Showing posts with label law enforcement. Show all posts
Showing posts with label law enforcement. Show all posts

Privacy dilemma illustrated in Vermont library

The local Halifax paper is running an AP story about the tough choices that custodians of personal information are sometimes called upon to make. After a young girl went missing, the police showed up at the public library demanding to take the public access computers that the girl had apparently used to communicate on MySpace. The librarian stood her ground and demanded that the police get a warrant. They did. Here's the full story:

Nova Scotia News - TheChronicleHerald.ca

Police raid on library offers privacy dilemma

By JOHN CURRAN The Associated Press

Sun. Jul 20 - 5:19 AM

RANDOLPH, Vt. — Children’s librarian Judith Flint was getting ready for the monthly book discussion group for eight and nine-year-olds on Love That Dog when police showed up.

They weren’t kidding around: Five state police detectives wanted to seize Kimball Public Library’s public access computers as they frantically searched for a 12-year-old girl, acting on a tip that she sometimes used the terminals.

Flint demanded a search warrant, touching off a confrontation that pitted the privacy rights of library patrons against the rights of police on official business.

"It’s one of the most difficult situations a library can face," said Deborah Caldwell-Stone, deputy director of intellectual freedom issues for the American Library Association.

Investigators obtained a warrant about eight hours later, but the June 26 standoff in the 105-year-old, red brick library on Main Street frustrated police and had fellow librarians cheering Flint.

"What I observed when I came in were a bunch of very tall men encircling a very small woman," said the library’s director, Amy Grasmick, who held fast to the need for a warrant after coming to the rescue of the 4-foot-10 Flint.

Library records and patron privacy have been hot topics since the passage of the U.S. Patriot Act after the Sept. 11, 2001, terror attacks.

Library advocates have accused the government of using the anti-terrorism law to find out, without proper judicial oversight or after-the-fact reviews, what people research in libraries.

But the investigation of Brooke Bennett’s disappearance wasn’t a Patriot Act case.

"We had to balance out the fact that we had information that we thought was true that Brooke Bennett used those computers to communicate on her MySpace account," said Col. James Baker, director of the Vermont State Police.

"We had to balance that out with protecting the civil liberties of everybody else, and this was not an easy decision to make."

Brooke, from Braintree, vanished the day before the June 26 confrontation in the children’s section of the tiny library.

Investigators went to the library chasing a lead that she had used the computers there to arrange a rendezvous.

Brooke was found dead July 2.

An uncle, convicted sex offender Michael Jacques, has since been charged with kidnapping her.

Authorities say Jacques had gotten into her MySpace account and altered postings to make investigators believe she had run off with someone she met online.

Flint was firm in her confrontation with the police.

"The lead detective said to me that they need to take the public computers and I said ‘OK, show me your warrant and that will be that,’ " said Flint, 56. "He did say he didn’t need any paper.

"I said ‘You do.’ He said ‘I’m just trying to save a 12-year-old girl,’ and I told him ‘Show me the paper.’"

Cybersecurity expert Fred H. Cate, a law professor at Indiana University, said the librarians acted appropriately.

"If you’ve told all your patrons ‘We won’t hand over your records unless we’re ordered to by a court,’ and then you turn them over voluntarily, you’re liable for anything that goes wrong," he said.

Saskatchewan court considers lawful authority

The Provincial Court of Saskatchewan has just ruled that a police officer in the midst of a drug investigation has "lawful authority" to ask for and receive information about a customer of a car rental company, including the customer's contract and photocopy of the renters' drivers license. The Court held that Section 7(3) of PIPEDA was satisfied by the request and that Budget Rent A Car was able to hand over the info in the absence of a production order.

See: R v Siemens, 2011 SKPC 57

[51] Lastly, I am not satisfied that the information contained in the Budget Rent-a-Car contract or attached documents exposed any intimate details about the accused’s lifestyle or information of a biographic nature. The information in the contract included the accused’s name and Mastercard number. It also included a copy of the accused’s driver’s license which provided a photo of the accused, his driver’s license number, his address, his height, weight, eye and hair colour, sex, birthdate, issue date, expiry date, class, endorsements and restrictions.

[52] A lot of this information is personal to the accused but it does not reveal intimate details of his lifestyle or his personal choices. In today’s world we have become increasingly dependent on the Internet and technology. Some of the information such as name and address are readily available on the Internet or in a phone book. I heard no evidence that the accused went to any lengths to keep this information out of a phone book or off the cyber highway. People use credit and debit cards to purchase things or make payments. A driver’s license gives an individual the privilege to drive a vehicle and it has become a very common form of identification. Indeed, it is one of only a handful of acceptable identification when it comes to purchasing alcohol or cigarettes, travelling on an airplane within Canada, when cashing a cheque, when picking up merchandise already paid for, among other things. It is also used by retailers to deter and detect fraud. All provinces in Canada have given police the right to request a driver’s license from someone driving a vehicle to verify the identity of the person driving to ensure that they are legally driving. Barring evidence to the contrary about a particular person, such reliance on driver’s license and technology reduces the expectation of privacy that that person can expect in the information contained in these things.

[53] It is also significant to note that the disclosure of this information did not lead to the police obtaining more intimate details of the accused’s lifestyle or choices such as sexual orientation, religion or personal likes or dislikes. The only thing the information revealed was that Lindsay Siemens had a driver’s license and a credit card and rented the red Cobalt that the police saw meet with Ms. Holmes and Mr. Soare in Rosedale, Alberta. It was only after the police did further investigation that they satisfied themselves that Mr. Siemens was the person who met with Ms. Holmes and Mr. Soare and that he was involved in the drug trade.


[54] Taking into account the nature of the information in question, the fact that PIPEDA was complied with the lawful authority of Constable Hicks to request the information pursuant to section 47.014(1) and Phelps Leasing’s right, in accordance with its contractual arrangement with the accused to disclose the information to a police officer engaged an active investigation, the accused did not have an objectively reasonable expectation of privacy in this information.


In the end, the court found the information was not unlawfully obtained, was not an unreasonable invasion of privacy and therefore did not offend Section 8 of the Charter.

US and Europe closer to information sharing pact

For over a year now, the United States and the European Union have been negotiating an arrangement so that US law enforcement and national security organizations can have easier access to data in Europe and about Europeans. The New York Times is reporting that that the two parties are closer to an arrangement that would permit trolling through personal information for suspicious activities, such as the review of SWIFT data that the American government undertook as the data was resident in the United States. One of the remaining issues is whether European citizens will have an ability to sue the Americans for misuse of their data.

The fact that Europe and the Bush administration are engaged in this process is a good thing. The alternatives are to shut off the tap entirely, which may not be a good idea, or to allow American authorities to freely troll through European data as easily as information about Americans, which would be worse. In Canada, Maher Arar learned the hard way about what can happen if an unstructured, unregulated information sharing "system" results in the transfer of unreliable information to the Bush administration.

Recently, the Canadian Bar Association presented its recommendations to Parliament, demanding that all information sharing arrangements be in writing with safeguards and oversight to make sure that information is accurate and does not unreasonably invade personal privacy.

The NYTimes article is here: U.S. and Europe Near Accord on Privacy - NYTimes.com.

Thanks to Rob Hyndman for the link.

Privacy and law enforcement access to information

I had the great pleasure today of giving a presentation at the Canadian IT Law Association's annual Spring Training event on law enforcement access to personal information.

Here is the presentation, though I caution that the new proposed amendments to PIPEDA will tweak some of it.

Halifax police plan to use covert cameras in public places

Halifax Police plan to augment their network of surveillance cameras with hidden cameras in public places. Law abiding citizens have nothing to fear, according to the Mayor. Besides, the Mayor says, people are used to being surveilled on private property. What he doesn't seem to get is that private property is "private" property that you enter on the terms set out by the property owner. Public places do not have those stipuations. Or at least they shouldn't.

From the Halifax Chronicle Herald:

Police plan more camera surveillance - Nova Scotia News - TheChronicleHerald.ca

Halifax police intend to step up camera surveillance in public places, the city’s police chief said Tuesday.

Chief Frank Beazley said Halifax Regional Police officers will be using portable digital equipment in the near future to record images at "hot spots" in the municipality and public gatherings like rock concerts.

He told a city hall budget meeting the new gear won’t need to be installed — the police department already has fixed cameras at several locations — because police personnel will simply arrive at a potential trouble spot with cameras and leave with the pictures they’ve collected.

Mayor Peter Kelly supports more secret camera use at different sites. He said cameras tracking public goings-on are already a fact of life here and in other cities.

Asked if extra police snooping is an invasion of privacy, Mr. Kelly said law-abiding citizens have nothing to fear.

"For those who cause concern for others, you’ll have things to worry about," the mayor said, adding, additional surreptitious camera work will hopefully lead to crime prevention and the arrests of lawbreakers.

Mr. Kelly said people are routinely photographed on private property, such as banks, stores, parking lots and elsewhere, and the police plan to beef up surveillance at common areas used by many people makes sense.

Chief Beazley acknowledged the enhanced camera gear will be used at various locations throughout the city.

"If we have a hot spot — there’s crime going on in certain areas — we’re going to be able to take these mobile cameras and surreptitiously (use) them" without the knowledge of those being photographed, he told regional council’s committee of the whole.

Metro has seen a month of violent crime, including three murders. The most recent shootings in the city occurred Friday night and Saturday afternoon. Nobody was killed in either attack.

Saturday’s shooting took place at a house in a residential neighbourhood in Fall River, prompting RCMP to say police are concerned an innocent bystander could get hurt, or worse.

PIPEDA amendments will expand private sector "collaboration" with police, permit disclosure of personal information

With today's proposed amendments to the federal private sector privacy law, most of the attention has been focused at "breach notification". But there's another very important amendment that seems to be a little below the radar.

On this blog, I've had a lot to say about cooperation between the private sector and law enforcement/national security agencies. One of the problems that telcos in particular have been struggling with is how to deal with warrantless demands for customer information. Section 7 of PIPEDA allows limited disclosure without consent to law enforcement/national security agencies where they have "lawful authority" to request the information. Courts have ruled that an active police investigation is not "lawful authority", so a disclosure would be unlawful.

It appears that the bill introduced today to amend PIPEDA will expand the ability for organizations to provide customer information to authorities without a warrant. (I haven't seen the text of the bill yet.)

Here's the official word from the Industry Canada media release


Industry Canada Site - Government of Canada Moves to Enhance Safety and Security in the Online Marketplace

Supporting Effective Law Enforcement

Another key thrust of the Bill is supporting effective law enforcement. The Government considers the safety and security of Canadian citizens to be of utmost importance. Proposed amendments will reaffirm the view that the information needs of law enforcement and security agencies can be met while respecting the privacy rights of Canadians. Proposed amendments would make it clear that organizations may collaborate with government institutions, such as law enforcement and security agencies that have requested personal information, in the absence of a warrant, subpoena, or order. To avoid jeopardizing investigations, new provisions would prohibit organizations from notifying an individual about the disclosure of their personal information to law enforcement and security agencies where the government institution to whom the information was disclosed objects.


I expect that the amendments will be permissive, in that they will allow a custodian of information to pass personal information to the police rather than require it. But for many, that's a distinction without a difference as I've often seen police take the position that if privacy legislation would permit it, it's almost obligatory.

Update: Here is the First Reading text of Bill C-29.

Senator Leahy introduces much-needed update to Electronic Communications Privacy Act

Today, May 17, 2011, Patrick Leahy introduced a bill to amend and substantially fix the Electronic Communications Privacy Act (ECPA). The bill made sense at the time it was first authored by Leahy a quarter century ago, but it has needed a substantial re-write in this cloud computing age. The most problematic provision allows obtaining stored communications that are more than 180 days old with just a subpoena, rather than a warrant based on probable cause. Twenty-five years ago, you might consider an un-downloaded e-mail message to have been abandoned, but that is no longer the case when millions of users are keeping all of their e-mails and documents in the cloud.

The Digital Due Process Coalition has been heavily lobbying for this change for some time.

For more info: Patrick Leahy introduces update to electronic privacy law - Post Tech - The Washington Post

Google releases Government Requests Tool, showing info and takedown demands

Google has just announced a new "Government Requests tool", which shows graphically how many governmental requests Google and YouTube receive for either user information or to take down content. The background is explained at the Google Public Policy Blog: Greater transparency around government requests.

This can only be a good thing. Legal processes for the disclosure of user information and the removal of content are often not well understood. Any measure that increases transparency and accountability, while providing information to inform public debate, is a good thing. I would hope to see other service providers stepping up to provide this sort of information as well.

Then I'd like to see more well-informed debate on the matter.

Canadian police state legislation needs closer examination

I try not to get too opinionated on this blog, but there are some things I feel strongly about. One thing is the ability of people to live their lives (online and off) free of state surveillance and intrusion unless an impartial judge decides that the balance needs to be shifted in favour of the state.

When the recent election was called, a bill fell off the order paper that would remove the impartial judge and put significant surveillance powers it the hands of the state. (In fairness, I have to say that this was originally conceived under the previous Liberal goverment, but is currently part of the Conservative Party's law and order platform that they say will be passed within 100 days if they win a majority (Conservative majority would pass lawful access [laws] within 100 days)). One Bill in particular needs a full airing and thorough debate. It was introduced in the last session and never made it past first reading. This means there was no debate and no scrutiny of any kind.

Here's why Bill C-52 - An Act regulating telecommunications facilities to support investigations needs much closer examination.

Section 16 of the Bill requires all telecommunication service providers to hand over enormous quantities of customer information to the police, CSIS or the competition cops. There is no limit on the amount of information to be provided and is only restricted to "duties" of the cops or intelligence agency.

The provisions, at least as they appeared in Bill C-52, read as follows:

OBLIGATIONS CONCERNING SUBSCRIBER INFORMATION

16. (1) Every telecommunications service provider must provide a person designated under subsection (3), on his or her written request, with any information in the service provider’s possession or control respecting the name, address, telephone number and electronic mail address of any subscriber to any of the service provider’s telecommunications services and the Internet protocol address, mobile identification number, electronic serial number, local service provider identifier, international mobile equipment identity number, international mobile subscriber identity number and subscriber identity module card number that are associated with the subscriber’s service and equipment.

(2) A designated person must ensure that he or she makes a request under subsection (1) only in performing, as the case may be, a duty or function

(a) of the Canadian Security Intelligence Service under the Canadian Security Intelligence Service Act;

(b) of a police service, including any related to the enforcement of any laws of Canada, of a province or of a foreign jurisdiction; or

(c) of the Commissioner of Competition under the Competition Act.



(3) The Commissioner of the Royal Canadian Mounted Police, the Director of the Canadian Security Intelligence Service, the Commissioner of Competition and the chief or head of a police service constituted under the laws of a province may designate for the purposes of this section any employee of his or her agency, or a class of such employees, whose duties are related to protecting national security or to law enforcement.

(4) The number of persons designated under subsection (3) in respect of a particular agency may not exceed the greater of five and the number that is equal to five per cent of the total number of employees of that agency.

(5) The Commissioner of the Royal Canadian Mounted Police and the Director of the Canadian Security Intelligence Service may delegate his or her power to designate persons under subsection (3) to, respectively, a member of a prescribed class of senior officers of the Royal Canadian Mounted Police or a member of a prescribed class of senior officials of the Canadian Security Intelligence Service.

17. (1) A police officer may request a telecommunications service provider to provide the officer with the information referred to in subsection 16(1) in the following circumstances:

(a) the officer believes on reasonable grounds that the urgency of the situation is such that the request cannot, with reasonable diligence, be made under that subsection;

(b) the officer believes on reasonable grounds that the information requested is immediately necessary to prevent an unlawful act that would cause serious harm to any person or to property; and

(c) the information directly concerns either the person who would perform the act that is likely to cause the harm or is the victim, or intended victim, of the harm.



The police officer must inform the telecommunications service provider of his or her name, rank, badge number and the agency in which he or she is employed and state that the request is being made in exceptional circumstances and under the authority of this subsection.



Let me break this down: Any designated police officer or CSIS agent can ask a telecommunications service provider to hand over any of the following information about a customer:

  • name,
  • address,
  • telephone number,
  • electronic mail address,
  • Internet protocol address,
  • mobile identification number,
  • electronic serial number,
  • local service provider identifier,
  • international mobile equipment identity number,
  • international mobile subscriber identity number and
  • subscriber identity module card number.


This goes well beyond the usual scenario of when the cops have an IP address of someone suspected of online child exploitation and want the customer name and address information. But the bill doesn't say that if the cops have X info, they can get Y subscriber data. Instead, it just says on request the telco has to hand over the entire laundry list of data on customers. This is without a warrant, without a production order and without any court oversight at all. Unlike wiretap laws where stats have to be released, there is no obligation on the part of the police or the ministers responsible to release information about how these powers are used and under what circumstances. The Privacy Commissioner gets to audit it, but I don't think this saves any of the problems with the Bill.

The Bill contained no limitation on what level of investigation was required. It isn't limited to serious crimes or even trivial crimes. It is not limited to criminal or national security investigations. All that's necessary is that it be connected with the cop's duties. Collecting parking tickets fit within that category.

Think about what this means, given the laundry list of data to be provided with no threshold of probable cause or even a real investigation. The police can scan the airwaves at a protest and identify the IMEIs of the mobile phones in the vicinity. One request to the telcos can get the names and addresses of virtually everyone who was there. I bet the Egyptian authorities would have loved to have done this in Tahrir Square. Next time there's a G-20 protest in Canada, the police can do this, too.

There is no limitation in the statute that would prevent the police from asking for all the above data for any subscribers who connected, for example, to any cell site in a particular neighbourhood at a particular time.

In Canada, we expect that we can generally live our lives free of government surveillance and intrusion, unless an independent judge says that the government interest in crime fighting outweighs our individual right to privacy. This legislation would remove this balance and tips the scales dramatically toward police state powers.

Telco and ISP snooping? Don't hate the player, hate the game

The 'net and twitter have been all abuzz this past week with revelations about telco and ISP cooperation with law enforcement. We've seen Wikileaks post the internal policies of MySpace and Cryptome's posting of Yahoo!'s internal policies.

Blame for this appears to be laid at the feet of the service providers.

I'm all in favour of privacy and completely in favour of government restraint. I'm even more keen on court oversight and requirements that warrants be produced in order for cops and national security types to get access to customer information. I'm also in favour of transparently and accountability. But I haven't seen much nuance in any of the online discussion of this topic. Perhaps that's just the analytical limitations of twitter and the general tone of much of the blogosphere.

Two important issues are being missed. First: just about any time you interact with any business these days, a data trail of some sort is left. If you buy a book using any credit or debit card, there's a record that can connect that purchase to you. If you check out a book from the library, there's a record. If you use a transponder-based tolling system, there's a record of where you were, when and maybe where you are going. If you use any loyalty program to collect points on your purchases, there's an even denser data trail. Your mobile phone provider knows where you phone is at all times and who you have called. This is not unique to online companies. It's simply the reality of our digital lives. Some information collection or retention may be gratuitous, but more often than not it is essential to provide the service that users are asking for. It is not unreasonable, however, to question how much information is collected and how long it is retained. Fair information practices demand that service providers only collect the amount of information necessary to provide the service and that they keep it for only as long as they need to in order to provide the service.

The second, and more important, issue: love it or loathe it, it is the law. If a third party has information about you, the government can get access to it with a court order, a warrant or a subpoena. The third party can sometimes go to court to challenge the legality of the request, but it seldom has enough information to do so. And in many cases, it really has no ability to do so. The fact is, if there is a lawful demand for information, the service provider has to comply or face criminal sanctions itself.

And that's not just unique to the US and the USA Patriot Act. In Canada, take a look at the Anti-Terrorism Act, the Criminal Code, the Canadian Security Intelligence Service Act or the National Defence Act. European democracies have similar rules, too. These companies are generally following their legal obligations. If you have a problem with that, energies and outrage might be more usefully channelled to changing those laws.

ISPs and telcos may influence the laws, but they generally don't make they rules they have to abide by. In short: don't hate the player, hate the game.

Lifting the veil on telco cooperation with law enforcement

Over the last little while, there has been much discussion about cooperation between telcos and ISPs, on one hand, and law enforcement, on the other hand. We've certainly seen a lot of talk about "lawful access" in Canada.

If you're curious about some of the goings on behind the scenes at American telcos and ISPs in this regard, Cryptome and Wikileaks both have some interesting leaked documentation about policies and procedures for companies like MySpace, Sprint, Yahoo! and others. Just go to Cryptome.org and WikiLeaks.org and do a little digging around.

EU Clears SWIFT Data Transfers to United States Treasury Department

The New York Times is reporting on an agreement reached between European ministers and the United States for restored access to information about bank transfers processed by the Society for Worldwide Interbank Financial Telecommunications (SWIFT). See: EU Clears Bank Data Transfers to United States - NYTimes.com.

There has been some coverage of this already on blogs, particularly the Brussels Blogger (SWIFT - EU to grant USA nearly unlimited access to all EU banking data). Much of the tone has suggested that wholesale transfers of information will take place with massive datamining operations to be set up, but take a look at the actual agreement between the US and Europeans. It's available at wikileaks: EU draft council decision on sharing of banking data with the US and restructuring of SWIFT, 10 Nov 2009 - Wikileaks.

The agreement doesn't contemplate wholesale, massive data downloads of the kind one would expect if the database were in the United States. Instead, targeted requests must be made and these are directed through European authorities rather than to SWIFT directly. There are covenants on the US side that it will not be used for data mining purposes and other privacy-protective promises. And, to top it off, the term of the agreement is one year so that it can be renegotiated if it's not working out.

While all of this needs to be examined with a critical eye and it's not perfect, the cynic in me was pleasantly surprised by the details of the agreement.

Privacy-related bills to die on the order paper if Canadian election called

With talk of an election heating up in Canada, I thought I'd provide a list of the government bills that will likely die on the order paper if the government is brought down or if the PM wanders over to speak with the Governor General about dissolving parliament:














C-29An Act to amend the Personal Information Protection and Electronic Documents Act

(Safeguarding Canadians’ Personal Information Act)
First Reading in the House of Commons (May 25, 2010)XML


C-50An Act to amend the Criminal Code (interception of private communications and related warrants and orders)

(Improving Access to Investigative Tools for Serious Crimes Act)
First Reading in the House of Commons (October 29, 2010)XML
C-51An Act to amend the Criminal Code, the Competition Act and the Mutual Legal Assistance in Criminal Matters Act

(Investigative Powers for the 21st Century Act)
First Reading in the House of Commons (November 1st, 2010)XML
C-52An Act regulating telecommunications facilities to support investigations

(Investigating and Preventing Criminal Electronic Communications Act)
First Reading in the House of Commons (November 1st, 2010)XML





Bills C-50, C-51 and C-52 need some major work so I'm fine to see them go back into parliamentary purgatory, but the PIPEDA amendments (C-29) were pretty good and I'd hate to think we're back to the drawing board.

A look at video surveillance in Halifax

The Sunday Chronicle Herald has two articles on the increasing use of video surveillance by police and private organizations in Halifax. They are interesting reading, but what I find most interesting is that this is the first time that I've seen any dicussion of how the police manage the feeds and access to recordings. Check them out:

  • Eyes in the sky - Nova Scotia News - TheChronicleHerald.ca
  • Wireless cameras add to police toolbox - Nova Scotia News - TheChronicleHerald.ca
    The cameras in place now are not monitored all day long, although they are recording, Supt. Moore said. The images are automatically deleted if there’s no request to see them within 14 days.

    The department used guidelines from the province’s Freedom of Information office as well as the federal Office of the Privacy Commissioner to develop its guidelines for using the images, he said.

    All viewing requests are made to him and only he and his technical staff have access to the recordings.

    "They’re very much locked down and once they’re collected, there’s a formalized process for someone looking to go in and find these images," he said.

    Supt. Moore said police haven’t used video from those downtown cameras to solve "big" crimes – yet.

    "We are still optimistic that it will, but to date it has not been pivotal," he said.




Any discussion of the policies regulating the use of video surveillance is a good thing, and better late than never.

The new lawful access bills

Here is the first reading text of the Investigative Powers for the 21st Century Act:

BILL C-51 An Act to amend the Criminal Code, the Competition Act and the Mutual Legal Assistance in Criminal Matters Act aka Investigative Powers for the 21st Century Act.

I will post a link to the Investigating and Preventing Criminal Electronic Communications Act when it is posted on the parliamentary website.

(Note: I had previously linked to the wrong bill on this post ...)

Lawful access back before Parliament

Once again, the Government of Canada has put "lawful access" back before Parliament.

Notice that it again allows for the police and "national security agencies" to require the personal information of telecommunications customers without a warrant.

I will post a link to the bill itself as soon as I can get my hands on it, but in the meantime here's the press release from the Department of Justice:

Government of Canada Introduces Legislation to Fight Crime in Today’s High-Tech World

GOVERNMENT OF CANADA INTRODUCES LEGISLATION TO FIGHT CRIME IN TODAY’S HIGH-TECH WORLD

OTTAWA, November 1, 2010 – The Honourable Rob Nicholson, P.C., Q.C., M.P. for Niagara Falls, Minister of Justice and Attorney General of Canada, together with Dave MacKenzie, M.P. for Oxford and Parliamentary Secretary to the Minister of Public Safety, and Daniel Petit, M.P. for Charlesbourg–Haute-Saint-Charles and Parliamentary Secretary to the Minister of Justice, today re-introduced in the House of Commons two bills that would provide law enforcement and national security agencies with up-to-date tools to fight crimes such as gang- and terrorism-related offences and child sexual exploitation.

“New and evolving technologies provide new ways of committing crimes, making them harder to investigate,” said Minister Nicholson. “We must ensure that law enforcement has the means to bring to justice those who would break the law. Twenty-first-century technology demands twenty-first-century tools for police to effectively investigate crime.”

The proposed Investigative Powers for the 21st Century Act would provide law enforcement agencies with new, specialized investigative powers to help them take action against Internet child sexual exploitation, disrupt on-line organized crime activity and prevent terrorism by:

  • enabling police to identify all the network nodes and jurisdictions involved in the transmission of data and trace the communications back to a suspect. Judicial authorizations would be required to obtain transmission data, which provides information on the routing but does not include the content of a private communication;
  • requiring a telecommunications service provider to temporarily keep data so that it is not lost or deleted in the time it takes law enforcement agencies to return with a search warrant or production order to obtain it;
  • making it illegal to possess a computer virus for the purposes of committing an offence of mischief; and
  • enhancing international cooperation to help in investigating and prosecuting crime that goes beyond Canada’s borders.

“We are giving our police the tools they need to keep up with criminals who are increasingly using new technology in carrying out their crimes. High-tech criminals must be met by high-tech police,” said Mr. MacKenzie. “This announcement once again demonstrates our commitment to give our law enforcement agencies the tools they need to make our communities safer.”

The Investigating and Preventing Criminal Electronic Communications Act would address challenges posed by today’s technologies that did not exist when the legal framework for interception was last updated nearly 40 years ago. The Act would require service providers to include interception capability in their networks, thereby allowing law enforcement and national security agencies to execute authorizations for interception in a more timely and efficient manner with a warrant. The proposed Act also calls for service providers to supply basic subscriber information upon request to designated law enforcement, Competition Bureau and national security officials.

Requirements to obtain court orders to intercept communications will not be changed by this Act. This legislation will simply help ensure that, when warrants are issued, telecommunications companies have the technical ability required to intercept communications for the police and the Canadian Security Intelligence Service.

Other countries, such as the United Kingdom, the United States, Australia, New Zealand, Germany and Sweden, already have similar legislation in place.

“Both of these pieces of legislation will provide vital tools to allow law enforcement officers to trace serious computer crimes such as child pornography and hate crime,” said Mr. Petit. “Both acts help to address Canadians’ privacy concerns by including strict privacy safeguards which, in the case of the Investigative Powers for the 21st Century Act, includes heightened requirements for obtaining judicial authorization before police can obtain data relating to a suspect’s location.”

The Government carefully considered input provided by a broad range of stakeholders in developing these two pieces of legislation, including the telecommunications industry, civil liberties groups, victims’ advocates, police associations and provincial/territorial justice officials. As a result, the Government has ensured that the Investigative Powers for the 21st Century Act and the Investigating and Preventing Criminal Electronic Communications Act adopt a balanced approach, taking full account of the need to protect the safety and security of Canadians, the competitiveness of the telecommunications industry, and the privacy rights of Canadians.

An on-line version of the legislation will be available at www.parl.gc.ca.

Backgrounder: Investigative Powers for the 21st Century Act.

R. v. Wilson: Police get warrantless access to Sympatico customer's data

I blogged earlier this week about a decision from the Ontario Superior Court of Justice that held that Bell Sympatico customers do not have a reasonable expectation of privacy when the police come knocking for the name and address behind an IP address. (See: Canadian Privacy Law Blog: Police get warrantless access to Sympatico customer's data.) I managed to get a copy of the decision in R. v. Wilson (6MB PDF file).

While I disagree with the judge's determination that there is no "reasonable expecation of privacy" in this information, what must be remembered is that Bell voluntarily handed the information over.

Laptop searches at airports infrequent, DHS privacy report says

Computerworld is reporting on the first report of the Department of Homeland Security Privacy Office since the changeover to the Obama administration. The report itself is interesting, but perhaps most interesting are the statistics related to the number of searches of laptops at border crossings. This has been a controversial practice since reports on it came to light some time ago. I was surprised to read that fewer than two thousand took place in the year under review, in light of the millions of people (and laptops) that have crossed the border during that time.

Here's Computerworld's coverage: Laptop searches at airports infrequent, DHS privacy report says.

The British Government plans to step in to the abyss with massive telecom database

The Independent is reporting that the British government is planning to announce a 1 BILLION POUND project that would involve the creation of a database to log every e-mail, telephone call and website click and retain the information for one year.

The project seems to be universally panned: the independent reviewer of UK anti-terrorism laws says "as a raw idea it is awful". The Information Commissioner calls it a "step too far".

If anyone had asked me (which they didn't, but I have constitutional rights here in Canada and get to say what I want), I would have said the idea is not surprising given the way things are going in England, but it is a clear step into the abyss of giving up any sense of private life in the country. See: Exclusive: Storm over Big Brother database - Home News, UK - The Independent. Big thanks to DP thinker: Proposed Database for pointing to the story.

Lawful access rears its head again

Here we go again .... the government is preparing a new "lawful access" law. The media coverage seems to suggest that it covers both eavesdropping of internet based communications (with a warrant) and obtaining subscriber data (without a warrant).

globeandmail.com: New law to give police access to online exchanges

BILL CURRY

From Thursday's Globe and Mail

February 12, 2009 at 3:39 AM EST

OTTAWA — The Conservative government is preparing sweeping new eavesdropping legislation that will force Internet service providers to let police tap exchanges on their systems - but will likely reignite fear that Big Brother will be monitoring the private conversations of Canadians.

The goal of the move, which would require police to obtain court approval, is to close what has been described as digital "safe havens" for criminals, pedophiles and terrorists because current eavesdropping laws were written in a time before text messages, Facebook and voice-over-Internet phone lines.

The change is certain to please the RCMP and other police forces, who have sought it for some time. But it is expected to face resistance from industry players concerned about the cost and civil libertarians who warn the powers will effectively place Canadians under constant surveillance.

Public Safety Minister Peter Van Loan confirmed the plan yesterday during an appearance before a House of Commons committee and offered further explanation afterward.

Public Safety Minister Peter Van Loan confirmed the plan. (Sean Kilpatrick/The Canadian Press)

"We have legislation covering wiretap and surveillance that was designed for the era of the rotary phone," Mr. Van Loan said.

"If somebody's engaging in illegal activities on the Internet, whether it be exploitation of children, distributing illegal child pornography, conducting some kind of fraud, simple things like getting username and address should be fairly standard, simple practice. We need to provide police with tools to be able to get that information so that they can carry out these investigations."

Mr. Van Loan said there have been situations where the police want to act quickly to stop a crime, but can't because of the current laws.

"In some of these cases, time is of the essence," he said. "If you find a situation where a child is being exploited live online at that time - and that situation has arisen before - police services have had good co-operation with a lot of Internet service providers, but there are some that aren't so co-operative."

Although police agencies have been calling for such a law since at least the mid-1990s, this would be the first legislative effort in this direction by the Conservatives.

The reaction can be predicted, however, because Paul Martin's Liberal government faced stiff resistance when his public safety minister, Anne McLellan, introduced a "lawful-access" bill in November, 2005, shortly before that government was defeated.

The Conservative justice critic at the time, Peter MacKay, who is now in the Conservative cabinet, expressed concern with the bill, and Privacy Commissioner Jennifer Stoddart went further, saying there was no justification for such a law.

The concern of critics is that unlike a traditional wiretap that cannot commence without judicial approval, lawful-access legislation in other countries has forced Internet providers to routinely gather and store the electronic traffic of their clients. Those stored data can then be obtained by police via search warrant.

"That means we're under surveillance, in some sense, all the time," said Richard Rosenberg, president of the B.C. Freedom of Information and Privacy Association. "I think that changes the whole nature of how we view innocence in a democratic society."

RCMP Commissioner William Elliott said yesterday the lack of such legislation is causing problems for police.

"We're speaking generally about the development of technology that is difficult or impossible to wiretap," Mr. Elliott said after appearing alongside Mr. Van Loan at the House of Commons Public Safety and National Security Committee.

"In the old days, for a wiretap it was pretty simple. You sort of clicked onto the physical wires. So we have some instances where the court authorizes us and other police forces, for example, to intercept communications, but we don't have the technical ability to do that. So certainly the RCMP is supportive of changes of legislation that would allow those kind of intercepts."

Popular entries

 

Web world of law online law enforcement © 2012