Posts

Showing posts with the label privacy

A Privacy Engineer's Guide to the EU AI Act

Image
I've been thinking about the ways the EU AI Act's requirements fit within existing privacy review or software development processes more generally. After the past few years of gradually improving data governance practices thanks to GDPR and other sources, tossing in a few more compliance requirements shouldn't be a big deal, right? Here are some answers and plenty of references for those who are just getting started. What is it? The EU AI Act is a risk-based framework for evaluating creation, use, and deployment of models. Some uses of AI are strictly prohibited, while requirements for others vary. Here's the raw text and a helpful AI Act Explorer .  Obligations are based primarily on whether you're a provider (of a general-purpose AI system) or deployer. (Definitions here .) It will be interesting to see where the line is drawn between provider and deployer; in other words, whether a deployer can modify a general purpose system enough to become a provider. Jurisdi...

Privacy by Design References

(This was written and first published elsewhere in June 2020) Below are some resources that have been useful as I've been exploring the relationship between privacy by design and engineering.

Changing PDF Metadata with Python

While updating a pdf recently, I noticed some metadata I wanted to change and a few annotations that were hidden from view but still in the file. However, the "Get Info" pane in Preview on OS X doesn't provide a metadata editor, nor does its Export function, so it seemed like a good opportunity to learn a bit more about the PDF standard and Python packages for getting the job done. Adobe Acrobat or other GUI's would've been much faster, but I'll likely need to do this programmatically again at some point like those of you who might've found this post by looking on your favorite privacy-preserving search engine for "change pdf metadata in python". So here we go. Before starting, I hopped into a new folder and created a git repository with a first commit of my original pdf in case anything went wrong. Then I ran conda create --name pdf --python=3.8.1 and conda activate pdf to set up an Anaconda virtual Environment named pdf to keep my work is...

Thinking About BIPA and Machine Learning

One article that really caught my attention recently discussed the use of Creative Commons-licensed images from Flickr as part of the MegaFace dataset for training facial recognition algorithms. Despite its aggressive (but not untrue) title, it highlights the many sides of the questions we the people and we the companies building products with these technologies face confront. Focusing on the licensing, Flickr truly expanded the available commons of openly-licensed images by allowing its community to choose Creative Commons (CC) licenses. Interestingly, the latest version of the most permissive CC license expressly does not license "publicity, privacy, and/or other similar personality rights", yet the licensor agrees not to assert such rights to the extent necessary to support the rest of the license. However, previous versions of this or other CC licenses probably apply to many photos in the data set, and not all of the other licenses contain this language. For the Cre...

Where's Our 86.4%?

Over the past few weeks as the scope and nature of the government's surveillance activities have been revealed, citizens have been nothing less than outraged. Or have they? A recent Pew Research survey shows a majority of Americans find the NSA's surveillance of phone records to be acceptable, while a substantial minority go the other way. As Tim Cushing explains on TechDirt , a Rasmussen poll covering the same period showed that only 26% of Americans approved. Cushing notes that the differences may reflect the phrasing of questions in each poll, or potentially unawareness or ambivalence of the severity of what's been going on. A recent Gallup poll also supports the view that most of us have had enough. As scholars and activists have reminded us for years , "if you have nothing to hide, you should have nothing to worry about" is just a slippery slope to a loss of fundamental freedoms and merely leaves us vulnerable . While reading a draft of the forthcoming ...

Mapping out the Rosen Docket

Federal prosecutors in D.C. typically provide notice to a person after receiving court approval to track them with geolocation data. However, after obtaining a warrant to search journalist James Rosen's Gmail account in May 2010, the government argued it did not have any obligation to provide the same notice to the customer/subscriber when it comes to email and ultimately won. The difference comes down to the different provisions under ECPA and other procedural rules under which the government obtains warrants for the different types of information. Check out the ACLU's post for an overview, or this link for my summary of the arguments contained in the recently unsealed documents. Keep in mind that the issue here is the ECPA language applied to the government's disclosure obligations, not the service provider's, although the latter is often prohibited from giving the user notice.

Weekend Project

After first setting out to create something along the lines of Click-That-Hood with legal information about different jurisdictions, I decided to create a slightly more robust document management system to help keep track of existing and developing legal issues related to privacy law in U.S. states and/or nationwide. As someone frequently collecting references, annotating documents, bookmarking pages, etc, I wanted to bring things together in a way that also lets me play around more in Drupal 7. I intend to add features like news/API feeds, map enhancements and maybe even calendar reminders (for when a law takes effect, for example). There are some great tools out their to do similar things but I see this potentially turning into somewhere between a reference manager, CMS and task manager. You know, because none of those have been made before :) You can take a peek at how it's coming along here .

A Bright Line in a Blurry Landscape

Image
The law is in a state of flux regarding the government's ability to search the contents of an arrestee's cell phone without a warrant. Should a higher standard apply given the breadth of information stored or one's expectation of privacy? Is it really that different from poking through the contents of a wallet? What if it's not password-protected? The First Circuit recently parted ways with most other courts by announcing a very bright line rule in United States v. Wurie . The court decided that an officer's viewing of a suspect's call log after seeing "my house" calling constituted a search under the Fourth Amendment. (HT @slashdot ) Without needing a password, the police looked up "my house" and matched it to a house where they later found Wurie's name on the mailbox. The police then obtained a warrant to search the property and eventually found crack, marijuana, ammunition, drug paraphernalia and more. The issue is whether the warran...

Song-Beverly and PII

Last week, the California Supreme Court decided a case ( pdf ) involving application of the  Song-Beverly Credit Card Act, California Civil Code 1747 , to the collection of telephone numbers and addresses by Apple during the sale of iTunes downloads. The majority reached a narrow, fact-based holding that there's no support in the legislative intent or statutory scheme to apply the Act to electronic transactions involving downloads. Three justices signed on to two written dissents expressing myriad concerns with the majority's difficult reading of the statute. Section 1747.08 of the Act prohibits retailers from collecting "personal identification information" or requiring it to be written on transaction forms for credit card transactions. The Act defines PII as “information concerning the cardholder, other than information set forth on the credit card, and including, but not limited to, the cardholder’s address and telephone number.” The majority acknowledges a...

Some Thoughts on The Net Delusion

Evgeny Morozov's The Net Delusion had been on my reading list since it debuted to much fanfare in early 2011.  I left the book with the impression that the author had painted the "cyber-utopians" he so carefully tears apart with too broad a brush by ignoring the nuance of others' arguments while fighting the propagation of substance-deficient general interest news media and politicians' sugarcoated information freedom platitudes.  While necessary at times and supportive of his points, at others it seemed unnecessarily antagonistic.  Overall, The Net Delusion makes clear how easy it is to ignore or obscure the root causes of socio-political problems when we place too much blind faith in the church of techno-evangelism.  Regardless of my inflated expectations and any criticism contained in this post, the book is a must-read. The author begins by distinguishing cyber-utopians from Internet-centrists, noting that "cyber-utopianism stipulates what has to be do...

Pounds of Mail and Corporate Twitter Policy

Image
Since moving within the past year, I've been amazed by the amount of junkmail I get.  So, I started keeping track of it on June 20.   Last week, I looked down at the mounting pile on my floor and assumed it had to be at least one pound.  Easily, about 1.5.  Naturally, I tweeted it: " it took less than a month for me to receive one POUND of credit card offers in the mail from 3 banks. (mostly from chase & citi)."  When I weighed the pile and it clocked in at TWO POUNDS, I opened the draft of this blog post containing my plan to calculate the costs and realized it had been nearly two months - 7 weeks and 2 days - since I started collecting the junk.  Either way, a pound in over three weeks (July 20 - August 8) or two pounds in 7 weeks and 2 days (June 20 - August 8), at least the volume is consistently annoying.  Anyways, Citi had already responded to my tweet so I left it alone.  " @ joemerante I can help stop the offers. Pls DM the nam...

Some thoughts on COICA and ACTA

S. 3804: Combating Online Infringements and Counterfeits Act ("COICA") is on its way to the full Senate after breezing through Committee 19-0.  It provides procedures for the U.S. Attorney General ("AG") to shut down a web site that is "primarily designed, has no demonstrable, commercially significant purpose or use other than, or is marketed by its operator, or by a person acting in concert with the operator..." to violate copyright or trademark rights.  The provisions are slightly more detailed in terms of what the AG must show in order to temporarily or permanently shut down a site (not much!), jurisdictional (in rem proceedings) and appeal issues, and other fun stuff found in a piece of legislation (except this one's got a distinct "guilty until proven innocent" ring to it), but that's the gist of it.  See here for a rundown of the threats to free speech, innovation and internet architecture contained in the bill as currently writte...

----book

Tonight I had the pleasure of watching a great program on CNBC, “Executive Vision: Leadership in Action – Technology”. The panel discussion spanned nearly every hot topic in technology, including cybersecurity, global development, jobs, U.S. and/versus foreign education, IP, broadband infrastructure and [you name it]. You can find out more about the show and the series here . One statement struck me: “Social networking has become like air, you don’t notice it until it’s missing.”  I’m sure others have made the same or similar observations; this time it came from Nicholas Negroponte.  I agree with his statement for the most part but come at it from a slightly different angle. In late 2008, when Facebook became (IMHO) overrun by apps and had recently opened registration to anyone (not just those with a .edu or school-specific email), I decided I’d had enough. After watching Myspace become totally overrun by spammers, I feared the worst for Facebook.  I'm fine with o...