Sunday, March 11, 2007

Economics of identity theft

Stephen Dubner and Steven Levitt, the authors of the best-selling book Freakonomics and the consistently interesting Freakonomics Blog have a very interesting piece in today's New York Times on the economics of identity theft and credit card fraud: Identity Theft - Identity Crisis - Stephen J. Dubner and Steven D. Levitt - New York Times. Read more at the blog: Freakonomics Blog » Who Cares About Identity Theft?

Saturday, March 10, 2007

UK Information Commissioner calls for international harmonization

Richard Thomas, the Information Commissioner of the UK is calling for international privacy standards, particularly focusing on the ongoing squabbles between Europe and the United States. (See: UK official calls for international privacy standards.).

I agree that harmonization should be a goal, but I am concerned that this may lead to a "lowest common denominator" system which would reduce the protection that some jurisdictions afford to their citizens' privacy. The following quote suggests this may be the outcome:

"There could be 'scope for less bureaucracy, less emphasis on prior authorization and a more concrete focus on preventing real harm', he said."

"Privacy" is not just about preventing fraud and indentity theft. Most modern privacy regimes are about giving people choices about how (and whether) their information is collected, used and disclosed. Reducing emphasis on "prior authorization" would likely undermine this.

Canada's PIPEDA, for all its faults, has shown that you can have a comprehensive privacy law that is based on consent and still permits legitimate business use of personal information.

Hospitals must encrypt patient data on portable devices

The Information and Privacy Commissioner of Ontario yesterday released order HO-004 under the Personal Health Information Protection Act following the theft of a laptop containing confidential personal health information on 2,900 patients at the Sick Kids hospital in Toronto.

The order requires the hospital

  • to develop or revise and implement policies and procedures the ensure that records of personal health information are safeguarded
  • to develop a corporate policy that prohibits the removal of identifiable personal health information in from the premises. If identifiable personal health information must be removed in electronic form, it must be encrypted;
  • to develop an encryption policy for mobile computing devices, a policy relating to the use of virtual private networks, a privacy breach policy, and to educate staff regarding the policies how to secure the information contained on mobile computing devices.

While the order directly relates to a hospital, it would applyl to all health information custodians in the province of Ontario and will likely serve as guidance to all health care providers in the country.

For more info, see TheStar.com - News - Sick Kids ordered to encrypt all electronic patient files.

Friday, March 09, 2007

US DOJ audit discloses abuses of National Security Letter powers

This probably isn't a big surprise to a lot of people, but I'm surprised to see it publicly disclosed:

Mueller Admits Fault in FBI Intrusions

Mar 9, 8:33 PM EST

By LARA JAKES JORDAN

Associated Press Writer

WASHINGTON (AP) -- The nation's top two law enforcement officials acknowledged Friday the FBI broke the law to secretly pry out personal information about Americans. They apologized and vowed to prevent further illegal intrusions.

Attorney General Alberto Gonzales left open the possibility of pursuing criminal charges against FBI agents or lawyers who improperly used the USA Patriot Act in pursuit of suspected terrorists and spies.

The FBI's transgressions were spelled out in a damning 126-page audit by Justice Department Inspector General Glenn A. Fine. He found that agents sometimes demanded personal data on people without official authorization, and in other cases improperly obtained telephone records in non-emergency circumstances.

The audit also concluded that the FBI for three years underreported to Congress how often it used national security letters to ask businesses to turn over customer data. The letters are administrative subpoenas that do not require a judge's approval.

"People have to believe in what we say," Gonzales said. "And so I think this was very upsetting to me. And it's frustrating."

"We have some work to do to reassure members of Congress and the American people that we are serious about being responsible in the exercise of these authorities," he said.

Under the Patriot Act, the national security letters give the FBI authority to demand that telephone companies, Internet service providers, banks, credit bureaus and other businesses produce personal records about their customers or subscribers. About three-fourths of the letters issued between 2003 and 2005 involved counterterror cases, with the rest for espionage investigations, the audit reported.

...

FBI Director Robert S. Mueller said many of the problems were being fixed, including by building a better internal data collection system and training employees on the limits of their authority. The FBI has also scrapped the use of "exigent letters," which were used to gather information without the signed permission of an authorized official.

...

The American Civil Liberties Union said the audit proves Congress must amend the Patriot Act to require judicial approval anytime the FBI wants access to sensitive personal information.

...

Both Gonzales and Mueller called the national security letters vital tools in pursuing terrorists and spies in the United States. "They are the bread and butter of our investigations," Mueller said.

...

In 2000, for example, the FBI issued an estimated 8,500 requests. That number peaked in 2004 with 56,000. Overall, the FBI reported issuing 143,074 requests in national security letters between 2003 and 2005.

But that did not include an additional 8,850 requests that were never recorded in the FBI's database, the audit found. A sample review of 77 case files at four FBI field offices showed that agents had underreported the number of national security letter requests by about 22 percent.

Additionally, the audit found, the FBI identified 26 possible violations in its use of the letters, including failing to get proper authorization, making improper requests under the law and unauthorized collection of telephone or Internet e-mail records.

The FBI also used exigent letters to quickly get information - sometimes in non-emergency situations - without going through proper channels. In at least 700 cases, these letters were sent to three telephone companies to get billing records and subscriber information, the audit found.


On the Net:

The report is at: http://www.usdoj.gov/oig/reports/FBI/index.htm

Justice Department: http://www.usdoj.gov

FBI: http://www.fbi.gov

Privacy, customer information and law enforcement

I had the honour of being asked to give a presentation for today's Dalhousie Student Association for Law and Technology conference. I spoke on the topic of privacy, customer information and law enforcement (200k PDF).

I was on a panel with a federal prosecutor and was surprised that we were in substantial agreement on the relationship between private businesses and law enforcement.

The rest of the day was great, as it included such heavyweights in IT law as Rod Burgar, Don Johnston, Duncan Card, Sunny Handa.

Monday, March 05, 2007

NHLPA investigated for allegedly reviewing members' e-mail

The Toronto Police are apparently investigating whether the National Hockey League Players' Association reviewed or blocked e-mail of members provided through the NHLPA's website. The police report has been referred to crown prosecutors, who will determine whether charges should be laid.

TheStar.com - News - Email furor has NHL players on edge

Toronto police are investigating complaints that executives at the NHL Players Association accessed and in some cases blocked the email accounts of players who have challenged the hiring of the union's executive director.

The allegations by players is the latest salvo in the battle for control of the splintered Toronto-based union.

Last month, the players voted for an independent investigation into the hiring of NHLPA executive director Ted Saskin in July 2005.

The investigation is also looking into the circumstances that led to the players association accepting a labour contract that included for the first time a cap on player salaries.

For the past two weeks, police have been looking into whether Saskin and Ken Kim, the union's senior director of business, ordered technical support staff at the union to access player email accounts hosted by the union, and whether such an action would be illegal, four sources familiar with the investigation told the Star.

Toronto police have now presented their findings to a Crown counsel, who will decide whether there is enough evidence to lay criminal charges....

Saturday, March 03, 2007

Canada.com pawns off webmail service to US provider; says PIPEDA no longer applies

Apparently, CanWestGlobalAsperOmniMedia has outsourced the Canada.com e-mail service to an American company, Velocity Services, Inc.

This is the blurb from the Canada.com website:

About canada.com

Where will my canada.com e-mail account information be stored?

canada.com e-mail (the "Service") is provided by Velocity Services, Inc. ("VSI"), a company located in and conducting its business from the United States. By registering for and/or logging on to the Service, you accept and acknowledge that the information processed or stored outside of Canada may be available to the foreign government of the country in which the information or the entity controlling it, is situated under a lawful order made in that jurisdiction and no longer falls under the jurisdiction of Canada's Personal Information Protection and Electronic Documents Act ("PIPEDA") nor be subject to canada.com's Privacy Statement.

That's all well and good, but I'm pretty confident that you can't wave a magic wand and say that PIPEDA no longer applies. Either of two things have happened here: (a) VSI is providing this service on behalf of CanWest, or (b) CanWest has now sold Canada.com's e-mail service to VSI. In neither case would PIPEDA cease to apply. For Canadian customers, there is enough of a real and substantial connection between the service and Canada for Canadian laws to apply. This would include PIPEDA.

In this conclusion, I have some comfort in the recent decision in Lawson v. Accusearch Inc., 2007 FC 125 (CanLII):

"[49] We revert to geographical considerations, and the concept of forum non conveniens. The collection and communication of private information was both here (Canada) and there (United States) (Libman v. The Queen, 1985 CanLII 51 (S.C.C.), [1985] 2 S.C.R. 178). The location of the website and the jurisdiction in which Accusearch Inc. was incorporated are not all controlling.

[50] It would not be appropriate to comment further on the discretion, if any, of the Commissioner to decline to exercise the jurisdiction given her by Parliament. The decision before me was that Parliament had not given her jurisdiction. However, I raise this point of discretion because it may be relevant when this matter is referred back to her for further investigation, or in other complaints. We do not know the status of the complaint filed in the United States, or the risk of double jeopardy to the respondent.

[51] In conclusion, PIPEDA gives the Privacy Commissioner jurisdiction to investigate complaints relating to the transborder flow of personal information."

Thanks to Canadian Journalist :: Canada.com now ...AMERICAN??? for the link. Time to cancel my old Canada.com e-mail account.

Friday, March 02, 2007

Prison sentence for installing spyware in the UK

A UK court has sentenced a 67 year old man to four months in prison for consipring to install spyware on the compuer of the accused's estranged wife, whom he suspected was hiding assets. See: DP thinker: First UK case on Spyware.

US Appeals Court upholds eight year sentence for theft of e-mail addresses

According to Computerworld, a US Appeals Court has upheld the eight year setence for the theft of billions of e-mail addresses from Acxiom: Appeals court: Stiff prison sentence in Acxiom data theft case stands. It's worth noting that the convictions were under the federal hacking staute and not theft of information simpliciter.

Thursday, March 01, 2007

This time it's personal

In addition to my weekly New Yorker magazine, today's mail contained a plain envelope with a PO Box return address. From a mile away, I could tell it was a credit card. Like many people recently, my bank has sent me a new credit card in the mail because I shopped at Winners. According to the letter, there is reason to believe my credit card was compromised in the Winners/TJX breach. The form letter tells me that there's been no evidence of fraudulent activity, but this is just in case.

When the TJX story broke, I attempted to contact their privacy officer through the address on the website. What I was looking for was a fax number becuase I did not want to communicate with them, particularly about my credit card, via e-mail. That was months ago and no contact and no reply. Not impressive.

I just went to the Winners website and tried to check out their IMPORTANT CUSTOMER ALERT, which connects (or rather doesn't connect) to a TJX server:

Less impressive.

Going directly to the TJX website provided a working link:

As TJX’s President and Chief Executive Officer, I want our customers to know how much I personally regret any difficulties you may experience as a result of the unauthorized intrusion into our computer systems. We are working with leading computer security firms to investigate the problem and enhance our computer security in order to protect our customers’ data. We are dedicating significant resources to evaluate the issue. Given the nature of the breach, the size and international scope of our operations and the complexity of the way credit card transactions are processed, the evaluation is, by necessity, taking time.

Since we learned of the probability of a breach in mid-December 2006, we have cooperated with law enforcement as well as with the banks and credit card companies that process our customer transactions. Further, we have established customer helplines in three countries and are making available a great deal of helpful information on our company websites.

We are committed to continue to address the situation and to provide periodic updates as we learn more. We have reported updated information in a press release which you will find below.

Additionally, I encourage you to access the information we are providing on this website to learn more about steps you can take to protect your credit and debit card information, or to contact our special customer helplines.

With the help of computer security experts, we have strengthened the security of our computer systems and we believe customers should feel safe shopping in our stores. We value the trust our customers place in us and again, I’d like you to know that we sincerely apologize for any difficulties you may be caused. Thank you for continuing to shop at our stores and for your years of loyal patronage.

Respectfully,

Carol Meyrowitz
President and Chief Executive Officer

Those affected may seek some perverse comfort that TJX may face significant penalties under the PCI Data Security Standard.

It will be interesting (but certainly not remedial in any way) to see what the Privacy Commissioner concludes about this investigation.