Showing posts with label online privacy. Show all posts
Showing posts with label online privacy. Show all posts

Friday, May 23, 2014

Real ID Online? New Federal Online Identity Plan Raises Privacy and Free Speech Concerns



The White House recently released a draft of a troubling plan titled "National Strategy for Trusted Identities in Cyberspace" (NSTIC). In previous iterations, the project was known as the "National Strategy for Secure Online Transactions" and emphasized, reasonably, the private sector's development of technologies to secure sensitive online transactions. But the recent shift to "Trusted Identities in Cyberspace" reflects a radical — and concerning — expansion of the project’s scope.

The draft NSTIC now calls for pervasive, authenticated digital IDs and makes scant mention of the unprecedented threat such a scheme would pose to privacy and free speech online. And while the draft NSTIC "does not advocate for the establishment of a national identification card" (p. 6), it’s far from clear that it won’t take us dangerously far down that road. Because the draft NSTIC is vague about many basic points, the White House must proceed with caution and avoid rushing past the risks that lay ahead. Here are some of our concerns.

Is authentication really the answer?

Probably the biggest conceptual problem is that the draft NSTIC seems to place unquestioning faith in authentication — a system of proving one's identity — as an approach to solving Internet security problems. Even leaving aside the civil liberties risks of pervasive online authentication, computer security experts question this emphasis. As prominent researcher Steven Bellovin notes:


The biggest problem [for Internet security] was and is buggy code. All the authentication in the world won't stop a bad guy who goes around the authentication system, either by finding bugs exploitable before authentication is performed, finding bugs in the authentication system itself, or by hijacking your system and abusing the authenticated connection set up by the legitimate user. All of these attacks have been known for years.

A Real ID Society?

The draft NSTIC says that, instead of a national ID card, it "seeks to establish an ecosystem of interoperable identity service providers and relying parties where individuals have the choice of different credentials or a single credential for different types of online transactions," which can be obtained "from either public or private sector identity providers." (p. 6) In other words, the governments want a lot of different companies or organizations to be able to do the task of confirming that a person on the Internet is who he or she claims to be.

Decentralized or federated ID management systems are possible, but like all ID systems, they definitely pose significant privacy issues. 1 There’s little discussion of these issues, and in particular, there’s no attention to how multiple ID's might be linked together under a single umbrella credential. A National Academies study, Who Goes There?: Authentication Through the Lens of Privacy, warned that multiple, separate, unlinkable credentials are better for both security and privacy (pp. 125-132). Yet the draft NSTIC doesn’t discuss in any depth how to prevent or minimize linkage of our online IDs, which would seem much easier online than offline, and fails to discuss or refer to academic work on unlinkable credentials (such as that of Stefan Brands, or Jan Camenisch and Anna Lysyanskaya).

Providing a uniform online ID system could pressure providers to require more ID than necessary. The video game company Blizzard, for example, recently indicated it would implement a verified ID requirement for its forums before walking back the proposal only after widespread, outspoken criticism from users.

Pervasive online ID could likewise encourage lawmakers to enact access restrictions for online services, from paying taxes to using libraries and beyond. Website operators have argued persuasively that they cannot be expected to tell exactly who is visiting their sites, but that could change with a new online ID mechanism. Massachusetts recently adopted an overly broad online obscenity law; it takes little imagination to believe states would require NSTIC implementation individuals to be able to access content somehow deemed to be "objectionable."

Anonymity

The draft NSTIC "envisions" that a blogger will use "a smart identity card from her home state" to "authenticate herself for . . . [a]nonymously posting blog entries." (p. 4) But how is her blog anonymous when it’s directly associated with a state-issued ID card?

The proposal mistakenly conflates trusting a third party to not reveal your identity with actual anonymity — where third parties don’t know your identity. When Thomas Paine anonymously published Common Sense in 1776, he didn’t secretly register with the British Crown.

Indeed, the draft NSTIC barely recognizes the value of anonymous speech, whether in public postings or private email, or anonymous browsing via systems like Tor. Nor does it address issues about re-identification, e.g. the ability to take different sets of de-identified data and link them so as to re-identify individuals.

Bellovin credits the draft NSTIC for suggesting the use of attribute credentials rather than identity credentials — that is, using credentials that could establish that you're authorized to do something without saying who you are. But, as he puts it, "We need ways to discourage collection of identity information unless identity is actually needed to deliver the requested service," and the draft NSTIC doesn't seem to address this.
Privacy, Identity Theft and Surveillance

The draft NSTIC seems to presuppose widespread use of smart ID cards. In one example, it envisions that an individual will use "a smart identity card from her home state" to "authenticate herself for a variety of online services," presumably modeled upon driver’s licenses. (p. 4)

One major concern, acknowledged briefly in the draft, is whether people's computers can really be secure enough to be used for these purposes — smart ID cards or no smart ID cards. As noted above, the vast majority of privacy and authentication vulnerabilities stem from buggy software, and when a computer is trivial to compromise, its users’ credentials are easy to steal. The NSTIC proposal could, in fact, decrease user privacy and enable identity theft: once a user’s digital ID is stolen, it could be used to both pose as the user and access all the user’s accounts and data.

Consider, for example, the proposal to use a state digital ID card to access health records and online banking. What happens next time you lose your wallet?

Furthermore, by consolidating your credentials, the NSTIC plan may provide the government with a centralized means of surveilling your online accounts. And if the government issues your digital ID itself, it won’t even need to approach a third party with any kind of legal process before surveilling you.

The draft NSTIC also mentions the development of a public-key infrastructure (PKI). (pp. 15, 27) We support good, widespread encryption, which could allow people to get correct public keys reliably and possibly cut down on phishing, spam, fraud, and pretexting. But as Bruce Schneier and Carl Ellison have explained, doing PKI properly isn’t easy.2 All of their concerns apply, in some form, to the NSTIC proposal.

Another concern that’s emerged recently is whether governments could coerce certificate authorities in a PKI to issue false credentials in order to facilitate surveillance. Chris Soghoian and Sid Stamm have reported on an industry claim that governments could get "court orders" giving them access to falsified cryptographic credentials. This threat seems greater if the government itself is running the PKI.

Much more could be said. The NSTIC is only a draft, and the Department of Homeland Security and the White House sought public input online through July 19th. Because of the importance of this issue, EFF has joined with a coalition of concerned civil liberties group to ask the Administrations for a longer comment period and a way to submit more detailed comments. We hope and expect that this will be only the beginning of a public debate about ID management online.

US Government Begins Rollout Of Its 'Driver's License For The Internet'

from the seizing-the-(wrong)-moment dept

An idea the government has been kicking around since 2011 is finally making its debut. Calling this move ill-timed would be the most gracious way of putting it.
A few years back, the White House had a brilliant idea: Why not create a single, secure online ID that Americans could use to verify their identity across multiple websites, starting with local government services. The New York Times described it at the time as a "driver's license for the internet."

Sound convenient? It is. Sound scary? It is.

Next month, a pilot program of the "National Strategy for Trusted Identities in Cyberspace" will begin in government agencies in two US states, to test out whether the pros of a federally verified cyber ID outweigh the cons.
The NSTIC program has been in (slow) motion for nearly three years, but now, at a time when the public's trust in government is at an all time low, the National Institute of Standards and Technology (NIST -- itself still reeling a bit from NSA-related blowback) is testing the program in Michigan and Pennsylvania. The first tests appear to be exclusively aimed at accessing public programs, like government assistance. The government believes this ID system will help reduce fraud and overhead, by eliminating duplicated ID efforts across multiple agencies.

But the program isn't strictly limited to government use. The ultimate goal is a replacement of many logins and passwords people maintain to access content and participate in comment threads and forums. This "solution," while somewhat practical, also raises considerable privacy concerns.
[T]he Electronic Frontier Foundation immediately pointed out the red flags, arguing that the right to anonymous speech in the digital realm is protected under the First Amendment. It called the program "radical," "concerning," and pointed out that the plan "makes scant mention of the unprecedented threat such a scheme would pose to privacy and free speech online."

And the keepers of the identity credentials wouldn't be the government itself, but a third party organization. When the program was introduced in 2011, banks, technology companies or cellphone service providers were suggested for the role, so theoretically Google or Verizon could have access to a comprehensive profile of who you are that's shared with every site you visit, as mandated by the government.
Beyond the privacy issues (and the hints of government being unduly interested in your online activities), there are the security issues. This collected information would be housed centrally, possibly by corporate third parties. When hackers can find a wealth of information at one location, it presents a very enticing target. The government's track record on protecting confidential information is hardly encouraging.

The problem is, ultimately, that this is the government rolling this out. Unlike corporations, citizens won't be allowed the luxury of opting out. This "internet driver's license" may be the only option the public has to do things like renew actual driver's licenses or file taxes or complete paperwork that keeps them on the right side of federal law. Whether or not you believe the government's assurances that it will keep your data safe from hackers, keep it out of the hands of law enforcement (without a warrant), or simply not look at it just because it's there, matters very little. If the government decides the positives outweigh the negatives, you'll have no choice but to participate.

http://s3.documentcloud.org/documents/1153382/nsticstrategy-041511.pdf


Wednesday, February 5, 2014

Google Has Launched a For-Profit Privacy Invasion Into Our Electronic Lives

By Steven Rosenfeld
February 3, 2014 | AlterNet

No longer content to vacuum up, scan, index and sell analytics based on the content of our texts, emails, searches, locations and more, Google now has a new target: tapping, mapping and colonizing the networks wiring our lives.

Google argues that it has the right to collect your most sensitive data, as long as it flows across an open WiFi network,” PrivacySOS.org [3] said [4] last month after Google announced a $3.2 billion acquisition of Nest [5], which sells WiFi-controlled home heating appliances. “Now do you want to let this company inside your home?”

“Uhm… I hate to break this to the ACLU—given they’re supposed to be on the cutting edge of the privacy debate—but the thing is, Google’s already in our homes,” commented [6] PandoDaily’s Yasha Levine. “It has been in our homes for a long, long time. And not just in our homes, but at work, in our cars and even when we’re walking down the street.”

“As many have pointed out the privacy concerns of this development are huge,” wrote two other PandoDaily writers, Carmel Deamicus and Michael Carney. “Nest products track detailed information [7] about their users’ movements, in addition to things like a user’s WiFi IP address, and whether the specific address is a home or a business.”

Google is poised to cross another personal boundary. It is not just that our questions and queries are being aggressively collected, parsed, sold and resold, but that the networks tying together our digitized lives—via our devices, their settings and passwords—are also being eyed by the global data-hungry Goliath.
“The acquisition will help Google close the circle of search, people and goods in a broad Internet of Everything,” wrote [8] Wall Street Journal editor Michael Hickins. “As Aaron Levie, CEO of Box Inc. tweeted, ‘With home automation, self-driving cars, robots, mobile, and life sciences, Google is setting itself up to own the 21st century.’”

Anyone who cares about maintaining some degree of privacy should pay attention. Google has been doing a lot more than its lobbyists and executives have disclosed when defending or promoting its initiatives. Here are four examples that undescrore Google’s corporate ethos that any data it can grab is Google's for the taking.

  1. Street View: not just street mapping. After being sued by 38 states, Google admitted last March that its weird-looking cars outfitted with roof cameras facing four directions were not just taking pictures; they were collecting data from computers inside homes and structures, including “passwords, e-mails and other personal information from unsuspecting computer users,” the New York Times reported [9].
  2. Gmail: prying and spying. This October, a federal judge refused to dismiss a potential class-action lawsuit brought by Gmail users who objected to its practice of analyzing the content of all the messages on its network and selling byproducts to advertisers. Those suing Google said it violated federal wiretap laws.
    This issue isn’t new to Google. In congressional testimony in 2009, Google’s lawyers said [10] its email technology was used for scanning for spam, computer viruses and serving ads “within the Gmail user’s experience.” But last fall, U.S. District Court Judge Lucy Koh held that Google never told Gmail users that Google would create personal profiles and target users with ads. Nor did people who are not Gmail users, but who were writing to Gmail addresses, agree to let Google collect and parse their messages.
  3. Google Safari: not just hunting WiFi. Google’s court record includes more than just grabbing and snatching data. In early 2012, theWall Street Journal broke the story that its software was bypassing security settings for Apple devices using the Safari browser. “Google hated this [Safari’s anti-tracking features] and used a secret code to bypass this security setting,” the blog GoogleExposed wrote [11]. “This exposed millions of Safari users to tracking for months without them even knowing about it.” In August 2012, the Federal Trade Commission fined [12] Google $22.5 million, its largest civil fine, noting that Google also had violated previous privacy agreements.
  4. Android: another data gateway. One year after the FTC fine, ComputerWorld.com [13]’s Michael Horowitz, who writes its Defensive Computing feature, noted Google was back to its old tricks. “Google knows nearly every WiFi password in the world,” he declared, explaining that was the result of backdoor access to hundreds of millions of phones and devices using its Android operating system.
    “Sounds great. Backing up your data/settings makes moving to a new Android device much easier,” Horowitz wrote, citing how the company sold this feature to consumers. “It lets Google configure your new Android device very much like your old one. What is not said, is that Google can read the WiFi passwords.” The good news, he said, is that this feature can be turned off. “The bad news is that, like any American company, Google can be compelled by agencies of the U.S. government to silently spill the beans.”

ComputerWorld was careful [14] not to pick just on Google for domestic spying. DropBox, Microsoft, Apple, Yahoo, FaceBook, Skype—and others—all do pretty much the same thing: read user data and grant government access to it. But Google’s mission, detailed [15] in its patents, stands apart. Its business is based on analyzing user metrics with ever-growing [8] precision, and selling those insights to advertisers.

Thus, the recent handwringing [16] by Google CEO Eric Schmidt that Google—and others—was taken advantage of by America’s top spymasters following Edward Snowden’s still-unfolding National Security Agency whistleblowing, is more than hollow. It’s a farce. The record shows that Google knows exactly what it is doing.

2014 is likely to be a year where the trade-off for more profits and data for Google will be the loss of privacy. It’s not paranoid to say that Google’s acquisition of Nest is at the cutting edge of colonizing the links between our electronic devices and our lives. The trend of aggregating all the data that’s out there is behind many privacy-invading social media products, such as an app launching this week [17] that literally allows a man to walk into a bar, see a woman and know her name “before he even says hello."

Later this summer, Google will start selling its voice- and video-capturing Glass eyewear. Google Glass may be fantastic as a hands-liberating computing platform, but it also enables its users to film, analyze or spy upon others from afar. But it's up to us to say where the red lines should be drawn when it comes to protecting privacy and personal rights, and balacing those aganist overly intrusive individuals, corporations, institutions and governments.



Links:
[1] http://alternet.org
[2] http://www.alternet.org/authors/steven-rosenfeld
[3] http://privacysos.org/
[4] http://privacysos.org/node/1299
[5] https://nest.com/blog/2014/01/13/welcome-home/
[6] http://pando.com/2014/01/14/privacy-advocates-freak-out-at-googles-nest-acquisition-what-took-them-so-long/
[7] https://nest.com/legal/privacy-statement/
[8] http://blogs.wsj.com/cio/2014/01/14/the-morning-download-googles-nest-building-may-alarm-privacy-hawks/
[9] http://www.nytimes.com/2013/03/13/technology/google-pays-fine-over-street-view-privacy-breach.html
[10] http://www.nytimes.com/interactive/2013/10/02/technology/google-email-case.html
[11] http://googleexposed.wordpress.com/2012/04/18/huge-fine-against-google-for-violating-privacy-is-imminent/
[12] http://bits.blogs.nytimes.com/2012/08/09/f-t-c-fines-google-22-5-million-for-safari-privacy-violations/
[13] http://computerworld.com/
[14] http://blogs.computerworld.com/print/22300
[15] http://www.google.de/patents/EP1634206A4?hl=de&cl=en
[16] http://www.engadget.com/2013/11/04/eric-schmidt-slams-for-snooping/
[17] http://blogs.wsj.com/venturecapital/2014/01/30/socialradar-balances-privacy-with-new-social-geolocation-app/?KEYWORDS=google+privacy
[18] http://www.alternet.org/tags/google-0
[19] http://www.alternet.org/%2Bnew_src%2B

Tuesday, October 22, 2013

Lobbyists Will Win and We Will Lose If TPP Trade Deal Goes Through

Civil Liberties  
October 18, 2013 |

Something very important happened last week.

For the first time, Presidents and Prime Ministers of several countries met with industry lobbyists to discuss the Trans-Pacific Partnership (TPP) on the sidelines of the annual Asia-Pacific Economic Cooperation (APEC) summit in Bali, Indonesia. Although U.S. President Obama suddenly announced he would not [3] be joining these discussions, industry lobbyists are hoping to push through [4]  TPP talks to finalize the agreement.

What exactly is the TPP? It’s been called one of the most significant international trade agreements since the creation of the World Trade Organization [5]- but you’d be forgiven for not knowing about it. Discussions about this monumental agreement have been so secret that the little we know about the text is from leaked documents [6]- documents that show we have grave reason to be concerned.

One of its most troubling chapters includes an extreme Internet censorship plan that could break your digital future. Here are the top five ways the TPP censors the Internet and why it should concern you:

5.The TPP could criminalize small-scale copyright infringement

The next time you want to share a song or a recipe online, you’d have to ask yourself: Am I a criminal? Interested in writing some fan fiction based on your favourite detective series and sharing it online? Ask yourself that very same question. That’s how TPP provisions could characterize you based on what we know about its Intellectual Property chapter.

According to the leaked drafts, unauthorized small-scale downloading or sharing of copyrighted material could result [7] in severe fines and criminal penalties. Law enforcement could even seize your computer and send you to jail for minor copyright infringement.

4. The TPP could prohibit blind and deaf users from breaking digital locks to access their content

Under the TPP, attempts to circumvent digital locks in order to use your paid-for and legally-acquired media may become illegal. If you are blind, this means you could be criminalized [8] for circumventing digital locks on your purchased e-books and other digital materials in order to convert text to braille, audio, or other accessible formats. If you are a librarian, it may become very difficult to share [9] excerpts of content with students for education purposes, lend out material to the public, or even gain full access to purchased content; and as a consumer of digital media, attempts to [10] make backup copies of that DVD you purchased or transfer your legally-purchased e-book on a different device would become unlawful.

3. The TPP could lead to excessive copyright terms

Copyright, which was originally intended to promote the creation of new works by giving authors certain exclusive rights for a limited time, may be threatened [11] by excessive terms and a rigid system that could stifle creativity and innovation under the TPP.

Under the TPP, excessive copyright terms [10] could be created beyond internationally-agreed upon periods; it could also lengthen terms for corporate-owned works. Despite the strong and growing body of evidence demonstrating the importance of a rich commons [12] in creating new works, such a rigid copyright regime would stifle creativity and innovation. It would also restrict [13] the limitations and exceptions that member countries could enact, ensuring that countries enact compliant laws in order to avoid trade sanctions.

2.The TPP may regulate temporary copies at the cost of innovation and freedom

Temporary copies, or the small copies that your computer needs to make in order to move data around, are being targeted by TPP lobbyists who are attempting to redefine the very meaning of the word “copy”. The very notion of regulating temporary copies is ludicrous given how basic [14] the creation of temporary copies of files and programs is to computer functioning and the Internet. As the Electronic Frontier Foundation notes [14]:

This proposal may seem absurd to you. It should. Given how crucial the storage of “temporary copies” of digital files is to the functioning of our devices, the inclusion of unfettered provisions to regulate it is purely backward, especially given the supporters’ failure to justify a legitimate purpose for imposing a burden without a balance.

If lobbyists have their way, anyone viewing content on any device could potentially be committing copyright infringement. Companies like Wikipedia and Connexions would face serious difficulty [14] in hosting and storing user-generated content. Ultimately, this provision could make it more expensive for you to access licensed content, make you more vulnerable to liability, require you to purchase licenses from copyright-holders for transactions, and hinder your ability to use and create online content.

1. The TPP could kick you off the Internet

The TPP will place the burden [15] of monitoring copyright infringement on your Internet Service Provider (ISP), potentially resulting in the blocking of entire websites. Your ISP would have to institute what’s called a “three-strike rule [15]” – a rule that would kick you and your whole family off the internet after three infringement accusations by copyright holders.

It would also force websites to police user-contributed material.. Not only would this mean added financial burden [16], which could lead to the stifling of technology startups, it would also result in websites having to actively monitor for banned links – forcing the creation of a stringent Internet censorship regime. If ISPs are incentivized to remove content because of the resource-heavy nature of investigating copyright infringement complaints, such immediate takedown could censor time-sensitive news, including information to facilitate social organization, protest, and community-building.

It would also break your right to privacy [17] by forcing your ISP to share your private sensitive information with law enforcement in order to investigate your alleged copyright crimes.

Here’s the bottom line: The TPP is a secretive and extreme agreement that could break our digital future. It could change how we behave online, threaten our freedom of expression by promoting an extreme Internet censorship plan, and invade our privacy. The TPP will stifle creativity and innovation, hinder our ability to access information and organize, and criminalize our Internet use. The TPP is an affront to global Internet freedom.

Over 100,000 people have said no [18] to the TPP’s extreme Internet censorship plan and several thousand have put forward their vision of a fair digital future [19]. Join them and make your voice heard – the time is now [20].

Sunday, September 15, 2013

Internet S.O.S.



Saturday, September 14, 2013 by Media Citizen
by Tim Karr







Last week we learned that U.S. and British intelligence agencies have broken the back of digital encryption — the coded technology hundreds of millions of Internet users rely on to keep their communications private.

Is the Internet on life support?

Over the weekend, Der Spiegel reported that the NSA and its British counterpart are also hacking into smartphones to monitor our daily lives in ways that wouldn’t have been possible before the age of the iPhone.

This news, just the latest revelations from the files of Edward Snowden, only heighten our sense that we can no longer assume anything we say or do online is secure.

But that’s not all. In a case that was heard in a U.S. federal appeals court on Monday, telecommunications colossus Verizon is arguing that it has the First Amendment right to block and censor Internet users. (That’s right. Verizon is claiming that, as a corporation, it has the free speech right to silence the online expression of everybody else.)
It's come to this. Government and corporate forces have joined to chip away at two pillars of the open Internet: the control of our personal data and our right to connect and communicate without censorship or interference.

The Surveillance Industrial Complex

A series of reports coordinated among the Guardian, the New York Times and ProPublica revealed that the NSA and its British counterpart have secretly unlocked encryption technologies used by popular online services, including Google, Facebook and Microsoft.

Using National Security Letters and other secret court orders, intelligence agencies can wedge their way onto the large telecommunications networks that move most of the world’s Internet traffic. Getting access to the data is only half the challenge. To read and sort these communications, the NSA works with a lesser-known assortment of security vendors that filter through mountains of data, target references and patterns of interest and crack codes designed to safeguard user identity and content.

Many of the companies that ply this trade are only now being exposed through “Spyfiles,” collaboration among WikiLeaks, Corporate Watch and Privacy International designed to shed light on the multibillion-dollar industry. According to the latest documents provided by Edward Snowden, U.S. intelligence agencies alone spend $250 million each year to use these companies’ commercial security products for mass surveillance.

Without safeguards that protect users from surveillance and censorship, the Internet’s DNA will change in ways that no longer foster openness, free expression and innovation.It’s part of a sprawling complex of companies, lobbyists and government officials seeking to rewire the Internet in ways that wrest control over content away from Internet users.

While motivations may differ, the result is the same: a communications network that works against the Interests of many for the benefit of the few.

Tearing the Fabric

The Internet wasn’t meant to be like this. Bruce Schneier, an encryption fellow at Harvard's Berkman Center for Internet and Society, writes that the NSA and the companies it works with are “undermining the very fabric of the Internet.”

Telecommunications companies are doing their part by giving spy agencies access to our data. They’re also bankrolling a multimillion-dollar lobbying effort to destroy Net Neutrality — the one rule that prohibits Internet service providers from blocking or degrading our ability to connect to one another, share information and use the online services of our choosing.

If Verizon wins its case in Washington, ISPs will be able to prioritize certain online content while degrading user access to sites and services that the big companies don’t like.

It’s a business that puts at risk the most integral function of the World Wide Web. Sir Tim Berners-Lee, the Web’s pioneer, saw the network as a “blank canvas” — upon which anyone could contribute, communicate and innovate without permission.

Berners-Lee’s invention relied on an open protocol that gave everyday users power over the network. This networking principle has far-reaching political implications, favoring systems that are more decentralized and democratic.

Without safeguards that protect users from surveillance and censorship, the Internet’s DNA will change in ways that no longer foster openness, free expression and innovation.

Media Policy

If we’ve learned anything during the Summer of Snowden, it’s that corporations and governments alone can’t be trusted to be good stewards of the Internet. We need media policies that protect our privacy and promote access to open networks.

The fight for these policies is being led by a diverse and bipartisan alliance of civil liberties and communications-rights organizations, including the ACLU, EFF, Free Press and Public Knowledge.

We’re not alone. Millions joined the call for Net Neutrality in 2010; millions more stood up to defend the Internet against the PIPA and SOPA Web-censorship bills in 2012. The battle to protect users’ privacy has engaged new audiences as we've learned more about the extent of the NSA's mass surveillance.

In each of these arenas, we’re working to stop bad laws, amend others and implement new policies that put Internet users first.

A grassroots movement is fueling this fight. If you haven’t joined us yet, now’s the time to step up and save the Internet.

Wednesday, April 24, 2013

CISPA in limbo thanks to Senate apathy

RT, April 23, 2013

Despite an $84 million lobbying effort, CISPA, the controversial bill aimed at making it easier for corporations to share customers' personal information with the government, faces an uncertain future after approval in the US House of Representatives.

The next step for the Cyber Intelligence Sharing and Protection Act, or CISPA, after passing by a 288 to 127 margin in the House, is a Senate vote. However, the Senate has yet to debate the bill and has given no indication that the proposal is a priority, as major issues including gun control and immigration linger in the national consciousness.

CISPA co-sponsor Rep. Mike Rogers (R-Mich.) of the House Intelligence Committee has maintained that the law would help corporations defend against supposedly inevitable cyber-attacks by striking “that right balance between our privacy, civil liberties and stopping bad guys in their tracks from ruining what is one-sixth of the US economy,” as quoted by the Associated Press.
If CISPA were to become law it would grant businesses and the government an unprecedented ability to share data without the need to consider anti-trust or classification laws. Hacked businesses would be granted legal immunity if they acted in “good faith” to protect their networks, thanks to a part of the bill whose broad language has drawn the ire of consumer and privacy advocates.

An initial version of the bill passed in the House of Representatives in 2012 but faded after a Senate filibuster. Last year only 40 Democrats supported the bill – though that number nearly doubled to 92 who voted for it in 2013. That seemingly sudden ideological shift followed an $84 million lobbying effort from major sponsors like Viacom, Time Warner, Verizon Wireless, and others, according to the Daily Tech.

The Electronic Frontier Foundation and American Civil Liberties Union, two of CISPA’s chief opponents, have warned that the legislation would reveal health records, credit information, and other information to the government without first being scrubbed by the companies turning over those files. The National Security Agency could then be granted access to those transmissions when investigating foreign hackers.

Google, Yahoo and Microsoft are among the tech companies that have supported the bill, but public backing has slowly eroded after Facebook revoked its support and a series of amendments in the House Intelligence Committee failed to sway the ACLU.

US President Barack Obama threatened to veto CISPA in 2012 and, citing privacy concerns, has kept his position with the current language of the bill. If CISPA overcomes the odds in the Senate, a presidential veto would again doom the law to months of debate in the House.

Thursday, April 18, 2013

CISPA Vote: House Passes Cybersecurity Bill To Let Companies Break Privacy Contracts

Guilty until proven guilty...

Zach Carter
Sabrina Siddiqui

Huffington Post
04/18/2013

WASHINGTON -- The House of Representatives passed a broad cybersecurity bill Thursday that allows corporations to share customers' personal data with other firms and the U.S. government, even in cases in which a company has a signed contract explicitly vowing not to do so.

The Cyber Intelligence Sharing and Protection Act, known as CISPA, passed by a margin of 288 to 127, despite receiving a late veto threat from the Obama administration, which warned that the bill does not sufficiently protect civil liberties. The veto threat was particularly noteworthy, given President Barack Obama's Department of Justice has been urging Congress to expand its data-gathering and cybercrime powers for years. Congress shelved a similar bill last year after the White House expressed its formal opposition.

Supporters of the bill argue that it's needed to help the government protect key infrastructure and institutions from online attacks. They also have said the bill doesn't require companies or the government to monitor customer content, although it does authorize them to share personal account data, including emails and other information. Firms that voluntarily turn over such data would be immune from civil lawsuits.

The broad language of the bill, which imposes its standards above "any other provision of law," would effectively void privacy contracts between companies and their customers. Specifically it states that "Notwithstanding any other provision of law, a self-protected entity may, for cybersecurity purposes ... share such cyber threat information with any other entity, including the Federal Government." Companies could not be held accountable for violating terms of service agreements or other arrangements in which they promise not to share customer information with other parties.

Privacy and civil liberties advocates, including the American Civil Liberties Union, have blasted CISPA for overriding private contracts and authorizing both corporate and government access to personal information. Several Internet freedom groups also objected to the bill, warning that people will be less willing to use online services for fear that their privacy will be compromised.

Privacy proponents like the Electronic Frontier Foundation had urged the House to adopt an amendment that would have allowed companies to make legally enforceable privacy contracts with their customers. The amendment was never brought up for a vote.

The bill's opponents shared their concerns with the White House in the form a petition, which received the 100,000 signatures necessary to elicit a formal response last month. They also submitted more than 300,000 online signatures to the House Intelligence Committee.

But the corporate coalition that teamed up with web activists to take down the Stop Online Piracy Act in January 2012 was notably fractured during the congressional debate over CISPA. Many telecom companies, including AT&T and Comcast, support the legislation, which exempts them from legal liabilities. Chip manufacturer Intel and security software firm McAfee are also in favor. Others, such as Google, took no public position, while Microsoft and Facebook rescinded their support for the legislation, the latter after facing pressure from Demand Progress, the Internet freedom advocacy group founded by Aaron Swartz.

The intensity of the opposition, however, has been far more muted than that against SOPA, which pitted the bill's Silicon Valley opponents against support from corporate interests in Hollywood.

The weak corporate opposition to CISPA underscores the uphill battle that many nonprofit advocacy groups face in Washington when they lack such support: With corporate backing for the opposition, SOPA was abandoned without a vote, while CISPA, which is opposed largely by nonprofits, sailed through the House.

The CISPA vote also tested the Internet freedom credentials of SOPA opponents Reps. Darrell Issa (R-Calif.) and Jason Chaffetz (R-Utah), who have made significant inroads among web activists and tech firms on behalf of the Republican Party. Nevertheless, both voted in favor of CISPA.

Issa and Chaffetz defended their votes and argued that resurrecting their opposition to SOPA in the debate over CISPA was comparing apples to oranges.

"[SOPA] was a totally different thing ... just completely about something else," Chaffetz told The Huffington Post. "This is a question of cyber threats and our national security, and I believe we have to do everything we can to protect our national security."

Issa, who serves as the House Oversight Committee Chairman, said he was aware of the backlash the bill will provoke from the privacy and civil liberties communities but that he was comfortable with the final product.

"We've done our best to address their concerns in this bill," he told HuffPost, adding that measures would be taken to ensure oversight of what information was being shared, should the bill become law. "I'm confident we have all of the appropriate privacy protections in place."

The bill's chief backers stepped up pressure on members to garner their support ahead of the vote. CISPA sponsor Rep. Mike Rogers (R-Mich.) implied opponents were basically teenagers in their basements, while Rep. Michael McCaul (R-Texas) on the House floor invoked this week's Boston Marathon bombing to underscore the need to enhance national security.

Friday, March 29, 2013

How Corporate Power Seized the Internet

Digital Grab
by NORMAN SOLOMON



If your daily routine took you from one homegrown organic garden to another, bypassing vast fields choked with pesticides, you might feel pretty good about the current state of agriculture.

If your daily routine takes you from one noncommercial progressive website to another, you might feel pretty good about the current state of the Internet.

But while mass media have supplied endless raptures about a digital revolution, corporate power has seized the Internet — and the anti-democratic grip is tightening every day.

“Most assessments of the Internet fail to ground it in political economy; they fail to understand the importance of capitalism in shaping and, for lack of a better term, domesticating the Internet,” says Robert W. McChesney in his illuminating new book, Digital Disconnect.
Plenty of commentators loudly celebrate the Internet. Some are vocal skeptics. “Both camps, with a few exceptions, have a single, deep, and often fatal flaw that severely compromises the value of their work,” McChesney writes. “That flaw, simply put, is ignorance about really existing capitalism and an underappreciation of how capitalism dominates social life. . . . Both camps miss the way capitalism defines our times and sets the terms for understanding not only the Internet, but most everything else of a social nature, including politics, in our society.”

And he adds: “The profit motive, commercialism, public relations, marketing, and advertising — all defining features of contemporary corporate capitalism — are foundational to any assessment of how the Internet has developed and is likely to develop.”

Concerns about the online world often fixate on cutting-edge digital tech. But, as McChesney points out, “the criticism of out-of-control technology is in large part a critique of out-of-control commercialism. The loneliness, alienation, and unhappiness sometimes ascribed to the Internet are also associated with a marketplace gone wild.”

Discourse about the Internet often proceeds as if digital technology has some kind of mind or will of its own. It does not.

For the most part, what has gone terribly wrong in digital realms is not about the technology. I often think of what Herbert Marcuse wrote in his 1964 book One-Dimensional Man
“The traditional notion of the ‘neutrality’ of technology can no longer be maintained. Technology as such cannot be isolated from the use to which it is put; the technological society is a system of domination which operates already in the concept and construction of techniques.”

Marcuse saw the technological as fully enmeshed with the political in advanced industrial society, “the latest stage in the realization of a specific historical project – namely, the experience, transformation, and organization of nature as the mere stuff of domination.” He warned that the system’s productivity and growth potential contained “technical progress within the framework of domination.”

Fifty years later, McChesney’s book points out:
“The Internet and the broader digital revolution are not inexorably determined by technology; they are shaped by how society elects to develop them. . . . In really existing capitalism, the kind Americans actually experience, wealthy individuals and large corporations have immense political power that undermines the principles of democracy. Nowhere is this truer than in communication policy making.”

Huge corporations are now running roughshod over the Internet.
At the illusion-shattering core of Digital Disconnect are a pair of chapters on what corporate power has already done to the Internet — the relentless commercialism that stalks every human online, gathering massive amounts of information to target people with ads; the decimation of privacy; the data mining and surveillance; the direct cooperation of Internet service providers, search engine companies, telecomm firms and other money-driven behemoths with the U.S. military and “national security” state; the ruthless insatiable drive, led by Apple, Google, Microsoft and other digital giants, to maximize profits.

In his new book, McChesney cogently lays out grim Internet realities. (Full disclosure: he’s on the board of directors of an organization I founded, the Institute for Public Accuracy.) Compared to Digital Disconnect, the standard media critiques of the Internet are fairy tales.

Blowing away the corporate-fueled smoke, McChesney breaks through with insights like these:

  • “The corporate media sector has spent much of the past 15 years doing everything in its immense power to limit the openness and egalitarianism of the Internet. Its survival and prosperity hinge upon making the system as closed and proprietary as possible, encouraging corporate and state surreptitious monitoring of Internet users and opening the floodgates of commercialism.”
  • “It is supremely ironic that the Internet, the much-ballyhooed champion of increased consumer power and cutthroat competition, has become one of the greatest generators of monopoly in economic history. Digital market concentration has proceeded far more furiously than in the traditional pattern found in other areas. . . As ‘killer applications’ have emerged, new digital industries have gone from competitive to oligopolistic to monopolistic at breakneck speeds.”
  • “Today, the Internet as a social medium and information system is the domain of a handful of colossal firms.”
  • “It is true that with the advent of the Internet many of the successful giants — Apple and Google come to mind — were begun by idealists who may have been uncertain whether they really wanted to be old-fashioned capitalists. The system in short order has whipped them into shape. Any qualms about privacy, commercialism, avoiding taxes, or paying low wages to Third World factory workers were quickly forgotten. It is not that the managers are particularly bad and greedy people — indeed their individual moral makeup is mostly irrelevant — but rather that the system sharply rewards some types of behavior and penalizes other types of behavior so that people either get with the program and internalize the necessary values or they fail.”
  • The tremendous promise of the digital revolution has been compromised by capitalist appropriation and development of the Internet. In the great conflict between openness and a closed system of corporate profitability, the forces of capital have triumphed whenever an issue mattered to them. The Internet has been subjected to the capital-accumulation process, which has a clear logic of its own, inimical to much of the democratic potential of digital communication.”
  • What seemed to be an increasingly open public sphere, removed from the world of commodity exchange, seems to be morphing into a private sphere of increasingly closed, proprietary, even monopolistic markets. The extent of this capitalist colonization of the Internet has not been as obtrusive as it might have been, because the vast reaches of cyberspace have continued to permit noncommercial utilization, although increasingly on the margins.”
  • “If the Internet is worth its salt, if it is to achieve the promise of its most euphoric celebrants and assuage the concerns of its most troubled skeptics, it has to be a force for raising the tide of democracy. That means it must help arrest the forces that promote inequality, monopoly, hypercommercialism, corruption, depoliticization, and stagnation.”
  • Digital technologies may bring to a head, once and for all, the discrepancy between what a society could produce and what it actually does produce under capitalism. The Internet is the ultimate public good and is ideally suited for broad social development. It obliterates scarcity and is profoundly disposed toward democracy. And it is more than that. The new technologies are in the process of truly revolutionizing manufacturing, for example, making far less expensive, more efficient, environmentally sound, decentralized production possible. Under really existing capitalism, however, few of the prospective benefits may be developed — not to mention spread widely. The corporate system will try to limit the technology to what best serves its purposes.”
The huge imbalance of digital power now afflicting the Internet is a crucial subset of what afflicts the entirety of economic relations and political power in the United States. We have a profound, far-reaching fight on our hands, at a crossroads leading toward democracy or corporate monopoly. The future of humanity is at stake.

Ex-White House Official Joins Group Fighting "Excessive" Online Privacy Laws



As the Obama administration and tech company lobbyists chip away at the European Union's attempts to protect online privacy, a new pro-industry coalition has popped up to join the fray. Not quite two weeks ago, the Coalition for Privacy and Free Trade announced its existence. The group's senior academic adviser is Daniel Weitzner, who, less than two years ago, was working as the White House's deputy chief technology officer for internet policy.

Weitzner tells Mother Jones that he joined the coalition because he wants to strengthen privacy laws while ensuring the free flow of information. He worked for the administration from March 2011 to August 2012, leading the development of the much-lauded Consumer Privacy Bill of Rights, a blueprint that asserts Americans' right to control what happens to their online data. Marc Rotenberg, president of the Electronic Privacy Information Center, calls the document "a significant achievement" and says that "Danny deserves a fair amount of credit for it." But, he adds, "the critical question is whether it will be enacted into law." For now, its recommendations are voluntary.

Some privacy experts are concerned that Weitzner and the Coalition for Privacy and Free Trade will help companies like Facebook and Google continue to have free rein over their users' personal information. "This coalition appears to be a well-oiled campaign driven by the special interests of tech companies," says Jeffrey Chester, executive director of the Center for Digital Democracy. "The use of a former, now revolving-door, White House official is also disturbing, because it gives them influence to win major concessions." Joe McNamee, the EU advocacy coordinator at European Digital Rights, a coalition of privacy groups, notes, "There is a fundamental concern whenever high-level staff or politicians take a corporate position."

"It's true that I worked on privacy in the administration and I continue to work on privacy issues," Weitzner says. "But I believe really strongly that privacy tends to make progress when there are broad coalitions." He says he is not lobbying the Obama administration in any way.

Weitzner is currently the director and cofounder of MIT's Computer Science and Artificial Intelligence Laboratory's Decentralized Information Group. He has also worked as the policy director of the World Wide Web Consortium (which has been criticized for emphasizing voluntary regulation over privacy laws) and cofounded the Center for Democracy and Technology.

"This coalition appears to be a well-oiled campaign driven by the special interests of tech companies."

The Coalition for Privacy and Free Trade was launched on March 18 by Hogan Lovells, an international law firm that has worked with corporations like Apple, IBM, and Amazon, as well as various governments. The coalition's members include legal experts, a former EU ambassador to the United States, and Reagan-era trade representative Clayton Yeutter. Christopher Wolf, director of Hogan Lovells' privacy and information management practice group, says that the coalition is not intended to be comprised solely of tech companies, but instead, "we welcome all companies that collect, use, and transfer personal data." Wolf says the coalition is not ready to announce its members, but will soon.

The coalition plans to participate in the upcoming Transatlantic Free Trade Agreement negotiations, pushing for laws that provide privacy protections like those found in Obama's consumer privacy bill, while also making sure that "excessive" regulations don't inhibit economic growth. Earlier this month, Wolf testified before the US International Trade Commission that one of the big differences between the US and the EU proposals is that the United States still intends to rely on "self-regulation" and won't require companies to report data breaches within 24 hours.

Companies like Google, Yahoo, Facebook, Amazon, and eBay have been spending millions of dollars lobbying against the European Union's attempt to protect internet users' personal information. In January, the EU proposed requiring its member states to let users opt out of targeted advertising and web tracking (similar to what the struggling "Do Not Track" bill proposed by West Virginia Sen. Jay Rockefeller would do). It also proposed giving users the right to erase any of their personal information from the web, meaning that you could ask Facebook to stop holding on to your information even after you delete your profile (Facebook tends to hang on for dear life to your info) or, more controversially, ask Google to remove information from its search results that you plain just don't like.

It's not just tech companies that are trying to weaken the EU proposals: The Department of Commerce is also lobbying the European Parliament. "The Obama administration has been very destructive in the EU privacy discussions so far," says McNamee of European Digital Rights. "It intervened even before the draft regulation was published and put sufficient pressure on the European Commission to have entire swaths of text deleted."

McNamee thinks that the Obama administration will have better luck influencing the EU Commission through the upcoming free-trade negotiations. In a letter the Department of Commerce sent to the Center for Digital Democracy on March 12, Lawrence E. Strickling, assistant secretary for communications and information, acknowledged that discussions about the privacy regulations were taking place between the US government and European governments, but said that they "are not intended to limit the protections that the European law would provide its citizens. Our primary focus is to achieve interoperability between our systems."

Interoperability is the big, snazzy word in these discussions, but what does it mean? Weitzner explains, "I think there's a real opportunity to improve privacy standards both in the US and Europe and do so in a way that keeps the free flow of information on the internet…I want to make sure that we don't end up with a privacy law only because people think a law sounds nice." In other words, interoperability is about finding a way for different privacy frameworks to work together—be it in China or the EU—without necessarily changing the way US corporations do business.

Ben Wizner, director of the ACLU's Speech, Privacy, and Technology Project, notes this could lead to a scenario where "interoperability becomes this race to the bottom, where the weaker protections of the American system are exported to Europe and the world."

But Weitzner says some of the proposals the EU is suggesting, like the "right to be forgotten," could be "very damaging for the right to free expression around the world" because anyone could have the right to erase information from the web that makes them unhappy. He also says that the United States "has a lot of very good, strong privacy practices that US companies are held legally accountable for by the Federal Trade Commission." Wolf agrees: "Tech companies generally know their practices are subject to extreme strict scrutiny by regulators, including the FTC and state attorneys general."

Wizner concurs that the FTC has been "admirably aggressive in enforcing its mandate" but points out that "the FTC mandate is limited—they can only police outright deceit and unfairness. There is no basic privacy law that governs whether those companies can collect information, what information they can collect, and how long they can store it."

Rotenberg, who supervised Weitzner as an intern when they both worked for the Washington, DC, office of Computer Professionals for Social Responsibility, calls the concerns about the Coalition for Privacy and Free Trade "legitimate" but says that "Danny Weitzner should be working to ensure that the White House makes good on its commitment to establish privacy legislation…The fact that the president has made clear his support for stronger privacy laws is very important. I tend to be an optimist."

Monday, February 4, 2013

Congress Will Battle Over Internet Privacy in 2013

Saturday, February 2, 2013 by Deeplinks Blog / EFF  
by Mark M. Jaycox

Last year, we saw more battles in Congress over Internet freedom than we have in many years as user protests stopped two dangerous bills, the censorship-oriented SOPA, and the privacy-invasive Cybersecurity Act of 2012. But Congress ended the year by ramming through a domestic spying bill and weakening the Video Privacy Protection Act.

In 2013, Congress will tackle several bills—both good and bad—that could shape Internet privacy for the next decade. Some were introduced last year, and some will be completely new. For now, here's what's ahead in the upcoming Congress:

Reforming Draconian Computer Crime Law

The Computer Fraud and Abust Act (CFAA), was one of the key laws the government used in its relentless and unjust prosecution of Aaron Swartz. Zoe Lofgren has proposed "Aaron's Law," which ensures that breaking a terms of service or other contractual obligation does not amount to a CFAA violation. Lofgren's reforms are a terrific start and will be introduced in Congress over the coming weeks. EFF has also proposed revisions to Lofgren's language and overall reform to the CFAA that reduces the draconian penalties and clarifies key definitions in the statute. The proposed reforms will go a long way in preventing a similar situation from happening to a freedom fighter like Aaron again. It's unclear where the language stands in the Senate, but Senators like Ron Wyden have voiced support for Lofgren's bill and should take up CFAA reform. You can take action and email your members of Congress to tell them to support reform of the Computer Fraud and Abuse Act here.

Update to the Electronic Communications Privacy Act (ECPA)

Once again, the 113th Congress will try to update the archaic Electronic Communications Privacy Act. The law, which was passed in 1986, lays out procedures for when the government can obtain your private electronic messages, like email or Facebook messages, from service providers. ECPA states that the government doesn’t need a warrant for emails when they are older than 180 days—even though the Sixth Circuit held that this “180-day rule” violates the Fourth Amendment. Despite the ruling, the Justice Department continues to argue that the DOJ does not have to obtain a warrant.

Last Congress Senator Leahy successfully moved the Senate Judiciary Committee to approve an ECPA amendment mandating warrants for all private electronic communications, but the bill didn’t get to the full Senate. This year, both Senator Leahy and House Reps. Goodlatte and Lofgren will introduce similar legislation to ensure that the same protections that apply to physical private messages also apply to virtual private messages.

Congress should take the lead from the courts and move the legislation forward.

Restricting Government and Corporate Use of your Cell Phone GPS Info

Updating ECPA is also about protecting users geolocation information, especially after the Supreme Court’s decision in the GPS case, United States v. Jones. Senator Wyden and Rep. Chaffetz's GPS Act mandates that the government obtain a warrant before it seeks a user's geolocation information. Currently, the government can obtain such information without a warrant or probable cause, which is something the government has done at a staggering rate.

But the government isn't the only entity spying on cell phone users. Over and over, users are learning the hard way that private companies surreptitiously collect information from users' mobile devices and often share that data with unknown third parties. That's why Congressmen like Rep. Markey and Senator Franken introduced legislation last Congress that requires clear notification and disclosures when a company collects and shares user information with third parties. Both Congressmen plan to reintroduce and move the legislation forward in the 113th Congress.

Cybersecurity Legislation

Congressmen are also girding for another fight on Cybersecurity. Along with more warnings of an upcoming "cyber-Pearl Harbor," Congressmen named cybersecurity a priority in 2013 and are planning to reintroduce a new version of an “information sharing” cybersecurity bill called CISPA, which as EFF described at the time, carved a giant and vague “cybersecurity” loophole into all US privacy laws, while alsogranting new powers and legal immunity to companies.

The Internet community helped defeat the Cybersecurity legislation and Congress needs to craft any new bill with the utmost concern for privacy.

FBI Silent About Wanting To “Back Door" the Web

Lastly, there are rumors that the Obama Administration will propose a new Internet surveillance law, which will expand the Communications Assistance to Law Enforcement Act (CALEA), which forces telephone companies to build wiretap-friendly backdoors into all their technology—but not social networks and other web-based communications services.In 2005, the FBI pushed the FCC to rule that VOIP and "facilities-based internet access providers" had to abide by CALEA requirements. Now they want even more power. This expansion is in spite of the fact that the FBI has yet to respond adequately to EFF's FOIA lawsuit seeking records that would justify the need to expand federal surveillance laws, given they have a myriad of ways to get such data already (Google’s transparency report shows the government requests for user data is skyrocketing).

The White House and the FBI have not released what is in the proposed legislation, but one report states the FBI wants to require Internet companies, like Google, Facebook, and Twitter to build the same type of backdoors for real-time government surveillance. This would not only create a huge Internet security problem, making the Internet less safe just as Congress pushes for a cybersecurity bill, but threatens basic privacy on the web.

The potential for the 113th Congress to introduce backwards bills like CISPA and CALEA is great. But Congress, and especially new members, should take note of the Internet community's strong—and successful—opposition to bills like SOPA.

It's time to curry favor with everyday constituents, and not with giant corporations or overreaching law enforcement.

Wednesday, January 23, 2013

Google Report Shows 'Disturbing Growth in Government Surveillance'

Wednesday, January 23, 2013 by Common Dreams
Most recent Transparency Report from web giant reveals 136% increase in user data requests from US since 2009
- Andrea Germanos, staff writer

Google has released its newest semiannual Transparency Report on Wednesday, which shows a "steady increase in government requests" for user data and marks a "disturbing growth in government surveillance online."

The US made 8,438 user data requests during the second half of 2012, a nearly 136% percent increase since 2009. The report from the web giant, which discloses the number of requests it receives from governments and courts worldwide, shows that user data requests are up 70 percent since 2009, with a total of over 21,000 user data requests from over 33,000 users or accounts in the second half of 2012.

The U.S. made the biggest number of requests by far—8,438 during this period, which marks a nearly 136 percent increase since 2009.

Of those U.S. requests, 68% were from subpoenas, as Richard Salgado writes on Google's blog on the report, and "are requests for user-identifying information, issued under the Electronic Communications Privacy Act (ECPA), and are the easiest to get because they typically don’t involve judges."

The Guardian's Dominic Rushe points out how the use of EPCA to get user data is dangerous:
The ECPA has been widely criticised by privacy advocates, and was passed in 1986, long before electronic communication became so common. Under the act, email stored on a third party's server for more than 180 days is considered abandoned. To access that information, officials need only a written statement certifying that the information is relevant to an investigation.

But Holmes Wilson, co-founder of online advocacy group Fight For the Future, said the Justice Department had argued that emails are "abandoned" once they are opened. "Ironically, the emails that now have the most protection are the spam that you never open," he said. "ECPA is under dire need of reform. Right now the government can access almost anything that you have online without a warrant and at anytime. Electronic communication should be afforded the same protection as your physical mail or files stores in a cabinet," he said.

Berin Szoka, president of TechFreedom, says the report "reveals a disturbing growth in government surveillance online," and adds:
On its own, the growth in number of requests for private information like emails should be alarming, especially after the Petreus case. Even more disturbing is that most requests have not been reviewed by a court to ensure that law enforcement has established probable cause to believe a crime has actually been committed, as the Fourth Amendment generally requires.

Today's report doesn't really tell us the full extent of unconstitutional privacy invasions. Law enforcement officials rightly note that they need subpoena access to subscriber information as the 'building blocks' for establishing probable case. They also insist they're already getting warrants for content information, even when ECPA doesn't require that. But we still don't have hard data on either claim. Worse, while large companies like Google may rightly refuse to turn over user data without a warrant, smaller companies without legal staffs may feel compelled to turn over private data with only a subpoena, or perhaps even without one at all.