PDA

View Full Version : Secret Police



Marcus Bryant
01-12-2010, 05:08 PM
http://amconmag.com/article/2010/feb/01/00010/

Secret Police
Can personal privacy survive the digital revolution?

By Brian Doherty
The American Conservative

Civil libertarians hoped that the Obama era would see a renewed commitment to privacy protections. But their dreams are being dashed. Congress seems likely to recess without adjusting aspects of the Patriot Act set to expire at the end of the year, which means that the existing law will be temporarily extended. Elements up for reconsideration include roving wiretaps in foreign intelligence investigations that are not targeted to a specific communication mode or person and “section 215” ability to seize business or other records in a presumptive terror investigation.

Different bills to reform these and other powers have come out of the Judiciary Committees of the House and Senate. The House version is slightly better in terms of demands it makes on law enforcement and intelligence agencies to have defensible reasons for their searches and seizures. But the controversial provisions will survive, even if slightly circumscribed.

So will other post-9/11 surveillance practices. Candidate Obama swore that under his reign, Americans would see “no more National Security Letters to spy on citizens who are not suspected of a crime.” But his administration has shown no desire to relieve itself of NSL powers. National Security Letters allow FBI agents to grab records and information about you from third parties without any judicial supervision. The recipients are legally prohibited from telling anyone other than their lawyers that they gave up the information.

The Patriot reauthorization debate unfolded as the telecommunications industry, already known for craven capitulation to the National Security Agency’s warrantless wiretapping program, was revealed by researcher Chris Soghoian to be continuing to cooperate with law enforcement against customers’ interests at a level that, in the words of a request from Yahoo! to keep its collaboration quiet, would “shock” customers and “shame” telcos.

Sprint Nextel, for example, provided the government with GPS locations of its subscribers via their cell-phone signals 8 million times between September 2008 and October 2009. As Soghoian writes, telecom and Internet providers “all have special departments, many open 24 hours per day, whose staff do nothing but respond to legal requests. Their entire purpose is to facilitate the disclosure of their customers’ records to law enforcement and intelligence agencies.” Verizon, objecting to a FOIA request by Soghoian, expressed concern that subscribers might start bothering it to provide information dumps that the company only provides for cops. Verizon also worried that customers would ask whether their info was being coughed up to law enforcement. Of course, Verizon would not tell them.

These two stories—Patriot reauthorization and telco cooperation—frame the battlefield on which American privacy is being slaughtered. On one end is a government that wants to suck up as much information as it can with as little oversight as possible. On the other end are private companies—to which we entrust more and more information about what we are saying, writing, buying, and thinking—that in effect act as government information agencies.

So many alarming procedures and plans that impact Americans’ privacy—our ability to move through the world without giving up information to authorities, whether knowingly or unaware—are either in the works or already implemented that if you talk to 10 different privacy-rights advocates, you hear 10 different primary worries. A big one, the de facto national ID card created through the “Real ID” system—a set of federal demands on security and verification measures on state ID’s—has been effectively killed by grassroots federalism: states just refused to go along, and the federal government had pretty much given up, despite the law having passed in 2005. But the Senate is now considering a revival of most of Real ID’s features through the PASS ID act, which the ACLU’s Christopher Calabrese characterizes as “the government giving us a permission slip on whether you can engage in the right to travel, and potentially to work or vote or even own a gun.”

Republicans, both in Congress and in the grassroots, don’t seem particularly concerned with these issues. As Julian Sanchez, who studies privacy and technology issues for the Cato Institute, noted, “Thus far, the approved conservative position appears to have been that Barack Obama is some kind of ruthless Stalinist with a secret plan to turn the United States into a massive gulag—but under no circumstances should there be any additional checks on his administration’s domestic spying powers.”

Meanwhile the privacy-advocacy community often conflates privacy threats from government with those from marketers. The information-collection practices that alarm privacy mavens range from such seemingly innocuous practices as supermarket discount cards—which create permanent records of your buying habits—to things as creepy as tracing and saving Internet searches and webpage visits to generate ads computer-calculated to fit a data-derived image of “you.” But these schemes are ultimately dedicated to nothing more sinister than trying to sell you things.

Government, on the other hand, can do things to you, or deny you the right to do things, based on the information it captures. This might seem to create a clear-cut free-market line between when information-gathering is a public-policy issue and when it isn’t. But the situation is more complicated than that. Private information-gathering companies such as ChoicePoint make a lot of money selling their data to … the government. A 2006 GAO study found $30 million being spent by just four government agencies on services from private information brokers.

Assaults on our ability to keep facts about ourselves to ourselves come from both private and public directions, and in many cases it’s hard to distinguish. At the heart is what privacy researcher James Rule of UC Berkeley, author of Privacy in Peril, identifies as our tendency to embrace, or at least accept, any data-collection or surveillance system as long as we think it has utilitarian benefit.

The cell phone is emblematic of our modern approach to privacy. In the space of a decade, it has gone from expensive rarity to perceived necessity. It keeps us connected everywhere we go, which most now think of as a blessing (and even many who acknowledge it as a curse feel unable to escape). But a cell phone creates a record of exactly where you have been via the signals it pings back to cell towers, a record that is generally available to government investigators with ease, though lower courts have tried to establish standards for the circumstances and methods by which the government can get that data. Even turning your phone off won’t necessarily keep it from being a silent betrayer of your every step; you either need to take the battery out or—if this can be contemplated—leave it at home.

The cell phone is the most extreme example of the trail we create in pursuit of convenience. Such data-hungry sectors as credit and insurance also hoover up information about us, but the efficiencies they provide would be difficult for most of us to live without. The credit-information industry in particular creates an interesting irony: by gathering so much about our private financial behavior in a faraway database, making decisions based on it, and often trading that information to others, these companies allow access to credit with greater face-to-face privacy since, unlike a century ago, a merchant need know nothing about our probity, wealth, family, or job before extending credit, as long as MBNA vouches for us.

In the realm of business interactions—from cell phones to credit cards to our search-engine use—we see privacy crumbling beneath the weight of a conflicting need. The same dynamic drives government surveillance, though the need is not ours but the state’s. Even before the massive security apparatus erected after 9/11, government’s desire to punish Americans for the sale or possession of certain drugs was dramatically reducing historic protections. Among the privacy-damaging precedents we owe to the war on drugs are the “good faith” exception for illegally obtained evidence; warrantless searches of private, clearly posted land; warrantless monitoring of yards via low-flying helicopters; and searches via sniffing dog without probable cause.

Various other public-policy needs are pushing us in the direction of more government data collection, monitoring, and verification—the classic “your papers, please” measures that have long evoked tyranny. The desire to ensure illegal immigrants can’t work feeds the “E-Verify” data system, currently voluntary but possibly soon to be part of comprehensive immigration reform (and requiring a true national biometric ID card to achieve its goal). Border security has led to easily hackable RFID chips in our passports and warrantless searches of our computers. The desire for safety feeds such privacy-wrecking expedients as public closed-circuit TV (with local programs often funded by the federal Department of Homeland Security) and whole-body imaging scanners at airports (150 new ones being rolled out this year).

The government’s law-enforcement goals result in data collection even outside the politically controversial Patriot Act provisions. The FBI has its National Security Branch Analysis Center, which as a September 2009 Wired story reported, “maintains a hodgepodge of data sets packed with more than 1.5 billion government and private-sector records about citizens and foreigners, the documents show, bringing the government closer than ever to implementing the ‘Total Information Awareness’ system first dreamed up by the Pentagon in the days following the Sept. 11 attacks.” (The FBI also has its own telecom listening program, the Digital Collection Systems Network.) Then there’s FinCEN, which in the words of the privacy watchdog organization Privacilla, “handles more than 140 million computerized financial records compiled from 21,000 depository institutions and 200,000 nonbank financial institutions. Banks, casinos, brokerage firms and money transmitters all must file reports with FinCEN on cash transactions over $10,000. And FinCEN is the repository for ‘Suspicious Activity Reports’ which must be filed by financial institutions under the Bank Secrecy Act.” There are deadbeat-dad databases, criminal-record databases, and “secure flight” systems to check us at airports.

But the mother of all privacy violations in its potential scope is the NSA warrantless wiretapping program codified through the FISA Amendment Act of 2008. That project, as Kevin Bankston of the Electronic Frontier Foundation says, switched American surveillance from a model where investigators “picked a target and wiretapped that person” to “a wholesale model where we essentially wiretap everyone.” It’s the realization of the vision of your most paranoid friend, quite sure that every single phone call, e-mail, and website visited is marked, recorded, and examined by spooks.

That nightmare, Bankston says, “is not paranoia.” It is at the root of lawsuits against both the NSA and AT&T after a whistleblower revealed that the NSA really did have a secret room built into a major AT&T center in San Francisco to grab all its Internet traffic. While the extent of this brazen program shocked some, the principle has been built into American telecommunications law since 1994’s Communications Assistance for Law Enforcement Act, which required telecom companies to design their systems to allow government eavesdropping. And Fourth Amendment restrictions against searches and seizures don’t apply to information given freely to a third party, including any telecom system sending your messages along.

It’s hard to know how many people are harmed by such programs. In one ACLU suit against the practice, a District Court threw out the case since none of the plaintiffs could prove he had been specifically victimized—because the program is secret.

The legal and philosophical debates about privacy continue. What standards are appropriate for law-enforcement seizure of electronic communications? To what extent can we even claim property rights to information about us or by us once it’s in someone else’s hands? In a wired age of tiny and ubiquitous detection and recording devices, where all of our communications go over third-party systems, can any vestige of 20th-century notions of private life experiences truly survive?

All of these debates about principles and processes seem beside the point in the shadow of two huge structures under construction in Utah and Texas. As NSA historian James Bamford explained in the New York Review of Books in November, the Utah facility will be “a million square feet … one-third larger than the US Capitol and will use the same amount of energy as every house in Salt Lake City combined … house trillions of phone calls, e-mail messages, and data trails: Web searches, parking receipts, bookstore visits, and other digital ‘pocket litter’… . the NSA is also completing work on another data archive, this one in San Antonio, Texas, which will be nearly the size of the Alamodome.” Their data storage capacity will probably exceed that of every computer in the world; their legal and technical ability to snoop, data mine, and draw conclusions about all of us will be nearly unstoppable.

But the public doesn’t seem concerned enough about any of this to make a political fuss. When I asked the EFF’s Bankston if the change in administrations had made any positive impact on government policy toward privacy and surveillance, he answered quickly, “None.”
__________________________________________

Brian Doherty is a senior editor at [I]Reason magazine and author of This is Burning Man, Radicals for Capitalism, and Gun Control on Trial.

Winehole23
01-12-2010, 05:22 PM
Not to minimize, but didn't Project Eschalon (http://cryptome.org/echelon-60min.htm) putatively cover similar territory?

Marcus Bryant
01-12-2010, 05:31 PM
To an extent. One of the primary differences is the extent to which personal information and interaction has been digitized. Also, and I forget the details, Echelon intercepted international communications while now virtually all communications are intercepted - we just have to trust that the feds are in fact not taking a peek at communications between US citizens on US soil.

Echelon was at least science fiction in the sense that back then, it was much more limited in what was intercepted and, of course, there were plenty of communication alternatives which escaped that net. Think of what is emailed now versus what used to go via snail mail. And of course once upon a time cable transmissions were intercepted, but the feds supposedly had a procedure in place to protect those.

I do recommend Bamford's books if anyone has an interest in the NSA's history and activities. I've read the first two and have slowly been reading The Shadow Factory (http://www.amazon.com/Shadow-Factory-NSA-Eavesdropping-America/dp/0307279391/ref=sr_1_1?ie=UTF8&s=books&qid=1263335358&sr=8-1). The NSA essentially collects all of your digital communications.

Winehole23
01-13-2010, 02:00 AM
The NSA essentially collects all of your digital communications.That was the gist of the 60 minutes interview posted upstream.

Winehole23
01-13-2010, 03:26 AM
National security state >>> retrofitted for terror. Technology changes a lot in ten years.

boutons_deux
01-13-2010, 05:52 AM
Combined with the data mining and selling of personal info that the corps do (all of which is available to the feds for the asking, with complete immunity for the corps),

People who are vehemently against national ID cards because of the potential for abuse are silly turds. The abuse is already systematic.

And just wait until the medical records go digital and national.

Information is power, and all power is always abused, sooner or later.

DarrinS
01-13-2010, 09:09 AM
And just wait until the medical records go digital and national.





qEb6FrSuUJs

ElNono
01-13-2010, 09:17 AM
PGP for the win...

DarrinS
01-13-2010, 10:24 AM
PGP for the win...


I'd venture to guess that a large number of people that are paranoid about their personal digital information are too dumb to secure their wireless router.

Marcus Bryant
01-13-2010, 01:06 PM
That was the gist of the 60 minutes interview posted upstream.

Echelon to me is what was in place prior to 9/11. The fiber optic explosion which occurred in the 90s passed the NSA by, as Echelon was built on satellite download/upload intercepts.

Now the NSA is building mammoth warehouses in SLC and SA.

And we have to count on our congresspeoples to figure out what is going on.

Wild Cobra
01-13-2010, 05:01 PM
I find it ignorant, ironic, and hypocritical that the liberals complain about the Patriot Act, yet accept the digital health care records, and madatory insurance.

Is there much reason not to call them libtards?

boutons_deux
01-13-2010, 05:08 PM
"digital health care records"

An excellent way to reduce costs, deliver more accurate care, and stop the very expensive doctor-shopping.

Also prevents docs from denying you access to your own health records when you want to change docs.

When France went with Health ID cards, they were able to shutdown a millions of people who going Michael Jackson and shopping docs for anti-depressants.

Security of health records is totally different issue.

Patriot Act is by definition about violating personal privacy and security BY THE GOVERNMENT with the corps recruited and deputized.

Didn't expect you to wrap your partisan brain around such fine details.
'
mandatory insurance paid to gouging for-profit insurers is an abomination. progressives wanted a public option to be mandatory, the health insurers killed it and got themselves enriched.

As always, your fucking wrong if you think progressives are happy with health reform fiasco.

Winehole23
01-13-2010, 05:15 PM
I find it ignorant, ironic, and hypocritical that the liberals complain about the Patriot Act, yet accept the digital health care records, and ma[n]datory insurance.@b_d?

Wild Cobra
01-13-2010, 05:18 PM
Security of health records is totally different issue.

WTF...

If it is mandated that they be archived, then any good hacker can get that information. Anyone with access to the system can abuse it. I choose not to participate in such a system. It is a clear violation of the 4th amendment, as it lacks reasonability.

Patriot Act is by definition about violating personal privacy and security BY THE GOVERNMENT with the corps recruited and deputized.

Bullshit.

It is the governments responsibility to protect this nation from enemies. Itis not unreasonable to selectively access communications. What you speak of is mandatory data collection of all US citizens. The only contitutional act of any such thing is the US census, and even that is abused.

Wild Cobra
01-13-2010, 05:20 PM
I find it ignorant, ironic, and hypocritical that the liberals complain about the Patriot Act, yet accept the digital health care records, and ma[n]datory insurance.@b_d?
LOL...

Usually I go back and correct my typos... I'll leave it now!

Marcus Bryant
01-13-2010, 05:20 PM
You have no right to liberty and privacy when there is a world to be saved, or perfected, or whatever the fanatics of all stripes seek. Fuck you.

Winehole23
06-10-2018, 09:54 PM
HART


The U.S. Department of Homeland Security (DHS) is quietly building what will likely become the largest database of biometric and biographic data on citizens and foreigners in the United States. The agency’s new Homeland Advanced Recognition Technology (HART) (http://www.planetbiometrics.com/article-details/i/5614/desc/dhs-reveals-details-of-rfp-for-hart/)database will include multiple forms of biometrics—from face recognition (https://www.eff.org/pages/face-recognition) to DNA, data from questionable sources, and highly personal data on innocent people. It will be shared with federal agencies outside of DHS as well as state and local law enforcement and foreign governments.https://www.eff.org/deeplinks/2018/06/hart-homeland-securitys-massive-new-database-will-include-face-recognition-dna-and

Winehole23
06-10-2018, 09:54 PM
https://www.eff.org/files/2018/06/06/hart_timeline_slide.png

boutons_deux
06-10-2018, 10:17 PM
America is fucked and unfuckable. The fucking continues, is unstoppable, irreversible.

Winehole23
07-15-2021, 10:52 AM
“The policies of the large providers are known and published by them and are often included in their law enforcement response guidelines,” said Opsahl, “so the government would be already aware of the promises these companies have given [customers] to provide notice” when law enforcement agencies seek their records.


Proofpoint, however, doesn’t have a published policy about how it handles law enforcement requests like this, and may not have received such a request before. This may be why the government sent the request to them, Opsahl noted.


He says it’s a warning to customers that even if their provider has strong protections against improper law enforcement requests, the government “can bypass that by going to a service provider that layers on top of that provider” and noted that it’s particularly “sad and ironic” that the government targeted a security firm in this case — “a company that would be brought into protect the mail for threats, actually becomes an attack vector.”
https://zetter.substack.com/p/justice-department-sought-reporter