Thursday, 26 February 2009

David's Damascene Conversion

Here at Data Grub we’ve so far held off from writing about ID cards, in part because this long-running saga has been so comprehensively covered in most mainstream media.

But we couldn’t let the Rt Hon David Blunkett get away with Tuesday’s speech at, of all places, Essex University. Blunkett, the original panegyrist of ID cards in this country, used his speech in part to propose scrapping compulsory ID cards.

So, what prompted David’s Damascene conversion, especially given that he’s often expatiated on the benefits of ID cards in his News of the World column and was at one point trousering a decent sum as adviser to Entrust, a company interested in bidding to run the UK card scheme?

Well, let’s not get ahead of ourselves. Blunkett went on to recommend that all UK citizens be required to have a fancy biometric passport which is, in effect, an ID card with a handy notebook attached for shopping lists. (Let’s be honest, when was the last time Bermondsey Bob needed a visa?)

Blunkett proposes that ID cards be voluntary but that biometric passports – which contain exactly the same information and will be linked to exactly the same database – will be compulsory. That way, the government can spin ID cards as a handy “mini-passport” that fits snugly into your wallet.

But even if compulsory passports are merely ID cards in disguise, one wonders what his rational is for jumping horses now, especially given that the current Home Secretary is still keen on the cards. Could it be that he wants the law on the statute books before the Tories’ inevitable election in 2010?

Blunkett and his successors have been trying to get make ID cards mandatory for donkeys’ years, but couldn’t do so until a large proportion of the population started carrying them voluntarily.

That’s clearly not going to happen in the next 12 months; but plenty of people have passports – make them compulsory and you’ve got your ID database system sorted.

Of course, all this completely ignores the question of whether ID cards might not, in fact, be quite a Good Thing after all. In spite of the government’s claims that they will prevent benefit fraud and halt terrorists in their tracks, Data Grub remains to be convinced of their utility.

Should Jacqui Smith decide to take Blunkett’s advice by making passports compulsory, it’ll be interesting to see if she employs the traditional ID card arguments (fraud, terrorism) or if Labour spins it some other way.

Watch this space.

Tuesday, 10 February 2009

Clayton makes a suggestion

Enough has been written about the House of Lords' report into surveillance in Britain, so today we'll be returning to Microsoft's latest version of Internet Explorer.

We've written previously about IE8's notorious InPrivate function, the sole purpose of which is to keep the wife from knowing about the surprise holiday / present you've bought for her online. According to Microsoft, anyway. Let's face it, they weren't going to dub the function "PornCloaking+" were they?

But still, there's nothing inherently evil about InPrivate.

What does cause concern is IE8's "Suggested Sites" feature, which allows users (in Microsoft's words) to "discover websites you might like based on sites you've visited". By activating the service in your browser, you consent to send various data about your browsing activity to Microsoft. This could include the URLs of visited sites, search terms and form data, as well as information that could potentially identify individuals, such as a user's IP address.

It's the classic trade-off: you agree to give up personal data in return for a service. But since users are fully aware of what data they'll be giving up and are able to give their informed consent to the service, this shouldn't present a privacy problem, should it?

Unfortunately for Microsoft, Suggested Sites has attracted criticism from the esteemed Richard Clayton, the Bill Bryson-lookalike and doyen of Internet privacy campaigners.

Dr Clayton says Microsoft must be clearer about explaining the risks, as well as the potential benefits of the service. He points out that full URL sharing via Suggested Sites poses a privacy and security risk and in particular warns that Microsoft should avoid sharing data submitted by surfers with other users of the service.

The risks hinge upon the fact that Microsoft will get the full URL of the site you visit. In some cases, this is essential - knowing that you visited blogger.com ain't going to help Steve Ballmer to suggest sites, but a visit to blogger.com/animals-do-the-funniest-things will help him to point you in the direction of some cutesy squirrel pics.

But sometimes, a full URL may hold clues to your identity, give permissions to others to access the site, or compromise your privacy or security in some other manner, says Clayton.

It's not so much that a Microsoft employee might one day go rogue and start stealing these sensitive URLs; it's the possibility that Microsoft hands the URL to someone with similar tastes and these users visit the exact places that you go to. "Suddenly all that "security through obscurity", the pious hope that no one could possibly guess that URL, goes up in
smoke," says Clayton.

Dr Clayton is a Cambridge academic and an eminently sensible, if somewhat cautious, voice in a debate which is all too often conducted by shrill, ignorant or ill-informed comentators.

Clayton doesn't want to score cheap points by gratuitously slating Microsoft - he merely points out that they could do better, by minimising the data transfer, and only obtaining longer URLs for the sites, like blogger.com, where it actually matters.

In the meantime, they should honest and transparent about the potential risks.

But Clayton's comments do have a silver lining for Microsoft: he points out that selecting the InPrivate mode automatically disables Suggested Sites, even if users have opted in. So, at least they can claim another alternative use for Pr0n-Mode...

Thursday, 29 January 2009

A day for quiet reflection

Yesterday was European Data Protection Day; this blog held a one day's silence as a gesture of respect to the millions of pieces of personal and sensitive data that have been lost in the last year.

Across the continent people gathered in their hundreds of thousands, coming together in their workplaces, in their communities, in the fields, in the hills and in the streets, to mark this most solemn and momentous day of data.

I need not tell you what an emotional day it was for us all.

Some of us may have brushed aside manly tears as we reflected on the 182 per cent rise in card cloning and phishing in the second quarter of 2008 compared with the same period in 2007; others may have stifled their sobs over the $2.8bn cost of phishing attacks; still more wept -openly and without shame - for the 44 per cent of small businesses that have fallen victims to identity fraud through phishing, internet scams and data theft.

But all were united in their fervent hope that 2009 finally marks the year when the UK's government pulls its bloody finger out and puts a stop to departments' haemorrhaging of our personal and sensitive data.

Fat chance...

Friday, 23 January 2009

A load of nonce-sense

If the first law of marketing is that sex sells, the first rule of tabloid journalism is that paedos shift papers.

Things may have quietened down a bit since the 2000 moral panic, when the News of the World whipped up a hysterical mob of mouth-breathing simpletons into an orgy of vigilante violence, but tabloid editors still know that their barely-literate readers love a good “hate” almost as much as a new Lizzy Duke sovereign ring.

So it’s no surprise to see yet another paedo story in today’s Sun, with the baffling headline: “Internet pervert charges rap”. In a nutshell, the story concerns comments made by the chief executive of the Child Exploitation and Online Protection (CEOP) Centre which "slammed" (criticised) Internet Services Providers (ISPs) for charging child abuse investigators to access their data.

The way that the Sun spins it, cynical ISPs are making an easy profit from the authorities hunting down Britain's biggest nonces. Naturally, the Sun is sympathetic to CEOP’s chief executive, Jim Gamble, who believes that ISPs should waive these charges in the public interest.

Balance has never been the Sun’s strongest suit. If it were, they would have pointed out that under the Regulation of Investigatory Powers Act (RIPA) ISPs are entitled to charge the police for reasonable costs for data retrieval and that in the last four years, the Government has paid ISPs and telcos £19m for its agencies’ growing demands for access to communications data. This information was obviously deemed by the Sun to be of no interest to its audience, even to its more intellectual readers who don’t need to use their index fingers to read a newspaper.

Interestingly, CEOP’s share of this £19m amounts to around £170,000 – less than one per cent of the total paid to ISPs. With CEOP having made just shy of 10,000 requests, the average cost of each request works out at less than £18.

Why, then, is the Sun focused purely on paedophile investigators, when all regular police forces and government agencies are charged, fairly and under UK law, for using ISPs’ time and resources?

As Malcolm Hutty, policy chief at the London Internet Exchange (Linx) points out, "Regular police forces investigate extremely serious crimes using communications data, including murder, rape and kidnapping, and they believe they are better served by cost recovery. We don't believe that the situation becomes different for child abuse cases merely because they are investigated by a specialist national unit."

But here we come to the second law of tabloid journalism: never let the facts get in the way of a good story.

Friday, 5 December 2008

The DNA of the UK Constitution

The European Union really makes my blood boil. If they’re not telling us what shape our bananas should be, they’re ordering our grocers to sell potatoes by the metre. Now, in the latest piece of politically correct European legislation, convicted paedophiles will be allowed to keep a pale 8 year old boy in their cells, after the European Court of Justice ruled that this was a fundamental “Yuman Rite”.* You couldn’t make it up. We’re literally going to hell in a handcart.

Or so you’d believe if you had access to no other media than the Daily Mail. But even readers of what Alan Partridge described as “arguably the best newspaper in the world” surely can’t complain about a recent judgement from the European Court of Human Rights (ECHR) which ruled that it is illegal to retain DNA profiles and fingerprints of people who have never been convicted of a crime.

The case was brought by two men from Sheffield whose DNA was taken after they were arrested on two separate and unrelated charges; one case involving alleged harassment was dropped, while the other man was acquitted of attempted robbery. Yet in spite of their innocence, these two men’s DNA and prints are still on a national criminal database, along with 570,000 other profiles of innocent individuals (some sources, notably today’s Guardian, say 850,000).

In reaction to the ruling the Home Secretary, Jacqui Smith, said that while she was “disappointed” (shouldn’t that be “disappointing”? Ed.), the existing law would remain in place “while we carefully consider the judgement.”

Well Jacqui, consider this. Presumption of innocence is an inseparable part of this country’s DNA, stretching back at least to Magna Carta. The principle of ei incumbit probatio qui dicit, non qui negat (that the burden of proof rests on whom asserts and not on whom denies, for those of you with a state education) is a fundamental foundation of our entire legal system which, in spite of frequent criticisms, remains one of the best in the world.

Ms Smith argues that DNA and fingerprinting is vital in the fight against crime, and claims that it provides the police with more than 3,500 matches a month. But Jacqui, we’re going to let you into a little secret. You know that statue of Justice on top of the Old Bailey? What’s that she’s holding in her left hand? That’s right – scales! And do you know what that represents, Jacqui?
Yes, it’s balance! And that’s what justice is all about – balance.

Taking the Home Secretary’s comments at face value, we should take the prints and DNA of every British child at birth; then we’d have a nice big database of everyone’s details. But that wouldn’t play very well with the public, would it, so how about taking young people’s DNA the moment they turn 16 – what could be objectionable about that?

Merely the fact that it criminalises the innocent and robs us of a fundamental principle of our centuries-old legal system.

The EU can often be a ponderous, calciferous and obtuse organisation, but we should applaud it when it makes the right decisions. Well done.

* Probably.
Well, actually you could.

Thursday, 20 November 2008

Gut feeling

In spite of our previous post about the NHS, this blog is concerned primarily with data in general, and the impact of technology on personal information in particular.

So, at the risk of appearing to stray off topic, we’ll start today with Gordon Brown’s plan to liberalise the UK’s rules on organ donation. The prime minister wants everyone in the UK to be automatically included in the organ donor register under a system of “presumed consent”. Anyone who objects to having their kidneys re-used after their death would have to opt out of the system.

The thorny issue of organ donation provokes visceral (sorry) reactions in most, if not all, of the population: some see it as inherently selfish not to let others use your lights after you’re dead; others see it as yet another example of the creeping nanny state robbing citizens of jurisdiction over their own bodies.

There are, of course, powerful arguments both for and against presumed consent, and it’s beyond the remit of this blog either to defend or denounce Gordon’s plan.

But the principle of consent, and specifically the opt-in / opt-out debate, sits at the very heart of the continuing debate about the protection of our personal data, especially on the web.

Should services that use our personal data be opt-in or opt-out? Most people would instantly and decisively declare that any Internet service which collects, processes, uses or stores our personal data should naturally be opt-in.

We strongly disagree.

Regular readers will know that this blog tries to champion people’s right to privacy, whether online of offline, so there might be some who are surprised that we feel so strongly against the opt-in model. After all, shouldn’t we have to give our express permission, based on thorough information, before allowing others access to our private lives?

Ah, but indeed; and therein lies the problem.

Every time we tick the checkbox accepting terms and conditions – be it for a website, a new online service, or to set up an email account – we are giving our consent to everything in the small print.

When was the last time you read through a website’s Ts&Cs? In fact, have you ever done so? Do you know what you consented to when you signed up to watch YouTube or set up a Google Mail account? No, but you checked the box without thinking, just because you were impatient to get on with it.

And that’s where the danger of opt-in lies. Irresponsible sites – unlike YouTube and Google Mail – can use the opt-in mechanism to obtain people’s explicit consent for any number of nefarious activities by slipping new services into their terms and conditions, knowing that the vast majority of people will blithely tick the box without reading them.

Much better, then, to obtained people’s informed consent before they sign up – let them know exactly what they’re consenting to by having an unavoidable notice, explaining any changes to service, on the log-in page.

No reasonable person can argue that it should be easy as possible for people to see what they’re signing up to; yet most campaigners on this issue seem still to be in thrall to the sanctity of opt-in, which makes it so easy for people to bury nasty surprises in the Ts&Cs.

This visibility, this informing of stakeholders, is what’s lacking from the prime minister’s plans for presumed consent. While presumed consent is fair to the educated, literate and informed, it ignores the much greater majority of people who are not au courant and thus are in no position to give informed consent to organ donation.

Monday, 10 November 2008

Two cheers for the NHS

Of all the categories of sensitive data, it is information about our health and our medical histories that is perhaps the most personal and private.

For example, you wouldn’t want a stranger – or worse, a colleague – knowing that you’re being prescribed Anusol Ultra for your chalfonts, would you? Nor would you want your boss to know about the methadone prescription, or your mother to know about your latest suicide attempt. Unless, of course, it was a cry for help.

But even if it contains nothing as dramatic as an overdose, we tend to guard our medical history very jealously.

So it may come as a shock to learn that not only has the NHS amassed a central database of around one billion confidential records of patient visits to hospital, it is routinely sending some of these records to an academic organisation outside the NHS. These records contain personally identifiable information, such as postcodes and NHS numbers, as well as medical information, including diagnoses and any treatment given.

Now, a certain breed of querulous privacy advocate will start whining the moment they hear the words “giant database” in conjunction with “confidential data”. Not so data grub: we understand that there are often the very best reasons for aggregating personal data, as long as stringent measures are in place to ensure absolute confidentiality.

In this case, the aim is to use this vast resource of information to improve the NHS’s service and treatment outcomes, which I think we can agree is a Good Thing.

The other good news is that both the NHS and the academic organisation that uses this data, the inanely-titled Dr Foster Unit, seem to have taken decent precautions to protect patients. All data is held on encrypted discs and is sent by secure courier, which is a pretty good start. Then, at the Dr Foster Unit, the data is kept in secure offices, on disc-less workstations which have no link to the Internet.

While this compares pretty favourably with the cavalier approach towards data security shown by other public sector bodies, among them the Ministry of Justice, the MoD and the Department for Work and Pensions, it’s certainly far from perfect.

Our main gripe is that personally identifiable information (PII) is contained within the data that’s being sent out of the NHS. While PII such as postcodes may be vital for making distinctions between different areas of a town or the country, surely the NHS should secure people’s informed consent if they are to use their data in this way?

So, two cheers for the NHS and the Dr Foster Unit for at least trying to apply best practice to the use of sensitive data. But, as we asked at the beginning, why should anyone other than one’s doctor be able to look at your confidential medical history, even if it’s just some academic at Imperial College?

Now, if they anonymised this PII irreversibly, ensuring that records cannot be traced to an individual, while at the same time remaining useful to the bean counters (all perfectly possible with today’s technology), well – that would be just what the doctor ordered.