body scanner

Showing posts with label body scanner. Show all posts
Showing posts with label body scanner. Show all posts

Eye scans at airport for U.S.-bound travellers

I was contacted by the Canadian Broadcasting Corporation yesterday to comment on a new inititiave to speed cross-border travel between the US and Canada for "low risk" travellers. New technologies allow pre-screened passengers to skip through customs and immigrations after confirming their identity with an iris scan:

Eye scans at airport for U.S.-bound travellers:

"...The iris scans are voluntary, and no one is compelled to go through a process that critics say is invasive.

But Halifax privacy lawyer David Fraser says increasingly, people are deciding it's worth it.

'Survey after survey says that people are concerned about their privacy, but they really don't put their money where their mouth is,' he says.

'It's easy to tell a pollster that, but when it comes to trading privacy for convenience, people often chose convenience.' ..."

Leading privacy groups release annual global report

Privacy International and the Electronic Privacy Information Center have recently released their seventh annual Privacy and Human Rights Survey, which details global threats to privacy and related civil rights. It particularly highlights the increasing surveillance of citizens and intrusive uses of technology in the battle against terrorism.

From the joint EPIC/PI press release:


Privacy International & EPIC Release Annual Global Privacy Study

17/11/2004

GLOBAL HUMAN RIGHTS STUDY WARNS OF ENDEMIC PRIVACY THREATS

Major report sets out government surveillance strategies

17th November 2004

A major international privacy report published today has concluded that governments across the world have substantially increased surveillance in the past year. The report warns that threats to personal privacy have reached a level that is dangerous to fundamental human rights.

The 7th annual Privacy and Human Rights survey, published by Privacy International & the US based Electronic Privacy Information Center (EPIC) reviews the state of privacy in sixty countries and warns that invasions of privacy across the world has increased significantly in the past twelve months. The 800 page report is available free of charge at http://www.privacyinternational.org/survey/phr2004

The report paints a bleak picture of the erosion of the right to privacy, particularly since the September 11th attacks in the United States. It observed: that crime and public order laws passed in recent years have placed substantial limitations on numerous rights, including freedom of assembly, privacy, freedom of movement, the right of silence, and freedom of speech. Governments have continued to use terrorism as the pretext for an increase of surveillance, even when surveillance is unwarranted.

The report identifies a trend across the world toward mass surveillance of the general population, and cited a catalogue of illegal spying and surveillance activities by government agencies.

In response to calls for increased security many countries have pursued policy and legislative efforts that aim at implementing identification schemes, expanding the surveillance of communications for law enforcement and national security agencies, weakening data protection regimes, and intensifying data sharing and collection practices - all made possible by a growing cooperation between government entities and the private sector.

The report singles out a number of trends:


  • New identification measures and new traveller pre-screening and profiling systems
  • New anti-terrorism laws and governmental measures provide for increased search capabilities and sharing of information among law enforcement authorities
  • Increased video surveillance
  • DNA and health information databases
  • Censorship measures
  • Radio frequency identification technologies
  • New electronic voting technologies
  • Mismanagement of personal data and major data leaks


Privacy International's Director, Simon Davies, said the report highlighted a 'disturbing' trend toward greater state power. 'Governments are systematically removing the right to privacy. Surveillance of every type is being instituted throughout society without any thought about the need for safeguards.'

'The spectre of terrorism has at last become the device that any government can deploy to entrench the powers they always sought. The situation has become a dangerous farce,' he added.

'Governments are joining together their data systems. They are sharing information to a greater extent each year with the private sector. And they are cooperating unquestioningly with other governments to exchange vast reserves of personal information. This situation cannot continue without imperilling the right to privacy', said Mr Davies.

On a more upbeat note, the report did identify positive counter-trends:

'Invasions of privacy were met in various countries with forceful reactions from human rights groups. In Germany, outcry against a retail chain's use of RFID tags unbeknownst to its customers led to the halt to the company's projects. In Greece, the data protection authority struck down the use of biometric identity verification in airports because the collection of personal information through RFID tags exceeded its purpose. In Malaysia, the Bar Council criticized the security and privacy risks of Mykad, the multi-purpose smart card, which forced the government to work on a legislation to answer such concerns. In Poland, the Constitutional Tribunal held unconstitutional a law that allowed police officers to observe and record events in public places. Public interest groups had opposed the law alleging that it violated the right to privacy enshrined in the Polish Constitution. In Sweden, the privacy commissioner forbade a school's fingerprint recognition program. In Ukraine, a new law that restricts access to information was strongly opposed by several NGOs and international organizations because of its violation of the Constitution and global freedom of information standards. In reaction, amendments were introduced that improve the final version of the law.'

ChoicePoint appoints first privacy officer

ChoicePoint has appointed a big name former TSA official to be its new privacy officer, according to Forbes:

Forbes.com: Smith: ChoicePoint Names TSA Big As Chief Privacy Officer:

Faces In The News Smith: ChoicePoint Names TSA Big As Chief Privacy Officer Greg Levine, 03.08.05, 5:13 PM ET NEW YORK - Doers and doings in business, entertainment and technology: It's a start. Data dealer ChoicePoint (nyse: CPS - news - people ) on Tuesday announced it hired a U.S. Transportation Security Administration big to batten its info hatches. Helmed by Chief Executive Derek Smith, the firm has recently suffered an incursion by identity thieves. (Related note: On Feb. 25, Bank of America (nyse: BAC - news - people ) too suffered a security compromise.) ChoicePoint said its new employee, TSA Deputy Administrator Carol A. DiBattiste, has been named chief credentialing, compliance and privacy officer. She will lead an independent office to oversee improvements to ChoicePoint's screening process, and its enacting of procedures to streamline how incidents are reported. The TSA oversees airport screening in the U.S. Any such moves to regain the public's trust are vital at this juncture: After the CEO stated that the recent incident was the only such major security compromise of which he was aware, Assistant U.S. Attorney Mark Krause in Los Angeles claimed he'd dug up evidence of to the contrary, viz.: A sizable identity theft in 2002. Then, on March 4, the firm said the U.S. Securities and Exchange Commission is investigating stock sales by Smith and by Chief Operating Officer Douglas Curling. So it couldn't hurt ChoicePoint's image--not to mention its operations--to bring in "untouchables" like DiBattiste. More...


It is somewhat surprising that a company that deals in personal information never had an officer responsible for privacy. Perhaps that's why the original breaches never came to the attention of the executives.

Facial scans, digital fingerprints to be compiled for Canadian border security project

Canadian immigration authorities are making their first foray into using biometrics to keep track of refugees, immigrants and visitors to Canada. A pilot project is being implemented at border crossings in British Columbia and the Vancouver International Airport. The test will involve digital photos and fingerprints. At the moment it is only a pilot project, but is likely a sign of things to come. From the Canadian Press: Facial scans, digital fingerprints to be compiled for border security project - Yahoo! News.

Article: Product ID tags raise privacy concerns

Delaware Online has an article referring to a recent conference on RFID technology an includes a brief discussion of the privacy issues raised by the use of the chips:

www.delawareonline.com : Product ID tags raise privacy concerns:

"The potential for tracking more than just products has prompted the formation of groups such as Consumers Against Supermarket Privacy Invasion and Numbering.

RFID devices can be read from 20 to 30 feet away and the antennas, first made from copper, can now be printed with conductive ink, making it difficult for consumer to know if products they buy contain RFID transmitters, the group argues. The group has proposed legislation that would require the complete disclosure of products containing RFID devices.

While some have concerns about the tags being used to track more than just products, Ed Coyle, head of the Department of Defense's Logistics Automatic Information Technology office, said at the confer- ence that the key to security, or privacy concerns, is limiting the amount of information on the tags, which also makes the system speedier. "



I am not sure I agree with this last sentiment. The privacy impact of the technology has very little to do with the amount of information embedded in the chip. What matters is the database that the unique identifier is connected with. Afterall, your social insurance number is only nine digits long but has the potential to be a universal tracking code. The VIN on your car is longer, but is connected with your driver's license, which is connected to you.

The following scenario demonstrates the potential of these simple codes: If you buy a pair of shoes with RFID embedded in them at your local mega store, ostensibly for inventory tracking purposes, it will have a unique serial number. At the point of purchase, that unique number can be attached to your visa card number or your debit card in the back office database. The database can connect that to your address, etc. If the RFID in the shoes is linked to your personal unique identifier, anybody who scans the code from the shoes can connect it with you. And it can be scanned from twenty feet away. If your local mega storage puts scanners at the entrances, it will know, for example, if you visited the store again wearing those shoes. It can follow you around the store and know more about your behaviour in the store than you'd probably like. This micro tracking has the potential to be taken to the macro level if scanners, linked to databases, become pervasive.

More information on the privacy impact of RFID is available from Consumers Against Supermarket Privacy Invasion and Numbering at http://www.spychips.com/ (bonus points if you can figure out what side of the issue they espouse).

Rumours about spy chips in cash

The following link was sent by a regular correspondent ...

Bearing in mind that rumours are rumours, this one is rather interesting and perhaps chilling:

New rumours about spy chips in Euro notes | EDRI:

"

There is a renewed rumour that the European Central Bank is going to add spy chips (RFIDs) to Euro banknotes. 'Czerwensky intern', a German newsletter providing bank and insurance background reports, says the ECB might have already signed contracts with Hitachi, and is ready to introduce the spy-notes this year. Allegedly, the contract requires such a high volume of RFIDs that Hitachi can't deliver all chips itself, but has to rely on subcontractors.

Earlier rumours (dating back to 2001) about plans to track and trace all Euro notes with the help of RFIDs were strongly denied by the ECB. On 4 June 2003 EDRI-gram reported about a press release from Hitachi announcing negotiations about the contract to Japanese investors. The RFIDs in euro banknotes could help against counterfeiting and make it possible to detect money hidden in suitcases at airports. But the technology would also enable a mugger to check if a victim has given all of his money. If RFIDs are embedded in banknotes, governments and law enforcement agencies can literally 'follow the money' in every transaction. The anonymity that cash affords in consumer transactions would be eliminated.

According to the biannual report from the ECB on the counterfeiting of the euro, released on 13 January 2005, the amount of counterfeited euro banknotes is still very low. It has risen 8% compared to 2003, "but the recent trend has been downwards."..."

Biometrics coming soon to an airport near you

From Washington Technology:

Canada-DHS pilot program to use iris scanning:

"The Canada Border Service Agency, which is working on a Registered Traveler-style pilot program with the U.S. Homeland Security Department, is implementing iris-scanning technology at Canadian airports to verify the identity of travelers.

The program, called Nexus Air, will begin in November at Vancouver International Airport, Vancouver, British Columbia, before rollout at other Canadian airports for a yearlong trial. ...

Nexus Air builds on Canada’s Canpass Air program, which has 4,000 members and also uses iris scanning. As in the U.S. Transportation Security Administration’s Registered Travel pilot program, frequent fliers enroll in Canpass Air -- and soon Nexus Air -- by volunteering personal information and submitting to an iris scan. In return, they can then enjoy expedited check-in and customs screening. "

Update on weird questions at airport checkin

There has been a lot of buzz about Cory Doctorow's experience checking in for a transatlantic flight with American Airlines. (See PIPEDA and Canadian Privacy Law: Weird personal questions reported on checkin with airline.) The author of Secondary Screeining contacted the airline and actually received a prompt reply, which is posted in his site:

Secondary Screening: Cory Doctorow and Secondary 'Secondary Screening' Classes:

"After reviewing our documentation on Mr. Doctorow's experience in London, it is evident that both our contracted security screener and Mr. Doctorow contributed to what is not a representative example of our security screening process.

Mr. Doctorow exhibited specific behaviors and cues before and during our initial security screening that caused our screener to initiate a secondary screening process. We will not publicize those behaviors because to do so might hamper the effectiveness of the screening process in the future.

That said, our contracted screener veered from standard procedure when she asked for Mr. Doctorow to write the addresses of his destinations in the United States. She did clearly state that once the interview was completed, the address list would be destroyed in front of Mr. Doctorow or that he could have the list to keep. American Airlines absolutely does not register or record that type of personal data.

Although the agent concerned is very promising, this incident clearly showed a lack of experience in the questioning process. The agent will go through additional training and supervision. Through daily briefings, the remainder of the station will benefit from the experience gained from this incident.

American Airlines is entirely serious about the security procedures we undertake to help ensure the safety of our passengers and crews. We expect that our passengers apply the same serious consideration when they encounter our procedures. The vast majority of airline travelers appreciate the increased security and have adapted to a new reality in air travel. That is not, however, an excuse for security measures to be applied unevenly, and to reiterate, we do not keep personal information gathered during screening processes.

We appreciate that Mr. Doctorow called our attention to the mistakes that were made because it helps us rectify the situation going forward. He will also receive a personal response to the letter he sent to our Customer Relations department.

Tim Wagner

American Airlines Spokesman"

Handling customer complaints under PIPEDA

Anybody reading the Canadian media before Christmas couldn't help but notice the huge amount of coverage given to a stream of faxes sent by a number of branches of a particular bank that kept on finding their way to a junkyard in West Virginia. The story took off and other complainants came out of the woodwork. Other banks were also the subject of stories, all related to mishandling of sensitive personal information (PIPEDA and Canadian Privacy Law: Bank faxes saga continues; involves other banks, too). Further examples of misdirected personal information are appearing in the media (see TheStar.com - Customer privacy concerns continue at CIBC).

The most obvious thing to learn from these incidents is that people need to be very careful when faxing customer information. Or mailing it. But what is not as obvious is that none of these stories should have ever made it as far as they did. Not only was customer information mishandled, but more importantly (from the bank's point of view), the customers were mishandled.

I've touched on this before (PIPEDA and Canadian Privacy Law: Two magic words, big effects ...), but it bears repeating. Where the banks (and most organizations that end up at the unpleasant end of a privacy complaint) went wrong is the way they acted when their misstep was brought to their attention: (i) they did little to assure their customers, (ii) they did not appreciate the gravity of the situation, and (iii) they did not escalate the issue to the proper level.

From what I understand of the faxing fiasco, the faxes went from a wide range of branches to one unintended recipient. Calls to the branches may have elicited a response, but they were not reported to a higher authority who would get a sense of the big picture and realize that there was a problem and it was chronic. Each branch did not know that dozens of other branches were making the same mistake and nobody was tracking the issue. When it comes to privacy breaches, one person in senior management must be apprised of the situation. Only that person will know if it was an one-off incident or whether the screw-up is pervasive.

Secondly, employees of organizations need to be resensitised to the importance of the personal information they handle. It may not be important to the company, but that is irrelevant. It is important to the customer, so it must be treated appropriately. I happened upon an example of this at Ottawa airport night before last. Sitting in the restaurant, the woman at the table next to me got up to go. She must have been an airline employee because she left behind a copy of a manifest for a flight from Halifax to Ottawa. Being a nosy sort, I picked it up. I recognized a few names on the list, including a particular superior court judge who would not have been impressed. It told me that the person in seat 23A was 73 years old and needed help to get on and off the plane (why the put her in a window seat at the back of the plane should be the subject of a different sort of complaint). It also listed who ordered kosher meals.

To some, this is sensitive personal information and should not have been left lying around. But I think that people who deal with sensitive personal information all the time become numb to the fact that it really is sensitive and needs to be properly protected. I am sure that all lawyers know of colleagues who can be pretty casual when talking about clients. I've certainly heard some doozies about testimony about intimate matters that was probably humiliating to the person to reveal, but really had no effect on the lawyers since they've seen it all. When the information is routine, you start treating it routinely. I have heard from dozens of managers and business owners who say that they don't have to worry about privacy law because the information they handle isn't "sensitive." Well, in many cases it is, but the company has forgotten that it is sensitive or may be sensitive to their clients. All businesses need to think about information through the eyes of their clients. Even more, they need to think about it through the eyes of their most sensitive, paranoid clients. Personal information is important and must be treated accordingly.

Finally, each customer concern must be treated seriously. Most people don't complain routinely. Some may be chronic complainers, but most are not. If a client takes the time to complain about how their information was handled, they only have done so because it matters to them. If you treat the complaint casually, it can easily get out of control. If they don't get satisfaction from the organization, with the respect and priority they think it deserves, they will take their complaint to the privacy commissioner or, worse yet, to the media. I've read all the published findings on the Commissioner's website. Initially, would sometimes think that some people complain about truly trivial things. I scratched my head at more than a few. Then I began to wonder more and more often how the organization ever let the complaint get to the Office of the Privacy Commissioner in the first place. When a complaint gets that far, particularly about something "trivial", it is most likely because the organization didn't fix the "trivial problem" and let it get out of control. If you fix it as soon as it happens, that's it. No complaint. No problem.

I've dealt with customer concerns on behalf of clients. In almost every case, they are resolved favourably if you take the concern seriously, give it due priority, treat the customer with respect, and ultimately fix their problem.

To give an example, I was involved with a concern/complaint about a consent form that had been prepared for a client. This particular client was in a large industry but was the only location in their city that was visibly tackling the privacy issue. The customer called with some questions and was immediately referred to the privacy officer. Initially, the customer sounded a little indignant. He had read the form and had a problem with one of its provisions. We were satisfied with the correctness of the document, but the customer didn't seem to be amenable to our explanation. Since we were right, we could have told him that and walked away. But that wouldn't have ended the matter, since he knew enough about PIPEDA to make it likely that he'd buy a stamp and complain to the Commissioner. So we figured that if he was asking questions, there were probably a dozen or so customers who had the same question but didn't contact the client. Rather than fight it, we redrafted the form to make it more clear. We even asked the customer for his opinion of the new form and he approved. In the end, rather than have a potential complaint on our hands, the customer actually sang the client's praises around town leading to more business. Not only was a complaint avoided, but we managed to improve the customer's relationship with the client.

Privacy is not just a legal compliance issue. As an increasing portion of customers are concerned with the protection of their personal information and whether they can trust the companies they deal with, privacy is a critical customer relations issue. If you don't appreciate that fact and begin to look at your business through your customers' eyes, you are at much greater risk of having a complaint go to the Privacy Commissioner. That involves expense, a risk of bad publicity and a lost customer.

One further thought: I'm often asked by my clients about who should assume the role of privacy officer for their company. If they are a large company, they often think it should be their in-house counsel. At first blush, this seems sensible since a lawyer has the tools to understand and apply the law. I always say that it depends upon the individual lawyer. Many lawyers reflexively get defensive and switch into denial mode. (Or at least begin denying until they have a chance to investigate.) Because this is a customer service issue as well as a legal issue, the privacy officer needs to be customer-friendly. Not all lawyers have this trait. Automatic denials and switching to "damage control" tend to escalate matters, while empathy, understanding and focusing on a solution for the customer will calm the situation. A lawyer with privacy expertise should always be consulted, because this is a legal, risk-management issue. Few employees have the knowledge of PIPEDA to fully understand the company's obligations and the risk it faces in a particular situation.