Showing posts with label DETECTER. Show all posts
Showing posts with label DETECTER. Show all posts

Tuesday, March 16, 2010

Thursday, January 28, 2010

News: Florence DETECTER Programme Announced

The second DETECTER Project Meeting will take place in Florence on Thursday the 18th of February 2010. The Programme will run as follows:

9.00 – 9.15 Introduction by Prof. Martin Scheinin, Professor of International Law at the European University Institute and United Nations Special Rapporteur on the protection of human rights while countering terrorism

9.15 – 11.00 Identification of terrorist suspects through detection technologies: risks and opportunities
Chair: Martin Scheinin (European University Institute, Italy)
  • Ehud Givon (WECU-technologies, Israel) – Security through intent detection
  • Jacques Verraes (Europan Commission, Belgium) – Data protection issues related to identification of terrorist suspects
  • Ben Hayes (Statewatch, United Kingdom) – Respondent to presentations of Commission and WeCU technologies

11.00 – 11.30 Coffee break

11.30 – 13.30 Human rights aspects of the use of detection technologies

Chair: Daniel Moeckli (University of Zurich, Switzerland)
  • Roos van der hilst (University of Oslo, Norway) – Human rights risks of selected detection technologies - sample uses by governments
  • Emilio Mordini (HIDE, Italy) - Biometrics, Body, Identity
  • R. Leenes (University of Tilburg, the Netherlands) – Location based surveillance – why planes, trains and automobiles are the new castles
13.30 – 15.00 Lunch

15.00-17.00 Martin Scheinin presenting WP4 Deliverable on "Developments in the Declarations of Exceptions, Claims of Inapplicability, or Unilateral Modifications in Respect of Internation Law for the Sake of Counter-Terrorism"

Limited Places - To register, please e-mail mathias.vermeulen@eui.eu

Monday, January 18, 2010

Focus on Full-Body Scanners

Since the Christmas Day plot, many voices on both sides of the Atlantic have called for increased use of full-body scanners—even to the point of having them replace the now traditional metal detector screening. But how do they work and what’s the fuss about?

Operation

There are full-body scanners that have been developed that use x-rays (generally referred to as “backscatter” scanners), but the scanners that have attracted so much attention in the media lately are millimeter wave scanners. These units rely on waves that lie somewhere between microwaves and infrared light on the frequency spectrum. According to this article from the Austrian newspaper, Der Standard, human bodies naturally emit millimeter waves. In order to produce a clear image, however, millimeter wave scanners using the so-called “active method” bombard the body with additional millimeter waves. These waves are able to pass through clothing, paper, and thin plastics but not through human bodies. Thus, the reception of these waves as they bounce back from the body can be used to construct a picture of the outer surface of the body and reveal unusual objects hidden beneath clothing. Apparently, “passive method” scanners, which merely read naturally occurring millimeter wave emissions, have been developed and used in some airports (See e.g., this article from heise online (in German)). However, I can imagine that these scanners may not produce images of the same clarity and/or may require longer screening times.

Are the “active method” machines safe?

The jury is still out. The German Federal Office for Radiation Protection indicated in an article in the sueddeutsche that existing wave research has tended to concentrate on testing the health risks of waves used in mobile devices such as mobile phones. Therefore, there isn’t a great deal of research available on the health impact of these millimeter wave frequencies. What scientists seem to agree on is that the waves won’t ionize atoms within the body like X-rays and thus won’t damage cells the way ionizing radiation does. Millimeter waves will, however, warm the tissues that they strike. What tissues they strike depends on the wavelength of the wave. These waves encompass a range of frequencies beginning somewhere around 10 gigahertz and ending somewhere around 10 terahertz. According to the article in the sueddeutsche, waves at the lower end of that spectrum could penetrate a few millimeters into the skin. I don’t know whether current models of scanners tend to use waves around one specific frequency, whether they always send out waves at various frequencies, or whether they have frequency settings which may be adjusted by the operator. This article on the German Wikipedia, however, indicates that different frequencies may be useful for detecting different materials. For one official of the German Federal Office for Radiation Protection, the “big question” is whether the waves could cause other biological effects in addition to warming—such as bringing components of skin cells into oscillation or causing changes within the blood as it flows through surface capillaries. He adds, however, that these questions are “pure speculation.” For me, the question that always arises with radiation exposure is whether more frequent exposure will pose risks that don’t present themselves in simple, short-term testing. It’s not inconceivable that frequent flyers may have to pass through such scanners 2-3 times within a 10 hour period on several occasions within a single month.

Privacy issues

There are obvious privacy issues connected with a scanner that produces images of the naked body. But apart from revealing intimate parts of the anatomy and physical anomalies that an individual might not want to bare, the scanners might also reveal details such as that the person has had a colostomy, has incontinence problems, or is menstruating. Cognizant of the privacy issues, developers of these scanners aimed to develop solutions that would address them. Initially, the idea was to place the person reviewing the images from the scanner in a separate location than where the actual scanning takes place. Thus, the person viewing the image would be unable to see “in the flesh” the individual with whom that image was associated. Additionally, algorithms were introduced to automatically blur faces (an example of an image with facial blurring can be seen here). In this way, the image reviewer would be unable to link the image to an actual person. Of course, the problem is that colostomy pouches, feminine hygiene pads, devices that deliver medications or insulin, and the like still might prompt an embarrassing or uncomfortable confrontation with security personnel at the screening location.

Scan Tech: The Next Generation?

What if we could remove the image reviewer? Could we design software to do the reviewing for us and indicate where suspicious things crop up? One project led by Loughborough University that we heard about at the first DETECTER meeting in Birmingham was aiming to develop just such a program—one that could distinguish a bottle from a handgun carried in the hand of an individual captured in video recordings. We also heard from one of the manufacturers of a millimeter wave scanner who indicated that they were working to develop that kind of technology, but that it hadn’t yet matured to where it could be implemented.

But news reports today suggest that this “second generation” technology is now available and pictures have emerged from Amsterdam’s Schiphol airport which feature just the kind of generic, impersonal gingerbread-man-like graphic that we had talked about in Birmingham (an example is available here with a close-up here). Areas of the body that hold suspicious objects are then highlighted on the graphic, so that security personnel can conduct a search of that area. Unlike the original setup, the system in Amsterdam displays the computer-generated “results” directly to the personnel manning the scanner.

There are a few things to point out about this second generation of scanning. First of all, just because pictures in the media show displays with the gingerbread man figure doesn’t necessarily mean that the viewing of the “raw” image—so to speak—has been eliminated altogether. Secondly, I’m a bit skeptical as to how well this software will perform as compared with a human viewer. It seems like getting the optimal set of algorithms would take countless test runs and tweaking, and I imagine that there would still be things that the software would miss but that a human reviewer would pick up on, as well as things that the software would catch that a human reviewer would miss or identify as harmless (like colostomy pouches). Which brings us to the third point—that the software-based solution might result in more uncomfortable confrontations with security than with the human reviewer. Lastly, the software would rely on raw data from the scanner, and it would still be theoretically possible for someone to “reconstruct” the image if that someone had access to the raw data.

Access and Data Storage

The Electronic Privacy Information Center (EPIC) has obtained documents from the US Transportation Security Administration pertaining to the procurement of full-body scanners (For links, see this post on the LIFT). The procurement specifications indicate that the TSA has put significant thought and planning into the implementation of these systems, including privacy safeguards. Nonetheless, EPIC points out that, despite TSA’s public assurances that scan images could not be saved, the documents reveal that the systems would be able to store images when in “test mode.” Granted, TSA foresees different levels of access to these systems. In this case, only TSA headquarters, maintenance technicians, and so-called “super users” would be able to put a scanner system into test mode, and image storage would be disabled during normal operation, according to the TSA’s procurement specifications (see pp. 4, C-1). A note in Appendix C of these specifications indicates that super user access for a particular system would be disabled once the system was installed, suggesting that these super users would be representatives of the equipment vendor responsible for the initial setup of the system. Thus, for normal operation on passengers, that would officially leave just TSA headquarters and technicians who would be able to place the system in test mode in which images would be stored.

Nonetheless, this news does indicate that the systems have storage capacity. The question is how much. By limiting the storage capacity to only a few images, the risk of negative privacy impact could be minimized. Of course, the flip-side of not saving images is that it rules out the possibility of performing ex post re-evaluations. Suppose another incident like that on Christmas Day occurs, but the attempted bomber had gone through a full-body scanner. Would security specialists want to take another look at that person’s scan image (supposing they can identify it) to see if they can learn something from the mistake?

Open or Closed Network(s)?

Related to the issue of access is the question of whether the system represents a closed system or is linked or exposed to broader communication networks such as the internet. At first glance, I don’t see too many reasons why these systems would need to be connected to the internet. The image reviewer would not need to read e-mail or access websites to do his or her work. One advantage of allowing internet communication is that it would permit quick, uniform updating of changes to user accounts from a central office. Thus, if an image reviewer left his or her position with the TSA, that former employee’s access could be lifted for all scanner systems throughout the country more or less simultaneously. It might also be desirable to have uniform access at all airports so that image reviewers could be shifted around according to need. On the other hand, these same objectives might be achieved through other systems, such as physical access controls—using an employee ID card or the like—that would prevent unauthorized personnel from entering image viewing facilities. However, the ability to access remotely every system’s system log would allow auditing to take place on a more efficient basis. Thus, this point would speak in favor of network access. But I’m not convinced that the burden of conducting audits on the local level would necessarily outweigh the benefit of the added security. Alternatively to local audits, audit data (which does not include image data) could be exported using flash drives or a temporary network connection.

There are indications that the TSA is opting for the fully linked system. The TSA’s procurement specifications for a “Whole Body Imager” state that the system should support a minimum user database of 10,000 accounts (p. 17). That’s an extremely high number for any single airport. Additionally, the TSA’s operational requirements call for the system to have an “802.11X compatible” network interface (p. 11). IEEE 802.11 denotes a set of wireless network protocols. Thus, the inclusion of this functionality within the operation requirements indicates that the TSA would like to ensure that these systems are capable of sending and receiving wireless communications. The operational requirements also call for the network interface to be “configurable with an IP address” (Ibid.). This requirement suggests that there would be internet access. Lastly, the documentation requires that the system be able to interface with “STIP” (Security Technology Integrated Program) (Ibid.), which appears to be the TSA’s enterprise architecture for allowing communication between detection technology instruments in the field and central headquarters (See this entry on the US government’s “IT Dashboard”).

Summing Up


In sum, health-related risks are probably minimal, but currently unknown. In light of this fact, why not simply use passive systems that rely on the human body’s own millimeter wave emissions to eliminate any possible health risk? In terms of privacy protections, replacing the human reviewer with software algorithms may reduce the privacy impact for many but increase it for others. Eliminating network access would also substantially lower the risk that scan images end up distributed where they don’t need to be but could hamper other aspects of operations. All of these considerations come on top of the questions concerning the scanners’ effectiveness and necessity (See the last full paragraph of this earlier post and this from the LIFT).

Thursday, September 3, 2009

Zurich DETECTER Site Launched

We've set up a few webpages related to the DETECTER project on the University of Zurich's website. The pages provide some information about Work Package 6, contact information for the researchers involved, and will provide a platform for any future publications that may come out in connection with the project. The "homepage" for the site is accessible here.

Tuesday, August 18, 2009

Who Should Have Access to What When?

Stories surfaced recently that two police officers in the State of Georgia in the US ran an unwarranted background check on President Obama. Evidently, the Secret Service alerted the local county government that computers within their system had been used to access information on the President. As a result, the two officers in question have been placed on suspension. Remarkably, a similar incident occurred in Pennsylvania involving a Philadelphia police officer shortly thereafter.

These incidents bring two issues to mind:

First is the issue of access controls or access monitoring with respect to information systems and databases containing personal information. On the one hand, it’s refreshing to know that the kind of controls are in place to allow the Secret Service to know that someone from a particular computer network has accessed information on the President stored on criminal justice systems. Yet, clearly the Secret Service is not going to be extending this kind of safeguard to too many people beyond the President, Vice-President, and potentially their families. It’s also unclear to what extent anyone within the network of federal and state agencies that have access to this information runs audits to ensure that other unwarranted access has not been made. With respect to at least one of the databases in question, the FBI’s National Crime Information Center database—which I discuss below—there are local agencies that oversee the administration of the system of access to the database within their locality (state, territory, etc). This agency is “responsible for monitoring system use, enforcing system discipline and security, and assuring that all users follow operating procedures.” Yet, according to on article that appeared on Slate, it was “common practice” in one locality for police “to run checks for friends and family, and to run prank names to alleviate boredom.”

Then again, I’m not sure how you would structure such an audit given the fact that probably anyone who gets pulled over by police for even the slightest traffic violation can legitimately be subjected to such a background check (Another interesting question is whether anyone has ever challenged the legitimacy of allowing officers to call up this variety of information during a routine traffic stop). Multiple system queries issued in relatively quick succession might be one indication of abuse, but this kind of action wouldn’t be inappropriate where multiple individuals have been stopped for suspicious activities. Perhaps looking for checks run on notable figures such as President Obama might be another way to catch some illegitimate use of the system, but it would not provide much of a safeguard for the majority of citizens. At any rate, my point is to draw out an issue pertaining to the “watching of the watchers” and potential remedies for “violations” on the part of the watchers. This issue of providing access controls and auditing capabilities is likely to be a significant theme in Work Package 6 of the DETECTER Project, which I am working on.

The second issue concerns the actual extent of information that access to a particular system grants—and in the context of these incidents, information sharing or consolidation among different data collecting agencies. The fact is, I don’t know exactly what information is featured in these background check queries; according to the article on Slate, it may vary from police agency to police agency since different agencies may have different access policies and procedures. I would guess they would contain: name, date of birth, height, weight, gender, eye color, address (all of these are standard things included on US driver’s licenses), driver’s license number and state of issue (perhaps even for past driver’s license numbers, too?), vehicle registration information, list of outstanding parking tickets or fines, list of traffic viola-tions, list of arrests, list of criminal convictions, list of outstanding warrants or other All-Points-Bulletin type notices (including e.g. Interpol notices), perhaps even social security number and driver’s license photo. The Slate account adds aliases, tattoos, scars, and other distinguishing marks. However, these clearly would only be available if you had been arrested. As for fingerprints, I know of at least one state that requires fingerprinting when issuing a driver’s license. Otherwise, these also would not generally be available without a prior arrest.

But where does this information come from? According to the Slate article, the information is culled from a number of different databases. Alongside local databases, the primary source for data from all states as well as certain federal information is the National Crime Information Center database mentioned above (see also this page maintained by the Federation of American Scientists). According to the Slate article, not every police officer will necessarily have direct access to this database from his or her squad car. Thus, at least in some places, there are built-in safeguards to limit the extent of information that is made available without some justification on the part of the officer.

Yet the trend has been toward increased availability of information—including increased information sharing and extending the reach of intelligence and criminal justice resources to include more and more databases and data sources. An initiative known as MATRIX (Multi-State Anti-Terrorism Information Exchange)—I’m guessing they didn’t see the movie—represented one effort in the US in the early to mid-2000s to pool information and resources for the support of a better (and perhaps more extensive?) information system. Accounts vary, but some claimed the system would provide access to records from a number of public sources in addition to the usual law enforcement databases. One account, for instance, claimed that things such as credit information, marriage and divorce records, names of business associates, neighbors’ addresses and telephone numbers would also be made available (Duane D. Stanford and Joey Ledford, “State to Link Up Private Data,” Atlanta Journal-Constitution, October 10, 2003, cited by the ACLU in this report). There was certainly discussion of incorporating the use of an analytic system developed by a private corporation which would also include access to that corporation’s databases that held “billions of public and commercial records.” The fear that the new system would provide local police with access to an enormous variety of personal information gave forth to public uproar. Probably at least in part due to that backlash, most of the states that had initially signed on to the program gradually began to withdraw involvement.

There’s a lot more to be said on this subject of what is the appropriate extent of information that should be readily available—particularly in light of the potential for misuse. Especially in the context of national security intelligence, it is often not clear what information is of significance to prevent terrorist attacks. There is this idea, perhaps reflected in programs like DARPA’s Total Information Awareness (or “Terrorist Information Awareness” if you prefer), that if only the greatest possible amount of information were available for analysis, analysts would be able to pick up on patterns of “suspicious” activity before incidents occur. I’ll perhaps save further discussion of this subject for a future post. But beyond the question of the extent to which we should permit data aggregation, there are also the issues of what extent of existing information should be made available to whom and under what circumstances.

Wednesday, February 25, 2009

DETECTER Research Fellow Joins UoB

The new DETECTER Research Fellow, John Guelke, will be joining the Centre for the Study of Global Ethics, University of Birmingham, in early March 2009. John, who joins UoB from the University of Manchester, UK, will be responsible for - among other things - the DETECTER website and blog.

To find out more about John Guelke, visit his staff profile on the Global Ethics site.

Thursday, January 22, 2009

DETECTER Meeting, 31st January

The DETECTER Project will hold the first meeting on the 31st January, 2009. Held at the Jury's Inn, Birmingham, the project partners and the advisory board will meet to discuss the DETECTER project.

Wednesday, January 14, 2009

DETECTER Blog Goes Online

The DETECTER Blog has been officially launched. The blog will provide news, events and comments from or relating to the EU FP7 DETECTER project, which is co-ordinated by the Centre for the Study of Global Ethics at the University of Birmingham.