INTRODUCING BEN WIZNER
REBECCA
LAFORGIA: What follows are two excerpts from the interview with Mr Ben
Wizner, who we're introduced to in week two. The interviews complement
the modules we have just completed, but they also introduce us to things
we are yet to cover. In the interviews he speaks to several
observations, one of them being around democracy. That even if mass
surveillance and security is often in technical terms, it is at its core
about democracy and democratic participation. In the second
observation, Mr Wizner speaks of the ongoing nature of this question
around mass surveillance and the importance of developing over time the
capacity to enter into democratic dialogue around mass surveillance. So
watch them both. They complement what we've covered, but they also
introduce us to concepts we're going to cover.
BEN WIZNER ON DEMOCRACY
BEN WIZNER: So, I think if we were to summarise what we've all learned in the last two years from Edward Snowden's revelations and the media's excellent reporting, it is that surveillance technologies have outpaced democratic controls. And that governments have placed mass surveillance ahead of cyber security. And I think that this is something that perhaps the broader public has not sufficiently understood. Which is that there's actually a tension between the government's surveillance efforts, which include creating and exploiting vulnerabilities in communication systems, and the government's cyber security mission which is aimed at protecting us from malicious attacks from hackers, from foreign governments, from criminals. That in effect, governments-- particularly the US government and the British government, but not only those two governments-- have made the strategic decision to weaken communication systems for everyone in order to facilitate mass surveillance. Not targeted surveillance of individuals who are suspected of wrongdoing, but mass passive collection of as many communications as they can intercept. So, that has been the primary message to the technology community. And of course, the response of the technology community has been impressively to bolster defences, to increase encryption, to raise the cost of mass surveillance. I think the message to the broader public-- not the technology community-- is as much one about democratic participation as it is about surveillance. This is what our governments did without consulting us. Now, we have subsequent concerns about these surveillance practices, but we also have procedural concerns about how something like this can happen in free societies without the public being consulted. And so, I think those are really two messages for the people of the world. First of all, how could something like this be done without our consent? Second of all, now that we have been brought in to the conversation with our governments, are we going to accept this?
BEN WIZNER ON MASS SURVEILLANCE
BEN WIZNER: I hope that citizens don't feel powerless in the face of this debate. Citizens have always known how to affect change, they just haven't always had the energy and motivation to make it so. We know how to mobilise. We know how to engage in public debates. If we sit this out, if we decide that these issues are too complicated then we know who's going to be shaping our future. It's going to be corporations who want to collect all of our information because that's their business model. It's going to be security agencies who want to collect all of that information because that's their natural tendency. It's in their nature. And if we leave the decisions to those powerful entities, over time that's going to be corrosive to our free societies. And so it's very, very important for common people to participate in this debate, to become more digitally literate, to understand how technology is shaping our lives, and to tell our elected officials that these issues are very, very important to us.
THE DEMOCRATIC QUESTION IN THE COLLECTION OF METADATA
REBECCA LAFORGIA: Surveillance is and always will be a political question. Who gets to look over your information? What do they get to do with it? Why are they looking at it? Surveillance is inherently about power. Now when that someone doing the surveillance is a state, it becomes at its very core, a question about the individual's relationship with the state. And that, by definition, is a political question. When we think about this issue, perhaps old metaphors come to mind, for example, the classic imagery of George Orwell's Nineteen Eighty-Four in which we imagine a big brother cruel in different arbitrary powerful and through surveillance controlling the moment of every individual's life turning them into fearful, small, disconnected, lonely beings. This historical image of the relationship, the risks of surveillance doesn't quite work in modern day society. And there's two reasons why. First of all, in some ways we desire and need the big brother to look over us. There are legitimate reasons for surveillance. There are security threats which require surveillance. This is accepted. So the image of big brother becomes slightly reworked. It's got a level of consent. In some ways, we do need an element of surveillance. Secondly, unlike the very fearful individuals that were leading small lives because they knew they were being watched, our lives are often large and performative. We are performing like never before on the internet, and in need and in some ways and in some situations, we ourselves are using the internet to document and promote surveillance of the state itself to record human rights concerns and political concerns. So the difficulty therefore is working out how in the 21st century in the context of cybersecurity, metadata, extraterritoriality, which is surveillance beyond borders, how do we frame the politics of this question? What are our metaphors? What are we looking for if the old analogies don't quite fit? This section of the course will look to reports from the United Nations on surveillance and international human rights. The purpose of looking at these reports is to enable us to think about metadata and surveillance to give language and concepts from international law that can assist in understanding how surveillance, in particular of metadata, affects our relationship with the state. The political element is what gives urgency to the inquiry. I want to consider very briefly two quotes illustrating the politics in surveillance. Firstly, Ben Emmerson QC, who is the current special rapporteur on the promotion and protection of human rights and fundamental freedoms while countering terrorism reported to the General Assembly on counterterrorism and mass digital surveillance and metadata. In that report he stated that and I'm quoting, "The international community needs to squarely confront this revolution in our collective understanding of the relationship between the individual and the state." The General Assembly resolution 68/167 on the right to privacy in digital age also speaks about the politics affirming that previously leads to protecting rights which are, quote "One of the foundations of a democratic society." This course will be exploring the language, ideas, and concepts in international law for squarely confronting this challenge in the collective relationship between individual and the state.
This blog contains notes from different learning sites. This notes falls in Information Security, Cyber Security, Network Security and other Security Domain class. Any suggestion to make this site helpful is truly welcome :)
Showing posts with label Metadata. Show all posts
Showing posts with label Metadata. Show all posts
Sunday, September 6, 2015
Cyber101x Cyberwar, Surveillance and Security - Week 4 - Public justification in context of metadata
WHAT DOES PUBLIC JUSTIFICATION IN THE CONTEXT OF METADATA MEAN?
REBECCA LAFORGIA: This right to privacy is, of course, not absolute. But it does encompass mandatory requirements that the state is required to publicly justify its actions in the area of metadata and surveillance, and provide independent review. And let's consider in more detail the right to privacy itself. It's contained in Article 17, of the International Covenant on Civil and Political Rights, "that no one shall be subjected to arbitrary or unlawful interference with his or her privacy, family, home and correspondence ..." And it proceeds, "Everyone has the right to the protection of the law against such interference or attacks." Article 17 is described in the Special Rapporteur Mr Emmerson QC's report: "Article 17 of the International Covenant on Civil and Political Rights is the most important legally binding treaty provision guaranteeing the right to privacy at the universal level." The special rapporteur notes that among other requirements, Article 17 requires a lawful reason, or a legitimate aim for interference. It needs to be lawful, it needs to be proportionate. Each of these has their own meanings, and the report elaborates on this. I want to centre on two ideas. One, of the legitimate aim to interfere with privacy, and secondly the requirement that even if there is a legitimate aim, the state still has a requirement to justify its surveillance actions. Firstly, legitimate aim. The special rapporteur notes that "Terrorism can destabilise communities, threaten social and economic development, fracture the territorial integrity of states, and undermine international peace and security." And it is a legitimate aim to form a justification for the interference of the right to privacy, metadata and surveillance. However, even if collection of metadata and surveillance is for this legitimate aim, nevertheless, there are requirements on the state that come from Article 17. This comes from the fact that the collection of information is so wide. And given its breadth, and the fact it operates not on suspicion, but preemptively, then the state must justify why it is collecting the information. This need for justification, given the breadth of the reach, is a significant legal requirement. It arises from proportionality. It is not an optional aspect where the state shares information or not. The justification is a central requirement of privacy itself. And I want to reiterate, this is because in the context of metadata and surveillance, it has moved from what the special rapporteur calls the small or the micro level, where an individual was under suspicion, to this macro level, in which there's a whole system, in which there is quote "wholesale interference with individual and collective privacy rights of all internet users", end quote. He suggests that because of this magnitude, then justification must be equally rigorous. It must be equally factually based, public. Without such justification, then a state is not in compliance with Article 17 of the international covenant. Let's think about it. Privacy was once small. It was about the state having perhaps a search warrant, judicial review. Privacy exceptions are now large. Preemptive collection across, in some cases, the world, of everyone's data. So, surveillance operates in an internal and an external mode. It's not limited to state borders. That is, it's extraterritorial. It requires justifications that are equally broad and encompassing. Justifications are a significant aspect of complying with the right to privacy under Article 17. They would need to be ongoing, clear, detailed, public. You may have had a visual imagery of privacy. Perhaps somebody sitting alone, somebody not intruding. But what we're increasingly seeing in privacy in the context of metadata and surveillance is it creates an obligation on the state to have a dialogue, to justify its surveillance to the citizen in ongoing, rational basis. And also to have independent review. So what is the core element of this justification? What would you be looking for from the state? In Australia, there was a committee which was looking at changes to a bill or a future law. And they made suggestions which are, I think, concrete and helpful for thinking about the notion of justification and what it might look like. And I'm just sort of paraphrasing here. There were suggestions that the cost of the scheme, that the implementation plan, should be made public. There should be categories, there should be breakdown of offences, there should be a clear indication of number of requests, there should be continual briefing. There should be an ability to have any potential improvements. Essentially, dialogue which relates to how the scheme is actually working. And an openness to mistakes, an openness to revisit it. It's important to reiterate that justification is not a luxury, it is a requirement of privacy. It will be ongoing, it'll be reflective. It will enable enough information for citizens to make a considered assessment. And it will document mistakes. Perhaps we can think about justification in another way. That was sort of pragmatic, and it was drawn from a committee. Think about justification as moving from what we might call 'security theatre' to actually justifying, rationally, public outcomes of metadata and surveillance. This idea of 'security theatre' is posited in a blog by Bruce Schneier. He starts with a story, and I'm paraphrasing somewhat here from the blog. He was visiting his friends. They had a baby. He noticed something interesting. He noticed that the infants had, essentially, tags attached to their ankles. And these were sensors. And if they would be abducted, then the alarm would go off. He then goes on to note that "Infant abduction is rare." He quotes a statistic. There have been in the last 22 years about 233 such abductions. About four million babies are born each year. And he says that the baby has a one in 375,000 chance of being abducted. He then goes on to compare this with the mortality rate in the US, which is one in 145. Quote, "and it becomes clear where the real risks are." He goes on, so why are hospitals bothering with our FID bracelets? I think they're primarily there to reassure the mothers. Quote, "Security is both a reality and a feeling." “The reality of security is mathematical, based on the probability of different risks and the effectiveness of different countermeasures.” He goes on to say that the tags are clearly a reassurance measure. He's not questioning this, he's observing. And he says, "Security is both a reality and a feeling." And importantly, this is further quoting from his site, "Of course, too much security theater and our feeling of security becomes greater than the reality, which is also bad. And others, politicians, corporations, and so on, can use security theater to make us feel more secure without doing the hard work of actually making us secure." End of quote. So justifications for the purposes of Article 17 are this hard work. If someone is reassuring you, speaking in authoritative tones, before a national symbol, whatever that may be, then chances are they're performing security theatre rather than the hard work of justification. Justification is detailed work, actually explaining the detailed, ongoing way the effects of extensive and, at times, limitless surveillance. It's explained to the public, and the public has an opportunity to question. It is a justificatory style dialogue. It is required under Article 17, the right to privacy. This is the constant and stable demand Article 17, the right to privacy, makes of the state.
Cyber101x Cyberwar, Surveillance and Security - Week 4 - Privacy in context of Metadata and Surveillance
Privacy in context of Metadata and Surveillance
DR REBECCA LAFORGIA: Surveillance is and always will be a political question. Who gets to look over your information? What do they get to do with it? Why are they looking at it? Surveillance is inherently about politics and power. Now, this political element is highlighted by UN reports which consider the right to privacy in the area of metadata and surveillance. Ben Emmerson, QC, is the current special rapporteur on the promotion and protection of human rights and fundamental freedoms while countering terrorism. And he reported to the General Assembly on counterterrorism and mass digital surveillance and metadata. He stated that "the international community needs to squarely confront this revolution in our collective understanding of the relationship between the individual and the State." Similarly, the General Assembly resolution located the right to privacy in the digital age in its political context. It affirmed that privacy leads to protecting rights which are, quote, "one of the foundations of a democratic society." The UN reports we will consider acknowledge that there is a core obligation that is relevant to rebalancing power and politics in mass digital surveillance, and that is the right to privacy. This right is contained in Article 17 of a treaty -- the treaty is the International Covenant on Civil and Political Rights. The Office of the High Commissioner for Human Rights notes, "The General Assembly resolution recalls international human rights law provides the universal framework against which any interference in individual privacy rights must be assessed." Before considering the content of the obligation, I want to reflect on the fact that the first and very important contribution which international human rights make, and privacy in particular provides, is stability. It's a way of engaging with this rapidly evolving world of metadata and surveillance. The United Nations reports from the Office of the High Commissioner for Human Rights and also from the special rapporteur that we will be considering were produced in 2014. And they were created due to increasing concerns as to the question of metadata surveillance and its relationship to privacy. Both reports do apply and interpret the international right to privacy in the context of this increasing surveillance through the collection of metadata. But the reports begin with a factual reality, that there is an increasing surveillance across the board. The High Commissioner for Human Rights notes, "Deep concerns have been expressed as policies and practices that exploit the vulnerability of digital communications technologies to electronic surveillance and interception in countries across the globe [have been exposed]. Examples of overt and covert digital surveillance in jurisdictions around the world have proliferated, with governmental mass surveillance emerging as a dangerous habit rather than an exceptional measure." I want to centre on this point. The reports consider the issue of metadata and surveillance as a global problem around the world, impacting both on citizens and on individuals outside of state borders, that is called extraterritorially. Through stepping back from a national perspective, the reports therefore frame the issue of increased surveillance as being subject to a universal right, to a conceptual idea that can apply to all and across the states, that of privacy. The effect of centering on core and stable rights, as contained in Article 17, is to produce a very important stabilisation of the debate around metadata and surveillance, which has the capacity to transcend the latest technology or surveillance scheme because often technology and covert actions seem relentless. For example, the special rapporteur reports and describes Prism and then Quantum. Consider his description of Quantum. "The agency is said to operate an internet exploitation mechanism called Quantum, which enables it to compromise third-party computers. The methodology reportedly involves taking secret control or ownership over servers in key locations on the backbone of the internet. By impersonating chosen websites (including such common sites as the Google search page), Quantum is able to inject unauthorised remote control software into the computers and Wi-Fi-enabled devices of those who visit the clone site, who will, of course, have no reason to doubt the clone site's authenticity. Technology experts assess that this methodology can permanently compromise the user's computer, ensuring that it continues to provide intelligence to the National Security Agency in the United States indefinitely." He goes on, though, to consider a virus called the Ambassador's Reception. It's from the United Kingdom. Quote: "Subsequent disclosures have focused on the role of the Joint Threat Intelligence Group in Government Communications Headquarters. This agency is reported to have deployed a computer virus called the Ambassador's Reception for the purpose of online covert action. This virus is said to be able to encrypt itself and act as a chameleon imitating communications by other internet users." Consider this, the Prism, Quantum, the Ambassador's Reception. And these will be replaced, and maybe are being replaced now, by further technological advances and actions. One of the issues in engaging with such a relentlessly developing area of technology, with its, quite frankly, dramatic and intriguing descriptions, is a tendency of being swept along, following each development and revelation. Human rights language, its first contribution is to offer a stability in such a rapidly changing area and therefore to enhance the capacity to engage in the debate politically, to give stable language in contrast to the relentless evolution of technological advances. I want to illustrate this through an analogy exploring the same relationship between technology and development, and the importance of stable human rights language, but just from a different perspective for a moment. Consider the evolution of weaponry, the technological advances, for example, Predator Reaper drones creating increased capacity for targeting. However, no matter what the evolution of technology in terms of weaponry, the human right to life remains, the human right to life as a core foundation idea stabilising the relentless development of technology. It remains a constant benchmark. In the same way, metadata and surveillance, there are endless terms for surveillance actions. There will be more being developed even now. But at the same time, human rights stabilises this relentless evolution. And through considering the right to privacy, there is a way of engaging, despite technological advances. This is an important contribution to political engagement. It enables demands to be made on the state, consistently and coherently, in a rapidly evolving area.
Cyber101x Cyberwar, Surveillance and Security - Week 3 - Surveillance and National Security - Domestic Law
DOMESTIC CYBER SURVEILLANCE LEGISLATION
DR DALE STEPHENS: In this module, I will be discussing the domestic surveillance legislation that currently exists in Australia, the UK, and US. Understanding the nature of domestic legal frameworks will give a better appreciation of the values at play in this field of law, and create a basis for investigating the international cyber law standards that we will discuss later in this course. In respect to Australia, the federal Privacy Act was, among other reasons, implemented to reflect Australia's privacy responsibilities in accordance with the United Nations International Covenant on Civil and Political Rights and other international standards such as the OECD Guidelines on the Protection of Privacy and Transborder Flows of Personal Data. These privacy obligations regulate the management of personal information by a number of Australian government departments. The Australian intelligence and defence intelligence agencies are explicitly exempt from the direct provisions of the Privacy Act. These exemptions are accepted by bodies such as the Australian Law Reform Commission to be consistent with international standards that come with a number of corresponding safeguards within legislation, accountability processes, and oversight mechanisms that apply to intelligence and defence intelligence agencies. Metadata is often collected by Australian intelligence agencies in accordance with the Telecommunications (Interception and Access) Act. While metadata is not explicitly defined in Australian law, Section 172 of the federal Telecommunications (Interception and Access) Act 1979 negatively defines metadata as the supply of telecommunications data that does not disclose the contents or substance of the communication or document. Metadata is therefore, the information about a communication that remains after its contents are omitted. Requests by intelligence organisations to access existing metadata can be made by the Director General of Security, the Deputy Director General of Security, or an employee of the Australian Security and Intelligence Office, ASIO, or ASIO affiliate. The Telecommunications (Interception and Access) Act specifies that the information may be released if the request is aligned with a purpose of the relevant organisation and its activities. While warrants are not required to obtain metadata, the information available from this data is limited in order to protect the privacy interests of Australians. For example, telecommunication providers have traditionally only been required to provide records of calls that were traditionally maintained for billing purposes. Due to the development of online communication, internet service providers have similarly been obliged to provide IP addresses, sender, recipient, and time and date information for email communications. Again, it is important to note that for both traditional telephonic methods of communication and for online communication records, no content must be recorded or provided to law enforcement unless subject to a warrant. In Australia, there is a general prohibition against the interception of telecommunications. And this is enshrined within Section 7(1) of the Telecommunications (Interception and Access) Act 1979. This means that it is an offence to access stored content or intercept communications through a telecommunications system without the knowledge of the sender or recipient. There are, however, exceptions to this provision, including exceptions for intelligence gathering purposes. There are two warrant-based processes that allow for the interception of the content of communications under the Act. Firstly, there is the ability for the Australian government and state agencies to apply for a warrant from a judge or administrative appeals tribunal member. Additionally, in order for a security organisation to obtain a warrant for surveillance, a request may be made by the Director General of Security to the Attorney General in accordance with Section 9 of the Telecommunications (Interception and Access) Act. Section 9 requires that the Attorney General must be satisfied when granting the warrant that the proposed interception of communications will or is likely to assist the organisation in obtaining intelligence relating to security. Warrants must be similarly obtained to access stored content communications. In 2014, a bill of amendment was proposed to alter the Telecommunications (Interception and Access) Act. These amendments proposed that all service providers in Australia must keep standard records of telecommunications data for two years in order to support the investigation of crimes and threats to national security. Service providers will not be required to retain the content or substance of communications, including posts on social media or email subject fields. The retention of web browsing history is expressly excluded, and there is no requirement to keep detailed location records, avoiding captured data being utilised as a location surveillance device. Turning now to the United Kingdom, two of the most important pieces of legislation pertaining to surveillance in the UK are the Data Retention and Investigatory Powers Act 2014 and the Regulation of Investigatory Powers Act 2000. Under Section 1(1) of the Data Retention and Investigatory Powers Act 2014, the United Kingdom's Secretary of State may require a public telecommunications operator to retain relevant communications data if the UK's Secretary of State considers that the requirement is necessary and proportionate for a purpose that falls within Section 22(2) of the Regulation of Investigatory Powers Act 2000. In particular, Section 22(2) of the Regulation of Investigatory Powers Act 2000 states that obtaining communications data may be deemed necessary in the interests of national security, for the purpose of preventing or detecting crime, or of preventing disorder, in the interest of public safety, or for any purpose not specifically mentioned in Section 22 which is specified for the purposes of subsection 22 by an order made by the Secretary of State. Communications data is defined in the Regulation of Investigatory Powers Act 2000 as any information which includes none of the contents of a communication and is about the use made by any person of any postal service or telecommunication service. A retention notice issued by the Secretary of State may require the retention of all data or any description of data. This notice will specify the period or periods for which data is to be retained. In the United Kingdom, 12 months is currently the maximum period for which data is to be retained under a retention notice. Turning now to legislation in the United States. It is important to acknowledge that there is a significant political debate regarding the classification of metadata collection in the United States. This comes partly through the US constitutional guarantees regarding search and seizure provisions, and whether these provisions, which traditionally related to physically breaking into citizens' homes, can apply in a digital world and to the collection of metadata. Congress established the Foreign Intelligence Surveillance Court in 1978 in accordance with the Foreign Intelligence Surveillance Act of 1978. The court's function is to assess applications made by the US government for electronic surveillance, physical search, and investigative actions for foreign intelligence purposes. In recent times, metadata has been collected in the US in accordance with inter alia Section 215 of the US Patriot Act, which amended the Foreign Intelligence Surveillance Act. The Patriot Act has been interpreted by the US government to authorise on warrant from the FISA court the storage of bulk telephony metadata within the US. Section 215 of the Patriot Act requires there be reasonable grounds to believe that the metadata accessed under the provision is relevant to an authorised national security investigation. The metadata collected includes the numbers of both recipient and outbound caller, the time of calls, and the date of calls. Orders for the collection of metadata are generally authorised ex parte to ensure the success of operations. Mass data collection by the United States government allows security organisations to find patterns and connections, aiming to detect threats and helping the government to rapidly identify terrorist operatives and networks. We heard in an earlier module Mr Renn Gade of the US National Counterterrorist Center speak to the usefulness of this data in the NCTC's mission. A general prohibition against government access to the content of communications exists in the United States. However, similar to the other domestic regimes I have discussed in this module, this prohibition is subject to a number of exceptions. The first exception exists when a warrant is issued by a federal judge on finding of probable cause that an individual has committed, will commit, or is committing a crime. And that communications intercepted will relate to the crime. The second exception exists when a warrant is issued from a judge of the FISA court for the purpose of surveilling an agent of a foreign power who is inside the United States, including individuals engaged in international terrorism, for the purpose of obtaining foreign intelligence information. Executive Order 12333 specifies the missions and authorities of each element of the intelligence community and sets out principles that aim to strike the appropriate balance between personal privacy and the collection of information for intelligence purposes. To briefly summarise this module, it is clear that the collection of metadata is lawful under Australian, UK, and US domestic legislative regimes. If a government or intelligence agency wishes to access the content of communications rather than just the metadata, a further set of requirements need to be met, usually in the form of obtaining a warrant. While the specifics of these warrant applications differ from state to state, it is evident that all three states share the notion that both metadata and the content of communications should be accessible to intelligence agencies in the interests of national security, but only if it is deemed reasonable and necessary that they are allowed access to that information. Clearly, there is a constant drive for balance between the privacy of citizens and the protection of national security within the domestic legislation that I have discussed.
METADATA SUCCESS
DALE STEPHENS: The importance of metadata collection for the purposes of national security is clear when one reviews the successful use of metadata. The metadata may be used exclusively to ground an investigation or more likely in conjunction with other information, possibly through the obtaining of a warrant that facilitates the capture of key information that acts to successfully thwart attacks or other criminal activity. Significantly, it is useful to remember that operations involving the use of metadata are not always disclosed to ensure that national security capabilities are not revealed. Despite this, a handful of successful operations in many countries have been disclosed over recent years and provide significant insight into the capabilities of metadata as part of the tools of an effective national security process. In Australia, authorities report that they have a strong history of damaging terrorist plots with the aid of metadata. For example, it is now public knowledge that the targeted retention of metadata by the Victorian police, the Australian Security Intelligence Organisation, and the Australian Federal Police over 16 months through Operation Pendennis disrupted a terrorist plot against the 2005 AFL Grand Final. Additionally, the Attorney General stated in December, 2013 that Australia's intelligence in the form of metadata has also helped to prevent at least four attacks in Southeast Asia in the last decade and contributed to the arrest of over 20 terrorists in Southeast Asia. In the United States, officials have acknowledged that metadata has been key to thwarting threats to national security. While details of thwarted plots are scarce in order to protect ongoing national security operations, three examples have been publicly disclosed in recent times. It has been acknowledged that NSA provided phone records led authorities to identify a terrorist financier in San Diego. The financier was arrested in 2007 after the analysis of relevant metadata. Metadata compiled by the NSA was also used to thwart a 2009 plot to attack and cause serious damage to the New York City subway system. Once the source of the plot had been established, the phone records collected relating to the perpetrator led investigators to his terrorist associates in other US states. Finally, a plot to bomb the New York Stock Exchange was thwarted in its early stages because the NSA was able to identify an extremist in Yemen who was in touch with a man in Kansas City. This web of linked metadata communications enabled investigators to identify co-conspirators and prevent an attack. While, for obvious reasons, public information about the success of metadata collection is scarce, it is clear that both serious criminal offences and terrorist attacks have been thwarted through the aid of metadata, many of which undoubtedly would not have even been known about until it was too late. The secrecy surrounding the gathering and success of metadata collection does often draw criticism. However, similar to more traditional forms of warfare and the secrecy of these operations, it appears obvious that strategic plans and operations should remain as confidential as possible to ensure that national security is not compromised and the tactical capabilities of the state are not exposed. There seems to be significant debate about the efficacy of cyber surveillance and particularly that pertaining to metadata collection and analysis. For some, while accepting the need for national security measures, it represents too invasive a step. Bruce Schneier, who has already been featured in this MOOC, regards these measures as a very costly insurance policy of negligible effectiveness. But for others, they see the value in maintaining such capabilities. We have previously heard Mr Renn Gade of the National Counterterrorism Center speak to the value of such information and its utility in maintaining national security.
THE NATURE OF THE CONTEMPORARY THREAT
[...contemporary threat] DALE STEPHENS: It is abundantly clear that we live in a world that grapples with new threats to our security. Our cyber capacities have allowed us unlimited opportunities for collaboration, for prosperity, for efficiencies, and for building personal and professional networks. They also represent enormous vulnerabilities. The emergence of the non-state actor in the world of terrorist threat represents a particular challenge rarely faced in the past. Non-state actors have the means to exploit and use cyber networks to deliver their deadly agenda. Security agencies have been compelled to react quickly, and to develop means to counter these existing and emerging threats. This module will start with an outline of the role of the US National Counterterrorism Center. The NCTC was established after 9/11 to coordinate and facilitate the exchange of valuable intelligence between US agencies in order to prevent any future attacks on the US. To that end, Mr Renn Gade, the senior legal counsel to the NCTC, will outline the role and capacities of the NCTC, as well as its background. RENN GADE: The terror attacks of 9/11 prompted the creation of NCTC. If you recall the conclusions of the 9/11 Commission Report-- they concluded that there was a lack of interagency coordination and cooperation, so that forced the creation of the National Counterterrorism Center. Our core missions are derived primarily from our founding statute, other laws, and intelligence directives. If I can, I'll read our mission statement, and I think that'll be a pretty good summary of what we do. I'll go into a little bit greater detail then. The mission statement is, "Lead our nation's effort to combat terrorism at home and abroad by analysing the threat, sharing that information with our partners, and integrating all instruments of national power to ensure unity of effort." Now, what that really means is that on a daily basis our joint operation centre conducts three times a day secure VTCs [video teleconferences] across the interagency, across the intelligence community, to share that information. What that really means is that it operates as a partnership of organisations-- DOD, FBI, Central Intelligence Agency, State Department, and other agency partners. DALE STEPHENS: While a uniquely US agency, many other countries have similar agencies to the NCTC that seek to identify the nature of emerging threats, so as to enable a timely response to any attack. Listen to Mr Gade as he describes the nature of the collection effort, and the effect the Snowden disclosures have had on this effort. RENN GADE: Well I've already referred to the 9/11 Commission Report, but if you remember the 9/11 Commission Report there was a tremendous amount of information that was out there, and the inability of various parts of government to put that information together, so acting on that, then, in October, 2001 Congress passed the Patriot Act. And the idea behind that was to break down the artificial wall between intelligence and law enforcement. So writ simple, that's what that's about. Now since then, of course, it's been reauthorised several times. Next time it will come up is in 2015 for reauthorisation. We've talked -- there are many tools, not just the Patriot Act -- that we've developed since 9/11. We've talked a little bit about the Patriot Act, but as it relates to NCTC it's important to remember that we are-- our statutory mission is -- to serve as the central insured knowledge bank of all known suspected terrorists. So Patriot Act is one part of that tool that's shared across various parts of government. It would be derelict of me if I didn't talk a little bit at this time about the current environment. As you know there have been a number of unauthorised disclosures. And the environment that we're in from a counter-terrorism perspective is increasingly challenging, partly as a result of unauthorised disclosure from Mr Snowden and others. But what we've seen is that terrorists are adapting-- changing their tactics-- to avoid our intelligence collection as a result of the leaks and disclosures. They understand better now, and they watch very closely, to see the scope and scale-- of not just US collection, but generally Western collection efforts. And they are changing their capabilities in a way-- in the way they communicate. They're adopting encryption technologies, shifting accounts-- most recently you know the Paris attacks you saw that one of the attackers had 13 phones. That's a pretty good example in open source about how folks are changing their techniques and tactics. Or, even worse for us, avoiding electronic communications altogether. So in areas where we have, in many cases, limited human intelligence collection, the ability to-- and our dependence on-- intercepted communications is incredibly important to our ability to identify and disrupt those plots. Going back to the 9/11 Commission Report, if we-- we can't connect the dots unless we can collect the dots. And that's what we're seeing right now is the increasing difficulty to collect the dots. DALE STEPHENS: The task is not just to identify patterns and behaviour, but to understand the behaviour in the first place. Listen carefully again to Mr Gade as he further explains the work of the NCTC in relation to metadata-- and poignantly notes that the issue is not just joining the dots, but also identifying the dots in the first place. RENN GADE: Well I think you understand the tactical definition of metadata that's been out in the press. But what we call metadata is otherwise called DRAS-- D-R-A-S-- and that's the dialling, routing, and signalling information. It does not involve the content, the substance, the purpose of that information whatsoever. So as it relates to NCTC, the NCTC is an aggregator of data, aggregator of information. So when we pull that data-- we get that data from elsewhere, from other agencies, the same protections that were applicable to those agencies are applicable to us. So whether it's by statute, court orders, internal regulations, oversight from Congress, the courts, that is all applicable to us from the originating source. Well it's one of the tools you rely on. Remember my last comment about connecting the dots, you have to collect the dots? Those are some of the dots that you have available in the universe of information-- is that metadata. DALE STEPHENS: Finally, while a compelling case can be made for government agencies to have the capacity to collect data relevant to emerging or actual threats to national security, it is important to keep in mind the need for public trust in this activity. The collection of information that can have personal implications necessarily raises a level of anxiety in rational thinking people. Listen, then, as Mr Gade discusses this issue, and speaks to the recognition of agencies like the NCTC to these values. RENN GADE: Well let me start by saying that the NCTC doesn't have any interest in what grandma says on the phone. None. The thought that NCTC or that interagency partners have an interest in what grandma says on the phone, what she purchases, what book she reads, is absolutely preposterous. But your question isn't directed necessarily at NCTC, it's directed at the US government in general. And since those unauthorised disclosures, we've had many of those questions. And if you can put that-- the answer in kind of a historical analysis, I think it's useful. If you take a look at privacy, nobody talked about the right to privacy until the end of the 19th century. You know this probably, but it wasn't until a 1890 article that Louis Brandeis-- later Supreme Court Justice Brandeis-- talked about the right to privacy. Previously the right of privacy was thought about, you know, with peeping toms or something like that. But technology brought about changes and he addressed that in his 1890 article talking about that, and it was addressed to technology of the day-- photographs and newspapers. Today citizens around the globe put troves of data out there for public consumption. Whether it's by way of e-commerce, social media, whatever it might be, we put that out there willingly. That's the way we do business, if you would, these days, and how we conduct our personal lives. Government access to that same information causes concern, for good reason, because of what the government-- whatever government-- can do to us. A little bit of a digression here as it relates to the Snowden disclosures. Nowhere in there is it to be found that there were any violations of law. Nowhere. These are not the FBI abuses-- Federal Bureau of Investigation abuses-- of the '60s and '70s. Nowhere out there are they in violations of law. So put that in context. I think the president last year-- little bit over a year ago now-- issued Presidential Policy Directive 28. And PPD 28 looks to address some of these fundamental concerns we have of privacy in the private sector, privacy in government as well. And the intent behind PPD 28 was to assure not only US citizens but people across the world of how data is handled, particularly in that case signals intelligence. So one last thing I might point to is, since those disclosures, there's been a concerted effort for greater transparency across the US government and across the intelligence community. I think that's true not only from a US perspective, but many of our partners as well. And those should be efforts in a really diverse, complex, and in many cases, violent world, where you're trying to balance privacy and protection. That's what we try to do every day.
DR DALE STEPHENS: In this module, I will be discussing the domestic surveillance legislation that currently exists in Australia, the UK, and US. Understanding the nature of domestic legal frameworks will give a better appreciation of the values at play in this field of law, and create a basis for investigating the international cyber law standards that we will discuss later in this course. In respect to Australia, the federal Privacy Act was, among other reasons, implemented to reflect Australia's privacy responsibilities in accordance with the United Nations International Covenant on Civil and Political Rights and other international standards such as the OECD Guidelines on the Protection of Privacy and Transborder Flows of Personal Data. These privacy obligations regulate the management of personal information by a number of Australian government departments. The Australian intelligence and defence intelligence agencies are explicitly exempt from the direct provisions of the Privacy Act. These exemptions are accepted by bodies such as the Australian Law Reform Commission to be consistent with international standards that come with a number of corresponding safeguards within legislation, accountability processes, and oversight mechanisms that apply to intelligence and defence intelligence agencies. Metadata is often collected by Australian intelligence agencies in accordance with the Telecommunications (Interception and Access) Act. While metadata is not explicitly defined in Australian law, Section 172 of the federal Telecommunications (Interception and Access) Act 1979 negatively defines metadata as the supply of telecommunications data that does not disclose the contents or substance of the communication or document. Metadata is therefore, the information about a communication that remains after its contents are omitted. Requests by intelligence organisations to access existing metadata can be made by the Director General of Security, the Deputy Director General of Security, or an employee of the Australian Security and Intelligence Office, ASIO, or ASIO affiliate. The Telecommunications (Interception and Access) Act specifies that the information may be released if the request is aligned with a purpose of the relevant organisation and its activities. While warrants are not required to obtain metadata, the information available from this data is limited in order to protect the privacy interests of Australians. For example, telecommunication providers have traditionally only been required to provide records of calls that were traditionally maintained for billing purposes. Due to the development of online communication, internet service providers have similarly been obliged to provide IP addresses, sender, recipient, and time and date information for email communications. Again, it is important to note that for both traditional telephonic methods of communication and for online communication records, no content must be recorded or provided to law enforcement unless subject to a warrant. In Australia, there is a general prohibition against the interception of telecommunications. And this is enshrined within Section 7(1) of the Telecommunications (Interception and Access) Act 1979. This means that it is an offence to access stored content or intercept communications through a telecommunications system without the knowledge of the sender or recipient. There are, however, exceptions to this provision, including exceptions for intelligence gathering purposes. There are two warrant-based processes that allow for the interception of the content of communications under the Act. Firstly, there is the ability for the Australian government and state agencies to apply for a warrant from a judge or administrative appeals tribunal member. Additionally, in order for a security organisation to obtain a warrant for surveillance, a request may be made by the Director General of Security to the Attorney General in accordance with Section 9 of the Telecommunications (Interception and Access) Act. Section 9 requires that the Attorney General must be satisfied when granting the warrant that the proposed interception of communications will or is likely to assist the organisation in obtaining intelligence relating to security. Warrants must be similarly obtained to access stored content communications. In 2014, a bill of amendment was proposed to alter the Telecommunications (Interception and Access) Act. These amendments proposed that all service providers in Australia must keep standard records of telecommunications data for two years in order to support the investigation of crimes and threats to national security. Service providers will not be required to retain the content or substance of communications, including posts on social media or email subject fields. The retention of web browsing history is expressly excluded, and there is no requirement to keep detailed location records, avoiding captured data being utilised as a location surveillance device. Turning now to the United Kingdom, two of the most important pieces of legislation pertaining to surveillance in the UK are the Data Retention and Investigatory Powers Act 2014 and the Regulation of Investigatory Powers Act 2000. Under Section 1(1) of the Data Retention and Investigatory Powers Act 2014, the United Kingdom's Secretary of State may require a public telecommunications operator to retain relevant communications data if the UK's Secretary of State considers that the requirement is necessary and proportionate for a purpose that falls within Section 22(2) of the Regulation of Investigatory Powers Act 2000. In particular, Section 22(2) of the Regulation of Investigatory Powers Act 2000 states that obtaining communications data may be deemed necessary in the interests of national security, for the purpose of preventing or detecting crime, or of preventing disorder, in the interest of public safety, or for any purpose not specifically mentioned in Section 22 which is specified for the purposes of subsection 22 by an order made by the Secretary of State. Communications data is defined in the Regulation of Investigatory Powers Act 2000 as any information which includes none of the contents of a communication and is about the use made by any person of any postal service or telecommunication service. A retention notice issued by the Secretary of State may require the retention of all data or any description of data. This notice will specify the period or periods for which data is to be retained. In the United Kingdom, 12 months is currently the maximum period for which data is to be retained under a retention notice. Turning now to legislation in the United States. It is important to acknowledge that there is a significant political debate regarding the classification of metadata collection in the United States. This comes partly through the US constitutional guarantees regarding search and seizure provisions, and whether these provisions, which traditionally related to physically breaking into citizens' homes, can apply in a digital world and to the collection of metadata. Congress established the Foreign Intelligence Surveillance Court in 1978 in accordance with the Foreign Intelligence Surveillance Act of 1978. The court's function is to assess applications made by the US government for electronic surveillance, physical search, and investigative actions for foreign intelligence purposes. In recent times, metadata has been collected in the US in accordance with inter alia Section 215 of the US Patriot Act, which amended the Foreign Intelligence Surveillance Act. The Patriot Act has been interpreted by the US government to authorise on warrant from the FISA court the storage of bulk telephony metadata within the US. Section 215 of the Patriot Act requires there be reasonable grounds to believe that the metadata accessed under the provision is relevant to an authorised national security investigation. The metadata collected includes the numbers of both recipient and outbound caller, the time of calls, and the date of calls. Orders for the collection of metadata are generally authorised ex parte to ensure the success of operations. Mass data collection by the United States government allows security organisations to find patterns and connections, aiming to detect threats and helping the government to rapidly identify terrorist operatives and networks. We heard in an earlier module Mr Renn Gade of the US National Counterterrorist Center speak to the usefulness of this data in the NCTC's mission. A general prohibition against government access to the content of communications exists in the United States. However, similar to the other domestic regimes I have discussed in this module, this prohibition is subject to a number of exceptions. The first exception exists when a warrant is issued by a federal judge on finding of probable cause that an individual has committed, will commit, or is committing a crime. And that communications intercepted will relate to the crime. The second exception exists when a warrant is issued from a judge of the FISA court for the purpose of surveilling an agent of a foreign power who is inside the United States, including individuals engaged in international terrorism, for the purpose of obtaining foreign intelligence information. Executive Order 12333 specifies the missions and authorities of each element of the intelligence community and sets out principles that aim to strike the appropriate balance between personal privacy and the collection of information for intelligence purposes. To briefly summarise this module, it is clear that the collection of metadata is lawful under Australian, UK, and US domestic legislative regimes. If a government or intelligence agency wishes to access the content of communications rather than just the metadata, a further set of requirements need to be met, usually in the form of obtaining a warrant. While the specifics of these warrant applications differ from state to state, it is evident that all three states share the notion that both metadata and the content of communications should be accessible to intelligence agencies in the interests of national security, but only if it is deemed reasonable and necessary that they are allowed access to that information. Clearly, there is a constant drive for balance between the privacy of citizens and the protection of national security within the domestic legislation that I have discussed.
METADATA SUCCESS
DALE STEPHENS: The importance of metadata collection for the purposes of national security is clear when one reviews the successful use of metadata. The metadata may be used exclusively to ground an investigation or more likely in conjunction with other information, possibly through the obtaining of a warrant that facilitates the capture of key information that acts to successfully thwart attacks or other criminal activity. Significantly, it is useful to remember that operations involving the use of metadata are not always disclosed to ensure that national security capabilities are not revealed. Despite this, a handful of successful operations in many countries have been disclosed over recent years and provide significant insight into the capabilities of metadata as part of the tools of an effective national security process. In Australia, authorities report that they have a strong history of damaging terrorist plots with the aid of metadata. For example, it is now public knowledge that the targeted retention of metadata by the Victorian police, the Australian Security Intelligence Organisation, and the Australian Federal Police over 16 months through Operation Pendennis disrupted a terrorist plot against the 2005 AFL Grand Final. Additionally, the Attorney General stated in December, 2013 that Australia's intelligence in the form of metadata has also helped to prevent at least four attacks in Southeast Asia in the last decade and contributed to the arrest of over 20 terrorists in Southeast Asia. In the United States, officials have acknowledged that metadata has been key to thwarting threats to national security. While details of thwarted plots are scarce in order to protect ongoing national security operations, three examples have been publicly disclosed in recent times. It has been acknowledged that NSA provided phone records led authorities to identify a terrorist financier in San Diego. The financier was arrested in 2007 after the analysis of relevant metadata. Metadata compiled by the NSA was also used to thwart a 2009 plot to attack and cause serious damage to the New York City subway system. Once the source of the plot had been established, the phone records collected relating to the perpetrator led investigators to his terrorist associates in other US states. Finally, a plot to bomb the New York Stock Exchange was thwarted in its early stages because the NSA was able to identify an extremist in Yemen who was in touch with a man in Kansas City. This web of linked metadata communications enabled investigators to identify co-conspirators and prevent an attack. While, for obvious reasons, public information about the success of metadata collection is scarce, it is clear that both serious criminal offences and terrorist attacks have been thwarted through the aid of metadata, many of which undoubtedly would not have even been known about until it was too late. The secrecy surrounding the gathering and success of metadata collection does often draw criticism. However, similar to more traditional forms of warfare and the secrecy of these operations, it appears obvious that strategic plans and operations should remain as confidential as possible to ensure that national security is not compromised and the tactical capabilities of the state are not exposed. There seems to be significant debate about the efficacy of cyber surveillance and particularly that pertaining to metadata collection and analysis. For some, while accepting the need for national security measures, it represents too invasive a step. Bruce Schneier, who has already been featured in this MOOC, regards these measures as a very costly insurance policy of negligible effectiveness. But for others, they see the value in maintaining such capabilities. We have previously heard Mr Renn Gade of the National Counterterrorism Center speak to the value of such information and its utility in maintaining national security.
THE NATURE OF THE CONTEMPORARY THREAT
[...contemporary threat] DALE STEPHENS: It is abundantly clear that we live in a world that grapples with new threats to our security. Our cyber capacities have allowed us unlimited opportunities for collaboration, for prosperity, for efficiencies, and for building personal and professional networks. They also represent enormous vulnerabilities. The emergence of the non-state actor in the world of terrorist threat represents a particular challenge rarely faced in the past. Non-state actors have the means to exploit and use cyber networks to deliver their deadly agenda. Security agencies have been compelled to react quickly, and to develop means to counter these existing and emerging threats. This module will start with an outline of the role of the US National Counterterrorism Center. The NCTC was established after 9/11 to coordinate and facilitate the exchange of valuable intelligence between US agencies in order to prevent any future attacks on the US. To that end, Mr Renn Gade, the senior legal counsel to the NCTC, will outline the role and capacities of the NCTC, as well as its background. RENN GADE: The terror attacks of 9/11 prompted the creation of NCTC. If you recall the conclusions of the 9/11 Commission Report-- they concluded that there was a lack of interagency coordination and cooperation, so that forced the creation of the National Counterterrorism Center. Our core missions are derived primarily from our founding statute, other laws, and intelligence directives. If I can, I'll read our mission statement, and I think that'll be a pretty good summary of what we do. I'll go into a little bit greater detail then. The mission statement is, "Lead our nation's effort to combat terrorism at home and abroad by analysing the threat, sharing that information with our partners, and integrating all instruments of national power to ensure unity of effort." Now, what that really means is that on a daily basis our joint operation centre conducts three times a day secure VTCs [video teleconferences] across the interagency, across the intelligence community, to share that information. What that really means is that it operates as a partnership of organisations-- DOD, FBI, Central Intelligence Agency, State Department, and other agency partners. DALE STEPHENS: While a uniquely US agency, many other countries have similar agencies to the NCTC that seek to identify the nature of emerging threats, so as to enable a timely response to any attack. Listen to Mr Gade as he describes the nature of the collection effort, and the effect the Snowden disclosures have had on this effort. RENN GADE: Well I've already referred to the 9/11 Commission Report, but if you remember the 9/11 Commission Report there was a tremendous amount of information that was out there, and the inability of various parts of government to put that information together, so acting on that, then, in October, 2001 Congress passed the Patriot Act. And the idea behind that was to break down the artificial wall between intelligence and law enforcement. So writ simple, that's what that's about. Now since then, of course, it's been reauthorised several times. Next time it will come up is in 2015 for reauthorisation. We've talked -- there are many tools, not just the Patriot Act -- that we've developed since 9/11. We've talked a little bit about the Patriot Act, but as it relates to NCTC it's important to remember that we are-- our statutory mission is -- to serve as the central insured knowledge bank of all known suspected terrorists. So Patriot Act is one part of that tool that's shared across various parts of government. It would be derelict of me if I didn't talk a little bit at this time about the current environment. As you know there have been a number of unauthorised disclosures. And the environment that we're in from a counter-terrorism perspective is increasingly challenging, partly as a result of unauthorised disclosure from Mr Snowden and others. But what we've seen is that terrorists are adapting-- changing their tactics-- to avoid our intelligence collection as a result of the leaks and disclosures. They understand better now, and they watch very closely, to see the scope and scale-- of not just US collection, but generally Western collection efforts. And they are changing their capabilities in a way-- in the way they communicate. They're adopting encryption technologies, shifting accounts-- most recently you know the Paris attacks you saw that one of the attackers had 13 phones. That's a pretty good example in open source about how folks are changing their techniques and tactics. Or, even worse for us, avoiding electronic communications altogether. So in areas where we have, in many cases, limited human intelligence collection, the ability to-- and our dependence on-- intercepted communications is incredibly important to our ability to identify and disrupt those plots. Going back to the 9/11 Commission Report, if we-- we can't connect the dots unless we can collect the dots. And that's what we're seeing right now is the increasing difficulty to collect the dots. DALE STEPHENS: The task is not just to identify patterns and behaviour, but to understand the behaviour in the first place. Listen carefully again to Mr Gade as he further explains the work of the NCTC in relation to metadata-- and poignantly notes that the issue is not just joining the dots, but also identifying the dots in the first place. RENN GADE: Well I think you understand the tactical definition of metadata that's been out in the press. But what we call metadata is otherwise called DRAS-- D-R-A-S-- and that's the dialling, routing, and signalling information. It does not involve the content, the substance, the purpose of that information whatsoever. So as it relates to NCTC, the NCTC is an aggregator of data, aggregator of information. So when we pull that data-- we get that data from elsewhere, from other agencies, the same protections that were applicable to those agencies are applicable to us. So whether it's by statute, court orders, internal regulations, oversight from Congress, the courts, that is all applicable to us from the originating source. Well it's one of the tools you rely on. Remember my last comment about connecting the dots, you have to collect the dots? Those are some of the dots that you have available in the universe of information-- is that metadata. DALE STEPHENS: Finally, while a compelling case can be made for government agencies to have the capacity to collect data relevant to emerging or actual threats to national security, it is important to keep in mind the need for public trust in this activity. The collection of information that can have personal implications necessarily raises a level of anxiety in rational thinking people. Listen, then, as Mr Gade discusses this issue, and speaks to the recognition of agencies like the NCTC to these values. RENN GADE: Well let me start by saying that the NCTC doesn't have any interest in what grandma says on the phone. None. The thought that NCTC or that interagency partners have an interest in what grandma says on the phone, what she purchases, what book she reads, is absolutely preposterous. But your question isn't directed necessarily at NCTC, it's directed at the US government in general. And since those unauthorised disclosures, we've had many of those questions. And if you can put that-- the answer in kind of a historical analysis, I think it's useful. If you take a look at privacy, nobody talked about the right to privacy until the end of the 19th century. You know this probably, but it wasn't until a 1890 article that Louis Brandeis-- later Supreme Court Justice Brandeis-- talked about the right to privacy. Previously the right of privacy was thought about, you know, with peeping toms or something like that. But technology brought about changes and he addressed that in his 1890 article talking about that, and it was addressed to technology of the day-- photographs and newspapers. Today citizens around the globe put troves of data out there for public consumption. Whether it's by way of e-commerce, social media, whatever it might be, we put that out there willingly. That's the way we do business, if you would, these days, and how we conduct our personal lives. Government access to that same information causes concern, for good reason, because of what the government-- whatever government-- can do to us. A little bit of a digression here as it relates to the Snowden disclosures. Nowhere in there is it to be found that there were any violations of law. Nowhere. These are not the FBI abuses-- Federal Bureau of Investigation abuses-- of the '60s and '70s. Nowhere out there are they in violations of law. So put that in context. I think the president last year-- little bit over a year ago now-- issued Presidential Policy Directive 28. And PPD 28 looks to address some of these fundamental concerns we have of privacy in the private sector, privacy in government as well. And the intent behind PPD 28 was to assure not only US citizens but people across the world of how data is handled, particularly in that case signals intelligence. So one last thing I might point to is, since those disclosures, there's been a concerted effort for greater transparency across the US government and across the intelligence community. I think that's true not only from a US perspective, but many of our partners as well. And those should be efforts in a really diverse, complex, and in many cases, violent world, where you're trying to balance privacy and protection. That's what we try to do every day.
Cyber101x Cyberwar, Surveillance and Security - Week 1 - The New Internet
CONCEALING YOUR IDENTITY ON THE INTERNET
BRUCE SCHNEIER: The old saying is that on the internet, nobody knows you're a dog. And these days, it's more like, on the internet, everyone knows exactly what kind of dog you are. It is becoming harder to change your identity. And if you're a woman, to have a male name and maybe be taken more seriously. Or if you're a member of a minority to use a more common name and be treated differently. That's incredibly valuable. Even taking an alias to explore a different aspect of yourself. If you're joining a support group at some time, you might not want to use your real name. This is becoming harder. It's incredibly important. We know that being able to shed the baggage of your identity, especially if you are from a minority class, is incredibly empowering. And that's something we shouldn't give up lightly.
HOW WE GIVE UP METADATA
BRUCE SCHNEIER: I mean, certainly, we give up metadata continuously willingly on our computers, on our phones. And every device we use these days is producing data and metadata sitting as the cloud. And in some ways, yes, we do it willingly. We accept Facebook, which is collecting enormous data and metadata about us, for free in exchange for that. Now you can argue that we're doing that as consumers willingly, but I'm not sure we're really doing it informed. I'm not convinced that we think in the morning, you know, I'm really happy my phone company is tracking my location 24/7 and maybe sharing that data with the government, because I love getting cell phone calls. We just think, I need my cell phone. So a lot of this data and metadata collection is hidden. It's not salient. We're not really thinking about it as it happens. So even though we're doing it willingly, I'm not convinced there's informed consent going on. I think that most of us believe, at some level, that we're maintaining our privacy. That if I go off and sneak around the corner, I'm thinking I'm sneaking around the corner. I don't think, well, the jig is up, because Apple knows where I am.
SOCIAL NORMS AND KIDS MAINTAINING PRIVACY
BRUCE SCHNEIER: It's interesting to see how social norms change. We are seeing changes that for now for kids, it's public by default private by effort. Kids still value privacy enormously. And if you're a teenager or know a teenager, you know that's true. Privacy from their peers, their teachers, their parents, they don't think about the government, but they certainly think about privacy. And kids spend a lot of effort trying to maintain their privacy. Whether it's using apps like Snapchat that delete things, or scraping their Facebook wall or using aliases, kids take a lot of pains to keep their privacy. They may not be sophisticated. They might not be able to maintain privacy against the government or foreign governments, but they are trying to maintain privacy. Even though it's harder, even though public is more of a default, privacy is an inherent human need. So I think we are in the middle of some profound social changes, but we're not going to move to a world where kids say oh I never had any privacy.
BRUCE SCHNEIER: The old saying is that on the internet, nobody knows you're a dog. And these days, it's more like, on the internet, everyone knows exactly what kind of dog you are. It is becoming harder to change your identity. And if you're a woman, to have a male name and maybe be taken more seriously. Or if you're a member of a minority to use a more common name and be treated differently. That's incredibly valuable. Even taking an alias to explore a different aspect of yourself. If you're joining a support group at some time, you might not want to use your real name. This is becoming harder. It's incredibly important. We know that being able to shed the baggage of your identity, especially if you are from a minority class, is incredibly empowering. And that's something we shouldn't give up lightly.
HOW WE GIVE UP METADATA
BRUCE SCHNEIER: I mean, certainly, we give up metadata continuously willingly on our computers, on our phones. And every device we use these days is producing data and metadata sitting as the cloud. And in some ways, yes, we do it willingly. We accept Facebook, which is collecting enormous data and metadata about us, for free in exchange for that. Now you can argue that we're doing that as consumers willingly, but I'm not sure we're really doing it informed. I'm not convinced that we think in the morning, you know, I'm really happy my phone company is tracking my location 24/7 and maybe sharing that data with the government, because I love getting cell phone calls. We just think, I need my cell phone. So a lot of this data and metadata collection is hidden. It's not salient. We're not really thinking about it as it happens. So even though we're doing it willingly, I'm not convinced there's informed consent going on. I think that most of us believe, at some level, that we're maintaining our privacy. That if I go off and sneak around the corner, I'm thinking I'm sneaking around the corner. I don't think, well, the jig is up, because Apple knows where I am.
SOCIAL NORMS AND KIDS MAINTAINING PRIVACY
BRUCE SCHNEIER: It's interesting to see how social norms change. We are seeing changes that for now for kids, it's public by default private by effort. Kids still value privacy enormously. And if you're a teenager or know a teenager, you know that's true. Privacy from their peers, their teachers, their parents, they don't think about the government, but they certainly think about privacy. And kids spend a lot of effort trying to maintain their privacy. Whether it's using apps like Snapchat that delete things, or scraping their Facebook wall or using aliases, kids take a lot of pains to keep their privacy. They may not be sophisticated. They might not be able to maintain privacy against the government or foreign governments, but they are trying to maintain privacy. Even though it's harder, even though public is more of a default, privacy is an inherent human need. So I think we are in the middle of some profound social changes, but we're not going to move to a world where kids say oh I never had any privacy.
Subscribe to:
Posts (Atom)