Categories
Writing

Cyberstalking, Victimization, and the Experience of Fear

Ars Technica has a good piece on how cyberstalkers and bullies operate, with reporting based on studies (circa 2006, admittedly) and some anecdotal evidence. In effect, the mechanisms to stalk and bully online are often easy to use, reasonably accessible, and capable of significant intrusion into people’s lives. However, what struck me most poignantly was the concluding section of the article:

In this particular case, going to law enforcement wasn’t going to be much of an option. The woman said she had gotten rid of the BlackBerry, so there was no way to perform forensics on it to gather evidence. The same was true of her father’s computer, which the technician had wiped clean.

That’s a common problem in dealing with these sorts of cases, Southworth said. “Some victims just want their device clean and just want the stalking to stop. But if you clean off the device, you’re destroying the evidence.” And for victims who are trying to deal with an abusive relationship, trying to do anything to remove malware from a phone or computer could put the victim in danger. “Even looking for the spyware can raise the risk,” Southworth said, because the software could alert the attacker of the attempt and trigger violence.

And even when software is removed, the persistence of such stalkers usually means that they won’t stop their behavior—they’ll just take different approaches. That, paradoxically, is an upside for law enforcement, Southworth said. “They don’t stop, so if she wants law enforcement to get involved,” she said referring to the victim, “there’s likely another form of stalking going on for them to catch him with.”

People who haven’t experienced stalking, or the fear of stalking, may not appreciate the emotional desire to just make it stop. Such desires are often based on an attempt to feel ‘safe’ again, often when doing simple things like buying groceries, waiting for a bus, or just going home. As such, wanting to remove the suspicious tracking systems – instead of leaving them there, and maintaining the fear, in the hopes of a criminal arrest – will often take priority over ‘catching’ the perpetrator. But, at the same time, there is often a fear that the very act of ‘making the surveillance stop’ could lead to physical consequences. It’s a lose-lose experience, where any decision merely modifies the ‘kind’ of fear instead of terminating the experience of fear itself.

Moreover, removing suspected surveillance-ware may not alleviate the fear of being monitored: most technical systems (effectively) operate like magic for the majority of the computer-using population. How the surveillance-ware was even installed, or if it was all purged, or if it could infect a person’s computer systems again, will often pervade how a person uses computers. In light of specific concerns (surveillance) that are imprecisely directed (i.e. is my phone, my computer, or other device infected and, if so, would I even know?) a person may simply avoid some actions or actively engage in deceptions to ‘throw off’ someone who might be watching.

In effect, concerns of possible but undetected surveillance are often accompanied by heightened privacy and security efforts. These efforts might be more or less effective (or even needed!), and taking such efforts will almost certainly diminish a person’s ‘normal’ uses of services (e.g. Facebook) that their (not-stalked/bullied) friends and colleagues get to enjoy. Moreover, the experience of having to use such privacy and security techniques is representative of the scarring left by online stalking and bullying: ‘normality’ becomes defined as a defensive posture online based on (often) physical fears. No one’s ‘normal’ should be predominantly defined by fear.

It’s this broader emotional fear that is challenging to address, both in terms of law (i.e. getting the data needed to pursue a meaningful conviction or punishment) and personal mental health (i.e. learning to ‘trust’ systems that aren’t really understood and that have previously compromised a person’s life possibilities).

In Canada, the federal government has recently introduced legislation ostensibly meant to crack down on cyberbullying linked to the unauthorized sharing of a person’s intimate images. While criminalizing the sharing of such images may be a helpful addition to the Criminal Code for certain kinds of cases, doing so doesn’t address the broader challenges linked to cyberstalking and cyberbullying. Addressing these challenges requires something else – though I don’t know what – that meaningfully responds to the societal issues associated with online stalking and bullying in a more holistic manner, a manner that frees people from the persistent fear of being a victim despite going to either law enforcement or removing the stalking-ware.

Categories
Quotations

2013.11.11

Generally it takes an incident to focus attention on the issue of informational privacy – and such incidents tend to focus on one type of record system at a time. This human interest element helps to define the policy problem, galvanize media and public attention, and give members of Congress concrete examples of privacy invasion to justify their votes. There is always vocal and well-financed opposition to privacy protections, generally from business and government bureaucrats who do not want to restrict access to information. Their opposition is usually quite successful in weakening the proposed privacy protections and in further narrowing the scope of such protections. And after passage opponents are likely the challenge legislation in the courts, often on the basis of First Amendment grounds that any information, including that about individuals, should flow freely and without government restrictions.

Priscilla M. Regan (2008), “The United States,” in Global Privacy Protection: The First Generation, James B. Rule and Graham Greenlead (eds.).
Categories
Writing

We Need Clarity on ‘National Security’ Rules for Telecommunications

The story of Blackberry has gripped many technology watchers, watchers who are bearing witness to the trials and tributations of the company as it struggles to compete in the increasingly populated smartphone market. To some, it seemed that one way ‘out’ for Blackberry was for the company to be purchased by another firm looking to aggressively enter this market. Based on recent reporting by the Globe and Mail, however, it looks like any hopes that Blackberry might be purchased could be scuttled for ‘national security’ reasons.

Specifically, Steven Chase and Boyd Erman write that,

Ottawa made it clear in high-level discussions with BlackBerry that it would not approve a Chinese company buying a company deeply tied into Canada’s telecom infrastructure, sources said. The government made its position known over the last one to two months. Because Ottawa made it clear such a transaction would not fly, it never formally received a proposal from BlackBerry that envisioned Lenovo acquiring a stake, sources said.

on Monday the Canadian official took pains to emphasize that concerns about BlackBerry are not part of a trend to shut out Chinese investment. “This is a company that has built its reputation and built its success on system security and its infrastructure. That’s one of the reasons businesses use BlackBerries. … The security is robust and we’d obviously have an interest in making sure we didn’t do anything or allow anything that would compromise Last fall, citing a rarely used national-security protocol, Ottawa has sent a signal to Chinese telecom equipment giant Huawei Technologies that it would block the firm from bidding to build the Canadian government’s latest telecommunications and e-mail network. Huawei, founded by a former People’s Liberation Army member, has on numerous occasions found itself having to reject claims its equipment could be used to enable spying.

In October. 2012, a senior spokesman for Prime Minister Stephen Harper publicly hinted Huawei would be left out the cold. “I’ll leave it to you if you think that Huawei should be a part of [the] Canadian government security system,” Mr. MacDougall said.

I’m particularly mindful of the possible security issues that may be linked to letting foreign-located businesses playing significant roles in Canadian telecommunications networks. But, at the same time, the present Canadian government seems to be applying ‘national security considerations’ in a manner that prevents market analysts and watchers from clearly assessing when such considerations might be applied.

Without clear criteria, what are the conditions under which a non-Canadian company could purchase Blackberry? Could a well-financed American company buy it, based on what we’ve learned about NSA surveillance? Could a company that was known to comply with foreign governments’ lawful interception requirements buy Blackberry, given that such requirements could have a global reach? Could Blackberry be purchased by companies that operate in countries that, if their governments had access to Blackberry communications, could gain an edge in international diplomatic engagements with Canada or its closest international partners?

I don’t dispute that national security may sometimes demand terminating business deals that would violate the national interest. However, given that incredibly large investments are being killed by the federal government of Canada it is imperative that the government make clear what ‘national security’ interests are at play, and the security models that motivate terminating such deals. To date, neither the interests nor models are particularly clear. As a result, analysts are forced to read the outcome of federal decisions without the benefit of understanding the full rationale of what went into them in the first place. The result has been to make it incredibly uncertain whether foreign businesses will be legally permitted to engage in market operations with Canadian companies.

Canadians are all to aware that the current federal government has failed on its promise to provide a digital strategy for the Canadian marketplace. In the absence of such a strategy, perhaps the federal government could at least provide its rules for determining when a business proposal runs counter to national security?

Categories
Links

The Politics of Deep Packet Inspection: What Drives Surveillance by Internet Service Providers? | Technology, Thoughts & Trinkets

My dissertation is now available to the public!

Categories
Links

iCloud Keychain isn’t the same as Lightroom!

Jon Brodkin, writing for Ars Technica:

Unfortunately, it’s kind of a mess. iCloud Keychain does accomplish the most basic things you’d expect a password manager to do, but it often does so in an awkward manner. Important functionality is hard enough to find that it may be effectively hidden from the average user, particularly on iPhones and iPads.

Ultimately, iCloud Keychain can be put to good use if you’ve carefully examined what it does well and doesn’t do well. It works best as a complement to a complete service like 1Password or LastPass, but it just isn’t convenient and robust enough to act as a standalone password manager.

I think it’s a bit harsh to call it a “mess”, but Brodkin provides a good overview of what iCloud Keychain does. Complaining that it’s not as full-featured as 1Password is like complaining that iPhoto doesn’t do everything Lightroom or Aperture do.

Comparing iCloud Keychain and Lightroom is a bit odd. One helps to manage the security of one’s online life and is meant to resolve a security problem for anyone who uses the Web. Lightroom is a specialist product that caters to experts in a particular field. The two products may have an overlapping user base (i.e. individuals who want secured usernames and passwords) but otherwise bear little resemblance to one another.

Categories
Quotations

2013.11.4

The NSA allegedly collected the phone records of 320 million people in order to identify roughly 300 people who might be a risk. It’s just bad public policy.

Eric Schmitt, in “Google’s Eric Schmidt calls NSA surveillance ‘outrageous’
Categories
Links Quotations

Andrew Coyne: Conservatives’ effort to hide from public only gains them more enemies

“…the Conservative tragedy grinds on. When your only principle is paranoia — when your central organizing proposition is that “everyone is out to get us” — when every criticism is merely confirmation of the essential rightness of that proposition, and every deviation is evidence of disloyalty, then you are less a party than a cult.”

Strong words, this time from Andrew Coyne.
Categories
Links Writing

Did Canadian Oil Companies Get a Tip-Off from CSEC?

The Globe and Mail reports on discussions in the Canadian Senate. Specifically, Liberal Senator Wilfred Moore asked:

“Can the [Senate] leader enlighten this chamber as to what was done with the data obtained by CSEC from the Brazilian Ministry of Mines and Energy?”

Alleging that CSEC’s “cyberhacking” was intended to probe Brazil’s claims about discovering billions of barrels of oil in a new offshore-field find, Mr. Moore noted that no Canadian or U.S. corporations have joined the bidding for drilling rights in an auction that was held earlier this week in Brazil.

This is an incendiary question. If it turns out that Canadian companies didn’t bid because CSEC found Petrobras has overestimated the oil reserves in the Libra field, or if CSEC found that it was going to be harder to extract the oil that stated by the Brazilian government, then it’s a very, very big deal on the basis that the Canadian government (and extension of the department of national defence) would then be engaging in espionage on the behalf of Canadian companies.

Categories
Links Writing

NSA Revelations Kill IBM Hardware Sales in China

For several months there have been warnings that the NSA revelations will seriously upset American technology companies’ bottom lines. Though not directly implicated in any of the leaks thus far it appears that IBM’s Chinese growth predictions have just been fed through a wood chipper. From Zerohedge:

In mid-August, an anonymous source told the Shanghai Securities News, a branch of the state-owned Xinhua News Agency, which reports directly to the Propaganda and Public Information Departments of the Communist Party, that IBM, along with Oracle and EMC, have become targets of the Ministry of Public Security and the cabinet-level Development Research Centre due to the Snowden revelations.

“At present, thanks to their technological superiority, many of our core information technology systems are basically dominated by foreign hardware and software firms, but the Prism scandal implies security problems,” the source said, according to Reuters. So the government would launch an investigation into these security problems, the source said.

Absolute stonewalling ensued. IBM told Reuters that it was unable to comment. Oracle and EMC weren’t available for comment. The Ministry of Public Security refused to comment. The Development Research Centre knew nothing of any such investigation. The Ministry of Industry and Information Technology “could not confirm anything because of the matter’s sensitivity.”

This is the first quantitative indication of the price Corporate America has to pay for gorging at the big trough of the US Intelligence Community, and particularly the NSA with its endlessly ballooning budget. For once, there is a price to be paid, if only temporarily, for helping build a perfect, seamless, borderless surveillance society. The companies will deny it. At the same time, they’ll be looking for solutions. China, Russia, and Brazil are too important to just get kicked out of – and other countries might follow suit.

Now, IBM et al. aren’t necessarily purely victim to the NSA’s massive surveillance practices: there likely are legitimate domestic market changes that are also affecting the ability of Western companies to sell product in China and other Asian-Pacific countries. But still, that NSA can be used to justify retreats from Western products indicates how even companies not clearly and directly implicated in the scandals stand to lose. One has to wonder whether the economic losses that will be incurred following the NSA revelations are equal to, or exceed, any economic gains linked to the spying.

Categories
Links

Greater Oversight Required for Canada’s Spy Agencies

This is the kind of introspection and critique that all backbenchers should be able to present to the public. They shouldn’t be forced to leave their party caucus to do so.

Source: Greater Oversight Required for Canada’s Spy Agencies