Reports from news outlets (NY Times, CBC) suggest that the target of the FBI raid was Lulz Group, a hacker organization that are allegedly responsible for some high profile hacks such as Sony and, possibly, the CIA.
Regardless of the target, the FBI's tactics have been criticized as being heavy handed, though they may be justified in that the target was a purported hacker ring who may have had various assets stored on adjacent equipment hosted by their data center provider. While I am not a lawyer, it is incumbent on the FBI to ensure that all private information remains private and that it is not disclosed publicly, by accident or by design; the warrant should limit their investigation to information that is relevant to the target.
I will continue to look for information related to this event and will post more as it becomes available.
The Case for Cloud is an ongoing discussion about cloud computing and how it impacts business and the economy.
Showing posts with label privacy. Show all posts
Showing posts with label privacy. Show all posts
Jun 28, 2011
May 2, 2011
What does the election in Canada and cloud computing have in common? Issues with Article 329.
Canada is a big country. Really. Big. So big, it has 6 time zones; by the time the West coast wakes up, the East coast has already had 3-4.5 hours of productive time. So big, in fact, that election results from the East coast are available before polling stations close on the West coast. And, if you Tweet, blog, or post on a wall in Facebook about results in the East before polls have closed in the West, you're breaking the law. Go figure.
In this day and age of social media and ubiquity of computing, the ability to share information is so great, that it can accelerate revolution. You know, the kind that deposes authoritarian governments? Despots aside, this technology can land you in trouble if you share election results. There is a section of the Canada Elections Act that governs "Premature Transmission":
In a sense, social media is the wild west: it is difficult to control and regulate, applicable laws are a grey area at best, and there are as many opinions are there are users. What, then, is the responsibility of the service providers such as Twitter and Facebook? Private information being what it is, and terms of use being what they are, are Twitter and Facebook, US based companies, obligated to divulge private information of users who are being investigated by Elections Canada and/or the RCMP for violations of Section 329? Can Canadian users hide behind US companies?
Assuming that the charges are specific, which they would be considering the infraction, these organizations would simply comply with a subpoena or warrant. Not to mention that your hardware would be confiscated and used to collect evidence against you. What does this mean? Your footprint is out there. Even if you delete an account, data persists in backups and can be used to build a case against you.
Obviously this was intended to keep elections fair and to avoid influencing voters in an era of television and radio broadcasts. Clearly, the Elections Act never contemplated that information could be shared in such an environment as the Internet, and particularly, in social media. Changes to the electoral procedure have reduced this discrepancy between East and West down to 1.5 hours but this gap is sufficient to be in violation of the law.
Legalities and discourse on right and wrong aside, this is a good example of a Government's right to prosecute an individual and obtain private information in an effort to enforce law. However archaic it may be.
In this day and age of social media and ubiquity of computing, the ability to share information is so great, that it can accelerate revolution. You know, the kind that deposes authoritarian governments? Despots aside, this technology can land you in trouble if you share election results. There is a section of the Canada Elections Act that governs "Premature Transmission":
"329. No person shall transmit the result or purported result of the vote in an electoral district to the public in another electoral district before the close of all of the polling stations in that other electoral district."
Assuming that the charges are specific, which they would be considering the infraction, these organizations would simply comply with a subpoena or warrant. Not to mention that your hardware would be confiscated and used to collect evidence against you. What does this mean? Your footprint is out there. Even if you delete an account, data persists in backups and can be used to build a case against you.
Obviously this was intended to keep elections fair and to avoid influencing voters in an era of television and radio broadcasts. Clearly, the Elections Act never contemplated that information could be shared in such an environment as the Internet, and particularly, in social media. Changes to the electoral procedure have reduced this discrepancy between East and West down to 1.5 hours but this gap is sufficient to be in violation of the law.
Legalities and discourse on right and wrong aside, this is a good example of a Government's right to prosecute an individual and obtain private information in an effort to enforce law. However archaic it may be.
Labels:
government,
law,
privacy,
regulation
Mar 11, 2011
Takeaway #1 from Cloud Connect 2011
Cloud Connect this year was excellent and brought with it some maturity to cloud computing.
It seems that there was some consensus about whether it's all about public or private clouds with proponents at both ends of the spectrum. To paraphrase, it's not really about the hardware any more.
There is no doubt that adoption is gaining momentum (double and triple digit rates for the current leaders); regulatory authorities and industry must now engage each other to further advance the agenda instead of staring at each other and wondering who will blink first.
It seems that there was some consensus about whether it's all about public or private clouds with proponents at both ends of the spectrum. To paraphrase, it's not really about the hardware any more.
- A purely public cloud is somewhat of a holy grail - a "cloudtopia", to coin a term - and can only occur once all regulatory hurdles, such as privacy concerns, have been overcome. Will this ever happen? No one knows for sure.
- Private cloud seems to be the solution for those organizations and industries that have a low tolerance to risk and prefer to control their environment. How can these organizations relax their governance?
There is no doubt that adoption is gaining momentum (double and triple digit rates for the current leaders); regulatory authorities and industry must now engage each other to further advance the agenda instead of staring at each other and wondering who will blink first.
Labels:
cloud based services,
cloud connect,
privacy,
regulation
Mar 9, 2011
Changing Concepts of Privacy and Self
Larry Clinton, President and CEO of the Internet Security Alliance, brought up an interesting point regarding privacy during his session at Cloud Connect: subsequent generations will think differently about privacy. This may or may not force law makers to reconsider the definition of privacy and their related laws.
To illustrate this, and I'm paraphrasing this next bit, he gave an example of teens using Facebook and the future risk of employers finding unacceptable content during a hypothetical interview process. "By that time, the interviewer will have had their own Facebook page and won't care what's on mine." It is interesting to think that the concept of self, also changed by the Internet, has been redefined to include a digital self or reasonable facsimile (Facebook, LinkedIn, Twitter, etc.) and has blurred personal boundaries.
Privacy law and regulation may need to change. Current privacy laws in Canada, the US, and more extensively in the EU, protect private information. It is not unreasonable to think that, at some point, it will be up to the individual to opt to disclose information of their choosing. That said, the cost of retooling the laws and implementing processes capable of permitting such freedom might be prohibitive.
To illustrate this, and I'm paraphrasing this next bit, he gave an example of teens using Facebook and the future risk of employers finding unacceptable content during a hypothetical interview process. "By that time, the interviewer will have had their own Facebook page and won't care what's on mine." It is interesting to think that the concept of self, also changed by the Internet, has been redefined to include a digital self or reasonable facsimile (Facebook, LinkedIn, Twitter, etc.) and has blurred personal boundaries.
Privacy law and regulation may need to change. Current privacy laws in Canada, the US, and more extensively in the EU, protect private information. It is not unreasonable to think that, at some point, it will be up to the individual to opt to disclose information of their choosing. That said, the cost of retooling the laws and implementing processes capable of permitting such freedom might be prohibitive.
Labels:
cloud connect,
Facebook,
LinkedIn,
privacy,
Twitter
May 27, 2010
Jurisdiction, or, I have to comply with whose laws?
Judith Hurwitz, of Hurwitz & Associates, has a slide in one of her presentations that refers to protecting data in the cloud and reads, "Government and Industry regulation must be adhered to regardless of the location of your applications and your information."
The first thing that popped into mind was the classic 70s cop show scene where the cops, all sporting mutton chops and polyester leisure suites, are arguing about ownership of the crime scene...
The next thing that popped into mind was how confusing this must be; organizations have to be aware of, and comply with, the laws and/or regulations that apply to their operations in the country where the application(s) and data sit as well as their own country's. There can be no other interpretation of the slide because we know that privacy laws in Europe can be tough and those in the US are different but yet there is an expectation of data privacy in both jurisdictions. The slide deck contains several examples ranging from specific country laws, co-mingling of data, secondary data use, and the next point, data transfer across borders.
What about data in transit? Is data subject to the laws and/or regulations of the jurisdictions through which it passes en route to/from the site hosting the application? There are restrictions on sending data out of some European countries unless the receiving end complies with European requirements on data security, but what of the countries in between? Data stored in Europe usually go through gateways to get to North America and then through a gateway into the US, Canada, or Mexico and vice-versa. I suppose that the argument can be made that data in transit over backbone infrastructure is not susceptible to attack. But then I recall a certain government agency that wanted to snoop Internet data streams not too long ago...
What of the end users' expectation of privacy? If these users are in yet another country, can the requirements of that country be imposed on the applications' owner? Can lawsuits be filed in this case?
The simplest and most efficient solution would be to comply with the common requirements and the most stringent requirements from each country in order to be compliant with all. Not sure if this is the answer but it seems that it could be. Then again, I'm no lawyer so I may be wrong here.
The first thing that popped into mind was the classic 70s cop show scene where the cops, all sporting mutton chops and polyester leisure suites, are arguing about ownership of the crime scene...
The next thing that popped into mind was how confusing this must be; organizations have to be aware of, and comply with, the laws and/or regulations that apply to their operations in the country where the application(s) and data sit as well as their own country's. There can be no other interpretation of the slide because we know that privacy laws in Europe can be tough and those in the US are different but yet there is an expectation of data privacy in both jurisdictions. The slide deck contains several examples ranging from specific country laws, co-mingling of data, secondary data use, and the next point, data transfer across borders.
What about data in transit? Is data subject to the laws and/or regulations of the jurisdictions through which it passes en route to/from the site hosting the application? There are restrictions on sending data out of some European countries unless the receiving end complies with European requirements on data security, but what of the countries in between? Data stored in Europe usually go through gateways to get to North America and then through a gateway into the US, Canada, or Mexico and vice-versa. I suppose that the argument can be made that data in transit over backbone infrastructure is not susceptible to attack. But then I recall a certain government agency that wanted to snoop Internet data streams not too long ago...
What of the end users' expectation of privacy? If these users are in yet another country, can the requirements of that country be imposed on the applications' owner? Can lawsuits be filed in this case?
The simplest and most efficient solution would be to comply with the common requirements and the most stringent requirements from each country in order to be compliant with all. Not sure if this is the answer but it seems that it could be. Then again, I'm no lawyer so I may be wrong here.
Labels:
cloud,
governance,
law,
privacy
Subscribe to:
Posts (Atom)