Friday, October 04, 2013

BBC Newsnight, Greenwald, Snowden & Entick v Carrington

The BBC finally got round to doing what they might consider an in-depth feature on the Edward Snowden affair last night on Newsnight. I came across it by accident since I rarely watch Newsnight any more but I'd recommend watching it in full before it times out on the iPlayer in 7 days for three reasons -
  • firstly Glenn Greenwald's powerful and passionate critique of the behaviour of the UK & US governments and the weak journalism of the BBC on the Snowden affair
  • secondly it is a classic example of the BBC's determination to report in a way that they perceive to exhibit "balance" i.e. that there are two and only two diametrically opposed sides to every story. The God of 'balance', it seems, trumps objectivety and evidence at the beeb.
  • Ross Anderson's contribution
Kirsty Wark, opening the programme by asking if Snowden's action was "a noble strike against an authoritarian establishment OR an act of vandalism against our national security", gave a taste of things to come. The introductory sequence of the show (I use that word deliberately) goes on to present a video extract of former GCHQ chief, Mr David Ormand, breathlessly saying "not even the KGB in its heyday of  Philby and Burgess and Maclean in the 1950s could have dreamt of acquiring 58,000 highly classfied intelligence documents." With the theme music still running Ms Wark then says they have an exclusive interview with Glenn Greenwald, visible on the studio screen in the background.

There follows 11 to 12 minutes of BBC "balanced" reporting by security correspondent Gordon Corera. You know the sort of thing. Is Snowden the good guy or the bad guy? Are the UK & US governments doing mass surveillance as the good guys to protect us all or the bad guys and spying on us all? All sadly rather superficial.

Ross Anderson is very clear in pointing out that the NSA's actions have more than undermined internet security, they have threatened to break the internet; and quite amusing when explaining that security experts around the world have been astonished that the UK and US governments have managed to build big complex information systems that actually work.

Actually Ross's contribution to that first 12 minutes is probably the one bit of that part if the show worth retaining. Though in fairness to David Ormand, when he says the police and intelligence services need a powerful capability to get at the communications of terrorists, pedophiles and other nefarious actors he's absolutely right, they do. But you don't make that job easier with a mass surveillance - blanket data collection & retention - approach. It has to be done through an intelligence led, targeted data preservation regime. Gordon Corera didn't even present this question to Mr Omand or if he did it didn't make the final cut of the show.

Ross Anderson also explains that the Guardian "revelations in early September that the NSA had had a major covert programme to compromise internet security standards and products were a 9/11 moment" for security specialists globally; and the the goal of the NSA and GCHQ is to ensure they can break anyone's privacy at any given time and interfere with any transaction at any given time. In order to do this they have compromised in various ways many of the protocols on which the internet relies. Yet when you introduce these vulnerabilities they are not just available for the spies to use, they are available to the bad guys too. You can't make people safe by making the communications infrastructure they rely on less secure.

I think Ross is worth quoting in full over his and others' surprise at the NSA and GCHQ's apparent technical competence.
"They pushed it even further than we thought they would. The surprising thing to us was that there appear to be occasional pockets of competence within the NSA and GCHQ. Many of us thought for many years that the real secret was that, like other large public sector IT projects it didn't work; and there was really nobody there. But to find that they had built this machine and got it working was an eye opener."
Glenn Greenwald is introduced at 12 minutes 35 seconds into the programme. It's difficult to capture the passion and power of Mr Greenwald's contribution in a blog post, so I'm not going to try. Instead I'll just point you to the video on YouTube and the Newsnight website. Just to be clear, I don't agree with or endorse the YouTube video poster's opprobrious labelling of Ms Wark or former security minister, Pauline Neville-Jones, as apologists. Given how badly prepared Ms Wark came across in the Greenwald interview, I'm not sure how long the BBC will allow it to remain available on YouTube but here it is for now:



Do watch the 25 minute or so full segment on the Newsnight website whilst it remains available.

Just some final thoughts for readers who are seduced by the argument that the only way for governments to catch the bad guys is to vacuum up the comms data of everyone, could I refer you to the case of Entick v Carrington (1765) 19 Howell’s State Trials 1029, 2 Wils 275, 95 ER 807, Court of Common Pleas.

Nearly 250 years ago, Lord Chief Justice Camden decided that government agents are not allowed to break your door down and ransack your house and papers in an effort to find some evidence to incriminate you.

The short version of the story is that a member of the government, Lord Halifax, had taken a dislike to Mr Entick and ordered Mr Carrington and some of his king’s messengers buddies to dig the dirt to bury the problem with a charge of seditious libel. In court, government lawyers argued that most people subjected to the kind of over-exuberant behaviour exhibited by Carrington & co. were happy to comply and it was rather irritating that Mr Entick was complaining about it. And besides, if the government didn’t have the authority to forcibly extract evidence how could it possibly be expected to deal with terrorists, or in the parlance of the time, purveyors of sedition?

Lord Chief Justice Camden, who had form having sided with another government labelled terrorist, MP John Wilkes, 2 years earlier, didn’t buy the argument. “This power” said he “so claimed by the Secretary of State is not supported by one single citation from any law book extant.”

The good judge also declared personal papers to be one’s “dearest property”. I suspect he might view personal data likewise in the internet age.  I understand Lord Camden's reasoning in Entick became the inspiration behind the 4th Amendment to the US Constitution which offers protection from unreasonable searches and seizures.  The point is, however, that fishing expeditions of the type that the GCHQ and NSA are engaged in fundamentally undermine the rule of law.

Update: Early editions of Bailey, Harris & Jones: Civil Liberties Cases, Materials and Allen, Thompson & Walsh Cases and Materials on Constitutional and Administrative Law, real old books I still have on my shelf, were the sources I referred to in order to double check my ancient memories of Entick v Carrington.

Update 2: BBC Newnight has now posted the full 33 minutes 26 seconds of the Snowden report and interviews to YouTube. Kudos to them



Newsnight's editor Ian Katz has responded to Jay Rosen's criticism of the piece. Former BBC news chief Richard Sambrook also thought "it was an ill-thought through interview and consequently weak. More broadly, for at least 25 years British broadcasting has been enthralled by the adversarial, devil’s advocate, form of interview. Journalists careers have been made and interviewees careers destroyed by it. Personally, as a form, I think it is all but exhausted and is increasingly tiresome – and seldom reveals as much as a more forensic approach could achieve."

Friday, September 27, 2013

Alas medical confidentiality in the UK, we knew it well...

The UK government's disastrous plan to extract all our personal medical data from GP surgery systems and dump it in a, to say the least, inadequately controlled central database, has hit a speed bump.  It seems that the Information Commissioner's Office has decided to inform NHS England that they have not given GPs enough time to hand over the data legally.

Don't get me wrong. The ICO has no intention of blocking this government induced systemic national kneecapping of the Hippocratic oath and the principle of medical confidentiality. They merely want to give GPs more time to let people know it is happening. The government previously refused to fund a publicity campaign explaining they were collecting all UK electronic medical data into one big pot (or actually in practice several big central pots). NHS England did send GPs some posters and leaflets for display in surgeries though.

I'm being a little hard on the ICO here since, in fairness, his power to actually do anything about all this is limited by the way Part 9 of the 2012 Health and Social Care Act, which came into force in April 2013, has been written and additionally the 'get out of medical confidentiality free card' provided by Section 251 of the National Health Service Act 2006.

There are several aspects of this I've been tempted to rant about here for many months - in particular the misleading, false and/or delusional claims on the part of politicians that the data will be anonymised - but I've just had a terrific email from Terri Dowty at medConfidential who sums the situation up better than I could and I'm sure she won't mind me sharing it with you in full:
"Information that you share with your GP is about to be extracted from surgery records and stored on a centralised NHS system with your identifying details still attached. From there, it will be made available for administrative, research and other purposes. The government has claimed that your records will be ‘anonymised’ before they are handed over to anyone else, but this is not true. There are several circumstances in which data that identifies patients will be made available.

Once your information has been uploaded, neither you nor your GP will have any control over who it is shared with, who has access or what is done with it. You will not be consulted, nor will you be asked for consent. Uploads will take place automatically every month.

When you next visit your GP, you may see a small poster headed ‘how information about you helps us to provide better care’. This is how the NHS is explaining its plans to you and it is very misleading. It does not give you full details of the information that will be collected, and it claims that information will not identify you.

Further down the poster you will see the words ‘you have a choice’. What this actually means is: if you do not want personal and confidential information to be taken from your medical record every month, the onus is on you to opt out of the scheme. If you don’t do so, it will be assumed that you consent to the extraction.

You can download an opt-out letter to complete and send to your GP from the medConfidential website:
http://medconfidential.org/how-to-opt-out/
You will also find more detailed information about the scheme – known as ‘care.data’ – on the medConfidential website.

Please tell all of your friends, family and colleagues about this scheme, or forward this email to them. It is very important that everyone knows they must take action if they don’t want their information to leave their GP’s surgery."
The government's plan, if you can call it that, is that data will be made available to researchers in universities, hospitals and commercial organisations.  There is now even a Health & Social Care Information Centre (HSCIC) data access and extraction price list. NHS England's chief data officer, Geraint Lewis, has however, reportedly suggested that the cost of access expanded HSCIC data sets should be reduced from from around £30,000 to a nominal £1.

I'd highly recommended you find 20 minutes in the next few days and read Terri Dowty's and Phil Booth's outline at medconfidential of the rather complex story at play here. It's yet another one of those government giant database cure for all ills stories. Another information system disaster in the making. Another careless metaphorical bullet through the head of a crucial societal value, this time medical confidentiality.

Thursday, September 26, 2013

European Parliament LIBE hearing on mass surveillance Pt2

A more accurate title for this post might be Caspar Bowden's evidence to the European Parliament LIBE hearing on mass surveillance Pt2, since that's the focus. (Pt1 is here) The 63 minute video of Caspar's statement and subsequent Q&A is now available in full on YouTube courtesy of Henrik Alexandersson.



Moving to section 2.2.5 of his report on The US National Security Agency (NSA)surveillance programmes (PRISM) and Foreign Intelligence Surveillance Act (FISA) activities and their impact on EU citizens' fundamental rights, Caspar notes that the collection of foreign intelligence information under the PRISM programme is based on the Patriot Act s215 power. This power is subject to originally classified “minimization” and “targeting” procedures, which were published in full by the Guardian on 20 June this year. These procedures provide no limitations or protections whatsoever for non US nationals. As the report says,
One therefore suspects that US operational practice places no limitations on exploiting or intruding a non - US person's privacy, if the broad definitions of foreign intelligence information are met.
Moreover in a May 2012 letter to the Congress intelligence review committees the government states that:
Because NSA has already made a “foreignness” determination for these selectors·in accordance with its FISC - approved targeting procedures, FBI's targeting role differs from that of NSA. FBI is not required to second - guess NSA's targeting determinations...
The versions of the targeting procedures released are generic, but the American Civil Liberties Union (ACLU) obtained redacted copies of slides related to FBI staff training that referred specifically to FISAAA for counter-terrorism purposes. The letter continues:
Once acquired, all communications are routed to NSA. NSA also can designate the communications from specified selectors acquired through PRISM collection to be "dual - routed'' to other intelligence Community elements. (emphasis added)
(Note FISAAA is the Foreign Intelligence Surveillance Act Amendments Act 2008. s1881 of FISAAA was incorporated into the Foreign Intelligence Surveillance Act as s702)

If data flowing to the NSA is adjudged to be 50% likely to be associated with foreigners, it is fair game. (The "targeting procedures" say analysts may only proceed to use data under the FISA s702 power if there is more than a 50% likelihood the target is not American and located outside the US). All of this data, i.e. data not filtered out as American only, is then available to the CIA, amongst others, of the sixteen  US intelligence community agencies.

We don't know the scope of intelligence agency data Edward Snowden had access to but it is unlikely he access to all of the intelligence agencies compartmentalised information exploitation guidelines. It is highly significant, however, that each of these agencies can have their own copies of the 50% non American data flowing from the NSA electronic fire hose.

Meanwhile on the EU side of the pond our general approach to data protection and control of data flows to the US exhibits all the features of EU regulators being asleep at the wheel (section 2.3). That's the case whether we are talking about the EU-US "safe harbour" provisions, Binding Corporate Rules (BCRs) for processors or cloud computing. One of the central issues in the whole report is that there are enormous loopholes in these supposed privacy safeguards for EU citizens. Caspar accused EU Commission officials of knowingly or unknowingly permitting or designing these loopholes into the text of the regulations. Get out clause typically include terms like "national security" (that old catch all) and "a legally binding request" and give US government and commerce a blanket licence to collect, process, store, copy and analyse any and all EU data they can get their hands on. "A legally binding request", for example, will include the all encompassing "foreign intelligence information" net which in turn includes any data of assistance to US foreign policy, not least expressly political surveillance over ordinary lawful democratic activity of citizens of EU countries.

Caspar strongly suggests it is the duty of the LIBE committee to investigate the 10 years or more incompetence and/or complicity of the Commission in creating instruments supposed/believed/claimed to protect the privacy of EU citizens but in practice undermining it. He wants Commission papers thoroughly scoured to analyse who made the key decisions, whether they were made in good faith and was it bungling, ineptitude or complicity that led to the prevailing state of affairs where EU privacy is wide open to US abuse. He reckons he delves into this criticism a bit more with less restraint in the report. Whilst it's true he does go into more detail there, I'm not sure he is quite so blunt about the failure of the Commission in their duty of care to protect privacy of the citizens they are supposed to represent.

He then moves onto the recommendations. In the summer of 2013 it became know that the EU Commission had dropped provisions in proposed new data protection regulations that would block the kind of data hoovering that the NSA are doing. The deletion of what would have been article 42 of the regulations was reportedly due to diplomatic pressure coming from the US government. (This is also covered in section 3.2 of the report). You can read article 42 in a draft version of the regulations leaked towards the end of 2011 (p69). Caspar makes his recommendations conscious of the fact that there is talk of re-instating article 42. But as things stand now, EU citizens are placing their data in jeopardy by using US services and websites.

The 1995 data protection directive 95/46 already requires that the basis of processing is consent and that must be informed consent - informed of all relevant risks. Under directive 95/46 EU citizens should be informed of the fact that if they use a US web server their data is going to be subject to political surveillance by the US intelligence communities. So he recommends:
- Prominent notices should be displayed by every US web site offering services in the EU to inform consent to collect data from EU citizens. The users should be made aware that the data may be subject to surveillance (under FISA 702) by the US government for any purpose which furthers US foreign policy. A consent requirement will raise EU citizen awareness...
- Since the other main mechanisms for data export (model contracts, Safe Harbour) are not protective against FISA or PATRIOT, they should be revoked and re-negotiated...
There simply is no case for allowing data transfers from the EU to the US under model contracts or safe harbour. He recognises disengaging these is a very serious matter and that it will have to be done in a phased and strategic way but it must be done. In addition, thinking strategically, 
- A full industrial policy for development of an autonomous European Cloud computing capacity based on free/open - source software should be supported. Such a policy would reduce US control over the high end of the Cloud e-commerce value chain and EU online advertising markets. Currently European data is exposed to commercial manipulation, foreign intelligence surveillance and industrial espionage. Investments in a European Cloud will bring economic benefits as well as providing the foundation for durable data sovereignty.
In relation to this EU cloud infrastructure, when the forthcoming report on Sigint (signals intelligence) in the EU gets published some member states may find themselves in a problematic position. Cryptically, Caspar then said he would say no more about that.

On the potential re-instatement of article 42 in the new data protection regulations (section 3.2 of the report) he is of the opinion that it does not go far enough. The CEO of Yahoo! recently said she could have been jailed for 10 years if she'd said more about government coercion under s702 powers. Depending on how and who interprets the law the penalty could be up to 30 years in jail or conceivably even the death penalty. The latter is unlikely but is part of US law.

By comparison Article 42 would create a conflict of law where the penalty on the EU side is a 2% fine. From Caspar's experience of working for Microsoft this is not going to work. Tiny proportionate penalties in the EU compared to more severe punishment in the US means the data controllers & processors will always take the smaller risk in the EU and comply with US government coercion.

So a re-instated Article 42 should make non compliance at the very least a serious criminal offence.

At the moment the way article 42 is structured there is complete discretion for member states to set penalties. This won't work. Also the imposition of fines won't work. The biggest fine the EU has ever dished out was $1 billion relating to Microsoft's anti-competitive practices in local area networks. Microsoft's profits over the 10 year operation of that monopoly were about $20 billion and that's a conservative estimate. The Microsoft lawyer who "lost" the case got promoted. A fine level of 20% of global revenue may be needed to persuade such corporations to take Article 42 compliance seriously. That might sound extraordinary but such large economic actors actually factor $1 billion fines into their corporate strategies as acceptable write-offs/losses.

The final point he wanted to emphasise before taking questions was in relation to BULLRUN, the NSA project to subvert cryptographic security -
Even after BULLRUN, cryptography is probably intact in theory, however it is not known which encryption implementations and products may have been rendered insecure. Therefore consideration should be given to extending the scope of 'Art.42' also to cover vendors of systems/products (as well as Controllers/Processors) in EU markets. Existing encryption security product accreditations, especially if influenced by NSA or GCHQ, must be regarded as suspect.
So if vendors of security products are coerced by the NSA to build back doors into their systems, even if they are not processing personal data, there should be a requirement for them to tell the EU about the backdoor. This would create a further conflict of law and further jeopardy and penalties for those companies that choose to comply with US rather than EU law. Again the sanctions have to be proportionately as severe or more so for non compliance as they would be in the US.

At that point he opened the session to the floor for a Q&A which ran for a further 40 minutes or so. Well done Mr Bowden on an impressive performance.

The Brazilian President, H.E. Dilma Rousseff, lambasted the US mass surveillance practices with her opening speech at the UN General Assembly in New York on Tuesday, September 24, 2013, just as President Obama was due to step on the same platform in her wake. That same day the EU Parliament held this whole day hearing criticising the US for those same practices (full videos of the morning and afternoon sessions are available via the Parliament website).

A day to remember for privacy advocates. Will it also prove to be a small step forward in reigning in the excesses of the digital surveillance state or just get lost in the noise of history and our mass electronic data addicted society?

Wednesday, September 25, 2013

European Parliament LIBE hearing on mass surveillance Pt1

The EU Parliament LIBE Committee held their Inquiry on Electronic Mass Surveillance of EU Citizens yesterday. Full videos of the morning and afternoon sessions are available via the Parliament website. Some short extracts from the morning session -



Some short extracts from Caspar Bowden's evidence in the final session of the day -



Caspar's statement is really worth watching in full. It's only about 22 minutes but it's pretty impressive how much information he can pack into that time. He gets introduced by Dutch MEP Sophie in 't Veld at 17:07:04. Amusingly but emphatically he declines her invitation to introduce or provide a short overview of his report on The US National Security Agency (NSA)surveillance programmes (PRISM) and Foreign Intelligence Surveillance Act (FISA) activities and their impact on EU citizens' fundamental rights for the Parliament's Policy Department for Citizens' Rights and Constitutional Affairs. Caspar prefers to take a forensic approach, assuming MEPs have read the report (or will do at their leisure at some point) but highlighting some of the detail they may have missed the significance of (or might do when they read it). The scope of the report is limited to the US and the NSA.

There is a widely held view that the collection of data is less important than its use. Caspar disagrees. Now that Edward Snowden's revelations are public we know we are being watched and as a result likely to change our behaviour. It's the Heisenberg principle at a societal scale - you cannot monitor/measure/surveil without influencing those under surveillance. This poisonous mass surveillance it has been going on for perhaps over 10 years and this creates profoundly dangerous destabilizing factors in democracy.

We have never had disclosures on the scale we have seen from Snowden.

[Note In his statement Caspar refers to page numbers of his report in his evidence which are slightly out of sync with the copy I've read and link to on the parliament website. I'll use the numbers from the linked version if I refer to page numbers.]

The first theme in the report he draws attention to is the competing models of privacy governance in the EU and US. This is fundamental and often overlooked. From the long term perspective the underlying principle of EU data protection law is rather odd since it removes the key power to control their personal data from the individual. Once data is submitted to a government or private sector system the individual can no longer object when that data is copied - if it's copied to thousands of machines in that organisation or to a thousand other organisations or other legal regimes. The data protection system assumption is that if the right legal boxes are ticked, the individual must put up and shut up.

Yet every time data is copied from one system to another, privacy risk is increased. It never decreases. With every copy the risk that something bad will happen to that data goes up and the risk that something bad will happen to the person connected to that data likewise increases.

So EU data protection law disables individual control of personal data and the Snowden revelations should make us question this unsound regulatory foundation of privacy protection.

The next section of the report he picks is on the XKeyscore system. From the report:
The XKeyscore system was described in slides 20 (dated 2008 21 ) published by The Guardian on the 31 st of July. It is an “exploitation system/analytic framework”, which enables searching a “3 day rolling buffer” of “full take” data stored at 150 global sites on 700 database servers. The system integrates data collected 22 from US embassy sites, foreign satellite and microwave transmissions (i.e. the system formerly known as ECHELON), and the “upstream” sources above.
The system indexes e - mail addresses, file names, IP addresses and port numbers, cookies, webmail and chat usernames and buddylists, phone numbers, and metadata from web browsing sessions (including words typed into search engines and locations visited on Google Maps). The distinctive advantage of the system is that it enables an analyst to discover “strong selectors” (search parameters which identify or can be used to extract data precisely about a target), and to look for “anomalous events” such as someone “using encryption” or “searching for suspicious stuff”
When you stop to think about this immense surveillance power you realise it goes beyond even George Orwell's imagination. Data can be extracted retrospectively in time, so it gives an analyst a time machine. So without any prior suspicion about an individual it is possible to go back and examine behaviour and conduct of anybody in the world, except Americans, to a limited degree. Not only is it a facility for officials to engage in fishing expeditions it is an irresistible (and most likely official) compulsion.

The next point of interest in the report is BULLRUN (page 16), the codename for the NSA programme to break into widely used encryption systems. Not exclusively by mathematical means but also via side channel attacks - electronic emanations from computers through which keys can be reconstructed - and also through co-opting manufacturers of security equipment. BULLRUN has created the most shock amongst the technology security community of all the Snowden leaks.  All over the world security experts are trying to guess what is vulnerable and re-key/re-grade those systems. But they are working in the dark.

From Caspar's conversations with journalists and experts who have seen some of the Snowden material it appears unlikely that there will emerge much more specific detail about what exactly is vulnerable and what is not. That leaves us with the problem that a large number of systems we thought were secure may not be so and we don't know how to find out which ones are compromised.

He then moved onto the FISA definition of “foreign intelligence information” which is incredibly broad. The Foreign Intelligence Surveillance Act (FISA) foreign intelligence information, Caspar describes, poetically, as "the core term of art" underlying the NSA PRISM mass electronic surveillance programme. It is first defined in the original FISA in 1978 but the parts of the definition that are pertinent to this discussion have not changed since then.

To get to the definition you have to substitute in 2 levels of definition (from related statutes) in what is a complex formulation. (Just an aside - it is really irritating when regulators do this, leading to the byzantine searching of loosely connected laws, with multiple clauses referring to multiple other clauses, when you just want a clear notion of what the law actually is). From the report:
The FISA definition of “foreign intelligence information” has been amended several times to include specific and explicit categories for e.g. money laundering, terrorism, weapons of mass - destruction, but has always included two limbs which seem almost unlimited in scope. When the terms are unwound it includes:
information with respect to a foreign - based political organization or foreign territory that relates to, and if concerning a United States person is necessary to the conduct of the foreign affairs of the United States. [emphasis added]
This definition is of such generality that from the perspective of a non - American it appears any data of assistance to US foreign policy is eligible, including expressly political surveillance over ordinary lawful democratic activities.
That's worth dwelling on and this represents only about a tenth of the full definition of foreign intelligence information. Read it again - any data of assistance to US foreign policy is eligible, including expressly political surveillance over ordinary lawful democratic activity of citizens of EU countries.

We do not know to what extent that definition is applied or exploited because a curious fact is that there has been nothing written about it in 40 years
  • no legal commentary
  • no published guidance
  • no executive orders elaborating on what it means
It is simply unknown to what effect that broad facility has been put over the past 40 years. However, the natural supposition is that this is the power under which purely political surveillance of activities in a foreign country, counter espionage possibly but essentially political spying would be conducted.

There is, in the definition, a discrimination by nationality. In the case of US citizens the threshold for surveillance is necessity, a very strict legal line. For non US citizens the requirement is merely "relates", about the weakest legal hurdle you can imagine.

The FISA section 702 power (Procedures for targeting certain persons outside the United States other than United States persons) contains an express discrimination by nationality too, amounting to a double discrimination by nationality favouring US citizens.

There is nothing in EU law remotely like that and human rights experts say this is simply and obviously unlawful under the European Convention on Human Rights.

At this point Caspar refers to the contribution of an earlier speaker in the day relating to section 215 of the US Patriot Act. The reforms of s215 being discussed in the US are not going to help very much with the 'suspicious through lack of US citizenship' problem. The provision to "obtain foreign intelligence information not concerning a US citizen" gives carte blanche to apply section 215 power to foreigners. Even if they fix and restrict the selective collection of information to counter terrorism criteria but conveniently overlook the 'guilty of being a foreigner' provisions, it won't do any good.

I'm going to have to cut the report short at that point but will get back to the rest of this testimony in a later post.

Tuesday, September 24, 2013

Brazilian President attacks US Mass Surveillance

The Brazilian President, H.E. Dilma Rousseff, has used her opening address at the General Debate of the 68th Session of the UN General Assembly to criticise the mass surveillance activities exposed by Edward Snowden.
"I would like to bring to the consideration of delegations a matter of great importance and gravity.
Recent revelations concerning the activities of a global network of electronic espionage have caused indignation and repudiation in public opinion around the world.
In Brazil, the situation was even more serious, as it emerged that we were targeted by this intrusion. Personal data of citizens was intercepted indiscriminately. Corporate information often of high economic and even strategic value - was at the center of espionage activity. Also, Brazilian diplomatic missions, among them the Permanent Mission to the United Nations and the Office of the President of the Republic itself, had their communications intercepted.
Tampering in such a manner in the affairs of other countries is a breach of International Law and is an affront to the principles that must guide the relations among them, especially among friendly nations. A sovereign nation can never establish itself to the detriment of another sovereign nation. The right to safety of citizens of one country can never be guaranteed by violating fundamental human rights of citizens of another country.
The arguments that the illegal interception of information and data aims at protecting nations against terrorism cannot be sustained.
Brazil, Mr. President, knows how to protect itself. We reject, fight and do not harbor terrorist groups.
We are a democratic country surrounded by nations that are democratic, pacific and respectful of International Law. We have lived in peace with our neighbors for more than 140 years.
As many other Latin Americans, I fought against authoritarianism and censorship, and I cannot but defend, in an uncompromising fashion, the right to privacy of individuals and the sovereignty of my country. In the absence of the right to privacy, there can be no true freedom of expression and opinion, and therefore no effective democracy. In the absence of the respect for sovereignty, there is no basis for the relationship among Nations.
We face, Mr. President, a situation of grave violation of human rights and of civil liberties; of invasion and capture of confidential information concerning corporate activities, and especially of disrespect to national sovereignty.
We expressed to the Government of the United States our disapproval, and demanded explanations, apologies and guarantees that such procedures will never be repeated.
Friendly governments and societies that seek to build a true strategic partnership, as in our case, cannot allow recurring illegal actions to take place as if they were normal. They are unacceptable.
Brazil, Mr. President, will redouble its efforts to adopt legislation, technologies and mechanisms to protect us from the illegal interception of communications and data.
My Government will do everything within its reach to defend the human rights of all Brazilians and to protect the fruits borne from the ingenuity of our workers and our companies.
The problem, however, goes beyond a bilateral relationship. It affects the international community itself and demands a response from it. Information and telecommunication technologies cannot be the new battlefield between States. Time is ripe to create the conditions to prevent cyberspace from being used as a weapon of war, through espionage, sabotage, and attacks against systems and infrastructure of other countries.
The United Nations must play a leading role in the effort to regulate the conduct of States with regard to these technologies.
For this reason, Brazil will present proposals for the establishment of a civilian multilateral framework for the governance and use of the Internet and to ensure the effective protection of data that travels through the web.
We need to create multilateral mechanisms for the worldwide network that are capable of ensuring principles such as:
1 - Freedom of expression, privacy of the individual and respect for human rights.
2 - Open, multilateral and democratic governance, carried out with transparency by stimulating collective creativity and the participation of society, Governments and the private sector.
3 - Universality that ensures the social and human development and the construction of inclusive and non-discriminatory societies.
4 - Cultural diversity, without the imposition of beliefs, customs and values. 5 - Neutrality of the network, guided only by technical and ethical criteria, rendering it inadmissible to restrict it for political, commercial, religious or any other purposes.
Harnessing the full potential of the Internet requires, therefore, responsible regulation, which ensures at the same time freedom of expression, security and respect for human rights"
That's quite a critique -

Dear UN, the US has been engaged in illegal mass surveillance - a grave violation of human rights - industrial espionage and unconscionable political spying, generally behaving in ways likely to lead to us descending into uncontrolled cyberwarfare. I suggest you sort it out.

Interesting also that President Rousseff's address should be made in parallel with Caspar Bowden presenting his findings on the impact of the NSA surveillance on the fundamental rights of EU citizens to the European Parliament. More on the latter when I get the time in the next few days. It is absolutely essential reading for anyone with a serious interest in the Snowden affair.

Tuesday, August 27, 2013

Brief incomplete stocktake on Snowden leaks issues

Whatever stance you take on Edward Snowden's actions and motives, the Guardian's dogged reporting of his leaks has revealed -
  • government security services with the aid of large commercial organisations engage in mass surveillance - collecting, processing and storing the personal data - of that large proportion of the population using and/or visible to communications networks
  • UK government - with echoes of the Spanish Inquisition's, Nazi Germany's and Mao Zedong's book burning - is prepared to be responsible for the physical destruction of mainstream press equipment 
  • UK government is prepared to threaten the press with D notices and prior restraint through the courts
  • the fourth estate - mainstream broadcasters and press - in the UK has largely been content to ignore or marginalise Guardian revelations, allowing that publication to plow an isolated furrow on the Snowden affair until a journalist's partner, David Miranda (what an appropriate name), got detained for 9 hours at Heathrow and relieved of his electronic kit under Schedule 7 of the Terrorism Act 2000
  • US government via NSA reportedly route significant funds ($100 million) to UK government intelligence service GCHQ 
  • UK's GCHQ appreciate their "light oversight regime compared to the US"  
  • UK spied on G20 London summit attendees in 2009
  • US intelligence chief James Clapper lied (responded in the "least untruthful manner") to Congress about the extent of NSA surveillance
  • the secret US FISA Court's ability to oversee US spy agencies is very limited
  • the NSA have rules for circumventing democratic oversight
  • politicians who have long since lost sight of the boundaries between right and wrong, are all too willing to demonise the messengers and trot out poisonous soundbites - the innocent have nothing to fear; our critics comfort/support our enemies/terrorists; government's first duty is to protect the public; be afraid but give us the power and we'll protect you; move on there's nothing to see; ...national security...; trust us we're acting within the law - to defend the indefensible and sate their ambitions
  • the Secretary General of the Council of Europe, Thorbjørn Jagland, was sufficiently concerned to write to the UK Home Secretary about Mr Miranda's detention and the destruction of the Guardian's computers
  • the information consuming public take an essentially soporific attitude to all this 
The stories have raised fundamental questions of public interest (even if, in our world of short attention spans, the public is only superficially and transitionally interested, if at all) about -
  • security (no top secret can be secure if a million or more people have access to it as a routine part of their jobs)
  • privacy (you have none on the internet)
  • anonymity (again you have none on the internet)
  • free speech (when does a whistleblower become a traitor?; why and how is is ok to smash up a computer in the offices of the Guardian in the UK in 2013?)
  • management and oversight of the police, intelligence and security services (what are the political, legal, environmental, societal, economic, technical and architectural checks and balances, if any and are they fit for purpose?)
  • the size, power and reach of the security/intelligence/surveillance/anti-terror industrial complex
  • secret courts (FISA, FISAAA 2008; the UK now has its own secret courts courtesy of the Justice and Security Act 2013 which came into force in June)
  • circumvention of human rights laws and constitutional protections (Prism, Tempora, XKeyscore, GCHQ-NSA data sharing?)
  • dangerous normalisation of activities that would have horrified earlier generations and been condemned as the actions & infrastructure of a despotic police state if connected with the Soviet Union, East Germany, China et al

Monday, July 01, 2013

State & corporate interests aligned on mass surveillance

Lucian Hudson, the Open University's Director of Communications and a former senior civil servant in both the Foreign Office and the Justice Department, posted some interesting thoughts on the Snowden PRISM revelations recently, suggesting we ourselves pose the biggest threat to liberty. I've responded in comments on Lucian's blog but include a copy here for posterity.

Lucian,

Whilst agreeing with your broad theme – on disproportionate societal fear, the consequent attraction of simplistic paternalistic securocratic governance and our undermining of fundamental liberties through e.g. trading privacy for convenience with modern communications technologies – I don’t completely subscribe to the notion that the biggest threat to liberty is ourselves.

At the moment a bigger issue is that the interests of the state and corporate establishments happen to be aligned in relation to big data. The collection and processing of personal data is [wrongly] perceived to be a silver bullet route to solving a range of political issues in the case of the state (e.g. terrorism as you mention) and to financial success in the markets in the case of the private sector. Simplistic and ill-informed though these mindsets are – computers do not magically solve complex political, social, economic, environmental, security or market problems just by chucking money at them or by making them bigger/faster or capable of collecting & processing more data – they fundamentally undermine privacy/liberty interests of the individual.

Whilst the state is subject to significantly tighter formal checks and balances than the private sector in relation to mass surveillance – the rule of law theoretically precludes the engagement in indiscriminate fishing expeditions in the hope of finding smoking gun evidence – the arguments rolled out by politicians, under the pressure of the modern 24/7 news cycle, relay a persuasive if misleading message to the contrary on preferred policy. We can, it is said, have liberty OR security; security OR privacy; or in more subtle form, we have to BALANCE privacy and security. This is a false dichotomy. As you rightly point out, security and liberty are mutually dependant not opposing forces.

Additionally we have the powerful but false and, frankly, poisonous ‘nothing to hide, nothing to fear’ meme repeated by William Hague and others in response to the PRISM revelations recently. When you cast the apparently small privacy need of the individual against the national security gain of the state which will seemingly benefit society as a whole, it is impossible to argue the needs of the individual outweigh the common good.

The ‘nothing to hide…’ argument, however, is based on two huge and erroneous foundations.

The first is that it assumes all privacy is only about hiding bad things. Yet without personal privacy/liberty our society would be suffocating – privacy, liberty and the common good are inextricably interlinked and mutually dependent.

The second is that decimating privacy is the solution to the problem du jour – security, terrorism, serious crime, benefit fraud, NHS patient care etc. It’s possible to prove this thesis wrong mathematically but for the present purposes think of terrorist detection as a needle in a haystack problem. You don’t make it easier to find the needle by throwing more electronic data hay on the stack. Mass data collectors can dig deeply into the digital persona of anyone but don’t have the resources to do so with everyone. The resultant pursuit of false positive leads mean the real bad guys often get lost in the noise, as happened with the 9/11 attackers who were known to US authorities but not considered sufficiently important to intercept.

There is no magic computer solution to the rare terrorism problem.

Don’t get me wrong. Law enforcement and security services need to be able to move with the times, use modern digital technologies intelligently in their work and through targeted data preservation regimes – not a mass surveillance regime – engage in technological surveillance of individuals about whom they have reasonable cause to harbor suspicion. That is not, however, the same as building an infrastructure of mass surveillance.

This brings us back to the current alignment of state and corporate interests in relation to the architectures of our digital communications technologies. We could architect systems that enhance privacy and facilitate anonymity and net neutrality. We don’t.

The organisations that construct and operate these technologies have no market or regulatory incentives to build or run them this way. We, I agree, contribute enormously to this state of affairs by trading our privacy for the convenience/ attraction/gratification/access/community/conformity of the services that we use on the internet. We additionally contribute by failing to engage in a meaningful and persuasive way in the public debate on these issues. Our much maligned politicians are busy generalists subject to the constant glare of the media spotlight who really do not understand the technology and we have to be better at explaining it to them.

The state, likewise, has no incentive either to direct its vast purchasing power towards or to pass regulations to require the building and operation of liberty respecting network architectures. [Neither, in relation to regulations, has it got the required understanding of the technology to do so.] The state establishment, at the highest levels of its requisite parts, has largely bought into the belief that big data is good and their unfettered access to it even better.

We have to be more active/persuasive/engaged as individuals, citizens, employees, consumers or prosumers in convincing ourselves, our organisations, communities, society, the market and the state that an infrastructure of mass surveillance is not conducive to the public good. As long as the most powerful actors in this calculus, however, the state and the corporate sector, continue to share the belief that the continued building and operation of such an infrastructure of mass surveillance is in their mutual interest, it will be a difficult argument to win.

Regards,

Ray

PS Aside from the Snowden story, on the positive side, if the earlier Bradley Manning Wikileaks leaks revealed anything it was the huge numbers of dedicated US government officials and diplomats working day to day, above and beyond the call of duty, to uphold the values of the US Constitution and Bill of Rights. Having worked yourself at senior level in the civil service, you’ll no doubt be aware of equivalent commitment to democratic values on the part of UK government officials. There are a multitude of similarly dedicated individuals in the the state and corporate establishment across the globe. So it can’t be beyond us to evolve the surveillance state that is the internet of 2013 into something more respecting of democratic values and freedoms.

Monday, June 17, 2013

US Supreme Court confused reasoning on Myriad gene patents

On the 13th of June the US Supreme Court handed down it's decision in the case of Association for Molecular Pathology et al v Myriad Genetics., Inc et al.

A lot of the commentary in the conventional news media has been to the effect that the Supreme Court has banned the patenting of human genes. That's not necessarily so. The Court specifically held:
“A naturally occurring DNA segment is a product of nature and not patent eligible merely because it has been isolated, but cDNA is patent eligible because it is not naturally occurring.”
Myriad Genetics, as is clear from the statement about the case on their website, see the decision largely as a victory in two respects -
  • Firstly although the Court struck down the company's claimed ownership of the naturally occurring DNA segments that are the BRCA1 and BRCA1 genes, they upheld Myriad's patent claims relating to complementary DNA, cDNA. (Note cDNA is called complementary DNA by experts, not 'composite' DNA, the term used by Justice Thomas in the decision). So Myriad has the exclusive right to synthetically create BRCA1&2 cDNA.
  • Secondly, though the case was not reviewing Myriad's method patents – patents relating to the way the company does genetic testing, biotech research and other processes – the company are interpreting some of the remarks of Justice Thomas in Part III of the ruling as re-inforcing all of their method patent claims.
The Association for Moleular Pathology seems equally pleased:
"The decision helps to lay the foundation for continued research and application of diagnosis and treatment of diseases at the molecular level. "AMP applauds the U.S. Supreme Court on their ground breaking, unanimous decision. There is no question that this is a critical and right decision for the future of medicine and science. Biomedical researchers, clinicians, and most importantly patients will see great benefit from this development," said Jennifer L. Hunt, MD, MEd, AMP President."
Which of the two parties has the most right to claim victory only time will tell. What does appear clear is that the reasoning of the Court in striking down the DNA claims and upholding the cDNA claims was effectively unanimous but confused.

Justice Scalia wrote a separate short concurring opinion disassociating himself from Justice Thomas's efforts to explain the science, and implying that doing science was not the business of the Court. He would not put his name to what he did not understand.
"I join the judgment of the Court, and all of its opinion except Part I–A and some portions of the rest of the opinion going into fine details of molecular biology. I am unable to affirm those details on my own knowledge or even my own belief. It suffices for me to affirm, having studied the opinions below and the expert briefs presented here, that the portion of DNA isolated from its natural state sought to be patented is identical to that portion of the DNA in its natural state; and that complementary DNA (cDNA) is a synthetic creation not normally present in nature."
The fact that the Court has decided that a naturally occurring  DNA segment is not patentable is clear. The attempted logic they use to get from there to the patentability of cDNA is flawed. Justice Thomas goes to great pains to emphasise that the Myriad patents under review are information patents not chemistry patents (see p14):
...extensive effort alone is insufficient to satisfy the demands of §101. Nor are Myriad’s claims saved by the fact that isolating DNA from the human genome severs chemical bonds and thereby creates a nonnaturally occurring molecule. Myriad’s claims are simply not expressed in terms of chemical composition, nor do they rely in any way on the chemical changes that result from the isolation of a particular section of DNA. Instead, the claims understandably focus on the genetic information encoded in the BRCA1 andBRCA2 genes"
Merely doing chemistry and breaking a chunk of gene out of a DNA chain is not enough to grab ownership of that gene. That makes sense. We shouldn't be allowed to cut up products of nature and say we now own the offcuts.

DNA chains have useful functional sequences of crossbars called exons and less useful sequences called introns.

DNA exons introns

On the route from DNA -
  • to RNA where the DNA unwinds into single strands from the original double helix 
  • to the removal of the useless introns
  • to mRNA where the exons spliced back together in their original sequence
  • then on to the production amino acids and proteins in cells
the naturally occurring information content of the DNA does not change. So breaking down BRCA1&2 genes, stripping out the introns and putting the genes back together as cDNA without the introns does not change the information content of the genes. So if the DNA is not patentable the equivalent cDNA cannot be patentable, from an information perspective.

Let's put it another way. The collections of genes inside living cells are a bit like the cells' recipe books. When a cell needs to do something like manufacture a protein it consults the gene recipe book and follows the instructions there. BRCA1&2 DNA and cDNA have the same information content, in the same order, the same recipes. The BRCA1&2 cDNA recipe book might be shorter and neater, stripped of the waste intron pages, but it contains the same instructions, methods, recipes.

Not only has the Supreme Court not banned patenting human genes, in this case it has granted Myriad Genetics control of the most functionally useful naturally occurring information in BRCA1 and BRCA2 genes.

So as I understand the reasoning, it goes something like this -
  • BRCA1 & BRCA2 genes are naturally occurring DNA segments
  • As naturally occurring DNA segments (with their naturally occurring exon recipe books) they are not patentable just by cutting them out of the DNA chain they form part of
  • Chemistry doesn't cut it - excuse the pun - to earn patent control
  • BRCA1&2 cDNA, however, (with their naturally occurring exon recipe books with the same natural recipes) are patentable because they are different without the introns and there's more chemistry (you have to cut out the genes, cut out the introns, put the exons back together in the same order)
The Supremes themselves, in page 2 of the summary of the decision, say:
"Myriad did not create or alter either the genetic information encoded in the BCRA1 (sic)and BCRA2 (sic) genes or the genetic structure of the DNA. It found an important and useful gene, but groundbreaking, innovative, or even brilliant discovery does not by itself satisfy the §101 inquiry."
Neither has Myriad created or altered the functional genetic information encoded in the BRCA 1 and BRCA2 cDNA. It makes little sense, therefore, that the DNA is not patentable but the cDNA is. Justice Scalia may have been honest in noting he could not sign up to the fine details of molecular biology in the opinion. All nine justices may have had a variable grasp of the science but it seems none of the nine had a proper handle on the information science.

Casual readers should probably call a halt there. I look at some extracts from the decision below.

Justice Thomas in Part I, Section A, pp1-4, attempts to explain the science in the case. I can't help feeling the inclusion of pictures/illustrations could have helped his task enormously here. I wonder when courts looking at science and technology are going to embrace science and technology beyond text to help deliver their reasoning. In section B he describes Myriad's discovery.
"Myriad discovered the precise location and sequence of what are now known as the BRCA1 and BRCA2 genes. Mutations in these genes can dramatically increase an individual’s risk of developing breast and ovarian cancer... Myriad identified the exact location of the BRCA1 and BRCA2 genes on chromosomes 17 and 13. Chromosome 17 has approximately 80 million nucleotides, and chromosome 13 has approximately 114 million...
Within those chromosomes, the BRCA1 and BRCA2 genes are each about 80,000 nucleotides long. If just exons are counted, the BRCA1 gene is only about 5,500 nucleotides long; for the BRCA2 gene, that number is about 10,200. Knowledge of the location of the BRCA1 and BRCA2 genes allowed Myriad to determine their typical nucleotide sequence. That information, in turn, enabled Myriad to develop medical tests that are useful for detecting mutations in a patient’s BRCA1 and BRCA2 genes and thereby assessing whether the patient has an increased risk of cancer. "
Once they found BRCA1&2 they headed for the patent office. Nine claims from 3 of those resultant patents were under consideration here - claims 1, 2, 5, 6 and 7 of US Patent No. 5,747,282; claim 1 of US Patent no. 5,693,473; and claims 1, 6 & 7 of US Patent no. 5,837,492. From Section C, page 6 of the decision:
"Myriad’s patents would, if valid, give it the exclusive right to isolate an individual’s BRCA1 and BRCA2 genes (or any strand of 15 or more nucleotides within the genes) by breaking the covalent bonds that connect the DNA to the rest of the individual’s genome. The patents would also give Myriad the exclusive right to synthetically create BRCA cDNA"
The italics above are mine. Not only did Myriad want control of the 80,000 nucleotide strings in BRCA1 or BRCA2, they wanted control of any 15 nucleotide strand within the 80,000. Any 15 piece nucleotide string that could be chopped out of BRCA1&2 would belong to Myriad.

Justice Thomas then goes on to explain (p7) that once the patents were granted Myriad sued or threatened to sue "entities that performed BRCA testing" ending up with a monopoly as a result. One of the doctors on the receiving end of the Myriad's legal action along with a number of others returned the compliment several years later declaring Myriad's patents invalid. That case eventually reached the Supreme Court via the District Court which ruled against Myriad and the Federal Circuit appeal court which ruled in favour of Myriad (see pp 9-10 for an outline of the decisions in those courts).

In Part II Section A, Justice Thomas describes the provisions of §101 of the Patent Act.
“Whoever invents or discovers any new and useful . . . composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.”
He follows up with an important exception:
We have “long held that this provision contains an important implicit exception[:] Laws of nature, natural phenomena, and abstract ideas are not patentable.” ... Rather, “‘they are the basic tools of scientific and technological work’ ” that lie beyond the domain of patent protection... the Court has explained, without this exception, there would be considerable danger that the grant of patents would “tie up” the use of such tools and thereby “inhibit future innovation premised upon them.” ... The rule against patents on naturally occurring things is not without limits, however, for “all inventions at some level embody, use, reflect, rest upon, or apply laws of nature, natural phenomena, or abstract ideas,” ...patent protection strikes a delicate balance between creating “incentives that lead to creation, invention, and discovery” and “imped[ing] the flow of information that might permit, indeed spur, invention.”
Part II Section B gets onto the meat of the decision.
"It is undisputed that Myriad did not create or alter any of the genetic information encoded in the BRCA1 and BRCA2 genes. The location and order of the nucleotides existed in nature before Myriad found them. Nor did Myriad create or alter the genetic structure of DNA. Instead, Myriad’s principal contribution was uncovering the precise location and genetic sequence of the BRCA1 and BRCA2 genes within chromosomes 17 and 13. The question is whether this renders the genes patentable."
On page 12 Justice Thomas compares Myriad's work to the Chakrabarty case in 1980 where the US Supreme Court held that a modified bacterium used to break down components of crude oil was patentable.
"In this case, by contrast, Myriad did not create anything. To be sure, it found an important and useful gene, but separating that gene from its surrounding genetic material is not an act of invention.
Groundbreaking, innovative, or even brilliant discovery does not by itself satisfy the §101 inquiry." {My emphasis}
...
Myriad found the location of the BRCA1 and BRCA2 genes, but that discovery, by itself, does not render the BRCA genes “new . . . composition[s] of matter,” §101, that are patent eligible." {My emphasis again}
From page 14 onwards Justice Thomas tackles Myriad's patent claims.
Many of Myriad’s patent descriptions simply detail the “iterative process” of discovery by which Myriad narrowed the possible locations for the gene sequences that it sought.6
[Note 6: Myriad first identified groups of relatives with a history of breast cancer (some of whom also had developed ovarian cancer); because these individuals were related, scientists knew that it was more likely that their diseases were the result of genetic predisposition rather than other factors. Myriad compared sections of their chromosomes, looking for shared genetic abnormalities not found in the general population. It was that process which eventually enabled Myriad to determine where in the genetic sequence the BRCA1 and BRCA2 genes reside.]
Myriad seeks to import these extensive research efforts into the §101 patent - eligibility inquiry. Brief for Respondents 8–10, 34. But extensive effort alone is insufficient to satisfy the demands of §101.
Nor are Myriad’s claims saved by the fact that isolating DNA from the human genome severs chemical bonds and thereby creates a nonnaturally occurring molecule. Myriad’s claims are simply not expressed in terms of chemical composition, nor do they rely in any way on the chemical changes that result from the isolation of a particular section of DNA. Instead, the claims understandably focus on the genetic information encoded in the BRCA1 and BRCA2 genes. If the patents depended upon the creation of a unique molecule, then a would-be infringer could arguably avoid at least Myriad’s patent claims on entire genes (such as claims 1 and 2 of the ’282 patent) by isolating a DNA sequence that included both the BRCA1 or BRCA2 gene and one additional nucleotide pair. Such a molecule would not be chemically identical to the molecule “invented” by Myriad. But Myriad obviously would resist that outcome because its claim is concerned primarily with the information contained in the genetic sequence , not with the specific chemical composition of a particular molecule."
In essence this section of the decision amounts to two things - firstly the sweat of the brow or hard work is not enough to make something patentable; and secondly Myriad's specific patent claims are not about chemistry, they are about information. Myriad's claims are "concerned primarily with the information contained in the genetic sequence , not with the specific chemical composition of a particular molecule." {My emphasis} That key point is crucial when the Court later distinguishes the patentability of naturally occurring DNA from that of cDNA.

Another small but important point on page 15 related to Myriad's argument that the US PTO's past practice of awarding gene patents was "entitled to deference". Justice Thomas for the Court simply said "We disagree". The notion that decisions of a patent office should not be subject review in the courts is unsustainable. And even the US government had argued in the Federal and Supreme Courts that isolated DNA was not patent-eligible.

That was it on the patentability of isolated DNA. Yet the Court goes on to make the following enormous (il)logical leap in sanctioning cDNA as patent eligible in Part II Section C on page 16-17 of the decision:
"cDNA does not present the same obstacles to patentability as naturally occurring, isolated DNA segments. As already explained, creation of a cDNA sequence from mRNA results in an exons-only molecule that is not naturally occurring. Petitioners concede that cDNA differs from natural DNA in that “the non-coding regions have been removed.” Brief for Petitioners 49. They nevertheless argue that cDNA is not patent eligible because “[t]he nucleotide sequence of cDNA is dictated by nature, not by the lab technician.” Id., at 51. That may be so, but the lab technician unquestionably creates something new when cDNA is made. cDNA retains the naturally occurring exons of DNA, but it is distinct from the DNA from which it was derived. As a result, cDNA is not a “product of nature” and is patent eligible under §101, except insofar as very short series of DNA may have no intervening introns to remove when creating cDNA. In that situation, a short strand of cDNA may be indistinguishable from natural DNA."
Remember that Myriad's claims are "concerned primarily with the information contained in the genetic sequence , not with the specific chemical composition of a particular molecule." Yet the lab technician doing chemistry "unquestionably creates something new when cDNA is made"? The lab technician doing chemistry may well be breaking up gene molecules, clearing out the intron rubbish and rebuilding the molecules with the clean exon components but s/he does not create new genetic information.  So are we dealing with information patents or chemistry patents here?

Well in Part III the Court says "It is important to note what is not implicated by this decision" but this short conclusion doesn't help deal with the confused interpretation of the information science. It does, however, explain Myriad's confidence that their methods patents have received some re-enforcement.
"It is important to note what is not implicated by this decision. First, there are no method claims before this Court. Had Myriad created an innovative method of manipulating genes while searching for the BRCA1 and BRCA2 genes, it could possibly have sought a method patent.
...
Similarly, this case does not involve patents on new applications of knowledge about the BRCA1 and BRCA2 genes. Judge Bryson aptly noted that, “[a]s the first party with knowledge of the [BRCA1 and BRCA2] sequences, Myriad was in an excellent position to claim applications of that knowledge. Many of its unchallenged claims are limited to such applications.” 689 F. 3d, at 1349.
Nor do we consider the patentability of DNA in which the order of the naturally occurring nucleotides has been altered. Scientific alteration of the genetic code presents a different inquiry, and we express no opinion about the application of §101 to such endeavors. We merely hold that genes and the information they encode are not patent eligible under §101 simply because they have been isolated from the surrounding genetic material."
So there is a hint not only that Myriad's method patents may be ok but that the company is in a strong position to claim such patents. Though they approve cDNA patents where the order of the exons is not altered from the DNA from which they are derived, the Court didn't consider the patentability of naturally occurring DNA where the nucloetides have been shuffled.

To conclude, then, let's return to the heart of the decision where the Court has held that:
"A naturally occurring DNA segment is a product of nature and not patent eligible merely because it has been isolated, but cDNA is patent eligible because it is not naturally occurring."
The case is specifically about information encoded in genes not chemistry. Myriad's claims are "concerned primarily with the information contained in the genetic sequence , not with the specific chemical composition of a particular molecule."

The naturally occurring DNA segments that are the BRCA1&2 genes are products of nature and not patent eligible merely because they have been isolated. The isolation and lopping of a gene out of a DNA chain is not sufficient to engender ownership rights over that gene. Fair conclusion.

However, somehow breaking up those genes, throwing away the useless bits (introns) from the cellular recipe book perspective and putting the functional bits (exons) back together in the same order with the same, naturally occurring, information - doing chemistry which is specifically excluded by the Court (pp14-15) as the focus of this decision - such that they provide the same cellular recipes as those naturally occurring in products of nature, does facilitate (patent time limited) ownership rights over BRCA1&2 cDNA. That, in the words of certain fictional Vulcan of Star Trek fame, is illogical.

The upshot is that Myriad can control the useful information in BRCA1 and BRCA2 genes but not the naturally occurring DNA kind. They are "limited" to controlling the same information except in synthetic cDNA form, once some chemical magic has been deployed, to extract the functionally information free introns. (Remember the introns don't make it into the cellular recipe book).

In summary the Court's decision effectively reads:
  • The dispute is concerned primarily with the information contained in the genetic sequence
  • Myriad cannot control the information in the naturally occurring DNA segments that are the BRCA1 & BRCA2 genes; because these are products of nature and not patent eligible merely because they have been discovered/isolated
  • Myriad can control the same information after some chemistry has tidied up the naturally occurring DNA and turned it into synthetic cDNA 
In other words -

It's not about chemistry.

It's about information.

The information cannot be commercially controlled.

If you do some chemistry the same information can be commercially controlled.

QED.

This not the kind of "logic", I suspect, that Paul Otlet, Henri Le Fontaine or Claude Shannon would recognise as such (and Otlet and Le Fontaine were lawyers!).

I'm tempted to launch again into my diatribe on the absence of scientific and technical understanding of the legislature, the executive, and the judiciary but to those who have made it this far, it's probable you have suffered enough.

Update: On the advice of a much more informed scientist friend, the wonderful Jo Davis, I've tweaked the bullet points under the diagram describing the sequence from DNA through RNA to mRNA and onto amino acids and proteins. Apologies for any confusion.

Wednesday, June 12, 2013

Obama's initial reaction to PRISM leak

The video of President Obama's initial public response, on 7 June, to Edward Snowden's PRISM leaks is available on the White House website. He answers a journalist's question 11min 45s into the video.


Monday, June 10, 2013

ORGCon 2103 FISAAA & PRISM

I finally made it to an ORGCon on Saturday. The conference was opened with a Tim Wu keynote telling some stories from his book, The Master Switch, and closed by John Perry Barlow who, perhaps surprisingly, took a 'we have to embrace transparency even in private data' theme.

Undoubtedly the highlight of the show, though, was Caspar Bowden's deeply informed and passionate delivery of a talk on the US Foreign Intelligence Surveillance Act of 1978 Amendments Act of 2008, data protection and PRISM, the NSA electronic surveillance program. His slides are available online.

Having prefaced his remarks with the fact that he has acquired his knowledge entirely from information in the public domain, Caspar started out with a whistle stop history of intelligence sharing between the UK and US; including Alan Turing's detention at Ellis Island during the war and subsequent 3 month battle with US intelligence bureaucracy to get access to the stuff he had been sent/invited to see. Turing's treatment led to an agreement between the two governments that the US and UK should not spy on each other.

He went on to explain that the FISA law of 1978 was one of the results of the fallout from Watergate. It was paramount, as far as the US Senate Church Committee was concerned, that American citizens should be differentiated sharply from foreigners and not subject to suspicionless surreptitious surveillance by US agents of state.

Everything changed again post 9/11 when President Bush instigated mass warrantless wiretapping and, in 2007, the Protect America Act eliminated the need for warrants, even secret FISA warrants, for government surveillance of foreign intelligence targets "reasonably believed" to be outside of the US; the Act also gave all the telcos involved in illegally facilitating the mass warrantless wiretapping retrospective immunity from prosecution and ended the requirement for targeted warrants. Then in 2008 came the Foreign Intelligence Surveillance Act of 1978 Amendments Act which was renewed at the beginning of 2013.

FISA as it now stands (including the FISAAA) has led to the kind of general broad ranging collect everything warrant the Guardian exposed last week. FISAAA essentially means if you are guilty of not being a US citizen your personal data has no protection in a US cloud. Yet European governments and the EU Commission have effectively been oblivious to this in spite of efforts of Caspar and others to inform them. Much of the reaction to the Fighting cyber crime and protecting privacy in the cloud report was on Twitter, falling into the category of amazement and wondering how exactly such unchecked mass surveillance could be going on. US commentators' reactions were muted, even amongst US civil libertarians who Caspar later accused of being entirely silent on the §1881a 'guilty of being a foreigner' FISA surveillance. The report's authors have had a tough time getting conventional journalists to listen and take them seriously about the issue.

Caspar states with some conviction that there is a lot of misleading PR and outright lying about the complete lack of protection for foreign citizens' personal data in the US cloud, in a commercial and political effort to promote the use of US based cloud services. The notion that US law offers good protection to its citizens, "as good or better as foreign law for foreigners" doesn't withstand any kind of serious scrutiny certainly for non US citizens and not a lot for US citizens e.g. if you look at the cases of William Binney, Thomas Drake or Jacob Applebaum.

You might suggest that encryption is the solution but encryption can only protect data to or from the cloud and “lawful” access (FISA §1881a) reaches inside the SSL. Caspar then went on, convincingly again and expounding in some technical detail, the degree to which evolving platform-as-a-service PaaS facilities will enable scalable mass surveillance. ETSI are already developing LIaaS (Lawful interception as a service) standards! Before going on to make some general remarks about the Guardian disclosures about PRISM, he concluded on FISAAA:
  • EU personal data is naked to FISAAA, contrary to much “Cloudwash” White Paper propaganda – 
  • Whilst the PATRIOT Act is bad, FISAAA is much worse for Cloud data
  • US mass-surveillance over foreign political data in Clouds has been lawful since 2008
  • Astonishingly, the EU Commission, DPAs, MS, MEPs, didn't know about FISAAA 1881a until 2012 
  • There are no practical technical defences in sight 
  • Some LIBE Amendments to the draft DPR have been tabled – Consent-with-drastic-warning and whistle-blower protection are essential
  • Need massive vertical investment in indigenous EU Cloud software platforms and operation
  • And FLOSS has crucial security advantages for Cloud 
  • Proposed new EU data protection regulations have been captured by the surveillance state and commerical interests agendas
On PRISM, Caspar rounded off by saying that in addition to direct documentary evidence of the existence of the programme now being in the public domain, possibly the most significant development last week was the confirmation from James Clapper, the US's Director of National Intelligence, that PRISM was about §1881a of FISAAA (now incorporated as s702 of FISA); §1881a which intentionally targets individuals whose only crime is being guilty of not being a US citizen.

So I'm thinking of adding the following text to my email signature:
Please be aware that this message has, quite likely, been harvested and possibly processed by the NSA, under §1881 FISAAA (now s702 FISA as amended). I am, after all and in fairness to the good guys in the NSA, entirely guilty of the charge of not being a US citizen.
In a final contribution later in the day to the excellent ORGCon 2013, Caspar, at the end of John Perry Barlow's closing keynote, managed to elicit an initially reluctant admission from the EFF founder that the silence from US civil liberties groups on §1881a's blanket licence for the US to spy on the rest of the world had been deafening. When he got JPB to agree to encourage the EFF board to make a noise about §1881a it produced one of the loudest ovations of the day.

In any case, I'm sure ORG will be making audios and videos of the various sessions available in due course and I hope I've convinced at least a few that an hour set aside to view Caspar Bowden's talk would be well worth the investment.

Thanks generally to ORG organisers and volunteers for facilitating such a useful event.

Update: my Google Drive embedded version of  Caspar's slides was causing clunky page loading problems so I've removed the embed code from this post. The version of the slides on the ORG site is much more readable in any case and the video of Caspar's talk is now available on ORG's YouTube channel.

Thursday, June 06, 2013

US ITC order Apple to stop importing/selling certain devices

The US International Trade Commission has issued a limited exclusion order prohibiting Apple from importing or selling "wireless communication devices, portable music and data processing devices, and tablet computers" that infringe one of Samsung's patents

The Commission decided that Samsung proved that the iPhone 4 (AT&T models); iPhone 3GS (AT&T models); iPhone 3 (AT&T models); iPad 3G (AT&T models); and iPad 2 3G (AT&T models) infringe the relevant patent (claims 75-76 and 82-84 of US Patent No. 7,706,348). They dismissed Samsung's claims about Apple's alleged infringement of three other patents.

One commissioner, Commissioner Pinkert, dissented from the majority on public interest grounds.

President Obama has the power to veto the ITC decision within 60 days and Apple are also planning to appeal it through the US federal courts.

A copy of the order is below.

UNITED STATES INTERNATIONAL TRADE COMMISSION Washington, D.C.

In the Matter of
CERTAIN ELECTRONIC DEVICES,INCLUDING WIRELESS COMMUNICATION DEVICES,PORTABLE MUSIC AND DATA PROCESSING DEVICES, AND TABLET COMPUTERS

Inv. No. 337-TA-794

NOTICE OF THE COMMISSION’S FINAL DETERMINATION FINDING A VIOLATION OF SECTION 337; ISSUANCE OF A LIMITED EXCLUSION ORDER AND A CEASE AND DESIST ORDER; TERMINATION OF THE INVESTIGATION

AGENCY: U.S. International Trade Commission.
ACTION: Notice.

SUMMARY:
Notice is hereby given that the U.S. International Trade Commission has found a violation of section 337 in this investigation and has issued a limited exclusion order prohibiting respondent Apple Inc. of Cupertino, California (“Apple”), from importing wireless communication devices, portable music and data processing devices, and tablet computers that infringe claims 75-76 and 82-84 of U.S. Patent No. 7,706,348 (“the ’348 patent”). The Commission has also issued a cease and desist order against Apple prohibiting the sale and distribution within the United States of articles that infringe claims 75-76 and 82-84 of the ’348 patent. The Commission has found no violation based on U.S. Patent Nos. 7,486,644 (“the ’644 patent”), 7,450,114 (“the ’114 patent”), and 6,771,980 (“the ’980 patent”). The Commission’s determination is final, and the investigation is terminated.

FOR FURTHER INFORMATION:
Clark S. Cheney, Office of the General Counsel, U.S.International Trade Commission, 500 E Street, S.W., Washington, D.C. 20436, telephone(202) 205-2661. Copies of non-confidential documents filed in connection with this investigation are or will be available for inspection during official business hours (8:45 a.m. to 5:15 p.m.) in the Office of the Secretary, U.S. International Trade Commission, 500 E Street,S.W., Washington, D.C. 20436, telephone (202) 205-2000. General information concerning the Commission may also be obtained by accessing its Internet server (http://www.usitc.gov). The public record for this investigation may be viewed on the Commission’s electronic docket (EDIS) at
http://edis.usitc.gov. Hearing-impaired persons are advised that information on this matter can be obtained by contacting the Commission’s TDD terminal on (202) 205-1810.

SUPPLEMENTARY INFORMATION:
The Commission instituted this investigation on August 1, 2011, based on a complaint filed by Samsung Electronics Co., Ltd. of Korea and Samsung Telecommunications America, LLC of Richardson, Texas (collectively, “Samsung”).

76 Fed. Reg. 45860 (Aug. 1, 2011). The complaint alleges violations of section 337 of the Tariff Act of 1930, as amended (19 U.S.C. § 1337), in the importation into the United States, the sale for importation, and the sale within the United States after importation of certain electronic devices, including wireless communication devices, portable music and data processing devices,and tablet computers, by reason of infringement of various U.S. patents. The notice of investigation names Apple as the only respondent. The patents remaining in the investigation are the ’348, ’644, ’114, and ’980 patents. The complaint also alleged infringement of U.S. Patent No. 6,879,843, but the investigation with respect to that patent was previously terminated based on withdrawn allegations.

On September 14, 2012, the presiding administrative law judge (“ALJ”) issued his final initial determination (“ID”) finding no violation of section 337 based on the four patents remaining at issue. The ALJ determined that the ’348, ’644, and ’980 patents are valid but not infringed and that the ’114 patent is both invalid and not infringed. The ALJ further determined that the economic prong of the domestic industry requirement was satisfied with respect to the remaining asserted patents, but that the technical prong was not satisfied for any of those patents.

On October 1, 2012, complainant Samsung and the Commission investigative attorney(“IA”) filed petitions for review of the ID, while Apple filed a contingent petition for review.

On November 19, 2012, the Commission determined to review the ID in its entirety.
77 Fed. Reg. 70464 (Nov. 26, 2012). The Commission issued a public notice requesting written submissions from the parties and the public on various topics, many of which concerned the Commission’s authority to issue a remedy for the importation of articles that infringe patents that the patent owner has stated it will license on fair, reasonable, and non-discriminatory(“FRAND”) terms. Other topics concerned patent issues specific to this investigation. The Commission received written submissions from Samsung, Apple, and the IA addressing all of the Commission’s questions. In response to the FRAND-related topics posed to the public, the Commission received responses from the following: Association for Competitive Technology; Business Software Alliance; Ericsson Inc.; GTW Associates; Hewlett Packard Company; Innovation Alliance; Intel Corporation; Motorola Mobility LLC; Qualcomm Incorporated; Research In Motion Corporation; and Sprint Spectrum, L.P.

On March 13, 2013, the Commission issued another public notice requesting written submissions from the parties and the public on various additional topics, including some FRAND-related topics. 78
Fed. Reg. 16865 (March 19, 2013). The Commission received written submissions from Samsung, Apple, and the IA addressing all of the Commission’s questions. In response to the FRAND-related topics posed to the public, the Commission received responses from the following: Association for Competitive Technology; Business Software Alliance; Cisco Systems, Inc.; Hewlett Packard Company; Innovation Alliance; Micron Technology, Inc.; and Retail Industry Leaders Association.

Having examined the record of this investigation, including the ALJ’s final ID and submissions from the parties and from the public, the Commission has determined that Samsung has proven a violation of section 337 based on articles that infringe claims 75-76 and 82-84 of the ’348 patent. The Commission has determined to modify the ALJ’s construction of certain terms in the asserted claims of the ’348 patent, including “controller,” “10 bit TFCI information,” and “puncturing.” Under the modified constructions, the Commission has determined that Samsung has proven that the accused iPhone 4 (AT&T models); iPhone 3GS(AT&T models); iPhone 3 (AT&T models); iPad 3G (AT&T models); and iPad 2 3G (AT&T models) infringe the asserted claims of the ’348 patent. The Commission has further determined that the properly construed claims have not been proven by Apple to be invalid and that Samsung has proven that a domestic industry exists in the United States with respect to the ‘348 patent.The Commission has determined that Apple failed to prove an affirmative defense based on Samsung’s FRAND declarations.

The Commission has determined that Samsung has not proven a violation based on alleged infringement of the ’644, ’980, and ’114 patents. With some modifications to the ALJ’s analysis, the Commission has determined that the asserted claims of the ’644 and ’980 patents are valid but not infringed and that the asserted claims of the ’114 patent are not infringed and are invalid. The Commission has further determined that Samsung did not prove a domestic industry exists in the United States relating to articles protected by the ’644, ’980, and ’114 patents.

The Commission has determined that the appropriate remedy is a limited exclusion order and a cease and desist order prohibiting Apple from importing into the United States or selling or distributing within the United States wireless communication devices, portable music and data processing devices, and tablet computers that infringe claims 75-76 and 82-84 of the ’348 patent. The Commission has determined that the public interest factors enumerated in section 337(d)(1)and (f)(1) do not preclude issuance of the limited exclusion order and cease and desist order. The Commission has determined that Samsung’s FRAND declarations do not preclude that remedy.

Finally, the Commission has determined that a bond in the amount of zero percent of the entered value is required to permit temporary importation during the period of Presidential review (19 U.S.C. § 1337(j)) of wireless communication devices, portable music and data processing devices, and tablet computers that are subject to the order. The Commission’s order and opinion were delivered to the President and to the United States Trade Representative on the day of their issuance. Commissioner Pinkert dissents on public interest grounds from the determination to issue an exclusion order and cease and desist order.

The authority for the Commission’s determination is contained in section 337 of the Tariff Act of 1930, as amended (19 U.S.C. § 1337), and in Part 210 of the Commission’s Rules of Practice and Procedure (19 C.F.R. Part 210).

By order of the Commission.

Lisa R. Barton
Acting Secretary to the Commission

Issued: June 4, 2013