Thursday, August 31, 2006

Privacy: One law for them, one law for us

The Telegraph reports that "Celebrity children will get database privacy" in the Orwellian "Children's Index":
Children of celebrities will be given special safeguards in a new database that will store details of every child in England and Wales, it was disclosed yesterday. ...

Ministers said the contentious two-tier level of privacy will protect children of the rich and famous from intrusion.

Addresses and telephone numbers of celebrities will be removed from the database if, for example, their children are deemed at risk of kidnap.

But opponents of the £241 million Children's Index — a supposedly confidential system intended as an early warning system for children at risk of abuse — said the move underlined their concerns about its security.

In further embarrassment to the Government, an independent report commissioned by Parliament's Information Commissioner and due to be published next month, is understood to warn that the index is causing serious concern and is possibly unlawful.

There are fears that it does not comply with the European Convention on Human Rights and may contravene the Data Protection Act. ...

Files are held by many bodies on the 11 million children in England and Wales, but the index will link this sensitive information in one database accessible to hundreds of thousands of officials. ...

Lord Adonis, the education minister, told the House of Lords: 'Between 300,000 and 400,000 users will access the index. Children who have a reason for not being traced, for example where there is a threat of domestic violence or where the child has a celebrity status, will be able to have their details concealed.'

Robert Whelan, the deputy director of the think-tank Civitas, said Lord Adonis's remarks showed there were legitimate concerns about the security of the index.

'The Government is showing it has no confidence in this database,' he said.

'There have been all these assurances it is secure, but how can we believe them now? I will tell you who will be off the register — the Blairs' children. This is just politicians protecting their own.

'And how is the Government going to define celebrity? It is a very fluid term — an assembly of high-profile clergy, disgraced politicians, topless models, pop singers and reality TV contestants.' ...

But, in an interview for tomorrow's Channel 4 programme Your Kids Under Surveillance, Prof Ross Anderson, an author of the report sent to the Information Commissioner, expressed concern about security.

'There will always be bent insiders. If you connect all these systems up and if you've got over a million professionals needing to access this every day it will all get out.

'Paedophiles for example can use the database to find out which children in their neighbourhood are vulnerable and where they live.'

Yet another argument against ID cards - UK Edition

ID card fears as staff hack into Home Office database | This is London:
"Office staff are hacking into the department's computers, putting at risk the privacy of 40million people in Britain.

The revelation undermines Government claims that sensitive information being collected for its controversial ID Cards scheme could not fall into criminal hands.

The security breaches occurred at the Identity and Passport Service, which is setting up the National Identity Register to provide access to individuals' health, financial and police records as part of the £8billion ID card scheme scheduled to begin in 2008.

MPs and technology experts have expressed fears that the national register, which will store sensitive details of more than 40million people, will be a honeypot for hackers and identity thieves. Liberal Democrat

Home Affairs spokesman Mark Hunter said: 'These revelations show it is folly to put all the precious personal data of our citizens in one place.'

Personal information about every British passport holder - including their date of birth, mother's maiden name, address and photographs - is already held in the IPS computers.

A Home Office spokesman last night confirmed the IPS security breaches. He also confirmed that three staff involved had been sacked and a fourth had resigned before disciplinary procedures had concluded."

Tuesday, August 29, 2006

NY Times uses geolocation to avoid contempt of court

Times Withholds Web Article in Britain:
If Web readers in Britain were intrigued by the headline “Details Emerge in British Terror Case,” which sat on top of The New York Times’s home page much of yesterday, they would have been disappointed with a click.

“On advice of legal counsel, this article is unavailable to readers of nytimes.com in Britain,” is the message they would have seen. “This arises from the requirement in British law that prohibits publication of prejudicial information about the defendants prior to trial.”

In adapting technology intended for targeted advertising to keep the article out of Britain, The Times addressed one of the concerns of news organizations publishing online: how to avoid running afoul of local publishing laws.

“I think we have to take every case on its own facts,” said George Freeman, vice president and assistant general counsel of The New York Times Company. “But we’re dealing with a country that, while it doesn’t have a First Amendment, it does have a free press, and it’s our position that we ought to respect that country’s laws.”

Jonathan Zittrain, a professor of Internet governance and regulation at Oxford University, said restricting information fit with trends across the Internet. “There’s a been a sense that technology can create a form of geographic zoning on the Internet for many years now — that they might not be 100 percent effective, but effective enough,” Mr. Zittrain said. “And there’s even a sense that international courts might be willing to take into account these efforts.

Plans were made at The Times over the weekend to withhold print versions of the article in Britain, as well as news agency and archived versions.

But the issue of the Web was more complicated.

Richard J. Meislin, the paper’s associate managing editor for Internet publishing, said the technological hurdle was surmounted by using some of The Times’s Web advertising technology. The paper could already discern the Internet address of users connecting to the site to deliver targeted marketing, and could therefore deliver targeted editorial content as well. That took several hours of programming.

“It’s never a happy choice to deny any reader a story,” said Jill Abramson, a managing editor at The Times. “But this was preferable to not having it on the Web at all.”"
This sets an interesting precedent - if the NY Times is willing to filter content for one jurisdiction to avoid contempt of court problems, how long will it be able to avoid filtering for possible libel issues?

Monday, August 28, 2006

Yet another argument against ID cards - Australian edition

The Register reports:
Australia's identity card system was routinely searched for personal reasons by government agency employees, some of whom have been sacked.

Police are now investigating allegations of identity fraud resulting from the security breaches.

There were 790 security breaches at government agency Centrepoint involving 600 staff. Staff were found to have inappropriately accessed databases containing citizens' information. The databases are part of a massive federal Government smart card project which will link medical, welfare, tax and other personal data on Australia's 17m citizens.

Thursday, August 10, 2006

AOL Searches Now Available Online

Hot on the heels of AOL's disclosure of private customer information, the AOL Search Database has put that information into a searchable format for the world to see.

Wednesday, August 09, 2006

Still more on the AOL disclosure - what your internet history might say about you

CNET News looks at the AOL disclosure to show how much information your internet history can reveal about your life. Two examples:
A woman affiliated with Temple University in Philadelphia, perhaps a student, shared her life's troubles with AOL Search this spring. That woman, user 591476, typed:
  • replica loius vuitton bag
  • how to stop bingeing
  • how to secretly poison your ex
  • how to color hair with clairol professional
  • girdontdatehim.com
  • websites that ask for payment by checks
  • south beach diet
  • nausea in the first two weeks of pregnancy
  • breast reduction
  • how to starve yourself
  • rikers island inmate info number
  • inmatelookup.gov
  • www.tuportal.temple.edu
  • how to care for natural black hair
  • scarless breast reduction
  • pregnancy on birth control
  • temple.edu
  • diet pills
Some AOL users seem to be worried that an abusive partner in a relationship may come back to hurt them. This person, AOL user 005315, searched for information about prison inmates, gang members, sociopaths in relationships, and women who were murdered in southern California last year:
  • resources for utility bill paying assistance in southern california
  • section 8 housing southern california
  • los angeles county ca. gang member pictures
  • orange county california jails inmate information
  • fractured ankle
  • letters and responses written by women to emotionally
  • abusive partners
  • men that use emotional and physical abandonment to control their partner
  • warning signs of a mans infidelity or sexual addiction
  • the sociopathic relationship
  • southern california newspaper stories about woman murdered by boyfriend in pomona december2005
  • names of females murdered or found dead in pomona california in 2005
  • characteristics of a sociopath in a relationship
  • a person that shows lack of empathy
  • help in writing a letter to a abusive narcissistic ex boyfriend
  • how to hurt the narcissistic man
  • retaliating against the narcisisstic man

The NY Times puts a face on one of AOL's victims

A Face Is Exposed for AOL Searcher No. 4417749 - New York Times:
Buried in a list of 20 million Web search queries collected by AOL and recently released on the Internet is user No. 4417749. The number was assigned by the company to protect the searcher’s anonymity, but it was not much of a shield.

Thelma Arnold’s identity was betrayed by AOL records of her Web searches, like ones for her dog, Dudley, who clearly has a problem.

No. 4417749 conducted hundreds of searches over a three-month period on topics ranging from “numb fingers” to “60 single men” to “dog that urinates on everything.”

And search by search, click by click, the identity of AOL user No. 4417749 became easier to discern. There are queries for “landscapers in Lilburn, Ga,” several people with the last name Arnold and “homes sold in shadow lake subdivision gwinnett county georgia.”

It did not take much investigating to follow that data trail to Thelma Arnold, a 62-year-old widow who lives in Lilburn, Ga., frequently researches her friends’ medical ailments and loves her three dogs. “Those are my searches,” she said, after a reporter read part of the list to her." ...

Ms. Arnold, who agreed to discuss her searches with a reporter, said she was shocked to hear that AOL had saved and published three months’ worth of them. “My goodness, it’s my whole personal life,” she said. “I had no idea somebody was looking over my shoulder.”

In the privacy of her four-bedroom home, Ms. Arnold searched for the answers to scores of life’s questions, big and small. How could she buy “school supplies for Iraq children”? What is the “safest place to live”? What is “the best season to visit Italy”?

Her searches are a catalog of intentions, curiosity, anxieties and quotidian questions. There was the day in May, for example, when she typed in “termites,” then “tea for good health” then “mature living,” all within a few hours.

Her queries mirror millions of those captured in AOL’s database, which reveal the concerns of expectant mothers, cancer patients, college students and music lovers. User No. 2178 searches for “foods to avoid when breast feeding.” No. 3482401 seeks guidance on “calorie counting.” No. 3483689 searches for the songs “Time After Time” and “Wind Beneath My Wings.”

At times, the searches appear to betray intimate emotions and personal dilemmas. No. 3505202 asks about “depression and medical leave.” No. 7268042 types “fear that spouse contemplating cheating.”
If this story disturbs you, you might want to visit Digital Rights Ireland and support our campaign against data retention.

Tuesday, August 08, 2006

Your personal information is for sale, episode 8,763 - AOL reveals users search history

From Techcrunch :
AOL must have missed the uproar over the DOJ’s demand for “anonymized” search data last year that caused all sorts of pain for Microsoft and Google. That’s the only way to explain their release of data that includes 20 million web queries from 650,000 AOL users.

The data includes all searches from those users for a three month period this year, as well as whether they clicked on a result, what that result was and where it appeared on the result page. It’s a 439 MB compressed download, expanded to just over 2 gigs. The data is available here (this link is directly to the file) and the output is in ten text files, tab delineated.

The utter stupidity of this is staggering. AOL has released very private data about its users without their permission. While the AOL username has been changed to a random ID number, the abilitiy to analyze all searches by a single user will often lead people to easily determine who the user is, and what they are up to. The data includes personal names, addresses, social security numbers and everything else someone might type into a search box.

The most serious problem is the fact that many people often search on their own name, or those of their friends and family, to see what information is available about them on the net. Combine these ego searches with porn queries and you have a serious embarrassment. Combine them with “buy ecstasy” and you have evidence of a crime. Combine it with an address, social security number, etc., and you have an identity theft waiting to happen. The possibilities are endless.

Marketers are going nuts over the possibilities, users are calling for a boycott of AOL, and others are just enraged:

User 491577 searches for “florida cna pca lakeland tampa”, “emt school training florida”, “low calorie meals”, “infant seat”, and “fisher price roller blades”. Among user 39509’s hundreds of searches are: “ford 352″, “oklahoma disciplined pastors”, “oklahoma disciplined doctors”, “home loans”, and some other personally identifying and illegal stuff I’m going to leave out of here. Among user 545605’s searches are “shore hills park mays landing nj”, “frank william sindoni md”, “ceramic ashtrays”, “transfer money to china”, and “capital gains on sale of house”. Compared to some of the data, these examples are on the safe side. I’m leaving out the worst of it - searches for names of specific people, addresses, telephone numbers, illegal drugs, and more. There is no question that law enforcement, employers, or friends could figure out who some of these people are.

There is some really scary stuff in this data.

Bear in mind that this was not an accidental or inadvertent disclosure - much less a security breach. AOL took a deliberate and planned decision to release this information.

Wednesday, August 02, 2006

Today's outrage - Millions of children to be fingerprinted

The Observer reports that:
British children, possibly as young as six, will be subjected to compulsory fingerprinting under European Union rules being drawn up in secret. The prints will be stored on a database which could be shared with countries around the world.

The prospect has alarmed civil liberties groups who fear it represents a 'sea change' in the state's relationship with children and one that may lead to juveniles being erroneously accused of crimes. Under laws being drawn up behind closed doors by the European Commission's 'Article Six' committee, which is composed of representatives of the European Union's 25 member states, all children will have to attend a finger-printing centre to obtain an EU passport by June 2009 at the latest.

The use of fingerprints and other biometric data is designed to prevent passport fraud and allow European member states to meet US entry visa requirements, but the decision to fingerprint children has disturbed human rights groups.

The civil liberties group Statewatch last night accused EU governments of taking decisions in which 'people and parliaments have no say'. It said the committee's decisions were simply based on 'technological possibilities - not on the moral and political questions of whether it is right or desirable.'

'This is a sea change,' said Ben Hayes, spokesman for Statewatch. 'We are going from fingerprinting criminals to universal fingerprinting without any real debate. In the long term everyone's fingerprints will be stored on a central database. You have to ask what will be the costs to a person's privacy.'
[Edited to add]

It's not clear what effect this may have in Ireland. The legal basis is Regulation 2252/2004 which is a Schengen act and therefore not binding on Ireland. The Government's current policy is not to include fingerprints on passports - see the Dept. of Foreign Affairs FAQ. However, if and when Ireland does enter Schengen this will be a fait accompli.

Tuesday, July 25, 2006

When surveillance meets bureaucracy

"Innocent People Placed On 'Watch List' To Meet Quota":
You could be on a secret government database or watch list for simply taking a picture on an airplane. Some federal air marshals say they're reporting your actions to meet a quota, even though some top officials deny it.

The air marshals, whose identities are being concealed, told 7NEWS that they're required to submit at least one report a month. If they don't, there's no raise, no bonus, no awards and no special assignments.

"Innocent passengers are being entered into an international intelligence database as suspicious persons, acting in a suspicious manner on an aircraft ... and they did nothing wrong," said one federal air marshal. ...

What kind of impact would it have for a flying individual to be named in an SDR?

"That could have serious impact ... They could be placed on a watch list. They could wind up on databases that identify them as potential terrorists or a threat to an aircraft. It could be very serious," said Don Strange, a former agent in charge of air marshals in Atlanta. He lost his job attempting to change policies inside the agency.
(via MetaFilter)

Tuesday, July 18, 2006

UK Government implements "Minority Report" - Department of Pre-Crime awaits

The Register reports that the UK government plans to tackle crime at birth by means of yet more entries in the proposed "Children's Index" database:
Children's Minister Hilary Armstrong was due today to outline what could become one of Project Blair's most ambitious, misguided and hubristic projects yet. The Government will attempt to identify children at risk of failure, violent behaviour or criminality at birth, and take the necessary corrective actions to steer them onto a law-abiding and successful path.

Ironically, Armstrong is floating these proposals just as this same predictive approach to future behaviour patterns is becoming discredited. A couple of national newspapers, the Independent and The Observer, appear to have seen outlines of the plans. According to the Independent, midwives, doctors and nurses are to be "asked to identify 'chaotic' families whose babies are in danger of growing up to be delinquents, drug addicts and violent criminals." The plan will be backed up by "research" which "shows that children from the most dysfunctional families are 100 times more likely to abuse alcohol commit crimes or take drugs", and a "source" close to Armstrong says: "It is the 'supernanny' model.' There is no reason why midwives who ask mothers lots of questions anyway can't ask a few more about the family circumstances and identify families where there may be problems. We need to intervene early to stop the cycle that leads to social exclusion."
The Register has some interesting comments about the quality of the data we can expect this database to contain:
The information they're sharing, meanwhile, will become more junk-like as the boxes they need to check and the fields they need to fill in multiply. Social workers, police, anyone who's given the job of spotting early warning signs will feel the need to put something in the box, for all too obvious reasons. What's it going to look like in five years time when some kid on your books gets beaten to death, and it turns out you didn't notice anything? The empty box clearly indicates negligence on your part. So the slightest, part-imagined 'signs' will go down, the people you're sharing the data with will see this 'concern' flagged and put in some 'signs' of your own. And as Brian Sheldon, Emeritus Professor, University of Exeter and former director of the Centre for Evidence-Based Social Work puts it, once social workers decide people need visiting, "they need visiting a lot." Or as Hine says, "if you're looking for problems, you will find problems."

The cases will tend to build themselves, the effect much magnified by the 'share and deploy' approach, and they'll also tend to focus on the easier cases. The ones who're easier to get at and who're on the receiving end of self-generating warning signs will get lots of attention (despite quite possibly never having needed any in the first place), and quite possible acquire real problems because of this, while harder cases of real need may not get any attention at all.

At ground level, midwives (and one presumes other professionals) are beginning to see the collateral damage of the Blair Project's data kleptocracy (Sheldon diagnoses this as symptomatic of a country suffering from obsessive-compulsive disorder). Some of the women midwives are dealing with have noticed that their histories can be taken down and used against them, and that it does not matter whether or not they have successfully coped, or are successfully coping with whatever the problem might have been. If you tell someone, it will be flagged as a 'concern' and will breed more concerns, and turn you into a 'case'. So they're starting to withhold information, and as midwives, and other professionals continue to ask "a few more" questions, people on the receiving end of the data kleptocracy will start to go underground.

Leaving systems built on junk science sharing junk data in pursuit of imaginary concerns and a pre-defined criminal underclass, while the rest of us hide.( Emphasis added)
For another perspective see the proceedings of the LSE conference "Children: Over Surveilled, Under Protected".

Monday, July 17, 2006

Online Anonymity - Ryanair Edition (continued)

The Irish Times reports that Ryanair has lost its action seeking to identify pilots posting to a bulletin board under pseudonyms. While the judgment doesn't seem to address the privacy issues involved, it does look at motive behind the action, and notes that "when Ryanair set up an investigation to find out who was behind the website, the real purpose of that investigation was to 'break the resolve' of pilots to seek better terms and conditions." This is an important finding - it indicates that actions to identify internet users should be assessed carefully to see whether there is some improper purpose underlying the application. From the Irish Times:
A High Court judge has rejected claims by Ryanair that its pilots or their unions had engaged in bullying, intimidation or isolation of other pilots over conditions imposed by Ryanair relating to training on new aircraft.

The only evidence of bullying was by Ryanair itself, Mr Justice Thomas Smyth stated yesterday. He described as "most onerous and bordering on oppression" a condition requiring pilots to pay Ryanair €15,000 for training on new aircraft in 2004. The €15,000 was payable by pilots if they left the company within five years or if Ryanair was required to engage in collective bargaining within the same period.

In a strongly worded reserved judgment, the judge dismissed a bid by the private airline for orders aimed at identifying pilots who posted messages under codenames, such as "ihateryanair" and "cantfly, wontfly" on a pilots' website. Ryanair had claimed the messages showed evidence of wrongful activity against it and its employees.

The judge also made a finding of false evidence in relation to two members of Ryanair management who had given evidence at the hearing. He held that, when Ryanair set up an investigation to find out who was behind the website, the real purpose of that investigation was to "break the resolve" of pilots to seek better terms and conditions. There was no warrant for Ryanair's action in seeking assistance from gardaí on the matter, he added.

He rejected as "baseless and false" the evidence of Ryanair director of personnel Eddie Wilson in relation to the setting up the investigation. The judge also said there was no conspiracy in relation to the setting up of the website and it was not engaged in anything unlawful. There was "no actionable wrong", he held, and dismissed Ryanair's application.

Friday, July 14, 2006

Dutch court upholds refusal to disclose file-sharers' identities

The Register reports that the Dutch decision in BREIN (holding that information about alleged filesharers had been obtained in breach of data protection law) has been upheld on appeal. The result is that litigation by the music industry will be unable to proceed.
A Dutch appeals court has thwarted attempts by the Dutch anti-piracy organisation BREIN to get the identities of file-sharers from five ISPs, including Wanadoo and Tiscali.

The court found that the manner in which IP addresses were collected and processed by US company MediaSentry had no lawful basis under European privacy laws. A lower court in Utrecht had reached a similar conclusion last year.

The court also argued that the software MediaSentry uses can't properly identify users or provide evidence of infringement.

Last year, expert witnesses at Delft University of Technology criticised MediaSentry's software for being too limited and simplistic. For instance, MediaSentry took filenames in Kazaa at face value. More importantly, the software scans all the content of the shared folder on the suspect's hard disk. In that process, it breached privacy laws.

The Dutch Protection Rights Entertainment Industry Netherlands (BREIN) represented 52 media and entertainment companies and has been investigating 42 people suspected of swapping song files. Nine file-sharers decided to settle with BREIN.

BREIN says it will go to a higher court, but lawyer Christiaan Alberdingk Thijm, who represented the ISPs, sees the decision as an important victory.

Wednesday, July 12, 2006

UK government abusing copyright to silence whistleblower

The Foreign Office is now seeking to misuse copyright law to stop a former ambassador from publishing material showing British involvement in torture. From the Guardian:
The government is threatening to sue former ambassador Craig Murray for breach of copyright if he does not remove from his website intelligence material that was censored out of his newly published memoirs.

Mr Murray has posted full texts of all passages the Foreign Office ordered deleted from the book version of Murder in Samarkand, the former Tashkent ambassador's account of alleged British complicity in torture by the despotic Uzbekistan regime. His book contains links to the website.

The passages detail CIA intelligence reports that Mr Murray says were false, and accounts of US National Security Agency intercepts and conversations with John Herbst, the US ambassador in Uzbekistan at the time. The Foreign Office says release of the material is damaging. ...

The Foreign Office is also demanding, in a claim that breaks new legal ground, that Mr Murray remove from his website the text of Foreign Office correspondence which he says he obtained officially through Freedom of Information Act and Data Protection Act requests.

The Treasury solicitors, the government lawyers, wrote to Mr Murray last week claiming: "Even if a document is released under the Freedom of Information Act or the Data Protection Act, that does not entitle you to make further reproductions of that document by, for example, putting them on your website."

Mr Murray said yesterday: "If the media do not react to this, they will lose the ability to report in any detail material released under the Freedom of Information Act. The documents in question are the supporting evidence for my book. The government continues to claim my story is untrue."
It is unacceptable that a government can silence its critics by relying on copyright law. The approach taken by US law is preferable, under which government publications don't benefit from copyright protection. After all, this material has already been paid for by the taxpayer.

Tuesday, July 11, 2006

Henry Porter on ID cards

Henry Porter gives an eloquent statement of the case against ID cards in today's Guardian:
Some, like the editor of Prospect, David Goodhart, have attempted to portray the cards as "badges of citizenship embodying the idea of the contract between citizen and state". The argument is superficially comforting. "They help us to know who is in the country and what their status is and to protect the precious entitlements of all existing citizens." There is no mention in his recent essay of the database or the terrible potential for intrusion and control. And of course the idea of this being a contract is ridiculous when one party is being forced to sign or face penalties. The notion of a badge of citizenship is codswallop being put about by people who are too impressed by authority and too weak to oppose it.

When reading the ID card bill I am constantly struck by its minatory tone - the threats of fines and the general contempt for the average citizen. There's a reason for this. Rather than being something that is designed to help us, the card and the register are, in fact, tools of government control and surveillance. Over and above the information you have supplied at enrolment (please note the voluntary connotations of the word enrolment ) your file on the NIR will build an entire picture of your life - your hospital visits, your children's schools, your driving record, your criminal record, your finances, insurance policies, your credit-card applications, your mortgage, your phone accounts (and, one presumes your phone records), and your internet service providers.

Every time you get a library card, make a hire-purchase agreement, apply for a fishing or gun licence, buy a piece of property, withdraw a fairly small amount of your money from your bank, take a prescription to your chemist, apply for a resident's parking permit, buy a plane ticket, or pay for your car to be unclamped you will be required to swipe your card and the database will silently record the transaction. There will be almost no part of your life that the state will not be able to inspect. And it will be able to use the database to draw very precise conclusions about the sort of person you are - your spending habits, your ethnicity, your religion, your political leanings, your health and even perhaps your sexual preferences. Little wonder that MI5 desired - and was granted - free access to the database. Little wonder that the police, customs and tax authorities welcome the database as a magnificent aid to investigation.

But know this: from the moment the database goes live, we will become subjects not citizens and each one of us will be diminished in relation to the state's power.

Something enormous and revolutionary is about to happen to us. We are giving the most precious part of ourselves to the government, allowing it complete freedom to roam through our privacy. And it's not just to this government, but to the governments of the future, the nature of which we cannot possibly know. And it's not just our privacy - it is the rights and privacy of future generations. While we are comfortable about handing this information over to the state, the citizens of the future may feel strongly about our complacency and our faith in the British government. We have a duty to those people, just as all the people who fought for the rights we enjoy today felt a sense of obligation to us.

The prime minister asks us to trust him and implies that abuse of a database would be unthinkable in Britain. But after the lies before the invasion of Iraq, the revelations of the Hutton inquiry and the evidence about rendition flights using British airspace I would suggest that we treat these sorts of assurances and appeals with the utmost suspicion.

Remember this government's attack on liberty. Remember what we have already lost - the campaign that has diminished defendants rights, introduced punishment without a court deciding that the law has been broken, restricted protest and speech and even assembly. Blair is unabashed about his record and has taken to describing civil liberties as a privilege that may be removed from someone the moment they become a suspect or a defendant.

I am afraid I do not trust the government's motives - nor do I trust its competence. The past decade is littered with failed government IT projects - the Child Support Agency, the immigration records, the working tax credit database, the farmers' single payment scheme are a few that come to mind. This is to say nothing of its record on security. The NIR will literally have thousands of entry points where the information on your file can be accessed.

One of the worst failures of a government database came to light a few weeks ago when the Home Office admitted that the Criminal Records Office had wrongly identified 2,700 people as having criminal records. I cannot think of a clearer case of defamation and it is surprising there is not some kind of class action against the Home Office. Not only were these people's reputations seriously damaged, many were turned down for jobs as a result of the CRO's mistake and can therefore argue for a serious loss of earnings. But the Home Office did not even apologise. It is exactly the arrogance that I fear will come to characterise all government dealings with the person in the street once this database is operational.

As I said, I am instinctively - genetically, as I put it - opposed to ID cards and the Identity Register. I am also politically opposed because as the government database grows, I believe there will be a commensurate lessening in the state's respect for each one of us. We will be reduced to the great mass of classified specimens, pinned down and itemised like dead butterflies in a showcase. Because of the power it possesses over us, I believe the government will gradually become less accountable and less responsive to the needs and wishes of the people. Whereas once politicians were our servants, they will become our masters and we their slaves.

I have philosophical objections, too. In a free country I believe that every human being has the right to define him or herself independently and without reference to the government of the time. This, I believe, is particularly important in a multicultural society such as ours. The ID card and NIR require and will bring about a kind of psychological conformity, which is utterly at odds with a culture that has thrived on individualism, defiance and the freedom to go your own way.

And it will remove the right of those who for whatever reason wish to withdraw from the cares of the world and the influence of society, to resort to the consolations of solitude and privacy without inspection from a centralised authority. Privacy, anonymity and solitude are rights, and we are about to lose them for ever.

People say that everything about you is known already. Someone has calculated that each of us appears on up to 700 databases. But the real point is that everything that is known about you will become linked up on the NIR. The register will take on a life of its own, for once you set up a system like this it becomes ineluctably compelled to find out more and more about you. That will be its hardwired purpose.

Imagine handing over the keys to your home when you are out at work to allow some faceless bureaucrat to rifle through your desk and drawers, your photograph albums and children's school reports, your bills and love letters. That is the kind of access they are going to have, and it is going to grow as time goes by and we become accustomed to this unseen presence in our lives.

Well, it's not for me. I cannot do it. I will not do it, and I hope you won't either.

Tuesday, June 13, 2006

Does Irish law protect your voicemail?

The Irish Independent has a story about wrongful access to mobile phone voice mailboxes. Although the story claims that access to voicemail messages is "a crime under the Postal and Telecommunications Act 1983", it's not clear if that is true. Section 98(1) of the 1983 Act provides:
A person who-
(a) intercepts or attempts to intercept, or
(b) authorises, suffers or permits another person to intercept, or
(c) does anything that will enable him or another person to intercept,
telecommunications messages being transmitted by [a person deemed to be authorised under the Authorisation Regulations] or who discloses the existence, substance or purport of any such message which has been intercepted or uses for any purpose any information obtained from any such message shall be guilty of an offence.
The reference to telecommunications messages being transmitted suggests that stored messages, such as voicemail messages, may not be protected by section 98.

There are two counter arguments. First, it might be said that such messages are "being transmitted" until they are first listened to. This is an incomplete solution, however, at best it would only protect new messages, with those already listened to having no protection.

Second, it could be argued that the act of dialing into the voice mail itself causes the message to be transmitted, and the interception takes place where you listen to such a message. This is given support by the very wide definition of "interception" contained in section 98:
In this section, "interception" means listening to, or recording by any means, or acquiring the substance or purport of, any telecommunications message ...
Again, though, this is an incomplete solution. If we adopt this argument, then the mobile phone company employee who listens to the message at work would not be guilty of an offence, as the (locally held) message would not be transmitted.

This article highlights, then, one problem with Irish interception law. Whatever view we take, it seems that stored messages such as voicemail do not enjoy adequate protection - and it is long past time that the 1983 Act was updated to take account of technological changes in the meantime.

Monday, June 12, 2006

You couldn't make it up: Part 2

BBC NEWS - Guantanamo suicides 'acts of war':
"The suicides of three detainees at the US base at Guantanamo Bay, Cuba, amount to acts of war, the US military says.

The camp commander said the two Saudis and a Yemeni were 'committed' and had killed themselves in 'an act of asymmetric warfare waged against us'.

Friday, June 09, 2006

You couldn't make it up

George W. Bush, 2002: "I just want you to know that, when we talk about war, we're really talking about peace."

George Orwell, 1984: "War is Peace"

via the entertaining Students for an Orwellian Society

Sunday, May 28, 2006

Amnesty launches Irrepressible.info

Amnesty International have launched a campaign against online censorship called irrepressible.info. From that site:
Irrepressible
Adj. 1) Impossible to repress or control.

Chat rooms monitored. Blogs deleted. Websites blocked. Search engines restricted. People imprisoned for simply posting and sharing information.

The Internet is a new frontier in the struggle for human rights. Governments – with the help of some of the biggest IT companies in the world – are cracking down on freedom of expression.

Amnesty International, with the support of The Observer, is launching a campaign to show that online or offline the human voice and human rights are impossible to repress.
Amnesty's UK director Kate Allen explains:
'Open your newspaper any day of the week and you will find a report from somewhere in the world of someone being imprisoned, tortured or executed because his opinions or religion are unacceptable to his government.'

So began an article in this newspaper 45 years ago called 'The Forgotten Prisoners'. The author, Peter Benenson, urged people to call on governments to stop this persecution. The 'appeal for amnesty' that he started went on to become Amnesty International, a movement that now has 1.8 million supporters in more than 100 countries around the world and continues to stand up for freedom and justice wherever it is denied.

Much has changed in those 45 years. The Iron Curtain has been torn down and apartheid has ended; we have witnessed genocide in Rwanda and ethnic cleansing in the Balkans. And the world has moved on technologically: in 1961 people were expressing their opinions in books and newsprint; Amnesty members responded to their repression by writing letters. Now we have the internet; and Amnesty is able to mobilise its supporters online to lobby governments with emails and web-based campaigning.

Sadly what remains the same is that people are still being imprisoned for peacefully expressing their beliefs. Benenson started Amnesty after reading about two students arrested in a Portuguese cafe for raising a toast to freedom: 45 years on, we were recently made aware of three young Vietnamese people arrested after taking part in an online chatroom debate about democracy.

Governments still fear dissenting opinion and try to shut it down. While the internet has brought freedom of information to millions, for some it has led to imprisonment by a government seeking to curtail that freedom. They have closed or censored websites and blogs; created firewalls to prevent access to information; and restricted and filtered search engines to keep information from their citizens.

China is perhaps the clearest example. Its internet censorship and clampdown on dissent online is sophisticated and widespread. But Amnesty has documented internet repression in countries as diverse as Iran, Turkmenistan, Tunisia, Israel, the Maldives and Vietnam.

Another massive change since 1961 has been the rising power of multinationals, but some companies have been complicit in these abuses. So Amnesty is increasingly lobbying not just governments but powerful firms to respect the rights of ordinary people.

The internet is big business, but in the search for profits some companies have encroached on their own principles and those on which the internet was founded: free access to information. The results of searches using China-based search engines run by Yahoo, Microsoft, Google and local firms are censored, limiting the information users can access. Microsoft pulled down the work of one of China's most popular bloggers who had made politically sensitive comments. Yahoo gave information to the authorities that led to people being jailed for sending emails with political content. We do not accept these firms' arguments that it is better to have a censored Google, Yahoo or Microsoft in China than none at all.

So Amnesty International is again calling on Observer readers to join with us to take a stand for basic human freedoms. The internet has the potential to transcend national borders and allow the free flow of ideas around the world. Of course there is a need for limits to free expression to protect other rights - promoting violence or child pornography are never acceptable - but the internet still has immense power and potential.

Just by logging on to my computer I can exchange views with someone in Beijing or Washington. I can read what bloggers in Baghdad think of the situation in Iraq. I can find a million viewpoints that differ from my own on any topic. It is the greatest medium for free expression since the printing press, a meeting of technology and the social, inquisitive nature of human beings and the irrepressible force of the human voice. This is the new frontier in the battle between those who want to speak out, and those who want to stop them. We must not allow it to be suppressed.
As part of the campaign they've produced some clever html which allows you to display examples of the censored material on your own site, like this:

Saturday, May 27, 2006

US Government pushing internet data retention

ZDNet reports that:
U.S. Attorney General Alberto Gonzales and FBI Director Robert Mueller on Friday urged telecommunications officials to record their customers' Internet activities, CNET News.com has learned.

In a private meeting with industry representatives, Gonzales, Mueller and other senior members of the Justice Department said Internet service providers should retain subscriber information and network data for two years, according to two sources familiar with the discussion who spoke on condition of anonymity.

The closed-door meeting at the Justice Department, which Gonzales had requested, according to the sources, comes as the idea of legally mandated data retention has become popular on Capitol Hill and inside the Bush administration. Supporters of the idea say it will help prosecutions of child pornography because in many cases, logs are deleted during the routine course of business.
The Justice Department appears to be seeking "voluntary" data retention, but there are also proposals to introduce federal legislation:
Two proposals to mandate data retention have surfaced in the U.S. Congress. One, backed by Rep. Diana DeGette, a Colorado Democrat, says that any Internet service that "enables users to access content" must permanently retain records that would permit police to identify each user. The records could only be discarded at least one year after the user's account was closed.

The other was drafted by aides to Wisconsin Rep. F. James Sensenbrenner, the chairman of the House Judiciary Committee, a close ally of President Bush. Sensenbrenner said through a spokesman last week, though, that his proposal is on hold because "our committee's agenda is tremendously overcrowded already."
If you haven't already thought about protecting your privacy online, now would be a good time to start. At the moment, the best way of ensuring anonymous communication is probably the EFF's Tor system. If you're running Windows, Torpark is a quick and easy way of getting started. From the Torpark FAQ:
Installation Instructions

1. Download and run the exe, it will extract Torpark.
2. Put the Torpark directory where you want it, like on a USB drive.
3. Run Torpark.exe

What is Torpark, exactly?

Torpark is a fully configured combination of Tor (The Onion Router) and Mozilla's browser technologies, enabled by John T. Haller's Portable Firefox. As of v1.5, the whole package is wrapped up in a nice single executable with file directory. No installation, no registry keys, no files left behind.

How can this be used?

Lots of ways! It can be used to circumvent censorship firewalls, like at work or in China. It can be used to bypass paying for internet access at a wifi cafe. It can be used at school computers so you can get full access to the internet. And best of all, if there is no key loggers secretly installed on the machine, nobody is going to know where you went, what you saw, who you spoke to, or what you said. It is all encrypted in a tunnel between your computer, and at least three others somewhere in the world. Only after your data has passed through the encrypted and constantly changing tunnel (a tor circuit) will it reach the internet as unencrypted. The data from surfing the internet goes through the same tunnel as well, passing back to you encrypted, where your computer uses Tor to decrypt it to the Torpark browser. When you need a secret and secure tunnel to surf the internet, Torpark is your mobile solution.