Showing posts with label technology. Show all posts
Showing posts with label technology. Show all posts
Wednesday, February 23, 2011
Did US Government Agencies spend over 20 million USD on Bogus Software for Counter-Terrorism?
Eric Lichtblau and James Risen of the New York Times report that various US agencies spent a total exceeding 20 million USD between 2002 and 2009 for phony counter-terrorism technologies linked to a California computer programmer. Among the things which the programmer allegedly claimed to be able to do were "find terrorist plots hidden in broadcasts of the Arab network Al Jazeera; identify terrorists from Predator drone videos; and detect noise from hostile submarines." Reportedly, the technology provided the basis for the diversion and grounding of several US-bound flights in 2003. The story is available here in the Sydney Morning Herald. The news follows on charges from Senator Bernie Sanders that, between 2007 and 2009, the US Defense Department awarded hundreds of billions of US dollars to companies involved in fraud. Sen. Sanders’ assertion was based on a Pentagon report released in January.
Wednesday, February 2, 2011
Petition for Rehearing of Maynard GPS Case Denied
The petition for rehearing the GPS issues from the DC Maynard case was denied this past November.
It was a close decision with 4 of the 9 judges dissenting. Two dissenting opinions were issued. The first, drafted by Chief Judge Sentelle and also signed by Judges Henderson, Brown, and Kavanaugh, argued that Maynard was not distinguishable from the Knotts case, and therefore there was no reason to have decided Maynard differently than Knotts. The opinion also took issue with the theory that aggregation of information could amount to violation of the Fourth Amendment, which the original decision appeared to promote. It expressed concern that this line of reasoning would mean that other forms of surveillance—including personally conducted visual surveillance—could be held to violate the Fourth Amendment when done on a prolonged basis. Citing an opinion from the Seventh Circuit, it also suggested that GPS tracking should perhaps not even be considered a search within the meaning of the Fourth Amendment.
The second dissenting opinion, drafted by Judge Kavanaugh, pointed out that the appellant had also asserted a Fourth Amendment violation on the basis of the interference with personal property through the installation of the GPS tracking device on the appellant’s automobile. Thus, Judge Kavanaugh opined that a rehearing was additionally warranted in order to adjudicate this question.
The order, a concurring opinion, and the two dissenting opinions are available here thanks to courtlistener.com.
It was a close decision with 4 of the 9 judges dissenting. Two dissenting opinions were issued. The first, drafted by Chief Judge Sentelle and also signed by Judges Henderson, Brown, and Kavanaugh, argued that Maynard was not distinguishable from the Knotts case, and therefore there was no reason to have decided Maynard differently than Knotts. The opinion also took issue with the theory that aggregation of information could amount to violation of the Fourth Amendment, which the original decision appeared to promote. It expressed concern that this line of reasoning would mean that other forms of surveillance—including personally conducted visual surveillance—could be held to violate the Fourth Amendment when done on a prolonged basis. Citing an opinion from the Seventh Circuit, it also suggested that GPS tracking should perhaps not even be considered a search within the meaning of the Fourth Amendment.
The second dissenting opinion, drafted by Judge Kavanaugh, pointed out that the appellant had also asserted a Fourth Amendment violation on the basis of the interference with personal property through the installation of the GPS tracking device on the appellant’s automobile. Thus, Judge Kavanaugh opined that a rehearing was additionally warranted in order to adjudicate this question.
The order, a concurring opinion, and the two dissenting opinions are available here thanks to courtlistener.com.
Labels:
human rights,
police,
privacy,
surveillance,
technology,
United States
Friday, November 19, 2010
Increasing Controversy with Introduction of New Pat-Down Procedures for US Airline Travel
When the US deployed backscatter x-ray and millimeter wave scanners, travellers were given the choice to opt for a physical pat-down instead of going through the scanner. Now, the TSA has introduced new, more invasive pat-down procedures that involve exploring around breasts and genitals and between the buttocks (See for instance this particularly graphic account as well as this account reportedly from author Erin Chase). Some early reports speculated that the new measures were introduced in order to intimidate those who would otherwise choose the pat-down into deciding that maybe the scanners aren’t that bad. Jeffrey Goldberg of The Atlantic has stated that TSA personnel explicitly admitted that that was the reason behind the new policy. John Pistole, Administrator of the TSA, who was called before the US Senate Commerce Committee this week, suggested that the new procedures are in response to covert testing of the old pat-down method which indicated it wasn’t “thorough” enough.
Meanwhile, concerns about the health effects of the scanners continue. Four scientists affiliated with the University of California at San Francisco drafted an open letter last spring to President Obama’s Assistant for Science and Technology outlining their concerns with the backscatter scanners. They argue that official assessments of the health impact from backscatter radiation may underestimate the potential effects of the low-levels of dosage that the scanners emit since they are based on whole body exposure, whereas the scanners would concentrate all radiation in the skin. Additionally, they express concern that certain groups or individuals may be particularly vulnerable to the increased radiation exposure, and they decry the failure to publish key data that would permit independent assessment of the health risks. Both the Allied Pilots Association and the US Airline Pilots Association have advised their members not to go through the scanners. The US Airline Pilots Association further notes that experiences with the new “enhanced” pat-down procedures have involved “a wide range of possibilities … and the results can be devastating.” Others have more general objections to both the scanner/ pat-down procedures. Two commercial pilots have even filed a lawsuit against the Department of Homeland Security citing Fourth Amendment violations. A number of State legislators in New Jersey have objected to the current screening regime and have introduced resolutions calling on the TSA to reconsider its procedures. Additionally, one private individual is calling for a national “opt-out” day to stage a protest.
Meanwhile, concerns about the health effects of the scanners continue. Four scientists affiliated with the University of California at San Francisco drafted an open letter last spring to President Obama’s Assistant for Science and Technology outlining their concerns with the backscatter scanners. They argue that official assessments of the health impact from backscatter radiation may underestimate the potential effects of the low-levels of dosage that the scanners emit since they are based on whole body exposure, whereas the scanners would concentrate all radiation in the skin. Additionally, they express concern that certain groups or individuals may be particularly vulnerable to the increased radiation exposure, and they decry the failure to publish key data that would permit independent assessment of the health risks. Both the Allied Pilots Association and the US Airline Pilots Association have advised their members not to go through the scanners. The US Airline Pilots Association further notes that experiences with the new “enhanced” pat-down procedures have involved “a wide range of possibilities … and the results can be devastating.” Others have more general objections to both the scanner/ pat-down procedures. Two commercial pilots have even filed a lawsuit against the Department of Homeland Security citing Fourth Amendment violations. A number of State legislators in New Jersey have objected to the current screening regime and have introduced resolutions calling on the TSA to reconsider its procedures. Additionally, one private individual is calling for a national “opt-out” day to stage a protest.
Labels:
body scanners,
flight screening,
politics,
technology,
United States
Wednesday, October 13, 2010
US Government seeks rehearing of Maynard decision
The US Attorney’s Office has submitted to the DC Circuit Court a petition for rehearing of the GPS issue from the recent Maynard decision. I discussed that case in a previous post. In the petition, the government argues that the court’s holding on GPS surveillance is inconsistent with both existing US Supreme Court and DC Circuit jurisprudence, “raises enormous practical problems for law enforcement” and “implicitly calls into question common and important practices such as sustained visual surveillance and photographic surveillance of public places.” A copy of the petition is available here courtesy of Wired’s Threat Level blog (See also this post there on the FBI's GPS surveillance of an Arab-American for unknown reasons).
Labels:
police,
surveillance,
technology,
United States
Schneier on Web Surveillance
Security specialist Bruce Schneier has published an opinion piece on CNN. The article comes in response to reports that the Obama administration is seeking to secure law enforcement access to web-based communications data through the enactment of new legislation. See also this related post on the LegaLIFT blog.
Labels:
internet monitoring,
law,
police,
surveillance,
technology,
United States
Monday, August 16, 2010
DC Circuit Rules on Fourth Amendment and GPS
In an earlier post, I discussed the case of People v. Weaver which was argued before the New York Court of Appeals. Now, the Federal Circuit Court for the District of Columbia has decided on the issue of whether the long-term use of GPS surveillance must be supported by a warrant. Unlike in People v. Weaver, the DC Circuit decided the case on the basis of the Fourth Amendment of the US Constitution as opposed to an analogous guarantee under a State Constitution. The case, United States v. Maynard, No. 08-3030 (D.C. Cir. August 6, 2010), does have some similarities to People v. Weaver, but there are also some interesting and significant differences.
Maynard involved the use of a GPS device to monitor the movements of a suspect’s vehicle over the course of 28 days. Inevitably, as in Weaver, much of the discussion in Maynard centers around the Knotts case (460 U.S. 276 (1983)). Knotts was the Supreme Court case involving the “beeper” homing device and the drum of chloroform (See my earlier post for more details). In Maynard, however, the court seized upon specific language indicating a limitation on the scope of the Knotts holding. In this way, the DC court argued that the Knotts court had drawn a distinction between the limited type of surveillance at issue in that case versus “more comprehensive or sustained” surveillance as was at issue in the Maynard case (“Most important for the present case, the Court specifically reserved the question whether a warrant would be required in a case involving ‘twenty-four hour surveillance,’….” (p. 17)).
Thus, for the Maynard court, the issue in question in the case was whether prolonged GPS-tracking of a vehicle without a warrant violated the Fourth Amendment protection against unreasonable searches. As in Weaver, the DC court was particularly impressed by the amount of information that could be extracted from having the complete record of an individual’s movements over an extended period of time.
Since the case concerned the Fourth Amendment, the Court had to apply the so-called Katz test (after Katz v. United States, 389 U. S. 347 (1967)) to determine whether there was a violation. That involves application of the famous (or infamous) “reasonable expectation of privacy” standard. Under that standard, US Supreme Court jurisprudence has established that one cannot reasonably expect that aspects of life that are exposed to the public remain in or belong to the private sphere. Thus, the reasoning in Knotts was that the use of the homing device did not implicate the Fourth Amendment since “[a] person traveling in an automobile on public thoroughfares has no reasonable expectation of privacy in his movements from one place to another” (Knotts, at 281). Interestingly, the DC court held that the prolonged surveillance of a suspect’s vehicle with GPS does not concern movements that are “exposed to the public” in the same way as the journey of the drum of chloroform from its place of purchase to Knotts’ cabin. Here, the extent of information gathered was the distinguishing factor. Although each of the vehicle’s movements on public roads was undoubtedly in public view, the DC court maintained that the likelihood that anyone would track each of those movements week after week was “essentially nil” (p. 26). Thus, in essence, it may be unreasonable to expect that no one will observe the totality of a single trip made with one’s automobile on public roads, but it is not unreasonable to expect that no one person will observe the totality of every trip made with that automobile over the course of a month. That, at least, appears to be the court’s reasoning.
This line of thought makes this case particularly remarkable. The notion that the extent of information itself that is gathered about a criminal subject could hold significance for Fourth Amendment analysis has not been adopted by the Supreme Court; yet, many have questioned or criticized the shortcomings of the reasonable expectation of privacy standard, including the potential lack of differentiation with respect to the aggregation of “publicly exposed” information as opposed to individual bits. I’m not sure that any other federal court has introduced this notion – there at least don’t appear to be any other such cases concerning the use of GPS. In fact, the 7th and 9th Circuits tended to suggest the sort of result one would expect—i.e. that use of GPS generally wouldn’t constitute a Fourth Amendment search since it merely conveyed information that was exposed to public view (See United States v. Garcia, 474 F.3d 994 (7th Cir. 2007), United States v. Pineda-Moreno, 591 F.3d 1212 (9th Cir. 2010)). If the Supreme Court were to adopt Maynard’s line of reasoning, it would mean a significant change for the scope of Fourth Amendment protection, not to mention the future of law enforcement surveillance.
But how does Maynard differ from Weaver—apart from the fact that they dealt with different bodies of law? Weaver seemed to focus on the technology itself and the novel dangers it posed—as bemoaned by Judge Smith in his dissent. As a result, Weaver appears to hold that the use of GPS for surveillance will always require a warrant whatever the circumstances. The holding in Maynard is narrower. It doesn’t subject GPS in and of itself to the warrant requirement but rather only the “prolonged” use of it. Again, it’s essentially the body of information that is acquired that is the key issue. “Prolonged” use results in the collection of too much information—beyond what one would reasonably expect to be public. That means that more limited use of GPS without a warrant should be OK within DC (assuming there aren’t other bases for objecting on Fourth Amendment grounds—for instance on the basis that depositing the GPS device on the car constituted an impermissible seizure). Where exactly the line would lie between overintrusive surveillance and permissible surveillance remains to be seen. It’s significant to note that the court expressly reserved any determination as to whether prolonged visual surveillance would be subject to the warrant requirement. That fact might, in a way, leave some room for technology to have some significance after all. However, if it were ruled that no warrant was required for police officers to maintain visual surveillance of a suspect over the course of a month and record that suspect’s movements—effectively accumulating the same body of information that was at issue in Maynard—this would be a strange result.
Maynard is interesting for another reason. On pages 36 - 37, it refers to what in German is known as a right to “informational self-determination” (informationelle Selbstbestimmung). In English scholarship, this right is often referred to as “informational privacy” (See DETECTER Deliverable D17.1: van der Hilst, "Human Rights Risks of Selected Detection Technologies: Sample Uses by Governments of Selected Detection Technologies," p. 4 (citing Alan F. Westin, Privacy and Freedom (1967) and Arthur Miller, The Assault on Privacy (1971))). If a right to control information about oneself wins greater recognition in the US—beyond law pertaining to the Freedom of Information Act and (potentially) common law torts—this would also represent a significant development for privacy law in the US.
Maynard involved the use of a GPS device to monitor the movements of a suspect’s vehicle over the course of 28 days. Inevitably, as in Weaver, much of the discussion in Maynard centers around the Knotts case (460 U.S. 276 (1983)). Knotts was the Supreme Court case involving the “beeper” homing device and the drum of chloroform (See my earlier post for more details). In Maynard, however, the court seized upon specific language indicating a limitation on the scope of the Knotts holding. In this way, the DC court argued that the Knotts court had drawn a distinction between the limited type of surveillance at issue in that case versus “more comprehensive or sustained” surveillance as was at issue in the Maynard case (“Most important for the present case, the Court specifically reserved the question whether a warrant would be required in a case involving ‘twenty-four hour surveillance,’….” (p. 17)).
Thus, for the Maynard court, the issue in question in the case was whether prolonged GPS-tracking of a vehicle without a warrant violated the Fourth Amendment protection against unreasonable searches. As in Weaver, the DC court was particularly impressed by the amount of information that could be extracted from having the complete record of an individual’s movements over an extended period of time.
Since the case concerned the Fourth Amendment, the Court had to apply the so-called Katz test (after Katz v. United States, 389 U. S. 347 (1967)) to determine whether there was a violation. That involves application of the famous (or infamous) “reasonable expectation of privacy” standard. Under that standard, US Supreme Court jurisprudence has established that one cannot reasonably expect that aspects of life that are exposed to the public remain in or belong to the private sphere. Thus, the reasoning in Knotts was that the use of the homing device did not implicate the Fourth Amendment since “[a] person traveling in an automobile on public thoroughfares has no reasonable expectation of privacy in his movements from one place to another” (Knotts, at 281). Interestingly, the DC court held that the prolonged surveillance of a suspect’s vehicle with GPS does not concern movements that are “exposed to the public” in the same way as the journey of the drum of chloroform from its place of purchase to Knotts’ cabin. Here, the extent of information gathered was the distinguishing factor. Although each of the vehicle’s movements on public roads was undoubtedly in public view, the DC court maintained that the likelihood that anyone would track each of those movements week after week was “essentially nil” (p. 26). Thus, in essence, it may be unreasonable to expect that no one will observe the totality of a single trip made with one’s automobile on public roads, but it is not unreasonable to expect that no one person will observe the totality of every trip made with that automobile over the course of a month. That, at least, appears to be the court’s reasoning.
This line of thought makes this case particularly remarkable. The notion that the extent of information itself that is gathered about a criminal subject could hold significance for Fourth Amendment analysis has not been adopted by the Supreme Court; yet, many have questioned or criticized the shortcomings of the reasonable expectation of privacy standard, including the potential lack of differentiation with respect to the aggregation of “publicly exposed” information as opposed to individual bits. I’m not sure that any other federal court has introduced this notion – there at least don’t appear to be any other such cases concerning the use of GPS. In fact, the 7th and 9th Circuits tended to suggest the sort of result one would expect—i.e. that use of GPS generally wouldn’t constitute a Fourth Amendment search since it merely conveyed information that was exposed to public view (See United States v. Garcia, 474 F.3d 994 (7th Cir. 2007), United States v. Pineda-Moreno, 591 F.3d 1212 (9th Cir. 2010)). If the Supreme Court were to adopt Maynard’s line of reasoning, it would mean a significant change for the scope of Fourth Amendment protection, not to mention the future of law enforcement surveillance.
But how does Maynard differ from Weaver—apart from the fact that they dealt with different bodies of law? Weaver seemed to focus on the technology itself and the novel dangers it posed—as bemoaned by Judge Smith in his dissent. As a result, Weaver appears to hold that the use of GPS for surveillance will always require a warrant whatever the circumstances. The holding in Maynard is narrower. It doesn’t subject GPS in and of itself to the warrant requirement but rather only the “prolonged” use of it. Again, it’s essentially the body of information that is acquired that is the key issue. “Prolonged” use results in the collection of too much information—beyond what one would reasonably expect to be public. That means that more limited use of GPS without a warrant should be OK within DC (assuming there aren’t other bases for objecting on Fourth Amendment grounds—for instance on the basis that depositing the GPS device on the car constituted an impermissible seizure). Where exactly the line would lie between overintrusive surveillance and permissible surveillance remains to be seen. It’s significant to note that the court expressly reserved any determination as to whether prolonged visual surveillance would be subject to the warrant requirement. That fact might, in a way, leave some room for technology to have some significance after all. However, if it were ruled that no warrant was required for police officers to maintain visual surveillance of a suspect over the course of a month and record that suspect’s movements—effectively accumulating the same body of information that was at issue in Maynard—this would be a strange result.
Maynard is interesting for another reason. On pages 36 - 37, it refers to what in German is known as a right to “informational self-determination” (informationelle Selbstbestimmung). In English scholarship, this right is often referred to as “informational privacy” (See DETECTER Deliverable D17.1: van der Hilst, "Human Rights Risks of Selected Detection Technologies: Sample Uses by Governments of Selected Detection Technologies," p. 4 (citing Alan F. Westin, Privacy and Freedom (1967) and Arthur Miller, The Assault on Privacy (1971))). If a right to control information about oneself wins greater recognition in the US—beyond law pertaining to the Freedom of Information Act and (potentially) common law torts—this would also represent a significant development for privacy law in the US.
Labels:
human rights,
police,
privacy,
surveillance,
technology,
United States
Wednesday, August 11, 2010
Update: US Marshalls Service Incident
I noted in a post on Monday that the US Marshalls Service had revealed that it had stored more than 35,000 images from a Brijot Gen2 scanner that was in use at a Florida courthouse. The Marshalls Service has issued a statement in response to that disclosure. That statement is available on the Brijot website here.
A reader of my earlier post "Focus on Full Body Scanners" pointed out in a comment that the Brijot scanners are passive wave scanners--i.e. they don't emit radiation--and as the statement from the Marshalls Service indicates, the images produced don't represent clear images of the naked body (the statement includes a link to the Brijot website with a couple of examples).
Evidently, however, the scanner also took photographic images of the individuals passing through, and I'm curious as to whether the photos were among the images that were stored.
I think I would be happier with these kind of scanners in airports than the active wave scanners. Some UK airports have also been taking photographs of travellers as they pass through the airport. As long as the photos aren't generally retained for too long, say 24 - 48 hours, that might also be acceptable.
A reader of my earlier post "Focus on Full Body Scanners" pointed out in a comment that the Brijot scanners are passive wave scanners--i.e. they don't emit radiation--and as the statement from the Marshalls Service indicates, the images produced don't represent clear images of the naked body (the statement includes a link to the Brijot website with a couple of examples).
Evidently, however, the scanner also took photographic images of the individuals passing through, and I'm curious as to whether the photos were among the images that were stored.
I think I would be happier with these kind of scanners in airports than the active wave scanners. Some UK airports have also been taking photographs of travellers as they pass through the airport. As long as the photos aren't generally retained for too long, say 24 - 48 hours, that might also be acceptable.
Labels:
body scanners,
privacy,
technology,
United States
Tuesday, August 10, 2010
European Union Agency for Fundamental Rights: Document on Body Scanners
The European Union Agency for Fundamental Rights published a Q&A document on the use of full body scanners last month.
It addresses the following questions:
1. Which fundamental rights are at risk of being affected by the use of body scanners?
2. Is the use of a body scanner to be considered as processing personal data?
3. How could the requirements on the design and selection of body scanners best respect rules on data protection?
4. How can body scanners be assessed from a rule of law perspective?
5. Are there specific considerations to be taken into account when selecting people to be screened?
6. Should the person to be screened be given the choice between a body scanner and other screening methods?
7. Which information should be given to persons before they choose to be screened by a body scanner?
8. How intrusive are body scanners if compared to other screening methods?
9. Is the detection capability of body scanners an added value regarding security?
10. Which conditions should apply in order to address the concerns related to fundamental rights?
It addresses the following questions:
1. Which fundamental rights are at risk of being affected by the use of body scanners?
2. Is the use of a body scanner to be considered as processing personal data?
3. How could the requirements on the design and selection of body scanners best respect rules on data protection?
4. How can body scanners be assessed from a rule of law perspective?
5. Are there specific considerations to be taken into account when selecting people to be screened?
6. Should the person to be screened be given the choice between a body scanner and other screening methods?
7. Which information should be given to persons before they choose to be screened by a body scanner?
8. How intrusive are body scanners if compared to other screening methods?
9. Is the detection capability of body scanners an added value regarding security?
10. Which conditions should apply in order to address the concerns related to fundamental rights?
Labels:
body scanners,
data protection,
EU,
human rights,
law,
technology
Monday, August 9, 2010
News: US Marshalls Service stored more than 35,000 images from full body scanners
In a letter responding to a Freedom of Information Request from the Electronic Privacy Information Center, the US Marshalls Service indicated that it had a file of approximately 35,314 images from a Brijot Gen2 scanner that were created between 2 Feb. 2010 and 28 July 2010. In this instance, the machine was not being used for airport security but rather was installed at the security checkpoint of a Florida courthouse. Additionally, the letter indicated that there may have been other images stored by a scanner being tested at a federal courthouse in the District of Columbia. That machine was returned to the manufacturer once testing had been completed and “any images that may have been stored on that machine are therefore no longer under agency control.” No copies of images from that machine were stored by the agency, the letter states.
Labels:
body scanners,
privacy,
technology,
United States
Wednesday, July 28, 2010
News: Body Scanner Developments
EPIC points out that DHS announced last week it plans to roll out full body scanners (now known as “Advanced Imaging Technology” in TSA-speak) to 28 additional airports. Meanwhile, EPIC has attempted to bring an action to suspend use of the scanners, and a bill has been introduced in the US Senate (S.3536) that would require deployment of the scanners at all US airports by 2013.
In Switzerland, the Zurich Airport began a pilot test involving a single body scanner on 8 June 2010. The test involved the “second generation” system which uses the gingerbread-man-like display rather than an actual scan image. The pilot test was completed on 14 July 2010, and the Airport states that the use of the system enjoyed a high acceptance rate among passengers. The results from the test are being assessed, and future tests may take place, but there are currently no plans to acquire any scanners, the Airport reports.
In Switzerland, the Zurich Airport began a pilot test involving a single body scanner on 8 June 2010. The test involved the “second generation” system which uses the gingerbread-man-like display rather than an actual scan image. The pilot test was completed on 14 July 2010, and the Airport states that the use of the system enjoyed a high acceptance rate among passengers. The results from the test are being assessed, and future tests may take place, but there are currently no plans to acquire any scanners, the Airport reports.
Labels:
body scanners,
flight screening,
privacy,
Switzerland,
technology,
United States
Wednesday, July 21, 2010
News: Washington Post launches New Series on "Top Secret America"
For those who haven't already read about it on the LIFT, the Washington Post began a new series of reports and features this week highlighting the ballooning national security and intelligence apparatus in the US since Sept. 11. The main page of the project is accessible here.
One figure that stuck out for me was the claim that "[a]n estimated 854,000 people, nearly 1.5 times as many people as live in Washington, D.C., hold top-secret security clearances." (Found in this article)
Also have a look at the gallery of anti-deception technology.
One figure that stuck out for me was the claim that "[a]n estimated 854,000 people, nearly 1.5 times as many people as live in Washington, D.C., hold top-secret security clearances." (Found in this article)
Also have a look at the gallery of anti-deception technology.
Labels:
government,
national security,
surveillance,
technology,
United States
Monday, May 3, 2010
Israeli Security Expert Decries Body Scanners Before Canadian Parliament
The Vancouver Sun has reported that an Israeli security expert who assisted in the design of the security system at Tel Aviv's Ben Gurion International Airport suggested in parliamentary hearings that the deployment of body scanners is a “useless” waste of money.
“I don't know why everybody is running to buy these expensive and useless machines. I can overcome the body scanners with enough explosives to bring down a Boeing 747,” he is quoted as saying, “That's why we haven't put them in our airport.”
According to the story, a Canadian transport minister has defended the installation of body scanners at Canadian airports. Political scientist Mark Salter also reportedly testified that he viewed body scanners as a “genuine leap forward” in airline security. (Hat tip to unwatched.org)
“I don't know why everybody is running to buy these expensive and useless machines. I can overcome the body scanners with enough explosives to bring down a Boeing 747,” he is quoted as saying, “That's why we haven't put them in our airport.”
According to the story, a Canadian transport minister has defended the installation of body scanners at Canadian airports. Political scientist Mark Salter also reportedly testified that he viewed body scanners as a “genuine leap forward” in airline security. (Hat tip to unwatched.org)
Labels:
body scanners,
Canada,
flight screening,
Israel,
privacy,
technology
Friday, April 16, 2010
Data Mining on Facebook?
The Guardian has run a story on Facebook against the backdrop of the Ceop “panic button” proposal which reveals that the social networking site conducts algorithm-driven monitoring that “track[s] the behaviour of its users and flag[s] up suspicious activity.” OK, that sounds like data mining, but why is this story of relevance to counter-terrorism? Interestingly, the article states that "Facebook's international law enforcement is lead by Max Kelly, a former FBI agent who worked on cyber-crime and counter-terrorism before moving to Facebook five years ago." The article also discusses how Facebook interacts with law enforcement in the US and UK. It suggests that UK officials still feel Facebook doesn’t do enough to assist them and the UK public to protect the safety of children.
Tuesday, March 16, 2010
Friday, February 12, 2010
Millimetre Wave Scanners and Mastectomies
There's an interesting discussion piece on politicsdaily.com by a woman who whose breast surgery confused TSA officials following a 'full body scan' prompting further examination.
She is not upset about her experience, concluding simply that 'the takeaway here is, if you have fake body parts, you should be prepared to explain them to the full-body screening folks at the TSA.' However, a number of comments left underneath her article report terrible experiences of insensitive, and wholly avoidable treatment. A selection:
She is not upset about her experience, concluding simply that 'the takeaway here is, if you have fake body parts, you should be prepared to explain them to the full-body screening folks at the TSA.' However, a number of comments left underneath her article report terrible experiences of insensitive, and wholly avoidable treatment. A selection:
"Wow, I thought I was the only one. TSA in Tampa held me on display for about 20 minutes while they tried to figure out was was on my chest. I was put through the full body scanner also sans shoes. After I was finished, I was told "DO NOT MOVE!" "Ok, but can I please have my sandals, they have already been scanned?" 'DO NOT MOVE." I suppose they were busy, scanning another woman's BARE FEET." Ok, they were having communication problems with the guys in the little room. I figured they were laughing so hard at the scan they could not respond. I am a 66 year old grandmother, the scan had to be really exciting. After 20 minutes the "gentleman" returned and announced to all who were within a 100 foot radius, "There is something on her left breast." They must be fixated on left breasts. At that point I realized they were talking about my breast prothesis. I am a breast cancer survivor. I explained this and was told "DO NOT MOVE!" At this time, the TSA moron told another that she would have to pat me down. No, would you please step into a private area, just pat her down. I offer to whip it out. He was not happy with that idea. I understand security, but please, a little consideration. Would they stop a man with a penal implant? Doubtful. After all, this was a bomb of a boob."
"Okay, I have to comment. I had the same problem. When they did a biopsy to diagnose my breast cancer, they inserted a few metal clips to mark the place of the tumor. Because I went out of state for my mastectomy and reconstruction, I had to fly. And I had the same thing happen. Stopped at security for setting off a metal detector (this was before the full body scans) and then "searched" with the wand right there in the airport, in front of everyone...and she kept waving it over my left breast (yeah - my left, too) and saying, "It's something here." I kept telling them it was probably the surgical clip. I finally had to take out my mammograms (I'd brought the films for my surgeon, and thankfully, they were in my carry-on) and show them it was just a clip. It helped that my neighbor, who works for TSA, showed up about then and told them he knew me."
Labels:
body scanners,
privacy,
technology,
terrorism
Friday, February 5, 2010
U.S. Mobile Phone Provider Received Some 8 Million Requests for Geo-Locational Data
Chris Soghoian has an interesting blog post from December. While attending the ISS World conference (Intelligence Support Systems for Lawful Interception, Criminal Investigations and Intelligence Gathering), Chris heard some surprising things. Counsel for the US telecom company Sprint Nextel indicated in a presentation that, within the space of a year, the company had received some 8 million requests from law enforcement for geo-locational data associated with mobile phones on the company’s network. In the comments on the post, one person conjectures that those don’t represent requests on 8 million distinct individuals, and that supposition is corroborated by another Sprint representative. This makes sense since typically police will want to know a single suspect’s location at various times throughout the course of an investigation. They may even want to check location continuously at regular intervals, say, every 1-2 minutes, in order to essentially track the suspect’s every move. Given the price lists associated with obtaining this information from telecoms (see Chris' post), a question for economists is whether that kind of electronic tracking is more cost effective than simply assigning a police officer to tail the suspect. The answer may depend on the particular level of crime incidence within the police force’s jurisdiction. Where crime incidence is higher, it may be more “economical” to assign officers to walk the beat and be available for incident response as opposed to conducting surveillance. It’s also unclear whether the +/- 8 million requests include emergency calls, where the location of the caller is revealed in the event that he or she is unable to give locational details verbally. But another interesting revelation related to the 8 million or so requests concerns how those requests were made and processed: evidently, Sprint has set up a special network interface to allow police agencies to submit geo-locational queries via computer.
Monday, January 18, 2010
Focus on Full-Body Scanners
Since the Christmas Day plot, many voices on both sides of the Atlantic have called for increased use of full-body scanners—even to the point of having them replace the now traditional metal detector screening. But how do they work and what’s the fuss about?
Operation
There are full-body scanners that have been developed that use x-rays (generally referred to as “backscatter” scanners), but the scanners that have attracted so much attention in the media lately are millimeter wave scanners. These units rely on waves that lie somewhere between microwaves and infrared light on the frequency spectrum. According to this article from the Austrian newspaper, Der Standard, human bodies naturally emit millimeter waves. In order to produce a clear image, however, millimeter wave scanners using the so-called “active method” bombard the body with additional millimeter waves. These waves are able to pass through clothing, paper, and thin plastics but not through human bodies. Thus, the reception of these waves as they bounce back from the body can be used to construct a picture of the outer surface of the body and reveal unusual objects hidden beneath clothing. Apparently, “passive method” scanners, which merely read naturally occurring millimeter wave emissions, have been developed and used in some airports (See e.g., this article from heise online (in German)). However, I can imagine that these scanners may not produce images of the same clarity and/or may require longer screening times.
Are the “active method” machines safe?
The jury is still out. The German Federal Office for Radiation Protection indicated in an article in the sueddeutsche that existing wave research has tended to concentrate on testing the health risks of waves used in mobile devices such as mobile phones. Therefore, there isn’t a great deal of research available on the health impact of these millimeter wave frequencies. What scientists seem to agree on is that the waves won’t ionize atoms within the body like X-rays and thus won’t damage cells the way ionizing radiation does. Millimeter waves will, however, warm the tissues that they strike. What tissues they strike depends on the wavelength of the wave. These waves encompass a range of frequencies beginning somewhere around 10 gigahertz and ending somewhere around 10 terahertz. According to the article in the sueddeutsche, waves at the lower end of that spectrum could penetrate a few millimeters into the skin. I don’t know whether current models of scanners tend to use waves around one specific frequency, whether they always send out waves at various frequencies, or whether they have frequency settings which may be adjusted by the operator. This article on the German Wikipedia, however, indicates that different frequencies may be useful for detecting different materials. For one official of the German Federal Office for Radiation Protection, the “big question” is whether the waves could cause other biological effects in addition to warming—such as bringing components of skin cells into oscillation or causing changes within the blood as it flows through surface capillaries. He adds, however, that these questions are “pure speculation.” For me, the question that always arises with radiation exposure is whether more frequent exposure will pose risks that don’t present themselves in simple, short-term testing. It’s not inconceivable that frequent flyers may have to pass through such scanners 2-3 times within a 10 hour period on several occasions within a single month.
Privacy issues
There are obvious privacy issues connected with a scanner that produces images of the naked body. But apart from revealing intimate parts of the anatomy and physical anomalies that an individual might not want to bare, the scanners might also reveal details such as that the person has had a colostomy, has incontinence problems, or is menstruating. Cognizant of the privacy issues, developers of these scanners aimed to develop solutions that would address them. Initially, the idea was to place the person reviewing the images from the scanner in a separate location than where the actual scanning takes place. Thus, the person viewing the image would be unable to see “in the flesh” the individual with whom that image was associated. Additionally, algorithms were introduced to automatically blur faces (an example of an image with facial blurring can be seen here). In this way, the image reviewer would be unable to link the image to an actual person. Of course, the problem is that colostomy pouches, feminine hygiene pads, devices that deliver medications or insulin, and the like still might prompt an embarrassing or uncomfortable confrontation with security personnel at the screening location.
Scan Tech: The Next Generation?
What if we could remove the image reviewer? Could we design software to do the reviewing for us and indicate where suspicious things crop up? One project led by Loughborough University that we heard about at the first DETECTER meeting in Birmingham was aiming to develop just such a program—one that could distinguish a bottle from a handgun carried in the hand of an individual captured in video recordings. We also heard from one of the manufacturers of a millimeter wave scanner who indicated that they were working to develop that kind of technology, but that it hadn’t yet matured to where it could be implemented.
But news reports today suggest that this “second generation” technology is now available and pictures have emerged from Amsterdam’s Schiphol airport which feature just the kind of generic, impersonal gingerbread-man-like graphic that we had talked about in Birmingham (an example is available here with a close-up here). Areas of the body that hold suspicious objects are then highlighted on the graphic, so that security personnel can conduct a search of that area. Unlike the original setup, the system in Amsterdam displays the computer-generated “results” directly to the personnel manning the scanner.
There are a few things to point out about this second generation of scanning. First of all, just because pictures in the media show displays with the gingerbread man figure doesn’t necessarily mean that the viewing of the “raw” image—so to speak—has been eliminated altogether. Secondly, I’m a bit skeptical as to how well this software will perform as compared with a human viewer. It seems like getting the optimal set of algorithms would take countless test runs and tweaking, and I imagine that there would still be things that the software would miss but that a human reviewer would pick up on, as well as things that the software would catch that a human reviewer would miss or identify as harmless (like colostomy pouches). Which brings us to the third point—that the software-based solution might result in more uncomfortable confrontations with security than with the human reviewer. Lastly, the software would rely on raw data from the scanner, and it would still be theoretically possible for someone to “reconstruct” the image if that someone had access to the raw data.
Access and Data Storage
The Electronic Privacy Information Center (EPIC) has obtained documents from the US Transportation Security Administration pertaining to the procurement of full-body scanners (For links, see this post on the LIFT). The procurement specifications indicate that the TSA has put significant thought and planning into the implementation of these systems, including privacy safeguards. Nonetheless, EPIC points out that, despite TSA’s public assurances that scan images could not be saved, the documents reveal that the systems would be able to store images when in “test mode.” Granted, TSA foresees different levels of access to these systems. In this case, only TSA headquarters, maintenance technicians, and so-called “super users” would be able to put a scanner system into test mode, and image storage would be disabled during normal operation, according to the TSA’s procurement specifications (see pp. 4, C-1). A note in Appendix C of these specifications indicates that super user access for a particular system would be disabled once the system was installed, suggesting that these super users would be representatives of the equipment vendor responsible for the initial setup of the system. Thus, for normal operation on passengers, that would officially leave just TSA headquarters and technicians who would be able to place the system in test mode in which images would be stored.
Nonetheless, this news does indicate that the systems have storage capacity. The question is how much. By limiting the storage capacity to only a few images, the risk of negative privacy impact could be minimized. Of course, the flip-side of not saving images is that it rules out the possibility of performing ex post re-evaluations. Suppose another incident like that on Christmas Day occurs, but the attempted bomber had gone through a full-body scanner. Would security specialists want to take another look at that person’s scan image (supposing they can identify it) to see if they can learn something from the mistake?
Open or Closed Network(s)?
Related to the issue of access is the question of whether the system represents a closed system or is linked or exposed to broader communication networks such as the internet. At first glance, I don’t see too many reasons why these systems would need to be connected to the internet. The image reviewer would not need to read e-mail or access websites to do his or her work. One advantage of allowing internet communication is that it would permit quick, uniform updating of changes to user accounts from a central office. Thus, if an image reviewer left his or her position with the TSA, that former employee’s access could be lifted for all scanner systems throughout the country more or less simultaneously. It might also be desirable to have uniform access at all airports so that image reviewers could be shifted around according to need. On the other hand, these same objectives might be achieved through other systems, such as physical access controls—using an employee ID card or the like—that would prevent unauthorized personnel from entering image viewing facilities. However, the ability to access remotely every system’s system log would allow auditing to take place on a more efficient basis. Thus, this point would speak in favor of network access. But I’m not convinced that the burden of conducting audits on the local level would necessarily outweigh the benefit of the added security. Alternatively to local audits, audit data (which does not include image data) could be exported using flash drives or a temporary network connection.
There are indications that the TSA is opting for the fully linked system. The TSA’s procurement specifications for a “Whole Body Imager” state that the system should support a minimum user database of 10,000 accounts (p. 17). That’s an extremely high number for any single airport. Additionally, the TSA’s operational requirements call for the system to have an “802.11X compatible” network interface (p. 11). IEEE 802.11 denotes a set of wireless network protocols. Thus, the inclusion of this functionality within the operation requirements indicates that the TSA would like to ensure that these systems are capable of sending and receiving wireless communications. The operational requirements also call for the network interface to be “configurable with an IP address” (Ibid.). This requirement suggests that there would be internet access. Lastly, the documentation requires that the system be able to interface with “STIP” (Security Technology Integrated Program) (Ibid.), which appears to be the TSA’s enterprise architecture for allowing communication between detection technology instruments in the field and central headquarters (See this entry on the US government’s “IT Dashboard”).
Summing Up
In sum, health-related risks are probably minimal, but currently unknown. In light of this fact, why not simply use passive systems that rely on the human body’s own millimeter wave emissions to eliminate any possible health risk? In terms of privacy protections, replacing the human reviewer with software algorithms may reduce the privacy impact for many but increase it for others. Eliminating network access would also substantially lower the risk that scan images end up distributed where they don’t need to be but could hamper other aspects of operations. All of these considerations come on top of the questions concerning the scanners’ effectiveness and necessity (See the last full paragraph of this earlier post and this from the LIFT).
Operation
There are full-body scanners that have been developed that use x-rays (generally referred to as “backscatter” scanners), but the scanners that have attracted so much attention in the media lately are millimeter wave scanners. These units rely on waves that lie somewhere between microwaves and infrared light on the frequency spectrum. According to this article from the Austrian newspaper, Der Standard, human bodies naturally emit millimeter waves. In order to produce a clear image, however, millimeter wave scanners using the so-called “active method” bombard the body with additional millimeter waves. These waves are able to pass through clothing, paper, and thin plastics but not through human bodies. Thus, the reception of these waves as they bounce back from the body can be used to construct a picture of the outer surface of the body and reveal unusual objects hidden beneath clothing. Apparently, “passive method” scanners, which merely read naturally occurring millimeter wave emissions, have been developed and used in some airports (See e.g., this article from heise online (in German)). However, I can imagine that these scanners may not produce images of the same clarity and/or may require longer screening times.
Are the “active method” machines safe?
The jury is still out. The German Federal Office for Radiation Protection indicated in an article in the sueddeutsche that existing wave research has tended to concentrate on testing the health risks of waves used in mobile devices such as mobile phones. Therefore, there isn’t a great deal of research available on the health impact of these millimeter wave frequencies. What scientists seem to agree on is that the waves won’t ionize atoms within the body like X-rays and thus won’t damage cells the way ionizing radiation does. Millimeter waves will, however, warm the tissues that they strike. What tissues they strike depends on the wavelength of the wave. These waves encompass a range of frequencies beginning somewhere around 10 gigahertz and ending somewhere around 10 terahertz. According to the article in the sueddeutsche, waves at the lower end of that spectrum could penetrate a few millimeters into the skin. I don’t know whether current models of scanners tend to use waves around one specific frequency, whether they always send out waves at various frequencies, or whether they have frequency settings which may be adjusted by the operator. This article on the German Wikipedia, however, indicates that different frequencies may be useful for detecting different materials. For one official of the German Federal Office for Radiation Protection, the “big question” is whether the waves could cause other biological effects in addition to warming—such as bringing components of skin cells into oscillation or causing changes within the blood as it flows through surface capillaries. He adds, however, that these questions are “pure speculation.” For me, the question that always arises with radiation exposure is whether more frequent exposure will pose risks that don’t present themselves in simple, short-term testing. It’s not inconceivable that frequent flyers may have to pass through such scanners 2-3 times within a 10 hour period on several occasions within a single month.
Privacy issues
There are obvious privacy issues connected with a scanner that produces images of the naked body. But apart from revealing intimate parts of the anatomy and physical anomalies that an individual might not want to bare, the scanners might also reveal details such as that the person has had a colostomy, has incontinence problems, or is menstruating. Cognizant of the privacy issues, developers of these scanners aimed to develop solutions that would address them. Initially, the idea was to place the person reviewing the images from the scanner in a separate location than where the actual scanning takes place. Thus, the person viewing the image would be unable to see “in the flesh” the individual with whom that image was associated. Additionally, algorithms were introduced to automatically blur faces (an example of an image with facial blurring can be seen here). In this way, the image reviewer would be unable to link the image to an actual person. Of course, the problem is that colostomy pouches, feminine hygiene pads, devices that deliver medications or insulin, and the like still might prompt an embarrassing or uncomfortable confrontation with security personnel at the screening location.
Scan Tech: The Next Generation?
What if we could remove the image reviewer? Could we design software to do the reviewing for us and indicate where suspicious things crop up? One project led by Loughborough University that we heard about at the first DETECTER meeting in Birmingham was aiming to develop just such a program—one that could distinguish a bottle from a handgun carried in the hand of an individual captured in video recordings. We also heard from one of the manufacturers of a millimeter wave scanner who indicated that they were working to develop that kind of technology, but that it hadn’t yet matured to where it could be implemented.
But news reports today suggest that this “second generation” technology is now available and pictures have emerged from Amsterdam’s Schiphol airport which feature just the kind of generic, impersonal gingerbread-man-like graphic that we had talked about in Birmingham (an example is available here with a close-up here). Areas of the body that hold suspicious objects are then highlighted on the graphic, so that security personnel can conduct a search of that area. Unlike the original setup, the system in Amsterdam displays the computer-generated “results” directly to the personnel manning the scanner.
There are a few things to point out about this second generation of scanning. First of all, just because pictures in the media show displays with the gingerbread man figure doesn’t necessarily mean that the viewing of the “raw” image—so to speak—has been eliminated altogether. Secondly, I’m a bit skeptical as to how well this software will perform as compared with a human viewer. It seems like getting the optimal set of algorithms would take countless test runs and tweaking, and I imagine that there would still be things that the software would miss but that a human reviewer would pick up on, as well as things that the software would catch that a human reviewer would miss or identify as harmless (like colostomy pouches). Which brings us to the third point—that the software-based solution might result in more uncomfortable confrontations with security than with the human reviewer. Lastly, the software would rely on raw data from the scanner, and it would still be theoretically possible for someone to “reconstruct” the image if that someone had access to the raw data.
Access and Data Storage
The Electronic Privacy Information Center (EPIC) has obtained documents from the US Transportation Security Administration pertaining to the procurement of full-body scanners (For links, see this post on the LIFT). The procurement specifications indicate that the TSA has put significant thought and planning into the implementation of these systems, including privacy safeguards. Nonetheless, EPIC points out that, despite TSA’s public assurances that scan images could not be saved, the documents reveal that the systems would be able to store images when in “test mode.” Granted, TSA foresees different levels of access to these systems. In this case, only TSA headquarters, maintenance technicians, and so-called “super users” would be able to put a scanner system into test mode, and image storage would be disabled during normal operation, according to the TSA’s procurement specifications (see pp. 4, C-1). A note in Appendix C of these specifications indicates that super user access for a particular system would be disabled once the system was installed, suggesting that these super users would be representatives of the equipment vendor responsible for the initial setup of the system. Thus, for normal operation on passengers, that would officially leave just TSA headquarters and technicians who would be able to place the system in test mode in which images would be stored.
Nonetheless, this news does indicate that the systems have storage capacity. The question is how much. By limiting the storage capacity to only a few images, the risk of negative privacy impact could be minimized. Of course, the flip-side of not saving images is that it rules out the possibility of performing ex post re-evaluations. Suppose another incident like that on Christmas Day occurs, but the attempted bomber had gone through a full-body scanner. Would security specialists want to take another look at that person’s scan image (supposing they can identify it) to see if they can learn something from the mistake?
Open or Closed Network(s)?
Related to the issue of access is the question of whether the system represents a closed system or is linked or exposed to broader communication networks such as the internet. At first glance, I don’t see too many reasons why these systems would need to be connected to the internet. The image reviewer would not need to read e-mail or access websites to do his or her work. One advantage of allowing internet communication is that it would permit quick, uniform updating of changes to user accounts from a central office. Thus, if an image reviewer left his or her position with the TSA, that former employee’s access could be lifted for all scanner systems throughout the country more or less simultaneously. It might also be desirable to have uniform access at all airports so that image reviewers could be shifted around according to need. On the other hand, these same objectives might be achieved through other systems, such as physical access controls—using an employee ID card or the like—that would prevent unauthorized personnel from entering image viewing facilities. However, the ability to access remotely every system’s system log would allow auditing to take place on a more efficient basis. Thus, this point would speak in favor of network access. But I’m not convinced that the burden of conducting audits on the local level would necessarily outweigh the benefit of the added security. Alternatively to local audits, audit data (which does not include image data) could be exported using flash drives or a temporary network connection.
There are indications that the TSA is opting for the fully linked system. The TSA’s procurement specifications for a “Whole Body Imager” state that the system should support a minimum user database of 10,000 accounts (p. 17). That’s an extremely high number for any single airport. Additionally, the TSA’s operational requirements call for the system to have an “802.11X compatible” network interface (p. 11). IEEE 802.11 denotes a set of wireless network protocols. Thus, the inclusion of this functionality within the operation requirements indicates that the TSA would like to ensure that these systems are capable of sending and receiving wireless communications. The operational requirements also call for the network interface to be “configurable with an IP address” (Ibid.). This requirement suggests that there would be internet access. Lastly, the documentation requires that the system be able to interface with “STIP” (Security Technology Integrated Program) (Ibid.), which appears to be the TSA’s enterprise architecture for allowing communication between detection technology instruments in the field and central headquarters (See this entry on the US government’s “IT Dashboard”).
Summing Up
In sum, health-related risks are probably minimal, but currently unknown. In light of this fact, why not simply use passive systems that rely on the human body’s own millimeter wave emissions to eliminate any possible health risk? In terms of privacy protections, replacing the human reviewer with software algorithms may reduce the privacy impact for many but increase it for others. Eliminating network access would also substantially lower the risk that scan images end up distributed where they don’t need to be but could hamper other aspects of operations. All of these considerations come on top of the questions concerning the scanners’ effectiveness and necessity (See the last full paragraph of this earlier post and this from the LIFT).
Friday, January 8, 2010
News: Aiport Security Technology
Forbes has posted an interesting article today discussing various proposals for improving airport security, including behavioral analysis systems, physiological sensors, and increased use of profiling. One system being tested in Israel even sounds like psychological warfare—flashing images onto airport screens, “such as symbols associated with a certain terrorist group or some other image only a would-be terrorist would recognize” and then assessing individuals’ reactions to those images. The article also cites Jim Harper of the Cato Institute for suggesting that security be placed in the hands of the airlines in order to introduce more variation in security procedures.
Labels:
flight screening,
Israel,
profiling,
surveillance,
technology,
terrorism
Wednesday, January 6, 2010
Comment: Christmas Day Plot, Part I
“Failure to connect the dots” became a catch-phrase paraphrasing the mistakes within the intelligence community that permitted the 9/11 attacks despite the presence of intelligence within the possession of various US agencies that pointed toward the development of the underlying plot. This phrase has cropped up again in connection with the Christmas Day plot involving Northwestern Flight 253, leading to the question as to whether the lessons learned from the 9/11 review have been implemented.
As news of the attempted attack began to unfold, reports began to roll in that the individual behind the attempt, Umar Farouk Abdulmutallab, had raised a number of red flags which should have resulted in enhanced screening, potentially his detention for further investigation, or--as some have suggested--the denial of an entry visa for the US. First it was revealed that Abdulmutallab had been included in the National Counterterrorism Center’s TIDE (Terrorist Identitites Datamart Environment) database (more on TIDE in Part II) (See this story from CBS). Then, it came to light that Abdulmutallab’s father had approached US State Department officials in Nigeria with concerns that his son had “fallen under the influence of ‘religious extremists’ in Yemen” (See this story from CBS). According to a report from CBS News, this information was forwarded to officials in Washington (In fact, it may have been the basis for Abdulmutallab being entered in TIDE). Apparently, however, no flags were attached to Abdulmutallab’s US visa, and the CBS report suggests that US officials who had received information relating the father’s concerns did not realize that the individual in question had been issued a multiple-entry visa by the US Embassy in London that was valid from June 16, 2008 to June 12, 2010. Lastly, it has been reported that the NSA had identified communications among Al Qaeda members in Yemen concerning a plot involving a Nigerian (See articles here and here).
The Obama administration called for two reviews: one quick review of flight screening procedures and technologies, the other a more in-depth review of the terrorist watch list system in use in the US. President Obama has promised that the results of the reviews will be revealed in public reports in the near future. It will be interesting to see to what extent the details of what happened at each stage of Abdulmutallab’s journey will be released. For me, the following questions come up: 1) Were any personal data pertaining to Abdulmutallab submitted to the TSA before he boarded the flight from Nigeria? 2) What security procedures did Abdulmutallab undergo in Lagos (or Ghana)? 3) Was Abdulmutallab subjected to security procedures at Schiphol? It would be particularly interesting to know whether he underwent a full-body scan (such scanners are evidently in common use at Schiphol) (more on full-body scanning below)?
In this case, it isn’t clear to what extent fault can be found with US authorities. Clearly mistakes were made, but even if all the information on Abdulmutallab had come together and resulted in an operational decision, measures stemming from that decision would have to have been taken in Nigeria or the Netherlands in order to have been effective. The incident may primarily reflect the lack of uniform and coordinated procedures at the international level. The US has expressed the desire to receive passenger name records for all passengers who have booked flights to the US. Yet, the question arises as to how many airlines indulge that desire and with what level of accuracy. This requirement has been particularly contentious within the EU. However, given the fact that Abdulmutallab had booked passage with a US-based air carrier for the final leg of his journey, it seems likely that the US carrier submitted passenger record data on Abdulmutallab to the TSA. But again, even if the TSA had singled out Abdulmutallab for enhanced screening or identified him as being on the no-fly list, how does it ensure that Dutch or Nigerian airport security take appropriate action? If a Dutch or Nigerian equivalent of the TSA have special requests with respect to a particular passenger departing from the US en route to the Netherlands or Nigeria, would the TSA automatically comply in reciprocal fashion? Note that according to an editorial in the New York Times, the TSA can still request a US-bound flight to return to its point of departure if there is a suspicious passenger on board, but for long distance flights, this option may become unfeasible if the request is not received until later stages of the flight.
Suggestions for changes already began to be voiced soon after the incident. Among the calls for improvements to security that have emerged in public discourse, the notion of making more use of body scanners, such as millimeter wave scanners, has been particularly prominent--notably former US Department of Homeland Security Secretary, Michael Chertoff, has been among those advocating this move (see here) (although it later came to light that Chertoff’s company, the Chertoff Group, has a manufacturer of such machines as a client). Some commentators, however, have argued that such full-body scanners would have failed to detect the explosive device in this case. The Telegraph has cited two former US officials from counter-terrorism agencies for having long argued that swabbing for explosive substances and other chemicals is “cheaper, easier and more effective” than full-body scanners. In that article, Larry Johnson, former deputy director of Counter Terrorism at the US State Department was quoted as saying “[s]wabbing everyone is not hard and it’s just about the only way, short of making passengers fly naked and without luggage, of being reasonably sure they aren’t carrying a bomb.” Although swabbing would entail making bodily contact with the swabs, for some--if not most--it may raise fewer privacy concerns than the full-body scanners. The Telegraph article suggests that the swab tests would not need to be taken from the same part of the body or baggage where explosives were located. That means that contact with sensitive areas of the body could be avoided.
In Part II, I’ll discuss databases and watch lists.
As news of the attempted attack began to unfold, reports began to roll in that the individual behind the attempt, Umar Farouk Abdulmutallab, had raised a number of red flags which should have resulted in enhanced screening, potentially his detention for further investigation, or--as some have suggested--the denial of an entry visa for the US. First it was revealed that Abdulmutallab had been included in the National Counterterrorism Center’s TIDE (Terrorist Identitites Datamart Environment) database (more on TIDE in Part II) (See this story from CBS). Then, it came to light that Abdulmutallab’s father had approached US State Department officials in Nigeria with concerns that his son had “fallen under the influence of ‘religious extremists’ in Yemen” (See this story from CBS). According to a report from CBS News, this information was forwarded to officials in Washington (In fact, it may have been the basis for Abdulmutallab being entered in TIDE). Apparently, however, no flags were attached to Abdulmutallab’s US visa, and the CBS report suggests that US officials who had received information relating the father’s concerns did not realize that the individual in question had been issued a multiple-entry visa by the US Embassy in London that was valid from June 16, 2008 to June 12, 2010. Lastly, it has been reported that the NSA had identified communications among Al Qaeda members in Yemen concerning a plot involving a Nigerian (See articles here and here).
The Obama administration called for two reviews: one quick review of flight screening procedures and technologies, the other a more in-depth review of the terrorist watch list system in use in the US. President Obama has promised that the results of the reviews will be revealed in public reports in the near future. It will be interesting to see to what extent the details of what happened at each stage of Abdulmutallab’s journey will be released. For me, the following questions come up: 1) Were any personal data pertaining to Abdulmutallab submitted to the TSA before he boarded the flight from Nigeria? 2) What security procedures did Abdulmutallab undergo in Lagos (or Ghana)? 3) Was Abdulmutallab subjected to security procedures at Schiphol? It would be particularly interesting to know whether he underwent a full-body scan (such scanners are evidently in common use at Schiphol) (more on full-body scanning below)?
In this case, it isn’t clear to what extent fault can be found with US authorities. Clearly mistakes were made, but even if all the information on Abdulmutallab had come together and resulted in an operational decision, measures stemming from that decision would have to have been taken in Nigeria or the Netherlands in order to have been effective. The incident may primarily reflect the lack of uniform and coordinated procedures at the international level. The US has expressed the desire to receive passenger name records for all passengers who have booked flights to the US. Yet, the question arises as to how many airlines indulge that desire and with what level of accuracy. This requirement has been particularly contentious within the EU. However, given the fact that Abdulmutallab had booked passage with a US-based air carrier for the final leg of his journey, it seems likely that the US carrier submitted passenger record data on Abdulmutallab to the TSA. But again, even if the TSA had singled out Abdulmutallab for enhanced screening or identified him as being on the no-fly list, how does it ensure that Dutch or Nigerian airport security take appropriate action? If a Dutch or Nigerian equivalent of the TSA have special requests with respect to a particular passenger departing from the US en route to the Netherlands or Nigeria, would the TSA automatically comply in reciprocal fashion? Note that according to an editorial in the New York Times, the TSA can still request a US-bound flight to return to its point of departure if there is a suspicious passenger on board, but for long distance flights, this option may become unfeasible if the request is not received until later stages of the flight.
Suggestions for changes already began to be voiced soon after the incident. Among the calls for improvements to security that have emerged in public discourse, the notion of making more use of body scanners, such as millimeter wave scanners, has been particularly prominent--notably former US Department of Homeland Security Secretary, Michael Chertoff, has been among those advocating this move (see here) (although it later came to light that Chertoff’s company, the Chertoff Group, has a manufacturer of such machines as a client). Some commentators, however, have argued that such full-body scanners would have failed to detect the explosive device in this case. The Telegraph has cited two former US officials from counter-terrorism agencies for having long argued that swabbing for explosive substances and other chemicals is “cheaper, easier and more effective” than full-body scanners. In that article, Larry Johnson, former deputy director of Counter Terrorism at the US State Department was quoted as saying “[s]wabbing everyone is not hard and it’s just about the only way, short of making passengers fly naked and without luggage, of being reasonably sure they aren’t carrying a bomb.” Although swabbing would entail making bodily contact with the swabs, for some--if not most--it may raise fewer privacy concerns than the full-body scanners. The Telegraph article suggests that the swab tests would not need to be taken from the same part of the body or baggage where explosives were located. That means that contact with sensitive areas of the body could be avoided.
In Part II, I’ll discuss databases and watch lists.
Monday, October 19, 2009
News: More on facial recognition technology
According to a report from USA Today, the FBI has begun trials of facial recognition technology in North Carolina. Reportedly, the trials helped to identify a suspect to a double homicide who had seemingly relocated to North Carolina from California and assumed a false name. FBI officers took a photo from the suspect’s California driver’s license and ran it against the photos contained in North Carolina’s Department of Motor Vehicles database. From “dozens” of potential matches, an FBI investigator zeroed in on one particular individual. That individual has now been placed under arrest. Marc Rotenberg of EPIC, however, questioned how effective the use of such technologies will be in counter-terrorist efforts since good photos of terrorists will rarely be available in DMV databases or elsewhere.
Labels:
biometrics,
databases,
facial recognition,
national security,
privacy,
technology,
terrorism
Subscribe to:
Posts (Atom)