Category: Privacy

Welcome to the Handmaiden’s Tale

A woman had a miscarriage in Spokane, Washington and Spokane police treated it as a crime, and swore out a search warrant against her.

This sort of sh%$ needs to be slapped down hard by the Feds.  The local US Attorney should make their lives hell:

In March, a woman miscarried in a Spokane hotel. Police investigated. They searched her room, told her they’d meet her at the hospital and found it suspicious when she did not show up. They filed a search warrant in hopes of finding her.

Considering the fetus her dependent, officers suspected that the woman could be guilty of criminal mistreatment of a child if she did not call 911 soon enough to potentially save her pregnancy, according to a warrant filed at the time.

Police later closed the investigation without pursuing criminal charges, but to Paul Dillon, a spokesperson for Planned Parenthood of Greater Washington and North Idaho, the move to investigate was “a huge violation of privacy and very stigmatizing.”

………

“Under Washington law, everything about this is discriminatory and potentially violating of constitutional rights,” Ainsworth said.

………

The case arises as reproductive freedoms have been restricted in Republican-led Legislatures from Texas to Idaho, and with the U.S. Supreme Court seemingly poised to curtail or even overturn the abortion rights enshrined in the landmark Roe v. Wade case. While abortion remains legal in all 50 states, Ainsworth said under Washington’s Equal Rights Amendment, investigating pregnancy losses could be discriminatory as such investigations are necessarily biased against women, Ainsworth said.

“Here this person is suffering, an ambulance is called to make sure they’re OK, then the police show up and the police are surprised they didn’t check themselves into a hospital,” Ainsworth said. “This person needed their autonomy and grief to be respected and instead there’s a search warrant.”

The goal here is to eventually make a miscarriage a matter for law enforcement, and it must be aggressively fought at every level, because any step back will be occupied by people who want to keep women in chains.

A Good Start

One of the problems with privacy is that law-enforcement uses private actors to collect personal information to collect data which it would otherwise be constitutionally forbidden from doing.

Senator Ron Widen has introduced the 4th Amendment is not for Sale Act to forbid this.

It’s nice, but the bill should be expanded to the point where Peter Thiel’s Palantir is driven out of business:

Federal agencies have taken advantage of legal loopholes to collect massive amounts of personal information from cell phone and internet users without congressional or judicial authorization for years, but that practice is being challenged by a bipartisan and bicameral group of lawmakers who introduced legislation on Wednesday that would prevent the U.S. government from buying individuals’ information from data brokers without a court order.

Led by Sen. Ron Wyden (D-Ore.), a group of 20 senators introduced the Fourth Amendment Is Not For Sale Act (pdf) in the upper chamber of Congress. Reps. Jerry Nadler (D-N.Y.) and Zoe Lofgren (D-Calif.) also unveiled an equivalent bill in the House.

By closing major loopholes in federal privacy laws—including the Electronic Communications Privacy Act and the Foreign Intelligence Surveillance Act—the newly proposed legislation seeks to protect everyone in the U.S. from unlawful searches and seizures, one of the key civil liberties spelled out in the Bill of Rights.

In a press release (pdf), the lawmakers said that “while there are strict rules for consumer-facing companies—phone companies like AT&T and Verizon and tech companies like Google and Facebook—loopholes in the law currently permit data brokers and other firms without a direct relationship to consumers to sell Americans’ private information to the government without a court order.”

………

The Fourth Amendment Is Not For Sale Act would require law enforcement agencies to obtain a court order before accessing data about people through third-party brokers that “aggregate and sell information like detailed user location data, surreptitiously gathered from smartphone apps or other sources,” The Verge reported Wednesday.

As Free Press Action explained, the bill would also prevent “police and intelligence agencies from buying data on people if the information was obtained from a user’s account or device, or via deception, hacking, violations of a contract, privacy policy, or terms of service.”

In addition, the bill would close loopholes that enable the national security state to buy metadata about U.S. residents’ international calls, texts, and emails, and to collect records about their web browsing of foreign websites. While this is information that would typically require a warrant to access, the intelligence community has found ways to circumvent the Fourth Amendment, routinely violating individuals’ constitutional rights in the process.

Call your Congress Critters and tell them to support the bill.

Not only will it force elements of the state security apparatus to behave more ethically, but it will also take money out of the pickets of the data brokers.

H/t naked capitalism.

I Picked the Right Time to Switch to Verizon®

As I noted yesterday, my family and I changed my provider from Sprint® to Verizon®.

To be sure, the problem was not with Sprint® per se, it was because Verizon® gave us a better deal, particularly since we were already FIOS®, the land line fiber service, customers, particularly with regard to getting new phones for Sharon, Natalie, and Charlie.  (We’ll be saving about $50 a month including various discounts, and replacing Sharon’s* and the kid’s decrepit cell phones for free.)

That being said, I have had some misgivings about the T-Mobile®‘s takeover of Sprint® a few years back, and the increasing move to T-Mobile®-ize Sprint was concerning.

What I did not expect T-Mobile® to do though was to attempt to aggressively spy on its customers to collect ad dollars, but is what they did, as the folks at The Register noted, ” Privacy Purists Prickle at T-Mobile Us Plan to Proffer People’s Personal Web, App Pursuits to Ad Promoters.” (Seriously, El Reg’s headline writers should get a Pulitzer

T-Mobile is requiring users to opt out in order for them not to share data like, phone location, apps installed on the phones,  web browsing habits.

T-Mobile® is claiming that the data is “Anonymized”, but each phone user will have a unique identifier, and by aggregating as few as 5 data points, the likelihood of specifically identifying a user becomes well more than 90%. (The term is “Profiling” or “Stalking”)

What’s more, as the folks at Ars Technica note the opt-out process is (unsurprisingly) not working reliably, “We’ve heard from customers who say they’ve had problems opting out so you may have to try multiple links or make multiple attempts,” because ATAB (All Telcos Are Bastards).

It’s a rather depressing turn of events for a wireless company that markedly improved consumer treatment in the US market a few years ago.

*Love of my life, light of the cosmos, she who must be obeyed, my wife.

My Next Computer is not Going to Be Windows 10

The latest Microsoft operating system is a privacy horror show:

By default, Microsoft gets to see your location, keystrokes and browser history — and listen to your microphone, and some of that stuff is shared with “trusted [by Microsoft, not by you] partners.”

You can turn this all off, of course, by digging through screen after screen of “privacy” dashboards, navigating the welter of tickboxes that serve the same purposes as all those clean, ration-seeming lines on the craps table: to complexify the proposition so you can’t figure out if the odds are in your favor.

Oh, and if you’ve already chosen to use Firefox as your default browser, Microsoft overrides your decision when you “upgrade” and switches you to the latest incarnation of the immortal undead monster formerly known as Internet Explorer.

See also here, where they note that you cannot shut the service off except by getting deep into dodgy operating system functions, and it listens to everything that you say.

A ain’t gonna go Mac though:  I hate walled gardens, so it’s probably some flavor of Linux for me next time around.

The Internet of Things Got Hacked Again, Things that go Buzz in the Night Edition


In news of the coming tech utopia, a network enabled sexual aid has been hacked, and even in the unhacked condition, it sends personal data back to the manufacturer.

The Internet of Things That Can Be Hacked grows daily. Lightbulbs, trucks, and fridges all have computers inside them now, and all have been hacked by someone. But at least you don’t put those inside your body.

Two years ago, someone had the good idea to put a bluetooth connection inside a vibrator, and the We-Vibe 4 Plus was born. The vibrator can connect with a smartphone app that its makers say “allows couples to keep their flame ignited – together or apart”: that is, it can be controlled remotely, while, say, making a video call.

The consequences of a wrong number are left to reader’s imagination.

But at the Def Con hacking conference in Las Vegas, two independent hackers from New Zealand, who go by the handles goldfisk and follower, revealed that the way the vibrator speaks with its controlling app isn’t really secure at all – making it possible to remotely seize control of the vibrator and activate it at will.

In their talk, Hacking the Internet of Vibrating Things, Follower argued that despite titters at the back of the room, the security of a sex toy should be taken seriously. “The company that makes this vibrator, Standard Innovation: They have over 2 million people using their devices, so what’s at stake is 2 million people.”

“A lot of people in the past have said it’s not really a serious issue,” he added, “but if you come back to the fact that we’re talking about people, unwanted activation of a vibrator is potentially sexual assault.”

Potentially worse still, the pair discovered that the app itself was phoning home, letting the manufacturer discover some very intimate information about users.

(emphasis mine)

I want no part of this brave new world.

Microflaccid Screws the Pooch

A court in France has ruled that Windows 10 illegally invades user privacy, as well as being too insecure:

A French regulator has issued Microsoft a formal warning over Windows 10, saying the operating system collects excessive amounts of personal data, ships that information illegally out of the EU, and has lousy security.

The warning comes from the Commission Nationale de l’Informatique et des Libertés (CNIL), an independent data privacy watchdog with the power to levy fines against companies. The CNIL has been investigating Windows 10 since its launch and has now drawn up a damning list of criticisms.

“The CNIL has decided to issue a formal notice to Microsoft Corporation to comply with the Act within three months,” said the group on Wednesday.

………

Chief among the regulator’s concerns is the amount of information Windows 10 slurps up about its users and sends back to Microsoft’s servers. While all recent flavors of Windows send some information back to Redmond, Windows 10 harvests much more and the CNIL considers this intrusive and also not needed to run the OS.

It could also be breaking the law. The collapse of the Safe Harbor agreement last year didn’t stop this flow of data from French users back to the US, and the CNIL is concerned that Microsoft made no attempt to comply with the law. The watchdog estimates that there are at least 10 million Windows users in the Euro nation.

This in addition to buying Nokia’s cell phone business, where they wrote down over 7 billion dollars , and then they sold off the Nokia brand.

And then there is the whole ribbon thing in the more recent versions of Office.

Why is this company still a going concern?

Your Daily Guck Foogle

I’ve just discovered a web site that monkey wrenches your Google search history.

Seeing as Google Alphabet has gone full Monty privacy invading evil, I recommend this service, particularly since it is a bit of a screw you to the NSA as well:

Unless you’ve specifically told it not to, Google remembers everything you’ve ever searched for—a fact that’s been useful for artists, Google’s bottom line, law enforcement investigations, among many other things. We’ve all searched for stuff we probably shouldn’t have from time to time, but a web developer has decided to take the shared experience of regretting a specific search to its logical extreme.

Ruin My Search History” promises to “ruin your Google search history with a single click,” and that’s exactly what it does. Click on the magnifying glass and it’ll take over your browser and immediately cycles through a series of search terms ranging from the mildly embarrassing (“why doesn’t my poo float,” “smelly penis cure urgent”) to the potentially relationship-ruining (“mail order paternity test,” “attracted to mother why”) to the type of thing that might get your name on a list somewhere (“isis application form,” “cheap syria flights,” “how to kill someone hypothetically”).

………

“I [Jon, the guy who authored the site] thought better of that and went down the route of things you’d hate for people to see in your search history,” he said. “I tried to make a semi-story out of the searches to add to the horror. And added in the person’s location to the queries (though people don’t seem to have noticed that).”

………

“Really not sure how I came up with the idea originally,” Jon wrote. “It was probably sparked by the never ending surveillance saga in the news: Snowden, NSA, phone taps, metadata, who searches for what.” I asked Jon if he thought there’s something to the idea that if we all search for words that are likely to be on a watchlist somewhere, we can confuse the NSA or make a comment about mass surveillance.

“I had the idea that the best way to make the government’s search surveillance useless is for us all to be on ‘the list,’” he said. “Maybe it does a bit, but if that’s enough to throw their surveillance off course, it’s probably not great surveillance.”

After it was posted, the website quickly went to the top of Reddit’s /r/internetisbeautiful, where people immediately began to freak the f%$# out over the inclusion of ISIS-related search terms. The reaction has been so visceral, in fact, that one of the moderators has had to step in and defend leaving the link to the site—which now has warnings all over it—on the page: “We’ve taken adequate steps to warn redditors that this link might be something you shouldn’t just blindly click,” internetisbeautiful moderator K_Lobstah wrote in an incredibly long post. “I promise the NSA is not going to black bag you in your sleep (unless you are a terrorist). I promise the police are not calling a judge off his poker game tonight to obtain an emergency search warrant for your apartment.”

It’s mostly harmless, but one warning:  one search term is “Donald Trump”.

Panglossian Bullsh%$

I just love the techno-utopians who seem to think that your car spying on your driving habits and phoning home will create a travel paradise,

The author thinks that Tesla invading your privacy is the bee’s knees:

………

The majority of cars sold in the U.S. now have event data recorders—sometimes described as black boxes—that log data to be examined in the event of an accident.

Most of those devices don’t record as much detail as Tesla does, or send it out over the Internet. But Internet connectivity in cars is becoming more common, and carmakers are keen to make use of whatever data they can get from our vehicles.

Only about a quarter of new cars have the necessary technology today, but that’s expected to reach over 90 percent by 2020. Companies such as GM are open about their interest in expanding the range of data they collect on driver actions to open up new business opportunities.

One big motivation for car companies is to get into the insurance business. Some insurance companies already offer discounts if you install a device in your car with sensors that monitor your driving habits, and GM has partnerships with several that tap into its OnStar system. But insurance companies could have much to gain by getting more detailed data as Tesla does, so they can see not only the car’s motion but every action of the driver.

The word for this is dystopian.

Big Brother, Big Auto, whatever.

This Has Fail Written All Over It

Some whiz kid (as in urine for brains) at Google has decided that they can simply profile you well enough to do know who you are:

Google will begin testing an alternative to passwords next month, in a move that could do away with complicated logins for good.

The new feature, introduced to developers at the company’s I/O conference, is called the Trust API, and will initially be tested with “several very large financial institutions” in June, according to Google’s Daniel Kaufman.

Kaufman is the head of Google’s Advanced Technology and Projects group, where the Trust API was first created under the codename Project Abacus. Introduced last year, Abacus aims to kill passwords not through one super-secure replacement, but by mixing together multiple weaker indicators into one solid piece of evidence that you are who you say you are.

Among the pieces of evidence that Google suggests the Trust API could use are some obvious biometric indicators, such as your face shape and voice pattern, as well as some less obvious ones: how you move, how you type and how you swipe on the screen. With the service continually running in the background of the phone, it can keep track of whether those indicators match how it knows you use your phone.

Individually, it would be ludicrous to use any of those methods to secure web services. Even facial recognition, now built in to many Android phones, is significantly less secure than a fingerprint scanner, according to Google’s own metrics. But combining them can, the company suggests, result in something more than 10 times as secure as a fingerprint.

This is a verification system that would fail when, for example, you have a migraine coming on, or when you have fallen and broken your wrist, or when you are shaken up following a car crash, then you cannot unlock your phone.

I understand why Google likes this,  “With the service continually running in the background of the phone,” it means that they can invade your privacy, and sell your data to identity thieves even more efficiently.

For the rest of us, it does not make a whole lot of sense.

Today’s Must Read

Edward Snowden has an essay in The Intercept on on the nature whistle-blowing that you really need to read:

………

If harmfulness and authorization make no difference, what explains the distinction between the permissible and the impermissible disclosure?

The answer is control. A leak is acceptable if it’s not seen as a threat, as a challenge to the prerogatives of the institution. But if all of the disparate components of the institution — not just its head but its hands and feet, every part of its body — must be assumed to have the same power to discuss matters of concern, that is an existential threat to the modern political monopoly of information control, particularly if we’re talking about disclosures of serious wrongdoing, fraudulent activity, unlawful activities. If you can’t guarantee that you alone can exploit the flow of controlled information, then the aggregation of all the world’s unmentionables — including your own — begins to look more like a liability than an asset.

Read the rest.

Live in Obedient Fear, Citizen!

What a surprise. People are using facial recognition to stalk porn stars. I expect this to extend to non porn stars shortly:

This story originally appeared on Global Voices Advocacy

The developers behind “FindFace,” which uses facial recognition software to match random photographs to people’s social media pages on Vkontakte, say the service is designed to facilitate making new friends. Released in February this year, FindFace started gaining popularity in March after a software engineer named Andrei Mima wrote about using the service to track down two women he photographed six years earlier on a street in St. Petersburg. (They’d asked him to take a picture of them, but he never got their contact information, so he wasn’t able to share it with them at the time.)

From the start, FindFace has raised privacy concerns. (Even in his glowing recommendation, Mima addressed fears that the service further erodes people’s freedoms in the age of the Internet.) In early April, a young artist named Egor Tsvetkov highlighted how invasive the technology can be, photographing random passengers on the St. Petersburg subway and matching the pictures to the individuals’ Vkontakte pages using FindFace.

“In theory,” Tsvetkov told RuNet Echo, “this service could be used by a serial killer or a collector trying to hunt down a debtor.”

It ain’t just the government that is creating a panopticon.  The private sector is moving there even faster.

Live in Obedient Fear, Citizen

In Seattle, police raided the apartment of a privacy activist.

They got a warrant by noting that the IP address of the activist was tied to child porn, but they did not tell the judge that the activist was running a Tor node, which meant that he was not the origin point, and had no way to know the content of the material:

One week after Seattle police searched the home of two well-known privacy activists for child porn and found nothing, critics are questioning why the department failed to include a key piece of information in its application for a warrant—the fact that the activists operated a Tor node out of their apartment, in order to help internet users all over the world surf the web anonymously.

“You knew about the Tor node,” said Eric Rachner, a cybersecurity counsultant and co-founder of Seattle’s Center for Open Policing, addressing the police department on Twitter, “but didn’t mention it in warrant application. Y’all pulled a fast one on the judge… you knew the uploader could have been literally anyone in the world.”

At 6 a.m. on March 30, Seattle police showed up at the Queen Anne apartment of Jan Bultmann and David Robinson with a search warrant to look for child porn, based on a tip that traced an illicit video to their IP address. Six officers arrived with two vans and spent over an hour doing forensic searches on the computers in the home. One officer stood in the bedroom and watched as Robinson got dressed.

They didn’t find anything. Bultmann and Robinson, both board members of the Seattle Privacy Coalition, were released after being detained in a van, but they were left shaken and upset.

………

Bultmann and Robinson had publicly advertised that they operated a Tor exit relay node—a node in the global Tor network, whose purpose is to give users the ability to browse the web anonymously. They said they operated the node as a service to dissidents in repressive countries, knowing full well that criminals might use it as well, much like any other communication tool. Tor stands for “the onion router,” a mechanism by which information is encrypted in layers as it passes through multiple, randomized nodes in the network.

In the aftermath of the search, the question was whether Seattle police had done their technical due diligence: Did they recognize that Bultmann and David were operating a Tor node? If so, did they realize that a tip about child porn coming from that IP address, absent any other evidence, likely meant someone else in another part of the world had uploaded the material and it had been randomly routed through their node?

………

“It’s like raiding the mailman’s house for delivering an illegal letter with no return address,” said one commenter on the tech website YCombinator. “Sure, it could have been sent by the mailman, but it could have been sent by anyone. There isn’t any more reason to suspect the exit node operators than anyone else in the whole world who could also have used the exit node.”

The warrant application (PDF), signed by King County Superior Court Judge Bill Bowman, makes no mention of the Tor node, much less Bultmann and Robinson’s public roles as privacy activists. Nor does a warrant application dated February 24 to obtain subscriber records related to the address from Wave G, the Internet service provider. Both documents suggest that Bultmann and Robinson are ordinary web users with a private home connection.

………

SPD spokesperson Sean Whitcomb said the department understands how Tor works and that before executing the search, officers knew that Bultmann and Robinson operated the Tor node out of their apartment. “Knowing that, moving in, it doesn’t automatically preclude the idea that the people running Tor are not also involved in child porn,” Whitcomb told NPR. “It does offer a plausible alibi, but it’s still something that we need to check out.”

But in a statement today, the department said its detectives didn’t know about the Tor node when they filed the warrant application on March 28. If true, this means detectives took notice of the Tor node after the judge approved the warrant, then carried out the exhaustive early-morning search two days later anyway.

Robinson questions whether police deliberately delayed checking the IP address against the public list of Tor nodes in order to avoid sharing exculpatory information with the judge. He believes a sound investigation would have checked the IP address as soon as the tip came in. “Why spoil a perfectly good warrant with facts?” he asked.

Of course, there will be on consequences for the police who deceived the judge.

There never is.

What a Surprise. The FBI and the DoJ Lied

After attempting to invoke the All Writs Act, the FBI just unlocked the San Bernardino shooter’s phone all by themselves:

The Justice Department is abandoning its bid to force Apple to help it unlock the iPhone used by one of the shooters in the San Bernardino terrorist attack because investigators have found a way in without the tech giant’s assistance, prosecutors wrote in a court filing Monday.

In a three-sentence filing, prosecutors wrote that they had “now successfully accessed the data” stored on Syed Rizwan Farook’s iPhone and that they consequently no longer needed Apple’s court-ordered help getting in. The stunning move averts a courtroom showdown pitting Apple against the government — and privacy interests against security concerns — that many in the tech community had warned might set dangerous precedents.

I am going to put my tinfoil hat on here, and suggest that the FBI always knew that they could hack the phone.  It was probably only a call to Fort Meade away.

It took them just a few days once they realized that the court was not receptive to their demands and they were getting excoriated in the press.

 They were sandbagging the court and abusing legal process.

The FBI Probably Never Needed Apple’s Help to Read That iPhone

The Department of Justice has asked for a recess in the court proceedings to force Apple to write a hacking tool for the iPhone:

The Justice Department said on Monday that it might no longer need Apple’s assistance in opening an iPhone used by a gunman in the San Bernardino, Calif., rampage last year.

The disclosure led a judge to postpone a court hearing over the issue and temporarily sidesteps what has become a bitter clash with the world’s most valuable company.

In a new court filing, the government said an outside party had demonstrated a way for the F.B.I. to possibly unlock the phone used by the gunman, Syed Rizwan Farook. The hearing in the contentious case — Apple has loudly opposed opening the iPhone, citing privacy concerns and igniting a heated debate — was originally set for Tuesday.

While the Justice Department must test this method, if it works “it should eliminate the need for the assistance from Apple,” it said in its filing. The Justice Department added that it would file a status report by April 5 on its progress.

This happened because they think that the case is going against them.

None of this would happened if the FBI hadn’t “mistakenly” reset the iCloud password for the phone, which would have allowed them to access the phoe.

My take is that the FBI attempted to sandbag the judge, and deliberately f%$#ed up the analysis of the phone to have a court case and create a precedent.

What a Surprise. The Terrorists in Paris Did Not Use Encryption

They used burner phones and made calls instead of texting and emailing:

New details of the Paris attacks carried out last November reveal that it was the consistent use of prepaid burner phones, not encryption, that helped keep the terrorists off the radar of the intelligence services.

As an article in The New York Times reports: “the three teams in Paris were comparatively disciplined. They used only new phones that they would then discard, including several activated minutes before the attacks, or phones seized from their victims.”

The article goes on to give more details of how some phones were used only very briefly in the hours leading up to the attacks. For example: “Security camera footage showed Bilal Hadfi, the youngest of the assailants, as he paced outside the stadium, talking on a cellphone. The phone was activated less than an hour before he detonated his vest.” The information come from a 55-page report compiled by the French antiterrorism police for France’s Interior Ministry.

Outside the Bataclan theatre venue, the investigators found a Samsung phone in a dustbin: “It had a Belgian SIM card that had been in use only since the day before the attack. The phone had called just one other number—belonging to an unidentified user in Belgium.”

As police pieced together the movements of the attackers, they found yet more burner phones: “Everywhere they went, the attackers left behind their throwaway phones, including in Bobigny, at a villa rented in the name of Ibrahim Abdeslam. When the brigade charged with sweeping the location arrived, it found two unused cellphones still inside their boxes.” At another location used by one of the terrorists, the police found dozens of unused burner phones “still in their wrappers.”

As The New York Times says, one of the most striking aspects of the phones is that not a single e-mail or online chat message from the attackers was found on them. That seems to be further evidence that they knew such communications were routinely monitored by intelligence agencies. But rather than trying to avoid discovery by using encryption—which would in itself have drawn attention to their accounts—they seem to have stopped using the Internet as a communication channel altogether, and turned to standard cellular network calls on burner phones.
 
………

As Ars has reported, along with other countries the UK government is pushing for ways to circumvent or weaken encryption because it claims strong crypto creates a “safe space” for terrorists. This new information that the Paris attackers did not routinely use encryption, if at all, but turned instead to the tried-and-tested technique of burner phones, undermines the argument that everyone’s communications must be weakened in order to tackle terrorism.

………

Until we have stronger evidence to the contrary, it seems likely that encryption played little or no part in the Paris terrorist attacks.

The various agencies of various state security apparatuses have been trying to sell the idea that the terrorists will kill us all if we don’t let them.

It does not make us safer.

They intend to use this to go after ordinary criminals and dissidents.

Why Law Enforcement Data Dragnets Are a Wicked Bad Idea, Part 95

In Denver, it has been revealed that police have been using law enforcement databases for personal purposes, including helping friends stalk their exes.

Rather unsurprisingly, no police officers have received any meaningful discipline for that behavior:

Denver police officers performed searches on state and federal criminal justice databases that were not work-related and instead were made to help officers’ in the romance department and to assist friends, according to an independent department monitor. The report said that punishment, usually a written reprimand instead of being charged criminally, is not enough to deter future abuse of the National Crime information Center (NCIC) and the Colorado Crime Information Center (CCIC) databases.

“When used appropriately, they can be powerful tools to investigate crime,” the report stated. “But the misuse of these databases for personal, non-law enforcement purposes may compromise public trust and result in harm to community members. We believe that the reprimands that are generally imposed on DPD (Denver Police Department) officers who misuse the databases do not reflect the seriousness of that violation, and may not sufficiently deter future misuse.”

The report by Independent Monitor Nicholas Mitchell listed a host of wrongful searches, including an officer getting a phone number of a woman he met on assignment, and an officer running the license plate of a man for a friend who then stalked that person. None of the 25 Denver officers who abused the crime databases were charged with any access crime. The harshest penalty was a three-day suspension. Civilians who accessed the databases without authorization, however, most likely would be charged with hacking.

There’s been reports across the country of officers wrongly accessing criminal justice records for their personal use, sometimes resulting in criminal punishment. And sometimes police officers abuse the database to troll their own. In 2012, for example, Minneapolis paid out $1 million to a former female police officer whose driver’s license record was looked up more than 400 times by fellow officers.

I would bet dollars to navy beans that the suspensions were of the paid variety.

We saw the exactly the same thing with the NSA.

This is what happens when the authorities have access to your data.  They abuse that access for their personal benefit.

This is why the bulk collection of data by the state security apparatus is so toxic.

First Tor News Site

Rather unsurprisingly, it’s the not-for-profit news organization ProPublica:

The so-called dark web, for all its notoriety as a haven for criminals and drug dealers, is slowly starting to look more and more like a more privacy-preserving mirror of the web as a whole. Now it’s gained one more upstanding member: the non-profit news organization ProPublica.

On Wednesday, ProPublica became the first known major media outlet to launch a version of its site that runs as a “hidden service” on the Tor network, the anonymity system that powers the thousands of untraceable websites that are sometimes known as the darknet or dark web. The move, ProPublica says, is designed to offer the best possible privacy protections for its visitors seeking to read the site’s news with their anonymity fully intact. Unlike mere SSL encryption, which hides the content of the site a web visitor is accessing, the Tor hidden service would ensure that even the fact that the reader visited ProPublica’s website would be hidden from an eavesdropper or Internet service provider.

“Everyone should have the ability to decide what types of metadata they leave behind,” says Mike Tigas, ProPublica’s developer who worked on the Tor hidden service. “We don’t want anyone to know that you came to us or what you read.”

Of course, any privacy-conscious user can achieve a very similar level of anonymity by simply visiting ProPublica’s regular site through their Tor Browser. But as Tigas points out, that approach does leave the reader open to the risk of a malicious “exit node,” the computer in Tor’s network of volunteer proxies that makes the final connection to the destination site. If the anonymous user connects to a part of ProPublica that isn’t SSL-encrypted—most of the site runs SSL, but not yet every page—then the malicious relay could read what the user is viewing. Or even on SSL-encrypted pages, the exit node could simply see that the user was visiting ProPublica. When a Tor user visits ProPublica’s Tor hidden service, by contrast—and the hidden service can only be accessed when the visitor runs Tor—the traffic stays under the cloak of Tor’s anonymity all the way to ProPublica’s server.

I don’t think that this is the start of a trend, as near as I can figure out, there is no way to monetize a Tor node through advertising, though I imagine that the classified ad section would be ……… different ……… and I am sure that the FBI would find this very interesting.

How the Internet of Things Will Actually Be Used

It will be invading our privacy and discrimination, all while presenting it as a benefit to the consumer.

You might want to check out this bit of propaganda from the insurance industry courtesy of the Washington Post, and imagine what they would do if they knew what food was in your fridge, or how often you drink, or what you set your thermostat to.

The term to describe this is “dystopian”:

For years, insurance companies have used estimates of your annual mileage to determine your car insurance rates. But with recent changes in technology, insurers now have an unprecedented ability to judge your actual driving habits. Armed with detailed data on how often you slam on the brakes and what times of day you’re on the road, insurance companies are increasingly relying on precise, technological means of assessing risk — and using that information to set your monthly premiums.

Liberty Mutual, the country’s third-largest property-and-casualty insurer, took the latest step in that direction Monday when it announced a partnership with Subaru. Beginning later this year, Subaru drivers who have paid for the automaker’s Starlink infotainment system will be able to download an app to their cars that notifies them when they are accelerating too aggressively or braking too hard.

The app is part of Liberty Mutual’s RightTrack program, which gives drivers a 5 percent discount on their rates for enrolling and additional discounts up to 30 percent for heeding the app’s guidance on driving safely.

Liberty Mutual, which began offering RightTrack in 2012, isn’t the only insurer to embrace usage-based insurance — a tactic that draws on a person’s real-world driving behavior to gauge his accident risk. Progressive, Allstate and State Farm operate similar programs, too.


.………

But as more Americans begin buying high-tech, connected cars that can talk to the Internet, other analysts say the rise of usage-based insurance raises uncomfortable questions for consumers and insurance companies alike.

“Don’t assume this is always going to be a way to lower your rates,” said Karl Brauer, an analyst at Kelley Blue Book. “It could be used against you to raise your rates long before you ever have an accident.”

Although many insurance companies say that agreeing to be tracked can only result in a discount, not a rate hike, those terms could always change in the future, Brauer and other analysts say. And people who drive safely one year but more riskily the next could effectively see their rates rise when an insurer decides to grant a smaller discount than before.

Then there’s the matter of consumer privacy. How long insurance companies can hold onto your data, and whom they can share it with, depends on each firm’s policies as well as state or local regulations. Insurers would also have to obey court orders for user data.But as more Americans begin buying high-tech, connected cars that can talk to the Internet, other analysts say the rise of usage-based insurance raises uncomfortable questions for consumers and insurance companies alike.

“Don’t assume this is always going to be a way to lower your rates,” said Karl Brauer, an analyst at Kelley Blue Book. “It could be used against you to raise your rates long before you ever have an accident.”

Although many insurance companies say that agreeing to be tracked can only result in a discount, not a rate hike, those terms could always change in the future, Brauer and other analysts say. And people who drive safely one year but more riskily the next could effectively see their rates rise when an insurer decides to grant a smaller discount than before.

Then there’s the matter of consumer privacy. How long insurance companies can hold onto your data, and whom they can share it with, depends on each firm’s policies as well as state or local regulations. Insurers would also have to obey court orders for user data.

………

Consumers who don’t want to be tracked don’t have to sign up. But when such programs become more common, opting out could serve as a “red flag” to insurance companies, according to Renee Stephens, vice president of U.S. auto quality for J.D. Power and Associates.

Insurers find behavioral monitoring attractive because it provides them with a clearer picture of the entire risk pool. By understanding better how each driver behaves, companies can design insurance plans that match a person’s risk more accurately and determine how much coverage a given driver requires.

Yes, just trust the insurance companies with your data, allow them to apply opaque algorithms to their systems, and the consumer will always benefit.

Yeah, sure, and Donald Trump does not have a comb over.

The insurance companies will use this to f%$# us like a drunk sorority girl.

It’s Back

After having their plans to thwarted by activists, CISA is back:

US librarians have joined with a host of civil liberties groups to condemn a cybersecurity bill now passing through Congress they claim will be both “unhelpful” and “dangerous to Americans’ civil liberties”.

The American Library Association, the world’s oldest and largest library affiliation, has joined with 18 other groups including Fight for the Future, Demand Progress and FreedomWorks to issue a letter to the White House and Congress urging lawmakers to oppose the final version of a bill they claim will dramatically expand government surveillance while failing to tackle cyber-attacks.

Politicians from both sides of the House have been pushing for stronger cybersecurity measures in the wake of the Paris attacks and the recent San Bernardino shooting.

Republican House speaker Paul Ryan has been leading the charge to push through legislation and reconcile two bills, the Protecting Cyber Networks Act (PCNA) and the National Cybersecurity Protection Advancement with the Cybersecurity Information Sharing Act of 2015 (Cisa), a controversial bill that passed a Senate vote in October.

The speed with which Ryan is trying to push through a compromise has worried privacy activists. “We’ve just learned that the Intelligence Committees are trying to pull a fast one,” Nathan White, senior legislative manager at digital rights advocate Access, said in a recent email to supporters. “They’ve been negotiating in secret and came up with a Frankenstein bill – that has some of the worst parts from both the House and the Senate versions.”

  • According to the letter’s signatories, the proposed “conference” legislation would:
  • Create a loophole that would allow the president to remove the Department of Homeland Security, a civilian agency, as the lead government entity managing information sharing.
  • Reduce privacy protections for Americans’ personal information.
  • Overexpand the term “cyber threat” to facilitate the prosecution of crimes unrelated to cybersecurity.
  • Expand already broad liability protection for information disclosure.
  • Pre-empt state, local or tribal disclosure laws on any cyber-threat information shared by or with a state, tribal or local government.
  • Eliminate a directive to ensure data integrity.

They are going to keep trying until we put a stake through the heart of the surveillance industrial complex.