Categories
Links Writing

Draft Paper: Do Transparency Reports Matter for Public Policy?

Telecommunications companies across Canada have begun to release transparency reports to explain what data the companies collect, what data they retain and for how long, and to whom that data is, or has been, disclosed to. This article evaluates the extent to which Canadian telecommunications companies’ transparency reports respond to a set of public policy goals, namely: of contextualizing information about government surveillance actions, of legitimizing the corporate disclosure of data about government-mandated surveillance actions, and of deflecting or responding to telecommunications subscribers’ concerns about how their data is shared between companies and the government. In effect, have the reports been effective in achieving the aforementioned goals or have they just having the effect of generating press attention?

After discussing the importance of transparency reports generally, and the specificities of the Canadian reports released in 2014, I argue that companies must standardize their reports across the industry and must also publish their lawful intercept handbooks for the reports to be more effective. Ultimately, citizens will only understand the full significance of the data published in telecommunications companies’ transparency when the current data contained in transparency reports is be contextualized by the amount of data that each type of request can provide to government agencies and the corporate policies dictating the terms under which such requests are made and complied with.

Download Telecommunications Transparency in Canada 1.4 (Public Draft) (Alternate SSRN link)

Categories
Quotations

2015.1.6

We understand that cellphone searches are sometimes necessary to obtain important evidence. But the same is true of searching your home. The most invasive searches tend to be the most useful, precisely because of their invasiveness. The U.S. Supreme Court recently recognized this in a unanimous decision requiring a warrant for cellphone searches. As a society, we’ve decided that police need a warrant to search your home, barring exceptional circumstances. But the underlying assumption – that our homes, not our phones, contain our most private information – is increasingly untrue. Should police search our homes, we would not be alone among our generation were our first thought: “Oh god – is my phone there?”

Anisah Hassan and Josh Stark, “Phones are more private than houses – so shouldn’t be easier to search”
Categories
Aside

2015.1.3

So…did GCHQ et al intercept and decrypt BBM messages, or were they just handed over?

Categories
Quotations

2015.1.2

Our relationship with Facebook, Google and Amazon isn’t symmetrical. We have no power to define the relationship and have zero say in how things work. If this is how commercial companies treat humanity, what can we expect from governments that are increasingly normative in what they expect from their citizens? Our governments have been taken hostage by the same logic of productivity that commercial companies use. With the inescapable number of cameras and other sensors in the public space they will soon have the means to enforce absolute compliance. I am therefore not a strong believer in the ‘sousveillance’ and ‘coveillance’ discourse. I think we need to solve this problem in another way.

Hans de Zwart, “Ai Weiwei Is Living In Our Future: Living under permanent surveillance and what that means for our freedom”
Categories
Links Writing

The Canadian SIGINT Summaries | Technology, Thoughts & Trinkets

The Canadian SIGINT Summaries | Technology, Thoughts & Trinkets :

Journalists with access to leaked documents have reported on the partnerships and activities undertaken by Canada’s foreign signals intelligence (SIGINT) agency, the Communications Security Establishment (CSE), since October 2013. As a result of their stories we know that the Canadian government hosts collection facilities in its diplomatic outposts for American SIGINT operations, has co-ordinated with the NSA to monitor for threats to international summits that took place in Canada, and shares a cooperative relationship with the National Security Agency (NSA) to protect North America from foreign threats. CSE, itself, was found to be conducting signals intelligence and development operations against the Brazilian government, running experiments using domestically collected metadata to track Canadians’ devices, and automating both the discovery of vulnerable computer devices on the Internet for later exploitation and identifying network administrators’ Internet traffic.

The aforementioned revelations are just a sample of what Canadians have learned as journalists have reported on documents leaked to them by Edward Snowden and other whistleblowers. But it has been challenging for even experts to keep track of the Canadian discoveries amongst the tidal wave of information concerning American and British SIGINT agencies. I have created and published a resource to help researchers and members of the public alike track mentions of CSE in documents that have been reported on by professional journalists.

Curious what has been revealed about Canada’s signals intelligence agency since Edward Snowden’s revelations began in summer 2013? Then check out The Canadian SIGINT Summaries. They’ll be updated as more information is available!

Categories
Links

Privacy issues could not be ignored in 2014 (video)

This links to the full video interview I gave to Postmedia about privacy issues in 2014. On the whole I’m actually pretty optimistic about things: we know more than in the past about the extents to which governments engage in surveillance. The organizations and individuals who subsequently act on this knowledge are more capable, today, than they were even two years ago. And the political class is increasingly aware that privacy and transparency issues are becoming more and more important to their constituents.

Now, does this optimism mean that things will necessarily improve dramatically in 2015? Of course not. But momentum continues to build and more and more individuals and organizations are taking privacy issues seriously. And that’s cause for some celebration as far as I’m concerned.

Categories
Links

Privacy issues could not be ignored in 2014 (Transcript Summary)

Privacy issues could not be ignored in 2014 (Transcript Summary):

Categories
Aside Links

U.S. Cyber Command investment ensures hackers targeting America face retribution

U.S. Cyber Command investment ensures hackers targeting America face retribution :

Later that summer, Marine Lt. Gen. Richard P. Mills bluntly told a conference in Baltimore that commanders under his control in Afghanistan routinely used cyberwarfare tactics to attack and disable al Qaeda and Taliban enemies.

“I can tell you that as a commander in Afghanistan in the year 2010, I was able to use my cyberoperations against my adversary with great impact,” Gen. Mills was quoted at the time as saying. “I was able to get inside his nets, infect his command and control, and in fact defend myself against his almost constant incursions to get inside my wire, to affect my operations.”

While the military is developing the capability, the political and policy realm is struggling with the right parlance.

If that’s the language that US generals are using to explain what ‘cyber’ is then I think that the executive-class is clueless about the things that their ‘cyberwarriors’ are up to. And if they’re this clueless then how can they be relied on (or quoted in anything other than a mocking way?) to provide expert advice to policy makers, politicians, or the public?

Categories
Links Writing

Hacking Our Humanity: Sony, Security and the End of Privacy

Hacking Our Humanity: Sony, Security and the End of Privacy :

The lesson here isn’t that Hollywood executives, producers, agents and stars must watch themselves. It isn’t to beware of totalitarian states. It’s to beware, period. If it isn’t a foreign nemesis monitoring and meddling with you, then it’s potentially a merchant examining your buying patterns, an employer trawling for signs of disloyalty or indolence, an acquaintance turned enemy, a random hacker with an amorphous grudge — or of course the federal government.

And while this spooky realization prompts better behavior in certain circumstances that call for it and is only a minor inconvenience in other instances, make no mistake: It’s a major loss. Those moments and nooks in life that permit you to be your messiest, stupidest, most heedless self? They’re quickly disappearing if not already gone.

Though I find various aspects of Bruni’s article insulting (e.g. “…the flesh that Jennifer Lawrence flashed to more people than she ever intended…”) the discussion of who are the most common threat actors that people have to worry about is a fair point. It’s also important to discuss, and discuss regularly, that the ‘defences’ which are commonly preached to protect our privacy are fraught with risk. While being silent, not associating with one another, or not reading certain things online might keep one ‘safe’, engaging in such censorious activities runs counter to the freedoms that we ought to cherish.

Such responses ignore the costs — often paid in blood or years of people’s lives— that have gone into fighting for the freedoms that we now enjoy and that are engrained in our constitutions, our laws, and our social norms. They forget the men and women who fight and die on battlefields to protect the freedoms of citizens of other nations. And, perhaps most significantly, such responses demonstrate how larger social movements directed at enshrining our freedoms through collective action are set aside, often cynically, so that we can try and resolve the problems we all face as individuals instead of as collective political actors. Self-censorship isn’t just a means of ensuring self-protection; it’s an exhibition of citizens’ unwillingness to at try and utilize our political processes to resolve common social ills.

Categories
Links Writing

Public and private sector companies vulnerable to Sony-like attacks

Public and private sector companies vulnerable to Sony-like attacks :

Christopher Parsons, the managing director of a telecom transparency project in The Citizen Lab at the University of Toronto, said agrees with Tobok; it’s not enough for companies to leave digital security to their designated IT employees or mid-level management.

“It’s an increasingly serious issue; companies not treating it at the top do so at their own peril.”

Bigger security breaches are a reality of a more digitally-literate world, Parsons said.

“If you’re dealing with a well-resourced attacker with lots of time, there’s a reasonable chance they will find some way through.”

That’s why companies also need to invest in a strong remediation strategy in case an attack does occur, he said.

I should be particularly emphatic on one point: the hack of Sony does not constitute ‘cyberwar’. To begin, the very definition of the term is ambiguous at best. Moreover, the attack on a non-critical-systems company cannot be understood as an assault on critical infrastructure systems (e.g. dams, power grids, etc) that could be interpreted as an undeclared war-like action. What has happened to Sony is a corporate tragedy and one for the textbooks on remediation and mitigation strategies. To be clear: this is a lesson for business and security textbooks, not military strategy textbooks.

Claims that the attacks on Sony are some kind of ‘warlike’ behaviour operate on the assumption that we can attribute who is responsible for the attacks. We are unable to so ascribe action at the moment. And until the NSA or the other SIGINT agencies pull stuff from their bags of tricks to more positively establish a link between the attacks on Sony and a specific nation-state threat actor with obvious war-based intentionality, any calls that we are witnessing some kind of ‘cyberwar’ are ill-considered at best, and outright ignorant at worst.

Or, alternately, such calls might constitute efforts on the parts of those with Top Secret/Special Compartmentalized information to raise awareness about some kind of ‘behind the scenes’ action. I strongly doubt those calling the Sony attacks cyberwar have access to such kinds of deeply sensitive operational, and classified, information. But perhaps I’m wrong. And, if I am, I hope they’re leaking with authorization or have particularly terrific counsel to defend them against allegations of leaking classified information.