Tuesday, June 9, 2009

Saving Privacy

An interesting piece in today's Times by Nigel Shadbolt, who is a professor of AI at Southampton University. He argues that advances in technology are eroding privacy at an alarming rate. In response he proposes nine measures.
  1. The commissioning of a report on privacy similar to Baroness Warnock's on fertilisation and embryology.
  2. Oblige government and private companies to inform the public in the event of data breaches.
  3. All government departments controling large databases to appoint a 'privacy officer'.
  4. Written procedures to manage, monitor and report on the accuracy of the personal data held.
  5. Regular auditing of government departments to ensure compliance with the Data Protection Act, the results of which would be published.
  6. Routine open access to government data on schools, health, transport and commerce.
  7. All Freedom of Information Act requests and results to be made available in web accessible formats.
  8. Insist on proportionality in cases of surveillance.
  9. Rule employer use of social networking information as inappropriate.
Are some of these too elaborate to be practical? Or is it rather that surveillance done justly, or centralising information justly, requires much more effort than is being spent at the moment?

Monday, June 8, 2009

More Clumsy Disclosures...

Another story of clumsy government disclosure of extremely sensitive data. This time discs were lost of RAF vetting records with details of affairs, debt, drug use, extra marital affairs (complete with names of third parties) and use of prostitutes.

This sort of vetting is very intrusive. We wouldn't accept it as common practice and we consider those who gather the data to owe it to the recruits to not let this sort of thing happen. Indeed, we only would tolerate such questions being asked in part because the individuals vetted freely consent to the process. Interestingly the same BBC programme that uncovered this case also reports one former director of GCHQ's claim that all internet and phone traffic 'must' be recorded to help the fight against terrorism.

It strikes me that much of the sensitive information gathered by this vetting process could also be uncovered by a thorough examination of the record of someone's internet activity. If governments decide to hold records of such sensitive information, do they owe it to the surveilled individuals to keep the information secure?

Friday, June 5, 2009

Databases and Chill

The Daily Telegraph reports that police are taking the DNA evidence of kids as young as ten, in an attempt to 'dissuade youths from committing offences in the future'. In the words of one officer:

"It is part of a long-term crime prevention strategy. If you know you have had your DNA taken and it is on a database then you will think twice about committing burglary for a living."

The police officer in question may well be right that the knowledge that one's DNA is on file might well chill criminal behaviour. But might it also chill other sorts of perfectly legitimate behaviour? Particularly if your innocence has not been enough to prevent your DNA from being taken.





Thursday, June 4, 2009

USB Scanner

From Slashdot: apparently police in the UK are seeking USB devices to scan hard drives for evidence of illegal activity. It's already the case that if your computer is seized then police have the right to thoroughly search your hard drive for any such evidence. So this device would only be cutting down on the number of police man hours needed for such a search.

I wonder, however, if a consequence of such a convenient device for the job might be that such searches were conducted much more often. Does this raise any ethical issues? Is one subject to a privacy intrusion if one's computer hard drive is scanned by computational algorithm, and no resulting scrutiny by a human being takes place?

Monday, June 1, 2009

Journalists' Sources

A journalist, Suzanne Breen, has been taken to court by the Police Service of Northern Ireland who want her to turn over all records of her interactions with Real IRA sources. The judge in the case has said he may order her to hand this material over, depending on how Breen's legal team respond.

Although there are specific reasons for thinking that Breen ought to have the right to keep her sources secret on this occasion - i.e. her own security - I'm interested in the general principle of journalists being allowed to keep their sources secret. What is this institution for? Is it a net benefit? I take it that the argument in favour runs that it is better for more information about terrorists to reach the public domain, and if journalists couldn't conceal their sources they would be severely restricted in how they cover these sorts of stories. Wheras the benefit of police access to journalists' information would be short term only - terrorists just wouldn't talk to journalists.

I'm inclined to think that the principle is a good one, and the only reason I can see for not actually having the principle encoded in law is that this could be exploited by people using it as a cover for involvement in terrorism and serious criminality.

Also, the fact that police are going through the courts may contradict a piece in the Guardian I blogged about a few weeks ago suggesting that journalists would soon be unable to keep sources secret because of the insecurity of digital communications.