Showing posts with label Data Protection. Show all posts
Showing posts with label Data Protection. Show all posts

Tuesday, 2 February 2010

Solicitors From Hell -- Real life experience

solicitors from hell

A curious little matter dropped onto my desk last week - one of many at the moment, actually; there just don't seem enough working hours in the day.

Essentially, it seems that we provided communication services to firm of solicitors who are now subject to an Intervention under s35 and Schedule 1 of the Solicitors Act 1974.  We were approached by the firm who are acting as Intervention Agents on behalf of the Solicitors Regulation Authority to confirm detailed information about our client and re-direct their phone lines to the offices of the Intervention Agents. Initially, I found out, these requests were made via a phone call to the support dept. and then, when information was not forthcoming from that member of staff, a firmly word fax hinting that they were on the cusp of applying for a court order to compel us to provide the information required.

Being the most cautious of all risk-averse people, my data protection spiny senses were initially sent into overdrive at the mere thought of all this.

I did a little research as to exactly what our obligations were, checked out the firm acting as Intervention Agents and the firm being investigated.  My preliminary research bore their fax and phone calls out.

A quick flick through the Solicitors Act didn't seem to reveal anything as to what our obligations were to provide this information and how it sat with the relevant Data Protection legislation. I was left with no alternative then, than a rummage through the depths of the Data Protection Act, something I hadn’t done in well over a year, since early on in my LLM. It didn’t take me long to find that this situation pretty much fell squarely under s31 of the Act, covering exemptions from the Subject Information Provisions in relation to regulatory activity.

So that was more or less that then.  I was shocked at how prominently the firm being investigated featured on the web from previous clients who’d had their fingers burnt.  Perhaps unsurprisingly, I also found that they were featured on the Solicitors From Hell website. I’d not heard of this site until last Thursday; since then, I’ve noticed that Charon QC and Aimless Wanderer have both mentioned it. I should imagine that a lot of lay people out there believe that all firms of solicitors should feature on that site!!

Still, this bit of excitement made a change from drafting and reviewing endless contracts, resolving number portability conundrums and advising on stuff under the Communications Act – plus strategising how to prod, poke or otherwise coerce OFCOM into action over a specific issue.

Tuesday, 21 July 2009

Facebook, Privacy, Risks – you know what’s coming

social media

From Outlaw.com 21/07/09:

Jennifer Stoddart's office has investigated the social networking website's use of personal information and has found that Facebook is not clear enough about how users can control their information or restrictive enough in restricting other companies' access to it.*

The Commissioner's office said that the company needed to be more transparent.

"Social networking sites can be a wonderful way to connect. They help us keep up with friends and share ideas and information with people around the globe," said assistant commissioner Elizabeth Denham. It is important for these sites to be in compliance with the law and to maintain users’ trust in how they collect, use and disclose our personal information*.”

The investigation found that users were told on Facebook how to deactivate accounts, but not how to delete them*. Only deleting accounts actually removes personal information from Facebook's servers.

* My emphasis

Seeing as I haven’t engaged in any Facebook-bashing for a while, I thought I’d throw this post up. This topic actually reminds me of a paper I wrote for a competition earlier this year concerning the future of social networking services and the privacy of their respective users. Alas, I didn’t win though still believe I made some excellent arguments throughout (it was probably a touch too forward-thinking and conceptual for them).

In it I argued that for social networking services and privacy to co-exist in any meaningful way together, the first and crucial step was to raise awareness and educate users about the risks they faced and the tools at their disposal to manage those risks.

With informed users, I reckoned, not only would there be less online stupidity with people failing to appreciate the dangers and the full effects of their actions but it would allow for the harnessing of market forces to successfully regulate social networking providers. In short, where users were well-informed enough to choose a service which offered safe connectivity, prized security and respected users’ privacy, the respective social networking services would compete with one another on this front; security would become less of a trade-off with functionality and more of a function in its own right. For the average, less technically au fait user, well, they would be influenced by those in the know and the herd theory would operate to result in an exodus of users from services which didn’t pass muster on the security/privacy front.

There was a lot more to the paper than that, obviously, and it was heavily weighted on the side of regulatory theory rather than black letter law – perhaps that’s why I didn’t win – but I think many of the ideas I advanced are still good. I may publish it myself via Law Actually given time.

Monday, 2 March 2009

Citibank Identity Theft

I first saw Citibank’s series of hilarious commercials back in 2004 when I was out in the US over the summer.  While Citibank – like all banks at the moment – aren’t faring so well, this might be just the time for a light-hearted blast from the past.  Who said bank commercials can’t be fun?

Sunday, 8 February 2009

Privacy Law – In Need of a Legislative Broom?

Privacy Law From Outlaw 03/02/09:

Parliament will investigate privacy law in the UK and may give the law a 'nudge', Justice Minister Jack Straw has said. A select committee of MPs will look into how the law has developed and how it is being implemented by courts, he said.

How has the law developed? I can think of some fairly colourful responses to that. For the present, however, I think the following would all be particularly apt:

· Slowly  · Painfully  · Inconsistently  · Awkwardly

· Incoherently 

There are a bunch of other words I could include but a list has to stop somewhere. Of course, many of these descriptions are also applicable to how the law has been implemented by the courts.

“Historically, the UK has not had a law of privacy, but one has emerged in recent years that has combined confidentiality laws covering the exchange of information with human rights laws protecting the right to a private life.

Courts have ruled in several cases that the publication of information violates these laws, and
these judgments will form the basis of future rulings.

That case law was ferociously attacked last year by powerful Daily Mail editor Paul Dacre [in the aftermath of Mosley v NGN Ltd [2008] EWHC 1777] who condemned the fact that it had developed through the courts and not through Parliament.

Straw has told Parliament's Joint Committee on Human Rights, though, that a committee of MPs will look into the development of the law.”

Recent developments in privacy rights in the context of ‘celebrity newsgathering’ have illustrated that the law has now swung to opposite end of the spectrum whereby the courts have been inclined to attach more weight to the individual’s right to privacy than to the right to freedom of expression for the press. This change has happened relatively quickly: in 2002 both the Flitcroft and Theakston cases saw a ‘naming and shaming approach’ for celebrities caught in compromising situations robustly endorsed by the courts. Since Campbell and now Mosley, however, the approach has clearly changed.

The current test which evolved out the wealth of jurisprudence in this area essentially involves examining whether the individual had a reasonable expectation of privacy in all the material circumstances. If that is the case, there is then a need to move on to balance the right of privacy under Article 8 of the ECHR with the right to freedom of expression pursuant to Article 10. An inherent part of this balancing act is determining whether there is countervailing public interest that can justify the intrusion.

Mr Justice Eady has come in for a lot of ‘stick’ in recent times – not least in the aftermath of the Mosley decision. Eady J has had heard the majority of high-profile cases in this area and because of this, it’s no surprise that he was very much at target in Dacre’s scathing attack last year.

The Times notes how far-reaching Mr Justice Eady’s contributions to this area of law are perceived to be:

“Mr Dacre told the audience at the Society of Editors’ annual conference in Bristol that the judge’s “amoral” judgments, in this and other defamation and libel cases, were “inexorably and insidiously” imposing a privacy law on the press.”

Moreover, “[Dacre accused Eady J] of bringing in a privacy law by the back door: the judge, he said, had used the Human Rights Act against the age-old freedom of newspapers to expose moral shortcomings of people in high places.”

So what’s the Justice Minister’s take on privacy?

Again from the Times:

Lord Lester of Herne Hill, one of the Joint Committee members, asked Mr Straw where he stood on privacy: the Mail interview, Lord Lester said, gave the impression that Mr Straw would like to weaken the Human Rights Act, “so as to make it easier for the press to make unwarranted attacks on personal privacy”.

Straw did not say where he stood — other than backing the forthcoming privacy review. But he did indicate support for the Act’s critics. “Those of us keen to ensure that the legacy of the Human Rights Act continues and thrives need to be alive to that criticism — and respond to it,” he said.

The realisation of privacy rights under English law is essentially achieved via a blatant shoehorning of privacy rights into the law of breach of confidence. Have Parliament finally recognised the need for a legislative broom to sweep clean the detritus of confusion which plagues the law relating to privacy?

Without doubt, it’s high time for a review at the very least and considering afresh whether legislating is the way to go. Whether this leads to a ‘Privacy Act’, though, is another matter entirely. Ironically, this area of law has weathered greater uncertainty than it’s currently plagued with and it could be argued the courts are actually demonstrating a greater degree of creativity and recognition of wider societal issues when adjudicating than ever before. For instance, the case of David Murray v Big Pictures Limited [2008] EWCA Civ 446. involving photos taken of J.K. Rowling’s son as well as the application of the Harassment Act 1997 in respect of compromising photos published on an aggrieved former-lover’s Facebook profile illustrate that the jurisprudence is developing in a way that is factoring-in modern technologies and the privacy implications that the internet and social networking brings with it.  The equivalent could certainly not have been said in the early days of wiretapping by police nor in how the courts dealt with early forms of harassment via telephone.

Now, though, privacy issues seem to rank much higher on the list of priorities.  Currently, privacy concerns have been elevated to an all time high by virtue of the rise of the internet as a publishing medium, the Web 2.0 phenomenon and society’s voracious appetite for celebrity gossip which has fuelled the ever-more aggressive and intrusive behaviour of the press.  Also, in direct response to the Mosley case, perhaps it’s been recognised that the jurisprudence has developed in a direction which is now no longer deemed suitable and legislation is required to ‘nudge’ it back on track.

The use of the ‘legislative broom’ may help in certain areas to sweep clean and clear up the awkward uncertainty such as the apparent conflating of the right pursuant to Article 10 of freedom of expression with the ‘public interest defence’ in some judgements.  Whether privacy law which is more favourable to the press is the right approach to be taking going forwards, however, seems less clear.

In any event, the Times concludes: If legislation is mooted, then it will be an irony to think that Mr Justice Eady himself — when on the Calcutt committee that reported in 1990 on privacy — favoured a privacy law. The difference is that any new law would not be seeking to curb the press but to free it.

Monday, 28 July 2008

Another Facebook fiasco – here we go again

 

facebook privacy disaster From vnunet.com 16/07/08:

Facebook has accidentally revealed personal information about its members.

The social networking site divulged the dates of birth of many of its 80 million active users, even those who had requested that the information remained confidential.

Graham Cluley, senior technology consultant at Sophos, explained that the information was exposed during a public beta test of Facebook's new design.

"I was shocked to see people's full date of birth revealed, even though I knew they had their privacy set up correctly to supposedly hide the information." he said.

I’m not even the slightest bit shocked at this news; in fact, I’m surprised it wasn’t something more serious. With the social networking/web 2.0 wave that has swept the world in the last year and a half, people have thrown all sorts of personal information up on social networking sites without much regard to the consequences.

My gripe here is the principle and not the specific circumstances: revealing someone’s date of birth is hardly the end of the world but let’s not forget, it wasn’t meant to happen. What other personal information that people have entrusted with social networking sites might leak out to all and sundry? This is just the tip of the iceberg, people. It really is.

And BTW, what’s the deal with the new design: it doesn’t look that much different to me. Worst of all, from what I read, it’s going to mean even more Facebook oriented apps and widgets coming down the pike. You mean there weren’t enough already?! Oh great!

Thursday, 3 April 2008

Trouble on Myspace? Dial 999

Social Networking VictimFrom Gizmodo.com 02.04.08 

Social networking sites like Facebook, Bebo and MySpace may soon have to carry a '999' emergency link to improve the safety of kids online.

In a 73-page draft of a report due to be published on Friday by Home Secretary, Jacqui Smith, the sites will have to carry ads for the emergency services so that kids can call if they feel they are being targeted by potential abusers.

Experts contributing to the report claimed that youngsters are at risk from 'sexual grooming' by paedophiles, bullying and online fraud.

I'm not quite sure how practical and effective this suggestion is, quite honestly but at least the Government are examining the problems poses by social networking for young web users.  Undoubtedly, they want to be seen to be doing something, but whatever the reason, this issue is too important to ignore. 

I can't help feeling that better education of the risks involved, coupled with technological advances to help filter or restrict some of the more dangerous elements of the sites would be a more effective way to go.  I mean, blocking the site completely is more of a sure-fire way of removing the danger, but, sadly, if a kid wants to do something which their parents have forbidden, they'll generally find a way of doing it.  After all, they could opt for something as quick and straightforward as using the site at a friend's house whose parents don't block access to the site.

Better education, awareness and guidance are crucial because the whole point about online grooming is that the kids rarely recognise they're in danger.  Sticking an online banner ad up saying 'Dial 999' is going to have little effect on this problem, surely?  Save, perhaps, for tripling the number of hoax emergency calls.

In related news, Ofcom have today reported that around half the children using the net in the UK have profiles on social networking sites, despite the policies those site have in place to discourage and prevent pre-teens signing up.  In a somewhat trite observation, Ofcom noted from their research that such users are not particularly concerned with such issues as online privacy.  Oh really?

Sunday, 30 March 2008

Weekly roundup

There’s a lot making the news recently that I’ve felt the need to post about in the last 7 days, but haven’t had the chance. So, there’s nothing else for it but to release another ‘round-up of the week’ with 5 hot picks of unrelated, random stories that have caught my eye.

ICO re-states preventative not hard-line enforcement role - From outlaw.com 19.03.08

ICO Role The ICO said that it would concentrate more on the avoidance of this risk than strict enforcement of the law. "We are not seeking compliance with the law as an end in itself," it said. "Making our vision a reality means minimising data protection risk for individuals and society. The law is the main tool we have at our disposal to achieve this, but we go further and promote good practice."

"We cannot address all areas of data protection risk equally, nor should we attempt to do so," it said.

Maybe the ICO feel they are trying to do too much - to be all things to all people. Perhaps, they feel, you can’t wholeheartedly work as an advisory body for the public and data controllers as to the data protection law and actively enforce these laws as well.

But this isn’t a time for the ICO to start getting worried about being perceived as too hard line, police-like or even interventionist. Excuse me, ICO – if you start shying away from cracking down on data protection issues, who, exactly is going to pick up the slack? Perhaps, even, this announcement is more politically motivated; a bid aimed at increasing their budget. Who knows? Either way, with more data being created, processed and stored than ever before, the need for effective enforcement is greater than ever.

BMiss Bimbo Websiteimbo Game - Officially dubbed a ‘virtual fashion game’ this online atrocity has really hit the headlines in the last week or so. And seriously, this stuff just kills me.

People said that First Person Shooters and other action games are harmful for children - so what about this one?  Surely, this type of game could do an immeasurable amount of damage to young web users.  At least FPSs and other games of an extreme nature - such as the Grand Theft Auto franchise - are obviously dangerous. Still, at least you know what you’re getting with those. The risks presented by games such as Bimbo are more subtle and, therefore, arguably more hazardous. After all, gam es which play and even feed on people's insecurities, doubts and fears can never be a good thing. But by perpetuating the dangerous, misguided and unrealistic illusion of size zero body sizes via a game designed for kids makes it something all together worse.

Then again, maybe I shouldn’t be so surprised. If such things as Zwinky the toolbar exist, what’s more logical than a game where your slut-up your bimbo, sh*g your way to money and puke your way to a skeletal shell.

EULA slip-up prevents Windows users from installing safari

SafariApple got their act together after news of the EULA detail was embarrassingly bandied about the net and now have changed with wording to allow Windows users to legally install Safari. If you’re running iTunes, you might not even have a choice, given that Steve Jobs has seen fit to use the software update function to push out the latest version of Safari, Apple’s web browser. For what it’s worth, Safari does a nice job of text rendering but other than that, it’s a definite also ran behind Firefox and IE. Given the lack of customisation and innovative features Safari boasts, probably behind Opera, too.

Adobe finally release online version of Photoshop

Photshop ExpressDubbed Photoshop Express, this watered down online version of the best-of-breed graphics software was released this week. I heard about the project over a year ago and have been eagerly awaiting its release. Early signs are interesting, though not necessarily encouraging. I have to admit I was hoping for a slightly more full-featured offering than Adobe seem to have released at this stage. It’s clearly pitched more towards competing with Piknik and other such programs, tied closely with online storage and sharing of digital photos, rather than being a hardcore graphic manipulation program.

 

Data SecurityAnd finally, vnunet reports that “just one in 10 adults in the UK trusts the government with their personal information, according to a study commissioned by Data Encryption Systems (DES).” Well, tell us something we don’t know.

Wednesday, 26 March 2008

More Facebook trouble afoot?

Facebook Community

From vnunet.com 25.03.08

Security researchers claim to have uncovered a new wave of attacks in which profiles on Facebook are used to post images of child torture.

The attack was reported by Chris Boyd, director of malware research at FaceTime Communications.

Boyd claimed in a blog posting to have discovered multiple instances of the attacks in which accounts were stolen and used to post photos on other pages.

"I am still trying to process this, but one of my close contacts has confirmed there is someone going around either hijacking, hacking or phishing user accounts on Facebook, then randomly uploading pictures of child torture to their funwall," he wrote.

I really wanted to put the series of Facebook-related posts to bed by now. It seems like I've been blogging my feelings about the social networking site and other news stories relating to it all too frequently in the last few months. That said, there's a lot that merits discussion when it comes to the darker side of Facebook.

Regarding this latest story, account hijacking is always a big risk for any large site with sign-in facilities. When you get so many users, trouble often ensues: you become a bigger target for hackers, users still insist on choosing insecure passwords, 3rd party applications often bring in unwanted security threats etc. Still, Facebook just seem to be making a bad name for themselves. What with Facebook's plan last year to sell their users' personal information and the multitude of privacy issues that I've highlighted previously on law actually, here's to hoping that the millions of users that flock to Facebook everyday, soon wake up and smell the coffee.

With so many applications being written for Facebook now - coupled with users' propensity to litter their pages with them - it was only a matter of time before trouble reared its head. And let's face it: Facebook is a potential hotbed for all kinds of malware and vulnerabilities to thrive; a digital ambush just waiting for the millions of FB users around the world to sign in and join the party. Arguably, Facebook should be doing more to actively guard against vulnerabilities that its users are subjected to. It would be much better for security purposes if all Facebook apps needed to go through a strict verification process and be 'signed' by Facebook before release. Creativity and freedom for developers must sometimes take second place behind ensuring a safe and secure experience. For instance, what Apple have elected to do with 3rd party applications for the iPhone - since recently announcing they would officially release an SDK for developers - is a credible paradigm that Facebook would do well to mimmick.

Thursday, 13 March 2008

'Rate my Cop' website causes a stir

Rate My Cop From CBS13.com 9/3/08:

Police agencies from coast to coast are furious with a new website on the internet. RateMyCop.com has the names of thousands of officers, and many believe it is putting them in danger.

Kevin Martin, the vice president of the San Francisco Police Officers Association, agrees. "Will they be able to access our home addresses, home phone numbers, marital status, whether or not we have children? That's always a big concern for us," he said.

Creators of the site say no personal information will be on the site. They gathered officers' names, which are public information, from more than 450 police agencies nationwide. Some listings also have badge numbers along with the officer's names.

Rebecca Costell says, in a statement, that the site helps people rate more than 130,000 officers by rating them on authority, fairness and satisfaction. She adds, "Our website's purpose is to break the stereotype that people have that cops are all bad by having officers become responsible for their actions."

At first glance, this is disturbing on so many levels. Having said that, seeing how many other ‘rate my..’ sites are around, maybe it was only a matter of time before something like this reared its head. While it could represent a security risk, I suppose, many will argue that if the information is limited in scope and available from other sources anyway, there can’t be too much harm in it. It all comes down to the extent of the information available. Names and numbers are one thing; photos, home addresses, vital statistics and the school their kids go to is quite another.  Still, the perceived security risk that the website poses has got Sacramento County Sheriff John McGinness considering letting his officers use aliases when on duty. 

But why shouldn’t they be rated – it goes on internally to some extent? Regular police officers are hardly operating clandestinely, hold a position of high responsibility and authority and are directly accountable for their actions. What’s more natural, then, for them to be rated by the public they serve? You never know, it might even help members of the public to re-establish a connection with the police and get the local community rallying behind their local bobby. Then again it might just alienate the local constabulary even more than they were before.  The biggest question, though, is whether people would ever care enough to vote.  Unless an officer was spectacularly bad, I can't see anybody taking the time and trouble of rating a name on a website. 

I doubt we’ll have to worry about it; I can’t see the idea taking off in the UK somehow. But, still, you never know.

Tuesday, 4 March 2008

Privacy Act?!? I’ve never heard of it.

clip_image001The other day, my girlfriend forwarded an email on to me, one that she was surprisingly eager for me to read.

It turned out it was an email concerning data privacy and how it related to driving licences. When I discovered it originated from her somewhat notorious ‘Uncle John’ I should have probably smelt a rat. Thinking she was showing me because of my penchant for this type of thing, though, I was prepared to give it the benefit of the doubt.

Anyway, the subject line read: New Drivers License and the Privacy Act. “Privacy Act - - I’ve never heard of it”, I snapped, worriedly. Was I really this ignorant? Had the existence or, even worse, the passing of such an Act in England and Wales occurred without my knowing? For someone who likes to feel that they have their finger at least partially on the IT and privacy law pulse, if this should have passed me by unawares, I was going to look like a prize turkey. And that's putting it mildly.

A quick search on Google for privacy act allayed my fears. “See, there’s no such Act”, I calmly stated. My faith in my knowledge and the general order of the world was at least partly restored. “What are all those, then?” my girlfriend questioned, pointing to a long list of hits. “Look, they’re all Canadian, Australian and American”, I retorted, almost angrily.

Still, somewhat intrigued, I read the through the body of the email:

Did you know that this was happening?

Check your driver's license information on-line.

Now you can see anyones driver's license on the Internet, including your own!

It asks for U.S. Info, but unfortunately it works for Canadian, English,

Australian and New Zealand licenses as well.

Just searched for mine....putting in England as the city and there it is, picture and all.

This is really scary. I removed mine. I suggest you all do the same.

Go to the website and check it out.

So that explained the American spelling of licence in the subject line, I thought to myself. It’s clearly an American site but they claim drivers’ details from several countries are available. Given the shocking state of the nation’s data security – many incidents of which have been documented on this blog - I couldn’t rule out completely that this wasn’t a bona fide situation being brought to the world’s attention.

It was, of course, a harmless spoof, albeit one that created a cheeky and somewhat ignominious copy of a US driver’s licence.

To my girlfriend, Sarah’s credit, she played the part well. I was surprised she was ostensibly taking it so seriously – particularly as it was from her ‘Uncle John’, and I really should have caught on sooner. It was unlike her to be so trusting of anything like this. After all, this is the girl who I’ve described on more than one occasion as being ‘suspicious of ‘everywhere, everything, and everyone’. Still a forensic science degree is wont to have that effect on a person.

So, children, the moral of the story can be summed up like this: bad as the data privacy situation is in the UK, it’s not quite at this stage yet. That being said, it might not be long until this type of thing is for real.

Sunday, 2 March 2008

Urgent need for internet security review

Internet security From Computeractive 21/02/08:

The House of Lords Science and Technology Committee has announced a follow-up inquiry to its Personal Internet Security report.

It is taking the measure after its “disappointment” with the way the Government dismissed the vast majority of its recommendations last October.

The report, published in August 2007, called on the Government to take strong measures to protect against internet crime. It branded the web as a “playground for criminals” and made 23 recommendations it said would help instill public confidence in the internet.

They included a kite mark scheme for internet service providers and security software. It also wanted to make software manufacturers legally responsible for security flaws and establish a central e-crime police unit.

These recommendations were dismissed by the Government, which led to Committee member Lord Erroll accusing it of "putting its head in the sand".

The Committee plans to release its new report soon after Easter

Good though (some of) these recommendations are, I don’t see any of them coming to fruition anytime soon. It’s going to take a massive shake-up, change of culture and approach for some of them to ever be seriously considered, let alone implemented. Short of a massive internet security disaster, most won’t ever see the light of day. Still, we watch and wait in vague anticipation.

Thursday, 28 February 2008

Facebook privacy update

Facebook Update From Outlaw.com 21.02.08 

Social networking website Facebook claims to have fixed the privacy problems that have dogged it in recent weeks.

Users reported that it was impossible to delete all their information from the site, but Facebook says that total deletion is now possible.

There was an outcry when users discovered that they could leave Facebook, but that their details would remain on Facebook servers. The company said that this is in case users changed their minds and wanted to reactivate accounts.

Facebook, though, now says that it has introduced a method by which a user can permanently delete all of their information.

Let’s hope this represents a small step in the right direction but being unable to fully delete an account is a situation that should never have happened in the first place. The way people are using Facebook as a portal to throw up a plethora of personal information is nonetheless worrying. And there are so many doing so without stopping to think of the trail or ‘electronic footprint’ they are leaving behind, let alone giving thought to the repercussions. There should at least be more conspicuous warnings displayed on Facebook about the dangers of including personal details on the site. And while they’re at it, how about better access to the controls which users can adjust to limit others’ access to their personal details? While Facebook can’t be held responsible for people’s stupidity they surely owe a duty to highlight the dangers of their users’ actions.

In the computer room yesterday, I overheard a conversation which perfectly illustrated one of the main reasons why I despise Facebook.

"I've got 62 requests and they're all just....... nothing!” Oh great. Well worth visiting then and spending hours on the site. But it was still the first site she went to. I really give up with this one – I just don’t get Facebook’s mystical appeal.

But wait, there was more. She soon piped up with another belter: “oh and my friend joined the group that my cousin joined and that I joined and...”.  Yeah, whatever.  Let me guess, they’re all just..... nothing, right? A blatant waste of time and effort, building virtual cliques that are as desultory as they are irritating. And that's one of my biggest gripes about Facebook.  It's just aimless congregating of people, albeit in the online world. Not much better, though, than kids on street corners.

Wednesday, 27 February 2008

Security Toilet-Cameras

Security camera toilets From Mark Frauenfelder on Boing Boing, 26.02.08

Students at Lipson School in Plymouth UK returned from a one-week break to discover closed-circuit security cameras in the lavatories (They were "the round ones that can move," said one 15-year-old who saw them). After hundreds of students protested, the school agreed to remove the cameras.

I'm not sure I believe principal Steve Baker when he says he didn't know about the cameras, but if he's telling the truth, he should either fire the creep who ordered them to be installed, or he should resign in shame for not knowing what's going on in the school he is paid to oversee. However, Baker says he's not going to even discipline the unnamed miscreant who had the cameras installed. "It's a learning situation, not a disciplinary one," Baker said.

Principal Steve Baker said contractors fitted them on the orders of another staff member, who did not have the measure approved by him or school governors.

Mr Baker added that the system had now been disabled and would be removed as soon as possible.

He said: "Someone made an error. They had no authorisation from me or from the governors to install these cameras"

What the hell’s up with this? I seriously thought it was a joke when I first read it and I’m staggered that this hasn’t hit the news in a bigger way yet. I initially came across this on Boing Boing yesterday and traced it back to the source article, from the Daily Mail of all places. Well, there’s no accounting for taste.

But seriously? Tell me this is just an early April Fools’. Some random staff member saw fit to have security cameras installed in the pupils’ toilets and the school and contractors didn’t question it but rather looked the other way. The cameras, apparently, were installed as part of an ongoing surveillance system. But surveying what, that’s the question?

I’m gobsmacked over this, quite frankly. And that doesn’t happen very often.

Thursday, 21 February 2008

Facebook - You’ll Never Leave

Facebook Evil I just don’t ‘get’ Facebook, Myspace, Bebo and the other long list of candidates for the award of  ‘biggest online waste of space’. I never have understood the appeal and I never will. In fact, they drive me crazy as do the people who flock to those sites at every spare minute of their day. I have remained deliberately detached from such social networking sites and firm in my conviction to resist countless invitations and suggestions that I join up. Even if I wanted to – which I don’t – I couldn’t join now, anyway, through mere principle.

Anyway, given my palpable disgust of Facebook I was delighted to see that its popularity has dropped for the first time in 17 months on the Telegraph’s website:

But it still has 8.5 million users, making it the most visited social networking site in the UK, according to Neilsen Online, the internet research company.

MySpace also attracted 5 per cent fewer users in the period [December 2007-January 2008], from 5.3 million to 5.1 million, while Bebo came third with an audience of 4.1 million.

Nic Howell, the deputy editor of internet industry trade magazine New Media Age, said the figures indicated that Facebook’s popularity was in decline.

“This fall is a significant moment in the development of Facebook and potentially marks the high water mark of the site’s popularity in the UK.”

So although the novelty seems to be truly wearing off, I’m still gobsmacked by how long it’s lasted.

But it’s not just a case of me just choosing to be prudishly obtuse over these sites; there are real privacy concerns here. I’ve read many a lot of stuff recently relating to the difficulty people have experienced when trying to quit Facebook for good. For instance, the New York Times’ article on February 11th: How Sticky Is Membership on Facebook? Just Try Breaking Free:

“It’s like the Hotel California,” said Nipon Das, 34, a director at a biotechnology consulting firm in Manhattan, who tried unsuccessfully to delete his account this fall. “You can check out any time you like, but you can never leave.

And that’s just the tip of the privacy iceberg. Don’t even get me started about the flagrant disregard for online anonymity, with users being readily searchable and contactable by all and sundry registered with Facebook themselves. Those registrations, of course, could be under a pseudonym, by people using the site as a rich data base for fraudulent or sinister purposes. Factor into that the potential for online grooming and you’ve got a very dark side of the Facebook moon. I hate it.

I hope the world wakes up and smells the proverbial soon. Maybe then they’ll suddenly question what exactly all the fuss was about. ‘Pokes’ for instance - what’s the deal there?!? Seriously? It’s a just a website - get over it.

Wednesday, 20 February 2008

Parents' powers to check on paedos

Paedophile Picture From: The Times 18.02.08

A watered-down form of "Megan's law" is to be trialled in four police areas, giving parents the power to check with police whether people given regular unsupervised access to their children have convictions for paedophile offences.

Single mothers will be able to ask police whether potential boyfriends have child sex convictions before they start a relationship. Family members or neighbours who regularly look after children could also be checked.

Police and probation services will have discretion on what information is revealed in each case and disclosure will be carefully controlled. But it is understood that if children are thought to be at risk, parents and carers will be told.

Despite feeling that the whole ‘Megan’s Law’ idea relied on an over-simplification of the complex situations involved, I suppose that a trial like the one proposed is the best way to sample such an idea. It’ll be interesting to see how it fares and whether widespread adoption is a feasible option, without inciting mass public panic, a culture of obsessive checking and paranoia plus a repeat of the ‘naming and shaming’ debacles of a few years back. Going forwards too, I suppose, it’ll be another test to add to the growing list for determining the suitability of new partners. 

Saturday, 16 February 2008

Fighting piracy - the wrong way

Illegal Download From The Times 12.02.08:

People who illegally download films and music will be cut off from the internet under new legislative proposals to be unveiled next week.

Internet service providers (ISPs) will be legally required to take action against users who access pirated material, The Times has learnt.

Users suspected of wrongly downloading films or music will receive a warning e-mail for the first offence, a suspension for the second infringement and the termination of their internet contract if caught a third time, under the most likely option to emerge from discussions about the new law.

Broadband companies who fail to enforce the “three-strikes” regime would be prosecuted and suspected customers’ details could be made available to the courts. The Government has yet to decide if information on offenders should be shared between ISPs.

My initial reaction to this news was far from positive. I just didn’t ‘get’ the logic in operation here – if indeed there is any - and to me, it merely smacked of absolute desperation. When trying to combat illegal activity where there is a supply/demand equation in operation, logic and experience says you target the source. Not only is that approach much more achievable, effective and in line with common sense but it prevents the need to clumsily wade in and target the end users who, whilst indirectly culpable in their own way, never gets to the root problem. A good analogy could be drawn with this and an illegal drug supply/taker situation.

So it’s come to this? After years of chasing the big bad pirates, the authorities have recognised that such an approach is failing. And failing miserably. But at least that target was a manageable one. Under these plans, instead of crime-fighting the perpetrators of the crime – the pirates themselves – the idea seems is based on simply palming the responsibility onto ISPs who are to take up the slack instead.

I appreciate, of course, that piracy is a big problem and that equally something must be done. But this? If the scheme was for ISPs to monitor users’ access and activities on known file-sharing sites per se – I can at least see a grain of logic behind it. But if large, infamous file sharing sites are the problem – and not the much vaster number of sites from which music and other files can be downloaded - why not tackle the problem directly and cut them off at the knees? Why not impose more stringent scrutiny of the management of such sites and the type of content it can host? Monitoring each internet user’s downloads in the UK seems to be the entirely wrong way of going about it. After all, supervising and scrutinising every single download is not only a verging on a logistical impossibility but poses a privacy nightmare as well.

Educating the public is also crucial. Download sites are always changing, new services and ideas are always being churned out. Clearly establishing to internet users exactly what constitutes an illegal download is an essential starting place.

Perhaps at a push, a scheme such as the one proposed could work for known black-listed file sharing sites and, say, peer to peer file sharing clients. But even here it would make more sense to target the hosts of the service, not the visitors. Failing that, you could argue that it would be more effective to go after the uploaders of illegal content; they are the more tech-savvy party after all and more aware of what they are doing. And what’s more, there are fewer of them. But targeting the visitors? That’s just wrong.

But, of course, it would never be as simple as that: file-sharing clients such as bit torrent and the like are used by many for the legitimate sharing of content which in no way represents an infringement of intellectual property rights nor does it constitute piracy.  A hard and fast banning of file-sharing clients is, therefore, absolutely the wrong way to tackle the problem .  After all, such clients represent an important technology and one that has been available online since the early days.  Banning the facility for all because of the illegitimate actions of a few is grossly unfair.  Fairly policing the use of such clients, then, would result in having to filter out the legal and legitimate files shares from the illegal ones.  And what a nightmare that would be.

In addition to having a fractured and illogical foundation, this proposed legislation is further fraught with difficulties, possible caveats and uncertainties. To name a few:

Can ISPs truly be trusted to keep users’ download information secure? What if someone moves ISPs – does their record move with them?

What about wireless piggy-backing – who is responsible? If there’s someone sat in your front garden with a laptop downloading music illegally, say, are the ISPs to hold the bill-payer responsible? Is it time to start criminalising the act of failing to secure your wireless network or just relying on low level, easily breakable WEP protection for instance.

If people sign up for telephone, internet, TV package etc. will they lose all their services if they were found guilty? That really is cutting them off at the knees.

Who will arbitrate disputed allegations – what is the appropriate body to do that?

In family situations where several people use the internet connection, is it fair to prohibit them all for the actions of one?

As the internet is becoming an increasingly essential utility, is it right to ban users entirely? If someone is found guilty of breaking a hosepipe restriction, their water is not turned off at the mains.

Will users seek to take advantage of the Wi-Fi hotspots for their downloading-fests instead?

With so much vagueness and ambiguity over the issue, I’m eager to see the proposed Green Paper when it’s unveiled next week.

Wednesday, 13 February 2008

Safer Internet Day

Online Girl From BBC News 13/02/2008:

Safer Internet Day is being marked around Europe with events to educate
children and parents about net dangers.


Themed events will reveal the risks of sharing too much personal data
and warn children that their virtual friends may not be who they say they are.


Public events will encourage parents to oversee their children's online
life so they know who they are talking to.

Raising public awareness and promoting good, safe online practices is half the battle in combating internet dangers. Children, of course, are particularly vulnerable and focussing on educating that section of the internet-using public in ways of increasing net safety is a no-brainer. I've always argued that computer security software can only do so much; educating people in safer, more responsible online practices is largely much more effective. After all, prevention is much better than cure.

If an international awareness day helps to achieve these objects, then I'm all for it. Good stuff.

Wednesday, 30 January 2008

CCTV sound recording - a step too far

Security Camera

From vnunet.com - 30/01/08

The ICO has described the use of sound recording in CCTV equipment as "highly intrusive".

A new ICO code of practice outlines key issues which organisations and businesses must consider when routinely capturing images of individuals on CCTV.

The ICO warned that the use of sound recording could only be justified in highly exceptional circumstances.

The decision follows recent research revealing that seven out of 10 individuals oppose the idea of CCTV cameras recording their conversations.

Furthermore, over half of individuals are not aware that the use of CCTV cameras is covered by the Data Protection Act.

Jonathan Bamford, assistant commissioner at the ICO: "It is essential that organisations and businesses use CCTV responsibly in order to maintain public trust and confidence and to prevent its use becoming viewed as part of the 'surveillance society'."

No kidding. Obviously CTTV has considerable benefits in the fight against crime but arbitrarily recording sound along with images is, in most instances, a step too far. There cannot be many cases where the evidential value of CCTV footage is considerably increased by including sound material. Improving the image quality would perhaps be a more effective and meaningful way of removing ambiguity or adding clarity to further increase the value of video footage as a crime-fighting tool. And to be of any real worth, the microphones built in/accompanying the cameras would need to be so effective that they would be inadvertently documenting the conversations of millions of innocent citizens as they go about their business up and down the UK. The intrusiveness of such sound recorders would surely massively outweigh any potential advantages, except, possibly, in very rare circumstances.

Monday, 28 January 2008

Happy Data Protection Day

Data Protection Day 08 From: The Council of Europe - Data Protection Day - 28/01/08

The aim of the Data Protection Day is to give European citizens the chance to understand what personal data is collected and processed about them and why, and what their rights are with respect to this processing.

They should also be made aware of the risks inherent and associated with the illegal mishandling and unfair processing of their personal data.

The objective of the Data Protection Day is therefore to inform and educate the public at large as to their day-to-day rights, but it may also provide data protection professionals with the opportunity of meeting data subjects.

Bit ironic really, given the data protection crisis currently plaguing the UK.  Perhaps we should have opted out of it this year.

Tuesday, 22 January 2008

"Carphone Warehouse broke Data Protection Act, says ICO"

Carphone From Outlaw News 17/01/08

“The Carphone Warehouse allowed customers to view other people's account details, passed inaccurate information on to debt collectors and opened accounts in the wrong name, according to the Information Commissioner's Office (ICO).

The actions were in breach of the Data Protection Act and the ICO has issued Carphone Warehouse and sister company Talk Talk with enforcement notices ordering them to comply with the Data Protection Act. If they fail to do so they risk a criminal prosecution.

"Both companies failed to meet the basic principles of the Data Protection Act," said an ICO statement.

Carphone Warehouse said that the incidents happened when the company was extremely busy.”

Sounds about right.

This story is worthy of a mention on law actually for at least two good reasons. Firstly, frequent readers of my blog will recall my penchant for covering stories relating to data protection issues and associated bungles, foul-ups and all the rest of it. Secondly, I’ve actually done a stint at ‘Carphone’ myself – not an entirely happy episode it has to be said, but there it remains etched in my memory, despite my best attempts to sweep it under the proverbial carpet.

I’ve no doubt Carphone Warehouse will have learnt its lesson from this run-in with the ICO. Far be it for me to criticise them, of course.