Showing posts with label Collection. Show all posts
Showing posts with label Collection. Show all posts

Monday, December 30, 2013

Judge Upholds N.S.A.’s Bulk Collection of Data on Calls

In just 11 days, the two judges and the presidential panel reached the opposite of consensus on every significant question before them, including the intelligence value of the program, the privacy interests at stake and how the Constitution figures in the analysis.

The latest decision, from Judge William H. Pauley III in New York, could not have been more different from one issued on Dec. 16 by Judge Richard J. Leon in Washington, who ruled that the program was “almost Orwellian” and probably unconstitutional.

The decision on Friday “is the exact opposite of Judge Leon’s in every way, substantively and rhetorically,” said Orin S. Kerr, a law professor at George Washington University. “It’s matter and antimatter.”

The case in New York was brought by the American Civil Liberties Union, which said it would appeal.

“We are extremely disappointed with this decision, which misinterprets the relevant statutes, understates the privacy implications of the government’s surveillance and misapplies a narrow and outdated precedent to read away core constitutional protections,” said Jameel Jaffer, a lawyer with the group.

A spokesman for the Justice Department said, “We are pleased the court found the N.S.A.’s bulk telephony metadata collection program to be lawful.”

The next stops for the parallel cases are the appeals courts in New York and Washington. Should the split endure, the Supreme Court is likely to step in.

In the meantime, the decisions, along with recommendations issued on Dec. 18 by the presidential review group, illustrate the absence of agreement about the effectiveness and legality of the program, which, Judge Pauley said, “vacuums up information about virtually every telephone call to, from or within the United States.” That information is “metadata” — the phone numbers involved, when calls were made and how long they lasted.

The two judges had starkly differing understandings on how valuable that program is.

Judge Pauley, whose courtroom is just blocks from where the World Trade Center towers stood, endorsed arguments made in recent months by senior government officials — including the former F.B.I. director Robert S. Mueller III — that the program might have caught the Sept. 11, 2001, hijackers had it been in place before the attacks.

Judge Pauley began his opinion with an anecdote. In the months before Sept. 11, he said, the N.S.A. intercepted seven calls made to a Qaeda safe house in Yemen from the United States. They were from Khalid al-Mihdhar, who was living in San Diego and would become one of the hijackers.

But the security agency “could not capture al-Mihdhar’s telephone number,” the judge wrote, and “N.S.A. analysts concluded mistakenly that al-Mihdhar was overseas and not in the United States.”

“Telephony metadata would have furnished the missing information and might have permitted the N.S.A. to notify the Federal Bureau of Investigation of the fact that al-Mihdhar was calling the Yemeni safe house from inside the United States,” Judge Pauley wrote.

Judge Leon, in Washington, took the opposite view, saying the government had failed to make the case that the program is needed to protect the nation. “The government does not cite a single instance in which analysis of the N.S.A.’s bulk metadata collection actually stopped an imminent attack, or otherwise aided the government in achieving any objective that was time-sensitive in nature,” he wrote.

The presidential review group took a middle ground, though it seemed to lean toward Judge Leon’s position. It said the security agency “believes that on at least a few occasions” the program “has contributed to its efforts to prevent possible terrorist attacks, either in the United States or somewhere else in the world.” But it added that its own review suggested that the program “was not essential to preventing attacks,” and that less intrusive measures would work.

The group recommended that bulk storage of telephone records by the government be halted in favor of “a system in which such metadata is held instead either by private providers or by a private third party.” Access to the data, it said, should require a court order.

The two judges did not limit their disagreements to how well the program worked. They also drew different conclusions about its constitutionality.

Saturday, July 27, 2013

Under Code, Apps Would Disclose Collection of Data

A variety of groups, including app developers and consumer advocates, have agreed to test a voluntary code of conduct that would require participating app developers to offer short-form notices about whether their apps collect certain personal details from users — including health and social networking data — or share user-specific data with entities like advertising networks or consumer data resellers.

The idea is to allow people to compare the data collection practices of, say, flashlight apps and choose one that does not ingest unrelated material like their photos or contact lists. The determination that the notices are ready for testing is the outcome of yearlong negotiations — convened by the National Telecommunications and Information Administration, a division of the United States Commerce Department — to increase mobile app transparency for consumers. Participants included app developers, digital marketing, civil liberties, consumer and privacy groups.

On Thursday, many participants in the process voted to support a version of the code drafted by a diverse coalition including the Application Developers Alliance, an industry association, and advocacy groups like the American Civil Liberties Union and the World Privacy Forum.

Although major mobile app developers like Apple and Google, which develops mobile apps for its Android platform, have not indicated whether they intend to sign on to the code of conduct, groups involved in drafting it say it is a significant advance in mobile privacy for consumers — and an unusual agreement among industry and consumer advocates.

“It’s a victory for common sense,” said Tim Sparapani, vice president for law, policy and government relations at the Application Developers Alliance, a group representing more than 100 companies and 20,000 individual developers.

But other participants in the negotiations said the notices would do little to give individual consumers more insight into or control over the vast piles of information about them that online entities collect and analyze. The notices would display only a limited list of data collection categories, they say, and would not allow consumers to opt out of data-mining or even see the records companies had amassed about them.

“A very modest slice of privacy was put forward,” for the groups to tackle, said Susan Grant, the director of consumer protection at the Consumer Federation of America, a research and advocacy organization representing about 300 consumer groups. “As time went on, that slice became more and more narrowed.”

She abstained from the vote Thursday on whether to support the code.

In the past, the app industry has been heavily criticized by some federal regulators and consumer advocates for collecting personal details from users without their knowledge or consent. A review last year by the Federal Trade Commission of 400 popular children’s apps available on Google and Apple platforms concluded that only 20 percent disclosed their data collection practices.

The code of conduct would require participating mobile app developers to show notices indicating whether their apps collected user-specific details in any of eight categories: biometrics, including fingerprints or facial recognition data; Web browsing history; logs of phone calls or texts made or received; contact list details like e-mail addresses or social network connections; financial information, like credit or banking data; health or medical data; precise location data; and stored text, video or photo files.

Signatories to the code would also have to list any of eight categories of entities with which their apps shared information; these include ad networks; mobile carriers; consumer data resellers; data analytics companies; government entities; operating systems; social networks; or other apps.

Companies that violated a promise to adhere to the code would be subject to enforcement action by the Federal Trade Commission. The code is the first step in a larger plan by the Obama administration to institute a wide-ranging consumer privacy bill of rights that would give consumers some rights to access, control and correct the personal details companies collected about them.

Last year, the White House issued a report proposing that Congress enact such a consumer privacy bill. The report said the bill would rely on codes of conduct, worked out in industry-advocacy group negotiations, to specify how different industries would adhere to those principles. The administration has yet to make public the proposed text for the legislation.

But some participants who helped develop the mobile app transparency notices said the modest gains that resulted for consumers indicated a need for stronger privacy legislation and regulation.

“If we want to move expeditiously through bigger issues, we are going to need some legislative action,” said Christopher Calabrese, legislative counsel for privacy issues at the Washington office of the A.C.L.U.

Monday, June 3, 2013

Gadgetwise: Q&A: Pruning the Mac’s Font Collection

I’d like to weed out a bunch of unused fonts on my Mac OS X Lion computer. How do I safely delete them?

One way to remove unwanted fonts from Mac OS X (versions 10.5 and later, which includes the Lion 10.7 system), is to use the built-in Font Book program. Note that you cannot remove fonts that the Mac itself uses in the operating system. To get started, click the Mac desktop to switch to the Finder, click Go in the Mac’s menu bar and select Applications. (When you are in the Finder, you can also press Shift-Command-A on the keyboard to automatically open the Applications folder.)

Once inside the Mac’s Applications folder, open the Font Book app. In the program’s main window, click All Fonts in the far left column. In the Fonts column next to it, locate the name of the typeface you wish to remove and select it. Go to the File menu at the top of the screen and choose the option to remove that font family from the computer.

The Font Book program lets you view, organize and temporarily disable fonts on the Mac as well. Apple has a guide to using Font Book here.

Tuesday, February 26, 2013

Special Report: Technology and Innovation: Microsoft Inherits Sticky Data Collection Issues From Skype

BARCELONA — When Microsoft, the world’s largest software maker, bought Skype in May 2011 for $8.5 billion, it acquired not only the technology behind the world’s dominant Internet voice and video service, but a connection with more than 250 million active users.

But perhaps what Microsoft did not anticipate when it made the purchase was that it would inherit the delicate privacy aspects of Skype’s business, including its billions of encrypted, peer-to-peer Internet conversations.

Those conversations, and the access Microsoft grants to them, are now the focus of a lobbying campaign by 50 digital rights groups and dozens of individuals.

In a letter sent in January, the group asked Microsoft to disclose what data it collected from Skype users and whether that data was passed on — whether to potential advertisers or to law enforcement agencies conducting criminal investigations.

The group, a collection of Internet activists from around the world that includes the Electronic Frontier Foundation, Reporters Without Borders and Zwiebelfreunde, a German university group, called on Microsoft to begin publishing regular transparency reports listing the requests made by government agencies for Skype client information around the world.

Amid the pressure, there are signs that Microsoft may be preparing to relent and publish what are known as transparency reports, which disclose the level of government requests for information. Google has provided the reports since 2010. Since then, Twitter and LinkedIn, among others, have moved toward offering regular reports — but not Microsoft.

Besides public disclosures, said Eva Galperin, a global policy analyst at the Electronic Frontier Foundation, the group also wanted to know the location of Skype’s headquarters — whether in Luxembourg, as it was before it was acquired by Microsoft, or at Microsoft’s base in Redmond, Washington.

The location is important, Ms. Galperin said, because if Skype’s headquarters are in the United States, Microsoft and Skype would be required to comply with requests made by U.S. intelligence services under Calea, the Communications Assistance for Law Enforcement Act, which gives agencies easier access to monitor data from online businesses like Skype.

Internet activists in countries with authoritarian regimes also need to know whether their Skype conversations, once considered a hack-proof way of avoiding government phone wiretaps because of the peer-to-peer nature of the exchanges, are still secure, she said.

“What we know right now is that we don’t know,” said Paul Bernal, a lawyer and professor of technology, intellectual property and media law at the University of East Anglia in Norwich, England, one of 61 individuals who also signed the open letter to Microsoft.

“We need to know how Microsoft and Skype cooperate with law enforcement and others around the world,” Mr. Bernal said. “People living under authoritarian regimes need to know what kinds of personal risks they are taking when using Skype.”

Dominic Carr, a Microsoft spokesman in Redmond, said that Skype’s headquarters, even after the purchase, remained in Luxembourg and the company was subject to laws of Luxembourg and the European Union, not the United States.

Luxembourg, like other E.U. countries, has mutual assistance pacts and other legal mechanisms that permit companies like Microsoft to share information with foreign law enforcement agencies in continuing investigations. The purchase of Skype by Microsoft has not changed the ability of law enforcement to gain access to Skype data, Mark Gillett, a corporate vice president responsible for Skype engineering and operations, wrote in a blog post.

According to Microsoft’s published privacy policy, three types of information are generated by Skype: personally identifiable information on users; nonidentifiable information; and the actual contents of Skype-to-Skype audio and video conversations.