« August 2013 | Main | October 2013 »

September 2013 Archives

September 24, 2013

"Our Data, Our Lives"

The Public Voice: "Our Data, Our Lives"

The Public Voice
Warsaw, Poland
September 24, 2013

September 4, 2013

European Parliament Begins Hearings on NSA Surveillance

The European Parliament will hold a hearing, "Electronic Mass Surveillance of EU Citizens," on September 5, 2013. The hearing is hosted by the Committee on Civil Liberties, Justice, and Home Affairs ("LIBE Committee"). Witnesses include journalists and the Editor-in-Chief of the Guardian as well as current and former government officials. The hearing will focus on surveillance conducted by the United States, but will also address EU-Member State surveillance. A live stream will be accessible. The hearings is the first in a series mandated by a resolution of the European Parliament. EPIC has filed a Petition for a Writ of Mandamus in the U.S. Supreme Court, calling the National Security Agency's practice of collecting U.S. person phone call information unlawful. For more information, see EPIC: In re EPIC - NSA Telephone Records Surveillance.

September 5, 2013

EPIC, Privacy Groups, Urge FTC to Block Facebook Policy Changes

EPIC, joined by several leading privacy and consumer protection organizations, has called on the Federal Trade Commission to enforce the terms of a 2011 settlement with Facebook. Facebook recently announced changes that would allow the company to routinely use the names, images, and content of Facebook users for commercial advertising without consent. The changes arise from a flawed class action settlement over Facebook’s Sponsored Stories program. In the letter, the privacy groups explain that Facebook’s changes violate the terms of a 2011 settlement with the FTC. For more information, see EPIC: Federal Trade Commission and EPIC: Facebook Privacy.

September 6, 2013

Pew Survey Finds that Vast Majority of Americans Take Steps to Maintain Privacy Online

A recent survey by the Pew Research Center's Internet Project has discovered that 86 percent of Americans take steps to conceal their actions or identities while online. The survey also found that 21 percent had an email or social networking account compromised or taken over by someone else without permission. Furthermore, the majority of respondents believe that "current laws are not good enough in protecting people's privacy online." Other Pew surveys have found that most teens were taking steps to protect their privacy, that a majority of parents were concerned about their children's online privacy, and that users were becoming more active in managing their social media accounts. For more information, see EPIC: Public Opinion on Privacy.

September 9, 2013

EPIC Files FOIA Suit to Determine If Tor Is Compromised

EPIC has filed a Freedom of Information Act lawsuit against the Broadcasting Board of Governors, a federal agency that oversees all U.S. civilian international media. EPIC seeks information about the federal government's interest in the Tor network. Tor is a program designed to allow encrypted, anonymized online browsing and is used by many human rights organizations. Recent news reports indicate that the National Security Agency has targeted the communications of Tor users. In a related matter, EPIC has asked the Supreme Court to halt the NSA collection of domestic telephone records. For more information, see EPIC: EPIC v. BBG - Tor.

September 10, 2013

Federal Appellate Court Upholds Privacy Protection for Wi-Fi Communications

The Court of Appeals for the Ninth Circuit has upheld a lower court ruling against Google in a case arising out of the Street View interception of private Wi-Fi communications. The lawsuit alleges that Google's ongoing interception of Wi-Fi payload data through its Street View program violated several laws, including the federal Wiretap Act. The court rejected Google's arguments that the interception was permissible. The court said that Google's interpretation could have the absurd result of rendering private communications, like email, unprotected simply because the recipient fails to encrypt their Wi-Fi network. Furthermore, the court explained that the unencrypted nature of the Wi-Fi networks did not make the data transmitted over them "readily accessible to the general public" because the data was still difficult for an ordinary person to intercept. EPIC filed a "friend of the court" brief in the case urging the court to uphold legal protections for Wi-Fi communications, and discussing both the intent of the federal law and the operation of a typical home W-Fi network. For more information, see EPIC: Ben Joffe v. Google and EPIC: Google Street View.

September 11, 2013

"NSA Surveillance and the Legacy of 9/11"

"NSA Surveillance and the Legacy of 9/11"

Marc Rotenberg,
EPIC Executive Director

Kojo Nnamdi Show
WAMU.ORG
September 11, 2013

September 26, 2013

"Terms and Conditions May Apply" Discussion

"Terms and Conditions May Apply" Discussion

Amie Stepanovich,
Director, EPIC Domestic Surveillance Project

Camden International Film Festival
Camden, ME
September 26-29, 2013

September 11, 2013

Office of National Intelligence Releases New Documents on NSA Surveillance

The Office of the Director of National Intelligence has just released new documents concerning the NSA's surveillance programs. The documents, which include numerous filings with the Foreign Intelligence Surveillance Court, date back to 2006. The documents specifically relate to the governments collection of information under Section 215 of the USA PATRIOT Act. In a Mandamus Petition to the United States Supreme Court, EPIC has argued that the FISA Court exceeded the statutory authority under Section 215 when it authorized bulk collection of American's telephone records in an Order concerning Verizon. Under Section 215, the FISA Court may order businesses to produce records that are "relevant" to an authorized national security investigation, but the Verizon Order requires production of all domestic telephone records on an ongoing basis. For more information, see EPIC: In re EPIC - NSA Telephone Records Surveillance.

September 30, 2013

"Inquiry on Electronic Mass Surveillance of EU Citizens"

"Inquiry on Electronic Mass Surveillance of EU Citizens"

Marc Rotenberg,
EPIC President

LIBE Committee
European Parliament
Brussels, Belgium
30 September 2013

September 9, 2013

EPIC Meets with President's Intelligence Review Group

EPIC President Marc Rotenberg and EPIC Advisory Board Member Steve Aftergood met today with the Review Group on Intelligence and Communication Technology. The President tasked the panel with the responsibility to assess whether the "United States employs its technical collection capabilities in a manner that optimally protects our national security and advances our foreign policy while appropriately accounting for other policy considerations, such as the risk of unauthorized disclosure and our need to maintain the public trust." EPIC submitted detailed recommendations and included copies of EPIC's Supreme Court petition, arguing that the current domestic surveillance program is unlawful, as well as EPIC's Congressional testimony on the FISA Amendments Act and EPIC's 2010 letter to the Foreign Intelligence Surveillance Court concerning reform of FISA procedures. The panel will accept comments from the public until October 4, 2013. Comments are to be sent to reviewgroup@dni.gov, which oddly is the domain of the current Director of National Intelligence.

September 17, 2013

"Privacy, National Security, and Law Enforcement"

"Privacy, National Security, and Law Enforcement"

Marc Rotenberg,
EPIC Executive Director

Center for Constitutional Studies
Orem, Utah
September 17, 2013

September 13, 2013

Pressure Mounts on Facebook to Withdraw Proposed Changes, New Scrutiny of "Faceprints"

Facebook is under increasing pressure to withdraw proposed changes that would allow the company to use the names, images, and content of Facebook users for advertising without consent. After EPIC and several privacy groups wrote to the Federal Trade Commission that the changes would violate a 2011 Consent Order, the Commission has opened an investigation. Senator Ed Markey also wrote to the FTC, stating that Facebook's changes "raise[] a number of questions about whether Facebook is improperly altering its privacy policy without proper user consent and, if the changes go into effect, the degree to which Facebook users will lose control over their personal information." Senator Al Franken has called on Facebook to reconsider expansion of its facial recognition activity. In a letter to Mark Zuckerberg, Senator Franken asked "How many face prints does Facebook have?" For more information, see EPIC: EPIC: Federal Trade Commission and EPIC: Facebook Privacy.

September 15, 2013

OECD Releases Updated Privacy Guidelines

The Organization for Economic Cooperation and Development has released the 2013 revisions to its privacy guidelines. The revisions build from the original guidelines, developed in 1980, and retain the core set of Fair Information Practices while updating the framework to address new challenges, such as national implementation and cross-border enforcement. The OECD explains that the revisions aim to "focus on the practical implementation of privacy protection" and to "address the global dimension of privacy through improved interoperability." EPIC Executive Director Marc Rotenberg, a member of the expert review group, has said that “the OECD Privacy Guidelines are the most influential international framework for privacy ever established.” For more information, see EPIC: International Privacy Standards.

September 18, 2013

Security, Freedom and Privacy in the Digital Age

Security, Freedom and Privacy in the Digital Age

Khaliah Barnes,
EPIC Administrative Law Counsel

Newseum
Washington, DC
September 18, 2013

TSA Seeks to Remove Privacy Act Safeguards for TSA PreCheck

The TSA has proposed to exempt a new TSA PreCheck database from important Privacy Act safeguards. TSA PreCheck allow the federal agency to grant expedited screening to certain travelers. The TSA PreCheck database contains personally identifiable information, including name, birthdate, biometric information, Social Security Number, and financial information. The TSA proposes to disclose TSA PreCheck applicant information to federal, state, tribal, local, territorial, and foreign governmental agencies. The TSA also proposes to exempt these records from the notification, access, and amendment provisions of the federal Privacy Act, the primary law that protects personal information held by the federal government. EPIC has previously testified before Congress that traveler screening procedures should follow all Privacy Act requirements. Comments on the proposed exemptions are due October 11, 2013.

September 26, 2013

The Foreign Intelligence Surveillance Act - What’s Working and What Needs Fixing?

The Foreign Intelligence Surveillance Act - What’s Working and What Needs Fixing?

Alan Butler,
EPIC Appellate Advocacy Counsel

Federal Communications Bar Association - Privacy and Data Security Committee
Washington, DC
September 26, 2013

September 19, 2013

FAIA: NSA Surveillance and Foreign Affairs

FAIA: NSA Surveillance and Foreign Affairs

Amie Stepanovich,
Director, EPIC Domestic Surveillance Project

Yale Law School, Information Society Project
New Haven, CT
September 19, 2013

September 24, 2013

Integrating Approaches to Privacy Across the Research Lifecycle

Integrating Approaches to Privacy Across the Research Lifecycle

Khaliah Barnes,
EPIC Administrative Law Counsel

Harvard School of Engineering and Applied Sciences
Cambridge, MA
September 24 - 25, 2013

September 20, 2013

Foreign Intelligence Court Releases Controversial Opinion on Domestic Telephone Records Program

The Foreign Intelligence Surveillance Court (FISC) has released an Opinion, justifying the NSA's telephone record collection program. In the Opinion, Judge Claire Eagan states that "there is no Fourth Amendment impediment to the collection" of all domestic call detail records. Judge Eagan also concluded that all domestic call detail records are "relevant" under Section 215 because "individuals associated with international terrorist organizations use telephonic systems to communicate" and because the government argued that bulk collection is 'necessary to create a historical repository of metadata' in order to identify 'known and unknown operatives. This FISC opinion was issued more than a month after EPIC filed its Mandamus Petition challenging the NSA domestic surveillance in the U.S. Supreme Court. The Eagan opinion has also been criticized by legal scholars. For more information, see In re EPIC.

September 21, 2013

Sen. Franken Questions Apple on iPhone Fingerprint Scanning

Senator Al Franken has raised questions about the privacy and security implications of the fingerprint reader on Apple's new iPhone 5S. "If someone hacks your password, you can change it—as many times as you want. You can't change your fingerprints," Senator Franken wrote. He also pressed Apple for additional details on the protection available to users against law enforcement access to biometric data. In Congressional testimony, EPIC has previously warned that biometric identifiers will "allow for greater data collection and tracking of individuals." For more information, see EPIC: Biometric Identifiers.

September 24, 2013

Senators Call for Public Report by IC Inspector General on NSA Surveillance

A bipartisan group of Senators, including the Chairman and Ranking Members of the Senate Judiciary Committee, have called for a full-scale review of the use of surveillance authorities by the intelligence community. The Senators emphasized that the findings and conclusions of this review be made public to "help promote greater oversight, transparency, and public accountability." The requested report would address activities conducted under Section 215 of the USA PATRIOT Act and Section 702 of the FISA, which includes the collection of the telephone call records of hundreds of millions of Americans. Specifically, the report would review the use and implementation of 215 and 702, the applicable minimization procedures, any improper use of the authorities, and examine the effectiveness over the 2010-2013 period. EPIC is currently challenging the order for bulk collection of domestic call records in its Petition for Writ of Mandamus in the U.S. Supreme Court. For more information, see In re EPIC and EPIC: FISA Reform.

California Enacts Strong Digital Privacy Law for Minors

California Gov. Jerry Brown today signed a law to protect Privacy Rights for California Minors in the Digital World. The law, which goes into effect Jan. 1, 2015, sets out a broad range of rights for minors concerning the collection and use of their personal information by commercial service providers. The law does not limit the rights of minors, it seeks to regulate the practices of businesses. EPIC has long advocated for the privacy rights of children, testifying before the House in 1996 in support of the Children's Online Privacy Protection Act and again before the Senate in 2010 as new technologies and business practices emerged. EPIC also wrote comments to the FTC in 2011 supporting stronger regulations to protect the data concerning children. Some organizations, financed by Internet companies, are opposing the legislation. For more information, see EPIC: Children's Online Privacy Protection Act.

September 25, 2013

EPIC FOIA Request Reveals No Evidence of NSA Interference with Tor Network

In response to a FOIA request to the BBG, EPIC has received 74 pages of documents that reveal no efforts by the NSA to undermine the security or reliability of the Tor network. Recent news reports show a concerted effort by the National Security Agency to compromise cryptographic standards set by the NIST as well as Android, iPhone, and BlackBerry encryption. The NSA and FBI have also targeted the communications of Tor users. EPIC will continue to pursue FOIA requests that shed light on the efforts of the intelligence community to undermine cryptographic standards. For more information, see EPIC v. BBG.

In EPIC FOIA lawsuit, ODNI Submits Documents for Court Review

Following EPIC's motion in a FOIA case against the Office of the Director of National Intelligence, the ODNI has submitted 21 disputed documents to a federal court regarding the consolidation of databases containing detailed personal information on US persons. The documents are among those EPIC requested through the Freedom of Information Act. ODNI withheld the documents and EPIC filed a lawsuit challenging the decision. EPIC is seeking the documents to determine whether the agency is complying with the Privacy Act. A federal judge ordered ODNI to produce the documents for the Court's examination. For more information, see EPIC: EPIC v. ODNI.

September 27, 2013

ABA Forum on Air and Space Law Annual Meeting

ABA Forum on Air and Space Law Annual Meeting

Khaliah Barnes,
EPIC Administrative Law Counsel

ABA Forum on Air and Space Law
New York, NY
September 27, 2013

September 25, 2013

MacArthur Foundation Withdraws From Consumer Cy Pres Settlement

The prestigious MacArthur Foundation has asked to be removed from a controversial consumer privacy settlement. The foundation noted that it was not an appropriate cy pres recipient and asked that the funds be "redirected to other non-profit organizations engaged in the underlying issues." Consumer privacy organizations, including EPIC, have opposed the Fraley settlement stating that it violates a 2011 consent order with the Federal Trade Commission and that the cy pres allocations proposed do not reflect the interests of the class or the purpose of the litigation. A recent survey by Gigaom found that many of the named organizations are funded by Facebook and have no plans to assist class members. Public Citizen has appealed the settlement to the Ninth Circuit. The Federal Trade Commission has opened an investigation and Facebook has suspended implementation of the proposed privacy changes that would result from the settlement. For more information, see EPIC: Fraley v. Facebook.

Senator Leahy Urges FISA Reform at Georgetown Law

Speaking at a conference hosted by the Georgetown University Law Center, the Chairman of the Senate Judiciary Committee called for an end "to the bulk collection of Americans' phone records." Senator Leahy said "the system set up in the 1970s to regulate the surveillance capabilities of our Intelligence Community is no longer working. We must recalibrate." Senator Leahy has introduced bipartisan legislation that would end the telephone record collection program, reduce secret law, and improve the structure of the Foreign Intelligence Surveillance Court. The Senate Judiciary Committee will hold an oversight hearing next week on the Foreign Intelligence Surveillance Act. EPIC has filed a petition with the US Supreme Court, arguing that the bulk collection of telephone toll records is unlawful. For more information, see EPIC - In re EPIC.

NGOs, Experts, Officials Gather in Warsaw for Public Voice Conference

NGO leaders, privacy experts, and government officials from around the world gathered in Warsaw, Poland for the event "Our Data, Our Lives." The Public Voice conference was held in conjunction with the 35th International Conference of Data Protection and Privacy Commissioners. Following the revelations this year of mass surveillance of US and EU citizens, there was extensive discussion of the need for greater oversight, transparency and accountability. Two NGO documents -- the Madrid Privacy Declaration and 13 International Principles on the Application of Human Rights to Communication Surveillance -- were put forward as vital policy frameworks. The Privacy Commissioners also adopted several resolutions.

September 26, 2013

Court Rules that Gmail Case Can Go Forward, Internet Users Do Not Consent to Routine Inspection of Private Email

A federal district court has ruled that Google may have violated the federal Wiretap Act when it routinely intercepted, read, and acquired the contents of email users for advertising purposes. "The court finds that it cannot conclude that any party -- Gmail users or non-Gmail users -- has consented to Google's reading of e-mail for the purposes of creating user profiles or providing targeted advertising," Judge Lucy Koh stated. The court rejected arguments from Google that the activity occurred in the "ordinary course of business." The court said that the interception must be "instrumental" to the provision of an email service and that Google's business interest was not sufficient to meet that test. The court also found that Google had not obtained consent from users for the ad profiling practices. According to the court, "Google has cited no case that stands for the proposition that users who send emails impliedly consent to interceptions and use of their communications by other . . . than the indented recipient of the email." The ruling applies also applies to Google Apps for Education, through which Google obtains emails from educational organizations of students, faculty, staff, and alumni. For more information, see EPIC - Gmail Privacy FAQ.

About September 2013

This page contains all entries posted to epic.org in September 2013. They are listed from oldest to newest.

August 2013 is the previous archive.

October 2013 is the next archive.

Many more can be found on the main index page or by looking through the archives.