Tuesday, February 11, 2014

The Day We Fight Back

I've written to my MP, Nicola Blackwood, again. This time to highlight the Don't Spy on Us campaign launched by the Open Rights Group, Liberty, Big Brother Watch, Article 19, English Pen and Privacy International. It's the UK arm of the global The Day We Fight Back.

The form on the Don't spy on us campaign page returned an error when I tried to use it, so I emailed Ms Blackwood directly instead.
"Nicola,

I realise from our recent correspondence that you don't necessarily agree with my perspective on the Snowden revelations.


So I expect you will not be surprised to learn I have signed up to the "Don't Spy on Us" campaign, launched today by the Open Rights Group, Liberty, English Pen, Big Brother Watch, Privacy International and Article 19.

It's based on 6 principles which it's really a little surprising anyone would consider in any way controversial in 2014:

1. No surveillance without suspicion
2. Transparent laws, not secret laws
3. Judicial not political authorisation
4. Effective democratic oversight
5. The right to redress
6. A secure Web for all
(Personally I would have rephrased that last one to "A secure internet for all" but a secure Web would be a start).

Even if you have made up your mind on the UK government response to the Snowden affair, I would ask that you still give serious consideration to the general points of principle raised by the Don't Spy on Us campaign in this centenary year marking the beginning of World War 1.

You may additionally be interested in my submission to the Intelligence and Security Committee Inquiry into privacy and security -


You can also find more details on the Don't Spy on Us campaign at the website
Thanks as ever for taking the time to consider my thoughts on what are inherently difficult matters.
Regards,
Ray"

Friday, February 07, 2014

Submission to ISC Inquiry into Privacy and Security

I've sent a submission to the Intelligence and Security Committee's Inquiry into Privacy and Security. It was done in a hurry so hopefully is not too incoherent.

To the members of the Committee,

Thank you for the opportunity to make a submission to your inquiry into privacy and security.

My name is Ray Corrigan. I’m a Senior Lecturer in the Maths, Computing & Technology Faculty of The Open University though I write to you in a personal capacity.

Executive Summary

Privacy and security are not opposites but mutually dependent. It is essential the committee understand that the false privacy v security dichotomy that so often frames public debate seriously undermines policymakers’ and the public’s understanding of the issues at hand. The single most important airline security measure put in place following the terrible attacks on September 11th 2001 was the reinforcement of cockpit doors. That had absolutely no impact on the personal privacy of travellers. The hugely expensive naked scanners installed at airports, however, take a terrible toll on personal privacy whilst being functionally worse than useless as a security measure (and the X-ray variety has been shown to pose a risk to health). A door lock or a strong high fence provides security without compromising privacy.

Massive data collection and mining compromise privacy and security. The NSA gave 850,000 people access to classified materials as a routine part of their jobs. Their systems are big and complex and require a lot of staff to operate but there can be no security when that number of people has access to secrets. 

There is no “balance” to be achieved between the “individual right to privacy and the collective right to security”. The collective right to security requires an individual and collective right to privacy. The value of protecting individual and collective privacy is that those rights make a fundamental contribution to the overall health of society. Framing privacy as the opposite of security assumes privacy is only about hiding bad things. That couldn’t be more wrong.

It is fundamentally incompatible with the rule of law to collect information about every member of the population in the hope of conducting post hoc fishing expeditions to look for evidence of misbehaviour. Could I remind the committee of the belief of Cardinal Richelieu that given 6 lines written by the most honest man he could show you the evidence to hang him. 

It is unnecessary and completely disproportionate, not to mention dangerously ineffective, “to collect innocent communications in order to find those who might threaten our security.” Finding a terrorist or serious criminal is a needle in a haystack problem – you can’t find the needle by throwing infinitely more needle-less electronic hay on the stack.  Law enforcement, intelligence and security services have to be able to move with the times. They need to use modern digital technologies intelligently in their work and through targeted data preservation regimes – not the mass surveillance regime they are currently operating – engage in technological surveillance of individuals about whom they have reasonable cause to harbour suspicion. That is not, however, the same as building an infrastructure of mass surveillance which, incidentally, in addition to being a clear and present danger to democracy, makes it mathematically impossible for dedicated intelligence services staff to do their job with any degree of effectiveness.

The committee should understand that computers are not magic. These machines do exactly what they are programmed to do not what you would like them to do.  I make this point specifically in light of the Prime Minister’s recent comments to the effect that the TV crime drama he likes so much justifies the mass data collection activities of the intelligence services. TV crime drama and Hollywood films generally are terrible guides to how computers actually work in practice.  The committee should additionally understand that there is no clear distinction to be made between communications data (or so called meta data) and communications content. If it is difficult to define the distinction from a social or legal perspective it is impossible to implement from the technical perspective.

a)      What balance should be struck between the individual right to privacy and the collective right to security?
How does this differ for internet communications when compared to other forms of
surveillance, such as closed-circuit television cameras? To what extent might it be
necessary and proportionate to monitor or collect innocent communications in order to find those which might threaten our security? How does the intrusion differ between data (the fact a call took place between two numbers) as opposed to content (what was said in the call)?

1. If the committee only takes one thing away from this submission let it be this –
       ·        Privacy and security are not opposites.
       ·        There is no balance to be struck between the individual right to privacy and the collective right to security.

2. Privacy has an image problem. It is constantly portrayed as out of date, costly, an obstacle to public safety and new and exciting forms of commerce and research. So if we pitch privacy against something as essential as national security, it is a no contest. What does it matter if we have to dispense with a little personal privacy for the guaranteed gain of being safer and more secure?

3. It matters because when you start with this fundamentally flawed premise and the committee’s flawed question, it leads you to the wrong answers.  The notion that privacy has to be sacrificed for security is wrong. More privacy does not mean less security any more than more security means less privacy. The associated (unspoken) idea that individual privacy is damaging to society is wrong. There’s no strict division between individuals and society. The welfare of both is inextricably interlinked. The fundamental right to privacy of the individual is one of the foundation stones of a healthy society. The value of protecting individual and collective privacy is incalculably important to the future of our information society.

4. The constant refrain about the need to balance privacy and security is quite simply wrong because it has a number of built in assumptions that are wrong.

5. It assumes that privacy and security are opposites which is false. A locked door and a tall strong fence provide security and facilitate privacy. A reinforced cockpit door – the most important airline security measure put in place since the atrocities of September 11th 2001 – does nothing to compromise privacy.

6. It assumes that undermining privacy through the use of magic modern computer systems will improve security. This is false. Democracy and freedom requires privacy and security. That such mass surveillance will not work can be demonstrated mathematically.

7. The esteemed chairman of the ISC, Mr Rifkind, has stated in parliament (in the debate on oversight of intelligence & security services on 31st October 2013) that

“Of the totality processed by computers, perhaps 0.01% will have selectors that the computer has been programmed to look for. The communications of the other 99.99%— covering virtually every citizen of this country, bar a very small number—are never even looked at by the computer, other than in relation to a selector, such as an e-mail address. Even for the tiny minority identified by the computers as potentially relevant to terrorism, if GCHQ, MI5 or MI6 want to read the content of any of the e-mails, they have to go to the Secretary of State for permission. Under the law, only if they are given permission can the content be read”

8. I'm going to do some very rough maths here in an attempt to explain the problem with Mr Rifkind’s point that only 0.01% of communications data is looked at.

9. 0.01% of 60 million people in the UK implicates 6000. Now the pattern flagging will be nowhere near as simple as that but just run with it as a crude estimate. We know from the deputy director of the NSA testifying before the House Judiciary Committee that you don't need to be a terrorist or have contact (deliberate or inadvertent) with a terrorist to be flagged as suspicious. The NSA (and presumably GCHQ?) is allowed to travel “three hops” from its targets – who could be people connected to people connected to people connected to you. 0.01% of the UK population or 6000 people are 2 degrees of separation from about 160,197,360 and 3 degrees of separation from over 26 billion others (about three and a half times the population of the world).

10. Even limiting suspicion to two hops, your 0.01% of data on UK residents, Mr Rifkind, implicates more than 2.6 times the entire UK population. So the question then becomes, given that we are all suspects, who decides which suspects the intelligence services' limited resources should be deployed to further investigate and pursue, once the computer algorithms have worked their magic? 

11. Every time the (theoretically 99.99% effective) magic terrorist catching system is asked for a suspect it implicates vastly more people than the security services could possibly investigate in any detail.

12. Mr Rifkind also rightly stated "Modern computers... are programmed to run using certain selectors". So who gets to program the computers and what are the specific 'selectors'/filters? Who decides what the selectors should be? Who decides who decides what the selectors should be? The chair of the ISC doesn't understand computers, so how can he effectively and his committee scrutinise the technical aspects of this work? How do you measure the efficacy of these filters given it is widely known in the tech community how ineffective electronic filters can be? How, when someone is tagged as suspicious via these secret algorithms, does the information on that individual then get further processed? What happens when someone is wrongly tagged and how do they retrieve their innocence and clean bill of electronic health? Are you aware of the nature of false negative results and false positive results?

13. In multiple media engagements the Prime Minister, the Home Secretary and other members of the government refer to "protecting the public" from the four horsemen of the infocalypse - terrorists, drug dealers, child abusers and organised crime - and more. The Prime Minister last week extolled the virtues of TV crime dramas as a guide to how electronic surveillance systems should be deployed in practice. TV crime drama and Hollywood films generally are terrible guides to how computers actually work in practice. 

14. Mathematically the four horsemen are not problems that lend themselves to mass data mining. Even highly accurate (to 99.99% and by the way no current system comes close to that) data mining systems will swamp investigators with false positives when dealing with a large population. Law enforcement authorities end up investigating and alienating large numbers of innocent people. That’s no good for the innocents, for the investigators or for society.

15. There is an oft repeated the myth that the 9/11 attacks would have been prevented if only the US intelligence and security services had known where Mohamed Atta was when he had made a phone call to a terrorist suspect in Syria. The assumption is the magic terrorist catching mass data collection and analysis apparatus now run by the NSA would have pinpointed his location and led to his arrest.

16. Wrong.

17. Atta was known to the intelligence and security services and considered a threat. Police, intelligence and security systems are imperfect. Even in 2001 they processed vast amounts of imperfect intelligence information. At least one FBI agent believed Atta to pose a serious and imminent threat. That belief got lost in the noise of the intelligence information processes, suspects and issues the agencies were then dealing with, to the degree that they did not detain Atta or his associates and prevent the attack.

18. There was too much data noise in the system and they lost him. You cannot cure that excess of data noise problem by treating the entire population as suspects, engaging in suspicionless, blanket collection and processing of personal data. You cannot find the real terrorist by assuming everyone is a threat.

19. Mass data collectors can dig deeply into the digital persona of anyone but don’t have the resources to do so with everyone. The resultant pursuit of false positive leads mean the real bad guys often get lost in the noise, as happened with the 9/11 attackers including Atta who were known to US authorities but not considered sufficiently important to intercept.

20. Finding the four horsemen is a needle in a haystack problem and you can’t find the needle by throwing infinitely more needle-free hay on your stack and/or creating multiple giant and exponentially growing data haystacks.

21. Operating multiple massive databases of intimate personal communications data makes the public more vulnerable to the four horsemen not less so.

22. That such mass databases are useless for finding terrorists is clear from the maths and the evidence. The NSA has admitted in spite of previous claims that their mass data collection and analysis stopped 54 major terror attacks since 9/11 it didn't really stop any, but may possibly have provided secondary supportive evidence in relation to one. The most recent argument they used to support the deployment of such systems is mass data collection might be useful as an "insurance policy". An insurance policy?! The infrastructure of mass surveillance might be useful in the future, somehow, to someone?

23. That such systems also make the public less safe is associated with the impossibility of securing mass silos of valuable personal data. Computer scientists simply do not know how to keep databases of the magnitude of those used by the NSA and GCHQ secure from external hackers or the multitude of insiders who have access to these databases as a routine part of their jobs (850,000 including Edward Snowden in the case of the NSA).  Security experts like Ross Anderson, Bruce Schneier, Edward Felten and Peter Sommer have written extensively about this.  To understand this you have to think about how such systems can fail - how they fail naturally, through technical problems and errors (a universal problem with computers), and how they can be made to fail by attackers (insiders and outsiders) with malign intentions e.g. the four horsemen. When the inevitable hacks, leaks, data contaminations happen, what then?

24. In its most insidious form the misleading privacy v security question is phrased as a statement along the lines “the innocent have nothing to hide”. This assumes two underlying falsehoods – firstly that privacy is only about hiding bad things and secondly that decimating privacy will solve the problem du jour. I hope I’ve demonstrated clearly to the committee that both these assumptions are wrong and that in answer to your questions –
      ·       There is no balance to be struck between the individual right to privacy and the collective right to security
·        It is neither necessary nor proportionate nor is it effective to engage in blanket monitoring or collection of  innocent communications in an attempt to find those who might threaten our security
25. On the question of whether the intrusion differs between data and content I would refer you to Peter Sommer’s writings and analysis e.g. analysis (sic) at
http://scramblingforsafety.org/2012/sf2012_sommer_commsdata_content.pdf
And his evidence before the select committee on the Communications Data Bill.
b) Whether the legal framework which governs the security and intelligence agencies’ access to the content of private communications is ‘fit for purpose’, given the developments in information technology since they were enacted.

26. The notion that the day to day activity of every citizen should be recorded in the expectation that those records can, in future, be mined for nefarious activity is anathema to a healthy functioning liberal democracy. Yochai Benkler in a recent Guardian article (http://www.theguardian.com/commentisfree/2013/oct/16/nsa-fbi-endrun-weak-oversight) put it more eloquently than I could:

     “Mass surveillance represents a commitment to near-universal all-seeing gaze, so as to assess and respond to threats that can arise anywhere, at any time. Privacy as a check on government power represents a constitutional judgment that a limited government must have limited power to inspect our daily lives, and that an omniscient government is too powerful for mere rules to restrain. The experience of the past decade confirms this incompatibility...

    Technology has enabled government to have investigative and situational awareness on a scale and scope that were science fiction when the Stasi shut its doors. The "state of emergency" mindset necessary to justify the program in the first place drives those charged with assuring the safety of Americans to always use this technology to its full potential; it also gives them an independent source of legitimacy for their actions – the fierce urgency of necessity.
    Their mission clashes with the fundamental premise of privacy as a civil right: that state power is best contained by making the overwhelming majority of what goes on in society invisible to the state. As Justice Alito put it in the supreme court's decision to strike down GPS tracking:

        [Historically] the greatest protections of privacy were neither constitutional nor statutory, but practical.

    Once the state knows about behaviour, it is hard to rely on rules alone to bear the full burden of preventing overreach by those who wield its awesome power...

    Rules alone cannot hold back the millions of potential abuses of an omniscient state.

    As long as government is allowed to collect all internet data, the perceived exigency will drive honest civil servants to reach more broadly and deeply into our networked lives.”
 
c) Proposals for specific changes to specific parts of legislation governing the collection, monitoring and interception of private communications.

27. As Jemina Stafford QC made clear in a formal opinion for a parliamentary committee last week, (http://www.tom-watson.co.uk/wp-content/uploads/2014/01/APPG-Final.pdf) the current mass data collection activities of sections of the UK government already undermine the right to privacy guaranteed in the Human Rights Act and article 8 of the European Convention on Human Rights. It is clear that the Regulation of Investigatory Powers Act does require an update but I don’t have any specific proposals to put before the committee at this stage.

28. However, I do have a general proposal that suspicion should be the test for surveillance.

29. The government of course has the right to intercept and record information when someone is suspected of a serious crime. But current operation [sic] appear to involve collection of data without suspicion: which is in effect mass surveillance. Due process, since the 1765 case of Entick v Carrington, requires that surveillance of a real suspected criminal be based on much more than general, loose, and vague allegations, or on suspicion, surmise, or vague guesses. To operate the mass date [sic] collection and analysis systems GCHQ has been reported as doing which give the entire population less protection than a hitherto genuine suspected criminal, based on a standard of reasonable suspicion, is indefensible. The gathering of mass data to facilitate future unspecified fishing expeditions is indefensible in law.

30. I appreciate the ISC and a multitude of highly dedicated public officials are grappling with really complex issues here. But it is critically important that you understand –

·        Privacy and security are not opposites.

·        There is no balance to be struck between the individual right to privacy and the collective right to security.

·        Computers are not magic and never will be

·        Mass data collection and analysis is mathematically provable to be unfit for the purpose of hunting the four horsemen of the infocalypse

31. It is also hugely important that you be provided with the resources and expertise required to fulfil the immensely demanding duties required of the committee.

32. I'd leave you with one final thought. Nearly 250 years ago, Lord Chief Justice Camden decided that government agents are not allowed to break your door down and ransack your house and papers in an effort to find some evidence to incriminate you (the case of Entick v Carrington (1765) 19 Howell’s State Trials 1029, 2 Wils 275, 95 ER 807, Court of Common Pleas).

33. The good judge also declared personal papers to be one’s “dearest property”. I suspect he might view personal data likewise in the internet age. I understand Lord Camden's reasoning in Entick became the inspiration behind the 4th Amendment to the US Constitution which offers protection from unreasonable searches and seizures. For a quarter of a millennium, fishing expeditions of the type that the GCHQ and NSA are engaged in have been considered to fundamentally undermine the rule of law. It's time Parliament brought these modern practices into line with that rule of law.
 Update: I neglected to number the paragraphs in my submission on Friday. Now rectified and amended above.

Wednesday, February 05, 2014

Further MP response on Snowden

I've had another response from my MP, Nicola Blackwood, this time to my admittedly somewhat caustic critique of Foreign & Commonwealth Office Minister of State, Hugh Robertson's, letter on the oversight of intelligence and security services. It appears as though she has misinterpreted the tone of that post and rapidly retreated behind the shield of the government mantra on the Snowden affair:
"Dear Mr Corrigan,
Thank you for your further email about intelligence services and I apologise for the lengthy delay in my response.
I am sorry to learn that you were disappointed by the Minister's response, and having read your blog I understand that you feel the Minister did not address the point at hand and you are disappointed that he is unable to comment on specific intelligence matters. I do apologise that I cannot offer any further information than the Minister, but I would stress that the UK has one of the world's strongest legal and regulatory frameworks governing the use of secret intelligence. UK legislation is fully compatible with the right to privacy in Article 8 of the European Convention on Human Rights (ECHR). Our secret intelligence agencies are subject to the provisions of the Data Protection Act 1998 and additional UK statutory controls and safeguards, including the relevant sections of the Intelligence Services Act, the Human Rights Act 1998, and the Regulation of Investigatory Powers Act, and robust oversight mechanisms including the Intelligence Security Committee and the Interception of Communications Commissioner.
You also ask how many constituents contacted me on this debate, I can tell you that 15 constituents in total wrote to me to ask that I attend the debate on 31st October. Unlike yourself, other constituents who had contacted me on this issue had done so in the form of a campaign template email. Thank you again for contacting me, I hope this response is helpful.
Kind regards
Nicola"
I've further responded as follows:
Nicola,
I fear the sardonic nature of my blogpost criticising the Minister's response may have led you to misreading it. It doesn't ask anywhere that the Minister should comment on specific intelligence matters. It does ask essentially, as did the FT in its editorial earlier this week, as do a multitude of security and legal experts with a deep understanding of the technology and the law, that Edward Snowden’s revelations be understood and acted upon, since they raise important questions about surveillance in a free society. As I said to you before, since Entick v Carrington in 1765, fishing expeditions of the type that the GCHQ and NSA are engaged in have been considered to fundamentally undermine the rule of law. It's time Parliament brought these modern practices into line with that rule of law.
Your stressing of the government line that 'the UK has one of the world's strongest legal and regulatory frameworks governing the use of secret intelligence' and the UK intelligence services are subject to 'robust oversight mechanisms' is, I'm afraid, in direct contradiction to the evidence. Academics do have a rather irritating affinity for evidence.:-) A senior legal adviser to GCHQ has noted "We have a light oversight regime compared with the US". The members of the Intelligence Security Committee do not understand the technologies and do not have the resources to do the oversight job expected of them. Only last week Jemina Stafford QC, in a formal legal opinion for a parliamentary committee, declared GCHQ's mass data collection activities to be illegal and to have been signed off by ministers in breach of human rights and surveillance laws.
I could go on but suspect your retreat into a repetition of the government mantra on the affair means you have already disengaged.
Thanks for letting me know 15 constituents contacted you to ask you to attend the parliamentary debate on the 31st October. It would be disappointing if you were to give limited credence to those who decided to use the internet and a campaign template email to communicate with you on this or any other matter. I appreciate you probably deal with a large number of communications but it would be sad to return to the Blairite days of officially counting more than 10,000 [sic] objections to the proposed ID card scheme as a single response because they were coordinated through an internet facilitated campaign.
I would make one final point before signing off. Law enforcement, intelligence and security services need to be able to move with the times. They need to use modern digital technologies intelligently in their work and through targeted data preservation regimes – not the mass surveillance regime they are currently operating – engage in technological surveillance of individuals about whom they have reasonable cause to harbor suspicion. That is not, however, the same as building an infrastructure of mass surveillance which, incidentally, in addition to being a clear and present danger to democracy, makes it mathematically impossible for dedicated intelligence services staff to do their job with any degree of effectiveness.
Thanks for taking the time to respond again but it would appear that we are settling on different sides of the fence on the Snowden affair.
Regards,
Ray"

Friday, January 31, 2014

ORG recruiting legal director

Some of the Open Rights Group's learn'd friends are calling for help to enable ORG to recruit a legal director:
"We are lawyers who work with the Open Rights Group. 
You and the Open Rights Group can make a huge difference in the UK and European courts, defending your digital rights. That’s why we are asking you to join ORG today, so they can hire a Legal Director. We need just 40 more people to hire them full time.

Help hire ORG's Legal Director 
But perhaps it’s best if we explain in our own words:
“The appointment of a legal director will make a real impact on the work of the Open Rights Group.  It has never been more important to have informed interventions at the High Court and appeal courts on matters to do with digital rights.
“I know from my own experience as appeal solicitor in the “Twitter Joke Trial” the difference it makes when courts properly understand technological issues, especially when imposing criminal liability on the citizen”
David Allen Green, solicitor at Preiskel & Co LLP, and member of Advisory Council, ORG.

“In the US, digital freedoms have been fought for and won in historic legal battles such as Reno v ACLU  and countless smaller cases where the EFF and other digital rights groups have helped take on cases involving freedom of speech online, privacy online, cyber- harassment, vindictive copyright enforcement and so on. In the UK until now civil society has never had the capacity to take such important legal cases. Help ORG hire a Legal Director to change this and bring UK law into the 21st century.”
Dr Lilian Edwards, ORG Advisory Council and Professor of Internet Law at Strathclyde University

“ORG is a vital partner with EFF in addressing mass surveillance. Just as GCHQ and NSA work together, it's increasingly critical that we strengthen the capabilities of groups on both sides of the Atlantic to push back to regain our privacy and free speech.”
Cindy Cohn, Legal Director, Electronic Frontier Foundation

“There is no doubt that Parliament and the Courts have struggled with the challenges posed by the explosion of online interaction and the growing importance of rights in an increasingly digital world. Decisions made now will shape the approach that the Law takes for decades and possibly longer. This is a key moment. ORG speaks up for those whose interests are usually discounted when it comes to governmental and judicial policy making – it speaks up for you and everyone else who lacks a vested interest and a lobbying budget. A Legal Director is exactly what ORG needs at exactly the time we all most need ORG.”
Seán Jones QC11KBW Chambers

“The law can be an instrument of repression but it can also be a powerful tool for change. Your support for ORG's Legal Director post can make a real difference in the fight for digital freedom in the UK.”
Eric Metcalfe, Monckton Chambers, former director of human rights policy at JUSTICE

“Please help with the appointment of a Legal Director for the Open Rights Group. In my personal experience, ORG have initiated valuable interventions on civil liberties issues affecting millions of adults in the UK, such as filtering.”
Myles Jackman, Law Society Junior Lawyer of the YearConsultant Solicitor-Advocate at Hodge Jones and Allen LLP @ObscenityLawyer

"As an American lawyer I've seen how important it is to have boots on the ground to defend civil liberties in court.  Even when the underlying law itself is designed to protect civil liberties, being able to appeal directly to the courts may be the only way to keep them protected not just in theory but in practice."
Cathy Gellis, US Tech and civil liberties lawyer

“I have had the honour of working with ORG to do some marvellous work: both intervening in high profile cases and working behind the scenes to help individuals who have fallen foul of laws that were not or should not have been drafted for the modern digital world. I am convinced that ORG could do so much more with the assistance of a full-time legal director and I am excited by all the things that ORG could do if it had one. Money pledged for this purpose will be money well spent.”
Francis Davey, Independent barrister and ORG legal volunteer
We need just 40 people to join to make this project happen.Please help us hire a full time Legal Director by joining the Open Rights Group today!
https://www.openrightsgroup.org/join/help-hire-orgs-legal-director
Yours,
ORG Legal volunteers and ORG Law group
_________
[1] British government to answer fast-track spy challenge https://www.privacynotprism.org.uk/news/2014/01/24/british-government-to-answer-fast-track-spy-challenge/"
Given this prompt I'd like to invite the academy to consider again the possibility of creating a network of digital rights cyberlaw clinics to provide ORG and their forthcoming legal director with pro bono support in critical cases.

Friday, January 17, 2014

BBC ignorance on mass surveillance again

I was listening to the BBC Radio 5 Live station on the way back from Milton Keynes this evening. They noted President Obama made a speech about reforming NSA practices.

Around about 5.55pm they spoke to a correspondent in Washington. She got almost everything about the Snowden mass surveillance revelations wrong.

She uncritically repeated the myth that the 9/11 attacks would have been prevented if only the US intelligence and security services had known where Mohamed Atta was when he had made a phone call to a terrorist suspect in Syria. She assumed  the magic terrorist catching mass surveillance apparatus now run by the NSA would have pinpointed his location and led to his arrest.

Wrong.

Atta was known to the intelligence and security services and considered a threat. Police, intelligence and security systems are imperfect. Even in 2001 they processed vast amounts of imperfect intelligence information. At least one FBI agent believed Atta to pose a serious and imminent threat. That belief got lost in the noise of the intelligence information processes, suspects and issues the agencies were then dealing with, to the degree that they did not detain Atta or his associates and prevent the attack.

There was too much data noise in the system and they lost him. You cannot cure that excess of data noise problem by treating the entire population as suspects, engaging in suspicionless, blanket collection and processing of personal data. You cannot find the real terrorist by assuming everyone is a threat.

Mass data collectors can dig deeply into the digital persona of anyone but don’t have the resources to do so with everyone. The resultant pursuit of false positive leads mean the real bad guys often get lost in the noise, as happened with the 9/11 attackers including Atta who were known to US authorities but not considered sufficiently important to intercept. Finding the terrorist is a needle in a haystack problem, and you don't make it easier by throwing more hay on the stack. It is mathematically impossible for such mass surveillance to be an effective tool for catching terrorists.

The BBC correspondent also implied that there was no problem with the blanket, suspicionless, mass collection of personal data that is going on and that Obama's plan to continue this practice but privatise it would cure most concerns.

Wrong.

I'm tempted to get into a long dissection of this dangerous meme but I'll keep it to a couple of points -

Blanket, suspicionless, untrammeled, mass surveillance is corrosive and wrong-headed. The implied notion that decimating privacy is not just the solution but the obvious solution to the security, terrorism or serious crime problem is naive. Spreading that invidious notion uncritically is irresponsible of the BBC.

Blanket, suspicionless, untrammeled, mass surveillance is dangerous no matter who the government tasks with the job of actually collecting, processing and storing the data.

There is no magic computer solution to the rare preventing terrorism problem.

Don’t get me wrong. Law enforcement and security services need to be able to move with the times, use modern digital technologies intelligently in their work and through targeted data preservation regimes – not a mass surveillance regime – engage in technological surveillance of individuals about whom they have reasonable cause to harbor suspicion. That is not, however, the same as building an infrastructure of mass surveillance.
 
The BBC has an appalling record on the reporting of the Snowden affair. I know there are some very smart people in the BBC who get the serious implications of what Edward Snowden has put into the public domain. But the collective ignorance of the corporation as a public service broadcasting institution has almost gone so far as to have become a public menace.

It's hard to decide if their failures are worse when they follow the government wish for them to ignore the issues or when on the odd occasion they do get round to it, it is often to spread the corrosive memes of governments caught in the act... "nothing to hide nothing to fear", "only there for your protection", "essential for national security", "privacy must be balanced with security"...

As a result of their complete failure to fulfil their public service remit on the Snowden affair, every suit, producer, presenter, correspondent and journalist at the BBC should be made to repeat at least a hundred times a day:
Quite simply an infrastructure of mass surveillance is not conducive to the public good.
Perhaps that might be a little long for the attention span the corporation believe they cater to.  How about
Mass surveillance is not conducive to the public good.
Maybe something a little simpler: 
Mass surveillance is bad for you and it doesn't work
That might do it.
Mass surveillance is bad for you and it doesn't work
Mass surveillance is bad for you and it doesn't work
Mass surveillance is bad for you and it doesn't work...
To the good folk at the Beeb who do get Snowden - I know how frustrating it can be when an institution you care about gets really important things wrong.  Good luck with what will undoubtedly be heroic, exhausting, painful and sometimes risky internal efforts to turn your supertanker round.

BBC page screening parts of Obama's NSA reform speech.

Channel 4 News on the speech here.

Update: thanks to @eldonnn for alerting me to the error in my original post.

Saturday, January 11, 2014

Thoughts on BBC failure on Snowden

Adrian Chiles is an affable broadcaster who now works for the BBC and ITV. He does the Drive programme on BBC Radio 5 Live on a Friday. I happened to catch a bit of it on the way home from work yesterday evening, just as he was introducing Myles Allen, Geosystem Science Professor and Head of the Climate Dynamics group at Oxford University's Atmospheric, Oceanic and Planetary Physics Department.

The short extract from the programme is worth listening to (before it gets timed out on the BBC iPlayer). It is one illustration of the low level of understanding BBC presenters seem to have of science and technology.

The segment begins a little over 2 hours in at  2:11:24. Mr Chiles was friendly as always. Prof Allen was engaging and informative but it sounded to me that the presenter was not really following him too well. In fairness to Mr Chiles, unlike many of his colleagues who determinedly and rudely cut people off and paint the world in simplistic "balanced" extremes, he did his best to listen, ask questions and give the good professor the opportunity to make his points. Mr Chiles then closed by deciding he's going to get a tractor to deal with the bad weather.

I use this example not to criticise Mr Chiles in particular - he's a terrific broadcaster who does his job really well, particularly on the sports end of his varied portfolio - but because in spite of his difficulty in following the argument he, at least, made an effort. Many of his colleagues use straw men, sarcasm, the god of "balance", attack the messenger and/or a variety of other tactics to cover their low level understanding of or lack of interest in science; some even boast and cheer about that ignorance.

However, in an information age, the scientific, technological and mathematical ignorance of mainstream public service broadcast and print journalists presents a significant democratic deficit.

The 4th Estate is supposed to talk truth to power and provide a check on the branches of government and hopefully help prevent them getting out of control. Well parts of the US and UK government are out of control.

Edward Snowden has revealed the levers of power are being wielded in secret to engage in suspicionless mass surveillance of entire populations, via complex modern technologies. Also that the political hierarchy in charge of this activity have been dangerously clueless about the mass surveillance infrastructure they have funded, constructed and facilitated.

If the journalists tasked with holding these people to account don't understand the science, technology or mathematics then they cannot do their job with any degree of credibility. IMHO the BBC has largely failed in its public duty to report on the Snowden affair with any degree of credibility. The poor scientific and technical background of many of their mainstream presenters will have been a contributory factor in this failure.

The latest from the NSA is that they now seem to be admitting (in spite of previous claims that this mass surveillance stopped 54 major terror attacks it didn't really stop any, but may possibly have provided secondary supportive evidence in relation to one) that the best argument they can come up with is mass data collection might be useful as an "insurance policy". What?! An insurance policy?! The infrastructure of mass surveillance might be useful in the future, somehow, to someone?

Who? Why? When? How? What? Where? Those six honest serving men serve pretty well in the science and technology arena too. BBC presenters might like to take note.

Opt out of NHS data grab before it's too late

The inimitable Ross Anderson, Professor in Security Engineering at the University of Cambridge Computer Laboratory, has succinctly pointed out the importance of opting out of the latest NHS data grab before it is too late. I hope he won't mind me reproducing his advice here in full:
"The next three weeks will see a leaflet drop on over 20 million households. NHS England plans to start uploading your GP records in March or April to a central system, from which they will be sold to a wide range of medical and other research organisations. European data-protection and human-rights laws demand that we be able to opt out of such things, so the Information Commissioner has told the NHS to inform you of your right to opt out.
Needless to say, their official leaflet is designed to cause as few people to opt out as possible. It should really have been drafted like this. (There’s a copy of the official leaflet at the MedConfidential.org website.) But even if it had been, the process still won’t meet the consent requirements of human-rights law as it won’t be sent to every patient. One of your housemates could throw it away as junk before you see it, and if you’ve opted out of junk mail you won’t get a leaflet at all.
Yet if you don’t opt out in the next few weeks your data will be uploaded to central systems and you will not be able to get it deleted, ever. If you don’t opt out your kids in the next few weeks the same will happen to their data, and they will not be able to get their data deleted even if they decide they prefer privacy once they come of age. If you opted out of the Summary Care Record in 2009, that doesn’t count; despite a ministerial assurance to the contrary, you now need to opt out all over again. For further information see the website of GP Neil Bhatia (who drafted our more truthful leaflet) and previous LBT posts on medical privacy."

Wednesday, January 08, 2014

Foreign & Commonwealth Office Minister of State, Hugh Robertson, response on oversight of security services

My MP, Nicola Blackwood, has had a reply from Foreign & Commonwealth Office Minister of State, Hugh Robertson, to her letter "to the Foreign Secretary, on behalf of a number of your constituents, about concerns about oversight of the security services". Mr Robertson describes himself as "the minister responsible for this issue."  I wrote to Ms Blackwood about the Snowden affair in October and briefly again in December when she got back to me.

Copy of Mr Robertson's letter to Ms Blackwood here. (Update: I've removed the embedded copy of the letter from this post because of the irritating glitch in Blogger/ Google Drive that causes the homepage to jump to the Drive pdf insert).

In summary, Mr Robertson's response states "it is the longstanding policy of successive British Governments not to comment on intelligence matters" but that he would like to draw our attention to -
  • the statement the Foreign Secretary made to Parliament on 10 June
  • the Intelligence & Security Committee (ISC) statement of 17 July saying the initial NSA/Prisrn allegations were unfounded
  • the ISC press release of 17 October saying they intended to do further work
  • Home Office minister James Brokenshire's statement in the parliamentary debate of 31 October saying we should be proud of UK oversight of intelligence agencies 
  • a link to the Hansard transcript of the debate www.publications.parliament.uk/pa/cm201314/cmhansrd/cm131031/hallindx/131031-x.htm 
Seriously? Six months on and the best the UK government can do is -
  • We don't comment on intelligence matters
  • All praise William Hague
  • There's nothing to see here, move along
  • We'll check the law anyway
  • We had a chat about it and the minister said we should be proud and here's the web link to prove it
So though I would thank Mr Robertson for taking the time to write to Ms Blackwood in relation to the concerns I raised with her, I would note, for the record, that his letter provides no reassurance on any of the fundamental issues at play here.  The one positive thing to come out of this non-response from the minister is that a number of Ms Blackwood's constituents (plural), not just this lone academic, have been concerned enough to contact her about untrammeled mass electronic surveillance.

(The helpful link provided by Mr Robertson to the parliamentary debate of 31 October would suggest that he is not, unsurprisingly perhaps, a B2fxxx reader; not, at least, of the three relatively long posts on this blog on that debate)

Monday, December 23, 2013

Patent trolls aka Patent Assertion Entities (PAEs) and the FTC

The Federal Trade Commission has had a public consultation on patent trolls. The FTC, however, adopt the industry's own description of itself as "Patent Assertion Entities (PAEs)". Once the government accepts patent trolls as legitimate economic actors, the battle to explain (or even attempt to understand properly) the complex calculus of their effect on the economy is effectively over.

Some of the submissions make interesting reading, though unsurprisingly, Intellectual Ventures (IV) have a slightly different perspective to, say, the Electronic Frontier Foundation (EFF) and Public Knowledge (PK). 

IV conclude:
For all the reasons described above, the information requests do not meet the requirements of the Paperwork Reduction Act, nor, more importantly, will they assist the Commission in meeting the goals of the 6(b) study. As currently drafted, the requests miss the opportunity to focus on the broader, economy - wide effects of patent assertion activity by different types of entities, and thus provide the Commission with no ability to compare the costs and benefits of PAE activity to its alternatives. The requests will also create enormous burdens for respondents, require unnecessary information, and generate a record far too large for the Commission to process efficiently. This combination may significantly delay the issuance of the report, which would greatly diminish its value. Because timely insights are critical, and IV is eager to work cooperatively with the Commission to ensure that it receives the information it needs to meet its goals in a timely manner, we respectfully urge the Commission to modify the requests as noted above.
Translation: stop irritating us with costly red tape and produce a report telling everyone how wonderful we are.

The EFF and PK, on the other hand, say:
The proposed Section 6(b) study would significantly advance the quantity and quality of public information regarding patent assertion entities. The study would, thus, both directly help the diverse targets of PAE activity and enable the FTC and other policymakers to better serve consumers and preserve competition. The FTC is also particularly well suited to make these requests; it has the necessary statutory authority and experience in consumer protection and patent policy to conduct this particular study. Finally, the Section 6(b) study's proposed respondents would find complying with the questions manageable and straightforward. Because the public understanding of PAEs remains limited by PAEs' covert practices, the FTC should proceed in asking these entities to provide basic answers that would serve consumers, small businesses, policymakers, and the general public.
Translation: these sneaky patent troll parasites are sucking real innovators and consumers dry; and the FTC are well placed to expose them to the public gaze and take them down a peg or two. It won't cost the trolls anything to fill in a few forms to attempt to justify themselves, so it's the least they should be asked to do.

Wednesday, December 18, 2013

Glenn Greenwald testimony at EP Inquiry on mass surveillance

Glenn Greenwald testified this morning at the EU parliament LIBE committee hearing on mass electronic surveillance. Copy of the recorded session below.



It's worth viewing in full if you can find a spare 90 minutes (otherwise wait for the transcript). If you can't last the full 90, there is a 7 minute video of extracts from Mr Greenwald's statement -



Mr Greenwald subsequently took exception to the misrepresentation of his evidence on twitter by conservative MP Julian Smith.

Video of the full morning session, including evidence from security specialists Christopher Soghoian of the ACLU, Christian Horcher, Prof Bart Preneel of the University KU Leuven in Belgium and Stephan Lechne of the IPSC (one of the seven institutes of the European Commission's Joint Research Centre) will be available shortly.

Update: Christopher Soghoian's written testimony has been made available by the ACLU.

Wednesday, December 11, 2013

Former whistleblowers: open letter to intelligence employees

Former whistleblowers, , , , , , , have published an open letter to intelligence employees in today's Guardian. I hope they won't mind if I reproduce it here in full.
"At least since the aftermath of September 2001, western governments and intelligence agencies have been hard at work expanding the scope of their own power, while eroding privacy, civil liberties and public control of policy. What used to be viewed as paranoid, Orwellian, tin-foil hat fantasies turned out post-Snowden, to be not even the whole story.
What's really remarkable is that we've been warned for years that these things were going on: wholesale surveillance of entire populations, militarization of the internet, the end of privacy. All is done in the name of "national security", which has more or less become a chant to fence off debate and make sure governments aren't held to account – that they can't be held to account – because everything is being done in the dark. Secret laws, secret interpretations of secret laws by secret courts and no effective parliamentary oversight whatsoever.
By and large the media have paid scant attention to this, even as more and more courageous, principled whistleblowers stepped forward. The unprecedented persecution of truth-tellers, initiated by the Bush administration and severely accelerated by the Obama administration, has been mostly ignored, while record numbers of well-meaning people are charged with serious felonies simply for letting their fellow citizens know what's going on.
It's one of the bitter ironies of our time that while John Kiriakou (ex-CIA) is in prison for blowing the whistle on US torture, the torturers and their enablers walk free.
Likewise WikiLeaks-source Chelsea (nĂ©e Bradley) Manning was charged with – amongst other serious crimes – aiding the enemy (read: the public). Manning was sentenced to 35 years in prison while the people who planned the illegal and disastrous war on Iraq in 2003 are still treated as dignitaries.
Numerous ex-NSA officials have come forward in the past decade, disclosing massive fraud, vast illegalities and abuse of power in said agency, including Thomas Drake, William Binney and Kirk Wiebe. The response was 100% persecution and 0% accountability by both the NSA and the rest of government. Blowing the whistle on powerful factions is not a fun thing to do, but despite the poor track record of western media, whistleblowing remains the last avenue for truth, balanced debate and upholding democracy – that fragile construct which Winston Churchill is quoted as calling "the worst form of government, except all the others".
Since the summer of 2013, the public has witnessed a shift in debate over these matters. The reason is that one courageous person: Edward Snowden. He not only blew the whistle on the litany of government abuses but made sure to supply an avalanche of supporting documents to a few trustworthy journalists. The echoes of his actions are still heard around the world – and there are still many revelations to come.
For every Daniel Ellsberg, Drake, Binney, Katharine Gun, Manning or Snowden, there are thousands of civil servants who go by their daily job of spying on everybody and feeding cooked or even made-up information to the public and parliament, destroying everything we as a society pretend to care about.
Some of them may feel favourable towards what they're doing, but many of them are able to hear their inner Jiminy Cricket over the voices of their leaders and crooked politicians – and of the people whose intimate communication they're tapping.
Hidden away in offices of various government departments, intelligence agencies, police forces and armed forces are dozens and dozens of people who are very much upset by what our societies are turning into: at the very least, turnkey tyrannies.
One of them is you.
You're thinking:
● Undermining democracy and eroding civil liberties isn't put explicitly in your job contract.
● You grew up in a democratic society and want to keep it that way
● You were taught to respect ordinary people's right to live a life in privacy
● You don't really want a system of institutionalized strategic surveillance that would make the dreaded Stasi green with envy – do you?
Still, why bother? What can one person do? Well, Edward Snowden just showed you, what one person can do. He stands out as a whistleblower both because of the severity of the crimes and misconduct that he is divulging to the public – and the sheer amount of evidence he has presented us with so far – more is coming. But Snowden shouldn't have to stand alone, and his revelations shouldn't be the only ones.
You can be part of the solution; provide trustworthy journalists – either from old media (like this newspaper) or from new media (such as WikiLeaks) with documents that prove what illegal, immoral, wasteful activites are going on where you work.
There IS strength in numbers. You won't be the first – nor the last – to follow your conscience and let us know what's being done in our names. Truth is coming – it can't be stopped. Crooked politicians will be held accountable. It's in your hands to be on the right side of history and accelerate the process.
Courage is contagious.
Signed by:
Peter Kofod, ex-Human Shield in Iraq (Denmark)
Thomas Drake, whistleblower, former senior executive of the NSA (US)
Daniel Ellsberg, whistleblower, former US military analyst (US)
Katharine Gun, whistleblower, former GCHQ (UK)
Jesselyn Radack, whistleblower, former Department of Justice (US)
Ray McGovern, former senior CIA analyst (US)
Coleen Rowley, whistleblower, former FBI agent (US)"

Monday, December 09, 2013

Kids can opt out of school fingerprinting

May I recommend Jon Baines' short blogpost pointing out that kids can opt out of school fingerprinting and/or biometrics collection whether the school or their parents like it or not. Jon succinctly draws attention to Chapter 2 of Part 1 of The Protection of Freedoms Act 2012.
"The school
must ensure that a child’s biometric information is not processed unless—
(a)at least one parent of the child consents to the information being processed, and
(b)no parent of the child has withdrawn his or her consent, or otherwise objected, to the information being processed….
The relevant authority must ensure that reasonable alternative means are available by which the child may do, or be subject to, anything which the child would have been able to do, or be subject to, had the child’s biometric information been processed.
But also note (here’s the totally rad bit) that, even if your parents are OK with it, you have the right to object, and if you do, that trumps what your parents, and your school, think. Cool eh?
if, at any time, the child—
(a)refuses to participate in, or continue to participate in, anything that involves the processing of the child’s biometric information, or
(b)otherwise objects to the processing of that information,
the relevant authority must ensure that the information is not processed, irrespective of any consent given by a parent of the child"