Seattle Privacy Coalition https://seattleprivacy.org Individual privacy - Institutional transparency Fri, 23 Feb 2018 21:28:25 +0000 en-US hourly 1 https://wordpress.org/?v=4.9.4 Threat Modeling the Privacy of Seattle Residents https://seattleprivacy.org/threat-modeling-the-privacy-of-seattle-residents/ https://seattleprivacy.org/threat-modeling-the-privacy-of-seattle-residents/#respond Mon, 19 Feb 2018 17:01:56 +0000 https://seattleprivacy.org/?p=2539 Continue reading "Threat Modeling the Privacy of Seattle Residents"]]> [Update Feb 23: Updated spreadsheet based on initial feedback]

[Update, Feb 21: here’s the deck I used: web version, pptx deck.]

I’m pleased to say that we have some first results from our threat modeling for Seattle resident privacy project. In this post, I’m going to share those results, and look forward to what we might do next. (See A Privacy Threat Model for the People of Seattle and Introducing Threat Modeling For Seattlites for more background.)

This blog post provides an overview, and there’s a longer discussion in Seattle Resident Threat Model white paper (draft).

Overall, I’m happy to say that the effort has been a success, and opens up a set of possibilities.

  • Every participant learned about threats they hadn’t previously considered. This is surprising in and of itself: there are few better-educated sets of people than those willing to commit hours of their weekends to threat modeling privacy.
  • We have a new way to contextualize the decisions we might make, evidence that we can generate these in a reasonable amount of time, and an example of that form.
  • We learned about how long it would take (a few hours to generate a good list of threats, a few hours per category to understand defenses and tradeoffs), and how to accelerate that. (We spent a while getting really deep into threat scenarios in a way that didn’t help with the all-up models.)
  • We saw how deeply and complexly mobile phones and apps play into privacy.
  • We got to some surprising results about privacy in your commute.

Methodology

Results

What we can learn from this:

  • Walking and biking are the most privacy preserving commutes. Everything else generates long-term records of your movement. However, some electric bikes have anti-theft GPS built in, as do the new dockless rental bikes.
  • It’s easier to prevent camera tracking on a bike because a helmet is not as attention-grabbing as a mask. Bikes also limit “gait biometrics.”
  • Motorcycles have far less electronics and fewer radios than a car, but still carry license plates and may be tracked via road toll systems. There’s obviously complex tradeoffs involved in motorcycle commuting, but it wasn’t obvious to us going in that privacy could play in those tradeoffs.
  • Between Lyft/Uber and your own car, your own car is trackable in more ways, and more ways that tie to you.  Unless you’re worried about those companies, you’re better off with a taxi or carshare.  If you’re worried about Feds or local government, there are a lot of parties a government will subpoena, and so that’s neutral.  (Taxis vs app-driven: if you call a taxi, your pickup location/phone combo may be recorded.  If you hail it, then pay with a card, your dropoff location may be recorded.  If you hail and pay cash, then you’re more private than with an app.  Thanks to @internmike for teasing that out.)

We also looked at phones. There’s a set of radios, some of which (bluetooh, wifi) can be turned off with less impact on usability. The cellular network radios can only be turned off with a substantial loss of function. We also discussed differences in usability of turning off app access to location between various brands.

Next Steps

One of the things we did not do was a risk assessment for any particular vulnerable group, but we believe that the information we’ve gathered can support and accelerate such analysis. For example, we know that cell site location information can only be disabled by discarding a mobile phone or leaving it in airplane mode. We also know that DHS collected mobile phone information from DACA applicants . We have not attempted to analyze this or its implications, but we’d be happy to do so in partnership with organizations that have specific concerns.

Since we were exploring how we might do this, we have not yet produced a guide to doing it yourselves.

The Raw Data

The raw data is available under a creative-commons attribution license. Here it is as an Excel spreadsheet. (We use xlsx rather than CSV because we needed Excel’s “sheets” feature.) Here’s a version in Excel and a web view, exported HTM here.

]]>
https://seattleprivacy.org/threat-modeling-the-privacy-of-seattle-residents/feed/ 0
Securing my data for international travel https://seattleprivacy.org/securing-my-data-for-international-travel/ https://seattleprivacy.org/securing-my-data-for-international-travel/#comments Sat, 23 Dec 2017 17:25:49 +0000 https://seattleprivacy.org/?p=2582 Continue reading "Securing my data for international travel"]]> By Regus Patoff, Anonymous Person

I have a complicated international trip coming up, and I want to protect my private information from border officials. Abroad or in the US, border officials can and do abuse their discretionary power to interrogate travelers, seize electronic devices, demand passwords, and generally inquire into matters unrelated to border safety. This post summarizes my plan. Later I’ll let you know how it went.

 

I’m hard to find online

I started preparing by making my Twitter account anonymous and taking down my personal blog. Now I don’t pop up in Google, so I’m protected from a casual search on my name. It took a full year for my name to fade off of Google, so start this in advance if you want to do it.

I’m not a “target”

I am not important enough to need to worry about state security agencies, and this post isn’t for people who are. . I just want to provide zero information to border guards. All they need to know is that I’m not carrying weapons on a flight, and beyond that, in matters of my heart and mind, they can piss off. My border crossings double as resistance to the erosion of my legal and human rights.

I carry a lot of electronic equipment with me when I travel, though no more that what a typical business traveler might. Basically, a phone, a tablet, and a laptop, though no laptop on this trip . I’m leaving behind many computer services that I need to stay in touch with:

  • A computer server providing websites for myself and others, and also DNS. I need administrative access to that even when traveling.
  • Hidden Tor services that I host.
  • Other various backup services hosted by a major cloud services provider.
  • My personal email hosted by another cloud services provider.
  • A backup email provider, a big one, just in case.
  • My private cloud that I host, full of information that I like to have available all the time and on any device, but which I don’t want to trust to a vendor.

Devices I’m taking along

These are the devices I’ll be carrying:

  • An Android phone (cell and Wi-Fi connectivity, with an add-on SD-card for storage). Serves as a phone, of course, but also as a music player.
  • An Android tablet (Wi-Fi connectivity, with an add-on SD-card for storage). This, with an accessory keyboard and mouse, serves as a full-service computer substitute, an ebook reader, and a mapping+navigation device.

Why Android?

I know that iOS devices are regarded as more secure by the extremely careful and/or extremely threatened. I’m not an Android expert who can improvise my own iOS-equivalent security. However, I am not trying to defend myself against intelligence services at the border, I’m just trying to beat border guards. Stock Android with encryption will work. I prefer Android because I like to tinker, so that’s what I’m taking. Loyal iOS users reading this will have no trouble translating its suggestions into the language of their favorite mobile platform.

I’m also carrying a philosophy

Don’t be a hostage to your stuff. My travel devices are cheap and/or old enough to make losing them to government seizure acceptable. It’s the data that matters.

Sensitive data

My data protection strategy is to keep my sensitive data in the cloud where I can access it when it is safe to do so. My sensitive data in this case includes:

  • Contacts
  • Email
  • Calendar
  • Bookmarks
  • Browser history
  • Passwords
  • Cryptographic keys
  • Photographs

Backups

I’ll be keeping data of this sort in the cloud (private or public) and accessing them through secure connections (HTTPS, SSH) or by secure synchronization services (Android sync, Google Drive, Mozilla sync). I also store configuration profiles for important applications (for example, email) so I don’t have to remember them. I have made several layers of backups for everything, in several locations, including my private cloud and a virtual machine I pay a cloud services provider for. If the sync services fail or I lose my devices, I’ll be able to access my important data from any Internet-connected computer.

Passwords

Passwords are a problem. I use around one hundred strong, random passwords for various websites and services, which means I have to use a password manager to keep track of them. I don’t care much for the hosted password management services, so I run my own and sync its database through my private cloud. My Android devices automatically sync up with my password database.

However, to be truly independent of particular devices and safe from government seizure, I need to carry a few strong but unforgettable passwords in my head. I use one to access my private cloud, where everything important is stored. I have another memorized password for my password database, which is itself encrypted, and one more for my backup email account. In general, the correct-battery-horse-staple (https://xkcd.com/936/) method of password building is the way to go for these master, memorized passwords.

Non-sensitive data

In addition to the sensitive data, I’ll be carrying some relatively bulky, non-sensitive stuff:

  • Music files
  • Map files
  • Ebooks

I’ll keep this data on the external MicroSD cards in each device, unencrypted. I’ll avoid carrying anything controversial. These things are already backed up at home, but are too bulky to sync if I lose them. Worst case scenario, I can’t listen to LCD Soundsystem on the funicular. It’s something of a technical trick, though, to keep sensitive data from being saved to those cards by the ever-helpful Android operating system.

My pilot protocol

Putting all this together, here is my planned device security protocol for before and after entering a country:

  1. Before: Factory reset the devices. Do not begin device setup.[Non-random thought: Will border officials be annoyed to find a factory-reset device? I imagine the Israelis would be annoyed, or the authorities in Urumqi. An alternative would be to set up a false/alternative identity on the device, which would take planning and time. A secondary and very uninteresting Google account would do the trick. However, DO NOT GET CAUGHT LYING TO THE AUTHORITIES. When I was living in {oppressive regime}, I planned my lies very carefully and kept them effectively unfalsifiable.]
  2. After border crossing, set up the devices using Google account credentials.
  3. Choose option to restore from a cloud backup, including apps.
  4. Finish setup, and when prompted, have the device restore all apps.
  5. Retrieve email configuration from the cloud.
  6. Set up SSH keys.
  7. Re-sync browser bookmarks.
  8. Rebuild the home screen, which in my experience is not restored.

Coming soon: How this worked in a “liberal democracy” with draconian security measures, and in an “undemocratic regime” with the same.

 

]]>
https://seattleprivacy.org/securing-my-data-for-international-travel/feed/ 1
TA3M October 16, 6pm-8pm UW CMU 104 https://seattleprivacy.org/ta3m-october-16-6pm-8pm-uw-cmu-104/ https://seattleprivacy.org/ta3m-october-16-6pm-8pm-uw-cmu-104/#respond Sun, 15 Oct 2017 03:15:06 +0000 https://seattleprivacy.org/?p=2571 Continue reading "TA3M October 16, 6pm-8pm UW CMU 104"]]> Greetings!

Techno-Activism Third Mondays (TA3M) is an informal meetup designed to connect software creators and activists who are interested in censorship, surveillance, and open technology. Currently, TA3M are held in various cities throughout the world, with many more launching in the near future. In Seattle, thanks to a special donor, there will be free pizza!

When: Monday, October 16, 6-8pm
Where: University of Washington Seattle Communications Building CMU 104.

We are looking forward to a great talk from Michelangelo van Dam about the new privacy rights and international effects of the General Data Protection Regulation in the EU. Michelangelo is a senior software engineer, co-founder and CEO of In2It, community leader at PHP Benelux, and a coach with Coder Dojo.

Join the email list:
https://lists.ghserv.net/mailman/listinfo/ta3m-seattle

We’re on Twitter!

To best support the global TA3M meetup, please tweet using the #TA3M hashtag.

@TA3Mseattle
@SeattlePrivacy
@TechnoActivism

]]>
https://seattleprivacy.org/ta3m-october-16-6pm-8pm-uw-cmu-104/feed/ 0
TA3M Seattle Monday July 17 2017 https://seattleprivacy.org/ta3m-seattle-july-2017/ https://seattleprivacy.org/ta3m-seattle-july-2017/#comments Tue, 11 Jul 2017 00:32:43 +0000 https://seattleprivacy.org/?p=2526 Continue reading "TA3M Seattle Monday July 17 2017"]]> Greetings!

Techno-Activism Third Mondays (TA3M) is an informal meetup designed to connect software creators and activists who are interested in censorship, surveillance, and open technology. Currently, TA3M are held in various cities throughout the world, with many more launching in the near future. In Seattle, thanks to a special donor, there will be free pizza!

When: Monday, July 17, 2017, 6:30 – 9:00 PM
Where: Tor Office, Pioneer, Square https://goo.gl/maps/aun6E4r4s5E2 80 S. Washington st. Suite 203 Seattle
WA, 98194


Pump.io by AJ (7pm)

Pump.io is a promising project to create a federated social network – think email, where you can have multiple providers that all work together, but for social networking. It stagnated for a while, but the project has recently completed the transfer of governance and code maintenance to the community. This presentation will talk about pump.io’s history (right up to its newly-created community governance), its API, and why it’s pretty freakin’ neat. We’ll end with the work that’s gone out the door in recent releases, the work that remains, and how you can (should?) get involved. Attendees will walk out with an understanding of the historical context behind pump.io, an understanding of how the software works on a technical level, and how it fits into wider social web efforts. No prior knowledge necessary, although a basic familiarity with JSON and HTTP will help.

AJ is a core developer of the Pump.io reference implementation.


Lightning Talks (8pm)

Sign up to give a Lightning Talks by emailing the list. Feel free ask questions of the list too!

Talks:

  • Paul English – Why & How to use 2 Factor Authentication

 


Join the email list!

https://lists.ghserv.net/mailman/listinfo/ta3m-seattle


We’re on Twitter!

To best support the global TA3M meetup, please tweet using the #TA3M hashtag.

@TA3Mseattle
@SeattlePrivacy
@TechnoActivism

]]>
https://seattleprivacy.org/ta3m-seattle-july-2017/feed/ 2
Introducing Threat Modeling for Seattlites https://seattleprivacy.org/introducing-threat-modeling-for-seattlites/ https://seattleprivacy.org/introducing-threat-modeling-for-seattlites/#respond Mon, 10 Jul 2017 02:16:58 +0000 https://seattleprivacy.org/?p=2492 Continue reading "Introducing Threat Modeling for Seattlites"]]> In May, one of our board members, Adam Shostack, author of Threat Modeling, Designing for Security, issued a challenge to the Seattle Privacy Coalition discussion list:

“I would like to ask Seattle Privacy to think about privacy more holistically: What threats exist? How are we, as residents and citizens, tracked, monitored, or analyzed throughout the day?”

Adam said something I think we all know: there are so many ways that data is gathered on any one of us at any given time, it’s hard for us to wrap our heads around it, much less muster defenses.

He asked us to take the tool well-known to technical experts, threat modeling, and apply it to ourselves and our fellow Seattle residents. Another board member,  Number Six, rose to the challenge, and “Threat modeling for Seattlites” was underway.

Four questions to start with

At our first meeting at Delridge Public Library, Adam got us started by making a chart on a whiteboard with the following columns across the top. Then we proceeded through an imaginary day:

  • What are you doing? (The task you want to accomplish, and what information is involved.)
  • What can go wrong? (How might your personal information be gathered in ways that are bad.)
  • What are your possible defenses? (Are there alternatives you can use to avoid the risk?)
  • What are the costs of your alternatives?

We brainstormed “A Day in the Life of a Seattlite” for three hours. The result was an epic spreadsheet.

 

 

 

 

 

 

 

 

Somewhat absurdly, with our fitbits, phone-based alarm clocks, CPAP machines, instructions to Alexa, Siri, Google Home, or whoever, and our social media time, it took us an hour to list the potentially gathered data before we would even leave our imaginary homes to start the day.

Define “required”

As we worked through the day, encountering various aspects of the internet of things both private and publicly owned, it emerged that we needed another column. Is the task, and the corresponding use of the technology, required or optional?

For example, it’s easy enough to use a cheap old-fashioned non-connected scale to weigh yourself in the morning, instead of an internet-connected device. Or is it? What if your health insurance requires that you transmit this data to keep your policy? Or, what if you can get a lower premium if you opt to transmit the information?

This means that we need to characterize the data collection: is it easy to avoid? Required by law? Easy to avoid if you’re rich?  (In particular, we don’t want to fall into the trap of treating ‘opt-in/opt-out’ as if it’s a
reasonable and nuanced thing.)

It also became clear that who was collecting data needed categorization. We settled with three categories for starters:

  • Government
  • Employer
  • Third-party

A few surprises

I learned a few tidbits during this process that were new to me, although I’ve been tracking privacy issues for a few years now. For example, I learned that some types of car insurance offer usage- or behavior-based policies, in which your driving habits, such as rate of acceleration or speed relative to speed limit, are captured and evaluated to adjust the cost of your policy. Perhaps this is also already happening, I don’t know, but one person had read recently that insurers were considering sending along tips to drivers about how they might improve their driving (and thus lower their premiums).

I also learned that it is already not-uncommon for insurers to insist upon the use of connected CPAP machines or blood sugar monitors, to ensure that the insured is actually using the care paid for. Doctors can also remotely check the status of these devices.

Building out the model

In our second meeting, in July, we began thinking about what we needed to do next. Our data set was fairly messed up, because we hadn’t made any effort to normalize it while brainstorming, and we knew we’d captured only those tasks and data-gathering technologies that those of us in the room knew about. We knew we needed to run our data by many more people before we could consider it complete.

We also started thinking about ways to communicate the information we were gathering. We thought about ways to graph “effort against hurdles,” such as:

  • x,y, where x is task and y is Legal Requirement | Benefit | Cost to Avoid | Effort
  • Pie charts, where size represents total effort.
  • Stoplight charts that could indicate relative risk, and allow people to drill into details if they want them.

We concluded that we definitely wanted to make our data free for others to use and easily available to incorporate into presentations of all kinds.

(Here is a downloadable version of our first very rough cut at the data. Much more to do, and we’ll set it up for proper use when we’re farther along. Threat Model grid v3.)

Trying a walkthrough

We decided to try to walk through fleshing out one example. We selected “Commute.”

An area that we struggled with was how to define when we had enough information to be useful to share with others. This sort segued into discussion about the right level of modeling versus detail. That’s an open issue. Here are the steps we followed just to get something down that we could respond to:

  1. Choose category: commute.
  2. Identify Methods of commute.
  3. List data-gathering technologies.
  4. List potential defenses.
  5. List cost of defenses.
Method Tech that gathers data Defense Cost of defense
Walk Camera (Mounted)

Camera (Mobile)

Microphone

SmartApp

Meshnet

RF

Threats: cameras, microphones, smart apps,

Cell

Wi-Fi

RFID/NFC/Bluetooth

Do nothing

Clothing

Avoid officers and known cameras

Stay home

Turn off devices

Airplane mode

Farraday pouch

Policy

Join SPC and advocate

Privacy loss

Social stigma (tinfoil hat)

Financial

Time

Backlash unintended consequences

Stress

Loss of convenience of device

Watchdogging

Meetings

Drive own car
Bike
Carshare
Ride corporate bus

Next steps

Obviously, we still have a lot of work to do. Here’s how we plan to do it:

  • We will meet again in August to finish the commute example, so that we have something substantial to share with reviewers. Watch twitter for an announcement; it will be in Delridge again.
  • We’ll present a prototype for feedback to Seattle-TA3M in October and ask for volunteers to help us continue fleshing out the data set.
  • We’ll reach out for help finding under-represented communities who can supplement our data set and help us understand what kinds of building blocks would make it useful for scenarios we might not have thought of.
  • Finally, we’ll identify ways that our information about the total cost of privacy invasions can be used to help educate policy makers, technologists, and individuals.

This project is fun and fascinating. If you are in the Seattle area and are interested in participating, please do join us for our next meeting in August. We also welcome ideas about how our data set might best be used.

]]>
https://seattleprivacy.org/introducing-threat-modeling-for-seattlites/feed/ 0
Here’s a template for universal video surveillance, but at least it’s GREEN! https://seattleprivacy.org/heres-a-template-for-universal-video-surveillance-but-at-least-its-green/ https://seattleprivacy.org/heres-a-template-for-universal-video-surveillance-but-at-least-its-green/#respond Sat, 03 Jun 2017 20:25:11 +0000 https://seattleprivacy.org/?p=2479 Continue reading "Here’s a template for universal video surveillance, but at least it’s GREEN!"]]> Isn’t this a lovely logo with a lovely message? Silicon and chlorophyll, kissed by the sun in a circle of life….

But the solar lighting company Sun-In-One has more to offer than just lighting. It also offers street lamp modules with motion detection, video surveillance, and mesh networking. Now cities can light roadways and record every movement of their citizens — all in one, convenient, extensible package. Image analysis software included!

Attention Seattle Police Department: Get those facial recognition databases ready.

Attention Seattle City Light: The ATF won’t have to work through you anymore to put up illegal cameras.

Read the product brochure for details.

[pdfviewer]https://seattleprivacy.org/wp-content/uploads/2017/06/SkyEye-Street-Light-System-2.pdf[/pdfviewer]

]]>
https://seattleprivacy.org/heres-a-template-for-universal-video-surveillance-but-at-least-its-green/feed/ 0
Proposal: Overhaul Surveillance Ordinance as Data Collection, Retention and Sharing Ordinance https://seattleprivacy.org/proposal-overhaul-surveillance-ordinance-as-data-collection-retention-and-sharing-ordinance/ https://seattleprivacy.org/proposal-overhaul-surveillance-ordinance-as-data-collection-retention-and-sharing-ordinance/#respond Tue, 11 Apr 2017 07:01:19 +0000 https://seattleprivacy.org/?p=2408 Continue reading "Proposal: Overhaul Surveillance Ordinance as Data Collection, Retention and Sharing Ordinance"]]> By Jan Bultmann and Christopher Sheats

 

Our city has committed to protecting immigrants, refugees, and the many thousands of other vulnerable populations. We argue that this is not possible without strong privacy oversight, safeguards, and enforcement. The local privacy community urges Seattle’s leadership to set aside for the moment the discussion of our Surveillance Ordinance and any amendments to it, and instead to develop an ordinance that holistically addresses the government’s role in data collection, retention, and sharing.

Why pause now? The ACLU of Washington has proposed a stronger version of the existing bill, which has been watered down by multiple revisions that remove the many critical elements including independent oversight, auditing, reporting, and enforcement requirements. But even with the ACLU’s original, stronger proposal, the foundation of the bill is inadequate.

We now live in a very different environment than when the Surveillance Ordinance was first crafted, although it has only been 3 years. This legislation was drafted in response to the public outcry that accompanied the Seattle Police Department’s acquisition of drones without public knowledge. Council chambers were repeatedly packed with demonstrators. After having wasted $82,000 dollars, the drones were ultimately decommissioned. The Surveillance Ordinance was successful to meet that immediate challenge.

Now we promise vulnerable people that we are a sanctuary city that will defend their human rights. We are literally in the crosshairs of a hostile federal government, one that has been shown to disregard local regulations and make backroom deals with city agencies. For example, putting cameras on City Light poles in direct violation of our existing surveillance law, putting nothing in writing, and further, evading any form of FOIA or PDR process.

“As a sanctuary city we have a greater obligation to protect private citizens.” — Kshama Sawant

We have autonomous cars coming, including wireless car to car technology, wireless car to infrastructure technology, and the lobbyists that come with them. We have facial recognition technologies coming and the lobbyists that come with them. We will be seeing the largest developments of these technologies within President Trump’s term.

Seattle’s Race and Social Justice Initiative clearly states:

By 2017, the City of Seattle will work with community-based organizations to support the movement to end structural racism.

We can tell you that the City has not asked the Seattle Privacy Coalition for input on how we might accomplish this, and we are well into 2017. Further, CTAB-Privacy has not been asked for input on these amendments by the Council. How can Seattle’s Surveillance Ordinance go on to exempt technologies designed and purchased for surveillance? Do black lives really matter to Seattle when data collection, retention, and sharing technologies are historically and routinely purchased in the name of defense but used offensively?

If we do not hold ourselves accountable, a government for the people, how are we going to ethically govern the use of these technologies when they are funded, deployed, and managed by third parties? How is Seattle going to defend our human rights if we have a “surveillance ordinance” that is not adequate for the complexity of a major municipality? Common sense demands that we broaden the scope to include all forms of data collection, retention, and sharing. This would eliminate splitting hairs on terms that exclude any technology not specifically purchased to support law enforcement.

The Electronic Frontier Foundation is a legal digital rights organization that maintains an umbrella grassroots organization called Electronic Frontier Alliance. Last week we discussed surveillance ordinances under development in more than 11 municipalities across the United States. The Seattle Washington ordinance was cited as being “well-intended but weak” whereas the Oakland California legislation was cited as effective because their draft legislation includes provisions for independent oversight that are fundamental to all controls, auditing and reporting requirements, and enforcement options such as the public’s right to sue for privacy harms. We strongly advise that Council review the Oakland California ordinance.

The Seattle ordinance MUST include oversight, auditing, reporting, and enforcement, and it cannot be limited to a false notion of what is or it not for surveillance. Without these fundamental changes, we are a sanctuary city in name only. With federal access to municipal databases unmonitored, unchecked, and unreported, anyone who makes use of a city service is vulnerable. When privacy is by design and policies are made to support the most vulnerable in our city, we, in effect, defend everyone’s human rights.

As defined by Seattle’s Privacy Program, we have a Privacy Review Process (PDF) that we can leverage for all forms of data collection. All forms, because there cannot be a lack of transparency and accountability. This must be baked into a Data Collection, Retention and Sharing Ordinance. Every act by the City that takes in information should have a corresponding unique identifier that must be published so that anyone can learn more about the data being collected, what it is being used for, and who is responsible for it. This will build trust. In line with Councilmember Sawant’s wishes to pull down foreign cameras from City utility poles, people have the right to be informed about what their government is collecting about them and their community. We should have the ability to learn about and to respond to our government in constructive ways. With the City’s drive for increasing open data and community engagement, why haven’t we started doing this yet?

Privacy is at risk from always-on microphones, cameras, smartphones, smart meters, automobiles, internet assistants like Alexa, Siri, Echo, and Cortona, Internet connected children’s toys, home appliances, and so many other things that have yet to even be invented. The city of Seattle cannot protect people today from predatory corporate data exploitation. We can, however, model what a human-rights respecting privacy policy looks like. And we must.

Please do not pass the watered-down Surveillance Ordinance rewrite into law because it will cause more harm than good. Instead, we urge the City Council to reach out to local community organizations such as the Seattle Privacy Coalition, Electronic Rights Rainier, and the body that the City Council assembled to advise them on technical issues, the Community Technology Advisory Board, to create a bill we can all be proud of.

]]>
https://seattleprivacy.org/proposal-overhaul-surveillance-ordinance-as-data-collection-retention-and-sharing-ordinance/feed/ 0
If We Care For Survivors, Surveillance Technologies Must Be Heavily Regulated https://seattleprivacy.org/if-we-care-for-survivors-surveillance-technologies-must-be-heavily-regulated/ https://seattleprivacy.org/if-we-care-for-survivors-surveillance-technologies-must-be-heavily-regulated/#respond Tue, 11 Apr 2017 07:00:50 +0000 https://seattleprivacy.org/?p=2403 Continue reading "If We Care For Survivors, Surveillance Technologies Must Be Heavily Regulated"]]> By Christopher Sheats

 

In Seattle tomorrow, City Council will be discussing Surveillance Ordinance amendments originally proposed by ACLU of Washington and watered down by the council. The Surveillance Ordinance would be incredibly deficient if we passed these amendments. Of primary concern, there are multiple exemptions that are *crazy* if you were to juxtapose a United Nations privacy report.

Surveillance technology does not include:

(a) technology used to collect data from individuals who knowingly and voluntarily consent to provide, or who do not avail themselves of an opportunity to opt out of providing, such data for use by a City department;

(b) social media sites or news monitoring and news alert services;

(c) a body-worn camera;

(d) a camera installed in or on a police vehicle;

(e) a camera installed in or on any vehicle or along a public right-of-way used to record traffic patterns or traffic violations or to otherwise operate the transportation system safely and efficiently, including in any public right-of-way;

(f) a camera installed on City property for security purposes;

(g) a camera installed solely to protect the physical integrity of City infrastructure, such as Seattle Public Utilities reservoirs; and

(h) routine patches, firmware and software updates, and hardware lifecycle replacements.

In February, I spoke along side ACLU of Washington lawyers, University of Washington lawyers, and a domestic violence survivor at a public hearing in our state capitol to support an ACLU bill limiting Automatic Licence Plate Readers. Domestic violence survivors’ privacy, specifically their physical location privacy, is paramount to them and their families. Further, many survivors are victims to police men and women, making this under-served population a critical voice in discussions concerning surveillance technologies. At the hearing, A women with incredible courage showed up to educate the committee about her and the other 5,000+ Address Confidentiality Program participants. With permission, below is her testimony.

As content on our website is licensed using Creative Commons, please feel free to use share her testimony to further privacy rights.

Madame Chair, and members of the committee,

I am here today to discuss a part of my life so terrifying that, at times, I have actually contemplated writing a horror movie script.

Please forgive me, but by the end, it will make sense to today’s hearing.

I am here as a participant in the Washington State Address Confidentiality Program, ACP for short.

You will never understand, nor will I ever be able to convey the fear and torment that one individual can deliver. His words are still etched in my mind: “No woman is going to tell me, a man, what to do.” When trying to end a relationship, what I got in return was physical abuse and psychological terror. I would see him outside my home, my work, at my children’s school or stalking me in my rear-view mirror.

At times, he would convey to me each and every way or place he could have killed me that day.

I discovered that he had made duplicate keys of both my home and my car. Changing door locks didn’t matter. He still got inside. He was letting me know that he was in control.

My oldest son and I would eventually bobby trap our doors when we left, to more easily determine if he might be inside when we returned.

And though time, our much-loved pet cats disappeared one by one.

I lived through death and kidnapping threats to my children’s lives. I feared for my own life.

And in utter, desperate fear one night, I called a helpline, told them of my situation, and was advised to leave the state immediately. I did. On their advice, I gave my house keys to a friend, told nobody where I was going, put my kids and some clothes in my car, and drove to a state where I was offered protection.

I thank you so very much WA for the ACP. I no longer have to be afraid. It took me months but I no longer have to fear looking in my rear-view mirror.

This is hopefully the end of my desperate story.

But now, I want you to clearly understand one implication of unrestricted ALPR technology
I am here representing a vulnerable part of society, those who live in domestic violence situations. My ex-boyfriend kept telling me that he had connections to the police department, that there was no place to hide.

What if that was true? What if someone like me, couldn’t hide ever?

With unrestricted and retained ALPR data that becomes a real possibility.

I want you to consider the lives of spouses of law enforcement who might be in a domestic violence situation. My tale of torture existed because my stalker knew where I lived. Please protect your citizens, all your citizens, from potential location abuse. Please put restrictions on ALPR data.

]]>
https://seattleprivacy.org/if-we-care-for-survivors-surveillance-technologies-must-be-heavily-regulated/feed/ 0
Letter to Council re Surveillance Ordinance CB 118930 https://seattleprivacy.org/letter-to-council-re-surveillance-ordinance-cb-118930/ https://seattleprivacy.org/letter-to-council-re-surveillance-ordinance-cb-118930/#respond Mon, 10 Apr 2017 21:24:05 +0000 https://seattleprivacy.org/?p=2397 Continue reading "Letter to Council re Surveillance Ordinance CB 118930"]]> Today I sent the following email to the Gender Equity, Safe Communities, and New Americans Committee of Seattle City Council, speaking only for myself as an individual, not for the Seattle Privacy Coalition or board.

(The board is currently discussing possibilities for a unified position on this legislation that we could endorse as a group.)

I strongly encourage anyone interested in privacy to contact the committee with your own thoughts on this issue.

Dear Councilmembers Gonzales, Burgess, and Bagshaw,

I’m a 30-year resident of Seattle; I live in Councilmember Bagshaw’s district, and I work for Google in the cloud computing division. Previously I have worked for both Microsoft and Amazon on documenting online privacy and security issues.

I am the Chair of the Board of the Seattle Privacy Coalition, and I am a former LA to Councilmember Bagshaw and former Councilmember Sally J. Clark.

I’m writing to call on your committee to discuss and vote for the strongest possible version of the ACLU’s amendments to CB 118930, the Seattle Surveillance Ordinance, and to follow that by tackling the issue of strengthening protections from data-gathering software or hardware that is purchased for reasons other than surveillance.

I am absolutely opposed to council passing any version of this bill that fails to mandate oversight, reporting, auditing, and enforcement (enforcement through such mechanisms as the right to sue for privacy harms).

Finally, please be aware that even the strongest version of the amendments to the ordinance submitted by the ACLU address only a small subset of data-gathering technologies. The world of data-gathering is moving so quickly that technologies not purchased for the use of surveillance can easily become surveillance technology, particularly when information from multiple technologies is combined and shared.

This is an issue that urgently needs to be addressed, since we are now literally being pressured by the federal government to provide information on people for use in deporting them, while at the same time promising those same people that we will protect them as a sanctuary city.

The city must vigorously enforce its privacy program and hire an effective and committed Chief Privacy Officer as soon as possible.

I participated in an Electronic Frontier Foundation call last week in which grassroots activists from around the country discussed surveillance ordinances they are working to enact on municipal, county, and state levels. Seattle’s was cited as “well-intended, but weak.”

Please, help change how people talk about the hard work you do to protect Seattlites, so that they call this legislation “a brilliant model for other municipalities to follow,” instead.

]]>
https://seattleprivacy.org/letter-to-council-re-surveillance-ordinance-cb-118930/feed/ 0
Sawant is a privacy badass; some hope for Dems https://seattleprivacy.org/positive-moves-in-democratic-party/ https://seattleprivacy.org/positive-moves-in-democratic-party/#respond Sun, 29 Jan 2017 21:23:28 +0000 http://192.168.42.120/?p=2303 Continue reading "Sawant is a privacy badass; some hope for Dems"]]> With a few very notable exceptions (Mike O’Brien), it has been a huge uphill battle to get Dems at any level of government to acknowledge need for privacy protections or oversight of big data use and sharing, or protection from federal overreach. (Indeed, we had some city council staff openly laughing at us before the Snowden revelations.)

(Councilmember Kshama Sawant deserves special mention for having been on top of this problematic issue since her first day in office, but of course she is not a Dem.)

I have high hopes of the new party leadership in Washington state however, Tina Podlodowski and Joe Pakootas, and now that Mayor Ed Murray is taking a very unambiguous stand on our sanctuary status, hopes that we might get some enforcement teeth in our municipal surveillance ordinance and start setting some precedents. (Such as the right to sue over privacy harms.)

Surveillance most harms vulnerable populations such as immigrants, survivors of domestic violence, and people of color — the people we offer sanctuary.

Here’s a round up of coverage on Sawant’s committee meeting that started investigating federal cameras on SCL poles last week:

Video of the committee meeting

Sawant Blasts Secret Federal Surveillance Cameras on Seattle Utility Poles

Fearing Trump administration’s reach, Seattle City Council fights FBIand SPD’s ‘warrantless surveillance cameras’

Sawant wants to strengthen Seattle’s laws against warrantless surveillance

Surveillance on Seattle’s mind in light of Trump presidency

Sawant moves to curb federal surveillance

Seattle City councilmember wants federal surveillance cameras removed

New push to restrict law enforcement surveillance cameras on City Lightpoles

Court Says Location Of FBI’s Utility Pole-Piggybacking Surveillance Cameras Can Remain Secret

]]>
https://seattleprivacy.org/positive-moves-in-democratic-party/feed/ 0