Showing posts with label data privacy. Show all posts
Showing posts with label data privacy. Show all posts

Sunday, October 12, 2008

Can Privacy Come Back?

In this interview at Computer World private investigator Steve Rambam argues that "Privacy is dead. Get over it. You can't put the genie back in the bottle." His argument seems to be based in large part on his own database, which supposedly contains
pretty much every American's name, address, date of birth, Social Security number, telephone number, personal relationships, businesses, motor vehicles, driver's licenses, bankruptcies, liens, judgments [etc...]

He uses that database, as well as advances in computer technology and changes in government policy to make the case that more and more information is becoming available about people, and that privacy is a thing of the (rapidly receding) past.

My belief is that Rambam is wrong. I'm willing to concede that the state of individual privacy right now is pretty grim (though I don't think it's dead). However, there is a substantial disconnect between observing that things are bad now, and concluding that they'll never get better in the future. Indeed, as my own contribution to putting Rambam's genie back in the bottle, I would like to present the following things people can do to use the law to help privacy:
1) Remember the FTC. While people generally have little success in suits alleging damages based exposure of their personal data, the FTC has broad enforcement authority to combat unfair and deceptive trade practices. That means that if a company isn't following their privacy policy, or if they're saying they value privacy while they actually sell your personal information to the highest bidder, a complaint to the FTC could be a way to deal with it.
2) Watch the EULAs. As I have written before (e.g., here) contract law in general, and abusive end user license agreements in particular present a serious threat to privacy. Thus, when someone asks you to click before continuing, read what it is that you're being asked to agree to and, if it's abusive, don't agree. In fact, not only should you refuse to agree, you should also complain. While generally consumer complaints are of questionable effectiveness, if a company is interested in its image, it can lead to changes in behavior (e.g., Google Chrome).
3) Know your rights. For example, the Fair and Accurate Credit Transactions Act prohibits printing complete credit or debit card numbers on receipts. By being aware of their rights, consumers can know how to protect themselves and their privacy, either by enforcing their rights themselves (e.g., through a private suit) or though others (e.g., by bringing an FTC complaint).

Sunday, May 4, 2008

Private Information in Court Documents

As described in a pair of articles (here and here) from Computer World, privacy advocate Betty "BJ" Ostergren has been campaigning to have personal data removed from California court websites. BJ claims that she has turned up "complete tax filings, medical reports pertaining to cases handled by the court, and images of checks complete with signatures as well as account and bank-routing numbers" on the court's website. Further, she says that it's possible to retrieve similar documents by entering popular last names at random. The response to this from the court's personnel - that they have tens of millions of documents and finding personal information among them is like looking for a needle in a haystack - is not encouraging. Essentially, everyone who comes into contact with their system is defended through "security through obscurity," and there's nothing that they can do about it.

The question then, is whether the posting of thousands, perhaps tens or hundreds of thousands, of documents containing personal information to the court's website is a problem. As it happens, in my opinion is isn't. I think it is a huge benefit to society for courts to make filings publicly available. Indeed, full access to court records gives people the option of finding out how courts have handled various types of scenarios so that they can plan their actions accordingly. This ability to know (and therefore follow) the law is an indispensable aspect of any system where rule of law is taken seriously. If a court makes tens of millions of document available, I'm not at all surprised that some small percentage of them include information which shouldn't be made publicly available. Certainly that's regrettable, but I think it's a small price to pay for making courts and the law available to all.

Does that mean I think the status quo is optimal? No. I think the response from the court is totally inappropriate. The correct response would have been to to redact the personal information from the identified documents. Even then, the system wouldn't be perfect, since there's no guarantee that personal information would be discovered by privacy advocates who report it to court personnel rather than by criminals who would use it in identity theft. However, it doesn't make sense to expect any system to be perfect, and shutting down something so clearly positive as public access to court filings because they don't perfectly protect privacy would be a terrible mistake.

Sunday, March 16, 2008

Problems with U.S. Courts' Treatment of Security Breach Damages

This article from Computer World asks the question "When Does a Privacy Breach Cause Harm?" and then proceeds to take U.S. courts to task for failing to recognize damages from security breaches beyond verifiable damages from identity theft or account fraud. While I agree that U.S. courts have done an atrocious job with respect to protecting privacy (see, e.g., here, describing the 7th Circuit's statement that plaintiffs could not proceed on a action based on a data security breach, despite circumstances showing that the breach was caused by identity thieves), I have to take issue with the analysis offered in the article. The article states that the problem with what courts have done is that they have overlooked "[t]he assault to personality and feelings [that is] is the quintessential privacy injury." That rationale just doesn't work for me. Human feelings are notoriously hard to quantify, which means that damages based on assaults to personality and feelings would likely swing wildly from case to case and judge to judge, even if the actual underlying facts in particular cases are similar. Moreover, basing damages on feelings of loss and assault to personality runs the significant risk that juries will simply decide that those losses are too small to justify compensating, since studies (e.g., here) have shown that most people place little to no value on the privacy of their personal information.
A better option, and one I happen to agree with, is for businesses which suffer a security breach through their own fault (e.g., negligence) should be held responsible for the quantifiable damages caused by that breach, even if there is no subsequent identity theft. For example, time spent by customers replacing credit cards with stolen numbers, or the cost of various identity theft protection services are easily determined, and would serve as a measure of damages that courts could easily compute and assess. Indeed, since limiting damages to those directly caused by identity theft or account fraud provides an incentive for consumers not to prevent identity theft, making companies responsible for quantifiable costs would improve the status quo by increasing the level of protection given to privacy by courts, while avoiding the difficulties of trying to quantify injuries to personality. To me, that's a far superior alternative to relying on damages to personal integrity, which are both hard to quantify, and easy to undermine.

via The Dunning Letter.

PostScript: I am well aware that laws vary tremendously from state to state. My statements regarding the state of current privacy laws reflect the holding in Pisciotta v. Old National Bancorp, in which the 7th circuit addressed the issue of damages for a data security breach in the absence of subsequent identity theft.

Monday, February 11, 2008

Who Cares About Privacy?

Wired.com has an article up about a startup called Credentica, which uses multi-party computation to allow people to verify information about themselves (e.g., age) without sharing that information, thereby eliminating data leaks which can lead to identity theft.

While the technology of the new service is neat, the headline of the article asks what I believe is an important question: Does Anyone Care? As discussed here, studies show that people always place greater value on even small amounts of money than they do over the privacy of their personal information, meaning that even a startup with a great new privacy protection product is likely to have a tough time in the market. In my opinion, that's too bad. To my mind, protecting your personal information is like playing poker against the world with all your cards exposed. Perhaps my profession as an attorney makes me more vigilant about privacy than other people, after all, lawyers have affirmative duties to protect information. One great example of those duties is this opinion which states in part that
The employees of the public defender's office must be the only individuals who have access to client information, including that which is stored on the computer system. If any component of the computer system is linked or somehow shared by other county offices, the public defender must take whatever reasonable and necessary precautions there are to ensure that this information cannot be accessed by the other offices. This is the public defender’s primary responsibility in this scenario. If the public defender is not satisfied that client confidentiality can be secured, then the ethical alternative is to either maintain a separate computer system from the other county offices or discontinue storing client information on the shared system. (emphasis added)

In other words, for lawyers, if a system isn't secure, it shouldn't be used to store client information. If all individuals had this same type of regard for data privacy, companies like Credentica would be almost sure to succeed. However, my experience, backed up by empirical data, is that most individuals have little to no regard for their personal data, which means that companies like Credentica, even if they have a great product, will likely have a difficult time in the market.

Friday, September 21, 2007

DRM: a Threat to Privacy

Via Michael Geist by way of BoingBoing we learn that The University of Ottawa's Canadian Internet Policy and Public Interest Clinic has released a report concluding that DRM pose a significant threat to privacy. From the executive summary:


• Fundamental privacy-based criticisms of DRM are well-founded: we observed
tracking of usage habits, surfing habits, and technical data.
• Privacy invasive behaviour emerged in surprising places. For example, we
observed e-book software profiling individuals. We unexpectedly encountered
DoubleClick – an online marketing firm – in a library digital audio book.
• Many organizations take the position that IP addresses do not constitute
“personal information” under PIPEDA [Personal Information Protection and
Electronic Documents Act] and therefore can be collected, used
and disclosed at will. This interpretation is contrary to Privacy Commissioner
findings. IP addresses are collected by a variety of DRM tools, including
tracking technologies such as cookies and pixel tags (also known as web
bugs, clear gifs, and web beacons).
• Companies using DRM to deliver content often do not adequately document
in their privacy policies the DRM-related collection, use and disclosure of
personal information. This is particularly so where the DRM originates with a
third party supplier.
• Companies using DRM often fail to comply with basic requirements of
PIPEDA.


This, sadly, should not be a surprise. Copyright organizations have shown themselves to be actively hostile to concerns about information security and data privacy (see, e.g., the discussion of concerns related to watermarking here, or Sony's now infamous fondness for installing rootkits). Indeed, the only time when copyright and information security are (supposedly) aligned is when copyright is trying to piggyback on security concerns to achieve its own ends (e.g., the destruction of P2P networks, as described here).

The happy news though, is that the study came out in the first place. It is possible that this examination of the impact of DRM on privacy could be a reflection of some sort of backlash against the copyright industry's current tactics - something that, if supported by legislation, could result in significant benefits for privacy and security of individual data.

Tuesday, August 21, 2007

Watermarking: Threat to Privacy?

Recently, a mini-firestorm has erupted over the possibility that the recording industry will add watermarks to music files (e.g., articles here, here, and here). The idea behind the watermarks is that they will allow copyright holders to see where files on peer to peer networks came from and file lawsuits accordingly. Whether such tracking would actually allow the RIAA to file suits without being embarassed (e.g., as described in this article, which eventually led to a charge of malicious prosecution) is an open question. However, what I would like to address is not whether the watermarks will help in prosecution of copyright infringers, but what they will do for individual privacy. In a wired.com article on the subject, Evan Hill, CTO of Activated Content, a company that provides watermarking solutions to Universal, Sony/BMG and other labels is quoted as calling watermarks which uniquely identify each file purchased by each user a "privacy nightmare." While there are certainly concerns about watermarking, I don't think those concerns are really that significant. The reason for this is that problems with watermarking are really only a symptom of a larger issue: users being forced to sacrifice their privacy in order to participate in the modern economy. I've blogged previously (see post here) about the threat posed to privacy by the routine enforcement of clickwrap licenses where service providers can basically dictate terms because users either don't or can't understand what they're agreeing to. Similarly, in the case of music distribution, service providers (i.e., record companies) can basically dictate terms to users, because people won't bother to read the licenses provided with the songs and, even if they did, they wouldn't have any choice about accepting them because the record labels have government enforced copyrights (assuming the consumers care about buying licensed copies of the songs, of course). In both cases though, the problem isn't the watermarks (or the clickwraps) it's the economy, and the legal system which allows those tools to be used in ways that strip users of their privacy.

Friday, August 3, 2007

Privacy and Contract Revisited

Two weeks ago today, I wrote that individual privacy was basically dead (original post here). I wrote this in response to an article which discussed the terms of service for the new iPhone, and I pointed out that, since courts routinely enforce clickwrap licenses that are never read or understood by consumers, there was nothing in the world to prevent businesses from writing provisions into those contracts which basically stripped consumers of their privacy. Happily, I may have written too soon.

Since my original post, Wired.com has reported on two court decisions which, contrary to the general practice, have ruled against businesses on the enforceability of clickwrap licenses (stories on the subject are here and here). Does this mean that end user license agreements won't be the death of privacy? It's too early to tell - the cases reported on by Wired weren't directly concerned with privacy, and they might be an aberration rather than a sign of an emerging trend against click licenses. However, it is possible that my conclusion that privacy would be effectively destroyed by EULAs was premature. I hope it was, as that was one circumstance where I would much rather be wrong than right.

Tuesday, July 17, 2007

Department of Energy Levying Security Breach Fines?

Apparently, the Department of Energy (DOE) can levy fines for security breaches - when you're working for them and allow their information to be stolen. At least, that's what's currently happening to the University of California, and a company called Los Alamos National Security, in connection with a loss of classified information from 2006. According to this article from ComputerWorld, the DOE has proposed a fine of $3,000,000 on the University of California, Oakland - the largest fine ever assessed by the DOE. The university, not surprisingly, is fighting back, noting that the breach took place after the university's contract had expired, and noting that the university had taken a number of steps to enhance security. One particular measure taken by the university which is likely to become a trend in other enterprises is the implementation of a diskless and medialess environment, which, when properly implemented, can address one of the most difficult challenges in information security - sensitive data walking off in a portable hard drive or other medium.

Friday, July 6, 2007

And why beholdest thou the mote that is in thy brother's eye?

As if a reminder was necessary, a recent theft of data at Fidelity National Information Services, Inc. has demonstrated that threats to data security doesn't have to come from outside an organization. According to this article from ComputerWorld a senior database administrator - the very person who had responsibility for defining and enforcing data access rights - stole over 2 million consumer records and sold them to a data broker. How can this type of incident be avoided? Well, good personnel policies might help. If there were any red flags (e.g., criminal convictions for related crimes) then putting the former DBA in such a sensitive position would have been a clear mistake. However, not all potential thieves have actually committed a crime (after all, there's always a first time), so looking at an employee's background isn't foolproof. Given that, businesses should make sure that they have in place policies which can detect unauthorized data use (preferably not all enforced by one person, in case that one person happens to be the thief) and then respond quickly, thus minimizing the damage if a theft of data does occur.

Wednesday, May 23, 2007

I-Spy Act Clears House

Yesterday, the House of Representatives voted to approve the Internet Spyware (I-SPY) Prevention Act of 2007. As a quick summary, the bill does not actually prevent, or even target, most spyware. The proposed legislation has two main substantive portions. The first of those substantive provisions, section 1030A(a) adds an additional five year prison term for anyone who makes unauthorized access to a protected computer in furtherance of another Federal criminal offense. In other words, it does not have any effect whatsoever on behavior which is not otherwise a crime. The second of the substantive provisions, section 1030A(b), makes it a crime to make unauthorized access to a protected computer and install software on that computer "with the intent to defraud or injure a person or cause damage to a protected computer." There is no indication in the bill that installing software on a computer which simply monitors the user's behavior and reports to a third party for purposes other than to defraud, injure, or damage a protected computer would come within the reach of the act. Thus, a significant portion of spyware which reports Internet user's browsing habits for commercial gain would arguably be outside of the scope of the so-called Spyware Prevention Act.

Of course, it should be kept in mind that I-SPY has only passed the House, and so it is impossible to know what provisions will be included in the bill if it goes through the Senate and becomes law. However, to the extent that the act is passed in its current form, it will likely have little real effect on the prevalence of spyware on the internet.

Monday, April 23, 2007

The Federal Government in the News

Recently, members of the U.S. House of Representatives Cybersecurity subcommittee recently held a hearing during which serious concerns were raised regarding the security of computers within the State and Commerce departments. The bottom line, from this article from CNET is that
21 of 24 major federal agencies had weak or deficient information security controls in place during the last fiscal year, according to audit reports, said Gregory Wilshusen, director of information security issues for the Government Accountability Office.

troublingly, many of the vulnerabilities can only be described as the result of bad IT practices, such as
failing to replace well-known vendor-supplied passwords on systems to not encrypting sensitive information to not creating adequate audit logs to track activity on their systems.
Of course, it's not at all clear how much the security flaws identified at the hearing even matter, given the federal government's exceptionally lax stance toward data privacy. For example, according to this article, which describes how, until recently, the Agriculture Department and Census Bureau were maintaining a publicly accessible database filled with private information, including social security numbers, of people who received loans from the Department of Agriculture. Thus, while threats from cyberterrorists on State Department servers might be significant, they almost seem redundant, given the amount of information which the government makes publicly available, but shoudln't.

Tuesday, April 17, 2007

Google's Purchase of Doubleclick: Privacy Disaster or Positive Step?

Wired.com has an interesting article up about possible implications of Google's recent purchase of Doubleclick (a company famous for its almost ubiquitous multimedia ads). The Center for Digital Democracy says that this deal raises huge privacy concerns, by allowing Google to more easily create comprehensive profiles of individuals' web usage. On the other hand, Google says that the acquisition will actually increase internet users' privacy, because Google will impose its own data retention policies on a company which had been a poster child for threats to on-line privacy. Who's right? At this point it's impossible to say. However, it's worth noting that Google has in the past been willing to go to court to protect the privacy of its users (e.g., in its fight against the US government, described here). Thus, this could be one case where the expansion of a giant organization with omnipresent data collection abilities could actually be a good thing for individual privacy.

Wednesday, April 11, 2007

State Enforcement Actions

While federal laws such as Gramm-Leach-Bliley and HIPAA are often the focus of concern for organizations seeking to maintain regulatory compliance, it is important to remember that many states have put in place requirements which must be observed as well. Case in point: Texas, where the attorney general took action against Radio Shack for violating that state's 2005 Identity Theft Enforcement and Protection Act and section 35.581 of Chapter 35 of Texas' Business and Commerce Code. According to the attorney general's press release Radio Shack had failed to properly protect and dispose of their customers' by simply dumping bulk records in a garbage receptacle behind a store. The dumped records included, ironically, a receipt from a woman who purchased a shredder from Radio Shack to protect herself from identity theft - just the kind of potential victim the media loves to focus on. Thus, the Radio Shack prosecution should serve as a reminder to businesses everywhere that Federal Law isn't the only source of data privacy and information security law, and it is necessary to be mindful of state statutes as well.

Monday, March 12, 2007

Private Sector Responding to Data Privacy and Security Concerns

While my last post discussed whether federal data security legislation was inevitable, it seems that industry isn't waiting for Congress to act before implementing measures which should be welcome news for anyone concerned with the security of their personal information. First, on the 12th, Seagate Technology announced that a manufacturer would begin selling laptops with built in encryption technology. According to this article, Seagate the new machines
will include a chip that makes it impossible for anyone to read data off the disk, or even boot up a PC, without some form of authentication.
thus (hopefully) making the scares following loss or theft of laptops containing sensitive information a thing of the past. Also, coming fast on the heels of the Seagate announcement, Google has announced that it will revise its data retention policies to protect user privacy. According to this article, Google will begin implementing a policy to anonymize user search records 18-24 months after their creation. When some privacy advocates, such as the electronic privacy information center's executive director, Mark Rotenberg, say that Google's new policy doesn't go far enough, it should be a welcome improvement from Google's current policy of maintaining identifying information in search records indefinitely.

Wednesday, February 14, 2007

Real ID Compliance

The "Real ID Project" being promoted by the Department of Homeland Security pursuant to recently enacted legislation is running into opposition in many state legislatures. According to a recent Associate Press report, at least 17 state legislatures have passed or are considering legislation opposing the Real ID bill. Passed by Congress and signed by President Bush as part of a funding package for the Iraq war, it sets a national standard for driver's licenses and requires states to link their records to national databases. States have until 2008 to comply, and failure will render state driver's licenses insufficient as IDs to board a plane, enter a federal building, or open certain kinds of bank accounts. There are also complaints that it is an unfunded mandate, and an invasion of privacy. Perhaps in recognition of the states' opposition, or as a result of the recent change in control of the Congress, Sen. Daniel Akaka (D-Hawaii) and Sen. John Sununu (R-N.H.) have introduced legislation that would add privacy and civil liberties safeguards to the act. Realistically, it will take states substantially more time to comply, and the efforts of the sponsors of this legislation will likely force an extension of time for compliance by the states.

Friday, February 9, 2007

CNET has an interesting article regarding a number of bills in the house designed to protect consumers from spyware, pretexting, and other potentially obnoxious aspects of modern life. Of the bills summarized the Spy Act intorduced by Mary Bono (R-CA) and Edophus Towns (D-NY) particularly caught my eye. The reason is that that bill would prevent resetting of a browser's home page, something which, when it happens by surprise, is tremendously annoying (at least for me).

Tuesday, February 6, 2007

According to this article in the Washington Post, Congress is once again considering data breach notification laws. The question, of course, is whether any laws passed by Congress will provide an incentive for companies to better protect customer data, or whether they will simply allow Congress to grandstand about consumer rights while actually stripping consumers of rights they already have by pre-empting tougher state legislation. While it's still too early in the process to definitively answer that question, my guess is that whatever eventually emerges from the legislative sausage machine won't have much happy news for the overwhelming majority of Americans.

Sunday, February 4, 2007

Wired.com currently has a very interesting series of articles up on the world or criminal carders (individuals who steal, sell, and use credit card and identify information of others). Largely, the articles are interesting because they provide a fascinating look into a world that most law abiding citizens don't even know exists. However, they also provide some helpful advice for businesses seeking to reduce their vulnerability (e.g., when information is changed on an on-line account, have a substantial waiting period before the assets in the account can be withdrawn).

Bottom line: an interesting read for anyone who uses or issues credit cards.