law enforcement

Showing posts with label law enforcement. Show all posts
Showing posts with label law enforcement. Show all posts

Credit card info taken from Guidance Software is used in fraudulent activity

I reported last week that Guidance Software Inc.'s customer database had been hacked (The Canadian Privacy Law Blog: Incident: Computer forensics firm hacked; credit card info of 3800 customers compromised). Now, there are some reports that some of the credit card numbers taken have been used in fraudulent activity:

The ChronicleHerald.ca: Hackers infiltrated key police database

...John Colbert, chief executive of Guidance, said the attack "is ironic, but it highlights that intrusions can happen to anybody. It’s not a matter of if, but of when, so nobody should be complacent about their (computer network) security."

The Los Angeles Electronic Crimes Task Force is leading an investigation, along with the U.S. Secret Service and FBI, Colbert said. He said the breach has led to "a few instances of fraud" involving the stolen credit card numbers.

.

For additional coverage, see:

Outsourcing of Canadian student loans process to US results in complaint to the Privacy Commissioner

This is the first week that I've thought it would be easier to blog about who isn't complaining to the Office of the Privacy Commissioner ...

A Vancouver man is taking his complaint about foreign outsourcing of studen loans to the Privacy Commissioner, according to the Georgia Straight:

Straight.com: Student-Debt Activist Seeks Privacy Probe:

"A Vancouver man has asked the federal privacy commissioner to investigate the outsourcing of Canada student loans to a U.S.-owned company. Mark O'Meara, founder of the www.canadastudentdebt.ca/ Web site, claimed that as a result of a recent corporate takeover, Nebraska-based Nelnet has access to all federal student debtors' personal information and financial data.

On December 6, Nelnet announced that its wholly owned Canadian subsidiary had completed its purchase of a CIBC subsidiary, Edulinx Canada Corp., which administers the Canada Student Loans Program on behalf of the federal government. According to Human Resources and Skills Development Canada, more than 1.8 million students have borrowed approximately $15.6 billion through the Canada Student Loans Program since 1993.

In an e-mail to the Straight, O'Meara stated that the federal privacy commissioner should examine whether student-loan data is now subject to the USA PATRIOT Act (Uniting and Strengthening America by Providing Appropriate Tools Required to Intercept and Obstruct Terrorism). Under Section 215 of the act, the FBI is permitted to obtain secret court orders to obtain "any tangible things".

On October 29, provincial Information and Privacy Commissioner David Loukidelis released a report concluding that there is a "reasonable possibility" of unauthorized disclosure of personal information under the USA PATRIOT Act. He issued numerous recommendations to mitigate this risk.

O'Meara claimed that the federal privacy commissioner's office never responded to his e-mail asking for an investigation. Federal Privacy Commissioner Jennifer Stoddart also did not respond to the Straight's request for an interview by deadline.

Nelnet's Nebraska-based spokesperson, Ben Kiser, told the Straight that nothing will change for students and borrowers as a result of the change in ownership. "Edulinx will remain a Canadian firm with operations in Canada," he said. "That means all processing, call-centre, data-storage, records-storage, and other student-loan functions will continue to take place exclusively in Canada."

Last August, however, the American Civil Liberties Union filed a submission to Loukidelis claiming that the FBI could obtain personal records stored by a subsidiary of a U.S. corporation operating in another country. In one instance, a U.S. grand jury subpoenaed a foreign-bank employee while he was on U.S. soil. In a separate submission filed by the B.C. Government and Service Employees' Union, ACLU lawyer Jameel Jaffer claimed that the USA PATRIOT Act could enable the FBI to obtain entire databases of personal records without notifying anyone."

Canadian draft guidelines to shield personal information from the USA Patriot Act

The Canadian Press just released a story about new draft guidelines for Canadian federal government departments designed to (at least try to) shield information about Canadians from the reach of the USA Patriot Act. The guidelines remain in draft form as the election has intervened to prevent them from being tabled in Parliament this fall and more internal consultations are taking place.

Canada drafts proposals to shield personal data from U.S. anti-terror law - Yahoo! News

... The draft guidance document suggests, in the interest of upholding Canadian privacy laws, that federal databases of sensitive personal information created by contractors be located in Canada and be accessible only within the country.

However, it recognizes international trade obligations may make this impossible. In such cases, the government suggests contractors must agree to respect Canadian privacy laws as a condition of contract.

The guidelines say that if the privacy risk is considered high, a federal department might go so far as to cut off the flow of personal information to a foreign firm should it be "presented with an order" - such as an FBI notice - compelling release of data about Canadians.

In general, the guidelines encourage departments to assess each potential contract case-by-case to gauge the possibility of privacy invasion, the expectations of Canadians, and likelihood of injury to a person's "career, reputation, financial position, safety, health or well-being."

Treasury Board spokesman Robert Makichuk said the draft guidelines were undergoing revision following internal federal consultations....

Round two of labour-sponsored privacy campaign against BC government to begin

Labour groups are once again attacking the government of British Columbia for outsourcing public services that involve personal information. This second campaign comes after its high-profile attempt to derail the outsourcing of the province's medicare administration (See BCGEU's privacy campaign). While that campaign did not dissuade the Campbell government from its plans (BC announces medical privatization plan), it did lead to a significant inquiry by the province's Information and Privacy Commissioner. Now under attack is the province's plan to outsource bill collection:

B.C. opens private bank and credit data to U.S. scrutiny: "B.C. opens private bank and credit data to U.S. scrutiny

New privatization deal means U.S. authorities will have access to bank account and credit card numbers, property records, income and driver's licence information on B.C. residents

Vancouver - The B.C. Government and Services Employees' Union (BCGEU/NUPGE) plans to launch a new campaign this week warning residents that the Liberal government of B.C. Premier Gordon Campbell is making highly personal data vulnerable to American scrutiny through outsourcing and privatization.

The latest information to be placed in the hands of private American companies involves a wide range of information on most B.C. residents, including bank account and credit card numbers, property records, income and driver's licence information.

The province announced a $572-million ($483-million US) deal Friday with Electronic Data Systems (EDS) of Plano, Texas, to take over much of its bill collection activity. The 10-year deal comes with barely six months remaining in the Liberals' current mandate.

The province argues that privacy provisions contained in the contract will safeguard personal information but the union says the government is misleading citizens because it is already known that the contract will not withstand the overriding and intrusive powers available to American authorities under the U.S. Patriot Act.

The Patriot Act was passed by Congress and signed into law by President George Bush following the Sept. 11, 2001 terrorist attacks on New York and Washington.

The deal is even worse than a recent 10-year, $324-million contract signed with U.S.-based Maximus Inc. to privatize the processing of the medical claims of B.C. residents.

Privacy commissioner ignored

Once again, the province has ignored concerns raised by its own information and privacy commissioner, putting private sector ideological interests ahead of those of its own people, the BCGEU says.

Essentially, the latest contract means that intensely personal information on most British Columbians will be exposed to potential scrutiny by the FBI and other U.S. government agencies, the union warns.

"It’s another example of the Liberals bullying ahead without heeding the warnings of privacy commissioner David Loukidelis issues raised by the privatizing of records management, says BCGEU president George Heyman.

Loukidelis said the U.S. Patriot Act creates a real risk that personal information, once placed in the hands of private companies with U.S. links, will be open to scrutiny by the FBI and other American agencies. He recommended a series of measures to protect the privacy of British Columbians.

Heyman says Premier Campbell has failed to take the necessary range of measures recommended by the commissioner.

Patriot Act applies

"The fact is that the Patriot Act applies. EDS is an American company, and all the records in its possession are exposed," Heyman says.

"The Campbell government is clearly misleading the public and betraying the promise they made to British Columbians that real protections would be in place before any contracts were signed."

A long list of personal data at risk, Heyman warns..

"It includes everything from credit card and bank account numbers, personal property and asset details, individual and family income, and drivers license, vehicle and insurance information. It’s pretty serious stuff that British Columbians wouldn’t want to share with the Bush government," he says.

Meanwhile, the BCGEU leader said full details on his union's latest campaign to warn residents will be announced this week. The union is also continuing efforts to mount a legal challenge to the government.

The union says privacy guarantees written into the contract by EDS and the province will be overridden by the all-intrusive federal powers of the U.S. Privacy Act.

NUPGE


Incident: Hacker hits Troy Group's eCheck Secure service, affects customers of Scot Trade online brokerage

Thanks to Brian Krebs on Computer and Internet Security for pointing me to this story ...

One of the largest online brokerage houses in the United States has started informing a large group of its customers that a hacker has obtained access to information on customers of Troy Group's eCheck Secure service, which is used by a number of Scot's customers to settle their accounts. Scot is the fifth or sixth largest such service provider in the US. Customers received the following letter:

Scottrade:

November 11, 2005



Re: Alert for users of the eCheck Secure™ Service

Dear Customer:


We are contacting you to inform you that Scottrade has experienced a data security issue with the eCheck Secure™ service. Our records indicate that you have used eCheck Secure™ for the purpose of electronically moving funds from your bank to Scottrade. We will detail what we know about the situation and also what steps you should consider taking to safeguard your information.


On October 25, 2005, Troy Group Inc., the provider of the eCheck Secure™ service and other services to the financial services industry, reported to us that a computer hacker had compromised its eCheck Secure™ servers. As a result, some of your personal information, including your name, driver's license or state ID number, date of birth, phone number, bank name, bank code, bank number, bank routing number, bank account number and Scottrade account number may have been compromised. If you used your Social Security number as your driver's license or state ID number, your Social Security number may have been compromised as well. We do not know whether the hacker has actually accessed and/or used any of your personal information. However, Troy has notified us that it has blocked further unauthorized access to the information. The eCheck Secure™ service cannot be used to withdraw funds from your Scottrade account. Troy has filed a report with the FBI and is investigating in conjunction with a forensic analysis firm that it has retained. Scottrade has also contacted the FBI on this matter, and has a dedicated team to work on this issue and assist our customers who may have been affected.


We suggest taking the following steps for all your accounts that have eCheck Secure™ activated.


  1. Contact your local Scottrade branch office for additional information or to change your Scottrade account number. If it is not possible or convenient for you to contact your local Scottrade branch office, then you can reach our Service Center at 866-476-6500. Our Service Center is open Monday - Friday, 7 a.m. to 11 p.m. EST. Although this is not a situation where Scottrade's network was breached, you may, nevertheless, want to consider changing your Scottrade account number for additional protection.

  2. Remember to review your Scottrade account activity regularly and statement promptly. Report any suspicious activity to us.

  3. Although this was not an Internet security issue, you may want to change your Scottrade account access password periodically (a secure password that is easy for you to remember, but difficult for others to guess) by using our online change password process.

  4. Since your bank information could have been accessed, contact your bank immediately so it is aware of the situation and can monitor for unusual activity in your bank account.

  5. Review your bank activity and statements promptly to detect and prevent fraud. Look for transactions with strange payees or amounts you do not recognize. The more frequently you review your activity and statements, the easier it will be to detect suspicious transactions.

  6. If you use your Social Security number for your driver's license or state ID card, we strongly urge you to change your account number and place a fraud alert on your credit file. A fraud alert tells creditors to contact you before they open any new accounts or change your existing accounts. For more information on placing a fraud alert on your credit file, please see www.scottrade.com/security, a website that we have dedicated to this issue.



We are extremely sorry about this matter and will strive to rectify the situation to the best of our abilities. If you have any questions or concerns, please contact us, so we may be of assistance.

Sincerely,



Ellis Hough

Manager

Risk Management


I haven't heard of any other eCheck customers being notified.

ChoicePoint sells access to FBI and Pentagon to track terrorists and others

According to GovExec.com, a Freedom of Information Act request has revealed that embattled ChoicePoint has been providing extensive services to the FBI and the Defense Department, essentially providing access to its enormous databases that the US government would not be able to compile on its own.

www.GovExec.com - FBI, Pentagon pay for access to trove of public records (11/11/05):

"To help the government track suspected terrorists and spies who may be visiting or residing in this country, the FBI and the Defense Department for the past three years have been paying a Georgia-based company for access to its vast databases that contain billions of personal records about nearly every person -- citizens and noncitizens alike -- in the United States.

According to federal documents obtained by National Journal and Government Executive, among the services that ChoicePoint provides to the government is access to a previously undisclosed, and vaguely described, 'exclusive' data-searching system. This system in effect gives law enforcement and intelligence agents the ability to use the private data broker to do something that they legally can't -- keep tabs on nearly every American citizen and foreigner in the United States."


Thanks to beSpacfic for the link: beSpacific: Gov't Pays Aggregator for Access to Extensive Database of Personal Info.

National Security Letters under the microscope

The Washtington Post has a very long and equally interesting article on "national security letters", a new tool given to the FBI under the USA Patriot Act. Their use is growing quickly and, as importantly, the FBI is putting all information gleaned by this mechanism into large databases. Thanks to Daniel Solove at Concurring Opinions for pointing to this article:

The FBI's Secret Scrutiny

The FBI now issues more than 30,000 national security letters a year, according to government sources, a hundredfold increase over historic norms. The letters -- one of which can be used to sweep up the records of many people -- are extending the bureau's reach as never before into the telephone calls, correspondence and financial lives of ordinary Americans.

Issued by FBI field supervisors, national security letters do not need the imprimatur of a prosecutor, grand jury or judge. They receive no review after the fact by the Justice Department or Congress. The executive branch maintains only statistics, which are incomplete and confined to classified reports. The Bush administration defeated legislation and a lawsuit to require a public accounting, and has offered no example in which the use of a national security letter helped disrupt a terrorist plot.

The burgeoning use of national security letters coincides with an unannounced decision to deposit all the information they yield into government data banks -- and to share those private records widely, in the federal government and beyond. In late 2003, the Bush administration reversed a long-standing policy requiring agents to destroy their files on innocent American citizens, companies and residents when investigations closed. Late last month, President Bush signed Executive Order 13388, expanding access to those files for "state, local and tribal" governments and for "appropriate private sector entities," which are not defined.

National security letters offer a case study of the impact of the Patriot Act outside the spotlight of political debate. Drafted in haste after the Sept. 11, 2001, attacks, the law's 132 pages wrought scores of changes in the landscape of intelligence and law enforcement. Many received far more attention than the amendments to a seemingly pedestrian power to review "transactional records." But few if any other provisions touch as many ordinary Americans without their knowledge.

Senior FBI officials acknowledged in interviews that the proliferation of national security letters results primarily from the bureau's new authority to collect intimate facts about people who are not suspected of any wrongdoing. Criticized for failure to detect the Sept. 11 plot, the bureau now casts a much wider net, using national security letters to generate leads as well as to pursue them. Casual or unwitting contact with a suspect -- a single telephone call, for example -- may attract the attention of investigators and subject a person to scrutiny about which he never learns.


BC announces medical privatization plan

Over the protests of public sector unions and privacy advocates, the government of British Columbia has formally announced that it is outsourcing the processing of medicare claims to a US-based company, Maximus. The prospect of this happening led to complaints by the BC Government and Service Employees Union to file a complaint to the province's Information and Privacy Commissioner, prompting the Commissioner's investigation into the impact of outsourcing and the USA Patiot Act on the privacy of British Columbians (see BC Privacy Watchdog Seeks US Government, FBI Input in Patriot Act). For more info on the recent outsourcing announcement, see:

CNEWS - Politics: B.C. announces medical privatization plan:

"...Maximus, Inc., a U.S.-based firm, has been given a 10-year contract worth $324 million, the government announced Thursday. The company also has a five-year renewal option...."

Summaries of incidents cataloged on PIPEDA and Canadian Privacy Law

Since I started this blog in January 2004, I have noted a few incidents related to inappropriate release of personal information. After an e-mail exchange with Rob Hyndman, I thought it would be interesting to figure out how many incidents I've blogged about. So here is a brief catalog of what I've picked up over the last year and a bit.

Hacking and inappropriate disposal rank highly as the reasons for ending up on this list. But, if there is one thing to learn from all of this: inadequate security of personal information is the one practice that is the most likely to put your company on the front pages of the paper and to destroy any customer trust you've managed to develop.


Last updated - 20050405

FBI Papers Indicate Intelligence Violations

Even when the FBI can go to a secret court for authorization for intrusive surveillance or, in some cases, do it according to internal oversight, the Washinton Post is reporting that some FBI agents have circumvented all oversight to conduct surveillance on US residents:

FBI Papers Indicate Intelligence Violations

In other cases, agents obtained e-mails after a warrant expired, seized bank records without proper authority and conducted an improper "unconsented physical search," according to the documents.

Although heavily censored, the documents provide a rare glimpse into the world of domestic spying, which is governed by a secret court and overseen by a presidential board that does not publicize its deliberations. The records are also emerging as the House and Senate battle over whether to put new restrictions on the controversial USA Patriot Act, which made it easier for the government to conduct secret searches and surveillance but has come under attack from civil liberties groups.

The records were provided to The Washington Post by the Electronic Privacy Information Center, an advocacy group that has sued the Justice Department for records relating to the Patriot Act.

David Sobel, EPIC's general counsel, said the new documents raise questions about the extent of possible misconduct in counterintelligence investigations and underscore the need for greater congressional oversight of clandestine surveillance within the United States.

"We're seeing what might be the tip of the iceberg at the FBI and across the intelligence community," Sobel said. "It indicates that the existing mechanisms do not appear adequate to prevent abuses or to ensure the public that abuses that are identified are treated seriously and remedied."

UC Berkeley reports massive security/privacy breach

Another in a series of significant privacy incidents has hit California universities. This time, a research database containing very sensitive personal information was penetrated. See the discussion on Slashdot and the article, below, from Security Focus:

SecurityFocus HOME News: California reports massive data breach:

"The FBI is investigating the penetration of a university research system that housed sensitive personal data on a staggering 1.4 million Californians who participated in a state social program, officials said Tuesday.

The compromised system had the names, addresses, phone numbers, social security numbers and dates of birth of everyone who provided or received care under California's In-Home Supportive Services program since 2001, says Carlos Ramos, assistant secretary of the state's Health and Human Services Agency. The program pays a modest hourly wage to workers who provide in-home care for hundred of thousands of low-income elderly, blind and disabled people.

Officials say they have not determined whether or not the intruder actually downloaded the database, which had been made available to researchers at the University of California, Berkeley under a confidentiality agreement. 'We don't know whether or not the information was accessed,' says Ramos. 'Since it is sensitive data we figured it would be best to get word out to people so they can take preventive measures just in case.' ..."


See also the California Department of Social Services information about this incident at: http://www.cdss.ca.gov/ihss/. The Department also has an FAQ related to the incident at http://www.cdss.ca.gov/ihss/IHSSSecuri_1720.htm.

Leading US spammer shut down by the FBI

From the Associated Press, via Yahoo! News:

FBI Raid Shuts Down Suspected Spammer - Yahoo! News:

"WEST BLOOMFIELD, Mich. - A man described as one of the nation's leading senders of spam says an FBI raid on his home office has halted his e-mail operation.

Warrants unsealed last week show that a September raid on Alan M. Ralsky's home in a Detroit suburb included the seizure of financial records, computers and disks.

'We're out of business at this point in time,' Ralsky said. 'They didn't shut us down. They took all our equipment, which had the effect of shutting us down.'

Terry Berg, the top deputy in the Detroit U.S. attorney's office, declined to comment.

Ralsky, 60, has said that he has 150 million or more e-mail addresses, and he has been a target of anti-spam efforts for years.

Verizon Communications Inc. sued him in 2001, saying he shut down its networks with millions of e-mail solicitations. He settled, promising not to send spam on its networks.

A federal law that took effect last year bans use of misleading subject lines and the sending of commercial e-mail messages that appear to be from friends. It also bans use of multiple e-mail addresses or domain names to hide senders' identities."

Article: Subsidiary of US weapons manufacturer will help conduct Canada's 2006 census

Expect a new round of concern about US Government access to Canadians' personal information after the announcement that Lockheed Martin has been awarded a contract to assist Statistics Canada with the 2006 census.

Yahoo! News - Subsidiary of US weapons manufacturer will help conduct Canada's 2006 census:

"Critics fear some census information could leak out and make its way into the hands of the U.S. government.

They point to the U.S. Patriot Act, which was enacted following the terrorist attacks of 2001. It allows the FBI (news - web sites) and other U.S. authorities access to information held by private American companies. There are concerns that power might extend to companies in Canada and other countries with headquarters in the United States.

'It's our understanding that it makes Canadian information vulnerable,' said Masse, who is the NDP's industry critic.

..

Statistics Canada says security concerns about the census are not valid.

'No private sector contractor will have access to completed census questionnaires,' said Arora.

That information, Arora added, will only be available to Statistics Canada employees who have signed confidentiality agreements. "

BC Government Employees' Union says amendments won't protect personal information

The BCGEU (who started all the fuss about privacy and outsourcing in BC in the first place) has issued a release saying that the amendments to the Freedom of Information and Protection of Privacy Act (BC) do not go far enough to protect the privacy of British Columbians:

BCGEU: Amendments to privacy laws won't protect our personal data from the FBI:

"The B.C. Government and Service Employees' Union (BCGEU) is rejecting the government's claim that amendments to B.C. privacy laws will be sufficient protection for British Columbians if their medical and financial records and other personal information are handed over to U.S.-linked companies.

'The Campbell Liberals can try to build a fortress around our personal data but once it outsources information technology (IT) services to American-linked companies, the FBI can use the USA Patriot Act to knock down any legal, constitutional or electronic walls to get British Columbians' personal information,' said Diane Wood, BCGEU Secretary-Treasurer..."

See, also, my blog entry on the amendments: BC amends public sector privacy law to block access to information is services are outsourced.

UPDATE: The Canadian Union of Public Employees, a federal public sector union, has also come out against the proposed amendments:



B.C. Liberals using FOI amendments to mask privatization agenda, says CUPE Bill 73 pre-empts Privacy Commissioner's report on effects of USA Patriot Act:

"BURNABY, BC, Oct. 8 /CNW/ - Amendments to the Freedom of Information and Protection of Privacy (FOIPP) Act are mere window dressing for the provincial government's privatization agenda and do nothing to alleviate British Columbians' concerns about the all-powerful USA Patriot Act, says CUPE BC president Barry O'Neill.

Bill 73, tabled in the legislature yesterday by Management Services Minister Joyce Murray, includes restrictions on public bodies and service providers storing, accessing or disclosing personal information outside Canada.

But amendments to Canadian law cannot protect the privacy of Canadians when U.S. companies are in possession of Canadians' personal information, says O'Neill...."

Security breach forces FBI e-mail system offline

The FBI has been forced to shut down its non-classified e-mail system due to a potential security breach.

Yahoo! News - Possible Breach Forces FBI To Turn Off E-Mail System:

"The FBI said Friday it has shut down an e-mail system that it uses to communicate with the public because of a possible security breach.

The bureau is investigating whether someone hacked into the www.fbi.gov e-mail system, which is run by a private company, officials said...."

Canadian Privacy and the USA Patriot Act

Interesting how this has only now appeared on the US radar screens. When this was only about the British Columbia and Alberta governments, the only coverage was Canadian. Now that there is some small reaction out of Ottawa, it shows up in the US media ...

UPI Intelligence Watch - (United Press International):

"Washington, DC, Feb. 4 (UPI) -- Because of security concerns related to the Patriot Act, the Canadian government will revise the wording of future federal contracts. Ottawa will attempt to blunt U.S. ability, granted under the act to tap into personal information about Canadians. The Canadian government is particularly concerned that the FBI might attempt to view sensitive Canadian data the government supplies to American firms doing business with federal departments in Ottawa. Ottawa has requested that all government agencies and departments conduct a "comprehensive assessment of risks" to Canadian information they release to U.S. companies when fulfilling work under contract. The Patriot Act gave the FBI broader access to the records of U.S. firms. Under its provisions, the FBI can apply to a U.S. court to force a business to allow access to its records, including information about Canadians, to assist with investigations involving prevention of terrorism or espionage. Canadian Privacy Commissioner Jennifer Stoddart says that if a Canadian federal entity hires an American company to process personal information about Canadians, then U.S. laws apply to the data if the work is being done in the United States. The federal Treasury Board is in charge of a working group that is drafting special clauses to be used in future business proposal requests and contracts. According a federal notice recently circulated to departments, the group is consulting with Stoddart's office on clauses "that we believe to be fundamental" to include in future request proposals and contracts. Treasury Board spokesman Robert Makichuk said the changes would "further enhance and clarify existing protection" for such things as establishing custody and control of data, ensuring confidentiality of information and setting conditions related to use and disclosure."

Don't keep the data that you don't need

The recent controversey over subpoenas of high-profile search engines has spurred a lot of discussion about what search engines know about you. For example, John Battelle was able to get confirmation from Google of what a lot of people have probably always suspected:

1) "Given a list of search terms, can Google produce a list of people
who searched for that term, identified by IP address and/or Google
cookie value?"

2) "Given an IP address or Google cookie value, can Google produce a
list of the terms searched by the user of that IP address or cookie
value?"

I put these to Google. To its credit, it rapidly replied that the answer in both cases is "yes." Just FYI.



What else does Google know? Given that Google operates


  • one of the most widely used advertising networks,
  • one of the most widely used webmail services,
  • one of the most widely used mapping services,
  • one of the most widely used website statistics services,
  • one of the most widely used browser toolbars,
  • one of the most widely used news aggregators,
  • one of the most widely used online group services,

they know a heck of a lot. Every time you visit a site that uses adwords, your computer connects to google and tells them what you're viewing and probably what got you there. And all this can be matched by your google cookie or your IP address.

The question is, other than for personalized services, why should a company maintain information that is personally identifiable? Why keep logs that have your ip address down to the last digit when the same value can be obtained from the data by only keeping the first three units (192.168.168.* compared to 192.168.168.111)? The level of trust that consumers have for companies like Google is eroding and businesses should take heed of this. If you don't need the information in personally identifiable form, don't keep it.

It will not be long before the cost of keeping this stuff is prohibitive if you have to spend valuable personel time responding to subpoenas. I can imagine the FBI or some other three-letter-agency having a form subpoena that will seek all the records from Google, Yahoo!, DoubleClick and others about the supposed "owner" of a suspicious IP address. What did you search for? What did you read? When were you online? All this info is mantained by a small handful of companies.



UPDATE: While you're thinking about this, check out Google's data minefield by Mark Rasch (via robhyndman.com).

Technorati tags: :: :: :: :: ::
::
::

Canada moves to counter privacy threat posed by U.S. Patriot Act

According to the Canadian Press, the Federal Government is in the final stages of taking contractual steps to limit the access of American authorities to personal information of Canadians. It is worth noting that this appears to apply only to future contacts and that the government is content to include blocking clauses in agreements with contractors, rather than amending the Privacy Act, as has been done in British Columbia:

Yahoo! News - Canada moves to counter privacy threat posed by U.S. Patriot Act:

"OTTAWA (CP) - The government will revamp the wording of future federal contracts with the aim of countering U.S. powers, granted under anti-terrorism laws, to tap into personal information about Canadians.

The move is intended to prevent the U.S. Federal Bureau of Investigation from seeing sensitive Canadian data the government supplies to American firms doing business with federal departments in Ottawa.

The government has also asked all agencies and departments to conduct a 'comprehensive assessment of risks' to Canadian information they release to U.S. companies carrying out work under contract.

The U.S.A. Patriot Act, passed following the Sept. 11, 2001 terrorist attacks, gave the FBI broader access to records held by firms in the United States.

The FBI can apply to a U.S. court to have a company disclose records, including information about Canadians, to assist with investigations involving prevention of terrorism or espionage.

Privacy Commissioner Jennifer Stoddart says that if a federal institution hires a U.S. company to process personal information about Canadians, then American laws apply to the data if the work is being done south of the border.

The federal Treasury Board leads a working group that is now busy finalizing special clauses to be used in future business proposal requests and contracts.

The group is consulting with Stoddart's office on clauses 'that we believe to be fundamental' to include in future request proposals and contracts, says a federal notice recently circulated to departments...."

USA Patriot Act "national security letters" provision is thrown out by Court

The ACLU has been successful in challenging the portion of the USA Patriot Act that allows the FBI to compel the production of records without court authorization. Parry Aftab has a number of good blog entries about it, including her analysis of the decision. Take a look at Patriot Act Provision is thrown out by Court - effective date is delayed 60 days to allow government time to appeal, The Decision in ACLU v. Ashcroft, and Overview of the Section 2709 Patriot Act decision. While you're there, bookmark her excellent blog.

FBI Keeping Records on Pre-9/11 Travelers

In the aftermath of the terrorist attacks on September 11, 2001, US federal investigators obtained massive amounts of information on individuals who were airline passengers in the months leading up to the attack. The FBI is keeping those records, according to the Associated Press, with no intention of giving them up. Privacy activists are up in arms over it:

FBI Keeping Records on Pre-9/11 Travelers: "

WASHINGTON (AP) - If you're among the millions of Americans who took airline flights in the months before the Sept. 11, 2001, terrorist attacks, the FBI probably knows about it - and possibly where you stayed, whom you traveled with, what credit card you used and even whether you ordered a kosher meal.

The bureau is keeping 257.5 million records on people who flew on commercial airlines from June through September 2001 in its permanent investigative database, according to information obtained by a privacy group and made available to The Associated Press.

Privacy advocates say they're troubled by the possibility that the FBI could be analyzing personal information about people without their knowledge or permission.

'The FBI collected a vast amount of information about millions of people with no indication that they had done anything unlawful,' said Marcia Hofmann, attorney with the Electronic Privacy Information Center, which learned about the data through a Freedom of Information Act request.
'The fact that they're hanging on to the information is inexcusable,' Hofmann said on Friday...."