Showing posts with label RFID. Show all posts
Showing posts with label RFID. Show all posts

Tuesday, February 14, 2012

Domestic Spy Drones Approved by Congress

As if I planned it myself, just the day after I wrote a major blog (see the last one) about 7 privacy threats that the Constitution can't protect you from, Congress goes ahead and APPROVES two of them for widespread use. The two I speak of, as detailed by Alternet's Tana Ganeva, have to do with domestic spy drones. As I wrote at the time, apparently, these drones do more than just kill innocent women and children around the world, but in fact, are perfect domestic spying devices too.

As Ganeva also detailed, "An ACLU report from December says that local law enforcement officials are pushing for domestic use of the new technology, as are drone manufacturers. As Glenn Greenwald points out, drone makers "continuously emphasize to investors and others that a major source of business growth for their drone products will be domestic, non-military use."

Right now drones range in size from giant planes to hummingbird-sized, the ACLU report says, with the technology improving all the time. Some can be operated by only one officer, and others by no one at all. The report points to all the sophisticated surveillance technology that can take flight on a drone, including night vision, video analytics ("smart" surveillance that can track activities, and with improvements in biometrics, specific people), massive zoom, and the creepy see-through imaging, currently in development.

Similarly, there are also what are called "Super drones" that actually know who you are, because, as reported by Wired magazine, the military has given out research grants to several companies to spruce up these drones with technology that lets them identify and track people on the move, or "tagging, tracking, and locating" (TTL).

After writing about these disturbing possibilities, I then read these 3 stories, "Congress OKs FAA Bill allowing drones in US, GPS air traffic control", "Bill authorizes Use of Unmanned Drones in US Airspace", and "Drones over US get OK by Congress"

Let's go to the Chicago Tribune's report on this...this clip was found about halfway into the article:

The FAA is also required under the bill to provide military, commercial and privately-owned drones with expanded access to U.S. airspace currently reserved for manned aircraft by Sept. 30, 2015. That means permitting unmanned drones controlled by remote operators on the ground to fly in the same airspace as airliners, cargo planes, business jets and private aircraft.

Currently, the FAA restricts drone use primarily to segregated blocks of military airspace, border patrols and about 300 public agencies and their private partners. Those public agencies are mainly restricted to flying small unmanned aircraft at low altitudes away from airports and urban centers.

Within nine months of the bill's passage, the FAA is required to submit a plan on how to safely provide drones with expanded access.


Interestingly, not much more was said or discussed about these new rules and right in the article. So, let's go to the piece by the New American for more: 

Big Brother is set to adopt a new form of surveillance after a bill passed by Congress will require the Federal Aviation Administration (FAA) to open U.S. airspace to drone flights under a new four-year plan. The bill, which passed the House last week and received bipartisan approval in the Senate on Monday, will convert radar to an air traffic control system based on GPS technology, shifting the country to an age where satellites are central to air traffic control and unmanned drones glide freely throughout U.S. airspace.

By using GPS technology, congressional leaders argued, planes will land and take off more efficiently, as pilots will be able to pinpoint the locations of ground obstacles and nearby aircraft. The modernization procedures play into the FAA’s ambitious plan to achieve 50-percent growth in air traffic over the next 10 years. This legislation is "the best news that the airline industry ever had," applauded Sen. Jay Rockefeller (D-W.Va.). "It will take us into a new era."


...

Furthermore, privacy advocates worry that the bill will open the door to widespread use of drones for surveillance by law enforcement and, eventually, by the private sector. Some analysts predict that the commercial drone market in the U.S. could be worth hundreds of millions of dollars once the FAA authorizes their use, and that 30,000 drones could be flying domestically by 2020. "There are serious policy questions on the horizon about privacy and surveillance, by both government agencies and commercial entities," said Steven Aftergood, director of the Project on Government Secrecy at the Federation of American Scientists.

The Electronic Frontier Foundation, a digital rights advocacy and legal group, also is "concerned about the implications for surveillance by government agencies," affirmed attorney Jennifer Lynch, and it is "a huge push by lawmakers and the defense sector to expand the use of drones" in U.S. airspace.

"Congress — and to the extent possible, the FAA — need to impose some rules to protect Americans’ privacy from the inevitable invasions that this technology will otherwise lead to," wrote American Civil Liberties Union policy analyst Jay Stanley. "We don’t want to wonder, every time we step out our front door, whether some eye in the sky is watching our every move."


Now that I have your attention, let's get to the Washington Times (an admitted rag of a paper...but that doesn't mean they don't have anything of use to report):

Look! Up in the sky! Is it a bird? Is it a plane? It's ... a drone, and it's watching you. That's what privacy advocates fear from a bill Congress passed this week to make it easier for the government to fly unmanned spy planes in U.S. airspace.

....

Privacy advocates say the measure will lead to widespread use of drones for electronic surveillance by police agencies across the country and eventually by private companies as well.

"There are serious policy questions on the horizon about privacy and surveillance, by both government agencies and commercial entities," said Steven Aftergood, who heads the Project on Government Secrecy at the Federation of American Scientists.

....


The Electronic Frontier Foundation is suing the FAA to obtain records of the certifications. "We need a list so we can ask [each agency], 'What are your policies on drone use? How do you protect privacy? How do you ensure compliance with the Fourth Amendment?' " Ms. Lynch said.

"Currently, the only barrier to the routine use of drones for persistent surveillance are the procedural requirements imposed by the FAA for the issuance of certificates," said Amie Stepanovich, national security counsel for the Electronic Privacy Information Center, a research center in Washington.


Let's remember what I posted last week on this topic - before I knew Congress was about to legitimize all of it. As Noah Shachtman wrote: Perhaps the idea of spy drones already makes you nervous. Maybe you’re uncomfortable with the notion of an unblinking, robotic eye in the sky that can watch your every move. If so, you may want to click away now. Because if the Army has its way, drones won’t just be able to look at what you do. They’ll be able to recognize your face — and track you, based on how you look. If the military machines assemble enough information, they might just be able to peer into your heart.

One company claims it can equip drones with facial recognition technology that lets them build a 3-D model of a face based on a 2-D image, which would then allow the drone to ID someone, even in a crowd. 


They also say that if they can get a close enough look, they can tell twins apart and reveal not only individuals' identity but their social networks.

The Army also wants to identify potentially hostile behavior and intent, in order to uncover clandestine foes. Charles River Analytics is using its Army cash to build a so-called “Adversary Behavior Acquisition, Collection, Understanding, and Summarization (ABACUS)” tool. The system would integrate data from informants’ tips, drone footage, and captured phone calls. Then it would apply “a human behavior modeling and simulation engine” that would spit out “intent-based threat assessments of individuals and groups.” In other words: This software could potentially find out which people are most likely to harbor ill will toward the U.S. military or its objectives. Feeling nervous yet?


We're getting into truly Orwellian levels of surveillance that makes one ask, "just what in the hell are we so afraid of that we need to be monitored at all times?" We know that, study after study indicates we ARE NOT under a dangerous threat from terrorists, either from abroad or from within.We know that the chances of being killed by a terrorist are a fraction of the chance that you'll be hit by lightning.

Yet, here we are, rationalizing and legitimizing MASSIVE surveillance apparatuses that leave our privacy, and the Constitution, in tatters. What is the bigger threat here? A government, and in fact, a PRIVACY drone industry that can watch us anywhere, at all times, and even facially recognize us, for who knows what purposes (i.e. stifle dissent)....or, can we, as brave Americans simply take the TINY TINY risk that living in a world in which we're not constantly watched is acceptable? I hate to repeat myself so much on this blog, but, I also know how many readers are first time readers, so let me break this privacy versus security paradox down again.

In the final analysis, if we include in our definition of "safe" the concept of "safe" from government intrusiveness and corporate profiteering off fear peddling, I would argue these machines make us less secure, not more. So let’s scrap the meme that we should live in fear and that our constitutional rights must be sacrificed to address a threat the fraction of that posed by lightning, salmonella, and the health insurance industry.

The trend line is all too clear. More concerning than any single threat posed by any single technology – including drone surveillance – is this larger pattern indicating that privacy as both a right and an idea is under siege. The consequences of such a loss would be profound.

This false dichotomy between security and privacy must be directly confronted. As security and privacy expert Bruce Schneier once wrote, "If you set up the false dichotomy, of course people will choose security over privacy -- especially if you scare them first. But it's still a false dichotomy. There is no security without privacy. And liberty requires both security and privacy. The famous quote attributed to Benjamin Franklin reads: "Those who would give up essential liberty to purchase a little temporary safety, deserve neither liberty nor safety." It's also true that those who would give up privacy for security are likely to end up with neither.”

And let me sum this all up, once again, as I often do here.

Whether its the knowledge that everything we do on the internet is followed and stored, that we can be wiretapped for no reason and without a warrant or probable cause, that smart grid systems monitor our daily in home habits and actions, that our emails can be intercepted, that our naked bodies must be viewed at airports and stored, that our book purchases can be accessed (particularly if Google gets its way and everything goes electronic), that street corner cameras are watching our every move (and perhaps drones too), and that RFID tags and GPS technology allow for the tracking of clothes, cars, and phones (and the list goes on)...what is certain is privacy itself is on life support in this country...and without privacy there is no freedom. I also fear how such a surveillance society stifles dissent and discourages grassroots political/social activism that challenges government and corporate power...something that we desperately need more of in this country, not less.

But perhaps the GREAT Jim Hightower frames this attack on privacy the best when he writes, "Look, up in the sky! Neither a bird nor Superman, the next must-have toy for assorted police agencies is the unmanned aerial vehicle, better known as drones. Yes, the same miniaturized aircraft that lets the military wage war with a remote-controlled, error-prone death machine is headed to your sky, if the authorities have their way. Already, Homeland Security officials have deployed one to a Texas sheriff's office to demonstrate its crime-fighting efficacy, and federal aviation officials are presently proposing new airspace rules to help eager departments throughout the country get their drones.

But airspace problems are nothing compared to the as-yet-unaddressed Fourth Amendment problems that come with putting cheap, flying-surveillance cameras in the air. As usual, this techno-whiz gadget is being rationalized as nothing more than an enhanced eye on crime. But the drone doesn't just monitor a particular person or criminal activity, it can continuously spy on an entire city, with no warrant to restrict its inevitable invasion of innocent people's privacy. Drones will collect video images of identifiable people. Who will see that information? How will it be used? Will it be retained? By its nature, this is an invasive, all-encompassing spy eye that will tempt authorities to go on fishing expeditions. The biggest question is the one that is not even being asked: Who will watch the watchers?."



We would do well to - sooner rather than later - to recognize the inherent and fundamental value that privacy provides ANY claimed democracy. Without one there can not be the other..

Thursday, September 1, 2011

5 Places You Can Be Tracked by Facial Recognition Technology

Just a few days ago I posted a pretty extensive blog on Facial Recognition technology and the threat it poses to individual privacy. So for the sake of time and repetition I'm not going to go back over the basics (see that post for this), but rather, get straight to a fantastic article from Alternet entitled 5 Unexpected Places You Can Be Tracked With Facial Recognition Technology. Of particular interest to me was the coverage the piece gives to California's own recent fight that we at the Consumer Federation of California were deeply involved in, over biometric identifiers being used by the DMV. As such, our Executive Director, Richard Holober, is quoted in the article as well.

Before I provide some especially choice clips of this article (because it dovetails very well with my recent post on the topic), let me refresh everyone's memories regarding the successful campaign by privacy and consumer groups against the California DMV which resulted in, with just one day to spare, the Joint Legislative Budget Committee (JLBC) stepping in to reject the DMV’s proposal to impose sweeping new biometric technologies - such as facial and thumb print scans - as elements in a renewal of a vendor contract to produce driver’s licenses and ID cards.

At the time, the Consumer Federation of California had joined organizations from across the political spectrum – including the ACLU, Electronic Frontier Foundation, California Eagle Forum, Consumers Union, Privacy Activism, Privacy Rights Clearinghouse, and the World Privacy Forum - to urge the legislature to reject the DMV's request on the grounds that any change of this magnitude should be a policy matter for the legislature to decide, after considering whether it is effective, affordable, and if it contains the appropriate privacy safeguards.


If the JLBC did not act in time the proposal would have moved forward. Thankfully, at the very last moment a letter that was unequivocal in its opposition to the proposal was sent to the DMV from Senator Denise Ducheny - the Committee Chair.

Click here to read the complete letter. Here's a particularly important passage:

"Of particular concern is the proposed use of biometric technology as part of the card issuance process and the related privacy issues. I think the Legislature should consider the policy implications of using biometrics in the issuance of driver licenses before the department starts to use the technology. In addition, after review and discussions with DMV, the Analyst concluded that the request was not fully justified, in part because the department was unable to provide key information on the specific costs and benefits related to the proposed use of biometrics."

Click here to read the Monday, February 16th article in the San Jose Mercury News, entitled "DMV biometric plan will undergo public hearings".

Here was some of our argument on the DMV Proposal:

On January 14th the California Department of Finance – without notifying the public – sent a letter to inform the state Joint Legislative Budget Committee that it planned to issue a new vendor contract for production of California Driver’s Licenses, ID cards and Salesperson cards starting in June of 2009. Hidden in the fine print, the proposal called for “enhanced” biometric identification in state IDs. Unless this legislative committee objects to this plan within 30 days, the Department of Motor Vehicles will be free to begin implementing the biometric technology.

What are Biometrics?

Biometric technology is the computerized matching of an individual’s personal characteristics (like a thumbprint or facial scan) against an image or database of images.  In other words, the DMV and the Department of Finance are seeking to create a massive government database of biometric information from virtually every Californian over the age of 16 without debate or review - raising significant concerns regarding the increased surveillance, monitoring and tracking of individuals.

One would expect, in light of the ongoing and intensifying debate over the REAL ID Act (a federal plan to create a national identity card based on drivers’ licenses) and the increasing number and degree of privacy violations committed by the federal government in recent years, that such a program would be fully debated, in the open, by our representatives in the State Legislature and with public comment, before it could ever be enacted.

Because no such debate has occurred, and no attention has been given to the privacy concerns such a program warrants, a broad coalition of consumer and privacy rights advocates joined forces to urge the legislature to reject this request while there’s still time.

Our case against the proposal is twofold.

(1) The first is procedural: the DMV is attempting to use a routine contract renewal process to effectuate major policy changes.

As the ACLU noted:

    A 30-day expedited opt-out letter to the Legislature is an inappropriate vehicle to move from photographs and thumbprints of millions of Californians to advanced facial recognition technology and biometric systems that pose a number of privacy and security concerns if not handled carefully.

•    The DMV does not appear to have authority to implement biometric technologies that the Legislature has considered and rejected over the years, without the issues being fully considered and addressed in policy and budget hearings.

(2) The second relates to privacy and security: the underlying proposal to use biometric technologies has yet to establish appropriate safeguards to protect against identity theft and unwarranted government snooping into our private lives.

It’s important to understand the limitations of biometrics as well as their strengths. The fact is, biometrics are easy to steal. Our fingerprints are left everywhere we touch, and our iris scans are everywhere we look.

According to experts, biometrics work only if two things can be verified by the verifier: one, that the biometric came from the person at the time of verification, and two, that the biometric matches the master biometric on file. If the system can't do that, it can't work.

You can see more of this original post of mine here.


As face recognition and other biometrics advance, the technology has begun to proliferate in two predictable realms: law enforcement and commerce. Here are 5 places besides Facebook you might encounter face recognition and other biometric technology -- not that, for the most part, you would know it if you did. 

1. The streets of America 

In the fall, police officers from 40 departments will hit the streets armed with the Mobile Offender Recognition and Information System (MORIS) device. The gadget, which attaches to an iPhone, can take an iris scan from 6 inches away, a measure of a person's face from 5 feet away, or electronic fingerprints, according to Computer vision central. This biometric information can be matched to any database of pictures, including, potentially, one of the largest collections of tagged photos in existence: Facebook. The process is almost instant, so no time for a suspect to opt out of supplying law enforcement with a record of their biometric data.

...
 
2. The DMV

Slightly fewer than half of the DMVs in the US have the capacity to run your picture through biometric databases. Ostensibly, these searches are intended to catch people trying to collect multiple IDs from different states. Fair enough. But as EFF's Lee Tien told AlterNet, the DMV can also log into and run a person's face against any government database, including ones that hold criminal records. Last August, former New York Gov. David Paterson and DMV commissioner David Swartz held a triumphant news conference where they announced that more than 100 felony arrests were made through the DMV's facial recognition program.

In the past, the FBI has applied facial recognition technology to the DMV's vast database of photo images in pursuit of suspects, according to the AP...
'We see this as sort of creeping Big Brother government, an invasion of people's privacy,' said Richard Holober, executive director of the San Mateo-based Consumer Federation of California."

...

3. Las Vegas casinos, and Kraft and Adidas stores

For years Las Vegas casinos have used various forms of facial recognition to identify card-counters. Now, Vegas is at the forefront of efforts to adapt facial recognition to more efficiently suck money out of visitors. The LA Times reported last week that the Venetian hotel and casino has installed basic facial recognition software in advertisements. A camera captures an image of a person passing by and an algorithm determines their gender and rough age. The advertisement can then present them with products most likely to appeal to their demographic. 

...

4. Bars 

Inevitably, facial recognition software is also being deployed for the purpose of getting people laid. SceneTap, an app developed by a Chicago company uses information from facial recognition cameras planted in bars to determine the ratio of women to men and the average age of customers. As of June, 200 bars across the country had signed up to take partaccording to Forbes. SceneTap developers assured reporters that the cameras they're installing in bars do not capture high-enough-quality images to match them up to databases or Facebook profiles. 

In my last post I give a short summation of why I find the spread of this technology, and many other privacy related intrusions, so disturbing. It's not that any one violation alone is the problem, its the totality of them all...and the direction it indicates we're headed as a society. 

I wrote, "Whether its the knowledge that everything we do on the internet is followed and stored, that we can be wiretapped for no reason and without a warrant or probable cause, that smart grid systems monitor our daily in home habits and actions, that our emails can be intercepted, that our naked bodies must be viewed at airports and stored, that our book purchases can be accessed (particularly if Google gets its way and everything goes electronic), that street corner cameras are watching our every move, and that RFID tags and GPS technology allow for the tracking of clothes, cars, and phones (and the list goes on)...what is certain is privacy itself is on life support in this country...and without privacy there is no freedom. I also fear how such a surveillance society stifles dissent and discourages grassroots political/social activism that challenges government and corporate power...something that we desperately need more of in this country, not less."

Today's article from Alternet certainly gives me no reason to retract any of this...

Wednesday, August 10, 2011

Are New California PUC Smart Grid Privacy Rules Adequate?

For those that may not know, last year, March 19th to be exact, I spoke before the California Public Utilities Commission regarding the privacy challenges and implications of transitioning to a smart grid electrical system. That's not to say I spoke against the development of such a system, in fact, if implemented correctly, it makes public policy, particularly environmental and economic, sense.

First, briefly: a smart grid system will allow utilities to collect and possibly distribute detailed information about household electricity consumption habits - ice makers will operate only when the washing machine isn't, TVs will shut off when viewers leave the room, air conditioner and heater levels will be operated more efficiently based on time of day and climate. Home gadgets and appliances will be wirelessly connected to the Internet so consumers can access detailed information about their electricity use, and reduce their carbon footprint appropriately.

Soon this technology will be near ubiquitous: Up to three-fourths of the homes in the United States are expected to be placed on the “Smart Grid” in the next decade, and there will be nearly 50 million by 2012. Some foresee it becoming 100 to 1000 times larger than the internet.

But back to the presentation, and then I'll get to the first privacy rules established here in California for this burgeoning electrical system. I happened to be one of three consumer advocates that spoke that day at the CPUC's smart grid workshop...with the focus of that seminar purely on privacy. I suspect I was asked in part due to my op-ed in the California Progress Report, as well as my position at the Consumer Federation of California, and my occasional blog posts here on the topic.

To watch the presentation click here and scroll down to my name - Zack Kaldveer...and click again. The purpose of my presentation, as I will detail here today, was to breakdown ALL the different ways a smart grid system could threaten the privacy of consumers, and the real world damage such privacy violations could cause if the system wasn't developed in a way that put privacy, and consumer control, first.

As I said at the time, "But the paradox of a smart grid system is that what will ostensibly make it an effective tool in reducing energy usage and improving our electric grid – our information - is precisely what makes it a threat to privacy: our information...

The sheer volume of data provided by Smart Grid technologies will make it a prospective goldmine for numerous parties other than the utilities themselves, for reasons other than energy efficiency, and used for purposes that do not benefit the consumer: advertisers and marketers will seek to create and utilize increasingly detailed behavioral profiles, law enforcement and the government will seek to monitor our homes, and criminals will seek to steal identities and rob homes.

As such, without proper safeguards and ironclad rules in place, a myriad of new privacy threats could eventually find their way into every home in America. 

Activities that might be revealed through analysis of home appliance use include personal sleep and work habits, cooking and eating schedules, the presence of certain medical equipment and other specialized devices, presence or absence of persons in the home, and activities that might seem to signal illegal behavior. 

Personal privacy issues routinely arise when data collected is harmless in isolation, but becomes a threat when combined with other data, or examined by a third party for patterns. In other words, what are the potential “unintended consequences” of such an electrical system? And more importantly, what must we do to ensure that those unintended consequences are never realized? 

Such interest in our private data by third parties begs some important questions: How much information should we give up to the grid? Should it be up to the customer to decide? Who stores all that information and for what reasons? How will this information be managed and how long will it be stored? Who will come asking for that information, for what purposes and under what rules? And will there be proper and enforceable accountability for those that abuse our data?

So, with that general description of the system itself, and the related privacy concerns, now let's get to the unanimous vote by the CPUC to adopt the world’s first comprehensive set of rules to ensure that consumers can access the detailed energy usage data gathered by their smart meter — while also protecting the privacy and security of their data. At least...in theory....


The decision applies to the three large investor-owned utilities which serve 80% of Californians with electricity (Pacific Gas & Electric, San Diego Gas & Electric and Southern California Edison). At last count, these three utilities had installed 8 million smart meters. By the end of 2012 they will deploy the final 3 million. 

As detailed by the San Francisco Business Times, "The CPUC is requiring utilities to regularly conduct independent security audits of their wireless meters and to restrict the access of third parties, such as energy-efficiency consultants, to customers' personal details. In addition to the privacy and security rules, the commission is requiring utilities to provide pricing, usage, and cost data to customers online and update the data at least on a daily basis. Each day's usage data, along with applicable price and cost details, must be available by the next day...the standards are consistent with privacy and security principles adopted by California's Senate Bill 1476, which former Gov. Arnold Schwarzenegger signed into law last September, and by the Department of Homeland Security

.....

Although hackers and spammers have so far spared digital smart meters and electrical grids from their cyber intrusions, the massive national rollout of devices and grid upgrades planned for this decade cyber thugs.

"In all systems of this type, the install base needs to reach a critical mass before attackers start looking at breaking these things," Jun said.

In June, the Department of Energy announced that a $4.5 billion stimulus program to ramp up smart grid technology projects, matched by $5.5 billion from the private sector, has already led to the installation of 5 million of the nation's meters. The DOE requires that eligible projects include security provisions to protect against hacking, but it doesn't detail what those measures should look like.

"We are putting devices in homes where — if the right investments in security aren't made now — it is going to be impossible to retrofit them," Jun said. "For an industry that is so new and building infrastructure to last 50 years, one of our major challenges is helping people think ahead."
 

More specifically in relation to the privacy component of the decision, it notes, "Consumers will be able to authorize third parties to receive their backhauled smart meter data data directly from the utility (as opposed to data that comes directly from the meter), to support services such as energy efficiency, demand response, energy advice, and more. The three major utilities will submit to the CPUC applications with specific plans, including which standards they will use — probably the Open Automated Data Exchange (OpenADE) standard in final development by NIST’s Smart Grid Interoperability Panel and the North American Energy Standards Board. The utilities, however, will bear no new liability for the actions of third parties which acquire information via this [mechanism].”

Furthermore, to protect consumer privacy and data security, the CPUC is exercising jurisdiction over third parties who receive data (via the backhaul mechanism) in the course of providing services to utilities, or when authorized by consumers. However, the CPUC is not exercising jurisdiction over third parties who receive energy usage data directly from a device installed at residence or business that receives data via the HAN interface.


In this decision the CPUC relied mainly on existing privacy law, using the Fair Information Practice Principles which the U.S. Department of Homeland Security developed as its privacy framework. To clarify the application of these principles, the CPUC decision includes an appendix with details of its privacy rules.
 

Here are the FIP principles, all of which are utilized by the CPUC:
1.    Transparency
2.    Individual participation
3.    Purpose specification
4.    Data minimization
5.    Use limitation
6.    Data quality and integrity
7.    Security
8.    Accountability and auditing


Now, there does appear to be a lot of good things about this ruling...and certainly, privacy has been seriously taken into account. But all it takes is one loophole to release the floodgate of privacy violations and loss of consumer control.

Essentially, there are two general concerns (so far) that I have - namely third party jurisdiction and the lack of adequate enforcement mechanisms (to serve as a proper deterrent).

First and foremost, and I have spoken about third parties A LOT on this blog, my concern is the line about the CPUC not using, or suggesting they don't even have, jurisdiction to enforce the same kind of privacy standards that the utilities must abide by as those that will be applied to third parties. Here’s the key passage of their decision:

The utilities, however, will bear no new liability for the actions of third parties which acquire information via this [mechanism]"

and 

"it will not exercise jurisdiction over third parties who receive energy usage data directly from a device installed at residence or business..."

On a similar note, after talking with our staff attorney who has been deeply involved in this debate, there also  could be confusion when it comes to definitions of just which devices fall under which category, and which provide maximum privacy protection and which don't. And because of these definitional challenges, third parties will be able to circumvent the registration process by asserting that their devices are “unlocked.” I think that this challenge can be remedied if all parties who sought Smart Grid data would fall under the Commission’s jurisdiction.

The other concern I have, is what appears to be weak penalties  for those that violate basic consumer privacy rules. As I understand it, the only real penalty is that they can no longer ask for data…not exactly a powerful deterrent. AS our attorney wrote to the CPUC, “CFC stated that the proposed rules should be modified to reflect a balance in responsibility between customers and utilities/third parties. When it comes to consumer authorized access to energy data, consumers are left to regulate themselves with what CDT states “a heightened responsibility [for consumers] to understand the implications of this disclosure.” Moreover, there is no penalty or enforcement if utilities or third parties violate these privacy rules. CFC supports the Commission’s adoption of requirements that promote customer education, awareness, and empowerment. However, customer empowerment is only one piece of the puzzle when it comes to effective consumer protection. Proper accountability that includes penalties for violations by utilities and third parties is the other piece."

Now, let's say a third party is given access to this data unknowingly or unwittingly by the consumer...what  are some potential, specific examples of the kinds of “unintended consequences” that might take place? Well, here's the list I gave personally:

• Travel agencies might start sending you brochures right when your annual family vacation approaches.

• Financial institutions making home mortgage loans might also be interested in their customers’ energy usage records to verify whether the customers are actually living in those houses.

• Law enforcement officials might use our information against us. Consider the predictable desire of police to locate in-home marijuana growers by monitoring household power usage? What about increasingly intrusive surveillance of proclaimed suspects homes?

• Lawyers might seek to subpoena your data in a divorce trial, "Have you ever left your child home alone? If so, how often, and for how long?

• Insurance companies, always seeking to maximize profits by denying coverage or jacking up premiums, might start developing connections between energy use patterns – like eating late at night - and unhealthy tendencies.

• Soon RFID tagged labels – read by smart meters – will be found on more and more of the food and prescription drugs that fill our refrigerators and cabinets. Could our health insurance go up because we eat too much unhealthy food? Might we start receiving mailers trying to sell us new prescription drugs that their detailed behavioral profile has led them to conclude we need?

• Hackers and criminals might seek to falsify power usage, pass on their charges to a neighbor, take down the grid entirely, disconnect others, and plan burglaries with an unprecedented degree of accuracy.

• Some consumers are already getting statements that compare their use to their neighbors. Could we see a system develop in which some are penalized for more “wasteful” usage? What if the comparisons aren't fair? Will details such as the number of occupants be properly taken into account?

• Landlords might be interested in know more about what's happening inside their properties.

• If recent revelations regarding warrantless wiretapping, Patriot Act abuses and increasingly intrusive surveillance techniques are an indicator, we should also expect government agencies to come seeking our data.

As I also said that day, "such privacy implications strike at the heart of the Fourth Amendment, the California Constitution, and a core American value: our right to keep private what goes on in our homes, and the inherent freedom that that right provides us. The challenge that now stands before us is how to both protect consumer privacy while simultaneously empowering customers with the ability to access their data in near real time and potentially share it with entities other than the utility.

It is paramount then that our state’s transition to a smart grid system addresses the potential privacy pitfalls while we are in the early stages of its implementation; because once that genie is out of the bottle it’s difficult to put him back in.

A few principles we should keep in mind as we develop a regulatory framework will be consumer control, informed consent, transparency, security and accountability - including strict limits on the amount of data collected, its use, and the length of time it’s stored.

Such privacy safeguards will increase, not decrease, the long-term viability of, and consumer confidence in, the system itself. The only real conflict I foresee in implementing such a system is between those that want to protect their personal data versus those that seek to access and profit off it; as well as the expected public policy rush to get the system up and running before it’s truly ready.

The endless accumulation of our personal data – combined with the outlandish profits being made off it and growing government demand for it – represents a direct assault on our right to privacy. We would do well to contemplate the steady erosion of this right and its long-term implications.

Corporations, by definition, care about profit, not reducing energy usage, and certainly not protecting privacy, just as governments, particularly federal, care more about access and control.

Rapid technological advancement - without the requisite regulatory safeguards – will only add to the increasing disintegration of privacy rights in this country - something the Smart Grid could come to epitomize if we allow ourselves to be seduced by arguments that claim we have no time to spare or to just “trust” those with inherent conflicts of interest."

At this point, its too early to say whether my warnings have been properly heeded...certainly the jurisdiction issue suggests they have fallen short - so far.  But nothing is in stone yet...so I'll keep you posted.

Friday, February 18, 2011

Legislative Review: "Do Not Track", "Kill Switch", and Body Scanner Images

There was a flurry of federal privacy legislation introduced this past week I thought I'd quickly review.

Jackie Speier's Privacy Bills

Let's begin with the the especially good. In particular, the "Do Not Track" (DNT) and financial privacy legislation being proposed by privacy stalwart, and Congresswoman, Jackie Speier. The bill would essentially allow Internet users to opt-out from "cookies, sniffing, scraping, or any other new and creative methods developed by those looking to profit through these activities."

The "DNT" legislation would allow the Federal Trade Commission to force online advertisers to respect the wishes of users who do not want to be tracked for marketing purposes. Why is this important?

The Center for Digital Democracy explains:

Perhaps the most powerful - but largely invisible - force shaping our digital media reality is the role of interactive advertising and marketing. Much of our online experience, from websites to search engines to social networks, is being shaped to better serve advertisers. Increasingly, individuals are being electronically "shadowed" online, our actions and behaviors observed, collected, and analyzed so that we can be "micro-targeted." Now a $24 billion a year industry [2008 estimates] in the U.S., with expected dramatic growth to $80 billion or more by 2011, the goal of interactive marketing is to use the awesome power of new media to deeply engage you in what is being sold: whether it's a car, a vacation, a politician or a belief. An explosion of digital technologies, such as behavioral targeting and retargeting, "immersive" rich media, and virtual reality, are being utilized to drive the market goals of the largest brand advertisers and many others.

As I have written in the past, the DNT option is an interesting concept - one that privacy advocates have supported in the past. The feature, which the FTC has said could be located within browsers, would prevent a person from being exposed to behavioural advertising and would function like 'do not call' lists of phone numbers.

This is a sensible component of a much larger web privacy strategy that will ideally put the individual in control, or ownership, of their own data. While I favor the opt-in versus over the opt-out method as a rule of thumb, certainly a visible DNT mechanism in browsers would be an acceptable piece of the internet "privacy puzzle". The bill would give the FTC 18 months to come up with a set of regulations that would require advertisers to allow users to "effectively and easily" choose not to have their online behavior tracked or recorded.

The second bill introduced by Speier would enable consumers to better control financial information collected about them by banks and other institutions. That bill includes a provision that would prevent companies from sharing consumer financial information without explicit pre-approval from the consumer, a process known as opting in.

Speier stated, "These two bills send a clear message — privacy over profit. Consumers have a right to determine what if any of their information is shared with big corporations, and the federal government must have the authority and tools to enforce reasonable protections."

My friend Ryan Calo, director of the Consumer Privacy Project at Stanford Law School, had some important insights I'd like to share, stating "It really is a strong pro-consumer bill," (noting that the bill's teeth included provisions that would allow state prosecutors to go after privacy violators if the FTC didn't have time or resources.) He, as I have argued, also noted that the bill was not a panacea for preserving online privacy, particularly being that it would apply only to consumers who elect not to be tracked — a process called opting out. Anyone who did not opt out, for instance because they did not know how or know that they could, would not be protected.

This goes back to the issue I always raise here: Opt-in should be the privacy standard, not opt-out. If you want my personal information to share and sell, and you want to track what I do and when I do it, than you should have to ask me, period.

Schumer/Nelson Body Scanner Legislation


As some of you may know, I have written extensively about why I believe these airport body scanners and the subsequent aggressive pat downs for those that choose that "option", are grossly ineffective, intrusive, expensive, and unnecessary.

This bill does - at least partly - address just one of the myriad of problems I have with them: the accessing and sharing of these digital strip searches with the public. The bill - approved by the Senate on Tuesday - would make the misusing of body scanner images a federal crime punishable by up to a year in prison.

In other words, its aim is to prohibit anyone with access to the scanned body images, whether security personnel or members of the public, from photographing or disseminating those images. Besides a prison term, violators could be fined up to $100,000 per violation.

A quick sidenote on this issue, the USA Today wrote a blistering editorial this week on what they called the "'Inexcusable' delay on TSA body-scanner safety reports". The article notes that "The Transportation Security Administration has told members of Congress that more than 15 million passengers received full-body scans at airports without any malfunctions that put travelers at risk of an excessive radiation dose. Despite the reassurance, however, the TSA has yet to release radiation inspection reports for its X-ray equipment - two months after lawmakers called for them to be made public following USA TODAY's requests to review the reports.

Fueling concerns about the potential for scanner malfunctions and the TSA's ability to identify problems: TSA and its contractors had failed in the past to detect when some baggage X-ray machines were emitting excessive levels of radiation or had safety features that were missing or disabled. The TSA says that it has made improvements since then and that all of its X-ray scanners - for people and luggage - have passed recent inspections by contractors. The agency in January asked the CDC to repeat its luggage X-ray study "to confirm the progress TSA has made," Lee says.


By the least this is an issue to keep an eye on.

Leiberman/Collins Kill Switch Legislation

It should surprise no one that one of the most anti-civil liberties bill's of the session would come from Senator Joe Lieberman. What's particularly revolting about this bill is we saw, just these past few weeks in Egypt, how government can use such power over the internet and the peoples access to information.

The USA Today has more:

The bill - crafted by Sens. Joseph Lieberman, I-Conn.; Susan Collins, R-Maine; and Tom Carper, D-Del. - aims to defend the economic infrastructure from a cyberterrorist attack. But it has free-speech advocates and privacy experts howling over the prospect of a government agency quelling the communication of hundreds of millions of people.

"This is all about control, an attempt to control every aspect of our existence," says Christopher Feudo, a cybersecurity expert who is chairman of SecurityFusion Solutions. "I consider it an attack on our personal right of free speech. Look what recently occurred in Egypt."

...

The disruption to communications and economic activity "could be catastrophic," says Marc Rotenberg, executive director of the Electronic Privacy Information Center.

...


Cyberthreats aside, deep questions persist over what critics claim is the bill's heavy-handed approach, what it means to free speech and whether it can be enforced practically.

The crux of the issue, to computer-law expert Fertik and others, is if the Internet is a national asset, should it be nationalized? "Determining where the Internet connects to infrastructure is hard to define and impose," Kagan says.

"In its current form, the legislation offers no clear means to check that power," says Timothy Karr, campaign director for media-policy group Free Press, a non-profit organization.



....


A provision in the bill lets the president take limited control during an emergency and decide restrictions. "It, essentially, gives the president a loaded gun," Fertik says.

"Say there is a mounted attack from a terrorist group on the Internet," Fertik says. "(The law) could present the president with a kill switch option. But what are the conditions, and how far does (the law) go?"

The debate extends to minutiae in the bill's wording. It neither expressly calls for the creation of an Internet kill switch nor does it exclude one. It only requires the president to notify Congress before taking action, and it specifically prohibits judicial review of the president's designation of critical infrastructure. The non-profit Center for Democracy and Technology, in a measured letter to Lieberman, Collins and others, wants more specifics on the sweep of "emergency" measures mentioned in the bill.


"In our constitutional system of checks and balances, that concentrates far too much power in one branch of government," says Karr. "The devil is always in the details, and here the details suggest that this is a dangerous bill that threatens our free-speech rights."

Giving the president broad power to "interfere" with the Internet - even bottling up chunks of it in the name of national security - would require him to go to court to stop communications, says Michelle Richardson, legislative counsel for the American Civil Liberties Union. What's more, a new law may be next to impossible to administer widely, technology experts say.
Read more here.


More generally, particularly on the issue of privacy on the internet, as I have written here before, the fact that we have next to no privacy standards as related to these technological innovations and trends is disturbing, and more than enough of a reason for some of the bills being offered here - like Speier's for instance.

What kind of control should we have over our own data? And, what kind of tools should be available for us to protect it? What about ownership of our data? Should we be compensated for the billions of dollars being made by corporations from their tracking of us? And of course, what of the government's access to this new world of data storage?

The argument by some, such as Mark Zuckerberg, is that all information should be public, and as time goes on we'll only be sharing more of it. In addition, we all will benefit from this communal sharing of private information in ways yet to even be discovered. Already, from this sharing, we forge more online friendships and connections, old friends are reconnected, distant parents see pictures of their kids' day-to-day activities, jobs might be more easily found due to our profiles being more public, internet services improve as companies like Facebook and Google learn about peoples' Web browsing histories, sites are able to tailor content to the user, and so on, and so forth.

That last point, has particular resonance with me. What concerns me is what are the side effects of living in a society without privacy? Not just on the next, about our personal habits, but from the watchful eye of government, be it the knowledge that we could be wiretapped, that smart grid monitors are daily in home habits, that our emails can be intercepted, that our naked bodies must be viewed at airports, that our book purchases can be accessed (particularly if Google gets its way and everything goes electronic), that street corner cameras are watching our every move, that RFID tags allow for the tracking of clothes, cars, and phones...and the list goes on.

Stay tuned...

Tuesday, January 11, 2011

4th Amendment Takes Another Hit - Phone Records/Texts

I've argued quite often here in favor of a strong 4th Amendment (what a radical!), particularly in light of the continuous assault on it - especially since 9/11 and the Patriot Act.

I'll run down some of the ways this critical protection against unreasonable search and seizure has been so weakened in recent years once I delve into the latest assault a bit.

I speak of last week's ruling handed down by California's top court involving a 2007 arrest of someone who had purchased drugs from a police informant. Investigators later looked through the individuals phone and found text messages that implicated him in a drug deal. The suspect appealed the conviction, saying the evidence was gathered in violation of the Fourth Amendment, which prohibits unreasonable searches and seizures.

The justices disagreed: "The cell phone was an item (of personal property) on the person at the time of his arrest and during the administrative processing at the police station. Because the cell phone was immediately associated with defendant’s person, (police were) entitled to inspect its contents without a warrant."

But court went further - comparing the cell phone to personal effects like clothing. Worse, it argued that it wasn't because the police had a particular right in this particular case, or there was some special exception that allowed such a search, but rather, it argues that no exception was even necessary. In other words, this case was not an exception, but rather the NEW rule: cell phone records are now of little difference than the shirt on your back if you've been arrested. This is a deeply disturbing precedent if it holds.

MSNBC's Red Tape Chronicles reports:

The next time you're in California, you might not want to bring your cell phone with you. The California Supreme Court ruled Monday that police can search the cell phone of a person who's been arrested -- including text messages -- without obtaining a warrant, and use that data as evidence.

The ruling opens up disturbing possibilities, such as broad, warrantless searches of e-mails, documents and contacts on smart phones, tablet computers, and perhaps even laptop computers, according to legal expert Mark Rasch.

...

Rasch, former head of the Justice Department's computer crime unit, pulled no punches in his reaction to the ruling. "This ruling isn't just wrong, it's dangerous," said Rasch, now director of cybersecurity and privacy at computer security firm CSC in Virginia. "It's remarkable, because it simply misunderstands the nature of these devices."

The door is open for police to search the entire contents of iPhones or other smart phones that people routinely carry, he said. "In fact, I would be shocked if police weren't getting instructions right now to do just that," he said.

By applying the "personal property on the defendant's person" standard, Rasch said, the ruling could logically extend to tablets or even laptop computers, he said. It also flies in the face of established law, which prohibits the warrantless search of briefcases by police, other than a quick search for weapons, Rasch said.

...

Rasch said the analogies don't hold, however, as modern phones that can store years' worth of personal information are a far cry from drugs hidden in a cigarette case or clothes pockets. "There is a process for looking at data inside devices,” he said. “It's called a warrant."

The California ruling was not unanimous. Dissenting Justice Kathryn Werdegar raised similar concerns in her opinion. "The majority’s holding ... (grants) police carte blanche, with no showing of exigency, to rummage at leisure through the wealth of personal and business information that can be carried on a mobile phone or handheld computer merely because the device was taken from an arrestee’s person...The majority thus sanctions a highly intrusive and unjustified type of search, one meeting neither the warrant requirement nor the reasonableness requirement of the Fourth Amendment to the United States Constitution."

Jonathan Turley, a Constitutional law expert at George Washington University, took to his blog to raise his concerns about the ruling. "The Court has left the Fourth Amendment in tatters and this ruling is the natural extension of that trend," he wrote. "While the Framers wanted to require warrants for searches and seizures, the Court now allows the vast majority of searches and seizures to occur without warrants. As a result, the California Supreme Court would allow police to open cell phone files — the modern equivalent of letter and personal messages.”

Click here for more.

This decision will of course be appealed to the U.S. Supreme Court. But keep in mind, as I understand it, nearly 1/3 of all federal judges were appointed by George W. Bush...meaning we probably have something close to a Federalist Society majority running the courts. And what does that mean? Well, let's just say such judges and courts adhere to two key principles: corporations are always right, and law enforcement is always right.

In the meantime for Californians however, this decision means warrantless searches of cell phones is essentially state law now. One suggestion coming from the author of the article is use password-protection on your smart phones as a possible way to ward off a warrantless searches. While it's not clear that an arrested suspect could be compelled to divulge his or her password to police, at least legal arguments have not yet been made giving them that right.

Other Attacks on the 4th Amendment

As I have said, with the passage (and renewal) of Patriot Act, and the technological advancement in things like RFID tags and GPS tracking capabilities, the 4th Amendment is itself an endangered species. Just recently the Obama Administration has argued that prohibition against unreasonable searches and seizures does not apply to cell-site information mobile phone carriers retain on their customers.

The government has been arguing, consistently now, that federal law requires judges to approve their applications for location information from cell phone companies - even if the police don't have probable cause to obtain this sensitive information. Courts have the right under statute - and the duty under the Constitution - to demand that the government obtain a search warrant before seizing this private location data.

Mobile phone providers store data about where customers make and receive calls, based on the cell towers the customers' phones used. And that's why the government has been attempting to collect past mobile-phone tracking information. That way they can go back in the past for as long as the cell phone companies keep records.

The ACLU had recently provided documents showing that of the states randomly sampled, New Jersey and Florida used GPS tracking without obtaining probable cause or warrants. Four other states, California, Louisiana, Indiana, Nevada and the District of Columbia reported having obtained GPS data only after showing probable cause.

Those documents were part of the ongoing lawsuit by the ACLU and Electronic Frontier Foundation, in which they argued government tracking without a probable cause or warrant is a violation of the Constitution's Fourth Amendment.

The essential argument by privacy advocates, be it the tracking of a cell phone user, or placing a tracking device in a suspect's vehicle, is that, whether you're driving a car or carrying a cell phone you should not be more susceptible to government surveillance. The idea being, no one wants to feel as if a government agent is following you wherever you go - be it a friend's house, a place of worship, or a therapist's office - and certainly innocent Americans shouldn't have to feel that way.

This argument won the day, at least in this case, as a federal appeals court ruled last year the police can’t covertly track a suspect’s car using a GPS device for an extended period of time without getting a warrant. The ruling in the D.C. Court of Appeals overturned the conviction of a suspected cocaine dealer, saying that the use of a secret GPS tracking device on the man’s vehicle for two months violated the Fourth Amendment’s protection against unreasonable searches and seizures.

But while that case, in the meantime anyway, represented a victory, let's remember too that the FBI was found to have illegally collected more than 2,000 U.S. telephone call records between 2002 and 2006 by invoking terrorism emergencies that did not exist or simply by persuading phone companies to provide records.

E-mails obtained by The Washington Post have detailed how counter terrorism officials inside FBI headquarters did not follow their own procedures that were put in place to protect civil liberties. The stream of urgent requests for phone records also overwhelmed the FBI communications analysis unit with work that ultimately was not connected to imminent threats.

The Patriot Act versus the 4th Amendment

And also last year we saw Congress renew some of the most egregious components of the Constitution eviscerating Patriot Act including:

1. Allowing broad warrants to be issued by a secretive court for any type of record, from financial to medical, without the government having to declare that the information sought is connected to a terrorism or espionage investigation.

2. Renewing the so-called “roving wiretap” provision, allowing the FBI to obtain wiretaps from the secret court, known as the FISA court, without identifying the target or what method of communication is to be tapped.

3. Renewing the so-called “lone wolf” measure that allows FISA court warrants for the electronic monitoring of a person for whatever reason — even without showing that the suspect is an agent of a foreign power or a terrorist.

4. And of course, the government can still essentially break into your house as long as it doesn't tell you it did...may the 4th Amendment rest in peace.

Border Laptop Seizures

But wait, I'm not finished. The war on the 4th Amendment also includes these border zones in which the government is essentially allowed to stop and question people anywhere without suspicion within 100 miles of the border. This little known power of the federal government to set up immigration checkpoints far from the nation's border lines came about after 9/11, when Congress gave the Department of Homeland Security the right to use some of its powers deeper within the country.

According to the ACLU in October of 2008, the Department of Homeland Security had set up at least 33 internal checkpoints where they stop people, question them and ask them to prove citizenship. At that time I noted that if we allow these kinds of constitutional violations along our border, how long will it take before we start allowing them in the heartland? And I tend to be of the opinion that anytime we weaken the rights of ANYONE, we weaken them for EVERYONE.

And that brings us to the the supposed right of these border agents, for any reason they deem appropriate, to look into or even seize your laptop computer and all that it contains within. So, for ANY reason, YOUR laptop and everything you have stored on it, can be taken from you by the government...the same government responsible for Abu Graihb, Rendition, Guantanamo, warrantless wiretapping, military tribunals, the Patriot Act, and the evisceration of Habeus Corpus.

In response to the work of the ACLU, the government came back with a slightly less intrusive policy, requiring the CBP to complete a search of an electronic device within five days and ICE to complete a search within 30 days.

In addition, agents must take additional steps to inform and educate travelers about the searches, and the DHS Office for Civil Rights and Civil Liberties will conduct an assessment of the policy's impact on civil rights within 120 days.

The practice of suspicion-less laptop searches violates fundamental rights of freedom of speech and protection against unreasonable seizures and searches, and are especially invasive because devices like laptops contain personal data, which people should be able to keep private.

As I wrote on this blog in the past, "Can't we all agree that the 4th Amendment has taken enough of a beating over the past 8 years??? Can we not also agree that warrantless government searches of our homes is a grotesque subversion of the Constitution (I would also argue our privacy)?"

And now, a California court has ruled that smart phones are no different than a cigarette carton in a suspect's jacket? I would simply ask how can any free society benefit from, or reconcile, such policies as illegal search and seizures (including of laptops), warrantless wiretapping, the tracking of GPS devices in peoples cell phones, the utilization of "whole-body-imaging" (digital strip search) scanners in airports, the evisceration of Habeus Corpus, Rendition, Military Tribunals, and the Patriot Act? (and the list goes on and on).

My point in bringing all these up is so we stop viewing each, individual case as existing in some vacuum. What we must begin to see, clearly, is the pattern, and the direction we are headed.

Thursday, September 9, 2010

More On "Chipping" (RFID) School Children

I wanted to follow up just a bit on my last post (see below) about a preschool in Richmond digitally tracking children using microchips embedded into their jersey tops. As I wrote last Friday, the question for me comes down to whether the minor benefits associated with this monitoring outweigh the myriad of potential pitfalls associated with an ever expanding surveillance state.

My answer to this question of course was "no", its not a worthwhile trade off. The focus of my concerns in that last post was on the larger deleterious effect, I believe, constant, ubiquitous monitoring has on human consciousness itself, and worse, how it functions to stifle dissent in an ostensibly "free" society.

Now, before I get to some additional problems with chipping kids enumerated by my friend at the ACLU, Nicole Ozer, let me restate my conclusion from last week. I wrote:

"This issue is far from over. The rapid evolution of RFID technology and its uses makes it essential that we draw common sense lines now. Whether its video cameras on every street corner, RFID tags in our clothes and cars, or government wiretapping and corporate surveillance, or social networking sites like Facebook, or Smart Grid metering and in home monitoring technologies, or just about anything created by Google, the trend line is all too clear.

More concerning than any single threat posed by any single technology – including chipping children – is this larger pattern indicating that privacy as both a right and an idea is under siege.

As young people grow up with so much of their information so public and accessible to all, including government, and nearly every action they take is in some way being recorded and/or monitored, I fear their sense, appreciation and understanding of privacy will continue to fade away.

The consequences of such a loss would be profound. Yes, there are lots of more tangible, and immediate threats associated with the loss of privacy, from identity theft to intimidation to stalking. But, what concerns me most about the trajectory we're on is how does the knowledge that EVERYTHING you do is being watched and recorded effect human consciousness? Could we actually be stifling young peoples' creativity, their courage to dissent, and perhaps even their individuality, if they're conditioned at such a young age to accept being monitored and watched at all times?

Specifically, how does a lifetime of being constantly surveilled effect human behavior? Could it lessen peoples courage to stand up to authority (a prerequisite for a functioning democracy)? Is this all just another way to steadily stifle, and even eliminate dissent - dissent that is needed now more than ever?

But let me now transition to some more specific privacy threats these RFID chips pose to the children themselves. Remember, these chips function somewhat like a GPS system - and thus expose these children to stalking, tracking and identity theft.

Here's some of what the ACLU'S Nicole Ozer had to say:

While school officials and parents may have been sold on these tags as a "cost-saving measure," we are concerned that the real price of insecure RFID technology is the privacy and safety of small children. RFID has been billed as a "proven technology," but what’s actually been proven time and again (PDF) since the ACLU first looked at this issue in 2005 is just how insecure RFID chips can be:

* RFID chips in US passport cards were cracked and copied from a distance of 30-feet using $250 in parts bought from eBay (2009).
* RFID chips used in building access cards across the country were cracked and copied with a handheld device the size of a standard cell phone that was built using spare parts costing $20 (2007).
* California State Capitol RFID-based identification cards were cracked and copied and access was gained to member-only, secure entrances (2006).
* RFID chips implanted in humans were cracked and copied (PDF) (2006).
* The RFID chips used in the Dutch and British e-passport were cracked (PDF) (2006).

Without real security, RFID chips could actually make preschoolers more vulnerable to tracking, stalking, and kidnapping. Someone who wants to do children harm could potentially sit in a car across the street and scan the children’s jerseys without teachers, school officials, parents, or children ever knowing that any information has been read. And if this information can be read, it can be copied easily to a duplicate chip. A child could be taken off campus while the duplicate chip continues to tell RFID readers that the child is safely at school.

...

If the price for parents going to Head Start is that your kids are tracked and potentially made unsafe, that's not acceptable. These chips are really high powered. They can be read up to 100 meters away which means someone could pick up the signal from across the street from the center. So rather than make the kids safer they may be making them more vulnerable.

These are just the tip of the security issues—and we haven’t even touched on the core privacy concerns. The editors of Scientific American said it well back in May 2005: "Tagging … kids becomes a form of indoctrination into an emerging surveillance society that young minds should be learning to question."

At this point, we have far more questions than answers about the RFID system in use in Richmond:

*
What security measures are in place on the RFID chips?
* How will data collected from the chips be used? How long will it be kept?
* Were parents given a choice whether or not to have their child "chipped?"
* Were parents told how RFID technology works, what the privacy and security risks are, and what the school has done to make sure the chips are secure and compliant with student privacy laws?
* And did the County consider these questions before they received a federal grant for this program?

You can read the rest of her blog here.

To once again reiterate what I said last week, these kinds of mechanical devices might be useful for tracking cattle, but when it comes to children, RFID’s are no substitute for teacher and school staff responsibility.

And I would add, again, that in addition to these chips exposing to children to stalking, tracking and identity theft, it all strikes me as feeling a bit too much like Orwell's 1984 or Huxley's Brave New World. It's not that I'm that frightened about how this surveillance will be used against people, though that's a real concern too, but more so, I fear how this loss of privacy and freedom negatively effects consciousness - creating a more docile, servile populace.

Wednesday, September 1, 2010

Tracking Preschoolers With RFID Tags?

When I read the story today about a preschool in Richmond digitally tracking children using microchips embedded into their jersey tops I was immediately reminded of legislation I worked on a few years ago partially addressing this very issue. And of course, I also had that old "slippery slope" argument immediately come to mind when I picture all these chipped kids with digital markers tracking everywhere they go as some administrator watches.

The legislation I'm referring to (and an op-ed I had published about it) would have required any school seeking to chip their students to first ask the parents for permission. Seems like a straight forward, no brainer, right? Well, that's what we thought, until the Governor vetoed the legislation, even in the face of overwhelming support in the legislature and in the public.

Before I get into more reasons why I generally don't like the idea of chipping kids for tracking purposes, let's clarify what we're talking about. Essentially, the school is tagging the children's clothes with monitoring devices that transmit a signal to sensors installed throughout their buildings, ostensibly helping administrators secure the child's whereabouts at all times. Parents will also digitally sign the child in and out of school, thereby eliminating the need for attendance records filed by hand.

Okay, so maybe there are a few pro's to such monitoring. And at least in this case, unlike the situation I wrote about in my article, the parents are at least involved and aware. The question of course is whether the minor benefits associated with this monitoring outweigh the potential pitfalls associated with an ever expanding surveillance state.

Now let's first go back to that legislation the Governor vetoed and what I wrote at the time:

In 2005 a tiny school district in Northern California inadvertently ignited a statewide debate over the appropriate use of modern technologies in the school system. The technology in question was Radio Frequency Identification, or RFID, which the district had embedded in student badges without parents' knowledge. The children were required to carry these tracking devices or suffer suspension.

Controversy erupted when parents discovered that the new badges - which function somewhat like a GPS system - exposed their children to stalking, tracking and identity theft. Worse, the children were “chipped” without parental notice or consent. The district had intended to use the technology to remotely monitor student movement on campus; even installing readers on the bathroom doors. Parents rightly objected, strongly, but it wasn’t until a media firestorm was ignited that the district backed down.

Had the district engaged parents in a conversation before installing the RFID-enhanced ID system the community’s sensitivities and concerns could perhaps have been adequately balanced with the districts goals of enhancing campus safety and improving attendance recording.

Unfortunately that’s not how it happened, but that’s how it should have happened.

Given the controversial nature of RFID technologies, and the inherent risks associated with it, school districts should be required to notify parents and get their consent BEFORE “chipping” their children.

Schools are already required to get parental permission for sex education, field trips, and in some cases, student cell-phone use on campus.

If the Sutter case illustrates nothing else, it’s that parents, not schools, should decide whether children must carry a tracking devise. Mechanical devices might be useful for tracking cattle, but when it comes to our children, RFID’s are no substitute for teacher and school staff responsibility.

Parental notification and consent would also provide an important check on district incentives to use invasive RFID-systems. Because schools receive funding based on attendance, a financial incentive exists to closely monitor student presence on campus. But there is a line that can be crossed – RFID monitors in the bathroom, for example – between sensible oversight and invasion of privacy.

Absent a countervailing force in defense of student privacy, the district’s natural tendency will be to secure its interests at the expense of the students’. Parents can only function as this countervailing force if they are granted their rightful seat at the table. Currently, no such right exists!

The Governor had an opportunity to rectify this injustice in the form of Senate Bill (SB) 29 by Senator Joe Simitian (D-Palo Alto). The legislation was specifically crafted as a response to the Sutter County incident and to ensure that in the future schools notify parents and get their consent before embedding students with RFID-enabled tracking devices.

This pragmatic measure – remarkably and painstakingly moderate so as to be in tune with the Governor’s general sensibilities - was supported by nearly every state legislator and organizations spanning the political spectrum from the ACLU to the Liberty Coalition to the Parents and Teachers Association to the Consumer Federation of California.

Nonetheless, the Governor vetoed the bill – and missed an important opportunity to ensure child safety, protect personal privacy, and defend the rights of California parents.

Now let's go to the story in California Watch about this Contra Costa situation:

Tracking microchips have become popular in recent years as the technology of choice for pet owners, prison guards and cattle wranglers. But the rapid social acceptance of such technology troubles some civil rights and privacy advocates.

....

Cedric Laurant, a lawyer with the Electronic Privacy Information Center, said this about Brittan's microchip program in 2005:

Monitoring children with RFID tags is a very bad idea. It treats children like livestock or shipment pallets, thereby breaching their right to dignity and privacy they have as human beings. Any small gain in administrative efficiency and security is not worth the money spent and the privacy and dignity lost.


Click here to read more.

This issue is far from over. The rapid evolution of RFID technology and its uses makes it essential that we draw common sense lines now. Whether its video cameras on every street corner, RFID tags in our clothes and cars, or government wiretapping and corporate surveillance, or social networking sites like Facebook, or Smart Grid metering and in home monitoring technologies, or just about anything created by Google, the trend line is all too clear.

More concerning than any single threat posed by any single technology – including chipping children – is this larger pattern indicating that privacy as both a right and an idea is under siege.

As young people grow up with so much of their information so public and accessible to all, including government, and nearly every action they take is in some way being recorded and/or monitored, I fear their sense, appreciation and understanding of privacy will continue to fade away.

The consequences of such a loss would be profound. Yes, there are lots of more tangible, and immediate threats associated with the loss of privacy, from identity theft to intimidation to stalking. But, what concerns me most about the trajectory we're on is how does the knowledge that EVERYTHING you do is being watched and recorded effect human consciousness? Could we actually be stifling young peoples' creativity, their courage to dissent, and perhaps even their individuality, if they're conditioned at such a young age to accept being monitored and watched at all times?

Specifically, how does a lifetime of being constantly surveilled effect human behavior? Could it lessen peoples courage to stand up to authority (a prerequisite for a functioning democracy)? Is this all just another way to steadily stifle, and even eliminate dissent - dissent that is needed now more than ever?

I have to say, this all starts to sound too much like Orwell's 1984 or Huxley's Brave New World. It's not that I'm that frightened about how this surveillance will be used against people, though that's a real concern too, but more so, I fear how this loss of privacy and freedom negatively effects consciousness - creating a more docile, servile populace.

As noted privacy expert Bruce Schneier recently stated:

“…lack of privacy shifts power from people to businesses or governments that control their information. If you give an individual privacy, he gets more power…laws protecting digital data that is routinely gathered about people are needed. The only lever that works is the legal lever...Privacy is a basic human need…The real choice then is liberty versus control.”