Showing posts with label advocates. Show all posts
Showing posts with label advocates. Show all posts

Sunday, 28 July 2013

Some privacy advocates question mobile apps agreement

A proposed code of conduct for mobile app developers intended to make them explain how user data is collected and used does not have a clear enforcement mechanism,  one privacy advocate said.

The code was negotiated this week by several trade groups and the U.S. National Telecommunications and Information Administration (NTIA). While many participants in the NTIA's mobile privacy negotiations voiced support Thursday for the transparency code of conduct, Consumer Watchdog criticized the document and the NTIA process.

Just two participants voted to fully endorse the code, while 20 supported it, 17 voted for further consideration and one objected. Participants voicing support had no obligation to adopt the code, the NTIA said.

"This is absurd Orwellian doublespeak," John Simpson, Consumer Watchdog's Privacy Project director, said in an email.  "A company can put out a press release saying it supports the transparency code, boosting its public image and then do absolutely nothing."

Several consumer and privacy groups voted to support the code, including the American Civil Liberties Union, Consumers Union, the Center for Democracy and Technology and the Electronic Frontier Foundation.

The code defines a short notice to provide consumers with information about the data collection and sharing practices of the mobile apps they use. The short notices tell consumers if the apps are collecting biometrics, browser history, contacts, financial information, health information, location, and other information.

NTIA Administrator Lawrence Strickling, called Thursday's vote a "seminal milestone in the efforts to enhance consumer privacy on mobile devices. "

Several software trade groups also praised the transparency code. The short notice will quickly and easily inform consumers about the personal information apps collect, said Jon Potter, president of the Application Developers Alliance.

"App developers know that consumer trust is critical to our industry's continuing success," Potter said in a statement. The agreement that "the model notices are ready for introduction and consumer testing is a win for both consumers and app developers."

But Jeffrey Chester, executive director of the Center for Digital Democracy, criticized the NTIA's negotiation process. Chester, who abstained from the vote, had asked the NTIA to review existing mobile and app practices to determine the extent and range of data collection, but the agency didn't do that, he said.

"The NTIA process is seriously flawed," he said in an email. "It's as if a surgeon was allowed to operate without first examining the patient. [The agency] refused to make the industry discuss all the ways mobile apps use data and target users."

The code approved Thursday "is just words on a very small screen," Chester added.

Wednesday, 24 July 2013

Ban passwords, say advocates of alternative authentication

Passwords are a thing of the past and they need to go, according to a group of Silicon Valley-based tech companies who are part of a public advocacy campaign called Petition Against Passwords.

Passwords are the keys that enable access. At the same time, they're also the weak link that smashes the security chain, according to many experts, who for years have warned that passwords simply don't work as they used to, and that password protection alone isn't enough.

The problem with passwords is twofold, according to the advocacy group, which aims to influence large digital service providers to move toward "password-less" authentication and identity protection. On one hand, users either create easily remembered passwords that are entirely too weak or they are forced to pick passwords that are hard to remember, but quickly cracked by machines. The other side to that is a lack of password policy enforcement, and the gaps in basic data protection that can lead to breaches that expose millions of passwords. When breaches expose passwords, they often make their way online and wind up in wordlists that are used by password cracking software.



Last April, LivingSocial, a website dedicated to offering consumers daily deals on local products and services, was compromised and some 50 million users were urged to change their passwords. The concern was that many of the users that were exposed faced additional risk due to password recycling. The incident also highlighted the importance of properly protecting user data, especially passwords.

"Because passwords must be stored on a central server, sites are tasked with protecting them from a persistent onslaught of attacks. Even the best protected servers eventually fall. The results can cost the company millions of dollars and drastically impact consumer trust," wrote Brennen Byrne, the CEO of Clef, an Identity Management and Protection firm that leverages smartphones as a means of authentication, which is part of the campaign. Other companies, including OneID, LaunchKey and Nok Nok Labs have also joined in support of the movement.


Byrne's words come from a manifesto of sorts, calling for Internet users to demand something different when it comes to authentication. Over the last few years, there has been a push to replace passwords, or at least augment them with additional layers of security. For example, Two-Factor Authentication is one such augmentation. It works, and it has seen wide adoption by businesses and consumers alike. However, there are others that wanting to move far beyond Two-Factor and similar advancements.

In May, Motorola's Regina Dugan made headlines when she suggested tattoos and pills as alternate means of authentication. A month before that, researchers at the University of California, Berkeley, released research on using brainwaves as a means of authentication.

To date identity companies LaunchKey, Nok Nok Labs, Clef, and leading consumer advocacy group TechFreedom have signed on to support the petition. The Petition Against Passwords initiative will go live on July 24, 2013.

Thursday, 11 July 2013

Privacy advocates call on government to rein in NSA


A U.S. government board focused on privacy and civil rights should push Congress to rein in the National Security Agency’s mass collection of telephone records and Internet communications, privacy advocates said Tuesday.
The U.S. Privacy and Civil Liberties Oversight Board, established by Congress in 2004 to be a watchdog of government antiterrorism efforts, should also demand that the NSA and other government agencies be more transparent about the data they collect, said privacy advocates speaking at a board meeting in Washington, D.C.

While two former government officials defended the NSA’s collection of U.S. phone records and overseas Internet communications, other speakers told the board the agency has exceeded its legal authority, particularly when collecting U.S. records. Recent revelations about NSA data collection and surveillance show a lack of congressional and court oversight, said Jameel Jaffer, a lawyer with the American Civil Liberties Union.

Congress needs to limit what information the NSA and law enforcement agencies collect because internal privacy safeguards won’t work, Jaffer said. “You don’t know what the privacy safeguards are going to look like three years from now, five years from now” when there may be another terrorist attack, he said.

Board member Patricia Wald, an appeals court judge, asked if the NSA should be able to collect large amounts of data about U.S. residents, then have data minimization rules that limit what the agency can do with the data.
“Minimization is one of the great euphemisms of our time,” said James Robertson, a former Foreign Intelligence Surveillance Court judge who’s criticized current surveillance practices. “No one knows what it means.”
The surveillance court now appears to be issuing opinions on policy in addition to approving surveillance requests, Robertson said. The policy rulings are not in the court’s authority, he and other privacy advocates told the board.
Asked if the NSA could protect privacy through technological safeguards on the use of the data collected, some participants suggested a technology solution wasn’t enough. Technology can only implement policy, said Steven Bellovin, a computer science professor at Columbia University.
As the NSA collects more and more data, it will find new ways to use it, said Marc Rotenberg, president of the Electronic Privacy Information Center (EPIC). “A threshold is crossed once the data is collected,” he said. “There’s no guarantee the safeguard will remain over time.”
But the NSA and other agencies are already collecting massive amounts of data, said Daniel Weitzner, director of the Decentralized Information Group at the Massachusetts Institute of Technology’s Computer Science and Artificial Intelligence Laboratory. It would be useful for privacy advocates to work both on changing U.S. policies and on implementing technological limits on what the NSA can do with the data it collects, said Weitzner, a former deputy CTO in President Barack Obama’s administration.

“All the useful data has been collected,” he said.
The surveillance court and the NSA should be more transparent about the data collected, and the court should publish some of its orders, some panelists said. Part of the reason for concern about the surveillance is that the “searches are done in secret,” said Kate Martin, director of the Center for National Security Studies, a civil liberties watchdog group.
But it makes sense that the NSA doesn’t broadcast the targets of its surveillance, said Kenneth Wainstein, a former White House homeland security adviser. The surveillance court process, which doesn’t include a lawyer arguing against the surveillance, mirrors criminal wiretap requests, he said.
“We trust judges” to scrutinize surveillance requests, he said.
Still, Wainstein said there may be some merit in creating a new role for a public advocate during the surveillance court’s process because it may restore some public confidence in the process, Wainstein said.
Wainstein and Steven Bradbury, formerly with the U.S. Department of Justice’s Office of Legal Counsel, defended the surveillance efforts, saying they are necessary to protect the U.S. from terrorism. Despite the recent uproar about the programs prompted by leaks from former NSA contractor Edward Snowden, the U.S. shouldn’t significantly limit the surveillance because of some “speculative concerns down the road,” Wainstein said.
Bradbury questioned the suggestion to include a public advocate in the surveillance court process. The current process is “workable,” he said.

Board member James Dempsey, vice president for public policy at the Center for Democracy and Technology, called on privacy advocates to propose concrete ideas for fixing the surveillance process and on defenders to engage in the debate.
“It can’t be that everything is perfect,” he said to Wainstein and Bradbury. “It can’t be that no changes can be made.”
Follow me on Twitter @sajilpl

Friday, 21 June 2013

Civil liberties advocates call for more oversight of NSA surveillance

Congress should press for privacy protections and more information about surveillance programs at the National Security Agency, some technology and civil liberties activists said Friday.


After recent news leaks about two broad surveillance programs at the NSA, it’s clear that congressional and court oversight of the agency is lacking, representatives of the American Civil Liberties Union and the Cato Institute, a libertarian think tank, told congressional staffers during a briefing on the NSA programs.


Oversight of the surveillance programs by the Senate and House of Representatives intelligence committees has been “pretty feeble,” Julian Sanchez, a research fellow at the Cato Institute, said at a surveillance forum hosted by the Congressional Internet Caucus Advisory Committee.


The limited number of lawmakers and the judges that are supposed to check the NSA programs appear to have fallen victim to a form of a governmental phenomenon called “regulatory capture,” when a body that is supposed to regulate an industry begins to “serve its interests,” Sanchez said.


Lawmakers outside the intelligence committees need to provide oversight of the programs, added Michelle Richardson, the ACLU’s legislative counsel.


“So far, Congress has allowed the intelligence committees to do secret oversight of secret programs allowed under secret court orders, and it has led to the collection of every American’s phone calls,” she said. “This cannot continue. The secret oversight is not working.”


Representatives of both intelligence committees didn’t immediately respond to requests for comment on the criticism from Sanchez and Richardson.


When the Federal Bureau of Investigation asks the Foreign Intelligence Surveillance Court for a broad swath of U.S. telephone records, there’s no opposing attorney, Richardson said.


“No one is representing the interests of the people whose records are collected,” Richardson added. “It is just the government before a secret court, and no one is representing the other side.”


Richardson and other speakers at the event called on Congress to add transparency to the surveillance court process.


The mass collection of data on U.S. phone calls and Internet communications under the two programs represents a “dangerous shift” in the way the government views the Fourth Amendment to the Constitution protecting U.S. residents from unreasonable searches and seizures, Sanchez said. There appear to be fewer prohibitions on the government collecting data and more mass collection, with some restrictions on how intelligence agencies can access the data they have collected, he said.


“Analysts themselves have the discretion to select which things are going to be queried for search,” he added. “Back-end restrictions on what you do [with the collected data] last only until you decide to change them, and the record so far suggests we won’t necessarily know if they decide to change them.”


While four of the five speakers at the event said they were troubled by the surveillance programs, lawyer Michael Vatis, a former official at the FBI and the U.S. Department of Justice, said he wasn’t overly concerned about reports of the NSA collecting Internet communications from nine Web service providers.


The Prism collection program, as described, appears to give the NSA little new surveillance power than it has always had, said Vatis, now a partner in the Steptoe & Johnson law firm. The NSA’s longtime mission is to provide surveillance on overseas communications, and the Prism program appears to be an extension of that, he said. The NSA is targeting U.S. Web companies because much of the Internet’s traffic routes through the U.S., he said.


Vatis said he had some concerns about the NSA’s bulk collection of U.S. phone records, but he takes some comfort that the agency is collecting phone numbers and not the content of phone calls.


If the NSA and DOJ have strong procedures in place to protect privacy, as they say, then the data collection can help protect U.S. residents, Vatis added. “In the worst-case scenario, when an individual brings a suitcase nuke onto Wall Street and detonates it, the questions are going to be, ‘The government had this technical capability to keep track of people, but didn’t use it,’” he said. “That will be the scandal.”


Critics of the data collection were surprised about the “breadth of the order” allowing the NSA to collect all Verizon phone traffic, countered Alan Davidson, a visiting scholar in the Technology and Policy Program at the Massachusetts Institute of Technology and a former public policy director at Google.


The data collection raises not only civil liberties and privacy concerns but also business concerns, Davidson added. “If people don’t trust these services, they’re not going to use them,” he said.


Vatis discounted the business concern. “Have many people stopped using Gmail or Yahoo?” he said.