Showing posts with label Internet. Show all posts
Showing posts with label Internet. Show all posts

Saturday, March 16, 2013

License to Intrude, Part 4

There have been no updates to the blog in a few months, and this series in particular has not been updated in almost a year. But, what I haven't written about is actually quite interesting.

First, a review. In Part 1 we saw how the FBI - government agents whose job is to protect our Constitutional form of government - were taking shortcuts around the Constitution to collect and retain information on law-abiding American citizens who were engaged in lawful activities. (!) We also saw how connected Facebook's senior leadership was to the Obama regime, and this certainly raised the question about potential for abuse. Then, in Part 2, we saw how Facebook collected extensive information on its users, and considered Facebook's policy of sharing information collected with government agencies based on the presumed good faith of those agencies.

Well, in Part 3 we looked at issues being addressed with recent proposed legislation regarding privacy and security and cyberspace. We then went on to see how Facebook was making the location of its users public, and we saw how this trend might likely evolve, with apps that could tell you about the people around you. Of course, if the app can tell you about the people around you, it could also tell someone else about the people around you, and thus about whom you hang around with. ;)

Of course, what has happened since that last post is hardly surprising, but it is important to consider.


First, we examine excerpts from a December 27, 2012, article entitled Prevent Facebook from automatically importing photos by CNET's Dennis O'Reilly (I have reproduced links found in the original):

A few weeks ago, Facebook introduced the ability to sync photos taken on your iPhones, iPads, and Android phones to your Facebook account automatically. Jason Cipriani describes how to enable the feature in "Getting started with Facebook photo sync on Android, iPhone."

[snip]

As you can imagine, having all the photos taken by your phone or tablet uploaded to Facebook imperils your privacy and security. As MercuryNews.com's Brandon Bailey reported earlier this month, Facebook claims it will not use the data associated with the photos until they are posted.

The referenced article, Facebook says it won't use data from private photos, by Brandon Bailey, December 4, 2012, has this to say:

Some analysts raised the possibility this week that Facebook might analyze private photos for digital clues about where they were taken or even the identities of people in the photos, perhaps applying that information in the same way it relies on other user data to determine which ads and other messages are shown to different users.

A Facebook representative appeared to dispute that on Tuesday, saying in a statement: "We only utilize photo data after users decide to share them to Facebook." In response to a follow-up question, the representative said that means the company won't use data from uploaded photos in the user's private album, although the company would apply its normal policies if the user opts to share the photos on Facebook.

[snip]

Bloggers and security experts have praised some aspects of the Photo Sync feature, while cautioning that it could still give Facebook access to more data if it leads to users sharing more photos, and that it might also increase the chances for sharing photos inadvertently.

Of course, let us trust both the ability and the intentions of Facebook. The next logical question is: Who really cares what Facebook does or what Facebook says it will do? Haven't we established in this series that Facebook is a de facto feeder of raw data to the government? And, again, we are assuming government employees are acting competently and in good faith. Considering all the scandals governments are known for, can we trust the people who brought us Fast and Furious with this information?

As pointed out in Prevent Facebook from automatically importing photos:

However, all the data associated with the photos, including where and when they were taken, is still accessible to Facebook and can be used to determine the ads you see. Privacy advocates have pointed out that Facebook users are much more likely to post photos that are already uploaded, often inadvertently.

And, if it is accessible to Facebook, then it is accessible to whom else? Government agents? Hackers? Obamanista operatives?

A situation that is not dissimilar has hit close to home for Facebook. In an article from December 26, enttiled Randi Zuckerberg loses control on Facebook (and Twitter), author Chris Matyszczyk points out how the sister of Facebook's CEO inadvertently posted publicly a photo that she had intended to be seen only by her friends. The article addresses issues such as human decency.

My point, however, is that Facebook's senior leadership is well-connected with an administration that traffics weapons to at least one Mexican drug cartel. Believing that such a government acts in good faith and therefore releasing information to that government's agents trumps any hopes for human decency regarding the possibilities for what might happen with all this information that Facebook has by tracking us online even when we are not logged in to Facebook, and by tracking our location in the physical world, and by automatically uploading photos of the places we are and the people with whom we interact into Facebook's database.

But, of course, it doesn't end there, does it?

What happens once the FBI gets all this information on you, including photos uploaded automatically from your smartphone of where you are and of whom you are with?

Well, FBI security has not always been the best, and another recent scandal specifically illustrates the danger of FBI databases.

Back on September 3, activists involved in AntiSec, an operation run in part by members of the hacker group Anonymous, posted online one million Apple Unique Device Identifiers (UDIDs) from a database of 12 million it claimed to have hacked.


Several articles (AntiSec claims to have snatched 12M Apple device IDs from FBI, September 3, 2012; FBI finds no evidence that AntiSec hacked its laptop, September 4, 2012; How the FBI might've been owned (12M Apple records), September 4, 2012) tell the story of how AntiSec claims to have exploited a bug in Java to access a laptop being used by FBI Special Agent Christopher K. Stangl.


Some key details emerge in this excerpt from FBI finds no evidence that AntiSec hacked its laptop which, in turn, links to another of the articles listed above:

Stangl was among a group of four dozen or so U.S. and UK law enforcement agents who were recipients of an e-mail that AntiSec members got ahold of related to investigating AntiSec, Anonymous and their affiliates. The e-mail was sent last January to organize a conference call among the agents which the hackers then listened in on. Robert David Graham speculates on his Errata Security blog that the hackers got Stangl's e-mail address off that list and targeted him for compromise with a phishing e-mail.

The @AnonyOps Twitter account responded to the FBI statement, saying "FBI says there was no hack. That means either they're lying or they *gave* the information up to someone in #antisec. It's happened before."

Security Space Rogue, the former editor of Hacker News Network, tweeted: "FBI statement is ambiguously short. States not from an 'FBI' laptop. How about a personal laptop of an FBI agent?" An FBI spokesperson did not immediately respond when asked that question late this afternoon.

So, the question hangs as to whether SA Stangl was using this database on a personal laptop. If so, was he doing his official work on his personal computer? Many people do, though one would expect government agencies dealing with issues requiring security and confidentiality would not permit this.

Or, was non-official work being done with this database?

Apparently, access to SA Stangl's laptop (and possibly to other devices?) was gained by exploiting this Java bug after Anonymous intercepted an email with SA Stangl's email address on it. The email had the addresses of many other law enforcement officials, and was scheduling a conference call for French, British, Europol and FBI personnel to discuss these hacktivists and their activities.


It all makes for a nice package, really.

Facebook gets your information (location, photos) automatically, shares it based on presumed good faith with the government run by an administration of a President for whom Facebook officers have campaigned and fundraised. The FBI is then targeted by hackers whom the FBI is investigating and who have successfully stolen other personal information from computers used by FBI agents.

If the FBI can't protect itself and its investigation from the group it is investigating, how well will it protect your information? Will it even admit it has your information, and that your information has been compromised?

Why does the Clinton/FBI Filegate scandal come to mind here?

Of course, there is more to this, isn't there?

An alleged Anonymous hacker was arrested because his presumed girlfriend posted a picture of her breasts online, and US authorities supposedly traced this back to the hacker they were looking for by tying in GPS data of where the photo was taken with a statement the hacker had made online about the location of his female friend.


The article, Breasts lead to arrest of Anonymous hacker, dated April 14, 2012, by Chris Matyszczyk (another of whose articles was mentioned above), concludes thusly:

However, the photograph of the breasts apparently linked authorities to Ochoa -- because, taken with an iPhone, it contained GPS information. The information allegedly suggested she lived in Melbourne, Australia.

Further burrowing led the police to discover a posting on Ochoa's Facebook page that allegedly revealed his girlfriend was Australian.

The claim is that police have managed to match pictures of her that Ochoa allegedly posted on Facebook to the breast image.

To the untrained eye, this might seem curious, as the Facebook pictures allegedly show her face, while the taunting picture does not.

Perhaps the authorities have gone beyond mere facial-recognition technology and are in possession of software that can match other bodily parts with astonishing accuracy.

So, photos get uploaded to Facebook automatically - who knows where they go from there? - and now an expert with a highly reputable computer news magazine speculates that the authorities may have software that can do recognition of other body parts besides faces.

Why do I feel it is not just Hooters girls who need be concerned about this?

Tuesday, April 20, 2010

Triplethought, Part 4

In Part 3 we considered the 2006-2007 push by the Bush-43 Administration and certain elements of Congress to gain the legal right to invade our on-line privacy and snoop on our use of the Internet under the pretext of protecting us from child pornography and other cybercrimes.

By 2008, proposals to what records should be kept and of who could snoop what were becoming more aggressive. Here are some excerpts from FBI, politicos renew push for ISP data retention laws by Declan McCullagh, April 23, 2008:

WASHINGTON--The FBI and multiple members of Congress said on Wednesday that Internet service providers must be legally required to keep records of their users' activities for later review by police.

Their suggestions for mandatory data retention revive a push for potentially sweeping federal laws--which civil libertarians oppose--that flagged last year after the resignation of Attorney General Alberto Gonzales, the idea's most prominent proponent.

FBI Director Robert Mueller told a House of Representatives committee that Internet service providers should be required to keep records of users' activities for two years.

"From the perspective of an investigator, having that backlog of records would be tremendously important if someone comes up on your screen now," Mueller said. "If those records are only kept 15 days or 30 days, you may lose the information you may need to bring that person to justice."

[snip]

Based on the statements at Wednesday's hearing and previous calls for new laws in this area, the scope of a mandatory data retention law remains fuzzy. It could mean forcing companies to store data for two years about what Internet addresses are assigned to which customers (Comcast said in 2006 that it would be retaining those records for six months).

Or it could be far more intrusive. It could mean keeping track of e-mail and instant-messaging correspondence and what Web pages users visit. Some Democratic politicians have called for data retention laws to extend to domain name registries and Web hosting companies and even social-networking sites. During private meetings with industry officials, FBI and Justice Department representatives have said it would be desirable to force search engines to keep logs--a proposal that could gain additional law enforcement support, but raise additional privacy concerns and potentially conflict with European laws.

[snip]

Multiple proposals to mandate data retention have surfaced in the U.S. Congress. One, backed by Rep. Diana DeGette, a Colorado Democrat, said that any Internet service that "enables users to access content" must indefinitely retain records that would permit police to identify each user. Another came from Wisconsin Rep. F. James Sensenbrenner, a close ally of President Bush, and a third was written by Rep. Smith, who endorsed the idea again on Wednesday.

[snip]

At the moment, Internet service providers typically discard any log file that's no longer required for business reasons such as network monitoring, fraud prevention or billing disputes. Companies do, however, alter that general rule when contacted by police performing an investigation--a practice called data preservation.

Did you catch all that?

Currently, ISPs cooperate and maintain records as needed, and particularly if requested to do so by the police.

This isn't good enough.

That crowd in Washington wants to be able to find out who accessed what, and when. And they want these records kept available for them - forever!

By 2009, a bill was under consideration that would just give the President control of the Internet - ostensibly during emergencies. From Bill would give president emergency control of Internet by Declan McCullagh, August 28, 2009:

Internet companies and civil liberties groups were alarmed this spring when a U.S. Senate bill proposed handing the White House the power to disconnect private-sector computers from the Internet.

[snip]

The new version would allow the president to "declare a cybersecurity emergency" relating to "non-governmental" computer networks and do what's necessary to respond to the threat. Other sections of the proposal include a federal certification program for "cybersecurity professionals," and a requirement that certain computer systems and networks in the private sector be managed by people who have been awarded that license.

The government wants to be able to decide who, in the private sector, may manage "certain computer systems".

But, it gets better! Skipping down:

When Rockefeller, the chairman of the Senate Commerce committee, and Olympia Snowe (R-Maine) introduced the original bill in April, they claimed it was vital to protect national cybersecurity. "We must protect our critical infrastructure at all costs--from our water to our electricity, to banking, traffic lights and electronic health records," Rockefeller said.

[snip]

The privacy implications of sweeping changes implemented before the legal review is finished worry Lee Tien, a senior staff attorney with the Electronic Frontier Foundation in San Francisco. "As soon as you're saying that the federal government is going to be exercising this kind of power over private networks, it's going to be a really big issue," he says.

Probably the most controversial language begins in Section 201, which permits the president to "direct the national response to the cyber threat" if necessary for "the national defense and security." The White House is supposed to engage in "periodic mapping" of private networks deemed to be critical, and those companies "shall share" requested information with the federal government. ("Cyber" is defined as anything having to do with the Internet, telecommunications, computers, or computer networks.)

"The language has changed but it doesn't contain any real additional limits," EFF's Tien says. "It simply switches the more direct and obvious language they had originally to the more ambiguous (version)...The designation of what is a critical infrastructure system or network as far as I can tell has no specific process. There's no provision for any administrative process or review. That's where the problems seem to start. And then you have the amorphous powers that go along with it."

Translation: If your company is deemed "critical," a new set of regulations kick in involving who you can hire, what information you must disclose, and when the government would exercise control over your computers or network.

To be sure, the Senate seems to think this is excessive concern:

Update at 3:14 p.m. PDT: I just talked to Jena Longo, deputy communications director for the Senate Commerce committee, on the phone. She sent me e-mail with this statement:

The president of the United States has always had the constitutional authority, and duty, to protect the American people and direct the national response to any emergency that threatens the security and safety of the United States. The Rockefeller-Snowe Cybersecurity bill makes it clear that the president's authority includes securing our national cyber infrastructure from attack. The section of the bill that addresses this issue, applies specifically to the national response to a severe attack or natural disaster. This particular legislative language is based on longstanding statutory authorities for wartime use of communications networks. To be very clear, the Rockefeller-Snowe bill will not empower a "government shutdown or takeover of the Internet" and any suggestion otherwise is misleading and false. The purpose of this language is to clarify how the president directs the public-private response to a crisis, secure our economy and safeguard our financial networks, protect the American people, their privacy and civil liberties, and coordinate the government's response.

Since the Constitution gives the President the authority and duty to protect the American people and direct the national response to any emergency that threatens our security and safety, why don't we let the President go a little further? Food and clothing are necessary - why shouldn't the President secure these things from attack by establishing regulations deciding who can be hired to work at your supermarket or department store? We need to get around, and we are dependent upon cars and trucks. Why shouldn't the President decide what information must be disclosed about your car, and when it last had its brakes checked or oil changed?

And, if these things are important, shouldn't hospitals answer to the President? Oh, I forgot - Obama is way ahead of me on that one.

The government is interested in knowing who is saying what to whom, and they want to make sure that they have the power the hire or fire - or even render destitute - anyone in a position to stand in their way.

The First Amendment:

Congress shall make no law respecting an establishment of religion, or prohibiting the free exercise thereof; or abridging the freedom of speech, or of the press; or the right of the people peaceably to assemble, and to petition the Government for a redress of grievances.

Congress, together with the Presidency, is working very hard on making a law abridging our freedom of speech and of the press, and abridging our right to peaceably assemble - via the Internet.

As George Orwell explained:

If you want a vision of the future, imagine a boot stamping on a human face - forever.

The means to bring about this future is by controlling communications now; as Orwell explained:

Who controls the past controls the future. Who controls the present controls the past.

Stay tuned for Part 5!

Triplethought, Part 3

In Part 2, we saw how the Washington was reversing course from an Administration position that was concerned about protecting privacy to a position of pushing through laws that would allow the government to snoop on Americans protect us from child pornographers and other lawbreakers.

Specifically, we consider excerpts from Congress may make ISPs snoop on you by Declan McCullagh, May 16, 2006:

A prominent Republican on Capitol Hill has prepared legislation that would rewrite Internet privacy rules by requiring that logs of Americans' online activities be stored, CNET News.com has learned.

The proposal comes just weeks after Attorney General Alberto Gonzales said Internet service providers should retain records of user activities for a "reasonable amount of time," a move that represented a dramatic shift in the Bush administration's views on privacy.

[snip]

Until Gonzales' speech, the Bush administration had explicitly opposed laws requiring data retention, saying it had "serious reservations" (click here for PDF) about them. But after the European Parliament last December approved such a requirement for Internet, telephone and voice over Internet Protocol (VoIP) providers, top administration officials began talking about it more favorably.

Attorney General Gonzales' speech was just the beginning, though. Behind closed doors, he was armtwisting the telecommunications industry.

Gonzales pressures ISPs on data retention by Declan McCullagh May 26, 2006:

U.S. Attorney General Alberto Gonzales and FBI Director Robert Mueller on Friday urged telecommunications officials to record their customers' Internet activities, CNET News.com has learned.

In a private meeting with industry representatives, Gonzales, Mueller and other senior members of the Justice Department said Internet service providers should retain subscriber information and network data for two years, according to two sources familiar with the discussion who spoke on condition of anonymity.

The closed-door meeting at the Justice Department, which Gonzales had requested, according to the sources, comes as the idea of legally mandated data retention has become popular on Capitol Hill and inside the Bush administration. Supporters of the idea say it will help prosecutions of child pornography because in many cases, logs are deleted during the routine course of business.

Attorney General Alberto Gonzales In a speech last month at the National Center for Missing and Exploited Children, Gonzales said that Internet providers must retain records for a "reasonable amount of time."

"I will reach out personally to the CEOs of the leading service providers and to other industry leaders," Gonzales said. "Record retention by Internet service providers consistent with the legitimate privacy rights of Americans is an issue that must be addressed."

Notice how lip-service is still paid to "the legitimate privacy rights of Americans"; notice also the direction this goes in. A bill was introduced early the next year. From GOP revives ISP-tracking legislation by Declan McCullagh, February 6, 2007:

All Internet service providers would need to track their customers' online activities to aid police in future investigations under legislation introduced Tuesday as part of a Republican "law and order agenda."

Employees of any Internet provider who fail to store that information face fines and prison terms of up to one year, the bill says. The U.S. Justice Department could order the companies to store those records forever.

Rep. Lamar Smith of Texas, the top Republican on the House Judiciary Committee, called it a necessary anti-cybercrime measure. "The legislation introduced today will give law enforcement the tools it needs to find and prosecute criminals," he said in a statement.

[snip]

Details about data retention requirements would be left to Gonzales. At a minimum, the bill says, the regulations must require storing records "such as the name and address of the subscriber or registered user to whom an Internet Protocol address, user identification or telephone number was assigned, in order to permit compliance with court orders."

Because there is no limit on how broad the rules can be, Gonzales would be permitted to force Internet providers to keep logs of Web browsing, instant message exchanges, or e-mail conversations indefinitely. (The bill does not, however, explicitly cover search engines or Web hosting companies, which officials have talked about before as targets of regulation.)

That broad wording also would permit the records to be obtained by private litigants in noncriminal cases, such as divorces and employment disputes. That raises additional privacy concerns, civil libertarians say.

Are you following this? They pay lip-service to protecting privacy, but then leave themselves a loop-hole to keep track of web browsing, instant messages and emails - forever - and go so far as to leave open the possibility of allowing this information to be brought out in non-criminal court proceedings.

So, hypothetically, under such a law, if you witness illegal activities at your place of employment (as did Sibel Edmonds when working as a contract translator for the FBI) and you come forward to report this (as she did), and your case gets shut down (as hers did), your employer can now go after you for breach of confidentiality rules, or just for calling the boss a crook and a moron (defamation of character) - and the records are there forever.

They're not protecting our privacy - they're protecting themselves.

But wait! There's more! In Part 5 we will zoom ahead to 2010 and see how this is actually being applied in courtrooms today - but first, Part 4.

Monday, April 19, 2010

Triplethought, Part 2

In Part 1, we began looking at how the US government was seeking to require ISPs to keep records of Internet activity, and was seeking access to such records.

We now jump across "the pond" to see the progress of a similar endeavor in Europe. From Europe passes tough new data retention laws, by Jo Best, December 14, 2005:

The European Parliament on Wednesday passed new, far-reaching data retention legislation for the telecommunications industry.

[snip]

Telecommunications providers will now have to keep data such as the time of each fixed and cell phone call made in Europe; whether a call is answered or not; the duration of the call; and other details that can help trace the caller. On the Internet side, they will be required to retain information on the times people connect to the Internet, people's IP addresses, and details pertaining to e-mail messages and VoIP calls. The content of the communications will not be recorded.

"The content of the communications will not be recorded" - and we trust them to not record the content, and we trust them that this will not change.

The legislation is being championed by the U.K. and other governments. They say it will help trace terrorists through communications records. The change in the law was proposed during the U.K.'s presidency of the European Union in the wake of the July 7 bombings in London.

If the UK government were serious about ending terrorism, why do their politicians persist with their program of population replacement, driving the native population off the British Isles, even as those loyal to a foreign ideology of armed conquest - Islam - are being brought in by droves?

It is politically easier to get some technical means to maintain surveillance over the entire population that it is to have the balls to single out the militant groups that are causing the problems and deal with them.

But, back to Amerika... (Oops, did I spell that wrong?) From ISP snooping gaining support by Declan McCullagh, April 14, 2006:

The explosive idea of forcing Internet providers to record their customers' online activities for future police access is gaining ground in state capitols and in Washington, D.C.

Top Bush administration officials have endorsed the concept, and some members of the U.S. Congress have said federal legislation is needed to aid law enforcement investigations into child pornography. A bill is already pending in the Colorado State Senate.

Mandatory data retention requirements worry privacy advocates because they permit police to obtain records of e-mail chatter, Web browsing or chat-room activity that normally would have been discarded after a few months. And some proposals would require providers to retain data that ordinarily never would have been kept at all.

[snip]

At a hearing last week, Rep. Ed Whitfield, a Kentucky Republican who heads a House oversight and investigations subcommittee, suggested that data retention laws would be useful to police investigating crimes against children.

Yeah, do it for our children. (Since I question this, I must be an extremist siding with child pornographers, right? Maybe it's worse - maybe I'm Osama bin Laden...)

"What we haven't seen is any evidence where the data would have been helpful, where the problem was not caused by law enforcement taking too long when they knew a problem existed," said Dave McClure, president of the U.S. Internet Industry Association, which represents small to midsize companies.

McClure said that while data retention aficionados cite child pornography, the stored data would be open to any type of investigation--including, for instance, those focused on drug crimes, tax fraud, or terrorism prosecutions. "The agenda behind this doesn't appear to be legitimate," he said.

Mr. McClure's comment is right on the money!

I leave you to read a position paper on the topic from the USIIA. (See also this link, dated February 17, 2005.)



I will come back to this in Part 5.

Meanwhile, the story continues as a few days later, the US Attorney General called for "'reasonable' data retention", then Congress quickly picked up on this way to infringe into the privacy of the people protect children from pornographers. From Congress may consider mandatory ISP snooping by Declan McCullagh, April 28, 2006:

It didn't take long for the idea of forcing Internet providers to retain records of their users' activities to gain traction in the U.S. Congress.

Last week, Attorney General Alberto Gonzales, a Republican, gave a speech saying that data retention by Internet service providers is an "issue that must be addressed." Child pornography investigations have been "hampered" because data may be routinely deleted, Gonzales warned.

Now, in a demonstration of bipartisan unity, a Democratic member of the Congressional Internet Caucus is preparing to introduce an amendment--perhaps during a U.S. House of Representatives floor vote next week--that would make such data deletion illegal.

Colorado Rep. Diana DeGette's proposal (click for PDF) says that any Internet service that "enables users to access content" must permanently retain records that would permit police to identify each user. The records could not be discarded until at least one year after the user's account was closed.

It's not clear whether that requirement would be limited only to e-mail providers and Internet providers such as DSL (digital subscriber line) or cable modem services. An expansive reading of DeGette's measure would require every Web site to retain those records. (Details would be left to the Federal Communications Commission.)

So a bunch of bureaucrats and appointed officials, who worked for Bush-43 at the time, would be in charge of invading our privacy.

Interestingly, concerns about protecting our privacy were in the minds of our Department of Justice only five years previously, in response to the then-growing movement in Europe for ISP record retention. From Comments of the United States Government on the European Commission Communication on Combating Computer Crime, March, 2001:

Any regulation of conduct involving the use of the Internet requires a careful consideration of different societal interests. Triumph over network crime cannot and must not come at the price of lost privacy and individual freedom. Our domestic investigative tools are subject to strict constitutional, statutory, courtordered, and internal policy limitations, and we are committed to ensuring that such tools continue to be developed and used consistent with our laws and our much-cherished notions of individual liberty.

An interesting comment follows the above paragraph, only a little farther down in the paper:

Because cyber criminals are not confined by national borders or geography, numerous US agencies participate in an initiative coordinated by the State Department to conduct international outreach on critical infrastructure protection. This initiative recognizes that exploitation of information technology is an increasing feature of transnational crime, and that governments around the world must work together to harmonize their substantive and procedural computer crime laws and establish new mechanisms that allow for prompt assistance in investigating and prosecuting computer-related crimes.

Cyber criminals are not confined by national borders or geography; neither are they confined to extra-governmental service! And, by 2006, the US government had reversed course concerning the privacy of American citizens.

Stay tuned for Part 3!

Sunday, April 18, 2010

Triplethought, Part 1

George Orwell explained to us his prophetic vision of humanity's future:

If you want a vision of the future, imagine a boot stamping on a human face - forever.

The musician Leonard Cohen comments about the future, in his song by the same title:

I've seen the future, brother: it is murder.

__________


The Russian Federation is implementing new regulations requiring Internet service providers (ISPs) to keep information on their clients. We begin with Russian ISPs have no fears over new rules by Evgeniya Chaykovskaya, April 16, 2010.

Russia's Ministry of Communications insists that an order for Internet providers to log IP addresses and share them with the authorities is not a clamp-down on net freedom - because it's been going on for ages.

But a federal ban on hosting "extremist" sites already seems to be counter-productive, according to many experts.

Those two comments sum up government programs that are designed to "help" society: they formalize infringements on our liberty while facilitating the very activities they are supposed to protect us against.

Think about that.

And the ruling was received calmly, with 80 per cent of ISPs already doing this, according to Andrei Vorobyov of RU-CENTER's PR department.

"The logic of our business makes us take part in the fight against cybercrime - companies are objectively interested in it. Large companies have been registering clients' IP addresses for a long time. Now those who neglected it will have to register - for example small 'last-mile' providers," Leonid Filatov, CEO of Masterhost hosting company told iToday.

First of all, they are already keeping records of Internet use, and have been for years. And notice, they are doing this in the public interest - who can argue with that? :)

But Andrei Kolesnikov, the Director of Coordination Center for TLD .RU, is certain that fixing IP addresses will not eliminate the problem of the search for cybercriminals: "Those who want to commit a crime on the Internet can take measures to make sure that they are not found afterwards."

Meanwhile Kommersant was unimpressed with a the federal Communications Monitoring Service's efforts to block extremist sites.

Reports cited one Chechen rebel site which attracted a mere handful of visitors until the ban was announced - and the subsequent publicity boosted its traffic as the restrictions were technically difficult to implement.

Nothing like forbidding the fruit to get people to taste it, huh?

Of course, what does one expect from Russia? They have always had an absolutist government, not responsible to the people. Individual liberty, privacy - not factors.

Not a problem in America, right? This could never happen here. We are safe. We live in a free country. We can go back to sleep.

From Your ISP as Net watchdog, by Declan McCullagh, June 16, 2005:

The U.S. Department of Justice is quietly shopping around the explosive idea of requiring Internet service providers to retain records of their customers' online activities.

Data retention rules could permit police to obtain records of e-mail chatter, Web browsing or chat-room activity months after Internet providers ordinarily would have deleted the logs--that is, if logs were ever kept in the first place. No U.S. law currently mandates that such logs be kept.

In theory, at least, data retention could permit successful criminal and terrorism prosecutions that otherwise would have failed because of insufficient evidence. But privacy worries and questions about the practicality of assembling massive databases of customer behavior have caused a similar proposal to stall in Europe and could engender stiff opposition domestically.

Whatever it is they are going to claim they want to protect us from, understand that sorting through massive databases will diminish their ability to protect us from it. Investigators will go after innocent people who have done something that looks suspicious, and this will mean fewer critical resources are allocated to investigate people who really are doing something that needs to be investigated.

This is how government bureaucracy works.

What is it they want to protect us from? Skipping down in the article:

Justice Department officials endorsed the concept at a private meeting with Internet service providers and the National Center for Missing and Exploited Children, according to interviews with multiple people who were present. The meeting took place on April 27 at the Holiday Inn Select in Alexandria, Va.

"It was raised not once but several times in the meeting, very emphatically," said Dave McClure, president of the U.S. Internet Industry Association, which represents small to midsize companies. "We were told, 'You're going to have to start thinking about data retention if you don't want people to think you're soft on child porn.'"

Protect children from exploitation? Help missing and exploited children? Crack down on child pornography? Who can argue with that?

And, remember, if you're not with the government in the fight against child pornography, then you're with the pornographers.

Most of the comments to the article call attention to the threat posed here by government. One comment nails it:

The Justice Department, FBI, CIA, and NSA all report to the Executive Branch. We have seen over the years, starting with Nixon and Watergate to Clinton and Filegate (remember that one -- FBI files that mysteriously appeared in the White House), that there are few real protections and NO OVERSIGHT as to what goes on behind White House closed doors. Having access to individuals' web and email activity will provide a boon to corrupt administrations that want to compile dirt on their opposition and wage character assasination. This is the real danger -- that the opposition will effectively be neutralized. The govenerance of the country then basically becomes a dictatorship.

Filegate - first there were a hundred or so files. When caught, the Clinton Administration explained that it was no big deal, there were actually about 300. Then, when America was a little more upset, the number jumped to 500, 700, 900. The Clinton Administration taught us that little crimes upset the American people, but when you excuse yourself by explaining the crime was bigger than we had thought, then it's okay.

As the crimes get bigger, then it's okay....

Stay tuned for Part 2.