<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://haverkamp.com" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title>Otherwise Occupied - privacy</title>
 <link>http://haverkamp.com/taxonomy/term/104/0</link>
 <description></description>
 <language>en</language>
<item>
 <title>The twisted logic of border searches of electronics</title>
 <link>http://haverkamp.com/2008/08/07/the-twisted-logic-of-border-searches-of-electronics</link>
 <description>&lt;p&gt;Jayson Ahern, Deputy Commissioner, U.S. Customs and Border Protection, recently posted a blog entry at the Department of Homeland Security&#039;s site.  In it, Mr. Ahern takes issue with the criticism that has been level against Customs and Border Protection (&quot;CBP&quot;) in light of the news that they&#039;ve been routinely nabbing laptops and other electronic devices, imaging the full contents, and sharing those contents with other agencies.  It&#039;s a tired refrain of the typical DHS line: 1) we&#039;re at risk; 2) we&#039;ve always been doing it, anyway, and you just didn&#039;t know about it; and 3) the courts say it&#039;s okay, so that makes it okay.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.dhs.gov/journal/leadership/2008/08/answering-questions-on-border-laptop.html&quot;&gt;Leadership Journal:  Answering Questions on Border Laptop Searches&lt;/a&gt;:&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;
First, it’s important to note that for more than 200 years, the federal government has been granted the authority to prevent dangerous people and things from entering the United States. Our security measures at the border are rooted in this fundamental fact, and our ability to achieve our border mission would be hampered if we did not apply the same search authorities to electronic media that we have long-applied to physical objects--including documents, photographs, film and other graphic material.&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;Who knew that documents, photographs, film, and other material constituted &quot;dangerous things?&quot;  Those things aren&#039;t dangerous, of course, and to characterize them as such is the way of the simple, who have no reasoned explanations for their mindless actions.  Might those items contain information that might be used to commit harm?  Probably.  However, it is people acting, not the things in their possession, that cause harm and create dangers.  That&#039;s true whether the items contain child pornography, bomb making plans, or obscene comic books.&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;
In the 21st century, terrorists and criminals increasingly use laptops and other electronic media to transport illicit materials that were traditionally concealed in bags, containers, notebooks and paper documents. Making full use of our search authorities with respect to items like notebooks and backpacks, while failing to do so with respect to laptops and other devices, would ensure that terrorists and criminals receive less scrutiny at our borders just as their use of technology is becoming more sophisticated.&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;So, to, do many law abiding Americans and aliens, who might like &quot;to be secure in their persons, houses, papers, and effects.&quot;  The difference is one of need.  In this modern era of electronic media, there&#039;s little reason to feel threatened by the transport of a laptop.  There are countless smarter, more efficient ways that a devious criminal would find to migrate that data across the border.  In fact, a laptop with a spinning hard drive is perhaps one of the worst.  It&#039;s the clear electronic devices that are the least threatening.&lt;/p&gt;
&lt;p&gt;The agency would be better off not lying to the American people and fully explaining what this is: a fishing expedition.  Grab laptops and these other electronic devices, create images, and then use them either in the coming copyright enforcement battles or to simply watch and hope for the appearance of incriminating data.&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;This brings me to my third point, which is that travelers whose laptops are searched represent a very small number of people. As Secretary Chertoff noted in a recent &lt;a href=&quot;http://blogs.usatoday.com/oped/2008/07/opposing-view-s.html&quot;&gt;op-ed&lt;/a&gt;,&lt;br&gt;&lt;br&gt;&lt;br /&gt;
&lt;blockquote&gt;&quot;Of the approximately 400 million travelers who entered the country last year, only a tiny percentage were referred to secondary baggage inspection…[and] of those, only a fraction had electronic devices that may have been checked.”&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;This number is less than one percent of people entering the United States. Contrary to some media accounts, we’re not rolling out a new strategy and screening an exorbitant number of travelers. We’re simply following a common sense border policy that has been in place for years, and has been reaffirmed by the courts.&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;Unless they&#039;re horribly misstating their case, there is a &quot;common sense&quot; policy that permitted the CBP to search the electronic devices of up to 4 million people entering the United States last year.  One percent may, indeed, be a small percentage.  However, 4 million people is not a small number of people.&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;
I hope this has helped answer some of your questions. One of the lessons 9/11 taught us was that we must adapt to 21st century risks and anticipate rather than react to new threats. Our CBP officers are on the front lines every day ensuring that these lessons are heeded. We trust that travelers understand the need for these sensible security measures.&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;&quot;One of the lessons 9/11 [has] taught&quot; the rest of us is that those in power will use 9/11 as a ready justification for any unwarranted intrusion into the privacy of Americans and the expansion of governmental power and knowledge.  Can Mr. Ahern look at the mirror after trotting out this 9/11 crap to support his points?  More importantly, if this has been long-standing policy, backed by more than 200 years of authority, as he asserts in the posting, shouldn&#039;t we have better lessons than 9/11?  What laptops with plans slipped through prior to 9/11 that permitted it to occur?&lt;/p&gt;
&lt;p&gt;None, would be my guess.&lt;/p&gt;
</description>
 <comments>http://haverkamp.com/2008/08/07/the-twisted-logic-of-border-searches-of-electronics#comment</comments>
 <category domain="http://haverkamp.com/topics/border">border</category>
 <category domain="http://haverkamp.com/topics/cbp">cbp</category>
 <category domain="http://haverkamp.com/topics/dhs">dhs</category>
 <category domain="http://haverkamp.com/topics/fourth-amendment">fourth_amendment</category>
 <category domain="http://haverkamp.com/topics/laptops">laptops</category>
 <category domain="http://haverkamp.com/topics/privacy">privacy</category>
 <pubDate>Thu, 07 Aug 2008 21:03:50 -0500</pubDate>
 <dc:creator>gregh</dc:creator>
 <guid isPermaLink="false">669 at http://haverkamp.com</guid>
</item>
<item>
 <title>NCSL calls on Congress to repeal REAL ID</title>
 <link>http://haverkamp.com/2008/04/23/ncsl-calls-on-congress-to-repeal-real-id</link>
 <description>&lt;p&gt;&lt;a href=&quot;http://www.ncsl.org/statefed/RealID040408.htm&quot;&gt;NCSL Supports The Identification Security Enhancement Act of 2007&lt;/a&gt;:&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;However, lacking the full policy and financial commitment of the federal government to ensure the success of the state-federal partnership needed to make REAL ID possible, NCSL now calls upon Congress to repeal REAL ID and reinstate the negotiated rule-making process.  This approach  will achieve our shared goals for security in a manner that respects states’ rights, privacy protections, and fiscal responsibility.&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;&lt;a href=&quot;http://thomas.loc.gov/cgi-bin/query/z?c110:s717:&quot;&gt;S.717&lt;/a&gt;, which I &lt;a href=&quot;http://haverkamp.com/2006/12/13/american-civil-liberties-union-aclu-lauds-akaka-sununu-real-id-fix-bill-says-additional-privacy-and-civil-liberties-s&quot;&gt;previously covered&lt;/a&gt; in its 2006 form, would bring back the negotiated rulemaking and return to the states the authority to preserve their own privacy regimes.&lt;/p&gt;
&lt;p&gt;Keep your fingers crossed.&lt;/p&gt;
&lt;p&gt;(Via &lt;a href=&quot;http://techliberation.com/2008/04/23/ncsl-calls-for-repeal-of-real-id/&quot;&gt;Jim Harper&lt;/a&gt;.)&lt;/p&gt;
</description>
 <comments>http://haverkamp.com/2008/04/23/ncsl-calls-on-congress-to-repeal-real-id#comment</comments>
 <category domain="http://haverkamp.com/taxonomy/term/51">Law</category>
 <category domain="http://haverkamp.com/topics/ncsl">ncsl</category>
 <category domain="http://haverkamp.com/topics/privacy">privacy</category>
 <category domain="http://haverkamp.com/topics/real-id">real_id</category>
 <pubDate>Wed, 23 Apr 2008 11:44:24 -0500</pubDate>
 <dc:creator>gregh</dc:creator>
 <guid isPermaLink="false">617 at http://haverkamp.com</guid>
</item>
<item>
 <title>Facebook Beacon Dissection</title>
 <link>http://haverkamp.com/2007/11/27/facebook-beacon-dissection</link>
 <description>&lt;p&gt;Jay Goldman has written &lt;a href=&quot;http://www.radiantcore.com/blog/archives/23/11/2007/deconstructingfacebookbeaconjavascript&quot;&gt;an excellent description of Facebook Beacon&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;The long-and-short of it?  &lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;When you&#039;re done using Facebook, log out of Facebook.  If you&#039;re not logged into Facebook, Facebook effectively rejects Beacon info.  (Note that because you&#039;ve probably got lingering Facebook cookies even after logging out, Facebook still knows who you are and where you&#039;re coming from.  At this point, it appears that they terminate the rest of the Beacon setup.)&lt;/li&gt;
&lt;li&gt;If you are logged in to Facebook, don&#039;t ever go anywhere else unless you want Facebook to know about it and potentially publish it.  Facebook knows about every transaction sent by a cooperating site, even if you&#039;ve chosen not to publish it.&lt;/li&gt;
&lt;li&gt;Consider &lt;a href=&quot;http://adblockplus.org&quot;&gt;AdBlockPlus&lt;/a&gt; on Firefox; other suggestions for IE are in the post.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The Beacon functionality is really pretty elegant, but it&#039;s useful to note that &quot;Beacon&quot; is an excellent name.  Like other web beacons or web  bugs, it uses embedded JavaScript, effectively tracking your movements around the web in very much the same way that modern web tracking applications do so.  In essence, Facebook is making itself a web analytics service for advertisers.&lt;/p&gt;
&lt;p&gt;The irony here is that the information collected by Facebook is likely far more valuable than the publication of that information and whatever ad revenue they may get from it.  However, to get advertisers to buy in, they needed the Beacon profile entries.  But just imagine being able to track the flow of collaborative purchasing information.  Imagine I buy a Diet Coke, and that gets published to my profile.  Suddenly, members in one of my Facebook groups starts buying Diet Coke shortly after my purchase is published.  Not only can Facebook tout its ability to spread the word about the Diet Coke thing, but it also can tell Coca Cola the characteristics (including n-orders of social graph characteristics) of those who buy Diet Coke.&lt;/p&gt;
&lt;p&gt;Powerful stuff.  Scary.  But Powerful.&lt;/p&gt;
</description>
 <comments>http://haverkamp.com/2007/11/27/facebook-beacon-dissection#comment</comments>
 <category domain="http://haverkamp.com/topics/facebook">facebook</category>
 <category domain="http://haverkamp.com/topics/privacy">privacy</category>
 <pubDate>Tue, 27 Nov 2007 09:31:24 -0600</pubDate>
 <dc:creator>gregh</dc:creator>
 <guid isPermaLink="false">595 at http://haverkamp.com</guid>
</item>
<item>
 <title>Who&#039;s running this show?</title>
 <link>http://haverkamp.com/2007/11/11/whos-running-this-show</link>
 <description>&lt;p&gt;&lt;a href=&quot;http://ap.google.com/article/ALeqM5hJKgeE0Z-SivATjok-utYBdh9wDwD8SRK4LG0&quot;&gt;Definition Changing for People&#039;s Privacy&lt;/a&gt;:&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;Privacy no longer can mean anonymity, says Donald Kerr, the principal deputy director of national intelligence. Instead, it should mean that government and businesses properly safeguard people&#039;s private communications and financial information.&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;How lovely for Kerr to think that way.  &lt;i&gt;You silly Americans; let me tell you what you can have.&lt;/i&gt;  What should happen is that our intelligence and law enforcement agencies need to work within the confines of our Constitution and laws.  If they can&#039;t work within those confines, they need to show why they can&#039;t, so we can consider going about the business of amending the Constitution.&lt;/p&gt;
&lt;p&gt;One problem with the land grab like the one Kerr describes is that there&#039;s been no evidence presented that it&#039;s either necessary or useful.  Instead, what evidence exists shows that it&#039;s a crutch, violating our traditional notions of privacy with little benefit.&lt;/p&gt;
&lt;p&gt;The other -- huge! -- problem is that the government cannot be trusted to properly safeguard private communications and financial information.  That has been made clear in recent years.  Business is even worse, unless it&#039;s strategically competitive information, of course.&lt;/p&gt;
&lt;p&gt;Perhaps the definition that needs to be changed defines suitable government employees.  Rather than the Kerrs and Chertoffs, who feel it is their position to determine what we can demand, we need people who will recognize that a Constitution and body of privacy protection laws exists, and that their inability to do their jobs without dreaming up ways around those things suggests their incompetence, not a need for the American people to change how they live their lives.&lt;/p&gt;
</description>
 <comments>http://haverkamp.com/2007/11/11/whos-running-this-show#comment</comments>
 <category domain="http://haverkamp.com/topics/information-privacy">information_privacy</category>
 <category domain="http://haverkamp.com/taxonomy/term/51">Law</category>
 <category domain="http://haverkamp.com/topics/privacy">privacy</category>
 <pubDate>Sun, 11 Nov 2007 18:23:41 -0600</pubDate>
 <dc:creator>gregh</dc:creator>
 <guid isPermaLink="false">591 at http://haverkamp.com</guid>
</item>
<item>
 <title>We now have case law on email interceptions</title>
 <link>http://haverkamp.com/2007/07/07/we-now-have-case-law-on-email-interceptions</link>
 <description>&lt;p&gt;Until yesterday, my paper on Fourth Amendment and statutory protections against interception of Internet communications had little directly related case law.  Now I have the &lt;a href=&quot;http://www.ca9.uscourts.gov/ca9/newopinions.nsf/F0E09BB37A97D51A88257310004D1DAC/$file/0550410.pdf?openelement&quot;&gt;Ninth Circuit&#039;s decision in &lt;i&gt;U.S. v. Forrester&lt;/i&gt;&lt;/a&gt;, in the matter of the second defendant, Alba.  When I &lt;a href=&quot;http://www.concurringopinions.com/archives/2007/07/the_fourth_amen.html&quot;&gt;first read the headline&lt;/a&gt;, I was a bit concerned.  After reading the rest of Prof. Solove&#039;s commentary, as well as the opinion itself, I am no longer.&lt;/p&gt;
&lt;p&gt;That is to say, I am no longer concerned about the state of my paper.  I am  concerned about where the courts are going to take constitutional protections on the Internet.  Many of my complaints continue to come down to many of the overly simplistic analyses of email transport on the Internet.  Prof. Solove trumpets Prof. Kerr&#039;s work in the above post:&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;Orin Kerr has usefully analogized the distinction between the non-content / content information to that between an envelope and the contents of a letter. The envelope contains addressing information that is exposed to others; the contents of the letter are concealed. Envelope information falls outside Fourth Amendment protection, but content information is fully protected by the Fourth Amendment.&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;Kerr&#039;s work does often make this distinction, but it often does so with an apparent misunderstanding of how email transportation works.  Judge Fisher, in the &lt;i&gt;Forrester&lt;/i&gt; decision, follows a path of similar technical missteps.&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;First, e-mail and Internet users, like the telephone users in &lt;em&gt;Smith&lt;/em&gt;, rely on third-party equipment in order to engage in communication. &lt;em&gt;Smith&lt;/em&gt; based its holding that telephone users have no expectation of privacy in the numbers they dial on the users’ imputed knowledge that their calls are completed through telephone company switching equipment. 442 U.S. at 742. Analogously, e-mail and Internet users have no expectation of privacy in the to/from addresses of their messages or the IP addresses of the websites they visit because they should know that these messages are sent and these IP addresses are accessed through the equipment of their Internet service provider and other third parties.&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;In fact, all telephone users rely on third-party equipment.  However, there are decided differences between telephone numbers opening a circuit and the routers that route traffic to destination IP addresses.  But the problem runs deeper, and this is a significant complaint of mine in the literature.  This peering of email and Internet use, as if sending an email is somehow different, is what allows for this butchery.  For instance, the next paragraph begins:&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;Second, e-mail to/from addresses and IP addresses constitute addressing information and reveal no more about the underlying contents of communication than do phone numbers.&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;An Internet email address without an IP network attached goes nowhere.&lt;/p&gt;
&lt;p&gt;There is a useful (to me) diversion into an email/snail mail comparison:&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;The government’s surveillance of e-mail addresses also may be technologically sophisticated, but it is conceptually indistinguishable from government surveillance of physical mail. In a line of cases dating back to the nineteenth century, the Supreme Court has held that the government cannot engage in a warrantless search of the contents of sealed mail, but can observe whatever information people put on the outside of mail, because that information is voluntarily transmitted to third parties.&lt;br /&gt;
. . .&lt;br /&gt;
E-mail, like physical mail, has an outside address “visible” to the third-party carriers that transmit it to its intended location, and also a package of content that the sender presumes will be read only by the intended recipient. The privacy interests in these two forms of communication are identical. The contents may deserve Fourth Amendment protection, but the address and size of the package do not.
&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;Oh, it does, indeed.  Email has an outside address called an IP address.  But beyond that, it has outside addresses called envelope addresses, as specified by the RFCs.  These, the technical envelope specifications, are ignored in the literature, but they are key to using Prof. Kerr&#039;s envelope terminology.  For something to be an envelope, it must surely have an impact on the delivery of a message.  The RFC content of a message has no bearing on delivery, yet Prof. Kerr (and now the Ninth Circuit) appear to be perfectly willing to allow it to be intercepted.&lt;/p&gt;
&lt;p&gt;And so, this is just another lousy decision, crafted not with an understanding of Internet communications, but with the more typical understanding, that seems to reflect the belief that a &quot;send button&quot; magically whisks an email message to some remote spot on the globe.  In the case of the Ninth Circuit, that spot appears to be someplace that need not have even heard of IP addresses.&lt;/p&gt;
</description>
 <comments>http://haverkamp.com/2007/07/07/we-now-have-case-law-on-email-interceptions#comment</comments>
 <category domain="http://haverkamp.com/topics/fourth-amendment">fourth_amendment</category>
 <category domain="http://haverkamp.com/taxonomy/term/51">Law</category>
 <category domain="http://haverkamp.com/topics/ninthcircuit">ninthcircuit</category>
 <category domain="http://haverkamp.com/topics/penregisters">penregisters</category>
 <category domain="http://haverkamp.com/topics/privacy">privacy</category>
 <pubDate>Sat, 07 Jul 2007 21:17:05 -0500</pubDate>
 <dc:creator>gregh</dc:creator>
 <guid isPermaLink="false">518 at http://haverkamp.com</guid>
</item>
<item>
 <title>Speaking in SMTP</title>
 <link>http://haverkamp.com/2007/07/02/speaking-in-smtp</link>
 <description>&lt;p&gt;As &lt;a href=&quot;http://haverkamp.com/2007/06/06/substance-purport-or-meaning&quot;&gt;I&#039;ve previously written&lt;/a&gt;, what I consider a key flaw in current analysis of Fourth Amendment (and Electronic Communications Privacy Act) protections against interception of Internet communication is that it takes a narrow view of what constitutes communication on the Internet.  The standard is &quot;any information&quot; that concerns the substance, meaning, or purport of a communication.&lt;/p&gt;
&lt;p&gt;We should look to other forms of communication to arrive at a reasonable definition of Internet communication.  I&#039;ve suggested voice as the most pervasive.  We don&#039;t permit the recording of waveforms of speech and only exclude transcripts.  Without a warrant, the government may not record a telephone conversation.&lt;/p&gt;
&lt;p&gt;When a person sends an email message, that form of communication is chosen, for whatever reason, over a telephone call.  While the propagation of sound is required for meaningful oral communication by telephone, the propagation of properly formatted SMTP commands and RFC 822 message bodies are required for comprehension of the stream of bytes comprising an email message.  Without that formatting, there is no substance, purport, or meaning of an email. In many cases, it won&#039;t be delivered at all.&lt;/p&gt;
&lt;p&gt;The SMTP commands that transport a message across the Internet are, therefore, comparable to the use of voice to communicate across a telephone line.  The courts and the Congress don&#039;t allow the recording of the electrical underpinnings that make up that voice communication.  It makes little sense to allow recording of the commands and formatting that make up an email message.&lt;/p&gt;
&lt;p&gt;If I can get to a point where I can substantively establish this, it becomes clear that what follows is protection of the application layer.&lt;/p&gt;
</description>
 <comments>http://haverkamp.com/2007/07/02/speaking-in-smtp#comment</comments>
 <category domain="http://haverkamp.com/topics/ecpa">ECPA</category>
 <category domain="http://haverkamp.com/topics/fourth-amendment">fourth_amendment</category>
 <category domain="http://haverkamp.com/topics/interception">interception</category>
 <category domain="http://haverkamp.com/topics/privacy">privacy</category>
 <category domain="http://haverkamp.com/topics/wiretaps">wiretaps</category>
 <pubDate>Mon, 02 Jul 2007 23:26:24 -0500</pubDate>
 <dc:creator>gregh</dc:creator>
 <guid isPermaLink="false">511 at http://haverkamp.com</guid>
</item>
<item>
 <title>Foolish consistency... How the little minds behind Real ID killed the possibility of meaningful immigration reform</title>
 <link>http://haverkamp.com/2007/06/28/foolish-consistency-how-the-little-minds-behind-real-id-killed-the-possibility-of-meaningful-immigration-reform</link>
 <description>&lt;p&gt;Did Real ID bring down immigration reform?  That&#039;s probably not the right way to put it.  &lt;/p&gt;
&lt;p&gt;Are the forces of evil (Sensenbrenner, et al) so incredibly gung ho to track the details of every American who chooses to work that they&#039;ll scuttle immigration reform rather than see Real ID go down the tubes?  The answer appears to be yes.  However, the problem is deeper than immigration; it may extend to your ability to find work, change jobs, and in turn, move freely about the country.&lt;/p&gt;
&lt;p&gt;Declan describes how attempted to kill Real ID in the current immigration reform efforts brought a halt to the process in his article, &lt;a href=&quot;http://news.com.com/2100-7348_3-6193916.html&quot;&gt;National ID plan may have killed immigration bill&lt;/a&gt;:&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;Privacy advocates were quick to claim that a vote against Real ID cards the previous evening doomed the bill.&lt;/p&gt;
&lt;p&gt;Wednesday&#039;s vote showed that senators were willing to delete the portion of the labyrinthine immigration bill that would require employers to demand the Real ID cards from new hires. Because some of the bill&#039;s backers had insisted that the ID requirement remain in place--as a way to identify illegal immigrants--they were no longer as willing to support the overall bill.&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;Commentary in that article also comes from the &lt;a href=&quot;http://www.cato.org&quot;&gt;Cato Institute&#039;s&lt;/a&gt; Jim Harper:&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;&quot;The proponents of national ID in the Senate weren&#039;t getting what they wanted, so they backed away,&quot; said Jim Harper, a policy analyst at the free-market Cato Institute who opposes Real ID. &quot;It was a landmine that blew up in their faces.&quot;&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;(By the way, if you&#039;re looking for an easy-to-read book with broad coverage of identity issues, I recommend Harper&#039;s &lt;a href=&quot;http://www.amazon.com/Identity-Crisis-Identification-Overused-Misunderstood/dp/1930865856&quot;&gt;Identity Crisis: How Identification is Overused and Misunderstood&lt;/a&gt;.)&lt;/p&gt;
&lt;p&gt;However, it&#039;s important to note that another key facet of this immigration reform bill came in the form of pre-employment verification.  A database of huge importance that would be run by, of all agencies, the Department of Homeland Security, employers would be forced to query the database preferably before, but certainly shortly after you went to work.  In &lt;a href=&quot;http://www.huffingtonpost.com/caroline-fredrickson/immigration-reform-needed_b_52844.html&quot;&gt;this Huffington Post entry&lt;/a&gt;, the ACLU&#039;s Caroline Fredrickson explains the system:&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;For instance, Title III of the bill expands the error-plagued &lt;a href=&quot;http://www.aclu.org/immigrants/gen/29878prs20070525.html&quot;&gt;Employment Eligibility Verification System (EEVS)&lt;/a&gt;, creating a vast federal database to verify the eligibility to work of all job applicants in America -- including U.S. citizens. This expansive system would contain extraordinary amounts of personal information on everyone who seeks or holds a job, all of it keyed to a person&#039;s Social Security number. If the immigration bill passes as written, all Americans will need to have their eligibility to work approved by the Department of Homeland Security. Invariably, DHS will confuse the files of people with similar names or use outdated or erroneous information to deny people the right to work, creating a &#039;No Work List&#039; similar to the government&#039;s &#039;No Fly List.&#039; They have testified that they will need to &quot;manually reverify&quot; the work-eligibility of eight percent of all workers.&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;So, we can&#039;t get passports out to people to travel, but we&#039;ll certainly be able to manually verify 80% of the legally working population in no time.  No doubt.&lt;/p&gt;
&lt;p&gt;John Gilmore &lt;a href=&quot;http://www.politechbot.com/2007/06/28/john-gilmore-on/&quot;&gt;paints a much scarier picture&lt;/a&gt; of the growing &quot;In DHS We Trust&quot; phenomenon:&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;
The attempt to force a process of &quot;get federal permission to hire FIRST&quot; on the country is eerily parallel to the DHS proposal to require airlines to &quot;get federal permission to transport FIRST&quot;. Today, airlines can bring you to the US without permission, but they are liable for the cost of carrying you elsewhere if the US won&#039;t admit you. This naturally limits their willingness to bring random people -- but allows people to come and apply for asylum, for example. The Gestapo announced months ago that they plan to change this to require each passenger&#039;s info to be submitted long before the plane takes off, getting an affirmative &quot;OK&quot;, or else the passenger would not be allowed on board at all. As with other federal watchlist checks, this would come with zero due process protection for the passenger, and zero accountability for the government. If they mysteriously keep saying &quot;No&quot;, there&#039;s nothing that you as a citizen could do to get back into your own country. They wouldn&#039;t even have to jail or detain you, such that a lawyer could go to court with some urgency to spring you. No, YOU would have to sue THEM, and it would take years in the courts.&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;In our fervor to regulate and control immigration, we&#039;ve got to be very wary of those in &lt;b&gt;our&lt;/b&gt; legislature who would like to use this opportunity to regulate and control the rest of us.  As &lt;a href=&quot;http://baucus.senate.gov/newsroom/details.cfm?id=277952&amp;amp;&amp;&quot;&gt;Senators Max Baucus and Jon Tester said&lt;/a&gt; after the immigration bill was eventually put out of its misery:&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;
&quot;We scored a major victory today in our efforts to protect privacy and defeat a bad immigration bill at the same time,&quot; said Baucus, Montana’s senior U.S. Senator. &quot;If Jon and I just brought down the entire bill, that’s good for Montana and the country.&quot;&lt;br /&gt;
...&lt;br /&gt;
&quot;If by fighting to keep government out of people’s private lives, Max Baucus and I stopped the senate from passing this flawed immigration bill, then this was a real victory for Montana and the American people,&quot; Tester said.
&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;Indeed.&lt;/p&gt;
</description>
 <comments>http://haverkamp.com/2007/06/28/foolish-consistency-how-the-little-minds-behind-real-id-killed-the-possibility-of-meaningful-immigration-reform#comment</comments>
 <category domain="http://haverkamp.com/topics/eevs">eevs</category>
 <category domain="http://haverkamp.com/topics/immigration">immigration</category>
 <category domain="http://haverkamp.com/topics/privacy">privacy</category>
 <category domain="http://haverkamp.com/topics/real-id">real_id</category>
 <pubDate>Thu, 28 Jun 2007 21:25:16 -0500</pubDate>
 <dc:creator>gregh</dc:creator>
 <guid isPermaLink="false">507 at http://haverkamp.com</guid>
</item>
<item>
 <title>Dialing, routing, addressing, and signaling</title>
 <link>http://haverkamp.com/2007/06/17/dialing-routing-addressing-and-signaling</link>
 <description>&lt;p&gt;Dialing, routing, addressing, and signaling.  Pen registers and trap-and-trace devices are devices that may be used to collect the non-content portions of a communication.  As I&#039;ve &lt;a href=&quot;http://haverkamp.com/2007/06/06/substance-purport-or-meaning&quot;&gt;previously written&lt;/a&gt;, contents refers to &quot;any information concerning the substance, purport, or meaning&quot; of a communication.  Therefore, non-content dialing, routing, addressing, and signaling information is necessarily such information that does not concern any such information about a communication.  Simple enough, right?&lt;/p&gt;
&lt;p&gt;Well, it seemed simple enough to Congress.  They proceeded with the intention to call an &quot;email address&quot; a communications &quot;facility,&quot; moving it into the definitions of pen registers and trap-and-trace devices.  This involves a convoluted notion that one communicates from email address to email address, much as one communicates from phone to phone.  Obviously, this is nonsense, but that hasn&#039;t stopped law enforcement from seizing upon this expansion.&lt;/p&gt;
&lt;p&gt;However, let&#039;s assume for a minute that an email address actually is a communications facility unto itself, and that when we communicate via email, the endpoints are actually email addresses.  If we focus solely on the real-time interception of non-content information of an email communication, what is &quot;dialing, routing, addressing, and signaling&quot; information, and what is &quot;any content concerning the substance, purport, or meaning&quot; of that communication?  Remember, this is still a message in transit across the Internet.&lt;/p&gt;
&lt;p&gt;Here&#039;s what we know.  Before the email message can be sent, there is already going to be a TCP connection established between the sending computer and the receiving computer.  Only after the TCP connection is established may the actual communication take place.  When that message gets to the remote computer, that remote computer is going to have to receive it, most likely via the SMTP.  In this day and age of heavy spam and other deviousness online, it is very likely that the message is going to have to be formatted somewhat well in order to be delivered.&lt;/p&gt;
&lt;p&gt;In order for a message to be properly formatted for receipt by the remote computer, the sending computer will send SMTP commands, continuing to send others, followed by the actual content of the message being sent, in response to replies from the remote computer.  The sending computer will give, at a minimum, its name, the email address that is sending the message, the email address that is the destination of the message, and finally, the message.  If these steps aren&#039;t followed, the message will not be delivered.&lt;/p&gt;
&lt;p&gt;But there&#039;s more.  Once a message is delivered, for a communication to be complete, the message must be read.  There are many things that may be carried in a message to allow it to be understood.  Obviously, the body of the message allows it to be understood.  But we&#039;re concerned, also, with &lt;b&gt;any&lt;/b&gt; information that concerns the substance, purport, or meaning of the message.  &lt;/p&gt;
&lt;p&gt;In a telephone call, a great deal of substance, purport, or meaning may be derived from the voice of the communicator.  In email, there is no such voice.  However, the sending address certainly gives a message voice.  The personalizable &quot;From:&quot; header my also lend such a voice.  Bayesian spam filters assign scores to a message based on tokens in the headers, and these can also lend a voice, as can such headers as message priorities and the &quot;Received:&quot; headers, which allow a message to be traced and in many mail programs, is used to sort messages by date (and &lt;b&gt;not&lt;/b&gt; the &quot;Date:&quot; header.)&lt;/p&gt;
&lt;p&gt;In short, the proper use of SMTP commands, the email addresses and addressing, as well as received headers and the nature of the contents of the headers all lend substance, purport, and meaning to a message.  However, under the most common interpretations of the current laws, all of those pieces of content may be readily obtained by law enforcement agents under the Pen Register Act.&lt;/p&gt;
</description>
 <comments>http://haverkamp.com/2007/06/17/dialing-routing-addressing-and-signaling#comment</comments>
 <category domain="http://haverkamp.com/topics/ecpa">ECPA</category>
 <category domain="http://haverkamp.com/topics/email">email</category>
 <category domain="http://haverkamp.com/topics/fourth-amendment">fourth_amendment</category>
 <category domain="http://haverkamp.com/topics/privacy">privacy</category>
 <pubDate>Sun, 17 Jun 2007 23:43:03 -0500</pubDate>
 <dc:creator>gregh</dc:creator>
 <guid isPermaLink="false">491 at http://haverkamp.com</guid>
</item>
<item>
 <title>Internet anonymity ain&#039;t dead yet.</title>
 <link>http://haverkamp.com/2007/03/21/internet-anonymity-aint-dead-yet</link>
 <description>&lt;p&gt;[The following was largely spawned by a Cyberspace Law class last night, and the repeated suggestions that we must authenticate users before we allow them to &quot;use the Internet&quot; so that we may track down evildoers.]&lt;/p&gt;
&lt;p&gt;Are we really heading toward the end of a (relatively) anonymous Internet?  I don&#039;t think so.&lt;/p&gt;
&lt;p&gt;To properly answer this, it&#039;s important to consider how the Internet is constructed.  Sure, you&#039;ll often read accounts of your data traveling across the Internet&#039;s &quot;backbone.&quot;  The problem is, there isn&#039;t a single backbone.  The internetwork that is the Internet is comprised of numerous independent network backbones that interconnect.  For any one node on any one of those backbones to identify with any certainty the sender of a packet would require a vast identity infrastructure that simply is nowhere near existence.  However, it&#039;s possible that this extreme example of the impossibility of defeating anonymity is more than what some consider necessary.  In fact, I know it is, based on class discussion.&lt;/p&gt;
&lt;p&gt;Let&#039;s take another popular example that has been used: all users must authenticate their identities before they are allowed to &quot;connect to the Internet.&quot;  The obvious first question I have to ask is &quot;To whom must they authenticate?&quot;  This is not an easy question to answer.&lt;/p&gt;
&lt;p&gt;Is the answer the user&#039;s Internet Service Provider?  If so, who&#039;s going to mandate that?  If it&#039;s the ISP who mandates this, what other limitations of service will the ISP then have to place on the user to enforce this authentication?  A user who wishes to remain anonymous will simply tunnel traffic through an anonymizing conduit, whether this is an application like TOR, or wilder approaches like tunneling one application layer protocol through another.&lt;/p&gt;
&lt;p&gt;This raises another problem: who authenticates the conduit?  Not all Internet &quot;users&quot; are discrete individuals.  Many are servers providing services, remote access devices providing connectivity, or bots gathering and processing data.  Who authenticates every process that connects to the Internet?  Who do these processes authenticate to?&lt;/p&gt;
&lt;p&gt;Finally, are users going to be expected to authenticate to every peer process?  This suggests that every process and every user on the Internet will use a single authentication mechanism, or sufficient federation will have to exist for these authentications to take place.  Who&#039;s going to write the software that allows the millions of autonomous servers, routers, switches, and other devices connected to the Internet to be able to carry out these authentications so that anonymous actors may eventually be identified?&lt;/p&gt;
&lt;p&gt;My point is this: until everything authenticates, there is no forced, universal authentication to &quot;connect&quot; to the Internet.  As long as unauthenticated systems exist, and as long as owners of some of those systems prize anonymity, a step as limited as forcing users to properly authenticate to an ISP before using the Internet (a concept that has still more questions) will not kill one&#039;s ability to act anonymously, nor will it lead to discoverable identification of anonymous sources.&lt;/p&gt;
</description>
 <comments>http://haverkamp.com/2007/03/21/internet-anonymity-aint-dead-yet#comment</comments>
 <category domain="http://haverkamp.com/topics/anonymity">anonymity</category>
 <category domain="http://haverkamp.com/topics/cyberspace-law">cyberspace_law</category>
 <category domain="http://haverkamp.com/taxonomy/term/57">Internet</category>
 <category domain="http://haverkamp.com/topics/privacy">privacy</category>
 <pubDate>Wed, 21 Mar 2007 13:09:51 -0600</pubDate>
 <dc:creator>gregh</dc:creator>
 <guid isPermaLink="false">458 at http://haverkamp.com</guid>
</item>
<item>
 <title>Schneier on Real-ID:  Costs and Benefits</title>
 <link>http://haverkamp.com/2007/01/30/schneier-on-real-id-costs-and-benefits</link>
 <description>&lt;p&gt;&lt;a href=&quot;http://www.schneier.com/blog/archives/2007/01/realid_costs_an.html&quot;&gt;Real-ID:  Costs and Benefits&lt;/a&gt;:&lt;br /&gt;
&lt;blockquote&gt;All of these problems demonstrate that identification checks based on Real ID won&amp;rsquo;t be nearly as secure as we might hope. But the main problem with any strong identification system is that it requires the existence of a database. In this case, it would have to be 50 linked databases of private and sensitive information on every American -- one widely and instantaneously accessible from airline check-in stations, police cars, schools, and so on.&lt;/p&gt;
&lt;p&gt;The security risks of this database are enormous. It would be a kludge of existing databases that are incompatible, full of erroneous data, and unreliable. Computer scientists don&amp;rsquo;t know how to keep a database of this magnitude secure, whether from outside hackers or the thousands of insiders authorized to access it.&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;And yet, there&#039;s a group that will carry on insisting that this is something we must have.  We open ourselves up to theft of identity information on a grand scale, and for what?  As Schneier continues:&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;Even worse, as soon as you divide people into two categories -- more trusted and less trusted people -- you create a third, and very dangerous, category: untrustworthy people whom we have no reason to mistrust. Oklahoma City bomber Timothy McVeigh; the Washington, DC, snipers; the London subway bombers; and many of the 9/11 terrorists had no previous links to terrorism. Evildoers can also steal the identity -- and profile -- of an honest person. Profiling can result in less security by giving certain people an easy way to skirt security.&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;So, we do all of this Real ID nonsense, and what do we get?  Oh, right.  Less security.  Along with the false sense of security, we also receive diminished privacy, heightened risks to privacy, greater government aggregation of data that is is unlikely to be able to manage, and just generally a worse situation than we had before.&lt;/p&gt;
</description>
 <comments>http://haverkamp.com/2007/01/30/schneier-on-real-id-costs-and-benefits#comment</comments>
 <category domain="http://haverkamp.com/taxonomy/term/52">Politics</category>
 <category domain="http://haverkamp.com/topics/privacy">privacy</category>
 <category domain="http://haverkamp.com/topics/real-id">real_id</category>
 <category domain="http://haverkamp.com/topics/security">security</category>
 <pubDate>Tue, 30 Jan 2007 12:28:49 -0600</pubDate>
 <dc:creator>gregh</dc:creator>
 <guid isPermaLink="false">427 at http://haverkamp.com</guid>
</item>
</channel>
</rss>
