Wednesday, February 2, 2011
Petition for Rehearing of Maynard GPS Case Denied
It was a close decision with 4 of the 9 judges dissenting. Two dissenting opinions were issued. The first, drafted by Chief Judge Sentelle and also signed by Judges Henderson, Brown, and Kavanaugh, argued that Maynard was not distinguishable from the Knotts case, and therefore there was no reason to have decided Maynard differently than Knotts. The opinion also took issue with the theory that aggregation of information could amount to violation of the Fourth Amendment, which the original decision appeared to promote. It expressed concern that this line of reasoning would mean that other forms of surveillance—including personally conducted visual surveillance—could be held to violate the Fourth Amendment when done on a prolonged basis. Citing an opinion from the Seventh Circuit, it also suggested that GPS tracking should perhaps not even be considered a search within the meaning of the Fourth Amendment.
The second dissenting opinion, drafted by Judge Kavanaugh, pointed out that the appellant had also asserted a Fourth Amendment violation on the basis of the interference with personal property through the installation of the GPS tracking device on the appellant’s automobile. Thus, Judge Kavanaugh opined that a rehearing was additionally warranted in order to adjudicate this question.
The order, a concurring opinion, and the two dissenting opinions are available here thanks to courtlistener.com.
Wednesday, September 15, 2010
News of the World Phone Hacking Update
The claim that MPs have so far refrained from coming down on press intrusion with too much vigour for fear of becoming victims themselves is replicated elsewhere, for example in a Guardian article reporting the claim of former Plaid Cymru MP Adam Price:
Price told Channel 4 News last night that four members of the committee had considered asking the serjeant at arms to issue a warrant forcing Brooks to attend. He said: "We could have used the nuclear option. We decided not to, I think to some extent because of what I was told at the time by a senior Conservative member of the committee, who I know was in direct contact with executives at News International, that if we went for her, called her back, subpoenaed her, they would go for us. [This] meant effectively that they would delve into our personal lives in order to punish them and I think that's part of the reason we didn't do it." Watson told Channel 4 News that News International had further interfered by asking Downing Street to persuade him to tone down his questioning. "A [former Labour] cabinet minister has confirmed to me this week that News International talked to my former colleagues in No 10 Downing Street to ask them whether I would withdraw my aggressive line of questioning … I felt very frightened and intimidated." Watson added that he was told that Brooks vowed to destroy him after he led the Labour coup that persuaded Tony Blair to resign. "A very senior News International journalist told me at the Labour party conference in 2006, in the early hours of the morning, that his editor would never forgive me for resigning as a minister in Tony Blair's government and that she would pursue me for the rest of my political career until I was destroyed."
Monday, September 6, 2010
News: Metropolitan Police to Look at new Evidence in News of the World Phone Tapping Case
This announcement follows claims in the New York Times at the weekend that the practice of phone hacking at the newspaper was far more widespread than so far recognised. Furthermore the detail that the then editor Andy Coulson apparantly knew about, condoned and even requested phone hacking is likely to continue to be a focal point to the story due to his current role as a close advisor to David Cameron and Director of Communications - the News of the World continue to maintain that only one employee is ever known to have been hacking people's phones and that he did so without the knowledge of his employers. The NYT story presents a very different picture:
But interviews with more than a dozen former reporters and editors at News of the World present a different picture of the newsroom. They described a frantic, sometimes degrading atmosphere in which some reporters openly pursued hacking or other improper tactics to satisfy demanding editors. Andy Coulson, the top editor at the time, had imposed a hypercompetitive ethos, even by tabloid standards. One former reporter called it a “do whatever it takes” mentality. The reporter was one of two people who said Coulson was present during discussions about phone hacking. Coulson ultimately resigned but denied any knowledge of hacking.
News of the World was hardly alone in accessing messages to obtain salacious gossip. “It was an industrywide thing,” said Sharon Marshall, who witnessed hacking while working at News of the World and other tabloids. “Talk to any tabloid journalist in the United Kingdom, and they can tell you each phone company’s four-digit codes. Every hack on every newspaper knew this was done.”
Monday, August 16, 2010
DC Circuit Rules on Fourth Amendment and GPS
Maynard involved the use of a GPS device to monitor the movements of a suspect’s vehicle over the course of 28 days. Inevitably, as in Weaver, much of the discussion in Maynard centers around the Knotts case (460 U.S. 276 (1983)). Knotts was the Supreme Court case involving the “beeper” homing device and the drum of chloroform (See my earlier post for more details). In Maynard, however, the court seized upon specific language indicating a limitation on the scope of the Knotts holding. In this way, the DC court argued that the Knotts court had drawn a distinction between the limited type of surveillance at issue in that case versus “more comprehensive or sustained” surveillance as was at issue in the Maynard case (“Most important for the present case, the Court specifically reserved the question whether a warrant would be required in a case involving ‘twenty-four hour surveillance,’….” (p. 17)).
Thus, for the Maynard court, the issue in question in the case was whether prolonged GPS-tracking of a vehicle without a warrant violated the Fourth Amendment protection against unreasonable searches. As in Weaver, the DC court was particularly impressed by the amount of information that could be extracted from having the complete record of an individual’s movements over an extended period of time.
Since the case concerned the Fourth Amendment, the Court had to apply the so-called Katz test (after Katz v. United States, 389 U. S. 347 (1967)) to determine whether there was a violation. That involves application of the famous (or infamous) “reasonable expectation of privacy” standard. Under that standard, US Supreme Court jurisprudence has established that one cannot reasonably expect that aspects of life that are exposed to the public remain in or belong to the private sphere. Thus, the reasoning in Knotts was that the use of the homing device did not implicate the Fourth Amendment since “[a] person traveling in an automobile on public thoroughfares has no reasonable expectation of privacy in his movements from one place to another” (Knotts, at 281). Interestingly, the DC court held that the prolonged surveillance of a suspect’s vehicle with GPS does not concern movements that are “exposed to the public” in the same way as the journey of the drum of chloroform from its place of purchase to Knotts’ cabin. Here, the extent of information gathered was the distinguishing factor. Although each of the vehicle’s movements on public roads was undoubtedly in public view, the DC court maintained that the likelihood that anyone would track each of those movements week after week was “essentially nil” (p. 26). Thus, in essence, it may be unreasonable to expect that no one will observe the totality of a single trip made with one’s automobile on public roads, but it is not unreasonable to expect that no one person will observe the totality of every trip made with that automobile over the course of a month. That, at least, appears to be the court’s reasoning.
This line of thought makes this case particularly remarkable. The notion that the extent of information itself that is gathered about a criminal subject could hold significance for Fourth Amendment analysis has not been adopted by the Supreme Court; yet, many have questioned or criticized the shortcomings of the reasonable expectation of privacy standard, including the potential lack of differentiation with respect to the aggregation of “publicly exposed” information as opposed to individual bits. I’m not sure that any other federal court has introduced this notion – there at least don’t appear to be any other such cases concerning the use of GPS. In fact, the 7th and 9th Circuits tended to suggest the sort of result one would expect—i.e. that use of GPS generally wouldn’t constitute a Fourth Amendment search since it merely conveyed information that was exposed to public view (See United States v. Garcia, 474 F.3d 994 (7th Cir. 2007), United States v. Pineda-Moreno, 591 F.3d 1212 (9th Cir. 2010)). If the Supreme Court were to adopt Maynard’s line of reasoning, it would mean a significant change for the scope of Fourth Amendment protection, not to mention the future of law enforcement surveillance.
But how does Maynard differ from Weaver—apart from the fact that they dealt with different bodies of law? Weaver seemed to focus on the technology itself and the novel dangers it posed—as bemoaned by Judge Smith in his dissent. As a result, Weaver appears to hold that the use of GPS for surveillance will always require a warrant whatever the circumstances. The holding in Maynard is narrower. It doesn’t subject GPS in and of itself to the warrant requirement but rather only the “prolonged” use of it. Again, it’s essentially the body of information that is acquired that is the key issue. “Prolonged” use results in the collection of too much information—beyond what one would reasonably expect to be public. That means that more limited use of GPS without a warrant should be OK within DC (assuming there aren’t other bases for objecting on Fourth Amendment grounds—for instance on the basis that depositing the GPS device on the car constituted an impermissible seizure). Where exactly the line would lie between overintrusive surveillance and permissible surveillance remains to be seen. It’s significant to note that the court expressly reserved any determination as to whether prolonged visual surveillance would be subject to the warrant requirement. That fact might, in a way, leave some room for technology to have some significance after all. However, if it were ruled that no warrant was required for police officers to maintain visual surveillance of a suspect over the course of a month and record that suspect’s movements—effectively accumulating the same body of information that was at issue in Maynard—this would be a strange result.
Maynard is interesting for another reason. On pages 36 - 37, it refers to what in German is known as a right to “informational self-determination” (informationelle Selbstbestimmung). In English scholarship, this right is often referred to as “informational privacy” (See DETECTER Deliverable D17.1: van der Hilst, "Human Rights Risks of Selected Detection Technologies: Sample Uses by Governments of Selected Detection Technologies," p. 4 (citing Alan F. Westin, Privacy and Freedom (1967) and Arthur Miller, The Assault on Privacy (1971))). If a right to control information about oneself wins greater recognition in the US—beyond law pertaining to the Freedom of Information Act and (potentially) common law torts—this would also represent a significant development for privacy law in the US.
Wednesday, August 11, 2010
Update: US Marshalls Service Incident
A reader of my earlier post "Focus on Full Body Scanners" pointed out in a comment that the Brijot scanners are passive wave scanners--i.e. they don't emit radiation--and as the statement from the Marshalls Service indicates, the images produced don't represent clear images of the naked body (the statement includes a link to the Brijot website with a couple of examples).
Evidently, however, the scanner also took photographic images of the individuals passing through, and I'm curious as to whether the photos were among the images that were stored.
I think I would be happier with these kind of scanners in airports than the active wave scanners. Some UK airports have also been taking photographs of travellers as they pass through the airport. As long as the photos aren't generally retained for too long, say 24 - 48 hours, that might also be acceptable.
Monday, August 9, 2010
News: US Marshalls Service stored more than 35,000 images from full body scanners
Wednesday, July 28, 2010
News: Body Scanner Developments
In Switzerland, the Zurich Airport began a pilot test involving a single body scanner on 8 June 2010. The test involved the “second generation” system which uses the gingerbread-man-like display rather than an actual scan image. The pilot test was completed on 14 July 2010, and the Airport states that the use of the system enjoyed a high acceptance rate among passengers. The results from the test are being assessed, and future tests may take place, but there are currently no plans to acquire any scanners, the Airport reports.
Friday, July 9, 2010
News: US Official Claims SWIFT Data Used in Arrest of 3 al Qaeda Suspects in Norwegian Investigation
Thursday, July 8, 2010
EU Parliament Gives Green Light to EU-US SWIFT Agreement
Wednesday, June 30, 2010
Comment: EDRI on the New SWIFT Deal
Unfortunately, the new adopted text still allows for bulk data transfers. The Parliament would have liked to replace bulk data with targeted searches carried out by an EU-based authority but according to MEP Birgit Sippel, "We cannot reduce the problem of bulk data for the moment as we do not have the technical
capability."
The retention period is still 5 years and there is no real system in place from the US on a binding legal redress. The US Privacy Act court clauses only apply to US citizens and legal residents. Therefore there is currently no right of judicial review for foreign citizens and residents (including EU) under the US law.
Another key critique to the current text is the role of Europol that should authorize the data transfer requests from the US. Besides the fact that Europol is not a judicial authority, as requested by the European Parliament in May 2010 Resolution, the incentive from this agency to limit the amount of data being transferred is extremely reduced due to the fact that they can actually request data searches from the US.
Tuesday, June 29, 2010
News: Germany Expresses Concern over Apple's iPhone users Database
The case is being cited as further proof of Germany's tough line on privacy after previous tensions with Google Street View this year. However, a speedy resolution seems likely:
Stefan Köpsell, an instructor in data protection at the Technical University in Dresden, said that Apple could probably settle the controversy surrounding the iPhone 4 by having German users give their consent prior to the data being forwarded.
“I think there is probably a fundamental conflict between some Internet business models and German privacy law,” Mr. Köpsell said. “But in general, evidence shows that most Germans are willing to participate if there’s a benefit.” For example, 60 percent of households in Germany use a retail bonus card called Payback, owned by Loyalty Partner of Munich, which gives them points that can be used toward future purchases. By participating, consumers have given the company the right to collect and market data on their purchasing habits, as well as target them with advertising. “I would think the same would be possible for Apple,” Mr. Köpsell said.
News: New US/EU Agreement on Transfer of SWIFT Banking Data
Final agreement on the new wording was reached on Friday (25 January). After the draft agreement had been initialled by Malmström on 10 June, MEPs had demanded
changes to the text concerning the bulk transfer of data, the creation of an EU counterpart to the US Terrorist Finance Tracking Programme (TFTP), and EU oversight of TFTP data-processing on US soil.
The three largest political groups in the Parliament – the centre-right EPP, centre-left PES and liberal ALDE – are now in favour of the agreement. In February, the Parliament, using new powers under the EU's Treaty of Lisbon, had rejected an interim agreement on SWIFT transfers.
Over at the Legalift Mathias Vermeulen has a discussion of some of the new restrictions build in to the new agreement, such as a ban on the use of this information for data mining, the possibility of administrative redress for EU citizens and the involvement of Europol in verifying and approving US requests for data.
In its coverage the Register points out that the European Data Protection Supervisor continues to question the need for mass transaction and long term storage of this data, and has additionally called for more oversight.
Thursday, May 27, 2010
DETECTER: The Human Rights Risks of Selected Detection Technologies
Executive Summary
- Intelligence is a vital element in successful counter-terrorism. There is rapid development in detection technologies that aid in the gathering of information. However, there are concerns over the privacy intrusion these detection technologies cause.
- Privacy is important for individual well-being, as well as the proper functioning of a democratic society. The right to privacy is vested in different national, European and International laws, which prescribe that the right to privacy may only be limited by measures that have a sound legal basis and are necessary in a democratic society for the protection of national security.
- From the legal and moral framework around privacy it emerges that detection technologies used in counter-terrorism should take account of: legitimacy, proportionality, necessity, transparency, factors concerning the person targeted, the sensitivity of the data sought, the effectiveness, the possibility of function creep and the extent to which PET’s are implemented.
- Privacy concerns arise with the widespread and indiscriminate use of communication surveillance; the covert use of CCTV technology; the sensitivity of biometric data; and the ineffectiveness (and therefore disproportionateness) of data mining and analysis and decision support technologies.
- There are also risks inherent to the use of detection technologies in general. The use of detection technologies can have a ‘chilling effect’ and can be ineffective due to the huge amount of gathered data. However, positive effects of the use of detection technologies are the ability to detect and therefore prevent terrorist attacks and the deterrent effect they have.
- Detection technologies should be used, provided that their authorization is based on legislation that protects against abuse and presents fair consideration to the proportionality and necessity of the aim pursued. The ultimate assessment of the threat detection technologies pose to privacy depends on the actual usage of the technologies.
DETECTER: The Moral Risks of Preventive Policing in Counter-terrorism
Executive Summary
1. Preventive policing is any action carried out by police with the intention of identifying and preventing a specific crime or a type of crime. Preventive policing can include “special investigation techniques”, including secret surveillance. These carry obvious moral risks.
2. Recommendaton Rec (2005) 10 of the Committee of Ministers of the Council of Europe outlines possible restrictions on the use of special investigation techniques. It suggests that the least intrusive special investigation measures should be used, if at all, only when the prevention or prosecution of serious crime requires it, and not in a way that conflicts with the right of anyone arrested to a fair trial. The principles reflect legal privacy protections under European Convention on Human Rights, Article 8, and Convention 108.
3. Liberal theory supports the approach of Rec (2005) 10. It permits the use of special investigative techniques in preventive policing if the crime that these techniques are intended to prevent is very serious, e.g. a terrorist attack. In particular, liberal theory permits the use of secret surveillance, if the choice of targets for the surveillance is evidence-based.
4. The form of liberal theory that best reconciles the demands of privacy and counterterrorism with those of liberty is a modified Kantian theory, which is less utopian in its assumptions about human beings than a Lockean theory, but which excludes the total concentration of power, as in a Hobbesian theory.
5. Liberal theory condemns terrorist acts not just because of the injury and death they cause, but because of the contempt for impartiality that terrorist groups display. Impartiality is central to the liberal design of government institutions.
6. Privacy in Kantian theory is primarily the scope agents have for deliberating and choosing life plans free from other people’s interference. In liberal theory generally, privacy is also the scope people have for forming intimate relationships without scrutiny and adopting harmless life plans (harmless means of pursuing happiness) without being subject to outside criticism.
7. Kantian theory does not justify restrictions on thought or expression of thought about terrorism or in favour of terrorism, but it does justify restrictions on actions that contribute to terrorist acts.
8. Expression of thought about terrorism, even expression of thought sympathetic to
terrorism, should not be criminalized from the point of view of liberal theory. This counts against e.g. the “glorification” of terrorism provisions in the UK Terrorism Act (2006).
9. Kantian theory implies that preventive policing can fairly employ “profiling” techniques for identifying suspects in counter-terrorism, so long as these are evidence-based.
10. “Profiling techniques” cannot justifiably be used alongside detention and trial procedures that are revised ad hoc for counter-terrorism purposes.
Wednesday, May 19, 2010
News: More European Anger at Google Invasions of Privacy
From Privacy Digest: Google have admitted gathering private data on internet use in the course of the taking photographs for the Google Street View programme.
Google acknowledged on Friday that it had collected snippets of private data around the world. In a blog post on its Web site, the company said information had been recorded as it was sent over unencrypted residential wireless networks as Google’s Street View cars with mounted recording equipment passed by.
The data collection, which Google said was inadvertent and the result of a programming error, took place in all the countries where Street View has been catalogued, including the United States and parts of Europe. Google apologized and said it had not used the information, which it plans to delete in conjunction with regulators.
The Register reports that both Germany prosecutors and the Czech Republic data protection agency have launched investigations:
In effect, Mountain View may have hoovered up emails and other private information if the Google cars travelled over Wi-Fi networks while one of its vehicles was in range. The firm had previously claimed that no payload data was ever intercepted.
Hamburg prosecutors said they had received a complaint against unnamed Google workers over the “unauthorised interception of data”, and confirmed that an investigation - that could take about a fortnight to determine if the allegations warrant a full-blown probe - was underway.
News: Internet Browsers' Record of Your Web Habits Available to Other Websites
From the Sydney Morning Herald: The Electronic Freedom Foundation have been researching how easy it is to access information about a user’s internet activity. Commonly it is thought that disabling ‘cookies’ is enough to prevent one’s web browser collecting information on what websites are being visited. The EFF’s research implies that even with this safeguard the browser leaves ‘a virtual fingerprint’ which nearly uniquely identifies the user and enables websites to access information on the users browsing habits:
To conduct the research, the website anonymously logged information that most websites would normally access when users visit, the EFF said.
After comparing a database collected from almost a million visitors, the EFF discovered that 84 per cent of the configuration combinations were unique and identifiable, and where browsers had Adobe Flash or Java plug-ins installed they were 94 per cent identifiable.
"Browser fingerprinting is a powerful technique, and fingerprints must be considered alongside cookies and IP addresses when we discuss web privacy and user trackability,"
Monday, May 3, 2010
Israeli Security Expert Decries Body Scanners Before Canadian Parliament
“I don't know why everybody is running to buy these expensive and useless machines. I can overcome the body scanners with enough explosives to bring down a Boeing 747,” he is quoted as saying, “That's why we haven't put them in our airport.”
According to the story, a Canadian transport minister has defended the installation of body scanners at Canadian airports. Political scientist Mark Salter also reportedly testified that he viewed body scanners as a “genuine leap forward” in airline security. (Hat tip to unwatched.org)
Monday, April 19, 2010
Study: Privacy Not Dead to the Younger Generation
• Eighty-eight percent of people of all ages said they have refused to give out information to a business because they thought it was too personal or unnecessary. Among young adults, 82 percent have refused, compared with 85 percent of those over 65.
• Most people — 86 percent — believe that anyone who posts a photo or video of them on the Internet should get their permission first, even if that photo was taken in public. Among young adults 18 to 24, 84 percent agreed — not far from the 90 percent among those 45 to 54.
• Forty percent of adults ages 18 to 24 believe executives should face jail time if their company uses someone's personal information illegally — the same as the response among those 35 to 44 years old.
The sample is big: about 1,000 people, though smaller than the 27,000 the Eurobarometer surveys use (which also record some interesting results on attitudes to privacy). It's interesting to see empirical research on an issue people are all too often happy to accept quite crude generalisations as obvious truths.
I'd also be interested to see work on whether there has been a change in people's attitudes over the last 5-10 years. I have a hunch many young people who didn't care about privacy when they first started using the Internet and social networking sites have become far more conscious of privacy issues as they have become more prominent topics of controversy online and in the wider media.
Friday, April 16, 2010
Data Mining on Facebook?
Friday, March 26, 2010
News: Airport Worker Disciplined for Abuse of Full Body Scanner
BAA said: "We treat any allegations of inappropriate behaviour or misuse of security equipment very seriously and these claims are being investigated thoroughly," a BAA spokesman said. "If found to be substantiated we will take appropriate action."