A sample text widget
Etiam pulvinar consectetur dolor sed malesuada. Ut convallis
euismod dolor nec pretium. Nunc ut tristique massa.
Nam sodales mi vitae dolor ullamcorper et vulputate enim accumsan.
Morbi orci magna, tincidunt vitae molestie nec, molestie at mi. Nulla nulla lorem,
suscipit in posuere in, interdum non magna.
|
Most Americans do not care about exposing themselves to massive data surveillance but they should, says George Washington University law professor and New Republic legal affairs editor Jeffrey Rosen in his new book, “The Naked Crowd.” Rosen discussed technology and the uneasy balance between security and privacy on April 20 at 2 p.m. on washingtonpost.com.
Jeffrey Rosen: The book is a response to a challenge by my friend and teacher Lawrence Lessig, who writes about cyberspace. We were on a panel about liberty and security after 9/11, and I denounced the British surveillance cameras, which I had just written about for the New York Times magazine, as a feel good technology that violated privacy without increasing security. Lessig politely but firmly called me a Luddite. These technologies will proliferate whether you like it or not, he said, and you should learn enough about them to be able to describe how they can be designed in ways that protect privacy rather than threatening it. I took Lessig’s challenge seriously, and spent a year learning about the technologies and describing the legal and architectural choices they pose. The rest of the book followed naturally, and it’s an attempt to think through the behavior of the relevant actors who will decide whether good or bad technologies are adopted — that is, the public, the executive, the courts, and the Congress.
The Home office has admitted that it has no idea how much innocent citizens will be charged for being forced to have an Identity Card.
At Lord’s Question’s today, Home Office Minister Baroness Scotland of Asthal was asked to confirm the current estimate of £70 per person (already almost twice the figure that was being talked about a year ago). She refused to do so, saying that the Government would not be able to assess the costs until the compulsory phase begins.
So every single person in the country is effectively being told to write the Government a blank cheque.
The predicted cost has already almost doubled within a year. Given the Government record on IT projects, how much higher will it go?
Full report in the Scotsman.
Cross-posted from The Chestnut Tree Cafe
… and will soon be invisible. Anyone who bases their arguments about the dangers of camera surveillance on the primitiveness of current technology is, unlike the latest cameras, being very short sighted. Take a look, for example, at this:
It sounds like the speeder’s nightmare. A speed camera accurate up to 150mph which can be concealed in road studs as small as a cat’s eye indicator, and which can also – as you’re passing – cast a glance at your tyres to see if they’re a bit bald.
And at you, to see who you are and where you are, and what you’re up to. If not yet, then very soon.
Wake up: this camera exists, and it’s being trialled.
I’m awake already.
But the anti-camera lobby can rest easy for a while. The Department for Transport says that there is no way that these cameras, designed and made by a British company called Astucia, will ever be used for “enforcement” to level fines and penalty points. However, they will start being tested around the country later this year, as part of the wider efforts to encourage motorists to respect speed limits.
So, they will not (yet) do “enforcement”, not “for a while”. But they can already do “encourage”. Sounds like enforcement will be with us very soon.
The Australian government has long desired to force ISP’s and Internet content Hosts to take responsibility for the activities of their clients. An attempt to do this in 1999 was defeated, but the authorites are back for more.
The draft bill states that ISPs are required to determine whether their services are used for “illegal conduct or speech.”
Paragraph 152 of the Explanatory Notes to the draft bill says that “Possible action that could be taken by ISPs and Internet Content Hosts (ICHs) so as not to facilitate use of a carriage service by another person that breaches proposed subsection 474.16(1) includes an ISP ceasing to provide Internet services to that person or an ICH ceasing to host a particular Website containing content that breaches the proposed offence.”
Obviously, the implication is clear- should this measure get up, ISP’s will be legally required to be much more aggressive in their surveillance of their customers; a gross breach of their privacy.
(Via Whirlpool.net.au)
Via b3ta.com, I came across a nice piece of White Rose Relevant graphics, here.
Since I don’t know what the policy is here about pictures, and in any case do not have picture posting privileges, but since b3ta.com is such a Niagara of pictorial diversions, here today and gone tomorrow, I nailed down the relevant image here, amidst appropriately educational commentary.
“Money grabbing gits!” is what b3ta said. Would that our money was the only thing in danger here.
From the BBC last Friday:
Nearly 200 people have been wrongly accused by the Criminal Records Bureau of having criminal records.
The names of 193 people were mistakenly linked with convictions held on the police national computer (PNC), BBC Radio Five Live has learned.
In some cases the names of those being vetted by the bureau were similar or identical to those of actual criminals.
In others, the criminals had given someone else’s personal details to the authorities to avoid a police record.
The Criminal Records Bureau, which came into operation in March 2002, does background checks on those who work with children or vulnerable people.
They made this number of mistakes (that they already know of) in the criminal record list, which is only a minority of the population. How many would they make if the list contained, or was supposed to contain, everybody?
What is scary about this kind of thing is when the information-that-isn’t starts to really get around, into several different data bases at once. At that point it becomes extremely hard to eradicate. Something like a false reading on sexual perversion (which is what these background checks for working with children and vulberable people are all about) is liable to spring to life again after previously having been eradicated, supposedly. After all, you can’t be too careful, can you?
Wired has a follow-up reporting on the controversy surrounding the airline companies hand-over passanger data to government contractors (TSA)designing and testing CAPPSII in 2002.
Two senators on Wednesday asked the Transportation Security Administration whether the agency violated federal rules by helping its contractors acquire passenger data, and why the agency told government investigators it didn’t have such data.
The senators also pressed the TSA for an explanation of why it hadn’t revealed the transfer of millions of passenger records to government contractors. Senate members had asked TSA officials directly whether they had done so, but the answer was no.
Two TSA agency spokesmen also denied to Wired News that any data transfer had taken place, saying that the project did not need data at the time.
But this week, American Airlines became the third airline to reveal that it turned over millions of passenger records to the government without informing the passengers. JetBlue and Northwest Airlines had earlier revealed that they too had transferred passenger records to government contractors. For the past eight months, TSA officials and spokesmen have repeatedly denied that any data transfer occurred. Two senators, Susan Collins (R-Maine) and Joe Lieberman (D-Connecticut) wrote:
We are concerned by potential Privacy Act and other implications of this reported incident. Moreover, TSA told the press, the General Accounting Office and Congress that it had not used any real-world data to test CAPPS II.
American Airlines has now indicated that it provided over 1 million passenger itineraries at TSA’s request, which raises the question of why agency officials told GAO that it did not have access to such data.
And there was much fudging as you can read in the article…
The U.S. Department of Transportation’s Federal Highway Administration is working with four companies to develop new radio-frequency identification technology for roadways. Officials see RFID as a way to warn drivers of, for instance, impending intersection collisions and vehicle rollovers.
Specifically, the government and vendors are investigating technology called dedicated short-range communications, which is related to RFID. The vendors are Mark IV Industries, Raytheon, Sirit, and TransCore.
A prototype system co-developed by the quartet is expected to be ready for testing in about 18 months. The Federal Communications Commission has assigned a block of high-bandwidth radio spectrum for dedicated-communications products–5.850 to 5.925 GHz.
The news just goes from bad to worse on the RFID front. Trevor Mendham quoted Tesco CEO Sir Terry Leahy as saying that RFID tracks products, not people, but American tech company Applied Digital Solutions, through it’s subsidiary Verichip Corporation, has already broken through that barrier.
They have developed a RFID product that is implanted in the victim.
The VeriChip minaturized Radio Freqency Identifcation (RFID) Device is the core of all VeriChip applications. About the size of a grain of rice, each VeriChip contains a unique verification number, which can be used to access a subscriber-supplied database providing personal related information. And unlike conventional forms of identification, VeriChip cannot be lost, stolen, misplaced or counterfeited.
Once implanted just under the skin, via a quick, painless outpatient procedure (much like getting a shot), the VeriChip can be scanned when necessary with a proprietary VeriChip scanner. A small amount of Radio Freqency Energy passes from the scanner energizing the dormant VeriChip, which then emits a radio frequency signal transmitting the individuals unique verification (VeriChipID) number. The VeriChip Subscriber Number then provides instant access to the Global VeriChip Subscriber (GVS) Registry – through secure, password protected web access to subscriber-supplied information. This data is maintained by state-of-the-art GVS Registry Operations Centers located in Riverside, California and Owings, Maryland.
It’s a password protected website- anyone with knowlege of the internet knows that password protected websites are not that secure; anyone that says that they can guarantee the security of such a webserver is whistling in the wind.
It’s rather like that dreadful George Lucas film, The Phantom Menace, where the slaves are fitted with a tracking device. Verichip Corp. doesn’t have slaves in their sights as a target market- they have a wider target market in mind.
VeriChip products are being actively developed for a variety of security, defense, homeland security and secure-access applications, such as authorized access control to government and private sector facilities, research
laboratories, and sensitive transportation resources, including the area of airport security.
In these markets, VeriChip is able to function as standalone
personal verification technology or it is able to operate in conjunction with other security devices such as ID badges and advanced biometrics.
In the financial arena, VeriChip has enormous potential as a personal verification technology that could help curb identity theft and prevent fraudulent access to banking and credit card accounts.
In other words, they are after a world where everyone is fitted with these devices. Does Big Blunkett own shares in this company? At the moment, they are working with gun manufacturers. Who will be next?
This editorial by Electronic security expert Bruce Schneier that was published in the Minneapolis Star Tribune does a pretty good job of demolishing the case against compulsory ID cards. The case is a pretty familiar one to readers of this site, but the main points are there: it’s not about the card itself, it is about the people who use it and check for it. And the question really is does the card help or hinder them in improving security, and does it help or hinder them if they wish to break the rules themselves, and in any event, knowing someone’s identity doesn generally greatly help in knowing their intentions.
In fact, everything I’ve learned about security over the last 20 years tells me that once it is put in place, a national ID card program will actually make us less secure.
My argument may not be obvious, but it’s not hard to follow, either. It centers around the notion that security must be evaluated not based on how it works, but on how it fails.
It doesn’t really matter how well an ID card works when used by the hundreds of millions of honest people that would carry it. What matters is how the system might fail when used by someone intent on subverting that system: how it fails naturally, how it can be made to fail, and how failures might be exploited.
The first problem is the card itself. No matter how unforgeable we make it, it will be forged. And even worse, people will get legitimate cards in fraudulent names.
Two of the 9/11 terrorists had valid Virginia driver’s licenses in fake names. And even if we could guarantee that everyone who issued national ID cards couldn’t be bribed, initial cardholder identity would be determined by other identity documents … all of which would be easier to forge.
Not that there would ever be such thing as a single ID card. Currently about 20 percent of all identity documents are lost per year. An entirely separate security system would have to be developed for people who lost their card, a system that itself is capable of abuse.
Additionally, any ID system involves people… people who regularly make mistakes. We all have stories of bartenders falling for obviously fake IDs, or sloppy ID checks at airports and government buildings. It’s not simply a matter of training; checking IDs is a mind-numbingly boring task, one that is guaranteed to have failures. Biometrics such as thumbprints show some promise here, but bring with them their own set of exploitable failure modes.
But the main problem with any ID system is that it requires the existence of a database. In this case it would have to be an immense database of private and sensitive information on every American — one widely and instantaneously accessible from airline check-in stations, police cars, schools, and so on.
The security risks are enormous.
→ Continue reading: Bruce Schneier on why ID cards will not make us safer
Plenty of people around the world by now know of the allegations of philandering made against the English footballer David Beckham, based on claims made to the media, and also on transcripts of SMS phone messages that are said to have been sent between Beckham and one Rebecca Loos.
The ins and outs of the affair are none of our concern, but what did concern me was this explainatory article in The Advertiser:
He apparently even has offered to produce his mobile phone records to prove his innocence. It may surprise some mobile phone users that some carriers retain details of text messages.
In Australia, Telstra keeps SMS messages for up to 28 days and Optus keeps theirs for three days.
I have three questions here. First, why are telephone companies keeping records of these things at all, and second, why is there such a large difference between Telstra, the dominant company that is still half owned by the government, and Optus (which is now owned by Singtel, the phone arm of the Singaporean government.) And thirdly, why are these messages apparently so insecure?
One of the problems with governments collecting and controlling data on individuals is their failure to secure this information. As a recent article in The Register demonstrated, the number of incidents involving computer systems in the civil service is high.
There are a number of serious concerns including inappropriate access of personal records, inappropriate alteration of personal records and their appropriation by a third party. This has been a problem for some time with Inland Revenue staff noted for “celebrity browsing” tax returns. These concerns are hidden within general figures for computer misuse that number up to two thousand. As these are the cases where such changes were noted and disciplinary action brought against the civil servant involved, it is impossible to gauge the seriousness if this problem.
Even after the data has been collected by the civil service agency, it is difficult to ensure that the information is accurate, secure and used only for the purposes required. This could be a minor problem or the tip of the iceberg.
|
Commentary
Economics
Politics
Specialist
Tech
|