Wednesday, November 18, 2009

Comment: What's Worse?

The discussion of the UK plans for the 'Big Brother Database' has me wondering: What's worse, centralised storage of this communications data, or forcing ISPs and Mobile Phone companies to hold on the data for long periods of time?

Clearly this data is incredibly sensitive, and there are good reasons to want to restrict anyone's access to it. But, were such information to be stored, what would be worse? The idea of a centrally held database tends to make for bigger headlines, calling to mind, as it does, the vision of faceless government bureaucrats poring over our intimate secrets.

And the risk of government officials abusing such private information is indeed one of the reasons one would want to restrict access. But it's only one of the reasons. Surely another is the risk of any sort of public disclosure of this information. It is intrusive for anybody I haven't chosen to do so to view information about who I telephone or what websites I visit. But this information tends to be of much more interest to our neighbours, friends and work colleagues and of virtually zero interest to government. In deciding which is worse, one of the matters I think we should consider is which arrangement makes it less likely for some data breach to result in unauthorised access to my data.

Some will point to the many cases where various levels of government have proven hopelessly careless with our information (to the point of accidentally releasing vetting records with details of debt, extra marital affairs, drug use and use of prostitutes). But I don't think we can simplify this to a case of 'private sector good, public sector bad': some of the most notorious cases of releasing private information have been the fault of businesses - just think of the AOL scandal when records of people's searches were released, to remain posted in the internet to this very day. Private companies have a commercial interest in avoiding such scandals, to be sure, but is that any safer than trusting it to government?

Comment: UK Gov Plans Shelved

The shelving of plans for the Interception Modernisation Programme (IMP) has been reported in a number of different ways. According to the Independent this was effectively 'a cancellation of the Big Brother database' while the BBC reported that the UK surveillance plan was 'to go ahead'. In this confusion Slashdot resorted to the headline 'In the UK, Big Brother Recedes and Advances'.

I think the Register has this one right. The post makes three points:

1) Next years general election (probably to take place in May) makes this a bad time to bring forward legislation that might provoke negative headlines. (Henry Porter has a nice point about the timing as well: with all the recent column inches covering the 20th anniversary of the Berlin Wall coming down, proposing big increases in surveillance invites comparisons with the Stasi all too easily).

2) Internet Service Providers, whose cooperation is needed for the scheme, are currently resistent. Before proceeding, government has to convince them of its merits and feasibility.

3) The players who want this (GCHQ, SOCA, ACPO, the Security Service, the Child Exploitation and Online Protection Agency and the Met) are not going away anytime soon:

Note that GCHQ and friends will still be around after the next election, as will their demands for IMP.

Ever the political pragmatists, the Tories know this well, and the section of shadow justice minister Dominic Grieve's recent speech on reversing the rise of the surveillance state was notably soft on IMP.

He said a Conservative government would submit the proposals to the Information Commissioner's Office to assess their impact on privacy. The ICO has already said it believes the case for mass surveillance of the internet has not been made.

News: UK Gov Plans to Snoop on Internet and Mobile Use Shelved

From the Guardian: a previously mooted £2bn surveillance project for keeping tabs of all British citizens' email, internet use, mobile calls and texts, is to be left out of the upcoming Queens Speech, laying out the legislative plans for the coming year:

The Home Office ditched plans earlier this year for a central database tracking all phone, text, email and internet use. Instead ministers want internet service providers and phone companies to store this data for access by police and security services. The data includes who contacts whom, when, where and how – but not the content of what was said or written.

The Home Office summary of the responses to its consultation published shows that the internet and phone industry want assurances that they will be compensated for the costs involved and also fear technical problems.

Monday, November 16, 2009

Inadequate Information Sharing Again Cited as Key Problem

In the recent Fort Hood shooting incident, inadequate information sharing is again being cited as a critical flaw in government strategies to prevent acts of violence. The gunman, Maj. Nidal Malik Hasan, had come onto the FBI’s radar screen when he established contact with a radical imam believed to have ties to al Qaeda. When Hasan later underwent an FBI background check in the process of purchasing the firearm, which authorities believe he later used to open fire on soldiers at the Fort Hood base, the fact that Hasan was purchasing a gun was not shared with the Joint Terrorism Task Force (led by the FBI). The FBI, meanwhile, has issued a statement that their investigation had concluded that Hasan “was not involved in terrorist activities or terrorist planning.” Additionally, at least one military investigator was involved in that investigation, however, the fact that Hasan was under investigation was not communicated generally to military officials (see this story from ABC); that kind of disclosure beyond the Task Force requires the authorization of the Task Force supervisor from the FBI (see FBI Statement).

Monday, November 9, 2009

News: Resolution on International Privacy Standards Adopted

A resolution for International Standards on the Protection of Personal Data and Privacy was adopted at the 31st International Conference of Data Protection and Privacy Commissioners. A copy of the Resolution is available in Spanish here.