Showing posts with label online privacy. Show all posts
Showing posts with label online privacy. Show all posts

Thursday, July 03, 2014

Facebook, Secret Experiments and the Belmont Report

Facebook is eating some crow. Again.

Most OOTJ readers will have read about Facebook's data scientist, Adam D.I. Kramer and two academic partner running an experiment using Facebook users. The results were published in the Proceedings of the National Academy of Sciences, (PNAS), "Experimental evidence of massive-scale emotional contagion through social networks." But what got people riled was the inflammatory language used in the abstract and press releases:
We show, via a massive (N = 689,003) experiment on Facebook, that emotional states can be transferred to others via emotional contagion, leading people to experience the same emotions without their awareness.
People reacted with outrage, feeling that Facebook had (once again!) abused their membership in that social media giant. They did NOT like being manipulated without their knowledge. The experiment was really fairly benign, with a tweak to the algorithm showing a selection of users more positive newsfeed content, and others reduced positive newsfeed content. The experimenters then monitored the types of posts the various users made and judged whether they became more positive or more negative.

The woman who edited the paper for the PNAS, Susan Fiske, has been quoted as finding the experiment creepy and troubling. She did interview the researchers and found that they had cleared the experiment with an Institutional Review Board. Institutional Review Boards (IRBs) are mandated by several federal agencies for any organization carrying out research on human subjects. The Food and Drug Administration (FDA) and Health and Human Services' Office for Human Research Protections (HHS' OHRP) are the two main agencies, and CFR main sections are 21 CFR Part 56 (FDA regulations on Institutional Review Boards), and 45 CFR Part 46 (the Common Core or Common Rule, from ORHP) are the most important and useful regulations.

The impetus for the development of IRBs and the protection of human research subjects was a series of high profile, cruel medical research projects through the 20th century that shocked the conscience of the nation. The Belmont Report was the crystallization of a series of meetings by a group of physicians, scientists, ethicists, lawyers and lay leaders on the problem of how to protect human subjects of all types of research in the future. It is the basis for all future regulations and for decision-making by IRBs, who are supposed to keep the interests of the research subjects at the center of their deliberations, while balancing the interests of researchers. There is also some thought for the interests of the organization they represent as well. But three principles are supposed to be the primary concern of the IRB:

1. Respect for Persons (requires the researcher to both acknowledge the individual as an autonomous person AND to protect individuals who may be diminished in their autonomous capacity)
2. Beneficence (will the research benefit the research subject?)
3. Justice (who bears the burdens of the research and receives the benefits?)

The IRB then looks at three main issues in the proposed research:

1. Informed Consent (This may be waived in very narrow circumstances: The principle of Respect for Persons requires in most cases that research subjects know what is being proposed to be done to them and have a chance to voluntarily choose to participate or withdraw with no consequences. 45 CFR Part 46.116 lays out the basic requirements for Informed Consent. More on waiver below.)
2. Assessment of Risk and Benefits (The principle of Beneficence requires that the research balance the risks to subjects against the potential benefits, either to the subjects or generally.)
3. Selection of Subjects (The principle of Justice requires that the selection of subjects for the research be done equitably, so that, for instance, not all research ends up being done on poor subjects unless there is a reason related to the topic of research.)

Waiver of Informed Consent

45 CFR Part 45.115 (d) allows IRBs to approve research with consent procedures that alter or waive some or all of the general requirements if they find:
(1) The research involves no more than minimal risk to the subjects;

(2) The waiver or alteration will not adversely affect the rights and welfare of the subjects;

(3) The research could not practicably be carried out without the waiver or alteration; and

(4) Whenever appropriate, the subjects will be provided with additional pertinent information after participation.
This was probably the provision under which the IRB approved the waiver, although the response of Facebook to user outrage is that users had consented to the research by clicking the "agree" when they signed up for their accounts. I do not think such click amounts to any such consent for IRB informed consent purposes, and it certainly has not mollified any outraged users. Kramer has said that the research was undertaken because they wanted to test "the common worry that seeing friends post positive comments causes people to feel left out or negative, or that seeing too many negative posts might stop them from using the site." Yet people felt manipulated and that their trust was violated. The research probably does meet IRB/Belmont standards, but the reporting of the research was done in a ham-handed and inflammatory style that left Facebook users feeling used and disrespected. Ideally, after a secret or deceptive research project, subjects are supposed to be informed about the research, in a way that helps them, not makes them feel used or deceived. This is the Respect for Persons principle.

This is not the first time that Facebook has manipulated and experimented with its users. In September, 2012, Facebook reported on an experiment that boosted voter turnout in a mid-term election. They divided users 18 and older into three groups.
About 611,000 users (1%) received an 'informational message' at the top of their news feeds, which encouraged them to vote, provided a link to information on local polling places and included a clickable 'I voted' button and a counter of Facebook users who had clicked it. About 60 million users (98%) received a 'social message', which included the same elements but also showed the profile pictures of up to six randomly selected Facebook friends who had clicked the 'I voted' button. The remaining 1% of users were assigned to a control group that received no message.

The researchers then compared the groups' online behaviours, and matched 6.3 million users with publicly available voting records to see which group was actually most likely to vote in real life.

The results showed that those who got the informational message voted at the same rate as those who saw no message at all. But those who saw the social message were 2% more likely to click the 'I voted' button and 0.3% more likely to seek information about a polling place than those who received the informational message, and 0.4% more likely to head to the polls than either other group.

The social message, the researchers estimate, directly increased turnout by about 60,000 votes. But a further 280,000 people were indirectly nudged to the polls by seeing messages in their news feeds, for example, telling them that their friends had clicked the 'I voted' button. “The online social network helps to quadruple the effect of the message,” says [James] Fowler, [political scientist, University of California, San Diego].
(from online journal Nature, doi:10.1038/nature.2012.11401, link above). The report notes that only close real-world friends had the effect of increasing voting activity. The researchers also used real world voting data to check for those who simply clicked the "I voted" button, but didn't vote. This research did not cause the backlash that the recent experiment did. It did not seem as manipulative to people, or as deceptive. There are a few comments in media considering what would happen if a social media giant were to decide to use such tactics to nudge an election to one side or another, as opposed to simply increasing voting generally, or how it could impact elections just by increasing voter turnout. (New York Times sort of mention Sept., 2012, and Comment from Hiawatha Bray in Boston Globe July 3, 2014, bringing the old research up in new context of the new one).

Saturday, May 24, 2014

Facebook Privacy Check-up

The New York Times reported the other day that Facebook is offering a "privacy check-up" to subscribers. Apparently the growth of privacy-friendly services such as SnapChat and WhatsApp has caught the attention of Mr. Zuckerberg. Facebook is acquiring WhatsApp this year, according to the Times article. But Snapchat has a strong privacy policy, where they delete "snaps" from their servers and from users' devices once viewed. Snapchat allows users to more easily control what information the service collects and to control with whom they share information on the site (read the privacy policy).

WhatsApp, a "cross-platform mobile messaging app which allows you to exchange messages without having to pay for SMS," does not fund its service through advertisements that depend on user information. (Read "Why we don't sell ads"). It appears to be free for the first year (at least on the versions I checked), and then 99 cents a year thereafter. WhatsApp's privacy policy is contained in their "legal" or Terms of Service. It appears at the bottom of the page. They make the information clear, easy to understand, and easy to control. They also take some pretty good steps to secure the information users do send them against hacking. The policy includes a warning "in the event of merger, sale or bankruptcy" that the policy may change.

However, the Times article makes it sound as though Zuckerberg is seeing some financial benefit in making it easier for users to control the ways his company/companies collect and use their personal information. Both because European laws regulate this much more closely than the U.S. and because consumer pressure is building for more consumer control in this area, the article makes it sound as though Facebook and Zuckerberg are becoming privacy converts. Time will tell if they stay converted!

The image decorating this blog post is the WhatsApp logo from their home page.

Tuesday, March 11, 2014

Edward Snowden at SXSW calls on the tech community to add a technical solution to NSA surveillance


Edward Snowden, who leaked large amounts of data about the U.S. surveillance programs he had worked on, spoke at South By Southwest (now SXSW), with two ACLU staffers, Ben Wizner and Christopher Soghoian. The video is posted a number of places in full, but it's rather horrible to try to watch. Every time Snowden speaks, the audio starts to echo back on itself after a few moments, probably as a result of the wonky connection they cobbled together. The presenter jokes at the start that he is appearing "through seven proxies," but that is a joke, and part of the apology for the poor quality of the connection. "Good luck, I'm behind seven proxies" is an internet meme referring to protecting one's location/identity from being traced. (I warn you that it's really painful to watch the video & try to listen!)

The easier way to follow what Snowden spoke about, and the interesting questions that followed, is to read about it in the press reports. See Washington Post, which offers edited snippets of the Snowden video, CNN (nice details, especially on the questions), and the Guardian, which has a really excellent in-depth detailed report, plus links to all their previous coverage on Snowden, which is just great, from the beginning.

Sunday, February 16, 2014

NSA involved in spying on attorney-client communications: What do we do now?

My fabulous colleague, Andy Perlman, was quoted in the article that ran yesterday in the New York Times, as well as in today's Boston Globe. Apparently the Australian government security counterpart, the Australian Signals Directorate, was monitoring communications between the Indonesian government and the American law firm they had hired to advise them on trade relations. The Mayer Brown firm, home-base in Chicago, was advising on several import issues that came up in trade negotiations with the U.S. government, including clove and menthol cigarettes and shrimp. Mayer Brown was not identified in any of the communications, but, the article authors conclude that it is likely to be that firm, because of the timing and the client.

The Australians contacted their counterparts at the NSA, according to documents that surfaced in the materials released by Edward Snowden. They alerted them to possible problems with “information covered by attorney-client privilege may be included” in the surveillance. The Australian agency reported in a monthly bulletin that liaison officers asked the NSA for guidance on the matter and received "clear guidance." They noted their agency “has been able to continue to cover the talks, providing highly useful intelligence for interested US customers.”

This is especially interesting because lawyers have been increasingly concerned about computer, e-mail and telephone privacy issues (both government surveillance, but perhaps more commonly, hacking). They have recently rewritten the ABA Rule of Professional Conduct regarding Client-Lawyer Relationship, Rule 1.6, Confidentiality of Information. Subsection (c) now states:
A lawyer shall make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client.
Suffolk's Andy Perlman was involved in redrafting this provision, and is quite aware of the difficulties for modern lawyers in a technologically complex world.

The article in the Times discusses the recent Supreme Court decision, Clapper v. Amnesty International, 568 U.S. ___ (2013). The case, (see nice link here to SCOTUS Blog which includes the petition, all briefs and the procedural steps) was decided along ideological lines, with Justice Kennedy providing the swing vote and Justice Alito writing the majority opinion. Justice Breyer wrote a dissent in which Justices Ginsburg, Kagan and Sotomayor joined. The case turned on the question of whether the petitioners had standing. The majority felt that, since the petitioners could not prove that there was or would be any surveillance of themselves, in particular, they failed to show standing on that count. There was an alternative argument put forth by the petitioners that they could show they were suffering injuries through the concern they felt at the prospect of surveillance and through their efforts to protect their clients' interests in case they were being surveilled. This argument did not sway the majority either. If you think about it, though, how would a target of FISA Court-authorized surveillance ever be aware for sure that there was any surveillance or authorization for it? The whole point is that it's secret!

So it is of interest and some irony that the document from the trove released by Edward Snowden showed up now, proving that at least some foreign clients of American attorneys are, indeed, subject to surveillance, if not directly by the NSA, then with their knowledge and advice.

Many techie lawyers may already be miles ahead of this on the security front. But I talked with my tech consultant and have a couple of FREE security add-ons. First you might want a...

Brief Primer on Security Basics
The key to better security is to have 2 different pieces that guard your access or privacy. There are 3 ways to secure this access or privacy:
1. Who you are (biometrics)- your fingerprint, retinal scan, face or voice recognition sort of identification. This is not really feasible for most regular folks at this point.

2. What you know - your password

3. What you have - your cell phone or key fob or other security device.

You may already be using two factor security (also known as two step verification, which is Google's name for it). If you use a Google product like Blogger or Gmail, or Google Circles, you have undoubtedly been prompted to not only register a password, but also to give them your cell phone number. That cell number is not just their way to contact you if you lose the e-mail password. It is also a way they can verify that you are the real owner of the account. You may have lost the password, but you will still have the cell phone registered as belonging to the account owner. That way, Google is OK with sending you the new password - they know they have the right person!

Your ATM card is another example of a two factor security system. You must have the card, but you also need the pin number. Having one without the other, a thief still cannot access your account. This is an example that lets you see how the security system ideally works. By requiring two separate identifying verifications, from 2 different types of the three options, you increase the security level greatly. It's much less easy for a thief to steal both the card and the pin number unless you write the number on a sticky note and keep it with the card. That's the last part -- keep the verification items separately and securely.

Lawyers should also be aware of the very recently released CyberSecurity Framework from the National Institute of Standards and Technology. About a year ago, President Obama issued Executive Order no. 13636, Improving Critical Infrastructure Cybersecurity, DCPD-201300091, February 12,2013. The Framework was released on Feb. 12, 2014, and declares itself to be a living document that will be updated and amended in response to industry feedback on voluntary implementation. Silicon Valley type industries have been highly critical of the President's stance on the NSA and FISA embroglio, which is costing large social media and telecom companies thousands or millions of dollars in compliance with secret orders. But they seem, according to reports, fairly pleased with the new Framework, which is voluntary but is built to align with enlightened self-interest.


1. Encryption software (a quick answer to surveillance concerns?)
a. PGP (Pretty Good Privacy)
This was first introduced by Phil Zimmermann in 1991, according to the Open PGP Alliance, and several other sources as well. According to Zimmerman's homepage, he first designed PGP as a human rights tool, and that is why it was released free on Usenet. It's a sad and ironic commentary that the U.S. government then began a criminal investigation against Mr. Zimmerman for allegedly violating export restrictions on cryptographic software when PGP spread worldwide through the proto-Internet. The criminal charges were eventually dropped after three years.

PGP is still available for free. Here is a list of links to download it in various versions and to get patches. Here is a helpful tutorial and information page from University of Pittsburg at Johnstown. Not easy reading, but it is chock-full of information using the private and public keys to create a two-factor verification process between you and the person you are communicating with. If you encrypt your message, the guy at the other end needs a key to decode it, right? But how to get it there, without being intercepted? It's an ingenious system and has no backdoor. The system also allows you to use your encryption key as a digital signature, which is an interesting feature.

Back when Phil Zimmerman developed PGP originally, in the early 1990's, Linux was just a toy O.S. known only to a few geeky operating system managers. So, PGP was naturally written with Windows and (later I think) Mac (or here) in mind. Now it is being developed into Open PGP and is an open source collaborative coding project and supports all sorts of operating systems, including Blackberry, Android and other mobile O.S. See, for instance, Open PGP Ruby and the Wikipedia article which nicely pulls together a list of the supported systems. Still distributed free, PGP is probably the most widely used encryption standard in the world (per the Open PGP Ruby intro).

b. GPG (GNU Privacy Guard)
This was developed originally by German citizen Werner Koch, then by the GNU Project, which developed the GNU/Linux operating system. The standard is obviously built to support Linux and GNU/Linux systems. GPG can also support Windows, Mac, Android and many other operating systems.


... Should U.S. citizens have access to technology that permits private communication? And ultimately, do U.S. citizens have the right to communicate in absolute privacy?

There are forces at work that will, if unresisted, take from us our liberties. There always will be. But at least in the United States, our rights are not so much stolen from us as they are simply lost by us. The price of freedom is not only vigilance but also participation. ...
From statement by Phil Dubois, lead defense lawyer for Phil Zimmerman in the announcement of the government's dropping of criminal charges, dated Jan. 11, 1996.

Monday, February 10, 2014

Just say NO to continued government surveillance!

Call/email Congress. Ask legislators to oppose the FISA Improvements Act. Look here at the ACLU comments, here at the EFF comments on "fake fix bill", another EFF note on 54 civil liberties and public interest organizations opposing this bill and here for an analysis in the British paper The Guardian (Permanent loophole for "backdoor search provision," and the Cato Institute, which called it the NSA Fig Leaf.

Ask your congresspeople to support the USA Freedom Act, and enact protections for non-Americans. Read the ACLU comments supporting this alternative bill. The EFF also supports this bill, which was co-sponsored by Representative Sensenbrenner (R, Wis) and Senator Leahy (D, Ver).

There are limits to what the USA Freedom Act accomplishes, according to the EFF website:

The bill only addresses a small portion of the problems created by NSA spying and overreaching government secrecy. It does not touch problems like NSA programs to sabotage encryption standards, it does not effectively tackle the issue of collecting information on people outside of the United States, and it doesn't address the authority that the government is supposedly using to tap the data links between service provider data centers, such as those owned by Google and Yahoo.

The bill also does not address a key issue that the government uses to inhibit lawsuits contesting the spying: excessive secrecy. For instance, it won't deal with the major over-classification issues or the state secrets privilege, the latter of which is used aggressively to prevent litigation from getting to a court decision on whether the spying is unconstitutional. The bill also leaves out a clause appearing in Sen. Ron Wyden's bill [113 S. 1551 Intelligence Oversight and Surveillance Reform Act] and, which provides guidelines to obtain standing in legal cases against the spying.

Lastly, it does not hold public officials accountable for their role in allowing this spying to take place and hiding it from public and Congressional oversight, and it does not create a Congressional committee that could independently investigate the surveillance programs and give the country a full accounting. Remember we are still just learning the full depth of the programs on a piecemeal basis.

So while we are happy to support the USA FREEDOM Act, we also acknowledge that there is still much to do to dial back the NSA. This can happen through ongoing improvements to the USA FREEDOM Act as well as through additional bills.
The EFF does list 7 steps the USA Freedom Act uses to improve privacy rights:
1. It would likely stop the NSA's call records program;
2. The bill modifies Section 702 of the FISA Amendments Act (EFF thinks one effect of the amendment is good - it requires the NSA to get a more narrowly tailored order from the FISA court before searching its enormous databases of call data for information on U.S. citizens. However, EFF is concerned that the amendment codifies the practices and existence of the collection and databases rather than abolishing them.
3. The bill creates a special advocate before the FISA court.
4. "Significant decisions" by the FISA court must be disclosed by the Attorney General. This is hugely important, though the FISA court itself has increased the publication of some of its decisions in recent days, there is neither any confidence that it might continue nor anything to show the public that we have had publication of either the most significant decisions or any proportion of significant decisions.
5. It increases protections designed to limit the potential harm from the use of National Security Letters (NSLs, the secret orders from the FBI that include a gag order preventing recipients from ever announcing they got one). Nevertheless, the law fails to address the central problem with NSLs: NSLs would still be unconstitutional.
6. Increases (a tiny bit) the ability of the companies that are ordered to cooperate with government agencies to be more transparent to users about their cooperation. There would still be gag orders limiting the amount of information that could be shared, but reports could be somewhat more detailed.
7. It grants subpoena powers for the Privacy and Civil Liberties Oversight Board (PCLOB). PCLOB is supposed to provide oversight and recommendations to the executive branch when it comes to our civil liberties, but currently has no subpoena powers.


Fight for the Future coordinates an Internet Fight against NSA Surveillance


Who here has gotten the e-mail from Fight for the Future? FFtF is a not for profit that
is dedicated to protecting and expanding the Internet's transformative power in our lives by creating civic campaigns that are engaging for millions of people. Alongside internet users everywhere we beat back attempts to limit our basic rights and freedoms, and empower people to demand technology (and policy) that serves their interests.
Well, they don't have any problem with self esteem, anyway. Their issues, from their About Us page, listed as posing "major threats to freedom of expression online":

Copyright and patent laws are outdated and overzealous. They hurt artists and innovation, shifting control of our art, media, and ideas to large corporations.
Slow speed and limited access: Lack of competition in the U.S. broadband market has resulted in an Internet system that is among the slowest, most expensive and least available among developed nations.
Tracking and Spying: People can’t express themselves freely online when they feel like they are being watched. In an extreme form, government and corporate surveillance can lead to political repression.
On Feb. 11, they are urging websites to add a banner to their sites
urging people to call/email Congress. We'll ask legislators to oppose the FISA Improvements Act, support the USA Freedom Act, and enact protections for non-Americans.

If you're not in the US: Visitors will be asked to urge appropriate targets to institute privacy protections.
Visit their website to see.

I have mixed feelings about the breadth of their issues. But I do know what I think about the NSA and FISA courts.

Saturday, September 21, 2013

Stewardship, and Our Responsibility to Future Generations



I just read Roy Balleste's excellent post at Circle ID blog, Privacy and the Future: Are We Good Trustees of the Internet? He speaks eloquently about the need to safeguard against the government encroachment on privacy online.  But something about the post makes me think about a conversation I had weeks ago with my 23 year old daughter.

I was talking about the revelations of the NSA and DEA tapping citizen and foreign e-mails, phone conversations, and building or accessing huge databases of both types of traffic. I was just amazed and dismayed when my daughter's reaction was, "DUH! We always assumed they were listening. What are you upset about?"

It is one thing to be cynical about your government.  (and sneer at your parents regarding technology)  It is something else entirely to cede your Fourth Amendment rights without a blink. 

Once you give up Constitutional rights, I think you probably will have to shed blood to get them back. Just like the Minuteman decorating this blog post. Frederick Douglass told us, "Power concedes nothing without a demand. It never has and it never will."

The image is the The Minute Man, a statue by Daniel Chester French erected in 1875 in Concord, Massachusetts. The photo was originally at the National Park Service page,  http://www.nps.gov/mima/education.htm, which now is a 404 message. The image is on Wikimedia Commons.

Saturday, September 07, 2013

NSA and British counterpart cracking Internet codes


The Guardian, in partnership with The New York Times and ProPublica.org,reports on how the National Security Agency (NSA) and its British counterpart, the Government Communications Headquarters (GCHQ) have successfully cracked much of the code that people rely on to guard security across the Internet.   The NSA has been working for 10 years, concentrating on eliminating encryption algorithms as a possible source of security risks to the country.  In 2010, they made a breakthrough with allowed them to "exploit" vast amounts of Internet traffic which previously was inaccessible.  And now, both the NSA and the GCHQ are working in some collaboration with Yahoo, Google, Hotmail and Facebook to build "backdoors" to these systems and insert exploitable vulnerabilities into their encrypted traffic. From the Guardian article:

The agencies insist that the ability to defeat encryption is vital to their core missions of counter-terrorism and foreign intelligence gathering.

But security experts accused them of attacking the internet itself and the privacy of all users. "Cryptography forms the basis for trust online," said Bruce Schneier, an encryption specialist and fellow at Harvard's Berkman Center for Internet and Society. "By deliberately undermining online security in a short-sighted effort to eavesdrop, the NSA is undermining the very fabric of the internet." Classified briefings between the agencies celebrate their success at "defeating network security and privacy".

Chillingly, the documents from the NSA refer to the regular customers of the commercial systems such as Google or Facebook as "adversaries" and seeks to make the exploitable vulnerabilities in the system invisible to such persons. The NSA lists a number of goals in the document, several of which it has achieved. For instance, it has successfully introduced major weaknesses into international standards for encryption systems. The NSA continues to "shape" the worldwide marketplace, and attempts to make commercial encryption software 'more tractable" to NSA attacks.  They continue to try to break the encryption for 4G phones. The funding for the program, more than $250 million, dwarfs Prism, which looks like a bargain at $20 million. They have not yet cracked all encryption, and have not yet subverted all of the Internet.

The other danger is that by building in backdoors, the NSA and GCHQ are opening the door to others who may gain entrance besides themselves.  From the Guardian article:

"Backdoors are fundamentally in conflict with good security," said Christopher Soghoian, principal technologist and senior policy analyst at the American Civil Liberties Union. "Backdoors expose all users of a backdoored system, not just intelligence agency targets, to heightened risk of data compromise." This is because the insertion of backdoors in a software product, particularly those that can be used to obtain unencrypted user communications or data, significantly increases the difficulty of designing a secure product."

Read the 3 articles in depth.  They overlap a good deal, but are somewhat different from each other.


Tuesday, September 03, 2013

More on US government data gathering: Project Hemisphere, Spying on Brazil & Mexico


Well, just as President Obama is asking the Congress to grant him extraordinary powers to attack Syria, a couple more stories are popping up about extensive data gathering or spying by the United States. 

Brazil and Mexico are both summoning U.S. ambassadors to discuss how their sovereignty has been violated by spying. This is more fallout from the revelations of Edward Snowden about National Security Agency (NSA) activities.

And, more disturbing to U.S. citizens, Drug Enforcement Administration (DEA) agents appear to have had access for six years to a database of telephone calls that dwarfs that used by the NSA.  The New York Times reported on the Hemisphere Project, where employees of AT&T were actually embedded with the DEA and would thus be available on short notice to use the AT&T database as soon as a subpoena was received. The database was owned and housed by AT&T, and not accessed directly by the government agents, which raises interesting questions under the Fourth Amendment for Search and Seizure afficionados. 

But the DEA agents had access to far more data than the NSA agents through the Hemisphere Project. The database includes every phone call that passed through an AT&T switch for the past 26 years, not just AT&T customers.  That is a huge swath of the telephone calls made in the world, and certainly across the North American continent.  The metadata includes the city and state of the caller, and is aimed largely at trying to identify and track the cell phones that criminals buy, discard and replace to avoid tracking by law enforcement.  

The database was actually available to other agencies besides the DEA, and was also largely used by Homeland security, and to a lesser extent by the FBI and several agencies in Washington state.  A portion of the PowerPoint slide show that was released, eventually, to the New York Times (probably accidentally), discusses the importance of protecting the program from discovery.  Project Hemisphere is not classified, but is "law enforcement sensitive."

While the slides show several success stories about arrests enabled by Project Hemisphere, we should ask at what price these arrests are coming.  How much access to records, to privacy, are we willing to cede to government officials?  In an era of increasing digital collection, we should consider, as a society, where we stand on the search and seizure, Fourth Amendment rights enshrined in a different age.

Thursday, August 15, 2013

Privacy and free browsers and e-mail providers

I've been reflecting on the Google case.  Anybody who thinks about the matter should conclude pretty quickly that you have to "pay" for the browser and e-mail some how or other.  And in the case of Google, you are paying by letting them suss out for their 3rd party advertisers what your interests are likely to be.  So Google wants to check your browsing habits to see what sites you are visiting.

Anybody who has looked up a question and suddenly noticed ads on the side bar that mirror the question matter has seen the results of the Google snooping ability.  This is especially weird for librarians, who are often looking up things we have no personal interest in. 

The same is apparently happening when you use their "free" Gmail e-mail service.  Again, they never announced this was the program, but I think a lot of users sort of figured there had to be some quid pro quo involved, and it had to do with the ads that make Google so rich.  The thing that is most unnerving about the revelations about Gmail is the depth of the "scanning." 

Alert readers may notice that the Blogger system on which this little blog appears is also powered by good ol' Google.  Can't say I'm feeling totally comfortable right now.  But I'm relying on the essential boring nature of my communications. 

Librarian camouflage?


The camouflage wedding dress above (wow!), is courtesy of a temporarily unavailable website, http://plus.simplyformal.com/media/catalog/product/cache/7/small_image/5e06319eda06f020e43594a9c230972d/t/9/t9050_s8892_mossy_fullview_001_3.jpg

Stunning Google Admission in Court on Gmail Lack of Privacy

The Guardian reports on a stunning admission Google makes in a court document about the lack of privacy for users of the Gmail system.  ConsumerWatchdog.org filed a class action law suit, In re Google Inc. Gmail Litigation, Case No. 5:13-md-02430-LHK, which will be held before Judge Lucy H. Koh in U.S. District Court in San Jose, CA. at 1:30 p.m., Sept. 5. The complaint was sealed since it involved business practices, but a highly redacted version was filed publicly, and can be found here. And THIS is the Google motion to dismiss that is the source of the Guardian excited report.  The first argument is titled: 

"The Wiretapping Claims Fail Because

the Alleged Scanning Practices Are
Part of Google’s Ordinary Course
of Business as an ECS Provider"

I'd say that's pretty chilling stuff. Google says, "You can't sue us for cooperating with the NSA wiretapping because we already listen in to all your e-mail conversations as a matter of our business practices!

OK. That makes it all alright.  You go, guys.  Don't be evil.  

Tuesday, July 30, 2013

Online Privacy Under Seige



Meanwhile, the struggle is underway over the federal government's (and others!) widespread snooping activities, as uncovered by Edward Snowden.  It turns out that France and England, at least also had major programs for gathering and sifting e-mails, telephone and social media data. 

So, despite the fact that Congress had authorized the Foreign Intelligence Surveillance Act (FISA) (Pub.L. 95–511, 92 Stat. 1783, 50 U.S.C. ch. 36), many Congressmen, including some who sponsored FISA and the USA PATRIOT ACT in the first place, are now arguing over how to amend the Act, change the court that issues warrants under the Act, and arguing with the Executive branch over what they intended with the laws they passed.

The ACLU has filed with the FISA Court a brief arguing for a public release of the court's records.  Fifteen members of Congress have filed an amicus brief in support of the ACLU's position. 

Here is a handy list of important actions involving FISA, the FISA courts from the Federation of American Scientists.

Atlantic article on how rarely FISA court orders are challenged.

Commentary on some of the proposals in Congress to "modernize" FISA from the Center for Democracy and Technology.

Blog at EPIC.org on FISA courts.

EFF.org on FISA

The decoration if from the movie, 1984, with an image of Big Brother.

Protecting privacy as a human right in the digital world -- Roy Balleste

Our colleague Roy Balleste has a great blog post at the always interesting Circleid blog discussing the importance of privacy in the Internet world -- he cites the Universal Declaration of Human Rights as a source document, in asserting that we must continue to protect individuals' personal information in our increasingly digital world, even in the face of "security interests."  You rock, Roy!

Tuesday, July 09, 2013

Dept. of Unintended Consequences: COPPA

Children's Online Privacy Protection Act (COPPA, 15 USC §6501 - 6506, PL 105-277)
regulations from the FTC are just going into effect.  The Internet is going to be changing, both for those under 13, and for the website/app providers who deal with them.  COPPA.org offers a website explaining in some detail how to comply with the new regulations. According to the explanation provided there, the Act applies to any
commercial Web site or an online service directed to children under 13 that collects personal information from children or if you operate a general audience Web site and have actual knowledge that you are collecting personal information from children, ...
The COPPA.org website goes on to explain the factors the FTC considers in deciding whether a website or app is directed to children, who is an "operator" and what amounts to personal information.   Then, the COPPA.org folks lay out the requirements of the Act and regulations as cleanly as possible.  This also provides the full text of the Act.

Sadly, despite the efforts to make the Act's requirements seem less overwhelming, it appears that many smaller businesses operating on the Internet or with online services that either cater to children or to a general population that attracts the under-13 crowd, will be completely changing their business model in response.  AdWeek reports that already AOL Kids has stopped working, and at least one academic consultant is recommending smaller businesses simply change their websites to avoid being covered by the Act.   Some foresee that the final result will be less innovation on the Internet.  I hope they are wrong!  I am sure that is not what the FTC or Congress intended.  But many businesses seem quite shy of the new regs.

Wednesday, July 03, 2013

Metadata of your e-mail


An interesting interview in Sunday, June 30 Boston Globe's Ideas Section with César Hidalgo, a professor at MIT's Media Lab.  He is leading a fascinating project that invites volunteers with Gmail accounts to use their Immersion tool to analyze the patterns of the metadata in their account.  It creates a "people-centric" portrait of the networks in your e-mail life, and how thickly interconnected they are with one another.  The data remains completely within the volunteer's  control.  There are several key points the Professor Hidalgo makes in the interview: 
You're seeing all of your network and you're seeing yourself out of it and you're seeing it from afar and you're seeing it in one picture.

You start realizing that, eventually, you are not interacting with people -- you're interacting with webs of people. Because all the people you've interacted with, they're actually connected in tens or maybe hundreds of indirect paths between them.  They exist in your absence. So that out-of-body experience, I've found that it was very powerful.  ....

Q: Are there ethical or political lessons about metadata that Immersion teaches?

Hidalgo: ... if you're going to make platforms that deal with personal data, you have to develop ways of doing this in such a way that you can be transparent with the user about the data you have, about how you're handling it, and about how the user can withdraw the data from your system. 

The image decorating this is not from Immersion, but is a similar sort of graphic, derived from an analysis of a social media network, from http://fastballgirl.wordpress.com/2012/10/08/segmentation-using-gephi/ .   In this case, the person analyzed her own Facebook network.  I will warn my readers that following the Globe article, Immersion is experiencing very heavy traffic and will take your e-mail address to be notified when they have the ability to take more users. I was hoping to tell you about my own experience, but was not fast enough myself!

Fourth of July Protests Against NSA


Happy Fourth of July! Celebrate our freedoms, and contemplate what it takes to maintain them. 

The Boston Globe reports that two groups of web activists are planning protests against the NSA around the Fourth of July. The protests combine web protests with some live protests in selected cities across the country. 

One group is Fight for the Future, which helped coordinate the rallies against SOPA and PIPA last year.  The other group is Restore the Fourth, which is a reference to the Fourth Amendment, not the holiday.

Look for websites to carry messages, and the text of the 4th Amendment.  If you care to join a local rally, Fight for the Future may have information, though I don't see notes there. The closest I find is their page on the NSA cybersecurity program and opposition to Senate bill 2105, the Cybersecurity Act of 2012.  The bill failed to move to a full vote. That link will also provide a handy analysis and history of the bill and those who supported and opposed it. It is a scary sounding piece of legislation, in my opinion, especially in the wake of Snowden's revelations of how much data the NSA is already gathering.

Saturday, June 08, 2013

First BeenVerified, Now NSA, FBI, and the rest of the Feds... do you feel a bit surveilled?


The news broke in just the last day or two, about the large tech companies and telecommunications companies reluctantly acceding to government requests for vast amounts of user data.  The Boston Globe ran a nice report that summarizes the history of the group of programs involved in the news. It's an even-handed article that quotes from President Obama's comments about the need for balance if we want to catch terrorists while trying to protect civil liberties. It also quotes from Mark Rumold, a staff lawyer at the Electronic Frontier Foundation criticizing the extent of the surveillance programs.  (See order from a Foreign Intelligence Surveillance Court requiring Verizon to turn over telephone data acquired by the British Guardian; not clear how they got this since it's marked Top Secret do not declassify until 12 April 2038.)

The Globe article, "What Surveillance Can Uncover About You," (available in print at A1, A7, by Matt Viser, Noah Bierman and Bryan Bender) includes a Surveillance programs fact sheet (A7 in print), that does a very nice job of listing in a general way, what data the government collects under two different programs from the various major players.

From telephone conversations, without a warrant, from U.S. citizens, agencies collect metadata only, not the actual content of the conversations.  The metadata reveal information on:
beginning and end times and thus the length of the call;
place of origin of the call, and place of the receiver;
serial number of the phone placing the call;
phone number of the placing and receiving call;

However, there is a second, top-secret data-gathering program, PRISM, by US and British intelligence on which the British Guardian and the Washington Post, published a slide show provided them by the National Security Agency (NSA). The Post edited and annotated their slides, which is what I have linked here. The Post also provides an article about Prism. According to the material appearing at the Guardian and the Post, with the aid of NSA, the British analogous agency, Government Communications Headquarters (GCHQ), has been sieving the same U.S. tech company data as the NSA in the same ways. This has allowed GCHQ to evade the British laws requiring legal process to acquire photographs, e-mails and videos outside of the country.  From the Post's article:
PRISM was launched from the ashes of President George W. Bush’s secret program of warrantless domestic surveillance in 2007, after news media disclosures, lawsuits and the Foreign Intelligence Surveillance Court forced the president to look for new authority.

Congress obliged with the Protect America Act in 2007 and the FISA Amendments Act of 2008,  which immunized private companies that cooperated voluntarily with U.S. intelligence collection. PRISM recruited its first partner, Microsoft, and began six years of rapidly growing data collection beneath the surface of a roiling national debate on surveillance and privacy. Late last year, when critics in Congress sought changes in the FISA Amendments Act, the only lawmakers who knew about PRISM were bound by oaths of office to hold their tongues.

(FISA = Foreign Intelligence Surveillance Act, P.L. 95-511, 92 Stat 1783, 50 U.S.C. Chapter 36 
Protect America Act of 2007 = P.L. 110-55, 121 Stat 552, amending 50 U.S.C. certain sections of Chapter 36
USA PATRIOT ACT = P.L. 107-56, 115 Stat 272, amending MANY U.S.C. sections) The Post includes a separate article with details on how the Foreign Intelligence Surveillance Courts work, including statistics on number of requests and number denied during various administrations since the courts were established in 1979.

The Post web link includes in interesting video interview with the reporter who has done most of the work uncovering PRISM here in the U.S.  Besides stressing that the tech companies involved have all denied any knowledge of PRISM, and that the government has said that PRISM only applies to non-citizens, there are several fascinating parts to the conversation.  One is asking the reporter whether he is concerned about repercussions such as those suffered by the Fox News and AP reporters recently who had materials subpoenaed.  The second is asking about his contact within the NSA and whether this whistle blower is prepared for what will happen when or if he is unmasked.  And thirdly, the interviewer mentions receiving an e-mail that simply says "tip of the iceberg."  The conversation goes from there about the size of the data sets available and how unimaginable this was to them before the story broke.

Two organizations which have long been critical of the government's data gathering:

Electronic Frontier Foundation, which has helpful information, explanations and white papers on their website.

Electronic Privacy Information Center (EPIC)
which also has helpful information, explanations, and links to legal documents on their website. They have explanatory notes, pleadings, rulings, memoranda and briefs in a number of relevant court cases that are still working their way through appeals.  Very helpful.

The American Civil Liberties Union has some links and posts about this issue, but it is one small issue among many for them.

Only a few members of Congress have opposed the relentless expansion of the Executive's power of surveillance.  They have been lonely voices until now.  

The witty decoration for this post comes courtesy of an interesting new citation storage, sharing and organization service, www.CiteLighter.com.

Saturday, June 01, 2013

BeenVerified - How do YOU spell CREEPY?


Apparently BeenVerified.com has been thriving in the shadows of the Web since about 2011, and I just didn't know about it.  You go to the site and it offers a default "people search" of public records, but also lists telephone, address, e-mail and professional contacts searches.  They offer a snappy video explaining the sources of their public records, from the government documents, mortgages, bank documents and forms everybody fills out for social media sites, and to register all sorts of purchases, warranties, and so forth.  They explain that their aim is to aggregate all these privately held, but public documents, which have difficult and expensive to access.  It makes it sound so public-spirited and happy -- partly because of the up-beat music.

But there is a GOOD side to how difficult and expensive it has been to gather all that information about people.  It guards privacy.  Now, with BeenVerified.com, for a low annual or monthly membership fee, you can search as many people as you care to.  Or you can pay a single fee, or a fee to search 2 or 3 individuals.  Your nosy neighbor, in-law, potential employer, child's friend's parent, etc., can search all your "public records."  Background checks....  yes, but who is allowed to do them?!

The website makes a lot of statements that require users to "promise" that they will not mis-use the information they acquire through BeenVerified.  And it's very interesting to contemplate what sort of mess you will have to unravel if the records turn out to have incorrect information.  The agreement you "sign" in the terms and conditions holds BeenVerified harmless.  That clause probably would be interpreted differently in different states.  In Massachusetts, I do not think it would stand up if you suffered a lot of harm due to negligence on the website's part, for instance, in gathering information and linking it to your name. 

Fortunately, you CAN opt out of BeenVerified.  Here is a link.  I was going to actually test BeenVerified by buying a search on my own name, but then I got too paranoid to even give them that much information about myself and to give them my credit card. They do not accept PayPal -- only credit card payments!  So, opt out! 

Librarians may know lots of other spooky ways that gather information on people. There are for-profit commercial databases that are quite high-end.  But there are other, free websites that also are pretty scary.  I used to just have my students in my Advanced Legal Research class Google their own names.  But as the commercial value of this information was recognized, it mostly went behind pay walls of one sort or another.  It was a very sobering class when I did this.  We hand out so much personal information over the course of our lives.  Some of it, we have no choice -- the government requires it of us in order to get our driver's license, or other important documents.  The banks will not lend money without information that makes them feel secure.  But it is very unnerving that it's so accessible now in the wired world, and it angers me that this cheerful little company is selling it.

Sorry.  It's not a public service.  Tip of the  OOTJ hat to Alexa!

Saturday, April 27, 2013

Living Social Hack and AP Twitter Account Hacked


The website, LivingSocial, a daily deals site, was hacked late yesterday.  The original report came from AllThingsD.com, and includes the text of an e-mail the CEO sent to staff and now the public. No credit card data or merchant financial information was accessed, which must mean that they stored them on a separate server.  The cyberattack affected 50 million users (all users except those in Korea, Thailand, Indonesia and the Phillipines, which use different services with separate servers).  The attackers netted millions of user names, birthdates, e-mail and passwords.

The website now greets users with an announcement of the attack, and recommendation that users change their passwords.  The announcement notes that passwords are coded, and the CEO's e-mail says they have been "hashed and salted."  This mean they use an algorithm to code, or "hash" the passwords. Salting means that each user who uses the same password would have their password "hashed" into a different coded version.  However, those with passwords which are too easy may make it easy for the hackers to guess, since the hashing algorithm is known.  Hackers can use an online dictionary and a computer to try to guess multiple passwords in just a few seconds.  But because multiple passwords set to "password" would each have a different hashed version, the hackers will have to devote considerably more time to cracking passwords.

CNN Money Tech reports that a different cyberattack on the Twitter account of the Associated Press.  The hackers in that case planted a false report that President Obama had been injured in two explosions at the White House.   AP suspended their Twitter account, with an announcement that the report was false. However, the attack shows up security weaknesses with Twitter, which had been discussed for some time by security analysts with concern.  Apparently, unlike Facebook and Dropbox, among other sites which offer the option, Twitter does not yet require a "two-step authentication" process.

A two-step authentication, done properly, requires a combination of two out of three types of information:
1.  Who you are (physical ID for instance, or fingerprint scan or facial recognition now on many laptops)
2. What you have (a gadget that generates a code, or a one-time password provided in a list by the website for users, for instance),
3.  What you know (passwords, mother's maiden name for a security question, for example)

For instance, a good two-step authentication procedure might require not only your password, but also an individually created key, which might be stored only on a user's phone. The user sends the secret key along with their password.  A lower tech alternative to the gadget code is the list of passwords provided separately to users. A user would input one of the codes and mark it off the list.  When a user runs low on the number of provided by the website, they request a new list.  As long as the two items are received within a short time (approximately 30 seconds), the system will accept the combination log-in.  The CNN article notes that Twitter had advertised for engineers to develop a two-step security process, but apparently this has not yet been implemented.

Another hack previously compromised Fox News' Twitter account. In that case, the hacked tweet was that President Obama had been assassinated. The recent fake tweet actually caused a brief downturn in the stockmarket. According to the CNN report,  Twitter's response to these and various other hacks on corporate Twitter accounts has been to urge more care.  What they need is to implement better security.

The decoration for this post is from Wikipedia, which notes it was designed in the late 1990's by Dagmar D'Surreal, as a logo for the PhreakNIC annual conference in Nashville, Tennessee. Many thanks to my son, Joe McKenzie, for technical explanations made easy.

Friday, April 12, 2013

Technology to Locate Tax Evaders


I ran across a little Associated Press piece in my local paper about Lithuania using Google Streetview to do searches for people who failed to report upgrades to their property for tax purposes. When I searched for the AP report, I found a piece from Baltic Business  about Estonia following Lithuania's example, published December, 2012. 
Tõnis Kuuse, head of the information department of the Estonian Tax Authority, said ... "It’s an additional information source that we can use to check on real estate, for instance in case when a person who has declared minimum income is living in a very valuable house." 
Kuuse explained that Google Streetview is only one of a number of tools the Tax Authority uses to catch tax scofflaws. Like Lithuania's tax officials, they use the streetview snapshot as the basis to alert them to go in person to look at the real estate.  They have discovered instances of property owners who sell, and report the land as unimproved, sold for a much lower price.  Then they spot a new building on the Google Streetview, go to inspect and prove that the plot sold for a much higher price. It's sort of an investigative tool that gives the inspectors a probable cause to look further at the case.

Similarly, I found a report here about Irish revenue officials using Google Streetview and Google Earth to locate similarly under-reported property taxes and real estate sales.  The same blog post mentions that New York had used Google Earth to locate in-ground swimming pools that had not been reported. A report in 2010 also told of the Greek government using Google Earth to locate tax evaders.  In a similar vein, the Pappas Group reported in 2010 on efforts by the Oklahoma and federal revenue officials to use social websites like Facebook and Twitter to catch tax evaders.

And TechnoBuffalo repeats much of this, but adds that the IRS seems to be planning to check citizens' e-mails for evidence of tax cheating. And it seems they believe they can do so without a warrant to uncover evidence of tax fraud. 

Just in time to make you shiver for tax day.