moldybluecheesecurds 2

Showing posts with label privacy. Show all posts
Showing posts with label privacy. Show all posts

Thursday, January 24, 2008

The false dichotomy of privacy (or liberty) v. security

Think that we all have to give up some privacy to be safe from the 21st century threats of terrorism? You must work for the Bush Administration:
In order for cyberspace to be policed, internet activity will have to be closely monitored. Ed Giorgio, who is working with [Director of National Intelligence] McConnell on the plan, said that would mean giving the government the authority to examine the content of any e-mail, file transfer or Web search. "Google has records that could help in a cyber-investigation," he said. Giorgio warned me, "We have a saying in this business: 'Privacy and security are a zero-sum game.'"
Most accept that dichtomy, says Bruce Schneier. Problem is, it's a false one. He starts with several examples, such as stronger cockpit doors on airplanes or deadbolt locks on homes. There's no loss of privacy.

Instead, the only conflicts occur when security involves issues of identity (e.g. national ID cards). And in these cases, the government has either lied or misled the public about their effectiveness. The most effective security measures are the few immediate post-9/11 ones:
Since 9/11, two -- or maybe three -- things have potentially improved airline security: reinforcing the cockpit doors, passengers realizing they have to fight back and -- possibly -- sky marshals. Everything else -- all the security measures that affect privacy -- is just security theater and a waste of effort.
For more, read his entire 2-page essay.

Tuesday, August 14, 2007

American business: providing superior service to totalitarians internationally

Nothing like a little U.S. private sector ingenuity to help the Chinese government keep an eye on their peons:
China is building the largest and most sophisticated people-tracking network in the world, all to track citizens in the city of Shenzhen. This network utilizes 20,000 intelligent digital cameras and RFID cards to keep track of the 12.4 million people living in the Southern port city. The key to the system is the new residency cards fitted with powerful computer chips. 'Data on the chip will include not just the citizen's name and address but also work history, educational background, religion, ethnicity, police record, medical insurance status and landlord's phone number. Even personal reproductive history will be included...
Who cares about human rights and democracy. We're doing great business!


Wednesday, July 18, 2007

The unintended consequences of synthesizing government and technology

As technology becomes more sophisticated, government has access to more information about its citizens as a matter of course. Is this a problem?

It can be
I blogged previously about the addition of a "black box" in cars for the purposes of collecting crash data - now used by insurance companies to offer discounts for good driving (or perhaps as proof of bad driving?). And in Britain, it's just been revealed that the camera system used for assessing congestion fees will now be used regularly by anti-terror police, despite earlier assurances to the contrary.

I've got nothing to hide
Some folks argue that privacy concerns are hyperbole - that law-abiding citizens have nothing to fear from greater surveillance.

What privacy really means
GWU Professor Daniel Solove explores the fallacy of this argument in this compelling essay: "'I've Got Nothing to Hide' and Other Misunderstandings of Privacy"

Thursday, June 28, 2007

Data reuse endangers privacy

That data you give the Census bureau is private, right? It'll just be used in the aggregate to help assign congressional districts and distribute federal funds?

That's the theory, but electronic security columnist Bruce Schneier examines how data reuse (or repurposing) has led to significant violations of privacy.

The Census Bureau normally is prohibited by law from revealing data that could be linked to specific individuals; the law exists to encourage people to answer census questions accurately and without fear. And while the Second War Powers Act of 1942 temporarily suspended that protection in order to locate Japanese-Americans, the Census Bureau had maintained that it only provided general information about neighborhoods.

New research proves they were lying.

The article notes that this is not just the past and how our data-hungry society can leave a lot of information available for unscrupulous use.

There are two bothersome issues about data reuse. First, we lose control of our data. In all of the examples [Amazon recommending books based on browsing habits, airlines saving your seat preferences], there is an implied agreement between the data collector and me: It gets the data in order to provide me with some sort of service. Once the data collector sells it to a broker, though, it's out of my hands. It might show up on some telemarketer's screen...This, of course, affects our willingness to give up personal data in the first place. The reason U.S. census data was declared off-limits for other uses was to placate Americans' fears and assure them that they could answer questions truthfully.

The second issue about data reuse is error rates. All data has errors, and different uses can tolerate different amounts of error...That's OK; if the database of ultra-affluent Americans of a particular ethnicity you just bought has a 10 percent error rate, you can factor that cost into your marketing campaign. But that same database, with that same error rate, might be useless for law enforcement purposes.

...An even more egregious example of error-rate problems occurred in 2000, when the Florida Division of Elections contracted with Database Technologies (since merged with ChoicePoint) to remove convicted felons from the voting rolls. The databases used were filled with errors and the matching procedures were sloppy, which resulted in thousands of disenfranchised voters -- mostly black -- and almost certainly changed a presidential election result.

Of course, not examples of data reuse are bad. Medical records in the aggregate provide valuable research material for doctors and medical scientists, allowing connections to be drawn between treatments, behaviors, and outcomes. But it's important that the laws around data secure it and that data collection systems don't retain information forever (e.g. Google's recent promise to expunge search records after 18 months).




Tuesday, March 27, 2007

Your car's little black box

That little black box on airplanes has become part of popular lexicon and an invaluable tool for crash and accident investigators to improve the safety of air travel. But what about the little black box in your car?

The Goal - Better Crash Data
The Wall Street Journal has a story - "Will Your Automobile Become a Tattle-Tale?" - on the effort by General Motors to pioneer crash data technology in cars and to require cars to contain it in the near future. In addition to the existing OnStar technology, which can call 911 when the car's airbag deploys, GM's new crash detection system will record
"the direction of the impact, whether the car rolled over, the "delta V," or the change in speed, and other data."
GM is going to work with (and pay for) the Centers for Disease Control to determine how best to transmit that information to emergency services personnel on the scene of an accident. A high-speed side impact, for example, might suggest internal injuries that aren't immediately apparent.

The Effect - Tracking to Tailor Insurance Rates
Of course, once the car becomes a carrier of such data, other interested parties come knocking: insurers. In Europe, drivers can have a satellite tracking system installed in their cars and receive discounts for avoiding geographic areas and times of day with high accident rates. Canadian insurance companies have a similar scheme, but it also tracks vehicle speed, acceleration, and braking.

The Consequences?
And as we've learned with Social Security numbers, creating more data about people tends to lead far beyond the initial intent. So is it a good idea? Are better black boxes a boon to injured drivers? A great way to lower insurance rates? A nice piece of evidence that contradicts your alibi on the night of the 24th?

Monday, January 01, 2007

Pricking privacy to "protect children."

If the Justice Department can already track your internet activity via a court order, then why do they want ISPs to collect and store web surfing habits for every American? Ostensibly this will help us catch child pornographers. After all, the more vile the crime, the greater the sacrifice of liberty required to catch the criminal...

Thursday, December 28, 2006

Email is not actually private?

A federal case against a spam king has taken an interesting twist. During the investigation, the government applied for and received a court order to access the spammer's email accounts. A court order is similar to a search warrant, but it requires a lower burden of proof than a warrant. The federal government argued that it doesn't need a search warrant since emails are held on a third party server and therefore are more accessible under the Stored Communications Act. The spam king has now challenged this move, arguing that email is private and should be as such by law.

Since most people view email as private communications akin to letters (which would require a search warrant), it will be interesting to see how the case unfolds. For now, maybe I should switch on POP3 settings in my Gmail account...

Monday, October 23, 2006

Swiping the "swipeless" credit card

New Radio Frequency ID RFID-enabled credit cards won't need to be swiped (or even removed from your wallet) to make payments, ushering a new level of convenience. It may also enable a whole new kind of credit card theft. With a scanner as small as a pack of gum, someone could get a hold of your credit card information, including your name, card number, and expiration date.

The new type of credit card might make theft easier, but your card company is happy to sell you identify theft protection, only $12.99 a month! Nice. I think I'll stick with the non-broadcasting card for now...