About Me

My photo
I have a burning need to know stuff and I love asking awkward questions.
Showing posts with label Privacy. Show all posts
Showing posts with label Privacy. Show all posts

Thursday, March 06, 2025

Just Finished Reading: Surveillance – A Very Short Introduction by David Lyon (FP: 2024) [127pp] 

Until very recently if a company wanted to spy on someone it would have to hire a private detective to physically keep an eye on them and follow them around to see what they did and who they met with. For governments around the world it was, of course, much easier using their much greater resources of police forces and the Secret Services, the reading of mail and the tapping of phonelines. But still it was both expensive and time consuming. If the object was a group of people the cost ballooned spectacularly. The idea of monitoring whole groups or, most ridiculously, the WHOLE population was a fantasy even within the most authoritarian governments. But then, as with much else, technology solved everything. Computers became powerful enough and sophisticated enough to monitor multiple phonelines simultaneously. Physical mail became electronic and MUCH easier to monitor. Websites logged exactly what people were doing and where they went next. Then came mobile phones and social media. Suddenly surveillance was everywhere and everyone began to feel that someone somewhere was keeping tabs on them – and they were right. 

Surveillance does certainly SEEM all pervasive these days, partially because it's at least partially true even in so-called free countries. CCTV cameras are ubiquitous and obvious (when you look for them) but they are not only ‘old tech’ but the very tip of the iceberg. Of course, the irony of today’s pervasive surveillance environment is that we do much of the work ourselves. Not only do we give copious amounts of personal data to companies for free – which they then sell on to others for a tidy profit – but many of us carry tracking devices (AKA our phones) around in our pockets and think nothing of it. On top of this we keep track of others – friends, celebrities – and even ourselves with fitness/health apps (which we then upload or share and the data is harvested and sold back to us). Our surveillance society didn’t just appear overnight and it wasn’t (mostly) imposed on us by evil others. WE built this and we choose to live here. 

Despite being rather dry and academic at times this was still an interesting and informative look at the surveillance world we have created in the last 30 years or so. I actually liked the fact that the author looked beyond the usual idea of governments spying on us (which they do of course) to show how companies (not just Facebook) do the same or more and especially how WE, that is everyone, is at least partially complicit in that surveillance. Although little here was a revelation, I think it did help me to partially reset or reframe some of my thinking on the subject. More to come on the subject and more VSI books too... 

Monday, April 20, 2020


Just Finished Reading: We Have Been Harmonised – Life in China’s Surveillance State by Kai Strittmatter (FP: 2019)

Imagine you’re walking home from a late night drinking session with friends. You’re still 10 minutes away from your apartment but you’re desperate for a pee. You look around. It’s 2am so the streets are empty and there’s a handy dark corner near some large bins. Seconds later you’re feeling much better and even begin to hum a tune to yourself. You phone beeps with an incoming text message. Maybe it’s from that girl you met tonight. You fish your phone out and look at your phone in horror. You’ve just been fined for your public urination and what’s more video of the act has been posted to screens located outside your apartment, the nearby bus stop you use to get to work and outside your office. As this puts you over the monthly limit your Internet connect has been throttled back to its minimum setting and your high-speed train ticket has been revoked so no visiting your parents this weekend. One getting home you discover a printed note taped to your door from the landlord. If you don’t get your Harmony Score up in the next 30 days you’ll be looking for somewhere else to live. Time to clean up your act.

Is this the future? No, it’s present day China – a society dedicated to bringing Harmony through Technology. The author who has lived in China on and off for decades outlines the lengths that the authorities will go to in order to make its citizens toe the line, and it’s a LONG way. Surveillance of the public space as well as online activities is ever present and growing every day. The technology, including the addition of increasingly powerful AI software, is becoming more accomplished as whole cities become testbeds and countries across the world are becoming interested in applying lessons in their countries too and China is more than happy to help. This pervasive and intrusive technology might help outsiders to understand how the Chinese authorities apparently controlled the recent outbreak of COVID-19 so quickly and so effectively. Contact tracing was easy as they already knew a great deal about people’s day to day contacts. Isolation was a breeze as the authorities arrived, immediately identified the people they had come for with facial recognition on their phones, and whisked them away into quarantine without so much as a murmur of protest. Clamping down on apartment blocks, streets or whole cities was as easy as pushing a button and watching a handful of monitor screens.


This was a scary enough read when you think about it happening in China but it gets scarier as you realise that not only are the Chinese exporting this technology freely across the globe but that our countries are looking at this way of ‘harmonising’ their citizens too – maybe not as forcefully, maybe not as openly – but you can see them salivating at the power it gives them. It’ll be sold, naturally, as a painless way of protecting you from crime, from terrorism, and protecting your children from predators and it will work. After all, if you’re doing nothing wrong you have nothing to fear, right? I’m sure that European Jews said the same thing to themselves in 1932….. Highly recommended if you can keep your paranoia in check. Much more on China to come.

Translated from the German by Ruth Martin     

Saturday, January 25, 2020

Twitter demands AI company stops 'collecting faces'

From The BBC

23 January 2020

Twitter has demanded an AI company stop taking images from its website. Clearview has already amassed more than three billion photographs from sites including Facebook and Twitter. They are used by the FBI and Department of Homeland Security and more than 600 other law-enforcement agencies around the world to identify suspects. In a cease-and-desist letter sent on Tuesday, Twitter said its policies had been violated and requested the deletion of any collected data.

Twitter's developer agreement policy says: "Information derived from Twitter content may not be used by, or knowingly displayed, distributed, or otherwise made available to any public-sector entity for surveillance purposes." According to the New York Times, the Clearview app includes programming that could pair the images with augmented-reality glasses that would allow users to identify the names and addresses of anyone they saw. Clearview has not yet responded to a request for comment.

US senator Ron Wyden said on Twitter Clearview's activities were "extremely troubling". "Americans have a right to know whether their personal photos are secretly being sucked into a private facial-recognition database," he said. "Every day, we witness a growing need for strong federal laws to protect privacy." Senator Edward J Markey also shared his concerns, in a letter sent to the company on Wednesday, suggesting its technology could "facilitate dangerous behaviours and effectively destroy individuals' ability to go about their lives anonymously". It follows suggestions the European Commission is considering a five-year ban on the use of facial recognition in public areas. Regulators want time to work out how to prevent the technology being abused. Concerns over the use of facial-recognition technology have grown recently, even in China, where the government continues to embrace its uses. Some 74% of Chinese respondents in a recent survey by the Beijing research institute said they wanted the option to be able to use traditional ID methods over the tech to verify their identity.

[Yet another reason not to be on Social Media… Or have your photograph taken….. Ever.]

Thursday, November 28, 2019


Just Finished Reading: Crypto – Secrecy and Privacy in the New Code War by Steven Levy (FP: 2000)

Everyone knew it was coming. It was inevitable as the sun raising over the Californian scrubland. With computer technology growing faster and more sophisticated each year it was only a matter of time before the electronic behemoths were linked together and started to exchange messages. Before long banks, commercial enterprises and others would want to transfer money, sign contracts and over services to their customers all electronically. Eventually some even believed that computers would become so ubiquitous that members of the public might even own them. When things go that far, decades in the future, it would already be too late to look for solutions. Such were needed now – before the obvious problems became too acute. How to you protect the privacy of electronic communications? How do you prevent fraud or theft during an electronic fund transfer? How do you authenticate a signature sent over the wire in 1’s and 0’s? How do you stop the government reading your electronic mail? The answer to all of these problems seemed deceptively simple – cryptography. The problem though was twofold: First, few outside the government knew very much about encryption and second, the government had very strong views indeed about anyone else just talking about encryption never mind developing and using it.

At the centre of everything was a US organisation that few had even heard of. The inside joke called it No Such Agency – the NSA: National Security Agency – who developed and broke codes. The world’s experts worked there and that was supposed to be the end of the story. But commercialisation was coming, interesting problems never to be solved and, not a small incentive, there was money to be made – lots of money. It started in academia with the invention and reinvention of cryptographic knowhow. The goal was to produce a widespread standard (later known as DES – Data Encryption Standard) that would be used in industry as well as government. It would be strong enough to ensure privacy but not too strong so as to be unbreakable by the NSA. But there was a catch. Encryption was classified as a munition and could not be exported outside the US without a licence – something it would never get if it was too strong. So while DES was fairly strong inside the US any export version was much weaker outside its borders. Within the cracker community growing up across American universities weak encryption was less than useless – it was in every sense a false security. If the government would not allow universities to develop strong encryption maybe tech savvy individuals could do it themselves. The gauntlet had been drop and a number of young practitioners were more than happy to pick it up. So began the NSA’s nightmare scenario – groups of intelligent, knowledgeable and politically aware mathematicians and cryptographers working hard to bring a new reality into existence where privacy reigned supreme and were anonymity was available at the push of a button. It was going to be quite a fight.

This is the fascinating story of how a small group of students and tech guru’s brought encryption out of the dark places and offered it (usually for a price) to the public to use how they wished and how the US government did everything it its power to stop them. Both sides talked in apocalyptic terms about bring the existing system of government to its knees. Unsurprisingly both sides were wrong but in the turmoil a new world order did emerge that we have both adapted to and had to learn to live with. Personal privacy also means criminal privacy. When encryption is hard (or impossible) to crack it’s not just the concerned citizen that resorts to its use but the criminal, the political and the terrorist. The freedom to speak our mind, to correspond in private, to live outside the scrutiny of our governments has a price. Freedom isn’t free (and never has been) but for the time being at least it can be exercised in secret. Highly recommended to anyone interested in privacy issues or the history of information technology. 

Saturday, November 23, 2019

Chaayos cafe: Indian cafe's facial recognition use sparks anger

From The BBC

22nd November 2019

Indians have expressed concern after it emerged that a popular cafe chain - Chaayos - is using facial recognition software to bill customers. Nikhil Pahwa, the editor of media watchdog MediaNama, posted a video on Twitter after he said staff took his picture to bill him without consent. "This is unnecessarily intrusive and there was no opt-out option, which is problematic," Mr Pahwa told the BBC. Chaayos defended its system, saying it was committed to protecting customers. "We are extremely conscious about our customer's data security and privacy," the company said in a statement to the BBC. The chain also said that customers could choose to opt out of using the facial recognition feature and instead use their phone numbers to pay bills. However, Mr Pahwa told the BBC that the facial recognition system was a mandatory requirement for joining its loyalty programme. He added that his picture had been taken despite the fact he was not a part of it. More worryingly, according to Mr Pahwa, Chaayos' terms and conditions - also seen by the BBC - says that customers "should not expect that personal information should always remain private".

The terms also say that by joining the loyalty programme, users authorise it to "disclose information to government authorities or competent authorities or credit bureaus or third persons". However, in its statement, Chaayos said "there is no third party sharing of the data for any purpose. And Chaayos does not use or process this information for any other purpose". Mr Pahwa said his worry was that "customers are not made aware of the implications of giving out this data, so this is not informed consent." Mr Pahwa's tweets about his experience picked up traction on social media, with a number of users coming forward to share their experiences at the chain, while others described similar incidents elsewhere.

India does not have laws governing the collection of biometric data and experts warn that this is not a phenomenon limited to Chaayos alone. "This trend of private companies collecting vast volumes of biometric data with photos linked to user identity, phone numbers and other details is deeply worrying. Hundreds of companies collect and store biometric data, often with no visible checks and balances, and no published privacy policies. In the absence of any privacy law in India, this is extremely worrying," technology expert Prasanto K Roy told the BBC. "For instance DLF, one of north India's top real-estate developers which has built and manages dozens of commercial buildings, demands that a visitor first authenticate herself using a text message (OTP) password, and then on camera-equipped tablets placed at the entrance, gets photographs taken of her face and her government-issued identity card, and sign off on the page. "They thus have a database which has my name, face, driving license, authenticated phone number, and signature. There is no option to opt out if I want to enter one of their buildings, or to delete my information. Such databases tend to leak, be sold for considerable sums of money, and be misused."

[With the case of the CafĂ© the solution is an easy one – don’t shop there. Once they see their customer base erode they might think twice about using such an intrusive ‘payment’ system. As I’ve said before it won’t be long before people start wearing masks – which will increasingly become professionally produced fashion items – and not long after that they’ll be made illegal at least in some countries or some places (I’m looking at you Hong Kong). What a strange world we are creating where the act of resistance becomes much like breathing or putting on pants – a completely natural act.]

Thursday, July 19, 2012


Just Finished Reading: Privacy – A Very Short Introduction by Raymond Wacks

I am, despite the irony of the statement, a private person. So it’s understandable that the concept of privacy interests me a great deal. Unfortunately I should have read the potted biography of the author a little more closely and realised that this book really wasn’t what I was looking for on the subject. Professor Wacks is an international expert in the law of privacy – which is something I only find tangentially interesting. Fortunately for me, not only is the author a gifted communicator he also peppers the book with the historical origins of modern privacy (which is an interesting subject in its own right) as well as the implications of modern technology – with Facebook and surveillance camera’s featuring prominently in the discussion – and speculates on the future of privacy in a world easily conceived of and which is becoming all too real, in other words a world without a real private sphere.

Whilst this book wasn’t a huge struggle to read – for all of the reasons outlined above – I can’t really say that I enjoyed it very much. I guess that if I was of a more legal frame of mind that this would have provided me with a comparatively light and thought provoking read. As I’m more of a Geek with a passion for history I’m afraid that my interest was focused more on his introductory chapters and his technological sidetracks. Definitely one for the lawyers amongst us I think!  

Tuesday, July 31, 2007

Just Finished Reading: Beyond Fear – Thinking Sensibly About Security in an Uncertain World by Bruce Schneier.

I picked this up because I was impressed by another book of his on IT Network Security (which is something I have a passing interest in).

Schneier expands his expertise in the area of IT Security to cover most – if not all – security problems we face today especially, of course, that of fighting terrorism. It seemed to me that this book was written in response to the knee-jerk reactions around the world to the events of 9/11. Schneier makes the point several times (actually he does have a tendency of repeating himself to drive an issue home) that if you want any security measure to be effective you have to think calmly and rationally about things. You cannot have a system which will do the things you want it to if you base your requirement on unreasonable fears.

Schneier also makes the very valid point (again several times) that you cannot prevent attacks no matter what you do. The only thing you can do is be as ready as possible when the attack happens and have procedures in place to mitigate any nasty results. But no matter what you do unexpected things will still occur. Security is a fluid environment so thinking that you have ‘solved’ a security problem is a sure way to invite failure.

Finally Schneier states very clearly that any security measure involves trade-offs. Some of these trade-offs might be worth it – whilst some might not. Of course some people are willing to trade more for security than others. It’s really up to the people involved to find levels of trade-offs that they’re comfortable with.

Whilst rather dry overall this book is well worth a read for anyone concerned about security issues in today’s post-9/11 environment. Aimed primarily (I think) at the US market it can be read by anyone who wants to look at security – both on a small and large scale – in a reasonable manner rather than an emotional one. All in all not a bad read.

Saturday, September 30, 2006

Just Finished Reading: Secrets and Lies – Digital Security in a Networked World by Bruce Schneier

Although fairly old in IT terms (having been written 6 years ago) Secrets and Lies is still a useful introduction into the world of computer security. It certainly covers all of the bases including Cryptography, Authentication, Secure hardware and software together with my particular favourite – Attack Trees which do indeed sound like something from the movie Minority Report.

Anyway, [grin] this has been my bedtime reading for a while now – and not because it helped me sleep. Schneier actually has a very accomplished technique of getting complicated and, to be honest, sometimes tedious information across in a way that even I could understand. Certainly if you have any interest in computer security this is worth a read. It will definitely make you a little more paranoid about connecting your PC to the Internet, but that’s not necessarily a bad thing is it?