Showing posts with label profiling. Show all posts
Showing posts with label profiling. Show all posts

Friday, April 16, 2010

Data Mining on Facebook?

The Guardian has run a story on Facebook against the backdrop of the Ceop “panic button” proposal which reveals that the social networking site conducts algorithm-driven monitoring that “track[s] the behaviour of its users and flag[s] up suspicious activity.” OK, that sounds like data mining, but why is this story of relevance to counter-terrorism? Interestingly, the article states that "Facebook's international law enforcement is lead by Max Kelly, a former FBI agent who worked on cyber-crime and counter-terrorism before moving to Facebook five years ago." The article also discusses how Facebook interacts with law enforcement in the US and UK. It suggests that UK officials still feel Facebook doesn’t do enough to assist them and the UK public to protect the safety of children.

Thursday, January 28, 2010

Martin Scheinin on Body Scanners and Profiling

DETECTER Partner Martin Scheinin has a piece in the Guardian. He argues against the idea that the aim of preventing acts of terrorism always trumps privacy or other fundamental rights and that any restrictions of such rights ought to be specifically provided for in clear law ensuring their effectiveness, necessity and proportionality. A few select quotes:

...The current generation of body scanners entail an unnecessary and therefore disproportionate intrusion into privacy, by showing a graphic image of a naked human person to one or more observers. It would be technologically easy to avoid this, by securing that no images are ever stored, and by using an algorithm to replace on the observer's screen the image of a real person with a standard animation figure but places any suspicious items on that image...

What is worse, body scanners are ineffective. They are unlikely to detect 80 grams of PETN explosives hidden in the underware of a person. And once it is known that body scanners are in use, they are easy to avoid by hiding this type of explosives in a body cavity or in a commercial item in one's hand luggage...

There are better ways than body scanners and group-related profiling to improve security at airports and elsewhere. The technology already exists for detecting from distance most explosive substances, including PETN. Together with professional observation of behavioral patterns this provides a prospect of respecting privacy while at the same time doing a better job in preventing acts of terrorism. It seems to be the unwarranted obsession to know more about the perceived bad person that has slowed down work to detect explosives....

The article also features a link to his latest report written in his capacity as UN Special Rapporteur on Human Rights and Counterterrorism, highlighting the erosion of the right to privacy in the fight against terrorism.

Wednesday, January 20, 2010

News: New Security Measures for UK Airports

From the BBC: In a statement to the House of Commons earlier today, Prime Minister Gordon Brown announced the recommendations arising from a review of airport security and further intelligence briefings. The main measures include:
  • Direct Flights from Yemen to the UK are suspended until security concerns are addressed.
  • A "no fly" list is to be established to prevent suspected terrorists from travelling to the UK.
  • A second list of lower risk suspects will be established entailing 'special measures' for those attempting to fly to the UK, such as more stringent screening (officials are not currently specifying anything further).
  • All UK airports and ports to follow the 'e-borders' scheme, designed to collect personal data on all passengers entering or exiting the country, by the end of the year.
  • Enhanced global cooperation to enable suspect individuals to be checked against watchlists 24 hours before flying to or via the UK.
  • Full Body Scanners at British airports next week.
  • New Intelligence teams to identify threats to British security abroad.

Friday, January 8, 2010

News: Aiport Security Technology

Forbes has posted an interesting article today discussing various proposals for improving airport security, including behavioral analysis systems, physiological sensors, and increased use of profiling. One system being tested in Israel even sounds like psychological warfare—flashing images onto airport screens, “such as symbols associated with a certain terrorist group or some other image only a would-be terrorist would recognize” and then assessing individuals’ reactions to those images. The article also cites Jim Harper of the Cato Institute for suggesting that security be placed in the hands of the airlines in order to introduce more variation in security procedures.

Thursday, September 24, 2009

News: EP Resolution on US SWIFT Access

From EDRI: I previously reported the concerns about the US access to European banking data. Now the European Parliament have passed a resolution insisting on the need for a new agreement:


The EP believes that the transfer requests should be "based on specific, targeted cases, limited in time and subject to judicial authorisation, and that any subsequent processing is limited to data which disclose a link with persons or organisations under examination in the US" and that "EU citizens and enterprises are granted the same defence rights and procedural guarantees and the same right of access to justice as exist in the EU and that the legality and proportionality of the transfer requests are open to judicial review in the US". In order to prevent any abuse, the transferred data should be "subject to the same judicial redress mechanisms as would apply to data held within the EU, including compensation in the event of unlawful processing of personal data." The resolution also asks for a reciprocity mechanism that would oblige the US authorities to equally transfer relevant financial data to the competent EU authorities, upon request.

News: Newly Obtained Declassified Documents Reveal More Details about FBI's NSAC

Wired has run a story on the FBI’s National Security Branch Analysis Center (NSAC) based on newly obtained declassified documents. The Center makes use of a database system that includes “tens of thousands of records from private corporate databases, including car-rental companies, large hotel chains and at least one national department store.” The author of the article speculates that a number of businesses may be voluntarily providing records on specifically named individuals at the FBI’s request – as was the case with JetBlue and passenger records. The database system is being used both for counter-terrorist efforts as well as other criminal investigations. Among the things the system currently contains according to Wired:
• International travel records of citizens and foreigners

• Financial forms filed with the Treasury by banks and casinos

• 55,000 entries on customers of Wyndham Worldwide, which includes Ramada Inn, Days Inn, Super 8, Howard Johnson and Hawthorn Suites

• 730 records from rental-car company Avis

• 165 credit card transaction histories from Sears

• Nearly 200 million records transferred from private data brokers such Accurint, Acxiom and Choicepoint

• A reverse White Pages with 696 million names and addresses tied to U.S. phone numbers

• Log data on all calls made by federal prison inmates

• A list of all active pilots

• 500,000 names of suspected terrorists from the Unified Terrorist Watch List

• Nearly 3 million records on people cleared to drive hazardous materials on the nation’s highways

• Telephone records and wiretapped conversations captured by FBI investigations

• 17,000 traveler itineraries from the Airlines Reporting Corporation

Wired reports that the database system is being used in conjunction with a meta-search engine and link and pattern analysis software.

Friday, September 11, 2009

News: EC Proposes Police Access to Asylum Fingerprint Database

The Eurodac Database, which holds fingerprints for asylum seekers and other irregular border crossers, can currently only be accessed by national authorities dealing with asylum requests. Under the proposed legislation, however, Europol and national police services would gain access for fighting serious crime and terrorism. Human Rights groups have criticised the proposals:

The European Council on Refugees and Exiles (ECRE) has said the move could potentially put asylum-seekers in danger, since Europol has the right to exchange data with other EU bodies and with non-EU countries. “How would it be ensured that information about people fleeing persecution doesn't reach their persecutors?”, Bjarte Vandvik, the ECRE's secretary-general, has said.

News: ACPO Publish Policy Advice on the Use of ANPR

From Spyblog: The Association of Chief Police Officers has published its 'Practice Advice on the Management and Use of Automatic Number Plate Recognition'.

The post calls attention to the potential for the guidelines to result in 'false positives' and innocent people being flagged up for stop and search. Also some categories for 'flagging' vehicles do not seem to be indicative in any way of having any involvement in criminality such as 'Protest' - presubably flagging the driver as involved in protests. The full pdf can be found here

News: FOI Request Reveals DHS Travel Records

From Slashdot: A US citizen's FOI request has revealed what information the DHS is storing on travellers. The info listed includes:

  • Credit card number and expiration (really)
  • IP address used to make web travel reservations
  • Hotel information and itinerary
  • Full Name, birth date and passport number
  • Full airline itinerary, including flight numbers and seat numbers
  • Cruise ship itinerary
  • Phone numbers, incl. business, home & cell
  • Every frequent flyer and hotel number associated with the subject, even ones not used for the specific reservation

Thursday, September 3, 2009

Zurich DETECTER Site Launched

We've set up a few webpages related to the DETECTER project on the University of Zurich's website. The pages provide some information about Work Package 6, contact information for the researchers involved, and will provide a platform for any future publications that may come out in connection with the project. The "homepage" for the site is accessible here.

Friday, July 17, 2009

France Plans Development of Database for Threatening Personalities

Last year, the French government expressed the intention to create a new law enforcement database dubbed EDVIGE (exploitation documentaire et valorisation de l’information générale). The purpose was to have a profile of every individual from the age of thirteen on up as well as groups and organizations which “on the basis of their individual or collective activities represent a potential threat to the public order.” Allegedly, anyone who had a direct relationship with these individuals, groups, or organizations would also go into the database. Access to the database would be available to the French intelligence service and the police.

Public outcry against these plans resulted in revisions to the proposed enabling legislation behind the database and ultimately the withdrawal of the legislation in December 2008. Now a third version of the bill is on the table (“EDVIGE 3.0”). The latest bill, however, reportedly would still subject children of thirteen years and older to inclusion in the database, and complaints have been raised that definitions governing the scope of the database are too broad. A summary of the latest bill in French is available here. The Austrian media organization Unwatched.org also has an article on EDVIGE in German.

Friday, May 8, 2009

More on DNA Databases

Liberty's Shami Chakrabarti has a piece in the Telegraph on the proposed retention of DNA of those charged but not found guilty of crimes. Interestingly she points out that a disproportionate number of those whose DNA has been recorded are young, black men, commenting that it was only as a result of European human rights judges "who could remember when ethnic profiling meant something more sinister " that the government modified their policy.

She also mentions 'privacy' as a reason against such DNA retention. But I'm still uncertain as to why this is a matter of privacy. What private information can be derived from the data in question? Can intimate health issues be revealed for example? If this was possible then I think the case against retention would be water tight - but I've not seen anyone make this sort of argument.

Another scenario: perhaps the worry is that if someone with bad intentions got ahold of someone's DNA information they would then be able to track whether they had been in particular places, say (because traces of hair left behind could be tested) i.e. that people with bad intentions could use this info in the same way as the police do. Is this what people have in mind? Is this a significant risk?

Friday, May 1, 2009

Stop and Search

The Times has 2 pieces on the massive upsurge in the use of stop and search powers - a rise which has disproportionately affected ethnic minorities. This has been defended by police on the grounds that it is needed to combat terrorism.

There are so many issues one could talk about here, but I just want to pick out one line from the Met's defence: apparently stop and search is a vital tactic intended to "create a hostile environment for terrorists and provide a visible reassurance to the public".

I accept (as most surely do) that sometimes police work is going to inconvenience me. This is a very small price to pay for steps that make me safer. But 'reassuring the public' I'm less sure about - can you legitimately ask people to accept inconvenience in the name of 'reassuring the public'?