Sunday, March 09, 2008

The New School of Information Security

Adam Shostack, one of the most prolific contributors at Emergent Chaos, is the co-author of an interesting-sounding book being launched tomorrow. Here's the scoop from Amazon:

Amazon.com: The New School of Information Security: Adam Shostack,Andrew Stewart: Books

Why is information security so dysfunctional? Are you wasting the money you spend on security? This book shows how to spend it more effectively. How can you make more effective security decisions? This book explains why professionals have taken to studying economics, not cryptography--and why you should, too. And why security breach notices are the best thing to ever happen to information security. It’s about time someone asked the biggest, toughest questions about information security. Security experts Adam Shostack and Andrew Stewart don’t just answer those questions--they offer honest, deeply troubling answers. They explain why these critical problems exist and how to solve them. Drawing on powerful lessons from economics and other disciplines, Shostack and Stewart offer a new way forward. In clear and engaging prose, they shed new light on the critical challenges that are faced by the security field. Whether you’re a CIO, IT manager, or security specialist, this book will open your eyes to new ways of thinking about--and overcoming--your most pressing security challenges. The New School enables you to take control, while others struggle with non-stop crises.

Better evidence for better decision-making

  • Why the security data you have doesn’t support effective decision-making--and what to do about it
  • Beyond security “silos”: getting the job done together
  • Why it’s so hard to improve security in isolation--and how the entire industry can make it happen and evolve
  • Amateurs study cryptography; professionals study economics
  • What IT security leaders can and must learn from other scientific fields
  • A bigger bang for every buck: How to re-allocate your scarce resources where they’ll do the most good

Crossing the border? Consider the possibility of laptop searches

As March Break is almost in full swing, it's timely to read Compterworld's recent 5 things you need to know about laptop searches at U.S. borders. State sovereignty usually means that a country has total control over who and what gets in and traditional searches are being extended to laptop searches. This makes sense on one level but seems futile as any traveller can upload ilicit digital content before crossing into the US and then download it on the other side of the border.

But searches are happening, so make sure you delete from your computer all content that you wouldn't want disclosed as part of such a search. Lawyers should particularly remove any privileged content they don't need to be taking with them. And if you're a public servant from BC, Alberta or Nova Scotia, you can't take it with you thanks to the USA Patriot Act blocking legislation in your province.

Google/Doubleclick merger expected to clear EU hurdles this week

According to Reuters, the proposed merger of Google and Doubleclick is expected to clear all regulatory hurdles in the European Union despite protests of privacy advocates. See: EU set to clear Google/DoubleClick merger Technology Reuters.

Saturday, March 08, 2008

A small step for biometrics; a giant leap for the UK surveillance state

Passengers flying through Heathrow Airport, Terminal 5, will be photographed and fingerprinted twice before being permitted to board domestic flights. The British Airport Authority, which runs the new terminal through which all British Airways passengers will travel say this measure is "necessary to prevent criminals, terrorists and illegal immigrants trying to bypass border controls."

The only reason why this may be necessary is that the design of the new terminal permits international and domestic passengers to mingle in the secure area. Theoretically, transiting international passengers would be able to swap boarding passes with a domestic passenger circumventing border controls. On balance, it just makes sense to ramp up the big brother factor if it means the BAA doesn't have to follow the non-intrusive but universal designs used by every other airport I have ever been through.

The BAA also says the fingerprints will be discarded after 24 hours, unless -- of course -- they are of interest to the police. See: Heathrow airport first to fingerprint - Telegraph. Via the ever vigilant Boing Boing: Heathrow Terminal 5 to fingerprint domestic passengers - Boing Boing.

Friday, March 07, 2008

Assistant Commissioner takes the show on the road

Over the last couple of days, representatives of the Office of the Privacy Commissioner of Canada have had a real blitz through Halifax. Elizabeth Denham, the current Assistant Commissioner responsible for PIPEDA and her predecessor, Heather Black, have been in town as part of an outreach effort to determine what it takes to raise awareness of and compliance with privacy laws in the eastern hinterlands. As part of this, the office has hired a representative who is based in Halifax to lead these outreach efforts.

I had the pleasure of hearing Heather Black speak at Dalhousie Law School on Wednesday night about the genesis and drafting of PIPEDA. It's an interesting story about how we ended up with two pieces of legislation (the Personal Information Protection Act and the Electronic Documents Act) thrown together and how, at the last minute, the proposed bill was changed to go beyond the federally regulated sector.

Yesterday, the Information Technology Industry Alliance of Nova Scotia (of which I'm the Director of Advocacy) hosted a roundtable with representatives of the IT, telecom, health, marketing, retail and small business sectors to talk about why awareness of PIPEDA is so low among consumers and small business, and what can be done to change that. Earlier in the day, they had participated in a fraud prevention forum, also at Dalhousie: Nova Scotia News - TheChronicleHerald.ca.

I understand the mission in Halifax continues today ...

Thursday, March 06, 2008

Privacy Commissioners Release New Video Surveillance Guidelines

The Privacy Commissioners of Canada, British Columbia and Alberta today have released Guidelines for Overt Video Surveillance in the Private Sector to help businesses consider privacy matters when deciding whether to and how to implement overt video surveillance. (I wonder whether they'll also produce guidelines on covert surveillance?)

From the media release:

Privacy Commissioners Release New Video Surveillance Guidelines

Privacy Commissioners Release New Video Surveillance Guidelines

OTTAWA, March 6, 2008 — Private-sector organizations considering video surveillance systems must take specific steps to minimize the impact on people’s privacy, say video surveillance guidelines released today.

The new guidelines set out how companies should evaluate the use of video surveillance and ensure any surveillance they undertake is conducted in a way that respects privacy rights and complies with the law.

These guidelines have been endorsed by Jennifer Stoddart, the Privacy Commissioner of Canada, Frank Work, the Information and Privacy Commissioner of Alberta, and David Loukidelis, the Information and Privacy Commissioner for British Columbia.

“We have seen a dramatic increase in the use of surveillance cameras by private-sector organizations. Many of our day-to-day activities are now captured by these cameras,” says Commissioner Stoddart.

“There are some legitimate reasons to conduct video surveillance, but privacy laws in Canada impose restrictions and obligations when, where and how businesses can conduct this kind of surveillance,” says Commissioner Loukidelis.

“These guidelines make it clear that businesses must carefully evaluate why they are installing video surveillance equipment, and what they will do with the information that is collected,” says Commissioner Work.

The Commissioners say it is disturbing to hear stories about video surveillance operators deliberately pointing cameras to ogle women, as well as surveillance images of people caught in unflattering situations finding their way onto video sharing sites like YouTube and Vimeo.

The new guidelines are aimed at businesses subject to the Personal Information Protection and Electronic Documents Act, or PIPEDA. They are also targeted at businesses subject to the provincial Personal Information Protection Acts in Alberta and British Columbia.

The overarching principle for video surveillance – which stems from the key legal test under the federal and provincial laws – is that it should be used only for purposes that a reasonable person would consider appropriate in the circumstances.

The guidelines state that, in order to limit the impact on privacy, cameras should be positioned to avoid capturing the images of people not being targeted (e.g., someone walking outside a store). As well, cameras should not be used in areas where people have a heightened expectation of privacy, such as washrooms, and through building windows.

The guidelines also say:

  • People should be notified about the use of cameras before they enter the premises.
  • Individuals whose images are captured on videotape should, upon request, be given access to this recorded personal information.
  • Organizations must ensure that video surveillance equipment and videotapes are secured and used for authorized purposes only.
  • Individuals who operate video surveillance systems should understand the privacy issues related to surveillance and their obligations under the law.
  • Video surveillance recordings should be retained only as long as necessary and destroyed securely.

The complete guidelines for private-sector organizations are available at www.privcom.gc.ca, www.oipc.ab.ca and www.oipc.bc.ca. The Office of the Privacy Commissioner of Canada and the Office of the Information and Privacy Commissioner for British Columbia have previously published guidelines for the use of video surveillance in public places by police and law enforcement authorities.

All three privacy commissioners are statutorily mandated to oversee compliance with the Acts and are advocates and guardians of privacy and the protection of personal information rights of Canadians.

Wednesday, March 05, 2008

Federal Commissioner drops greeting card inquiry; political parties beyond reach of privacy legislation

Interesting, but not surprising, development:

CANOE -- CNEWS - Canada: Privacy czar drops Rosh Hashanah inquiry:

"OTTAWA - The federal privacy commissioner has quietly dropped her investigation into complaints that Prime Minister Stephen Harper mailed unsolicited Rosh Hashanah greetings, saying she has no jurisdiction over the matter because political parties fall outside Canada's two privacy laws."

Monday, March 03, 2008

Ontario Commissioner releases detailed report on TTC surveillance cameras

The Information and Privacy Commissioner of Ontario has released an extensive report on the use of video surveillance by the Toronto Transit Commission. The report can be found here: Privacy and Video Surveillance in Mass Transit Systems: A Special Investigation Report - Privacy Investigation Report MC07-68.

From the media release:

TTC’s surveillance cameras comply with privacy Act, but additional steps needed to enhance privacy protection, says Privacy Commissioner Ann Cavoukian

TORONTO – Ontario Information and Privacy Commissioner Ann Cavoukian ruled today that the Toronto Transit System’s expansion of its video surveillance system, for the purposes of public safety and security, is in compliance with Ontario’s Municipal Freedom of Information and Protection of Privacy Act – but she is calling on the TTC to undertake a number of specific steps to enhance privacy protection.

The Commissioner’s office conducted a four-month special investigation that went beyond the scope of the usual privacy investigation conducted in that it included:

  • A detailed review of the literature and analysis from various parts of the world on the effectiveness of video surveillance;
  • An examination of the role that privacy-enhancing technologies can play in mitigating the privacy-invasive nature of video surveillance cameras; and
  • A detailed investigation into a privacy complaint by U.K-based Privacy International about the expansion of the TTC’s video surveillance system.

“Video surveillance presents a difficult subject matter for privacy officials to grapple with impartially because, on its face, it is inherently privacy-invasive due to the potential for data capture – despite that fact, there are legitimate uses for video surveillance … that render it in compliance with our privacy laws,” said the Commissioner. “Mass transit systems like the TTC, that are required to move large volumes of people, in confined spaces, on a daily basis, give rise to unique safety and security issues for the general public and operators of the system.”

“The challenge we thus face is to rein in, as tightly as possible, any potential for the unauthorized deployment of the system. We have attempted to do this by ensuring that strong controls are in place with respect to its governance (policy/procedures), oversight (independent audit, reportable to my office) and, the most promising long-term measure, the introduction of innovative privacy-enhancing technologies to effectively eliminate unauthorized access or use of any personal information obtained.”

While the expectation of privacy in public places is not the same as in private places, it does not disappear. People have the right, the Commissioner stresses in her report, to expect the following when it comes to video surveillance:

  • That their personal information will only be collected for legitimate, limited and specific purposes;
  • That the collection will be limited to the minimum necessary for the specified purposes; and
  • That their personal information will only be used and disclosed for the specified purposes.

“These general principles,” said Commissioner Cavoukian, “should apply to all video surveillance systems. Where developments such as video surveillance in mass transit systems, like the TTC, can be shown to be needed for public safety, you must also ensure that threats to privacy are kept to an absolute minimum.”

Among the 13 recommendations the Commissioner is making to the TTC are the following:

  • That the TTC reduce its retention period for video surveillance images from a maximum of seven days to a maximum of 72 hours (the same standard as the Toronto Police), unless required for an investigation;
  • That the TTC’s video surveillance policy should specifically state that the annual audit must be thorough, comprehensive, and must test all program areas of the TTC employing video surveillance to ensure compliance with the policy and the written procedures. The initial audit should be conducted by an independent third party using Generally Accepted Privacy Principles, and should include an assessment of the extent to which the TTC has complied with the recommendations made in this special report;
  • That the TTC should select a location to evaluate the privacy-enhancing video surveillance technology developed by University of Toronto researchers, K. Martin and K. Plataniotis; and
  • That, prior to providing the police with direct remote access to the video surveillance images, the TTC should amend the draft memorandum of understanding (MOU) with the Toronto Police to require that the logs of disclosures be subjected to regular audits, conducted on behalf of the TTC. A copy of the revised draft MOU should be provided to the Commissioner prior to signing.

EMERGING PRIVACY-ENHANCING TECHNOLOGY

The Commissioner devotes part of her 50-page special report, and a specific recommendation, to the area of emerging privacy-enhancing video surveillance technology.

“In light of the growth of surveillance technologies, not to mention the proliferation of biometrics and sensoring devices, the future of privacy may well lie in ensuring that the necessary protections are built right into their design,” said the Commissioner. “Privacy by design may be our ultimate protection in the future, promising a positive sum paradigm instead of the unlikely obliteration of a given technology.”

As an example of the research being conducted into privacy-enhancing technologies, the Commissioner cites the work of researchers Karl Martin and Kostas Plataniotis at the University of Toronto, who used cryptographic techniques to develop a secure object-based coding approach. While the background image captured by a surveillance camera can be viewed, the sections where individuals are caught in the image would automatically be encrypted by the software. Designated staff could monitor the footage for unauthorized activity, but would not be able to identify anyone. Only a limited number of designated officials with the correct encryption key could view the full image.

The Commissioner is recommending that the TTC select a location to evaluate the video surveillance technology developed by Martin and Plataniotis.

A copy of the special report is available on the IPC’s website, www.ipc.on.ca.

Dilbert on drug testing, etc.

Sunday, March 02, 2008

Court of Appeal considers insured's right of access to IME notes

Last month, the Federal Court of Appeal issued its decision in Wyndowe v. Rousseau, 2008 FCA 39 (CanLII). This case involved an individual's request for access to information generated by a physician hired by his insurer for the purposes of an independent medical examination. At trial, Justice Tietelbaum held the information was "personal information" for the purposes of PIPEDA and that it was not covered by litigation privilege (See Rousseau v. Wyndowe, 2006 FC 1312 (CanLII) and Canadian Privacy Law Blog: FCA grants stay of judge's order for disclosure of personal information). The question of litigation privilege was not appealed.

The Federal Court of Appeal has some interesting things to say about the interplay of the common law and PIPEDA, the definition of personal information, the nature of "commercial activities".

On the question of "commercial activities", the Court was clear that the collection of the applicant's personal information was in the course of commercial activities:

[35] The question is whether the IME transaction was of a “commercial nature”, as defined in section 2. The transaction between Dr. Wyndowe’s corporation and Maritime Life, who was paying for the IME, is of a commercial nature. Mr. Rousseau’s relationship between himself and Maritime Life is also clearly of a commercial nature: it is governed by a contract between Mr. Rousseau and his insurer, where Mr. Rousseau presumably paid some premiums (or his employer paid the premiums as part of Mr. Rousseau’s compensation for employment) and he therefore may or may not be entitled to benefits.

[36] In the context of these two commercial relationships – between Dr. Wyndowe’s corporation and Maritime Life on the one hand and between Mr. Rousseau and Maritime Life on the second hand – I find it hard to believe that by introducing a third relationship – between Dr. Wyndowe and Mr. Rousseau – the commercial nature of the overall transaction is defeated. In my view, Dr. Wyndowe is merely the medical agent of Maritime Life. If Dr. Wyndowe worked as a full time doctor for Maritime life, there would be no question the transaction is commercial; being examined by him would merely be a step which Mr. Rousseau had to follow to collect his benefits. In that sense the examination would be akin to filling out a form required by Maritime Life in order to begin collecting benefits. Just because Dr. Wyndowe is an independent consultant hired by Maritime Life does not change the fact that the overall transaction retains its commercial nature. It also does not change the fact that Mr. Rousseau was only doing what his contract with Maritime Life required him to do to maintain his benefits, i.e. submitting to an IME.

With respect to whether the information is "personal information" of the applicant, the Court concluded it was:

[49] In light of the Privacy Commissioner’s recognition that there are in the notes information which is personal to Mr. Rousseau and information which is not, it may be said that in the end, Mr. Rousseau has a right of access to the information he gave the doctor, and to the final opinion of the doctor in the form of the report to the insurer. In accordance with Principle 4.9.1. of Schedule I to the PIPED Act, this enables Mr. Rousseau to correct any mistakes in the information he gave the doctor or which the doctor noted, as well as any mistakes in the doctor’s reasoned final opinion about his medical condition. But the process of getting to that final opinion from the initial personal information of Mr. Rousseau belongs to the doctor.

[50] This Court, in Canada (Information Commissioner) v. Canada (Minister of Citizenship and Immigration) (above, at para. 8), has recognized that “the same information can be “personal” to more than one individual” (at para. 15). It may well be, in the end, that some information in the notes will be personal to both Mr. Rousseau and Dr. Wyndowe. A balancing exercise similar to that proposed in our ruling in Canada (Information Commissioner) would then need to be performed.

And on the interplay between the common law and PIPEDA:

[26] A) the common law

The appellant first submits that as the PIPED Act does not clearly and unambiguously override the common law respecting the right of access to one’s personal health record, the common law should apply. At common law, as the argument goes, the right to inspect one’s medical records is only recognized where there is a fiduciary relationship between physician and patient (see McInerney v. MacDonald, 1992 CanLII 57 (S.C.C.), [1992] 2 S.C.R. 138. As there is no fiduciary relationship between the insured and the insurer’s doctor performing an IME (see X(Minors) v. Bedfordshire County Council, [1995] 3 All E.R. 353 (H.L.), the insured has no right of access to his medical records.

[27] I am not persuaded that at common law an insured has no right of access to his medical records. In any event, it is my view that the common law should not prevail where the very purpose of the PIPED Act is to provide new privacy protections to Canadians not otherwise enjoyed under the common law.

In the result, the Court of Appeal held that the applicant/insured had a right of access to the notes of the examining physician under PIPEDA.