Showing posts with label child pornography. Show all posts
Showing posts with label child pornography. Show all posts

Monday, May 04, 2015

PPS numbers: internet saviours?

Bank Holiday Mondays are quiet news days, making them a good time to get any old nonsense into the newspaper. Today is no exception as the Irish Times appears to have taken the opportunity for a special edition of breathless internet fear-mongering.

The prime example is this piece which makes the literally incredible assertion that "The PPS number provides the Irish Government with an opportunity to dramatically improve the safety of children and young people online." (Following on, no doubt, from the success of PPS numbers in the delivery of water services.) In effect, the author is demanding internet identity cards for the wider population. This is an astonishingly bad idea, as anybody with even a passing familiarity with the Korean internet ID fiasco should know.

So why is the author pushing this? The byline reveals that the author is "founder and CEO of TrustElevate, a technology products and services company that specialises in regulatory, policy and compliance online." But what the byline doesn't say is that her firm is selling the technology which the article promotes. According to its own site, "Trust Elevate is a UK-based technology solutions and advisory company. Our focus is on identity, privacy, security and safety from the perspectives of reputational compliance and commercial opportunities."

In short, the author is shilling her own service under the guise of an impartial opinion piece. This is bad enough in itself, but more fundamentally it is a distraction from what really needs to be done to protect children online.

At the most basic level, gardaí are dramatically under-resourced in dealing with the internet. The 2014 Garda Inspectorate report revealed there have been up to four year delays in analysing seized computers; that the Paedophile Investigation Unit had one (!) computer to receive and download evidence; that 40% of Garda stations are not networked and have no access to PULSE or internal email; that evidence cannot be shared electronically; and that even in networked stations many gardaí have no access to social media or external email.

One might expect that those genuinely interested in child welfare would address these basic points first. But where's the profit in that?


-----------

Some excerpts from the Garda Inspectorate Report - emphasis mine:
The current Garda Síochána IT system restricts the sending of evidence electronically, resulting in investigators having to travel to Dublin to view evidence. PIU only have access to one standalone computer to receive and download evidence, as they are unable to use PULSE. This is a fundamental tool for investigation of these crimes. When evidence arrives, it can take days to download information and this removes the availability of the computer to be used by investigators coming to the unit to view evidence for other cases. PIU gave an example where one case had over 8,000 videos.

Another problem area is the restriction placed on districts accessing social media sites. As a result, the PIU is swamped with requests from districts for help in cases under investigation. Since 2001, the unit has used a paper system for managing investigations and would like to move to an electronic system. Internally, the PIU uses an electronic spread sheet to monitor cases. There is a concern that two investigators could potentially be looking at the same suspect, without knowing that another garda is also investigating a crime against the same suspect. Like the SOMU, all PIU staff work on the same roster and again are all off-duty at the same time.

The delay in obtaining evidence from analysis of computers has contributed to a situation where no PIU investigation case file has been sent to the DPP for directions in the last four years of operation.


A consistent theme throughout the inspection of national and district intelligence units was that outdated IT equipment blocked them from accessing or viewing evidence about a crime. The Inspectorate was informed that the National Intelligence Unit is working on outdated software and is unable to load PDF documents and to view photographs. CIOs in particular experience daily challenges in accessing the necessary IT applications and equipment to perform their role effectively. CIOs often use personal laptops and computers to view CCTV footage, to download stills and to turn those stills into briefing documents and bulletins. This represents a risk of breaching security of intelligence data, but their motive is to ensure that intelligence is provided to local gardaí.

The access of gardaí to external e-mail was very inconsistent across the seven divisions. Some members stated that they had no external e-mail access and other gardaí explained that if you apply for access then it will be given. Many victims would like the option to use e-mail to communicate directly with the garda dealing with their case and it would ensure that the member actually received their message.

Monday, April 11, 2011

The curious case of internet filtering in Ireland

[Reblogged from the new website MediaLaws.eu, where I will be contributing updates from Ireland.]

One of the most important developments for freedom of expression online has been the growth of internet filtering systems, which have rapidly been adopted by national governments as the “solution” to various forms of internet wrongdoing. Ireland is no exception to this trend, and last month it was revealed that the Garda Síochána (the national police force) is now attempting to introduce a system whereby ISPs would block access to websites alleged to host child abuse images.

It is somewhat ironic that this news becomes public just as both Germany and the Netherlands have decided to abandon similar systems, having found that they are ineffective as a means of tackling child abuse images. Even leaving aside considerations of effectiveness, however, the proposed Irish system still presents a number of significant concerns.

A fundamental principle under Article 10 of the European Convention on Human Rights is that measures which have the effect of restricting freedom of expression must be “prescribed by law”. In this case, however, the Irish system would not have any legal basis whatsoever, much less any judicial oversight or control. Instead, it would involve the police in telling ISPs what domains to block on a “self-regulatory” basis. Consequently, it would seem on the face of it that the proposed system would violate Article 10. The European Commission recently reached the same conclusion about self-regulatory blocking systems (p.30) as did a government study which was decisive in causing the Dutch blocking system to be abandoned.

A further problem relates to the secret manner in which the government and the police have attempted to introduce this system. There has been no public consultation or debate of any kind regarding blocking – instead, information has only dripped out in response to freedom of information requests and leaks from ISPs. This is particularly worrying given that (as Lessig points out) internet filtering is an inherently opaque process, which is prone to operating in an unaccountable way and to being extended beyond its original purposes. In the Irish context, the secrecy surrounding the introduction of filtering doesn’t bode well for the future.

The nature of the proposed blocking is also worrying. What Irish police have suggested is based on the CIRCAMP model, which attempts to block material by using DNS tampering. In short, the police would notify ISPs to block http://example.com or http://subdomain.example.com and the ISP would then configure their DNS servers to redirect all attempts to visit any material hosted on those (sub)domains. The effect would be massive overblocking, where users would be unable to visit any page hosted on a particular domain, irrespective of whether it had any connection whatsoever with the blocked material. Last February, a similar approach in the United States saw over 84,000 innocent websites being wrongfully blocked, and there is no reason to think that the Irish approach would be any more precise.

Finally, one particularly unusual aspect of the proposals is the way in which police seek to introduce monitoring of users. According to the proposals, where a user attempts to view a blocked domain name, police would “obtain details of other websites visited by the user, along with other technical details, in order that [they] can identify any new websites that require blocking”. This in effect seeks the full browsing history of users – whether or not there has been any attempt on their part to view child pornography! (Bearing in mind that DNS tampering results in massive overblocking, it is quite likely that a user may have their browsing history disclosed due to an attempt to visit http://example.com/innocent_content when the entirety of example.com has been blocked due to a single image or page elsewhere in the site.) This raises fundamental privacy and data protection concerns, particularly given that a user can often be identified by viewing their browsing history (e.g.), and has therefore been referred to the Data Protection Commissioner for investigation.

Given these problems, it must be hoped that these proposals are abandoned. But quite apart from these particular proposals, it is now also time to look at the other systems of internet filtering in Ireland that have developed on an ad hoc basis. In particular, Irish mobile phone companies have been engaged in self-regulatory blocking for some time (1|2), in a manner which often affects innocent users due to crude DNS systems. Similarly, the largest Irish broadband provider Eircom recently settled an action brought by the music industry by (amongst other things) agreeing to block access to The Pirate Bay and “related domain names”. These systems have developed without any real public scrutiny or oversight and it is time to consider the effect which they have on users, whether they are subject to adequate transparency and oversight mechanisms and whether or not they are effective at achieving their goals.

Wednesday, November 24, 2010

EU Internal Security Strategy Published

The Commission has just published an internal security strategy document setting out a four year plan for European level action on the issues of "fighting and preventing serious and organised crime, terrorism and cybercrime, strengthening the management of our external borders and building resilience to natural and man-made disasters."

While the entire plan is likely to be controversial (and the sections on border control have already been criticised), I'd like to focus on the section on cybercrime and to offer a few thoughts:
Action 1: Build capacity in law enforcement and the judiciary

By 2013, the EU will establish, within existing structures, a cybercrime centre, through which Member States and EU institutions will be able to build operational and analytical capacity for investigations and cooperation with international partners. The centre will improve evaluation and monitoring of existing preventive and investigative measures, support the development of training and awareness-raising for law enforcement and judiciary, establish cooperation with the European Network and Information Security Agency (ENISA) and interface with a network of national/governmental Computer Emergency Response Teams (CERTs). The cybercrime centre should become the focal point in Europe's fight against cybercrime.

At national level, Member States should ensure common standards among police, judges, prosecutors and forensic investigators in investigating and prosecuting cybercrime offences. In liaison with Eurojust, CEPOL and Europol, Member States are encouraged by 2013 to develop their national cybercrime awareness and training capabilities, and set up centres of excellence at national level or in partnership with other Member States. These centres should work closely with academia and industry.
The recommendations for action at EU level are welcome, but unfortunately Ireland has a long way to go to meet the recommendations for action at national level. I've written about the failings in the Irish response to cybercrime recently in the Sunday Business Post.
Action 2: Work with industry to empower and protect citizens

All Member States should ensure that people can easily report cybercrime incidents. This information, once evaluated, would feed into national and, if appropriate, the European cybercrime alert platform. Building on the valuable work under the Safer Internet Programme, Member States should also ensure that citizens have easy access to guidance on cyber threats and the basic precautions that need to be taken. This guidance should include how people can protect their privacy online, detect and report grooming, equip their computers with basic anti-virus software and firewalls, manage passwords, and detect phishing, pharming, or other attacks. The Commission will in 2013 set up a real-time central pool of shared resources and best practices among Member States and the industry.

Cooperation between the public and private sector must also be strengthened on a European level through the European Public-Private Partnership for Resilience (EP3R). It should further develop innovative measures and instruments to improve security, including that of critical infrastructure, and resilience of network and information infrastructure. EP3R should also engage with international partners to strengthen the global risk management of IT networks.

The handling of illegal internet content – including incitement to terrorism – should be tackled through guidelines on cooperation, based on authorised notice and take-down procedures, which the Commission intends to develop with internet service providers, law enforcement authorities and non-profit organisations by 2011. To encourage contact and interaction between these stakeholders, the Commission will promote the use of an internet based platform called the Contact Initiative against Cybercrime for Industry and Law Enforcement.
Much of this is uncontentious, but the references to handling illegal internet content require careful scrutiny. The "guidelines on cooperation" and "notice and takedown procedures" reflect a worrying trend at EU level towards bringing about internet censorship by means of self-regulation. The result is that decisions about legality are being made in a way which doesn't have a legislative basis and excludes judicial oversight. This trend can already be seen in relation to internet filtering but this strategy, if implemented, would seem to extend it significantly further. It is hard to see how this proposal could be compatible with Article 10 of the European Convention on Fundamental Rights.
Action 3: Improve capability for dealing with cyber attacks

A number of steps must be taken to improve prevention, detection and fast reaction in the event of cyber attacks or cyber disruption. Firstly, every Member State, and the EU institutions themselves should have, by 2012, a well-functioning CERT. It is important that, once they are set up, all CERTs and law enforcement authorities cooperate in prevention and response. Secondly, Member States should network together their national/governmental CERTs by 2012 to enhance Europe's preparedness. This activity will also be instrumental in developing, with the support of the Commission and ENISA, a European Information Sharing and Alert System (EISAS) to the wider public by 2013 and in establishing a network of contact points between relevant bodies and Member States. Thirdly, Member States together with ENISA should develop national contingency plans and undertake regular national and European exercises in incident response and disaster recovery. Overall, ENISA will provide support to these actions with the aim of raising standards of CERTs in Europe.
The Irish CERT body (IRISS) does not have any state funding at present - will this recommendation encourage the Irish government to provide funding?

Friday, July 02, 2010

Hotline.ie 2009 Annual Report

Hotline.ie has just published its annual report for 2009 which makes for interesting reading. 2009 marks the 10th anniversary of the Hotline, which started operations in November 1999.

By way of background, Hotline.ie is an industry self-regulatory body (or perhaps co-regulatory: the boundaries are fluid) run by the ISPAI using funding from members and from the European Commission. The role of the Hotline is to receive complaints from the public about illegal content online and to act as a filter for those complaints - for example, if illegal material is found to be hosted in Ireland it will be notified to the Garda Síochána and/or the ISP; if hosted abroad it will be notified to the local authorities via either the INHOPE network or the Garda Síochána. Although it deals with reports of illegal content generally the primary focus of the Hotline is on preventing the distribution of child pornography.

Key statistics from the report:
* 2117 total number of reports processed by the Hotline.
* 284 of the above were determined as illegal under Irish law.
* 9 of the 284 proved to be duplicate reports, resulting in,
* 275 unique illegal reports. Of these:
* 9 were other issues (such as racism, threats of violence against individuals and financial scams that had an Irish connection).
* 267 were assessed as child sexual abuse and were forwarded for action through INHOPE or to An Garda Síochána for national investigation or forwarding via Interpol to other jurisdictions. One of these reports was of child grooming, all others were cases of child pornography.
Although the number of complaints had increased, the number of child pornography images reported was significantly reduced:
the reports assessed as illegal under Irish law numbered 536 in 2008 compared with 284 in 2009, a very significant drop of 252. Analysis of the figures suggests that the decline reflects that the public simply do not encounter illegal content with the same frequency as in previous years. Similar observations have been reported by other INHOPE hotlines. This could be a turning point reflecting some degree of success due to the sustained worldwide effort to counter child abuse images on the Internet.
One complaint related to child pornography on the web hosted in Ireland (the first time this had been detected):
The problem of weak log-on/password security was highlighted last October when the Hotline had its first absolutely confirmed report of a child pornography website in Ireland. The Garda investigation discovered that because of weak log-on/passwords the site had been hacked by criminals based outside the jurisdiction. The CSAM had been placed in a separate directory which was not navigatable from the shop website. However, clicking on the link in the banner site which held the full URL led directly to the planted directory. This contained PHP routines which created a pay-site portal with preview images pulled in from hosts in other countries.

The UK hotline, the International Watch Foundation (IWF), received a report about a banner site advertising a wide range of different child pornography sources. One of the banners linked to an IP address in Ireland. The IWF forwarded the report to Hotline.ie. Our content analysts verified that the content was indeed illegal under Irish law and confirmed the trace. The ISP was a major data centre in Dublin but we discovered that the IP was in fact sub-leased to a web developer/small hosting service in Co. Cork who had created and maintained the website on behalf of the client, a small retail business.
The complaints, as in previous years, overwhelmingly related to images hosted on the web and via spam emails, with complaints relating to p2p and Usenet being a vanishingly small proportion of the total:

(This statistic, however, appears to reflect the passive role of the Hotline, which is limited to receiving complaints from members of the public - it has no proactive role to actively search out child pornography. Recent media coverage of Irish p2p users downloading and uploading child pornography suggests that a significant number of Irish users may be sharing child pornography via p2p but that this is not registering on the Hotline radar.)

One particularly interesting part of the report was its analysis of those countries where child pornography is most often found to be hosted. Until recently the US and Russia were generally regarded as the worst offenders in this regard - recently, however, Russia appears to have improved its enforcement somewhat. Although the US continues to head this list, there has been a striking fall in the number of child pornography websites detected there, which may suggest that US procedures for taking down these sites are becoming more effective: