further protection to individuals participating in the Safe at Home Program by prohibiting their addresses and telephone numbers from being posted on the Internet, and establishing crimes for publishing or failing to remove their identifying information.

The Big Disappointment: Governor Vetoes SB 914 (Leno) - Police Search of Smart Phones

Currently police can seize and search an individual’s smart phone or android without a warrant, just like a traditional cell phone. SB 914 would have clarified that an arrestee’s cell phone can only be accessed with a warrant, except in circumstances where there is an immediate threat to public safety or the arresting officer. It acknowledges that accessing information on a cell phone is fundamentally different than searching an arrested person’s wallet, cigarette pack or jeans pockets.

Being that modern cell phones are becoming more like all purpose computers, and therefore contain ALL KINDS of personal, private information, the authorities should not be granted the right to that information without a warrant.

Unfortunately, in 2007, California's Supreme Court ruled against such a distinction, arguing, "The cell phone was an item (of personal property) on the person at the time of his arrest and during the administrative processing at the police station. Because the cell phone was immediately associated with defendant’s person, (police were) entitled to inspect its contents without a warrant." 

But these justices went even further - comparing the cell phone to personal effects like clothing. Worse, it argued that it wasn't because the police had a particular right in this particular case, or there was some special exception that allowed such a search, but rather, that no exception was even necessary. In other words, this case was not an exception, but rather the NEW rule: cell phone records are now of little difference than the shirt on your back if you've been arrested.

Dissenting Justice Kathryn Werdegar raised similar concerns we have in her opinion: "The majority’s holding ... (grants) police carte blanche, with no showing of exigency, to rummage at leisure through the wealth of personal and business information that can be carried on a mobile phone or handheld computer merely because the device was taken from an arrestee’s person...The majority thus sanctions a highly intrusive and unjustified type of search, one meeting neither the warrant requirement nor the reasonableness requirement of the Fourth Amendment to the United States Constitution."

In response to the ruling, Jonathan Turley, a Constitutional law expert at George Washington University, seconded Justice’s fourth amendment related concerns, "The Court has left the Fourth Amendment in tatters and this ruling is the natural extension of that trend. While the Framers wanted to require warrants for searches and seizures, the Court now allows the vast majority of searches and seizures to occur without warrants. As a result, the California Supreme Court would allow police to open cell phone files — the modern equivalent of letter and personal messages.”

In light of increasing economic injustice and income inequality, and the likewise growth in number and size in protests across the country, granting authorities such powers should be viewed with great skepticism and caution. As State Senator Mark Leno noted, "If you like to attend political rallies, parades, protests or sit-ins, you might consider leaving your cell phone at home in the unlikely event arrests are made. A recent California Supreme Court decision allows police to rummage through all of the private information on your smart phone as part of an arrest, including your text messages and e-mails. This warrantless search is now legal in California, regardless of whether the information on the phone is relevant to the arrest or if criminal charges are ever filed.”

This fight isn’t over. Senator Mark Leno has indicated he will bring this legislation back next year in another effort to overturn the state Supreme Court’s ruling. Clearly, in this case and many others like it in the age of the Patriot Act and the War on Terror, Governor Brown was mistaken in his veto message when he said the courts are "better suited" than legislators to decide when a search is legal. Perhaps in most cases this is true...but not when they are so clearly in conflict with something as fundamental to our basic rights as the Fourth Amendment. Let’s hope we can change the Governors mind next year.

Wednesday, August 3, 2011

Locational Tracking and the "Secret Patriot Act" Provision

Just last week, and before that in a recent op-ed I wrote on the Patriot Act, I've mentioned what some call "Secret Patriot Act" provisions and whether they relate to the government using cellular data to track Americans as they move around the U.S.

Here's the key point: the government has been claiming information regarding its interpretations and uses of the Patriot Act - particularly in relation to surveillance of American citizens - is classified. What tipped people like myself off that something was especially fishy were Senators Ron Wyden and Mark Udall sounding the alarm bells consistently and passionately for months now regarding this "secret legal interpretation" of the Patriot Act  - one they claim is so broad that it gives the government massive domestic surveillance powers.


Wyden recently even said, "When the American people find out how their government has secretly interpreted the Patriot Act they will be stunned and they will be angry." And, as a member of the Senate Intelligence Committee Wyden is in a position to know, as he receives classified briefings from the executive branch. 

Their requests for transparency has of course been met with obfuscation and denial from the Administration and Justice Department.

The good news is that Senator Wyden doesn't appear ready to take "no" for an answer, and is using the re-authorization of the Foreign Intelligence Surveillance Act (FISA) - adopted in 2008 essentially legalizing President George W. Bush’s “warrantless wiretapping” program - as the vehicle to get answers.

This FISA 2.0 law - abhorred by privacy advocates and civil libertarians - is set to expire by the end of next year, and is currently being heard in the Senate's Select Committee on Intelligence, of which Wyden is a member.

Of course, as has become typical when it comes to issues like privacy and surveillance, this proposed 2 1/2-year extension was inserted without any public notice into the Intelligence Authorization Act for the fiscal year that begins Oct. 1.  

As AP reported, "The move was unusual because it took place a full year and a half before the law's expiration date. Ordinarily, a proposed extension isn't brought up until closer to the expiration date of the law."

The bad news is that the intelligence bill was approved Monday by the Committee on Intelligence, would extend the 2008 changes until 2015. As the LA Times noted, "Those changes greatly expanded the government’s surveillance authorities. The targets must be foreigners out of the country, but their conversations with Americans are fair game. Senator vows to block surveillance bill over privacy concerns."

Also unfortunately, a measure by Sens. Ron Wyden and Mark Udall that would have forced the U.S. intelligence chief, and by extension the entire intelligence community, to admit that they went too far in their Patriot Act interpretations, was defeated.  

Essentially, Wyden and Udall asked that their colleagues include a measure compelling the Director of National Intelligence and the Attorney General to produce a “detailed assessment of the problems posed by the reliance of government agencies” on “interpretations of domestic surveillance authorities that are inconsistent with the understanding of such authorities by the public.” 

Specifically, Attorney General Eric Holder and Director of National Intelligence James Clapper would have to produce “a plan for addressing such problems” with secret legal interpretations regarding the Foreign Intelligence Surveillance Act (FISA) and the Patriot Act.

The Committee also rejected an amendment by Wyden and Udall that would have required the Justice Department to estimate how many Americans have been eavesdropped on, in violation of another surveillance law, the FISA Amendments Act of 2008. That amendment was voted down, 7-8.

Now, while we can't be sure what these senators are referring to, the evidence suggests, and some assert, that the current administration is using Section 215 of the Patriot Act - a provision that gives the government access to "business records" - as the legal basis for the large-scale collection of cell phone location records. 

And remember, mobile telephone users have LOTS of reasons to be concerned about this too. Consider:
  • In just a 13-month period, Sprint received over 8 million demands for location information;  
  • Michigan police sought information about every mobile phone near the site of a planned labor protest;
  • This spring, researchers revealed that iPhones were collecting and storing location information;
  • Just last week, the general counsel of the National Security Agency suggested to members of Congress that the NSA might have the authority to collect the location information of American citizens inside the U.S.
Watch Wyden here!



    Now, in response to this string of setbacks and stonewalling, Senator Wyden is vowing to block the surveillance bill altogether! The Los Angeles Times has more:

    Sen. Ron Wyden (D-Ore.) will seek to block passage of an intelligence bill that extends the government’s eavesdropping authorities because the intelligence community won’t say how many Americans are being monitored... 

    ... 

    "Congress passed the FISA Amendments Act in 2008 in an effort to give the government new authorities to conduct surveillance of foreigners outside the United States,” Wyden said in a statement. “The bill contained an expiration date of December 2012, and the purpose of this expiration date was to force members of Congress to come back in a few years and examine whether these new authorities had been interpreted and implemented as intended,” Wyden wrote. “I believe that Congress has not yet adequately examined this issue, and that there are important questions that need to be answered before the FISA

    After first opposing them, then-Sen. Obama voted for the 2008 FISA changes, which gave legal immunity to telecom companies that cooperated with Bush’s spying program. He said he became convinced the capabilities were needed to hunt for terrorists.

    ...


    Wyden also wants to know to what extent the government is tracking the location of Americans using data from their cellphones. Mobile devices are regularly telling their networks where they are, even when the use is not making a call, and that data is regularly used by law enforcement to track criminal suspects and fugitives. Whether intelligence agencies are doing that domestically is an open question.

    ...


    “During a July 2011 committee hearing, the general counsel of the National Security Agency acknowledged that certain legal pleadings by the executive branch and court opinions from the Foreign Intelligence Surveillance Court regarding the Patriot Act are classified,” Wyden and Udall said in dissent included in the Senate committee report on the bill. “We have had the opportunity to review these pleadings and rulings, and we believe that most members of the American public would be very surprised to learn how federal surveillance law is being interpreted in secret.”

    ...

    Wyden said he is placing a “hold” on the bill, a parliamentary maneuver that will make it much more difficult to pass. “I regret that the amendment that Sen. Udall of Colorado and I offered was not adopted, but I obviously plan to keep trying to get more information about the effects of this law,” Wyden said. “I hope that I will find out that no law-abiding Americans, or at least very few, have had their communications reviewed by government agencies as a result of this law, but I believe that I have a responsibility to get concrete facts rather than just hope that this is not the case.  And I believe that it would be not be responsible for the Senate to pass a multi-year extension of the FISA Amendments Act until I and others who have concerns have had our questions answered.” 

    Click here to read more. 

    While its heartening, and frankly inspiring, to see an elected official stand so strongly in favor of the bill of rights at a time when they are viewed with such disdain by governmental and corporate power, I'm perhaps more disheartened by the fact that the Wyden/Udall Amendments can't even pass out of a Democratic controlled Committee. As for Obama's flip flopping and betrayals on privacy and civil liberties related issues, this is now expected.

    It should be noted however that Senator Wyden is by no means on his own in the locational tracking and transparency fight. Just today the ACLU of California demanded information on how police are using surveillance technology to track people. The group has asked for public records from more than 50 police agencies across state focusing on mobile phone location data, GPS tracking, information gathered from social networking sites.

    From the groups release: "Demanding to know when, why, and how police are using mobile phone location data and deploying other surveillance technologies to track the people they are responsible for protecting and serving, the ACLU of California sent requests to more than fifty law enforcement agencies across the state today.  Today’s requests are part of the ACLU’s Demand your dotRights Campaign, designed to make sure that as technology advances, our privacy rights are not left behind. The Public Request Act inquiries are being filed in coordination with 33 American Civil Liberties Union affiliates across the nation.

    “The public has a right to know how and under what circumstances their personal information is being accessed by the government," said Peter Bibring, staff attorney with the ACLU of California.  "A detailed history of someone's movements – or the email and photographs stored in their mobile device - is extremely personal and exactly the kind of private information that the Fourth Amendment was written to protect." 

    In addition to the collection of mobile phone location data, the ACLU of California is asking the same questions about law enforcements’ use of information gathered from social networking sites, book providers, GPS tracking devices, automatic license plate readers, public video surveillance cameras and facial recognition technology.

    Police agencies are being asked for information including:
    • Statistics on how agencies are obtaining, using, storing and sharing personal information;
    • The stated purpose for gathering personal information, guidelines on how long the data is kept, when and how it is deleted, and whether privacy safeguards exist;
    • Training curricula, policies or protocol provided to officers to guide them in the use of these powerful new surveillance tools, including the capture of information from social networking sites like Facebook and Twitter;
    • Whether police demonstrate probable cause and obtain a warrant to access mobile phone location data and to collect other detailed personal information, or take a dragnet approach that captures data on individuals who are not suspected of wrongdoing;
    • The effectiveness of the use of digital surveillance in identifying or arresting suspects.
    “Unless we require transparency on the part of police agencies, powerful new methods of surveillance will become powerful new methods of invading our privacy,” said ACLU of California  attorney Linda Lye.

    With Congress considering new legislation to better safeguard location information and the U.S. Supreme Court poised to hear a case about the privacy of location data in the context of GPS tracking devices, it is essential for the American public to have a clear picture about when, why, and how law enforcement are obtaining sensitive location information.

    “It’s important to understand whether police agencies are using new surveillance technologies in ways that serve legitimate law enforcement goals and actually make us safer,” said ACLU of California attorney David Blair Loy."

    Wednesday, July 27, 2011

    Is the Government Locational Tracking US Citizens Movements?

    Is the government using cellular data to track Americans as they move around the U.S.?

    That was the question posed to the Mathew Olsen - who is currently at the NSA and has been nominated to lead the National Counterterrorism Center - at his confirmation hearing Tuesday morning in the Senate Select Committee on Intelligence.

    Now, one would expect, and certainly hope, that an immediate, forcefully delivered "no" came in response to that question. Unfortunately what we got instead was the acknowledgement that in fact, according to the general counsel of the National Security Agency, "There are certain circumstances where that authority may exist." Providing little more comfort, Olsen went on to say “it is a very complicated question” and that the intelligence community is working on a memo that will provide a better answer for the committee.

    I addressed this concern, particularly as it relates to a provision of the Patriot Act, in my article "The Patriot Act and the Quiet Death of the US Bill of Rights". In it I wrote, "In other words, the precedent set by the Patriot Act appears to be serving to accelerate the rapid disintegration of civil liberties in this country.

    Of equal concern is what we still don’t know about how the government might be using the Act, highlighted by recent statements made by US Senators regarding what they termed “secret Patriot Act provisions”. Senator Ron Wyden (D-OR), an outspoken critic of the recent reauthorization, stated, "When the American people find out how their government has secretly interpreted the Patriot Act they will be stunned and they will be angry." As a member of the Senate Intelligence Committee Wyden is in a position to know, as he receives classified briefings from the executive branch. 

    In recent years, three other current and former members of the US Senate - Mark Udall (D-CO), Dick Durbin (D-IL), and Russ Feingold (D-WI) - have provided similar warnings. We can't be sure what these senators are referring to, but the evidence suggests, and some assert, that the current administration is using Section 215 of the Patriot Act - a provision that gives the government access to "business records" - as the legal basis for the large-scale collection of cell phone location records. 

    The fact that in 2009 Sprint disclosed that law enforcement made 8 million requests in 2008 alone for its customer’s cell phone GPS data for purposes of locational tracking should only add to these legitimate privacy concerns

    And that's not all. Back in 2009, the Washington Post reported that while serving as a U.S. attorney during the Bush administration, Christopher Christie tracked the whereabouts of citizens through their cell phones without warrants. The ACLU obtained these documents from the Justice Department in an ongoing lawsuit over cell phone tracking. While the documents reveal 79 such cases on or after Sept. 12, 2001, they do not specify how many of the applications were made during Christie's tenure.

    Tracking without a warrant disregards an internal U.S. Justice Department recommendation that prosecutors obtain probable cause warrants before gathering location data from cell phones. Of the cases in which probable cause wasn't established, documents showed 19 allowed the most precise tracking available. Those cases occurred after the November 2007 Justice Department recommendation that prosecutors seek warrants.

    So we know this has gone on before. Perhaps that's why Senators Wyden and Udall recently introduced an amendment to the Patriot Act (rejected) calling upon the Attorney General to publish a report in the Federal Register that details, without describing specific surveillance programs, the Department's "legal interpretations and analysis necessary to understand the United States Government's official interpretation of" FISA (Because Section 215 of the PATRIOT Act modified FISA, this may be aimed in part at clarifying the reach of Section 215.)

    Wyden is also currently working on legislation that could become part of the chamber’s larger effort to set new rules for how and when federal law enforcement can access consumers’ location data. In fact, these Senators have been unusually focused on pushing for tighter rules on when, and under what circumstances, can the government track an individuals cell phone.

    Of course all efforts to amend this provision and make the information public has been met by both the Obama and Bush administrations with fierce opposition, and classified briefings...meaning members those who are briefed are constrained from fully voicing their concerns, which make these Senators efforts and cryptic warnings all the more disturbing.
     
    This is why these latest revelations, and Olsen's testimony, is so interesting...and telling.

    For more on these hearings and the Olsen testimony check out this video:

    Wednesday, July 13, 2011

    The Year in Wiretapping and the FBI's Next Generation of Biometrics

    I've written a lot in recent months about the FBI's insatiable appetite for power and our apparent willingness to give it to them. In my recent Patriot Act op-ed I detailed ALL THE WAYS in which the FBI has violated the civil liberties of American citizens for all kinds of purposes OTHER than "protecting" us from terrorism.

    I also discussed the use of what are called National Security Letters (NSLs) – which allow the FBI, without a court order, to obtain telecommunication, financial and credit records deemed “relevant” to a government investigation. The FBI issues about 50,000 a year and an internal watchdog has repeatedly found the flagrant misuse of this power.

    And, I have discussed new guidelines from the Justice Department will allow FBI agents to investigate people and organizations "proactively" without firm evidence for suspecting criminal activity. The new rules will free up agents to infiltrate organizations, search household trash, use surveillance teams, search databases, and conduct lie detector tests, even without suspicion of any wrongdoing.

    All in all, its a pretty dismal report card for the health of the US Bill of Rights. Sadly, there's more to report.

    Let me begin quickly with the latest op-ed from Julian Sanchez detailing what he termed The Year in Wiretapping. Essentially, it updates a lot of the data I cited in my article. So let's get to the piece to see how our phone line privacy fared last year.

    Sanchez writes:

    ....the annual Wiretap Report was finally released by the Administrative Office of the U.S. Courts, fully two months behind schedule (the first time in over a decade it’s been so late). While we often focus on the growth of the surveillance state in the context of national security and the War on Terror—such as foreign intelligence wiretaps, which aren’t counted in this report—it’s clear that surveillance is on the rise for ordinary law enforcement purposes as well. State and federal investigators obtained 3,194 wiretap orders in 2010, an increase of 34 percent over the previous year, and a whopping 168 percent increase over 2000. Only one wiretap application was denied—which you can choose to take as evidence that law enforcement is extremely scrupulous in seeking applications, or that judges tend to rubber stamp them, according to your preferred level of paranoia....

    The average wiretap order swept up the communications of 118 people
    (since, of course, each individual target converses with many people, including many innocent people). If there were no overlap between wiretap orders, that would imply 376,892 people affected. Since it’s common for multiple orders to be sought as part of a single investigation, however, many of the same people are presumably being counted as having been caught under more than one wiretap order.  Even on the wildly charitable assumption that only a third of those were unique individuals, though, that  would still be well over 125,000 people spied upon, many innocent of any wrongdoing. 

    Though such criminal intercepts are supposed to be “minimized” in realtime, to prevent the recording of innocent conversations, only 26 percent of intercepted communications contained incriminating material—which is to say, nearly three-quarters were innocent communications unrelated to criminal activity. (It’s possible some of these were partial intercepts discontinued once investigators realized the communication wasn’t pertinent—the report doesn’t make that clear.)

    It’s worth bearing in mind here that the nature of wiretaps, as opposed to conventional physical searches, is that they always involve invading the privacy of somebody other than the target named in the warrant—indeed, as the numbers show, very many people. You have to wonder what we’d think if traditional physical search warrants permitted police to rifle through the belongings of dozens of innocent people for each genuine criminal.

    Still, this invasive technique is still reserved for investigating the most serious violent crimes, right? Alas, no: For 84 percent of wiretap applications (2,675 wiretaps), the most serious offense under investigation involved illegal drugs. Further proof, if proof were needed, that privacy suffers enormous collateral damage in our failed drug war. Drugs have long been the reason for the vast majority of wiretaps, but that trend, too, is on the upswing: Drug cases accounted for “just” 75 percent of intercept orders in 2000.



    In other words, as I wrote in my op-ed in describing Patriot Act abuses and the FBI, "Monitoring political groups and activities deemed “threatening” (i.e. environmentalists, peace activists), expanding the already disastrous and wasteful war on drugs, and spying on journalists isn’t about fighting terrorism, it’s about stifling dissent and consolidating power – at the expense of civil liberties. How ironic that the very “tool” hailed as our nation’s protector has instead been used to violate the very Constitutional protections we are allegedly defending from “attack” by outside threats. What was promised as a “temporary”, targeted law to keep us safe from terror has morphed into a rewriting of the Bill of Rights."

    But wait...I'm STILL not finished. Now comes word, with special thanks to the Electronic Frontier Foundation's Jennifer Lynch, the FBI is pursuing what can only be called the next generation of Biometrics.

    Before I get to some choice clips to Jennifer's article, let me refresh everyone on the concept of biometric identifiers - like fingerprints, facial, and/or iris scans. These essentially match an individual’s personal characteristics against an image or database of images. Initially, the system captures a fingerprint, picture, or some other personal characteristic, and transforms it into a small computer file (often called a template).

    The next time someone interacts with the system, it creates another computer file
    There are a number of reasons why such technological identifiers should concerns us.

    So let's be real clear, creating a database with millions of facial scans and thumbprints raises a host of surveillance, tracking and security question - never mind the cost.

    Privacy expert Bruce Schneier recently pointed out some of pro's and con's of a biometrics:


    On the strength side, biometrics are hard to forge. It's hard to affix a fake fingerprint to your finger or make your retina look like someone else's. Some people can mimic voices, and make-up artists can change people's faces, but these are specialized skills.

    On the other hand, biometrics are easy to steal. You leave your fingerprints everywhere you touch, your iris scan everywhere you look. Regularly, hackers have copied the prints of officials from objects they've touched, and posted them on the Internet. We haven't yet had an example of a large biometric database being hacked into, but the possibility is there. Biometrics are unique identifiers, but they're not secrets.


    With that, let's get to the article by EFF. Lynch writes:

    Last week, the Center for Constitutional Rights (CCR) and several other organizations released documents from a FOIA lawsuit that expose the concerted efforts of the FBI and DHS to build a massive database of personal and biometric information. This database, called “Next Generation Identification” (NGI), has been in the works for several years now. However, the documents CCR posted show for the first time how FBI has taken advantage of the DHS Secure Communities program and both DHS and the State Department’s civil biometric data collection programs to build out this $1 billion database.

    Unlike some government initiatives, NGI has not been a secret program. The FBI brags about it on its website (describing NGI as “bigger, faster, and better”), and both DHS and FBI have, over the past 10+ years, slowly and carefully laid the groundwork for extensive data sharing and database interoperability through publicly-available privacy impact assessments and other records. However, the fact that NGI is not secret does not make it OK. Currently, the FBI and DHS have separate databases (called IAFIS and IDENT, respectively) that each have the capacity to store an extensive amount of information—including names, addresses, social security numbers, telephone numbers, e-mail addresses, fingerprints, booking photos, unique identifying numbers, gender, race, and date of birth. Within the last few years, DHS and FBI have made their data easily searchable between the agencies. However, both databases remained independent, and were only “unimodal,” meaning they only had one biometric means of identifying someone—usually a fingerprint.


    ...

    So why should we be worried about a program like NGI, which the FBI argues will “reduce terrorist and criminal activities”? Well, the first reason is the sheer size of the database. Both DHS and FBI claim that their current biometrics databases (IDENT and IAFIS, respectively) are the each the “largest biometric database in the world.” IAFIS contains 66 million criminal records and 25 million civil records, while IDENT has over 91 million individual fingerprint records.

    Once these records are combined into one database and once that database becomes multimodal, as we discussed in our 2003 white paper on biometrics, there are several additional reasons for concern. Three of the biggest are the expanded linking and tracking capabilities associated with robust and standardized biometrics collection systems and the potential for data compromise.

    Already, the National Institute for Standards and Technology, along with other standards setting bodies, has developed standards for the exchange of biometric data. FBI, DHS and DoD’s current fingerprint databases are interoperable, indicating their systems have been designed (or re-designed) to read each others’ data. NGI will most certainly improve on this standardization. While this is good if you want to check to see if someone applying for a visa is a criminal, it has the potential to be very bad for society. Once data is standardized, it becomes much easier to use as a linking identifier, not just in interactions with the government but also across disparate databases and throughout society. This could mean that instead of being asked for your social security number the next time you apply for insurance, see your doctor, or fill out an apartment rental application, you could be asked for your thumbprint or your iris scan.

    This is a big problem if your records are ever compromised because you can’t change your biometric information like you can a unique identifying number such as an SSN. And the many recent security breaches show that we can never fully protect against these kinds of data losses.


    The third reason for concern is at the heart of much of our work at EFF. Once the collection of biometrics becomes standardized, it becomes much easier to locate and track someone across all aspects of their life. As we said in 2003, “EFF believes that perfect tracking is inimical to a free society. A society in which everyone's actions are tracked is not, in principle, free. It may be a livable society, but would not be our society.”

    Click here to read more.

    As Bruce Schneier noted, "One more problem with biometrics: they don't fail well. Passwords can be changed, but if someone copies your thumbprint, you're out of luck: you can't update your thumb. Passwords can be backed up, but if you alter your thumbprint in an accident, you're stuck. The failures don't have to be this spectacular: a voiceprint reader might not recognize someone with a sore throat, or a fingerprint reader might fail outside in freezing weather. Biometric systems need to be analyzed in light of these possibilities."

    Let's hope that none of this leads to the requirement that ALL AMERICANS carry biometric ID'S at some point, particularly with the fingerprint or the iris as the biometric identifier.

    The ACLU put together an excellent fact sheet on a variety of the privacy implications associated with biometric identifiers, including whether biometric images should be collected, which images should be collected (i.e. facial v. thumbprint scan), who has access to those images, and for what purposes being the preliminary privacy questions that should addressed to protect individuals’ constitutional right to privacy.

    Similarly, as noted by Lynch, the ACLU also warns (now becoming a reality obviously), of the creation of dossiers about individuals and their activities in which a biometric identifier is used as a unique identifier to catalogue personal information about an individual - which would enable monitoring, tracking and surveillance of individuals. This concern applies to both the government and databrokers/private industry using the same biometric to gather information.

    Also noted by the ACLU:

    Threat to Anonymity and Anonymous Speech: likelihood rises of using facial recognition to identify and surveil innocent people just walking down the street or engaged in First Amendment protected speech on political or labor issues.

    The Supreme Court has found that compelling an individual to disclose his or her political ideas or affiliations to the government deters the exercise of First Amendment rights. The right to anonymous speech, protest and leafleting are critical to our democracy.

    o Perceived Infallibility and Inaccuracy: The concept that each of us is unique does not always translate into accurate biometric identification. Computer “matches” must be reviewed visually by people to confirm the accuracy. And, even then, errors are made.

    Brandon Mayfield, the Oregon Attorney, was erroneously linked to the 2004 Madrid train bombings after his prints were misidentified and he was held by the FBI for two weeks, though he was never charged. His prints were “identified” through the Integrated Automated Fingerprint Identification System (IAFIS). IAFIS identified a few potential matches that were then reviewed by a fingerprint examiner and an outside experienced fingerprint expert.

    Certainly more to come on this issue....

    Tuesday, July 12, 2011

    Murdoch Hacking Scandal Continues to Expand

    Before I get started, here's an excellent interview of John Dean by Keith Olbermann regarding where this incredible scandal is heading...



    I want to go straight to the excellent coverage of this growing privacy debacle by Think Progress. Of particular note, Carl Bernsteing has an OUTSTANDING article in Newsweek (entitled “Murdoch’s Watergate.”) essentially blowing the roof off the Murdoch/Fox empire.

    As noted by Think Progress, Gordon Brown himself has now joined other members of his Labour Party, members of the royal family, victims of terrorism, murder, and their family members in being targeted with shady or allegedly illegal practices by the newspapers.


    Here's more: "Much of the scandal has focused on Rebekah Brooks, the CEO of News International, who was previously editor of the News of the World and the Sun. It was Brooks who contacted the Browns in 2006 to tell them that she had obtained — likely in violation of privacy rules– records showing that their four-month-old son Fraser was suffering from cystic fibrosis. 

    But while victims have demanded that Rebekah Brooks resign, Murdoch has given her an “extraordinary show of support,” taking her to dinner yesterday and saying she is his “top priority.”

    But Murdoch may soon have bigger problems on his hands. Legal experts told the AP today that his company could face criminal prosecution in the U.S. for his U.K. papers’ alleged bribery of British police officers, which would be a violation of the Foreign Corrupt Practices Act (FCPA). According to the the Department of Justice, “The FCPA prohibits payments made in order to assist the firm in obtaining or retaining business.” 

    Thus the papers’ use of bribery to obtain information which helped sell newspapers could fall under the act’s purview. And even though the bribery occurred entirely in Britian, NewsCorp is an American company, incorporated in Delaware, and held accountable for its foreign subsidiary’s actions. Even if the corporation wasn’t directly involved in bribery, it could be found in violation of the law for turning a “blind eye.”

    The legal experts told the AP they would be surprised if the Securities and Exchange Commission and the DoJ have not already opened investigations into the matter and said the decision to shutter News of the World was potentially an attempt to limit Murdoch and NewsCorp’s legal exposure. 

    NewsCorp is also the parent company of the Wall Street Journal and Fox News, which have largely ignored the scandal."

    I'll get to this more in future posts, but suffice it to say, the Murdoch empire is by far the most destructive media/propaganda force in the world today, perhaps in history, just in terms of its reach and scope. I am extremely interested to see where this all leads....

    Thursday, May 26, 2011

    CA Privacy Legislation Targeted by Google, Facebook, and Other Tech Firms

    A few weeks ago, in discussing the landmark Do Not Track bill, SB 761 (Sen. Alan Lowenthal), that would require any company collecting data from a California resident to provide a method of opting out of that data collection, I pointed out how two of privacy's greatest enemies - Facebook and Google - had come to oppose the legislation.

    Yes, strange bedfellows in once sense, but brothers in arms in another (they both are aggressive opponents of the right to privacy). Recently, there's been another bill targeted by these tech goliaths, SB 242 (Ellen Corbett).

    As noted by Bill Mullin of Paid Content, "The bill, as currently written, would require big changes to social-networking sites like Facebook. Most significantly, it would require users to set their privacy settings upon registration, rather than look for privacy settings after they’ve joined. It would also require settings to default to keeping information private, rather than making it public. (It almost doesn’t need to be said at this point, but the settings for a new Facebook profile default to public.) Willful violations of the proposed law would result in $10,000 fines."

    As he also points out, technology and social media companies, from Facebook and Google to social media startups, are starting to form active coalitions designed to prevent California privacy bills from becoming law. This anti-privacy coalition now includes Google, Facebook, Yahoo, Zynga, Oodle, an online classified site; Identified, a professional networking site; Zecco, a community investing site; and BranchOut, a professional networking service on Facebook.

    Before I get to a major article in the Wall Street Journal detailing this alliance - particularly between Google and Facebook - let me return to a couple key points by Mullin, who wrote, "It may seem surprising that national and even global tech companies might be regulated from Sacramento—but it has happened before. In fact, the requirement that websites have privacy policies displayed at all is due to a California state law passed in 2003. There is no federal requirement to have a privacy policy at all; but the California privacy law includes fairly detailed language about what must be included in a privacy policy. It also defines what constitutes personal information."

    As I said, apparently California's efforts to bring regulatory protections up to speed with rapid technological advancements is garnering some well deserved attention.

    The Wall Street Journal reports:

    There’s not much love lost between Facebook and Google these days, but the companies are joining forces in one area – fighting two online-privacy bills that are moving through the California legislature.

    One of the bills, a “do not track” proposal introduced by State Sen. Alan Lowenthal, would require companies to let people opt out of having their online data collected. The other, by State Sen. Ellen Corbett, would require social-networking sites to keep users’ information private by default and to remove personally identifying information if requested.

    Both bills were approved by the Judiciary Committee, but they face strong opposition from some big players in the state. Google Inc. and Facebook Inc. are among dozens of companies and trade groups opposing at least one of the bills.
    ....
    The bills are evidence of growing interest in privacy legislation, which is also being debated at the federal level. Last month, Sens. John Kerry (D., Mass.) and John McCain (R., Ariz.) proposed legislation that would create a “privacy bill of rights” that would let people block information from being shared and access personally identifiable information about themselves.

    And the bill from Sen. Lowenthal adds to other efforts to regulate a “do-not-track” mechanism. Earlier this month, U.S. Sen. Jay Rockefeller (D, W.Va.) proposed a bill called the Do-Not-Track Online Act of 2011 that would prohibit companies from collecting information from people who have indicated they don’t want to be tracked. The Federal Trade Commission has discussed requiring companies to honor such opt-outs.

    This year, makers of the Firefox, Internet Explorer and Safari Web browsers have all made tools within their browsers that let users indicate they don’t want to be tracked. But tracking companies aren’t required to honor those messages.
     ...
    The California bills are the latest in a series of moves by the state to confront privacy concerns more aggressively than the federal government has thus far. The state already allows residents to get access to some of the data companies have on them, for example.
    “There may be more of a chance for federal legislation if we see states threatening action,” said Justin Brookman, the director of the Project on Consumer Privacy at the Center for Democracy and Technology.
    Privacy advocates have praised the general intent of the California bills – giving consumers more access to their information and more control over it. But even supporters of the ideas have said there are a few problems. The bill from Sen. Corbett, for example, would allow parents to request the removal of a child’s personally identifiable information as long as the child was under 18. Proving that someone is a child’s parent or guardian would be extremely difficult, and removing teens’ information would be problematic, Mr. Brookman said. “Teenagers actually have First Amendment rights,” he added.

    To read more on the Do Not Track bill in particular, you can check out my recent posts, here, here and here

    Clearly, I believe, strongly, that consumers should have the right and ability to tell websites not to spy on them or collect detailed profiles based on what they choose to do on the web. Remember, we should OWN our data, and that means we should have control over how its used - if used at all.

    I've also often made the point, that when it comes to this issue in particular, an interesting dichotomy is at work. On one hand, while its true people seem to "care" about privacy on one level, they tend to do very little to actually do so. Which in my mind, makes easy to use, clear options to protect privacy all the more paramount. Because, once people are given such a choice, not only will more people choose to "not be tracked", I think more people will become more AWARE of just how all pervasive such monitoring of nearly everything we do has become.

    Monday, May 23, 2011

    Another "Temporary" Extension of the Patriot Act

    This is becoming an annual slap in the face to the Constitution and codification of our burgeoning security state that I have termed the "Fear Industrial Complex". Yes, its Patriot Act extension time! The Senate, thanks to a deal between majority leader Harry Reid and his Republican colleagues to sidestep debate and jam the civil liberties killing legislation through, is expected to extend the Act for another 4 years.

    Forget about the fact that if there's ANYTHING deserving of debate, its the Patriot Act. But what of this increasingly common procedure to abdicate, you know, democracy related responsibilities in Congress (War on Libya anyone?)?

    Ironically, this is EXACTLY how the PATRIOT Act first came into existence 10 years ago. No debate, no reflection on the precedent we were about to set, and no real consideration for the pandora's box we were about to open.. Yet, here we are, again, with Congress putting its stamp of approval on such "unconstitutional greatest hits"as:

    • provisions allowing broad warrants to be issued by a secretive court for any type of record, from financial to medical, without the government having to declare that the information sought is connected to a terrorism or espionage investigation; 
    • the continuation of so-called “roving wiretaps”, allowing the FBI to obtain wiretaps from the secret court, known as the FISA court, without identifying the target or what method of communication is to be tapped. 
    • the so-called “lone wolf” measure that allows FISA court warrants for the electronic monitoring of a person for whatever reason — even without showing that the suspect is an agent of a foreign power or a terrorist.
    As for the question regarding why we need more debate, and more protections, how about the report recently released in which the FBI admitted to the President’s Intelligence Oversight Board to violating the law at least 800 times on national security letters, going well beyond even the loose safeguards in the original provision. According to the report the FBI “may have violated the law or government policy as many as 3,000 times” between 2003 and 2007, according to the Justice Department Inspector General, while collecting bank, phone and credit card records using NSLs.

    But don't take my word for it. The Electronic Frontier Foundation (EFF) has found plenty of evidence regarding FBI abuses of the PATRIOT Act. For instance, the FBI itself reported nearly 800 violations of privacy laws and regulations to the President's Intelligence Oversight Board from 2001 to 2008.

    EFF said it has also uncovered "indications that the FBI may have committed upwards of 40,000 possible intelligence violations in the 9 years since 9/11." It said it could find no records of whether anyone was disciplined for the infractions.  

    We also know that the FBI used the Patriot Act under the Bush Administration to target liberal groups, particularly anti-war ones during the years between 2001 and 2006 in particular. According to a recent report by the ACLU, there have been 111 incidents of illegal domestic political surveillance since 9/11 in 33 states and the District of Columbia.

    The report shows that law enforcement and federal officials work closely to monitor the political activity of individuals deemed suspicious, an activity that was previously common during the Cold War. That includes protests, religious activities and other rights protected by the first amendment.

    The spying could take the form of listening to phone calls, intercepting wireless communications, harassing photographers or infiltrating protest groups. Also discovered was the way in which agencies' are increasingly connected through various information sharing measures, making it more likely that information collected on an individual by a small police department could end up in an FBI or CIA database.

    All of this of course is part of a much larger trend that paints a disturbing narrative, a narrative that points in one direction only: an increasingly intrusive surveillance state with an Executive Branch getting dangerously close to being above the law.

    As noted scholar Juan Cole noted, "The US Bill of Rights says that people have the right to privacy in their personal effects and their communications from government prying except where the police obtain a warrant from a judge. The tendency in the US for the past 40 years has been to chip away at this requirement, giving government agencies more and more unsupervised surveillance authority."
     

    Yet, knowing all that, Congress isn't going to even have this debate in the light of day.

    As I point out each year we renew this abomination, it wasn't long ago that the American public, and certainly the majority of congressional Democrats would have been rightly outraged by Patriot Act provisions that allow for broad warrants to be issued by a secretive court for any type of record, without the government having to declare that the information sought is connected to a terrorism investigation; or that allow a secret court to issue warrants for the electronic monitoring of a person for whatever reason — even without showing that the suspect is an agent of a foreign power or a terrorist; and of course, that allow the government to search your home as long as it doesn't tell you it did.

    But that was then, this is now. Granted, during the Bush years there was at least some resistance in Congress to the Act, and at least some attention was given to the numerous, and continuous government abuses of the law. As the years have passed however, and a Democrat now sits in the White House, that resistance has largely evaporated, particularly with the last elections defeat of privacy champion Russ Feingold.

    To give credit where credit is due, Sen. Jeff Merkley (D-OR) did release a strong statement today lamenting the lack of debate

        Senator Jeff Merkley says he was very concerned when he heard Thursday Senate leaders would move to close debate Monday on a package extending three Patriot Act rules. Jeff Merkley: “I think it’s outrageous that there’s a proposal for a four-year extension in which the intention is to have no significant debate on the floor of the Senate, and no opportunity for amendments.” [...]

        Merkley says he isn’t sure if the extensions will pass, but notes some of his colleagues sounded unhappy about the parliamentary move used to forestall more debate.

        Jeff Merkley: “There is some chance that reaction may be strong enough to change that and turn this into a real debate. Leadership may say we have other things to get to by next Friday. My reaction is we’ve had plenty of time to have a thorough debate on the floor.”
     

    As David Dayen lays out, in addition to Merkley, Sen. Mark Udall (D-CO) opposes the quick reauthorization without debate. He sent an email to his supporters asking for them to sign a petition calling for the reform of the Patriot Act.

        Benjamin Franklin once said that any society that would give up essential liberties to pursue security deserves neither and will lose both. Those words ring true today [...]

        But while many of the PATRIOT Act’s provisions — which I support — have made our nation safer since the devastating terrorist attacks of 9/11, there are three provisions that fail to strike the right balance between keeping us safe while protecting the privacy rights of Coloradans. Instead, these three provisions have been far too susceptible to abuse by the federal government, even in the name of keeping us safe from terrorism [...]

        These three provisions are troubling because they are ripe for abuses that involve expansive government surveillance of innocent people, even though common sense fixes and protections exist if only we were allowed to debate them.


    Sadly, we are on the brink of yet another renewal of the act, with the active support of what was once an ardent critic of it - President Obama.

    Julian Sanchez provides another aspect of the Act that should be garnering more attention, stating:

    More urgent than any of these (provisions), however, is the need to review and substantially modify the statutes authorizing the Federal Bureau of Investigation to secretly demand records, without any prior court approval, using National Security Letters. Though not slated to sunset with the other three Patriot provisions, NSLs were the focus of multiple proposed legislative reforms during the 2009 reauthorization debates, and are also addressed in at least one bill already introduced this year. Federal courts have already held parts of the current NSL statutes unconstitutional, and the government’s own internal audits have uncovered widespread, systematic misuse of expanded NSL powers. of NSL authority — and, indeed, should significantly curtail it. In light of this history of misuse, as well as the uncertain constitutional status of NSLs, a sunset should be imposed along with more robust reporting and oversight requirements.


    John Whitehead wrote an excellent piece a couple months ago entitled "Renewing the Patriot Act While America Sleeps". He states:

    The Patriot Act drove a stake through the heart of the Bill of Rights, violating at least six of the ten original amendments–the First, Fourth, Fifth, Sixth, Seventh and Eighth Amendments–and possibly the Thirteenth and Fourteenth Amendments, as well. The Patriot Act also redefined terrorism so broadly that many non-terrorist political activities such as protest marches, demonstrations and civil disobedience were considered potential terrorist acts, thereby rendering anyone desiring to engage in protected First Amendment expressive activities as suspects of the surveillance state.

    The Patriot Act justified broader domestic surveillance, the logic being that if government agents knew more about each American, they could distinguish the terrorists from law-abiding citizens–no doubt an earnest impulse shared by small-town police and federal agents alike. According to Washington Post reporter Robert O’Harrow, Jr., this was a fantasy that had “been brewing in the law enforcement world for a long time.” And 9/11 provided the government with the perfect excuse for conducting far-reaching surveillance and collecting mountains of information on even the most law-abiding citizen.

    Suddenly, for the first time in American history, federal agents and police officers were authorized to conduct black bag “sneak-and-peak” searches of homes and offices and confiscate your personal property without first notifying you of their intent or their presence. The law also granted the FBI the right to come to your place of employment, demand your personal records and question your supervisors and fellow employees, all without notifying you; allowed the government access to your medical records, school records and practically every personal record about you; and allowed the government to secretly demand to see records of books or magazines you’ve checked out in any public library and Internet sites you’ve visited (at least 545 libraries received such demands in the first year following passage of the Patriot Act).


    In the name of fighting terrorism, government officials were permitted to monitor religious and political institutions with no suspicion of criminal wrongdoing; prosecute librarians or keepers of any other records if they told anyone that the government had subpoenaed information related to a terror investigation; monitor conversations between attorneys and clients; search and seize Americans’ papers and effects without showing probable cause; and jail Americans indefinitely without a trial, among other things. The federal government also made liberal use of its new powers, especially through the use (and abuse) of the nefarious national security letters, which allow the FBI to demand personal customer records from Internet Service Providers, financial institutions and credit companies at the mere say-so of the government agent in charge of a local FBI office and without prior court approval.

    ....

    In fact, since 9/11, we’ve been spied on by surveillance cameras, eavesdropped on by government agents, had our belongings searched, our phones tapped, our mail opened, our email monitored, our opinions questioned, our purchases scrutinized (under the USA Patriot Act, banks are required to analyze your transactions for any patterns that raise suspicion and to see if you are connected to any objectionable people), and our activities watched. We’ve also been subjected to invasive patdowns and whole-body scans of our persons and seizures of our electronic devices in the nation’s airports (there were 6,600 such seizures in airports alone between October 2008 and July 2010). We can’t even purchase certain cold medicines at the pharmacy anymore without it being reported to the government and our names being placed on a watch list. And it’s only going to get worse.

    Most Americans have been lulled into thinking that the pressing issues are voting in the next election or repealing health care. This is largely due to the media hoopla over the Tea Party, the recent elections and the health care law, and the continuous noise from television news’ talking heads. But the real issue is simply this–the freedoms in the Bill of Rights are being eviscerated, and if they are not restored and soon, freedom as we have known it in America will be lost. Thus, Congress should not renew the USA Patriot Act, nor should President Obama sign it into law. If he does so, he might just be putting the final nail in our coffin.



    As Glenn Greenwald questioned last year, does such a massive surveillance apparatus actually make us safer? Greenwald says no, statingThe problem is never that the U.S. Government lacks sufficient power to engage in surveillance, interceptions, intelligence-gathering and the like. Long before 9/11 -- from the Cold War -- we have vested extraordinarily broad surveillance powers in the U.S. Government to the point that we have turned ourselves into a National Security and Surveillance State. Terrorist attacks do not happen because there are too many restrictions on the government's ability to eavesdrop and intercept communications, or because there are too many safeguards and checks. If anything, the opposite is true: the excesses of the Surveillance State -- and the steady abolition of oversights and limits -- have made detection of plots far less likely. Despite that, we have an insatiable appetite -- especially when we're frightened anew -- to vest more and more unrestricted spying and other powers in our Government, which -- like all governments -- is more than happy to accept it.”

    Again, as I have written in response to past Patriot Act extensions: An undeniable pattern has emerged over the past few years that fundamentally challenges the entire premise of a "war on terror" and exposes just how ineffectual and counterproductive these policies have actually been. The reoccurring theme goes like this: Powerful interests - inside and outside of government - sell fear as way to justify the steady assault on our civil liberties, increased spending on military defense, and the growth of the surveillance state.

    But here's another important piece of the puzzle that keeps popping up: more often than not the government HASN'T USED these expanded powers to actually fight terrorism (instead often to thwart anti-war protesters, bust small time drug dealers, monitor journalists, and who knows what else?) - as was promised. This begs a larger question, "Who has been targeted and why?"Another question worth pondering: Can we really "defeat" terrorism by embracing a less free and more fearful society (two primary goals of terrorists)?

    Tuesday, April 26, 2011

    The Fourth Amendment and GPS Tracking

    As I've written in excruciating detail about on this blog, the Obama Administration has been a complete disappointment on issues related to privacy and civil liberties. To be sure, I never expected his actions as President to fully match his words as a candidate - this is rarely EVER the case, particularly when it comes to issues related to national security - but the two seem to have diverged to such a degree that they now represent diametrically opposed worldviews.

    As I have also said, with the passage (and renewal) of the Patriot Act, and the technological advancement in things like RFID tags and GPS tracking capabilities, the 4th Amendment is an endangered species. Now, we find that the Obama Administration is challenging an appellate court ruling over what the proper legal standard should be when law enforcement decides to track a suspects whereabouts? The court ruled there must be probable cause, now, the Obama Administration is arguing the opposite.

    Before I get to some choice clips from Truthdig's Juan Cole, let me provide a little case history first: Back in 2009, the Washington Post reported that while serving as a U.S. attorney during the Bush administration, Christopher Christie tracked the whereabouts of citizens through their cell phones without warrants. The ACLU obtained these documents from the Justice Department in an ongoing lawsuit over cell phone tracking. While the documents reveal 79 such cases on or after Sept. 12, 2001, they do not specify how many of the applications were made during Christie's tenure.

    Tracking without a warrant disregards
    an internal U.S. Justice Department recommendation that prosecutors obtain probable cause warrants before gathering location data from cell phones. Of the cases in which probable cause wasn't established, documents showed 19 allowed the most precise tracking available. Those cases occurred after the November 2007 Justice Department recommendation that prosecutors seek warrants.

    And if that wasn't enough, there was the 2009 revelation that Sprint received 8 million law enforcement requests for GPS location data in just one year.

    The government has been arguing, consistently now, that federal law requires judges to approve their applications for location information from cell phone companies - even if the police don't have probable cause to obtain this sensitive information. Courts have the right under statute - and the duty under the Constitution - to demand that the government obtain a search warrant before seizing this private location data.

    Mobile phone providers store data about where customers make and receive calls, based on the cell towers the customers' phones used. And that's why the government has been attempting to collect past mobile-phone tracking information. That way they can go back in the past for as long as the cell phone companies keep records.

    The ACLU had recently provided documents showing that of the states randomly sampled, New Jersey and Florida used GPS tracking without obtaining probable cause or warrants. Four other states, California, Louisiana, Indiana, Nevada and the District of Columbia reported having obtained GPS data only after showing probable cause.

    Those documents were part of the ongoing lawsuit by the ACLU and Electronic Frontier Foundation, in which they argued government tracking without a probable cause or warrant is a violation of the Constitution's Fourth Amendment.

    The essential argument by privacy advocates, be it the tracking of a cell phone user, or placing a tracking device in a suspect's vehicle, is that, whether you're driving a car or carrying a cell phone you should not be more susceptible to government surveillance. The idea being, no one wants to feel as if a government agent is following you wherever you go - be it a friend's house, a place of worship, or a therapist's office - and certainly innocent Americans shouldn't have to feel that way.

    This argument won the day, at least in this case, as a federal appeals court ruled last year the police can’t covertly track a suspect’s car using a GPS device for an extended period of time without getting a warrant. This ruling by the D.C. Court of Appeals overturned the conviction of a suspected cocaine dealer, saying that the use of a secret GPS tracking device on the man’s vehicle for two months violated the Fourth Amendment’s protection against unreasonable searches and seizures. Thus the court clearly drew the important distinction between short term monitoring that’s not much different from a police tail and ongoing, secret and ubiquitous tracking.
    Electronic Frontier Foundation and the ACLU had rightly argued that it's one thing to note someone’s car location and another to keep hourly data on every single stop you make along a specific route for days or months on end. The government tried to make the case that no such distinction existed.

    Now, Obama and Holder want to overturn this CRITICAL ruling protecting the fourth amendment...and worse, we are now at the mercy of a Supreme Court filled with a Federalist Society majority.

    But while that case, in the meantime anyway, represented a victory, let's remember that the FBI was found to have illegally collected more than 2,000 U.S. telephone call records between 2002 and 2006 by invoking terrorism emergencies that did not exist or simply by persuading phone companies to provide records.

    E-mails obtained by The Washington Post have detailed how counter terrorism officials inside FBI headquarters did not follow their own procedures that were put in place to protect civil liberties. The stream of urgent requests for phone records also overwhelmed the FBI communications analysis unit with work that ultimately was not connected to imminent threats.

    I addition, we know that the FBI uses 'dragnet'-style warrantless cell phone tracking


    Among the many elements of the Obama administration that have disappointed civil libertarians is its interest in spying on Americans. The Bush administration had instituted massive warrantless wiretapping and gathering of telephone records, with the complicity of most telecom corporations. Those who care about the Bill of Rights had hoped that Eric Holder’s Department of Justice would take a stand for the Fourth Amendment, which should be on the endangered species list along with the golden tree frog and the St. Helena dragonet.

    ...
    It should be remembered that it is perfectly possible for the police to make a mistake or act maliciously and to monitor someone who is innocent. The ACLU charges that these practices are increasingly common. If police and other security personnel are allowed to engage in domestic surveillance of this sort without a court warrant, they can start following large numbers of innocent people and learn details of their private lives. Just this year, Tacoma, Wash., police engaged in unconstitutional surveillance of anti-war activists, using an employee at a military base, which is even more troubling. Blanket permission for law enforcement to conduct warrantless GPS tracking of activists could reveal their private peccadilloes, which in turn could be used to blackmail them.

    ...

    Part of what defines public and private is a reasonable citizen’s expectations. You wouldn’t expect all your movements for a month to be public, even if they were in an automobile. It is that understandable expectation of privacy that brings the Fourth Amendment into play. Ginsburg continued, “A reasonable person does not expect anyone to monitor and retain a record of every time he drives his car, including his origin, route, destination, and each place he stops and how long he stays there; rather, he expects each of those movements to remain disconnected and anonymous.” The full court of nine judges upheld the three-judge panel’s decision to throw out the case, which was against nightclub owner Antoine Jones.

    The federal rulings so far on GPS tracking have been all over the map, so to speak, and that the Fourth Amendment will meaningfully survive the almost cosmic electronic surveillance capabilities of our burgeoning national security state is not at all clear. So far many of our eminent federal judges seem perfectly content with having police officers sneak around in our driveways, with allowing them to attach tracking devices to our private property, and with permitting them then to monitor everywhere we go and everyone we visit, without a warrant, for months at a time. Judge Ginsburg and two colleagues are so far all that stand in the way of this dystopian future becoming our present reality. Unfortunately, because Obama and Holder disagree with Ginsburg, his principled arguments will prevail only if they are permitted to do so by the likes of Antonin Scalia and Clarence Thomas. Welcome to Starship Amerika.

    I'd also point you to a piece in Computerworld by Darlene Storm. She writes: 

    If people can be tagged with a GPS-enabled dart in about a blink, and have no idea their movements on public streets are being tracked, then it seems reasonable that the warrantless surveillance violates the Fourth Amendment. In fact, it sounds a bit like stalking; if permitted to be done without a warrant, then it could easily be done on a large scale and without true suspicion.
    Despite three other courts of appeal ruling that law enforcement does not need a warrant to use GPS tracking on a vehicle, the D.C. appellate court did not agree. Inside GNSS reported that the D.C. court of appeal wrote, "Continuous human surveillance for a week would require all the time and expense of several police officers, while comparable photographic surveillance would require a net of video cameras so dense and so widespread as to catch a person's every movement, plus the manpower to piece the photographs together...A reasonable person does not expect anyone to monitor and retain a record of every time he drives his car, including his origin, route, destination, and each place he stops and how long he stays there."

    ...

    I'm certainly not an attorney, but it seems reasonable to expect the Supreme Court to uphold our Constitution and Fourth Amendment rights, including the right not to worry about warrantless surveillance in the form of GPS tracking when there is not even probable cause. Just because the technology exists does not mean it should be used against the people to invade their privacy as if everyone is a criminal. The next thing you know, the authorities will want warrantless wiretaps to search our email. Oh wait..

    What's at stake here is whether it's okay for the government to track the locations of cell phone users without having to demonstrate there's good reason to do so. If we've learned anything post Patriot Act, its that law enforcement and the government do abuse unchecked power, even if only in a small minority of the situations. But to me, that's enough of a reason to require a warrant, period.

    As the ACLU points out, "This case is not about protecting criminals. It's about protecting innocent people from unjustified violations of their privacy."

    Thursday, April 21, 2011

    Locational Privacy and Smart Phones

    Before I get to the startling news that security researchers have discovered that Apple's iPhone keeps track of EVERYWHERE you go – and saves every detail of it to a secret file on the device which is then copied to the owner's computer when the two are synchronized, let me briefly provide some context. As I have written here before, the fact that Americans are losing their privacy as they travel through public space due to location-based technologies isn't debatable. The question, as is so often the case when it comes to issues at the intersection of privacy and technology, is what kind of say do we have in the matter and what kind of rules are in place protecting our privacy rights?

    Now the issue of locational privacy has resurfaced in a way that was just "conspiracy theories" and "worst case scenarios" in the very recent past. In that past, we had services such as EZ Pass (allows you to bypass stopping to pay the bridge toll), Google Latitude, the GPS tracking of cellphones, the right of police and government to track our whereabouts (both by phone and car), transit cards, social networking sites, WiFi networks, and more, all opening up a brave new world of real time, locational tracking of Americans.

    But these new Smart Phone revelations take this to another level.

    The UK's Guardian reports: The files contained the latitude and longitude of the phone's recorded coordinates along with a timestamp, meaning that anyone who stole the phone or the computer could discover details about the owner's movements using a simple program. For some phones, there could be almost a year's worth of data stored, as the recording of data seems to have started with Apple's iOS 4 update to the phone's operating system, released in June 2010.

    "Apple has made it possible for almost anybody – a jealous spouse, a private detective – with access to your phone or computer to get detailed information about where you've been," said Pete Warden, one of the researchers.

    Only the iPhone records the user's location in this way, say Warden and Alasdair Allan, the data scientists who discovered the file and are presenting their findings at the Where 2.0 conference in San Francisco on Wednesday. "Alasdair has looked for similar tracking code in [Google's] Android phones and couldn't find any," said Warden. "We haven't come across any instances of other phone manufacturers doing this."

    Simon Davies, director of the pressure group Privacy International, said: "This is a worrying discovery. Location is one of the most sensitive elements in anyone's life – just think where people go in the evening. The existence of that data creates a real threat to privacy. The absence of notice to users or any control option can only stem from an ignorance about privacy at the design stage."


    Indeed it is an important element. I'd point everybody to check out a report from the Electronic Frontier Foundation (EFF) in 2009 on the issue of "locational privacy". The report warned that Americans are losing their privacy as they travel through public space due to location-based technologies and services.

    As the report detailed
    , "Location-based services that transmit, record, and store where a person is—such as EZ Pass, WiFi networks, transit cards, Google Latitude—can be exploited by government, business, or prying ex-lovers to track and reconstruct where people have been as they go about their daily life."

    And what of the common response to worries about locational privacy, or other privacy issues in fact, that posits "I'm not doing anything wrong, why should I care?"

    EFF lays out the folly of such a knee jerk defense of our ever expanding surveillance state...one that goes beyond the usual concerns of big government or law enforcement overreach:

    One answer to this concern is a reminder that there are more subtle reasons for needing privacy. It’s not just the government, or law enforcement, or political enemies you might want to be protected from.

    Your employer doesn’t need to know things about whether, when, and where you went to church.
    • Your co-workers don’t need to know how late you work or where you shop.
    • Your sister’s ex-boyfriend doesn’t need know how often she spends the night at her new boyfriend’s apartment.
    Your corporate competitors don’t need to know who your salespeople are talking to.

    Now, let's get back to the Guardian piece:

    Warden and Allan point out that the file is moved onto new devices when an old one is replaced: "Apple might have new features in mind that require a history of your location, but that's our specualtion. The fact that [the file] is transferred across [to a new iPhone or iPad] when you migrate is evidence that the data-gathering isn't accidental." But they said it does not seem to be transmitted to Apple itself.


    The iPhone system, by contrast, appears to record the data whether or not the user agrees. Apple declined to comment on why the file is created or whether it can be disabled.

    Warden and Allan have set up a web page which answers questions about the file, and created a simple downloadable application to let Apple users check for themselves what location data the phone is retaining. The Guardian has confirmed that 3G-enabled devices including the iPad also retain the data and copy it to the owner's computer.

    If someone were to steal an iPhone and "jailbreak" it, giving them direct access to the files it contains, they could extract the location database directly. Alternatively, anyone with direct access to a user's computer could run the application and see a visualization of their movements.

    Graham Cluley, senior technology consultant at the security company Sophos, said: "If the data isn't required for anything, then it shouldn't store the location. And it doesn't need to keep an archive on your machine of where you've been." He suggested that Apple might be hoping that it would yield data for future mobile advertising targeted by location, although he added: "I tend to subscribe to cockup rather than conspiracy on things like this – I don't think Apple is really trying to monitor where users are."


    We shouldn't view this as that big of a surprise of course. A study released last year by the Worcester Polytechnic Institute (WPI) in Massachusetts found that mobile social networks are giving data about users' physical locations to tracking sites and other social networking services. Researchers reported that all 20 sites that were studied leaked some kind of private information to third-party tracking sites.

    In the study, the researchers looked at the practices of 13 mobile online social networks, including Brightkite, Flickr, Foursquare, Gowalla and Urbanspoon. They also studied seven traditional online social networks, such as Facebook, LinkedIn, MySpace and Twitter, which allow users to access their sites using mobile devices.

    In many cases, the data given out contained the user's unique social networking identifier, which could allow third-party sites to connect the records they keep of users' browsing behavior with the their profiles on the social networking sites.

    As the report notes, "The combination of location information, unique identifiers of devices, and traditional leakage of other personally identifiable information all conspire against protection of users' privacy."

    I addition, we also know that the FBI uses 'dragnet'-style warrantless cell phone tracking. In other words, there are more and more ways, through more and more devices, that can track and store our location, and that data is worth more and more money.

    There is some good news to report on this however. Senator Al Franken, who continues to distinguish himself as an excellent Senator on issues related to privacy and the internet, has indicated he's not at all pleased by these revelations about Apple, and could seek a full fledged investigation.

    The Senator sent a letter to Apple late Wednesday to question why it included the feature in its software in the first place. The letter reads, “The existence of this information — stored in an unencrypted format — raises serious privacy concerns,” He later emphasized the information — which could be “accurate to 50 meters or less” — also applies to iPhones and iPads owned by children, and could easily be exploited by “criminals and bad actors.”

    As reported by Politico, "Franken wants to know why Apple included the feature in the operating system. In a two page letter issued Wednesday, the senator asked Apple to explain why it initiated this tracking process in iOS 4, and why the company “never affirmatively informed [consumers] of the collection and retention of their location data in this manner?”

    Franken also asked Jobs to explain whether the location data has been disclosed, and whether the same technology is also included as part of the operating system software that runs on the company’s popular MacBook laptops.

    Franken’s letter is significant given lawmakers’ heightened interest in reforming federal laws
    on privacy, tracking and surveillance. The issue of mobile phone privacy, in particular, has Sen. Ron Wyden (D-Ore.) still working on legislation that could become part of the chamber’s larger effort to set new rules for how and when federal law enforcement can access consumers’ location data.


    A constantly monitored citizenry used to conjure up images of totalitarian states - not Google and I-Phones. And granted, now technology does the surveillance — generally in the name of being helpful and entertaining, not to stifle dissent or oppress the public.

    This fact does not mean that these technologies can't still be used in ways that do reduce freedoms, do play into the hands of overly aggressive and/or oppressive governments, and does invade privacy by using our private information to maximize corporate profit.

    Perhaps its time for a serious conversation about how much of our privacy of movement we want to give up - and how much control do we get over that decision?