Tuesday, February 28, 2006

Facial recognition for banning bar "troublemakers"

Bars seem to be on the cutting edge of identification technology. Regular readers of the blog probably have noted references to bars scanning identification documents of visitors and some using external databases to keep track of banned patrons. (see Swiping driver's licenses - instant marketing lists?, Calgary student challenges nightclub over scanning ID, Alberta bar to continue scanning IDs despite Commissioner's advice not to, New technologies for scanning IDs.) Now, Wired News is reporting on facial recognition software that takes a picture of visitors to bars and matches them against a database of banned patrons. The technology was born in Toronto, Canada:

Wired News: BioBouncer Might Make Bars Safer

Privacy watchdog groups, however, don't like the sound of it, and it's not clear club patrons will dig it, either. Many people are already accustomed, or oblivious, to cameras recording their every move at ATMs and 7-11s. But in a bar's let-loose environment the sign Dussich wants posted at the entrance announcing that BioBouncer is recording their faces might send customers running.

Lee Tien, a staff attorney with the Electronic Frontier Foundation, said people may find BioBouncer insulting or invasive. Facial recognition software is notoriously inaccurate, he said, and he is concerned that data-sharing could be used to blackball innocent partiers.

"Think about it: Someone doesn't like you, your photo gets in there, you walk in someplace and they're telling you, 'You're a troublemaker, you got bounced from that other bar.'"

BioBouncer was born when a Toronto club owner asked if Dussich could help curb a burgeoning crime problem. Dussich may be on to something, as crime is plaguing the club scene nationwide, said Robert Smith, a police officer and nightclub security expert, who runs the Hospitality and Security Alliance.

Update: Bruce Schneier has some things to say about this:

Schneier on Security: Face Recognition Comes to Bars:

And the data will be owned by the bars that collect it. They can choose to erase it, or they can choose to sell it to data aggregators like Acxiom.

It's rarely the initial application that's the problem. It's the follow-on applications. It's the function creep. Before you know it, everyone will know that they are identified the moment they walk into a commercial building. We will all lose privacy, and liberty, and freedom as a result.

Technorati tags: :: :: ::

DNA tests to track down the toolbox piddler

Privacy is not always about identity theft and widespread eavesdropping. Sometimes it's a bit weird.

According to the Associated Press, a hospital in Baton Rouge, LA is about to spend $25,000 to test the DNA of a bunch of employees to figure out who peed in another employee's toolbox. Since nobody has stepped forward, there's no smoking gun and the trail has gone cold, the hospital administration is forcing 25 employees to provide a DNA sample or be terminated. Not surprisingly, some think it's an invasion of privacy.

DNA Tests Ordered for Urine Toolbox Prank - Yahoo! News:

'We checked with our legal counsel first and this is the next step in using technology to help solve a workplace incident,' hospital supervisor Stan Shelton said Monday.

The DNA testing, to be conducted by ReliaGene Technologies of New Orleans, will cost the hospital $25,000, he said.

Attorney Jill Craft worked with litigation involving swabs taken during the investigation into the South Louisiana serial killer cases. Craft fought for the rights of those swabbed during the probe that eventually resulted in the arrest of Derrick Todd Lee.

Craft said she believed the employees' rights are being violated. 'It's the intrusion by finding out what your DNA looks like, your unique pattern, which in my opinion, violates someone's right to privacy,' she said.

Technorati tags: :: :: ::

US judge strikes down Pennsylvania requirement for SSN for gun license

Thanks to a reader who passed this along ...

According to the Philadelphia Inquirer and the Associated Press, a US Federal judge has struck down Pennsylvania's requirement that prospective firearm purchasers provide their social security numbers. The PA law was found to violate the US federal Privacy Act. Here's the gist:

Philadelphia Inquirer 02/28/2006 Judge rejects Pa. gun-buying terms

...Sanchez's ruling noted that the right of privacy as to Social Security numbers exists under a federal law, not as a right the U.S. Supreme Court had interpreted as protected by the Constitution.

Still, Robert Ellis Smith, publisher of the Privacy Journal in Providence, R.I., said yesterday's ruling was "significant because it comes at a time when most government agencies are requiring more and more information from people."

"The decision is part of a trend in the last 10 years as courts realize the importance of keeping Social Security numbers confidential because of identity theft," Smith said. Smith, who is also a lawyer and journalist, was a paid expert for Michael Stollenwerk, the retired Army officer who brought the case in federal court in Philadelphia.

Stollenwerk said yesterday he hoped the ruling would inspire others to challenge government demands for Social Security numbers. He also said he hoped it would encourage local and state officials to review application requirements.

"A lot of state governments have blown off this law," said Stollenwerk, now a law student at Georgetown University. "I think someone had to stand up to the government and say, 'I'm going to challenge this.' "

Stollenwerk, 42, has pressed the matter on gun permits in other states, he said. In California, without going to court, he said, he was able to convince state authorities that their gun-purchase law violated the Privacy Act. In Virginia, he said, he was victorious in state court....

Technorati tags: :: :: :: ::

Oregon backup tape incident results in firing and policy changes

I blogged earlier this month about the theft of some computer backup tapes from a vehicle owned by an employee of Providence Home Services, a division of Providence Health System (The Canadian Privacy Law Blog: Correction: Information stolen from Providence Health System employee used fraudulently).

Here's a bit of an update: The company is reported by Computerworld to have carried out a thorough investigation of the incident. As a result, one employee has been fired and three have resigned. The company has also revised its security and backup policies so that data is not taken to employees' homes for offsite storage and data is routinely encrypted. From all appearances, the company has been very open about the incident and has issued a number of press releases on its website. This is critical, as trust is essential in the healthcare sector.

Technorati tags: :: :: ::

Unauthorised Photographs on the Internet and Ancillary Privacy Issues: Discussion Paper

The Australian Privacy Commissioner has released a discussion paper on the privacy issues inherent in the posting of photos on the internet by third parties. (It was actually released in November 2005, but I only recently found it.) It suggests following the lead set by the Dutch copyright law that would prohibit the use of a photo if it is against the reasonable interests of the subject of the photo. Check it out: Unauthorised Photographs on the Internet and Ancillary Privacy Issues: Discussion Paper.

Technorati tags: :: :: .

Medical ID theft on the rise

By now, we've all heard about identity theft in which someone assumes another's identity to obtain credit or other financial benefits. It is, we are told, the fastest growing crime in North America. Well, now Americans have to worry about "medical" identity theft. This is where someone (presumably uninsured) assumes another's identity to obtain medical services. That's what happened to Joe Ryan of Littleton, Colorado. Ryan unexpectedly received a bill for $44,000 for surgery and then the collection agents started calling. It appears that someone used his name to have a significant piece of surgery and Ryan is left holding the bag. At least one group of hospitals in Denver has information about fifteen such cases a year.

Where ID theft can put your credit rating in jeopardy, medical ID theft can do all that and kill you: victims' medical records now reflect conditions they don't have. Somewhat ironically, the hospital in Ryan's case refused to provide him with information about the services used by the impostor since HIPAA apparently prevented them from disclosing it to him. Check out the report on Ryan's case by Colorado 9News' I-TEAM: ID theft that could be deadly. There's a video link on the 9News site, as well.

Technorati tags: :: :: .

Monday, February 27, 2006

Montana enacts security breach notification law

Montana will be the next US state to have a when the state's new privacy law, HB 732, comes into force on Wednesday. The new law also requires companies to securely dispose of personal information and to only print the last five digits of credit card numbers on receipts. Check out New privacy law takes effect March 1.

Technorati tags: :: :: :: .

Symbolic fine imposed on photographers who pursued Princess Diana

According to the LA Times (and CBS and Canoe), three photographers have been fined one Euro each for invasion of privacy after the three took pictures of Princess Diana and Dodi al-Fayed on the night they both died in Paris. All three were found to be pursuing the Princess at the time her Mercedes crashed.

Technorati tags: :: :: ::

Back in Halifax

Sorry for the light blogging over the last little while. I've just come back from four days in Pasadena, California where I was attending the "Winter" Meeting of the Licensing Executives Society. (I've put winter in quotes because it was sunny and in the mid-twenties (c) the whole time.) There wasn't much there on privacy, but it did provide a lot of mental nourishment for the other side of my practice, IT and IP law.

While I was there, I met a fellow legal blogger, Bill Heinze of Atlanta, Georgia. He writes a blog entitled I/P Updates - News and Information for Intellectual Property Practitioners, which is one of the top ranked IP blogs and newsletters in the US. If your practice strays into that arena, you should check it out. If you need an incentive to visit the blog, Bill has written two posts about the content presented at the meeting: Asian Licensing Negotiating Tips and Music Licensing Update.

Waging war on pretexting, one state bar at a time

The Electronic Privacy Information Center (aka EPIC) has been waging war on the practice of "pretexting", which is most popularly associated with private investigators calling under under a fake identity with a fake rationale to get information about somebody they are investigating. Now, EPIC is taking it to the state bar associations in the US as they have concluded that lawyers are some of the prime consumers of pretexting services. In a letter sent to all the state bars, EPIC is calling upon the ethics bodies each state to issue an advisory opinion to prevent lawyers from using investigators who employ pretexting:

State Ethical Boards Must Take Action to Protect the Integrity of the Profession

We urge you to take action to review these practices under the ethical rules of your state. Pretexting involves using fraud to trick a company into releasing private personal information. We believe that hiring investigators or other services to engage in pretexting implicates ABA Model Rules 1.2, 3.4, 4.1, 4.4, and 8.4. We urge you to analyze the practice of pretexting under the ethical rules in force in your State.

We realize that attorneys may unwitting participants in this practice. They may hire investigators to locate witnesses or perform other functions without being aware that pretexting was being employed. Accordingly, issuing an advisory opinion or highlighting this issue in communications to members of the Bar may be appropriate action to addressing use of pretexting.

See also: EPIC West: Electronic Privacy Information Center West Coast Office: Pretexting and Attorneys' Ethical Rules

Technorati tags: :: :: ::