Showing posts with label Legislation. Show all posts
Showing posts with label Legislation. Show all posts

Monday, January 7, 2013

Slipstream: Legislation Would Regulate Tracking of Cellphone Users

THERE are three things that matter in consumer data collection: location, location, location.

E-ZPasses clock the routes we drive. Metro passes register the subway stations we enter. A.T.M.’s record where and when we get cash. Not to mention the credit and debit card transactions that map our trajectories in comprehensive detail — the stores, restaurants and gas stations we frequent; the hotels and health clubs we patronize.

Each of these represents a kind of knowing trade, a conscious consumer submission to surveillance for the sake of convenience.

But now legislators, regulators, advocacy groups and marketers are squaring off over newer technology: smartphones and mobile apps that can continuously record and share people’s precise movements. At issue is whether consumers are unwittingly acquiescing to pervasive tracking just for the sake of having mobile amenities like calendar, game or weather apps.

For Senator Al Franken, the Minnesota Democrat, the potential hazard is that by compiling location patterns over time, companies could create an intimate portrait of a person’s familial and professional associations, political and religious beliefs, even health status. To give consumers some say in the surveillance, Mr. Franken has been working on a locational privacy protection bill that would require entities like app developers to obtain explicit one-time consent from users before recording the locations of their mobile devices. It would prohibit stalking apps — programs that allow one person to track another person’s whereabouts surreptitiously.

The bill, approved last month by the Senate Judiciary Committee, would also require mobile services to disclose the names of the advertising networks or other third parties with which they share consumers’ locations.

“Someone who has this information doesn’t just know where you live,” Mr. Franken said during the Judiciary Committee meeting. “They know the roads you take to work, where you drop your kids off at school, the church you attend and the doctors that you visit.”

Yet many marketers say they need to know consumers’ precise locations so they can show relevant mobile ads or coupons at the very moment a person is in or near a store. Informing such users about each and every ad network or analytics company that tracks their locations could hinder that hyperlocal marketing, they say, because it could require a new consent notice to appear every time someone opened an app.

“Consumers would revolt if this was the case, and applications could be rendered useless,” said Senator Charles Grassley, the Iowa Republican, who promulgated industry arguments during the committee meeting. “Worse yet, free applications that rely on advertising could be pushed by the consent requirement to become fee-based.”

Mr. Franken’s bill may seem intended simply to protect consumer privacy. But the underlying issue is the future of consumer data property rights — the question of who actually owns the information generated by a person who uses a digital device and whether using that property without explicit authorization constitutes trespassing.

In common law, a property intrusion is known as “trespass to chattels.” The Supreme Court invoked the legal concept last January in United States v. Jones, in which it ruled that the government had violated the Fourth Amendment — which protects people against unreasonable search and seizure — by placing a GPS tracking device on a suspect’s car for 28 days without getting a warrant.

Some advocacy groups view location tracking by mobile apps and ad networks as a parallel, warrantless commercial intrusion. To these groups, Mr. Franken’s bill suggests that consumers may eventually gain some rights over their own digital footprints.

“People don’t think about how they broadcast their locations all the time when they carry their phones. The law is just starting to catch up and think about how to treat this,” says Marcia Hofmann, a senior staff lawyer at the Electronic Frontier Foundation, a digital rights group based in San Francisco. “In an ideal world, users would be able to share the information they want and not share the information they don’t want and have more control over how it is used.”

Even some marketers agree.

One is Scout Advertising, a location-based mobile ad service that promises to help advertisers pinpoint the whereabouts of potential customers within 100 meters. The service, previously known as ThinkNear and recently acquired by Telenav, a personalized navigation service, works by determining a person’s location; figuring out whether that place is a home or a store, a health club or a sports stadium; analyzing weather and other local conditions; and then showing a mobile ad tailored to the situation.

Eli Portnoy, general manager of Scout Advertising, calls the technique “situational targeting.” He says Crunch, the fitness center chain, used the service to show mobile ads to people within three miles of a Crunch gym on rainy mornings. The ad said: “Seven-day pass. Run on a treadmill, not in the rain.”

When a person clicks on one of these ads, Mr. Portnoy says, a browser-based map pops up with turn-by-turn directions to the nearest location. Through GPS tracking, Scout Advertising can tell when someone starts driving and whether that person arrives at the site.

Despite the tracking, Mr. Portnoy describes his company’s mobile ads as protective of privacy because the service works only with sites or apps that obtain consent to use people’s locations. Scout Advertising, he adds, does not compile data on individuals’ whereabouts over time.

Still, he says, if Congress were to enact Mr. Franken’s location privacy bill as written, it “would be a little challenging” for the industry to carry out, because of the number and variety of companies involved in mobile marketing.

“We are in favor of more privacy,” Mr. Portnoy says, “but it has to be done within the nuances of how mobile advertising works so it can scale.”

A SPOKESMAN for Mr. Franken said the senator planned to reintroduce the bill in the new Congress. It is one of several continuing government efforts to develop some baseline consumer data rights.

“New technology may provide increased convenience or security at the expense of privacy and many people may find the trade-off worthwhile,” Justice Samuel Alito wrote last year in his opinion in the Jones case. “On the other hand,” he added, “concern about new intrusions on privacy may spur the enactment of legislation to protect against these intrusions.”

E-mail: slipstream@nytimes.com.

Thursday, August 9, 2012

Bits Blog: Silicon Valley Sounds Off on Failed Cybersecurity Legislation

A cybersecurity bill that would have set security standards for the computer networks that govern the nation’s critical infrastructure was blocked by a Republican filibuster in the Senate on Thursday.

John McCain, the Republican Senator from Arizona, and other Republicans opposed the bill on the grounds that the standards would have been too onerous for corporations. In the weeks leading up to the Senate vote, a compromise was struck to make those standards optional. But on Thursday, following the filibuster, the Senate voted 52 to 46 to end debate on the bill, which fell eight votes short of the 60 it would have needed to pass.

In Silicon Valley, “regulation” is often treated like a four-letter word. But the Valley seems to have made an exception for cybersecurity, where a sort of Wild Wild West has taken hold. Criminals, “hacktivists” and government agents are able to have their way with few effective security technologies and regulations to stop them.

We contacted three Silicon Valley security experts to get their take on the bill, the cyber threat and the potential, as some have warned, for a 9/11-style cyberattack. They are Rob Rachwald,  director of security strategy at Imperva, a network security firm; Roger Thornton, the chief technology officer of AlienVault, a threat detection service; and Mark Seward, a senior security director at Splunk, a data security firm.

What was your take on the bill? Should it have passed?

Mark Seward: The bill went through a metamorphosis over time. At one point it had real teeth for industry. Then, there was compromise to remove that. The fact is, it’s needed.

Rob Rachwald: It wasn’t going to make any difference. The bill lost its teeth when it dropped the security mandate clause. The problem is that it was all sticks and no carrots. It included security mandates but it did not say, ‘We’re going to invest more in law enforcement, or create a central exchange where you can see where threats are coming from.’ It just said, ‘We’re going to impose a bunch of stuff on you.’ And then, ‘Actually, we’re going to make that voluntary.’ It lost its teeth. It became an empty suit.

What was the opportunity lost?

Mr. Seward: This is a huge setback. Frankly, every day we don’t pass legislation is a huge setback. It’s  the difference between whether we want to be a third world country or a first world country. I’ve traveled abroad and experienced power outages firsthand. The resilience of our infrastructure’s ability to resist an attack is the mark of a first world country. Not being able to trust that water is going to come out of the tap, or that when I light my stove natural gas is going to come out, is a real problem in a first world country. A cyberattack could literally mean that the things we most take for granted won’t be available.

Mr. Rachwald: After the standards became voluntary, it was a wash. The real opportunity loss was the fact that, at least initially, they wanted to build a centralized exchange between the public and private sectors for threat information. They weren’t clear how they were going to do it, but the fact they wanted to do it was important. If nytimes.com gets hacked by someone with ‘IP address 123’ it might look like an isolated incident. But if law enforcement could see that there was an attack from that IP address against multiple news sites, it would indicate that something much bigger was happening. That was the real opportunity missed here.

Roger Thornton: The fact is, intellectual property is being stolen from the industrial base at outrageous rates. Companies are getting broken into all the time. But the idea that there’s some kind of regulation — some sweeping mission to Mars — that is going to solve the whole thing overnight, well, that’s just not going to happen.

This regulation wouldn’t dramatically change the business of cybersecurity in my opinion. It would only build awareness — which is good. Maybe if it had passed 10 years ago, we might have avoided these problems. But now, it’s a different story.

Last week, Shawn Henry, the F.B.I.’s former top cybercop, warned of a 9/11-style cyberattack and said the public won’t take the threat seriously until they experience it firsthand. Is that fear-mongering? When do you think we will witness such an attack?

Mr. Seward: It’s my understanding that the Department of Homeland Security’s incident response team discovered that oil rigs are already under attack. But the fact that I can sit here and imagine scenarios where a key component, like water, might not be available to nuclear reactors is disconcerting. There are plenty of scenarios where the point at which two different parts of critical infrastructure intersect — like oil and gas pipelines, nuclear plants and water treatment facilities — could be jeopardized. All those things are interconnected. Our ability to have the society we have depends on the interconnection of those systems. An attack could happen tomorrow. It could happen next year. Or it could happen 10 years from now. There’s no predicting.

Mr. Rachwald: It’s always quote-unquote imminent. The point is, this legislation would have forced people to think about the threat much more seriously than they will otherwise.

Monday, August 6, 2012

Bits Blog: Silicon Valley Sounds Off on Failed Cybersecurity Legislation

A cybersecurity bill that would have set security standards for the computer networks that govern the nation’s critical infrastructure was blocked by a Republican filibuster in the Senate on Thursday.

John McCain, the Republican Senator from Arizona, and other Republicans opposed the bill on the grounds that the standards would have been too onerous for corporations. In the weeks leading up to the Senate vote, a compromise was struck to make those standards optional. But on Thursday, following the filibuster, the Senate voted 52 to 46 to end debate on the bill, which fell eight votes short of the 60 it would have needed to pass.

In Silicon Valley, “regulation” is often treated like a four-letter word. But the Valley seems to have made an exception for cybersecurity, where a sort of Wild Wild West has taken hold. Criminals, “hacktivists” and government agents are able to have their way with few effective security technologies and regulations to stop them.

We contacted three Silicon Valley security experts to get their take on the bill, the cyber threat and the potential, as some have warned, for a 9/11-style cyberattack. They are Rob Rachwald,  director of security strategy at Imperva, a network security firm; Roger Thornton, the chief technology officer of AlienVault, a threat detection service; and Mark Seward, a senior security director at Splunk, a data security firm.

What was your take on the bill? Should it have passed?

Mark Seward: The bill went through a metamorphosis over time. At one point it had real teeth for industry. Then, there was compromise to remove that. The fact is, it’s needed.

Rob Rachwald: It wasn’t going to make any difference. The bill lost its teeth when it dropped the security mandate clause. The problem is that it was all sticks and no carrots. It included security mandates but it did not say, ‘We’re going to invest more in law enforcement, or create a central exchange where you can see where threats are coming from.’ It just said, ‘We’re going to impose a bunch of stuff on you.’ And then, ‘Actually, we’re going to make that voluntary.’ It lost its teeth. It became an empty suit.

What was the opportunity lost?

Mr. Seward: This is a huge setback. Frankly, every day we don’t pass legislation is a huge setback. It’s  the difference between whether we want to be a third world country or a first world country. I’ve traveled abroad and experienced power outages firsthand. The resilience of our infrastructure’s ability to resist an attack is the mark of a first world country. Not being able to trust that water is going to come out of the tap, or that when I light my stove natural gas is going to come out, is a real problem in a first world country. A cyberattack could literally mean that the things we most take for granted won’t be available.

Mr. Rachwald: After the standards became voluntary, it was a wash. The real opportunity loss was the fact that, at least initially, they wanted to build a centralized exchange between the public and private sectors for threat information. They weren’t clear how they were going to do it, but the fact they wanted to do it was important. If nytimes.com gets hacked by someone with ‘IP address 123’ it might look like an isolated incident. But if law enforcement could see that there was an attack from that IP address against multiple news sites, it would indicate that something much bigger was happening. That was the real opportunity missed here.

Roger Thornton: The fact is, intellectual property is being stolen from the industrial base at outrageous rates. Companies are getting broken into all the time. But the idea that there’s some kind of regulation — some sweeping mission to Mars — that is going to solve the whole thing overnight, well, that’s just not going to happen.

This regulation wouldn’t dramatically change the business of cybersecurity in my opinion. It would only build awareness — which is good. Maybe if it had passed 10 years ago, we might have avoided these problems. But now, it’s a different story.

Last week, Shawn Henry, the F.B.I.’s former top cybercop, warned of a 9/11-style cyberattack and said the public won’t take the threat seriously until they experience it firsthand. Is that fear-mongering? When do you think we will witness such an attack?

Mr. Seward: It’s my understanding that the Department of Homeland Security’s incident response team discovered that oil rigs are already under attack. But the fact that I can sit here and imagine scenarios where a key component, like water, might not be available to nuclear reactors is disconcerting. There are plenty of scenarios where the point at which two different parts of critical infrastructure intersect — like oil and gas pipelines, nuclear plants and water treatment facilities — could be jeopardized. All those things are interconnected. Our ability to have the society we have depends on the interconnection of those systems. An attack could happen tomorrow. It could happen next year. Or it could happen 10 years from now. There’s no predicting.

Mr. Rachwald: It’s always quote-unquote imminent. The point is, this legislation would have forced people to think about the threat much more seriously than they will otherwise.