Showing posts with label databases. Show all posts
Showing posts with label databases. Show all posts

Friday, July 16, 2010

Swiss Intelligence Oversight Body Cites Problems with Database

Earlier this month, Swiss media announced that the oversight body for Swiss intelligence and national security activities, the “Geschäftsprüfungsdelegation” (GPDel), had produced a negative report on the state of the Federal Intelligence Service’s information system, the ISIS-NT. According to the report, the database held entries on 50,000 people in 2001 and grew to 60,000 entries in 2004 (p. 6). Since that time, however, the database has grown to contain primary entries on 120,000 individuals plus an additional 80,000 or so “third persons”. These third persons represent individuals who have some tie to the 120,000 individuals of primary concern or to some event recorded in the database.

The GPDel expressed concern about the overall quality of the data held in the database. Based on its inspection of various sample entries, the GPDel found instances where the individuals or incidents entered into the database were not serious enough to warrant inclusion as well as instances where data had expired but had not been deleted. The GPDel also opined that the database suffered from the systematic entry of incorrect data due to a flaw in internal entry guidelines. Additionally, it suspected that many of the 80,000 third person entries did not meet the legal requirements that warranted entry in the database.

According to an article in the Neue Zürcher Zeitung, only about 5% of the entries concern Swiss citizens and only 12.2% are Swiss residents. These facts have perhaps prompted the Federal Commission for Migration Issues to inquire whether the database has had any bearing on the issuance of resident permits, as reported by the NZZ (citing an interview on Swiss Radio DRS).

The report is available in French here and in German here.

Wednesday, June 30, 2010

Comment: EDRI on the New SWIFT Deal

European Digital Rights has a comment on the new SWIFT access deal signed earlier this week. It maintains that this deal has "no significant improvements from the Agreement rejected by the European Parliament in February 2010":

Unfortunately, the new adopted text still allows for bulk data transfers. The Parliament would have liked to replace bulk data with targeted searches carried out by an EU-based authority but according to MEP Birgit Sippel, "We cannot reduce the problem of bulk data for the moment as we do not have the technical
capability."


The retention period is still 5 years and there is no real system in place from the US on a binding legal redress. The US Privacy Act court clauses only apply to US citizens and legal residents. Therefore there is currently no right of judicial review for foreign citizens and residents (including EU) under the US law.


Another key critique to the current text is the role of Europol that should authorize the data transfer requests from the US. Besides the fact that Europol is not a judicial authority, as requested by the European Parliament in May 2010 Resolution, the incentive from this agency to limit the amount of data being transferred is extremely reduced due to the fact that they can actually request data searches from the US.

Tuesday, June 29, 2010

News: New US/EU Agreement on Transfer of SWIFT Banking Data

From European Voice: A new agreement to grant US Counter-Terrorism authorities access to European banking transaction data held in the SWIFT database:

Final agreement on the new wording was reached on Friday (25 January). After the draft agreement had been initialled by Malmström on 10 June, MEPs had demanded
changes to the text concerning the bulk transfer of data, the creation of an EU counterpart to the US Terrorist Finance Tracking Programme (TFTP), and EU oversight of TFTP data-processing on US soil.
The three largest political groups in the Parliament – the centre-right EPP, centre-left PES and liberal ALDE – are now in favour of the agreement. In February, the Parliament, using new powers under the EU's Treaty of Lisbon, had rejected an interim agreement on SWIFT transfers.

Over at the Legalift Mathias Vermeulen has a discussion of some of the new restrictions build in to the new agreement, such as a ban on the use of this information for data mining, the possibility of administrative redress for EU citizens and the involvement of Europol in verifying and approving US requests for data.

In its coverage the Register points out that the European Data Protection Supervisor continues to question the need for mass transaction and long term storage of this data, and has additionally called for more oversight.

Thursday, May 27, 2010

DETECTER: Survey of Counter-Terrorism Datamining and Related Programmes

D08.1 was written by Daniel Moeckli and James Thurman as part of Work Package 6. You can read the whole thing here.



Executive Summary




  1. The survey reflects a broad definition of data mining and also includes coverage of related programmes relating to data collection and database construction.
  2. In the West, collection activities have increased dramatically in the name of countering terrorism. In addition to data collection involving air passengers, this survey also describes general law enforcement collection activities as well as those specifically targeting terrorist activity.
  3. Air passenger information: in the United States, data mining in this area was proposed in order to identify terrorist suspects who might not otherwise raise suspicions. In the European Union, too, there seems to be interest in analyzing a passenger’s travel activities in order to identify suspicious patterns which might indicate criminal activity.
  4. Private companies and non-law enforcement databases: in the US there has been concern about the incorporation of data from these sources into general law enforcement data bases.
  5. Data analysis programmes that have been proposed and in some cases implemented for counter-terrorism purposes are also considered. These include not only data mining programmes but also a discernable trend of providing tools which guide users in their analysis and decision-making.

Thursday, May 20, 2010

News: Negotiations Reopen on US Access to SWIFT Bank Data

From the Lift: The EU and US have begun talks on a new agreement to enable transfers of European bank transfer information held on the SWIFT database to US authorities. Talks are taking place between the European Commission and United States Treasury and it is hoped an agreement can be reached by the end of June:

A Commission source told Euractiv.Com that “in the coming months little will be known about the substance of the actual negotiations”

The agreement will be concluded only after the adoption by the member states of the EU at qualified majority voting and the approval of the European Parliament. The Parliament introduced two weeks ago theconditions on the content of a future agreement, including for bulk transfers of personal data to the USA to be avoided, if necessary by processing them within the EU, and for Europe’s citizens to be guaranteed the right of appeal to the US authorities.

Tuesday, March 16, 2010

News: More Details on ID Card Databases - Ministers Seeking Advice from Industry on Security

The Register is reporting this morning that the Identity minister has announced that UK ID Card scheme is to have 3 different databases: "There is the one that holds the fingerprints and facial image, the biometric data, and then the other information which is broadly what is on your passport already and the third bit is the one that links the two,"

The announcement was made at a meeting organised by the Social Market Foundation. Meg Hillier, the minister, also revealed that her department is still researching how best to to make remote use of ID Cards work.

An example of an ID card reader, visually like a larger version of a card reader used by retailers, was available at the conference. Hillier said that the government "needed to do more work on this" and was keen to hear the views of industry about how this will work, particularly about security.

Monday, March 15, 2010

Comment: The Case for a Universal, DNA Database

There's an interesting Op-Ed piece on the NYTimes.com site today responding to Obama's apparent endorsement of a national DNA database to include profiles of everyone arrested, whether found guilty or not. The author, Michael Seringhaus, make the case for that the national DNA database ought to hold profiles on everybody not just those who are arrested.

He argues that at present, DNA databases are 'fraught' with problems of discrimination, the disproportionate bias towards racial minorities already having prompted one commentator to dub it 'Jim Crow's database'. This is exacerbated by the use of profiling methods and 'familial DNA search' - searching among the relatives of partial DNA matches as potential suspects when full matches cannot be found.

Instead, he recommends the far more just solution of placing everybody's DNA profile on the database:

Your sensitive genetic information would be safe. A DNA profile distills a person’s complex genomic information down to a set of 26 numerical values, each characterizing the length of a certain repeated sequence of “junk” DNA that differs from person to person. Although these genetic differences are biologically meaningless — they don’t correlate with any observable characteristics — tabulating the number of repeats creates a unique identifier, a DNA “fingerprint.”


The genetic privacy risk from such profiling is virtually nil, because these records include none of the health and biological data present in one’s genome as a whole. Aside from the ability in some cases to determine whether two individuals are closely related, DNA profiles have nothing sensitive to disclose.



He thinks this would be relatively easy to administer, requiring only the introduction of a mandatory sample taking either at birth, or as prerequisites to a drivers licence or social security card. Samples taken at this point would be used only to produce one of these 26 numbered profiles, after which they would be destroyed. I think there may still be objections to make here, however, that derive simply from the administrative scale of the proposal. It seems plausible to me to worry about DNA samples being taken for the purposes of creating a profile being destroyed in a timely fashion and being kept securely in the interim. I can well believe that the process would be secure and efficient much of the time, for much of the country, but if the proposal is to take samples from every single citizen I suspect its inevitable that there will be some malfunction of the sort that has become all too familiar - the information is placed on a CD or laptop that is left on a train, or some disgruntled employee decides to start selling the information on.

One part of his argument I find even more interesting is what he has to say about how this would change people's attitudes to the security and integrity of such a database:

Since every American would have a stake in keeping the data private and ensuring that only the limited content vital to law enforcement was recorded, there would be far less likelihood of government misuse than in the case of a more selective database.

I'm sympathetic to this line of thought, but I'm not wholly convinced that it would change people's priorities as much as Seringhaus thinks: 'everybody' has been quite vulnerable to clumsy losing of private government held data on previous occasions without it turning into an enormous issue. Furthermore, malfunctions in the security of such a system might easily be localised to particular areas or sectors of the community. For example, suppose that the function of generating profiles becomes the responsibility of those issuing driving licenses or birth certificates and that these are matters for local authorities. Some will fulfil this function much better than others and thus, the security of the DNA may be much lower in areas where these local authorities perform poorly. In such a case a majority could remain unconcerned about the risk the policy poses to a minority.

Thursday, February 11, 2010

News: European Parliament Says No to US Bank Access

From BBC News: By 378-196 with 31 abstentions, the European Parliament has voted down the agreement to continue allowing the United States' counter-terrorism authorities access to the SWIFT database of European banking transactions, citing concerns at the 'inadequate privacy safeguards'. The deal, agreed by EU governments, would have granted US access for another nine months and follows intensive lobbying on the part of the American government:

Last week the Greens' home affairs expert, Jan Philipp Albrecht MEP, said that in backing the new deal the European Commission and EU governments had "not respected the fundamental criticism about the lack of sufficient protections with regard to privacy and the rule of law".

The leader of the Socialist group, Martin Schulz MEP, said: "We want a new and better deal with proper safeguards for people's privacy."

Wednesday, February 3, 2010

News: European Parliament due to Decide on SWIFT Soon

From the Financial Times: We have reported on the issue of US access to the SWIFT banking transactions database before. The agreement provisionally came into force on February the 1st, but is subject to confirmation by a European Parliament vote in the plenary session of 8th-11th of February next week. The FT reports that the Parliament, long concerned at the privacy implications of US access, is likely to vote down the agreement in the face of strong objections from the US:


Adam Szubin, director of the Office of Foreign Assets control at the Treasury, said the intelligence programme processing the Swift data "provides perhaps the most important source on terrorism financing".


The European parliament looks set to block an interim agreement negotiated by the European Commission and representatives of the member states. "It's very unlikely to go in favour of the Swift agreement," one diplomat said.


Wednesday, January 20, 2010

News: New Security Measures for UK Airports

From the BBC: In a statement to the House of Commons earlier today, Prime Minister Gordon Brown announced the recommendations arising from a review of airport security and further intelligence briefings. The main measures include:
  • Direct Flights from Yemen to the UK are suspended until security concerns are addressed.
  • A "no fly" list is to be established to prevent suspected terrorists from travelling to the UK.
  • A second list of lower risk suspects will be established entailing 'special measures' for those attempting to fly to the UK, such as more stringent screening (officials are not currently specifying anything further).
  • All UK airports and ports to follow the 'e-borders' scheme, designed to collect personal data on all passengers entering or exiting the country, by the end of the year.
  • Enhanced global cooperation to enable suspect individuals to be checked against watchlists 24 hours before flying to or via the UK.
  • Full Body Scanners at British airports next week.
  • New Intelligence teams to identify threats to British security abroad.

Thursday, January 7, 2010

Comment: Christmas Day Plot, Part I (Update)

The Telegraph has published a story today claiming that US Customs and Border Protection had singled out Umar Farouk Abdulmutallab based on the human intelligence submitted by the State Department and were waiting to bring him in for interrogation in Detroit. This claim seems to take some steam out of the argument that US intelligence failed to “connect the dots.” This raises the question whether, under the circumstances, some other operative action should have been taken while the flight was in the air. Given what was known, would it have been appropriate to order the flight to turn back around to Amsterdam? Suppose Abdulmutallab caught on to what was happening and decided to detonate over Amsterdam upon the return. Would it have been appropriate to order the flight crew to restrain him? Think of the standards that would apply if the “suspect” were simply someone standing on a public street. Should different standards apply on airplanes?

The article also features an interesting quote from a “senior Homeland Security official” who indicated that “in-depth vetting only begins once the flight manifest has been generated, a few hours before takeoff.” This statement suggests that passenger name records are not submitted on a rolling basis as reservations are made but only once the list of passengers on any one flight has been relatively solidified.

Wednesday, January 6, 2010

Comment: Christmas Day Plot, Part I

“Failure to connect the dots” became a catch-phrase paraphrasing the mistakes within the intelligence community that permitted the 9/11 attacks despite the presence of intelligence within the possession of various US agencies that pointed toward the development of the underlying plot. This phrase has cropped up again in connection with the Christmas Day plot involving Northwestern Flight 253, leading to the question as to whether the lessons learned from the 9/11 review have been implemented.

As news of the attempted attack began to unfold, reports began to roll in that the individual behind the attempt, Umar Farouk Abdulmutallab, had raised a number of red flags which should have resulted in enhanced screening, potentially his detention for further investigation, or--as some have suggested--the denial of an entry visa for the US. First it was revealed that Abdulmutallab had been included in the National Counterterrorism Center’s TIDE (Terrorist Identitites Datamart Environment) database (more on TIDE in Part II) (See this story from CBS). Then, it came to light that Abdulmutallab’s father had approached US State Department officials in Nigeria with concerns that his son had “fallen under the influence of ‘religious extremists’ in Yemen” (See this story from CBS). According to a report from CBS News, this information was forwarded to officials in Washington (In fact, it may have been the basis for Abdulmutallab being entered in TIDE). Apparently, however, no flags were attached to Abdulmutallab’s US visa, and the CBS report suggests that US officials who had received information relating the father’s concerns did not realize that the individual in question had been issued a multiple-entry visa by the US Embassy in London that was valid from June 16, 2008 to June 12, 2010. Lastly, it has been reported that the NSA had identified communications among Al Qaeda members in Yemen concerning a plot involving a Nigerian (See articles here and here).

The Obama administration called for two reviews: one quick review of flight screening procedures and technologies, the other a more in-depth review of the terrorist watch list system in use in the US. President Obama has promised that the results of the reviews will be revealed in public reports in the near future. It will be interesting to see to what extent the details of what happened at each stage of Abdulmutallab’s journey will be released. For me, the following questions come up: 1) Were any personal data pertaining to Abdulmutallab submitted to the TSA before he boarded the flight from Nigeria? 2) What security procedures did Abdulmutallab undergo in Lagos (or Ghana)? 3) Was Abdulmutallab subjected to security procedures at Schiphol? It would be particularly interesting to know whether he underwent a full-body scan (such scanners are evidently in common use at Schiphol) (more on full-body scanning below)?

In this case, it isn’t clear to what extent fault can be found with US authorities. Clearly mistakes were made, but even if all the information on Abdulmutallab had come together and resulted in an operational decision, measures stemming from that decision would have to have been taken in Nigeria or the Netherlands in order to have been effective. The incident may primarily reflect the lack of uniform and coordinated procedures at the international level. The US has expressed the desire to receive passenger name records for all passengers who have booked flights to the US. Yet, the question arises as to how many airlines indulge that desire and with what level of accuracy. This requirement has been particularly contentious within the EU. However, given the fact that Abdulmutallab had booked passage with a US-based air carrier for the final leg of his journey, it seems likely that the US carrier submitted passenger record data on Abdulmutallab to the TSA. But again, even if the TSA had singled out Abdulmutallab for enhanced screening or identified him as being on the no-fly list, how does it ensure that Dutch or Nigerian airport security take appropriate action? If a Dutch or Nigerian equivalent of the TSA have special requests with respect to a particular passenger departing from the US en route to the Netherlands or Nigeria, would the TSA automatically comply in reciprocal fashion? Note that according to an editorial in the New York Times, the TSA can still request a US-bound flight to return to its point of departure if there is a suspicious passenger on board, but for long distance flights, this option may become unfeasible if the request is not received until later stages of the flight.

Suggestions for changes already began to be voiced soon after the incident. Among the calls for improvements to security that have emerged in public discourse, the notion of making more use of body scanners, such as millimeter wave scanners, has been particularly prominent--notably former US Department of Homeland Security Secretary, Michael Chertoff, has been among those advocating this move (see here) (although it later came to light that Chertoff’s company, the Chertoff Group, has a manufacturer of such machines as a client). Some commentators, however, have argued that such full-body scanners would have failed to detect the explosive device in this case. The Telegraph has cited two former US officials from counter-terrorism agencies for having long argued that swabbing for explosive substances and other chemicals is “cheaper, easier and more effective” than full-body scanners. In that article, Larry Johnson, former deputy director of Counter Terrorism at the US State Department was quoted as saying “[s]wabbing everyone is not hard and it’s just about the only way, short of making passengers fly naked and without luggage, of being reasonably sure they aren’t carrying a bomb.” Although swabbing would entail making bodily contact with the swabs, for some--if not most--it may raise fewer privacy concerns than the full-body scanners. The Telegraph article suggests that the swab tests would not need to be taken from the same part of the body or baggage where explosives were located. That means that contact with sensitive areas of the body could be avoided.

In Part II, I’ll discuss databases and watch lists.

Tuesday, December 1, 2009

News: US SWIFT Access Granted

From the Lift: The EU has agreed a nine month interim deal to allow the US non reciprocal access to SWIFT banking data. Germany and Austria, reported as threatening a veto over the privacy implications of such a deal, abstained. A unanimous vote was required, not counting abstentions as votes against. The agreement can be annulled in the Spring, when the European Parliament will have to give their assent to the plan.

The Register quotes an EU official as saying that "The truth is that we in Europe don’t have the technical ability to interpret this stuff," and that this is the reason why "We rely on the Americans to process it and pass it on as intelligence." Many European intelligence agencies end up as beneficiaries in the arrangement as they are not permitted by their home countries to gather such information themselves. In the event, delegates were apparantly put under huge pressure from US representatives to pass the deal:

The pressure from the Americans was "massive," say diplomats in Brussels. U.S. Secretary of State Hillary Clinton apparently told her European counterparts that the fate of the West hung in the balance. And in the capital cities of Europe, American ambassadors stormed governments like door-to-door salespeople. As one EU foreign minister put it, "they pulled out all the moral and political stops."

Thursday, November 26, 2009

News: SWIFT Update

The Legalift reported last week that 4 Countries remain opposed to the draft agreement granting US access to SWIFT banking transfers records. Germany's justice minister says that Berlin is uncomfortable with the plan and France, Austria and Finland have also signalled discontent with the scheme.

The draft plan is significantly different from the resolution issued by the European Parliament on the issue. 'Terrorism' is left undefined, requirements for judicial oversight are nowhere to be seen and the restriction of access to the specific issue of 'terrorism financing' is loosened to "prevention, investigation, detection, or prosecution of terrorism or terrorist financing". Ralf Bendrath has a round up of all these issues and many more.

If a decision is not reached by November 30th, then, as the Lisbon Treaty kicks in on December the 1st, the European Parliament may have much more say in the process (and it is likely to take another 6 months). Germany and Austria are reported to be under pressure to drop their opposition.

Wednesday, November 18, 2009

News: UK T-Mobile Staff Sold Private Data

From BBC News: T-Mobile staff sold customer data on to other mobile phone companies to target people coming to the end of their contract for coldcalls. Thousands of customers and millions of records were involved. The Information Commissioner has said he is preparing a prosecution.

News: New Policy on UK DNA Retention

From the Guardian: Police have announced that they are to retain the DNA of those released without charge. Home Office Ministers say they want a 6 year limit (having previously sought a 12 year limit) for retaining profiles. Ministers are also advocating indefinite retention of those arrested on suspicion of terrorism or other national security provisions. Those convicted of any offence remain on the database for life. The Tories say they would implement the Scottish system whereby the profile of those unconvicted of any offence is destroyed on release from prison:

The national DNA database is already the largest in the world, with the profiles of 4.5 million people already recorded. They include 850,000 DNA profiles of people who have never been charged with or convicted of a crime. The need to find a new regime follows a landmark ruling in the S and Marper case by the European court of human rights, which ruled that the Home Office's current regime of "blanket and indefinite" retention of innocent people's DNA was illegal.

News: ICO to Fine Companies £500,000 For Serious Data Breaches

From Panopticon Blog: The Information Commissioner is to get powers to deliver civil penalty notices on a data controller for a serious contravention of the data protection principles if the contravention is:

1) Deliberate or reckless
2) Of a sort that is likely to cause substantial damage or distress

The post makes two criticisms: first, the proposed cap of £500,000, as large as it might seem, compares less favourably with other regulator's powers to fine up to 10% of an organisations turnover. Second, as the government ultimately pays for many of the organisations in question, imposing large fines may have 'a slightly unreal quality to it'.

Comment: What's Worse?

The discussion of the UK plans for the 'Big Brother Database' has me wondering: What's worse, centralised storage of this communications data, or forcing ISPs and Mobile Phone companies to hold on the data for long periods of time?

Clearly this data is incredibly sensitive, and there are good reasons to want to restrict anyone's access to it. But, were such information to be stored, what would be worse? The idea of a centrally held database tends to make for bigger headlines, calling to mind, as it does, the vision of faceless government bureaucrats poring over our intimate secrets.

And the risk of government officials abusing such private information is indeed one of the reasons one would want to restrict access. But it's only one of the reasons. Surely another is the risk of any sort of public disclosure of this information. It is intrusive for anybody I haven't chosen to do so to view information about who I telephone or what websites I visit. But this information tends to be of much more interest to our neighbours, friends and work colleagues and of virtually zero interest to government. In deciding which is worse, one of the matters I think we should consider is which arrangement makes it less likely for some data breach to result in unauthorised access to my data.

Some will point to the many cases where various levels of government have proven hopelessly careless with our information (to the point of accidentally releasing vetting records with details of debt, extra marital affairs, drug use and use of prostitutes). But I don't think we can simplify this to a case of 'private sector good, public sector bad': some of the most notorious cases of releasing private information have been the fault of businesses - just think of the AOL scandal when records of people's searches were released, to remain posted in the internet to this very day. Private companies have a commercial interest in avoiding such scandals, to be sure, but is that any safer than trusting it to government?

Comment: UK Gov Plans Shelved

The shelving of plans for the Interception Modernisation Programme (IMP) has been reported in a number of different ways. According to the Independent this was effectively 'a cancellation of the Big Brother database' while the BBC reported that the UK surveillance plan was 'to go ahead'. In this confusion Slashdot resorted to the headline 'In the UK, Big Brother Recedes and Advances'.

I think the Register has this one right. The post makes three points:

1) Next years general election (probably to take place in May) makes this a bad time to bring forward legislation that might provoke negative headlines. (Henry Porter has a nice point about the timing as well: with all the recent column inches covering the 20th anniversary of the Berlin Wall coming down, proposing big increases in surveillance invites comparisons with the Stasi all too easily).

2) Internet Service Providers, whose cooperation is needed for the scheme, are currently resistent. Before proceeding, government has to convince them of its merits and feasibility.

3) The players who want this (GCHQ, SOCA, ACPO, the Security Service, the Child Exploitation and Online Protection Agency and the Met) are not going away anytime soon:

Note that GCHQ and friends will still be around after the next election, as will their demands for IMP.

Ever the political pragmatists, the Tories know this well, and the section of shadow justice minister Dominic Grieve's recent speech on reversing the rise of the surveillance state was notably soft on IMP.

He said a Conservative government would submit the proposals to the Information Commissioner's Office to assess their impact on privacy. The ICO has already said it believes the case for mass surveillance of the internet has not been made.

News: UK Gov Plans to Snoop on Internet and Mobile Use Shelved

From the Guardian: a previously mooted £2bn surveillance project for keeping tabs of all British citizens' email, internet use, mobile calls and texts, is to be left out of the upcoming Queens Speech, laying out the legislative plans for the coming year:

The Home Office ditched plans earlier this year for a central database tracking all phone, text, email and internet use. Instead ministers want internet service providers and phone companies to store this data for access by police and security services. The data includes who contacts whom, when, where and how – but not the content of what was said or written.

The Home Office summary of the responses to its consultation published shows that the internet and phone industry want assurances that they will be compensated for the costs involved and also fear technical problems.