Privacy Oriented

A one-man blog addressing privacy issues, covering privacy news, government attacks on privacy, corporate attacks on privacy, RFID, anonymous living, online privacy, financial privacy, surveillance, (pseudo) anonymous money transfer, offshore banking, cryptography and the like.


I support these folks:

  • Support Downsize DC!

Search Posts


Topics

US: Court rules hash analysis is a Fourth Amendment “search”

November 2nd, 2008 by privacyoriented

By Julian Sanchez | Published: October 29, 2008 - 01:46PM CT

A good coder has as many uses for hash functions as George Washington Carver did for peanuts—but law enforcement is fond of these digital fingerprinting techniques as well, because they allow reams of data to be rapidly sifted and identified. Legal scholars, however, have spent a decade puzzling over whether the use of hash value analysis in a criminal investigation counts as a Fourth Amendment “search.” A federal court in Pennsylvania last week became the first to rule that it does—but one legal expert says an appeal is very likely.

Chief Judge Yvette Kane of the U.S. District Court for the Middle District of Pennsylvania penned the opinion in United States v. Crist, granting Robert Crist’s request for the suppression of child pornography police found on his computer. Crist had fallen behind on his rent, and his landlord hired a father-and-son pair to move the delinquent tenant’s belongings out to the curb, where a friend of one of the movers, Seth Hipple, picked up Crist’s computer. When Crist returned home, he began freaking out over his vanished machine—while Hipple was freaking out over what he’d found in a folder on the hard drive: Videos appearing to depict underage sex, which he promptly deleted.

Hipple called the East Pennsboro Township Police Department, and though the computer had been reported stolen, it soon found its way to the Pennsylvania Attorney General’s Office, where special agent David Buckwash made an image of the hard drive and began sifting through its contents using a specialized forensics program called EnCase. Rather than directly examining the contents of the hard drive, Buckwash initially ran the imaged files through an MD5 hash algorithm, producing a unique (for practical purposes) digital fingerprint, or hash value, for each one. He then compared these smaller hash values with a database of the hash values of known and suspected child porn, maintained by the National Center for Missing and Exploited Children. He came up with five definite hits and 171 videos containing “suspected” child porn. He then moved to gallery view, inspecting all the photos on the drive, and ultimately finding nearly 1,600 images that appeared to be child pornography.

None of this, however, had been done with a warrant. That raised two intriguing legal questions. First, longstanding precedent holds that if a private party, unprompted by police, conducts a search—by opening a package or briefcase, for instance—then the owner has lost their “reasonable expectation of privacy” in the searched object. That means police are in the clear if they proceed to examine whatever the private party has discovered. But it’s not always clear how this rule applies in particular cases. If a private person opens a briefcase, police might scrutinize it more closely when they take a look—but the exception clearly doesn’t mean that police can scour an entire house, ripping open mattresses and digging through closets, just because someone else has already wandered through the place. So had Crist lost his expectation of privacy in the entire hard drive, or only in the few files and folders Hipple had seen?

Even if the entire hard drive wasn’t to be considered fair game, however, a more interesting question remained: Was the analysis of hash values of the files on the hard drive a search at all? The question was first broached in a 1996 Yale Law Journal article titled “Cyberspace, general searches, and digital contraband.” The author noted an interesting quirk of Fourth Amendment jurisprudence: Courts have held that a “search” occurs when someone’s “expectation of privacy” is violated, provided that expectation is one that society is prepared to regard as “reasonable.” But they’ve also held that there is no such “reasonable expectation” as regards the possession of illegal materials, like narcotics or child porn. In 2004, the Supreme Court would rely on this logic in the case of Illinois v. Caballes to hold that a trained drug dog’s sniff, which only reveals the presence or absence of illegal drugs, does not count as a search. In the digital realm, this raised the possibility of what we might call, with a nod to novelist Erica Jong, a “zipless search“—a more or less perfect means of detecting only contraband, circumventing the Fourth Amendment’s warrant requirement.

If hash value analysis isn’t a search, then even if the state went too far in directly inspecting the hard drive, the evidence of a hash match against the NCMEC database might still be admissible. But Judge Kane rejected that logic, writing:

By subjecting the entire computer to a hash value analysis—every file, internet history, picture, and “buddy list” became available for Government review. Such examination constitutes a search.

But as George Washinton University law professor Orin Kerr, author of the Justice Department’s computer search manual, wrote on the widely-read Volokh Conspiracy blog, this is almost maddeningly brief and vague. “Which stage was the search—the creating the duplicate?” asked Kerr. “The running of the hash? It’s not really clear.” And as Kerr notes, though the court alludes to the Caballes dog-sniff ruling earlier in its opinion, it does not directly take up the question of the “zipless search,” or explain how the hash analysis differs from a dog sniff. The answer could be massively significant, since it would determine, for instance, whether law enforcement agents serving a valid warrant against one user on a huge server are entitled to scan the entire machine, rather than only their target’s files, for illicit material.

The second question is whether Buckwash “expanded the scope of the private search” conducted by Hipple when he imaged and scrutinized Crist’s entire hard drive. In United States v. Runyan, the Fifth Circuit Court of Appeals seemed to accept the application of a “closed container” metaphor to digital storage devices. Just as the privacy interest in the contents of a package are lost once someone has opened it, the contents of a digital storage medium are fair game once it has been accessed. But as Kerr has pointed out in his paper, “Searches and Seizures in a Digital World,” physical metaphors are tricky in a world of bits. Is the computer really like a “container”? Or given the vast amounts of information a hard drive can contain, does it make more sense to think of the drive as analogous to a warehouse, where the “container” is an individual file or folder? Kerr ultimately opts for an “exposure theory” of digital searches, according to which only the information that has been displayed to a human user should be considered “searched,” leaving the privacy interest in all the other data intact. In this case, Judge Kane seemed to agree that Hipple’s “search” of a few files did not void Crist’s privacy interest in the rest of the drive, and that in any event Buckwash’s forensic analysis was qualitatively different and more extensive than Hipple’s casual examination.

Kerr, however, told Ars that he expects the government to appeal the ruling, both because the argument for counting hash analysis as a “search” is so brief, and because the court’s application of the Runyan precedent is subject to dispute.

That makes United States v. Crist a case to watch. Until now, the constitutional status of hash value analysis has been unclear. But if the Third Circuit Court of Appeals should disagree with Judge Kane’s reasoning, it could send a signal that a new era of zipless searching is at hand.

Posted in Encryption, Internet Privacy, Privacy News, Search & Seizure USA, US Privacy | 2 Comments »

Former US Millitary-Intel Officer says US Govt has “Plans to Impliment” Chinese-Style Surviellance State

May 20th, 2008 by privacyoriented

From RollingStone’s article about China’s “Golden Shield”:

In Shenzhen one night, I have dinner with a U.S. business consultant named Stephen Herrington.Communist China Before he started lecturing at Chinese business schools, teaching students concepts like brand management, Herrington was a military-intelligence officer, ascending to the rank of lieutenant colonel. What he is seeing in the Pearl River Delta, he tells me, is scaring the hell out of him — and not for what it means to China.”

I can guarantee you that there are people in the Bush administration who are studying the use of surveillance technologies being developed here and have at least skeletal plans to implement them at home,” he says. “We can already see it in New York with CCTV cameras. Once you have the cameras in place, you have the infrastructure for a powerful tracking system. I’m worried about what this will mean if the U.S. government goes totalitarian and starts employing these technologies more than they are already. I’m worried about the threat this poses to American democracy.”

Herrington pauses. “George W. Bush,” he adds, “would do what they are doing here in a heartbeat if he could.”

Fortunately, somebody actually cares that this kind of thing not be setup in the US. Unfortunately, this man cannot see that the US has already devolved into a totalitarian regime.

Posted in Online Privacy, Original Content, Privacy News, US Privacy | No Comments »

Peel: Congress should stop pandering to health data miners

March 7th, 2008 by privacyoriented
From GovernmentHealthIT
By Deborah C. Peel, MD Founder and Chair Patient Privacy Rights


The story last week on e-prescribing [“$3 billion annual savings estimated for Medicare e-prescribing,” GovHealthITcom, March 4] does not mention the elephant in the room: that every prescription in the nation has been data-mined and sold for over a decade to drug companies and employers without the legal consent of Americans.

The ‘consents’ on which this theft is based are illegal and coerced by health plans when you sign up annually for a health plan.

No e-prescribing legislation should pass unless it ends the daily theft of the nation’s electronic prescription records and restores Americans’ rights to health information privacy. My organization, Patient Privacy Rights, and our allies will oppose this bill unless it is fixed.

Today most Americans do not even know about this privacy disaster. Patient Privacy Rights is working to alert the public about this massive violation of their right to privacy.

Last Friday at a congressional briefing sponsored by the bipartisan Alliance for Health Reform and Divided We Fall, I called for congressional investigations into the secret corporate world that data mines our sensitive personal information.

The data mining industry makes billions in profits every year and not one dime goes to help a single sick person. Our healthcare system is so broken that the greatest profits in healthcare are made by corporations that steal our sensitive health records, not by the health professionals who actually treat and care for us when we are sick.

One prescription data mining corporation reported revenues in 2006 of $2 billion. One of the nation’s largest insurers sells the longitudinal claims and health data of all 79 million of its enrollees to large employers to lower their costs.

How on earth could they have obtained all that data without informed consent? All the data they sell can easily be re-identified with three bits of information, zip code, sex, and age. It is impossible to scrub the data in health records so clean that re-identification is impossible. Health data is so rich that it contains far too much detail to ever be safe.

Most health information technology systems were built either in ignorance or defiance of both medical ethics and the very strong laws in every state requiring informed consent before sensitive personal health information is disclosed. HIPAA is an “disclosure sure” rule, not a Privacy Rule. After it was secretly gutted in 2002 by HHS, it has been used by the data mining industry to justify access and use of the nation’s health information without consent.

To help address this issue, Patient Privacy Rights has formed a new organization, Privacy Rights Certified, which will begin certifying health IT platforms and applications in the next 30-60 days so that vendors with health IT products that protect the security of our data and ensure we are in control of who can see and use our data will be able to display a Good Housekeeping-type seal-of-approval to show the public that their personal health information is safe.

Microsoft’s HealthVault and e-mds.com’s EHR application for physicians’ offices will be the first to be certified. Vendors that build legal and ethical health IT products will want to prove to the public they are not data thieves by being audited by an independent, consumer-led non-profit organization. Certification by industry consortia will never be trusted by the public. The foxes will never convince us chickens that they are looking out for our best interests.

Its time for Congress to stop pandering to the insurance industry, the data mining industry, the drug industry, the hospital industry, and all those who profit from the illegal and unethical theft of our personal health data—-worth billions annually.

Congress should start by ending the daily data mining and theft of our prescriptions. Congress should show the American people that it will not stand for the systematic destruction of Americans’ long-held rights to privacy. Let the investigations begin!

Posted in Privacy News, US Health Privacy | No Comments »

Privacy Oriented News

March 7th, 2008 by privacyoriented

I will be posting a lot of privacy oriented news so the entire articles are archived here - maybe even with comments that are especially good. There may be articles that I would not normally post, but I have found that the publisher (NYTimes.com or whomever) will not let me read the whole thing without signing in or signing up - and those publishers rub me the wrong way, so I’ll be posting their full article here after I go to www.BugMeNot.com and get a working login prior to copying the entire article.

I’ll be giving credit and links to the original and all that, and I consider that fair use.

Posted in Original Content, Privacy News | No Comments »