Monday, February 28, 2011

Tracking Internet miscreants

A growing portion of my practice is working with the litigators in my firm on cases of online torts, including defamation and harassment. This mainly involves working to track down people who do harmful things under a veil of supposed internet anonymity. This includes people who hide behind pseudonyms on chat boards and other internet fora while saying defamatory things in addition to the (apparently) growing problem of creating fake Facebook profiles in order to harass and bully others. We've dealt with similar situations involving online dating sites, where people have set up fake profiles in the names of the victims in order to harass them.

I'm not sure about the psychology behind this, but it certainly appears as though many people feel free to say things about others on the internet that they would never say in "public" or to the person's face. Others, bullies in particular, see the internet as a great place to extend their activities, often with very harmful results.

Some of the cases I've worked on have become well-publicized in this region, and I was asked by the Canadian Bar Association - New Brunswick Branch to present on the topic at their annual Mid-Winter Meeting. In case you're interested, below is a presentation on what sorts of tracks people leave online and how they can be assembled and used to try to identify otherwise unnamed defendants. In almost all cases, they involve applying to the court for Norwich orders, which is a form of order from the court to require a mostly uninvolved third-party to provide information that will lead to the identification of the actual defendant. The court, acting as the gatekeeper, needs to balance the interests of the plaintiff who is looking for a remedy against the interests of both the third party service provider and the unnamed defendant. In short, the court should not allow a fishing expedition, nor should it allow the disclosure if the claim is not reasonably well established. Only if the plaintiff is able to satisfy the following test will the court order disclosure:

(1) the applicant must establish a bona fide claim against the unknown alleged wrongdoer;

(2) the third party against whom discovery is sought must be in some way connected to or involved in the misconduct;

(3) the third party must be the only practical source of the information available to the applicant;

(4) the third party must be reasonably compensated for expenses and legal costs arising out of compliance with the discovery order; and

(5) the public interest in favour of disclosure must outweigh the legitimate privacy interests.

Here is the presentation I gave to the Canadian Bar Association New Brunswick's Mid-Winter Meeting:

https://docs.google.com/present/view?id=ddpx56cg_379fgxwmgd4&interval=60

Here are a couple of notable reported cases where we have been successful in obtaining information from third party service providers to identify defendants:

Thursday, February 24, 2011

Ryerson University looks to the cloud

Today, I had the great pleasure of being one of the speakers at Ryerson University's broad consultation on the possibility of adopting cloud computing at the university. It was an incredibly high-quality event with a packed auditorium (in the middle of reading week, no less) and a very engaged audience.

The agenda is here: E-mail and Collaboration Tools Consultation | Email & Collaboration Tools Consultation.

My presentation is here:

If you can't see the embedded presentation, try this link: https://docs.google.com/present/view?id=ddpx56cg_415c4c8k5g5&interval=60

The full symposium was webcast live and will be available here:

If you want to see the many, many tweets which were sent out, search Twitter for #ryeprivacy.

UPDATE: Over at Slaw.ca, Dan Michaluk, who was at the symposium, has posted a few of his observations on the day: Commissioner Cavoukian says the Patriot Act is nothing.

Tuesday, February 22, 2011

Social Media and the Courts

In September of last year, I was honoured to be invited to give a presentation to the Canadian Centre for Court Technology as part of a panel on The Ethical Implications of Technology. My co-panelists were the Assistant Privacy Commissioner Chantal Bernier and Professor Pierre Trudel.

I've just been advised that the video of the presentation is now online here. It's worth checking as it's chock full o' privacy stuff.

If you want to see the presentation, it's here:

Monday, February 21, 2011

Court Grants Ex Parte Order to Preserve Facebook

Last month, one of my partners made an application before the New Brunswick Court of Queens bench for an unusual ex parte order for the preservation and production of the contents of plaintiff's Facebook account. The order and reasons are here: Sparks v. Dubé, 2011 NBQB 40 (CanLII).

It's an unusual situation, which is well summarized by Dan Michaluk: Court Grants Ex Parte Order to Preserve Facebook « All About Information.

Monday, January 31, 2011

Avoid ATM skimmers, use a hotel key card instead

Bank card skimmers and scammers are a pretty resourceful bunch. While people are becoming increasingly vigilant about skimming hardware being covertly added to bank machines, they may not be aware of skimmers being added to card readers that are used for after-hours access to ATMs in bank lobbies. (See: ATM skimmer that doesn't require any modifications to the ATM - Boing Boing.)

This may not be general knowledge, but most of these card readers don't validate the card but just check for a magnetic stripe.

To avoid having your card skimmed at the doorway, you can often use any card with a mag-stripe, such as an old hotel key card, a gift card or your library card. Next time you're at an ATM, give it a try.

Monday, January 17, 2011

Nova Scotia review officer considers investigation of WCB over misdirected file

Last week, the Halifax Chronicle Herald reported that the provincial Workers' Compensation Board mistakenly sent the wrong person's file to an individual who was contesting his claim under the program.

It looks like it was a one-off error:

WCB sends wrong file to man - Metro - TheChronicleHerald.ca)

.... MacLean insists the board does not often mix up its clients and she can’t remember the last time a file was mailed out in error.

"Our employees all go through (Freedom of Information and Protection of Privacy Act) and privacy breach training and we take this all very seriously."

And they have procedures to follow if something does go awry.

To help avoid personal information falling into a stranger’s hands, she said the envelope is stamped with a warning message that asks the recipient to alert the board if the received the envelope in error. It also asks the recipient not to open or destroy its contents.

However, she admitted, she didn’t know how anyone could tell if the file wasn’t theirs without first opening the envelope and reading the contents.

The board is mailing Kinsman his correct file, MacLean said.

Today the paper is reporting that the newly established Privacy Review Officer is considering an investigation: Privacy watchdog mulls probe of WCB - Front - TheChronicleHerald.ca.

I'm not sure that this error indicates any sort of a systemic problem, but I expect we'll hear more about it in the future.

Personal Health Information Act for Researchers

I was invited to give a presentation to staff and physicians at the IWK Health Centre in Halifax on the impact of the new Personal Health Information Act on researchers and research activities.

For anyone who may be interested, here is a copy of the presentation:

(If the embedding above is not working for you, this link should take you to the presentation: https://docs.google.com/present/view?id=ddpx56cg_32947mwh5hq&interval=30&autoStart=true&loop=true)

Saturday, January 15, 2011

Investigating and Preventing Criminal Electronic Communications Act bill one step closer to (warrantless) surveillance state

Want to know one reason why the Canadian government's proposed Bill C-52, referred to as the Investigating and Preventing Criminal Electronic Communications Act, is so horrible? Just look at what recently happened in Belarus. According to Boing Boing (Report: Belarusian mobile operators gave police list of demonstrators - Boing Boing), mobile operators in that country have cooperated with the secret police to identify people who were present at an anti-government demonstration. Shocking.

Bill C-52 gives the same tools to the Canadian secret and not-quite-secret police. Section 16 of Bill C-52 requires all telecommunciations service providers to hand over enormous quantities of customer information to the police, CSIS or the competition cops. There is no limit on the amount of information to be provided and is only restricted to "duties" of the cops or intelligence agency. In addition, the law just says that the following information has to be provided:

  • name,
  • address,
  • telephone number,
  • electronic mail address,
  • Internet protocol address,
  • mobile identification number,
  • electronic serial number,
  • local service provider identifier,
  • international mobile equipment identity number,
  • international mobile subscriber identity number and
  • subscriber identity module card number.

Usually, the cops say they need help chasing down a customer name and address when they have an IP address, but the bill doesn't say that if the cops have X info, they can get Y subscriber data. Instead, it just says on request the telco has to hand over the entire laundry list of data on customers. And this is without a warrant or any sworn justification of any kind. Unlike wiretap laws where stats have to be released, there is no obligation on the part of the police or the ministers responsible to release information about how these powers are used and under what circumstances.

If the police are able to scan the airwaves at a protest and pick out the IMEIs of all the phones present, telcos would have to hand over a list of all the names, addresses, etc of their customers upon request. I can't really see a limitation in the statute that would prevent the police from asking for all the above data for any subscribers who connected, for example, to any cell site in a particular neighbourhood at a particular time. How handy would that be to track down everyone who was present near the G-20 protests in Toronto.

If we're shocked at what repressive regimes are doing to their citizens, we shouldn't be giving our own governments tools to be repressive.

(The good news, if there is any, is that the Bill was introduced on November 1, 2010 and doesn't seem to be going anywhere fast. But don't count it out yet.)

Friday, January 14, 2011

Your smartphone could be your most dangerous possession, so secure it

After a decision out of California which found that police are able to rummage through all your portable electronics incident to arrest, much attention has been focused on how much data people carry around with in their portable electronics. CNN Money is running a story with the descriptive title: Your smartphone could be your most dangerous possession.

I've brought this up a number of times in presentations about border searches, where customs agents have always had the right to go through all your stuff you're carrying but what's different now is that people are carrying around the equivalent of their personal files, their scrapbooks and their correspondence in a small package.

The threat isn't just customs agents and police, but also the fact that people lose these devices all the time. People need to be mindful of this fact and take steps to either limit what they have on their devices or take steps to make it inaccessible to others. For some useful pointers on how to do so on most smartphones, check out LifeHacker's How to Secure Your Smartphone.

Thursday, January 13, 2011

Arizona hospital fires employees for snooping on records of shooting victims

Various media outlets are reporting that the Tucson University Medical Center has fired a number of employees for inappropriate accessing medical records of people involved in the shooting in Arizona that left Rep Gabrielle Giffords gravely injured and six dead. See: 3 UMC workers fired for invading records.

This is an example of how important it is to have auditability in your records system because curiosity often leads to employees overstepping established boundaries.