Monday, April 30, 2012

Alberta Commissioner faults Calgary police employee for logging into colleague's personal e-mail account

The Office of the Information and Privacy Commissioner of Alberta has found that a civilian employee violated the province's public sector privacy law by logging into a police service employee's personal e-mail account.

Here's a summary of ORDER F2012-07 [PDF], made against the Calgary Police Service:

Summary: The Complainant was a civilian employee with the Calgary Police Service (“Public Body”). In March 2010, the Public Body’s HR consultant was informed by the Complainant’s manager that several of the Complainant’s coworkers had made allegations about the Complainant’s behavior at work, including allegations of inappropriate sexual conduct.

The Public Body began to monitor the Complainant’s computer activities, as well as reviewing her past work email activity. While reviewing her work email, the IT Security Manager (“IT Manager”) found a personal email that the Complainant had sent to a family member, which included the login ID and password information for the Complainant’s personal web-based email account. The IT Manager used this information to access the Complainant’s personal email account and found photographs of a sexual nature, which appeared to have been taken on the Public Body’s premises. The IT Manager copied these photographs, and provided them to the Complainant’s manager and the HR consultant. These photographs were used in the Public Body’s decision to terminate the Complainant’s employment, and were also used by the Public Body during the subsequent grievance process.

The Complainant made a complaint to this office, stating that the Public Body collected, used, and disclosed her personal information in contravention of Part 2 of the Freedom of Information and Protection of Privacy Act (“FOIP Act”). Specifically, the Complainant objected to the Public Body accessing her personal email account, and the subsequent collection, use, and disclosure of photographs found by the Public Body in that email account.

The Public Body argued that the collection of the Complainant’s personal information occurred during the course of investigating the allegations of workplace misconduct against the Complainant, and that the subsequent use and disclosure of the photographs found in the Complainant’s personal email account were for the same purpose as they were collected.

The Adjudicator found that the Public Body collected the Complainant’s login ID and password to her personal email account in the course of reviewing the Complainant’s work email, to which the Complainant did not object. However, Adjudicator found that the use of the Complainant’s personal email login ID to access the Complainant’s personal email was not for the purpose of employee management, since the IT Manager had not been requested to monitor the Complainant’s personal email, rather only her work email. There was also no evidence of wrongdoing that would justify accessing a personal email account. The Adjudicator also noted that even were the use of the Complainant’s personal information for the purpose of the workplace investigation, a Public Body may only use personal information to the extent necessary to carry out its purposes in a reasonable manner; logging in to the Complainant’s personal web-based email account was exceptionally invasive, and patently unreasonable in the circumstances.

The Adjudicator found that the collection of the photographs from the Complainant’s personal email account could not be considered separately from the fact that they were collected from the Complainant’s personal email account. Because the photographs, even if relevant to the workplace investigation, were found as a result of an unauthorized use of personal information, their collection and subsequent use could not be justified as “necessary” for the purpose of the Public Body’s investigation.

The Adjudicator determined that the Complainant’s personal information was not disclosed to, but rather used by, various employees of the Public Body. The Adjudicator had already determined that the use was not authorized under the Act, but found that even if the personal information had been disclosed to the employees, the disclosure would not have been authorized, for similar reasons.

Friday, April 27, 2012

CSIS oversight and accountability to be slashed to save $1M

One of the arguments made in favour of Bill C-30 by the government when it was introduced was that it had accountability: Internal audits and a veneer of oversight by the Office of the Privacy Commissioner of Canada. Accountability is key.

Now, it is being reported that the federal government is eliminating the position of Inspector General of the Canadian Security Intelligence Services. (See: CSIS watchdog to be cut in budget - Politics - CBC News). It's hard to believe that the government is committed to oversight and accountability in the use of incredibly intrusive powers when steps such as these are taken.

What's worse is that it is being done for fiscal reasons and will only save $1,000,000. If you ask me, that's a million dollars well spent.

Sunday, April 08, 2012

RIM reportedly gives Indian government access to full range of BlackBerry messages

The Toronto Star is reporting that RIM has agreed to provide the Indian Government with access to the full range of Blackberry communications (RIM gives India access to BlackBerry messages - thestar.com). The article this is based on (http://indiatoday.intoday.in/story/govt-to-tap-blackberry-messenger-security-privacy/1/183403.html) suggests that the Indian Government has been given some sort of backdoor into Blackberry Enterprise Servers, which is something that RIM has staunchly refused to do until now.


If this is true, the era in which Blackberry was the ultra-secure communications platform is over.


This also shows that what was once Blackberry's main strength is also its greatest weakness. Blackberry is a system and RIM controls everything, from the device to the servers. If they compromise one aspect of it, the whole system is compromised. On my Android phone, on the other hand, I can configure just about anything, including what VPN to use and what communications apps to run.

Tuesday, April 03, 2012

House committee looking to require telcos and device manufacturers to decrypt communications

Bill C-30, with warrantless access to subscriber data and real-time internet monitoring, is the tip of the iceberg if the recommendations of the House Committee on Justice and Human Rights are followed. In a report just issued, The State of Organized Crime [PDF], the committee recommends changes to the law to require telcos to provide access to unencrypted communications:

RECOMMENDATION

The Committee recommends that the Government of Canada pursue legislation requiring telecommunications service providers and telecommunications device manufacturers to build the ability to intercept telecommunications into their equipment and networks.

RECOMMENDATION

The Committee recommends that the Government of Canada introduce legislation requiring telecommunications service providers and telecommunications device manufacturers to decrypt legally intercepted communications or to provide assistance to law enforcement agencies in this regard.

From the Motreal Gazette:

Proposal would force telecoms to decrypt messages

Telecommunications companies would be forced to decrypt messages for law-enforcement agencies if the federal government legislates recommendations outlined in a report by a House standing committee.

"Law-enforcement agencies are way behind, or have been way behind, in the ability to deal with the new modes of communications," said Conservative MP Dave MacKenzie, chair of the House standing committee on justice and human rights.

The report, the State of Organized Crime, states that although telecommunications can be intercepted, the service providers don't always release standardized information to law-enforcement agencies.

The committee argues that federal legislation could address this lack of standards by furthering ideas found in Bill C-30, the online surveillance bill.

"When you're dealing with organized crime, they're very well-funded and wellorganized .... They move communications abilities around in different ways: passing cellphones around is just the very beginning," said MacKenzie.

NDP MP Jack Harris added: "There has to be some sort of modernization of the law with respect to surveillance. We've got laws with respect to telephone surveillance and some of those laws should apply to use of other electronic devices, whether they be cellphones, emails and things like that."

The committee wants federal legislation requiring both telecommunications service providers and their manufacturers "to decrypt legally intercepted communications or to provide assistance to law enforcement agencies in this regard."

Under the committee's plan, all telecommunications companies would have to have access to decryption techniques or tools - something that wasn't provided for in Bill C-30.

Bill C-30 would require service providers to have the ability to intercept communications on their networks and to provide this information in the form specified by law enforcement.

Typically, law enforcement would want encrypted data decrypted to facilitate use of the information gathered.

Encryption is often used by organizations - both lawful and criminal - to protect the transmission of sensitive and private information.

As it stands, some service providers do not have the tools or techniques to decrypt these communications, exempting them from the requirement to provide decrypted information to police.

Although Harris said he believes that surveillance methods need to be updated, he has doubts about making decryption abilities mandatory.

"It certainly may be impractical and perhaps technologically infeasible," he said.

Telecommunication companies seemed to share that worry.

"Our primary concern in this area has always been the capacity of industry to implement any new requirements and who bears the cost," said Bell Canada spokesperson Jacqueline Michelis.

Should the recommendation become legislated, telecommunications manufacturers also would be affected.


Updated (April 4, 2012) - Apparently the article has been removed from the Gazette, Vancouver Sun and other PostMedia sites ...


Michael Geist adds:

The report includes a dissenting opinion from the NDP on the lawful access recommendations. There does not appear to be a similar dissent from the Liberals, who were represented on the committee by Irwin Cotler. Postmedia covered the release of the report but the article is no longer available on its media sites. The article included specific comments from Bell that suggest its primary concern associated with these demands boils down to questions of who will bear the costs. A company spokesperson stated "our primary concern in this area has always been the capacity of industry to implement any new requirements and who bears the cost." That is a troubling position for many Canadians who rightly expect their telecom companies to also be concerned with the privacy of their customers. After the outcry in February over Bill C-30, many also expected the government to be open to change on lawful access, yet this report suggests that the changes may not be what many were anticipating.

Tuesday, February 21, 2012

Some suggestions to fix the lawful access bill

There are many, many problems with the warrantless access to customer data in Bill C-30, known as the lawful access bill. The main problem pointed to by the proponents of the Bill is that it takes too long to get a warrant that requires an internet service provider to hand over customer name and address information that corresponds with an IP address. If that is really the problem they are trying to address, it would be best to address it by making the warrant-seeking process more efficient and limit warrantless requests to circumstances where there is a real emergency.

Since the government has suggested it is open to amending the Bill, it doesn’t sound like they are amenable to throwing it out and fixing the warrant process. In hopes of adding to the discussion on what’s wrong with the Bill and how it can be fixed, below I’ve set out some of the major problems and how they can be fixed in a way that restores the protection of privacy while permitting law enforcement to investigate serious crimes.

I don’t expect these are the only solutions, but will hopefully start a discussion on how to fix lawful access.

  1. There is no limitation on the circumstances under what these powers can be used.

    Problem: As drafted, there is no limitation under which these powers can be used. They can be used for child exploitation investigations or serious crime, but can also be used without any justification or to reunite someone with their lost iPhone.

    Solution: Limit the use of these powers to (a) the investigation of serious crimes only under the Criminal Code, the Narcotics Control Act, the Canadian Security Intelligence Service Act and the National Defence Act where there are reasonable and probable grounds to believe that the information is necessary for the investigation of a crime that has occurred or is likely to occur, or (b) where the subscriber about whom the information relates is reasonably believed to be a victim of the crime or whose life or safety is in imminent jeopardy, and the victim’s identity is unknown.

    (If lost iPhones are a serious problem that require police intervention, require the police to hand them them to the telco and require the telcos to reunite them with their heartbroken owners.)

  2. There is no accountability to the justice system.

    Problem: The requesting officer is not required to justify the request and to be accountable to the wider justice system. Under a warrants-based system, an affidavit is required and it needs to be filed with the courts.

    Solution: Require that the requesting officer swear an affidavit, under oath, articulating the circumstances described above and the basis for this belief. The affidavit shall be filed with the superior court of the relevant jurisdiction. This affidavit can be filed after the fact in exigent circumstances. This affidavit should be counter-signed by an officer of superior rank to the requesting officer or a senior crown attorney, who will also swear that she is of the view that the facts set out by the officer form the basis for a lawful request.

  3. There is no accountability to the individual if charges do not result.

    Problem: The individual whose information is sought will likely never know that this information was sought and obtained unless it comes out in open court after charges have been laid. In the current draft C-30, there is actually a gag order that prevents the ISP from telling the individual even if asked.

    Solution: The affidavit referred to above shall be provided to the individual whose information is sought within six months unless a judge agrees, based on affidavit evidence provided by the relevant law enforcement officer, that doing so would be harmful to an ongoing criminal or national security investigation. An individual whose information is wrongfully sought or obtained should have a private right of action against the officer and the officer’s employer if there were not reasonable grounds to seek the information.

  4. There is no accountability to the public at large.

    Problem: The Bill, as currently drafted, doesn’t give the public at large any understanding of how the intrusive powers are used and under what circumstances.

    Solution: The Minister of Justice or the Minister of Public Safety shall table an annual report before Parliament setting out the number of such requests, including the requesting police agency, the criminal code section or other violation being investigated, whether charges were laid against the individual and whether a conviction resulted. This is in addition to the ability of the federal and provincial privacy commissioners to audit the practices of the agencies within their jurisdiction, except that summary results of their audits shall be tabled in Parliament annually. (Additional funding to each privacy commissioner should be provided to defray the costs of such audits.)

I'd be happy to hear any other proposed solutions ...

Saturday, February 18, 2012

Police "PIPEDA requests" for customer information

As a follow-up to my previous post 'Dealing with police "Letters of Request for Information"', I thought I'd discuss a particular species of request letters, commonly referred to as "PIPEDA Requests".

The names are a bit misleading, since in many cases the recipient is led to believe that the authority to obtain the information is found in PIPEDA (the Personal Information Protection and Electronic Documents Act).

Here is an example letter, taken from R. v. Ward, 2008 ONCJ 355:

I, Constable Jason Tree of the National Child Exploitation Coordination Centre, am a law enforcement officer with the Royal Canadian Mounted Police.

I am conducting an investigation in relation to child sexual exploitation offences under the Criminal Code and I am requesting account information pursuant only to that investigation.

I request this disclosure in accordance with s. 7(3)(c.1) of the Personal Information Protection Electronic Documents Act. My authority to request and obtain this information derives from the Royal Canadian Mounted Police Act and the Royal Canadian Mounted Police Regulations as well as common law.

I am requesting the last known customer name and address of the account holder associated with IP address [number] used [date and time].

Should you agree to this request, please provide the information in the section below and reply via e-mail to Jason.tree@rcmp-grc.gc.ca.

As I understand it, the form of letter was a result of the coordinated effort of law enforcement and a group of internet service providers who have agreed to provide warrantless access to customer account information in connection with child exploitation investigations. They are designed to satisfy the requirements of Section 7(3)(c.1)(ii) of PIPEDA which permits disclosures of personal information to the police where they have the "lawful authority" to obtain the information and the information relates to "enforcing any law of Canada, a province or a foreign jurisdiction, carrying out an investigation relating to the enforcement of any such law or gathering intelligence for the purpose of enforcing any such law".

While I generally have a dim view of disclosing customer information without a warrant, I can certainly understand why internet service providers have worked with law enforcement to address these particularly grim crimes.

Friday, February 17, 2012

Lawful Access then and now: Comparing C-30 to 2005's Modernization of Investigative Techniques Act

I was asked how the new Bill C-30 compares to the Modernization of Investigative Techniques Act tabled by the liberals in 2005. Here's a redline to draw your own conclusions: https://docs.google.com/open?id=0B_bUaJvZ9k_BNmY2ODc1YmQtMzU3OC00MjhjLTlmMDYtYzA0OTAzMjhjNzAw.


Update: When the liberals introduced the Modernization of Investigative Techniques Act, it contained a provision that would allow the police to obtain warrantless access to customer information:

17. (1) Every telecommunications service provider shall, in accordance with the regulations, provide to a person designated under subsection (3), on his or her written request, any information in the service provider’s possession or control respecting the name and address of any subscriber to any of the service provider’s telecommunications services and respecting any other identifiers associated with the subscriber.

This is essentially the same as what's in the new Bill C-30 - Protecting Children from Internet Predators Act,

16. (1) On written request by a person designated under subsection (3) that includes prescribed identifying information, every telecommunications service provider must provide the person with identifying information in the service provider’s possession or control respecting the name, address, telephone number and electronic mail address of any subscriber to any of the service provider’s telecommunications services and the Internet protocol address and local service provider identifier that are associated with the subscriber’s service and equipment.

The Conservatives C-30 is actually more circumscribed, since the information is limited to customer name, address, phone number, e-mail address and IP address. The Liberals' C-74 allowed for name, address and "any other identifiers". I would assume that "any other identifiers" would include the laundry list of items that was included in last year's proposed Bill C-52:

  • mobile identification number,
  • electronic serial number (ESN),
  • local service provider identifier,
  • international mobile equipment identity (IMEI) number,
  • international mobile subscriber identity (IMSI) number and
  • subscriber identity module (SIM) card number

Regardless of the federal political party that is advocating for its adoption, warrantless access to customer information is a very bad idea.

The hidden gag order in Bill C-30 (aka the lawful access bill)

While much attention has been focused on the general problems with Bill C-30 - Protecting Children from Internet Predators Act, we are starting to see some very good commentary on the details.

One detail that hasn't really seen the light (and it may not be an accident) is the hidden gag order. Not only will the police, national security folks and the competition cops be able to get customer names, addresses, IP addresses and e-mail addresses without a warrant, there's a gag order that means you'll likely never find out you've been the subject of such an inquiry even if you ask your ISP.

Section 23 looks like it was designed to be obscure and obtuse:

23. Personal information, as defined in subsection 2(1) of the Personal Information Protection and Electronic Documents Act, that is provided under subsection 16(1) or 17(1) is deemed, for the purposes of subsections 9(2.1) to (2.4) of that Act, to be disclosed under subparagraph 7(3)(c.1)(i) or (ii), and not under paragraph 7(3)(i), of that Act. This section operates despite the other provisions of Part 1 of that Act.

Unless you're familiar with the Personal Information Protection and Electronic Documents Act, you'll probably miss what this means.

In short, by default everyone has the right to ask any company that is subject to the law what information they have about him or her, how they've used it and to whom they've disclosed it. That is, unless that right is overridden by Section 9. Section 23 of C-30 essentially says that any personal information that is handed over without a warrant under the lawful access law has to be treated in the same way under PIPEDA as information disclosed in response to a law enforcement request. Here's where the gag order kicks in. If the person exercises his lawful right to seek his or her personal information and accounting of its use, the ISP is prohibited from telling him or her unless the police, national security agencies or competition cops give their OK. And they can refuse to give their OK on a number of relatively flexible bases.

This is the opposite of transparency, and it looks like it was designed this way.


Update (18 February 2012): It is really worth noting that this gag order is not new. It has existed in PIPEDA for quite some time. What is new is extending it to cover "lawful access" requests.

People should be aware that -- I am told -- in the vast majority of cases, internet service providers will willingly hand over customer information without a warrant when the police tell them that it is connected with a child exploitation investigation (using something cynically called a "PIPEDA Request", which I've blogged about before). If your internet service provider hands over your information voluntarily, that's also subject to the gag order in Section 9 of PIPEDA.



For statute nerds, the particular subsections of PIPEDA referred to in Section 23 of C-30 are:

Information related to paragraphs 7(3)(c), (c.1) or (d)

9(2.1) An organization shall comply with subsection (2.2) if an individual requests that the organization

(a) inform the individual about

(i) any disclosure of information to a government institution or a part of a government institution under paragraph 7(3)(c), subparagraph 7(3)(c.1)(i) or (ii) or paragraph 7(3)(c.2) or (d), or

(ii) the existence of any information that the organization has relating to a disclosure referred to in subparagraph (i), to a subpoena, warrant or order referred to in paragraph 7(3)(c) or to a request made by a government institution or a part of a government institution under subparagraph 7(3)(c.1)(i) or (ii); or


(b) give the individual access to the information referred to in subparagraph (a)(ii).


Notification and response

(2.2) An organization to which subsection (2.1) applies

(a) shall, in writing and without delay, notify the institution or part concerned of the request made by the individual; and

(b) shall not respond to the request before the earlier of

(i) the day on which it is notified under subsection (2.3), and

(ii) thirty days after the day on which the institution or part was notified.


Objection

(2.3) Within thirty days after the day on which it is notified under subsection (2.2), the institution or part shall notify the organization whether or not the institution or part objects to the organization complying with the request. The institution or part may object only if the institution or part is of the opinion that compliance with the request could reasonably be expected to be injurious to

(a) national security, the defence of Canada or the conduct of international affairs;

(a.1) the detection, prevention or deterrence of money laundering or the financing of terrorist activities; or

*(a.1) the detection, prevention or deterrence of money laundering; or

*[Note: Paragraph 9(2.3)(a.1), as enacted by paragraph 97(1)(c) of chapter 17 of the Statutes of Canada, 2000, will be repealed at a later date.]

(b) the enforcement of any law of Canada, a province or a foreign jurisdiction, an investigation relating to the enforcement of any such law or the gathering of intelligence for the purpose of enforcing any such law.


Prohibition

(2.4) Despite clause 4.9 of Schedule 1, if an organization is notified under subsection (2.3) that the institution or part objects to the organization complying with the request, the organization

(a) shall refuse the request to the extent that it relates to paragraph (2.1)(a) or to information referred to in subparagraph (2.1)(a)(ii);

(b) shall notify the Commissioner, in writing and without delay, of the refusal; and

(c) shall not disclose to the individual

(i) any information that the organization has relating to a disclosure to a government institution or a part of a government institution under paragraph 7(3)(c), subparagraph 7(3)(c.1)(i) or (ii) or paragraph 7(3)(c.2) or (d) or to a request made by a government institution under either of those subparagraphs,

(ii) that the organization notified an institution or part under paragraph (2.2)(a) or the Commissioner under paragraph (b), or

(iii) that the institution or part objects.

Thursday, February 16, 2012

Vancouver police can't use ICBC biometric database to ID Stanley Cup rioters, says Privacy Commissioner

The Information and Privacy Commissioner of British Columbia, Elizabeth Denham, has rules that the Vancouver police cannot use the facial recognition database compiled by the Insurance Corporation of British Columbia without a court order or warrant. See: Police can't use ICBC facial recognition to track rioters - British Columbia - CBC News.

Tuesday, February 14, 2012

Lawful Access then and now: Comparing C-52 to current C-30

In case you are, like me, spending the evening checking out what has changed with respect to warrantless access to subscriber data between Bill C-52 (introduced last year) and Bill C-30 introduced in Parliament today, this redline comparison may help.