Wednesday, October 19, 2011

Why don’t Americans care about Privacy?

In my post from earlier this year, I commented on how Senator Leahy re-introduced his Personal Data Privacy Act…the same bill he has been submitted every year for the last 5 years. 5 months after the re-introduction of the bill this year, there is still no GOP support for Leahy’s Privacy bill.


By my count so far this year, there were 9 data privacy bills introduced into both houses of Congress. This may not sound like a ton, but is half the number of the bills introduced during the Health Care Reform debate of 2008. So it looks like 2011 won’t be the year we get a national data privacy law.


Why not? Do Americans not care about Privacy? Of course they do. Every state in America now has their own data privacy law. How often are their respective Attorney’s General enforcing those laws? Most of them don’t have private rights of action, so there isn’t any one else to enforce them. States probably wont enforce the laws unless they can collect some fines out of it, which means smaller infractions will get overlooked anyway. So Americans have some privacy, but not very much.


Facebook is at war with Privacy. In January of 2010, Facebook’s founder, Mark Zuckerberg pronounced that Privacy is dead. The EU Obviously cares. They’ve spent the last 30 years putting steroids into their Privacy laws. Max Screms, a European law student, is taking Facebook to task over their numerous violations of Irish Privacy laws. Although European members data privacy laws still differ, their push for privacy started with the OECD in 1980 and more recently the EU Data Protection Directive.


So why aren’t Americans more up in arms? Max Screms worries, “The KGB or the CIA never had 1200 pages [of information] on the average citizen.” But Facebook does.


Some theories about why American’s don’t care about Privacy:



  • We’re more worried about the economy – nope, the unemployment rate in Europe has been much worse for longer.

  • Most people haven’t read 1984 – that’s probably true…it’s never been made into an American movie with Brad Pitt.

  • We’re more worried about the stock market, the housing market, health care reform??? This is interesting…the Occupy Wall Street movement, along with the Tea Party, and the Iraq War Activists have been some of the few examples where Americans have been willing to take to the streets for a cause en mass in recent memory.

  • We’re more worried about Terrorism than the EU – I don’t think so. The Facebook case is going on in Ireland, and I think they’re slightly more sensitive to terrorism than we are.

  • What about Corporate Interests – some might say our politicians are bought and sold by corporations. While that may be a valid point, politicians everywhere suffer from the same temptations, and by all evidence, American politicians get in trouble a lot less than their European, Russian, or Asian counterparts.

  • Maybe we’re naturally voyeuristic? We are willing to trade our own privacy in order to invade other people’s privacy. This sounds pretty accurate to me.

  • Maybe we assume if it’s really a problem, then we can just sue somebody. Oh wait, all the so called ‘privacy’ legislation being thrown around doesn’t give individuals a private right of action against privacy infringers. Fines just go to state coffers and probably aren’t enough to deter bad behavior anyway. Remember CAN-SPAM? Of course you don’t.

  • Maybe Americans are just behind the curve? After all, Myspace fell apart, and that could have been an unconscious choice by the faceless public because Myspace felt less secure…from the viruses, to the unsolicited connections from weirdos, to how the apps felt like they gave away your information in a more overt way. Do we vote with our feet? Voting with one’s feet presumes that you have a meaningful choice…if you’re just voting between the lesser of two evils, then you end up voting for the more clean cut of two gangsters who doesn’t curse and swear while they rifle through your life.

  • Or maybe Americans do care about privacy. Maybe the ones that really care, haven’t bothered to join Facebook or have left. So why aren’t they up in arms? If they were, then they’d be in the spotlight, and that’s not really something they’re interested in. Why should they take a stand to protect you when you’re obviously okay with giving up your personal details? Also, this group of people tends to wear tin-foil hats.

Monday, October 17, 2011

Crimesourcing

Imagine a world where criminals used sophisticated networks of middlemen. Transactions between pawns were untraceable. All using the power of something called, the Internet. And people wonder why I say that the law is having a hard time keeping up with technology.

The article gives a great overview of the developments in cybercrime over the last 3 or 4 years:

http://www.forbes.com/sites/oreillymedia/2011/10/03/the-rise-of-crime-sourcing/

Daubert's Fingerprint

Everybody knows that every snowflake is one of a kind. Unique. Just like a fingerprint. Wait, how do we know a fingerprint is unique?

In a legal proceeding in the United States, the process the court uses to determine whether an expert witness is qualified to give testimony in their field is commonly referred to as the Daubert test. If a court were going to let an expert witness in to testify whether a certain fingerprint found at the scene of a crime or on a critical piece of evidence was a match for a defendant…the court would use the Daubert test to determine whether the expert had knowledge derived from sound scientific methodology.

Except they don’t.

What do you mean, they don’t?

They don’t. No court has ever challenged the expert-ness of an expert witness who purported to be an expert on fingerprints.

Why not?

To be an expert in something, there has to be a body of knowledge for you to know about. Where is the body of knowledge about fingerprints? They swirl around, we know that much right? There’s a database of them, right?

The FBI does have a database of fingerprints. But they’ve never let researchers look at it.

The question researchers want to know the answer to is: how unique is a fingerprint? The lines of a fingerprint are about a millimeter wide. A fingertip might be a square inch. So there obviously can only be so many variations in a fingerprint. We know that fingerprints don’t come in stripes or plaid, so the universe of possible variations is limited. So just how limited? How can you compare the relative uniqueness of other markers, like a retna scan, DNA, voice patterns, etc. to a fingerprint when there isn’t any scholarship on how unique a fingerprint is?

This is really interesting because it subjects the validity of fingerprint evidence to a birthday attack. This is a basic type of security problem where you can calculate the probability of two people in the same room having the same birthday. Assuming that there are 30 people in a room, the likelihood that there is one person in the room with a specific birthday is only about 8%. 1-(364/365)30. The likelihood that two people in the room with the same birthday is nearly 70%. The two variables here are the number of people in the room and the number of possible days. If there are 10 million possible variations of fingerprint and 5,000 were at a conference on IT security, what is the likelihood of finding two with the same fingerprint? I’ll keep this idea around for my next detective novel.

A Daubert test would look at the following 5 factors to determine whether a fingerprint expert would be able to testify:

  1. Empirical testing: the theory or technique must be falsifiable, refutable, and testable.
  2. Subjected to peer review and publication.
  3. Known or potential error rate.
  4. The existence and maintenance of standards and controls concerning its operation.
  5. Degree to which the theory and technique is generally accepted by a relevant scientific community.

The list is nondispositive and nonexclusive. The 4th and 5th factors are the only ones that have bearing on a fingerprint. Would these two factors alone be enough for courts to let a fingerprint expert testify? Maybe, but we would have to see a Judge to make that decision.

Friday, October 7, 2011

Cyberattack on Predator Drones?

Wired's Danger Room points out that US Predator and Reaper drones have been under attack by a computer virus:

http://www.wired.com/dangerroom/2011/10/virus-hits-drone-fleet

To date, the virus has only apparently been logging the keystrokes of the operators. From the article, I get the impression that it is the operators workstations and not the drones themselves that are the subject of the attack. Wasn't this how computers took over the world in Terminator 3? Or was that Terminator 4? I can never remember.

Monday, September 26, 2011

Netflix Hates Privacy?

There’s been a lot of news about how Netflix wants to fight an arcane video law, passed almost 25 years ago, to enable the future of movie streaming. Hulu wants to do the same thing, with their new video campaign, “This is my favorite part…” I like the Hulu commercials, but I’m not convinced that I want people to automatically know I’m watching reruns of Cashmere Mafia. It’s my wife, I swear.

Facebook has already been sued for sharing Blockbuster rental information, according to Wired.

Intro to the Video Privacy Protection Act

I think all the best consumer protection laws come from when politician’s private lives are exposed to us. This is what happened to get the VPPA enacted. A supreme court nominee’s local video store gave up his viewing history to a reporter. The reporter published the videos in an attempt to embarrass the nominee and derail his nomination, but instead, members of congress all realized that they’d be in deep trouble if clever reporters could all do the same thing to them. Interestingly, the bill was written by Senator Leahy, whose committee is now being asked to amend the bill in favor of Netflix sharing your movie tastes with everyone.

Some have called the VPPA the strongest protection of consumer privacy against data collection. Even stronger than HIPAA? Yes, it is. The reason is that it creates a private right of action for consumers to sue the offending offender directly. HIPAA and all of the new privacy legislation proposed so far in 2011 do not create a private right of action, instead putting the burden on the states Attorneys General.

Draw your own conclusions here, but I’m liking the VPPA a lot more than the new legislation currently being drafted. Giving the power to the consumers is a better solution than assuming an Attorney General will go after infringers. They already have the power to do this under HIPAA, and they haven’t exercised that power very often. Class Actions for privacy issues are also problematic, since courts are more and more reluctant to let them move forward.

Privacy is dead. Long live privacy.

Thursday, September 15, 2011

Hacking is free speech!

Hacking Is Free Speech! (or is it?)

I should start by noting that not all speech is protected under the 1st Amendment. For example, I can’t say to someone that I am a detective with Miami Metro Homicide, because I’m not. That’s called impersonating a police officer and carries a prison sentence. There are particular acts in speech that breakdown the structure of our society, so we don’t protect them. Libel. Slander.

The problem with laws governing fraud covering the Internet is that everyone is a fraud on the web. Why do we allow hate speech to be protected while we chastise hackers for typing in simple letters and numbers in URLs? One may very well incite violence, but the other is much more insidious somehow because we call it Cross Site Scripting? One is more insidious because a software company produced a terrible product and doesn’t spend enough resources keeping their software up to date?

Let’s face it. The Internet makes us bipolar. The whole point of the Internet is being connected, yet we put up barriers and firewalls to protect us. At the same time that we say we are worried about hackers and identity thieves ruining our lives, we believe news articles from people we don’t know the credentials of and we open up to complete strangers whom we’ve never met. Why can’t we just accept that you shouldn’t trust anyone on the Internet?

If we can accept it as true that nothing on the Internet should be trusted, then we wouldn’t be surprised when information was leaked or when sites went down. Should Hacking be considered protected speech under the 1st Amendment? In other words, should hacking be free speech?

As security practitioners and government legislators, we should accept the reality of computer insecurity rather than fight the evil hoardes that attempt to subvert our pristine online ivory towers.

Why not have laws that make it illegal to ship a computer product that is susceptible to computer hacking? Why not make it illegal to not patch a known vulnerability within a reasonable period of time? Why not make create real penalties for failed security at companies that have high value targets just like we have for banks and other institutions?

Because it’s impossible to make a computer secure? Exactly my point!

Because it’s easier to label ‘hackers’ as bad guys and go after them than change our paradigm?

The truth is that we don’t really understand the virtual world enough to apply the law to them. While I can accept the application of RICO to rings of identity thieves, it makes no sense that a person can get jail time for being an internet troll. (Keep in mind the difference between US and UK law…in the US there is a church that goes to protest at military funerals.)

So you say you want a revolution? You say that as the computer elite you should be the ones to change the world? Okay, let’s say that hacking is civil disobedience. There have been some meaty articles written on this in The Guardian, Slate, and Shiny Ideas.

Okay, so instead of being a Civil Rights Worker, you’re a Hacktivist. Now what? You should be prepared to be arrested. Civil Rights activists had a specific goal they were working towards and they were prepared to be arrested to support their cause, for change. The very act of their arrest only added to their cause. If you are a Hacktivist and you believe in whatever cause you are supporting, then nobly stand behind it. But don’t undermine your own cause by trying to overthrow society itself.

This is the problem then. What is the cause that Hactivitism supports? Is there only one? Are there more parallels with Batman or Martin Luther King Jr.?

Friday, September 9, 2011

What Would Jesus Hack


Interesting article in the Economist about the connection between Christian values and the values of the Hacker/Open Source Community:

http://www.economist.com/node/21527031