Showing posts with label Electronic Privacy Information Center. Show all posts
Showing posts with label Electronic Privacy Information Center. Show all posts

Sunday, April 29, 2012

Data Harvesting at Google Not a Rogue Act, Report Finds

New York Times
Dave Streitfield

SAN FRANCISCO — Google’s harvesting of e-mails, passwords and other sensitive personal information from unsuspecting households in the United States and around the world was neither a mistake nor the work of a rogue engineer, as the company long maintained, but a program that supervisors knew about, according to new details from the full text of a regulatory report.

The report, prepared by the Federal Communications Commission after a 17-month investigation of Google’s Street View project, was released, heavily redacted, two weeks ago. Although it found that Google had not violated any laws, the agency said Google had obstructed the inquiry and fined the company $25,000. 

On Saturday, Google released a version of the report with only employees’ names redacted.
The full version draws a portrait of a company where an engineer can easily embark on a project to gather personal e-mails and Web searches of potentially hundreds of millions of people as part of his or her unscheduled work time, and where privacy concerns are shrugged off. 

The so-called payload data was secretly collected between 2007 and 2010 as part of Street View, a project to photograph streetscapes over much of the civilized world. When the program was being designed, the report says, it included the following “to do” item: “Discuss privacy considerations with Product Counsel.” 

“That never occurred,” the report says. 

Google says the data collection was legal. But when regulators asked to see what had been collected, Google refused, the report says, saying it might break privacy and wiretapping laws if it shared the material. 

A Google spokeswoman said Saturday that the company had much stricter privacy controls than it used to, in part because of the Street View controversy. She expressed the hope that with the release of the full report, “we can now put this matter behind us.” 

Ever since information about the secret data collection first began to emerge two years ago, Google has portrayed it as the mistakes of an unauthorized engineer operating on his own and stressed that the data was never used in any Google product. 

Monday, March 19, 2012

As Occupy Arrestees Arraigned, Iris Scans Affect Bail

Village Voice
Nick Pinto

Refuse to have your iris photographed,
and your bail could go up.
The first of the more than 70 Occupy Wall Street protesters arrested Saturday afternoon and evening were arraigned yesterday in Manhattan Criminal Court.

Exhausted by a night and day in jail and shaken by the violence of the police response to Occupy Wall Street's six-month anniversary celebration, many burst into tears of relief when they were finally released to the friendly welcome of the movement's Jail Support team.

Unlike many of the other defendants with whom they shared cells, the protesters could feel confident that they would soon be released -- Occupy posts bail for those arrested during movement actions.

But protesters and their legal advisers were surprised yesterday to learn that the size of their bail was being affected by whether defendants were willing to have the distinctive patterns of their irises photographed and logged into a database.

Police and courts have been photographing irises since 2010, once at booking and once on arraignment. The practice is a response to a couple of instances in which mistaken identity allowed someone facing serious charges to go free by impersonating another defendant up on minor charges.

The idea of the state collecting distinctive biometric information from people who haven't even been charged with a crime yet, much less convicted of one, makes civil libertarians nervous, though, and over the last two years they've pushed back. Unlike fingerprints, they argue, no law was ever passed to require iris photographs -- it's just a policy. And while police regularly tell arrestees that the photographs are mandatory, and that failing to be photographed will prolong their stay in jail, defendants have often refused to comply without serious consequence.


That appears to be changing. Yesterday, a defense lawyer had told Judge Abraham Clott she was under the impression that her client -- not affiliated with Occupy Wall Street, facing charges of marijuana possession -- was not legally bound to submit to an iris photograph. Clott responded in no uncertain terms: Iris photographs may be optional in the sense that the court can proceed without them if it has to, he said, for example if the photographic equipment breaks down. But they are not optional for defendants.

Friday, July 15, 2011

Federal Court Rules TSA Violated Law By Introducing Body Scanners

Freedom4um

The D.C. Circuit Court of Appeals ruled today that the TSA violated federal law by rolling out radiation firing body scanners in airports without soliciting public comment. The court will allow use of the scanners to continue, however.

A unanimous three-judge panel ruled that the TSA’s failure to provide notice and allow sufficient time for comment before adopting the technology as a primary passenger-screening tool was unlawful.
“[M]uch public concern and media coverage have been focused upon issues of privacy, safety, and efficacy, each of which no doubt would have been the subject of many comments had the TSA seen fit to solicit comments upon a proposal to use [advanced imaging technology] for primary screening,” the court said.

Specifically, the TSA’s actions violated the Administrative Procedure Act, which requires federal agencies to provide notice and opportunity for comment when implementing a rule that affects the rights of the public.

Judge Douglas Ginsburg found there was “no justification for having failed to conduct a notice-and-comment rulemaking,” and said, “few if any regulatory procedures impose directly and significantly upon so many members of the public.”


The court said that the roll out of body scanners could not be “merely interpretive, procedural, or a general statement of policy.”

The TSA, currently operating close to 500 scanners in 78 airports and planning to add 500 more scanners by the end of 2011, must now receive comment on it’s continued deployment of the technology and respond accordingly by law, finally giving critics an official voice on the issue.
The case was brought by the Electronic Privacy Information Center (EPIC), which argued in its brief that body scanners are “invasive, unlawful, and ineffective,” and that the TSA’s deployment of the devices violated the U.S. Constitution and several other federal statutes.

The rights group is pursuing a case to completely suspend use of the scanners in airports.
EPIC president Marc Rotenberg described the court’s ruling as a “very good decision with far-reaching implications.”

Rotenberg said in a statement that the TSA “is now subject to the same rules as other government agencies that help ensure transparency and accountability. Many Americans object to the airport body scanner program. Now they will have an opportunity to express their views to the TSA and the agency must take their views into account as a matter of law.”


EPIC also argued that the scanners violate the Fourth Amendment by allowing for unreasonable searches, noting that a scan “is more invasive than is necessary to detect weapons or explosives”.

The court stopped short of ruling the scanners unconstitutional, however, noting “we are not persuaded by any of the statutory or constitutional arguments against the rule.”

The panel concluded that use of the scanners by the TSA should continue.

“Due to the obvious need for the TSA to continue its airport security operations without interruption, we remand the rule to the TSA but do not vacate it,” the court said in its ruling.

Monday, May 16, 2011

Scientists Cast Doubt on TSA Tests of Full-Body Scanners

IntelHub
By Michael Grabell

The Transportation Security Administration says its full-body X-ray scanners are safe and that radiation from a scan is equivalent to what’s received in about two minutes of flying. The company that makes them says it’s safer than eating a banana.

But some scientists with expertise in imaging and cancer say the evidence made public to support those claims is unreliable. And in a new letter sent to White House science adviser John Holdren, they question why the TSA won’t make the scanners available for independent testing by outside scientists.
The machines, which are designed to reveal objects hidden under clothing, have the potential to close a significant security gap for the TSA because metal detectors can’t find explosives or ceramic knives, which can be just as sharp as the box cutters that hijackers used on 9/11.

They are also important for TSA’s public relations battle over the alternative, the “enhanced pat-down,” which has bred an epidemic of viral videos: A 6-year-old girl is touched from head to toe. A former Miss USA says she was violated. A software programmer warns a screener, “If you touch my junk , I’m going to have you arrested.”

After the underwear bomber tried to blow up a Northwest Airlines plane on Christmas Day 2009, the TSA ramped up deployment of full-body scanners and plans to have them at nearly every security line by 2014.

There are two types of body scanners. Millimeter wave machines emit a radio frequency similar to cellphones. Backscatters work like a fast-moving X-ray. In the latter, the rays bounce off the skin and create a fuzzy white image of the passenger’s body. Because the beam doesn’t go through the body, most of its radiation is received by the skin.

The TSA says the backscatter technology has been evaluated by the Food and Drug Administration, the National Institute for Standards and Technology and the Johns Hopkins University Applied Physics Laboratory. Survey teams are using radiation-detecting dosimeters to check the machines at airports. The TSA says the results have all confirmed that the scanners don’t pose a significant risk to public health.

According to the agency and many radiation experts, the dose is so low, even for children or cancer patients, that someone would have to pass through the machines more than a thousand times before approaching the annual limit set by radiation safety organizations.

But the letter to the White House science adviser, signed by five professors at University of California, San Francisco, and one at Arizona State University, points out several flaws in the tests. Studies published in scientific journals in the last few months have also cast doubt on the radiation dose and the machines’ ability to find explosives.

A number of scientists, including some who believe the radiation is trivial, say more testing should be done given the government’s plans to put millions of passengers through the machines. And they have been disturbed by the TSA’s reluctance to do so.

“There’s no real data on these machines, and in fact, the best guess of the dose is much, much higher than certainly what the public thinks,” said John Sedat, a professor emeritus in biochemistry and biophysics at UCSF and the primary author of the letter.

The same group stirred controversy last year when it sent a letter to Holdren arguing that while the overall dose to the body may be low, the TSA hadn’t quantified the dose to the skin. Last fall, FDA and TSA officials released a study that estimated the dose to the skin to be twice the dose to the body, though still extremely low.

In the most recent letter sent to Holdren on April 28, the professors note that the Johns Hopkins lab didn’t test an actual airport machine. Instead, the tests were done on a model built by the manufacturer, Rapiscan, and configured to resemble a system previously tested by the TSA.

The researchers’ names have been kept secret, and the report on the tests is so “heavily redacted” that “there is no way to repeat any of these measurements,” they wrote.

The physics and medical professors also took issue with the device used to measure the radiation. Although the device, known as an ion chamber, is commonly used to test medical equipment, they argue that the detector gets overwhelmed by the amount of radiation the backscatter deposits in a short time and might not provide accurate readings.

Helen Worth, a spokeswoman for the Johns Hopkins lab, referred questions to the TSA.

Part of the trouble is that there is no ideal device for measuring the radiation dose given by backscatter X-rays, said David Brenner, director of the Columbia University Center for Radiological Research. The machines emit a pencil beam that rapidly moves across and up and down the body, he said.

“We are one of the oldest and biggest radiological research centers in the country, and we find this to be a very hard technical problem,” said Brenner, who was not involved with the letter.

Another issue is that there is a lot of uncertainty with the model used to estimate cancer risk from radiation exposure to the skin, said Rebecca Smith-Bindman, a UCSF radiologist who also was not involved in the letter.

Smith-Bindman, who has testified before Congress about excessive radiation from medical scans, studied the TSA reports and said she wasn’t concerned about the airport X-rays.
The risks are “truly trivial,” she wrote in an article for the Archives of Internal Medicine. A passenger would have to undergo 50 airport scans to reach the level of a dental X-ray, 1,000 for a chest X-ray, and 4,000 for a mammogram.

Though imperfect, the available models predict that the backscatters would lead to only six cancers over the course of a lifetime among the approximately 100 million people who fly every year, Smith-Bindman concluded.

“There’s really unnecessary fear related to these scans,” she said. “What I’m not as comfortable with is that there has not been access to these machines. They are not being tested on the same regulatory basis that we see on medical equipment.”

After her article was published, Smith-Bindman was contacted by a TSA public affairs officer. During the conversation, she suggested that she or other outside scientists be allowed to test the machine. The official was shocked by the suggestion and said such access could tip off people who want to avoid detection, Smith-Bindman said.

“It was not appreciating that there’s legitimate scientific questions that have to be balanced against the security questions,” she said.

The TSA did not respond to ProPublica’s questions about why it wouldn’t allow outside testing. But at a congressional hearing in March, Robin Kane, assistant administrator for security technology, said doing so would expose a lot of sensitive information the agency wouldn’t normally share publicly. The machines had already been tested several times, he said, and if set up securely, the agency would allow more testing.

The available information leaves scientists with little to work with. Peter Rez, the Arizona State physics professor who signed the letter to Holdren, has tried to calculate the radiation by examining the handful of backscatter images that have been released publicly.

The Electronic Privacy Information Center, a civil liberties group, sued the Department of Homeland Security, TSA’s parent agency, in federal court seeking release of 2,000 backscatter images used in testing. But it has not been successful.

The few images that have been made public do not reveal faces or detailed private features. The TSA says the images Rez used are out of date, but Rez says the current image on TSA’s website is unusable.

Using the earlier images, Rez concluded in the Radiation Protection Dosimetry journal that it was highly unlikely the machines could have produced such high-quality images with doses of radiation as low as those described by TSA. He estimated the dose, while still very small, is 45 times higher than the results measured by Johns Hopkins.

Applying Rez’s numbers, Brenner wrote a paper for the journal Radiology, estimating that 100 additional cancers would develop for every 1 billion scans.

For Rez, the real danger occurs if the machine stops in the middle of a scan, allowing the beam to focus on a tiny area for several seconds. Given that the backscatter works with a wheel rotating at a high speed, and that the agency plans to use the scanners continuously 365 days a year, mechanical failures are likely, he said.

The TSA says that the scanners have safety systems, such as automatic shutoffs and emergency stop buttons, that will kill the beam in the event of any problem that could result in abnormal radiation. How those fail-safe systems work isn’t entirely clear.

When Johns Hopkins researchers visited the Rapiscan facility, the automatic termination appeared to work. But the full results of the shutoff tests are redacted.

What’s more, the test system didn’t have an emergency stop button.

Friday, May 21, 2010

House votes to expand national DNA arrest database


cnet news

Millions of Americans arrested for but not convicted of crimes will likely have their DNA forcibly extracted and added to a national database, according to a bill approved by the U.S. House of Representatives on Tuesday.

By a 357 to 32 vote, the House approved legislation that will pay state governments to require DNA samples, which could mean drawing blood with a needle, from adults "arrested for" certain serious crimes. Not one Democrat voted against the database measure, which would hand out about $75 million to states that agree to make such testing mandatory.

"We should allow law enforcement to use all the technology available to them...to reduce expensive and unjust false convictions, bring closure to victims by solving cold cases, better identify criminals, and keep those who commit violent crime from walking the streets," said Rep. Harry Teague, the New Mexico Democrat who sponsored the bill.

But civil libertarians say DNA samples should be required only from people who have been convicted of crimes, and argue that if there is probable cause to believe that someone is involved in a crime, a judge can sign a warrant allowing a blood sample or cheek swab to be forcibly extracted.

"It's wrong to treat someone as guilty before they're convicted," says Jim Harper, director of information policy studies at the Cato Institute. "It inverts the concept of innocent until proven guilty."

House Speaker Nancy Pelosi and the Democratic leadership scheduled Tuesday's debate on the bill--called the Katie Sepich Enhanced DNA Collection Act of 2010--using a procedure known as the "suspension calendar" intended to be reserved for non-controversial legislation.

"Suspension of the rules is supposed to be for praising the winner of the NCAA championship or renaming Post Offices," Harper says. "Things like collecting Americans' DNA are supposed to be fully debated in Congress."

In a surprise move, as the U.S. Congress was expanding the FBI's DNA database, the U.K.'s new coalition government was pledging sharp curbs on its own databases.

Created in the mid-1990s, the UK National DNA Database originally was supposed to store data on convicted criminals, but grew to include records on more than 5 million Britons, including many who were only arrested on suspicion of a crime.

U.K. Deputy Prime Minister Nick Clegg promised once-in-a-century privacy reforms in a speech on Wednesday: "We won't hold your Internet and e-mail records when there is just no reason to do so. CCTV will be properly regulated, as will the DNA database, with restrictions on the storage of innocent people's DNA. Britain must not be a country where our children grow up so used to their liberty being infringed that they accept it without question."

Background

The United States has followed a similar pattern: first, DNA was collected from convicted criminals, and then the practice was expanded to sweep in Americans arrested on suspicion of a crime.

A 2000 federal law called the DNA Analysis Backlog Elimination Act required that DNA samples be taken from anyone convicted of or on probation for certain serious crimes. This was challenged in court on Fourth and Fifth Amendment grounds, but a federal appeals court upheld (PDF) the DNA collection requirement as constitutional.

A second bill that President Bush signed in January 2006 said any federal police agency could "collect DNA samples from individuals who are arrested." Anyone who fails to cooperate is, under federal law, guilty of an additional crime.

In addition, federal law and subsequent regulations from the Department of Justice authorize any means "reasonably necessary to detain, restrain, and collect a DNA sample from an individual who refuses to cooperate in the collection of the sample." The cheek swab or blood tests can be outsourced to "private entities."

A May 2009 ruling from a federal judge in California was the first decision to say that police can forcibly take DNA samples from Americans who have been arrested but not convicted of a crime. U.S. Magistrate Judge Gregory Hollows said the requirement of DNA-sampling felony arrestees did not violate the Fourth Amendment's prohibition of "unreasonable searches and seizures"--but noted that he took no position on whether or not DNA sampling for misdemeanor offenses was reasonable and constitutional.

But that law applied only to federal agencies, and the bill approved this week would provide a strong incentive for state and local governments to follow suit.

If states do follow suit, it's difficult to overstate how many more DNA samples would flood into the FBI's Convicted Offender DNA Index System (CODIS) database. Federal agencies arrested about 133,000 people in 2004, according to data compiled by the Urban Institute under a Justice Department grant.

But local and state governments arrested nearly 14 million Americans that year, not counting traffic offenses, according to FBI data.

Rep. Teague's proposal would extend DNA sampling and testing to anyone arrested on suspicion of burglary or attempted burglary; aggravated assault; murder or attempted murder; manslaughter; sex acts that can be punished by imprisonment for more than one year; and sex offenses against minors. The attorney general would be required to report to Congress which states have and have not signed up for the DNA database.

Rep. Dave Reichert (R-Wash.), a former sheriff who spoke on the House floor in favor of the bill, said the measure is supported by the National Sheriffs' Association, the National District Attorney's Association, and the Rape, Abuse, and Incest National Network (RAINN).

The legislation would allow states to receive 15 percent "bonuses" from the Edward Byrne Memorial Justice Assistance Grant Program. The program gave out $165 million in local funding and $318 million in state funding for fiscal year 2009, not counting stimulus grants.

"We're strongly opposed to expanding collection," says Marc Rotenberg, executive director of the Electronic Privacy Information Center in Washington, D.C. He suggested the U.S. should follow the lead of the European Court of Human Rights, which ruled two years ago that holding DNA samples from people arrested but not convicted of a crime violates their privacy rights.