Monday, May 19, 2008
Privacy discussion (US vs EU)
Thursday, May 8, 2008
Tell the world you're made in America
Monday, May 5, 2008
Aren't you glad your government listens to you?
Sunday, May 4, 2008
Chip hacking; ain't just for ninjas at the Lays factory
What is of concern is that someone would put these chips into the commercial stream (or even target it at specific customers). If that sounds outlandish; you may be in for a surprise that some of the computer communications routers (the devices that send messages around the net) have already been hit by counterfeit chips. Indeed; in this case the routers that were purchased went to the US military. Although there is no proof at the moment that these chips were compromised (in terms of having a back door installed) no-one really knows. This has sent the Department of Defense scrambling to inspect all of it's routers for these phony chips (for those who think this sounds like overkill; it may be given that the US (and Chinese) governments have already insisted that communications equipment makers design their equipment to be able to allow transmission monitoring (Cisco documentation).
The interesting part here is that this is forcing government agencies to flip the usual "privacy for security" trade-off" discussion on its head. In this case, the way they can ensure the security of their populations, is though increased privacy (this is the same argument that people make about anonymity being important to avoid governmental tyranny). Although governments are likely to do a two-step about how what's good for them is bad for you; the real danger here is that chips coming from unidentified sources (say Fabs (fabrications facilities) outside of the US) and then put in products to be resold could have back doors waiting to be unlocked (or have the machines disabled at a critical time). The fear for governments here is obvious but the impact to business and users is also important. I'd love to see a solution for how to protect against malicious hardware (somewhat akin to the challenge of sending secret messages across monitored channels that encryption faced until public key encryption was discovered).
Monday, April 21, 2008
Why Didn't I Think of That; Research in Thought Crime
Last week there was a really interesting article by Nita Farahany in the Washington Post. The article talks about DARPA research into remote brainwave analysis and it's applicability for crime prevention. The article spends most of it's time talking about the technology but there are a few short references made to the civil liberty issues that this research raises. Of particular privacy concern is the 4th amendment protections from unreasonable search and seizure as scanning someone's brain certainly falls into the area most of us would consider private. There is also the possibility that there are 5th amendment issues of self-incrimination from asking questions and then looking at the brain scans of the suspect to define guilt (or perhaps just reasonable suspicion for more questions or a more invasive search). An argument can also be made that there is a lack of due process in such actions. as guilt could be decided based upon nothing more than a machines output. These are definitely some interesting things to question, and ones we should answer before we introduce such technologies; but I don't think that it's quite time to call for tinfoil hats.
The best analogy I can think of is the polygraph (Lie detector) machine. Such machines are banned for compulsory use in prosecutions and have questionable use in defense or civil proceedings. Employers are also banned from using them though that came about via federal law (Employee Polygraph Protection Act of 1988 (EPPA)). The danger in such a thing might come from its "illegal" use in pointing law enforcement in the right direction or if covered up by gag rule legislations (like that which accompanies NSLs).
Perhaps the part of this article that bothers me most is the scenarios that are presented. For some reason the "ticking timebomb" example gets evoked with alarming frequency these days. Forgive my naive nature but how frequent an occurrence is someone in custody who knows about a time bomb that we are so willing to curtail our rights for it? I would think it would be much more common for people with anxiety disorders to be detained and questioned because their condition might create a "false positive" reading. Is this the balance of liberty we want?
Of course this is also assuming that those in power only ever use their power for the good of the society. If someone with such a device were much more unscrupulous (#2). In such a situation authority figures could use such tools to detect which people would pay a bribe; or even worse who might not report an illegal action like a beating or rape by that official.
The real danger is that in such a society, it’s not the though reading that is the end result; it's just the start. Thought reading necessarily leads people to thought control where people are afraid to even think certain thoughts (and in this it sounds quite Orwellian). Just think if everyone around you could read your mind, you would probably think very different thoughts. Such coerced thought control is antithetical to a society that believes in liberty.
If the best reasons for such a technology is to catch a person with knowledge of a "ticking timebomb" then I think it's time we really evaluated the risk/benefit trade off. We debate the safety of Mercury in fish, BPA in bottles and alcohol in drivers; each of these impacts many more people a year than "ticking timebombs". Still; people get angry when police set up "sobriety checkpoints"; why would we want something that stops far less crime and is far more invasive?
Thursday, March 20, 2008
Why RFID Should Never be Taken to Mean Private or Secure
I came across two interesting videos this week showing just how insecure RFID can be. I’ve linked them below. You should note that the first uses a system called Oyster that is used in many cases (including entry cards (as the video shows). The second shows an American Express card. Caveat emptor.
Note: the second video is done with a $0.99 reader off eBay (plus $7.99 in shipping). In general these cost around $50 but the prices are dropping and $50 is not much of a barrier. Tracking based on these things we carry (in this case an id or credit card) has the potential to be cheap and ubiquitous.
Sunday, March 16, 2008
Power Corrupts; Absolute Power Corrupts; Absolutely
Hidden between the salacious headlines about a prostitute patronizing governor, the release of a report by the Department of Justice seeped out. Apparently the government we have entrusted with our security, and with the legal, and moral, requirement to protect our privacy has been playing fast and loose with the second of those obligations. According to the report, the FBI was using National Security Letters (authorized under the USA PATRIOT Act for surveillance outside of usual 4th amendment protections and requirements) to spy on subject who they were not allowed to, forbidden by courts from monitoring or simply casting their net much wider than they had approval to do.
For those wondering how this ties to our current debate about providing telecoms with immunity for prosecution (the telecoms are who the FBI delivered these NSLs to and were then given people’s private records or access to wiretaps), The Senate has already approved such immunity while the House voted this week to pass surveillance legislation without telecom immunity. Bush has threatened a veto without this clause and there has been much discussion about this issue. What is interesting here is that our government, entrusted to protect us, has asked for powers to monitor us out side of its abilities and in violation of the constitution. As in the past (think Hoover administration, Files that showed up on the Clinton White House, etc.) we see that those given the ability to secretly monitor are abusing that privilege. When we discuss the concepts of domestic spying and why that must be done out the oversight, we should also ask who watches the watchers?
Monday, March 3, 2008
IP address; Your Home on the Net
OK, so here’s a quick primer on Internet traffic. Much like the traffic on the streets, it finds its way to its destination via an address (well except for male traffic which wanders randomly around until it sees its destination, luckily for us all, Internet traffic is androgynous). The world of computer technology (especially early technology in the space) used very descriptive naming and IP (or Internet Protocol) is one of those amazingly descriptive names. Every time you communicate with another machine on the internet (e.g. every time you type in an email address, a web-site or IM someone) your IP address is communicated to that site. Don’t believe me, go to www.WhatsMyIPAddress.com and it will tell you what your IP address is. The current version of IP addresses is called IPv4 (for version 4). The problem with IPv4 is that as the number of devices that are connected to the Internet has expanded (think of every server, Internet capable cell phone, desktop, laptop, etc.) the number of available addresses is getting pretty slim (much like with telephone numbers). Also like telephone numbers (or street addresses) sections are given out in blocks (blocks of numbers or just street blocks). To deal with the lack of addresses, organizations (probably like your workplace or school) set up a set of IP addresses and then allow the traffic to get sent to addresses only it knows within its network (this is called DHCP within a reverse-proxy, don’t worry about the tech parts of this, just accept that your IP address changed periodically to allow others to use that address when you weren’t). Your Internet Service Provider (ISP) most likely does this as (just like you might have an office number at work that the post office has no idea where it is). This has all changed.
Two things are changing this system. First off is IPv6. IPv6 has much more “addressing space” which means that if this were a city, you just built a ton of new roads and everyone can easily have their own address. This means that there is no need for dynamic addressing and thus people may keep their IP addresses for long periods of time (effectively making them personally identifiable). The second change was around data aggregation.
Data aggregation has become cheap enough that storing massive amounts of data is quite cheap. Right now I can go buy a terabyte of space (that’s 1,000,000 Megabytes (MB)) for a couple hundred dollars (US $). Since storage is cheap, organizations started to store this information and associate it with other information. IP address could be linked to users (say if you logged into an online website then linking your login time and IP address would give you a user’s identity, then use that IP address on other sites and you know where the person has been). You can even use this information to get a person’s physical location (or at least the location of the machine/access point they are using). Search engines use this information to build a profile of a user and use that information to build marketing profiles. In this is where Google has found itself on the bad side of the European Union’s Privacy initiatives.
Recently the EU, decided that IP addresses are personal information (called PII or personally Identifiable Information in the
If you are concerned about such actions, I can recommend two actions to take. The first is to use a service like Scroogle. You can make a search plug-in for your browser for them or just go to their homepage. They proxy searches to Google but take out the ads and the tracking cookies. In this way you can access the value of a search engine (like Google) without worrying about the nasty tracking aspects of such a company. The second option is to use an anonymizing service like TOR. TOR sends all your traffic though at least three other nodes. The data is thus Anonymized from its original source but it is NOT confidential (e.g. if you log into a website that is not using SSL (the little lock icon on your browser) then the person on the end of that chain of servers could capture your login and password). This is just as true if you aren’t using TOR but just a reminder that anonymity is different than privacy.
Wednesday, February 27, 2008
RFID – What it is and Why is it Showing Up Everywhere?
So by now you’ve probably heard of RFID. If not this technology is Radio Frequency Identification. At a technological level it’s actually a pretty cool technology that could enable slick things like taking a semi-full of goods and driving it to a dock and sensors could automatically update inventory by reading the tags while the semi was pulling up to the warehouse (no clerks, no data entry errors, not time spent filling out paperwork). This is the same technology used in things like the EZ Pass for bridge tolls in certain parts of the
Some organizations are pretty much against this RFID in all forms (like the folks at CASPIAN) while other folks see it as applicable for industrial use but not consumer products (as Tesco tried so that it could track consumer’s actions in their stores). Still others think this technology is fine as long as it isn’t used in humans. Finally there are those who are volunteering it be tagged. It is probably biasing but worthy of note that RFID “non-removable” bracelets are used at
As it turns out some of this info isn’t even well secured as a German hacker proved with the e-passports. As with any technology, it can be used for good or for evil. In this case, RFID has the ability to be used for significant privacy invasion; the funny part is that there is not that much to gain for individuals when their materials are tagged. This begs the question, why adopt it?
If you want to read about how scary some of the folks patenting this technology are getting (at least in their patents) the book Spychips is a bit alarmist but quite eye opening.
Sunday, February 10, 2008
You sound familiar… Writing Style Matching in a Blogged World
So the National Science Foundation created a program called Dark Web. For those not familiar it’s a project that tries to collect all the extremist and terrorist sites on the net. For monitoring, this is probably something that seems perfectly practical. Some of the technology has interesting applications. One in particular is a writing style matching technology Writeprinting. Writeprinting looks at things like your writing style, structure and semantics to identify who you are (or more appropriately identify writings by the same individual. The benefit to be able to identify “anonymous” extremists from other writings they have done online (or other sources) is of obvious benefit which few people would deny we should be looking into in an effort to keep all people safe. Indeed, the Unibomber was caught after his manifesto was published and his brother recognized the thoughts and writing style.
Of course, like most technologies, it can be used for good or evil as machines and algorithms are apathetic to purpose by definition. This means that the same technology we rely on to keep us safe from terrorists may also be the same technology that keeps us from expressing our thoughts and feelings about what is happening in our communities, country or world. Anonymous speech was important to our founding fathers (as much of what they were doing was treasonous under English rule) and this technology could easily be used for other “well meaning” though totally unintended purposes such as catching students who write other’s papers or unmasking anonymous whistle blowing bloggers.
Of course, not making any public writings available would thwart such a technology but it also has a down side. Right now public shows of dissent are the ways that people form movements against programs, policies, organizations and governments that they don’t agree with. This form of association allows a safety valve for people to express their concerns and help make change if their views are shared by enough individuals. If such speech is tracked and the authors found and punished (like those that have protested President Bush in the United States or were thrown out of the US Capital for shirts relating to the Iraq occupation). In individual cases this leads to motivating those who believe in the cause being suppressed. In extreme cases it leads people to go directly to much more drastic means such as subversion and terrorism.
The point here is that freedom of speech is as much about having a voice as it is about maintaining a civil society. The creation of technologies that remove that anonymity may have the ironic result of actually making things less safe in the long run as those who feel that they are being oppressed and don’t feel free to express their grievances (free from reprisal) move to more extreme tactics.
Will technology meant to make us safer actually have the opposite affect? I certainly hope not. But as we develop such technologies we should bear such possible outcomes in mind.
Of course, people also may just start to come up with obfuscation programs (such as used in computer code) to mask their identities; only time will tell.
Sunday, February 3, 2008
RFID: Tag Your Kids For More Efficient Busses… Hu?
The Associated Press is reporting that a
Monday, January 28, 2008
AT&T reborn, Former Death Star now Net Nanny
This is a great article about what AT and T is going to do; monitor every bit of information that goes across its network. Oh sure, we’ve known for a while that they do this for the government, but apparently now they are doing it for the RIAA (recording industry) and MPAA (film industry). If this feels a little strange, maybe it’s because it reverses the idea of innocent until proven guilty (granted that is for govt. and no such principal necessarily applies to private industry). The article does a great job of pointing out that the telecoms pushed for (and got) a protection from liability for providing material (as opposed to what happened to Napster or Grokster) assuming that they had no part in deciding what it was. This would seem to contravene that. This also brings in an interesting question about which is more important as a service provider; serving your customers, or helping another industry. If free enterprise is correct, then this knowledge should mean terrible impacts on AT and T’s financial (as the article predicts). If not, then we have a profound example of user’s naïveté about privacy and control measures that is destined to play itself out with potentially unfortunate consequences in the future (the TIA program’s plant to use letter carriers as agents for the govt. and then later firefighters comes to mind as such things in the govt. sector). As for how the public will react, and if AT and T will suffer any measurable financial impact, only the future will tell.
Sunday, January 13, 2008
Border Seizure: Is All Information Equal?
The New York Times reported that border guards have seized computers and searched hard drives. The auspices of such actions are based around the noble effort to stop the trafficking of child pornography into the country. The reference to two cases (supporting searches, blocking searches) about the same kinds of searches, the concern that I have in such cases is how a line is drawn between different kinds of data. If the government is allowed to take copies of the data on a hard drive, what is to distinguish between medical records or diary entries from child porn or calls to treason? On a hard drive they are all just zeros and ones and there in lies the difference between real and “intellectual” property. Perhaps one solution is technological (like the use of the carnivore (DCS 1000) email reading system that the NSA uses). Another option is to decide which is the more important liberty to our society. If we search all hard drives looking for illegal material and we find no illegal material but we do find information about a crime that was committed but unprosecuted, should the govt. be allowed to use that? What about the cost of the lost ability to be secure in your “papers” if such things are searchable? If we are not presented a technological solution then how do we draw this line and is this a bright line or one that changes with the times and other information? I personally question if such searches are worth the loss of liberty they provide. Carrying such data across borders is certainly less efficient than just copying it across the internet (Gmail account, LiveDrive, BitTorrent, Anonymous FTP, etc.) so the ability to transmit such data does not seem to me to be significantly impeded by such an action. On the flip side, the self-censorship that would be imposed by individuals who travel abroad based upon the knowledge that the government would have access to such data seems to have great ill effects on first and forth amendment protections. Likewise, the implications of such searches being used against political opponents (like that of Hoover’s FBI) or as a way to monitor US citizens should be something that we should not allow without eminent threat. How do we make decisions about such things in the current time is left to the courts but I think we should not tread recklessly on such tings as they are likely to set precedent for how digital data is perceived by the law in our world where all data is quickly becoming just ones and zeros.
If you are concerned about such searches, I suggest you check out encryption software, like TrueCrypt, and use it to create “virtual drives” that contain the files you would not want searched.
Monday, January 7, 2008
Steve Rambam on Why Privacy is Dead at ToorCon
OK, this lecture is a bit long (almost 2 hrs) but it covers many reasons why the genie may already be out of the bottle. He’s Ex-Law enforcement and a currently private Investigator. He goes over a lot of the sources where info is collected and how people are accessing that data. If you are interested in privacy, it’s worth your time to watch this: http://video.google.com/videoplay?docid=-383709537384528624&q=privacy&total=12601&start=0&num=10&so=0&type=search&plindex=0
Sunday, December 30, 2007
Don’t Go Towards the Light – Facebook and Beacon
Recently it has been hard to keep on top of the unfolding problems at Facebook. For those who are unaware of what Facebook is, it is a social networking site popular amongst college students. Of course, this didn’t send them into the netherworld or online privacy issues. No their problems started with their privacy policy. Most importantly what it didn’t say. What it didn’t say is that facebook employees might just be browsing your online activity (that Facebook tracks) for their own entertainment. Now that might some issues but that at least the caveat emptor of privacy policies. In an age where people narrowly tailor their privacy policies, it then falls to the user to think of all the things that a company could do with their information and decide if they want their information used that way before accepting the terms of the service (and many companies change their privacy policy at will and without notice). This is an interesting bent on contracts and informed consent. The contract is being modified at any time and without notice (note: most sites do this, not just Facebook). Furthermore, this is a one sided contract modification (much like the strategy credit card companies use). There is no negotiation and there is probably a serious question as to whether both sides are agreeing on the contract with the new policy (I know of more than one company that get’s people to agree to changes in the employee handbook before they get to see it!). Although concerning, this probably pales in comparison to the recent brouhaha over their Beacon software.
Beacon is Facebook’s advertising platform. Facebook tracks its user’s actions on the web (and off their site). It then posted this information for all to see on their page. This meant, if you had a friend that wanted a new GPS for xmas and you went to buy it for them online, they might see that you just made the purchase on your page (whoops, surprise gone). Worse yet, what if you wanted a GPS and so did someone else and they told you they weren’t buying gifts this year, or were doing something else but you could see they bought one for someone else). This policy was Opt out so it was on be default. When news of this broke, Facebook turned off this feature; sort of. Turns out, they didn’t turn it off at all, they just turned of the reporting part of it. So they were still tracking you, you just couldn’t see they were doing it so visibly. Finally Facebook let users completely opt-out of the system.
Opt-out has become the mantra of the marketing industry (assuming tacit acceptance of their practices). There is an interesting debate about this in the tech. community about if it is better to use Technology to stop such things (NoScript and AdBlocker can be used to block Beacon completely (for the moment) if you have FireFox while others say that policy should be implemented to stop such actions. Finally there are those who feel that consumer pressure will drive this (I got an email from one Social networking site saying how they would never implement such a system (of course there is some bitter irony there since they sent me that email without my permission though a spam posting on another social networking site). Which solution will work best (policy, technology or market pressure) is an interesting debate; each with its own merits. What is clear, is that what is in place now is not working.
Wednesday, December 19, 2007
A Response To The Re-definition Of Privacy
This is a dangerous game of re-definition. Indeed, it is not the benign use of private data that the ideas of privacy law are designed to protect. The misuse of data is the concern and there in lies the problem such re-definitions seek to maneuver around.
In the case of government, 4th amendment protections are there for those who have been wrongly searched and to protect people from intrusive, and intimidating, searches. The promise that "we'll look but trust us, we won't tell anyone or use it against you" is of small comfort. Privacy from a governmental aspect is one of concern based not only on what is happening now, but what may happen in the future. The example I think makes this most clear is Germany in the 1930s. To be Jewish in Germany in 1931 would not be much means for hiding this affiliation. By 1939, hiding this fact was, for some, a matter of life and death. The best protection a citizenry has against such misuses of information is to prevent it's collection in the first place.
In the private sector; the challenges are that the recourse people have is only civil. This creates a problem where an organization may choose to violate its privacy policy (we'll ignore the issues of informed consent, changing contracts without re-affirmation and liberty for now). A good example of this is when .coms in the late 90s would sell their only asset (a user list) upon bankruptcy. People who had their "private" information sold had little recourse since the company that they had given their information to (and thus had the contract with) was no longer around (and even if they were, the fact that they are in bankruptcy ensures that there will be relatively little way for them to receive adequate compensation for the wrong or for the court to provide a disincentive for such actions not to happen again).
My point in these two examples is that this re-definition has far reaching consequences that are somewhat masked by the gentle nature of this re-definition. People need to be sure they understand such implications before we re-write the law to turn the veil of privacy into the hope of non-disclosure.
Sunday, October 21, 2007
Gazing across the pond: Privacy in the UK
Sunday, October 14, 2007
Security or Transparency; different views of privacy
It is easy to see how to support this view; people point to the tracking information used by government databases, marketing lists and nosey neighbors as evidence of need for privacy. Stories such as how the Nazi’s used public records to track Jews are often used to show the dangers in government consolidation of private information. What is less clear is how the transparency paradigm works.
On the other side of this discussion is the idea that transparency may be the best way to deal security. This is an interesting model since it relies on two things, acquiescence to power and belief in benevolent (or controllable) leadership. In this case the idea is that certain pieces of data need to be inspected as part of contractual obligations, legal mandates or national interests. In such situations, it isn’t that the information needs to be protected from all viewers, but that the dissemination, or use of that data beyond defined limits should be banned or protected though civil litigation.
Some examples of these two views in action are Amazon.com and British Petroleum. Amazon.com has a large set of (sometimes onerous) remote access and data protection measures that are intended to protect the integrity of Amazon.com’s intellectual property. Like may high tech companies, Amazon is concerned that anyone might access it’s data inappropriately and thus has erected major hurdles to accessing this information (Hurdles that exist for those that legitimately want to access it as well).
On the other side of this discussion is British Petroleum. BP has decided to take some of its critical system (like email) and have them hosted by third parties (making them far easier to access from a governmental and legal discovery aspect). BP makes a compelling argument that any of these resources could be “discovered” though governmental powers or legal subpoenas so spending money and resources to “hide” these assets is not very valuable. In their mind, the money it would cost to implement such functions is not worth the cost.
Clearly other organizations take a different view. What is interesting is that this view is a bit like other models we see. From CEO of Sun Microsystems saying “Privacy is dead, get over it” to the explosion of social networking sites like MySpace, Orkut, Friendster and Facebook; it does appear that people do feel ok giving more of their personal information that would have been discoverable though general detective work online.
When might this matter? This week it was discovered that the NSA sought to setup warrantless wiretapping of Americans. This isn’t much of a revelation since the White House stated that this was done in a response to the 9/11 attacks. For better or worse, most Americans accepted this as a trade off of liberty for temporary security, but it now appears that this program was started before 9/11. This is a big shift from what we’ve heard before. Under the secrecy paradigm, this would be quite concerning. Effort would be spend investigating and trying to change laws to roll back this system. On the other hand, if the transparence (or disclosure) paradigm were the idea from the start, there would be no issue, worry or cost to such an action.
Some people might point out that the “transparency” view is really just a pretty package around the loss of privacy. I would point out that there are important distinctions that are part of this view though. All information is not public, it is simply managed differently. Liability would apply to its abuse while the efficient transfer of this information could facilitate the efficient adjudication of issues and protection of citizens. At the root of this view is the belief in differentiating what you want to hide and the benevolence in those that hold this information. Ultimately it’s a matter of trust and accountability. Secrecy has always been about trust, the transparency paradigm shifts the thinking around trust from a “me against the world” to an “us against the others”. Different organizations (and people) are choosing to act on each of these philosophies. Time will tell us, which works best for society.
Sunday, October 7, 2007
Third parties are like third wheels; rarely wanted.
Much of our communications these days is sent though third parties. Indeed, it’s pretty hard to think of anything besides face to face communications (or passing notes in gym class) that doesn’t go though a third party. I’d love to use the passing notes example as one that is analogous, but the fact is that it’s only half the story. Most communications (like phone calls, wireless phones, and cell phones) pass though third parties. Those parties can monitor those communications (with varying levels of required legal permission). This isn’t anything surprising since most people know about things like wiretaps. What may be surprising is that in the cases of electronic communications; not only can your communications be intercepted; they are (in many cases) recorded and archived.
This came to many people’s attention during the Koby Bryant case. To give a quick refresher; they were combing though the alleged victim’s text messages to see what she was saying to other people after the alleged incident. The same thing happens with emails.
At issue in each of these cases is the fact that communications are stored on a third party server. That server then monitors, archives or both those communications. This means that those communications are legally discoverable and have a lower level of legal protection than other communications you may have. For example, speaking to someone, is protected since you can’t be forced to incriminate yourself (5th amendment). Recording a conversations between two parties requires both consent in many states. On top of these, parties involved in such conversations, might fight the discovery of such pieces of evidence, should they exist. On the other hand, third parties have less of an incentive to protect this information. In some cases they actually have reason not to protect it. These reasons can be anything from wanting to maintain good relations with the government (who regulates their communications though licensing), or not wanting to endure the legal costs of protecting someone else’s information.
In each of the presented cases, the take-away is that information that transfers though third parties is out of your control. Just like property (which is the paradigm that the law uses for most personal information) once you give it to someone else (like a phone company or an email service) they have a different (lower) set of incentives to keep that information safe. You should always be aware that when you pass information though others, there is the change that they may read, archive, or even change that information.
Monday, October 1, 2007
Cell Phones – Is that a locator in your pocket or are you just happy to see me?
Cell phones are a nearly ubiquitous these days. Many of us care them with us at all times and give little thought to how the technology works. I won’t go into the legal differences for cell phones vs. land lines (there are drastically different legal treatments of the two technologies when it comes to tapping the “line”) but I do want to talk a little about cell phones as tracking devices.
You’re probably used to your phone working wherever you go and you have probably never given a lot of though to the question of “how does the phone company know to make my phone ring no matter where I am?” Do they send that same ring out to every tower in all the cell networks in the world simultaneously? Of course not. So how does it know to connect your call to you, where you’re at? The answer is that your phone does a “ping” ever once in a while. This ping (much like the computer networking term and the naval term it derived from) is sent from your phone to the closest cell tower to let it know that you’re there. This way the phone company knows where to send your calls when they come in. What you may not know is that the phone companies keep these records. In effect they have a log of where you are, and have been, for years. In
Of course this information isn’t all nefarious; but it is necessary for the network, and is now required by the
Consumers are also being sold this technology. In some cases, it’s a mapping service; while in others, it’s a set of personal tracking services. Many of these are sold to parents as a way to keep track of their children. In other cases people are using the technology so they can keep in touch with their friends (Mologogo, MSSLAM).
The take away is that, whether you know it or not, your cell phone is always tracking where you are at. This data is stored for an undisclosed period of time. You are also not able to have this data deleted or keep it from being collected (unless you turn your phone off). Since this data is sent at all times your phone is on, this data provides a very descriptive set of information about where you are, and have been. I’ve known more than a few privacy advocates that use pay as you go cell phones and get new phones every month in order to diminish their traceability. This seems a bit extreme to me though each of us will decide what level of privacy we want. Remember that since this is not considered your data (legally speaking) you should be comfortable with this data being collected, and potentially sold. Some countries (like