Showing posts with label privacy. Show all posts
Showing posts with label privacy. Show all posts

Wednesday, January 25, 2012

Facebook Timeline Becoming Mandatory For All Users



The winds of change are blowing across Facebook's international network of over 800 million profiles.

On Tuesday, Facebook announced in an updated blog post that its radically revamped profile design, called "Timeline," will become the mandatory format for all users "over the next few weeks."

The social network first unveiled the Timeline, a media-rich profile page designed to tell the story of the user's life in reverse chronological order from present day to the user's date of birth, at the company's f8 conference in September. Since the feature debuted, users could upgrade their profile by "liking" the Facebook Developer app and accessing the platform as a developer. The Timeline officially became available for all users to try out on December 15.

But the changes will soon become permanent. If you haven't tried out the new Timeline yet, you'd better get acquainted with it.

According to the Facebook Blog, users will have a weeklong grace period to try the new layout, which has the potential to make your online life more public.

"Over the next few weeks, everyone will get timeline," reads the Facebook Blog. "When you get timeline, you'll have 7 days to preview what's there now. This gives you a chance to add or hide whatever you want before anyone else sees it."

Last week Facebook announced the rollout of 60 new "frictionless" apps (plus more to come), developed to publicize more of users' activities to their friends. To quote my colleague Jason Gilbert,"'Frictionless' apps are so named because they do not require the user to take any action in order for the app to share its information to Facebook -- the sharing occurs automatically and instantaneously after you give the app permission to do so." For example, if the user reads a story via the Washington Post's social app, and has granted that app access to the Timeline, that story will appear in the user's news ticker and will be posted to his or her Timeline for friends to see.

There are, however, a number of new privacy settings that users can enable to restrict the amount of sharing by these new apps. Check out Jason Gilbert's run-down of the new settings (here).

"We want to design a place that feels like your home. Where you tell story online is very personal. You spend a lot of time curating it. We want to make timeline a place you're proud to call your home," Zuckerberg said of the Timeline at the f8 conference. "It's a completely new aesthetic for Facebook. It gives you the ability to curate all your stories so you can express who you really are."

If you don't have the new Timeline-style profile yet, you can visit Facebook's Timeline introductory page to learn about the new features and convert your profile now. Or, you can wait until you see Facebook's announcement appear at the top of your personal profile.

Source: http://www.huffingtonpost.com/2012/01/24/facebook-timeline_n_1228800.html

Thursday, February 3, 2011

U.S. Tries to Make It Easier to Wiretap the Internet

WASHINGTON — Federal law enforcement and national security officials are preparing to seek sweeping new regulations for the Internet, arguing that their ability to wiretap criminal and terrorism suspects is “going dark” as people increasingly communicate online instead of by telephone.

Essentially, officials want Congress to require all services that enable communications — including encrypted e-mail transmitters like BlackBerry, social networking Web sites like Facebook and software that allows direct “peer to peer” messaging like Skype — to be technically capable of complying if served with a wiretap order. The mandate would include being able to intercept and unscramble encrypted messages.

The bill, which the Obama administration plans to submit to lawmakers next year, raises fresh questions about how to balance security needs with protecting privacy and fostering innovation. And because security services around the world face the same problem, it could set an example that is copied globally.

James X. Dempsey, vice president of the Center for Democracy and Technology, an Internet policy group, said the proposal had “huge implications” and challenged “fundamental elements of the Internet revolution” — including its decentralized design.

“They are really asking for the authority to redesign services that take advantage of the unique, and now pervasive, architecture of the Internet,” he said. “They basically want to turn back the clock and make Internet services function the way that the telephone system used to function.”

But law enforcement officials contend that imposing such a mandate is reasonable and necessary to prevent the erosion of their investigative powers.

“We’re talking about lawfully authorized intercepts,” said Valerie E. Caproni, general counsel for the Federal Bureau of Investigation. “We’re not talking expanding authority. We’re talking about preserving our ability to execute our existing authority in order to protect the public safety and national security.”

Investigators have been concerned for years that changing communications technology could damage their ability to conduct surveillance. In recent months, officials from the F.B.I., the Justice Department, the National Security Agency, the White House and other agencies have been meeting to develop a proposed solution.

There is not yet agreement on important elements, like how to word statutory language defining who counts as a communications service provider, according to several officials familiar with the deliberations.

But they want it to apply broadly, including to companies that operate from servers abroad, like Research in Motion, the Canadian maker of BlackBerry devices. In recent months, that company has come into conflict with the governments of Dubai and India over their inability to conduct surveillance of messages sent via its encrypted service.

In the United States, phone and broadband networks are already required to have interception capabilities, under a 1994 law called the Communications Assistance to Law Enforcement Act. It aimed to ensure that government surveillance abilities would remain intact during the evolution from a copper-wire phone system to digital networks and cellphones.

Often, investigators can intercept communications at a switch operated by the network company. But sometimes — like when the target uses a service that encrypts messages between his computer and its servers — they must instead serve the order on a service provider to get unscrambled versions.

Like phone companies, communication service providers are subject to wiretap orders. But the 1994 law does not apply to them. While some maintain interception capacities, others wait until they are served with orders to try to develop them.

The F.B.I.’s operational technologies division spent $9.75 million last year helping communication companies — including some subject to the 1994 law that had difficulties — do so. And its 2010 budget included $9 million for a “Going Dark Program” to bolster its electronic surveillance capabilities.

Beyond such costs, Ms. Caproni said, F.B.I. efforts to help retrofit services have a major shortcoming: the process can delay their ability to wiretap a suspect for months.

Moreover, some services encrypt messages between users, so that even the provider cannot unscramble them.

There is no public data about how often court-approved surveillance is frustrated because of a service’s technical design.

But as an example, one official said, an investigation into a drug cartel earlier this year was stymied because smugglers used peer-to-peer software, which is difficult to intercept because it is not routed through a central hub. Agents eventually installed surveillance equipment in a suspect’s office, but that tactic was “risky,” the official said, and the delay “prevented the interception of pertinent communications.”

Moreover, according to several other officials, after the failed Times Square bombing in May, investigators discovered that the suspect, Faisal Shahzad, had been communicating with a service that lacked prebuilt interception capacity. If he had aroused suspicion beforehand, there would have been a delay before he could have been wiretapped.

To counter such problems, officials are coalescing around several of the proposal’s likely requirements:

¶ Communications services that encrypt messages must have a way to unscramble them.

¶ Foreign-based providers that do business inside the United States must install a domestic office capable of performing intercepts.

¶ Developers of software that enables peer-to-peer communication must redesign their service to allow interception.

Providers that failed to comply would face fines or some other penalty. But the proposal is likely to direct companies to come up with their own way to meet the mandates. Writing any statute in “technologically neutral” terms would also help prevent it from becoming obsolete, officials said.

Even with such a law, some gaps could remain. It is not clear how it could compel compliance by overseas services that do no domestic business, or from a “freeware” application developed by volunteers.

In their battle with Research in Motion, countries like Dubai have sought leverage by threatening to block BlackBerry data from their networks. But Ms. Caproni said the F.B.I. did not support filtering the Internet in the United States.

Still, even a proposal that consists only of a legal mandate is likely to be controversial, said Michael A. Sussmann, a former Justice Department lawyer who advises communications providers.

“It would be an enormous change for newly covered companies,” he said. “Implementation would be a huge technology and security headache, and the investigative burden and costs will shift to providers.”

Several privacy and technology advocates argued that requiring interception capabilities would create holes that would inevitably be exploited by hackers.

Steven M. Bellovin, a Columbia University computer science professor, pointed to an episode in Greece: In 2005, it was discovered that hackers had taken advantage of a legally mandated wiretap function to spy on top officials’ phones, including the prime minister’s.

“I think it’s a disaster waiting to happen,” he said. “If they start building in all these back doors, they will be exploited.”

Susan Landau, a Radcliffe Institute of Advanced Study fellow and former Sun Microsystems engineer, argued that the proposal would raise costly impediments to innovation by small startups.

“Every engineer who is developing the wiretap system is an engineer who is not building in greater security, more features, or getting the product out faster,” she said.

Moreover, providers of services featuring user-to-user encryption are likely to object to watering it down. Similarly, in the late 1990s, encryption makers fought off a proposal to require them to include a back door enabling wiretapping, arguing it would cripple their products in the global market.

But law enforcement officials rejected such arguments. They said including an interception capability from the start was less likely to inadvertently create security holes than retrofitting it after receiving a wiretap order.

They also noted that critics predicted that the 1994 law would impede cellphone innovation, but that technology continued to improve. And their envisioned decryption mandate is modest, they contended, because service providers — not the government — would hold the key.

“No one should be promising their customers that they will thumb their nose at a U.S. court order,” Ms. Caproni said. “They can promise strong encryption. They just need to figure out how they can provide us plain text.”

Source: http://www.nytimes.com/2010/09/27/us/27wiretap.html

Wednesday, January 5, 2011

Court: No warrant needed to search cell phone

The next time you're in California, you might not want to bring your cell phone with you. The California Supreme Court ruled Monday that police can search the cell phone of a person who's been arrested -- including text messages -- without obtaining a warrant, and use that data as evidence.

The ruling opens up disturbing possibilities, such as broad, warrantless searches of e-mails, documents and contacts on smart phones, tablet computers, and perhaps even laptop computers, according to legal expert Mark Rasch.

The ruling handed down by California's top court involves the 2007 arrest of Gregory Diaz, who purchased drugs from a police informant. Investigators later looked through Diaz's phone and found text messages that implicated him in a drug deal. Diaz appealed his conviction, saying the evidence was gathered in violation of the Fourth Amendment, which prohibits unreasonable searches and seizures. The court disagreed, comparing Diaz cell phone to personal effects like clothing, which can be searched by arresting officers.

"The cell phone was an item (of personal property) on (Diaz's) person at the time of his arrest and during the administrative processing at the police station," the justices wrote. "Because the cell phone was immediately associated with defendant’s person, (police were) entitled to inspect its contents without a warrant."

In fact, the ruling goes further, saying essentially that the Diaz case didn't involve an exception -- such as a need to search the phone to stop a "crime in progress." In other words, this case was not an exception, but rather the rule.

Rasch, former head of the Justice Department's computer crime unit, pulled no punches in his reaction to the ruling.

"This ruling isn't just wrong, it's dangerous," said Rasch, now director of cybersecurity and privacy at computer security firm CSC in Virginia. "It's remarkable, because it simply misunderstands the nature of these devices."

The door is open for police to search the entire contents of iPhones or other smart phones that people routinely carry, he said.

"In fact, I would be shocked if police weren't getting instructions right now to do just that," he said.

By applying the "personal property on the defendant's person" standard, Rasch said, the ruling could logically extend to tablets or even laptop computers, he said.

It also flies in the face of established law, which prohibits the warrantless search of briefcases by police, other than a quick search for weapons, Rasch said.

In its ruling, the majority likened cell phone inspection to police inspection of a cigarette pack taken from a suspect, which was ruled a legal search in a prior case. A second ruling was cited involving the search of clothing removed from a suspect.

Rasch said the analogies don't hold, however, as modern phones that can store years' worth of personal information are a far cry from drugs hidden in a cigarette case or clothes pockets.

"There is a process for looking at data inside devices,” he said. “It's called a warrant."

Grants police 'carte blanche'
The California ruling was not unanimous. Dissenting Justice Kathryn Werdegar raised similar concerns in her opinion.

"The majority’s holding ... (grants) police carte blanche, with no showing of exigency, to rummage at leisure through the wealth of personal and business information that can be carried on a mobile phone or handheld computer merely because the device was taken from an arrestee’s person," she wrote. "The majority thus sanctions a highly intrusive and unjustified type of search, one meeting neither the warrant requirement nor the reasonableness requirement of the Fourth Amendment to the United States Constitution."

Jonathan Turley, a Constitutional law expert at George Washington University, took to his blog to raise his concerns about the ruling.

"The Court has left the Fourth Amendment in tatters and this ruling is the natural extension of that trend," he wrote. "While the Framers wanted to require warrants for searches and seizures, the Court now allows the vast majority of searches and seizures to occur without warrants. As a result, the California Supreme Court would allow police to open cell phone files — the modern equivalent of letter and personal messages.”

Diaz’s lawyer, Lyn A. Woodward, has said she plans to appeal the decision to the U.S. Supreme Court. In the meantime, warrantless searches of cell phones are essentially the law of the land in California.

Password-protection of smart phones might be a useful tool to ward off a warrantless search -- it's not clear that an arrested suspect could be compelled to divulge his or her password to police -- but that legal argument has not yet been made.

Source: http://redtape.msnbc.com/2011/01/court-cops-can-search-cell-phone-without-warrant.html

Thursday, February 11, 2010

Feds push for tracking cell phones

Two years ago, when the FBI was stymied by a band of armed robbers known as the "Scarecrow Bandits" that had robbed more than 20 Texas banks, it came up with a novel method of locating the thieves.

FBI agents obtained logs from mobile phone companies corresponding to what their cellular towers had recorded at the time of a dozen different bank robberies in the Dallas area. The voluminous records showed that two phones had made calls around the time of all 12 heists, and that those phones belonged to men named Tony Hewitt and Corey Duffey. A jury eventually convicted the duo of multiple bank robbery and weapons charges.

Even though police are tapping into the locations of mobile phones thousands of times a year, the legal ground rules remain unclear, and federal privacy laws written a generation ago are ambiguous at best. On Friday, the first federal appeals court to consider the topic will hear oral arguments (PDF) in a case that could establish new standards for locating wireless devices.

In that case, the Obama administration has argued that warrantless tracking is permitted because Americans enjoy no "reasonable expectation of privacy" in their--or at least their cell phones'--whereabouts. U.S. Department of Justice lawyers say that "a customer's Fourth Amendment rights are not violated when the phone company reveals to the government its own records" that show where a mobile device placed and received calls.

Those claims have alarmed the ACLU and other civil liberties groups, which have opposed the Justice Department's request and plan to tell the U.S. Third Circuit Court of Appeals in Philadelphia that Americans' privacy deserves more protection and judicial oversight than what the administration has proposed.

"This is a critical question for privacy in the 21st century," says Kevin Bankston, an attorney at the Electronic Frontier Foundation who will be arguing on Friday. "If the courts do side with the government, that means that everywhere we go, in the real world and online, will be an open book to the government unprotected by the Fourth Amendment."

Not long ago, the concept of tracking cell phones would have been the stuff of spy movies. In 1998's "Enemy of the State," Gene Hackman warned that the National Security Agency has "been in bed with the entire telecommunications industry since the '40s--they've infected everything." After a decade of appearances in "24" and "Live Free or Die Hard," location-tracking has become such a trope that it was satirized in a scene with Seth Rogen from "Pineapple Express" (2008).

Once a Hollywood plot, now 'commonplace'
Whether state and federal police have been paying attention to Hollywood, or whether it was the other way around, cell phone tracking has become a regular feature in criminal investigations. It comes in two forms: police obtaining retrospective data kept by mobile providers for their own billing purposes that may not be very detailed, or prospective data that reveals the minute-by-minute location of a handset or mobile device.

Obtaining location details is now "commonplace," says Al Gidari, a partner in the Seattle offices of Perkins Coie who represents wireless carriers. "It's in every pen register order these days."

Gidari says that the Third Circuit case could have a significant impact on police investigations within the court's jurisdiction, namely Delaware, New Jersey, and Pennsylvania; it could be persuasive beyond those states. But, he cautions, "if the privacy groups win, the case won't be over. It will certainly be appealed."

CNET was the first to report on prospective tracking in a 2005 news article. In a subsequent Arizona case, agents from the Drug Enforcement Administration tracked a tractor trailer with a drug shipment through a GPS-equipped Nextel phone owned by the suspect. Texas DEA agents have used cell site information in real time to locate a Chrysler 300M driving from Rio Grande City to a ranch about 50 miles away. Verizon Wireless and T-Mobile logs showing the location of mobile phones at the time calls became evidence in a Los Angeles murder trial.

And a mobile phone's fleeting connection with a remote cell tower operated by Edge Wireless is what led searchers to the family of the late James Kim, a CNET employee who died in the Oregon wilderness in 2006 after leaving a snowbound car to seek help.

"This is a critical question for privacy in the 21st century. If the courts do side with the government, that means that everywhere we go, in the real world and online, will be an open book to the government unprotected by the Fourth Amendment."
--Kevin Bankston, attorney, Electronic Frontier Foundation


The way tracking works is simple: mobile phones are miniature radio transmitters and receivers. A cellular tower knows the general direction of a mobile phone (many cell sites have three antennas pointing in different directions), and if the phone is talking to multiple towers, triangulation yields a rough location fix. With this method, accuracy depends in part on the density of cell sites.

The Federal Communications Commission's "Enhanced 911" (E911) requirements allowed rough estimates to be transformed into precise coordinates. Wireless carriers using CDMA networks, such as Verizon Wireless and Sprint Nextel, tend to use embedded GPS technology to fulfill E911 requirements. AT&T and T-Mobile comply with E911 regulations using network-based technology that computes a phone's location using signal analysis and triangulation between towers.


T-Mobile, for instance, uses a GSM technology called Uplink Time Difference of Arrival, or U-TDOA, which calculates a position based on precisely how long it takes signals to reach towers. A company called TruePosition, which provides U-TDOA services to T-Mobile, boasts of "accuracy to under 50 meters" that's available "for start-of-call, midcall, or when idle."

A 2008 court order to T-Mobile in a criminal investigation of a marriage fraud scheme, which was originally sealed and later made public, says: "T-Mobile shall disclose at such intervals and times as directed by (the Department of Homeland Security), latitude and longitude data that establishes the approximate positions of the Subject Wireless Telephone, by unobtrusively initiating a signal on its network that will enable it to determine the locations of the Subject Wireless Telephone."

'No reasonable expectation of privacy'
In the case that's before the Third Circuit on Friday, the Bureau of Alcohol, Tobacco, Firearms and Explosives, or ATF, said it needed historical (meaning stored, not future) phone location information because a set of suspects "use their wireless telephones to arrange meetings and transactions in furtherance of their drug trafficking activities."

U.S. Magistrate Judge Lisa Lenihan in Pennsylvania denied the Justice Department's attempt to obtain stored location data without a search warrant; prosecutors had invoked a different legal procedure. Lenihan's ruling, in effect, would require police to obtain a search warrant based on probable cause--a more privacy-protective standard.

Lenihan's opinion (PDF)--which, in an unusual show of solidarity, was signed by four other magistrate judges--noted that location information can reveal sensitive information such as health treatments, financial difficulties, marital counseling, and extra-marital affairs.

In its appeal to the Third Circuit, the Justice Department claims that Lenihan's opinion "contains, and relies upon, numerous errors" and should be overruled. In addition to a search warrant not being necessary, prosecutors said, because location "records provide only a very general indication of a user's whereabouts at certain times in the past, the requested cell-site records do not implicate a Fourth Amendment privacy interest."

The Obama administration is not alone in making this argument. U.S. District Judge William Pauley, a Clinton appointee in New York, wrote in a 2009 opinion that a defendant in a drug trafficking case, Jose Navas, "did not have a legitimate expectation of privacy in the cell phone" location. That's because Navas only used the cell phone "on public thoroughfares en route from California to New York" and "if Navas intended to keep the cell phone's location private, he simply could have turned it off."

(Most cases have involved the ground rules for tracking cell phone users prospectively, and judges have disagreed over what legal rules apply. Only a minority has sided with the Justice Department, however.)

Cellular providers tend not to retain moment-by-moment logs of when each mobile device contacts the tower, in part because there's no business reason to store the data, and in part because the storage costs would be prohibitive. They do, however, keep records of what tower is in use when a call is initiated or answered--and those records are generally stored for six months to a year, depending on the company.

Verizon Wireless keeps "phone records including cell site location for 12 months," Drew Arena, Verizon's vice president and associate general counsel for law enforcement compliance, said at a federal task force meeting in Washington, D.C. last week. Arena said the company keeps "phone bills without cell site location for seven years," and stores SMS text messages for only a very brief time.

Gidari, the Seattle attorney, said that wireless carriers have recently extended how long they store this information. "Prior to a year or two ago when location-based services became more common, if it were 30 days it would be surprising," he said.

The ACLU, EFF, the Center for Democracy and Technology, and University of San Francisco law professor Susan Freiwald argue that the wording of the federal privacy law in question allows judges to require the level of proof required for a search warrant "before authorizing the disclosure of particularly novel or invasive types of information." In addition, they say, Americans do not "knowingly expose their location information and thereby surrender Fourth Amendment protection whenever they turn on or use their cell phones."

"The biggest issue at stake is whether or not courts are going to accept the government's minimal view of what is protected by the Fourth Amendment," says EFF's Bankston. "The government is arguing that based on precedents from the 1970s, any record held by a third party about us, no matter how invasively collected, is not protected by the Fourth Amendment."

Update 10:37 a.m. PT: A source inside the U.S. Attorney's Office for the northern district of Texas, which prosecuted the Scarecrow Bandits mentioned in the above article, tells me that this was the first and the only time that the FBI has used the location-data-mining technique to nab bank robbers. It's also worth noting that the leader of this gang, Corey Duffey, was sentenced last month to 354 years (not months, but years) in prison. Another member is facing 140 years in prison.

Source: http://news.cnet.com/8301-13578_3-10451518-38.html

Wednesday, January 20, 2010

With friends like these ...

Facebook has 59 million users - and 2 million new ones join each week. But you won't catch Tom Hodgkinson volunteering his personal information - not now that he knows the politics of the people behind the social networking site

The following correction was printed in the Guardian's Corrections and clarifications column, Wednesday January 16 2008

The US intelligence community's enthusiasm for hi-tech innovation after 9/11 and the creation of In-Q-Tel, its venture capital fund, in 1999 were anachronistically linked in the article below. Since 9/11 happened in 2001 it could not have led to the setting up of In-Q-Tel two years earlier.

The Independent Guide to Facebook



I despise Facebook. This enormously successful American business describes itself as "a social utility that connects you with the people around you". But hang on. Why on God's earth would I need a computer to connect with the people around me? Why should my relationships be mediated through the imagination of a bunch of supergeeks in California? What was wrong with the pub?

And does Facebook really connect people? Doesn't it rather disconnect us, since instead of doing something enjoyable such as talking and eating and dancing and drinking with my friends, I am merely sending them little ungrammatical notes and amusing photos in cyberspace, while chained to my desk? A friend of mine recently told me that he had spent a Saturday night at home alone on Facebook, drinking at his desk. What a gloomy image. Far from connecting us, Facebook actually isolates us at our workstations.

Facebook appeals to a kind of vanity and self-importance in us, too. If I put up a flattering picture of myself with a list of my favourite things, I can construct an artificial representation of who I am in order to get sex or approval. ("I like Facebook," said another friend. "I got a shag out of it.") It also encourages a disturbing competitivness around friendship: it seems that with friends today, quality counts for nothing and quantity is king. The more friends you have, the better you are. You are "popular", in the sense much loved in American high schools. Witness the cover line on Dennis Publishing's new Facebook magazine: "How To Double Your Friends List."

It seems, though, that I am very much alone in my hostility. At the time of writing Facebook claims 59 million active users, including 7 million in the UK, Facebook's third-biggest customer after the US and Canada. That's 59 million suckers, all of whom have volunteered their ID card information and consumer preferences to an American business they know nothing about. Right now, 2 million new people join each week. At the present rate of growth, Facebook will have more than 200 million active users by this time next year. And I would predict that, if anything, its rate of growth will accelerate over the coming months. As its spokesman Chris Hughes says: "It's embedded itself to an extent where it's hard to get rid of."

All of the above would have been enough to make me reject Facebook for ever. But there are more reasons to hate it. Many more.



Facebook is a well-funded project, and the people behind the funding, a group of Silicon Valley venture capitalists, have a clearly thought out ideology that they are hoping to spread around the world. Facebook is one manifestation of this ideology. Like PayPal before it, it is a social experiment, an expression of a particular kind of neoconservative libertarianism. On Facebook, you can be free to be who you want to be, as long as you don't mind being bombarded by adverts for the world's biggest brands. As with PayPal, national boundaries are a thing of the past.

Although the project was initially conceived by media cover star Mark Zuckerberg, the real face behind Facebook is the 40-year-old Silicon Valley venture capitalist and futurist philosopher Peter Thiel. There are only three board members on Facebook, and they are Thiel, Zuckerberg and a third investor called Jim Breyer from a venture capital firm called Accel Partners (more on him later). Thiel invested $500,000 in Facebook when Harvard students Zuckerberg, Chris Hughes and Dustin Moskowitz went to meet him in San Francisco in June 2004, soon after they had launched the site. Thiel now reportedly owns 7% of Facebook, which, at Facebook's current valuation of $15bn, would be worth more than $1bn. There is much debate on who exactly were the original co-founders of Facebook, but whoever they were, Zuckerberg is the only one left on the board, although Hughes and Moskowitz still work for the company.

Thiel is widely regarded in Silicon Valley and in the US venture capital scene as a libertarian genius. He is the co-founder and CEO of the virtual banking system PayPal, which he sold to Ebay for $1.5bn, taking $55m for himself. He also runs a £3bn hedge fund called Clarium Capital Management and a venture capital fund called Founders Fund. Bloomberg Markets magazine recently called him "one of the most successful hedge fund managers in the country". He has made money by betting on rising oil prices and by correctly predicting that the dollar would weaken. He and his absurdly wealthy Silicon Valley mates have recently been labelled "The PayPal Mafia" by Fortune magazine, whose reporter also observed that Thiel has a uniformed butler and a $500,000 McLaren supercar. Thiel is also a chess master and intensely competitive. He has been known to sweep the chessmen off the table in a fury when losing. And he does not apologise for this hyper-competitveness, saying: "Show me a good loser and I'll show you a loser."



But Thiel is more than just a clever and avaricious capitalist. He is a futurist philosopher and neocon activist. A philosophy graduate from Stanford, in 1998 he co-wrote a book called The Diversity Myth, which is a detailed attack on liberalism and the multiculturalist ideology that dominated Stanford. He claimed that the "multiculture" led to a lessening of individual freedoms. While a student at Stanford, Thiel founded a rightwing journal, still up and running, called The Stanford Review - motto: Fiat Lux ("Let there be light"). Thiel is a member of TheVanguard.Org, an internet-based neoconservative pressure group that was set up to attack MoveOn.org, a liberal pressure group that works on the web. Thiel calls himself "way libertarian".

TheVanguard is run by one Rod D Martin, a philosopher-capitalist whom Thiel greatly admires. On the site, Thiel says: "Rod is one of our nation's leading minds in the creation of new and needed ideas for public policy. He possesses a more complete understanding of America than most executives have of their own businesses."

This little taster from their website will give you an idea of their vision for the world: "TheVanguard.Org is an online community of Americans who believe in conservative values, the free market and limited government as the best means to bring hope and ever-increasing opportunity to everyone, especially the poorest among us." Their aim is to promote policies that will "reshape America and the globe". TheVanguard describes its politics as "Reaganite/Thatcherite". The chairman's message says: "Today we'll teach MoveOn [the liberal website], Hillary and the leftwing media some lessons they never imagined."

So, Thiel's politics are not in doubt. What about his philosophy? I listened to a podcast of an address Thiel gave about his ideas for the future. His philosophy, briefly, is this: since the 17th century, certain enlightened thinkers have been taking the world away from the old-fashioned nature-bound life, and here he quotes Thomas Hobbes' famous characterisation of life as "nasty, brutish and short", and towards a new virtual world where we have conquered nature. Value now exists in imaginary things. Thiel says that PayPal was motivated by this belief: that you can find value not in real manufactured objects, but in the relations between human beings. PayPal was a way of moving money around the world with no restriction. Bloomberg Markets puts it like this: "For Thiel, PayPal was all about freedom: it would enable people to skirt currency controls and move money around the globe."

Clearly, Facebook is another uber-capitalist experiment: can you make money out of friendship? Can you create communities free of national boundaries - and then sell Coca-Cola to them? Facebook is profoundly uncreative. It makes nothing at all. It simply mediates in relationships that were happening anyway.

Thiel's philosophical mentor is one René Girard of Stanford University, proponent of a theory of human behaviour called mimetic desire. Girard reckons that people are essentially sheep-like and will copy one another without much reflection. The theory would also seem to be proved correct in the case of Thiel's virtual worlds: the desired object is irrelevant; all you need to know is that human beings will tend to move in flocks. Hence financial bubbles. Hence the enormous popularity of Facebook. Girard is a regular at Thiel's intellectual soirees. What you don't hear about in Thiel's philosophy, by the way, are old-fashioned real-world concepts such as art, beauty, love, pleasure and truth.

The internet is immensely appealing to neocons such as Thiel because it promises a certain sort of freedom in human relations and in business, freedom from pesky national laws, national boundaries and suchlike. The internet opens up a world of free trade and laissez-faire expansion. Thiel also seems to approve of offshore tax havens, and claims that 40% of the world's wealth resides in places such as Vanuatu, the Cayman Islands, Monaco and Barbados. I think it's fair to say that Thiel, like Rupert Murdoch, is against tax. He also likes the globalisation of digital culture because it makes the banking overlords hard to attack: "You can't have a workers' revolution to take over a bank if the bank is in Vanuatu," he says.

If life in the past was nasty, brutish and short, then in the future Thiel wants to make it much longer, and to this end he has also invested in a firm that is exploring life-extension technologies. He has pledged £3.5m to a Cambridge-based gerontologist called Aubrey de Grey, who is searching for the key to immortality. Thiel is also on the board of advisers of something called the Singularity Institute for Artificial Intelligence. From its fantastical website, the following: "The Singularity is the technological creation of smarter-than-human intelligence. There are several technologies ... heading in this direction ... Artificial Intelligence ... direct brain-computer interfaces ... genetic engineering ... different technologies which, if they reached a threshold level of sophistication, would enable the creation of smarter-than-human intelligence."

So by his own admission, Thiel is trying to destroy the real world, which he also calls "nature", and install a virtual world in its place, and it is in this context that we must view the rise of Facebook. Facebook is a deliberate experiment in global manipulation, and Thiel is a bright young thing in the neoconservative pantheon, with a penchant for far-out techno-utopian fantasies. Not someone I want to help get any richer.

The third board member of Facebook is Jim Breyer. He is a partner in the venture capital firm Accel Partners, who put $12.7m into Facebook in April 2005. On the board of such US giants as Wal-Mart and Marvel Entertainment, he is also a former chairman of the National Venture Capital Association (NVCA). Now these are the people who are really making things happen in America, because they invest in the new young talent, the Zuckerbergs and the like. Facebook's most recent round of funding was led by a company called Greylock Venture Capital, who put in the sum of $27.5m. One of Greylock's senior partners is called Howard Cox, another former chairman of the NVCA, who is also on the board of In-Q-Tel. What's In-Q-Tel? Well, believe it or not (and check out their website), this is the venture-capital wing of the CIA. After 9/11, the US intelligence community became so excited by the possibilities of new technology and the innovations being made in the private sector, that in 1999 they set up their own venture capital fund, In-Q-Tel, which "identifies and partners with companies developing cutting-edge technologies to help deliver these solutions to the Central Intelligence Agency and the broader US Intelligence Community (IC) to further their missions".

The US defence department and the CIA love technology because it makes spying easier. "We need to find new ways to deter new adversaries," defence secretary Donald Rumsfeld said in 2003. "We need to make the leap into the information age, which is the critical foundation of our transformation efforts." In-Q-Tel's first chairman was Gilman Louie, who served on the board of the NVCA with Breyer. Another key figure in the In-Q-Tel team is Anita K Jones, former director of defence research and engineering for the US department of defence, and - with Breyer - board member of BBN Technologies. When she left the US department of defence, Senator Chuck Robb paid her the following tribute: "She brought the technology and operational military communities together to design detailed plans to sustain US dominance on the battlefield into the next century."



Now even if you don't buy the idea that Facebook is some kind of extension of the American imperialist programme crossed with a massive information-gathering tool, there is no way of denying that as a business, it is pure mega-genius. Some net nerds have suggsted that its $15bn valuation is excessive, but I would argue that if anything that is too modest. Its scale really is dizzying, and the potential for growth is virtually limitless. "We want everyone to be able to use Facebook," says the impersonal voice of Big Brother on the website. I'll bet they do. It is Facebook's enormous potential that led Microsoft to buy 1.6% for $240m. A recent rumour says that Asian investor Lee Ka-Shing, said to be the ninth richest man in the world, has bought 0.4% of Facebook for $60m.

The creators of the site need do very little bar fiddle with the programme. In the main, they simply sit back and watch as millions of Facebook addicts voluntarily upload their ID details, photographs and lists of their favourite consumer objects. Once in receipt of this vast database of human beings, Facebook then simply has to sell the information back to advertisers, or, as Zuckerberg puts it in a recent blog post, "to try to help people share information with their friends about things they do on the web". And indeed, this is precisely what's happening. On November 6 last year, Facebook announced that 12 global brands had climbed on board. They included Coca-Cola, Blockbuster, Verizon, Sony Pictures and Condé Nast. All trained in marketing bullshit of the highest order, their representatives made excited comments along the following lines:

"With Facebook Ads, our brands can become a part of the way users communicate and interact on Facebook," said Carol Kruse, vice president, global interactive marketing, the Coca-Cola Company.

"We view this as an innovative way to cultivate relationships with millions of Facebook users by enabling them to interact with Blockbuster in convenient, relevant and entertaining ways," said Jim Keyes, Blockbuster chairman and CEO. "This is beyond creating advertising impressions. This is about Blockbuster participating in the community of the consumer so that, in return, consumers feel motivated to share the benefits of our brand with their friends."

"Share" is Facebookspeak for "advertise". Sign up to Facebook and you become a free walking, talking advert for Blockbuster or Coke, extolling the virtues of these brands to your friends. We are seeing the commodification of human relationships, the extraction of capitalistic value from friendships.

Now, by comparision with Facebook, newspapers, for example, begin to look hopelessly outdated as a business model. A newspaper sells advertising space to businesses looking to sell stuff to their readers. But the system is far less sophisticated than Facebook for two reasons. One is that newspapers have to put up with the irksome expense of paying journalists to provide the content. Facebook gets its content for free. The other is that Facebook can target advertising with far greater precision than a newspaper. Admit on Facebook that your favourite film is This Is Spinal Tap, and when a Spinal Tap-esque movie comes out, you can be sure that they'll be sending ads your way.

Mark Zuckerberg, founder of Facebook Facebook founder Mark Zuckerberg (Photo: Paul Sakuma/AP)


It's true that Facebook recently got into hot water with its Beacon advertising programme. Users were notified that one of their friends had made a purchase at certain online shops; 46,000 users felt that this level of advertising was intrusive, and signed a petition called "Facebook! Stop invading my privacy!" to say so. Zuckerberg apologised on his company blog. He has written that they have now changed the system from "opt-out" to "opt-in". But I suspect that this little rebellion about being so ruthlessly commodified will soon be forgotten: after all, there was a national outcry by the civil liberties movement when the idea of a police force was mooted in the UK in the mid 19th century.

Futhermore, have you Facebook users ever actually read the privacy policy? It tells you that you don't have much privacy. Facebook pretends to be about freedom, but isn't it really more like an ideologically motivated virtual totalitarian regime with a population that will very soon exceed the UK's? Thiel and the rest have created their own country, a country of consumers.

Now, you may, like Thiel and the other new masters of the cyberverse, find this social experiment tremendously exciting. Here at last is the Enlightenment state longed for since the Puritans of the 17th century sailed away to North America, a world where everyone is free to express themselves as they please, according to who is watching. National boundaries are a thing of the past and everyone cavorts together in freewheeling virtual space. Nature has been conquered through man's boundless ingenuity. Yes, and you may decide to send genius investor Thiel all your money, and certainly you'll be waiting impatiently for the public flotation of the unstoppable Facebook.

Or you might reflect that you don't really want to be part of this heavily-funded programme to create an arid global virtual republic, where your own self and your relationships with your friends are converted into commodites on sale to giant global brands. You may decide that you don't want to be part of this takeover bid for the world.

For my own part, I am going to retreat from the whole thing, remain as unplugged as possible, and spend the time I save by not going on Facebook doing something useful, such as reading books. Why would I want to waste my time on Facebook when I still haven't read Keats' Endymion? And when there are seeds to be sown in my own back yard? I don't want to retreat from nature, I want to reconnect with it. Damn air-conditioning! And if I want to connect with the people around me, I will revert to an old piece of technology. It's free, it's easy and it delivers a uniquely individual experience in sharing information: it's called talking.

Facebook's privacy policy

Just for fun, try substituting the words 'Big Brother' whenever you read the word 'Facebook'

1 We will advertise at you

"When you use Facebook, you may set up your personal profile, form relationships, send messages, perform searches and queries, form groups, set up events, add applications, and transmit information through various channels. We collect this information so that we can provide you the service and offer personalised features."

2 You can't delete anything

"When you update information, we usually keep a backup copy of the prior version for a reasonable period of time to enable reversion to the prior version of that information."

3 Anyone can glance at your intimate confessions

"... we cannot and do not guarantee that user content you post on the site will not be viewed by unauthorised persons. We are not responsible for circumvention of any privacy settings or security measures contained on the site. You understand and acknowledge that, even after removal, copies of user content may remain viewable in cached and archived pages or if other users have copied or stored your user content."

4 Our marketing profile of you will be unbeatable

"Facebook may also collect information about you from other sources, such as newspapers, blogs, instant messaging services, and other users of the Facebook service through the operation of the service (eg, photo tags) in order to provide you with more useful information and a more personalised experience."

5 Opting out doesn't mean opting out

"Facebook reserves the right to send you notices about your account even if you opt out of all voluntary email notifications."

6 The CIA may look at the stuff when they feel like it

"By using Facebook, you are consenting to have your personal data transferred to and processed in the United States ... We may be required to disclose user information pursuant to lawful requests, such as subpoenas or court orders, or in compliance with applicable laws. We do not reveal information until we have a good faith belief that an information request by law enforcement or private litigants meets applicable legal standards. Additionally, we may share account or other information when we believe it is necessary to comply with law, to protect our interests or property, to prevent fraud or other illegal activity perpetrated through the Facebook service or using the Facebook name, or to prevent imminent bodily harm. This may include sharing information with other companies, lawyers, agents or government agencies."

Source: http://www.guardian.co.uk/technology/2008/jan/14/facebook

Saturday, January 16, 2010

Network flaw causes scary Web error

Alarming network glitch makes the Internet lose track of who is who on Facebook

SAN FRANCISCO (AP) -- A Georgia mother and her two daughters logged onto Facebook from mobile phones last weekend and wound up in a startling place: strangers' accounts with full access to troves of private information.

The glitch -- the result of a routing problem at the family's wireless carrier, AT&T -- revealed a little known security flaw with far reaching implications for everyone on the Internet, not just Facebook users.

In each case, the Internet lost track of who was who, putting the women into the wrong accounts. It doesn't appear the users could have done anything to stop it. The problem adds a dimension to researchers' warnings that there are many ways online information -- from mundane data to dark secrets -- can go awry.

Several security experts said they had not heard of a case like this, in which the wrong person was shown a Web page whose user name and password had been entered by someone else. It's not clear whether such episodes are rare or simply not reported. But experts said such flaws could occur on e-mail services, for instance, and that something similar could happen on a PC, not just a phone.

"The fact that it did happen is proof that it could potentially happen again and with something a lot more important than Facebook," said Nathan Hamiel, founder of the Hexagon Security Group, a research organization.

Candace Sawyer, 26, says she immediately suspected something was wrong when she tried to visit her Facebook page Saturday morning.

After typing Facebook.com into her Nokia smart phone, she was taken into the site without being asked for her user name or password. She was in an account that didn't look like hers. She had fewer friend requests than she remembered. Then she found a picture of the page's owner.

"He's white -- I'm not," she said with a laugh.

Sawyer logged off and asked her sister, Mari, 31, her partner in a dessert catering company, and their mother, Fran, 57, to see whether they had the same problem on their phones.

Mari landed inside another woman's page.

Fran's phone -- which had never been used to access Facebook before -- took her inside yet another stranger's page, one belonging to a young woman from Indiana. They sent an e-mail to one of their own accounts to prove it.

They were dumbfounded.

"I thought it was the phone -- `Maybe this phone is just weird and does magical, horrible things and I have to get rid of it,'" said Candace Sawyer.

The women, who live together in East Point, Ga., outside Atlanta, had recently upgraded to the same model of phone and all used the same carrier, AT&T.

Sawyer contacted The Associated Press after reporting the problem to Facebook and AT&T.

The problem wasn't in the phones. It was a flaw in the infrastructure connecting the phones to the Internet.

That illuminates a grave problem.

Generally Web sites and computers are compromised from within. A hacker can get a Web page or computers to run programming code that they shouldn't. But in this case, it was a security gap between the phone and the Web site that exposed strangers' Facebook pages to the Sawyers. Misconfigured equipment, poorly written network software or other technical errors could have caused AT&T to fumble the information flowing from the Sawyers' phones to Facebook and back.

Fortunately, Hamiel said, the vulnerability would be of limited use to a hacker interested in pulling off widespread mayhem, because this hole would let him access only one account at a time. To do more damage the criminal would have to pull off the unlikely feat of gaining full control of the piece of equipment that routes Internet traffic to individual users.

AT&T spokesman Michael Coe said its wireless customers have landed in the wrong Facebook pages in "a limited number of instances" and that a network problem behind those episodes is being fixed.

The Sawyers experienced a different glitch. Coe said an investigation points to a "misdirected cookie." A cookie is a file some Web sites place on computers to store identifying information -- including the user name that Facebook members would enter to access their pages. Coe said technicians couldn't figure out how the cookie had been routed to the wrong phone, leading it into the wrong Facebook account.

He also said AT&T could confirm only that the problem occurred on one of the Sawyers' phones, possibly because they had logged off Facebook on the other two before reporting the incident.

Facebook declined to comment and referred questions to AT&T.

Some Web sites would be immune from this kind of mix-up, particularly those that use encryption. A Web browser would have trouble deciphering the encryption on a page that a computer user didn't actually seek, said Chris Wysopal, co-founder of Veracode Inc., a security company.

Sensitive sites and those used for banking and e-commerce generally use encryption. But most other sites, including some Web-based e-mail services, don't use it. One way of checking: The Web addresses of encrypted sites begin with "https" rather than "http." Facebook uses encryption when user names and passwords are entered, to cloak the sign-on from snoops, but after the credentials are entered the encryption is dropped.

It's unclear how many people were affected by the problem the Sawyers discovered, and whether it was limited to Facebook.

The reason all three women experienced the glitch is a function of the way cellular networks are designed. In some cases, all the mobile Internet traffic for a particular area is routed through the same piece of networking equipment. If that piece of equipment is misbehaving or set up incorrectly, strange things happen when computers down the line receive the data.

Usually that means a Web site simply won't load, said Alberto Solino, director of security consulting services for Core Security Technologies. In the Sawyers' case, "somehow they got the wrong user but they could keep using that account for a long period of time. That's what's strange," he said.

The AP tried to contact two of the people whose Facebook pages were exposed to the Sawyers, but the calls and e-mails were not returned. It's unclear whether they are also AT&T customers, though security experts said that's likely the case.

Indeed, it was the case in a similar incident in November.

Stephen Simburg, 25, who works in marketing, was home for Thanksgiving in Vancouver, Wash., when he logged onto Facebook from his cell phone. He didn't recognize the people who had written him messages.

"I thought I had gotten really popular all of a sudden, or something was wrong," he said. Then he saw the picture of the account owner: A young woman.

He got her e-mail address from the site, logged off and wrote the woman a message. He asked whether he had met her at some point and she had borrowed his phone to check her Facebook account.

"No," she wrote back, "but I was just telling my family that I ended up in your profile!"

Simburg and the woman figured out they were both using AT&T to access Facebook on their phones. (AT&T had no comment because the incident wasn't reported to the company.)

"I felt like I had been let down by the phone company and by Facebook," he said.

He says he has put the incident behind him. But one piece of it remains: He and the young woman are now Facebook friends.

Source: http://finance.yahoo.com/news/AP-Exclusive-Network-flaw-apf-3043392874.html?x=0

Wednesday, April 30, 2008

Italian tax details posted on web

Privacy watchdogs have ordered the Italian authorities to block access to every Italian's personal tax details.

This comes after they were published on the internet and made available for almost 24 hours.

The move to release the information was one of the last acts of the outgoing centre-left government - and has shocked many tax-shy Italians.

Without warning, the tax authority posted on its website every tax payer's declared earnings and tax paid.

With just a couple of mouse clicks Italians were able to see just how much their favourite footballer, TV star or singer earned and paid in tax.

The idea was also an open invitation to nosey neighbours, making it just as simple to see how much the couple next door earned, or how much your local doctor or priest paid in tax.

The site proved a massive hit. Within hours it was overwhelmed and impossible to reach.

The finance ministry described the move as a bid to improve transparency. Critics condemned it as an outrageous breach of privacy.

The timing of the move, just days before the current administration hands over to Silvio Berlusconi, was intriguing too.

The outgoing government came to power promising to tackle Italians' notoriously lax approach to paying tax - prompting some sceptics to see the move as just end of term sour grapes.

Mr Prodi's coalition cracked down on tax evasion


Source: http://news.bbc.co.uk/2/hi/europe/7376608.stm

Wednesday, April 16, 2008

Feds to collect DNA from every person they arrest

By EILEEN SULLIVAN, Associated Press Writer
Wed Apr 16, 7:39 PM ET


WASHINGTON - The government plans to begin collecting DNA samples from anyone arrested by a federal law enforcement agency — a move intended to prevent violent crime but which also is raising concerns about the privacy of innocent people.

Using authority granted by Congress, the government also plans to collect DNA samples from foreigners who are detained, whether they have been charged or not. The DNA would be collected through a cheek swab, Justice Department spokesman Erik Ablin said Wednesday. That would be a departure from current practice, which limits DNA collection to convicted felons.

Expanding the DNA database, known as CODIS, raises civil liberties questions about the potential for misuse of such personal information, such as family ties and genetic conditions.

Ablin said the DNA collection would be subject to the same privacy laws applied to current DNA sampling. That means none of it would be used for identifying genetic traits, diseases or disorders.

Congress gave the Justice Department the authority to expand DNA collection in two different laws passed in 2005 and 2006.

There are dozens of federal law enforcement agencies, ranging from the FBI to the Library of Congress Police. The federal government estimates it makes about 140,000 arrests each year.

Justice officials estimate the new collecting requirements would add DNA from an additional 1.2 million people to the database each year.

Those who support the expanded collection believe that DNA sampling could get violent criminals off the streets and prevent them from committing more crimes.

A Chicago study in 2005 found that 53 murders and rapes could have been prevented if a DNA sample had been collected upon arrest.

"Many innocent lives could have been saved had the government began this kind of DNA sampling in the 1990s when the technology to do so first became available," Sen. Jon Kyl, R-Ariz., said. Kyl sponsored the 2005 law that gave the Justice Department this authority.

Thirteen states have similar laws: Alaska, Arizona, California, Kansas, Louisiana, Maryland, Minnesota, New Mexico, North Dakota, South Dakota, Tennessee, Texas and Virginia.

The new regulation would mean that the federal government could store DNA samples of people who are not guilty of any crime, said Jesselyn McCurdy, legislative counsel for the American Civil Liberties Union.

"Now innocent people's DNA will be put into this huge CODIS database, and it will be very difficult for them to get it out if they are not charged or convicted of a crime," McCurdy said.

If a person is arrested but not convicted, he or she can ask the Justice Department to destroy the sample.

The Homeland Security Department — the federal agency charged with policing immigration — supports the new rule.

"DNA is a proven law-enforcement tool," DHS spokesman Russ Knocke said.

The rule would not allow for DNA samples to be collected from immigrants who are legally in the United States or those being processed for admission, unless the person was arrested.

The proposed rule is being published in the Federal Register. That will be followed by a 30-day comment period.

Source: http://news.yahoo.com/s/ap/20080416/ap_on_go_ca_st_pe/dna_collection