Monday, September 17, 2007

Google in the News

There's a pair of articles about Google and privacy in Information Week. First, Google itself put out a call for a global privacy standard (article here). The initiative is laudable. Google's privacy counsel is quoted in the article as stating that

Yet despite the international scope of even the most ordinary Internet activity, the majority of the world's countries offer virtually no privacy standards to their citizens and businesses. And even if every country in the world did have its own privacy standards, this alone would not be sufficient to protect user privacy, given the Web's global nature. Data may move across six or seven countries, even for very routine Internet transactions. It is not hard to see why privacy standards need to be harmonized and updated to reflect this reality.

However, is Google really the organization to push privacy standards? According to the second article (link here) Canada's privacy commissioner has expressed concerns that Google's streetview product, which includes images of identifiable individuals captured in public places may violate Canadian privacy law. While streetview hasn't been introduced in Canada yet, making Google's legal violation largely hypothetical, the fact that the question is arising at all indicates that Google may still be a bit tone deaf on the issue of privacy, and might not be the right organization to spearhead a call for global standards.

Thursday, September 13, 2007

Search Engines React to EU Resolutions

The difference between the European approach to privacy and that followed in the U.S. has impacted the privacy practices of many search engines. Google has reduced the period after which its server logs will be made anonymous to 18 months, and its cookie retention period was reduced to 2 years. Other search engines quickly followed the lead. Yahoo! and Microsoft met Google's challenge, or implemented even shorter periods. It is likely that these moves were in reaction to the publication of an EU resolution on privacy protection and search engines last November, in which they called on the search engines "to respect the basic rules of privacy...and to change their practices accordingly." In the US, there is no one comprehensive and all-encompassing piece of legislation governing privacy to which all sectors of the economy are subject. Thus, US companies rely more on industry self-regulation and public pressure. Thus, the moves by the big three search engines can be seen as bowing to the concerns of the European public. Search engines are under pressure to deliver more targeted information to marketers, but also realize that customers have to feel comfortable that the information collected will be kept private. Successful search engines' business must start and end with consumer trust.

Major Change to California Law Regarding Security Breaches Coming

Back in July, I wrote about a proposed California law which would require merchants who suffer from data security breaches (think TJX) to reimburse financial institutions for the cost of replacing credit cards for people whose information is stolen (link here). Now, according to this article from Computer World, that bill has passed through the California senate and now awaits signature by governor Schwarzenegger. Though the law has had some changes as it moved through the legislature. For example, a new provision has been added which would allow merchants to excused for some or all of the costs of card replacement if it can show it was in compliance with all security requirements at the time of the breach. However, the main focus of the law - shifting costs from merchants to banks, remains intact. According to the Computer World article, if signed, the law is expected to have the same ripple effect that California's SB 1386 had on security breach notification in general.

Tuesday, September 11, 2007

Presumably, These People had Heard of HIPAA

Computer World has an interesting article up about companies which have, through their own incompetence, run afoul of the HIPAA data security rules. Highly recommended reading, and quite entertaining in a Darwin Award sort of way. My personal favorite was the one where a manager asked an employee to take backup tapes containing unencrypted personal data for patients home with him in order to accomplish the off site data storage requirements of HIPAA. When the tapes were stolen (of course) the employee reported their theft to the authorities and was fired for his trouble. The story doesn't end there though - because the employee was following his company policy and instructions from a supervisor, the employee is potentially protected from retaltiation from his employer. Thus, the employer might have bought itself both a HIPAA nightmare and a suit under the applicable whistleblower protection laws.

However, the bottom line of the article is serious. Too many organizations have been behaving as if HIPAA simply doesn't exist, or as if its requirements had no meaning. While the keystone cops level of competence of some organizations is amusing, it's no joke for the organizations and people involved. So, for HIPAA, know it, read it, do it...otherwise you could find yourself included in the next compilation of HIPAA disasters.

Friday, September 7, 2007

FBI Can't Stop an ISP from Telling Its Customers that the Government Wants Their Data

Yesterday the ACLU won a significant victory as the U.S. district court for the southern district of New York struck down certain provisions of the PATRIOT which information requests by the FBI (the decision can be found here). The basic subject matter of the lawsuit was national security letters (NSLs) which the FBI could send to wire and electronic communication service providers requesting information about their subscribers, such as the subscribers' names, addresses, lengths of service and records of their transactions. Under the challenged provision of the PATRIOT Act, the FBI could also prohibit the recipient of an NSL from disclosing that the FBI had sought or obtained access to information or records using an NSL if the director of the FBI, or his designee, certifies that disclosure "may result in a danger to the national security of the United States, interference with a criminal, counterterrorism, or coutnerintelligence investigation, [or other ennumerated harms]". Thus, not only could the FBI use a NSL to obtain information about an individual's electronic communications, but the FBI could prevent the individual from ever finding out about the NSL by stating that disclosing the NSL "may" pose a danger to certain listed (but generally poorly defined) interests. The judge analyzed the law under the rubric of a license to speak and found that the procedural safeguards necessary for such a licensing regime to survive were not present - a result the ACLU was understandably happy about (their press release can be found here).

The difficulty with this ruling though, is that it might not have any effect on the behavior of private entities. The judge struck down the portion of the PATRIOT act which allowed the FBI to prevent private entities from disclosing that they had received an NSL. However, the behavior of most entities when called on to do the government's bidding indicates that such a prohibition might not be necessary. For example, AT&T is currently in court for (allegedly) assisting the national security agency in illegally violating the rights of AT&T customers (the EFF page on the case can be found here). It doesn't take much imagination to visualize a situation where an entity such as AT&T receives an NSL, and then voluntarily declines to disclose the receipt of that letter (or anything about its contents) to anyone. While there have been some notable instances of businesses resisting the government (e.g., Google), in general, the government has substantial power to convince companies to cooperate even without being able to issue legally binding gag orders. Thus, until there is some indication that ISPs (and other relevant entities) won't simply cooperate with the government and voluntarily maintain their silence upon receipt of an NSL, there is a real danger that the ACLU's recent win may turn out to be a hollow victory.

In completely unrelated news, the Department of Justice has issued a public statement opposing Net Neutrality (link), a principle which would prevent ISPs from charging differential rates for internet traffic. Net Neutrality is generally opposed by telephone companies (e.g., AT&T) who would stand to profit from being able to charge higher rates for preferred access to internet resources link. Proponents of Net Neutrality generally include software companies (e.g., Google) which benefit from low cost internet access link.

Monday, September 3, 2007

Is Privacy Worthless?

Wired has an interesting article what value people put on privacy. The answer is unsurprising, if a bit depressing for people who do care about privacy: people always value even small amounts of money (e.g., a quarter) over the privacy of their personal information, even if that information is highly sensitive (e.g., number of sex partners). However, while the finding that consumers place very little value on privacy was depressing, one of the reasons given for that low value - a lack of understanding of the concrete risks to decreased privacy - was actually cause for hope. For example, consumers are generally highly concerned about identity theft (see, e.g., this article). Using that concern, it would seem that if privacy advocates can connect lack of privacy (i.e., everything you do being monitored and stored) with increased risk of identity theft (i.e., stored information about you being stolen and used for fraud) then they might be able to make a compelling case that consumers place too low a value on the privacy of their information.

Saturday, September 1, 2007

Know Your Pleadings: Electronic Communications Privacy Act

On the 22nd of August, a federal judge ruled that paying a hacker $15,000 to provide you with confidential emails did not lead to liability under the wiretap act or California's invasion of privacy act. The opinion itself can be found here.

So what happened? The judge stated that since the emails were taken from a server, they weren't "intercepted" for purposes of the wiretap act. As set forth in this article from C|NET, that would seem to indicate that the wiretap act simply doesn't cover email communications, since all emails are stored in memory (e.g., RAM), at least temporarily. No damages were available under California's invasion of privacy act because that act was preempted by the federal statute.

Does this mean that there is simply no remedy for someone whose emails have been stolen? Not at all. As the decision made clear, the wiretap act is only half of a larger bill, the electronic communications privacy act (ECPA). ECPA's other half, the stored communications act is designed to "address access to stored wire and electronic communications and transactional records." However, the plaintiffs made their claims under the wiretap act, note the ECPA. The moral of the story? There are two. First: the American legal system seems to have been designed in a deliberately confusing manner with traps for the unwary which can prevent even meritorious claims from being heard. Second: if someone steals your emails, you sue under the ECPA, not the wiretap act.