Showing posts with label internet spying. Show all posts
Showing posts with label internet spying. Show all posts

Saturday, March 15, 2014

Dragnet Nation


A lengthy excerpt from Dragnet Nation: A Quest for Privacy, Security and Freedom in a World of Relentless Surveillance by Julia Angwin, Pulitzer Prize winner, WSJ biz and tech writer, and now an investigative reporter for Pro Publica :
 Here’s How You May Already Be Getting Hacked

It's one thing to take for granted that we are all now being tracked via our cel phones, online banking and forums, voter lists, health file records, Google searches, Whole Foods digital signs that are actually facial recognition scanners,  etc.
Verizon even sells a product that allows businesses to track cell phone users in malls.

But it's quite another to read the stories of innocent people including minors who have found themselves outed, in virtual police line-ups, photographed in their bathrooms and while they were sleeping, blackmailed - all without their knowledge or being sloppy about their online privacy. 
The teenagers who were spied on at home by their school via webcam spyware installed on the laptops given out by the school - neither they nor their parents signed up for or knew about it.

News to me was that if you go online price shopping, retailers vary their prices to you depending on their assessment of your financial worth based on your geographic location.




Angwin's book primarily addresses privacy considerations in the US but as Steve is fond of saying - the War on Drugs and the GWOT, those bullshit policies and programs which fueled these invasions of our privacy right alongside the tech that made that made them possible, know no national boundaries.

The Canadian Civil Liberties Association is hosting a symposium : "Helping Canadians Find Pathways to Privacy" at UofT on March 20 and 21. Free to public but you have to register. To be webcast later.
.

Friday, December 13, 2013

Inside the Senate Committee on National Security

On Monday the Senate Committee on National Security and Defence heard from the watchdogs of both CSIS and CSEC - Chuck Strahl, Chair of the Security Intelligence Review Committee (SIRC), and CSEC Commissioner Jean-Pierre Plouffe.

Here Plouffe is explaining to Senator Romeo Dallaire why Justice Mosley slapped down CSIS for outsourcing their spying to their Five Eyes partners (US, UK, NZ, and Australia) via CSEC. Plouffe :
"CSIS has a jurisdiction which is limited to Canada, whereas CSE's jurisdiction reaches abroad. So CSIS, in accomplishing its activities, believes it has need of assistance from allies abroad and in order to obtain this, CSIS has to go through CSE because CSE deals directly with allies. In Justice Mosley's decision, CSIS asked for assistance from CSE because both individuals in question were abroad. And what happened is unfortunately CSIS did not disclose to Justice Mosley that they sought assistance from Five Eyes. So it is legal for CSE to call on the Five Eyes, however in this case there was a warrant from the court that specified it be within Canada not abroad. Mosley said CSIS was lacking in candor and good faith." 
Plouffe added this has "complicated" CSEC's relationship with the NSA and other partners.
The impression you get from listening to Plouffe is that the Five Eyes partners share just about anything and everything, with the Canadian contact being CSEC.

CSIS watchdog Chuck Strahl addressed this as problem for the privacy of Canadians, saying "we must put legal caveats on CSIS/CSE-generated intel" shared with Five Eyes partners and third parties :
 "CSIS is concerned with erosion of control of intelligence given to CSEC and by extension to the Five Eyes community." 
"CSIS has developed information privacy protocols with only one Five Eyes partner."
While Strahl doesn't reveal which Five Eyes partner it is we do have a privacy protocol with, a 2009 Memo of Understanding between the NSA and its Israeli counterpart does mention one between NSA and Canada. This was the Snowden-leaked doc which revealed an NSA agreement purporting to share raw unfiltered intelligence data with Israel, who is not a Five Eyes member, with the proviso that Israel weed out intel about Americans and other Five Eyes citizens .

Or as Strahl put it : "A Five Eyes partner may act independently on CSIS-originated info."

He said his office was limited to the oversight of CSIS and so his investigators were unable to follow threads that led into CSEC. Likewise Plouffe said his office could not stray into investigating CSIS. 
This was not, Strahl said, what O'Connor and Iacobucci had in mind when they each recommended a joint oversight, adding there is "no provision in current legislation, which is 30 years old, for parliamentary oversight", the only Five Eyes partner not to have any.
On Abdelrazik, Strahl said CSIS created an "exaggerated threat assessment" and "inappropriately disclosed classified information". 

The senators seemed far more concerned with what new measures had been put in place to prevent a "Snowden nightmare" in Canada than in the content his leaks revealed. They didn't ask a single question of Plouffe or Strahl about spying on the G20 in Canada and Brazil or allowing the NSA to build backdoors into internet encryption under our watch.
Not one.
For his part, Strahl said "Snowden has caused us to question how we work and that's good."

Asked what possessed him to come out of retirement last year to head up SIRC, Strahl laughed and said it was classified. 
I'll bet. SIRC has had an interim chair since the former SIRC chair and fraudster appointed by Harper, Dr. Arthur Porter, resigned in disgrace in 2011.
.
Dec 20 Update : Plouffe's explanation above - on Justice Mosley chastising CSEC/CSIS for outsourcing their spying on Canadians to Five Eyes partners - goes public :

CSIS asked foreign agencies to spy on Canadians, kept court in dark, judge says

Canada's spy agencies chastised for duping courts
Canada’s spy agencies have deliberately misled judges to expand their eavesdropping powers unlawfully
Update : Senate Committee transcript up.
.

Thursday, September 26, 2013

Get Your NSA On, Romulans!


Techdirt: NSA Chief Begs His Public To Help Agency 'Get The Facts Out'
Apparently sitting in the captain's chair on the bridge of the USS Surveillance* has lost its thrill.  
Keith Alexander, the director of the National Security Agency, called Wednesday on the public to help defend his agency's powers as Congress mulls restrictions aimed at protecting privacy. 
He warned that if Congress hampers the NSA's ability to gather information, it could allow for terrorist attacks in the United States similar to last week's massacre in a mall in Nairobi, Kenya. 
"If you take those [surveillance powers] away, think about the last week and what will happen in the future," he said. "If you think it's bad now, wait until you get some of those things that happened in Nairobi." 
Yeah, just you wait. 'Some of those things' like the Boston Marathon bombing or the Navy Yard shooting - things like that. 


Meanwhile here at home, it has now been two weeks since Canadian media declined to make any mention whatsoever of an NSA agreement purporting to share raw data with Israel  - data which 
"includes, but is not limited to, unevaluated and unminimized transcripts, gists, facsimiles, telex, voice and Digital Network Intelligence metadata and content."
So - likely emails and phone calls as well then.
Not to worry though. 
The Israelis were required to “destroy upon recognition” any communication “that is either to or from an official of the US government“. Such communications included those of “officials of the executive branch (including the White House, cabinet departments, and independent agencies), the US House of Representatives and Senate (member and staff) and the US federal court system (including, but not limited to, the supreme court)”.
So that's the important USians taken care of. What about the rest of us?
The doc specifies that US citizens are not to be targeted and that the NSA has agreements with its Five Eyes partners - Canada, Australia, New Zealand, and the UK - to protect information on their citizens and that Israel should respect those privacy agreements when looking through the data.

That must be why our media wasn't fussed enough to mention it.


.

Friday, September 20, 2013

CSEC presents Hackfest


Nope, not a photoshop this time. It's CSEC, the Canadian government's version of the NSA, presenting a hacker conference for computer security enthusiasts this November in Quebec. [h/t Lux ex Umbra] 
Events scheduled for Hackfest Strikes Back include :
And a panel discussion : "How can researchers make money selling vulnerabilities? Should they or is it extortion?"

A talk titled Why the NSA should have every vulnerability by now explains :
"High budgeted intelligence organizations, such as the NSA, will not help fix vulnerabilities, only find as many as possible. The intention is to use these vulnerabilities for offensive operations and fixing them is counter-intuitive to that goal."
Difficult to escape the irony here.

In 2006 CSEC was entrusted with overseeing the global encryption standards process for 163 countries. CSEC handed those keys to the NSA, which promptly used them to insert vulnerabilities and backdoors to allow them to spy on foreign companies and governments. The NY Times quotes an NSA memo on how they pwned CSEC:
"... beginning the journey was a challenge in finesse. After some behind-the-scenes finessing with the head of the Canadian national delegation and with C.S.E., the stage was set for N.S.A. to submit a rewrite of the draft … Eventually, N.S.A. became the sole editor.”
And now CSEC presents workshops and panel discussions on the efficacy and ethics of profiting from those same backdoors and vulnerabilities. 
.

Update : Dear CSEC : Stop bullshitting us.
When Clapper was asked by the US Congress if the NSA spies on Americans he said no.
When CSEC was asked, CSEC chief John Forster answered :
“CSEC does not direct its activities at Canadians and is prohibited by law from doing so."
which completely ignores Part C of CSEC's own 3-part mandate in law [emphasis mine] :
1. to provide technical assistance to CSIS and Canadian law enforcement agencies;  
2. to assist CSIS under s. 16 of the CSIS Act; and  
3. to assist CSIS and Canadian law enforcement agencies by intercepting the communications of a Canadian/person in Canada that is subject to a CSIS warrant or authorization from law enforcement agencies.
.

Monday, September 16, 2013

Get Your NSA On - Star Trek Fantasy Spy Centre



"When he was running the Army's Intelligence and Security Command, [Gen. Keith] Alexander brought many of his future allies down to Fort Belvoir for a tour of his base of operations, a facility known as the Information Dominance Center. It had been designed by a Hollywood set designer to mimic the bridge of the starship Enterprise from Star Trek, complete with chrome panels, computer stations, a huge TV monitor on the forward wall, and doors that made a "whoosh" sound when they slid open and closed. 

Lawmakers and other important officials took turns sitting in a leather "captain's chair" in the center of the room and watched as Alexander, a lover of science-fiction movies, showed off his data tools on the big screen.
"Everybody wanted to sit in the chair at least once to pretend he was Jean-Luc Picard," says a retired officer in charge of VIP visits."


Detailed photos of the Star Trek Fantasy Spy Center. 
Can't say I recognize the ubiquitous logo though. Anyone?



Meanwhile, up here in Canada - there's this morning's G&M :
"For nearly two decades, Ottawa officials have told telecommunications companies that one of the conditions of obtaining a licence to use wireless spectrum is to provide government with the capability to bug the devices that use the spectrum...
 ... including eavesdropping, reading SMS texts, pinpointing users’ whereabouts, unscrambling some encrypted communications, phone logs and keystrokes. ...
Carriers that help their customers scramble communications must decrypt them. "Law enforcement requires that any type of encryption algorithm that is initiated by the service provider must be provided to the law-enforcement agency unencrypted."
 This in addition to Canada's CSEC partnering up with the NSA to weaken Internet encryption standards.

Yet somehow the real Pierre Poutine still eludes them.
.

Friday, September 06, 2013

NSA is breaking the internet

Testifying before the US Senate last month, NSA Deputy Director John Inglis conceded that the bulk collection of phone records of millions of Americans under Section 215 of the Patriot Act has been key in stopping only one terror plot.

But then it never was just about phones and national security, was it?

In his 2013 Budget Intelligence Request, NSA director James Clapper - who lied to the US Congress under oath about the scope of secret surveillance and was then appointed by Obama to an independent review board to investigate his own agency - advised :
“We are investing in groundbreaking cryptanalytic capabilities to defeat adversarial cryptography and exploit Internet traffic." 
"The SIGINT Enabling Project actively engages the US and foreign IT industries to covertly influence and/or overtly leverage their commercial products' designs. These design changes make the systems in question exploitable through SIGINT collection with foreknowledge of the modification. To the consumer and other adversaries, however, the systems' security remains intact."
"the consumer and other adversaries"

Under a section for release to Five Eyes - that's us!
Insert vulnerabilities into commercial encryption systems, IT systems, networks ...
Collect target network data and metadata via cooperative network carriers...
The joint Guardian NYTimes ProPublica release yesterday doesn't tell us who those "co-operative" network carriers and IT systems are - publish the names! - but the NSA is pretty clear about their own role - weakening encryption standards and writing code with backdoors in them for security vendors . 
The NSA/GCHQ help them build the locks to keep your data safe; then the government gets one key and you get the other one.

The possibility for corruption and breaches of security built into a system that includes scoping out cell phones, tablets, Facebook, emails, web searches, medical and banking data are endless - industrial espionage, blackmailing political figures, fixing elections, corrupting markets, internet scams ...
"Snowden, one of 850,000 people in the US with top-secret clearance..."
And have any of these other 850,000 top-secret clearance people in what is already a massively corrupted security system taken it one stage farther and facilitated an internal black market for information about stocks, patents, trade deals, etc. within the larger market? Would there be any way of knowing? The NSA wouldn't know - they've already admitted to having no clue what Snowden took.

9/11 changed everything.  The Five Eyes govs upped the spying on their own citizens and started locking up whistleblowers while simultaneously supplying AlQaeda et al with arms, training, and money.

Nothing in the Canadian media about yesterday's release yet.
Update : National Post : NSA has now cracked common Internet encryption, including personal email and online banking
CBC : NSA cracked most online encryption says report

My fear is that we'll agree to ignore this assault on our privacy as long as the roving supply of cat videos doesn't dry up.

Ok - gotta go.  Some adversarial consumer Windows security patches have just automatically downloaded themselves onto my computer and I have to reboot for them to take effect. hey wait a minute ...
.

Wednesday, September 04, 2013

Outsourcing to surveillance mercenaries

Claudio Guarnieri @ Big Brother Awards 2013 from Bits of Freedom on Vimeo. opens his talk with an ad from a surveillance company billing itself as "The hacking suite for governmental interception". 


Obama's first question from the press in Sweden today was on NSA spying.
Barry still going with :
"What I can say with confidence is that when it comes to our domestic operations, the concerns that people have back home … we do not surveil the American people or persons within the US. There are a lot of checks and balances in place designed to avoid a surveillance state. 
"We." Does that include the surveillance mercenaries that collect data for you?
"And I can give assurances to the public in Europe and around the world that we're not going around snooping at people's emails or listening to their phone calls. What we try to do is to target very specifically areas of concern."
"Specific areas of concern" apparently include alleged snooping the email correspondence and listening in on the private phone calls of the presidents of Mexico and Brazil.

Last month Obama appointed NSA director James Clapper- who lied under oath about the scope of secret surveillance - to an independent review board to investigate his own agency.
Hoo ha.
In his last budget request Clapper wrote : 
 “We are investing in groundbreaking cryptanalytic capabilities to defeat adversarial cryptography and exploit Internet traffic."

Also today WikiLeaks published 249 documents from 92 global intelligence contractors.
"These documents reveal how, as the intelligence world has privatised, US, EU and developing world intelligence agencies have rushed into spending millions on next-generation mass surveillance technology to target communities, groups and whole populations."
If you click on the handy map provided at WikiLeaks, you can check out the three Canadian companies named.

I've written before about US corporate surveillance of Creekside here.
.

Friday, August 23, 2013

CSEC spies on Canadians : watchdog report

While whistleblower Edward Snowden and Glenn Greenwald have published reports about the USA's NSA and UK's GCHQ joint electronic surveillance of Brits and Americans, we've been pretty much in the dark in Canada about our own government's surveillance of us.

An annual report tabled two days ago from the independent watchdog commissioner for Canada's electronic eavesdropping agency Communications Security Establishment Canada elicited the following timid headlines repeated throughout yesterday's press coverage.
Post Media : Canadians may be victims of illicit spying 
NaPo : Canada’s spy agency may have illegally targeted Canadians: watchdog 
CBC : Security watchdog says agency may be spying on Canadians  
Star : Eavesdropping agency may have spied on Canadians, watchdog says
Whoa. "May be spying on Canadians"? "may"?   Which report did they read?

Several of the articles quote this reaction from a spokesy for DefMin Rob Nicholson :
 "The privacy of Canadians is of utmost importance. CSEC is prohibited by law from directing its activities at Canadians anywhere in the world or at any person in Canada."
Sure. Part (a) of CSEC's mandate** prohibits spying on "any person in Canada" or Canadians anywhere in the world.
Part (b) is a little looser, permitting CSEC to use information acquired by the Government of Canada system owners to protect their computer systems from mischief.

But Part (c) ... Part (c) specifically directs CSEC on when it may spy on Canadians on behalf of CSIS.

Communications Security Establishment Commissioner, 
Annual Report 2012 - 2013

CSEC assistance to CSIS under part (c) of CSEC’s mandate (Page 21)
In 2009 ... the Honourable Justice Richard Mosley*** ... issued the first warrant permitting CSIS to intercept the communications of Canadians located outside Canada using the interception capabilities of CSEC ... from within Canada.This assistance includes CSEC supporting CSIS with the interception of Canadians’ communications if CSIS has a judicially authorized warrant. 
CSIS is authorized to collect threat-related information about Canadian persons and others and, as discussed above, is not subject to territorial limitation.
...  the collection of the information by CSIS with CSE[C] assistance, as proposed, falls within the legislative scheme approved by Parliament and does not offend the Charter.
CSEC’s assistance to CSIS under the warrants may include use of Canadian identity information and the interception of the communications of Canadians.
So what's with these timid headlines, national press? Are you suggesting that while CSEC was permitted to spy on Canadians for CSIS, they didn't actually do any?

No, obviously not. Page 24 :
During the period under review, CSEC responded appropriately to two related privacy incidents it identified involving the unintentional release of Canadian identity information of some of the subjects of the warrants. 
 ... another incident involv[ed] the interception of communications for CSIS for a small number of days after a particular warrant had expired [due to] unintentional human error 
 Page 27 : the amount and treatment of private communications and Canadian identity information acquired by the activities as well as a sample of those private communications and Canadian identity information used by CSEC
Private Communication: “any oral communication, or any telecommunication, that is made by an originator who is in Canada or is intended by the originator to be received by a person who is in Canada"
Page 33 : In 2012, CSEC started using a new on-line secure system to process requests for and disclosures of Canadian identity information. CSEC provided my employees with a demonstration of the system, which is currently used with CSEC’s principal clients. CSEC intends to extend its use to other partners starting in the coming fiscal year. 
Headlines later on in the day gave us the CSEC response : 
Ottawa Citizen : CSEC Says It Is Not Breaking The Rules About Spying On Canadians  
PostMedia : In wake of spying allegations, Communications Security Establishment Canada insists it didn’t break law
No, CSEC isn't breaking the rules but only because those rules allow it to spy on Canadians while working under the guidelines of CSIS. 
But they don't say that, do they? Instead we get weasel crap like this :
“The commissioner’s statement about a lack of records is a reference to a single review of a small number of records gathered in the early 2000s, in relation to activities directed at a remote foreign location,” the agency said in an emailed response.
Yes, part of the commissioner's complaint is directed at incomplete records in "early years". Doesn't exactly address CSEC spying on Canadians since though, does it?

So how did all you reporters at different media outlets all separately decide to downplay the watchdog commissioner's report on electronic surveillance of Canadians to "may be" spying?

Yes, I realize he wrote a nice positive preamble about how he sees himself as working with CSEC on a "complementarity" not an adversarial basis, "more as CSEC’s conscience than as a sword of Damocles" and how he's been quite pleased with the results.   Further he writes that "where I have no mandate to follow-up, I may refer questions to SIRC that concern CSIS".

We recently learned that since 2009, CSEC - as a Five Eyes intelligence partner with the US, UK, New Zealand, and Australia alongside CSIS, RCMP, and CBSA - has been authorized to exchange intelligence with other nations even if there is “substantial risk” that sending info to or requesting info from a foreign agency would result in torture ... just as long as a deputy minister or agency head gives it the ok. 

What happened to Maher Arar - once so shocking to all of us - has a legal basis here now.

So you reporters in the Canadian media can't be letting us down like this.  
Read the friggin report - it's only 46 pages long.


More from POGGE : On watchdogs with no bite.

**CSEC’s mandate [Page 9 from Commissioner Robert Décary's report ]
When the Anti-terrorism Act came into effect on December 24, 2001, it added Part V.1 to the National Defence Act, and set out CSEC’s three-part mandate:  
• part (a) authorizes CSEC to acquire and use foreign signals intelligence in accordance with the Government of Canada’s intelligence priorities;  
• part (b) authorizes CSEC to help protect electronic information and information infrastructures of importance to the Government of Canada; and 
• part (c) authorizes CSEC to provide technical and operational assistance to federal law enforcement and security agencies, including helping them obtain and understand communications collected under those agencies’ own lawful authorities.

***The Honourable Justice Richard Mosley was a primary architect in the drafting of the 2001 Anti-Terror Act and more recently the judge in the six-riding election fraud case.
.
Sunday update : Michael Geist :
"Canadian domestic communications that travel from one Canadian location to another may still transit through the U.S. and thus be captured by U.S. surveillance. Despite these risks, Bell requires other Canadian Internet providers to exchange Internet traffic outside the country at U.S. exchange points, ensuring that the data is potentially subject to U.S. surveillance."

Friday, July 12, 2013

NSA : At Microsoft, your privacy is our "team sport"



Feel free to drop by this Microsoft ad and give it a thumbs down.
"At Microsoft, your privacy is our priority." 

Indeed. About that ...

Guardian : How Microsoft handed the NSA access to encrypted messages

• Secret files show scale of Silicon Valley co-operation on Prism  
• Outlook.com encryption including Hotmail unlocked even before official launch 
• Skype worked to enable Prism collection of video calls 
Microsoft has collaborated closely with US intelligence services to allow users' communications to be intercepted, including helping the National Security Agency to circumvent the company's own encryption, according to top-secret documents obtained by the Guardian. 
• In July last year, nine months after Microsoft bought Skype, the NSA boasted that a new capability had tripled the amount of Skype video calls being collected through Prism;
• Material collected through Prism is routinely shared with the FBI and CIA, with one NSA document describing the program as a "team sport".
US lawmakers, along with Microsoft, Skype, Apple, Google, Facebook, and Yahoo all initially attempted to deny knowledge of PRISM or that the intelligence agencies have back doors into their systems, explaining they are very occasionally under a legal compulsion to cough up customer data to comply with "existing and future lawful demands" in Microsoft's happy phrase, but this tiny ISP company bucked it and won.

Meanwhile ...

NSA Writes Code Used in Google Phone  [h/t West End Bob]
The tech giant Google has confirmed the National Security Agency furnished some of the code installed in its new Android phone. The NSA says the code is intended to enhance security against hackers and marketers, but will not confirm whether it also aids the agency’s PRISM program monitoring the global Internet.
Back to the Guardian :
"Blanket orders from the secret surveillance court allow these communications to be collected without an individual warrant if the NSA operative has a 51% belief that the target is not a US citizen and is not on US soil at the time."
That's us.

Michael Geist Feb 15 2012 on the situation in Canada : 
"[W]ith ISPs and telcos providing subscriber data without a warrant 95 percent of the time, there is a huge information disclosure issue with no reporting and no oversight. This is a major issue on its own, particularly since it is not clear whether these figures also include requests to Internet companies like Google and social media sites such as Facebook and Twitter.  
The RCMP alone made over 28,000 requests for customer name and address information in 2010. These requests go unreported - subscribers don't know their information has been disclosed and the ISPs and telecom companies aren't talking either."

If you'd like to opt out of the NSA and their "team sport", there are other options :

.
Related from Saskboy : PRISM : Oliver Stone vs NSA and Checkpoints
"The question is not Do you have something to hide? The question is whether we control government or the government controls us."
.

Wednesday, June 26, 2013

Did Canada spy on journos at the Toronto G8/20 summit?



Image from leaked UK Government Communications Headquarters briefing slide featuring the logos of Canadian, US, and UK signals intelligence spying agencies.

Ten days ago The Guardian published GCHQ briefing slides, courtesy of former NSA contractor turned whistleblower Edward Snowden, revealing :
Foreign politicians and officials who took part in two G20 summit meetings in London in 2009 had their computers monitored and their phone calls intercepted on the instructions of their British government hosts, according to documents seen by the Guardian. This included:
• Setting up internet cafes where they used an email interception programme and key-logging software to spy on delegates' use of computers;
• Penetrating the security on delegates' BlackBerrys to monitor their email messages and phone calls
The inclusion in the docs of the Communications Security Establishment Canada logo along side those of NSA and GCHQ, and the mention of bugged internet cafes and BlackBerrys, put me in mind of Canada's $2-million indoor fake lake built for the G8/20 the following year so that 3,000+ Canadian and foreign journos could, in Greg Weston's words at the time :
"file their reports ... their feet dangling in the water ... from only cottage dock in existence with bar service and high-speed Internet connections."
And according to Weston, they were all provided with free "special summit edition BlackBerrys" too.


Tuesday, February 21, 2012

Skynet : Connecting the dots

So remember how the Cons withdrew their just-tabled internet surveillance bill, the Lawful Access Act, on Feb 14 and replaced it an hour and 15 minutes later with the identical but renamed Protecting Children from Internet Predators Act , a bill which mentions neither children nor predators?

Coincidentally, the US Protecting Children from Internet Pornographers Act of 2011 - sponsored by Texas teabaggin' Rep Lamar Smith who also sponsored the Stop Online Piracy Act, another internet spying bill - has 39 co-sponsors and is heading off to the US House of Representatives for debate.

Good thing ours has that one-word difference in the title, the better to provide for Canadian independence and sovereignty.

Theirs :
House Panel Votes to Require ISPs to Keep Customer Records
"The Protecting Children From Internet Pornographers Act would require ISPs to retain all customer IP addresses [for 12 months, amended down from 18] so that law enforcement agents can use the information to investigate online child pornography. Law enforcement agents would gain access to the IP information with subpoenas they issue, not court-ordered warrants."
Hey, ours does that too!
Michael Geist yesterday :
Toews has not talked about a provision in Bill C-30 that creates a voluntary warrantless system that would allow police to ask for the content of emails or web surfing habits and allow ISPs to comply with the request without fear of liability.
Hey, Section 6 of the theirs does that too! As does SOPA.


So who else is looking to spy on us online?
From the Whitehouse National Northern Border Counternarcotics Strategy, January 2012 , pages 33-34:
"It is imperative that Canada and the United States work together to expedite the sharing of information from electronic communication service providers; and share information necessary to lay the foundation for intercepting internet and voice communications under their respective laws in a timely manner."
Meanwhile, across the pond, the UK isn't hiding their internet spying bill behind any malarkey about protecting children. Same basic mo though :
UK government to demand access to all phone and internet user data
"The British government is in the process of developing a scheme whereby all phone companies and broadband internet providers will be required to store customer transaction data for a year and hand it over to security services upon request."
Doesn't seem like it much matters who these various government online spying bills are purported to target - pornographers, copyright infringers, drug traffickers, drugbiz mirror sites, terrorists - or who they are supposed to protect - children, Hollywood, the recording industry, drug companies, the public at large. They'll just keep reframing and renaming those suckers until one of them sticks - a law we can't access the inner workings of that entrenches their access to our private info while simultaneously throttling the free flow of shared info out here.


In opposing the US pornography bill, Rep. John Conyers said : 
"This is not protecting children from internet pornography. It's creating a database for everybody in this country with a lot of other purposes."
Democrat Rep. Zoe Lofgren proposed an amendment to rename it the Keep Every Americans' Digital Data for Submission to the Federal Government Without a Warrant Act but sadly this did not accrue the required votes. Unlikely such a further name change would succeed here either, even with a one-word title change.
.

Monday, February 20, 2012

Oh sting, where is thy death?

Following the Ottawa Citizen's attempted sting to determine who was behind the Vikileaks twitter account targeting Vic Toews last week, the House Speaker's Office patiently explained that really it could be any one of over 4,000 people :
"The HoC, like many organizations, uses a series of private IP addresses for its internal network.  Having said that, when users are using the internet, they are only identified with one of our four public IP addresses. To support this approach we use a concept called NAT (Network Address Translation). All users, on the Parliamentary Network (over 4000), when using the internet, are publicly identified with one of these four unique addresses. 
As an example, if we had 100 users using the internet at once from the HOC, they would all be identified with one of the four addresses. Hence, just by looking at the IP address that is used on the internet you cannot correlate this to a person from the organization. "
Gosh I'll bet the Cons feel pretty silly now that Angry Baird raved away six times in the House on Friday that the NDP was behind the “sleazy, dirty” internet campaign, huh?

Here's Steve's Parliamentary Secretary Dean Del Mastro talking about it on CTV's Question Period last night :
"Well we know that the Ottawa Citizen set up a bit of a trap and in fact it seems pretty clear that the NDP's behind it .... What the NDP have demonstrated is that they will punch below the belt repeatedly and it doesn't matter. They put on this facade that they are clean and lilywhite but I can tell you in this case what the NDP has done, we would never do. Shame on them and they should come out and admit who's behind it and frankly take responsibilty for what they have done. It's wrong.
We know this is from an NDP computer. They should come out and admit who has done it and take responsibility and apologise. Canadians do not appreciate this kind of attack ... etc etc" 
And so it goes ...
.
Update : And in other Skynet surveillance news ...
UK government to demand access to all phone and internet user data
The British government is in the process of developing a scheme whereby all phone companies and broadband internet providers will be required to store customer transaction data for a year and hand it over to security services upon request.
.

Friday, February 17, 2012

Gutter politics, you say?

So the government which used the private medical records of Vets activist Sean Bruyea and Vets Review Board member Harold Leduc to smear them, and the private government correspondence of diplomat Richard Colvin to smear him - the same government which defended its dirty phone tricks campaign as "vital free speech" according to Conservative House Leader Peter Van Loan - is now going all Angry Baird that someone twittered already publicly available info about Toews in response to his Awful Access internet spying Act.

Really?

Public Safety Minister Vic Toews wants an investigation into someone repeating stuff about him that was already published in the MSM nearly four years ago?

What an absolutely awesome example of how they would use their Awful Access Act.
.

Saturday. Updates from my betters :
CBC : Online surveillance bill opens door for Big Brother
Canadian Privacy Law Blog : The hidden gag order of Bill C-30

The very funny Tabatha Southey : If only Tory caucus walls could talk 

Jeff Jedras : Vikileaks and the death of the journalist as news gatekeeper

.

Thursday, February 16, 2012

The Can't Be Arsed To Get a Warrant For That Final 5% Act


On CBC's The Current yesterday, internet law prof Michael Geist and Paul Gillespie, a former Toronto Police sergeant and CEO of Kids' INternet Safety Alliance, faced off on the potential for invasion of privacy afforded by the Lawful Access Act ... Protecting Children from Internet Predators Act ... Can't Be Arsed To Get a Warrant For That Final 5% Act

Partial transcript :

Gillespie explains the bill. Quote :
1)Requires service providers to give subscriber data to police upon request : name, unlisted phone #, IP address, without a warrant
2) If police have the authority, they should also have the ability to monitor peoples' communications
3) With a legitimate legal search warrant, be able to get the records logs
4) Compels service providers to store data

Michael Geist:
"If you look through the bill you don't find the words 'child pornography' anywhere because it's about far more than that.
On warrantless access to suscriber information - the reality is a warrant isn't always needed. Under current privacy law, telecom companies and internet companies have the power, the ability to provide the information, things like customer name and address information, without a warrant in appropreiate circumstances where it's part of an investigation. 
In fact according to RCMP data, they do so about 95% of the time. So in the overwhelming number of cases, they're already disclosing this information without any kind of court oversight. What we're talking about at the end of the day is that last 5%, instances where ISP or telecom companies say "We're not comfortable disclosing this subscriber information to you based on what you've shown us; come back with a warrant and we'll give you whatever you ask for."
That's been a bedrock principle we've had in Canada - it strikes the appropriate balance and really prevents potential fishing expeditions and prevents the prospect of a significant loss and erosion of the privacy balance we have in Canada." 

From Michael Geist's column, Feb 15 :
"[W]ith ISPs and telcos providing subscriber data without a warrant 95 percent of the time, there is a huge information disclosure issue with no reporting and no oversight. This is a major issue on its own, particularly since it is not clear whether these figures also include requests to Internet companies like Google and social media sites such as Facebook and Twitter. The RCMP alone made over 28,000 requests for customer name and address information in 2010."
Meanwhile, be sure to Tell Vic Everything #
.

Blog Archive