Tuesday, April 25, 2006

"The world was a safer place before t'internet. Oh yes. No risk out there in the real world, that's mad talk."

Media and government share a vested interest in hyping alarmist fears about the internet - fears good both for filling newsprint and justifying draconian laws. Eclectech neatly skewer the scaremongering in this hilarious animation (to the tune of the Teddy Bears' Picnic):

Monday, March 27, 2006

Dolores McNamara update: Social Welfare and Revenue snoops receive slap on wrist

The Sunday Times reports that one hundred officials who deliberately and consciously set out to snoop on the affairs of a private individual will escape with nothing more than a slap on the wrist:
MORE than 70 officials in the Department of Social and Family Affairs who breached the confidentiality of Dolores McNamara, the EuroMillions winner, when they accessed her files have been given a warning about their behaviour.

...

Officials at the department examined 106 cases where its staff logged onto McNamara’s records in the days after her record €115m jackpot win last July. It found that 72 of them had no reason to call up her details and, by doing so, breached department rules designed to protect the privacy of personal records.

The offending civil servants have been sent a formal letter pointing out that they are only supposed to consult such information as part of their assigned duties. They have also been warned that they will face disciplinary action, up to dismissal, should they ignore this advice.

A spokeswoman for the department said it was still looking into a further 19 cases where staff are believed to have wrongly accessed McNamara’s records.

...

The accessing of the files was revealed in The Sunday Times last September after details from McNamara’s tax and welfare records appeared in another newspaper. It claimed, wrongly, that the lottery winner was being investigated for welfare fraud and alleged she had been claiming payments while working.

The reports, which included dates, suggested the information could only have come from somebody close to McNamara or from people familiar with her records.

Under set procedures, staff are only supposed to access people’s records when they have a genuine business reason for doing so. In this case, only 34 employees were able to provide a reasonable explanation for examining the files, which included private welfare and benefits details.

...

The Irish Council of Civil Liberties also welcomed the outcome of the investigation. Malachy Murphy, its co-chairman, said: “Some people might say the civil servants got away lightly here, but we would respect the fact that the department has set disciplinary procedures and has to issue warnings to people, before going any further.”

He raised concerns, however, about the high number of staff who were able to call up McNamara’s records in the first place. “This case raises serious questions about the computer systems in use in government departments. It appears that excessive numbers of people are able to access detailed personal files and maybe this shouldn’t be the case.”

...

Earlier this year the Revenue Commissioners found that 28 of its staff looked up McNamara’s tax records after her win, even though they also had no reason for doing so. Thirty-two staff were originally under suspicion for accessing the files, but four were found to have valid reasons for doing so.
More on the Revenue invasion of privacy here.

More CCTV voyeurism

The Register points out that:
Tyneside police are investigating two civilian CCTV staff as part of a complaint into the 'possible misuse' of 'close-up' footage of naked participants in Spencer Tunick's mass nude shoot on the banks of the Tyne last July.
The Times has more details:
It is alleged that two police employees used the zoom lenses on the CCTV cameras to take close-ups of subjects and touted the images in pubs in the Tyneside area.
As I've said before the Irish Law Reform Commission warned about the abuse of CCTV in 1996 and again in 1998. To date, the Department of Justice has taken no steps to act on these warnings, despite rolling out extensive CCTV systems throughout Ireland.

Thursday, March 23, 2006

More Australian moves towards Internet Censorship

The Herald Sun is reporting a Labor commitment to require ISPs to censor the material viewed by users:
INTERNET service providers (ISPs) will be forced to block violent and pornographic material before it reaches home computers if Labor wins the next federal election.

Under the policy, announced by Opposition Leader Kim Beazley today, international websites would be banned by the Australian Communications and Media Authority if they contained graphic sexual or violent material, rated R or higher.

The bans would be maintained by ISPs.
It appears from the report that this would be a mandatory filtering system subject to a possible user opt-out. I've mentioned the Australian proposals before and Electronic Frontiers Australia has more on the existing system of internet censorship.

Update: More on the politics behind the proposals. Via BoingBoing

Monday, March 13, 2006

Quis custodiet ipsos custodes?

The head of the Metropolitan Police in London has been caught illegally recording telephone calls:
The Attorney-General, Lord Goldsmith, has accepted an apology from the Metropolitan Police Commissioner Sir Ian Blair for recording a private telephone conversation, the minister's office said today.

Lord Goldsmith was said last night to be "extremely angry" at the revelation that a conversation he had with Sir Ian last year - ironically about the subject of phone-tapping - was one of a number that Sir Ian had secretly recorded.

[...]

Shami Chakrabarti, director of human rights group Liberty, went further in condemning Sir Ian’s actions. "I think that his behaviour appears to be unconstitutional, unethical, quite possibly unlawful," she told the BBC Radio 4 Today programme.

"No doubt he has an explanation, perhaps he has already given his explanation to the Attorney. I think now we all want to hear it, and if it doesn’t ring true and it’s not adequate, I think it’s very hard for any of us to have trust in him as the senior law enforcer, police officer in this country.

"The bitter irony of this is that is a governnment that has has made great play of its support for the police. In my view it's given them too many unchecked powers and here it is on the receiving end of this most appalling abuse of police power."

The recorded call with the Attorney-General is believed to have taken place last September, and concerned the admissibility of wire tap evidence in court - although it did not relate to any particular case.

An IPCC spokesman said the taped conversations with three of its senior officials came to light as part of its inquiry in the aftermath of the Stockwell Tube station shooting of Mr de Menezes. One call was with its chairman, Nick Hardwick.

The calls had been recorded "without our prior consent", the spokesman said, adding: "We are surprised about the recording of calls and now have the recordings. We are dealing with this issue."

Sunday, March 12, 2006

Function Creep in Action: CCTV cameras used to generate revenue from motorists

The Sunday Times has the story:
When a London council decided to locate a CCTV camera in a quiet area of Camden the residents were delighted, especially as its declared purpose was to make the streets safer from muggers, drug dealers, burglars and car thieves. The £25,000 swivelling spy camera made them feel they were at last getting a tangible benefit from Camden’s rising council tax.

But it didn’t take long for them to discover it was going to cost a lot more — in ways they hadn’t expected. The camera proved not very good at identifying suspects lurking in the shadows but it was very good at reading residents’ car numberplates.

Since the Albert Street camera was installed last year its operators have issued 2,558 penalty notices for a range of minor motoring offences, such as double parking to unload groceries or allegedly blocking the flow of traffic.



CCTV images, left, record Jonathan Futrell pausing to pick up a friend in Albert Street. The car is stopped for less than a minute, but the result is still a fine.

Friday, February 10, 2006

Digital Rights Ireland is looking for your support

On the 6th December, Digital Rights Ireland formally launched. Our stated mission is to protect civil, legal and human rights in a digital age.

Now we're asking people who share that aim to help us out by pledging their money to DRI. If you're in a hurry and don't need to know more, here's where you can sign up:

www.digitalrights.ie/support

Since our launch, and without funding, we've managed to do the following;

Focus attention on data retention, by lobbying, use of parliamentary questions and encouraging media scrutiny of the European Parliament's vote to bring in a Data Retention Directive.

We've established ourselves as a point of contact for the media on digital rights issues. This is important, as editors are much more likely to run a story where they are able to present two competing views to their audiences. We've raised the profile of these issues across the entire range of media, including the Pat Kenny show, Newstalk FM, the Irish Times, Six One News, 2FM, Metro Ireland, the Star on Sunday, various local stations and (of course) internet news outlets such as The Register.

We have intervened in the filesharing debate to speak up for the privacy rights of innocent parties. We have also attempted, with some limited success, to inform the courts of relevant precedent.

We've started producing reliable, readable, guides to users' rights. So far, we have pamphlets on SMS Spam and Online Libel completed. More are in the works.

We have begun to introduce DRI to the other players involved in rights protection. We've met with the Data Protection Commissioner and with the Irish Council for Civil Liberties, and have been in contact with the Human Rights Commission. We've made a formal submission to the European Commission on Irish privacy laws.

We've also established DRI as Ireland's point of contact internationally in the digital rights sphere. We've joined EDRI , and have close relations with the Open Rights Group in the UK. We have also established informal links with other groups, such as the EFF, Liberty and Privacy International.

At the same time, we're working away behind the scenes on researching some of the issues which we expect to have to tackle in the months to come, such as the planned DNA Database and the proposals to introduce ID cards in Ireland.

Not a bad record for a three month old voluntary organisation working on a shoestring.

However, we're now reaching the limits of what we can do with no euro and no cent behind us. With your support, we could launch a flotilla of Freedom of Information requests, seeking information in targeted areas. We could raise awareness of digital rights issues in the professional spheres with a public conference. We could ship a representative to Brussels for crucial votes, to lobby our MEPs face to face. We could even pay for tea and coffee at our press conferences.

And, if needs be, we would be in a position to consider the possibility of seeking to block unconstitutional measures through the high-stakes gambles of the courts, as other advocacy groups regularly do.

Our suggested subscription rate is €10 per month. That is the cost of 2 pints. If we get 100 members willing to pledge that much to us, we will have a solid income base to work from.

We also have a concession membership of €5 a month. We aren't going to be checking IDs or anything like that - if you don't think you can afford to forgo both pints every month, then we'll happily spare you the effort of drinking one of them.

We have both a Paypal subscription option and our bank details for standing orders. Or if you like, you can bung us your full year's subscription in a single lump sum. And if you're not sure where you'll be for the next year, but know you'd like to send us something, we'd be most grateful.

Mechanics: Where does the money go? Money pledged to DRI will go to a bank account owned by Digital Rights Ireland Limited, a company limited by guarantee, registered with the Companies Registration Office in Dublin. As such, annual accounts will be filed for the company, which will be publicly available.

Who are Digital Rights Ireland Limited? Our Directors are listed here with links to their personal sites. Full details can be inspected via the Companies Registration Office.

[Cross-posted from digitalrights.ie]

Wednesday, February 01, 2006

Your personal information is for sale - Mobile Phone Location edition

The Guardian has an interesting story by Ben Goldacre entitled"How I stalked my girlfriend":
For the past week I've been tracking my girlfriend through her mobile phone. I can see exactly where she is, at any time of day or night, within 150 yards, as long as her phone is on. It has been very interesting to find out about her day. Now I'm going to tell you how I did it.

...

First I had to get hold of her phone. It wasn't difficult. We live together and she has no reason not to trust me, so she often leaves it lying around. And, after all, I only needed it for five minutes.

I unplugged her phone and took it upstairs to register it on a website I had been told about. It looks as if the service is mainly for tracking stock and staff movements: the Guardian, rather sensibly, doesn't want me to tell you any more than that. I ticked the website's terms and conditions without reading them, put in my debit card details, and bought 25 GSM Credits for £5 plus vat.

Almost immediately, my girlfriend's phone vibrated with a new text message. "Ben Goldacre has requested to add you to their Buddy List! To accept, simply reply to this message with 'LOCATE'". I sent the requested reply. The phone vibrated again. A second text arrived: "WARNING: [this service] allows other people to know where you are. For your own safety make sure that you know who is locating you." I deleted both these text messages.

On the website, I see the familiar number in my list of "GSM devices" and I click "locate". A map appears of the area in which we live, with a person-shaped blob in the middle, roughly 100 yards from our home. The phone doesn't go off at all. There is no trace of what I'm doing on her phone. I can't quite believe my eyes: I knew that the police could do this, and telecommunications companies, but not any old random person with five minutes access to someone else's phone. I can't find anything in her mobile that could possibly let her know that I'm checking her location. As devious systems go, it's foolproof. I set up the website to track her at regular intervals, take a snapshot of her whereabouts automatically, every half hour, and plot her path on the map, so that I can view it at my leisure. It felt, I have to say, exceedingly wrong.

...

Your mobile phone company could make money from selling information about your location to the companies that offer this service. If you have any reason to suspect that your phone might have been out of your sight, even for five minutes, and there is anyone who might want to track you: call your phone company and ask it to find out if there is a trace on your phone. Anybody could be watching you. It could be me.
This particular service isn't available in Ireland just yet. But other mobile phone location services are. MyHome.ie use similar technology to advertise houses based on their proximity to your mobile phone. 02 sell companies the ability to monitor the movements of their employees via their mobiles. And of course our Department of Justice has ensured that the movements of every mobile phone owner are tracked and stored for three years. It's time to make sure that adequate safeguards are put in place to control mobile phone location data - and by that I mean independent monitoring with teeth, not the ineffective and unaccountable internal administrative practices of mobile phone operators.

Monday, January 30, 2006

Dutch biometric passport cracked - personal details vulnerable

Biometric identity cards are being sold on the basis that they're supposedly secure. Before this debate comes to Ireland, it's worth noting that the Dutch biometric passport has already been cracked - allowing anyone to intercept your date of birth, facial image and fingerprint. To do this, they don't have to ever see your passport - merely come within 10 metres of a place where it is being used. (via The Register)

Monday, January 16, 2006

The innocent have nothing to fear: CCTV edition

We're often told that the innocent have nothing to fear. That extraordinary powers of surveillance won't be abused. This lady might disagree. From BBC News:
Two council CCTV camera operators have been jailed for spying on a naked woman in her own home.

Mark Summerton and Kevin Judge, from Sefton Council, Merseyside, trained a street camera into the woman's flat.

[...]

The images from the camera, including the woman without her clothes on, were shown on a large plasma screen in the council's CCTV control room in November 2004, Liverpool Crown Court heard.

Over several hours, she was filmed cuddling her boyfriend before undressing, using the toilet, having a bath and watching television dressed only in a towel.

[The trial judge said:]

"You only have to read the impact statements of the lady to realise the harrowing effect that this had on her.

"Her life has almost been ruined, her self-confidence entirely destroyed by the thought that prying male eyes have entered her flat."
It's worth noting that the Irish Law Reform Commission warned about the abuse of CCTV in 1996 and again in 1998. To date, the Department of Justice has taken no steps to act on these warnings, despite rolling out extensive CCTV systems throughout Ireland.

[Edited to add:] The Garda Siochana Act 2005 does address CCTV operations in section 38. That section provides no real safeguards however, and certainly does not meet the recommendations of the Law Reform Commission. It authorises the installation and operation of CCTV by the Garda or Community CCTV schemes. It does not prohibit others from putting CCTV in place to monitor public areas, nor does it require any permission before they can do so. Although authorisations to install Garda / Community CCTV systems can have conditions attached to them, those conditions are not backed by any criminal or civil sanction - the worst that can happen is revocation of the CCTV authorisation. The activity referred to in the above story, if it happened in Ireland, would most likely see the perpetrators escape any punishment.

Saturday, December 31, 2005

Garda Traffic Surveillance - Privacy Implications for Motorists?

The Irish Times reports that the police are proposing to bring Automatic Number Plate Recognition (ANPR) to Ireland:
The computer will be installed in Garda Traffic Corps vehicles and is due to be introduced in the coming months, The Irish Times has learned.

The computer and camera system will allow for the instant reading and analysis of registration plates of all traffic passing a Garda car. The system will be linked to the Garda's Pulse computer database.

It means any vehicles which are not taxed or insured or which have been reported stolen will trigger a warning notice on an in-car computer screen.

A warning will also be triggered for cars which have not passed the National Car Test (NCT) or which have any other outstanding infringement.

This will allow gardaí to give chase and issue a fine to the motorist. It will also allow gardaí to instantly identify repeat offenders who have ignored previous fines and other sanctions and to put them off the road.

Currently, if gardaí want to check on a vehicle they must call their local station via in-car radio and ask a colleague to manually check the registration on the Pulse system. This is time-consuming and means only a small number of checks can be carried out.

Under the new system, 50 Garda Traffic Corps vehicles will be fitted with two small in-car cameras. One camera will face to the front of the vehicle and the other to the rear.

The two cameras will allow for instant analysis of registration plates of all vehicles passing in both directions, whether a Garda vehicle is moving or parked by the roadside.
This scheme raises many questions. Will the Gardaí have access to the name and address of every motorist passing by? (In the US, where systems like this have been in place for some time, it's common for police to look up the details of an attractive woman in a passing car - known as "running a plate for a date".)

Given that the vast majority of motorists scanned will be entirely innocent, what happens to their data? Will it be retained? If so, for how long? What privacy safeguards have been built into the system? Has legal advice been taken on the data protection issues of ANPR? Will this be a precursor to a much wider system?

ANPR has already been controversial in other countries - notably England - so there is no excuse if it turns out that the Gardai and/or the Department of Justice have failed to consider these issues.

Friday, December 09, 2005

Last Chance to Fight EU Data Retention

Next Tuesday, the 13th of December, the European Parliament will vote on a Data Retention Directive. This proposes to extend data retention to the Internet, and will result in your ISPs logging every email you send, every web page you visit, and everything else you do online and storing that information for several years.

We urge you to email, fax or phone your MEPs as soon as possible to express your opposition to this measure, which will introduce mass surveillance of every man, woman and child in the EU.

As to what you should say, it is best if that comes directly from what you consider important. However, Privacy International and EDRI have adopted a position (which DRI has endorsed) setting out five key criticisms of the Directive. Feel free to copy and paste these if you wish.
1. This Directive invades the privacy of all Europeans. The Directive calls for the indiscriminate collection and retention of data on a wide range of Europeans’ activities. Never has a policy been introduced that mandates the mass storage of information for the mere eventuality that it may be of interest to the State at some point in the future.

2. The proposed Directive is illegal. It contravenes the European Convention on Human Rights by proposing the indiscriminate and disproportionate recording of sensitive personal information. Political, legal, medical, religious and press communications would be logged, exposing such information to use and abuse.

3. The Directive threatens consumer confidence. More than 58,000 Europeans have already signed a petition opposing the Directive. A German poll revealed that 78% of citizens were opposed to a retention policy. The Directive will have a chilling effect on communications activity as consumers may avoid participating in entirely legal transactions for fear that this will be logged for years.

4. The Directive burdens EU industry and harms global competitiveness. Retention of all this data creates additional costs of hundreds of millions of Euros every year. These burdens are placed on EU industry alone. The U.S., Canada and the Council of Europe have already rejected retention.

5. The Directive requires more invasive laws. Once adopted, this Directive will prove not to be the ultimate solution against serious crimes. There will be calls for additional draconian measures including:
* the prior identification of all those who communicate, thus requiring ID cards at cybercafes, public telephone booths, wireless hotspots, and identification of all pre-paid clients;
* the banning of all international communications services such as webmail (e.g. Hotmail and Gmail) and blocking the use of non-EU internet service providers and advanced corporate services.

Helpfully, we in Ireland are in a unique position to lobby our MEPs - because the Government has already stated it is so opposed to this particular draft that they will bring a case to the European Court of Justice to block it if the European Parliament approves it. Thus even MEPs from the Government Parties have no reason to support the proposed text in Tuesday’s vote.

It is not too late to stop this law: please join us by contacting your MEPs to say no to a surveillance society.

[Cross-posted from Digital Rights Ireland.]

Wednesday, November 30, 2005

Digital Rights Ireland Launches

Next Tuesday, December 6th sees the formal launch of Digital Rights Ireland, with a press conference in the Conference Room, Pearse St. Library, Dublin 2 at 11.00am. (Directions). We would like to formally invite to you to come along - we'd welcome your support, and the chance to chat with you about your concerns after the main conference. Please feel free to invite anyone else who you think would be interested in digital rights.

Monday, November 28, 2005

Your personal information is for sale - Motorists edition

The Mail on Sunday headline says it all: "DVLA sells your data to criminals"
The Government is selling the names and home addresses of motorists on its drivers' database to convicted criminals, a Mail on Sunday investigation has revealed.

The Driver and Vehicle Licensing Agency (DVLA) tells would-be wheel-clampers there is "no problem" with them buying drivers' home addresses - even if they have a criminal record.

Indeed, the two bosses of one clamping firm on the list of companies to whom the DVLA is happy to sell drivers' details are currently serving seven years' jail between them for extorting money from motorists.

The Mail on Sunday has now forced the DVLA to hand over its list of 157 firms which can buy personal information about drivers at £2.50 a time. All the companies need do is tap in a registration plate, and back comes the full name and address of the vehicle's owners.

The dossier shows that details of millions of drivers have been made available to bailiffs, credit control companies, debt collection agencies, property management firms, leisure centres, solicitors - and even one of the world's biggest loan and financial services companies.

A number of other companies on the list appear to be dissolved or simply not to exist.

The revelations, which suggest that the DVLA is in flagrant breach of data protection laws, last night caused a storm of protest, with MPs demanding an immediate end to the practice.
In Ireland the bodies which hold this information are the motor tax offices of each local authority. Queries have to be made by letter, and they charge somewhat more per query at €6. The legal basis for disclosure is Regulation 23 of the Road Vehicle (Licensing) Regulations, 2003:
A licensing authority shall, upon application, supply particulars from the licensing records or the joint licensing records:
(1) upon payment of the relevant amount specified in the Third Schedule to these Regulations, to any person who satisfies the licensing authority that he has reasonable cause therefor
The Regulations don't define "reasonable cause", leaving this up to the judgment of the manager in the relevant local authority. There doesn't appear to be any particular system in place to vet applications for release of these details. There may be scope for an enterprising journalist to put in a freedom of information request to see whether any similar abuses have taken place over here.

Sunday, November 27, 2005

Introducing Digital Rights Ireland

I've been involved recently in helping to set up Digital Rights Ireland, a civil rights group which will focus on issues such as privacy and freedom of expression online. We're now working towards a launch, and as part of the pre-launch publicity I recently did a podcast interview with Tom Raftery.

The interview covered how DRI came to form, what are our core beliefs and where we'll be taking the campaign for online civil and human rights. You can listen to the mp3 of the podcast here:
http://www.tomrafteryit.net/everything-you-blog-is-false/

Monday, October 24, 2005

Your personal information is for sale - private eye steals information to track down victim of domestic abuse

Via The Register
A private detective was fined this week for unlawfully obtaining information relating to 'vulnerable women' from medical centres. Ray Pearson, a director of North London-based Pearmac Ltd, was prosecuted by the Information Commissioner’s Office.

Pearson also persuaded an employee from Her Majesty’s Revenue and Customs (HMRC) to hand over his Employee Identity Number, and then misrepresented himself in order to find out about a customer of HMRC.

The Office of the Information Commissioner adds details on further offences also committed by Pearson.

Appalling as this report is, the full story behind it is worse. Two of the cases involved will show why.

One of the people whose information was stolen, Ms. X, was a victim of domestic abuse. She had left her husband, taking her daughter with her, to start a new life. The husband hired a private eye to track her down. He, in turn, subcontracted the work to Pearson. Pearson decided to track Ms. X via her father. Knowing that her father was a patient of a particular medical centre, Pearson rang the centre pretending to be from the local health authority and stating that he needed to contact the father in relation to a prescription. The medical centre gave him the father's telephone number, taking him one step closer to tracking down Ms. X on behalf of her abusive husband.

Another victim, Ms. Y, had recently been a prosecution witness in a criminal case. She discovered that her friends and associates were receiving suspicious telephone calls. Her utility company also received suspicious calls, as a result of which some of her personal information was revealed. British Telecom was also called in an attempt to obtain personal information. Most seriously, her GP was contacted by a person pretending to be a psychiatrist, seeking access to her medical file. Inquiries by the Office of the Information Commissioner revealed that these phone calls all came from Pearson's premises.

Why do these cases matter? When we express concern about issues such as data retention the official response is often that "the innocent have nothing to fear". These cases prove the contrary - you do not have to have done anything wrong to have your personal information stolen by unscrupulous criminals. The more information stored on you, the easier it will be for these abuses to take place, and the more risk you may be put in as a result.

(The information on the two cases above was supplied by the Office of the Information Commissioner and is redacted to protect the identities of the victims.)

Monday, September 26, 2005

Your personal information is for sale - Social Welfare edition

The Sunday Times reports that civil servants have been caught snooping through the social welfare files of lottery winner Dolores McNamara:
Officials at the Department of Social and Family Affairs have discovered there were up to 150 hits on McNamara’s welfare files after she scooped the EuroMillions prize. Departmental managers are now asking civil servants to explain why they opened her records.

While a small number of staff may have genuine reasons, it is believed the majority did not and could have broken data protection laws and department rules. Civil servants face disciplinary action or even criminal prosecution if they cannot show good cause for accessing the Limerick woman’s details.

The investigation was ordered after McNamara’s social welfare history was reported in detail by the media. The amount of social welfare payments she supposedly received, including specific dates, were published. The figures and dates, if correct, suggested the information could only have come from someone extremely close to her, or from someone with access to her social welfare records.
Presumably some civil servants were browsing her records for their own curiosity: but obviously some have realised that there's money to be made by selling information to the media. This isn't the first time that this has happened in Ireland, prompting the question: why should we trust the Government on data retention when they are incapable of protecting the personal information which they already have?

Thursday, July 14, 2005

Tackling spam - some freedom of expression problems

Wendy McElroy explains that new US anti-spam / child protection laws could criminalise perfectly ordinary email mailing lists, while attempting to comply with the laws will involve handing a list of recipients over to the government for vetting:
Both Utah and Michigan have created a 'child protection registry' for email addresses that belong to children or to which children have access. It functions like a 'no call list.' Spamfo.co explains, 'Once an email address is on the registry, commercial emailers are prohibited from sending it anything containing advertising, or even just linking to advertising, for a product or service that a minor is otherwise legally prohibited from accessing, such as alcohol, tobacco, gambling, prescription drugs, or adult-rated material.' In short, e-newsletters (such as ifeminists.net) are not permitted to send to registered email addresses if those newsletters include URLs to news sites that, in turn, link to child-inappropriate commerical information or products such as casino or viagra ads, tobacco or alcohol for sale.

Many credible news sources -- especially British ones, it seems -- offer links to adult-themed sites or products. These links can change constantly, which means that it is impossible to check a URL and 'clear' it of so-called objectionable links or ads.

Moreover, e-mailing to registered addresses is illegal even if the newsletter was requested, and the legal penalties for doing so are imposed without notifying the offender so that he/she can rectify the situation. What are those penalties? To quote Prof. Mitchell again, 'Under these laws...that email sender faces strict liability which can include up to 3 years in prison, and fines of $30,000 or more. In addition, ISPs and the individuals whose email addresses are on the registry have a right of action against the sender, as does the state attorney general.'

The only protection is for the emailer to make sure that a particular address is not 'illegal' by matching his/her mailing list against the registries. That process requires at least two things that I am unwilling to do: 1) turn my mailing list over to the government; and 2) pay a per-address fee.
There's more on these new laws from Declan McCullagh at News.com.

Linking as copyright infringement?

From ZDNet Australia:
It took almost two years but major record labels in Australia have finally won a legal battle against a Queensland man and his Internet Service Provider for alleged music piracy.

Stephen Cooper, operator of the mp3s4free Web site, was found guilty of copyright infringement by Federal Court Justice Brian Tamberlin.

Although Cooper didn't host pirated recordings per se, the court found he breached the law by creating hyperlinks to sites that had infringing sound recordings.
More analysis at The Register.

Saturday, July 09, 2005

Your personal information is for sale - Mobile phones edition

The Washington Post reports on the open sale of mobile phone (cell phone) records in the US. Excerpt:
Think your mate is cheating? For $110, Locatecell.com will provide you with the outgoing calls from his or her cell phone for the last billing cycle, up to 100 calls. All you need to supply is the name, address and the number for the phone you want to trace. Order online, and get results within hours.

Carlos F. Anderson, a licensed private investigator in Florida, offers a similar service for $165, for all major telephone carriers.

"This report provides all the calls with dates, times, and duration on the billing statement," according to Anderson's Web site, which adds, "Incoming Calls and Call Location are provided if available."

[...]

Such records could be used by criminals, such as stalkers or abusive spouses trying to find victims.

[...]

"Information security by carriers to protect customer records is practically nonexistent and is routinely defeated," said Robert Douglas, a former private investigator and now a privacy consultant who has tracked the issue for several years.

Experts say data brokers and private investigators who offer cell phone records for sale probably get them using one of three techniques.

They might have someone on the inside at the carrier who sells the data. Spokesmen for the telephone companies said strict rules prohibiting such activity make this unlikely. But Joel Winston, associate director of the Federal Trade Commission's Financial Practices Division, said other types of data-theft investigations have shown that "finding someone on the inside to bribe is not that difficult."

Another method is "pretexting," in which the data broker or investigator pretends to be the cell phone account holder and persuades the carrier's employees to release the information. The availability of Social Security numbers makes it easier to convince a customer service agent that the caller is the account holder.

Finally, someone seeking call data can try to get access to consumer accounts online.
I've written before about similar problems in Ireland.