Showing posts with label Online Privacy. Show all posts
Showing posts with label Online Privacy. Show all posts

Friday, September 24, 2010

Email, Cloud, Privacy and the ECPA

Congress passed the Electronic Communications Privacy Act (ECPA) in 1986. This federal law is comprised of three different Acts: the Wiretap Act, amending Title III of the Omnibus Crime Control and Safe Street Act of 1968, the Stored Communication Act (SCA), and the Pen Register Act.

It is now time to reform the ECPA, and this reform is on Congress’ agenda. The House of Representative Committee on the Judiciary, Subcommittee on the Constitution, Civil Rights, and Civil Liberties, heard testimonies on September 23 regarding “ECPA Reform and the Revolution in Cloud Computing.”

The Fourth Amendment of the United States Constitution guarantees the “right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures.” The Supreme Court held in Katz v. United States, that the government cannot eavesdrop on telephone communications held in a place where one has an actual (subjective) expectation of privacy that society is prepared to recognize as reasonable (J.Harlan, concurring).The Court noted that it had emphasized “over and again… that the mandate of the [Fourth] Amendment requires adherence to judicial processes, and that searches conducted outside the judicial process, without prior approval by judge or magistrate, are per se unreasonable under the Fourth Amendment subject only to a few specifically established and well-delineated exceptions…” Indeed, pursuant to the Fourth Amendment, warrants may only be issued upon probable cause, and must “particularly describe the place to be searched, and the persons or things to be seized.”

In Berger v. New York, the Supreme Court emphasized that “the need for particularity and evidence of reliability in the showing required when judicial authorization of a search is sought is especially great in the case of eavesdropping. By its very nature eavesdropping involves an intrusion on privacy that is broad in scope…”

Enacted after Katz and Berger, Title III of the Omnibus Crime Control and Safe Streets Act of 1968 (the “Wiretap Act”), as amended in 1986 by the ECPA, defines electronic communication as “any transfer of signs, signals, writing, images, sounds, data, or intelligence of any nature transmitted in whole or in part by a wire, radio, electromagnetic, photoelectronic or photooptical system that affects interstate or foreign commerce, but does not include — (A) any wire or oral communication.”18. U.S.C. §2510(12) Electronic storage is defined as “(A) any temporary, intermediate storage of a wire or electronic communication incidental to the electronic transmission thereof; and (B) any storage of such communication by an electronic communication service for purposes of backup protection of such communication.” 18. U.S.C. §2510(17)

The ECPA was enacted in 1986 to set a "fair balance between the privacy expectations of American citizens and the legitimate needs of law enforcement agencies." (Senate Report No. 99-541, 99th Cong., 2d Sess. 5 (1986). At this time, only a few Americans had heard about the Internet. Storing data was expensive. In his testimony, Richard Salgado, Google’s Senior Counsel, Law Enforcement and Information Security, noted that it took $650 in 1986 to buy a 10 megabyte hard drive with room to store “about two high resolutions photos”, whereas today it will cost less than $100 to buy a 1.5 terabyte hard drive !

Data was not tucked in a cloud. A Gartner survey showed this month that cloud-computing services represents in 2010 10 percent of spending on external IT services. A Pew Research Center survey revealed in 2008 that 69% of only Americans store data online or use a web-based software application.

New technologies, new privacy challenges. In his testimony, Michael Hintze, Microsoft Associate General Counsel, argued that the ECPA, since having been enacted in to law in 1986, has failed to keep pace with technology. He took the example of the difference made by the ECPA between emails stored for less than 180 days and those stored for more than 180 days, and concluded that this distinction no longer makes any sense.

Indeed, the SCA, as codified at 18. U.S.C. §2703 (a), allows the government to require the disclosure by an electronic communication service provider of the contents of a wire or electronic communication that is in electronic storage in an electronic communications system for 180 days or less, but only if the government first obtains a federal or state court-issued warrant. If the data has been in storage for more than 180 days, the government can require the provider to disclose the data without prior notice to the subscriber or customer if it first obtains a federal or state court-issued warrant. If the government provides prior notice to the subscriber or customer, the government must still obtain (i) an administrative subpoena authorized by a Federal or State statute or a Federal or State grand jury or trial subpoena; or (ii) obtain a court order for such disclosure. 18. U.S.C. §2703 (b)

Therefore the ECPA provides more protection for emails stored for less than 180 days, than for emails stored for more than 180 days. That made sense in 1986, when storing data was extremely costly, but we are now living in a world where some of us keep emails for months, sometime years, tucked in the cloud. Should the privacy of these emails be less protected than when they were first arrived in our mailboxes?
The first version of Microsoft Exchange was released in 1996. The user was able to download emails from a server to a local machine. One could then conceive that an email which had not been downloaded after 180 days had been abandoned by the recipient, and thus had no expectation of privacy in the message. However, Hotmail, offered for the first time in 1997, stored emails in the cloud. The cloud retained the message even after its intended recipient had read it. Yet, data storing capacity was still limited in 1997, but it is no longer the case. Mr. Hintze concludes that users reasonably expect their data to be as private on day 181 as it is on day 179. It is hard to disagree with that statement.

A coalition of companies and non-profit organizations, the Digital Due Process Coalition, has also been advocating SCA reform. Members of the coalition include among others, the American Civil Liberties Union, the Center for Democracy and Technology, the Electronic Frontier Foundation, Google, Microsoft, IBM, and AT&T.

The coalition recommends the Act to be reformed so that the government could only require electronic communications providers to give it access to the non-public content of communications if producing a search warrant based on probable cause, and this “regardless of the age of the communication, the means or status of its storage or the provider’s access to or use of the content in its business operations.” (see p. 5 of Becky Burr, ECPA: PRINCIPLES FOR REFORM)

Sunday, May 23, 2010

Data as speech: we could become our own censors, in the name of privacy

The Electronic Frontier Foundation published on its site this week a proposal for “A Bill of Privacy Rights for Social Network Users.”

After Facebook (numerous) privacy policy changes which occurred recently, and the recent report in The Wall Street Journal that advertising companies were receiving information from Facebook and MySpace that could be then used to look up individual profiles, we certainly need to reassess the rights of social media users.

As a privacy advocate, I certainly applaud the proposed EFF bill of privacy rights. Privacy needs to be protected, especially online. It seems that social media users also need to be protected from themselves, and the right to delete embarrassing picture is certainly appealing.

But if I wear my First Amendment advocate hat, number 3 on the bill of privacy rights, The Right to Leave, does not seem to be such a good idea.

The author of the Bill, Kurt Opsahl, summarizes point 3 in this formula: “Users giveth, and users should have the right to taketh away."Social media users should have “the right to delete data or her entire account from a social network service.”

If I delete my data, should I have the right to take everything with me, including what I have posted on a friend’s wall? This is data, sure, but it is also speech after all.

I am not sure if the bill of privacy rights would cover only personal data. Point 3 refers to “data” or “uploaded information.” It could mean only personal data, but it could also mean all the information I have posted on social media sites, whether on my page, or on other’s people’s page. If the user chose to delete all of the information she uploaded over time on the social network, doesn’t this give her a right to censor other people speech?

Should we have a right to be forgotten online? Of course, we have the right to change opinion, anytime. You know how the saying goes, “Only stupid people never change their opinion,” and it is quite true. Having an opinion is one of the most difficult things one can achieve, and informing oneself, weighting different aspects of an issue, making a decision, should not be a process set in stone. A new piece of information, a new technology, a new event, may entice us to change opinion.

And we have opinions about just anything, right? Let’s just say I wrote years ago on my BFF’s Facebook wall: “I just so love kittens and sunsets on the beach!” Well, I have since changed my mind, and I now make a living in Alaska raising dogs. My formerly-professed love of kittens could damage my professional reputation.

This is just an opinion, and it is not defamatory, just maybe embarrassing for me. Should I be able to take these comments away, when I leave the site? What if my BFF had answered me: ”I love them too !” Her comment is now left tangling in cyberspace…

And should this Bill of Privacy Rights also apply to Twitter? Actually, that would be impossible right now, as Twitter has donated its entire archive of tweets to the Library of Congress.

According to Librarian of Congress James H. Billington: "The Twitter digital archive has extraordinary potential for research into our contemporary way of life. (...) The collection also documents a remarkable range of social trends. Anyone who wants to understand how an ever-broadening public is using social media to engage in an ongoing debate regarding social and cultural issues will have need of this material."

Our tweets are valuable speech indeed, and even the most mundane of tweets (aka the infamous what-I-ate-for-lunch tweet) could have great importance in the future.OK, so maybe Twitter is not a traditional social network site, and may be better defined as a micro-blogging, everything-is-public site, but it has a lot of social networking aspects.It also has been used, and probably will be used again, by eye witnesses to report important events instantly. Should they later be allowed to take this data away?

Should we have a right to be forgotten online? There is a bill recently introduced in the House that would allow us to be forgotten online. H.R.5108, the Cyber Privacy Act Bill, would “require certain Internet websites that contain personal information of individual's to remove such information at the request of such individuals.” The Act would define “personal information” as “any information about an individual that includes, at minimum, the individual's name together with either a telephone number of such individual or an address of such individual”.

The sponsors of this bill probably have in mind the protection of privacy, again, a very worthy cause! However, couldn’t this bill, if enacted, be used to have one’s name deleted from a message we have posted? (I love kittens, signed Jane Smith)

Friday, May 07, 2010

A Few Comments About the Privacy Bill Draft

A draft of a privacy bill which will be presented later this year by Representative Rick Boucher (D-Virginia) and co-sponsored by Representative Cliff Stearns (R-Florida) has been released this week.

Companies and nonprofit organizations, and generally “any person” collecting personal information from at least 5,000 people, would have to follow new privacy rules. If the information collected is “sensitive”, that is, medical records, financial records, or precise geolocation information, even an entity collecting information from fewer than 5,000 people would have to follow these rules. They would not apply, however, to governments agencies. (p.2)

Geolocation information

“Precise geolocation information” would be considered sensitive information, just as your bank records, or your patient’s file. What makes it sensitive is not the nature of the information (after all, everybody around me knows my geolocation when I stand on line for my morning coffee and bagel), but the fact that the information is collected, kept, and linked with a name, at least with an avatar.

Companies are more and more interested in knowing their (future) customer’s locations. Facebook will soon propose a check-In’ app in partnership with McDonald’s. Customers will be able to “check in” at McDonald, and their location will then appear on their Facebook page, complete with an ad featuring a McDonald product. Such application is likely to allow McDonald to know precisely when and where any customer using the app has visited one of their restaurants.

Render anonymous

The bill defines “render anonymous” as “remov[ing] or obscure[ing] covered information such that the remaining information does not identity and there is no reasonable basis to believe that the information can be used to identify [an individual or a computer/device used by a particular user.]" (p.6)

If “reasonable basis” is the benchmark used to assess whether an information is indeed anonymous, one can safely contend that it should be "reasonable” to take into account the paper written by Arvind Narayanan and Vitaly Shmatikov which proves that even anonymous data can be “re-identified” by using a specific algorithm.

Covered entities privacy policies must include how they render information anonymous after the expiration of the retention period. (p. 10). As we know, merely deleting name and addresses is not enough to make data anonymous. Remember in 2006 when New York Times journalists were able to identify an AOL user just by analyzing her different queries, even though the data had been rendered "anonymous” by AOL.

Covered entities would now have to delete or render anonymous any covered information, no later than 18 months after the date the covered information is first collected. (p.17)

Privacy notice

If the information is collected on the Internet, a privacy policy must be posted on the entity's website “clearly and conspicuously” and must be accessible through a direct link from the Internet home page of the covered entity.”

However, if the information is collected manually, the privacy notice must be made available to the individual, in writing, before the information is collected
The privacy notice must include how the information is collected the specific purpose for which the information is collected, and how the information is stored.

It also must inform the individual on how the entity may merge, link or combined his information with other information about him that the entity could obtain from third parties. This is very important as merging information from different sources allows for the building of digital files about one individual.

The policy must inform the individual on how to contact the entity, but also must contain either a hyperlink or a toll-free number for contacting the Federal Trade Commission. (p.11) This is a good point, as many consumers still do not know the role the FTC plays in defending their rights.

Opt-in?

The individual would have the option to opt-out. The entity must inform him of this option. The individual then either consents or decline consent. (p.12)

“Either”… Who has the power to choose between either opting-in or opting-out? If it is the entity, it is likely that it will always prefer to only allow the individual to opt-out. Opting-is much more protective for consumers. So, why use “either”? I am not sure why, and this point deserves clarification.

Opt-out

If the entity chooses the opt-out option, it must be done through a “readily accessible opt-out mechanism.”(p. 17)

Thursday, March 18, 2010

FCC Broadband Plan and Privacy

The FCC presented this week its much-awaited National Broadband Plan.

Parts of the plan deal with online privacy, as broadband makes collection of personal data easier.

The FCC notes (Chapter 4, p.53) that “the emergence of broadband and the growing use of the Internet make aggregation of detailed personal data much easier and more valuable.” Since it is now easy to collect data from Internet site visitors, even single companies have the power to collect, aggregate and analyze massive amounts of personal data, allowing them to create a “digital identity,” that is, a very detailed picture of an individual, from his geographic location, his health, his eating and entertainment tastes, and so on.

This data is of great value to marketers, allowing them to target specific ads based on these digital identities, making it six times more likely, according to the FCC, that a consumer thus targeted will click on an ad.

The FCC is concerned about the impact that the ability of gathering these digital identities will have on competition. On one hand, companies already in the market have collected this massive amount of data over the years, allowing them to fine tune their marketing strategy. Indeed, according to the plan, this data is so valuable that these companies “increasingly offer their products and services free of any monetary charges. Consumers gain access to a valuable service, and businesses gain valuable information.”

In exchange for giving companies access to our personal data, consumers gain free products and services: I have a lot of problem with that statement. Let’s consider that personal data has a market value, allowing us to trade it for free products. Well, personal data does not have a sustainable value. The scenario "trade it once, lose it for ever" is a real possibility, as it is very easy to copy digital data. Like copyright pirates, we could see the emergence of data pirates. So, increasingly, as I trade more and more of my personal information, I will have less and less info to trade for these free products, and that may prevent me from dealing effectively in the market.

True, we evolve constantly as human beings, and new data is added to our digital identify every day. However, not every new data has the same value: the fact that Jane discovered that indeed Strawberry Swirl is her favorite ice cream flavor is not as important for her, nor as important for a marketer, as the fact that she will give birth to triplets in the Fall.

New firms without access to these detailed “digital identities” face competive challenges: The report goes on by noting that since new firms have not yet gathered these digital identities, they cannot monetize their audience through advertising and thus are facing competitive challenges.

The solution, according to the plan, is giving individuals control of their digital profiles: “Giving consumers control of their digital profiles and personal data, including
the ability to transfer some or all of it to a third party of their choice, may enable the development of new applications and services, and reduce barriers to entry for new firms.”

But is it really possible to transfer data to a third party without that data loosing some of its value? Our data has already been traded by Firm number 1 to an advertiser. If Firm number 2 comes later and proposes the same product, our digital identity, to the same advertisers, isn’t the value of our data then lower? Just as a digital photograph, digital personal information can be copied and stored instantly. True, Firm number 2 may have gathered more information on us, but if individuals keep “reselling” their digital profiles to every company in the open market, these profiles will lose their value, as every advertiser will be able to gain access to them, and thus none of them will have any longer the competitive advantage of knowing its target audience with such precision. Every firm will have that power, and the value of our digital identity will be diluted, thus impairing our own ability to trade it.

Twitter

Blog Archive

AddThis Social Bookmark Button

Labels