Showing posts with label Data retention. Show all posts
Showing posts with label Data retention. Show all posts

Thursday, 25 June 2009

data retention - analysis of policies

The German Working group on data retention produced the following report:

Position on the processing of traffic data for “security purposes” (21 March 2009) on the statewatch website

Surveillance: EU Commission & responses to the Stockholm programme

In its Communication 262/4, on 10 June 2009, to the EU Parliament and the COuncil, the EU Commission seems to favour "wider freedom in a safer environment" so that there can be "An area of freedom, security and justice serving the citizen" (p. 2, 16).
http://www.statewatch.org/news/2009/jun/eu-com-stockholm-prog.pdf

The problem is as usual: safety is done through sharing of information. But how this information is collected and used remained very much undefined... So not surprisingly, there are oppositions to the Stockholm programme
See the Statewatch's summary: http://www.statewatch.org/future-group.htm (
and also the seminar organised on 31 may 2009 http://www.statewatch.org/news/2009/may/surveillance-states-seminar.pdf

with references to the European Civil Liberties Network's own analysis http://www.ecln.org/ECLN-statement-on-Stockholm-Programme-April-2009-eng.pdf

One can only agree when one looks at the EU Council's report of the "Check the Web" project launched in 2007 and presented by Europol to the COuncil on 15 May 2009 http://www.statewatch.org/news/2009/jun/eu-europol-use-of-personal-data-in-the-check-the-web-project-9604-09.pdf
and the analysis provided by Cryptohippie on Statewatch's website, which describes well what is a police state and how blissfully unaware we can be until it is too late http://www.statewatch.org/news/2009/jun/electronic-police-state-2008.pdf

See also, Watching the computers. Function creep allows EU states to use intrusive remote computer searches to target any crime, however minor (TheGuardian, 9 June 2009)

the fact that the surveillance attitude is widespread does not help Canadian Politicians Want To Pass Internet Snooping Legislation (TechDirt, 19 June 2009)

And contrary to the wide-spread feeling, security is not a justification per se for surveillance even if obviously increased CCTV and the like can help detecting crime As Google Agrees To Delete Unblurred Street View Images In Germany, One Is Used To Solve A Crime

Finally, see EU Parliament on the subject
with its "REPORT with a proposal for a European Parliament recommendation to the Council on strengthening security and fundamental freedoms on the Internet
(2008/2160(INI))"
(25 February 2009)

and the HL view on procedural rights in EU criminal proceedings http://www.statewatch.org/news/2009/may/eu-hol-ec-procedural-rights.pdf

Tuesday, 19 May 2009

Data collection and use by police

Quite a bit of irony here when thinking about the debate on whether ISPs should collect data and keep it available to police. The ACPO (Association of Chief Police Officers) considers that the sheer number of CCTV data makes it unusable to the police to track suspects! What a waste of money and time of all those concern who opposed the CCTV coverage in England. As politicians do not seem to agree (fear factor?), it may well be a long time before we see less CCTV
"ACPO: Police swamped by CCTV data" (ZDnet.co.uk, 15 May 2009)

and "UK Police Learn That More Surveillance Data Doesn't Mean Better Surveillance Data" (TechDirt, 18 May 2009)

The above obviously should make us think about any type of data mass collection: "Bad Idea: UK Launches Database Of Info On Every Child" (TechDirt, 18 May 2009)

Update: "British Cops Creating Nationwide License-Plate Surveillance System" (TechDirt 22 May 2009)

Tuesday, 21 April 2009

data retention, sale and fraud

"Report: Online black market for personal data thriving" (EurActiv, 16 April 2009) building on the Symantec report for 2008.
as long as data is detained/retained, risks about its use exist. Hence the interesting step taken by a Swedish ISP which destroys its data as it has no obligation to keep (just that of handing it in) "Swedish ISP Starts Deleting Log Files To Protect Users From IPRED Law" (TechDirt, 17 April 2009). It is certainly the safiest option, providing one cannot read on the computer disk image with specialised softwares of course!
But no doubt a new law will require retention of data, like the French law which nonetheless is so vague (no statutory instrument enacted to give details of what should be retained) that it creates uncertainties about what should be kept. "Vivement la publication du décret de l’article 6-II de la LCEN sur la conservation des données d’identification ! " (Juriscom, 25 March 2009)

Wednesday, 8 April 2009

Databases and data retention: are we giving up our liberties?

the five databases on custody, crime, intelligence, child abuse and domestic abuse should be put together via the use of new technologies.
Apart from the usual privacy issues, I don't think it is bad in itself. Let's face it: it was bound to happen because that what new technologies do. When fingerprinting arrived in 19th century, massive information (especially at the time) was collected and used. Nobody sees anything against it nowadays. And whatsoever, it is one way or another controled by the courts as it is related to criminal offences

"Police database is 'major new weapon' against crime" (ZDNet.co.uk, 6 April 2009)

On the other hand, I find it troubling that internet data can be retained. Apart from the technical side of how to use the data (frankly, if one does not use traditional investigatory techniques, how do you go through the materials?), I am puzzled by what it means in terms of control on citizens. Schematically, internet is used for e-mail, blogs (and the like), and website/shopping.
I don't see where Government can justify spying on e-mail traffic: one of the greatest advances in human rights in the 18th century was the privacy of letters (contents and where they go); why should it be different with the internet? the fear of crime CANNOT be an excuse to give away one of our liberties that our ancestors thought for, sometimes risking their lives in order to obtain those liberties.
Similarly, I don't see how we can justify spying on blogs/facebook type of traffic: do we spy on phone conversations? Well officially you need a warrant, don't you?
Similarly, for the rest of the traffic: I can't understand the basis of such a measure.

At the end of the day, our liberties are eroded in the name of crime and fear of crime. Liberties are not better protected by giving them up. Time to stand up. In that sense, I just finished going through the near 300 pages of Hypercrime. the new geometry of Harm by M. McGuire (Routledge, 2007). Although I don't agree with all what the author is saying, it conforts what I always thought: before affirming that the internet is per se different, let's compare with what happened in the past. McGuire's study is sociological and very valuable; I wish a lawyer could write the same book on a legal perspective. It would deflate the Government and media's hype we keep hearing about cybercrime.

Saturday, 28 March 2009

Anonymity, data and social networking

A scary report, but not surprising, that explains how so-called anonymised data can be reversed and named again. "New Study Shows Anonymous Data Isn't Very Anonymous At All" (TechDirt, 27 March 2009) linking to the blog of Arvind Narayanan, 33 bits of Entropy, http://33bits.org/2009/03/19/de-anonymizing-social-networks/

Sunday, 13 July 2008

Cyber-Investigations and human rights

To monitor the internet to detect (and deter?) crime seems a good idea at first sight. Yet objections are many:

  • practical objection: is it realistic to consider being able to control the internet? It's like wanting to monitor the mail correspondance of users throughout the world. Can we imagine the FBI or Europol controlling data held by post offices? Inachievable and therefore a pretence. I don't see how the physical world of letters could be much different from the cyberworld.
  • second practical objection: how on earth can you succesfully detect crime when faced with a mass of information? the old fashioned way of doing detective work (on the web understandibly) is a much more efficient than trying to cast a net so vast it would take centuries to find the problematic fish.
  • theoritical objection: again, parallels with the so-called physical world enlighten thoughts. Data "held" by post offices are private even when their contents are terrorist or criminal; why should data on the web not considered as private and thus submitted to the same regulations as for obtaining private correspondance? Where are the human rights?

And yet the FBI seriously considers asking the ISPs retention of data http://www.techdirt.com/articles/20080423/184451932.shtml (23rd April 2008)

as well as Russia's authorities who would even go further by blocking traffic like China does http://www.techdirt.com/articles/20080423/185834933.shtml (24th April 2008)

Similar problem with the 9th U.S. Circuit Court of Appeals (so federal law) agreed to let searches of laptop with no specific purposes that looking in the hard drive. Why should we set up conditions for the search of a house, but not the search of a computer when nowadays the computer is like a portable home with sometimes all the documents one needs? Where are the human rights of the accused here? Gone with the wind of fear of crime...

"Is This The Best Homeland Security Can Do In Defending Laptop Searches At The Border?" (TechDirt, 10 July 2008)

http://www.techdirt.com/articles/20080422/235343924.shtml (23rd April 2008) with an update for the Electronic Frontier Foundation asks for Congress to intervene http://www.eff.org/press/archives/2008/05/01 (1 May 2008)

Friday, 15 February 2008

Cybercrime: what is free information?

we've seen it with the theory of post-scarcity economy; but what about academic research? I always maintained research should be available for free but with acknowledgement of authors. It is thus interesting that Harvard takes that path. "Harvard Faculty Agrees To Free Up Its Research" (13 February 2008) http://www.techdirt.com/articles/20080213/003344243.shtml


If the EU goes that way, what about theft of IP address? Think about what stealing a postal address is and compare: same issues at stake; not so much, actually IP is worse.
"Is Your IP Address Your Personal Information?" (23 January 2008)http://www.techdirt.com/articles/20080121/19520029.shtml