Online Privacy

Twitter Forced to Hand Over Occupy Wall Street Protester Info

By Naomi Gilens, ACLU Speech, Privacy and Technology Project at 5:28pm

This morning, faced with the threat of criminal and civil contempt, Twitter turned over information about Occupy Wall Street protester Malcolm Harris to a New York criminal court judge. This development follows Twitter’s months-long effort to challenge the Manhattan District Attorney Office’s subpoena for Harris’s information, which was issued as part of the D.A.’s disorderly conduct prosecution of Harris stemming from his participation at an Occupy event last fall.

Your Boss Shouldn’t Read Your Email

By Catherine Crump, Staff Attorney, ACLU Speech, Privacy and Technology Project at 5:02pm

Senator Charles Grassley got it right: officials at the Food and Drug Administration “have absolutely no business reading the private e-mails of their employees.”

On Sunday, the New York Times ran a lengthy story detailing how the FDA monitored the communications of its own scientists, including communications with members of Congress, lawyers and journalists. Those scientists had blown the whistle on what they believed were flawed internal procedures that led to the approval of unsafe medical imaging devices. The FDA engaged in a massive email monitoring campaign to read their communications—including their private, personal emails. The emails that the FDA collected included those of a former member of Senator Grassley’s staff, presumably because he had exchanged messages with one or more of the targeted FDA officials.

The Burdens of Total Surveillance

By Jay Stanley, Senior Policy Analyst, ACLU Speech, Privacy and Technology Project at 1:33pm

Last week’s Washington Post report that the CIA had requested that Boston bomber Tamerlan Tsarnaev be placed on a terrorist watch list raises an interesting point about total surveillance societies: in addition to all their negative implications for citizens, they actually bring some disadvantages for the authorities as well.

It’s not clear what information the CIA’s request was based upon, but reportedly it came from Russian authorities. It is also possible that Tsarnaev’s communications were flagged by US agencies such as the NSA. Either way, it seems as though there’s a real possibility that Tamerlan’s name came to the attention of the authorities through some dragnet-style surveillance technique.

If so, the conundrum for the authorities is this:

Why Won’t the IRS Deploy Basic Web Security?

By Katie Haas, ACLU Human Rights Program & Chris Soghoian, Principal Technologist and Senior Policy Analyst, ACLU Speech, Privacy and Technology Project at 10:45am

This tax season, when you visit the IRS’s website seeking tax information, can you be certain that no one else is monitoring which pages you browse?

Unfortunately, right now the answer to that question is “no.” Unlike Facebook, Twitter, Google Mail (Gmail), and virtually every bank and credit card company, the IRS, like most government agencies, does not use HTTPS for encryption and authentication on its website. If you try typing “mail.google.com” into your browser right now, you will see that the URL you end up at is actually “https://mail.google.com.” That “s” after the “http” may seem insignificant, but it means a lot. It signifies that Google is using Secure Sockets Layer encryption, or SSL, to both encrypt and authenticate its communications. When you visit google.com and you see “https” at the beginning of the address, it lets you know that your connection is secure, and that third parties – such as your internet service provider, employer, or university cannot monitor what you’re doing through the use of network interception technology.

White House-Led Effort to Create Online ID Standards Proceeding; Stakeholders Gather in Phoenix

By Jay Stanley, Senior Policy Analyst, ACLU Speech, Privacy and Technology Project at 2:32pm

In April 2011, the White House set forth a proposed "National Strategy for Trusted Identities in Cyberspace," or NSTIC. The document was a proposal to create a mechanism by which people could identify themselves online to another party with certainty—a long-elusive goal that has been talked about and pursued by the private sector and "identity community" for many years, without success.

Business Model vs. Fourth Amendment

By Jay Stanley, Senior Policy Analyst, ACLU Speech, Privacy and Technology Project at 5:10pm

I wrote recently about the U.S. government and companies lobbying against the EU’s attempt to strengthen their privacy laws, and our own efforts at the ACLU to advance high transnational privacy standards. Our efforts helped attract a round of press coverage of this unfolding drama (including stories in the New York Times and Washington Post). We’ve also written a letter along with other privacy groups to senior Obama Administration officials, asking for a meeting to discuss the issue.

Congressmen Question DOJ Following Release of Surveillance Documents on National Counterterrorism Center

By Naomi Gilens, ACLU Speech, Privacy and Technology Project at 4:06pm

As The Wall Street Journal reported last week, a new program run by the National Counterterrorism Center (NCTC) is collecting and analyzing all manner of government data on American citizens, even those not suspected of any crime. This sweeping surveillance program was enacted in secret, with no input from either the people or our representatives in Congress, and records that the ACLU has obtained through a Freedom of Information Act request make it clear that the program was controversial even among those who knew about it.

Does Using Certain Privacy Tools Expose You to Warrantless NSA Surveillance? ACLU Files FOIA to Find Out

By Chris Soghoian, Principal Technologist and Senior Policy Analyst, ACLU Speech, Privacy and Technology Project at 1:04pm

Can using privacy-enhancing tools (such as Tor or a Virtual Private Network) actually expose you to warrantless surveillance by the National Security Agency? This week, the ACLU sent off four FOIA requests to federal agencies in order to try and answer this question.

To understand why we think that may be the case, we have to go back to the passage of the FISA Amendments Act (FAA) in 2008. That act was not a high-point for civil liberties or the rule of law. It included a provision giving immunity to the telecom companies that violated the law by assisting the NSA with its warrantless wiretapping program. Although the get-out-of-jail-free card given to the phone companies is the most well-known aspect to the FAA, there is much more to the law, and many other things that give privacy advocates reason to worry.

Corporate America: We Want to Track You

By Chris Calabrese, Legislative Counsel, ACLU Washington Legislative Office at 5:44pm

On Monday an extraordinary letter went out from a who’s who of major corporations claiming a mandate to track all of us on the internet.  In tone and substance, it is an amazing, over-the-top screed against efforts to give consumers even modest controls over who watches us as we surf online.

The letter was triggered by Microsoft’s announcement in May that when it ships its new browser, IE 10, the browser’s default setting will be Do Not Track.  Microsoft heard the vast preference of its users and is giving them the default setting they want—no tracking of their movements and habits online. Consumers who want to get targeted ads will still be able to do so—and in fact will get a chance to turn that preference on when the program loads. As we said at the time, this is exactly the right decision, a powerful tool for giving back American’s their privacy online.

Is the ACLU Inconsistent on Regulation of Speech and Privacy?

By Jay Stanley, Senior Policy Analyst, ACLU Speech, Privacy and Technology Project at 3:02pm

Adam Thierer of the libertarian Mercatus Center posted a thoughtful critique of my recent piece on online tracking and consumer “choice.” I wrote about a new paper on behavioral advertising and how it “demonstrates the absurdity of the position that individuals who desire privacy must attempt to win a technological arms race with the multi-billion dollar internet-advertising industry.”

Statistics image