Category: Privacy

Is a Password Protected by the 5th Amendment?

There is a general principal in US law, that one can be compelled to turn over physical evidence, but not the contents of one’s mind, as that is protected by the 5th amendment.

So, you can be compelled to turn over a key to a lock, but not a combination. There is a fairly long legal precedent.

This case asks what it means if the lock is unbreakable, or nearly so.

Case in brief: A Canadian, on crossing the US border, was told to show the contents of his hard drive, which he did, and some of the contents were deemed by the border guard to be likely child porn, though it’s unclear of this was simply random files in the cache, or Manga, or real kiddie porn.

The machine was confiscated, and subsequently turned off.

When it was restarted, its demanded a password, since the contents had been encrypted with PGP, and were inaccessible, and Magistrate Judge Jerome J. Niedermeier has ruled that compelling him to turn over his password violates the 5th amendment.

The prosecutors are appealing saying the standard stuff about terrorism, etc.

I’m with Marc Rotenberg, executive director of the Electronic Privacy Information Center, who has said, “The consequence of this decision being upheld is that the government would have to find other methods to get this information, but that’s as it should be. That’s what the Fifth Amendment is intended to protect.”

He’s right. If you hooked up this guy’s drive to a supercomputer, and ran it for a few months, and maybe less if you brought in some experts from the NSA, at the cost of a few million dollars, you’d probably crack the password, because even the best people don’t choose truly random passwords.

Inconvenient, yes, but inconvenience is not a basis for emasculating the Bill of Rights.

I generally oppose any granting any power to the government to either judge one based on the contents of one’s mind (hate crime laws), or to force revalation of the contents of one’s minds.

See In Child Porn Case, a Digital Dilemma.

Well Knock Me Over With a Halibut, Steny Hoyer Stands Up Against Telco Immunity

I’m pleasantly surprised, as he tends to be one of the guys who goes along, though his district is quite safe, butyesterday, he gave a very strong speech against Bush’s Telco immunity.

“Finally, this legislation is silent on the issue of retroactive immunity for telecommunications companies that possibly violated privacy laws in turning over consumer information – because Congress does not have full access to information about what the companies did.

“Simply stated, it would be grossly irresponsible for Congress to grant blanket immunity for companies without even knowing whether their conduct was legal or not. And, importantly, this view is shared by the Chairman and Ranking Republican on the Senate Judiciary Committee.

“Until we understand what legal authorities were used to justify the terrorist surveillance program, there does not appear to be any practicable way to include retroactive immunity in this bill.”

As always, with all Democrats, I hope that he sticks to his guns.

Obama Clarifies, He is Against ANY Telco Immunity

After Senator Chris Dodd announced his intention to filibuster any bill with Telco immunity, Senators Clinton and Obama announced that they support a filibuster of THE BILL that came from the Senate intelligence committee.

These are, of course, weasel words. It has to go through some more committees, Judiciary comes to mind, and it is inconceivable that it would do so without so much as a comma changed, so they were free to support the final product.

While Clinton has not clarified, Obama has now made it clear that
he will support a filibuster of ANY bill with telco immunity.

The by Bill Burton, the Obama Campaign’s spokesman:

“To be clear: Barack will support a filibuster of any bill that includes retroactive immunity for telecommunications companies.”

Biden is on board too, but Hillary is still using weasel words?

Geeky Tech Content: The iPhone Makes Windows Look Like Fort Knox

OMFG!!!! Apple® has come out with a system that is less secure than Windows.

The iPhone®, which runs an Apple® version of Unix® runs everything as root.

1) Every process runs as root. MobileSafari, MobileMail, even the Calculator, all run with full root privileges. Any security flaw in any iPhone application can lead to a complete system compromise. A rootkit takes on a whole new meaning when the attacker has access to the camera, microphone, contact list, and phone hardware. Couple this with “always-on” internet access over EDGE and you have a perfect spying device.

So, unlike your home computer, this is more vulnerable, and it can be set to listen in and photograph you with a remote compromise.

This is the NSA’s wet dream, you’ve bugged yourself.

Expanded Surveillance Will Make Our Infrastructure More Vulnerable to Spying and Attacks

Here is a very interesting article by Susan Landau.

Her thesis is that the actions taken by the Bush administration and our state security apparatus have the effect of making us more vulnerable to spying and cyberterrorism.

Her very valid point is that the surveillance society envisioned by Bush and His Evil Minions will require a back door on every phone switch in the country, and once there, it will be significantly easier for state and non state actors to hack into the switches and listen to our communications.

Another Victory for the End User.

The response of the record distributors to digital music has been punative and stupid, and they’ve just been slapped down by a Court in Germany.

They refused to force an ISP to turn over data of file sharers.

Under the European privacy regulations, this is typically restricted to criminal, not civil, matters:

The ruling follows the publication two weeks ago of an Advocate-General’s opinion prepared for the European Court of Justice (ECJ) which said that countries whose law restricted the handing over of identifying data to criminal cases only were compliant with EU Directives.

Advocate-General Juliane Kokott produced advice for the ECJ on a Spanish case in which a copyright holders’ group wanted ISP Telefonica to hand over subscriber details to it.

Kokott said that details did not have to be handed over in civil cases such as Telefonica’s, and that they only had to be handed over in criminal cases. The ECJ does not have to follow an Advocate-General’s advice, but does so in over three-quarters of cases.

Another German authority had made a similar decision earlier this year, according to Heise Online. The chief prosecutor’s office in Celle refused to offer a handover because it said that substantial damage had not been shown, and that it doubted that music industry representatives would use the evidence to bring a criminal case.

It would be nice if the US weren’t the 3rd world of privacy rights.

The US Government Wants to Record Religion, Sex Habits, and Politics

The Grauniad has a the scoop on what the US Government wants for Britons coming to the US.

Highly sensitive information about the religious beliefs, political opinions and even the sex life of Europeans traveling to the United States is to be made available to US authorities when the European Commission agrees to a new system of checking passengers.

It appears that the EU is upset about this agreement. So am I.

Eventually, Karl Rove is going to want to get his hands on this sort of information for political micro targeting, and considering that we know that DHS has been compromised politically, he will get this information too.

Does Privacy Sell?

I just read this story aboutAsk.com devising an aggressive privacy policy. It was couched as a way to compete with Google.

I’ve also heard about Microsoft doing the same (in the case of the Borg, however, I won’t trust them to follow through).

This is not an outbreak of corporate ethics, but rather an attempt to capitalize on a perceived weakness of Google, the Elephant in the room, regarding privacy.

My guess is that this will not make a big difference, and we’ll see relaxation of the new policies over the next 18-24 months.

Bush To Seek New Powers to Spy on Political Opponents

There is credible evidence that Bush’s illegal wireless surveillance activity targeted CNN correspondent Christiane Amanpour in 2004.

Her husband is James Rubin, who served as Wesley Clark’s chief foreign policy spokesman, and then as a senior foreign policy adviser for John Kerry, so he would be included in any such surveillance. It’s unavoidable.

Does anyone believe that these intercepts did not get passed off to Karl Rove?

VOA News – Bush Seeks Changes in Foreign Intelligence Surveillance Act

By Deborah Tate
Capitol Hill
05 July 2007

The Bush administration is seeking to update a law governing U.S. foreign intelligence surveillance. But members of the Democratic majority in Congress are signaling they may be reluctant to approve the proposed changes because they have concerns about a controversial administration wiretapping program. VOA’s Deborah Tate reports from Capitol Hill.

The Bush administration is asking Congress to approve changes to the 1978 Foreign Intelligence Surveillance Act, or FISA. The proposed modifications would give the government more power to gather foreign intelligence information. Supporters say the changes would bring the law up to date with changes in new technology, including e-mail and wireless communications.

….

Sony PlayStation 3 is Done. Put a fork in it.

They are so crushed by the Wii (what a stupid f$#@ing name) that they are going to pimp their already meager fan base.

Product placement won’t bother the fans, but the privacy issues of reselling gamer data will.

Look at Real. People hate them more than Microflaccid now, and there are multiple open source Real players because of this.

Sony PlayStation to sell user data to advertisers
There’s already plenty of product placement in video games, but Sony (SNE) appears to have plans to take the nascent industry — in which advertisers only spent $80 million last year — to a much more sophisticated level. The company has agreed to let Nielsen track the behavior of PlayStation gamers to let advertisers better understand gamers’ demographics, how much time they spend on a given game, and how closely they pay attention to the product placement. Sony and Nielsen aren’t being totally clear yet on how they’re going to acquire the information, but it could be a combination of self-reported data and stats gleaned directly from the consoles themselves somehow.

….

Orwell rolls in his grave

It appears that in addition to bad orthodonture, the British share a fetish for surveillance cameras. Blah

Orwell rolls in his grave: Britain’s endemic surveillance cameras talk back
05/30/2007 @ 10:56 am
Filed by Will Byrne

Observed by over 4.2 million closed circuit – or CCTV – cameras across the country, Britain is already the most surveilled industrialized state in the Western world. It was recently estimated that the average Briton is captured by electronic eyes more than 300 times on a typical workday.
a
Yet the country’s surveillance network, which boasts one camera for every fourteen citizens, is no longer merely facilitating observance: It has now begun talking back. In a scene eerily reminiscent of Orwell’s dystopian vision of 1984, loudspeakers in one small-town center in northern Britain scold anyone they catch engaged in “anti-social behaviour,” including littering, drunkenness, or fighting.

Observing a bank of monitors in the council “control centre,” Middlesbrough town officials use the technology to broadcast warnings to deviants in real-time. The crime-fighting strategy behind the “speaker cam” draws upon the humiliation of being rebuked in public. A representative explained its function to the BBC in April as being to “embarrass” misbehavers into following the rules. Reports of wrongful chiding have been plentiful.

In one case, a young mother named Marie Brewster was falsely reprimanded for littering. She recounted her experience for The Guardian. “We were in the town centre and I’d got some chips at McDonald’s for my daughter Ellie, but they were hot so I tipped them into a box and crumpled the packet up. I put it on the bottom of Ellie’s pram to take home but then heard this voice say: ‘Please place the rubbish in the bin provided.’” She filed her complaint when she saw footage of the event in a televised news piece advocating the effectiveness of the new innovation in combating crime.

EFF: Breaking News

This is good news, but I am dubious that the new strip search majority on the Supreme Court will affirm this.

After all, it’s not that tough to get a bloody warrant.

Court Protects Email from Secret Government Searches
June 18, 2007

Landmark Ruling Gives Email Same Constitutional Protections as Phone Calls

San Francisco – The government must have a search warrant before it can secretly seize and search emails stored by email service providers, according to a landmark ruling Monday in the 6th U.S. Circuit Court of Appeals. The court found that email users have the same reasonable expectation of privacy in their stored email as they do in their telephone calls — the first circuit court ever to make that finding.

Over the last 20 years, the government has routinely used the federal Stored Communications Act (SCA) to secretly obtain stored email from email service providers without a warrant. But today’s ruling — closely following the reasoning in an amicus brief filed the by the Electronic Frontier Foundation (EFF) and other civil liberties groups — found that the SCA violates the Fourth Amendment.

“Email users expect that their Hotmail and Gmail inboxes are just as private as their postal mail and their telephone calls,” said EFF Staff Attorney Kevin Bankston. “The government tried to get around this common-sense conclusion, but the Constitution applies online as well as offline, as the court correctly found. That means that the government can’t secretly seize your emails without a warrant.”

Warshak v. United States was brought in the Southern District of Ohio federal court by Steven Warshak to stop the government’s repeated secret searches and seizures of his stored email using the SCA. The district court ruled that the government cannot use the SCA to obtain stored email without a warrant or prior notice to the email account holder, but the government appealed that ruling to the 6th Circuit. EFF served as an amicus in the case, joined by the American Civil Liberties Union and the Center for Democracy & Technology. Law professors Susan Freiwald and Patricia Bellia also submitted an amicus brief, and the case was successfully argued at the 6th Circuit by Warshak’s counsel Martin Weinberg.

For the full ruling in Warshak v. United States:
http://eff.org/legal/cases/warshak_v_usa/6th_circuit_decision_upholding_injunction.pdf

For EFF’s resources on the case, including its amicus brief:
http://www.eff.org/legal/cases/warshak_v_usa

Contacts:

Kevin Bankston
Staff Attorney
Electronic Frontier Foundation
bankston@eff.org

Our Interconnected World

So there I was, at work, sitting on the toilet, and my cell phone rings.

It’s Natalie’s friend, Samantha. I believe that I had Natalie call her on our cell phone to say that we were going to be late, and she called back to my phone.

While I am taking a dump.

A show of hands please about our connected society:

How many of you would like to line our bathrooms with tin-foil to block cell phones?

How about movie theaters?

How many have begun to consider tinfoil hats?

A 22 Year Old INTERN is Given Personal data on 64,000 People???? Whiskey Tango Foxtrot????

This is un-dirtyword-believable.

Data on 64,000 Ohio state workers stolen

By MATT REED, Associated Press Writer Sat Jun 16, 7:15 PM ET

COLUMBUS, Ohio – A 22-year-old intern was given the responsibility of safeguarding the personal information of thousands of state employees, a security procedure that ended up backfiring.

The names andSocial Security numbers of all 64,000 Ohio state employees were stolen last weekend from a state agency intern who left a backup data storage device in his car, Gov. Ted Strickland said.