Monday, February 25, 2013

Commissioner expands HRSDC breach investigation to Justice Canada

The Toronto Star is reporting that the Privacy Commissioner's investigation of the loss of a USB device containing the sensitive personal information, health information and financial information of 5000 people has expanded to include Justice Canada. From the Star:

Privacy watchdog expands probe over lost USB key to include justice department | Toronto Star

Marian Ngo, a spokeswoman for the human resources department, said the department notified legal services on Nov. 16 that a USB key containing the personal information of 5,045 Canadians who had applied for CPP disability benefits went missing from an employee’s desk.

Information found on the USB stick included social insurance numbers, surnames, occupations, birth dates, medical conditions, level of education, whether there are other payers, such as workers’ compensation, and which Service Canada processing centre was dealing with their applications.

The USB key was not encrypted or protected by a password. Ngo said the memory stick had been delivered by hand two days earlier to legal services for work on a project dealing with transitioning files to the Social Security Tribunal, which opens Apr. 1.

Officials from both HRSDC and Justice Canada searched for USB key extensively on Nov. 16, including at the home of the employee, but could not find it and it was considered lost Nov. 27.

Friday, February 22, 2013

Password protect your phone if you care about your privacy: What R v Fearon means

The portions of the twitterverse that I follow were abuzz yesterday with posts about how, in Canada, the police can search your cell phone without a warrant unless it is password protected following the release of the Ontario Court of Appeal decision in R. v. Fearon, 2013 ONCA 106.

I think this is an important case (which I also don't agree with), but it bears mentioning that the case isn't as bad as some tweets would suggest. Don't get me wrong; I think it's wrongly decided, but some of the tweets and Facebook posts I saw were a bit misleading.

In this case, the defendant was arrested after a robbery. He was properly arrested and the police found his cell phone on his person. It was an LG feature phone, not a smart phone. The phone was on and did not have a password on it. The police went looking through its contents and found incriminating photos and text messages. The police later got a warrant to forensically examine the device.

At trial, the defendant tried to have this evidence excluded arguing that there was a reasonable expectation of privacy in the contents of the phone and they police should have first gotten a warrant. The Canadian Civil Liberties Association and others intervened on appeal, arguing that there should be a cell phone exception to the general rule that allows the police to search "incident to arrest". The Court did not agree. Here's what the Court said:

[72] The problem I have with the appellant’s position and, in particular, the position of the Canadian Civil Liberties Association, is that it would appear to mark a significant departure from the existing state of the law on the basis of a record that does not suggest it is necessary. While I appreciate the highly personal and sensitive nature of the contents of a cell phone and the high expectation of privacy that they may attract, I am of the view that it is difficult to generalize and create an exception based on the facts of this case. The facts of this case, with the correct application of the existing law, suggest that the search and seizure of the cell phone at the scene of the arrest were carried out appropriately and within the limits of the law articulated by the Supreme Court in Caslake.

[73] In this case, it is significant that the cell phone was apparently not password protected or otherwise “locked” to users other than the appellant when it was seized. Furthermore, the police had a reasonable belief that it would contain relevant evidence. The police, in my view, were within the limits of Caslake to examine the contents of the cell phone in a cursory fashion to ascertain if it contained evidence relevant to the alleged crime. If a cursory examination did not reveal any such evidence, then at that point the search incident to arrest should have ceased.

[74] The appellant directed this court to statements made by the trial judge in Little, where she concluded at para. 147 that the cell phone in issue “functioned as a mini-computer”. Furthermore, the court in Little found that the contents of the cell phone “were not immediately visible to the eye” and were “extracted by a police officer with specialized skills using specialized equipment.” There was no suggestion in this case that this particular cell phone functioned as a “mini-computer” nor that its contents were not “immediately visible to the eye”. Rather, because the phone was not password protected, the photos and the text message were readily available to other users.

[75] If the cell phone had been password protected or otherwise “locked” to users other than the appellant, it would not have been appropriate to take steps to open the cell phone and examine its contents without first obtaining a search warrant.

[76] In short, I find myself in the same position as this court found itself in Manley. To quote from the reasons of Sharpe J.A. again, it is “neither necessary nor desirable to attempt to provide a comprehensive definition of the powers of the police to search the stored data in cell phones seized upon arrest.”

[77] It may be that some future case will produce a factual matrix that will lead the court to carve out a cell phone exception to the law as articulated in Caslake. This is not that case. To put it in the modern vernacular: “If it ain’t broke, don’t fix it.”

So what does this case really mean?

  • Police cannot just search your cell phone if they want to. It has to be a search incident to arrest.
  • If you are legitimately arrested AND the phone is likely to contain relevant evidence AND it is unlocked, they can do a cursory search.

So what should everyone do, regardless of this case? If you have personal information on your [smart/dumb/feature/other] phone, put a password on it. Your phone is more likely to fall into the hands of the owner of the taxicab you left it in than the police (hopefully), but you never want sensitive personal information in the hands of ANYONE. Put a password on it and use the feature that puts your "If found, contact ..." on the lock screen.

Friday, February 15, 2013

HRSDC appears before Parliamentary Committee to account for massive data breaches

Representatives of Human Resources and Skills Development Canada appeared before the House of Commons Standing Committee on Human Resources, Skills and Social Development and the Status of Persons with Disabilities (HUMA) to account for HRSDC's data loss. The testimony will appear here, when the transcript is prepared: House of Commons Committees - HUMA (41-1) - Study Home - Ensuring the protection of personal information held by HRSDC. You can watch the testimony by clicking on the Webaast icon here.

Though the HUMA committee has oversight of HRSDC, they should also be dragged in front of the Standing Committee on Access to Information, Privacy and Ethics (ETHI), which has oversight of privacy more generally.

Here is the Toronto Star's coverage of the appearance: Ottawa sorry for losing data on 500,000 Canadians.

Despite the Silicon Valley boogeymen, the Canadian government is the greatest threat to your privacy

Jesse Brown at Macleans.ca has had a great series of four posts on his blog there, which highlight that despite all the attention being lavished on Facebook, Google, WhatsApp and other American internet companies, the most ignored threat to the privacy of Canadians is the Government.

Government information security practices are laughable, fear of the cloud means that public servants have to use insecure USB storage devices to move data, the regulatory regime is antiquated and not up to the task, and the Privacy Commissioner spends a disproportionate amount of time chasing Silicon Valley companies. It's a perfect storm that's not getting adequate attention.

The Privacy Act is completely not up to the task. If the Commissioner needs order-making powers and the ability to levy fines, that power should be directed to the government where her sensible advice is sorely needed and often ignored.

Privacy is generally about choice: you get to choose with whom you share your information, what they can do with it and with whom it can be disclosed. But personal information protection by governments is dramatically different from the private sector. If I don't like my bank's practices, I can go to another bank. If I don't like how Twitter or Facebook work, I can shut down my accounts or go somewhere else. Individuals do not have any choice about their governments. If you are disabled and want benefits you paid for, you have no choice but to go to HRSDC, which is -- by all appearances -- contemptuous of your privacy. In my view, governments have a much higher duty to protect your privacy because choice has been completely removed from the equation. It's time that government starts living by the same rules they impose on your bank and the Internet boogeymen.

Check Jesse's posts out:

Monday, February 11, 2013

Lawful access dead, says Justice Minister

According to the CBC, Bill C-30 is officially dead and any replacement measure will not have a provision for warrantless access to customer information:

Government killing online surveillance bill - Politics - CBC News

Federal Justice Minister Rob Nicholson says the controversial Bill C-30, known as the online surveillance or warrantless wiretapping bill, won't go ahead due to opposition from the public.

Canadians rallied against the bill after the public safety minister told an opposition MP that he could "either stand with us or with the child pornographers."

"We will not be proceeding with Bill C-30 and any attempts that we will continue to have to modernize the Criminal Code will not contain the measures contained in C-30, including the warrantless mandatory disclosure of basic subscriber information or the requirement for telecommunications service providers to build intercept capability within their systems," Nicholson said.

"We've listened to the concerns of Canadians who have been very clear on this and responding to that."

Nicholson made the announcement after introducing a bill to update provisions that would allow for warrantless phone tapping in emergencies.

Canadian law allows police to wiretap without authorization from a court when there is the risk of imminent harm, such as a kidnapping or bomb threat, but the Supreme Court last year struck down the law and gave Parliament 12 months to rewrite another one.

Friday, February 01, 2013

BC hospital employees point to privacy concerns to prevent outsourcing of transcription services

Once again, a public sector trade union is using supposed privacy concerns as a lever to prevent outsourcing: Hospital Employees’ Union requests investigation into transcription privatization.

Some may recall that it was union pressure to prevent outsourcing services in British Columbia that led to much of the hysteria about the USA PATRIOT Act.

Wednesday, January 30, 2013

PIPEDA Finding: In joint investigation with Dutch DPA, Commissioner finds WhatsApp didn't comply with Canadian privacy laws

Earlier this week, the Privacy Commissioner of Canada released its report of findings against the popular, cross-platform instant messaging app. (Commissioner’s Findings - PIPEDA Report of Findings #2013-001: Investigation into the personal information handling practices of WhatsApp Inc.) It's a long and interesting read in and of itself, but it also notable as the first time that the Commissioner has participated in a join investigation with another country's data protection authority. It is also notable that she "named names" and that the investigation was undertaken on her own initiative, rather than as a response to complaints.

Here's the Commissioner's media release, which summarises the investigation:

WhatsApp’s violation of privacy law partly resolved after investigation by data protection authorities

Canadian and Dutch data privacy guardians release findings from investigation of popular mobile app

Ottawa, Canada and The Hague, The Netherlands, January 28, 2013 —The Office of the Privacy Commissioner of Canada (OPC) and the Dutch Data Protection Authority (College bescherming persoonsgegevens, (CBP)) today released their findings from a collaborative investigation into the handling of personal information by WhatsApp Inc., a California-based mobile app developer.

The coordinated investigation is a global first, as two national data protection authorities conducted their work together to examine the privacy practices of a company with hundreds of millions of customers worldwide. This marks a milestone in global privacy protection.

“Our Office is very proud to mark an important world-first along with our Dutch counterparts, especially in light of today’s increasingly online, mobile and borderless world,” said Jennifer Stoddart, Privacy Commissioner of Canada. “Our investigation has led to WhatsApp making and committing to make further changes in order to better protect users’ personal information.”

Jacob Kohnstamm, Chairman of the Dutch Data Protection Authority, adds: “But we are not completely satisfied yet. The investigation revealed that users of WhatsApp – apart from iPhone users who have iOS 6 software – do not have a choice to use the app without granting access to their entire address book. The address book contains phone numbers of both users and non-users. This lack of choice contravenes (Dutch and Canadian) privacy law. Both users and non-users should have control over their personal data and users must be able to freely decide what contact details they wish to share with WhatsApp.”

Key findings and outcomes

  • The investigation focused on WhatsApp’s popular mobile messaging platform, which allows users to send and receive instant messages over the Internet across various mobile platforms. While WhatsApp was found to be in contravention of Canadian and Dutch privacy laws, the organization has taken steps to implement many recommendations to make its product safer from a privacy standpoint. At this time however, outstanding issues remain to be fully addressed.
  • The investigation revealed that WhatsApp was violating certain internationally accepted privacy principles, mainly in relation to the retention, safeguard, and disclosure of personal data. For example:
  • In order to facilitate contact between application users, WhatsApp relies on a user’s address book to populate subscribers’ WhatsApp contacts list. Once users consent to the use of their address book, all phone numbers from the mobile device are transmitted to WhatsApp to assist in the identification of other WhatsApp users. Rather than deleting the mobile numbers of non-users, WhatsApp retains those numbers (in a hash form). This practice contravenes Canadian and Dutch privacy law which holds that information may only be retained for so long as it is required for the fulfilment of an identified purpose. Only iPhone users running iOS6 on their devices have the option of adding contacts manually rather than uploading the mobile address numbers of their address books to company servers automatically.
  • At the time the investigation began, messages sent using WhatsApp’s messenger service were unencrypted, leaving them prone to eavesdropping or interception, especially when sent through unprotected Wi-Fi networks. In September 2012, in partial response to our investigation, WhatsApp introduced encryption to its mobile messaging service.
  • Over the course of the investigation, it was found that WhatsApp was generating passwords for message exchanges using device information that can be relatively easily exposed. This created the risk that a third party may send and receive messages in the name of users without their knowledge. WhatsApp has since strengthened its authentication process in the latest version of its app, using a more secure randomly generated key instead of generating passwords from MAC (Media Acess Control) or IMEI (International Mobile Station Equipment Identity) numbers (which uniquely identify each device on a network) to generate passwords for device to application message exchanges. Anyone who has downloaded WhatsApp, whether they are active users or not, should update to the latest version to benefit from this security upgrade.

Next steps

The OPC and CBP have worked closely together, but have issued separate reports, respecting each country’s data protection law (Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) and the Dutch Data Protection Act (Wet bescherming persoonsgegevens (Wbp)). Following the issuance of their respective reports of findings, the OPC and CBP will pursue outstanding matters independently.

Following investigation, the Dutch Data Protection Act provides for a second phase in which the CBP will examine whether the breaches of law continue and will decide whether it will take further enforcement actions. The Dutch legal framework contains the possibility to enforce the Dutch privacy law by imposing sanctions.

Under Canada’s PIPEDA, the OPC will monitor the company’s progress in meeting commitments made in the course of investigation. In most cases, companies are cooperative in meeting their obligations, and WhatsApp has demonstrated a willingness to fully comply with the OPC’s recommendations. Unlike the CBP, the OPC does not have order making powers.

Monday, January 28, 2013

Happy data privacy day!

Today is international data privacy day. I am sure there'll be some interesting content posted through the day around the world to acknowledge the event and I'll try to post links as I'm able.

First, Google's top lawyer, David Drummond, has posted on the Official Google Blog greater detail about Google's approach to government requests for user data (Google’s approach to government requests for user data). In the post, he points to a new part of their groundbreaking Transparency Report that provides even more information on "User Data Requests". It's great that Twitter has followed suit with its own Transparency Report. More companies should do so.

And speaking of Twitter, follow the #DPD13 hashtag to see what others are saying about Data Privacy Day.

Facebook has launched "Ask our CPO", where users can submit questions to be answered by Chief Privacy Officer Erin Egan.
If you are in Halifax, you should also check out Dalhousie University's annual Data Privacy Day. It's being celebrated all afternoon on Wednesday, January 30, 2013 with a great lineup of speakers, including Jill Clayton, the Information and Privacy Commissioner of Alberta. I'll be your emcee for the event.

Saturday, January 26, 2013

Members of the privacy community demand transparency from Skype/Microsoft on disclosure of user information

A group of civil society organizations and privacy activists are calling upon Microsoft and Skype to be much more forthcoming about Skype's privacy practices, particularly those related to disclosures of user information to governments and law enforcement. The open letter to Skype calls for Microsoft to follow the lead of Google's and Twitter's transparency reports:

Open Letter to Skype

We call on Skype to release a regularly updated Transparency Report that includes:

  1. Quantitative data regarding the release of Skype user information to third parties, disaggregated by the country of origin of the request, including the number of requests made by governments, the type of data requested, the proportion of requests with which it complied — and the basis for rejecting those requests it does not comply with.
  2. Specific details of all user data Microsoft and Skype currently collects, and retention policies.
  3. Skype’s best understanding of what user data third-parties, including network providers or potential malicious attackers, may be able to intercept or retain.
  4. Documentation regarding the current operational relationship between Skype with TOM Online in China and other third-party licensed users of Skype technology, including Skype’s understanding of the surveillance and censorship capabilities that users may be subject to as a result of using these alternatives.
  5. Skype's interpretation of its responsibilities under the Communications Assistance for Law Enforcement Act (CALEA), its policies related to the disclosure of call metadata in response to subpoenas and National Security Letters (NSLs), and more generally, the policies and guidelines for employees followed when Skype receives and responds to requests for user data from law enforcement and intelligence agencies in the United States and elsewhere.

Friday, January 25, 2013

HRSDC to provide credit protection for those affected by missing hard drive

HRSDC has decided to do the right thing -- which it should have done one day one: provide credit protection services to the more than half a million individuals affected by the HRSDC missing hard drive fiasco. The department's release only refers to this breach, which leaves me wondering why they are not providing the same protection to people whose information was compromised with the missing USB thumb drive full of equally sensitive information.

I expect this really takes the wind out of the sails of the many class actions against the government.

Canada News Centre - Department to provide credit protection for clients with information on missing hard drive

Ottawa, Ontario, January 25, 2013 — The Department of Human Resources and Skills Development (HRSDC) is responding to the concerns of Canadians and providing credit protection at no cost to Canada Student Loans Program (CSLP) clients whose personal information was contained in a missing hard drive.

In addition to the strong measures that the Minister recently directed the Department to implement, the Department has contracted with Equifax, a credit bureau, to provide the affected clients with credit and identity protection services for a period of up to six years.

“While there is no evidence that information has been fraudulently accessed or used, I want to reassure Canadians that we are serious about protecting their personal information,” said Minister Finley. “That is why we will provide potentially affected individuals with credit protection at no cost, which will flag their credit files and help detect any potential compromise of their personal information.”

While HRSDC has no evidence that any of the information has been accessed or used for fraudulent purposes, those clients who could potentially have been affected by this incident have the choice to request the credit protection services, and can contact the HRSDC call centre at 1-866-885-1866 within North America. For calls from outside of North America, affected citizens can call 1-416-572-1113 and dial 0 to speak to an operator in order to reverse the charges. Callers with a hearing or speech impairment and who use a teletypewriter (TTY) can call at 1-800-263-5883.

To protect privacy, the Department is asking that affected individuals call to provide their consent for their information to be shared with Equifax. The process will be simple and efficient.

A hard drive containing personal information on approximately 583,000 individuals who were Canada Student Loans clients from 2000-2006 has been deemed missing from an HRSDC office in Gatineau, Quebec, although the search is ongoing.

Credit protection services will be arranged once clients make contact with the HRSDC call centre.

HRSDC continues to take all efforts to reassure Canadians that rigorous new protocols are in place to protect their data.

With respect to the last sentence, shouldn't they be reassuring Canadians that they are taking all efforts to protect data rather than taking all efforts to reassure Canadians?