ID card cost rises above £5bnHopefully the fiasco of UK identity cards will deter attempts to introduce them in Ireland.
The official cost of the ID card scheme has risen by £400m to £5.31bn, the Home Office says.
The figure was released as Tony Blair announced his departure, leading to claims from the opposition that the government was "burying bad news".
The Tories also say that the actual rise in costs, when expressed in 2007/08 prices, is £640m.
The Home Office say that figure is 'concocted' and the increase was due to staff and anti-fraud expenditure.
Amid the row about the actual rise in the cost of the scheme, the Tories and Lib Dems also say that the Home Office broke the law by releasing the updated costings a month later than they should have.
Under the Identity Card Act, the government must give an update on the costs of the scheme twice a year. The latest update was due on 9 April.
Thursday, May 10, 2007
A good day to bury bad news - Labour attempts to bury spiralling cost of ID cards
Wednesday, May 09, 2007
"Mumsnet" case shows problems with forum liability for member comments
The controversial childcare expert Gina Ford today dropped her threat to sue the parenting website Mumsnet after a year-long dispute was settled out of court.Cases such as this highlight the draconian nature of English (and Irish!) libel laws, which in effect require bulletin boards and other social sites to police the actions of their users or risk being crippled by the costs (let alone the damages) of a libel action. This is difficult enough on a low-traffic site, let alone one which receives 15,000 posts a day. Quite apart from the chilling effect on freedom of expression, this also presents a competitiveness problem - why set up operations in Dublin or London when you can avail of a much more publisher friendly jurisdiction in the United States?
Lawyers for Ms Ford, author of The Contented Little Baby Book, agreed to halt legal action after the popular website agreed to pay a contribution of her costs and prevent “personal attacks” on the site.
The agreement brings to an end a bitter dispute that began more than a year ago.
Some of Mumsnets’ 60,000 members used messageboards to attack Miss Ford’s famously rigorous childcare methods.
A sarcastic comment last August accused her of “strapping babies to rockets and firing them in to south Lebanon”.
Ms Ford, 52, a strong advocate of routine, said the remarks amounted to “serious and offensive libel” and caused her huge distress.
She began legal proceedings against the site, which receives up to 15,000 internet posts a day.
Justine Roberts, the founder of Mumsnet, in turn accused Miss Ford of conducting a “menacing” campaign to stifle negative comment, which Ms Ford strongly denied.
But after a series of legal letters and an eight-week mediation period, both parties announced today that the dispute had been settled.
The exact terms of the agreement are confidential, but it is understood that Mumsnet has apologised and made a contribution to Gina Ford’s substantial legal costs to protect its individual members from legal action.
It has also agreed to abide by its own “personal abuse” policy, preventing members from making unnecessary attacks on individuals. The ban on discussing Miss Ford’s methods has also been lifted.
[Update] The Mumsnet site has now put up its own perspective on these issues:
Like many other website publishers, we have long maintained that libel law has not caught up with the digital age with the result that freedom of expression is being unacceptably curtailed. Now that we have settled our long running dispute with Gina Ford, we intend to campaign energetically for a review of how libel legislation applies to the internet.The E-Commerce Directive was intended to make online business easier by removing some of these liability fears. Unfortunately, it was drafted narrowly to apply to mere conduits (telecommunications providers), caching and hosting only. This appears to leave other online intermediaries (such as search engines, bulletin boards and content aggregators) out in the cold, unless they can bring themselves within the hosting defence. Might a bulletin board be able to rely on the hosting defence in respect of user posts? I have been unable to track down any discussion of this precise issue, but Lillian Edwards analyses a related issue in respect of eBay liability for user advertisements here.
Put crudely, the current legal situation is the rough equivalent of trying to use a set of railway signals to control the air traffic over Heathrow – the principles may be fine but different forms of communication, just like different forms of transport, require a different approach. Currently the law regards a bulletin board just as it does a newspaper or a book.
In fact the Law Commission, the body which advises the government on legislation, recognized this problem in 2002, warning that a rethink of defamation law was needed to protect freedom of speech online. At the time Hugh Beale QC, one of the law commissioners, warned: "When a website carries material to which someone objects - rightly or wrongly - it is often easier to complain to the ISP than to the author. The problem is that the law puts ISPs under pressure to remove sites as soon as they are told that the material on them may be defamatory. There is a possible conflict between the pressure to remove material, even if true, and the emphasis placed on freedom of expression by the European Convention of Human Rights."
Since then, however, no changes have been made to the law governing defamation on the internet and we believe website publishers running bulletin boards now find themselves in a similar position to that described by Mr Beale. Faced with any complaint about a bulletin board posting, website publishers, frequently small businesses or individuals with limited resources, find themselves with little choice but to remove the posting, with obvious consequences for freedom of speech.
Mumsnet has this week written to the Department of Constitutional Affairs urging the government to reconsider this area in its forthcoming consultation on defamation.
In particular we have asked to government to address these points:
1. Does holding websites liable for postings by users on their bulletin boards have the effect of unacceptably curtailing freedom of expression?
2. Is a website which swiftly removes material following a complaint protected from liability for the posting? And how swift is swift?
3. Should the different nature of bulletin board communication be taken into account in assessing whether a complainant has been defamed? For instance if a single poster makes a defamatory comment but is immediately rebutted by a large number of users should the resulting thread be considered as defamatory? Or should there be a requirement to consider bulletin board conversations in the whole?
We would stress that we accept that individuals have a right to protect their reputations. However this right always has to be balanced against the rights of others to freedom of expression. At present we believe that this balance is not struck in the right place.
Wednesday, April 04, 2007
UK Interim data retention measures published
The telescreen: coming soon to a street near you
Britain is already one of the most watched nations on earth and now "talking” CCTV cameras are to be installed in 20 areas across the country.As usual, Eric Blair was well ahead of Tony Blair:
The loudspeakers will allow CCTV operators to bark orders at people committing anti-social behaviour.
'Smith!' screamed the shrewish voice from the telescreen. '6079 Smith W.! Yes, you! Bend lower, please! You can do better than that. You're not trying. Lower, please! That's better, comrade. Now stand at ease, the whole squad, and watch me.'
Monday, April 02, 2007
Eric Blair watched by Tony Blair
This is London takes a look at the pervasive surveillance surrounding George Orwell's former home:
According to the latest studies, Britain has a staggering 4.2million CCTV cameras - one for every 14 people in the country - and 20 per cent of cameras globally. It has been calculated that each person is caught on camera an average of 300 times daily.
Use of spy cameras in modern-day Britain is now a chilling mirror image of Orwell's fictional world, created in the post-war Forties in a fourth-floor flat overlooking Canonbury Square in Islington, North London.
On the wall outside his former residence - flat number 27B - where Orwell lived until his death in 1950, an historical plaque commemorates the anti-authoritarian author. And within 200 yards of the flat, there are 32 CCTV cameras, scanning every move.
Orwell's view of the tree-filled gardens outside the flat is under 24-hour surveillance from two cameras perched on traffic lights.
The flat's rear windows are constantly viewed from two more security cameras outside a conference centre in Canonbury Place.
In a lane, just off the square, close to Orwell's favourite pub, the Compton Arms, a camera at the rear of a car dealership records every person entering or leaving the pub.
Within a 200-yard radius of the flat, there are another 28 CCTV cameras, together with hundreds of private, remote-controlled security cameras used to scrutinise visitors to homes, shops and offices.
The message is reminiscent of a 1949 poster to mark the launch of Orwell's 1984: 'Big Brother is Watching You'.
Saturday, March 31, 2007
Zooomr - Free pro photo hosting for bloggers
The only condition - you must host one of your blog photos with them. This is mine.
I'm very interested to see how Zooomr stacks up against Flickr. Unfortunately both have an annoying problem - try giving the url to somebody who isn't already familiar with the fun world of Web 2.0 naming. Chances are they'll end up at flicker.com, zoomr.com or zoomer.com - all of which are (now very valuable because of all the misdirected traffic) parked domains. In effect, Flickr and Zooomr have a self-inflicted typosquatting problem.
Wednesday, March 28, 2007
Blogger beware: Blog libel and privacy action settled for £150,000
Background to the case:
Two former business partners of advertising boss Sir Martin Sorrell launched a "vicious" campaign against him on blogs and emails, a court heard today.
One of his former associates referred in a private email to the WPP boss as a "mad dwarf" and described the company's former chief operating officer in Italy as a "nympho schizo", the High Court in London was told.
Marco Benatti, WPP's former manager in Italy, and his lieutenant Marco Tinelli, were spurred to publish defamatory remarks after Sir Martin sacked Mr Benatti over allegations of financial irregularities at WPP's Italian business, Sir Martin's barrister said.
Opening his case at a libel and invasion of privacy trial, Desmond Browne QC said the two men had taken "countermeasures" against Sir Martin and WPP's chief operating officer in Italy, Daniela Weber. ...
The "counter-measures" against Sir Martin included a blog that appeared in March last year containing a "host of libels" against the WPP boss, Mr Browne said.
Although the blog was taken down after three days, another one appeared a month later, he said.
"The day that Sir Martin managed to get the blog taken down, Mr Benatti emailed his friends saying that blogs were like mushrooms, they sometimes pop up again the next time it rains," Mr Browne said.
"What could be a stronger pointer to Mr Benatti's knowledge of what was going on and his being the architect of the whole exercise than that email shortly after the blogs had been taken down suggested that blogs were like mushrooms?"
Mr Browne said the other "countermeasure" was a series of emails that included a "vicious Jpeg image grossly intruding into the privacy of Sir Martin and Ms Weber".
"Naturally it would be to intrude further to even start to describe them. We say Mr Tinelli was directly involved in the dissemination of that vicious image.
"There is no doubt that he felt just as bitterly towards Sir Martin and Ms Weber as did his boss, Mr Benatti. I say 'no doubt' because on the very morning of the day the images were sent out by email he referred to them as the mad dwarf and the nympho schizo."
Mr Browne said that the two men had taken "elaborate steps to cover their tracks" but that computer evidence implicated them.
Friday, March 23, 2007
Data Protection Commissioner Guidance on CCTV in the Workplace and Biometrics in Schools
Significantly, the biometrics guidance takes a different approach to that recently adopted in England. The English approach has been to accept that once a minor is mature enough to give an informed consent to the use of biometrics in schools, parental consent is no longer required. Under this guidance, however, parental consent will always be necessary in the case of a minor, and if the minor is aged twelve or above they must also consent:
In the context of students attending a place of education, the Data Protection Commissioner would stipulate that the obtaining of consent is of paramount importance when consideration is being given to the introduction of a biometric system. It is the Commissioner’s view that when dealing with personal data relating to minors, the standards of fairness in the obtaining and use of data, required by the Data Protection Acts, are much more onerous than when dealing with adults. Section 2A(1)(a) of the Data Protection Acts states that personal data shall not be processed by a data controller unless the data subject has given his/her consent to the processing, or if the data subject by reason of his/her physical or mental incapacity or age, is or is likely to be unable to appreciate the nature and effect of such consent, it is given by a parent or guardian etc. While the Data Protection Acts are not specific on what age a subject will be able to consent on their own behalf, it would be prudent to interpret the Acts in accordance with the Constitution. As a matter of Constitutional and family law a parent has rights and duties in relation to a child. The Commissioner considers that use of a minor’s personal data cannot be legitimate unless accompanied by the clear signed consent of the child and of the child’s parents or guardian.Two aspects of this guidance may be significant in the future - in requiring a double lock (both parental and child consent) is there a possibility of a knock on effect in the area of marketing to children? (Where previously the consent of a child mature enough to give an informed consent would have sufficed.) Also, in imposing a strict test for determining when the use of biometrics is proportionate or necessary in education, will there be an impact on the use of biometrics in other sectors?
As a general guide, a student aged eighteen or older should give consent themselves. A student aged from twelve up to and including seventeen should give consent themselves and, in addition, consent should also be obtained from the student’s parent or guardian. In the case of children under the age of twelve, consent of a parent or guardian will suffice. All students (and/or their parents or guardians as set out above) should, therefore, be given a clear and unambiguous right to opt out of a biometric system without penalty. Furthermore, provision must be made for the withdrawal of consent which had previously been given.
The Register has a good discussion of the biometrics guidance note here. I've previously blogged about this issue here.
Thursday, March 22, 2007
Blogger beware - legal issues facing Irish bloggers
Tuesday, February 27, 2007
Function creep in action: Mobiles may be checked after crashes
Motorists face having their mobile phone records checked after a routine accident, under proposals unveiled by the Government yesterday...Remember - data retention was sold on the basis that it was necessary to prevent terrorism and serious crime.
In the review the Department for Transport paper says: "We will look at ways to make it easier for the police to be able to follow the process of investigating whether mobile phone use was a contributory factor in an accident and thus prosecute more offenders."
According to police sources this would entail lowering the seniority of both the officer who can check the records and the threshold of the severity of the accident.
Where the use of a phone is suspected to have been a cause in the accident, it is straightforward to check when calls were received or made, irrespective of whether the call was made on a hands-free or hand-held device.
If the phone were destroyed, police would, under the proposals, be able to use call records.
Data Retention in Ireland - stealth, bad faith, and contempt for the democratic process
"The history of data retention law in Ireland has been marked by stealth, bad faith, and a shocking contempt for the democratic process. The 2002 Direction in particular stands out as an attempt to make law in secret, by the abuse of an unrelated statutory power, and then to stymie any judicial review by directing the recipients of the Direction to remain silent as to its existence. Moreover, when finally forced by the Data Protection Commissioner to proceed by primary legislation, the Department of Justice did so in 2005 without notice, in a way calculated to exclude any public scrutiny, and ignoring earlier assurances that draft legislation would be published and debated."PDF of the article here.
Thursday, February 15, 2007
.ie Domain Disputes Multiply
There have been 10 complaints lodged with WIPO under the .ie Dispute Resolution Policy to date - resulting in four decisions transferring the domain to the complainant, three complaints which were terminated before decision (presumably because the respondent decided to voluntarily relinquish the domain), and just two complaints denied. Not a bad batting average for complainants.
More filesharing litigation coming to Ireland?
my home phone rang this morning with a little surprise for me. it was a representative of bt who asked me to confirm that i have a broadband service with them. when i said he did, he told me they had been contacted by paramount movies (as far as i can see there is no entity of this name, but who am i to split hairs) to say i was sharing a movie of theirs, an inconvenient truth. he asked me to remove it from my pc because if they didn't they could take further action.
Tuesday, February 13, 2007
Commission to make life easier for online businesses by streamlining consumer law
The European Commission will overhaul European contract law to make internet selling easier, more reliable and more efficient.Hopefully this will also review the areas of overlap between these directives and the E-Commerce Directive.
The commission has opened consultation on proposed changes that will affect eight EU Directives.
Recognising that e-commerce is hampered by a mass of conflicting national laws, the commission has proposed changes to Directives which it hopes will, when transferred into national laws, bring the law into line with technological developments.
'There is an urgent need for action, the world is moving so fast and Europe risks lagging behind', said Meglena Kuneva, the new EU Commissioner for Consumer Affairs, in her first press conference in Brussels. 'We need a root and branch review of consumer rules. At the moment, consumers are not getting a fair deal online, and complex rules are holding back the next generation of bright business ideas. We must find new solutions to new challenges.'
The commission believes that online businesses would benefit significantly if doubts about the legal implications of cross-border trading were removed.
'Consumer confidence is a key factor determining how and when consumers spend their money in different sectors of the economy,' said a Commission statement. 'All the evidence is that consumers are not yet comfortable enough in the digital and online world to seize its full potential. Only a tiny fraction – six per cent of EU consumers – are currently shopping online cross border.'
The commission will review all consumer contract law, which will involve a review of eight directives. They are: the Unfair Contract Terms Directive and the Directive on Sale of Consumer Goods and Guarantees; the Distance Selling Directive; the Doorstep Selling Directive; the Package Travel Directive; the Timeshare Directive; the Directive on Injunctions; and the Price Indication Directive.
Tuesday, January 30, 2007
NTR Deal introduces number plate surveillance
It is understood that NTR will be operating the toll on behalf of the State, which will effectively become the new landlord. This will involve photographing the registration of every vehicle and billing them unless they have a prepaid arrangement... Drivers are only tolled now if they cross the West-Link bridge. Under the new deal, everyone using the M50 will be charged.Expect this to be used to justify the roll out of number plate recognition and the monitoring of all car journeys.
Wednesday, January 17, 2007
Garda leaks and the right to privacy
A family who were forced to leave their new home in Kerry because of the leaking of confidential information by gardaà to journalists have been awarded €70,000 in the High Court.This case follows the 1997 decision in Hanahoe v. Hussey where gardaà tipped off the media to the fact that a solictor's office would be searched under a search warrant, leading to a "media circus" when gardaà arrived with damage to the reputation of the firm, and ultimately resulting in an award of £100,000 in damages. In that case, the basis for the decision was that the wrongful and negligent disclosure of this information amounted to negligence under the principles in Ward v. McMaster. It's not clear from the media coverage whether the decision in this case goes further, or whether data protection principles were also considered. (Compare section 7 of the Data Protection Acts, 1988-2003, creating a duty of care in respect of the handling of personal data.)
Alan and Phyllis Gray and their son Francis are originally from Blanchardstown in Co Dublin but moved to Ballybunion under the Rural Resettlement Programme.
They sued the Minister for Justice for breach of privacy.
They say they had to leave their home after gardaà leaked to the media that Mr Gray's nephew, who had served a sentence for rape, was staying with them.
It does, however, represent an interesting application of the Hanahoe v. Hussey principle that public bodies may owe you a duty of care to keep certain information confidential. It also reflects Hanahoe v. Hussey in that it shows a judicial willingness to impose vicarious liability in respect of unauthorised garda disclosures.
Update: Eoin O'Dell links to the full decision here with an interesting discussion of the issues involved.
Wednesday, January 10, 2007
Bar Camp talk - Who owns software?
Come to Bar Camp South East and find out. I'll be talking on the topic of "Who owns software?" - taking a practical look at the problems of determining who owns copyright and other rights in software and giving tips as to how you can protect your position.
[edited to add] I've since published an article dealing with these topics in more detail.
Tuesday, December 12, 2006
From "the innocent have nothing to fear" files - mortgage brokers selling financial information on buyers to estate agents
Hopefully we'll remember this the next time somebody tries to tell us that if you've done nothing wrong, you've nothing to fear.
Wednesday, December 06, 2006
From "the innocent have nothing to fear" files - police kept record of beautiful women
STOCKHOLM, Sweden - Two Swedish border control officers risk disciplinary action for keeping a photo collection of 'exceptionally beautiful' women who passed through their checkpoint, police officials said Tuesday.
The officers, who were working at a ferry terminal near Stockholm, made photocopies of the women's passport photos and placed them in a binder. They also noted the date of birth next to each entry, the Stockholm police department said.
The binder contained instructions on how to compile the collection, and orders to make backup copies in case the binder would go missing or be confiscated by 'evil-minded bores,' police said.
Friday, December 01, 2006
Irish law on metatags and keywords
As cybersquatting declines we find that trade mark owners now have to defend their names in a different context. As search engines become more sophisticated, users are tending to rely on them as their primary means of navigation. Rather than type in a domain name directly (or rely on a bookmark), many users will simply enter a term—such as a company name or product – into a search engine, expecting the site they are looking for to appear high in the list of results. Consequently, the importance of domain names is diminished and search engines take on a new prominence. As Nielsen puts it:
“Web users are growing ever-more search dominant. Search is how people discover new websites and find individual pages within websites and intranets. Unless you're listed on the first search engine results page … you might as well not exist.”
This poses a new problem for trade mark holders—what happens when a competitor uses their trade mark in such a way that a person searching for the term will be shown a competing site in the list of results, or will be shown an advertisement for the competitor? ...
At first glance the unauthorised use of trade marks as metatags or keywords might seem to be a clear infringement of the mark in question. The trade mark holder will certainly argue that the metatag or keyword improperly takes advantage of the goodwill in the trademarked term and confuses the user into believing that there is some link between the trade mark and the search results or advertisements displayed in response. It can also be argued that the search engine is itself guilty of infringement by selling the trademarked term as a keyword. In addition, the tort of passing-off may be available.
However, look more closely and the position becomes more complicated. Trade mark law was not drafted with metatags or keywords in mind, making it difficult to bring these situations within the legislative language. There will be some situations where the trade mark use is legitimate, for example, a company which manufactures spare parts for BMW cars might be entitled to use “spare parts suitable for BMW” in its metatags.
The likelihood of consumer confusion may also be less in metatag / keyword cases as the trade mark is being used “invisibly” — that is, in a way which is not directly visible to the user, reducing the likelihood that the user will associate the search result or the advertisement with the trade mark. If a search engine faces liability for selling trademarked keywords, it may be hard to determine whether that liability is direct or merely contributory. (Some cases suggest that the search engine should not be liable for the keywords chosen by its clients.)
In addition, some would argue that provided users are not confused, presenting advertisements for competing goods alongside search results is no more objectionable than a shop placing similar products in the same aisle.
Friday, November 03, 2006
Your personal information is for sale: Bank worker uses information to stalk model
A 27-year-old former bank official who harassed Irish model Glenda Gilson and her family has been given a three month suspended sentence and ordered to stay 100 yards from the victims.Despite Judge McMahon's comments, I suspect that it will take many more cases like this before people realise the dangers of their private information being open to abuse.
Daniel Rooney, of Castleknock Cottages, Castleknock, pleaded guilty at Dublin Circuit Criminal Court, to harassment of the Gilson family by persistently communicating with Glenda Gilson and her parents Noel and Aileen Gilson by e-mail and telephone at various locations on dates between November 12, 2004 and March 21, 2005.
Defence counsel Mr Luigi Rea BL, said Rooney was underachieving at that time in his life and he had became "jealous and obsessed" about Miss Gilsons progress in her modelling career. He had used his computer skills to "obtain telephone numbers he should not have".
Judge Bryan McMahon said one should not under estimate the "sinister impact these calls from a unknown quarter" can have on their victims but said he would take the mitigating factors into account and treat this as an "aberration".
He said this case was a "a feature of modern technology and mobile phones and the access to people on these phones" and that it was "indicative of the personal data of all citizens" which corporations hold.
Garda Deirdre Conway told Mr Paul Carroll BL, prosecuting, that there had been 49 calls to the family over the five month period. She said the harassment began on November 12, 2004, when Miss Gilsons model agency, Assets, received a call and an e-mail purporting to be from a friend.
It soon became evident that the caller was using a false name as he started shouting abuse about Miss Gilson and her career. Miss Gilson later received abusive calls on the land line at her parents home and also on her mobile. Many of the calls made to Miss Gilson’s home were answered by her parents...
Mr Rooney worked for AIB at the time and had been able to access the phone numbers though his work.
Friday, October 27, 2006
Your personal information is for sale: Call centre edition
One in 10 of Glasgow's financial call centres has been infiltrated by criminal gangs, police believe.Expect data retention to be a goldmine for criminals.
The scam works by planting staff inside offices or by forcing current employees to provide sensitive customer details.
The information is then used to steal identities and fraudulently set up accounts or transfer money...
Det Ch Insp Derek Robertson of Strathclyde Police told the BBC's Newsnight Scotland programme that there were a large number of call centres in the Glasgow area...
"I would say approximately 10% have been infiltrated in the past and we are working very hard to reduce that number."
Detectives believe that criminal crews are sent out to recruit volunteers to work in the centres.
Once they agree, they are asked to supply financial information in return for a fee.
Another tactic is to identify pubs where call centre workers visit and intimidate the employees to pass on the details.
Det Ch Insp Robertson said: "There are a number of different ways to do it.
"We know of organised crime groups who are placing people within the call centres so that they can steal customers' data and carry out fraud and money laundering.
"We also know of employees leaving the call centres and being approached and coerced, whether physically, violently or by being encouraged to make some extra money.
"And of course you have the disgruntled employee who may turn their hand to fraud just to benefit themselves."
Sunday, October 22, 2006
UK rules requiring all pub-goers to be fingerprinted at the door
The government is is funding the roll out of fingerprint security at the doors of pubs and clubs in major English cities.Edited to add:
Funding is being offered to councils that want to have their pubs keep a regional black list of known trouble makers. The fingerprint network installed in February by South Somerset District Council in Yeovil drinking holes is being used as the show case...
The council had assumed it was its duty under the Crime and Disorder Act (1998) to reduce drunken disorder by fingerprinting drinkers in the town centre.
Some licensees were not happy to have their punters fingerprinted, but are all now apparently behind the idea. Not only does the council let them open later if they join the scheme, but the system costs them only £1.50 a day to run.
Oh, and they are also coerced into taking the fingerprint system. New licences stipulate that a landlord who doesn't install fingerprint security and fails to show a "considerable" reduction in alcohol-related violence, will be put on report by the police and have their licences revoked.
Ralf Bendrath kindly posted a link to his detailed analysis of this measure.
Samizdata have an enlightening take on the abuse of regulatory authority behind these rules.
Thursday, September 21, 2006
Your personal information is for sale: Italian telco in wiretapping scandal
Telecom Italia has been in the headlines in recent weeksOf course the information stored by the same telecoms companies under data retention won't be abused. Oh no. Perish the thought.
Italy's justice minister has started an investigation into whether government officials were involved in an alleged wire-tapping scandal at Telecom Italia.
The news comes a day after police said they had arrested 20 people as part of an investigation into the case.
Prosecutors say the spy ring taped the phone conversations of politicians, industrialists and even footballers.
Tuesday, September 19, 2006
Godaddy caves in rateyoursolicitor.com case?
"AN American domain name provider has suspended access to the controversial rateyoursolicitor.com website after an Irish High Court issued a court order to remove offensive material about a barrister from the site.Slashdot has some interesting comments. More on this when I get the chance - but if these reports are accurate I'll certainly be moving my own registrations and hosting from Godaddy.
Godaddy.com, an award winning internet site, suspended access to the rateyoursolicitor.com portal within 24 hours of an injunction issued by Judge Michael Hanna.
Last Wednesday, Judge Hanna issued an order that defamatory material posted about Jayne Maguire, a barrister, on rateyoursolicitor.com must be removed with immediate effect.
Ms Maguire has claimed that John Gill, of Drumline, Newmarket on Fergus, defamed her by posting offensive remarks on rateyoursolicitor.com.
Mr Gill, chairman of the Victims of the Legal Profession Society, denied that anything concerning Ms Maguire was published or posted on the site.
Ms Maguire is seeking damages for defamation and privacy and an interlocutory injunction of the statements about her on the site which she says is administered by Mr Gill.
Godaddy.com have locked access to the site domain name until High Court proceedings are concluded. Lawyers acting for Ms Gill served notice on www.gmax.net, an American Internet Service Provider that is host to the site.
It had been thought that Godaddy.com was hosting the site which invites Irish people to rate their lawyers, however gmax.net has now been identified as the ISP and has received notice of the High Court proceedings.
Friday, September 15, 2006
Gardaà disclosing confidential information to media
"Garda Commissioner Noel Conroy is this afternoon to appoint a senior officer to investigate the circumstances surrounding the release of video footage to RTÉ News.
The footage, broadcast yesterday, features two men convicted of dangerous driving, videoing themselves driving at high speed on the N4, near Mullingar, Co Westmeath.
District Court judge John Neilan this morning requested the commissioner to commence an internal investigation.
Judge Neilan said his relationship with the force was deeply strained as a result of events this week.
Judge Neilan said he was appalled by the conduct of the garda officers in the case.
He said the case had first come before him in June and he was satisfied beyond any shadow of a doubt that one of the prosecuting officers had primed the media in respect of the case.
He said that since the tape from the camcorder found in one of the cars was not available to the court yesterday, the only evidence that was available was that as recounted by the Inspector at Mullingar District Court yesterday.
Judge Neilan also said that it was his belief that the evidence of the arresting officers was tainted and embellished by what they saw on the camcorder.
Charges withdrawn
He said that the prosecution had decided without indicating to the court or the media, which apparently had the inside track on the case, that it was withdrawing two of the charges.
Two of the charges related to the material which was used and retained on the camcorder.
The judge said the DPP did not give any reason to the court for not proceeding with those particular charges.
He said that the conduct of members of An Garda SÃochána in discussing evidence and possibly releasing material which was intended to be used in the case yesterday was nothing short of scandalous.
Judge Neilan said that the material seized by gardaà was material which was under the authority of his court.
He warned members of the public to be cautious about what he called the hype surrounding this case, and he said that every member of the public should be aware that certain members of the gardaà are priming the media well in advance of any case being dealt with in accordance with the law.
Judge Neilan also said that certain members of the gardaà believe they have 'a God given right to undermine the cases of the DPP and generate as much hype and hysteria as they can'."
Thursday, September 14, 2006
Digital Rights Ireland brings legal action over mass surveillance
Wednesday, September 13, 2006
McGarr Solicitors and public access to court files
Court documents in Ireland currently exist in a legal limbo - although justice must be administered in public, the practice has been to limit access to the court file. This is so even though every document in the file might have been read out in open court, and even though there is no rule prohibiting disclosure of the contents. Consequently if you as a member of the public wish to see the papers in a case you are dependent on the good will of the parties. This is unlike other jurisdictions such as the United States, where it is generally presumed that court documents are public documents in the same way that the proceedings themselves are public. I've long felt that the Irish practice is far too restrictive, and it's good to see solicitors making it easier to view these documents.
Thursday, September 07, 2006
Schools fingerprinting children - Data Protection Implications
Parents cannot prevent schools from taking their children's fingerprints, according to the Department for Education and Skills and the Information Commissioner.Update: Spongebobb asks what the situation would be in Ireland. The Irish Data Protection Commissioner has given guidance on whether children can consent to the use of their personal information, though this doesn't specifically address this situation:
But parents who have campaigned against school fingerprinting might still be able to bring individual complaints against schools under the Data Protection Act (DPA).
DfES admitted to The Register that schools can fingerprint children without parents' permission.
This position has also been taken by the Information Commissioner, who interprets and enforces the Data Protection Act - the law privacy campaigners hope might be used to stop schools fingerprinting their children.
The Information Commissioner's Office (ICO) is drawing up guidance on the use of fingerprints for purposes other than law-enforcement. The guidance will say once and for all whether parents can prevent their children's fingerprints being taken.
David Smith, deputy Information Commissioner, said it was a complex issue that was still being worked out, but it was likely that parents did not have an automatic right to decide whether their children's biometrics could be taken by a school.
"The Data Protection Act talks of consent of the individual - essentially that's consent of the child," he said.
"Now there's a requirement that consent is informed and freely given. That will depend on the age of the child," he said.
The minimum age at which consent can be legitimately obtained is not defined in the Data Protection Act, 1988.The closest Irish precedent is a case involving a primary school which put the personal details of pupils on a website without parental consent. The Data Protection Commissioner took a dim view of this:
Section 2A(1) of the Acts states that consent cannot be obtained from a person who, by reason of age, is likely to be unable to appreciate the nature and effect of such consent. Judging maturity will vary from case to case.
In the medical area, the GPIT Guide (www.GPIT.ie) suggests that an individual may be assumed to be competent to give consent for medical purposes on reaching the age of 16 years. Where the individual is below that age, consent may still be given, but this requires that the medical practitioner involved must assess whether a child or young person has the maturity to understand and make their own decisions about the handling of their personal health information. In relation to the right of access to health data, where the individual is below 16 years, it was recommended that the general practitioner should use professional judgement on a case by case basis, on whether the entitlement to access should be exercisable by (i) the individual alone, (ii) a parent or guardian alone, or (iii) both jointly. In making a decision, particular regard should be had to the maturity of the young person concerned and his or her best interests.
In the marketing area, where sensitive data is not involved, including on websites, a lower threshold may be permissible. For example, it is a matter for a company to judge if a 14 year old can appreciate the issues surrounding consent and to be able to demonstrate that a person of that age can understand the information supplied and the implications of giving consent. While care should be taken that a person under that age would not be enticed into a deception concerning his/her age, a clear statement that an age limit applies would normally suffice. Where the company becomes aware at a later date that a person has supplied false age-related information, then that data subject's details should be removed from the live site. Sufficient identifiers may be retained purely for the purpose of blocking future entry attempts by that individual.
Where the company accepts that an individual is a minor and are seeking parental consent, e-mail might not be the best medium, unless they can establish that the e-mail address is genuinely a parent/guardian's e-mail address. A postal address is more readily authenticated, though it still does not preclude a letter being addressed to a sibling.
A parent contacted my Office to complain that the local primary school was publishing personal details of pupils on the school web site, without the knowledge or consent of parents. The details included photographic images of named individual pupils, as well as general details volunteered by pupils regarding their hobbies, likes and dislikes. The parent was concerned that the non-selective publication of children’s details in this way was inappropriate, and could expose the children to unnecessary risks. The parent had raised the matter with the school authorities and was very dissatisfied with the response she had received.Of course, the children in this case were of primary school age and so unlikely to be able to give an informed consent. It leaves open the question of whether parental consent could still be required in respect of an older child.
I immediately contacted the school principal to arrange that personal details relating to identifiable children would be deleted from the web site, pending an urgent meeting on this matter. At the meeting, the school principal explained that the web site had been set up several weeks previously in order to meet the educational needs of children in relation to computing. The pupils themselves had been quite positive about the development. Photographs of individual pupils in the junior and senior infants classes had been posted on the web site. Other pupils had been invited to contribute to the web site through other activities, such as filling out questionnaires giving personal information that would be of interest to pupils in other schools, both nationally and internationally. It was noted that the school web site had been given an award by an internet service company in recognition of its merit. As regards parental consent, the principal said that the new web site had been mentioned in a recent school newsletter, and that parents had been invited to come to the school to check it out for themselves.
I pointed out that section 2(1)(a) of the Data Protection Act requires that personal data "shall have been obtained, and the data shall be processed, fairly ". When dealing with personal data relating to schoolchildren, "fairness" in my judgement requires that the clear and informed consent of parents or guardians must be obtained before any use is made of the children’s data. This is particularly so where the use envisaged involves the posting of data on the worldwide web. The principal accepted these points and undertook not to post personal details of schoolchildren on the web site except with the express authorisation of a parent or guardian.
Your personal information is for sale - HP spies on directors' home telephone calls
To catch a leaker, Hewlett-Packard's chairwoman spied on the home-phone records of its board of directors.The UK Information Commissioner has shown that "pretexting" is prevalent in the UK also, in his report "What Price Privacy? The Unlawful Trade in Confidential Personal Information". While we have no comprehensive report in respect of Ireland, it is likely that it is just as common here.
The confrontation at Hewlett-Packard started innocently enough. Last January, the online technology site CNET published an article about the long-term strategy at HP, the company ranked No. 11 in the Fortune 500. While the piece was upbeat, it quoted an anonymous HP source and contained information that only could have come from a director. HP’s chairwoman, Patricia Dunn, told another director she wanted to know who it was; she was fed up with ongoing leaks to the media going back to CEO Carly Fiorina’s tumultuous tenure that ended in early 2005. According to an internal HP e-mail, Dunn then took the extraordinary step of authorizing a team of independent electronic-security experts to spy on the January 2006 communications of the other 10 directors—not the records of calls (or e-mails) from HP itself, but the records of phone calls made from personal accounts. That meant calls from the directors’ home and their private cell phones. ...
The HP case specifically also sheds another spotlight on the questionable tactics used by security consultants to obtain personal information. HP acknowledged in an internal e-mail sent from its outside counsel to Perkins that it got the paper trail it needed to link the director-leaker to CNET through a controversial practice called “pretexting”; NEWSWEEK obtained a copy of that e-mail. That practice, according to the Federal Trade Commission, involves using “false pretenses” to get another individual’s personal nonpublic information: telephone records, bank and credit-card account numbers, Social Security number and the like. Pretexting is heavily marketed on the Web.
Typically—say in the case of a phone company—pretexters call up and falsely represent themselves as the customer; since companies rarely require passwords, a pretexter may need no more than a home address, account number and heartfelt plea to get the details of an account. According to the Federal Trade Commission’s Web site, pretexters sell the information to individuals who can range from otherwise legitimate private investigators, financial lenders, potential litigants and suspicious spouses to those who might attempt to steal assets or fraudulently obtain credit
Incidentally, one of the most common misconceptions about privacy is that it's merely about trusting the government not to abuse its powers. This case illustrates that when you create vast databases, you have to cross your fingers and hope that there is no one else (such as your employer) with a motive to spy on you.
Update: It's now emerged that HP spied on journalists' telephone calls also. Particularly in the US, there's been media lethargy about privacy issues - hopefully there'll be more coverage of the issues as reporters realise that it may be their ox being gored.
Thursday, August 31, 2006
Privacy: One law for them, one law for us
Children of celebrities will be given special safeguards in a new database that will store details of every child in England and Wales, it was disclosed yesterday. ...
Ministers said the contentious two-tier level of privacy will protect children of the rich and famous from intrusion.
Addresses and telephone numbers of celebrities will be removed from the database if, for example, their children are deemed at risk of kidnap.
But opponents of the £241 million Children's Index — a supposedly confidential system intended as an early warning system for children at risk of abuse — said the move underlined their concerns about its security.
In further embarrassment to the Government, an independent report commissioned by Parliament's Information Commissioner and due to be published next month, is understood to warn that the index is causing serious concern and is possibly unlawful.
There are fears that it does not comply with the European Convention on Human Rights and may contravene the Data Protection Act. ...
Files are held by many bodies on the 11 million children in England and Wales, but the index will link this sensitive information in one database accessible to hundreds of thousands of officials. ...
Lord Adonis, the education minister, told the House of Lords: 'Between 300,000 and 400,000 users will access the index. Children who have a reason for not being traced, for example where there is a threat of domestic violence or where the child has a celebrity status, will be able to have their details concealed.'
Robert Whelan, the deputy director of the think-tank Civitas, said Lord Adonis's remarks showed there were legitimate concerns about the security of the index.
'The Government is showing it has no confidence in this database,' he said.
'There have been all these assurances it is secure, but how can we believe them now? I will tell you who will be off the register — the Blairs' children. This is just politicians protecting their own.
'And how is the Government going to define celebrity? It is a very fluid term — an assembly of high-profile clergy, disgraced politicians, topless models, pop singers and reality TV contestants.' ...
But, in an interview for tomorrow's Channel 4 programme Your Kids Under Surveillance, Prof Ross Anderson, an author of the report sent to the Information Commissioner, expressed concern about security.
'There will always be bent insiders. If you connect all these systems up and if you've got over a million professionals needing to access this every day it will all get out.
'Paedophiles for example can use the database to find out which children in their neighbourhood are vulnerable and where they live.'
Yet another argument against ID cards - UK Edition
"Office staff are hacking into the department's computers, putting at risk the privacy of 40million people in Britain.
The revelation undermines Government claims that sensitive information being collected for its controversial ID Cards scheme could not fall into criminal hands.
The security breaches occurred at the Identity and Passport Service, which is setting up the National Identity Register to provide access to individuals' health, financial and police records as part of the £8billion ID card scheme scheduled to begin in 2008.
MPs and technology experts have expressed fears that the national register, which will store sensitive details of more than 40million people, will be a honeypot for hackers and identity thieves. Liberal Democrat
Home Affairs spokesman Mark Hunter said: 'These revelations show it is folly to put all the precious personal data of our citizens in one place.'
Personal information about every British passport holder - including their date of birth, mother's maiden name, address and photographs - is already held in the IPS computers.
A Home Office spokesman last night confirmed the IPS security breaches. He also confirmed that three staff involved had been sacked and a fourth had resigned before disciplinary procedures had concluded."
Tuesday, August 29, 2006
NY Times uses geolocation to avoid contempt of court
If Web readers in Britain were intrigued by the headline “Details Emerge in British Terror Case,” which sat on top of The New York Times’s home page much of yesterday, they would have been disappointed with a click.This sets an interesting precedent - if the NY Times is willing to filter content for one jurisdiction to avoid contempt of court problems, how long will it be able to avoid filtering for possible libel issues?
“On advice of legal counsel, this article is unavailable to readers of nytimes.com in Britain,” is the message they would have seen. “This arises from the requirement in British law that prohibits publication of prejudicial information about the defendants prior to trial.”
In adapting technology intended for targeted advertising to keep the article out of Britain, The Times addressed one of the concerns of news organizations publishing online: how to avoid running afoul of local publishing laws.
“I think we have to take every case on its own facts,” said George Freeman, vice president and assistant general counsel of The New York Times Company. “But we’re dealing with a country that, while it doesn’t have a First Amendment, it does have a free press, and it’s our position that we ought to respect that country’s laws.”
Jonathan Zittrain, a professor of Internet governance and regulation at Oxford University, said restricting information fit with trends across the Internet. “There’s a been a sense that technology can create a form of geographic zoning on the Internet for many years now — that they might not be 100 percent effective, but effective enough,” Mr. Zittrain said. “And there’s even a sense that international courts might be willing to take into account these efforts.
Plans were made at The Times over the weekend to withhold print versions of the article in Britain, as well as news agency and archived versions.
But the issue of the Web was more complicated.
Richard J. Meislin, the paper’s associate managing editor for Internet publishing, said the technological hurdle was surmounted by using some of The Times’s Web advertising technology. The paper could already discern the Internet address of users connecting to the site to deliver targeted marketing, and could therefore deliver targeted editorial content as well. That took several hours of programming.
“It’s never a happy choice to deny any reader a story,” said Jill Abramson, a managing editor at The Times. “But this was preferable to not having it on the Web at all.”"
Monday, August 28, 2006
Yet another argument against ID cards - Australian edition
Australia's identity card system was routinely searched for personal reasons by government agency employees, some of whom have been sacked.
Police are now investigating allegations of identity fraud resulting from the security breaches.
There were 790 security breaches at government agency Centrepoint involving 600 staff. Staff were found to have inappropriately accessed databases containing citizens' information. The databases are part of a massive federal Government smart card project which will link medical, welfare, tax and other personal data on Australia's 17m citizens.
Thursday, August 10, 2006
AOL Searches Now Available Online
Wednesday, August 09, 2006
Still more on the AOL disclosure - what your internet history might say about you
A woman affiliated with Temple University in Philadelphia, perhaps a student, shared her life's troubles with AOL Search this spring. That woman, user 591476, typed:
- replica loius vuitton bag
- how to stop bingeing
- how to secretly poison your ex
- how to color hair with clairol professional
- girdontdatehim.com
- websites that ask for payment by checks
- south beach diet
- nausea in the first two weeks of pregnancy
- breast reduction
- how to starve yourself
- rikers island inmate info number
- inmatelookup.gov
- www.tuportal.temple.edu
- how to care for natural black hair
- scarless breast reduction
- pregnancy on birth control
- temple.edu
- diet pills
Some AOL users seem to be worried that an abusive partner in a relationship may come back to hurt them. This person, AOL user 005315, searched for information about prison inmates, gang members, sociopaths in relationships, and women who were murdered in southern California last year:
- resources for utility bill paying assistance in southern california
- section 8 housing southern california
- los angeles county ca. gang member pictures
- orange county california jails inmate information
- fractured ankle
- letters and responses written by women to emotionally
- abusive partners
- men that use emotional and physical abandonment to control their partner
- warning signs of a mans infidelity or sexual addiction
- the sociopathic relationship
- southern california newspaper stories about woman murdered by boyfriend in pomona december2005
- names of females murdered or found dead in pomona california in 2005
- characteristics of a sociopath in a relationship
- a person that shows lack of empathy
- help in writing a letter to a abusive narcissistic ex boyfriend
- how to hurt the narcissistic man
- retaliating against the narcisisstic man
The NY Times puts a face on one of AOL's victims
Buried in a list of 20 million Web search queries collected by AOL and recently released on the Internet is user No. 4417749. The number was assigned by the company to protect the searcher’s anonymity, but it was not much of a shield.If this story disturbs you, you might want to visit Digital Rights Ireland and support our campaign against data retention.
Thelma Arnold’s identity was betrayed by AOL records of her Web searches, like ones for her dog, Dudley, who clearly has a problem.
No. 4417749 conducted hundreds of searches over a three-month period on topics ranging from “numb fingers” to “60 single men” to “dog that urinates on everything.”
And search by search, click by click, the identity of AOL user No. 4417749 became easier to discern. There are queries for “landscapers in Lilburn, Ga,” several people with the last name Arnold and “homes sold in shadow lake subdivision gwinnett county georgia.”
It did not take much investigating to follow that data trail to Thelma Arnold, a 62-year-old widow who lives in Lilburn, Ga., frequently researches her friends’ medical ailments and loves her three dogs. “Those are my searches,” she said, after a reporter read part of the list to her." ...
Ms. Arnold, who agreed to discuss her searches with a reporter, said she was shocked to hear that AOL had saved and published three months’ worth of them. “My goodness, it’s my whole personal life,” she said. “I had no idea somebody was looking over my shoulder.”
In the privacy of her four-bedroom home, Ms. Arnold searched for the answers to scores of life’s questions, big and small. How could she buy “school supplies for Iraq children”? What is the “safest place to live”? What is “the best season to visit Italy”?
Her searches are a catalog of intentions, curiosity, anxieties and quotidian questions. There was the day in May, for example, when she typed in “termites,” then “tea for good health” then “mature living,” all within a few hours.
Her queries mirror millions of those captured in AOL’s database, which reveal the concerns of expectant mothers, cancer patients, college students and music lovers. User No. 2178 searches for “foods to avoid when breast feeding.” No. 3482401 seeks guidance on “calorie counting.” No. 3483689 searches for the songs “Time After Time” and “Wind Beneath My Wings.”
At times, the searches appear to betray intimate emotions and personal dilemmas. No. 3505202 asks about “depression and medical leave.” No. 7268042 types “fear that spouse contemplating cheating.”
Tuesday, August 08, 2006
Your personal information is for sale, episode 8,763 - AOL reveals users search history
AOL must have missed the uproar over the DOJ’s demand for “anonymized” search data last year that caused all sorts of pain for Microsoft and Google. That’s the only way to explain their release of data that includes 20 million web queries from 650,000 AOL users.Bear in mind that this was not an accidental or inadvertent disclosure - much less a security breach. AOL took a deliberate and planned decision to release this information.The data includes all searches from those users for a three month period this year, as well as whether they clicked on a result, what that result was and where it appeared on the result page. It’s a 439 MB compressed download, expanded to just over 2 gigs. The data is available here (this link is directly to the file) and the output is in ten text files, tab delineated.
The utter stupidity of this is staggering. AOL has released very private data about its users without their permission. While the AOL username has been changed to a random ID number, the abilitiy to analyze all searches by a single user will often lead people to easily determine who the user is, and what they are up to. The data includes personal names, addresses, social security numbers and everything else someone might type into a search box.
The most serious problem is the fact that many people often search on their own name, or those of their friends and family, to see what information is available about them on the net. Combine these ego searches with porn queries and you have a serious embarrassment. Combine them with “buy ecstasy” and you have evidence of a crime. Combine it with an address, social security number, etc., and you have an identity theft waiting to happen. The possibilities are endless.
Marketers are going nuts over the possibilities, users are calling for a boycott of AOL, and others are just enraged:
User 491577 searches for “florida cna pca lakeland tampa”, “emt school training florida”, “low calorie meals”, “infant seat”, and “fisher price roller blades”. Among user 39509’s hundreds of searches are: “ford 352″, “oklahoma disciplined pastors”, “oklahoma disciplined doctors”, “home loans”, and some other personally identifying and illegal stuff I’m going to leave out of here. Among user 545605’s searches are “shore hills park mays landing nj”, “frank william sindoni md”, “ceramic ashtrays”, “transfer money to china”, and “capital gains on sale of house”. Compared to some of the data, these examples are on the safe side. I’m leaving out the worst of it - searches for names of specific people, addresses, telephone numbers, illegal drugs, and more. There is no question that law enforcement, employers, or friends could figure out who some of these people are.
There is some really scary stuff in this data.
Wednesday, August 02, 2006
Today's outrage - Millions of children to be fingerprinted
British children, possibly as young as six, will be subjected to compulsory fingerprinting under European Union rules being drawn up in secret. The prints will be stored on a database which could be shared with countries around the world.[Edited to add]
The prospect has alarmed civil liberties groups who fear it represents a 'sea change' in the state's relationship with children and one that may lead to juveniles being erroneously accused of crimes. Under laws being drawn up behind closed doors by the European Commission's 'Article Six' committee, which is composed of representatives of the European Union's 25 member states, all children will have to attend a finger-printing centre to obtain an EU passport by June 2009 at the latest.
The use of fingerprints and other biometric data is designed to prevent passport fraud and allow European member states to meet US entry visa requirements, but the decision to fingerprint children has disturbed human rights groups.
The civil liberties group Statewatch last night accused EU governments of taking decisions in which 'people and parliaments have no say'. It said the committee's decisions were simply based on 'technological possibilities - not on the moral and political questions of whether it is right or desirable.'
'This is a sea change,' said Ben Hayes, spokesman for Statewatch. 'We are going from fingerprinting criminals to universal fingerprinting without any real debate. In the long term everyone's fingerprints will be stored on a central database. You have to ask what will be the costs to a person's privacy.'
It's not clear what effect this may have in Ireland. The legal basis is Regulation 2252/2004 which is a Schengen act and therefore not binding on Ireland. The Government's current policy is not to include fingerprints on passports - see the Dept. of Foreign Affairs FAQ. However, if and when Ireland does enter Schengen this will be a fait accompli.
Tuesday, July 25, 2006
When surveillance meets bureaucracy
You could be on a secret government database or watch list for simply taking a picture on an airplane. Some federal air marshals say they're reporting your actions to meet a quota, even though some top officials deny it.(via MetaFilter)
The air marshals, whose identities are being concealed, told 7NEWS that they're required to submit at least one report a month. If they don't, there's no raise, no bonus, no awards and no special assignments.
"Innocent passengers are being entered into an international intelligence database as suspicious persons, acting in a suspicious manner on an aircraft ... and they did nothing wrong," said one federal air marshal. ...
What kind of impact would it have for a flying individual to be named in an SDR?
"That could have serious impact ... They could be placed on a watch list. They could wind up on databases that identify them as potential terrorists or a threat to an aircraft. It could be very serious," said Don Strange, a former agent in charge of air marshals in Atlanta. He lost his job attempting to change policies inside the agency.
Tuesday, July 18, 2006
UK Government implements "Minority Report" - Department of Pre-Crime awaits
Children's Minister Hilary Armstrong was due today to outline what could become one of Project Blair's most ambitious, misguided and hubristic projects yet. The Government will attempt to identify children at risk of failure, violent behaviour or criminality at birth, and take the necessary corrective actions to steer them onto a law-abiding and successful path.The Register has some interesting comments about the quality of the data we can expect this database to contain:
Ironically, Armstrong is floating these proposals just as this same predictive approach to future behaviour patterns is becoming discredited. A couple of national newspapers, the Independent and The Observer, appear to have seen outlines of the plans. According to the Independent, midwives, doctors and nurses are to be "asked to identify 'chaotic' families whose babies are in danger of growing up to be delinquents, drug addicts and violent criminals." The plan will be backed up by "research" which "shows that children from the most dysfunctional families are 100 times more likely to abuse alcohol commit crimes or take drugs", and a "source" close to Armstrong says: "It is the 'supernanny' model.' There is no reason why midwives who ask mothers lots of questions anyway can't ask a few more about the family circumstances and identify families where there may be problems. We need to intervene early to stop the cycle that leads to social exclusion."
The information they're sharing, meanwhile, will become more junk-like as the boxes they need to check and the fields they need to fill in multiply. Social workers, police, anyone who's given the job of spotting early warning signs will feel the need to put something in the box, for all too obvious reasons. What's it going to look like in five years time when some kid on your books gets beaten to death, and it turns out you didn't notice anything? The empty box clearly indicates negligence on your part. So the slightest, part-imagined 'signs' will go down, the people you're sharing the data with will see this 'concern' flagged and put in some 'signs' of your own. And as Brian Sheldon, Emeritus Professor, University of Exeter and former director of the Centre for Evidence-Based Social Work puts it, once social workers decide people need visiting, "they need visiting a lot." Or as Hine says, "if you're looking for problems, you will find problems."For another perspective see the proceedings of the LSE conference "Children: Over Surveilled, Under Protected".
The cases will tend to build themselves, the effect much magnified by the 'share and deploy' approach, and they'll also tend to focus on the easier cases. The ones who're easier to get at and who're on the receiving end of self-generating warning signs will get lots of attention (despite quite possibly never having needed any in the first place), and quite possible acquire real problems because of this, while harder cases of real need may not get any attention at all.
At ground level, midwives (and one presumes other professionals) are beginning to see the collateral damage of the Blair Project's data kleptocracy (Sheldon diagnoses this as symptomatic of a country suffering from obsessive-compulsive disorder). Some of the women midwives are dealing with have noticed that their histories can be taken down and used against them, and that it does not matter whether or not they have successfully coped, or are successfully coping with whatever the problem might have been. If you tell someone, it will be flagged as a 'concern' and will breed more concerns, and turn you into a 'case'. So they're starting to withhold information, and as midwives, and other professionals continue to ask "a few more" questions, people on the receiving end of the data kleptocracy will start to go underground.
Leaving systems built on junk science sharing junk data in pursuit of imaginary concerns and a pre-defined criminal underclass, while the rest of us hide.( Emphasis added)
Monday, July 17, 2006
Online Anonymity - Ryanair Edition (continued)
A High Court judge has rejected claims by Ryanair that its pilots or their unions had engaged in bullying, intimidation or isolation of other pilots over conditions imposed by Ryanair relating to training on new aircraft.
The only evidence of bullying was by Ryanair itself, Mr Justice Thomas Smyth stated yesterday. He described as "most onerous and bordering on oppression" a condition requiring pilots to pay Ryanair €15,000 for training on new aircraft in 2004. The €15,000 was payable by pilots if they left the company within five years or if Ryanair was required to engage in collective bargaining within the same period.
In a strongly worded reserved judgment, the judge dismissed a bid by the private airline for orders aimed at identifying pilots who posted messages under codenames, such as "ihateryanair" and "cantfly, wontfly" on a pilots' website. Ryanair had claimed the messages showed evidence of wrongful activity against it and its employees.
The judge also made a finding of false evidence in relation to two members of Ryanair management who had given evidence at the hearing. He held that, when Ryanair set up an investigation to find out who was behind the website, the real purpose of that investigation was to "break the resolve" of pilots to seek better terms and conditions. There was no warrant for Ryanair's action in seeking assistance from gardaà on the matter, he added.
He rejected as "baseless and false" the evidence of Ryanair director of personnel Eddie Wilson in relation to the setting up the investigation. The judge also said there was no conspiracy in relation to the setting up of the website and it was not engaged in anything unlawful. There was "no actionable wrong", he held, and dismissed Ryanair's application.
Friday, July 14, 2006
Dutch court upholds refusal to disclose file-sharers' identities
A Dutch appeals court has thwarted attempts by the Dutch anti-piracy organisation BREIN to get the identities of file-sharers from five ISPs, including Wanadoo and Tiscali.
The court found that the manner in which IP addresses were collected and processed by US company MediaSentry had no lawful basis under European privacy laws. A lower court in Utrecht had reached a similar conclusion last year.
The court also argued that the software MediaSentry uses can't properly identify users or provide evidence of infringement.
Last year, expert witnesses at Delft University of Technology criticised MediaSentry's software for being too limited and simplistic. For instance, MediaSentry took filenames in Kazaa at face value. More importantly, the software scans all the content of the shared folder on the suspect's hard disk. In that process, it breached privacy laws.
The Dutch Protection Rights Entertainment Industry Netherlands (BREIN) represented 52 media and entertainment companies and has been investigating 42 people suspected of swapping song files. Nine file-sharers decided to settle with BREIN.
BREIN says it will go to a higher court, but lawyer Christiaan Alberdingk Thijm, who represented the ISPs, sees the decision as an important victory.
Wednesday, July 12, 2006
UK government abusing copyright to silence whistleblower
The government is threatening to sue former ambassador Craig Murray for breach of copyright if he does not remove from his website intelligence material that was censored out of his newly published memoirs.It is unacceptable that a government can silence its critics by relying on copyright law. The approach taken by US law is preferable, under which government publications don't benefit from copyright protection. After all, this material has already been paid for by the taxpayer.
Mr Murray has posted full texts of all passages the Foreign Office ordered deleted from the book version of Murder in Samarkand, the former Tashkent ambassador's account of alleged British complicity in torture by the despotic Uzbekistan regime. His book contains links to the website.
The passages detail CIA intelligence reports that Mr Murray says were false, and accounts of US National Security Agency intercepts and conversations with John Herbst, the US ambassador in Uzbekistan at the time. The Foreign Office says release of the material is damaging. ...
The Foreign Office is also demanding, in a claim that breaks new legal ground, that Mr Murray remove from his website the text of Foreign Office correspondence which he says he obtained officially through Freedom of Information Act and Data Protection Act requests.
The Treasury solicitors, the government lawyers, wrote to Mr Murray last week claiming: "Even if a document is released under the Freedom of Information Act or the Data Protection Act, that does not entitle you to make further reproductions of that document by, for example, putting them on your website."
Mr Murray said yesterday: "If the media do not react to this, they will lose the ability to report in any detail material released under the Freedom of Information Act. The documents in question are the supporting evidence for my book. The government continues to claim my story is untrue."
Tuesday, July 11, 2006
Henry Porter on ID cards
Some, like the editor of Prospect, David Goodhart, have attempted to portray the cards as "badges of citizenship embodying the idea of the contract between citizen and state". The argument is superficially comforting. "They help us to know who is in the country and what their status is and to protect the precious entitlements of all existing citizens." There is no mention in his recent essay of the database or the terrible potential for intrusion and control. And of course the idea of this being a contract is ridiculous when one party is being forced to sign or face penalties. The notion of a badge of citizenship is codswallop being put about by people who are too impressed by authority and too weak to oppose it.
When reading the ID card bill I am constantly struck by its minatory tone - the threats of fines and the general contempt for the average citizen. There's a reason for this. Rather than being something that is designed to help us, the card and the register are, in fact, tools of government control and surveillance. Over and above the information you have supplied at enrolment (please note the voluntary connotations of the word enrolment ) your file on the NIR will build an entire picture of your life - your hospital visits, your children's schools, your driving record, your criminal record, your finances, insurance policies, your credit-card applications, your mortgage, your phone accounts (and, one presumes your phone records), and your internet service providers.
Every time you get a library card, make a hire-purchase agreement, apply for a fishing or gun licence, buy a piece of property, withdraw a fairly small amount of your money from your bank, take a prescription to your chemist, apply for a resident's parking permit, buy a plane ticket, or pay for your car to be unclamped you will be required to swipe your card and the database will silently record the transaction. There will be almost no part of your life that the state will not be able to inspect. And it will be able to use the database to draw very precise conclusions about the sort of person you are - your spending habits, your ethnicity, your religion, your political leanings, your health and even perhaps your sexual preferences. Little wonder that MI5 desired - and was granted - free access to the database. Little wonder that the police, customs and tax authorities welcome the database as a magnificent aid to investigation.
But know this: from the moment the database goes live, we will become subjects not citizens and each one of us will be diminished in relation to the state's power.
Something enormous and revolutionary is about to happen to us. We are giving the most precious part of ourselves to the government, allowing it complete freedom to roam through our privacy. And it's not just to this government, but to the governments of the future, the nature of which we cannot possibly know. And it's not just our privacy - it is the rights and privacy of future generations. While we are comfortable about handing this information over to the state, the citizens of the future may feel strongly about our complacency and our faith in the British government. We have a duty to those people, just as all the people who fought for the rights we enjoy today felt a sense of obligation to us.
The prime minister asks us to trust him and implies that abuse of a database would be unthinkable in Britain. But after the lies before the invasion of Iraq, the revelations of the Hutton inquiry and the evidence about rendition flights using British airspace I would suggest that we treat these sorts of assurances and appeals with the utmost suspicion.
Remember this government's attack on liberty. Remember what we have already lost - the campaign that has diminished defendants rights, introduced punishment without a court deciding that the law has been broken, restricted protest and speech and even assembly. Blair is unabashed about his record and has taken to describing civil liberties as a privilege that may be removed from someone the moment they become a suspect or a defendant.
I am afraid I do not trust the government's motives - nor do I trust its competence. The past decade is littered with failed government IT projects - the Child Support Agency, the immigration records, the working tax credit database, the farmers' single payment scheme are a few that come to mind. This is to say nothing of its record on security. The NIR will literally have thousands of entry points where the information on your file can be accessed.
One of the worst failures of a government database came to light a few weeks ago when the Home Office admitted that the Criminal Records Office had wrongly identified 2,700 people as having criminal records. I cannot think of a clearer case of defamation and it is surprising there is not some kind of class action against the Home Office. Not only were these people's reputations seriously damaged, many were turned down for jobs as a result of the CRO's mistake and can therefore argue for a serious loss of earnings. But the Home Office did not even apologise. It is exactly the arrogance that I fear will come to characterise all government dealings with the person in the street once this database is operational.
As I said, I am instinctively - genetically, as I put it - opposed to ID cards and the Identity Register. I am also politically opposed because as the government database grows, I believe there will be a commensurate lessening in the state's respect for each one of us. We will be reduced to the great mass of classified specimens, pinned down and itemised like dead butterflies in a showcase. Because of the power it possesses over us, I believe the government will gradually become less accountable and less responsive to the needs and wishes of the people. Whereas once politicians were our servants, they will become our masters and we their slaves.
I have philosophical objections, too. In a free country I believe that every human being has the right to define him or herself independently and without reference to the government of the time. This, I believe, is particularly important in a multicultural society such as ours. The ID card and NIR require and will bring about a kind of psychological conformity, which is utterly at odds with a culture that has thrived on individualism, defiance and the freedom to go your own way.
And it will remove the right of those who for whatever reason wish to withdraw from the cares of the world and the influence of society, to resort to the consolations of solitude and privacy without inspection from a centralised authority. Privacy, anonymity and solitude are rights, and we are about to lose them for ever.
People say that everything about you is known already. Someone has calculated that each of us appears on up to 700 databases. But the real point is that everything that is known about you will become linked up on the NIR. The register will take on a life of its own, for once you set up a system like this it becomes ineluctably compelled to find out more and more about you. That will be its hardwired purpose.
Imagine handing over the keys to your home when you are out at work to allow some faceless bureaucrat to rifle through your desk and drawers, your photograph albums and children's school reports, your bills and love letters. That is the kind of access they are going to have, and it is going to grow as time goes by and we become accustomed to this unseen presence in our lives.
Well, it's not for me. I cannot do it. I will not do it, and I hope you won't either.