Sunday, February 3, 2008

RFID: Tag Your Kids For More Efficient Busses… Hu?

The Associated Press is reporting that a Rhode Island town is going to implement a “test” program where they will RFID (Radio Frequency Identification) children’s backpacks to see where they get on and off the bus. They will also use a GPS system to track the busses location. The ACLU of RI is fighting this action as unnecessary. I’ll avoid the obvious question of why they need this at all since they could just GPS the bus and then have the driver record the number of kids that get on the bus without needing to identify each individual student. The school dismisses concerns that others could use this information to track children since they say it is “just a number”. If this sounds familiar, it might be the ghosts of the debates over the Social Security Number program (and we see how that number has remained just a number and not a personal identifier, right?). The push for RFID stalled some time ago over the debacle with Tesco and its hidden tracking of UK shoppers (and Gillette razors at Wal-Mart here in the US). It appears this is back in the news. There is no question that RFID (Radio Frequency Identification) has many uses, but tracking people is one that many folks are rightfully skeptical of (see www.spychips.com). I’ve not covered RFID yet in this blog (I will some time in the future) but there is good reason to be skeptical about technology that makes its carrier remotely traceable if we believe that people should have personal privacy). At least in the US, privacy is a balance; even in the case of the 4th amendment, there are weighing factors that have been used to determine the limits of privacy protections v govt. intrusions. In this case, all I can wonder is who thinks this is an appropriate trade off?

Monday, January 28, 2008

AT&T reborn, Former Death Star now Net Nanny

This is a great article about what AT and T is going to do; monitor every bit of information that goes across its network. Oh sure, we’ve known for a while that they do this for the government, but apparently now they are doing it for the RIAA (recording industry) and MPAA (film industry). If this feels a little strange, maybe it’s because it reverses the idea of innocent until proven guilty (granted that is for govt. and no such principal necessarily applies to private industry). The article does a great job of pointing out that the telecoms pushed for (and got) a protection from liability for providing material (as opposed to what happened to Napster or Grokster) assuming that they had no part in deciding what it was. This would seem to contravene that. This also brings in an interesting question about which is more important as a service provider; serving your customers, or helping another industry. If free enterprise is correct, then this knowledge should mean terrible impacts on AT and T’s financial (as the article predicts). If not, then we have a profound example of user’s naïveté about privacy and control measures that is destined to play itself out with potentially unfortunate consequences in the future (the TIA program’s plant to use letter carriers as agents for the govt. and then later firefighters comes to mind as such things in the govt. sector). As for how the public will react, and if AT and T will suffer any measurable financial impact, only the future will tell.

Sunday, January 13, 2008

Border Seizure: Is All Information Equal?

The New York Times reported that border guards have seized computers and searched hard drives. The auspices of such actions are based around the noble effort to stop the trafficking of child pornography into the country. The reference to two cases (supporting searches, blocking searches) about the same kinds of searches, the concern that I have in such cases is how a line is drawn between different kinds of data. If the government is allowed to take copies of the data on a hard drive, what is to distinguish between medical records or diary entries from child porn or calls to treason? On a hard drive they are all just zeros and ones and there in lies the difference between real and “intellectual” property. Perhaps one solution is technological (like the use of the carnivore (DCS 1000) email reading system that the NSA uses). Another option is to decide which is the more important liberty to our society. If we search all hard drives looking for illegal material and we find no illegal material but we do find information about a crime that was committed but unprosecuted, should the govt. be allowed to use that? What about the cost of the lost ability to be secure in your “papers” if such things are searchable? If we are not presented a technological solution then how do we draw this line and is this a bright line or one that changes with the times and other information? I personally question if such searches are worth the loss of liberty they provide. Carrying such data across borders is certainly less efficient than just copying it across the internet (Gmail account, LiveDrive, BitTorrent, Anonymous FTP, etc.) so the ability to transmit such data does not seem to me to be significantly impeded by such an action. On the flip side, the self-censorship that would be imposed by individuals who travel abroad based upon the knowledge that the government would have access to such data seems to have great ill effects on first and forth amendment protections. Likewise, the implications of such searches being used against political opponents (like that of Hoover’s FBI) or as a way to monitor US citizens should be something that we should not allow without eminent threat. How do we make decisions about such things in the current time is left to the courts but I think we should not tread recklessly on such tings as they are likely to set precedent for how digital data is perceived by the law in our world where all data is quickly becoming just ones and zeros.

If you are concerned about such searches, I suggest you check out encryption software, like TrueCrypt, and use it to create “virtual drives” that contain the files you would not want searched.

Monday, January 7, 2008

Steve Rambam on Why Privacy is Dead at ToorCon

OK, this lecture is a bit long (almost 2 hrs) but it covers many reasons why the genie may already be out of the bottle. He’s Ex-Law enforcement and a currently private Investigator. He goes over a lot of the sources where info is collected and how people are accessing that data. If you are interested in privacy, it’s worth your time to watch this: http://video.google.com/videoplay?docid=-383709537384528624&q=privacy&total=12601&start=0&num=10&so=0&type=search&plindex=0

Sunday, December 30, 2007

Don’t Go Towards the Light – Facebook and Beacon

Recently it has been hard to keep on top of the unfolding problems at Facebook. For those who are unaware of what Facebook is, it is a social networking site popular amongst college students. Of course, this didn’t send them into the netherworld or online privacy issues. No their problems started with their privacy policy. Most importantly what it didn’t say. What it didn’t say is that facebook employees might just be browsing your online activity (that Facebook tracks) for their own entertainment. Now that might some issues but that at least the caveat emptor of privacy policies. In an age where people narrowly tailor their privacy policies, it then falls to the user to think of all the things that a company could do with their information and decide if they want their information used that way before accepting the terms of the service (and many companies change their privacy policy at will and without notice). This is an interesting bent on contracts and informed consent. The contract is being modified at any time and without notice (note: most sites do this, not just Facebook). Furthermore, this is a one sided contract modification (much like the strategy credit card companies use). There is no negotiation and there is probably a serious question as to whether both sides are agreeing on the contract with the new policy (I know of more than one company that get’s people to agree to changes in the employee handbook before they get to see it!). Although concerning, this probably pales in comparison to the recent brouhaha over their Beacon software.

Beacon is Facebook’s advertising platform. Facebook tracks its user’s actions on the web (and off their site). It then posted this information for all to see on their page. This meant, if you had a friend that wanted a new GPS for xmas and you went to buy it for them online, they might see that you just made the purchase on your page (whoops, surprise gone). Worse yet, what if you wanted a GPS and so did someone else and they told you they weren’t buying gifts this year, or were doing something else but you could see they bought one for someone else). This policy was Opt out so it was on be default. When news of this broke, Facebook turned off this feature; sort of. Turns out, they didn’t turn it off at all, they just turned of the reporting part of it. So they were still tracking you, you just couldn’t see they were doing it so visibly. Finally Facebook let users completely opt-out of the system.

Opt-out has become the mantra of the marketing industry (assuming tacit acceptance of their practices). There is an interesting debate about this in the tech. community about if it is better to use Technology to stop such things (NoScript and AdBlocker can be used to block Beacon completely (for the moment) if you have FireFox while others say that policy should be implemented to stop such actions. Finally there are those who feel that consumer pressure will drive this (I got an email from one Social networking site saying how they would never implement such a system (of course there is some bitter irony there since they sent me that email without my permission though a spam posting on another social networking site). Which solution will work best (policy, technology or market pressure) is an interesting debate; each with its own merits. What is clear, is that what is in place now is not working.

Wednesday, December 19, 2007

A Response To The Re-definition Of Privacy

***The following is a response to this posting (http://privacy-law.blogspot.com/2007/11/is-privacy-still-privacy.html) on the re-defining of privacy. ***


This is a dangerous game of re-definition. Indeed, it is not the benign use of private data that the ideas of privacy law are designed to protect. The misuse of data is the concern and there in lies the problem such re-definitions seek to maneuver around.
In the case of government, 4th amendment protections are there for those who have been wrongly searched and to protect people from intrusive, and intimidating, searches. The promise that "we'll look but trust us, we won't tell anyone or use it against you" is of small comfort. Privacy from a governmental aspect is one of concern based not only on what is happening now, but what may happen in the future. The example I think makes this most clear is Germany in the 1930s. To be Jewish in Germany in 1931 would not be much means for hiding this affiliation. By 1939, hiding this fact was, for some, a matter of life and death. The best protection a citizenry has against such misuses of information is to prevent it's collection in the first place.

In the private sector; the challenges are that the recourse people have is only civil. This creates a problem where an organization may choose to violate its privacy policy (we'll ignore the issues of informed consent, changing contracts without re-affirmation and liberty for now). A good example of this is when .coms in the late 90s would sell their only asset (a user list) upon bankruptcy. People who had their "private" information sold had little recourse since the company that they had given their information to (and thus had the contract with) was no longer around (and even if they were, the fact that they are in bankruptcy ensures that there will be relatively little way for them to receive adequate compensation for the wrong or for the court to provide a disincentive for such actions not to happen again).

My point in these two examples is that this re-definition has far reaching consequences that are somewhat masked by the gentle nature of this re-definition. People need to be sure they understand such implications before we re-write the law to turn the veil of privacy into the hope of non-disclosure.