Showing posts with label right to privacy. Show all posts
Showing posts with label right to privacy. Show all posts

Monday, March 16, 2015

A Police Gadget Tracks Phones? Shhh! It’s Secret

By MATT RICHTEL NYTIMES 
MARCH 15, 2015

A powerful new surveillance tool being adopted by police departments across the country comes with an unusual requirement: To buy it, law enforcement officials must sign a nondisclosure agreement preventing them from saying almost anything about the technology.

Any disclosure about the technology, which tracks cellphones and is often called StingRay, could allow criminals and terrorists to circumvent it, the F.B.I. has said in an affidavit. But the tool is adopted in such secrecy that communities are not always sure what they are buying or whether the technology could raise serious privacy concerns.

The confidentiality has elevated the stakes in a longstanding debate about the public disclosure of government practices versus law enforcement’s desire to keep its methods confidential. While companies routinely require nondisclosure agreements for technical products, legal experts say these agreements raise questions and are unusual given the privacy and even constitutional issues at stake.

“It might be a totally legitimate business interest, or maybe they’re trying to keep people from realizing there are bigger privacy problems,” said Orin S. Kerr, a privacy law expert at George Washington University. “What’s the secret that they’re trying to hide?”

The issue led to a public dispute three weeks ago in Silicon Valley, where a sheriff asked county officials to spend $502,000 on the technology. The Santa Clara County sheriff, Laurie Smith, said the technology allowed for locating cellphones — belonging to, say, terrorists or a missing person. But when asked for details, she offered no technical specifications and acknowledged she had not seen a product demonstration.

Buying the technology, she said, required the signing of a nondisclosure agreement.

“So, just to be clear,” Joe Simitian, a county supervisor, said, “we are being asked to spend $500,000 of taxpayers’ money and $42,000 a year thereafter for a product for the name brand which we are not sure of, a product we have not seen, a demonstration we don’t have, and we have a nondisclosure requirement as a precondition. You want us to vote and spend money,” he continued, but “you can’t tell us more about it.”

The technology goes by various names, including StingRay, KingFish or, generically, cell site simulator. It is a rectangular device, small enough to fit into a suitcase, that intercepts a cellphone signal by acting like a cellphone tower.

The technology can also capture texts, calls, emails and other data, and prosecutors have received court approval to use it for such purposes.

Cell site simulators are catching on while law enforcement officials are adding other digital tools, like video cameras, license-plate readers, drones, programs that scan billions of phone records and gunshot detection sensors. Some of those tools have invited resistance from municipalities and legislators on privacy grounds.

The nondisclosure agreements for the cell site simulators are overseen by the Federal Bureau of Investigation and typically involve the Harris Corporation, a multibillion-dollar defense contractor and a maker of the technology. What has opponents particularly concerned about StingRay is that the technology, unlike other phone surveillance methods, can also scan all the cellphones in the area where it is being used, not just the target phone.

“It’s scanning the area. What is the government doing with that information?” said Linda Lye, a lawyer for the American Civil Liberties Union of Northern California, which in 2013 sued the Justice Department to force it to disclose more about the technology. In November, in a response to the lawsuit, the government said it had asked the courts to allow the technology to capture content, not just identify subscriber location.

The nondisclosure agreements make it hard to know how widely the technology has been adopted. But news reports from around the country indicate use by local and state police agencies stretching from Los Angeles to Wisconsin to New York, where the state police use it. Some departments have used it for several years. Money for the devices comes from individual agencies and sometimes, as in the case of Santa Clara County, from the federal government through Homeland Security grants.

Christopher Allen, an F.B.I. spokesman, said “location information is a vital component” of law enforcement. The agency, he said, “does not keep repositories of cell tower data for any purpose other than in connection with a specific investigation.”

A fuller explanation of the F.B.I.’s position is provided in two publicly sworn affidavits about StingRay, including one filed in 2014 in Virginia. In the affidavit, a supervisory special agent, Bradley S. Morrison, said disclosure of the technology’s specifications would let criminals, including terrorists, “thwart the use of this technology.”

“Disclosure of even minor details” could harm law enforcement, he said, by letting “adversaries” put together the pieces of the technology like assembling a “jigsaw puzzle.” He said the F.B.I. had entered into the nondisclosure agreements with local authorities for those reasons. In addition, he said, the technology is related to homeland security and is therefore subject to federal control.

In a second affidavit, given in 2011, the same special agent acknowledged that the device could gather identifying information from phones of bystanders. Such data “from all wireless devices in the immediate area of the F.B.I. device that subscribe to a particular provider may be incidentally recorded, including those of innocent, nontarget devices.”

But, he added, that information is purged to ensure privacy rights.

In December, two senators, Patrick J. Leahy and Charles E. Grassley, sent a letter expressing concerns about the scope of the F.B.I.’s StingRay use to Eric H. Holder Jr., the attorney general, and Jeh Johnson, the secretary of Homeland Security.

The Harris Corporation declined to comment, according to Jim Burke, a company spokesman. Harris, based in Melbourne, Fla., has $5 billion in annual sales and specializes in communications technology, including battlefield radios.

Jon Michaels, a law professor at the University of California, Los Angeles, who studies government procurement, said Harris’s role with the nondisclosure agreements gave the company tremendous power over privacy policies in the public arena.

“This is like the privatization of a legal regime,” he said. Referring to Harris, he said: “They get to call the shots.”

For instance, in Tucson, a journalist asking the Police Department about its StingRay use was given a copy of a nondisclosure agreement. “The City of Tucson shall not discuss, publish, release or disclose any information pertaining to the product,” it read, and then noted: “Without the prior written consent of Harris.”

The secrecy appears to have unintended consequences. A recent article in The Washington Post detailed how a man in Florida who was accused of armed robbery was located using StingRay.

As the case proceeded, a defense lawyer asked the police to explain how the technology worked. The police and prosecutors declined to produce the machine and, rather than meet a judge’s order that they do so, the state gave the defendant a plea bargain for petty theft.

At the meeting in Santa Clara County last month, the county supervisors voted 4 to 1 to authorize the purchase, but they also voted to require the adoption of a privacy policy.

(Sheriff Smith argued to the supervisors that she had adequately explained the technology and said she resented that Mr. Simitian’s questioning seemed to “suggest we are not mindful of people’s rights and the Constitution.”)

A few days later, the county asked Harris for a demonstration open to county supervisors. The company refused, Mr. Simitian said, noting that “only people with badges” would be permitted. Further, he said, the company declined to provide a copy of the nondisclosure agreement — at least until after the demonstration.“Not only is there a nondisclosure agreement, for the time being, at least, we can’t even see the nondisclosure agreement,” Mr. Simitian said. “We may be able to see it later, I don’t know.”

Thursday, February 6, 2014

'I Want Them To Be Worried We’re Watching... To Never Know When We’re Overhead.'


Law enforcement push 'persistent surveillance' monitoring systems

- Jon Queally, staff writer 
 
 
(Promotional image: Persistent Surveillance Systems)“I want them to be worried that we’re watching.
I want them to be worried that they never know when we’re overhead.”


'I Want Them To Be Worried We’re Watching... 
To Never Know When We’re Overhead.'
That's what Police Chief Richard Biehl of Dayton, Ohio told the Washington Post while referring to the people of his city as he supported new aerial surveillance technology that would allow his officers to "track every vehicle and person across an area the size of a small city, for several hours at a time."

Focused on the work of Persistent Surveillance Systems—a Dayton-based company that is already providing aerial surveillance for large events, like political rallies and sporting events—the Post's reporting reveals that even as "Americans have grown increasingly comfortable with traditional surveillance cameras, a new, far more powerful generation is being quietly deployed."

For its part, Persistent Surveillance bills itself as a "full-service, wide area surveillance provider" that sells its capabilities to law enforcement agencies, border patrol, and others private firms. According to the company's website, their signature "Hawkeye II" surveillance system "is similar to a live version of Google-Earth—only with a TiVo-like capability" and provides:
Wide-Area Surveillance Sensors and Services that enable continuous, second-by-second video monitoring of a city-sized area. Because of the very high-resolution nature of PSS's sensors (up to 200 megapixels), vehicle and pedestrian activity can be tracked over a 16 square-mile area. If an event-of-interest happens within this area (a murder, for example), users can rewind the event to identify the perpetrator's place-of-origin, meeting locations, accomplices, driving routes, and final destination.
 
 (Click for larger image. Source: WaPo) 

According to the Post:
Already, the cameras have been flown above major public events such as the Ohio political rally where Sen. John McCain (R-Ariz.) named Sarah Palin as his running mate in 2008, McNutt said. They’ve been flown above Baltimore; Philadelphia; Compton, Calif.; and Dayton in demonstrations for police. They’ve also been used for traffic impact studies, for security at NASCAR races and at the request of a Mexican politician.
Predictably, those in favor of the hovering surveillance technology, like Police Chief Biehl and the company's president Ryan McNutt, say the whole purpose of the 'unblinking eye-in-the-sky' is to solve crimes or prevent them from happening. And as McNutt explained, he envisions his companies technology not just attached to small planes, as they are now, but to ones with longer and wider ranges as well. He also thinks fixed surveillance units could "protect" large areas, boasting to the Post that "a single camera mounted atop the Washington Monument [...] could deter crime all around the [Natioanal] Mall."

But privacy advocates contend this is just another creepy development in the evolution of the 'Big Brother' society that George Orwell warned about and the National Security Agency has helped turn into a global enterprise.

“There are an infinite number of surveillance technologies that would help solve crimes . . . but there are reasons that we don’t do those things, or shouldn’t be doing those things,” said Joel Pruce, a University of Dayton postdoctoral fellow in human rights who opposed the use of the surveillance aircraft in Ohio supported by Biehl.

And Jay Stanley, a privacy expert with the American Civil Liberties Union, told the Post:  

“If you turn your country into a totalitarian surveillance state, there’s always some wrongdoing you can prevent. The balance struck in our Constitution tilts toward liberty, and I think we should keep that value.”

Friday, November 1, 2013

The Corporate State of Surveillance

Opting Out
by RALPH NADER

America was founded on the ideals of personal liberty, freedom and democracy. Unfortunately, mass spying, surveillance and the unending collection of personal data threaten to undermine civil liberties and our privacy rights. What started as a necessary means of reconnaissance and intelligence gathering during World War II has escalated into an out-of-control snoop state where entities both governmental and commercial are desperate for as much data as they can grab. We find ourselves in the midst of an all-out invasion on what’s-none-of-their-business and its coming from both government and corporate sources. Snooping and data collection have become big business. Nothing is out of their bounds anymore.

The Patriot Act-enabled National Security Agency (NSA) certainly blazed one trail. The disclosures provided by Edward Snowden has brought into light the worst fears that critics of the overwrought Patriot Act expressed back in 2001. The national security state has given a blank check to the paranoid intelligence community to gather data on nearly everyone. Internet and telephone communications of millions of American citizens and millions more citizens and leaders of other countries. Even friendly ones such as Germany, France and Brazil have been surveillance targets –over 30 foreign leaders such as German Chancellor Angela Merkel and Brazilian president Dilma Rousseff have reportedly been targeted by this dragnet style data-collecting. More blatantly, covert devices were reportedly placed in European Union offices and earlier by Hillary Clinton’s State Department on the United Nations to eavesdrop on diplomats. World leaders are not pleased, to put it mildly.

Many Americans are not pleased either. And while most of the recent public outrage in the U.S. has been directed at instances of government snooping, giant private corporations are equally as guilty of the troubling invasion of peoples’ selves. Companies such as Google, Apple, Microsoft and Facebook blatantly collect and commercialize personal data — often covering their tracks with complicated fine-print user agreement contracts that most people, whose property it is, “agree” to without any consideration. Clicking “I agree” on an expansive, non-negotiable user agreement for a website or a software program is, to most people, just another mindless click of the mouse in the signup process.

These “take-it-or-leave-it” contracts leave the consumer with little power to protect their own interest. (See here for our extensive work on this issue. Also, visit “Terms of Service; Didn’t Read” for a valuable resource that summarizes and reviews online contracts so that users can have a better understanding of what they are agreeing to.)

Just last week, news broke that Google plans to roll out a new advertising feature called “Shared Endorsements.” This policy allows Google the right to create user endorsements in online advertisements. So, if a Googler happens to share their preference for a particular product online, his or her endorsement might end up featured in an ad without any notice or compensation. Of course, users are welcome to “opt-out” of this program — but how many millions will remain ignorant of the fact that they unwillingly opted-in by clicking their consent to contract terms they did not bother to read out of habit. (Google’s official statement claims the move is to “ensure that your recommendations reach the people you care about.”)

Opting-out should be the default option for all these types of agreements.

School children are also being targeted by mass data collectors. InBloom, a nonprofit organization based in Atlanta, offers a database solution for student records between grades K-12. In theory, this service is supposed to make it easier for teachers to utilize emerging educational products and tools. But in practice, many parents are concerned about how this data will be used — in one instance, for example, student social security numbers were uploaded to the service. One parent told the New York Times:
It’s a new experiment in centralizing massive metadata on children to share with vendors… and then the vendors will profit by marketing their learning products, their apps, their curriculum materials, their video games, back to our kids.

Facebook poses another data mining risk for young children. Although Facebook does not currently allow children younger than 13 to join — the Children’s Online Privacy Protection Act prevents the online collection of data of children without parental permission — reportedly more than five million underage children use the social media website anyway. This exposes them (and their personal information) to thousands of advertisers that use Facebook to collect marketing data and promote their products. See the Center for Digital Democracy’s recent report “Five Reasons Why Facebook is Not Suitable For Children Under 13.” Notably, Facebook recently changed their privacy policy to allow teenagers between the ages of 13 and 17 to opt-in to sharing their postings with the entire world, as opposed to just their “friend network.”

The insatiable appetite for data is reaching beyond the digital realm, as well.

The Washington Post recently reported that Mondelez International, the company behind snack brands like Chips Ahoy and Ritz, has plans to deploy electronic camera sensors in snack food shelves to collect shopper data. These “smart shelves” can scan and save a customer’s facial structure, age, weight and even detect if they picked something up off the shelf. The device can then use that gathered data to target the consumers with “personalized ads.” For example, at the checkout line, a video screen might offer you 10 percent off the box of cookies you picked up but ultimately chose not to purchase. The Post reports: “The company expects the shelf to help funnel more of the right products to the right consumers, and even convince undecideds to commit to an impulse buy.”

The smart shelf builds on the Microsoft “Kinect” camera technology, which has the ability to scan and remember faces, detect movement and even read heart beats. Microsoft developed the Kinect camera as a video game control device for the home. In light of Microsoft’s reported connection to the NSA PRISM data gathering program, why would anyone willingly bring such a sophisticated spy cam into their living room?

Along the same lines, certain retailers are using smart phones to track the movement of customers in their store to gather information on what products they look at and for how long — similar to how Amazon tracks online shopper habits so it can direct them to other products that algorithms determine they might be interested in. Sen. Chuck Schumer (D-NY) has called on the Federal Trade Commission to regulate this disturbing practice. He recently announced a deal with eight analytic companies to institute a “code of conduct” for utilizing this seemingly Orwellian technology. Sen. Schumer told the Associated Press: “When you go into your store for your Christmas shopping, there’ll be a sign out there that says that you’re being tracked and if you don’t want to be, you can very simply opt out.” The details on how exactly one opts-out of this invasive technology, short of leaving their cell phone at home, is not yet clear.

With all these instances of Big Brother encroachment, one might want to opt out of the digital world entirely, and avoid supermarkets and retail chains that spy on customers. Unfortunately, that is becoming more and more difficult in an increasingly technology-obsessed world.

It’s time for citizens to stand up and demand their right to privacy, which is a personal property. Mass surveillance and rampant data collection are not acceptable and should not be the status quo. Recall that there was once a time when the federal government could defend our nation without limitless access to computer records, emails, online search histories and wiretapping phone calls without open judicial authorization. Businesses could be successful without tracking and saving your shopping habits and student records were not commodities to be traded away. Why do they now do what they do? Because they can.

Remember, what you allow to be taken from you by the private companies can also end up in the files of government agencies.

This Saturday, a coalition of groups including the ACLU, Public Citizen, the Electronic Privacy Information Center (EPIC), the Libertarian Party and many more are gathering on the National Mall to protest mass surveillance by the National Security Agency. This is a positive first step in letting our elected officials know that ceasing the collection of private personal information about you is important and mass surveillance should be prohibited. Visit here for more information about this weekend’s rally. Join the movement to end these burgeoning, tyranny-building abuses by runaway federal agencies.

Friday, September 6, 2013

New NSA Revelations: Internet Privacy Encryption Virtually 'Defeated'

Thursday, September 5, 2013 by Common Dreams
NSA builds 'industry relationships' to control encryption technologies, deteriorate privacy safeguards
- Jacob Chamberlain, staff writer

Internet privacy safeguards known as encryption technologies promised by email, online banking, and other such online databases have been virtually 'defeated' by the U.S. National Security Agency, according to new documents obtained by the Guardian, New York Times, and ProPublica.

According to the Guardian—which has reported extensively on the NSA's dragnet surveillance practices revealed by NSA whistleblower Edward Snowden—the NSA and its British counterparts the GCHQ have used "covert measures" to control and manipulate international encryption standards to tprivacyhe benefit of the NSA, largely through building "industry relationships" with many technology companies and internet service providers.

As joint reporting by ProPublica and the New York Times explains, according to the documents and interviews with industry officials, the NSA has deployed "custom-built, superfast computers to break codes" and began collaborating with "technology companies in the United States and abroad" to build 'backdoor' entry points into their products and introduce weaknesses into their encryption standards.

The records do not identify which specific companies have been working with the NSA to this extent. However, one document does reveal that a GCHQ team has been working to develop ways into encrypted traffic on the "big four" service providers, named as Hotmail, Google, Yahoo and Facebook.

"By deliberately undermining online security in a short-sighted effort to eavesdrop, the NSA is undermining the very fabric of the internet."

Through these relationships the NSA has become nearly immune to most encryption technologies, and has thus mastered the use of "supercomputers" to break encryption with "brute force," leaving a dying number of encryption technologies immune to NSA surveillance.

As one of the NSA documents obtained by the news agencies states, the NSA "actively engages US and foreign IT industries to covertly influence and/or overtly leverage their commercial products' designs," and in turn inserts "vulnerabilities into commercial encryption systems."

"US and British intelligence agencies have successfully cracked much of the online encryption relied upon by hundreds of millions of people to protect the privacy of their personal data, online transactions and emails," the Guardian reports.

"For the past decade, NSA has lead [sic] an aggressive, multi-pronged effort to break widely used internet encryption technologies," a 2010 GCHQ document states. "Vast amounts of encrypted internet data which have up till now been discarded are now exploitable."

"Cryptography forms the basis for trust online," said Bruce Schneier, an encryption specialist and fellow at Harvard's Berkman Center for Internet and Society. "By deliberately undermining online security in a short-sighted effort to eavesdrop, the NSA is undermining the very fabric of the internet."

The NSA's encryption busting program called "Sigint [signals intelligence] enabling" received $254.9 million in 2013 alone (compared to $20 million allotted to the previously exposed PRISM program).

“The encryption technologies that the NSA has exploited to enable its secret dragnet surveillance are the same technologies that protect our most sensitive information, including medical records, financial transactions, and commercial secrets,” stated Christopher Soghoian, principal technologist of the ACLU’s Speech, Privacy and Technology Project.

Soghoian continues:
Even as the NSA demands more powers to invade our privacy in the name of cybersecurity, it is making the internet less secure and exposing us to criminal hacking, foreign espionage, and unlawful surveillance. The NSA’s efforts to secretly defeat encryption are recklessly shortsighted and will further erode not only the United States’ reputation as a global champion of civil liberties and privacy but the economic competitiveness of its largest companies.

Saturday, May 4, 2013

Are all telephone calls recorded and accessible to the US government?

A former FBI counterterrorism agent claims on CNN that this is the case
by Glenn Greenwald
guardian.co.uk, Saturday 4 May 2013



The real capabilities and behavior of the US surveillance state are almost entirely unknown to the American public because, like most things of significance done by the US government, it operates behind an impenetrable wall of secrecy. But a seemingly spontaneous admission this week by a former FBI counterterrorism agent provides a rather startling acknowledgment of just how vast and invasive these surveillance activities are.

Over the past couple days, cable news tabloid shows such as CNN's Out Front with Erin Burnett have been excitingly focused on the possible involvement in the Boston Marathon attack of Katherine Russell, the 24-year-old American widow of the deceased suspect, Tamerlan Tsarnaev. As part of their relentless stream of leaks uncritically disseminated by our Adversarial Press Corps, anonymous government officials are claiming that they are now focused on telephone calls between Russell and Tsarnaev that took place both before and after the attack to determine if she had prior knowledge of the plot or participated in any way.

On Wednesday night, Burnett interviewed Tim Clemente, a former FBI counterterrorism agent, about whether the FBI would be able to discover the contents of past telephone conversations between the two. He quite clearly insisted that they could:
BURNETT: Tim, is there any way, obviously, there is a voice mail they can try to get the phone companies to give that up at this point. It's not a voice mail. It's just a conversation. There's no way they actually can find out what happened, right, unless she tells them?

CLEMENTE: "No, there is a way. We certainly have ways in national security investigations to find out exactly what was said in that conversation. It's not necessarily something that the FBI is going to want to present in court, but it may help lead the investigation and/or lead to questioning of her. We certainly can find that out.

BURNETT: "So they can actually get that? People are saying, look, that is incredible.

CLEMENTE: "No, welcome to America. All of that stuff is being captured as we speak whether we know it or like it or not."

"All of that stuff" - meaning every telephone conversation Americans have with one another on US soil, with or without a search warrant - "is being captured as we speak".

On Thursday night, Clemente again appeared on CNN, this time with host Carol Costello, and she asked him about those remarks. He reiterated what he said the night before but added expressly that "all digital communications in the past" are recorded and stored:

Let's repeat that last part: "no digital communication is secure", by which he means not that any communication is susceptible to government interception as it happens (although that is true), but far beyond that: all digital communications - meaning telephone calls, emails, online chats and the like - are automatically recorded and stored and accessible to the government after the fact. To describe that is to define what a ubiquitous, limitless Surveillance State is.

There have been some previous indications that this is true. Former AT&T engineer Mark Klein revealed that AT&T and other telecoms had built a special network that allowed the National Security Agency full and unfettered access to data about the telephone calls and the content of email communications for all of their customers. Specifically, Klein explained "that the NSA set up a system that vacuumed up Internet and phone-call data from ordinary Americans with the cooperation of AT&T" and that "contrary to the government's depiction of its surveillance program as aimed at overseas terrorists . . . much of the data sent through AT&T to the NSA was purely domestic." But his amazing revelations were mostly ignored and, when Congress retroactively immunized the nation's telecom giants for their participation in the illegal Bush spying programs, Klein's claims (by design) were prevented from being adjudicated in court.

That every single telephone call is recorded and stored would also explain this extraordinary revelation by the Washington Post in 2010:


Every day, collection systems at the National Security Agency intercept and store 1.7 billion e-mails, phone calls and other types of communications.

It would also help explain the revelations of former NSA official William Binney, who resigned from the agency in protest over its systemic spying on the domestic communications of US citizens, that the US government has "assembled on the order of 20 trillion transactions about US citizens with other US citizens" (which counts only communications transactions and not financial and other transactions), and that "the data that's being assembled is about everybody. And from that data, then they can target anyone they want."

Despite the extreme secrecy behind which these surveillance programs operate, there have been periodic reports of serious abuse. Two Democratic Senators, Ron Wyden and Mark Udall, have been warning for years that Americans would be "stunned" to learn what the US government is doing in terms of secret surveillance.

Strangely, back in 2002 - when hysteria over the 9/11 attacks (and thus acquiescence to government power) was at its peak - the Pentagon's attempt to implement what it called the "Total Information Awareness" program (TIA) sparked so much public controversy that it had to be official scrapped. But it has been incrementally re-instituted - without the creepy (though honest) name and all-seeing-eye logo - with little controversy or even notice.

Back in 2010, worldwide controversy erupted when the governments of Saudi Arabia and the United Arab Emirates banned the use of Blackberries because some communications were inaccessible to government intelligence agencies, and that could not be tolerated. The Obama administration condemned this move on the ground that it threatened core freedoms, only to turn around six weeks later and demand that all forms of digital communications allow the US government backdoor access to intercept them. Put another way, the US government embraced exactly the same rationale invoked by the UAE and Saudi agencies: that no communications can be off limits. Indeed, the UAE, when responding to condemnations from the Obama administration, noted that it was simply doing exactly that which the US government does:
"'In fact, the UAE is exercising its sovereign right and is asking for exactly the same regulatory compliance - and with the same principles of judicial and regulatory oversight - that Blackberry grants the US and other governments and nothing more,' [UAE Ambassador to the US Yousef Al] Otaiba said. 'Importantly, the UAE requires the same compliance as the US for the very same reasons: to protect national security and to assist in law enforcement.'"

That no human communications can be allowed to take place without the scrutinizing eye of the US government is indeed the animating principle of the US Surveillance State. Still, this revelation, made in passing on CNN, that every single telephone call made by and among Americans is recorded and stored is something which most people undoubtedly do not know, even if the small group of people who focus on surveillance issues believed it to be true (clearly, both Burnett and Costello were shocked to hear this).

Some new polling suggests that Americans, even after the Boston attack, are growing increasingly concerned about erosions of civil liberties in the name of Terrorism. Even those people who claim it does not matter instinctively understand the value of personal privacy: they put locks on their bedroom doors and vigilantly safeguard their email passwords. That's why the US government so desperately maintains a wall of secrecy around their surveillance capabilities: because they fear that people will find their behavior unacceptably intrusive and threatening, as they did even back in 2002 when John Poindexter's TIA was unveiled.

Mass surveillance is the hallmark of a tyrannical political culture. But whatever one's views on that, the more that is known about what the US government and its surveillance agencies are doing, the better. This admission by this former FBI agent on CNN gives a very good sense for just how limitless these activities are.

Sunday, May 6, 2012

Life Under Constant Watch

The Surveillance State
by FIRMIN DeBRABANDER

The surveillance state expands. Since 9-11, our phones are subject to warrantless wiretaps. Our email and internet transactions leave a trail for some to follow. The police can access our GPS location data through our smart phones, also without a warrant. Retailers record our purchasing habits with painstaking detail. Apparently, Target studies those purchases to determine when customers are pregnant—in the second trimester no less—for specialized marketing purposes.

And now, there will be surveillance drones. Congress recently passed a bill that opens the gates to widespread use of surveillance drones on US soil. There has been relatively little coverage of this alarming development: drones, so far associated with our illegal war in Pakistan and Yemen, are soon to become a domestic mainstay. On our shores, they will be used for law enforcement and border protection, but also commercially, for real estate, entertainment and journalistic purposes, for example. One prominent drone showcased on the internet is a hummingbird drone. As the name suggests, it’s tiny, quick and highly mobile. A popular video shows the hummingbird drone entering a building and flying down a corridor, transmitting everything it sees. Imagine the possibilities.

What is the effect of all this lost privacy? How does it change our behavior? Because surely it does; we are apt to behave differently when we feel we are alone or watched. What will our personal lives be like as so much more of them is made public?

In his book Discipline and Punish, the French philosopher Michel Foucault argues that constant surveillance has a devastating effect. It’s a subtle form of oppression.

When we feel we are being watched, we are more self-conscious of our behavior, more likely to watch what we do and conform to what we think the surveyors want or expect. The hawks among us say this is a good thing: if you’re doing nothing wrong, what do you have to fear from a hummingbird drone? But it’s not as simple as that.

Constant surveillance, Foucault maintained, can be a kind of torture—a revelation implemented by 19th century prison architects. It’s also ideal for authoritarian government in that it’s a highly efficient form of power: authority doesn’t need to coerce individuals physically to behave a certain way; surveillance inserts authority’s eye inside the individual, and he monitors himself. Surveillance enables power to be anonymous, Foucault says, which is especially devastating. You don’t know exactly why you are being watched, or exactly what’s expected of you, and ultimately cultivates a kind of inbred paranoia where you are unsure and timid about everything you do.

Further, Foucault suggests, surveillance that is widely established in society softens the ground for overt political oppression, because it makes us less resistant to breaches of our rights.

This thought occurred to me following the Supreme Court’s recent 5-4 decision to uphold the right of prison officials to strip-search anyone entering a prison facility, no matter how minor the offense. In the case in question, a man was strip-searched after being arrested for an unpaid fine; his arrest was mistaken—he had already paid the fine. The Supreme Court defended the right to strip-search him anyway. Clearly this would seem to undermine our cherished notion of presumed innocence, and it grievously offends our personal dignity. But such galling invasions of privacy, and disregard for personal dignity, become increasingly acceptable when we are already accustomed to them more broadly—all the time, in subtle ways.

The political problem with all this surveillance is obvious, if we’d care to admit it. The political authorities have so much more access to the details of our lives, and in the wrong hands, could do real harm. The only thing protecting us is the character of those in power who collect all this information—and swear they will do nothing objectionable with it. Regarding the new National Defense Authorization Act, which sanctions the president’s power to detain indefinitely or even assassinate US citizens suspected of involvement in terrorist organizations, Obama tried to allay fears by arguing that his administration will use discretion and judgment in exercising this power. What about subsequent administrations? Our founding fathers were highly concerned to design a government that was impervious to corruption by the character flaws of individual office holders. The War on Terror has steadily rendered us vulnerable to just that.

What is perhaps most remarkable in all this is how we are largely unperturbed by the growing surveillance state. Indeed, we jump headlong into these new technologies that allow us to be watched. The ACLU is like a voice in the wilderness screaming about civil rights threats, but we’re too busy shopping online, sharing intimate personal details on Facebook, Tweeting our most mundane revelations.

When I raise these concerns with my students, some consider them overly alarmist. Most are unfazed. I pressed them on this recently, and one student pointed out that they were 10 years old when the Patriot Act was implemented following the 9-11 attacks. They have also spent half their lives with the internet, email and smartphones, and so, have known nothing else. In short, surveillance is their norm.

And they have known only benevolent, or at least innocuous, surveillance to date. Does this mean they trust the powers that know so much about them, and could do so much with that knowledge? When I ask that question, the response is almost universally negative. They have very little confidence in the ruling parties—and that’s a view shared by populations across the spectrum. So what’s going on? Why are we giving so much information—and ultimately power—to authorities we have such little confidence in?

There are a variety of factors at work here. On one hand, you might say, we’re just lazy, or too enamored with new technologies, to worry about who is watching us and why. Alternately, as Boston College sociologist Juliet Schor has argued, we are a society increasingly suffering from ‘time poverty’: we work long hours, commute long distances, ferry our kids to and from countless activities, and in our frenzy, have come to rely on the multiple conveniences offered by the new technology that helps us get through our frantic schedules. In general, these new media are so fully integrated into our lives that we simply can’t imagine living without them. They have gotten us accustomed to levels of convenience such as we’ve never known before—a convenience directly proportionate to the amount personal information we surrender.

Underlying all of this, however, is something I have thought about for a while. As a society, we have lost sight of the significance of privacy, and that it is essential to freedom—and democracy. We willingly give up our privacy in the belief that our freedom remains untouched through it all. Indeed, in a War on Terror, forgoing our privacy seems like an easy sacrifice, especially when you get the wondrous conveniences of all the new media in return. But freedom without privacy, Foucault points out, is no freedom at all.

The more we are watched, he argues, we come to feel less free to be unique, quirky, sometimes eccentric individuals. Surveillance exerts a covert pressure. Under constant surveillance, we are more prone to conform, less liable to ask vexing social questions that might draw attention to ourselves and upset someone—who? We are less inclined to develop our own ideas and opinions, work them out in our thoughts and words, test them in public venues—and stick to them. We become more careful, less likely to take chances and engage in risky behavior. But democracy requires creative, independent, fearless individualism.

There is no halting the progress of technology, a progress that has become frighteningly quick in the digital age. However, this in itself is no excuse to accept a looming profusion of hummingbird drones on our streets and in our neighborhoods. The surveillance drones will come, to be sure, but we must watch them in turn—and the watchers. It starts when we recall that privacy is an essential good, an inalienable and non-negotiable right, as the authors of our Constitution—in an age very far removed from our technologies—once understood very well.

Wednesday, April 4, 2012

Even worse than SOPA: New CISPA cybersecurity bill will censor the Web

Published: 04 April, 2012 - RT
An onrush of condemnation and criticism kept the SOPA and PIPA acts from passing earlier this year, but US lawmakers have already authored another authoritarian bill that could give them free reign to creep the Web in the name of cybersecurity.

As congressmen in Washington consider how to handle the ongoing issue of cyberattacks, some legislators have lent their support to a new act that, if passed, would let the government pry into the personal correspondence of anyone of their choosing.

H.R. 3523, a piece of legislation dubbed the Cyber Intelligence Sharing and Protection Act (or CISPA for short), has been created under the guise of being a necessary implement in America’s war against cyberattacks. But the vague verbiage contained within the pages of the paper could allow Congress to circumvent existing exemptions to online privacy laws and essentially monitor, censor and stop any online communication that it considers disruptive to the government or private parties. Critics have already come after CISPA for the capabilities that it will give to seemingly any federal entity that claims it is threatened by online interactions, but unlike the Stop Online Privacy Act and the Protect IP Acts that were discarded on the Capitol Building floor after incredibly successful online campaigns to crush them, widespread recognition of what the latest would-be law will do has yet to surface to the same degree.

Kendall Burman of the Center for Democracy and Technology tells RT that Congress is currently considering a number of cybersecurity bills that could eventually be voted into law, but for the group that largely advocates an open Internet, she warns that provisions within CISPA are reason to worry over what the realities could be if it ends up on the desk of President Barack Obama. So far CISPA has been introduced, referred and reported by the House Permanent Select Committee on Intelligence and expects to go before a vote in the first half of Congress within the coming weeks.

“We have a number of concerns with something like this bill that creates sort of a vast hole in the privacy law to allow government to receive these kinds of information,” explains Burman, who acknowledges that the bill, as written, allows the US government to involve itself into any online correspondence, current exemptions notwithstanding, if it believes there is reason to suspect cyber crime. As with other authoritarian attempts at censorship that have come through Congress in recent times, of course, the wording within the CISPA allows for the government to interpret the law in such a number of degrees that any online communication or interaction could be suspect and thus unknowingly monitored.

In a press release penned last month by the CDT, the group warned then that CISPA allows Internet Service Providers to “funnel private communications and related information back to the government without adequate privacy protections and controls.

The bill does not specify which agencies ISPs could disclose customer data to, but the structure and incentives in the bill raise a very real possibility that the National Security Agency or the DOD’s Cybercommand would be the primary recipient,” reads the warning.

The Electronic Frontier Foundation, another online advocacy group, has also sharply condemned CISPA for what it means for the future of the Internet. “It effectively creates a ‘cybersecurity'’ exemption to all existing laws,” explains the EFF, who add in a statement of their own that “There are almost no restrictions on what can be collected and how it can be used, provided a company can claim it was motivated by ‘cybersecurity purposes.’”

What does that mean? Both the EFF and CDT say an awfully lot. Some of the biggest corporations in the country, including service providers such as Google, Facebook, Twitter or AT&T, could copy confidential information and send them off to the Pentagon if pressured, as long as the government believes they have reason to suspect wrongdoing. In a summation of their own, the Congressional Research Service, a nonpartisan arm of the Library of Congress, explains that “efforts to degrade, disrupt or destroy” either “a system or network of a government or private entity” is reason enough for Washington to reach in and read any online communiqué of their choice.

The authors of CISPA say the bill has been made “To provide for the sharing of certain cyber threat intelligence and cyber threat information between the intelligence community and cybersecurity entities,” but not before noting that the legislation could be used “and for other purposes,” as well — which, of course, are not defined.

“Cyber security, when done right and done narrowly, could benefit everyone,” Burman tells RT. “But it needs to be done in an incremental way with an arrow approach, and the heavy hand that lawmakers are taking with these current bills . . . it brings real serious concerns.”

So far CISPA has garnered support from over 100 representatives in the House who are favoring this cybersecurity legislation without taking into considerations what it could do to the everyday user of the Internet. And while the backlash created by opponents of SOPA and PIPA has not materialized to the same degree yet, Burman warns Congress that it could be only a matter of time before concerned Americans step up to have their say.

“One of the lessons we learned in the reaction to SOPA and PIPA is that when Congress tries to legislate on things that are going to affect Internet users’ experience, the Internet users are going to pay attention,” says Burman. H.R. 3523, she cautions, “Definitely could affect in a very serious way the internet experience.” Luckily, adds Burman, “People are starting to notice.” Given the speed that the latest censorship bill could sneak through Congress, however, anyone concerned over the future of the Internet should be on the lookout for CISPA as it continues to be considered on Capitol Hill.

Tuesday, March 20, 2012

Here's Your Job Application. Now Give Us Your Facebook Password

Tuesday, March 20, 2012 by Common Dreams
Employers asking for employees' Facebook passwords; ACLU calls it "gross breach of privacy"

Some companies and government agencies are demanding Facebook passwords from prospective employees during job interviews. Civil liberties advocates including the ACLU have slammed the practice as a violation of privacy. Unfortunately, for many who are unemployed or under-employed, the pressure to submit to such a request may be high.

Orin Kerr, a George Washington University law professor and former federal prosecutor, told the Associated Press, "It's akin to requiring someone's house keys," and called it "an egregious privacy violation."

Frederic Wolens, a Facebook spokesperson, gave a statement to MSNBC indicating that an employer asking for a prospective employee's login information would violate the terms of Facebook. "Under our terms, only the holder of the email address and password is considered the Facebook account owner. We also prohibit anyone from soliciting the login information or accessing an account belonging to someone else."

Students have not been immune to this privacy invasion either. A minor student in Minnesota was coerced into giving her Facebook and email login information to school authorities, prompting a lawsuit from the ACLU-Minnesota.

* * *


The Daily Mail: Revealed: How colleges and employers ask for candidates' Facebook and email passwords during job interviews
Rather than trying to get around the pesky password protections of Facebook and email accounts, certain government agencies and colleges are cutting straight to the source.
Some extremely inquisitive employers are asking candidates to hand over to them their email and Facebook login information when they apply for a job.

Others strongly request that the candidate opens their pages in front of them and allow their would-be bosses to scroll through their private information during the interview. [...]

They say that while ‘shoulder surfing’, as the practice is called, may technically be voluntary, the vast majority of applicants feel obligated to open up their lives to their employers or risk losing the job.
* * *


Alexis Madrigal: The Atlantic
Should Employers Be Allowed to Ask for Your Facebook Login?
The ACLU calls this policy "a frightening and illegal invasion of privacy" and I can't say that I disagree. Keep in mind that this isn't looking at what you've posted to a public Twitter account; the government agency here could look through private Facebook messages, which seems a lot like reading through your mail, paper or digital.


* * *


Meredith Curtis: ACLU
Want a job? Password, please!
Maryland corrections officer Robert Collins approached the ACLU of Maryland late last year, disturbed that he was required to provide his Facebook login and password to the Maryland Division of Corrections (DOC) during a recertification interview. He had to sit there while the interviewer logged on to his account and read not only his postings, but those of his family and friends too.

"We live in a time when national security is the highest priority, but it must be delicately balanced with personal privacy," said Collins. "My fellow officers and I should not have to allow the government to view our personal Facebook posts and those of our friends, just to keep our jobs." [...]

The demand for Facebook login information is not only a gross breach of privacy for Officer Collins and his friends, it raises significant legal concerns under the Federal Stored Communications Act and Maryland state law, which protect privacy rights and extend protections to electronic communications.



* * *


ACLU-MN files lawsuit against Minnewaska Area Schools
St. Paul, Minn. – Today, the American Civil Liberties Union of Minnesota filed a lawsuit in Federal District Court against Minnewaska Area Schools and the Pope County Sheriff's office for violating the constitutional rights of a minor student. R.S's free speech and privacy rights were violated by the school district in two separate instances involving Facebook. (To protect the privacy of the minor defendant, she will be referred to as R.S.)

In early 2011 R.S. posted a comment, while at home, on her Facebook page about her dislike of a school staff member. The school learned about the comment, and R.S. received a detention and was forced to write an apology to the staff member. She was disciplined again when she cursed on her Facebook page, complaining that someone reported her to the school. This time she was given an in-school suspension and was prohibited from attending a school field trip. The ACLU-MN contends that these sanctions violate her First Amendment right to freedom of speech.

In a second incident R.S. was brought into a school administrator's office where she was coerced to turn over (against her will) login information to her Facebook and email accounts because of allegations that she had online conversations about sex with another student off-campus. Present at the search was a local deputy along with two school officials. During this process, R.S. was called a liar and told she would be given detentions if she did not give the adults access to her accounts. R.S.'s mother was not informed about the search until after it happened. The Deputy and school officials did not have a warrant to search R.S.'s private accounts. The ACLU-MN alleges in their suit that this violated R.S.'s Fourth Amendment right to be free from unreasonable search and seizure. [...]

"Students do not shed their First Amendment rights at the school house gate," stated Charles Samuelson, Executive Director for the ACLU-MN. "The Supreme Court ruled on that in the 1970s, yet schools like Minnewaska seem to have no regard for the standard."


* * *


MSNBC: Govt. agencies, colleges demand applicants' Facebook passwords
Employers and colleges find the treasure-trove of personal information hiding behind password-protected accounts and privacy walls just too tempting, and some are demanding full access from job applicants and student athletes. [...]

Student-athletes in colleges around the country also are finding out they can no longer maintain privacy in Facebook communications because schools are requiring them to "friend" a coach or compliance officer, giving that person access to their “friends-only” posts. Schools are also turning to social media monitoring companies with names like UDilligence and Varsity Monitor for software packages that automate the task. The programs offer a "reputation scoreboard" to coaches and send "threat level" warnings about individual athletes to compliance officers. [...]

 on colleges, while spreading quickly among athletic departments, seems to be limited to athletes at the moment. There's nothing stopping schools from applying the same policies to other students, however. And Shear says he's heard from college applicants that interviewers have requested Facebook or Twitter login information during in-person screenings. [...]

The practice seems less common among employers, but scattered incidents are gaining attention from state lawmakers. The blog Tecca.com last year showed what it said was an image of an application for a clerical job with a North Carolina police department that included the following question:

"Do you have any web page accounts such as Facebook, Myspace, etc.? If so, list your username and password."

Thursday, March 8, 2012

Police Given Direct Line To Cell Phone Searches

Reporting Jay Gormley
March 6, 2012

DALLAS (CBSDFW.COM) – Think about all the personal information we keep in our cell phones: It’s something to consider after the U.S. Court of Appeals for the 7th Circuit ruled it is now legal for police to search cell phones without a warrant.

Former Dallas FBI Agent Danny Defenbaugh said the ruling gives law enforcement a leg up. “I think not only will it help them, but it could be life saving,” said the former Special Agent, who was based in Dallas.

The decision stems from an Indiana case where police arrested a man for dealing drugs. An officer searched the suspect’s cell phone without warrant.

The judge in the appeal case, Judge Richard Posner, agreed that the officer had to search the phone immediately or risk losing valuable evidence. Judge Posner ruled it was a matter of urgency, arguing it was possible for an accomplice to wipe the phone clean using a computer or other remote device.

Defenbaugh says the ruling takes into account exigent or time-sensitive circumstances that could be life saving in more urgent cases, such as child abduction. ”If the child is alive and you’re only minutes behind, that could be critical to recovering that child alive,” added Defenbaugh.

Judge Posner ruled that the search was legal because the officer conducted a limited search and only looked for phone numbers associated with the alleged drug deal. The judge argued it was similar to flipping through a diary to search for basic information such as addresses and phone numbers.

Paul Coggins is the former U.S. Attorney for the Northern District of Texas. Coggins says the court’s ruling pushes the envelope on privacy issues and wonders if it opens the door to more extensive searches down the road. “Does that mean officers now have the right to search through your phone, search through your search history, your photographs, your e-mails and the rest, because it could all be wiped clean,” Coggins asked.

Many critics are asking the same question. They call the ruling an invasion of privacy that far outweighs the needs of law enforcement.

Both Defenbaugh and Coggins agree that the case is likely to go to the U.S. Supreme court.

Friday, February 17, 2012

List of countries willing to ratify ACTA shrinks daily

'I Don’t Know Why I Signed': ACTA Support Tanks

Support for the controversial Anti-Counterfeiting Trade Agreement (ACTA) continues to wane this week as the Netherlands have imposed delays on ratification, joining the list of countries that have begun to back down on the agreement.

Last weekend saw tens of thousands of protesters across Europe in opposition to the agreement. In response to these protests, now the Netherlands have joined a growing list of countries including Germany, Poland, and Bulgaria who have recently taken steps to delay or reject ACTA.

UPI reports:
The Netherlands this week imposed delays on the ratification of the ACTA international anti-piracy agreement, which critics claim threatens Internet freedoms. 
Opponents say the draft Anti-Counterfeiting Trade Agreement puts users' privacy at risk while the European Commission contends the measure doesn't change existing data protection laws and is needed to mount a long-term global fight against copyright theft. 
Germany, Poland, the Czech Republic and Slovakia have already delayed the international trade agreement's ratification process, citing the same privacy concerns highlighted during a wave of anti-ACTA protests throughout Europe last week. 
The Netherlands joined that group Tuesday, when the Dutch lower house of Parliament backed a motion from the Green Left party calling on the Netherlands to refrain from signing onto ACTA, Radio Netherlands reported. [...] 
Dunja Mijatovic, media freedom representative for the Organization for Security and Cooperation in Europe, Tuesday urged the European Parliament to reject ACTA, which it is considering for ratification. 
"In my role as the OSCE representative on Freedom of the Media, I am mandated to observe media freedom developments in the OSCE participating states and am concerned that the present agreement on ACTA might have a detrimental effect on freedom of expression and a free flow of information in the digital age," Mijatovic said in Vienna.

RT reports:
As European parliaments reject the Anti-Counterfeiting trade Agreement on human rights grounds, some are asking why it was signed in the first place. 
It looks like some of the countries who signed ACTA in Tokyo on January 26 are already having second thoughts. 
“I don’t know why I signed ACTA”, former Romanian prime minister Emil Boc said on February 6. 
“We made insufficient consultations before signing the agreement in late January," said Polish PM Donald Tusk on February 3, implying that his government had not taken steps to fully "ensure it was entirely safe for Polish citizens.” 
A few days later Slovenia's foreign minister, who signed the agreement on behalf of her country, apologized for doing so: "Quite simply, I did not clearly connect the agreement I had been instructed to sign with the agreement that, according to my own civic conviction, limits and withholds freedom of engagement on the largest and most significant network in human history, and thus limits particularly the future of our children."

Saturday, December 31, 2011

Wiretap Suits OKd Against US, Not Telecoms

Friday, December 30, 2011 by The San Francisco Chronicle
by Bob Egelko

The nation's telecommunications companies can't be sued for cooperating with the Bush administration's secret surveillance program, but their customers can sue the government for allegedly intercepting their phone calls and e-mails without a warrant, a federal appeals court ruled Thursday.

In a pair of decisions, the Ninth U.S. Circuit Court of Appeals in San Francisco upheld a 2008 law immunizing AT&T and other companies for their roles in wiretapping calls to alleged foreign terrorists, but revived a suit that accused the government of illegally intercepting millions of messages from U.S. residents.

That lawsuit was partly based on testimony in 2003 by former AT&T technician Mark Klein about equipment in the company's office on Folsom Street in San Francisco that allowed Internet traffic to be routed to the government.

'Dragnet' surveillance

The Electronic Frontier Foundation, a privacy-rights organization representing AT&T customers, claimed the company had similar installations in other cities and used them for "dragnet" surveillance of everyday e-mails and phone calls, which the National Security Agency purportedly screened electronically for connections to terrorism.

"We look forward to proving the program is an unconstitutional and illegal violation of the rights of millions of ordinary Americans," said Cindy Cohn, the foundation's legal director.

Justice Department spokesman Dean Boyd declined comment.

President George W. Bush acknowledged in 2005 that his administration had eavesdropped on calls to suspected foreign terrorists without the warrants required by federal law, but his Justice Department denied the existence of a dragnet surveillance program.

Dozens of suits challenging the surveillance were transferred to San Francisco. In one case, then-Chief U.S. District Judge Vaughn Walker ruled in March 2010 that federal agents had illegally wiretapped an Islamic organization, which was accidentally sent a copy of the surveillance documents. The Obama administration, which inherited the case, is appealing the ruling.

Obama backed law

Walker also allowed suits against telecommunications companies that allegedly took part in illegal surveillance, but Bush then signed a law, supported by then-Sen. Barack Obama, that immunized companies cooperating in presidentially approved antiterrorism intelligence-gathering.

The appeals court upheld that law in a 3-0 ruling, rejecting arguments that Congress had interfered improperly in ongoing lawsuits and had delegated excessive power to Bush's attorney general, who certified the companies' eligibility for immunity in a confidential filing.

The Obama administration defended the law and also sought to dismiss the customers' suit against the government, arguing that it was based on speculation about wiretapping and involved political and national-security issues that were exempt from judicial review. The appeals court disagreed.

"Although the claims arise from political conduct and in a context that has been highly politicized, they present straightforward claims of statutory and constitutional rights" of customers who allege their messages were intercepted, said Judge Margaret McKeown in the 3-0 ruling.

Sunday, November 20, 2011

Judge Declares Law Governing Warrantless Cellphone Tracking Unconstitutional



By Julia Angwin - Wall Street Journal
November 16, 2011,

In a succinct one-page ruling, U.S. District Court Judge Lynn N. Hughes of the Southern District of Texas declared that the law authorizing the government to obtain cellphone records without a search warrant was unconstitutional.

“The records would show the date, time, called number, and location of the telephone when the call was made,” Judge Hughes wrote in the decision, dated Nov. 11. “These data are constitutionally protected from this intrusion.”

Judge Hughes’ decision comes as the U.S. government is facing increasing judicial challenges to its practice of obtaining information about the location of individuals without a search warrant. Last week, the Supreme Court heard oral arguments in a case where the government placed a GPS tracking device under a vehicle and monitored the driver’s movements for a month without a search warrant.

During the argument, Chief Justice John Roberts said to Michael Dreeben, deputy solicitor general of the Justice Department: “If you win this case then there is nothing to prevent the police or the government from monitoring 24 hours a day the public movement of every citizen of the United States.” The Justice Department argues that people have no expectation of privacy on public roads.

Cellphone records are governed by the Electronic Communications Privacy Act, a 1986 law that permits law enforcement officers to obtain certain digital records – such as some e-mail and cellphone records – without a search warrant. A coalition of technology companies—including Google Inc., Microsoft Corp. and AT&T Corp.—is lobbying Congress to update the law to require search warrants in more digital investigations.

At the same time, judges in lower courts have been questioning the constitutionality of the law, which only requires officers to show “specific and articulable facts” the electronic records sought are “relevant and material” to an ongoing investigation. For physical searches of a person’s home, the government is required to show probable cause that a crime was committed and obtain a search warrant.

Since 2005, more than a dozen magistrate judges have written opinions denying applications for court orders to track cellphones without search warrants. The nation’s roughly 500 magistrate judges handle applications for search warrants and other types of electronic surveillance in federal courts.

Of course, some have upheld warrantless searches. Last week, U.S. District Court Judge Liam O’Grady ruled that the government could obtain data from the Twitter accounts of three WikiLeaks without a search warrant.

Last year, Magistrate Judge Stephen Smith of U.S. District Court in the Southern District of Texas issued an opinion denying the government access to 60 days worth of information about a cellphone subscriber’s location and phone calls, without a search warrant.

Magistrate Judge Smith wrote that although cellphone tracking wasn’t envisioned by the writers of the Constitution, it had become so precise and pervasive that “for a cellphone user born in 1984, however, it is now conceivable that every movement of his adult life can be imperceptibly captured, compiled, and retrieved from a digital dossier somewhere in a computer cloud. Now as then, the Fourth Amendment remains our polestar.”

The government appealed, saying that the Fourth Amendment, which protects against unreasonable searches and seizures, does not apply because “a customer has no privacy interest in business records held by a cell phone provider, as they are not the customer’s private papers.” The government also challenged Judge Smith’s description of the accuracy of location tracking as “inaccurate or misleading,” and submitted an affidavit from cellular provider MetroPCS Wireless Inc. stating that the average coverage radius of its cellular towers was about “one or two miles.”

The district court ruling was short, but declarative. It affirmed Magistrate Judge Smith’s decision on constitutional grounds. “When the government requests records from cellular services, data disclosing the location of the telephone at the time of particular calls may be acquired only by a warrant issued on probable cause,” Judge Hughes wrote. “The standard under the [existing law] is below that required by the Constitution.”

Saturday, August 27, 2011

Dangerous Cybercrime Treaty Pushes Surveillance and Secrecy Worldwide

(Ain't it funny/how rights just keep slippin'/away...Corporations write our laws. Corporations control the government by controlling its two party system. And it will take a huge effort on the part of us, the disenfranchised. Rise up or be plowed under.--jef)


 
As part of an emerging international trend to try to ‘civilize the Internet’, one of the world’s worst Internet law treaties--the highly controversial Council of Europe (CoE) Convention on Cybercrime--is back on the agenda. Canada and Australia are using the Treaty to introduce new invasive, online surveillance laws, many of which go far beyond the Convention’s intended levels of intrusiveness. Negotiated over a decade ago, only 31 of its 47 signatories have ratified it. Many considered the Treaty to be dormant but in recent years a number of countries have been modeling national laws based on the flawed Treaty. Moreover, Azerbaijan, Montenegro, Portugal, Spain, and the United Kingdom are amongst those who have ratified within the last year. However, among non-European countries, only the U.S. has ratified the Treaty to date, making Canada and Australia’s efforts unique. The Treaty has not been harmless, and both Australia and Canada are fast-tracking legislation (Australia's lower house approved a cybercrime bill last night) that will enable them to ratify the Treaty, at great cost to the civil liberties of their citizens.

Leaving out constitutional safeguardsAustralia’s invasive bill highlights one of the fundamental flaws of the Convention on Cybercrime: the Treaty’s failure to specify proper level of privacy protection necessary to limit the over-broad surveillance powers it grants law enforcement agencies. This creates problems in countries like Australia since, as the Australia Privacy Foundation points out, Australia lacks the legal constitutional safeguards afforded to many other democratic countries:
The CoE Convention has to be read within the context that applies in CoE countries – where there are substantial and actionable constitutional protections for human rights. The absence of any such countervailing protection for human rights in Australia makes it completely untenable for the Convention to be implemented in Australia without very substantial additional provisions that achieve a comparable balance.
Bills proposed in Canada (read here and here) are also affected by the Convention’s flaws as they adopt the lowest possible standard of protection against many of the invasive powers they grant. The bills provide law enforcement access to sensitive data on the mere suspicion it might be useful to an investigation. Indeed, at times they leave out the safeguards altogether, as noted in a letter from Canadian privacy scholars and civil society organizations:
[the legislation] will give state agents the power to access ...highly sensitive personal information, even where there is no reason to suspect it will assist in the investigation of any offense...What [this] facilitates, simply put, are unjustified and seemingly limitless fishing expeditions for private information of innocent and non‐suspicious Canadians.
Gag orders in place of oversight: Cultivating a culture of secrecyThe Convention’s most systemic flaw is that it seeks to impose invasive surveillance powers without legal protections. Aside from failing to specify adequate safeguards, it also leaves out the types of oversight mechanisms necessary to ensure its broad powers are not abused. Worse, the Convention takes active steps to reduce oversight and transparency by calling for limitations on when individuals can and cannot be notified that they are being surveilled upon.

The Australian bill even criminalizes any attempt to disclose the fact that the powers it grants to law enforcement have been used to spy on an individual. These gag orders will prevent anyone from disclosing the existence and content of interception warrants, all but ensuring innocent individuals will never know their civil liberties have been violated:
...it should be possible for individuals to find out that their communications have been subject to a preservation order or disclosed to law enforcement agencies once there is no longer any prejudice to an ongoing investigation.

Nigel Waters, Australia Privacy Foundation, Parliamentarian hearing on the Cybercrime Bill.
Proposed Canadian legislation also paves the way to blanket and perpetual gag orders that will apply by default to the most invasive of the seizure powers it authorizes. These gag orders can insulate abuses of power --when innocent people are surveilled for no good reason--and they will never find out nor will be able to challenge the abuse of their rights, even in situations where there is no longer any risk to an ongoing investigation.
The far-reaching powers this legislation puts in place, if adopted at all, should be accompanied by equally far-reaching oversight regimes, not gag orders. Instead of preventing abuses from ever seeing the light of day, individuals should be notified when they have been surveilled, and the extent, nature and frequency of such surveillance must be subject to rigorous external oversight.

Tamir Israel, staff attorney, Samuelson-Glushko Canadian Internet Policy & Public Interest Clinic.
Blanket gag orders are strongly disfavored under U.S. law, and at least one U.S. court of appeals has found a similar gag order provision partially unconstitutional. A provision of the PATRIOT Act permitted the government to obtain electronic communication transaction records from an Internet Service Providers without a court order. The law imposed a gag order on “National Security Letter” recipients, with extremely limited judicial review that required courts to accept the FBI’s assertions as true and placed the burden on the ISP to challenge the gag order after it had been issued. As EFF argued, such gag orders stifle free expression, and without any judicial oversight, the government was free to do what it wanted. The court agreed that the gag order provision was unconstitutional as written, but it construed the gag rules narrowly so as to pass First Amendment muster. The court found that the U.S. Justice Department could adopt additional procedures to cure the remaining defects—a result that EFF disagrees with because it is Congress’s job to write laws.

Forcing service providers to record your online activity
Countries are also using the Convention to put in place powers aimed at forcing service providers to store customer information for extended periods of time. While the Convention itself foresees targeted preservation orders in scenarios where there is a reason to believe the information would otherwise be vulnerable to loss or modification, Australian and Canadian bills ignore this important limitation. Also, while the Convention envisions a distinction between orders forcing service providers to preserve data they have already collected and orders aimed at forcing service providers to intercept and record data in real time, the misuse of proactive or ‘ongoing’ preservation orders aims to undermine this distinction.

In the U.S. and in Canada, for example, there have been cases where preservation powers have been misused to proactively compel service providers to retain data such as email or text messages that are not yet in their possession or control. Proactive preservation force service providers to record data they would never have otherwise retained, effectively bypassing legal protections in place for real-time electronic interceptions. As the U.S. DOJ notes in its manual on seizing electronic communications:
...should not be used prospectively to order providers to preserve records not yet created. If agents want providers to record information about future electronic communications, they should comply with the electronic surveillance statutes discussed in Chapter 4.
Instead of attempting to avoid such problems, the Australian bill embraces this confusion, and expressly grants law enforcement the right to order ‘ongoing preservation’. This, combined with the complete lack of any obligation to ensure preservation orders are narrowly targeted to capture relevant data at risk of deletion, opens the door to blanket retention orders aimed at real-time interception of communications services on a mass scale.

The Australian law, for example, is phrased in such broad terms that it could be applied indiscriminately, without any assurance that it will only be used to preserve data that is at risk of being destroyed:
The Bill could require an Internet Service Provider to preserve all stored communications (e.g. traffic and content data) for a telecommunications service (e.g. email, text messaging, mobile phone) for a specified period of time. Unless our concerns about the meaning of a ‘service’ are addressed, then under an ongoing domestic preservation notice, a Commonwealth agency could arguably request that a major carrier such as Telstra or Optus, preserve all emails used on its service for a 30 day period.

Australia Privacy Foundation Submission to the Parliament.
The proposed Canadian legislation also fails to ensure preservation demands will be used in a targeted manner and is likely to lead to voluntary retention of personal information that would not otherwise have been kept by telecommunications service providers.

Convention premised on outdated concepts of online data
The flaws inherent in the Convention itself are exacerbated by the fact that it was drafted over ten years ago and much has changed since then. The Convention was premised on the notion that ‘traffic data’ (data generated by computers as a by-product of online interactions) is ‘less sensitive’, and so should be more readily accessible to law enforcement. That was then, and this is now: Today’s ‘traffic data’ can include such sensitive information as your otherwise anonymous online identity or your social network of contacts. Mobile companies and our Internet services providers are now recording our whereabouts at every moment, and we are leaving far more detailed footprints that reveal sensitive information of our daily lives. Sensitive data of this nature warrants stronger protection, not an all-access pass.
Other things have changed in the online environment as well. The ongoing move towards cloud computing means that more and more of our information will be stored online.

Nowadays, countless millions are trusting web-based email services such as Google Gmail to store years worth of private correspondence, and cloud services such as Dropbox or Google Docs store your most private documents. The Treaty could not envision this reality when it was drafted in 2001. Governments must now think carefully about what the Treaty’s increased law enforcement powers will mean for citizen rights in this new digital context.