<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Richard&#039;s Kingdom &#187; privacy</title>
	<atom:link href="http://www.richardskingdom.net/category/privacy/feed" rel="self" type="application/rss+xml" />
	<link>http://www.richardskingdom.net</link>
	<description>Privacy, security and politics in the digital era</description>
	<lastBuildDate>Wed, 07 Jul 2010 11:35:09 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Europe mulls search-term surveillance</title>
		<link>http://www.richardskingdom.net/europe-mulls-search-term-surveillance</link>
		<comments>http://www.richardskingdom.net/europe-mulls-search-term-surveillance#comments</comments>
		<pubDate>Thu, 03 Jun 2010 12:25:50 +0000</pubDate>
		<dc:creator>Richard King</dc:creator>
				<category><![CDATA[privacy]]></category>
		<category><![CDATA[dataretention]]></category>
		<category><![CDATA[digitalrights]]></category>
		<category><![CDATA[eu]]></category>
		<category><![CDATA[europe]]></category>
		<category><![CDATA[internet]]></category>
		<category><![CDATA[letter]]></category>
		<category><![CDATA[politics]]></category>
		<category><![CDATA[search]]></category>
		<category><![CDATA[surveillance]]></category>
		<category><![CDATA[thinkofthechildren]]></category>

		<guid isPermaLink="false">http://www.richardskingdom.net/?p=366</guid>
		<description><![CDATA[Europe wants to monitor what you search for on the Internet. Under the misleading guise of protecting children against sexual abuse (sigh) Written Declaration 29 calls for the Data Retention Directive to be extended to cover search engines. This would force national Governments to record everything you type into Google, Bing, Yahoo! et al and [...]]]></description>
			<content:encoded><![CDATA[<p><span class="drop">E</span>urope wants to monitor what you search for on the Internet. Under the misleading guise of protecting children against sexual abuse (<em>sigh</em>) Written Declaration 29 calls for the Data Retention Directive to be extended to cover search engines. This would force national Governments to record everything you type into Google, Bing, Yahoo! et al and store that information for years.</p>
<p>Your search terms are highly sensitive and very private. They are also <a href="http://en.wikipedia.org/wiki/AOL_search_data_scandal">uniquely identifiable</a>. Examining what you search for can <a href="http://www.eff.org/wp/six-tips-protect-your-search-privacy">reveal deeply personal facts about you</a>, such as your online reading habits, medical history, finances, sexual preferences and political affiliations.</p>
<p>A database of search terms, linked to subscriber accounts, would be a clear violation of the privacy rights of everyone who uses the Internet in Europe.</p>
<p>I&#8217;ve written to my MEPs urging them not to sign Written Declaration 29 and to withdraw their signature if they have already signed. You should do the same &#8211; it takes two minutes through <a href="http://www.writetothem.com/">writetothem.com</a></p>
<p>Here&#8217;s my letter (but, as always, please use your own words for maximum effect).</p>
<blockquote><p>
Dear Timothy Kirkhope, Edward McMillan-Scott, Andrew Brons, Godfrey Bloom, Diana Wallis and Linda McAvan,</p>
<p><a href="http://smile29.eu/doc/DS29_EN.pdf">Written declaration 29</a> [pdf] calls on the European Commission to extend the <a href="http://eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=CELEX:32006L0024:EN:HTML">data retention directive (2006/24/EC)</a> to Internet search-engines. If this were to happen all private searches done on Google et al would be monitored. I feel this would be an intolerable violation of <a href="http://www.hri.org/docs/ECHR50.html#C.Art8">article 8 ECHR</a> privacy rights.</p>
<p>Written declaration 29 is being marketed within the European Parliament by using an <a href="http://smile29.eu/">emotionally-loaded picture of a child</a> and talking about the need to set up an ”early warning system” to combat child abuse. Laudable though that aim is, as a technical expert it&#8217;s my opinion that these measures cannot achieve it, and the marketing is therefore misleading. Some MEPs have already said they feel they have been <a href="http://dekaminski.se/2010/06/den-luriga-eu-politiken-om-smile-29-och-nataktivism/#mepletter">misled into signing the declaration</a> because of the way in which it was presented to them.</p>
<p>If the declaration is adopted the names of the signatories will be made public.</p>
<p>If you have signed written declaration 29 and feel you have been misled I urge you to withdraw your signature.</p>
<p><a href="http://christianengstrom.wordpress.com/2010/06/02/urging-meps-to-withdraw-their-written-declaration-29-signatures/">Christian Engström MEP has published more information on his website.</a>
</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.richardskingdom.net/europe-mulls-search-term-surveillance/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>We must defend civil liberties at this election</title>
		<link>http://www.richardskingdom.net/we-must-defend-civil-liberties-at-this-election</link>
		<comments>http://www.richardskingdom.net/we-must-defend-civil-liberties-at-this-election#comments</comments>
		<pubDate>Thu, 15 Apr 2010 07:45:43 +0000</pubDate>
		<dc:creator>Richard King</dc:creator>
				<category><![CDATA[politics]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[cctv]]></category>
		<category><![CDATA[contactpoint]]></category>
		<category><![CDATA[crime]]></category>
		<category><![CDATA[foi]]></category>
		<category><![CDATA[freedom]]></category>
		<category><![CDATA[ge2010]]></category>
		<category><![CDATA[government]]></category>
		<category><![CDATA[idcards]]></category>
		<category><![CDATA[isa]]></category>
		<category><![CDATA[letter]]></category>
		<category><![CDATA[liberty]]></category>
		<category><![CDATA[ndnad]]></category>
		<category><![CDATA[no2id]]></category>
		<category><![CDATA[ripa]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[sheffield]]></category>
		<category><![CDATA[surveillance]]></category>
		<category><![CDATA[thinkofthechildren]]></category>
		<category><![CDATA[uk]]></category>

		<guid isPermaLink="false">http://www.richardskingdom.net/?p=338</guid>
		<description><![CDATA[Over the last two parliaments the British state has grown ever more authoritarian. Personal liberty has been sacrificed on the altar of public opinion for political ends. The false dichotomy of privacy versus security has been used repeatedly to justify robbing us of the former while failing to deliver the latter. Billions of pounds have [...]]]></description>
			<content:encoded><![CDATA[<p><span class="drop">O</span>ver the last two parliaments the British state has grown ever more authoritarian. Personal liberty has been sacrificed on the altar of public opinion for political ends. The <a href="http://www.schneier.com/blog/archives/2008/01/security_vs_pri.html">false dichotomy of privacy versus security</a> has been used repeatedly to justify robbing us of the former while failing to deliver the latter. Billions of pounds have been wasted on <a href="http://en.wikipedia.org/wiki/Security_theater">security theatre</a> yet we are no more secure. Meanwhile the Government claims we are as threatened today &#8211; if not more so &#8211; than it claimed nine years ago.</p>
<p>British civil liberties have been dismantled systematically since 2001. The <a href="http://www.richardskingdom.net/tag/no2id">National Identity Register</a>, <a href="http://www.richardskingdom.net/renew-your-passport-resist-compulsory-id-card-registration">biometric passports</a>, the <a href="http://www.thebigoptout.com/">NHS spine</a>, <a href="http://www.richardskingdom.net/british-children-have-nothing-to-hide-everything-to-fear">Contactpoint</a> and the <a href="http://www.telegraph.co.uk/comment/6179983/Why-the-Vetting-and-Barring-Scheme-is-pure-madness.html">Vetting and Barring Scheme</a> are just a few of the most egregious privacy invasions we have suffered.</p>
<p>Our every move is watched with suspicion by the authorities. <a href="http://www.richardskingdom.net/follow-every-car-the-anpr-privacy-threat-to-uk-drivers">ANPR</a> systems record every journey we make. Video and audio <a href="http://www.richardskingdom.net/uk-cctv-is-out-of-control-and-must-be-stopped">Surveillance Systems</a> (SS) watch us in every public space and many <a href="http://www.richardskingdom.net/school-fits-cctv-in-toilets">private ones</a> too. Thousands of public bodies <a href="http://www.richardskingdom.net/clouseau-councils-abuse-ripa-surveillance-powers">abuse their RIP Act powers</a> to spy on us for trivial reasons. The police can <a href="http://www.guardian.co.uk/world/2010/jan/12/stop-and-search-ruled-illegal">stop us and search us arbitrarily</a>, and they keep <a href="http://www.richardskingdom.net/uk-dna-abuse-to-continue-despite-eu-ruling">&#8220;pre-crime&#8221; databases on the innocent</a>. Our private communications are <a href="http://www.richardskingdom.net/mass-surveillance-is-neither-intelligence-nor-intelligent">monitored, analysed and recorded</a> both by the Government and <a href="https://nodpi.org/">private companies</a>.</p>
<p>Yet often MPs want one rule for us and another for them. The children of MPs can be &#8220;shielded&#8221; on ContactPoint to protect their privacy &#8211; but ours can&#8217;t. Very few MPs have an ID card even though ministers have been doing everything in their power to coerce the public into &#8220;volunteering&#8221; for them. Many MPs <a href="http://www.richardskingdom.net/stop-the-parliamentary-freedom-of-information-cover-up">voted to exempt themselves from the Freedom of Information Act</a>, to protect their &#8220;privacy&#8221;, whilst passing laws that erode ours.</p>
<p>When it comes to liberty in Britain today, all animals are equal, but some are more equal than others. This hypocrisy has to end and the systematic assault on our civil liberties must be reversed.</p>
<hr />
<p>The <a href="http://www.power2010.org.uk/home">Power2010</a> campaign is conducting a letter writing campaign asking Prospective Parliamentary Candidates to:</p>
<blockquote><p>&#8230;commit that, if you are elected, you will vote to repeal the Identity Cards Act 2006 and will defend our privacy as fiercely as you would defend your own and that of your family.</p></blockquote>
<p>The above reproduces what I sent to Sheffield Central PPCs. You can <a href="http://www.power2010.org.uk/page/speakout/hypocrisy">take part in the campaign here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.richardskingdom.net/we-must-defend-civil-liberties-at-this-election/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Follow every car! The ANPR privacy threat to UK drivers</title>
		<link>http://www.richardskingdom.net/follow-every-car-the-anpr-privacy-threat-to-uk-drivers</link>
		<comments>http://www.richardskingdom.net/follow-every-car-the-anpr-privacy-threat-to-uk-drivers#comments</comments>
		<pubDate>Mon, 08 Feb 2010 13:42:39 +0000</pubDate>
		<dc:creator>Richard King</dc:creator>
				<category><![CDATA[privacy]]></category>
		<category><![CDATA[technology]]></category>
		<category><![CDATA[acpo]]></category>
		<category><![CDATA[anpr]]></category>
		<category><![CDATA[cctv]]></category>
		<category><![CDATA[crime]]></category>
		<category><![CDATA[ico]]></category>
		<category><![CDATA[NADC]]></category>
		<category><![CDATA[NPIA]]></category>
		<category><![CDATA[panopticon]]></category>
		<category><![CDATA[police]]></category>
		<category><![CDATA[surveillance]]></category>
		<category><![CDATA[uk]]></category>

		<guid isPermaLink="false">http://www.richardskingdom.net/?p=280</guid>
		<description><![CDATA[There are now over 10,000 Automatic Number Plate Recognition (ANPR) cameras covering the UK road network. These are capable of recording, recognising and tracking your car by its numberplate. The data from the cameras is collated and stored at a national centre run on behalf of the private, profit-making company ACPO, where it is held [...]]]></description>
			<content:encoded><![CDATA[<p><span class="drop">T</span>here are now over <a href="http://www.kable.co.uk/automatic-numberplate-recognition-police-anpr-gc-feb10">10,000 Automatic Number Plate Recognition (ANPR) cameras</a> covering the UK road network. These are capable of recording, recognising and tracking your car by its numberplate. The data from the cameras is collated and stored at a national centre run on behalf of the private, <a href="http://www.telegraph.co.uk/news/newstopics/politics/lawandorder/4631631/ACPO-makes-18m-from-criminal-records-checks.html">profit-making</a> company ACPO, where it is held for at least two years. In some cases a detailed image of the driver and front-seat passenger is retained along with license plate information.</p>
<p>Mobile ANPR cameras are also used by some police forces. These are deployed in popular locations such as shopping centres for so-called &#8220;lockdown&#8221; operations, where every vehicle entering the area is checked against records as police fish for reasons to impound cars and fine drivers. One such operation in November 2008, <a href="http://demand.five.tv/Episode.aspx?episodeBaseName=C5141380012">which was filmed for television</a> (relevant segment starts at 21m30s), saw 369 vehicles stopped, 84 tickets issued, 51 cars seized and 12 people arrested at Bluewater shopping centre in Kent &#8211; in a single day.</p>
<p>It&#8217;s no longer a case of &#8220;follow that car&#8221; but &#8220;follow every car.&#8221;</p>
<p>ACPO defend their wholesale surveillance system by pointing to a few high-profile cases where ANPR evidence has formed part of a prosecution. They&#8217;re less keen to highlight the cases of mistaken identity, inaccurate record-keeping and official ineptitude that have left innocent people standing on the kerbside holding a ticket as an officer drives away in their vehicle. Even if these drivers manage to prove the database wrong they can end up <a href="http://www.thestar.co.uk/news/Mum39s-150-bill--to.6054206.jp">paying hundreds of pounds in fees to get their car back</a> &#8211; if it hasn&#8217;t been crushed.</p>
<p>Supporters of ANPR technology claim vehicle license-plate data is exempt from the Data Protection Act because it&#8217;s not &#8220;personal information&#8221; (it&#8217;s about the vehicle not the driver). However the Driver and Vehicle Licensing Agency (DVLA) sells access to the names and addresses of registered vehicle-keepers for £2.50p a time, making this distinction academic.</p>
<p>In common with the National Identity Register, National DNA Database and all the other tentacles of the database state, once this information is collected there&#8217;s nothing to stop it falling into the hands of other public or private organisations, either by accident, commercial arrangement or official decree. Wouldn&#8217;t you like to know where your partner <em>really</em> drives off to while you&#8217;re at work? I bet there&#8217;s a good number of private investigators who would.</p>
<p>The Information Commissioner&#8217;s Office is currently &#8220;working with&#8221; ACPO to determine whether the national ANPR network is &#8220;appropriate and proportionate&#8221; &#8211; which means nobody bothered to ask those questions before the system was commissioned.</p>
<p>Who stands up for the public interest in the rush to implement new technologies like ANPR for official convenience? I don&#8217;t recall there being a public or Parliamentary debate on giving the police these game-changing surveillance powers. Has anyone considered the down-side of collecting all this data?</p>
<p>Somehow I doubt it.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.richardskingdom.net/follow-every-car-the-anpr-privacy-threat-to-uk-drivers/feed</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Bruce Schneier on the Future of Privacy</title>
		<link>http://www.richardskingdom.net/bruce-schneier-on-the-future-of-privacy</link>
		<comments>http://www.richardskingdom.net/bruce-schneier-on-the-future-of-privacy#comments</comments>
		<pubDate>Tue, 08 Dec 2009 11:15:12 +0000</pubDate>
		<dc:creator>Richard King</dc:creator>
				<category><![CDATA[privacy]]></category>
		<category><![CDATA[control]]></category>
		<category><![CDATA[digitalrights]]></category>
		<category><![CDATA[government]]></category>
		<category><![CDATA[identity]]></category>
		<category><![CDATA[liberty]]></category>
		<category><![CDATA[openrightsgroup]]></category>
		<category><![CDATA[schneier]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[surveillance]]></category>
		<category><![CDATA[technology]]></category>

		<guid isPermaLink="false">http://www.richardskingdom.net/?p=255</guid>
		<description><![CDATA[Last Friday I travelled to London to see a talk by security visionary and cryptographer Bruce Schneier. The event was a fund-raiser for the Open Rights Group, and was chaired by its Executive Director, Jim Killock. His was not a demanding role. The capacity crowd of disciples, many of whom were also ORG supporters, needed [...]]]></description>
			<content:encoded><![CDATA[<p><span class="drop">L</span>ast Friday I travelled to London to see a talk by security visionary and cryptographer <a href="http://www.schneier.com/">Bruce Schneier</a>. The event was a fund-raiser for the <a href="http://www.openrightsgroup.org/">Open Rights Group</a>, and was chaired by its Executive Director, Jim Killock. His was not a demanding role. The capacity crowd of disciples, many of whom were also ORG supporters, needed no introduction to Schneier or his work. Personally, I&#8217;m an admirer of his thinking, and have been known to <a href="http://www.richardskingdom.net/tag/schneier">quote him</a> on this blog.</p>
<p>The title of the talk was &#8220;The Future of Privacy&#8221; and Schneier&#8217;s treatment of his topic was comprehensive. He started by listing some technologies and practices that can threaten our privacy: overt <a href="http://www.richardskingdom.net/tag/cctv">surveillance systems</a>; <a href="http://www.richardskingdom.net/shops-secretly-track-customers-via-mobile-phone">mobile phones</a>, <a href="http://en.wikipedia.org/wiki/Rfid#Problems_and_concerns">RFID tags</a> and the like that produce personal information as a byproduct; automatic identification technologies such as <a href="http://en.wikipedia.org/wiki/ANPR">ANPR</a>; and unique identifiers in gadgets such as <a href="http://en.wikipedia.org/wiki/Exchangeable_image_file_format#Problems">digital cameras</a> or <a href="http://en.wikipedia.org/wiki/Printer_steganography">colour laser-printers</a>.</p>
<p>Schneier reminded us of his famous saying, that just as greenhouse gasses are the polution of the industrial age, data is the polution of the information age. Data is generated when we <a href="http://www.visaeurope.com/business/reporting/main.jsp">transact business</a>, swipe our <a href="http://www.dunnhumby.com/">loyalty cards</a>, use a <a href="http://www.tfl.gov.uk/tickets/oysteronline/2732.aspx">travel card</a> or drive through an <a href="http://en.wikipedia.org/wiki/Toll_road#Toll_collection_technology">automatic toll-booth</a>. We give it away when we socialise by email, instant messenger and <a href="http://www.richardskingdom.net/facebook-terms-of-service-all-your-content-are-belong-to-us">Facebook</a>. Sometimes other people release data about us &#8211; possibly without our consent. As the cost of processing and storing all this information falls to zero even data of marginal value becomes worth keeping. In fact it&#8217;s often cheaper to keep everything than to decide what should be deleted! Data that was ephemeral 20 years ago is now stored.</p>
<p>In the information society most data about us isn&#8217;t controlled by us. In the US, laws protect the data that is under our control, but in the information society it tends not to be. Our Gmail, phone records, medical records, financial transactions and photos of us on Facebook are all controlled by someone else. <a href="http://ec.europa.eu/justice_home/fsj/privacy/index_en.htm">EU law</a> is substantially better in this area but it could still be improved.</p>
<p>Such a wealth of data enables new forms of surveillance. For example, surveillance can now occur backwards in time. This was done in London after the 7/7 bombings &#8211; the people responsible, and the route they took on the day, were <a href="http://en.wikipedia.org/wiki/7_July_2005_London_bombings#The_bombers">identified after the fact from surveillance-system footage</a>. Pervasive data collection also enables wholesale surveillance &#8211; not &#8220;follow that car&#8221; but &#8220;<a href="http://www.sheffieldforum.co.uk/showthread.php?t=475503">follow every car</a>.&#8221;</p>
<p>What will be the privacy impact of our society&#8217;s continuing technological advancement?</p>
<p>Schneier believes a step change is coming. We live in a unique time: cameras are everywhere AND we can see them; identity checks happen all the time AND we know they&#8217;re happening. However technology is a great distrupter of equilibriums and <a href="http://en.wikipedia.org/wiki/Moore%27s_law">Moore&#8217;s law</a> is a friend of intrusive tools. Soon face-recognition software will obviate the need to carry ID &#8211; when you walk into your workplace they&#8217;ll already know who you are and whether you&#8217;re supposed to be there.</p>
<p>New invasive technologies will emerge and become pervasive: digital video surveillance with <a href="http://en.wikipedia.org/wiki/Facial_recognition_system">automatic face recognition</a>; networked cameras that can track people through a city automatically; better tracking of our personal devices through their radio signatures or RFID tags; better quality images from cameras. Our era will herald the death of ephemeral conversation. Soon everything we say and do will be on the record. We could try to reject these technologies, but once general adoption occurs, opting out starts to look suspicious. In some cases the authorities have <a href="http://einstellung.so36.net/en/openletter">already</a> <a href="http://www.guardian.co.uk/world/2009/jan/03/france-terrorism-tarnac-anarchists">argued</a> that, &#8220;They left their mobile phone at home, which shows they didn&#8217;t want anyone to know where they were going.&#8221;</p>
<p>What can we do about these threats to our privacy?</p>
<p>Schneier doesn&#8217;t believe we can engineer our way back to a more private world. Privacy-enhancing technologies already exist and they could go a long way towards retoring the balance if they gained widespread adoption. However people are seduced by convenience so they tend to make <a href="http://www.richardskingdom.net/whither-social-networking-facebook-folds-over-controversial-conditions">bad privacy trade-offs</a>. We&#8217;re on Facebook because our friends are, and while we&#8217;re chatting to them we&#8217;re focused on the conversation, not on how much data we&#8217;re releasing or to whom.</p>
<p>A lot can be done by paying attention to the default settings of software and systems. Most of us won&#8217;t change these so if they are secure from the outset any loss of privacy will be minimised. However companies like Facebook make more money the more public we make our data so there&#8217;s no incentive for them to set privacy-enhancing defaults.</p>
<p>We need to press for legislation that protects privacy: comprehensive laws regulating what can be done with personal information about us and more privacy protection from the police. However the law finds it difficult to keep up with the pace of technological change.</p>
<p>We also need to start talking about the value of privacy. We want it as a social good. Individual privacy protects us from those in power and it&#8217;s also a fundamental human need. Privacy is a part of dignity.</p>
<p>Schneier rejects the security versus privacy notion as a false dichotomy. Only identity-based security reduces privacy and the effectiveness of this is limited. Physical security measures such as locks and burglar alarms don&#8217;t reduce privacy. Nor does knowing that you might have to <a href="http://en.wikipedia.org/wiki/United_Airlines_Flight_93#Revolt">fight back if terrorists hijack your flight</a>. We don&#8217;t need to know who&#8217;s sat next to us on an aeroplane &#8211; we just need to know know whether they&#8217;re planning to blow it up! However checking intent is difficult so we check identity instead and pretend that&#8217;s the same thing.</p>
<p>Privacy and openness have different effects on Governments and citizens. Government secrecy increases its power whereas transparency and openness reduces it. Conversely, forced openness in people increases the inbalance in power between them and the state, yet <a href="http://www.opsi.gov.uk/Acts/acts2000/ukpga_20000036_en_1">forced openness in Government</a> reduces the gap. The balance we need to strike is between liberty and control not privacy and security. Real security comes from having both liberty and privacy.</p>
<p>The above notwithstanding, sometimes we are forced to trade between security and privacy, for example when we give the police the power to search our homes. In such cases we can maintain the balance of power through audit and oversight. Search warrants are a security measure that restrict police searches to only those cases where a magistrate &#8211; an impartial advocate for the suspect &#8211; can be convinced there are reasonable grounds for suspicion.</p>
<p>Schneier concluded that the death of privacy is over-stated. Left unregulated and unconstrained, technology tends to tip the balance of our society against individual privacy, however it doesn&#8217;t make the balancing act go away. Society can choose to deliberately reset the balance with legislation.</p>
<p>We may ultimately have to wait for a new generation of digitally-savvy lawmakers to take office before the the future of privacy can be guaranteed in the information age.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.richardskingdom.net/bruce-schneier-on-the-future-of-privacy/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>UPDATED: Could cracked ID cards provide privacy protection?</title>
		<link>http://www.richardskingdom.net/could-cracked-id-cards-provide-privacy-protection</link>
		<comments>http://www.richardskingdom.net/could-cracked-id-cards-provide-privacy-protection#comments</comments>
		<pubDate>Fri, 07 Aug 2009 14:19:37 +0000</pubDate>
		<dc:creator>Richard King</dc:creator>
				<category><![CDATA[privacy]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[homeoffice]]></category>
		<category><![CDATA[idcards]]></category>
		<category><![CDATA[identity]]></category>
		<category><![CDATA[no2id]]></category>
		<category><![CDATA[technology]]></category>
		<category><![CDATA[uk]]></category>

		<guid isPermaLink="false">http://www.richardskingdom.net/?p=208</guid>
		<description><![CDATA[The UK National Identity Card can be cloned and altered by IT security experts.
Colour me unsurprised.
The consultants who carried out this work are from the same community of experts who have been warning [pdf] that the cards would be cracked since the Home Office first disclosed the mechanics of the scheme.
The alterations can be detected [...]]]></description>
			<content:encoded><![CDATA[<p><span class="drop">T</span>he UK National Identity Card can be <a href="http://www.dailymail.co.uk/news/article-1204641/New-ID-cards-supposed-unforgeable--took-expert-12-minutes-clone-programme-false-data.html#">cloned and altered</a> by IT security experts.</p>
<p>Colour me unsurprised.</p>
<p>The consultants who carried out this work are from the same community of experts who have been <a href="http://www.publications.parliament.uk/pa/ld/lduncorr/s&#038;tii170107.pdf">warning [pdf]</a> that the cards would be cracked since the Home Office first disclosed the mechanics of the scheme.</p>
<p>The alterations can be detected with a check against the National Identity Register (assuming this hasn&#8217;t also been compromised) however each such look-up will cost around £2. The Government expects the majority of transactions will be authorised through local checks rather than referring back to the central database.</p>
<p>Once someone automates the attack and publishes their code on the Internet, anyone with half a brain, the right mobile phone and access to the world-wide web will be able to change their Government-issued identity at will. As the cards use RFID chips this could be done in seconds while on the move. You wouldn&#8217;t even have to remove your card from your wallet.</p>
<p>Disturbingly, your card could also be changed without your knowledge by someone standing close to you, or from dozens of feet away with the right sort of radio antenna hooked up to a portable computer. The process leaves no trace, so when your card is subsequently checked against the database and is found to have been modified, it will be impossible to determine when the changes were made or by whom.</p>
<p>Possessing a falsified ID card could land you with a fine and up to two years in gaol. Owning the equipment or software needed to make the changes could be enough to win you a decade-long stay at Her Majesty&#8217;s pleasure. <a href="http://www.opsi.gov.uk/acts/acts2006/ukpga_20060015_en_3#pb8-l1g25">[Identity Cards Act 2006 s25 and s29]</a>.</p>
<p>If it weren&#8217;t for these stiff penalties, I&#8217;d be tempted to suggest the ability to change the details on your own ID card is an unintended benefit of the scheme, not for the Government but for those who value their privacy.</p>
<p>The National Identity Register will store fifty different classes of information about you in a collection of linked databases. The Transformational Government project (also known as the Database State initiative) plans to share all of this information with any official who cares to look. This is the antithesis of the &#8220;least privilege&#8221; security principal: that people should be given access to just enough sensitive information to do their job, but no more. For example you may wish to tell your doctor about your medical history but not about your bank balance or speeding fines. The ID card scheme wrests from you control over your personal information and gives it to the state: it will not be possible for individuals to choose which &#8220;registrable facts&#8221; about them are made available to whom.</p>
<p>It would be possible to regain some of this control, however, if we were able to change at will the details stored on our own ID cards. Facts that we are not willing to share could be either falsified, replaced with nonsense or erased. A mobile phone &#8220;identity management&#8221; application could be written to store multiple personality profiles for your ID card. Using this, you could switch between personae as the need arises, perhaps even employing your phone&#8217;s in-built GPS chip to make sure the &#8220;Mr. Smith&#8221; profile is on the card when you&#8217;re at the Doctor&#8217;s surgery and the &#8220;Mr. Jones&#8221; profile is active when visiting your bank. Being able to compartmentalise your relationships with third parties in this way would be a very strong personal privacy measure.</p>
<p>Yep, that&#8217;s right, I have just suggested committing fraud to regain some control over your identity in the event that you are made subject to the ID cards scheme. It&#8217;s a damning indictment of the relationship between UK citizens and the state that we should have cause to consider this at all. It&#8217;s a more damning indictment of the Government&#8217;s competence and character that it chose to pursue this illiberal scheme despite strident warnings and opposition from just about everyone who knows anything about security and technology. &#8220;We told them so&#8221; brings cold comfort after so much money and freedom has been wasted.</p>
<p>As each nail in the coffin of the ID cards scheme is hammered home the true motivation of the Home Office in persuing such an abysmal farce becomes ever more clear. If the Government understood security and respected individual privacy they would allow each of us to choose how much personal information we want to reveal to others. Instead they are trying to assume control over our identity, to nationalise it in a register that is not only a gross violation of the right to a private life, but will also lock those who conform into a system of fines and a lifetime of administrative strife. All in the pursuit of the ultimate bureaucratic convenience.</p>
<p>The confirmation that ID cards are totally insecure is a mortal wound. If the Government doesn&#8217;t now scrap this benighted scheme then we must scrap this Government at the General Election.</p>
<p><strong>UPDATED 10/8/09 14:00 to add:</strong></p>
<p>The Home Office has apparently <a href="http://news.zdnet.co.uk/security/0,1000000189,39709652,00.htm">turned down repeated offers to demonstrate this breach by the researchers who discovered it</a>. A spokesperson said that the story was <a href="http://www.computerweekly.com/Articles/2009/08/07/237247/id-card-cannot-be-hacked-uk-government-claims-encryption-secrets.htm">rubbish</a>. The Home Office has published details of the encryption technologies used by ID cards scheme.</p>
<p>I&#8217;m disappointed, but not surprised, that the Home Office thinks security is a product which, if sprinkled liberally over a system in a manner similar to magic pixie dust, will somehow make it impervious to attack. It&#8217;s no good having &#8220;elliptic-curve cryptography&#8221; and &#8220;root certificates with RSA 4096-bit strength keys&#8221; if the system allows these things to be tampered with or circumvented.</p>
<p>Props to the Home Office spin department though: releasing the geeky details has distracted at least some of the press from holding them to account on the principles of the scheme.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.richardskingdom.net/could-cracked-id-cards-provide-privacy-protection/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>
<!-- WP Super Cache is installed but broken. The path to wp-cache-phase1.php in wp-content/advanced-cache.php must be fixed! -->