Showing posts with label technology. Show all posts
Showing posts with label technology. Show all posts

Thursday, July 21, 2022

Panel calls for ending data dumps without a search warrant

A new law is needed to stop state, local and federal law enforcement and intelligence agencies from surveilling wide swathes of the U.S. population without a warrant, said panelists during a recent federal hearing, according to Government Technology.

The Fourth Amendment’s privacy protections require law enforcement to obtain a warrant before searching individuals’ personal records — and this definition should include their digital footprints, said Brett Tolman, executive director of Right on Crime, a group that advocates for “conservative criminal justice solutions.” Such requirements ought to prevent law enforcement from gathering extensive data collections on broad populations without first establishing probable cause, he said.

But agencies repeatedly skip getting permission to collect data themselves and instead purchase it from data brokers — essentially, a loophole, said panelist Bob Goodlatte, senior policy adviser for the nonpartisan advocacy group Project for Privacy and Surveillance Accountability.

“Agencies ranging from the Defense Intelligence Agency to the IRS to, likely, the FBI and CIA as well, are buying the personal data of millions of Americans they would otherwise have to get a warrant to obtain,” said Goodlatte.

Brokers sell vast data compilations that may include details like job histories, home addresses, voting records and more, and data broker LexisNexis alone contracts with more than 1,300 state and local law enforcement agencies, said Sarah Lamdan, law professor at The City University of New York School of Law.

Such practices can open the door to privacy invasions and wrongful arrests.

Rep. Jamie Raskin (D-MD) summarized calls to ban law enforcement from making such purchases:

“This is essentially the meta technological equivalent of saying that, if the government can't enter your home without a search warrant, they can't pay somebody who breaks into your home or otherwise gains access through some kind of duplicity [like] saying that they're a carpenter.”

'IT INVITES ABUSE'

Panelists and House representatives from both parties said that government purchasing collections and analyses of resident data without first establishing probable cause is unjustifiably invasive and enables governments to subject particular demographic groups and political parties for oversurveillance and arrest.

“It invites abuse, in particular, the targeting of people or groups based on race, religion or political activity,” said Elizabeth Goitein, senior director of the Brennan Center for Justice’s Liberty and National Security Program.

The discussion took place against the backdrop of the Dobbs decision, which has sparked fears that states criminalizing abortion might seek out anyone considering the procedure by collecting data from residents’ web searches, period apps and cellphone geolocation information. And warrantless data tracking and collection can affect people across all ideological and political divides, Goodlatte said, noting government could just as readily monitor people visiting gun stores.

Police data purchases raise concerns in the courtroom, too, according to Rebecca Wexler, an assistant professor of law and co-director of the Berkeley Center for Law and Technology. Current practices can tip the scales against criminal justice defendants. That’s in part because law enforcement and defense often get less insight into any potentially game-changing flaws and biases in third-party gathered data, causing them to miss context that could invalidate evidence.

A LEGISLATIVE FIX?

Many panelists recommended passing a federal privacy law restricting how and when private firms collect all this personal data in the first place. But that’s a larger task, and legislators should also push a quicker, targeted fix: passing the Fourth Amendment Is Not For Sale Act, panelists said. That measure would compel government to follow the spirit of existing rules, closing loopholes and updating policies to better reflect modern realities.

The act would bar law enforcement and intelligence agencies from buying customer and subscriber records or information collected illegally. And if agencies nonetheless violate this rule, they’d be forbidden to use that information as evidence in court or other proceedings.

The act also limits government’s ability to force companies to hand over such data. It says that if governments would - under current law - need a court order to get certain records from an electronic communications or remote computing services provider, then they’d also need a court order to get such records from a third party. That means officers who fail to get a judge’s approval to compel a telecom to share records could not just turn around and force that information out of a data broker the telecom sold the records to — unless officers first get a judge’s go-ahead.

“The government cannot obtain records from companies like Facebook and Google without a court order. Why should data brokers be treated any differently?” Goodlatte said.

EXISTING RULES

Goodlatte said there’s nothing necessarily wrong with agencies gathering personal data on suspects, so long as they follow the rules and show probable cause first. The process of seeking a warrant forces agencies to justify why they want the data, which helps catch situations in which unconscious or conscious prejudices — not genuine need — drive the quest for data on a particular group, Goitein said.

Speakers like Rep. Andy Biggs (R-AZ) also worried about the kind of data government can get through warrants. He cited a 2019 incident in which Gainesville, Fla., police used a warrant to make Google share data about all devices near the site of a break-in. This led them to wrongfully suspect a resident, because Google had tracked his phone passing by the house on his regular biking route.

SKEWED JUSTICE?

Criminal defense attorneys have the right to see evidence the other side has collected that could exculpate the defendant. For example, defendants ought to know if quality control errors make the data unreliable and if the software used to collect the data is skewed by bias or other issues, Wexler said. Government also generally cannot present illegally obtained evidence, and Wexler said defendants should learn if data was gathered “in violation of a privacy statue, or through breach of contract or through unlawful hacking,” she said.

But police buying information from data brokers are unlikely to know its limits or how it was gathered.

“When law enforcement purchases data from intermediaries, or uses private biometric databases, or licenses surveillance software from private companies, the officers can stay ignorant of flaws in the data,” Wexler said.

Defendants cannot discover such context through cross-examining police, if officers simply don’t know anything about their data brokers’ practices. Another hurdle: Firms are unlikely to voluntarily share information about their product, and defendants have limited abilities to compel them to through subpoenas, Wexler said. Some surveillance technology vendors also only sell to law enforcement, which blocks criminal defense from purchasing copies of the tools to test them for accuracy.

Evening out the playing field between prosecution and defense could require policies strengthening criminal defense’s subpoena powers, Wexler said.

WHAT IS 'VOLUNTARY'?

Laws crafted in the technological climate of the 1970s state that residents cannot expect to keep information private if they share it “voluntarily” — such as personal details shared with a bank when opening an account. But panelists say the interpretation of “voluntary” needs updating to match today’s realities.

Many personal data collected on people isn’t something they’re really giving up voluntarily, in an age when fully participating in society requires driving on roads with license plate readers and using cellphones that tightly track users, Lamdan said.

Plus, users of app and other digital services may not be able to give truly informed consent about data sharing. Company policies can be misleading, and customers who knowingly share information with a particular company have no control over whether and to whom that company then resells the data, Goitein said.

Users are also often told their data is “anonymous,” but this veil of privacy can easily be broken when data brokers purchase the records and combine them with other details, said Lamdan. And even customers who try to opt out cannot escape companies creating profiles on them through information gleaned from friends, families and associates’ online activities.

The Supreme Court appeared to give a nod to some of these concerns in a 2018 ruling that said police need warrants to seize certain cellphone records that reveal their locations. The court felt phone owners ought to trust that their personal movements are private and that they weren’t actively choosing to share this data.

To read more CLICK HERE

Tuesday, June 14, 2022

Woman murders boyfriend after using digital tracker to discover affair

An alleged homicide in Indianapolis is raising tough questions about digital trackers that are marketed for convenience but sometimes used for stalking.  

Gaylyn Morris, who was arrested and accused of murder, allegedly told witnesses that she was tracking her boyfriend Andre Smith with an Apple AirTag because she suspected him of cheating on her, as my colleague Lindsey Bever reports.  

Apple markets its AirTag mini trackers as a way to locate easily lost items such as keys and wallets. But privacy advocates have long warned that AirTags and similar products are frequently used to track unsuspecting people.

Morris allegedly used the AirTag to locate Smith at a local pub where he was with another woman and a heated confrontation ensued. According to police, Morris is accused of running over Smith several times with a car, per the Indianapolis Star. He was pronounced dead at the scene.

The case highlights how seemingly innocuous tracking technology can potentially be used for nefarious purposes — especially by romantic partners and exes — sometime with tragic results.  

Apple has made significant reforms to reduce the danger of AirTag stalking — but critics say the changes are far from sufficient.  

Here’s a rundown:

AirTags make a periodic chirping noise to alert people to their presence.

The tags also pop up an alert when they’re in proximity to an iPhone or other Apple product for an extended period of time.

That alert previously only popped up after three days of proximity, but Apple announced earlier this year that it is significantly shortening that window. In a test run in March, Post tech columnist Geoffrey A. Fowler received an alert after just 45 minutes.

Similar tracking products offered by Samsung and the company Tile can be discovered in proximity to a phone by scanning with apps offered by the companies.

But those safeguards leave plenty of loopholes that can work to a stalker’s advantage. Geoffrey highlighted several of them.

The AirTag sound can be tough to hear if you’re in a noisy place.

The AirTag alerts also don’t automatically pop up if the person being tracked uses an Android or other non-Apple product.

There’s an Android app people can download to find AirTags in proximity to their phones. But, as with the apps that identify trackers offered by Samsung and Tile, this puts the onus on the victim who may have no reason to suspect he or she is being tracked.

Students at the Technical University of Darmstadt developed a single app that scanned for all the major trackers, Geoffrey notes, something the companies themselves haven’t done that would at least make the process easier for people who fear being tracked.

Asked for comment on the Indianapolis case, Apple referred back to its statement from a series of anti-tracking updates in February. Security and privacy advocates were quick to highlight the Indianapolis case as evidence that more security checks are needed. 

To read more CLICK HERE

Sunday, December 22, 2019

Do you have a smart phone, you're being followed

The New York Times data review didn’t come from a telecom or giant tech company, nor did it come from a governmental surveillance operation. It originated from a location data company, one of dozens quietly collecting precise movements using software slipped onto mobile phone apps. You’ve probably never heard of most of the companies — and yet to anyone who has access to this data, your life is an open book. They can see the places you go every moment of the day, whom you meet with or spend the night with, where you pray, whether you visit a methadone clinic, a psychiatrist’s office or a massage parlor.
The Times and other news organizations have reported on smartphone tracking in the past. But never with a data set so large. Even still, this file represents just a small slice of what’s collected and sold every day by the location tracking industry — surveillance so omnipresent in our digital lives that it now seems impossible for anyone to avoid.
It doesn’t take much imagination to conjure the powers such always-on surveillance can provide an authoritarian regime like China’s. Within America’s own representative democracy, citizens would surely rise up in outrage if the government attempted to mandate that every person above the age of 12 carry a tracking device that revealed their location 24 hours a day. Yet, in the decade since Apple’s App Store was created, Americans have, app by app, consented to just such a system run by private companies. Now, as the decade ends, tens of millions of Americans, including many children, find themselves carrying spies in their pockets during the day and leaving them beside their beds at night — even though the corporations that control their data are far less accountable than the government would be.
 “The seduction of these consumer products is so powerful that it blinds us to the possibility that there is another way to get the benefits of the technology without the invasion of privacy. But there is,” said William Staples, founding director of the Surveillance Studies Research Center at the University of Kansas. “All the companies collecting this location information act as what I have called Tiny Brothers, using a variety of data sponges to engage in everyday surveillance.”
In this and subsequent articles we’ll reveal what we’ve found and why it has so shaken us. We’ll ask you to consider the national security risks the existence of this kind of data creates and the specter of what such precise, always-on human tracking might mean in the hands of corporations and the government. We’ll also look at legal and ethical justifications that companies rely on to collect our precise locations and the deceptive techniques they use to lull us into sharing it.
Today, it’s perfectly legal to collect and sell all this information. In the United States, as in most of the world, no federal law limits what has become a vast and lucrative trade in human tracking. Only internal company policies and the decency of individual employees prevent those with access to the data from, say, stalking an estranged spouse or selling the evening commute of an intelligence officer to a hostile foreign power.
Companies say the data is shared only with vetted partners. As a society, we’re choosing simply to take their word for that, displaying a blithe faith in corporate beneficence that we don’t extend to far less intrusive yet more heavily regulated industries. Even if these companies are acting with the soundest moral code imaginable, there’s ultimately no foolproof way they can secure the data from falling into the hands of a foreign security service. Closer to home, on a smaller yet no less troubling scale, there are often few protections to stop an individual analyst with access to such data from tracking an ex-lover or a victim of abuse.
To read more CLICK HERE

Saturday, March 23, 2019

GateHouse: FBI uses secret tracking device in Cohen investigation

Matthew T. Mangino
GateHouse Media
March 22, 2019
This week the search warrants related to the investigation of Michael Cohen, President Donald Trump’s personal attorney, were unsealed. There is a treasure trove of tantalizing information in the 897 pages of documents released for public consumption.
One issue tucked away in a search warrant executed on April 8, 2018, deserves some attention. The warrant authorized investigators to “employ an electronic investigation technique” to locate two cell phones used by Cohen.
The FBI used a secret cell phone sweeping device to pinpoint Cohen’s location in New York City.
The device, known as a Stingray, tricks cell phones into sending their location information to the device that simulates a cell phone tower. The device tracked Cohen’s two cell phones to a pair of hotel rooms in Manhattan where he was temporarily residing with his family.
According to CBS News, it is not clear exactly what additional information law enforcement obtained from the Stingray. The device is also capable of collecting calls, text messages and even emails sent to and from cell phones.
However, the Stingray doesn’t just collect data from the target of an investigation. The device is capable of gathering information from multiple cell phone users throughout an entire neighborhood, building or, as in this case, a hotel. The increasing use of the Stingray has alarmed privacy rights groups.
If a Stingray is deployed without Court approval, the result may be a violation of the Fourth Amendment right to be free from unreasonable searches.
The Washington Post reported that Courts in Washington, D.C., Maryland, New York and California have ruled that using a Stingray without first obtaining a search warrant violates the Constitution.
The Federal Court of Appeals in Washington, D.C. excluded evidence in a criminal case which utilized Stingray technology without a search warrant. Judge Corinne A. Beckwith wrote, “Locating and tracking a cell-site simulator has the substantial potential to expose the owner’s intimate personal information.”
“A (Stingray) allows police officers who possess a person’s telephone number to discover that person’s precise location remotely and at will,” continued Beckwith.
The United States Supreme Court has reviewed technology used to locate a suspect by tracking the pings from a cell phone to a cell tower. “We decline to grant the state unrestricted access to a wireless carrier’s database of physical location information,” wrote Chief Justice John G. Roberts Jr. in 2018.
According to the Washington Post, the Court’s 5-to-4 ruling protects “deeply revealing” records from more than 400 million devices. The Constitution must take account of changes in technology, Roberts wrote, noting that digital data can provide a comprehensive, detailed - and intrusive - overview of private affairs that would have been impossible to imagine not long ago.
The Supreme Court made exceptions for emergencies like bomb threats and child abductions. “Such exigencies,” Roberts wrote, “include the need to pursue a fleeing suspect, protect individuals who are threatened with imminent harm or prevent the imminent destruction of evidence.” Those are the same emergency exceptions that exist for entering a home or dwelling without a search warrant.
In addition, Cohen investigators wanted the search warrant sealed because of the secret nature of the Stingray. The secrecy is not unique to the Cohen investigation. According to CBS News, the government has, in the past, withdrawn charges against criminal defendants rather than reveal information about the use of a Stingray.
As a result, it’s unknown how often Stingray technology is used. As reported by CBS News, the ACLU found 14 federal agencies that use the device and cataloged Stingray use by 75 agencies in 27 states and the District of Columbia.
Stingray technology is here to stay. Fortunately, the shroud of secrecy has been lifted and courts have begun to formulate appropriate protections.
Matthew T. Mangino is of counsel with Luxenberg, Garbett, Kelly & George P.C. His book The Executioner’s Toll, 2010 was released by McFarland Publishing. You can reach him at www.mattmangino.com and follow him on Twitter @MatthewTMangino.
To visit the column CLICK HERE


Friday, May 25, 2018

The appliances in your home are potential witnesses against you


As our homes keep getting smarter: law enforcement will treat your appliances as potential witnesses.
It seems new smart gadgets are introduced every week, reported The Marshall Project. There are smart TVs, which suggest the programs they think you’ll like. Smart refrigerators are equipped with interior cameras and UPC scanners that keep track of the items you stock in your refrigerator, and then reorder them as they run out. One brand of smart mattress “tracks over 15 factors about your sleep and health, including deep sleep, heart rate and respiratory rate,” according to its website.
“From a law enforcement or intelligence perspective, these are very valuable tools that can let them monitor or listen to individuals,” says Dale Watson, the FBI’s former executive assistant director, now a consultant.
“Smart devices are also kind of frightening,” Watson says. “What are the legal ramifications? The technology is moving so fast that the laws and courts haven’t caught up with it.”
One reason there aren’t clear legal guidelines has to do with the way smart homes work, which, some analysts contend, means they’re not protected by the Fourth Amendment. “The right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated,” the Amendment declares. Courts have ruled that means police can’t search your home, except in emergencies, without convincing a judge to sign a search warrant on the grounds that there’s “probable cause” they will find evidence of a crime.
But the Supreme Court and other courts have established a broad exception, called the “third party doctrine.” The government does not need a search warrant in most cases to get personal information that you’ve already shared voluntarily with somebody else, like a bank or internet provider or utility.
Well, smart devices in your home are constantly sharing your personal information with somebody else. This “internet of things” sends details about your food orders and sleep cycles and conversations with Alexa through your router and over the internet, usually to the manufacturer or a contractor. So some government officials argue that the third party doctrine applies and they can get that information just by asking for it. When “third party” companies balk, police in some states get the information by issuing a subpoena, no judge’s approval needed. 
For instance, San Diego Gas & Electric Company disclosed recently that government agencies subpoenaed data generated by smart meters at 480 homes and businesses last year. A company spokesperson would not disclose which agencies, but the company has given meter data before to the FBI and Immigration and Customs Enforcement, among others.
The Supreme Court hasn’t ruled yet on issues raised specifically by smart homes, but it is about to decide another case that could have a bearing on the issue. The question in Carpenter v. United States is, can the government get historical cell phone location data from your phone company without a warrant? If so, how far back into your history can it go? In resolving those questions, the justices might hint how strictly they want to protect other data generated by your smart meter and refrigerator.
as our homes keep getting smarter: law enforcement will treat your appliances as potential witnesses.
It seems new smart gadgets are introduced every week. There are smart TVs, which suggest the programs they think you’ll like. Smart refrigerators are equipped with interior cameras and UPC scanners that keep track of the items you stock in your refrigerator, and then reorder them as they run out. One brand of smart mattress “tracks over 15 factors about your sleep and health, including deep sleep, heart rate and respiratory rate,” according to its website.
“From a law enforcement or intelligence perspective, these are very valuable tools that can let them monitor or listen to individuals,” says Dale Watson, the FBI’s former executive assistant director, now a consultant.
To read more CLICK HERE

Thursday, August 22, 2013

Crowd-scanning facial recognition soon to be deployed

The Department of Homeland Security tested a crowd-scanning project called the Biometric Optical Surveillance System — or BOSS — last fall after two years of government-financed development.  The surveillance system would pair computers with video cameras to scan crowds and automatically identify people by their faces, reported the New York Times.

Although the system is not ready for use, researchers say they are making significant advances. That alarms privacy advocates, who say that now is the time for the government to establish oversight rules and limits on how it will someday be used.

The effort to build the BOSS system involved a two-year, $5.2 million federal contract given to Electronic Warfare Associates, a Washington-area military contractor with a branch office in Kentucky.
  
Significant progress is already being made in automated face recognition using photographs taken under ideal conditions, like passport pictures and mug shots. The Federal Bureau of Investigation is spending $1 billion to roll out a Next Generation Identification system that will provide a national mug shot database to help local police departments verify identities.
 
But surveillance of crowds from a distance — in which lighting and shadows vary, and faces tend to be partly obscured or pointed in random directions — is still not reliable or fast enough. The BOSS research is intended to overcome those challenges by generating far more information for computers to analyze.
 
The system consists of two towers bearing “robotic camera structures” with infrared and distance sensors. They take pictures of the same subject from slightly different angles. A computer then processes the images into a “3-D signature” built from data like the ratios between various points on someone’s face to be compared against data about faces stored in a watch-list database, the documents show.
 
To read more Click Here