Monthly Archives: July 2011

The Spirit of Rube Goldberg

… is alive and well and taking photos in Canada.

httpv://www.youtube.com/watch?v=qKpxd8hzOcQ

Posted in Completely Different | 1 Comment

What Happens to the FDIC if the Debt Ceiling Is Not Raised?

If the US hits the debt ceiling, will there be a run on the banks?

And if there is, would the dept ceiling impose any limits on the FDIC’s ability to raise funds in the event of a bank failure?

The two questions seem the same to me: if there is confidence that the FDIC will have all the funds it needs, there will not be a run on the banks. But if there is any doubt, there will be, creating the very problem…

So, does anyone know if the FDIC would be limited or not?

Posted in Econ & Money | 11 Comments

Blogging: The Rules (per Jonathan Rauch)

My friend Jonathan Rauch discloses his plans.

While I’m blogging, I’m going to try to observe a few rules.

1) No second drafts. There isn’t time.

2) No reporting. There isn’t money.

3) Factuality is approximate.

4) Crabbiness is allowed.

I think he could be quite good at it.

Posted in Blogs | 2 Comments

Happy Shark Awareness Day

Today is Shark Awareness Day. Let me be the first to wish you joy on this happy occasion.

(Insert lawyer joke here — or in the comments.)

It is also Bastille Day.


Shark image copyright © 2006 Joe Lencioni, licensed via Creative Commons Attribution-NonCommercial-ShareAlike 2.5 License.

Posted in Completely Different | Comments Off on Happy Shark Awareness Day

Crypto: The Sky Did Not Fall

In Wiretapping and Cryptography Today Matt Blaze looks at the latest 2010 U.S. Wiretap Report and discusses why, despite all the predictions of doom we heard about strong crypto 15 years ago, in fact crypto has basically no effect at all on law enforcement ability to pursue an ever-increasing number of wiretaps:

the latest wiretap report identifies a total of just six (out of 3194) cases in which encryption was encountered, and that prevented recovery of evidence a grand total of … (drumroll) … zero times. Not once. Previous wiretap reports have indicated similarly minuscule numbers.

What’s going on here? Shouldn’t all this encryption be affecting government eavesdroppers at least a little bit more than the wiretap report suggests? Do the police know something about cryptanalysis that the rest of us don’t, enabling them to effortlessly decrypt criminal messages in real time without batting an eye? Is AES (the federally-approved algorithm that won an open international competition for a new standard block cipher in 2001) part of an elaborate conspiracy to lull us into a sense of complacency while enabling the government to secretly spy on us? Perhaps, but the likely truth is far less exciting, and ultimately, probably more comforting.

The answer is that faced with encryption, capable investigators in federal and local law enforcement have done what they have always done when new technology comes around: they’ve adapted their methods in order to get their work done.

Remember this the next time an earnest government official explains why they just have to store all your online communications for a couple of years.

Posted in Cryptography, National Security | Comments Off on Crypto: The Sky Did Not Fall

My Day With the DPIAC

I spent yesterday as a ‘special government employee’ — for no salary. This was the start of my two-year term as a member of the DHS Data Privacy and Integrity Advisory Committee (the DPIAC — pronounced “dippie-ack”) — some two years after being asked to apply — and I attended my first meeting today in Washington DC, which was a public meeting of the committee. Advisory committees are a pretty mixed bag in DC, but the people I knew who were already involved in the process assured me that the committee actually helps influence outcomes, if only by helping build a record for things to happen. There’s nice short description of the committee at the IT Law Wiki and the DPIAC Charter is online too.

The committee’s primary contact in DHS is Mary Ellen Callahan, the Chief Privacy Officer (CPO) for the DHS, and she opened the meeting. She noted that the DPIAC published a Federal Register notice at 76 Fed Reg 39406 (July 6, 2011) asking for new members, for two-year terms ending 2014; applications are due August 15, 2011. Be advised that membership requires a Secret clearance, and filling out the forms is a royal pain if you have done any substantial foreign travel, or have any recurring foreign contacts (I fit both descriptions).

The meeting was ably chaired by Richard Purcell, who among other things is the Chair of TRUSTEe, and was formerly CPO of Microsoft. In addition to the committee members, there were about 45 people in the audience, about half of whom, I was told, were either from DHS or from privacy offices in other agencies.

The first item on the agenda was an address by Jane Holl Lute, the Deputy Secretary of the DHS, who spoke about International Information Sharing Programs — ie data sharing with the EU over PNR. (Although she was extraordinarily eloquent, parts of it made me want to channel Ed Hasbrouck.)

Deputy Secretary Lute framed ‘data sharing’ as being in the service of ‘security’. But, she said the EU said, we don’t want security at the expense of our rights. To which she says she replied that ‘security is one of our rights’. (This seemed to me to leave out the possibility of there being costs of information sharing.) “We are trying to build a safe secure resilient place where the American way of life can thrive.” In 10 years of dealing with PNR, she said, “we haven’t had a single privacy incident.” (A ‘privacy incident’, it later transpired, is measured by the OMB definition — an unauthorized access or disclosure ie a data breach. This doesn’t of course tell us anything about what is going on with the authorized uses.) We didn’t want to re-open negotiations…we had a perfectly functioning agreement…it just wasn’t as good as some voices in Europe thought it could be in terms of privacy principles.

In the Q&A I asked what effect recent work on the failure of de-anonymization would have on the work of her department. Deputy Sec Lute’s long and elegant reply boiled down to saying tht the nature of the beast is that law and regulation are always going to lag the technology, which I found pragmatic but unsatisfying.

Another panel member asked what the policy was regarding other governments copying the US policies and doing to US citizens what we do to them — getting US person data and using it? Again the answer was the elegant form of cagey, although DepSec Lute did mention that the law enforcement community had told DHS that it needed to keeping all data that it thought might be relevant to possible international conspiracy for 15 years. (I wondered what fraction of the data collected on foreign travelers that would be?)

Mary Ellen Callahan, the DHS CPO spoke second, and provided an acronym-rich account of her department’s recent work. The office is certainly busy, both on projects it seems to have initiated to ensure that PII is handled carefully within DHS, and on projects that arise out of data sharing agreements, e.g. five new information sharing agreement (ISAAs) with the national counter-terrorism center (NCTC) — oh joy. I suspect that rather than mis-transcribing this rapid-fire account, I’ll have to wait for the meeting minutes (there were verbatim transcripts of previous meetings, but we were told these are being discontinued due to the budget cuts; the Federal Advisory Committee Act (FACA) only requires minues so that’s what we’ll have henceforth).

CPO Callahan also does FOIA for DHS, and its seems the DHS is the government leader in FOIA requests, having already gotten over 100,000 this year (the Dept of Defense had only 75,000 last year). 75% of the FOIA traffic is CIS — immigration related. Part of increase is due to fact that response time is better, so it encourages people to file. Some of the bulk is also from communities worried about immigration reform and/or enforcement activities.

Emily Andrew, Senior Privacy Officer, National Protection and Programs Directorate (NPPD), DHS spoke third, and described an office that had been a team of one when she started there, but has been growing rapidly.

Current DPIAC members are: Chair Richard V. Purcell (Corporate Privacy Group), Members: Joseph Alhadeff (Oracle), Ana Anton (NC State Computer Science), Ramon Barquin (Barquin Int’l), J. Joward Beales III (GWU Management & Public Policy), Renard Francois (Caterpillar Inc.), Yours Truly, Joanna L. Grama (Purdue IT), David Hoffman (Intel), Lance Hoffman (GWU Computer Science), Joanne McNabb (Cal Dept. of Consumer Affairs), Lisa S. Neslon (U. Pitt, Public & Int’l Affairs), Greg Nojeim (CDT), Charles Palmer (IBM), Lydia Parnes (Wilson Sonsini & ex-FTC), Christopehr Pierson (Citizens Financial Group/RBS), Jules Polonetsky (Future of Privacy Forum), John Sabo (CA Technologies), Ho Sik Shin (Millennial Media, Inc), Lisa J.Sotto (Hunton & Williams), Barry Steinhard (Privacy International, ex-ACLU).

It seems as if the DPIAC will have a busy fall. All of its work product, and all discussions other than subcommittee deliberations, are public documents, presented for discussion in public meetings, so I intend to at least blog pointers to them here as they come onstream.

Posted in Law: Privacy | 2 Comments