Wednesday, February 8, 2017

Dragnet Stingray Fishing

They say you can tell a lot about a woman by what’s in her purse. More generally, you can tell a lot about any person by what they always carry. In my case, I never leave the house without my keys, my wallet, and my cellphone. The keys are pretty self-explanatory – I’ve never left home without planning to get back in later – and my wallet is there so I can buy lunch. My phone, though, seems to just tag along to cause stress. Powered on, but idle, I wonder why it uses so much more battery than, say, a tablet. A partial answer to that question is that, several times per minute, my phone sends a small message to the cell tower1. Much as I would love better battery life, this makes sense. Without that “ping” to the cell tower, my phone would have no way to know of, for example, incoming text messages.

Unfortunately, the procedure a cellphone uses to connect to the tower is completely unauthenticated, meaning so-named Man-in-the-Middle (MITM)2 attacks are relatively easy to carry out. The basic idea of a MITM attack is very simple: Say I tell you I am someone I am not. For example, a police officer. You would probably want to see some identification for me to prove it. Many software systems do not ask for this identification, meaning they will just send data to anyone who asks for it.

This is a picture of an aquatic Ray. As a point of interest, the way this image is loaded is a massive security threat, and browsers should be upgraded to block it.

Not this kind of Stingray…
(Source: http://eskipaper.com/stingray-4.html)
This basic security oversight is what makes Stingrays (otherwise known as IMSI-catchers or cell site simulators) so effective. The Stingray masquerades as a cell tower, your phone connects, your phone sends its authentication information to the Stingray, the Stingray authenticates to the real cell tower using your information, and passes data back and forth between your phone and the tower. The Stingray is now able to eavesdrop on everything your phone does.

This is bad for two reasons: First, whoever owns the Stingray can record calls, (SMS/MMS) messages, and any unencrypted data. Secondly, your phone can be requested to send triangulation data about other cell towers in range, making it possible to track location with very good accuracy in real-time3.

Neither of these things sound great for privacy but, as we’ve already talked about in class, we aren’t too uncomfortable when such aggressive tracking is used in a criminal case. Of course, this is where everything starts to get messy. The first problem is that these Stingrays are often used without a warrant1, despite having precedent from other cases that real-time tracking amounts to a fourth-amendment search, and thus requires a warrant4. Added to this is that in cases where Stingrays are used, law enforcement often tries to conceal that fact, even going so far as to drop cases when they would potentially be forced to reveal the use of a Stingray.
The second privacy problem is that everybody’s cellphone within the Stingray’s range of operation is intercepted. This is by necessity – the way a Stingray works means it’s not possible to target an individual phone – but that doesn’t make it any less of an invasion of privacy. When court orders do authorize the use of Stingrays, there is often very little mention of what happens to the “collateral” data collected5. It may be immediately deleted, but it could also all be shoveled into some database. Given the secrecy surrounding law enforcement’s use of such devices, we have no real reason to choose one over the other. However, as the NSA was willing to collect massive amounts of data about American’s phone calls under the Patriot Act, it wouldn’t be unreasonable to believe that they collect and store information gathered by stingrays from unknowning citizens.
However, the worst news is yet to come. Although it would be, at best, questionably legal to own such a device, they are relatively easy to build and are available for purchase outside of the US6. This means that, quite aside from law-enforcement, it isn’t beyond belief that other individuals or organizations have the capability to perform mass surveillance by use of cell site simulators.

Given that, what can you do to protect yourself? Unfortunately, very little. The obvious answer is to switch your phone off and remove the battery. This is foolproof but impractical. Alternately, you could write to your cellphone provider and complain that they need to upgrade their security. This is not likely to be effective because it would cost the company money and because they would most likely have to retain the older, insecure system for backwards-compatibility.

Given the vast amounts of data it is possible to obtain using a Stingray, including live location information and calls, messages, and data, I think it is clear that law enforcement should require a warrant before using a Stingray, keeping in mind a plan for what to do with “collateral” data. However, this does not address the privacy concern that anyone can build a cell-site-simulator for $5007. Though a warrant should definitely be required to use this technology, the real problem is that cellular authentication and encryption are both totally broken and ought to be upgraded.

1https://www.eff.org/deeplinks/2012/10/stingrays-biggest-unknown-technological-threat-cell-phone-privacy

2Personal knowledge supported by https://en.wikipedia.org/wiki/IMSI-catcher

3https://www.eff.org/sls/tech/cell-site-simulators/faq#faq-What-data-can-a-cell-site-simulator-collect?-

4https://www.eff.org/deeplinks/2016/04/eff-and-aclu-expose-governments-secret-stingray-use-wisconsin-case

5https://www.eff.org/sls/tech/cell-site-simulators/faq#faq-If-I%E2%80%99m-not-a-target-of-a-criminal-investigation,-why-do-I-have-to-worry-about-cell-site-simulators?

6https://www.eff.org/sls/tech/cell-site-simulators/faq#faq-Who-else-uses-cell-site-simulators?

7https://hackaday.com/2016/04/08/build-your-own-gsm-base-station-for-fun-and-profit/

February 8 Case Scenarios: Group No. Three

Case Scenario No. One


Notice
Notice of the use of facial recognition technology, drones and video surveillance will be given to attendees before the game via a printed message on the back of their tickets (if ticket is available for viewing/printing online, it will be printed on that ticket as well as tickets distributed by the stadium). On the day of the game, there will be signs posted throughout the stadium (inside and outside the entry gates) stating that facial recognition, drones and video surveillance are being used. When attendees enter through the gates, an audio announcement will state that facial recognition, drones and video surveillance are being used. This audio announcement may also include other information, to be determined by the stadium or NFL (advertisements, general announcements or reminders, other security information, etc.). This should be a friendly announcement, in an informative tone so as not to detract from the festivities.


Consent
No express consent is required. Consent is implied upon purchase of a ticket as well as entry to the stadium. Attendees do not have a reasonable expectation of privacy at this event, due to the size, the number of people in attendance, the fact that it is televised and the close proximal relationship of attendees. If a person or group has issue with the use of facial recognition, drones or video surveillance, the event is being televised and they may view it through alternate means.


Policies
The database(s) used should be only through official sources (law enforcement agencies, DMV, watch lists and an NFL--and stadium, if available--database of people they have previously had problems with). Images and information will not be connected to Facebook; the system should not have access to Facebook.


Known convicts or people on watch lists will be “flagged” and the areas they occupy will be in constant video surveillance through the use of drones or video cameras. Security personnel or law enforcement may only get involved if a disturbance occurs. People who are flagged will not be immediately removed unless security personnel or law enforcement deem it necessary. Areas occupied by people who are not flagged will still be surveilled. Security personnel or law enforcement may only get involved if a disturbance occurs in this situation as well.


The information/data collected from the surveillance on game day will be stored for a month after game day. This allows time for people to come forward after the game, in case something happened that they would like to be investigated further. Law enforcement agencies may request longer storage of certain data if it is needed for a criminal investigation. The implementation of this technology is for security. The information/data collected may not be sold or distributed except in the case of criminal investigation.


Case Scenario No. Two


Concerns
  1. There ought to be an option to opt-out of being in the database.
  2. A person should consent to having their face scanned each time a scan is attempted.
  3. A person should consent to what information is being viewed and used by the kiosk.
  4. This beverage company sells products that may not be suitable for children and products that are illegal for persons under the age of 21 to consume. What will keep the kiosk from providing coupons and advertising of these products to young people?


Policy
  1. Since the kiosk technology is connected to the frequent shopper program (which requires the submission of a photo), signing up for the frequent shopper program automatically puts one’s face in the kiosk’s database. In order to opt-out of being in the database, a person would be required to not join the frequent shopper program.
  2. When signing up for the frequent shopper program, there should be a notice stating that signing up for the frequent shopper program automatically gives consent to have one’s photo included in the kiosk’s database. One must provide express consent (by checking a box or providing a signature) to have their photo included in the kiosk’s database.
  3. When signing up for the frequent shopper program, there should be an option to choose what the kiosk’s database has access to. One must provide express consent for the database to access Facebook (by checking a box, circling something, or providing a signature). If the company or store would like for the database to have access to any other information, this should be expressed when signing up for the frequent shopper program. The use of one’s photo and shopper history is already part of the frequent shopper program and will automatically be used by the kiosk. If a person signs up for the frequent shopper program, they do not have to provide additional consent for their photo and shopper history to be used by the kiosk.
  4. Because the information in the kiosk is connected to the frequent shopper program, a person must be a member of the frequent shopper program in order to use the kiosk and receive a coupon. Minors will be automatically excluded from the use of the kiosk because they will not be members of the frequent shopper program.


Questions
What is the incentive for the consumer to use this product (kiosk)? 
Is there any incentive beyond the coupon, the potential to find a product they may enjoy and the interactive experience of new technology?

What is the incentive for the store to use this product? 
Does the store collect the information collected by the database and use that for the future?

What is the incentive for the company to use this product?
Besides advertisement and immediately attempting to determine a consumer’s preferences based upon their shopper history and/or Facebook profile, does the company receive any other benefits from this product? Do they store and use the information collected to find statistics of potential and current consumers? If this is the case, they should probably record what coupons were given to certain consumers and whether or not these coupons were used.

How long is information stored and used? 
We assumed that the information collected through the kiosk and frequent shopper program are probably stored for an indefinite amount of time. It will probably be used by the store and companies in order to provide relevant promotions of items a particular person will most likely find useful.

TAKEAWAYS FOR WEEK 5

Article on Idaho rape
·      19 year old boy is convicted of statutory rape of a 14 year old girl
·      As part of his sentence, the judge rules that he cannot have sex until he is married
·      Does this infringe on his constitutional rights?
·      Cruel and unusual punishment? Search and seizure? Privacy on intimate relations?
Facial Recognition
·      Biometrics measure a physical or biological trait that is unique to person such as fingerprints, handwriting, iris scans, etc.
·      Identification vs Authentication
o   Identification- Trying to prove that the person is who they say they are. Ex. Facial recognition
o   Authentication- A way to show that you are who you say you are. Ex. Passwords on your computer
·      Next Generation Identification (NGI)
o   Fingerprints of criminals are uploaded on this database
o   FBI wants to replace fingerprints with other biometrics such as facial scans, iris scans, etc.
o   It would hold information of civilians not just criminals
o   Utah among with 18 other states allows FBI to access drivers license pictures
o   Body cameras take pictures of everyone
·      Statewide Information & Analysis Center (SIAC)
o   The purpose is to give intelligence to law enforcement to protect Utah citizens
o   Database where biometric information is accumulated
·      Concerns related to facial recognition
o   Collection- When and how is it being used?
o   Storage- How long is it being used?
o   Usage- How is it used?
o   Access- Who can have access to the information?
o   Data Security- How secure is the information and how confidential is it?
o   Accuracy- How well does this actually work? How is it regulated?
o   Protections against “Big or little brother”- How do we make sure we aren’t being tracked?
·      Collection issues
o   Warrant?
o   Regulations and rules on how information is obtained?
o   Notice required?
o   Consent?
o   Is it continuous or just as needed?
o   Persons or places where collection is categorically permitted or prohibited?
·      Retention and storage issues
o   Where is it stored?
o   How long is it retained?
o   Should there be mandated archiving/destruction procedures?
·      Usage issues
o   Limited to purpose collected?
o   Forensic use?
o   Business purposes?
o   Usage only as a unique identifier?
o   Disclosure/transparency of uses?
·      Access rights
o   Who has access?
o   Why is it being accessed?
o   Subject access?
o   Collector access?
o   Government access?
o   Researchers access?
o   Third party access?
·      Accuracy error issues
o   Right to review or correct by subject?
o   Who pays for corrections?
·      Regulation/Compliance
o   Industry best practices of government regulation?
o   Penalties for violation of practices?
o   Consumer notification requirement for unauthorized access?
·      Protections against big brother & little brother

Question of the week
·      Most of the class agreed that facial recognition can only be used with consent
Case Studies
·      Case 1
o   Super bowl with facial recognition cameras around perimeter
§  Group 1- Put a notice or sign. Implied consent when purchasing ticket.  Keep the footage only for a month and only for security purposes. No selling it to adds and such.  Only use it for security purposes.
§  Group 2- Give notice to attendees by printing warning on ticket. Consent is implied.  Only kept for 24 hrs.  Won’t sell footage.  Kept secure and only security personnel have access. 
§  Group 3- Giving noticed through signs, ticket, and announcement.  Consent is implied.  Information is kept for a month.  Security agencies can request longer storage with reasonable cause.  Known convicts are flagged to be watched.  Connected to law enforcement database.
·      Case 2
o   Beverage kiosk with facial recognition
§  Group 1- Intrusive and hesitant because of social media access.  How do you obtain consent from non-frequent shoppers.  Social media is not necessary or useful.  Accuracy and protection of others privacy.  Information from store is deleted right after use.  Data retention of company? Large invasion of privacy for little gain. Consent on kiosk? Large privacy policy and ways to opt out.  Who has access to this information? Companies have access to bulk data not individuals purchasing patterns.
§  Group 2- Does it save pictures? How long is info stored? Who has access? Parent company, store, or more access?  Can users check their own profile? Does it store private information like prescriptions and such.  Do you lose benefits from opting out? How accurate is scanner? Warnings and notice? Are customers able to give feedback?  Who is information shared with?
§  Group 3- Consent is given by pushing a button.  Frequent shopper allows giving access to what you want the kiosk to access.  Keeps information indefinitely.  Track coupon usage. 
·      Groups full answers are posted on blog


Monday, February 6, 2017

QUESTION OF THE WEEK NO. 4


The commercial use of facial recognition technology for security, access, marketing and customer service is rapidly growing.  Privacy advocates argue that widespread use of the technology will allow businesses to identify and track almost anyone in public without their consent or even knowledge.  Businesses argue that individuals should not expect complete privacy in public and that some loss of privacy is outweighed by the benefits the technology offers consumers and businesses.  Multiple privacy, government and industry organizations have listed best practices regarding the commercial use of biometric technology, but the recommendations often conflict and no consensus has been reached.
Should businesses be required to obtain a person’s consent, express or implied, before using facial recognition technology?

Friday, February 3, 2017

TAKEAWAYS FOR WEEK FOUR

Anonymity
Many founding fathers used pen names to remain anonymous.
US supreme court has recognized that anonymous speech is a right
  • Is not an absolute right.
Anonymity can be used
  • As a shield
    • Without anonymity speech may be chilled such as speech by victims of sexual abuse.
  • As a sword
    • Used to inflict harm to others without any link to their identity.
Real names v. Opaque usernames
  • Free speech and Privacy v. Accountability
    • Majority of internet users have used an opaque username
Emily Buhler's Blog post
  • Internet users have a "ring of Gyges
    • Opaque user names.
  • Many online sites require users to use a real name in an effort to
    • Promote safety
  • Face book does not require use of legal name but known name.
It is easy to voice derogatory view about people you will never meet.
  • Even with real name derogatory comments would still occur.
What is said anonymously doesn’t have much power.
  • The message may still be hurtful whether it is anonymous or not, but its credibility will differ depending on where it comes from.
Trolls seek attention through outrageous comments and will continue to do so even with their real names
Online anonymity is a privilege that should be revoked if abused.
  • The deciding forces could be
    • The webpage or company
    • The readers themselves
    • The Government
#Cutforbieber campaign
  • Began after photo of Bieber smoking marijuana
  • 4chan post made to begin a campaign to post fake pictures of girls cutting themselves for Justin Bieber to stop smoking marijuana to trick girls into cutting themselves
  • Campaign turned out to be a hoax
Group activity whether 4chan should post prominent warning and have a real name policy.
  • Group 1
    • Would allow for prominent warning, but not adopt a real name policy.
  • Group 2
    • Include prominent warning, and adopt real name policy.
    • Would also create an age policy
  • Group 3
    • Prominent warning
    • Require everyone to establish an account but maintain anonymity between users
Question of the Week
  • When reporting on allegations of sexual assault against women, most news organizations will identify the alleged perpetrator but will not identify the name of the alleged victim.  Some argue this policy is unfair to the accused and allows women to make false accusations without any accountability.  Others argue that identifying the victim is too privacy-invasive, will discourage women from coming forward, and will essentially victimize the woman a second time.  Do you agree with the policy?
    • 9 students said yes
    • 8 students said no
Plaintiff sue anonymously
  • As a general rule, persons who sue in court must do so using their real names
  • Courts will allow plaintiffs to remain anonymous under certain conditions.
    • If defendant objects then the plaintiff must demonstrate why their privacy interest outweigh the defendants and the public's.
  • Courts use different tests to determine if anonymity is permitted; majority of courts use a balancing test that weighs the competing interests:
    • Whether the plaintiff is bringing a suit against governmental action
    • Whether the lack of anonymity burdens a plaintiff's ability to file suit
    • Whether the plaintiff could suffer mental or physical retaliation
    • Whether the plaintiff will be forced to provide information of the "utmost intimacy"
    • Whether the plaintiff is a child
    • Whether the defendant's rights would be significantly subordinated

Thursday, February 2, 2017

A Picture is Worth...

A report done by the Georgetown law school’s Center on Privacy and Technology on the use of facial recognition technology by law enforcement was published in October 2016. The investigation raised concerns about the limited protections for and potential harm toward people’s privacy in regards to rules and regulations (or often rather the lack thereof) for law enforcement’s use of facial recognition technology, which can range from running photos of persons being detained for unlawful behavior to real-time scanning of ordinary, law-abiding citizens.

Summary of the Report

The report raised some troubling questions and problems and proposed some possible solutions:

Accuracy: There is insufficient testing to check accuracy on the software that is used by law enforcement agencies. Also, it has been found that facial recognition software is often less accurate on African Americans, women, and younger people, possibly because the software “learns” how to recognize faces using datasets of photos of largely comprised of Caucasian, older, males. In addition to these concerns, match results returned from databases are not always checked by trained analysts to accurately match faces. Possible solutions to these concerns are to have regular testing of the accuracy of software, “train” the software on more diverse datasets of photos, and ensure that trained analysts check match results.

1st and 4th Amendment Rights: Databases of photos used by law enforcement agencies are often comprised of pictures of law-abiding citizens (driver’s license photos, IDs, and mug shots from people who were not convicted of a crime). Another concern is that facial recognition has been used to identify people participating in protests, which may stifle free speech. Facial recognition has not legally been determined by the US government as a “search,” so it is not protected under American’s rights against unreasonable searches. Possible solutions to these concerns are to only allow searches of non-mug shot photos when there is probable cause involving a serious crime and an issued court order and that the use of facial recognition software should have legislative approval with laws to limit its use.

Regulations and Oversight: In many law enforcement agencies, there is insufficient auditing done to protect against the abuse of facial recognition technology. Also, use of this technology is not always made available to the public. Another issue is that some law enforcement agencies do not require probable cause before running a facial recognition search. Possible solutions to these concerns are to have auditing of the use of facial recognition searches, have policies on the use of the technology that are available to the public and have received legislative approval, and, again, require probable cause before making a search.

Legislative Response

After a different report on the use of facial recognition technology by the Baltimore Police Department on a protest in 2015, members of the legislative branch have called for answers to concerns. Senator Al Franken (Ranking Member of the U.S. Senate Judiciary Subcommittee on Privacy, Technology and the Law) said, “Now, I believe that facial recognition can be a very useful tool in the fight against crime — it can in fact help us catch violent offenders and criminals. But I’m also a firm believer that Americans have a fundamental right to privacy. So I want to ensure that this technology is accurate, transparent, and that our use of facial recognition technology appropriately balances privacy and public safety.”


There is facial recognition technology set up at the StatewideInformation & Analysis Center in Sandy, UT. It is used only when there is an active criminal investigation, except for its use to protect against identity fraud when someone gets a new driver’s license or ID photo.  The center does have human analysts check the results that are returned by the technology to try to eliminate false positives.

What Should Utah Law Enforcement Do With This Technology?

Utah Law Enforcement should be allowed to use facial recognition technology, but only under certain conditions. Searches of mug-shots should only be allowed when there is probably cause. Large scale surveillance should only be allowed in the case that there is an emergency where the public at large is in serious danger.

Utah is one of 16 states that allows the FBI to access their database of driver’s license photos and IDs. They should ensure that these  and any accesses are only used in the case of protecting against identity fraud and when there is a serious emergency.

Wide scale use of facial recognition software and constant surveillance may be able to help prevent and solve crimes. However, these benefits need to be weighed and balanced against the harm to people’s privacy. We shouldn’t become a police state. Law-abiding citizens shouldn’t be subjected to constant monitoring and being a part of a “perpetual line-up.”