Saturday, November 02, 2013

Debate on oversight of intelligence & security services Part 1

The UK parliament finally got round to debating the implications of the Snowden revelations on Thursday afternoon, 31 October. The Hansard record of the debate is now available. Thanks to the Open Rights Group for pointing out TheyWorkForYou.com also have a transcript of proceedings. With a handful of exceptions it was depressingly ill-informed and two dimensional. Contributors were either
  • Against mass surveillance - and make no mistake that is what this blanket electronic data collection, processing and retention is, even if you, as so many of the pro faction did, contend that there is no surveillance if only the computers 'see' the data - and, sadly, for "balancing" privacy and security, the false underlying assumption being that these are opposites; whilst insisting that doesn't mean they don't support the hard working intelligence & security services; and noting that the brave Guardian has done us all a public service and it was appalling they were accused of undermining national security when they hadn't
Or
  • For mass surveillance in the mistaken belief that it will help our hard working boys and girls in the security services to catch those bad bad bad terrorists; and anyone who has the appalling cheek to question the integrity of the security services is just a lover of pedophiles, terrorists, drug dealers and other criminals; and by the way the Guardian are treacherous traitors who had undermined national security because the anti mass surveillance crowd had no proof that they hadn't; with the occasional dose sarcasm from those who could not muster up sufficient pompous indignity - why are you fools so shocked that spies are doing their job and spying?
Julian Huppert (anti) opened the debate.
"As technology changes and the capacity of the state and companies to collect and analyse data grows massively, we are in danger of sleepwalking into a surveillance society on a scale that peacetime Britain has never seen. It is not planned, and nor is it the actions of malevolent individuals; it is merely the natural trend of what will happen if nothing is done to stop it.
It can be argued that the definitions of war and peace are no longer the same, and that our enemies are faceless and splintered and will attack our way of life if we give them an inch—that argument is often made by Prime Ministers and Home Secretaries—but if we shape our laws solely in response to that fear, chipping away at our own liberty and privacy, those enemies have already won.
The key questions of security, privacy and liberty in a digital age will come to define the 21st century. The world is changing. All of us carry around tracking devices, in the shape of our mobile phones, wherever we go. We carry devices that can be activated and controlled remotely and that store much of our most personal information. Who can read it? Who has access to that information? How do we want to protect it? We have to agree the rules now, before we lose control completely."
Julian Smith (pro), who else, interrupted to say
" Does my hon. Friend agree that the very people about whom he is talking have been put under grave threat by some of the reporting, particularly by The Guardian newspaper, of the leaks?"
D Huppert responded:
"No, I do not. I understand that the secretary who looks at the defence advisory notices has confirmed that nothing has been published in The Guardian that suggests a risk to life. The Guardian has not published photos on its website of anybody who works in the area without pixellating their faces."
Touché! That'll be a reference to Mr Smith publishing a photo on his official website of staff from Menwith Hill without pixellating their faces.

Caroline Lucas (anti) stepped in to make the point that the obsession with the Guardian was extraordinary. Wide ranging debates about mass surveillance were taking place all over the world and the UK is trying to stifle discussions and shoot the messenger.

Mr Huppert went on to suggest the UK sign up to the International Principles on the Application of Human Rights to Communications Surveillance. He also asked if we would be concerned if we found out the Chinese were tapping the prime minister's phone and by the way a Chinese company, Huawei, supply a lot of the equipment that makes up the core of our network infrastructure.
"I suspect that our intelligence agents would not miss the chance to install some equipment if we were given the chance to put in the backbone of the Chinese internet, so we should not assume that the Chinese would miss such an opportunity...
Individual surveillance is one thing, but the mass hoovering up of information enabled by new technologies has changed the system completely. It means that suspicion no longer comes first. I think that very few people think it inappropriate to target individuals where there is a serious suspicion of wrongdoing, but in the new approach, we are all suspects whose personal histories can be foraged through if ever there is interest in us later."
ID card cheerleader and former Home Office minister Blears popped up to give us the benefit of her er wisdom - mass surveillance was essential and stopped loads of terrorist plots in her day. The usual vague claims of secret amazing success and no mention of the flawed decision making leading to the shooting of innocent men and the killing and maiming of hundreds of thousands of innocents in Iraq and Afghanistan.

Once Julian Huppert concluded his contribution the chair of the session, Linda Riordan, said 12 people wanted to speak so she'd be imposing a 10 minute limit on each. Just think of that. On something as important as the operating and oversight of an infrastructure of mass surveillance, only a dozen of our 650 members of parliament could be bothered to show up with some prior preparation.

Tom Watson was next up and, disappointed he was only getting 10 minutes, posted the full speech he would have made on his website.
"At the heart of this cross party debate today is GCHQ’s own big data programme, Tempora, and its impact upon our citizens’ fundamental rights. It’s a new and profoundly challenging issue for policy makers. We have to answer questions about the nature, the scale and the depth of surveillance that should be tolerated in our democracy...
And let us be clear, if the Minister is telling us that the law permits such fundamental abuse of liberty, then the law is wrong, and the law must be changed.
I suspect the minster may point to section 16 of RIPA to suggest the Tempora programme is legal.
Interpreting S.16 of RIPA requires unravelling a triple-nested inversion of meanings, across six cross-referenced sub-sections, linked to a dozen other cross-linked definitions, and all dependent on a highly ambiguous “notwithstanding”.
It is probably the single most confusing and complex drafting ever put on the statute book, and I have heard that a former GCHQ Director said that it was drafted this way intentionally...
There is not a snowball’s chance on a hot day in Strasbourg that this will pass the tests of foresee ability and quality of law required by the European Convention (of Human Rights)"
I can't disagree with him about the spaghetti code of s16 of RIPA. Mr Watson's other significant contribution was in noting the practice of stripping citizenship from individuals with suspected terrorist connections.
"The Bureau of Investigative Journalism has highlighted the uneasy relationship between deprivation of citizenship, intelligence sharing with US, and targeting of former British citizens in drone strikes in Somalia. The concern is that citizenship may remove one obstacle on information sharing for the purpose of targeting British people...
David Ormand ex head GCHQ...mentioned the ‘ethically ambiguous position of the British public’ here because, he said, people here had benefited from the US drone programme, even though it would not be permitted in the UK. This can’t be right – the British public would surely be alarmed to hear that data collected in UK or on British citizens (or indeed anyone else) might end up being used to implement the US targeted killing programme – described as war crimes by Amnesty international."
Next up was the third co-sponsor of the debate, Dominic Raab (anti mass surveillance). He paid tribute to MI5 Director Andrew Parker for an under-reported aspect of his recent speech.
"While discussing trying to reduce the terrorist threat, he observed:
“In a free society ‘zero’ is of course impossible to achieve...A strong record of success risks creating an expectation of guaranteed prevention. There can be no such guarantee.”
Similarly, any democratic Government must be accountable to their citizens, particularly if they impinge on their citizens’ freedoms in the necessary pursuit of security. In recent years, UK surveillance of its citizens has increased exponentially, and the legal basis has sometimes, and now regularly, appeared strained at best. Oversight is frayed and legitimate debate is at risk of being drowned out by frankly untested assertions of national security.
In June, The Guardian published revelations by US National Security Agency whistleblower Edward Snowden that GCHQ was clandestinely tapping transatlantic fibre-optic cables, giving almost unfettered access to people’s phone call records, e-mails, Facebook entries and the like. The legal basis for Operation Tempora looks thin at best, and Parliament certainly had no idea of the scale of the use of those powers.
We also learned that Britain receives data from the US Prism surveillance programme, which appears to allow GCHQ to dilute—not circumvent entirely, but dilute—the safeguards that would apply if the same agencies were to gather the information themselves."
Mr Raab was particularly robust in rebuking the fear mongering of an intervening MP who was implying that terrorists are everywhere
" I thank my hon. Friend for his intervention, but he is wrong as a matter of fact. According to the terrorist threat assessment given publicly in annual speeches by successive director-generals at MI5, there was a spike—
My hon. Friend is shaking his head, but this is what the MI5 director-general said, so we ought to pay it some heed. There was a spike after 9/11, but it then dipped. In the most recent speech, given this month, the director-general said that the threat had not got worse...
In this month’s speech, the MI5 director-general also lambasted The Guardian for handing terrorists a “gift”—he used a potent word. More recently, Ministers have claimed that the disclosures have put lives at risk. I want to take that seriously, because Mr Parker claimed that making public
“the reach and limits of GCHQ techniques”
breaches national security. To be clear about what was being discussed, the newspaper was not disclosing interception techniques—the technical aspect—or revelations of sources or operatives, which would clearly be a major source of concern, but simply revealing our intelligence “reach”. I find the assertion that was made difficult to take at face value. The contention may be true, but it cannot be taken on mere assertion.
Any serious terrorist groups assume that their phones, e-mails and internet use will be monitored. That is no secret, and learning that Western spies drain the swamp of their own citizens’ data in the process does not aid terrorists in any tangible way. If national security had been materially breached, why has no one at The Guardian been charged or even arrested since the search of its offices back in July? Why was David Miranda not arrested and bailed, following his detention for several hours at Heathrow, in August?
Either UK law enforcement is surprisingly slow—given the assertions—or national security is being used as a fig leaf to muzzle disclosures that are just plain embarrassing.
I accept, by the way, that the disclosure that 850,000 contractors can access data from Project Tempora represents a security concern, but of course that vulnerability is entirely of the Government’s own making.
I am prepared to be proven wrong about all that, but Ministers and intelligence chiefs need to understand that the bald assertion of national security cannot be used to guillotine all debate. We are here to correct that understanding. Without revealing details that would prejudice the work of the security services, we need a coherent explanation of the damage to national security, not only vague and opaque assertions.
From reports in The Guardian, we also know that the Government are concerned about the legality of the powers that they are using—fears that public debate might lead to litigation, fears about legal challenge under the Human Rights Act. Those are legitimate concerns. I recall similar ones from my own experience of working with the agencies as a Foreign Office lawyer. Those, however, are altogether more nuanced concerns than the shrill and unsubstantiated suggestion that we have somehow lost track of terrorist plotters as a result of the revelations."
Very well said. He went on to assert with some justification that successive governments have been remiss in pushing and deploying mass surveillance, that the Intelligence & Security Committee charged with overseeing the security services is not fit for purpose and that, as Karl Popper said
“We must plan for freedom, and not only for security, if for no other reason than only freedom can make security more secure.”
He then concluded:
"We need to pursue our security in a way that respects our freedoms, limits incursions to genuine cases of national security and does so under a regime that commands the rule of law. Failing to do that would be the real gift to the terrorists—a victory for everything that they believe in and a blow against everything we stand for."
Mr Raab is to be congratulated for one of the few thoughtful and balanced contributions to the debate and his speech should be read in full by anyone with a serious interest in or commitment to democracy. And thanks to him, Dr Huppert and Mr Watson, who were also reasonably well briefed (though I'd encourage Dr Huppert to avoid repetition of the security v privacy balance false dichotomy), for finally getting the matter raised in a parliamentary debate. It was a shame though not unexpected that the debate itself, with some exceptions, descended into little more than sales pitches and sniping from opposite sides, the anti mass surveillance crowd being marginally the better informed of the two.

I'll post some further thoughts on the debate when I get the chance.

Update: Part 2 and Part 3 now done.

Thursday, October 31, 2013

Oversight of the intelligence and security services

Parliamentary debate on oversight of the intelligence and security services started 1.30pm, Thursday, 31 October 2013.

Beware the kite-flyers on surveillance, legal aid, judicial review

Retired Appeal Court judge, Stephen Sedley, is always good value. I'd recommend his "Beware Kite-Flyers" piece in the London Review of Books Vol. 35 No. 17 · 12 September 2013 pages 13-16. It is ostensibly a review of The British Constitution: A Very Short Introduction by Martin Loughlin
Oxford, 152 pp, £7.99, April, ISBN 978 0 19 969769 4.  

"a statutory surveillance regime shrouded in secrecy, part of a growing constitutional model which has led some of us to wonder whether the tripartite separation of powers – legislature, judiciary, executive – conventionally derived from Locke, Montesquieu and Madison still holds good. The security apparatus is today able in many democracies to exert a measure of power over the other limbs of the state that approaches autonomy: procuring legislation which prioritises its own interests over individual rights, dominating executive decision-making, locking its antagonists out of judicial processes and operating almost free of public scrutiny. The arbitrary use of sweeping powers of detention, search and interrogation created by the (pre-9/11) Terrorism Act, which recently made headlines with the detention of David Miranda at Heathrow, illustrates a long-term shift both in what is constitutionally permissible and in what is constitutionally acceptable. The former may be a matter for Parliament, but the latter is still a matter for the rest of us."
He is also scathing about the Blair government's "making the Lord Chancellorship a secondary occupation of the new secretary of state for justice" and the current government's cynical exploitation of that change to dismantle our legal aid and judicial review processes.
"The decision in 2012 to put a political enforcer, Chris Grayling, in charge of the legal system carried a calculated message: the rule of law was from now on, like everything else, going to be negotiable. The incoming legal aid reforms were introduced by a consultation paper which gave a dismissively short time for responses and parodied its own case for attenuating legal aid by pointing out that people affected by unlawful state action ‘may represent themselves in court, seek to resolve issues by themselves, pay for services which support self-resolution, pay for private representation or decide not to tackle the issue at all’. This is an argument not for modifying or reducing legal aid but for abolishing it, something the Treasury has wished it could do for half a century, but which the consultation paper, describing legal aid as a ‘hallmark of a fair, open justice system’, purports not to support.Instead, Grayling’s proposal is to undermine judicial review by starving claimants of legal aid on several fronts...
In recent years a practice has developed – routinely denied by ministers but privately confirmed by their civil servants – of flying kites as lightning conductors: a consultation paper or a bill will include an outrageous proposal which government neither needs nor particularly wants (an example in the legal aid consultation was the proposal, now dropped, to deny criminal defendants any choice in the lawyer to represent them). When it has served its purpose of distracting attention from other objectionable provisions, it can be abandoned. The trouble is that there are so many other objectionable proposals in the current legal aid consultation, it’s not easy to know which, if any, of them are kites. What we do know is what the 145 barristers who, as members of the attorney-general’s panels, argue cases on behalf of the central state, wrote to him in their joint letter: ‘We consider that the proposals in the consultation paper will undermine the accountability of public bodies to the detriment of society as a whole and the vulnerable in particular.’"

Monday, October 28, 2013

Schneier and Drake at the Stop Watching Us rally

Bruce Schneier and Thomas Drake talking sense at the Stop Watching Us rally in Washington DC on 26 October 2013.

Saturday, October 26, 2013

Jesselyn Radack reads Snowden statement at Stop Watching Us rally

Jesselyn Radack, the Government Accountability Project's National Security & Human Rights Director, read the following statement from Edward Snowden at the Stop Watching Us rally today:
In the last four months, we’ve learned a lot about our government. We’ve learned that the US Intelligence Community secretly built a system of pervasive surveillance.
Today, no telephone in America makes a call without leaving a record with the NSA. Today, no Internet transaction enters or leaves America without passing through the NSA’s hands. Our representatives in Congress tell us this is not surveillance. They’re wrong.
We’ve also learned this isn’t about red or blue party lines. Neither is it about terrorism.
It is about power, control, and trust in government; about whether you have a voice in our democracy or decisions are made for you rather than with you. We’re here to remind our government officials that they are public servants, not private investigators.
This is about the unconstitutional, unethical, and immoral actions of the modern-day surveillance state and how we all must work together to remind government to stop them. It’s about our right to know, to associate freely, and to live in an open society.
We are witnessing an American moment in which ordinary people from high schools to high office stand up to oppose a dangerous trend in government. We are told that what is unconstitutional is not illegal, but we will not be fooled.
We have not forgotten that the Fourth Amendment in our Bill of Rights prohibits government not only from searching our personal effects without a warrant but from seizing them in the first place. Holding to this principle, we declare that mass surveillance has no place in this country.
It is time for reform. Elections are coming and we’re watching you.

Letter to MP re parliamentary debate on surveillance

Following a prompt by the Open Rights Group I have written to my MP asking she intervene positively on the side of privacy or at least follow her conscience rather than party orders in the debate on mass surveillance in parliament next Thursday. Copy of my note below.
Dear Ms Blackwood,
As you know, MPs Tom Watson, Julian Huppert and Dominic Raab have secured a 'Westminster Hall' debate in Parliament next Thursday, on 'oversight of intelligence and security services.'
Intelligence agencies have significant powers to collect and analyse private information. It is Parliament's responsibility to ensure these are necessary, proportionate and that they are not abused.
We now know from Edward Snowden's leaks that GCHQ has developed a range of mass surveillance programmes, for example the tapping of undersea fibre-optic cables under the codename 'Tempora'. From the information published so far, it seems clear that surveillance law is unfit for the digital age and that significant reforms are needed.
Debates about the limits of surveillance and the oversight of intelligence agencies are being held in America and across Europe including potentially historic hearings on the matter in the EU parliament LIBE civil liberties committee. Whether the latter hearings come to be seen as historic will largely, of course, depend on the change they can effect.
MPs in the UK, however, have seemed reluctant to take the initiative and discuss mass surveillance by UK intelligence services. And so far the Government have only seemed worried about whether newspapers should have told us anything about the surveillance.
It is high time a substantial debate took place in the UK too. The debate next Thursday will be the first substantial debate in Parliament about the mass surveillance revealed by Edward Snowden. It is an opportunity to begin the process of updating our surveillance laws so they better respect our privacy and are more fit for purpose in facilitating targeted electronic surveillance with the appropriate checks, balances and oversights to inhibit the abuse of such laws.
I'm writing to ask you to speak up about this issue in the debate. There is a long and a short articulation of why this issue is one of the most fundamental questions of the information age. I appreciate you are busy so I'll use the short version. Simply speaking the evolving infrastructure of our surveillance state represents a clear and present danger to our democracy. If that sounds like hyperbole then I would just ask you to take some time to read two essays on the subject by hugely respected commentators - Bruce Schneier's Power in the Age of the Feudal Internet available at http://en.collaboratory.de/w/Power_in_the_Age_of_the_Feudal_Internet and Evgeny Morozov's The Real Privacy Problem at http://www.technologyreview.com/featuredstory/520426/the-real-privacyproblem/
I would ask that you consider the issues carefully and draw your own conclusions rather than follow the party line. The matter is far too serious to be in the business of just following orders.
If you would like some further details don't hesitate to get in touch. I'd leave you with one final thought. Nearly 250 years ago, Lord Chief Justice Camden decided that government agents are not allowed to break your door down and ransack your house and papers in an effort to find some evidence to incriminate you (the case of Entick v Carrington (1765) 19 Howell’s State Trials 1029, 2 Wils 275, 95 ER 807, Court of Common Pleas).
The good judge also declared personal papers to be one’s “dearest property”. I suspect he might view personal data likewise in the internet age. I understand Lord Camden's reasoning in Entick became the inspiration behind the 4th Amendment to the US Constitution which offers protection from unreasonable searches and seizures. For a quarter of a millennium, fishing expeditions of the type that the GCHQ and NSA are engaged in have been considered to fundamentally undermine the rule of law. It's time Parliament brought these modern practices into line with that rule of law.
Thanks for your time and consideration.
Regards,
Ray Corrigan

Friday, October 25, 2013

Tapping Merkel's phone and other stories

It's been a bumper week for Snowden revelations and EU reactions to them.

Monday
The French government expressed their disapproval via Prime minister Jean-Marc Ayrault and President Hollande of the industrial scale tapping of French telephones by the US.

Former editor of The Times and the Sunday Times, Harold Evans, felt compelled to defend the Guardian in the face of government and other news outlets accusations that the paper was undermining national security.
"No editor in his right mind wants to give aid and comfort to murderous enemies, but every editor is duty-bound to scrutinise the use of power – responsibly but fearlessly"
The EU Parliament LIBE Committee on Civil Liberties, Justice and Home Affairs voted through the complex 'General Data Protection Regulation' (Rapporteur: Jan Philipp Albrecht) and the 'Protection of individuals with regard to the processing of personal data by competent authorities for the purposes of prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, and the free movement of such data (Directive)' (Rapporteur (and former Greek foreign minister): Dimitrios Droutsas). Those MEPs sure know how to coin a catchy title. The associated press release painted a rosy picture of how the new regulations are going to put people
"in control of their personal data while at the same time making it easier for companies to move across Europe...
Responding to mass surveillance cases, MEPs inserted stronger safeguards for data transfers to non-EU countries. They also inserted an explicit consent requirement, a right to erasure, and bigger fines for firms that break the rules."
In the US the vote was seen as a stick to beat the US with in the wake of the Snowden leaks on the NSA.surveillance.

Unfortunately, in spite of the best intentions of MEPs, no one can possibly know the effect of the regulations even if they were to see the light of regulatory day in the form the LIBE committee approved them.

Firstly they are hugely complicated.

Secondly they were subject to 3999 amendments, tabled in various EU committees, the highest number with respect to a single legislative file ever in the parliament's history.

Thirdly because Article 6 of the proposed data protection regulations drives a coach and horses through all of the protections:
"Article 6
Lawfulness of processing
1. Processing of personal data shall be lawful only if and to the extent that at least one of the following applies:
[...]
(e) processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
(f) processing is necessary for the purposes of the legitimate interests pursued by the a controller or in case of disclosure, by the third party to whom the data is disclosed..."
Seriously? All those words, clauses, pages, negotiations and protections and buried in the midst of it there is a gigantic get-out-of-data-protection-free provision like this. The government and associated public services can process your data "in the exercise of official authority"; and commerce (including 3rd parties) can do so for the purpose of their own "legitimate interests"? With a loophole that enormous it's hard to believe the UK government are still fighting tooth and nail against the package.

Evgeny Morozov did a lovely job of outlining the clear and present danger to democracy posed by the voracious appetite of government and commerce for personal data when combined with privacy blind unrestrained information consumerism.

The Irish High Court granted Maximilian Schrems leave to pursue a judicial review case against the Irish Data Protection Commissioner. Schrems alleged that that esteemed body's refusal to investigate his complaint in June 2013 in relation to Facebook's actions in connection with the NSA PRISM program was unlawful.

Tuesday
Reporter Glenn Greenwald labelled Julian Smith, the MP who is demanding the Guardian gets prosecuted for endangering national security, an authoritarian functionary.

Mr Smith and security minister James Brokenshire shamefully used the platform of a parliamentary committee to abuse Guardian. All attempts at debate in the committee were curtailed by the chairman.

Privacy International wrote to NSA chief, Keith Alexander regarding their unauthorised access to the international financial messaging system, SWIFT.

A powerful cast of US dignitaries noted their objections to mass surveillance via a very well produced EFF video.

Wednesday
The European Parliament voted to suspend the Terrorist Finance Tracking Program (TFTP) agreement with the US - the transfer of the SWIFT finance data of European citizens to the US.

Dutch MEP Sophie in t Veld was pleased
The Commission in the form of Commissioner Malmström rapidly moved to calm US and UK jitters on the matter by issuing a statement saying they would "take note" of the vote and that they "have no indications that the TFTP Agreement has been violated" by the NSA. The Commission have asked for assurances that the agreement has not been violated and
"In the meantime, the provisions of the TFTP Agreement that clearly regulate the transfer of personal data, and that provide effective safeguards to protect the fundamental rights of Europeans, will remain in place."
MEPs also voted for enhanced whistleblower protections but Commissioner Malmström scuppered that notion too:
"For the time being, the commission does not however intend to propose new legislation on the definition of corruption or approximations of statutes or limitations of corruption offences or protection for whistleblowers," 
She's of the opinion that there are adequate international standards in place which will be why Edward Snowden is holed up in Russia of course.

Peter Sommer produced a succinct blueprint of how to engage in better oversight of security and intelligences agencies, specifically GCHQ.

Keith Alexander, head of the NSA, continued to defend his right to defend America in cyberspace.

Thursday
German Chancellor Merkel was reported as being rather upset that the NSA had been bugging her phone since at least 2006. Even the Taoiseach thought it might be a good idea to speak up against such misbehaviour.

So with France and Germany now less than enamoured with US digital shenanigans, the best laid plans of officials for the EU leaders' meeting got slightly sidetracked.

Friday
It wasn't just you Ms Merkel - the NSA monitored the calls of 35 world leaders. So Ms Merkel and Mr Hollande are agreed then that they should have a chat with the US government and that they might well be, contrary to popular belief, undermining the fight against terrorism.

Even David Cameron can't find a way out of signing a relatively innocuous statement from the EU leaders complaining about US surveillance. He hasn't changed his mobile phone though, so I assume he's got nothing to hide...

Some consolation for Mr Cameron was that he may have managed, with Chancellor Merkel's support and the disapproval of certain members of the Commission, to scupper the data protection package until 2015, i.e. beyond the next EU parliament elections, the deadline being pushed by the LIBE committee to get the provisions passed.

The EU Commission proposed a comprehensive reform of data protection rules to increase users' control of their data and to cut costs for businesses. They kinda agree with the LIBE committee but not really.

A study done for the EU parliament LIBE civil liberties committee on National Programmes for Mass Surveillance of Personal Data in Member States and their Compatibility with EU Law looks like a fascinating read.
"In the wake of the disclosures surrounding PRISM and other US surveillance
programmes, this study makes an assessment of the large-scale surveillance
practices by a selection of EU member states: the UK, Sweden, France,
Germany and the Netherlands. Given the large-scale nature of surveillance
practices at stake, which represent a reconfiguration of traditional intelligence
gathering, the study contends that an analysis of European surveillance
programmes cannot be reduced to a question of balance between data
protection versus national security, but has to be framed in terms of collective
freedoms and democracy. It finds that four of the five EU member states
selected for in-depth examination are engaging in some form of large-scale
interception and surveillance of communication data, and identifies parallels and
discrepancies between these programmes and the NSA-run operations. The
study argues that these surveillance programmes do not stand outside the
realm of EU intervention but can be engaged from an EU law perspective via (i)
an understanding of national security in a democratic rule of law framework
where fundamental human rights standards and judicial oversight constitute key
standards; (ii) the risks presented to the internal security of the Union as a
whole as well as the privacy of EU citizens as data owners, and (iii) the potential
spillover into the activities and responsibilities of EU agencies. The study then
presents a set of policy recommendations to the European Parliament."
Finally, for now, has the Guardian just got its own back on Julian Smith MP by accusing him of endangering national security? Apparently Mr Smith posted a picture on his official website of him posing with staff from the high-security US base in the UK, Menwith Hill. Mess with the press at your peril.

Thursday, October 24, 2013

Stop watching us: the US video; now where's the UK version?

The EFF has produced a nice video with an impressive cast of characters demanding a halt to mass suspicionless surveillance.



Now how about a UK version with an equally heavyweight cast? There is at least a debate up and running in the US.

Tuesday, October 22, 2013

MP & Minister "debate" aka accuse Guardian of breach of national security

The terms and conditions for embedding video of exchanges in the UK Parliament state that sites that "Lower the dignity of either House or that of individual members" are excluded from posting the recordings. You can judge for yourself whether this site or the particular MP and minister are the ones lowering the dignity of the House or its members in this "debate" on whether Guardian damaged national security.

Just for the record and so no one is in any doubt about my perspective - I believe it was an utter disgrace:


The Guardian bashing starts at 16:30:11. There follows 30 minutes of prepared speeches by Julian Smith MP and security minister James Brokenshire with all efforts to "debate" blocked by the session chairman. This is despite several MPs desperately trying to intervene. David Winnick makes a number of heckling interventions accusing Mr Smith in particular of McCarthyism and of making a "disgraceful speech". Mr Smith responds that Mr Winnick is "a rude man". As soon as Mr Brokenshire finishes his speech the chairman closes the session.

Mr Brokenshire allowed David Davis to make a single intervention to ask if it was so clear that the Guardian has broken the law and endangered national security why has there been no prosecutions? The minister dodged the question saying it was a matter for the police and CPS and continued with his pre-prepared speech.

That a parliamentary debate about one of the most fundamental issues in an information age should be orchestrated in such a manner is contemptible and inexcusable. That most people still won't care is, as John Naughton put it in the Observer this week, is really scary.

Update: the Guardian's own reserved report on Messrs Smith & Brokenshire's performance is now available.
I also recommend Evgeny Morozov's MIT Technology Review essay on how the erosion and neglect of privacy is putting democracy at risk. Extract:
"we can now be pinged whenever we are about to do something stupid, unhealthy, or unsound. We wouldn’t necessarily need to know why the action would be wrong: the system’s algorithms do the moral calculus on their own. Citizens take on the role of information machines that feed the techno-bureaucratic complex with our data. And why wouldn’t we, if we are promised slimmer waistlines, cleaner air, or longer (and safer) lives in return?
This logic of preëmption is not different from that of the NSA in its fight against terror: let’s prevent problems rather than deal with their consequences. Even if we tie the hands of the NSA—by some combination of better oversight, stricter rules on data access, or stronger and friendlier encryption technologies—the data hunger of other state institutions would remain. They will justify it. On issues like obesity or climate change—where the policy makers are quick to add that we are facing a ticking-bomb scenario—they will say a little deficit of democracy can go a long way."

Thursday, October 17, 2013

ORG interviews, the ISC inquiry & Benkler re the Snowden leaks

The Open Rights Group has done a series of interviews about the Snowden leaks with such luminaries as former GCHQ chief David Omand, human rights and freedom of information campaigners Peter Tatchell and Heather Brookes and the former Conservative foreign and defence secretary, Malcolm Rifkind.



Particularly telling is Mr Omand's point that we've got to grow up and have a public debate about the powers of the intelligence services to engage in operational surveillance, what that means in practice and what the boundaries, checks and balances of such powers should be.

Mr Rifkind, comes across as believing in the magic powers of computers, given enough personal data about everyone, to point out the bad guys. It doesn't matter, you see, that the data of the rest of us is in there too; because as long as it's only seen by the computer which grades us as innocents then there is no harm done.

His lack of understanding might not be a problem except for the fact that he is chairman of the parliamentary  Intelligence and Security Committee (ISC) charged with overseeing the work of the intelligence services. The ISC is also the committee that has announced it will look into the Snowden leaks. Unfortunately Mr Rifkind is also framing this inquiry as examining
"the appropriate balance between privacy and security in an internet age...
There is a balance to be found between our individual right to privacy and our collective right to security.
Wrong, wrong, wrong.

It is not about "balancing" privacy and security. They are not opposite sides of the same coin. More privacy does not mean less security any more than more security means less privacy. Door locks and strong fences provide privacy and security. Security gets pitched against privacy in the context of mass surveillance and identity; and the anti-privacy security measures like mass surveillance and identity cards not only don't work but can undermine security. (All the 9/11 attackers had their photo identities checked before boarding their planes.)

If Mr Rifkind does not understand that he should not be chairing such an influential parliamentary committee in this area. If he does understand it he's engaging in manipulative politics, framing the "inquiry" to get pre-ordained "answers".

Even if we did have Mr Rifkind's magic terrorist catching machine and it was 99.9% accurate (no existing surveillance system comes close to this) it would be still be useless.

Why?

Because even if the machine was watching only the 60 million people in the UK, it would wrongly accuse roughly 600,000 innocent people of being terrorists every time it was asked for a suspect. That’s a lot of false leads for the police and security services to follow whilst the bad buys get lost in the noise.

So even if there were 1000 terrorists (unlikely), our 99.9% accurate terrorist catching machine would be wrong more than 99.8% of the time (599,000/600,000).

Yet the machine still might miss the terrorist! Because not only will it wrongly identify innocent people as bad guys, it will also identify real bad guys as innocents.

Tuning the machine to accuse fewer innocents will make it more likely that it will miss the bad guys.
Finding a terrorist is a needle in a haystack problem. You don’t find the needle by throwing more electronic data hay on the stack. It requires targeted, intelligence led surveillance and investigation - targeted intelligence led data preservation not blanket data collection and mass surveillance.

So not only does the Rifkind-approved mass surveillance apparatus not work, it blows a hole in the constitutional, common law, statutory and international protections for privacy.

Yochai Benkler spelt it out nicely in yesterday's Guardian:
"Pervasive surveillance proponents make two core arguments.
First, bulk collection saves Americans from foreign terrorists. The problem with this argument is that all publicly available evidence presented to Congress, the judiciary, or independent executive branch review suggests that the effect of bulk collection has been marginal...
The second argument that defenders of mass surveillance offer is that detailed, complex and faithfully-executed rules for how the information that is collected will be used are adequate replacements for what the fourth amendment once quaintly called "probable cause" and a warrant "particularly describing the place to be searched, and the persons or things to be seized". The problem with this second argument is that it combines two fundamentally incompatible elements.
Mass surveillance represents a commitment to near-universal all-seeing gaze, so as to assess and respond to threats that can arise anywhere, at any time. Privacy as a check on government power represents a constitutional judgment that a limited government must have limited power to inspect our daily lives, and that an omniscient government is too powerful for mere rules to restrain. The experience of the past decade confirms this incompatibility...
Technology has enabled government to have investigative and situational awareness on a scale and scope that were science fiction when the Stasi shut its doors. The "state of emergency" mindset necessary to justify the program in the first place drives those charged with assuring the safety of Americans to always use this technology to its full potential; it also gives them an independent source of legitimacy for their actions – the fierce urgency of necessity.
Their mission clashes with the fundamental premise of privacy as a civil right: that state power is best contained by making the overwhelming majority of what goes on in society invisible to the state. As Justice Alito put it in the supreme court's decision to strike down GPS tracking:
[Historically] the greatest protections of privacy were neither constitutional nor statutory, but practical.
Once the state knows about behavior, it is hard to rely on rules alone to bear the full burden of preventing overreach by those who wield its awesome power...
Rules alone cannot hold back the millions of potential abuses of an omniscient state.
As long as government is allowed to collect all internet data, the perceived exigency will drive honest civil servants to reach more broadly and deeply into our networked lives. Bringing an end to mass government surveillance needs to be a central pillar of returning to the principles we have put in jeopardy in the early 21st century."
Mr Tatchell and Ms Brookes, as you would expect, are articulate on the need to protect human rights, expose wrong doing on the part of government, protect whistleblowers and wax skeptical about the constant 'trust us it's a matter of national security' refrain on the part of governments.

Tuesday, October 08, 2013

Machon & Drake at EU LIBE hearing on mass surveillance

Further essential viewing from the LIBE committee hearings on electronic mass surveillance - MI5 whistleblower Anne Machon on Mon, 30 Sep 2013 15:00 - 18:30. If you're watching via the EPTV site Ms Machon's evidence begins at 17:08:50. YouTube copy of Ms Machon's statement and Q&A with her and Tom Drake, whistleblower and former NSA senior executive:



Ms Machon and Mr Drake got several rare rounds of applause from the assembled MEPs. Ms Machon's recommendations to the committee:
  • Mean­ing­ful par­lia­ment­ary over­sight of intel­li­gence agen­cies, with full powers of invest­ig­a­tion, at both national and European levels.
  • These same demo­cratic bod­ies to provide a legit­im­ate chan­nel for intel­li­gence whis­tleblowers to give their evid­ence of mal­feas­ance, with the clear and real­istic expect­a­tion that a full inquiry will be con­duc­ted, reforms applied and crimes punished.
  • Insti­tute a dis­cus­sion about the legal defin­i­tion of national secur­ity, what the real threats are to the integ­rity of nation states and the EU, and estab­lish agen­cies to work within the law to defend just that. This will halt inter­na­tional intel­li­gence mis­sion creep.
  • EU-wide imple­ment­a­tion of the recom­mend­a­tions in the Ech­elon Report (2001):
  1. to develop and build key infra­struc­ture across Europe that is immune from US gov­ern­mental and cor­por­at­ist sur­veil­lance; and
  2. Ger­many and the United King­dom are called upon to make the author­isa­tion of fur­ther com­mu­nic­a­tions inter­cep­tion oper­a­tions by US intel­li­gence ser­vices on their ter­rit­ory con­di­tional on their com­pli­ance with the ECHR (European Con­ven­tion on Human Rights).”
  • The duty of the European par­lia­ment is to the cit­izens of the EU.  As such it should act­ively pur­sue tech­no­logy policies to pro­tect the pri­vacy and basic rights of the cit­izens from the sur­veil­lance of the NSA and its vas­sals; and if it can­not, it should warn its cit­izens abut this act­ively and edu­cate them to take their own steps to pro­tect their pri­vacy (such as no longer using cer­tain Inter­net ser­vices or learn­ing to use pri­vacy enhan­cing tech­no­lo­gies). Con­cerns such as the trust Europeans have in ‘e-commerce’ or ‘e-government’ as men­tioned by the European Com­mis­sion should be sec­ond­ary to this con­cern at all times.
  • Without free media, where we can all read, write, listen and dis­cuss ideas freely and in pri­vacy, we are all liv­ing in an Orwellian dysto­pia, and we are all poten­tially at risk. These media must be based on tech­no­lo­gies that empower indi­vidual cit­izens, not cor­por­a­tions or for­eign gov­ern­ments. The Free Soft­ware Found­a­tion has been mak­ing these recom­mend­a­tions for over two decades.
  • The cent­ral soci­etal func­tion of pri­vacy is to cre­ate the space for cit­izens to res­ist the viol­a­tion of their rights by gov­ern­ments and cor­por­a­tions. Pri­vacy is the last line of defense his­tor­ic­ally against the most poten­tially dan­ger­ous organ­isa­tion that exists: the nation state. There­fore there is no ‘bal­ance between pri­vacy and secur­ity’ and this false dicho­tomy should not be part of any policy debate.
Ms Machon's point in the Q&A session that she signed the Official Secrets Act to save lives and protect official secrets was particularly well made - she did not agree to protect unofficial secrets and cover up the criminal acts of spies which caused the deaths of innocent people.

The official version of Mr Drake's statement to the committee is at http://www.europarl.europa.eu/document/activities/cont/201310/20131001ATT72162/20131001ATT72162EN.pdf. The video of his statement is available on Youtube and I posted a copy here yesterday. He is a terrifically compelling witness.  Any politician, media commentator or anyone else seeking to excuse mass surveillance and secret illegal, criminal or unethical government behaviour in this context should be compelled to explain themselves under Mr Drake's questioning glare. We could call it the Tom Drake test.

Monday, October 07, 2013

Tom Drake statement to LIBE Committee Mass Surveillance hearings

NSA mass surveillance whistleblower Tom Drake's statement to EU Parliament LIBE Civil Liberties, Justice and Home Affairs committee hearing on mass surveillance on Monday, 30 September, 2013:



The Government Accountability Project has published an almost complete transcript of Mr Drake's statement which will probably be a relief to the interpreters at the committee who were finding it difficult to keep up with Mr Drake's fast talking, intense, potent delivery. The sense of justifiable controlled anger and determination emanating from Mr Drake is palpable, even to an observer in a foreign land viewing through the grace of the internet.

Snowden statement to EU LIBE Committee

Edward Snowden's statement to the EU Parliament LIBE Civil Liberties, Justice and Home Affairs committee on Monday, 30 September, 2013:
"I thank the European Parliament and the LIBE Committee for taking up the challenge of mass surveillance. The surveillance of whole populations, rather than individuals, threatens to be the greatest human rights challenge of our time. The success of economies in developed nations relies increasingly on their creative output, and if that success is to continue, we must remember that creativity is the product of curiosity, which in turn is the product of privacy.
A culture of secrecy has denied our societies the opportunity to determine the appropriate balance between the human right of privacy and the governmental interest in investigation. These are not decisions that should be made for a people, but only by the people after full, informed, and fearless debate. Yet public debate is not possible without public knowledge, and in my country, the cost for one in my position of returning public knowledge to public hands has been persecution and exile. If we are to enjoy such debates in the future, we cannot rely upon individual sacrifice. We must create better channels for people of conscience to inform not only trusted agents of government, but independent representatives of the public outside of government.
When I began my work, it was with the sole intention of making possible the debate we see occurring here in this body and in many other bodies around the world. Today we see legislative bodies forming new committees, calling for investigations, and proposing new solutions for modern problems. We see emboldened courts that are no longer afraid to consider critical questions of national security. We see brave executives remembering that if a public is prevented from knowing how they are being governed, the necessary result is that they are no longer self-governing. And we see the public reclaiming an equal seat at the table of government. The work of a generation is beginning here, with your hearings, and you have the full measure of my gratitude and support."
The statement was read on Snowden's behalf by Jesselyn Radack, the Government Accountability Project's Director of Security and Human Rights and a former ethics adviser to the United States Department of Justice. GAP was an early supporter of Edward Snowden following his revelations of secret US and UK government mass surveillance programs.



Jesselyn Radack's full statement to the LIBE committee is also available on YouTube.



It's powerful stuff and well worth setting aside 15 minutes to pay attention to, from the charge that the Bush administration crossed the rubicon with an attack on whistleblowers, in particular Tom Drake, which amounted to a criminalization of the truth, to the fact that in less than a year the Obama administration indicted more people under the Espionage Act than all previous US presidents combined. She respectfully requests that the committee strengthen laws to protect whistleblowers, laws to protect privacy and laws to protect the rights of publishers in the EU to disseminate revelations like those Snowden has exposed without fear of criminal penalty.

Friday, October 04, 2013

BBC Newsnight, Greenwald, Snowden & Entick v Carrington

The BBC finally got round to doing what they might consider an in-depth feature on the Edward Snowden affair last night on Newsnight. I came across it by accident since I rarely watch Newsnight any more but I'd recommend watching it in full before it times out on the iPlayer in 7 days for three reasons -
  • firstly Glenn Greenwald's powerful and passionate critique of the behaviour of the UK & US governments and the weak journalism of the BBC on the Snowden affair
  • secondly it is a classic example of the BBC's determination to report in a way that they perceive to exhibit "balance" i.e. that there are two and only two diametrically opposed sides to every story. The God of 'balance', it seems, trumps objectivety and evidence at the beeb.
  • Ross Anderson's contribution
Kirsty Wark, opening the programme by asking if Snowden's action was "a noble strike against an authoritarian establishment OR an act of vandalism against our national security", gave a taste of things to come. The introductory sequence of the show (I use that word deliberately) goes on to present a video extract of former GCHQ chief, Mr David Ormand, breathlessly saying "not even the KGB in its heyday of  Philby and Burgess and Maclean in the 1950s could have dreamt of acquiring 58,000 highly classfied intelligence documents." With the theme music still running Ms Wark then says they have an exclusive interview with Glenn Greenwald, visible on the studio screen in the background.

There follows 11 to 12 minutes of BBC "balanced" reporting by security correspondent Gordon Corera. You know the sort of thing. Is Snowden the good guy or the bad guy? Are the UK & US governments doing mass surveillance as the good guys to protect us all or the bad guys and spying on us all? All sadly rather superficial.

Ross Anderson is very clear in pointing out that the NSA's actions have more than undermined internet security, they have threatened to break the internet; and quite amusing when explaining that security experts around the world have been astonished that the UK and US governments have managed to build big complex information systems that actually work.

Actually Ross's contribution to that first 12 minutes is probably the one bit of that part if the show worth retaining. Though in fairness to David Ormand, when he says the police and intelligence services need a powerful capability to get at the communications of terrorists, pedophiles and other nefarious actors he's absolutely right, they do. But you don't make that job easier with a mass surveillance - blanket data collection & retention - approach. It has to be done through an intelligence led, targeted data preservation regime. Gordon Corera didn't even present this question to Mr Omand or if he did it didn't make the final cut of the show.

Ross Anderson also explains that the Guardian "revelations in early September that the NSA had had a major covert programme to compromise internet security standards and products were a 9/11 moment" for security specialists globally; and the the goal of the NSA and GCHQ is to ensure they can break anyone's privacy at any given time and interfere with any transaction at any given time. In order to do this they have compromised in various ways many of the protocols on which the internet relies. Yet when you introduce these vulnerabilities they are not just available for the spies to use, they are available to the bad guys too. You can't make people safe by making the communications infrastructure they rely on less secure.

I think Ross is worth quoting in full over his and others' surprise at the NSA and GCHQ's apparent technical competence.
"They pushed it even further than we thought they would. The surprising thing to us was that there appear to be occasional pockets of competence within the NSA and GCHQ. Many of us thought for many years that the real secret was that, like other large public sector IT projects it didn't work; and there was really nobody there. But to find that they had built this machine and got it working was an eye opener."
Glenn Greenwald is introduced at 12 minutes 35 seconds into the programme. It's difficult to capture the passion and power of Mr Greenwald's contribution in a blog post, so I'm not going to try. Instead I'll just point you to the video on YouTube and the Newsnight website. Just to be clear, I don't agree with or endorse the YouTube video poster's opprobrious labelling of Ms Wark or former security minister, Pauline Neville-Jones, as apologists. Given how badly prepared Ms Wark came across in the Greenwald interview, I'm not sure how long the BBC will allow it to remain available on YouTube but here it is for now:



Do watch the 25 minute or so full segment on the Newsnight website whilst it remains available.

Just some final thoughts for readers who are seduced by the argument that the only way for governments to catch the bad guys is to vacuum up the comms data of everyone, could I refer you to the case of Entick v Carrington (1765) 19 Howell’s State Trials 1029, 2 Wils 275, 95 ER 807, Court of Common Pleas.

Nearly 250 years ago, Lord Chief Justice Camden decided that government agents are not allowed to break your door down and ransack your house and papers in an effort to find some evidence to incriminate you.

The short version of the story is that a member of the government, Lord Halifax, had taken a dislike to Mr Entick and ordered Mr Carrington and some of his king’s messengers buddies to dig the dirt to bury the problem with a charge of seditious libel. In court, government lawyers argued that most people subjected to the kind of over-exuberant behaviour exhibited by Carrington & co. were happy to comply and it was rather irritating that Mr Entick was complaining about it. And besides, if the government didn’t have the authority to forcibly extract evidence how could it possibly be expected to deal with terrorists, or in the parlance of the time, purveyors of sedition?

Lord Chief Justice Camden, who had form having sided with another government labelled terrorist, MP John Wilkes, 2 years earlier, didn’t buy the argument. “This power” said he “so claimed by the Secretary of State is not supported by one single citation from any law book extant.”

The good judge also declared personal papers to be one’s “dearest property”. I suspect he might view personal data likewise in the internet age.  I understand Lord Camden's reasoning in Entick became the inspiration behind the 4th Amendment to the US Constitution which offers protection from unreasonable searches and seizures.  The point is, however, that fishing expeditions of the type that the GCHQ and NSA are engaged in fundamentally undermine the rule of law.

Update: Early editions of Bailey, Harris & Jones: Civil Liberties Cases, Materials and Allen, Thompson & Walsh Cases and Materials on Constitutional and Administrative Law, real old books I still have on my shelf, were the sources I referred to in order to double check my ancient memories of Entick v Carrington.

Update 2: BBC Newnight has now posted the full 33 minutes 26 seconds of the Snowden report and interviews to YouTube. Kudos to them



Newsnight's editor Ian Katz has responded to Jay Rosen's criticism of the piece. Former BBC news chief Richard Sambrook also thought "it was an ill-thought through interview and consequently weak. More broadly, for at least 25 years British broadcasting has been enthralled by the adversarial, devil’s advocate, form of interview. Journalists careers have been made and interviewees careers destroyed by it. Personally, as a form, I think it is all but exhausted and is increasingly tiresome – and seldom reveals as much as a more forensic approach could achieve."

Friday, September 27, 2013

Alas medical confidentiality in the UK, we knew it well...

The UK government's disastrous plan to extract all our personal medical data from GP surgery systems and dump it in a, to say the least, inadequately controlled central database, has hit a speed bump.  It seems that the Information Commissioner's Office has decided to inform NHS England that they have not given GPs enough time to hand over the data legally.

Don't get me wrong. The ICO has no intention of blocking this government induced systemic national kneecapping of the Hippocratic oath and the principle of medical confidentiality. They merely want to give GPs more time to let people know it is happening. The government previously refused to fund a publicity campaign explaining they were collecting all UK electronic medical data into one big pot (or actually in practice several big central pots). NHS England did send GPs some posters and leaflets for display in surgeries though.

I'm being a little hard on the ICO here since, in fairness, his power to actually do anything about all this is limited by the way Part 9 of the 2012 Health and Social Care Act, which came into force in April 2013, has been written and additionally the 'get out of medical confidentiality free card' provided by Section 251 of the National Health Service Act 2006.

There are several aspects of this I've been tempted to rant about here for many months - in particular the misleading, false and/or delusional claims on the part of politicians that the data will be anonymised - but I've just had a terrific email from Terri Dowty at medConfidential who sums the situation up better than I could and I'm sure she won't mind me sharing it with you in full:
"Information that you share with your GP is about to be extracted from surgery records and stored on a centralised NHS system with your identifying details still attached. From there, it will be made available for administrative, research and other purposes. The government has claimed that your records will be ‘anonymised’ before they are handed over to anyone else, but this is not true. There are several circumstances in which data that identifies patients will be made available.

Once your information has been uploaded, neither you nor your GP will have any control over who it is shared with, who has access or what is done with it. You will not be consulted, nor will you be asked for consent. Uploads will take place automatically every month.

When you next visit your GP, you may see a small poster headed ‘how information about you helps us to provide better care’. This is how the NHS is explaining its plans to you and it is very misleading. It does not give you full details of the information that will be collected, and it claims that information will not identify you.

Further down the poster you will see the words ‘you have a choice’. What this actually means is: if you do not want personal and confidential information to be taken from your medical record every month, the onus is on you to opt out of the scheme. If you don’t do so, it will be assumed that you consent to the extraction.

You can download an opt-out letter to complete and send to your GP from the medConfidential website:
http://medconfidential.org/how-to-opt-out/
You will also find more detailed information about the scheme – known as ‘care.data’ – on the medConfidential website.

Please tell all of your friends, family and colleagues about this scheme, or forward this email to them. It is very important that everyone knows they must take action if they don’t want their information to leave their GP’s surgery."
The government's plan, if you can call it that, is that data will be made available to researchers in universities, hospitals and commercial organisations.  There is now even a Health & Social Care Information Centre (HSCIC) data access and extraction price list. NHS England's chief data officer, Geraint Lewis, has however, reportedly suggested that the cost of access expanded HSCIC data sets should be reduced from from around £30,000 to a nominal £1.

I'd highly recommended you find 20 minutes in the next few days and read Terri Dowty's and Phil Booth's outline at medconfidential of the rather complex story at play here. It's yet another one of those government giant database cure for all ills stories. Another information system disaster in the making. Another careless metaphorical bullet through the head of a crucial societal value, this time medical confidentiality.

Thursday, September 26, 2013

European Parliament LIBE hearing on mass surveillance Pt2

A more accurate title for this post might be Caspar Bowden's evidence to the European Parliament LIBE hearing on mass surveillance Pt2, since that's the focus. (Pt1 is here) The 63 minute video of Caspar's statement and subsequent Q&A is now available in full on YouTube courtesy of Henrik Alexandersson.



Moving to section 2.2.5 of his report on The US National Security Agency (NSA)surveillance programmes (PRISM) and Foreign Intelligence Surveillance Act (FISA) activities and their impact on EU citizens' fundamental rights, Caspar notes that the collection of foreign intelligence information under the PRISM programme is based on the Patriot Act s215 power. This power is subject to originally classified “minimization” and “targeting” procedures, which were published in full by the Guardian on 20 June this year. These procedures provide no limitations or protections whatsoever for non US nationals. As the report says,
One therefore suspects that US operational practice places no limitations on exploiting or intruding a non - US person's privacy, if the broad definitions of foreign intelligence information are met.
Moreover in a May 2012 letter to the Congress intelligence review committees the government states that:
Because NSA has already made a “foreignness” determination for these selectors·in accordance with its FISC - approved targeting procedures, FBI's targeting role differs from that of NSA. FBI is not required to second - guess NSA's targeting determinations...
The versions of the targeting procedures released are generic, but the American Civil Liberties Union (ACLU) obtained redacted copies of slides related to FBI staff training that referred specifically to FISAAA for counter-terrorism purposes. The letter continues:
Once acquired, all communications are routed to NSA. NSA also can designate the communications from specified selectors acquired through PRISM collection to be "dual - routed'' to other intelligence Community elements. (emphasis added)
(Note FISAAA is the Foreign Intelligence Surveillance Act Amendments Act 2008. s1881 of FISAAA was incorporated into the Foreign Intelligence Surveillance Act as s702)

If data flowing to the NSA is adjudged to be 50% likely to be associated with foreigners, it is fair game. (The "targeting procedures" say analysts may only proceed to use data under the FISA s702 power if there is more than a 50% likelihood the target is not American and located outside the US). All of this data, i.e. data not filtered out as American only, is then available to the CIA, amongst others, of the sixteen  US intelligence community agencies.

We don't know the scope of intelligence agency data Edward Snowden had access to but it is unlikely he access to all of the intelligence agencies compartmentalised information exploitation guidelines. It is highly significant, however, that each of these agencies can have their own copies of the 50% non American data flowing from the NSA electronic fire hose.

Meanwhile on the EU side of the pond our general approach to data protection and control of data flows to the US exhibits all the features of EU regulators being asleep at the wheel (section 2.3). That's the case whether we are talking about the EU-US "safe harbour" provisions, Binding Corporate Rules (BCRs) for processors or cloud computing. One of the central issues in the whole report is that there are enormous loopholes in these supposed privacy safeguards for EU citizens. Caspar accused EU Commission officials of knowingly or unknowingly permitting or designing these loopholes into the text of the regulations. Get out clause typically include terms like "national security" (that old catch all) and "a legally binding request" and give US government and commerce a blanket licence to collect, process, store, copy and analyse any and all EU data they can get their hands on. "A legally binding request", for example, will include the all encompassing "foreign intelligence information" net which in turn includes any data of assistance to US foreign policy, not least expressly political surveillance over ordinary lawful democratic activity of citizens of EU countries.

Caspar strongly suggests it is the duty of the LIBE committee to investigate the 10 years or more incompetence and/or complicity of the Commission in creating instruments supposed/believed/claimed to protect the privacy of EU citizens but in practice undermining it. He wants Commission papers thoroughly scoured to analyse who made the key decisions, whether they were made in good faith and was it bungling, ineptitude or complicity that led to the prevailing state of affairs where EU privacy is wide open to US abuse. He reckons he delves into this criticism a bit more with less restraint in the report. Whilst it's true he does go into more detail there, I'm not sure he is quite so blunt about the failure of the Commission in their duty of care to protect privacy of the citizens they are supposed to represent.

He then moves onto the recommendations. In the summer of 2013 it became know that the EU Commission had dropped provisions in proposed new data protection regulations that would block the kind of data hoovering that the NSA are doing. The deletion of what would have been article 42 of the regulations was reportedly due to diplomatic pressure coming from the US government. (This is also covered in section 3.2 of the report). You can read article 42 in a draft version of the regulations leaked towards the end of 2011 (p69). Caspar makes his recommendations conscious of the fact that there is talk of re-instating article 42. But as things stand now, EU citizens are placing their data in jeopardy by using US services and websites.

The 1995 data protection directive 95/46 already requires that the basis of processing is consent and that must be informed consent - informed of all relevant risks. Under directive 95/46 EU citizens should be informed of the fact that if they use a US web server their data is going to be subject to political surveillance by the US intelligence communities. So he recommends:
- Prominent notices should be displayed by every US web site offering services in the EU to inform consent to collect data from EU citizens. The users should be made aware that the data may be subject to surveillance (under FISA 702) by the US government for any purpose which furthers US foreign policy. A consent requirement will raise EU citizen awareness...
- Since the other main mechanisms for data export (model contracts, Safe Harbour) are not protective against FISA or PATRIOT, they should be revoked and re-negotiated...
There simply is no case for allowing data transfers from the EU to the US under model contracts or safe harbour. He recognises disengaging these is a very serious matter and that it will have to be done in a phased and strategic way but it must be done. In addition, thinking strategically, 
- A full industrial policy for development of an autonomous European Cloud computing capacity based on free/open - source software should be supported. Such a policy would reduce US control over the high end of the Cloud e-commerce value chain and EU online advertising markets. Currently European data is exposed to commercial manipulation, foreign intelligence surveillance and industrial espionage. Investments in a European Cloud will bring economic benefits as well as providing the foundation for durable data sovereignty.
In relation to this EU cloud infrastructure, when the forthcoming report on Sigint (signals intelligence) in the EU gets published some member states may find themselves in a problematic position. Cryptically, Caspar then said he would say no more about that.

On the potential re-instatement of article 42 in the new data protection regulations (section 3.2 of the report) he is of the opinion that it does not go far enough. The CEO of Yahoo! recently said she could have been jailed for 10 years if she'd said more about government coercion under s702 powers. Depending on how and who interprets the law the penalty could be up to 30 years in jail or conceivably even the death penalty. The latter is unlikely but is part of US law.

By comparison Article 42 would create a conflict of law where the penalty on the EU side is a 2% fine. From Caspar's experience of working for Microsoft this is not going to work. Tiny proportionate penalties in the EU compared to more severe punishment in the US means the data controllers & processors will always take the smaller risk in the EU and comply with US government coercion.

So a re-instated Article 42 should make non compliance at the very least a serious criminal offence.

At the moment the way article 42 is structured there is complete discretion for member states to set penalties. This won't work. Also the imposition of fines won't work. The biggest fine the EU has ever dished out was $1 billion relating to Microsoft's anti-competitive practices in local area networks. Microsoft's profits over the 10 year operation of that monopoly were about $20 billion and that's a conservative estimate. The Microsoft lawyer who "lost" the case got promoted. A fine level of 20% of global revenue may be needed to persuade such corporations to take Article 42 compliance seriously. That might sound extraordinary but such large economic actors actually factor $1 billion fines into their corporate strategies as acceptable write-offs/losses.

The final point he wanted to emphasise before taking questions was in relation to BULLRUN, the NSA project to subvert cryptographic security -
Even after BULLRUN, cryptography is probably intact in theory, however it is not known which encryption implementations and products may have been rendered insecure. Therefore consideration should be given to extending the scope of 'Art.42' also to cover vendors of systems/products (as well as Controllers/Processors) in EU markets. Existing encryption security product accreditations, especially if influenced by NSA or GCHQ, must be regarded as suspect.
So if vendors of security products are coerced by the NSA to build back doors into their systems, even if they are not processing personal data, there should be a requirement for them to tell the EU about the backdoor. This would create a further conflict of law and further jeopardy and penalties for those companies that choose to comply with US rather than EU law. Again the sanctions have to be proportionately as severe or more so for non compliance as they would be in the US.

At that point he opened the session to the floor for a Q&A which ran for a further 40 minutes or so. Well done Mr Bowden on an impressive performance.

The Brazilian President, H.E. Dilma Rousseff, lambasted the US mass surveillance practices with her opening speech at the UN General Assembly in New York on Tuesday, September 24, 2013, just as President Obama was due to step on the same platform in her wake. That same day the EU Parliament held this whole day hearing criticising the US for those same practices (full videos of the morning and afternoon sessions are available via the Parliament website).

A day to remember for privacy advocates. Will it also prove to be a small step forward in reigning in the excesses of the digital surveillance state or just get lost in the noise of history and our mass electronic data addicted society?

Wednesday, September 25, 2013

European Parliament LIBE hearing on mass surveillance Pt1

The EU Parliament LIBE Committee held their Inquiry on Electronic Mass Surveillance of EU Citizens yesterday. Full videos of the morning and afternoon sessions are available via the Parliament website. Some short extracts from the morning session -



Some short extracts from Caspar Bowden's evidence in the final session of the day -



Caspar's statement is really worth watching in full. It's only about 22 minutes but it's pretty impressive how much information he can pack into that time. He gets introduced by Dutch MEP Sophie in 't Veld at 17:07:04. Amusingly but emphatically he declines her invitation to introduce or provide a short overview of his report on The US National Security Agency (NSA)surveillance programmes (PRISM) and Foreign Intelligence Surveillance Act (FISA) activities and their impact on EU citizens' fundamental rights for the Parliament's Policy Department for Citizens' Rights and Constitutional Affairs. Caspar prefers to take a forensic approach, assuming MEPs have read the report (or will do at their leisure at some point) but highlighting some of the detail they may have missed the significance of (or might do when they read it). The scope of the report is limited to the US and the NSA.

There is a widely held view that the collection of data is less important than its use. Caspar disagrees. Now that Edward Snowden's revelations are public we know we are being watched and as a result likely to change our behaviour. It's the Heisenberg principle at a societal scale - you cannot monitor/measure/surveil without influencing those under surveillance. This poisonous mass surveillance it has been going on for perhaps over 10 years and this creates profoundly dangerous destabilizing factors in democracy.

We have never had disclosures on the scale we have seen from Snowden.

[Note In his statement Caspar refers to page numbers of his report in his evidence which are slightly out of sync with the copy I've read and link to on the parliament website. I'll use the numbers from the linked version if I refer to page numbers.]

The first theme in the report he draws attention to is the competing models of privacy governance in the EU and US. This is fundamental and often overlooked. From the long term perspective the underlying principle of EU data protection law is rather odd since it removes the key power to control their personal data from the individual. Once data is submitted to a government or private sector system the individual can no longer object when that data is copied - if it's copied to thousands of machines in that organisation or to a thousand other organisations or other legal regimes. The data protection system assumption is that if the right legal boxes are ticked, the individual must put up and shut up.

Yet every time data is copied from one system to another, privacy risk is increased. It never decreases. With every copy the risk that something bad will happen to that data goes up and the risk that something bad will happen to the person connected to that data likewise increases.

So EU data protection law disables individual control of personal data and the Snowden revelations should make us question this unsound regulatory foundation of privacy protection.

The next section of the report he picks is on the XKeyscore system. From the report:
The XKeyscore system was described in slides 20 (dated 2008 21 ) published by The Guardian on the 31 st of July. It is an “exploitation system/analytic framework”, which enables searching a “3 day rolling buffer” of “full take” data stored at 150 global sites on 700 database servers. The system integrates data collected 22 from US embassy sites, foreign satellite and microwave transmissions (i.e. the system formerly known as ECHELON), and the “upstream” sources above.
The system indexes e - mail addresses, file names, IP addresses and port numbers, cookies, webmail and chat usernames and buddylists, phone numbers, and metadata from web browsing sessions (including words typed into search engines and locations visited on Google Maps). The distinctive advantage of the system is that it enables an analyst to discover “strong selectors” (search parameters which identify or can be used to extract data precisely about a target), and to look for “anomalous events” such as someone “using encryption” or “searching for suspicious stuff”
When you stop to think about this immense surveillance power you realise it goes beyond even George Orwell's imagination. Data can be extracted retrospectively in time, so it gives an analyst a time machine. So without any prior suspicion about an individual it is possible to go back and examine behaviour and conduct of anybody in the world, except Americans, to a limited degree. Not only is it a facility for officials to engage in fishing expeditions it is an irresistible (and most likely official) compulsion.

The next point of interest in the report is BULLRUN (page 16), the codename for the NSA programme to break into widely used encryption systems. Not exclusively by mathematical means but also via side channel attacks - electronic emanations from computers through which keys can be reconstructed - and also through co-opting manufacturers of security equipment. BULLRUN has created the most shock amongst the technology security community of all the Snowden leaks.  All over the world security experts are trying to guess what is vulnerable and re-key/re-grade those systems. But they are working in the dark.

From Caspar's conversations with journalists and experts who have seen some of the Snowden material it appears unlikely that there will emerge much more specific detail about what exactly is vulnerable and what is not. That leaves us with the problem that a large number of systems we thought were secure may not be so and we don't know how to find out which ones are compromised.

He then moved onto the FISA definition of “foreign intelligence information” which is incredibly broad. The Foreign Intelligence Surveillance Act (FISA) foreign intelligence information, Caspar describes, poetically, as "the core term of art" underlying the NSA PRISM mass electronic surveillance programme. It is first defined in the original FISA in 1978 but the parts of the definition that are pertinent to this discussion have not changed since then.

To get to the definition you have to substitute in 2 levels of definition (from related statutes) in what is a complex formulation. (Just an aside - it is really irritating when regulators do this, leading to the byzantine searching of loosely connected laws, with multiple clauses referring to multiple other clauses, when you just want a clear notion of what the law actually is). From the report:
The FISA definition of “foreign intelligence information” has been amended several times to include specific and explicit categories for e.g. money laundering, terrorism, weapons of mass - destruction, but has always included two limbs which seem almost unlimited in scope. When the terms are unwound it includes:
information with respect to a foreign - based political organization or foreign territory that relates to, and if concerning a United States person is necessary to the conduct of the foreign affairs of the United States. [emphasis added]
This definition is of such generality that from the perspective of a non - American it appears any data of assistance to US foreign policy is eligible, including expressly political surveillance over ordinary lawful democratic activities.
That's worth dwelling on and this represents only about a tenth of the full definition of foreign intelligence information. Read it again - any data of assistance to US foreign policy is eligible, including expressly political surveillance over ordinary lawful democratic activity of citizens of EU countries.

We do not know to what extent that definition is applied or exploited because a curious fact is that there has been nothing written about it in 40 years
  • no legal commentary
  • no published guidance
  • no executive orders elaborating on what it means
It is simply unknown to what effect that broad facility has been put over the past 40 years. However, the natural supposition is that this is the power under which purely political surveillance of activities in a foreign country, counter espionage possibly but essentially political spying would be conducted.

There is, in the definition, a discrimination by nationality. In the case of US citizens the threshold for surveillance is necessity, a very strict legal line. For non US citizens the requirement is merely "relates", about the weakest legal hurdle you can imagine.

The FISA section 702 power (Procedures for targeting certain persons outside the United States other than United States persons) contains an express discrimination by nationality too, amounting to a double discrimination by nationality favouring US citizens.

There is nothing in EU law remotely like that and human rights experts say this is simply and obviously unlawful under the European Convention on Human Rights.

At this point Caspar refers to the contribution of an earlier speaker in the day relating to section 215 of the US Patriot Act. The reforms of s215 being discussed in the US are not going to help very much with the 'suspicious through lack of US citizenship' problem. The provision to "obtain foreign intelligence information not concerning a US citizen" gives carte blanche to apply section 215 power to foreigners. Even if they fix and restrict the selective collection of information to counter terrorism criteria but conveniently overlook the 'guilty of being a foreigner' provisions, it won't do any good.

I'm going to have to cut the report short at that point but will get back to the rest of this testimony in a later post.