Blog

  • Is freedom from cross-border surveillance a human right?

    Among the revelations about NSA surveillance this summer was the news that the United States engaged in massive surveillance of foreign governments and citizens, including embassies, delegations, and politicians of its allies and trading partners, and the offices of the European Union and the United Nations.

    These revelations raise questions about the status of electronic surveillance under international law. In the United States, the Foreign Intelligence Surveillance Act authorizes the government to intercept the communications of foreign targets (any “non-United States Person”) without a court order, at the authorization of the Attorney General. Other countries have no legal restrictions at all on electronic surveillance outside their own borders, or have adopted extraterritorial legal frameworks to permit their governments to engage in foreign communications surveillance of other countries.

    Recently, however, there is a trend to see communications surveillance as a matter of human rights. Under this view, might cross-border espionage by a state be considered to be a violation of international human rights law?

    Conventional wisdom viewed international espionage at peacetime as unregulated by international law. To be sure, countries that conduct espionage on foreign soil violate the domestic laws of those countries, and acts of espionage are viewed as “unfriendly acts” among nations. However, there are currently no international customary norms or treaties forbidding such actions. It is argue that the very clandestine nature of espionage places it beyond the power of international law to regulate.

    However, earlier this year, the UN Human Rights Council received the “Report of the Special Rapporteur on the promotion and protection of the right to freedom of opinion and expression, Frank La Rue”.  The report ties the practice of communications surveillance, including foreign intelligence surveillance, to the human rights of privacy and freedom of opinion and expression. Recently, a coalition of non-governmental organizations issued a declaration of “International Principles on the Application of Human Rights to Communications Surveillance”, which ties surveillance to human dignity, the freedoms of expression and associations, and the right to privacy, but treats all surveillance activities equally and does not draw a distinction between foreign and domestic surveillance.

    It is hard to predict what affect, if any, will the trend to regard unlawful electronic surveillance as a matter of human rights have on foreign intelligence gathering under international law. Both the report of the HRC Special Rapporteur and the International Principles do not suggest any international measures against foreign surveillance, and confine their recommendations to countries’ domestic laws. Nevertheless, viewing mass electronic surveillance across borders as a violation of international human rights law might add weight to the diplomatic calls on the United States and its intelligence-sharing allies to limit their dragnet sweep of the world’s communications.

     

    References:

     

    Information on US surveillance activities against foreign counties:

    http://www.washingtonpost.com/blogs/the-switch/wp/2013/09/17/the-nsas-global-spying-operation-in-one-map/

    http://www.theguardian.com/world/2013/jun/08/nsa-boundless-informant-global-datamining

    http://www.spiegel.de/international/world/secret-nsa-documents-show-how-the-us-spies-on-europe-and-the-un-a-918625.html

    On the international law of espionage:

    A. John Radsan, The Unresolved Equation of Espionage and International Law, 28 Mich. J. Int’l L. 595 (2006-2007).

    Geoffrey B. Demarest, Espionage in International Law, 24 Denv. J. Int’l L. & Pol’y 321(1995).

     

    Report of the Special Rapporteur on the promotion and protection of the right to freedom of opinion and expression, Frank La Rue

    http://www.ohchr.org/Documents/HRBodies/HRCouncil/RegularSession/Session23/A.HRC.23.40_EN.pdf

     

    International Principles on the Application of Human Rights to Communications Surveillance.

    https://en.necessaryandproportionate.org/text

  • PRG – Overview of Legal Implications of NSA Spying

    Post-911 laws and FISA court developments. PRG Discussion on 9/18/13

    FISA Act governs gathering of data about foreign actors, set up in wake of Watergate.  Created framework for data collection and court review by FISA courts.   With the Patriot Act, push to expand powers and reach of a number of laws.  Patriot Act expanded FBI ability to send out administrative letters to collect information without court order and created roving wiretaps.  Legalized “sneak and peek” searches without immediate notification to target.

    Section 215 of the Patriot Act lowered the threshhold for search to any situation where collecting foreign intelligence is “a purpose” rather than just the only purpose.  16 provisions were set to sunset in 2005, but 14 were made permanent and two were reextended to 2015.

    Other key event was Bush Administration setting up wideranging wiretapping program and Section 702 of FISA creating official rules for targeting persons outside the United States.  These will be coming up for renewal in coming years.

    FISA court created under 1978 Act; 11 district court judges appointed by Chief Justice of the US Supreme Court.  Most opinions have been secret. Following expansion of requests to become more programmatic, FISA has been issuing long but secret opinions creating precedents for operation of the FISA court.    Existing Supreme Court precedent has been declared to make metadata given to a third party not subject to Constitutional protection.   34,000 surveillance requests since FISA created; 11 have been rejected.

    Not an adversarial proceeding with no actor representing person or groups whose data is to be accessed.  In many cases, information collected via FISA is then tracked down through other sources by FBI to “cover the tracks” so that the fact that FISA was used does not have to be presented in later public court proceedings.

    Anyone on US soil is not covered by FISA but non-citizens not on US soil have no protections under the law.

    Question raised about whether revelations about NSA were shocking because they revealed the extent of surveillance allowed by the law or whether there are real violations of US law.  A related question is whether the surveillance violates international law.

    Section 215 now allows collection of “any tangible thing”, which has been interpreting to mean whole telecommunications databases.  Restriction on collection if search is “solely based on First Amendment activities” which is not very restrictive if FBI can find any other reason to justify such a search.   Old law restricted access to specific information about a suspect person has become access to any data “relevant” to an authorized investigation. Minimization procedures are limited by fact that data retention allowed to “understand foreign intelligence” or related to a crime.

    Section 702 allows AG and Director of National Intelligence can set up surveillance program with no court overview once it’s established. Collection of data on US persons is allows as long as it is not intentionally targeting US persons. Statute says government does not have to specify who they want to target or where they want to look in any specific surveillance operation approved by a FISA proceeding.

     

  • Setting up Accounts at PRG

    Hi all– If you don’t have an account on the blog yet, please register at the link at the bottom of this post.

    If you have a twitter account that is devoted primarily to privacy-related tweets, please list it in comments in this post.

    For others, add #nyuprg to your tweets and we’ll figure out how to start incorporating them into the page.

  • New York’s E-ZPass: We’re watching you (Salon.com)

    Courtesy of Salon‘s Andrew Leonard:

    “Let’s file this one under the category of things we were reasonably sure were happening already, but are still greatly annoyed to have confirmed. New York City, reports Kashmir Hall in Forbes, has been tracking the movements of cars equipped with E-ZPass RFID tags all over the city — not just at the toll booths for which New York drivers presumably purchased their E-ZPasses to get through.

    The surveillance was uncovered when an electronics tinkerer who styles himself  ”Puking Money” hacked his E-ZPass to, no joke, go “moo cow” each time it was pinged by a reader.”

    Click through for the grizzly details.

  • Repost: DEA directs agents to cover up the sources of information used to investigate Americans

    This story courtesy of Akiva Miller:

    “Reuters reported yesterday that the Drug Enforcement Administration (DEA) has been starting criminal investigations of drug-related offenses based on information obtained from  from intelligence intercepts, wiretaps, informants and a massive database of telephone records – information that usually cannot be used in criminal investigations not related to national security matters. The DEA agents were directed to “recreate” the investigative trail to effectively cover up where the information originated. This practice violates defendants’ constitutional rights to a fair trial. http://www.reuters.com/article/2013/08/05/us-dea-sod-idUSBRE97409R20130805

    This Reuters context piece helps explain how this practice differs from the NSA Surveillance program, and is a far worse violation of civil rights: http://www.reuters.com/article/2013/08/05/us-dea-sod-nsa-idUSBRE9740AI20130805

    Meanwhile, USA Today reported that the Justice Department is now reviewing the DEA’s techniques:  http://www.usatoday.com/story/news/nation/2013/08/05/justice-dea-special-operations-shield/2620439/

    This revelation exposes how surveillance practices are going beyond the narrow realm of national security needs and are increasingly being employed against Americans for ordinary law enforcement purposes – the very realm where civil rights are vital safeguards against agency violation. Now that unlawful surveillance has been exposed in the fairly controversial area of drug enforcement, one can imagine the reaction if it turns out other agencies are using similar tactics: How would businesses react if the IRS were illegally obtaining their phone records, and then started a “random” audit on its secret surveillance target? Or how would gun rights supporters feel if the ATF Bureau were listening to phone conversations and arresting unregistered gun owners claiming “reliable informants” had led them to their targets? It wil also be interesting to see how this will affect the convictions of drug-related charges who may have been victims of these tactics. ”

     

  • Both sides to the NSA surveillance debate

    Position 1: Snowden is a whistleblower and what the government is doing is illegal: http://www.whistleblower-insider.com/the-simmering-storm-over-americas-secret-surveillance-court/

    Position 2: Snowden leaked classified documents improperly, and in fact, there are many controls and restrictions governing surveillance: See this talk by  Robert Litt (General Counsel of the Office of the Director of National Intelligenceat) at a recent a Brookings event http://www.c-spanvideo.org/program/GovernmentInte

  • ACLU’s revelations on License Plate Readers

    http://www.aclu.org/blog/technology-and-liberty-national-security/police-documents-license-plate-scanners-reveal-mass

     

    26000 pages of law enforcement data reveal: low hit rate, lots of variation across states and cities with regard to data retention policies.

  • Why trying to RFID track school kids may not work

    Possibly, because the idea is faulty. Something which this program in Texas is experiencing. Though, they seem to be replacing RFID with hundreds (!) of surveillance cameras. And why? To enjoy more federal funding.

    See the following link

     

  • Battling Big Brother, comments from Personal Democracy and Freedom, 2013

    I was invited to be a panelist at this year’s Personal Democracy and Freedom (PDF) conference held here in New York City. The panel was titled, “Battling Big Brother” and the idea was to comment on the degree to which individuals may be caught up in collateral damage from government collection and mining of data for the purpose of national security. I great question, indeed!

    I wanted to make a few comments on that panel, and thought I’d reproduce some of them for this blog below.

     

    I’m sure by now everyone is familiar with the hype around collecting and mining big data for individual patterns. And it’s not going to shock anyone to state that government, just as with private sector (e.g. facebook and google) have great interest in doing this.

    As far as commercial interests are concerned, from what I see, these often focus on advertising — how can content providers effectively identify their visitors in order to present them with relevant ads? On one hand, the consumer benefits are obvious. Think of all the free online services and mobile apps that we use every day — they are likely supported by advertising. On the other hand, there are privacy concerns when people are tracked, and other personal characteristics inferred, without their consent (e.g. target pregnancy girl). Moreover, there may be economic consequences from price discrimination which may also be seen as unfair. E.g. when those of higher income receive greater discounts than lower income people.

    Public interests of big data include, among other things, law enforcement and national security. But they have an advantage that private sector doesn’t in their ability to link many more kinds of disparate data sources and make more important inferences. They can combine CCTVs, drones, and of course, data collected from the private sector like phone records, emails, search engines, and network traffic from ISPs. I think we can all agree that the benefits of preventing bombings, and cyber attacks using these big data sources are large. What is of debate is how state agencies go about that and what tradeoffs we are willing to accept (e.g. PRISM and Verzion phone metadata collection).

    I now want to talk for a few minutes about two recent news stories that I think are relevant to this discussion. The first is this week’s supreme court decision to allow DNA collection at the time of arrest for a violent crime. Ostensibly, this is done to because of the strong force of recidivism: the notion that a criminal caught for one crime may have committed some other, unresolved crime. The novelty — and risk — is that DNA is thought to be a better detection mechanism than fingerprints because it’s more difficult to conceal one’s DNA at a crime scene. But again, consequences occur when we feel that the government is overstepping its authority — when they suddenly have access to data we don’t think they otherwise should.  What interests me most about the ruling, however, is the question: does DNA collection really work? I think there is a legitimate issue of whether law enforcement is more effective when they can obtain this information. I think this is important because if many more criminals are caught who would otherwise not be, then it becomes a discussion of tradeoffs. However, if there is no measurable effect, then the policy seems strictly bad.  Similar questions can — and probably should — be asked of other forms of government data collection and surveillance: unless  there is clear evidence of the effectiveness, where is the justification?

    The other story is one authorizing military commanders to engage in what’s called ‘active defense.’ i.e. to hit back at attackers who conduct cyber attacks on military systems. The benefits of this style of defense have been debated (at least) in the IT security community for many years, and it’s interesting to see acknowledgement of this kind of behavior by the military now. Perhaps this is due to reportedly dramatic increase in espionage from China.  There have also been calls by private companies (e.g,. those victimized by loss of IP) to engage in the same kind of behavior. What is not clear, however, is what force of retaliation is suggested, and what kind of collateral damage may be caused by this.

    Now, to the question of what can individuals do? On one hand there are a host of privacy enhancing technologies and practices that individuals can employ: when searching online, you can use duckduckgo; when looking to browse anonymously you can use TOR; when purchasing groceries, you can use someone else’s loyalty card number; you can choose not to register a DC metro card; etc, etc. This makes us very empowered as consumers. However, on the other hand, at some point, you *will* leave a digital trail. You will need to go outside (where you’re likely to be captured on CCTV); you will need to buy something with a credit card, or take out a loan (adding to your credit profile); make a call on your cell phone; or you will simply forget to use one of those PETs.  And so I’m quite conflicted regarding the extent to which individuals really have any power to control their digital trails at all.  To me, the persistence and ubiquity online tracking and surveillance as an unstoppable force and that while we may be able to redact some entries from the mountains of data files we leave, I don’t see any practical solution to avoiding creation of those files to begin with.

    PDF Program: http://personaldemocracy.com/conferences/nyc/2013/program

  • comScore and their privacy litigation woes

    I recently had a chance to learn about and speak with folks from a company called comScore. Essentially, this company offers free stuff to consumers in exchange for tracking all their web browsing activity. And they can get very detailed information about one’s buying habits. This can be very good for research, and potentially socially useful in other ways (advertising, etc).

    However, collecting that much personal browsing information about so many consumers (millions) seems very very risky. I’ll even go so far as to suggest a ticking timebomb of liability because of the concern of a data breach (i.e. some one hacking into the company stealing all this information). As it turns out, that liability is coming from consumer concerns that the company collected and sold data without the consumers’ consent. (now, I’m not really sure how people would be unaware of that, given that this is the company’s business model).

    I’ve examined privacy litigation in previous work (here: http://ssrn.com/abstract=1986461) and based on our work, that the class was certified in this current laswuist suggests bad news for comScore. We found that class certification was very strongly correlated with settlement. I don’t know how big the class will finally be, but if it does get into the millions, multiply that by the statutory damages from their ECPA and SCA claims and yikes!

    See: http://www.paulhastings.com/publications-items/blog/post/caveat-vendor/2013/04/10/certification-of-privacy-class-harbinger-of-things-to-come-#page=1