Showing posts with label Facebook. Show all posts
Showing posts with label Facebook. Show all posts

Sunday, November 30, 2014

Unconscionable political exploitation of Lee Rigby murder

Copy of my article in The Conversation about the ISC report into Fusilier Rigby's murder below.

The Intelligence and Security Committee (ISC) of Parliament has now released its 191-page report into Lee Rigby’s murder. The report concludes that even though the ISC “discovered a number of errors,” the murder could not have been prevented by the intelligence and security services.

Instead, the blame seems to have been put decisively on Facebook, which one of Rigby’s killers apparently used to discuss “killing a soldier” several months prior to the murder. This despite the fact that the security services were apparently well aware of the killers and their motives, independent of their social media presence.

Michael Adebolajo, the controlling mind in the murderous attack on Fusilier Lee Rigby, was first arrested in 2006 at a protest against Danish cartoons he perceived to be insulting to the prophet Muhammad. By the autumn of 2008, he was on MI5’s radar as having potential connections with al-Qaeda and by 2011 was the object of close surveillance.

Between then and April 2013 – when the intensive surveillance of Adebolajo was cancelled since there was “no indication of a national security concern” – he had multiple encounters with police and security services. A month later, Rigby was brutally murdered.

 

Counter-claims

Adebolajo claims MI5 attempted to recruit him as an informant – claims the UK government refuses to comment on, citing national security – and accuses MI6 of tacit complicity in alleged beatings and torture threats he received when detained by Kenyan police in 2010. He had travelled to Kenya with the apparent intention of joining extremists in Somalia.

Adebolajo’s partner in the murder, Michael Adebowale, came to MI5’s attention in August 2011 as a result of his interest in online extremist material and the intelligence services were aware of the two’s close connections. They nevertheless eventually considered Adebowale a low-level threat unworthy of their continuing attention.

By detailing various communications problems between police and security services and between the various branches of the intelligence services themselves and the inferences drawn from knowledge of the activities of Lee Rigby’s attackers, the report does a decent job of illustrating that security and intelligence systems are imperfect.

We can never be 100% secure, because these systems and agencies can and do fail – they fail naturally through human and technical and communications errors and they can be made to fail by actors with malign and, in this case, murderous intent.

What seems odd about the report and the ensuing media frenzy, however, is how Facebook has been framed as the single entity that could have prevented the murder.

Paragraph 17 of the report notes:
We have found only one issue which could have been decisive. This was the exchange – not seen until after the attack – between Adebowale and an individual overseas (FOXTROT) in December 2012. In this exchange, Adebowale told FOXTROT that he intended to murder a soldier. Had MI5 had access to this exchange, their investigation into Adebowale would have become a top priority. It is difficult to speculate on the outcome but there is a significant possibility that MI5 would then have been able to prevent the attack.
Paragraphs QQ to VV of the recommendations and conclusions go into this claim in a little more detail, saying: “Adebowale expressed his desire to murder a soldier “in the most explicit and emotive manner.” It then criticises US big tech companies for their lack of cooperation with government on fighting terrorism.

Happy though I usually might be to criticise Facebook or big tech – if more for their own anti-privacy practices than their lack of co-operation in counter-terrorism – it’s a bit of a stretch to suggest a giant beam of enlightenment would have engulfed the security services if Facebook had only shouted loudly enough, “look at this!”.

They were already aware of extreme views expressed by Adebowale on the net – and even Adebolajo, considered the more dangerous of the pair, was providing no continuing indication of a national security concern.

Brazen

For David Cameron and Theresa May to turn the deranged murder of a young soldier by damaged extremists into a political device for rehashing discredited surveillance proposals is unconscionable. It’s also not supported by the report: two members of the ISC have already criticised the notion that their work supports the further expansion of surveillance powers the government is now proposing.

Of course, with an election round the corner, we should hardly be surprised that party managers might be encouraging senior figures to ramp up their “tough on terrorism” rhetoric. The sad thing is to see how the media has uncritically swallowed the “blame Facebook” mantra hook, line and sinker.

Lee Rigby, who dedicated his life to defending the freedoms we enjoy in the UK, deserves better from our political leaders, from our media outlets and frankly, from all of us.

Wednesday, June 18, 2014

Irish High Court refers Schrems Facebook privacy case to ECJ

The Irish High Court has this morning referred Max Schrems Facebook privacy case to the European Court of Justice. Judge Hogan (at p33) refers the following specific questions -
Whether in the course of determining a complaint which has been made to an independent office holder who has been vested by statute with the functions of administering and enforcing data protection legislation that personal data is being transferred to another third country (in this case, the United States of America) the laws and practices of which, it is claimed, do not contain adequate protections for the data subject, that office holder absolutely [sic] bound by the Community finding to the contrary contained in the Commission Decision of 26 July 2000 (2000/520/EC) having regard to Article 7 and Article 8 of the Charter of Fundamental Rights of the European Union (2000/C-364/01), the provisions of Article 25(6) of Directive 95/46/EC notwithstanding? Or, alternatively, may the office holder conduct his or her own investigation of the matter in the light of factual developments in the meantime since that Commission Decision was first published?
Judge Hogan's summary of overall conclusions runs from paragraphs 74 to 84.
"74... Mr Schrems' complaints are not "frivolous or vexatious"...
 75... Mr Schrems enjoys locus standi to bring this complaint and to bring these proceedings. It is irrelevant that Mr Schrems cannot show his own personal data was accessed in this fashion by the NSA, since what matters is the essential inviolability of the personal data itself. The essence of that right would be compromised if the data subject had reason to believe that it could be routinely accessed by security authorities on a mass and undifferentiated basis.
76... the evidence suggests that personal data of data subjects is routinely accessed on a mass and undifferentiated basis by the US security authorities.
77... as far as Irish law is concerned, s. 11(1)(a) of the 1988 Act forbids the transfer of personal data to a third country unless it is clear that that jurisdiction sufficiently respects and protects the privacy and fundamental freedoms of the data subjects. In this particular context of national law, the standards in question are contained in the Constitution.
78... the chief constitutional protections are those relating to personal privacy and the inviolability of the dwelling. The general protection for privacy, person and security which is embraced by the "inviolability"  of the dwelling in Article 40.5 of the Constitution would be entirely compromised by the mass and undifferentiated surveillance by State authorities of conversations and communications which take place within the home. For such interception of communications to be constitutionally valid, it would, accordingly, be necessary to demonstrate that this interception and surveillance of individuals or groups was objectively justified in the interests of suppression of crime and national security and, further, that any such interception was attended by appropriate and verifiable safeguards."
Just an aside on that last sentence in that paragraph - it could be interpreted as reading that surveillance would be justified "in the interests of suppression of ... national security". Let's just assume that's not what the good judge was attempting to convey.
"79... if the matter were to be measured solely by Irish law and Irish constitutional standards, then a serious issue would arise which the Commissioner would then have been required to investigate as to whether US law and practice in relation to data privacy, interception and surveillance matched those data standards."
(The "Commissioner" referred to is the Irish Data Protection Commissioner).

In paragraph 80 Judge Hogan explains, however, that Irish standards are effectively bypassed by the data protection directive and the European Commission's Safe Harbour agreement with the US; and the EC 2000/520/EC decision essentially declaring the US privacy-safe territory for EU personal data.
"81... it follows, therefore, that if [my emphasis] the Commissioner cannot look beyond the Commissions Safe Harbour decision of July 2000, then it is clear that the present application for judicial review must fail... because the Commission has already decided that the US provides an adequate level of data protection...
82... in holding that the complaint was unsustainable in law, the... Commissioner has ... demonstrated scrupulous steadfastness to the letter of the 1995 Directive and the 2000 Decision.
83... the applicant's objection is, in reality, to the terms of the Safe Harbour Regime itself rather than to the manner in which the Commissioner has applied the Safe Harbour Regime...
84... the critical issue which arises is whether the proper interpretation of the 1995 Directive and the 200 Commission decision should be re-evaluated in light of the subsequent entry into force of Article 8 of the Charter and whether, as a consequence, the Commissioner can look beyond or otherwise disregard this Community finding. It is for these reasons accordingly that I have decided to refer this question (and other linked questions) to the Court of Justice..."
My brief take -

The Irish High Court's decision amounts to a critique of mass and undifferentiated surveillance by state authorities, particularly the US. However, the much maligned Irish Data Protection Commissioner, Billy Hawkes, gets a pat on the back in rejecting Mr Schrems complaints, for "scrupulous steadfastness to the letter" of the data protection directive of 1995 and the EC Safe Harbour decision on the US in 2000. It appears, however, to constitute significant progress for Mr Schrems Europe v Facebook campaign and a small step in the right direction (nearly said "directive" there) for privacy in digital communications.

Note: Post above amended from earlier following access to full decision. 

Update: One other thought - Judge Hogan seems to think the Commissioner is boxed in by the data protection directive and the 2000 European Commission decision on Safe Harbour; but from my limited dealings with the Irish Data Protection Commissioner's office they seem to be more boxed in by a lack of resources and by their agreement with Facebook.

Tuesday, April 29, 2014

Free is a lie - Aral Balkan at TNW

Take 32 mins and listen to Indie phone's Aral Balkan's talk at the recent TNW conference.



Balkan opens with a simple thought experiment. He's setting up a hypothetical business, Schnail Mail, which will solve the problem of mail delivery by delivering letters and parcels of all shapes and sizes anywhere in the world for free. He asks his audience how many of them would sign up for it. Sounds like an attractive enterprise so many would. In the interests of full disclosure he then explains that by the way Schnail mail will open and forensically examine all letters and parcels to learn about their customers, obviously in the interests only of offering them a better service. How many would now sign up? Not very many though there were still a hard core half a dozen or so. In any case the Schnail Mail business model is the Google, Facebook, [big tech co of choice] "free" service business model.

The business model of "free" is the business model of mass surveillance. We effectively hand over quarries of personal data for these corporations to mine for their own ends. He quotes Eric Schmidt noting Google knows who you are, where you are and what you are thinking; and Facebook knowing people are on the path to a relationship before those people possibly even know it themselves.

He also quotes the Google executive chairman saying:
"If you have something you don't want everyone to know maybe you shouldn't be doing it in the first place."
That's not the kind of world Balkan wants. Privacy is not about whether you have something to hide. It's about having control of what you want to share and what to keep to yourself. But in the world of "free" mass surveillance you don't have that control. The corporations do and they have acquired that control by deceit because consumers largely have no idea of the information they have surrendered/bartered in exchange for "free" services.  If we make the panopticon the default that leads to a society where anything we want to keep private has an association of guilt attached. Privacy becomes only about hiding bad things. Balkan rejects that notion.

Ordinary consumers currently have no choice - all roads lead to digital feudalism regardless of which corporate walled garden is chosen. Techies say use free and open source alternatives. But ordinary mortals have not got the time, skills or resources to architect or build our own FOSS, experience-led digital privacy assured shells to shield our rich personal data quarries / digital personas, thereby enabling us to participate in the information society without compromising our privacy. So techies, entrepreneurs, the market have to start to provide custom built user friendly privacy enhanced technologies. One such effort is Balkan's indie phone.

The true cost of "free" he says is our privacy, our civil liberties, our human rights.

Good luck to Mr Balkan with his indie phone venture. His success will likely depend on the degree to which he can manage the pathological calculus that is -

Privacy vs Convenience/attraction/gratification/access/community/conformity/convenience
- in addition to the small matter of taking on the power of the mass surveillance addicted market incumbents.

Thursday, April 17, 2014

Cory Doctorow & Barton Gellman at SXSW

Cory Doctorow and Barton Gellman discussing Edward Snowden, secure communications, encryption tools so easy your boss can use them, privacy, the revealing nature of metadata and mass surveillance, at SXSW should be required viewing.