Showing posts with label privacy. Show all posts
Showing posts with label privacy. Show all posts

Friday, 7 November 2014

How and why Australian Customs shares information

Isobel O'Brien

Have you ever wondered whether your identity is being tracked when you go through Customs at an airport?  There is no doubt that your personal information from your passport is recorded.  Even your ‘biometric identifiers’, like fingerprints, are collected.  But how much do you know about how your personal details are stored and shared by Customs beyond your control? 

Data sharing for national security purposes

The Australian Customs and Border Protection Service (‘Customs’) collaborates with governmental agencies, both nationally and internationally, by sharing the information it collects to “detect and deter unlawful movement of goods and people across the border.”

At the national level, such cross-agency data sharing unifies resources and centralises national security efforts, which enables greater accuracy in identifying potential security threats.  Analysis of information from multiple sources, including Customs, allows analysts to track peoples’ behavioural patterns and communications, as well as facilitating the identification of non-intuitive relationships between groups and individuals.  Identification of such trends aids in anticipating potential attacks, foreign interference and organised crime.

National agencies currently participating in information sharing agreements with Customs include the Australian Federal Police, Department of Immigration and Border Protection, Department of Defence, Australian Security Intelligence Organisation, Australian Security Intelligence Service, Department of Foreign Affairs and Trade, and the Department of Agriculture, Fisheries and Forestry.

Cooperative data agreements 

Australian Customs has data sharing partnership with the AFP, the New South Wales, Victorian and Tasmanian police, Australian Transaction and Reports and Analysis Centre (AUSTRAC) and the Australian Crime Commission, with a focus on preventing drug importation.  Customs often works particularly closely with the AFP and has developed a Joint Organised Crime Group (JOCG).  ‘Operation Inca’ is a specific example of such a partnership in 2007.  This operation targeted importations of the drug MDMA and led to the dismantling of a purported international drug ring, with 30 charges laid in Australia alone.  The partnership between Customs and law enforcement agencies at the state, national and international level enabled the sharing of information about the smuggling of cocaine in shipping containers, which had been gathered from surveillance data in ten different countries.  This led to the identification and arrest of the criminal ‘masterminds’ of the drug ring, as well as the smaller players. 

Customs also has a role in maritime security, protecting sovereign territories and preventing illegal activities in the Southern Ocean.  A current operation is the targeting of ‘illegal, unregulated and unreported fishing’, which widely affects ‘domestic, regional and international stakeholders’.  Illegal fishing is disrupted using measures such as the RP0A-IUU network, by which fishing vessels engaging in illegal activity are barred from accessing regional ports.  This network involves sharing of information with partner agencies, including the Department of Defence, law enforcement agencies and the Department of Foreign Affairs and Trade who work closely on collaborative initiatives combating border threats and illegal maritime activities. 

Biometrical and biographical data, immigration status and travel history will soon be shared and stored in the chips in e-passports in Australia.  At international airports and seaports, Australian Customs is already able to collect passengers’ biometric information.  This data may include fingerprints, facial recognition imaging or iris scans, and is stored in the Automated Biometric Identification System database.  Prospective laws foreshadowed in the ‘Foreign Fighters’ bill indicate that Customs would not only be able to store such information for its own purposes, but also share it with an international database of biometric information for unspecified national security purposes.  The biometric data collected at borders will be passed to the AFP and national security agencies to pre-emptively assess passengers’ risk status prior to their arrival in Australia, by matching passengers’ data to international databases.  Funding is currently being directed to developing secure international databases with partner countries to target identity fraud. 

International examples of large scale data exchange illustrate the potential for future expansion of Australian Customs’ data sharing capabilities, such as through direct connections with integrated global databases.  In the United States, biometrics databases hold millions of entries as part of the US-VISIT program and store the information of every international traveller within the US and those seeking to work, study or live in the country.  Such biometric databases are shared with over 77 foreign governments, including Australia, through collaborative data agreements.  The US also collects biometric data with private bodies, such as Facebook, for national security purposes.  Facebook’s data is mined for its vast collection of uploaded photographs and the site’s facial recognition software, which identifies individuals by matching faces to ‘tagged’ photographs.  This data enables significant accuracy in identification of individuals, as accounts are frequently linked to users’ real names.  The US further demonstrates the capacity for efficient data sharing between state and federal government bodies.  In response to the terrorist attacks in 2001, the federal US government reformed its predominantly siloed storage structure of biometric data to facilitate sharing between agencies through interoperable databases. 

Further issues regarding information sharing

The collection and sharing of information by agencies such as Customs poses many further issues for potential investigation.  It is useful to situate Customs’ data sharing activity within the broader context of resource and statutory limitations, which reduce efficiency and raise privacy concerns.  Lack of adequate funding and training can pose processing difficulties to individual agencies, which may lack the capacity to manage the sheer size and variety of information collected.  Further, when data is stored in multiple different ‘siloed’ systems, efficient data sharing is impeded by lack of interoperability and consistency between agencies.  Inadequate legislative privacy protections in Australia should also be flagged as an area of concern regarding the greater capacity of Customs and other agencies to share individuals’ private information.  Already, the small protections that do exist controlling information collection, such as the bar on the federal government from matching data in their possession to peoples’ tax file numbers, is being circumvented, as much of the information obtained by Australian governmental bodies is purchased from private organisations.  Such issues leave extensive scope for further investigation into the area of data sharing.

Wednesday, 11 June 2014

Big Data: The development of super powers?

Daniel Cater

The new millennium has witnessed a revolution in information technology with which society is only just beginning to grapple. Exponential increases in computing power have made it feasible to gather and process information in volumes previously contemplated only in science fiction. The use of super processors and machine learning algorithms is commonly referred to as “Big Data” and its hunger is well-fed by the gargantuan information pool that is the internet.

Increasingly, experts in computing, economic, marketing, medical and security fields are experimenting with the potential of data mining and Big Data. Meanwhile, the wider community and legislators appear to be struggling to understand this continuously evolving digital capability and its policy implications.

Defining “Big Data”

Despite its popularity, the term “Big Data” does not have any firm or universal definition. Broadly, it is the collection of massive quantities of information combined with the potential to process that information to search for patterns and correlative links. Big Data values quantity over quality - it accepts non-systematic errors and irrelevance in favour of volume. In fact, pre-determined relevance has little meaning to Big Data which is primarily concerned with patterns, however random, and the correlations that can be drawn from them. It is this nebulous and undefinable reach of Big Data conclusions that invokes the imagination.       

The evolution of a Super Power?


In the new Captain America film, one of pulp comic’s most iconic heroes, clashes with the machinations of evil manipulators. The primary villain, Alexander Pierce, far from exhibiting supernatural powers, is simply an influential political figure whose tool of world domination is the very essence of Big Data conjecture. Using a computer algorithm, the ‘infinite’ resource of the internet and powerful satellite linked weapon platforms millions of potential threats to the nefarious organisation will be exterminated. In essence the Hydra organisation will exploit the demand for security in order to eliminate opposition to its own agenda of control and Big Data is a primary tool in doing so. This is the apocalyptic vision of Big Data - super processors running arcane threat prediction programs utilising the streams of personal information on the internet which arbitrarily label people as dangers for elimination. Big Data has become the super-power of the next generation villain.

Of course, Big Data is not being employed as a tool of instant world domination in the real world. However, its potential, if fully realised, will have profound impacts on our world. Big Data and the algorithms which utilise its input are still in a formative stage and its failures are as notable as its successes. Google spectacularly demonstrated Big Data potential with a Flu monitoring algorithm which accurately predicted the 2009 H1N1 epidemic; however their same disease modelling program has since disappointed. The Prism and Tempora security data mining programs have resulted in widespread protests by privacy advocates and the international community. Marketing agencies have utilised Big Data in targeting specific demographics and it has been discussed in personalised pricing schemes, where product prices are based on individual consumer capacity and demand. Clearly Big Data has arrived and is expanding in utility, capacity, scope and implication; but what does that really mean?

A change in paradigm

Privacy is identified as a fundamental right internationally (ICCPR Art 17) and has long been protected (at least up to a point) by the simple inability of anyone to utilise personal information on a massive scale due to both technological and financial limitations. Even with the vast data accessibility of the internet, the cost of both mass processing information and individually focussing data has prevented many applications. The development of Big Data processes has changed that irrevocably. From social media to online shopping, banking to communication, we constantly share most if not all of our critical and personal information. Private information given up for a specific purpose has now become an invaluable resource mined and utilised by the Big Data industry and an entire economy has developed centred around data. There is growing recognition that our privacy laws and regulations are woefully inadequate for this digital revolution.

Privacy, access, usage and data legislation must adapt to the Big Data world, otherwise the utility of Big Data will be either unrestrained or crippled by legal fetters. Big Data is transnational in nature and policy must reflect a global understanding and cooperation for a resource with global value, implications and reach. Legislation must be developed which places boundaries on what action can be taken on the basis of probabilities suggested by Big Data in order to maximise advantage but minimise the oppression of actions based on possibilities. While reforms have been proposed, and both the European Union and the United States have at least attempted to address Big Data concerns, the vast majority of law and proposed legislation is simply inadequate. If personal rights, social justice and trust in the online world are to be maintained, legislators, legal and computing experts must collaborate and address the implications of Big Data.

While Captain America and Hydra are characters from our imaginations, the implications of Big Data are not. The question we must ask ourselves is this: are we going to take responsibility for our future? Perhaps a 1940’s superhero can remind us that with great power comes great responsibility.

Image by JD Hancock under Creative Commons License.

Tuesday, 13 August 2013

Protecting privacy in the digital era

Tessa Meyrick

The arrival late last month of the new heir to the throne was unsurprisingly attended by a flurry of media interest in the UK and beyond, with reports of the royal birth apparently accounting for a staggering 5 per cent of online news content consumed globally on 22 July 2013. When the (yet-to-be-named) Prince George of Cambridge made his first media appearance the following day, every portal, page, RSS and Twitter feed continued to be jammed with details of the Prince's BMI, speculations as to his naming (commiserations to those who'd put their cash on 'James'), and even the Royal swaddle he left wrapped in. 

Somewhere among all this emerged concern (including from the media itself) over how the Royal parents are to construct some semblance of an ordinary life for the Little Prince once the natal storm has passed. In the UK Government's official response to the news of the birth, Lord Hill of Oareford, Leader of the House of Lords, shared with his peers a hope that the Prince (and his no doubt fatigued parents) be given some privacy. The media agreed, with one major UK newspaper at pains to stress that 'no one, and certainly not the media, would want to deny the Duke and Duchess some time alone with their baby son'.

With the UK Government's plan for a new press regulator (set in chain by the Leveson inquiry) put on the back-burner until the Australian spring, it's uncertain which body in the UK will be responsible for ensuring the media comes good on its commitment to honouring the Royals' privacy. In any case, it's also not entirely clear that it’s the conventional media that’s going to need to be held to account.

Prince George is the first future monarch to grow up in an era of social media and under the gaze of many-a-quick-fingered 'citizen journalist' in possession of a smart phone. Which is to say, Prince George's privacy (or lack of it) won't depend purely on the strength and structure of media regulation in the UK, but will also hang on the development of a freestanding right to privacy in that jurisdiction. For the record: there is no such right in the UK, and nor is there in Australia. But if 'the right to be let alone is indeed the beginning of all freedom', then the influence of Article 8 of the European Convention on Human Rights and the extension of the law in relation to breach of confidence to cover misuse of private information by the Court of Appeal actually puts the UK in comparatively good stead. 

In Australia, the idea that privacy is solely a media regulation issue continues to hold ground. This was helped along by the Federal Government's decision in March this year – expressly in the context of its ill-fated media reforms – to sideline the question of whether Australians should be able to sue for serious invasions of privacy. Concerned that earlier consultations on a privacy tort (the 28 month Australian Law Reform Commission inquiry finalised in 2008 and the Government's own consultations in 2011) showed little consensus on what such a right would look like, the Government has referred the issue to the ALRC for yet another inquiry. That inquiry, 'Protecting privacy in the digital era', kicked off in June. The final report, focusing specifically on the legal design of a statutory cause of action, is due to be delivered in June 2014. Whether that report stays with its earlier counterparts in the 'too hard' basket will remain to be seen.

This piece first appeared on the Allens intellectual property blog, Scintilla.

Friday, 24 August 2012

Living with our heads in the Cloud

Hadeel Al-Alosi

Technology has led to rapid advancements in our society.  While reading this, many of us will probably be scrolling through a Facebook page or flicking through an iPhone.  Much of the data we are accessing may well be stored in the Cloud.

At its broadest level, cloud computing is the provision of computing resources as a service over a network, usually, the Internet. Cloud computing services have been made available for a number of years, including by well-known organisations such as Google, Microsoft and Hotmail.  These services allow consumers to access data and applications without having to install or store these on their personal computers.

The personal cloud promises many benefits. It allows you to manage all of your PC and mobile devices, and to have every piece of data you need at your fingertips, so that you can share your information with friends, family and colleagues in an instant.

But before becoming over-excited by all the benefits that cloud computing promises to deliver, there are important issues to consider.

Theft and loss of data: should cloud service providers be bound by some minimum security standards that ensure personal information is not lost or stolen? Should service providers be able to limit their liability contractually for lost or stolen data? What if the service provider is forced to close down due to financial or legal problems, which causes customers to lose their data? Who should be responsible in having back-up and recovery processes in place?

Data location: the fact that data is stored by a cloud provider, which may be located overseas, means that individuals and businesses have less control over their data. Users should be questioning who is actually holding their data and where it is being located. With the growth in reliance by Australians on cloud computing services, it may be worth choosing a provider based in Australia. This would reduce risks in storing data with overseas providers, which may be in countries that have inadequate privacy laws or are prone to natural disasters.

Privacy issues: there are endless privacy issues raised by cloud computing, such as who will have access to your data and whether (and which) privacy laws will apply. Are there circumstances that justify the disclosure of data (for example, to aid law enforcement)? Also, what happens to data once a contract with a cloud service provider is terminated? For example, Google Docs states that it “permanently deletes” data from its system. However, it also warns that “residual copies of your files and other information may remain in our services for three weeks”.

Most individuals and some businesses overlook these important issues. As is often the case with e-commerce transactions, many people blindly click on the “I agree” button when signing up for services without reading the terms and conditions provided. We tend to think more about these issues when something goes wrong. For example, when someone's Facebook account has been hacked into by a revengeful ex-partner, or when precious data has been lost.

As to the future of cloud computing services, I think it is timely that we generate some solutions to these problems. Perhaps, somewhere over the rainbow, we can find solutions that allow us to reap the benefits of the cloud, while ensuring we are protected from all external threats.

So, what do you think? – is cloud computing a threat or an opportunity?

Monday, 16 April 2012

Can My Facebook Photos Negate My Good Fame and Character?

Dr Catherine Bond

Teachers of legal ethics are to some extent used to the unusual questions that arise in classes on procedures and policies for admission to practice as a solicitor or barrister. In many instances this class will be a student’s first exposure to what happens post-law school and the requirements that the student be both eligible to be admitted (having previously completed the requisite academic qualifications and practical legal training) and are suitable to be admitted, on the basis that he or she is a ‘fit and proper person’. A fit and proper person is defined to include a person of good fame and character, who is not insolvent, has not previously practised in Australia or overseas without a practising certificate, or who has not previously committed an offence. Perhaps understandably, when students become aware of these rules, closets full of skeletons past begin to open and nervous students begin to question whether this or that incident could have an impact on his or her admission to practise law.

Great emphasis has been placed in New South Wales and more generally on the act of disclosure: that an applicant disclose any prior or current behaviour that may negate their good fame and character, ranging in activities from receiving a transport fine to a finding of plagiarism while at university. The forms that potential solicitors must complete are geared towards this act of disclosure, containing a number of general conduct statements that, if one is not true about the applicant, requires the applicant to ‘strike out’ and disclose the circumstances as to why that statement may not be true. The consequences of a failure to disclose can often lead to a decision by the Legal Profession Admission Board to not admit an applicant or, if the failure to disclose is found following admission, to be struck off from legal practice.

In a recent class a discussion arose as to what impact the existence of photos on Facebook may have on an applicant’s good fame and character. The debate follows a recent flurry of reports in the media of employers asking for the username and password of potential employee’s Facebook accounts as part of a virtual ‘background check’. In turn, Facebook has advised its members not to disclose such information. The student’s question was therefore quite topical: if employers are interested in what is on a potential employee’s Facebook page, then surely the Legal Profession Admission Board might be, particularly given that many individuals have photos depicting events and other information available via that social networking site that may ultimately negate their ‘good fame and character’?

Public embarrassment from Facebook photos is not a new phenomenon; Australia’s ‘public figures’ have in the past had photos posted either by themselves or their ‘Facebook friends’ published in the media. In 2008 a number of provocative photos of Olympic gold medallist Stephanie Rice that appeared on Facebook were subsequently published in a number of Australia’s major newspapers, tarnishing both the public ‘golden girl’ image of Rice and also her then-boyfriend, fellow Olympic swimmer Eamon Sullivan. Rice’s subsequent 2010 experiences with Twitter, which culminated in a teary press conference where she publicly apologised for her offensive tweet, further indicate the damage that an over-exuberant use of social media can cause.

Yet it is becoming difficult to avoid social networking if students want to keep informed about events going on in law schools, universities and law firms, with an increasing number of public and private organisations either creating Facebook pages or Twitter feeds to notify interested parties of news, legal updates and events. In England the UK Supreme Court has an official Twitter feed where the release of decisions are posted, questions answered and job opportunities with the court listed. Indeed, it is likely that, with the greater proliferation of both Generation Y and the ‘digital generation’ into the workforce, this trend will both continue and grow. Thus, on the one hand, social networks are a valuable source of information for students, but on the other, they have become areas where students may not use these sites for their primary purpose – ‘networking’ and connecting with friends – for fear that their activities may be accessed by potential employers or ultimately affect admission to legal practice.

It appears that today’s students must find a balance between a fleeting moment that may have affected their ‘good fame and character’ and the permanent digital capture of that moment on Facebook. In any event, we may be moving towards a system where potential solicitors have to disclose what is on their Facebook pages.

Monday, 12 September 2011

The microchipping of people and the uberveillance trajectory

Associate Professor Katina Michael

First came i-mode and then the iBook. Next the iPod, iPhone and iPad. Is it only a matter of time before we see the iPlant suddenly make its debut onto the global market? This is a real possibility for your future: a subdermal microchip implant that will potentially give you ubiquitous connexity: always on, always with you, 24x7x365.

The term “uberveillance”, coined by MG Michael in 2005, is defined in the Macquarie Dictionary as an omnipresent electronic surveillance facilitated by technology that makes it possible to embed surveillance devices in the human body. In that same year, the Parliament of Australia’s Senate Standing Committee on Legal and Constitutional Affairs published: "The Real Big Brother: Inquiry into the Privacy Act 1988”. Chapter three on “emerging technologies” addresses the role that microchip implants in humans could play in the future.

The idea of implanting technology into people is not new. The first implantable cardiac pacemaker was created in 1958. Since then, we have seen the introduction of the cochlear implant to help the deaf to hear and the brain pacemaker to aid those suffering with epilepsy, Parkinson's disease, major depression and other diseases.

However, human implant technology is getting cheaper, easier to access and looks increasingly like it is going to be part of your everyday future life.

So-called “do-it-yourself implantees”, like Jonathan Oxer of Melbourne and Joe Wooller of Perth, have had implants inserted into their bodies using a short procedure and is similar to getting one’s cat or dog chipped.  Oxer modified his house so that his implant could be used to personalise settings in his home.  Wooller can open the doors to his house, car and motorbike with a swipe of his hand.

The microchip implant, most commonly a passive radio-frequency identification (RFID) tag, carries a unique pin that identifies the chip. How does this let you open a door? An antenna in close proximity triggers the RFID tag embedded in the body and an ID is transmitted to a reader, which grants access to the implantee (but may also grant access to a potential hacker).

Opening doors using a unique RFID tag is elementary when compared to the role that microchip implants play in brain pacemakers. But the potential for implanting citizens with microchip technology has been considered to be beneficial on several fronts. Proponents of microchipping people often state that implants would signal the end of credit card fraud, losing your keys, kidnapping, even a partial solution to reducing carbon emissions. The most popular argument is often connected to national security. This is despite the reality that RFID is the most insecure ID technology in the market. The loss of privacy in any of these or other contexts is an issue which needs to continually be addressed.

Microchips are set to bring new life to a whole gambit of control applications. It was only a few months ago that wearable GPS monitoring devices were embraced by the Queensland State Government for use by sufferers of mental illness and, later, sex offenders. Australian cricketers have been using body wearable technologies to record their match fitness levels and productivity since 2006. We are now talking about the mainstream commercialisation of such technology solutions, along with a movement from wearable to implantable technology. Microchips will provide us with the ability to locate, track and monitor people and provide data such as longitude and latitude coordinates of an individual down to a metre, as well as their speed, distance, time stamps, altitude, direction, temperature, heart rate, pulse rate and other physiological measures.

RFID implants for humans are now clearly on the political agenda. Recently, South Australia’s Police Commissioner Mal Hyde stated that there were quite a few different groups of people he’d like to see microchipped. And Sunshine Coast MP Peter Wellington was widely cited as saying that he would like to see child sex offenders microchipped.

The question is how long it will take for integrated solutions based on microchip implants to surface in everyday applications and how the law will deal with the continued rise of new and disruptive technologies which have the capacity to change just about everything. The problem is that, in many instances, legislation will offer few permanent or secure solutions, leaving the question open to the broad spectrum of ethics and debates involving difficult moral judgments.

Photo by ONT Design, made available by a Creative Common licence via Flickr.