Showing posts with label corporate spying. Show all posts
Showing posts with label corporate spying. Show all posts

Wednesday, September 15, 2010

News of the World Phone Hacking Update

As police interview a former News of the World journalist who claimed Andy Coulson asked him to hack phones, the last week has seen the pressure increase on both the newspaper and David Cameron's Director of Communications. On Thursday the 9th of September House of Commons debate was the site of a series of robust attacks on press intrusion - for example see Tom Watson MP's forthright (but on the whole characteristic) contribution below:










The claim that MPs have so far refrained from coming down on press intrusion with too much vigour for fear of becoming victims themselves is replicated elsewhere, for example in a Guardian article reporting the claim of former Plaid Cymru MP Adam Price:

Price told Channel 4 News last night that four members of the committee had considered asking the serjeant at arms to issue a warrant forcing Brooks to attend. He said: "We could have used the nuclear option. We decided not to, I think to some extent because of what I was told at the time by a senior Conservative member of the committee, who I know was in direct contact with executives at News International, that if we went for her, called her back, subpoenaed her, they would go for us. [This] meant effectively that they would delve into our personal lives in order to punish them and I think that's part of the reason we didn't do it." Watson told Channel 4 News that News International had further interfered by asking Downing Street to persuade him to tone down his questioning. "A [former Labour] cabinet minister has confirmed to me this week that News International talked to my former colleagues in No 10 Downing Street to ask them whether I would withdraw my aggressive line of questioning … I felt very frightened and intimidated." Watson added that he was told that Brooks vowed to destroy him after he led the Labour coup that persuaded Tony Blair to resign. "A very senior News International journalist told me at the Labour party conference in 2006, in the early hours of the morning, that his editor would never forgive me for resigning as a minister in Tony Blair's government and that she would pursue me for the rest of my political career until I was destroyed."

Monday, September 6, 2010

News: Metropolitan Police to Look at new Evidence in News of the World Phone Tapping Case

From BBC News: The London Metropolitan Police have confirmed that they will look at new evidence which has come to light recently in relation to the News of the World phone hacking case in which stories were obtained by hacking the phones of the Royal Family, celebrities and politicians.

This announcement follows claims in the New York Times at the weekend that the practice of phone hacking at the newspaper was far more widespread than so far recognised. Furthermore the detail that the then editor Andy Coulson apparantly knew about, condoned and even requested phone hacking is likely to continue to be a focal point to the story due to his current role as a close advisor to David Cameron and Director of Communications - the News of the World continue to maintain that only one employee is ever known to have been hacking people's phones and that he did so without the knowledge of his employers. The NYT story presents a very different picture:

But interviews with more than a dozen former reporters and editors at News of the World present a different picture of the newsroom. They described a frantic, sometimes degrading atmosphere in which some reporters openly pursued hacking or other improper tactics to satisfy demanding editors. Andy Coulson, the top editor at the time, had imposed a hypercompetitive ethos, even by tabloid standards. One former reporter called it a “do whatever it takes” mentality. The reporter was one of two people who said Coulson was present during discussions about phone hacking. Coulson ultimately resigned but denied any knowledge of hacking.


News of the World was hardly alone in accessing messages to obtain salacious gossip. “It was an industrywide thing,” said Sharon Marshall, who witnessed hacking while working at News of the World and other tabloids. “Talk to any tabloid journalist in the United Kingdom, and they can tell you each phone company’s four-digit codes. Every hack on every newspaper knew this was done.”

Tuesday, June 29, 2010

News: Germany Expresses Concern over Apple's iPhone users Database

From Privacy Digest: The German minister of justice, Sabine Leutheusser-Schnarrenberger, has spoken out over Apple's compilation of data on iPhone users, requesting the company to provide state data protection officials with details of what information on German iPhone users was being gathered, how long it was being stored, and for what purpose.

The case is being cited as further proof of Germany's tough line on privacy after previous tensions with Google Street View this year. However, a speedy resolution seems likely:

Stefan Köpsell, an instructor in data protection at the Technical University in Dresden, said that Apple could probably settle the controversy surrounding the iPhone 4 by having German users give their consent prior to the data being forwarded.

“I think there is probably a fundamental conflict between some Internet business models and German privacy law,” Mr. Köpsell said. “But in general, evidence shows that most Germans are willing to participate if there’s a benefit.” For example, 60 percent of households in Germany use a retail bonus card called Payback, owned by Loyalty Partner of Munich, which gives them points that can be used toward future purchases. By participating, consumers have given the company the right to collect and market data on their purchasing habits, as well as target them with advertising. “I would think the same would be possible for Apple,” Mr. Köpsell said.

Wednesday, May 19, 2010

News: More European Anger at Google Invasions of Privacy

From Privacy Digest: Google have admitted gathering private data on internet use in the course of the taking photographs for the Google Street View programme.

Google acknowledged on Friday that it had collected snippets of private data around the world. In a blog post on its Web site, the company said information had been recorded as it was sent over unencrypted residential wireless networks as Google’s Street View cars with mounted recording equipment passed by.

The data collection, which Google said was inadvertent and the result of a programming error, took place in all the countries where Street View has been catalogued, including the United States and parts of Europe. Google apologized and said it had not used the information, which it plans to delete in conjunction with regulators.

The Register reports that both Germany prosecutors and the Czech Republic data protection agency have launched investigations:

In effect, Mountain View may have hoovered up emails and other private information if the Google cars travelled over Wi-Fi networks while one of its vehicles was in range. The firm had previously claimed that no payload data was ever intercepted.

Hamburg prosecutors said they had received a complaint against unnamed Google workers over the “unauthorised interception of data”, and confirmed that an investigation - that could take about a fortnight to determine if the allegations warrant a full-blown probe - was underway.

News: Internet Browsers' Record of Your Web Habits Available to Other Websites

From the Sydney Morning Herald: The Electronic Freedom Foundation have been researching how easy it is to access information about a user’s internet activity. Commonly it is thought that disabling ‘cookies’ is enough to prevent one’s web browser collecting information on what websites are being visited. The EFF’s research implies that even with this safeguard the browser leaves ‘a virtual fingerprint’ which nearly uniquely identifies the user and enables websites to access information on the users browsing habits:

To conduct the research, the website anonymously logged information that most websites would normally access when users visit, the EFF said.

After comparing a database collected from almost a million visitors, the EFF discovered that 84 per cent of the configuration combinations were unique and identifiable, and where browsers had Adobe Flash or Java plug-ins installed they were 94 per cent identifiable.

"Browser fingerprinting is a powerful technique, and fingerprints must be considered alongside cookies and IP addresses when we discuss web privacy and user trackability,"

Monday, April 19, 2010

Study: Privacy Not Dead to the Younger Generation

From Yahoo News: A new study coming out of Berkeley and the University of Pennsylvania suggests young people do not care significantly less about privacy than the older generation. Amongst the findings:

• Eighty-eight percent of people of all ages said they have refused to give out information to a business because they thought it was too personal or unnecessary. Among young adults, 82 percent have refused, compared with 85 percent of those over 65.

• Most people — 86 percent — believe that anyone who posts a photo or video of them on the Internet should get their permission first, even if that photo was taken in public. Among young adults 18 to 24, 84 percent agreed — not far from the 90 percent among those 45 to 54.

• Forty percent of adults ages 18 to 24 believe executives should face jail time if their company uses someone's personal information illegally — the same as the response among those 35 to 44 years old.

The sample is big: about 1,000 people, though smaller than the 27,000 the Eurobarometer surveys use (which also record some interesting results on attitudes to privacy). It's interesting to see empirical research on an issue people are all too often happy to accept quite crude generalisations as obvious truths.

I'd also be interested to see work on whether there has been a change in people's attitudes over the last 5-10 years. I have a hunch many young people who didn't care about privacy when they first started using the Internet and social networking sites have become far more conscious of privacy issues as they have become more prominent topics of controversy online and in the wider media.

Monday, February 1, 2010

News: 'Climate Change Emails a Foreign Intelligence Hack'

The lead story on the Independent today: Former chief scientific advisor to the Blair government David King says that the climate change emails leak bears all the hallmarks of a foreign intelligence agency operation:


Quite simply, it's the sophistication of the operation. I know there's a possibility that they had a very good hacker working for these people, but it was an extraordinarily sophisticated operation. There are several bodies of people who could do this sort of work. These are national intelligence agencies and it seems to me that it was the work of such a group of people," he said.

More than 1,000 emails, and some 2,000 documents, were stolen from a university back-up server where remote access is difficult. This represents a small fraction of the total number of emails for the period from 1996 to 2009, suggesting they had been selected for the most incriminating phrases relating to possible scientific misconduct and breaches of the Freedom of Information Act. The leak of the emails in the weeks running up to the climate change conference in Copenhagen appeared to be carefully timed to destabilise the meeting.



He does not draw concrete conclusions about who might be responsible, but responding to the fact that the emails appeared on a Russian company's server he speculates:


"If it was a job done on behalf of a government, then I suppose there is the possibility that it could be the Russian intelligence agency," he said.


"If it was a maverick group then I suppose it could be the Americans, but I am hazarding a guess as much as anyone else. The only thing is, I've worked within government and I've seen this in operation," Sir David added. "It was a sophisticated and expensive operation. In terms of the expense, there is the American lobby system which is a very likely source of finance. Right now, the American lobbyists are a very likely source of finance for this, so the finger must point to them," he said.

Monday, October 12, 2009

News: Targeted Billboard Ads Using DVLA Data

From Spyblog: The Mail reports that Castrol, the motor oil company, has been conducting an innovative advertising campaign - they were using giant billboards to display targeted messages directing a particular vehicle to use specified fuel. A typical message you can see in the article reads ' 1 DF L The right oil for your car is: Castrol Magnatec 5W-30 A1'.

The campaign was making novel use of Automatic Number Plate Recognition technology, but the big question is how Castrol has come by the data about the drivers held by Driver and Vehicle Licensing Agency. The DVLA sells the data it holds on 34,000,000 drivers to a number of organisations. The article reports that sources admit that in this case the data was passed on from one of these to a third-party contractor who then themselves sold it in contravention of the ban on using registration numbers for marketing purposes:

Liberal Democrat transport spokesman Norman Baker said: ‘This completely inappropriate and unacceptable behaviour by the DVLA shows how cavalier it is with motorists’ information.
‘They don’t even check what the end use is. It seems all you have to do is ask and the DVLA will give, no matter who you are and for what purpose. It’s outrageous this was allowed to happen.’
The row is a fresh embarrassment for the DVLA and raises new questions about how highly sensitive drivers’ information is handled by the agency.
The Mail on Sunday has previously revealed that the agency was selling motorists’ names and home addresses to convicted criminals. In the past five years the DVLA has earned £15million from selling the names and addresses of more than six million motorists.

Thursday, September 24, 2009

News: Insurers Offering Discounts to Put Cameras in Cars

From Slashdot: A car insurer is offering discounts to teen drivers who participate in the Teen Safe Driver scheme, whereby a camera is fixed under the rear view mirror. The recordings are sent to a third party analysis sender who then provide parents with footage and an assessment of the safety of the driving. Teen Safe maintain the footage would never be shared with insurers.

Tuesday, August 4, 2009

UAE Mobile Provider Installs Spyware on Customers' Blackberries

Wired and Silicon Valley have reported that a mobile telephony provider in the United Arab Emirates installed spyware on the Blackberries of subscribers to its services. Blackberry users were prompted to download a software update. Once the update was installed, however, users complained that their device’s performance was adversely impacted and that their batteries were quickly exhausted. As it turned out, the update had the device contact a certain server for registration. The high number of devices which attempted to connect to the server simultaneously caused the server to crash. As each Blackberry regularly tried to contact the server after the initial failure, this action quickly used up the device’s battery levels.

Code analysts reported that the update included code to permit surveillance of the Blackberry’s contents and communications, although this feature was deactivated upon initial download. The code was evidently written by US-based company SS8, which provides surveillance solutions to telecommunications providers as well as products for intelligence and law enforcement. As reported on Wired, analysis by the company Veracode suggested that the installation of the surveillance software on the user’s handheld device, as opposed to relying on surveillance at the server level, would prevent the use of messaging encryption from frustrating attempts to examine communications being sent from and received by the device. Rather than intercepting messages en transit over the server, the code would have the device deliver copies of the content stored there to a special server. These copies would be in unencrypted form since they would be either generated prior to the application of encryption in the case of sent messages, or have been decrypted by the user’s key in the case of received messages.

Tuesday, June 9, 2009

Saving Privacy

An interesting piece in today's Times by Nigel Shadbolt, who is a professor of AI at Southampton University. He argues that advances in technology are eroding privacy at an alarming rate. In response he proposes nine measures.
  1. The commissioning of a report on privacy similar to Baroness Warnock's on fertilisation and embryology.
  2. Oblige government and private companies to inform the public in the event of data breaches.
  3. All government departments controling large databases to appoint a 'privacy officer'.
  4. Written procedures to manage, monitor and report on the accuracy of the personal data held.
  5. Regular auditing of government departments to ensure compliance with the Data Protection Act, the results of which would be published.
  6. Routine open access to government data on schools, health, transport and commerce.
  7. All Freedom of Information Act requests and results to be made available in web accessible formats.
  8. Insist on proportionality in cases of surveillance.
  9. Rule employer use of social networking information as inappropriate.
Are some of these too elaborate to be practical? Or is it rather that surveillance done justly, or centralising information justly, requires much more effort than is being spent at the moment?

Thursday, May 28, 2009

Should Local Councils have Surveillance Powers?

I should now be able to return to regular posting (and get round to responding to the comments some of you have left). Today I have two stories involving Burnley Borough Council's use of Surveillance.

First a recent story from the Sunday Times. Apparently they mounted a "direct surveillance operation" against an employee they suspected of using the shower while clocked in.

There have been loads of stories like this over the last few years, and I can't find anybody who defends surveillance for uses like these - reading the newspapers you might get the impression that there's widespread consensus that local councils should not be engaged in surveillance at all.

But the stories keep coming. Presumably the councils doing this think they are doing the right thing, and that they are acting in a proportionate manner - how can there be such a big gap between their view and the widespread public condemnation?

The second story concerns a case which would be easier to defend but I'd be fascinated to hear some responses to the case: a few years back they caught someone flytipping through use of covert CCTV. The cameras covered public space, and surely nobody would object if the dumper had been caught as the result of, say, a chance eyewitness.

So is this a form of surveillance councils should be engaged in? Or is this still inappropriate and disproportionate?

Wednesday, April 29, 2009

Facebook: Private?

From Slashdot: Following on from the reports of people possibly having their social networking activities monitored by their work, it seems that at least one company has taken the step of prohibiting using social networking sites as part of the recruitment and hiring process.

Monday, April 27, 2009

Facebook: Public Space or Private Space?

A woman has been fired for using facebook while taking the day off work. The intriguing bit is that she claims her employers created a false profile to 'friend' her and spy on her. Whether or not that is actually what happened (the company deny that it is), I wouldn't be surprised if it were common - many employers will just find it irresistable to keep tabs on their employees.

I'm mainly interested in how this compares to real world interactions of a similar kind. If she had taken the day off work and was spotted talking to a friend in a cafe, presumably this would not count as an invasion of privacy, whereas if someone from work had spied on her through her bedroom window this would be completely unacceptable. So where does facebook fit in here? Is facebook interaction public or private?

Wednesday, April 22, 2009

Can Whistleblowing Survive?

An interesting piece from last weeks Guardian media supplement. New detection technologies will make it increasingly difficult for investigative journalists to make use of whistleblowers without the employers knowing.

Is this just a price which comes with the new technological innovations, or are there any viable solutions, whether legal or technological?

Monday, April 20, 2009

The Responsibility to Provide?

The Guardian reports that secret police intelligence on the movements and meetings of climate change protesters was passed on to energy firm E.ON, presumably gathered by surveillance which E.ON would not have been permitted to carry out itself.

I blogged previously about Omand's IPPR paper on the future of intelligence gathering. The phrase that jumped out at me in that paper was 'The Responsibility to Provide'. As I understood it, Omand's recommendation was that, rather than access to intelligence being restricted on a 'need to know' basis, instead intelligence ought to be readily provided to the various different levels of the policing and security services to which such intelligence might be pertinent - letting the local police know, for example, that they should keep an eye on a particular suspect. These reports seem to imply that this 'responsibility to provide' extends not only to the police but also private companies. I want to know who else is entitled to this sort of access to intelligence? What is the criteria? And also, as I said in my post on the Omand paper, can this access be reconciled with Omand's 6 conditions for oversight?

Thursday, April 2, 2009

More Corporate Spying

Another company has been caught spying on its employees. This time its airbus, who were monitoring staff bank accounts.

Just how common is this behaviour? Can we rely on our media to inform us? In this case the revelations emerged as a result of new management coming in and auditing the company. The former journalist David Simon who had such success writing about corruption in the modern American city in The Wire has warned that the slow death of newspapers spells great opportunities for corrupt public officials in the next 10-15 years. Could it also be a golden era for corporate spying?