Tuesday, December 18, 2007

ACLU presses candidates to repeal Real ID card law

The ACLU has rightly thrust the REAL ID Act - and the need for all candidates to proclaim their opposition to it - into the Presidential campaign.

For those that follow the campaign - or privacy for that matter - its probably not a great suprise to know that Democratic candidates Dennis Kucinich and John Edwards, as well as Republican candidate Ron Paul, are the only ones to date to CLEARLY articulate the threat the REAL ID Act poses to civil liberties.

New Hampshire's Union Leader reports:

Begun in July, the national and state organizations' efforts to get the candidates to publicly reject the plan to turn the state driver's license into a de facto national identification card haven't had much success.

While former Sen. John Edwards and Ron Paul are on record against Real ID as a threat to civil liberties, as is Congressman Dennis Kucinich, Sen. Barack Obama's only response so far has been to object on grounds it's an unfunded mandate and not enough has been done to help the state's implement it.

Ebel said requests to the national office of Sen. Hillary Clinton have produced no response, so she's hoping the campaign organization here will be more receptive. On the Republican side, former Mass. Gov. Mitt Romney's campaign said that he favors a national ID, but opposes driver's licenses for illegal immigrants. Former Arkansas Gov. Mike Huckabee has said he doesn't think DMV workers should be in the immigration business.

...

Calabrese said the ACLU projects that although Real ID calls for the states to be in charge of their own information, ultimately the Feds will say "let us handle the database."

Ebel and Calabrese said the Department of Homeland Security is beginning to figure out there's growing opposition to Real ID at the state level, so they've introduced the Western Hemisphere Travel Initiative that ACLU officials termed a "bait and switch" plan, which would hook up the driver's license base to customs databases.

Although people were originally going to have a passport to cross the border, DHS said if states linked their driver's license base to customs databases, they'd then be in compliance with Real ID. A key concern is that the DHS could expand the uses beyond the official purpose of Real ID. As specified by legislation, the Real ID is a secure card issued by states to be used only for the following reasons: to access a federal facility, board federally regulated commercial aircraft and enter nuclear plants.

Click here to read the article in its entirety.

Monday, December 17, 2007

Wider Spying Fuels Aid Plan for Telecom Industry

As the "FISA Retroactive immunity" bill is being debated on the Senate floor (and in fact just passed 76-10), Senator Chris Dodd is preparing a filibuster.

This critical debate, as often discussed here, is over whether the telecommunications industry should be protected from lawsuits for their aiding the National Security Agency’s warrantless, and illegal, eavesdropping program.

But aside from the political maneuverings taking place in the Senate as I write this, as the New York Times reported this weekend, this debate is as much about what was the relationship between the government and private industry, as it is about what the Bush administration wants this relationship to be in the future.

The New York Times reports:

But the battle is really about something much bigger. At stake is the federal government’s extensive but uneasy partnership with industry to conduct a wide range of secret surveillance operations in fighting terrorism and crime. The N.S.A.’s reliance on telecommunications companies is broader and deeper than ever before, according to government and industry officials, yet that alliance is strained by legal worries and the fear of public exposure.

...

After the disclosure two years ago that the N.S.A. was eavesdropping on the international communications of terrorism suspects inside the United States without warrants, more than 40 lawsuits were filed against the government and phone carriers. As a result, skittish companies and their lawyers have been demanding stricter safeguards before they provide access to the government and, in some cases, are refusing outright to cooperate, officials said.

...

The government’s dependence on the phone industry, driven by the changes in technology and the Bush administration’s desire to expand surveillance capabilities inside the United States, has grown significantly since the Sept. 11 attacks. The N.S.A., though, wanted to extend its reach even earlier. In December 2000, agency officials wrote a transition report to the incoming Bush administration, saying the agency must become a “powerful, permanent presence” on the commercial communications network, a goal that they acknowledged would raise legal and privacy issues.

...

The accusations rely in large part on the assertions of a former engineer on the project. The engineer, who spoke on the condition of anonymity, said in an interview that he participated in numerous discussions with N.S.A. officials about the proposal. The officials, he said, discussed ways to duplicate the Bedminster system in Maryland so the agency “could listen in” with unfettered access to communications that it believed had intelligence value and store them for later review. There was no discussion of limiting the monitoring to international communications, he said. “At some point,” he said, “I started feeling something isn’t right.”

...

The facts behind a class-action lawsuit in San Francisco are also shrouded in government secrecy. The case relies on disclosures by a former AT&T employee, Mark Klein, who says he stumbled upon a secret room at an company facility in San Francisco that was reserved for the N.S.A. Company documents he obtained and other former AT&T employees have lent some support to his claim that the facility gave the agency access to a range of domestic and international Internet traffic.

The telecommunications companies that gave the government access are pushing hard for legal protection from Congress. As part of a broader plan to restructure the N.S.A.’s wiretapping authority, the Senate Intelligence Committee agreed to give immunity to the telecommunications companies, but the Judiciary Committee refused to do so. The White House has threatened to veto any plan that left out immunity, as the House bill does.

“Congress shouldn’t grant amnesty to companies that broke the law by conspiring to illegally spy on Americans” said Kate Martin, director of the Center for National Security Studies in Washington.

Click here to read the article in its entirety.

Friday, December 14, 2007

Did Blockbuster, Facebook Break Privacy Law With Beacon?

Just when you thought the Facebook/Beacon scandal had been laid to rest, I find this article in PC World.

Apparently, there's a 1988 law called the Video Privacy Protection Act (VPPA). The law clearly "prohibits movie rental companies such as Blockbuster from disclosing personally identifiable rental records of the people who rent or buy movies from them to others -- unless the customer consents to the practice in writing."

We also happen to know that movie choices made by Facebook members on Blockbuster's website were made available to other members of the social network.

PC World details the story:

The case against Blockbuster is quite straightforward," said James Grimmelmann, associate professor at the New York Law School. "I'm surprised that there haven't been lawsuits already in terms of Blockbuster. The one against Facebook requires a couple more steps. It's one of those interesting issues" that can be viewed in multiple ways legally.

...

Civil remedies under the law include fines of at least US$2,500 for each violation. In the few situations where the law has been invoked, the cases involved the disclosure of customer movie rental records to law enforcement authorities by rental companies. The law has never been tested in an online situation such as the one involving Blockbuster and Facebook, and could raise interesting issues, according to Grimmelmann.

...

Facebook's Beacon ad service was released in early November as a part of the Facebook Ads platform. It is ostensibly designed to track the activities of Facebook users on more than 44 participating Web sites and to report those activities to the users' Facebook friends, unless specifically told not to do so. The idea is to give participating online companies a way to monitor the activities of Facebook users on their Web sites and to use that information to then deliver targeted messages to Facebook friends.

The problem with that arrangement, at least for Blockbuster, is that such information sharing put it in violation of VPPA before Facebook changed its privacy policies following an outcry over Beacon, Grimmelmann said. The mere fact that Blockbuster passed on movie choice information to Facebook friends without user consent is a violation of VPPA...


Click here to read the article in its entirety.

Unlikely allies unite to fight enhanced-ID plan

Not uncommon when it comes to the issue of privacy, unlikely allies from the left and right have joined forces. In this case, its the ACLU, the John Birch Society, and various Republican lawmakers voicing their opposition to Arizona Gov. Janet Napolitano's plan to create an enhanced state driver's license...which opponents believe moves the state a whole lot closer towards adopting requirements laid out in the REAL ID Act.

The Arizona Republic reports:

Napolitano last week signed an agreement with Homeland Security Secretary Michael Chertoff to create a three-in-one identification card. It would function as a driver's license, a valid ID for crossing the borders into Mexico and Canada, and a way for employers to verify workers' status under the soon-to-be-launched employer-sanctions law.

...

Under the terms of the agreement, the ID would be voluntary. It would cost $20 to $25 more than a standard driver's license because it would include an embedded information chip that could be read through radio-frequency identification technology. It's that technology that has opponents nervous and angry.

...

Alessandra Soler Meetze, executive director of the ACLU of Arizona, said the technology opens people up to having their identities stolen and to the government tracking citizens' every move."Any wireless signal is inherently insecure," she said.

As reported in the Arizona Daily Star, the debate centers around whether the idenities of those carrying the cards are truly at risk being that they contain no personal information, just an identification number. And, also argued by the Governor, is because the cards themselves are voluntary, not mandatory, they don't represent a government power grab or privacy invasion.

These arguments do not satisfy opponents of the program:

"I think they just value very much their privacy," the senator said. "And although it is voluntary at the moment, once the federal government gets involved I have no faith that it would stay voluntary."

...

Napolitano said the chips contain no personal information, just an identification number. She said only someone with access to the state Department of Public Safety database could learn anything more about the holder.

Homeland Security spokes-man Russ Knocke said the maximum range for reading the chips is 10 to 20 feet.

But Alessandra Meetze, executive director of the Arizona chapter of the American Civil Liberties Union, said that provides little comfort, even if true. She said it still would permit anyone with the right electronic equipment to track the movements of individuals.

Click here to read the article in the Arizona Republic.

Click here to read the Arizona Daily Star.

Thursday, December 13, 2007

Ask.com Puts a Bet on Privacy

It appears consumers are going to have an option now for greater privacy when searching the web. The fourth largest search engine company has begun offering a service called AskEraser, which allows users to make their searches more private.

The small company (compared to Google or Yahoo that is) from Oakland California is hoping that this new technology will help give them a leg up on the competition. Let us hope so.

The New York Times reports:

Ask.com and other major search engines like Google, Yahoo and Microsoft typically keep track of search terms typed by users and link them to a computer’s Internet address, and sometimes to the user. However, when AskEraser is turned on, Ask.com discards all that information, the company said.

...

The service will be conspicuously displayed on Ask.com’s main search page, as well as on the pages of the company’s specialized services for finding videos, images, news and blogs. Unlike typical online privacy controls that can be difficult for average users to find or modify, people will be able to turn AskEraser on or off with a single click.

...

I think that it is a step forward,” said Ari Schwartz, deputy director of the Center for Democracy and Technology, about AskEraser. “It is the first time that a large company is giving individuals choices that are so transparent.”

But underscoring how difficult it is to completely erase one’s digital footprints, the information typed by users of AskEraser into Ask.com will not disappear completely. Ask.com relies on Google to deliver many of the ads that appear next to its search results. Under an agreement between the two companies, Ask.com will continue to pass query information on to Google. Mr. Leeds acknowledged that AskEraser cannot promise complete anonymity, but said it would greatly increase privacy protections for users who want them, as Google is contractually constrained in what it can do with that information.

...

Last year, AOL released the queries conducted by more than 650,000 Americans over three months to foster academic research. While the queries where associated only with a number, rather than a computer’s address, reporters for The New York Times and others were quickly able to identify some of the people who had done the queries. The queries released by AOL included searches for deeply private things like “depression and medical leave” and “fear that spouse contemplating cheating.”

The incident heightened concerns about the risks posed by the systematic collection of growing amounts of data about people’s online activities. In response, search companies have sought to reassure consumers that they are serious about privacy.

...

In recent months, privacy has emerged as an increasingly important issue affecting major Internet companies. Several consumer advocacy groups, legislators and competitors, for instance, have expressed concerns about the privacy implications of the proposed $3.1 billion merger between Google and the ad serving company DoubleClick, which is being reviewed by regulators in the United States and Europe.

Last month, the Federal Trade Commission held a forum to discuss concerns over online ads that appear based on a user’s Web visits. And just last week, the popular social networking site Facebook suffered an embarrassing setback when it was forced to rein in an advertising plan that would have informed users of their friends’ buying activities on the Web. After more than 50,000 of its members objected, the company apologized and said it would allow users to turn off the feature.

The question remains - and perhaps will be answered to a degree with the offering of this new product - whether privacy is a strong enough concern among consumers to turn a feature like AskEraser into a major selling point for Ask.com. Click here for the article in its entirety.

Surveillance Court Declines to Release Secret Opinions

While not a surprise, this news is a disappointment. Despite the ACLU's best efforts, the Foreign Intelligence Surveillance Court has refused to release documents related to two past opinions it has given on the legality of the Bush administration wiretapping program.

The two decisions in question conflicted with one another, with the first seeming to give the administration more leeway in its continuation of the program it had been secretly conducting without court approval, while the second one was more restrictive.

The New York Times reports:

When Congress began debating changes in August, the civil liberties union asked the court to release the two opinions, arguing that the public had a right to know the court’s legal reasoning in the midst of a Congressional debate on the issue. The court’s presiding judge, Colleen Kollar-Kotelly, said then that it would consider the request, which she called “unprecedented.” In its own brief filed with the court, the administration opposed disclosure of the documents.

...

But, Judge Bates said, such benefits do not outweigh the government’s need or right to keep the material classified. Disclosure, he said, could allow the nation’s enemies to avoid detection and might compromise American intelligence activities. The potential damage is “real and significant, and, quite frankly, beyond debate,” the judge wrote.

...

Jameel Jaffer, director of the National Security Project at the A.C.L.U., said in an interview that he was disappointed. “A federal court’s interpretation of federal law should not be kept secret,” Mr. Jaffer said.

Click here to read the article in its entirety.

Wednesday, December 12, 2007

Ad-targeting system monitors your interests with ISP's help

The whole Facebook controvery over the past few weeks has highlighted the larger issue of internet privacy, and the role of advertiser targeting techniques.

A new product has been created to improve on Web sites' practice of dropping tiny tracking files known as cookies on visitors' computers. When those cookies indicate enough about a Web surfer's interests, related ads can be made to appear.

So, what are some of the privacy pro's and con's with this new technology? As you may have guessed, from a privacy perspective, it again comes down to the all important difference between "opt-in" or "opt-out". And to no ones surprise, industry wants to keep it as it is..."opt-out".

The Mercury News Silicon Valley reports:

...the fact that you visited a site doesn't say as much about your interests as knowing what you did there and afterward. Did you read several articles or quit halfway through one? Did you leave the site to research the topic further on a search engine?

To glean those deeper insights, NebuAd installs equipment inside the facilities of Internet service providers (ISPs), which see everything their customers do online. NebuAd's boxes examine many of the sites people visit, what they do there and what they hunt for on search engines.

...

Aspects of NebuAd's technique are already in play. For example, besides cookies, many online retailers deploy "clickstream analysis" tools that monitor what customers do on a given site - what they browse, what they read, which items they put in their shopping carts but fail to buy. As a much wider-ranging eye in the sky, NebuAd could pique more worries about privacy.

...Pam Dixon, director of the World Privacy Forum, said NebuAd should instead use an opt-in mechanism - automatically excluding anyone who doesn't sign up. She said even if a marketing profile is anonymous, someone might be able to tie it to an individual Web user, if its details were as richly detailed as NebuAd indicates.

"For this particular business model ... it's got to be opt-in, because people's expectation of privacy is that this isn't happening," Dixon said. The degree to which this privacy equation has been managed will likely be key for NebuAd.

Click here to read the article in its entirety.