Showing posts with label privacy. Show all posts
Showing posts with label privacy. Show all posts

Sunday, June 25, 2023

BIG BROTHER - San Diego Police Department Spy Cameras



"Board rejects SDPD smart streetlight proposal Council may still approve plan for adding 500 cameras across city" by Lyndsay Winkley, San Diego Union-Tribune 25 Jun 2020

NOTE:  This was copied from the eNewspaper, so there is no link to the article.

The San Diego Police Department wants to spend millions of dollars to outfit a network of streetlights with sophisticated cameras.

This week, after months of deliberation, the Privacy Advisory Board — a volunteer group charged with evaluating the city’s surveillance technologies — issued their response to that request: No.

At a Thursday meeting that went late into the evening, six of eight board members voted to recommend to city officials that they not allow the streetlight program to move forward.

The vote marked a pivotal point in a process that started in September when the city’s new surveillance ordinance went into effect.  Under the legislation, city departments are required to disclose their surveillance technologies and compile reports outlining how those tools are used and their impact on communities.

That information then makes its way to the newly formed Privacy Advisory Board and, subsequently, to the City Council.  Council members will decide whether to adopt the board’s recommendation regarding the smart streetlights in the coming weeks.

The Police Department’s streetlight proposal was the first to be reviewed by the board, and the undertaking highlighted challenges that may plague the evaluation of future technologies.

Questions remain

Before voting on whether to support the technology, the board highlighted several pressing concerns.

Members felt the department hadn’t provided enough information about various aspects of the plan, including the purpose or goals of the streetlight program, how data would be collected and safeguarded, who would have access to the information gathered, how those individuals would be trained, and how the effectiveness of the technology would be assessed.

But one concern outweighed the rest.

Department officials have said they plan to install cameras made by Ubicquia, a telecommunications company, but no information has been provided about the vendor that would supply the accompanying automated license plate reader technology.

Board members said the ordinance requires that the department produce this information and that without it, they can’t effectively assess potential privacy or security risks the tools may pose.

“That’s why we keep asking all these questions, because we want to make sure that everything is spelled out as clearly as humanly possible,” said Pegah Parsi, board member and chief privacy officer at UC San Diego.  “We’re not trying to be obstructionist; we understand that the technology is here, but it’s very important for the Police Department and for the city to show how the cow eats the cabbage.”

Police officials said they haven’t provided information about a vendor because one hasn’t been selected.  Acting Capt. Charles Lara told the board during its meeting that, based on the department’s understanding of the ordinance, police need City Council approval of the technology before a company can be chosen.

It’s a challenge department officials expect will continue to crop up.

In a memo addressing several questions from the board, Lara said, “because of the way the ordinance was drafted, city departments will have to bring proposals without the purchasing and contracting process being completed, and all potential vendors being identified or selected.”

Seth Hall, a member of "TRUST San Diego Coalition," which helped craft the surveillance ordinance, said the department’s failure to provide even the name of a probable vendor flies in the face of the spirit of the legislation.

“They’ve said they welcome oversight,” Hall said.  “So welcome it.

“Bringing unknown technologies that you refused to identify, that we don’t even know who manufactures it or what it can or can’t do — that’s not participating,” Hall said.  “There’s no way for us to use that to inform the public.  It’s not sufficient.”

Report finds deficiencies

Hall, who is also the co-founder of San Diego Privacy, a community group that seeks to boost the public’s understanding of privacy issues, said his organization found serious flaws in the department’s plan.

The group compared the department’s proposed policies with best practices for video surveillance as established by organizations like the U.S. Department of Homeland Security and the Security Industry Association.

The result?  A 74-page report detailing 43 deficiencies and 69 recommendations for how the department could improve its approach.

One recommendation suggested the department include additional information in its policy about how the system will be evaluated to determine whether it is meeting its objectives.  Another recommended the department place more stringent limits on how other law enforcement agencies access data collected by San Diego’s system.

“When we compare the Police Department’s policy to the way the standards say that it should be written, we just come out with a bunch of stuff missing,” Hall said.

The group also raised concerns about provisions that appeared to allow the department to surveil private property with permission from the property owner.

Hall noted that many San Diegans are renters, and the department policy doesn’t specify that officials would need to obtain permission from tenants as well.

“Perhaps a department person will come along and say, ‘Yeah, that’s what we meant.   We’ll get approval from the people that it affects.’  But that’s not what they wrote,” Hall said.  “And that’s the primary problem here.  These policies need to be carefully written.”

Department officials have said they believe the documentation they have provided, including its proposed policies, complies with the city’s surveillance ordinance.

Over the last few months, police have responded to 111 questions from the board about the streetlight proposal.  Police leaders have also stated that, in addition to the privacy board’s review, the technology is subject to vetting through the city’s information technology processes.

“The Department and the City work tirelessly to ensure our information technology systems are sound, protected from malicious intrusions and protect the civil liberties and data of San Diegans,” Lara said in a recent memo to board members.

Community outcry

Many of these concerns were echoed by community members who attended Thursday’s meeting — in person and online — to speak out against the streetlights.

Speakers said they worried the technology would invade people’s privacy and fuel unequal enforcement in communities of color.  Many said they didn’t trust the police to be good stewards of such powerful tools and felt the money to fund the program could be better spent if funneled to community groups that are already working to prevent crime and violence across San Diego.

“The goal for this technology is to enforce more safety, but I feel it will do the complete opposite by targeting innocent people,” said 16-year-old Sumaya Abdullahi.  “My community is already targeted and watched enough, and this will make it worse.”

Abdullahi is a member of the Partnership for the Advancement of New Americans’ Youth Congress (PANA), a group that empowers young immigrants and refugees to participate in the organization’s policy work.

Moments after she spoke, other members of the Youth Congress who stood alongside her began to chant: “Every step we take, every move we make, we don’t want to be watched or surveiled — put the camera away.”

A few speakers voiced support for the technology, saying they were in favor of tools that would aid officers in solving crimes.

In the past, police and city officials have praised smart streetlights for their effectiveness, and cited their positive impact on police work as the reason for pursuing their installation.

In 2016, City Council members signed off on a $30 million project that pledged to use 3,000 energy-saving smart streetlights to assess traffic and parking patterns throughout the city.  What the public didn’t know — and wouldn’t know for years — was that the technology came with cameras that could be accessed by police.

The resulting outcry — based on concerns about privacy and equity — led San Diego to shut down the network and fueled the creation of the surveillance ordinance and the Privacy Advisory Board.

Before losing access to the technology, police had used footage from the smart streetlights to investigate hundreds of cases, including 56 homicides or attempted homicides, 55 robberies or burglaries and 55 assaults involving a weapon.

Smart streetlights installed in San Ysidro helped investigators zero in on a suspected gunman in the Nov. 6, 2019 shootings of three Church’s Chicken workers, one of whom was killed.

In downtown San Diego, they helped identify a man suspected of donning a costume mask and fatally shooting a business owner in October 2018.

Police officials also accessed streetlights 35 times to gather evidence against demonstrators suspected of committing crimes during protests held in the wake of George Floyd’s murder in 2020.

On Thursday, Lara thanked both the board and community members for their active participation in the process.

“The board is working vigorously to defend the privacy rights of San Diegans, and that is an important charge,” he said.  “I also want to acknowledge the time and passion of all the people who came to express their opinion regarding this proposed program.”

What’s next

Despite its vote against the program, the Privacy Advisory Board is not a decision-making body.

The Police Department plans to present the proposal to the City Council’s Public Safety Committee on July 19.  Sometime after that, the City Council will vote on whether the tool should be given the green light.

San Diego Mayor Todd Gloria has already spoken out in favor of the technology, and the $4 million needed to kick start the program is included in this year’s budget.

lyndsay.winkley@sduniontribune.com

My Questions

What protections are included in the contract with Ubicquia (or any other company chosen) contain to protect the company from recording the information on their cameras and selling it outside law enforcement?

How long will SDPD keep the recordings?  There should be a time limit.

What protections are included to ensure the recordings cannot be used by ANYONE outside Traffic Courts, without a warrant (no blanket warrants)?

The ordnance was poorly written if it did not include the SDPD submitting (and updating) a list of camera companies being looked at BEFORE choosing any.  This would have prevented the SDPD wasting time looking at companies that would be rejected.



Monday, January 15, 2018

NATIONAL SECURITY - The FISA Debate

"The privacy concerns at the heart of the FISA renewal debate" PBS NewsHour 1/11/2018

Excerpt

SUMMARY:  The House of Representatives voted to reauthorize a key provision [Section 702] of the Foreign Intelligence Surveillance Act, which U.S. intelligence agencies say is critical to collecting communications from overseas.  But the complex issue has sparked some heated debate and seemingly contradictory tweets from the President.  Judy Woodruff learns more from Susan Hennessey of Lawfare.

Monday, August 29, 2016

TOO MUCH INFO - WikiLeaks Becomes a Danger to Personal Privacy

"Why is WikiLeaks publishing private individuals' personal information?" PBS NewsHour 8/23/2016

Excerpt

SUMMARY:  WikiLeaks has revealed classified information to the public for over a decade.  A new Associated Press report found that the website has also published personal details about private citizens, including the names of two teenage rape victims and a Saudi citizen arrested for being gay.  Some of the leaks have the potential to endanger lives.  William Brangham speaks with AP's Raphael Satter for more.

JUDY WOODRUFF (NewsHour):  For a decade, the anti-secrecy Web site WikiLeaks has published online millions of original documents and other material — leaks that have exposed the inner workings of the National Security Agency, the U.S. military and State Department, the Saudi government and, most recently, the Democratic National Committee.

But a new report by the Associated Press says that many private individuals are caught up in the disclosures.

William Brangham has more.

WILLIAM BRANGHAM (NewsHour):  The AP went through a sampling of the tens of thousands of documents WikiLeaks released in the last year, and found many personal details about private citizens, Social Security numbers, medical files, sensitive family and financial information.

In what the AP calls particularly egregious, WikiLeaks published the names of two teenage rape victims, as well as the name of a Saudi citizen who'd been arrested for being gay.  That revelation could endanger the man's life because, in Saudi Arabia, being gay is punishable by death.

Joining me now from Paris is Raphael Satter, one of the AP reporters who wrote this story.

Raphael, thanks for being here.

I wonder if you could tell us, what made you, first off, want to do this deep dive into WikiLeaks in the first place?

RAPHAEL SATTER, Associated Press:  I covered the Saudi files released back in 2015, and there was an enormous amount of newsworthy information in there.

But as we were going through the files with my colleague Maggie, who co-wrote today's story, we noticed that there was a lot of irrelevant information in there, too, including a few medical files.  Now, at the time, we sort of shrugged it off.  We thought, well, maybe there are a couple of stray files in there.

But we flagged it for further research.  And, finally, this year, we have gone back and done some digging.

WILLIAM BRANGHAM:  We mentioned that there was the mention of the Saudi man who had been arrested for homosexuality.  What sorts of other things did you find in this — in these documents?

RAPHAEL SATTER:  We found all kinds of things.

If it's personal or sensitive or family-related, we found it.  So, we found details of custody battles.  We found parents writing to authorities about missing children.  We found details of elopements, of divorces, of partners who had sexually transmitted diseases, partners who had AIDS, people who were in debt, in distress, in all kinds of financial difficulty, and, of course, some of the cases that you mentioned earlier, that is to say, people who were raped, including children who were raped.

Monday, August 22, 2016

PRIVATE EYE - Everybody Is Watching

"How one exhibit is rethinking privacy in a world that's always watching" PBS NewsHour 8/15/2016

"The changing role of privacy in a world inundated with surveillance and oversharing."

Excerpt

SUMMARY:  At lower Manhattan's International Center for Photography, the new exhibit “Public, Private, Secret” examines the changing role of privacy in light of contemporary surveillance and oversharing.  The exhibition offers a historical perspective on voyeurism and surveillance and considers the definition of photography in the digital age, when camera access is nearly universal.  Jeffrey Brown reports.

JEFFREY BROWN (NewsHour):  A stark message stops visitors in their tracks at the threshold of the International Center of Photography's new home:  “By entering this area, you consent to being photographed, filmed and/or otherwise recorded, and surrender the right to the use of such material throughout the universe in perpetuity.”

And that's what the museum's first exhibition in its brand-new space in Lower Manhattan explores, the changing role of privacy in a world inundated with surveillance and oversharing.

PAULINE VERMARE, Associate Curator, “Public, Private, Secret”:  What is your secret life?  How can you keep it secret?  I think that's one of the keys of this exhibition is really that, keeping your privacy, but also making sure that your secret life remains your secret life.

JEFFREY BROWN:  Pauline Vermare is the associate curator of Public, Private, Secret, a mix of visual media, modern and historical.

There's this 1946 Yale Joel photograph of a couple through a two-way mirror for a series in “LIFE” magazine, and more contemporary surveillance art by Jill Magid, who captured herself on surveillance cameras, and Merry Alpern, who secretly shot through the bathroom window of a seedy sex club for her “Dirty Windows” series.

The museum itself has come a long way from its 1974 beginnings in a Manhattan mansion under the direction of famed Hungarian photographer Cornell Capa.

Since then, the world of photography has changed.

MARK LUBELL, Executive Director, International Center of Photography:  It is the most Democratic format.  It is in the hands of all of us.  We all are now visually communicating.

JEFFREY BROWN:  Mark Lubell is the current director of the museum, known as the ICP.  He's overseen an institutional shift, from photojournalism and art photography to an embrace of today's digital media landscape, where cell phone cameras are ubiquitous.

MARK LUBELL:  The big difference is, it used to be a few people taking images that went out to millions.  And now it's millions and millions of people going out to millions and millions of people.  I think that's a seismic shift in the medium, and it's something that we should be looking at and exploring.

Monday, April 18, 2016

ON THE PARANOIA FRONT - Microsoft on the Bandwagon

"Microsoft sues DOJ over demands for access to customer data" PBS NewsHour 4/15/2016

Here we go again.  The paranoia over privacy that helps criminals and terrorists hide from the law, even with a legal warrant.

Excerpt

SUMMARY:  In the wake of the FBI’s showdown with Apple last month, a new tech giant is taking up arms against government oversight.  Microsoft sued the Department of Justice Thursday, arguing that it is unconstitutional for the government to request access to a customer’s data while banning Microsoft from informing the individual in question.  Microsoft president Brad Smith joins Judy Woodruff for more.

JUDY WOODRUFF (NewsHour):  A high-profile showdown between a tech giant and the U.S. government over accessing private data.

This time, it’s Microsoft.  Yesterday, the company filed a suit against the Department of Justice in federal court.  Microsoft argues it’s unconstitutional for the government to ask for customers’ personal data or e-mails in most cases without the individuals’ knowledge.  The company says it’s received more than 5,600 requests for such data from the government in the last year-and-a-half, often from the cloud or remote servers.  And nearly half of those requests come with a ban from the government on alerting customers.

Brad Smith is the president of Microsoft.  He joins me from company headquarters in Redmond, Washington.

And welcome to the program, Brad Smith.

I do want to point out we invited the Department of Justice to join the interview, but they declined.

So, let me begin by asking you, what is it that the federal government is doing that Microsoft doesn’t like?

BRAD SMITH, President, Microsoft:  Well, what gives us concern is the fact we have received almost 2,600 — almost 2,600 of these so-called gag or secrecy orders over the last 18 months.

Over two-thirds of them have no end date at all.  So it means that we are permanently prohibited from telling customers that the government has accessed, read and obtained copies of their e-mails.  We feel that infringes on the constitutional rights of consumers and businesses to be secure from unreasonable government searches.

It infringes on our First Amendment right to speak, to share information with our customers.

JUDY WOODRUFF:  Well, we know the Justice Department has not responded to the lawsuit.  They have not said anything publicly, but we know that in the past they have said these are investigations that involve criminals, people who are breaking the law, that involve — that are perhaps involved in potential terrorist acts.

Why not work with the government when they’re trying to go after the bad guys?

BRAD SMITH:  Well, this is an issue that we have discussed with various officials in government for some time.

And we readily recognize that there are many cases where there should be some kind of secrecy, that there is a real danger if information is disclosed.  But we feel that these kinds of secrecy orders have been — become too routine.  They’re being issued in cases that involve businesses, as well as consumers.

.....

...hence, the paranoia.  Like businesses can't be criminals or help terrorists hide?  Also, lets warn the criminals BEFORE they are brought to trial, think secret Grand Juries.  Oh, wait, the Black-WEB sites used by drug lords and terrorists to hide.  Humm.... could it be the big profits such companies make laundering hiding money?

Monday, April 11, 2016

EDUCATION - In the Student Digital World

"Why digital education could be a double-edged sword" PBS NewsHour 4/5/2016

Excerpt

SUMMARY:  Public education is becoming increasingly digitized -- these days, schools can compile everything from a student’s grades to their eating habits in online profiles.  But while this technology facilitates personalized learning, it also puts student data at risk of being compromised and misused, and extra security could come at the expense of education.  John Tulenko of Education Week reports.

JOHN TULENKO (NewsHour):  Miami, Florida, is taking on one of public education’s oldest problems:  With so many students, how do you personalize instruction?  One answer is with computers.

At Miami’s iPrep Academy, one-size-fits-all lessons are a thing of the past.

NICOLE RASMUSON, iPrep Academy:  We all started at the very beginning, and then some just took off.

JOHN TULENKO:  Nicole Rasmuson teaches math, using innovative software.

NICOLE RASMUSON:  It’s about 70 percent online.  And it’s a smart program, and so it checks, are they understanding, are they answering questions correctly right away?  Are they struggling?  Is it taking them a long time to answer questions?  Do they keep making mistakes?

JOHN TULENKO:  All the while, the computer is crunching and storing data about the students and sending back customized lessons.

NICOLE RASMUSON:  It’ll ask them, what are your interests?  And so, in the word problems, it’ll — if one kid’s really interested in food, it’ll talk about cookies and that kind of stuff.  It’ll even ask them, what are your friends’ names?  And then it’ll put their friends’ names in the problems, too.

JOHN TULENKO:  All that gets uploaded, along with student schedules, grades, discipline records, homework and even e-mails, the makings of what some have called a digital profile, that privacy expert Joel Reidenberg fears could someday be used in unauthorized ways.

Monday, April 04, 2016

CRACKED - iPhone vs FBI

aka 'The Right to Hide Criminals Case'

"FBI cracks the locked iPhone, but legal questions remain unanswered" PBS NewsHour 3/29/2016

Excerpt

SUMMARY:  A conflict between tech giant Apple and the FBI over the encrypted iPhone of one of the San Bernardino shooters came to a moot point when Justice Department officials announced they had cracked the phone's security without Apple's help.  Gwen Ifill talks to Devlin Barrett of The Wall Street Journal and Fred Kaplan of Slate for more on how the FBI got what it wanted and what happens now.

GWEN IFILL (NewsHour):  A pitched battle between the Obama Justice Department and one of the world's biggest tech companies appeared to end abruptly this week, when the government decided to drop its insistence that Apple crack the code for an iPhone used in the San Bernardino shootings.

Apple had refused, insisting such cooperation would constitute a major breach of privacy.  The impending standoff ended yesterday when the government announced it had been able to crack the phone after all, without Apple's help.

But questions remain.

For that, we turn to Devlin Barrett, who covers the Justice Department for The Wall Street Journal, and Fred Kaplan, a columnist with Slate.  He's the author of “The Dark Territory: The Secret History of Cyber War.”

Devlin, starting with you, did one or the other of the parties in this case back away, just back up?

DEVLIN BARRETT, The Wall Street Journal:  The government backed away.  The government said — but it also got what it wanted, in a sense, because it got into the phone it had been trying to get into for months.

I think what you saw happen was that the government spent two months saying it can't get into this phone without Apple, and then at the last minute, essentially, it said, actually, someone has just come to us and told us that we can get into it without Apple, and that's what happened.

GWEN IFILL:  So, Fred Kaplan, the obvious question for so many of us is, who broke into the phone for them, and how did they find them, and had they — would they have been able to find them before without all of this legal mishmash?

FRED KAPLAN, Slate:  Well, it seems to be an Israeli cyber-security firm called Cellebrite, which consists mainly of retired professionals from the — an outfit called Unit 822, which is a — the cyber-warfare branch of the Israeli intelligence agency, sort of the Israeli NSA.

You can imagine.  Here's the FBI saying, we can't break into this phone.  Here's Apple saying, we don't want anybody to break into this phone.  This is the most secure phone out there.  You have got hundreds, maybe thousands of hackers around the world who look at this and say, hmm, let me give this a try.

And, you know, the law that the FBI was invoking to get Apple to open it themselves, which is a 1789 law called the 'All Writs Act,' states that if somebody else can do it, if you can find some way to do it without demanding that a company like Apple do it, then you have to drop your suit.

And that's why the FBI withdrew.  They had to.  They really didn't want to.  They thought that they had a good case here and were ultimately trying to test a new legal principle to accommodate for this new stronger era of encryption.

IMO:  This is a case where the actual effects privacy-rights fanatics is to allow criminals to hide.  That is just WRONG!  There is no Constitutional right to have criminals hide.



RELATED:  Breaking into iPhone may help find Louisiana killer

Monday, February 29, 2016

FEAR MONGERING - The Privacy Issue

"The privacy vs. security battle, reignited" PBS NewsHour 2/24/2016

I will say again, and again, NO ONE has the right to Obstruct Justice by refusing a legally obtained warrant, nor use the excuse of 'privacy' to hid criminal activity.

Excerpt

SUMMARY:  As Apple’s standoff with federal courts reignites the debate over privacy versus security, some may wonder just how much American intelligence policies have changed since Sept. 11.  Hari Sreenivasan talks with former CIA Director Michael Hayden about the constitutional cost of national security, the efficacy of drone strikes and the human element within the Central Intelligence Agency.

GWEN IFILL (NewsHour):  We move now from defense to intelligence, and how the country has changed since the attacks of September 11.

The privacy vs. security debate has surfaced again in the wake of the FBI’s appeal to tech giant Apple to unlock an iPhone that belonged to one of the San Bernardino shootings.  And there is renewed campaign debate over torture.

Hari Sreenivasan has our conversation with one man who was at the center of U.S. intelligence policy.

HARI SREENIVASAN (NewsHour):  Retired Air Force General Michael Hayden is the only person to ever serve as both the director of the CIA and the head of the National Security Agency.  His tenure at both agencies came during a critical period, as the U.S. launched and prosecuted the global war on terror.

He’s just written a book about his time in government called “Playing to the Edge.”

He joins me now.

Thanks for joining us.

GEN. MICHAEL HAYDEN (RET.), Author, “Playing to the Edge”:  Thank you, Hari.
-----
HARI SREENIVASAN:  The other big story right now is obviously this tension between Apple and the government.  In this conversation, you have said that you come down on the side of Apple more often than not.  In this specific case, with this specific device, you are on the side of the government in trying to open it up.  This is the phone, of course, that was used by the attacker in San Bernardino.

You know, one of Apple’s arguments has been, listen, this will set a precedent, it will create a back door.  And, sure enough, there’s at least nine or 10 other cases where Apple is being asked to open up that phone.

GEN. MICHAEL HAYDEN:  Absolutely.

And the U.S. attorney in Manhattan says he has got 175 of these instruments sitting in a room that he wants to be reopened.  So, in this particular case, the original ask from the FBI, going back months now, was some sort of universal back door that would allow them to get into Apple and other companies’ encrypted devices.

Frankly, Hari, I think American safety, American security — put the privacy argument aside, which is quite powerful.  But I’m a security guy.  I think American security is better served with end-to-end unbreakable encryption.

And I recognize that makes the life of the FBI more difficult, may even make the life of my old agency more difficult.




Monday, September 21, 2015

POLITICS - They're Tracking You on Smartphones

"Smartphone user?  The 2016 candidates are watching you" PBS NewsHour 9/18/2015

Excerpt

SUMMARY:  If you own a smartphone, you are already on the frontline of the 2016 presidential race.  On the left and the right, campaigns are amassing information about you and figuring out how to influence you with individualized marketing.  And that's not the only way that candidates have gone digital.  Political director Lisa Desjardins reports.

LISA DESJARDINS (NewsHour):  With all the gentility of a marching band, the presidential campaign is under way and booming.  But like much of America, you may think the 2016 presidential fight has yet to really enter your life.

Do you think any of the campaigns are paying any attention to you right now?

WOMAN:  Not really, no.

MAN:  Very little.

WOMAN:  Not a whole lot.

MAN:  Probably almost zero.

WOMAN:  Not really, no.

LISA DESJARDINS:  And last question, do you have a cell phone?

WOMAN:  Of course.

MAN:  Yes, I do.

WOMAN:  I do.

MAN:  Yes, I have a cell phone.

MAN:  Yes, I have a cell phone.  It’s a very big part of my life because I do a lot with my cell phone.

LISA DESJARDINS:  If you have a smartphone — and two-thirds of us in America do, according to the Pew Research Center — you are already on the radar for most 2016 campaigns.  That’s because campaigns left and right are now amassing more and more data about voters, and they’re trying to influence you this time around using this.

COMMENT:  Hum..... so we are suppose to worry about government tracking but NOT about political tracking?  Really?!

Monday, September 07, 2015

HACKING - China and Russia Link-Up

"How China and Russia are mining major U.S. data hacks" PBS NewsHour 8/31/2015

Excerpt

SUMMARY:  Intelligence services in Russia and China are cross-referencing hacked U.S. databases to reveal the identities of U.S. intelligence workers, according to a report in the Los Angeles Times.  Jeffrey Brown learns more from reporter Brian Bennett.

GWEN IFILL (NewsHour):  Next, a closer look at how major hacks of U.S. data are being used by China and Russia to target U.S. spies.

Today’s Los Angeles Times reports that intelligence services in those two nations are aggressively cross-referencing leaked information, including security clearances, airline records and medical insurance forms, to reveal the identities of intelligence officers and agents.

Jeffrey Brown has more.

JEFFREY BROWN (NewsHour):  We hear about these high-level data breaches all the time.  Today’s story connects some of the dots in a chilling way, claiming, for example, that at least one clandestine network of American engineers and scientists who work with U.S. undercover agents overseas has already been compromised.

One of the article’s authors, L.A. Times reporter Brian Bennett, joins me now.

And welcome to you.

So, we hear about these acts.  This is about what happens afterwards, right, cross-indexing and putting together the information.  What kind of clues are they looking for?

BRIAN BENNETT, The Los Angeles Times:  So, right now, countries like China and Russia are collecting massive amounts of data on the lives of Americans and the lives of government workers.

And this is going to allow them to get a dossier on people and know about their medical history, their banking information, if they have financial difficulties and might be vulnerable to blackmail or something else, their — any marital indiscretions that may have come out, their connections overseas.  And all this information is put together in massive databases and powerful computers can crunch them and give a very detailed view of people traveling.

Monday, August 24, 2015

INTERNET - Not Private, Not Safe

IMHO:  As a computer specialist and IT Technician (retired) I can tell you that ANYTHING on the Internet is never safe and therefore not private.  Pay attention to the hacking going on world-wide.  Governments are hacked, military sites are hacked, businesses are hacked, and more.  Being on the Internet and expecting privacy is like holding a conversation in Central Park (New York) and expecting that no-one will overhear you.

"Is the trail of secrets we leave online ever safe?" PBS NewsHour 8/21/2015

Excerpt

SUMMARY:  Hackers dumped troves of personal information stolen from the adultery website Ashley Madison this week.  Millions of names, email addresses and partial credit card numbers were released, raising alarms about how much privacy any of us enjoy online.  Hari Sreenivasan discusses the fallout with Neil Richards of Washington University and Julia Angwin of ProPublica.

JUDY WOODRUFF (NewsHour):  Internet hackers dumped troves of personal information this week stolen from an adultery Web site, raising new questions about online privacy and the ability of Web sites to protect it.

Hari Sreenivasan has our look.

HARI SREENIVASAN (NewsHour):  The hackers said the attack on Ashley Madison was motivated by the failure of its parent company to deliver on a service that promised to erase users’ information for a fee.  Millions of names, e-mail addresses and partial credit card numbers were released, a public outing that has raised questions about how much privacy any of us enjoy online.

Joining me to discuss this are Neil Richards, a professor of law at Washington University in Saint Louis, where he studies privacy and the Internet.  His recent book is “Intellectual Privacy:  Rethinking Civil Liberties in the Digital Age.”  And Julia Angwin, who covers privacy for ProPublica, her most recent book is called “Dragnet Nation:  A Quest for Privacy, Security, and Freedom in a World of Relentless Surveillance.”

All right, so, Neil, I want to start with you first.

We have had the Sony Pictures hack, where thousands of employees of a corporation had their communication and their information released.  We have had the Office of Personnel Management hacked, 22 million employees of the federal government, right?

We have also had celebrity hacks before, where unsuspecting celebrities had their photos from iPhones or iClouds released.  What makes this different?

NEIL RICHARDS, Washington University:  Well, it’s certainly different because it’s more salacious.  Right?  It involves sex and betrayal.

I think the magnitude of the hack and the sensitivity of the information that is being exposed.  I think it’s important that we think about these questions, because this is a little more juicy in terms of — maybe like tabloid news, than some of the other hacks, but it’s important to draw attention to what is an increasingly enormous problem.

HARI SREENIVASAN:  So, Julia, I want to ask.  There is this notion that your information, especially on a sensitive site like this, sits in a lockbox.  And to credit this site, this digital set of locks that they had was actually better than average.

But is there such a thing as true security?  As soon as you type something, is it out there forever?

JULIA ANGWIN, ProPublica:  Sadly, what we’re learning is that there doesn’t seem to be a lot of true security out there in the real world.

Monday, May 25, 2015

PATRIOT ACT - The Divide

IMO:
  • On the Internet you CANNOT expect privacy, any more than you can if you are talking in the middle of Central Park.  There is always a chance that someone will overhear you.
  • Phone matadata does NOT have any personal data.  It is ONLY phone numbers and date-time stamps that are use by your phone carrier's billing computer to calculate cost.  It is the phone carrier's billing computer that holds personal information and should require a warrant to see.  Note you DO NOT own your phone number, your carrier does.

"The Patriot Act’s strange divide" PBS NewsHour 5/22/2015

Excerpt

SUMMARY:  On June 1, the NSA will lose legal authority to collect bulk phone records, as key provisions of the Patriot Act expire.  The House has passed a new bill replacing bulk collection with more targeted searches.  But some senators, including the majority leader, want to extend the Patriot Act, leaving lawmakers scrambling before the holiday.  Judy Woodruff talks to Mike DeBonis of The Washington Post.

JUDY WOODRUFF (NewsHour):  We now turn to the heated debate over government security and individual privacy.

Three key provisions of the Patriot Act that allow for government surveillance are set to expire soon, but the U.S. Senate is planning to be out of Washington next week, leaving lawmakers scrambling to find agreement on this controversial issue.

Senators came to work this morning confronting an impasse on surveillance and a looming deadline.

SEN. PATRICK LEAHY, (D) Vermont:  Unfortunately, the clock’s been run out.

JUDY WOODRUFF:  On June 1, the National Security Agency loses legal authority to collect bulk phone records, as key provisions of the Patriot Act expire.  But the Senate is leaving for the Memorial Day recess and won’t return until June 1, leaving Vermont Democrat Patrick Leahy to point across the Capitol.

SEN. PATRICK LEAHY:  The House worked very hard on this.  They completed their work and they left.  They’re not coming back until after the surveillance authorities are set to expire.  And the House leadership has made clear they will not pass an extension, even if they’re in.

MAN:  On this vote, the yeas are 338 and the nays are 88.  The bill is passed.

Monday, April 13, 2015

SOCIAL MEDIA - Book on Erosion of Privacy

"How can we return privacy control to social media users?" PBS NewsHour 4/7/2015

Excerpt

SUMMARY:  What’s the cost of being constantly connected through social media?  A new book, “Terms of Service” examines the erosion of privacy in the digital era.  Author Jacob Silverman sits down with Jeffrey Brown to discuss what data is being tracked, stored and sold.

GWEN IFILL (NewsHour):  Now the latest addition to the NewsHour bookshelf, “Terms of Service.”  It’s a look at the erosion of privacy in the age of social media.

Jeffrey Brown recently talked to author Jacob Silverman at Busboys and Poets, a restaurant and bookstore chain in and around Washington.

JEFFREY BROWN (NewsHour):  Welcome to you.

JACOB SILVERMAN, Author, “Terms of Service”:  Thanks for having me.

JEFFREY BROWN:  The case you’re making — and it’s a strong case — we don’t know or we don’t seem to care enough about what we’re giving away in our digital lives.

JACOB SILVERMAN:  Right.

Well, the same systems that make it so easy to communicate with one another and live these lives where we’re essentially all public figures now also make it very easy to sort of spy on us, to collect personal information, whether you’re companies or governments or other bad actors.

And I think that a lot of people don’t really realize how much is being collected on each and every one of us, that there are big data brokers out there forming dossiers on hundreds of millions of people.

JEFFREY BROWN:  There’s been a lot of emphasis on government surveillance.   Here, you’re really pointing to what we perhaps don’t know as much about, corporate surveillance.

JACOB SILVERMAN:  Right.

Well, actually, corporations have really led the way turning the Internet into what is really a remarkable surveillance machine.  Ever since the introduction of the cookie about 15 years ago, we have sort of shifted paths to make the Internet all about monitoring what users do, so that we can direct ads toward them.

Wednesday, August 27, 2014

SURVEILLANCE - NSA's Secret 'Google'

"The Surveillance Engine:  How the NSA Built Its Own Secret Google" by Ryan Gallagher, The Intercept 8/25/2014

Excerpt

The National Security Agency is secretly providing data to nearly two dozen U.S. government agencies with a “Google-like” search engine built to share more than 850 billion records about phone calls, emails, cellphone locations, and internet chats, according to classified documents obtained by The Intercept.

The documents provide the first definitive evidence that the NSA has for years made massive amounts of surveillance data directly accessible to domestic law enforcement agencies.  Planning documents for ICREACH, as the search engine is called, cite the Federal Bureau of Investigation and the Drug Enforcement Administration as key participants.

ICREACH contains information on the private communications of foreigners and, it appears, millions of records on American citizens who have not been accused of any wrongdoing.  Details about its existence are contained in the archive of materials provided to The Intercept by NSA whistleblower Edward Snowden.

Earlier revelations sourced to the Snowden documents have exposed a multitude of NSA programs for collecting large volumes of communications.  The NSA has acknowledged that it shares some of its collected data with domestic agencies like the FBI, but details about the method and scope of its sharing have remained shrouded in secrecy.

ICREACH has been accessible to more than 1,000 analysts at 23 U.S. government agencies that perform intelligence work, according to a 2010 memo.  A planning document from 2007 lists the DEA, FBI, Central Intelligence Agency, and the Defense Intelligence Agency as core members.  Information shared through ICREACH can be used to track people’s movements, map out their networks of associates, help predict future actions, and potentially reveal religious affiliations or political beliefs.

The creation of ICREACH represented a landmark moment in the history of classified U.S. government surveillance, according to the NSA documents.

“The ICREACH team delivered the first-ever wholesale sharing of communications metadata within the U.S. Intelligence Community,” noted a top-secret memo dated December 2007.  “This team began over two years ago with a basic concept compelled by the IC’s increasing need for communications metadata and NSA’s ability to collect, process and store vast amounts of communications metadata related to worldwide intelligence targets.”

The search tool was designed to be the largest system for internally sharing secret surveillance records in the United States, capable of handling two to five billion new records every day, including more than 30 different kinds of metadata on emails, phone calls, faxes, internet chats, and text messages, as well as location information collected from cellphones.  Metadata reveals information about a communication — such as the “to” and “from” parts of an email, and the time and date it was sent, or the phone numbers someone called and when they called — but not the content of the message or audio of the call.

Thursday, August 14, 2014

CENSORSHIP - As Practiced by Google Gmail

"Gmail scanning becomes censorship" by Alexander Hanff, Privacy Beyond Compliance Blog 1/5/2014

Earlier this weekend I was asked by a journalist friend of mine if I would mind answering a few questions for an article he was writing about the draft Data Protection Regulation and Safe Harbour.  The comments were for a feature article in the first 2014 print edition of Infosecurity Magazine.  Needless to say, I was happy to comment on the issue which, I know well and have worked on for the better part of the last 4 years; so this morning I sent my response - a little wordy but relevant none the less and hopefully useful for his article.

To my surprise, just seconds after hitting the send button, I received the following email back from Google's Gmail servers:

Our system has detected that this 550-5.7.1 message is likely unsolicited mail.  To reduce the amount of spam sent 550-5.7.1 to Gmail, this message has been blocked.  Please visit 550-5.7.1 http://support.google.com/mail/bin/answer.py?hl=en&answer=188131 for 550 5.7.1 more information. c2si3563013wie.0 - gsmtp (in reply to end of DATA command)

Obviously, the first thing I did was visit the link which provided me with the following information:

Why has Gmail blocked my messages?

Here at Gmail, we work very hard to fight spam.  While in some cases we may classify a message as spam and deliver it to the spam folder, we also try to find ways to reduce the amount of spam being sent to Gmail in general.  If we detect that a message has a strong likelihood of being spam, we’ll block the message from being sent to Gmail.

A message might be blocked if it contains suspicious-looking or spammy text or if the sending IP has had a history of sending unsolicited messages.

Is all of the mail I’m sending being blocked?

It’s likely that only a subset of the messages which have a strong likelihood of being spam are being blocked and not all of your messages.  However, to help improve your deliverability, we recommend reviewing our Bulk Sender Guidelines.

If you’re forwarding mail to Gmail and your domain also forwards spam, we recommend reviewing our mail forwarding best practices.

As you can see there is no information on how to have your emails removed from Google's filters.  Thinking that maybe the IPv4 address of my mail server was perhaps caught in some sort of RBL from the past (before I was provisioned with it for my server) I pointed my browser to http://mxtoolbox.com to check.  Neither my domain or my IP address were included in any blacklists on the site (which granted is not a definitive list but is pretty well populated).

This leads me to believe that the only reason the email was rejected by Google's Gmail servers was based on the content of the email and I have a couple of issues with this.

1.  I am deeply opposed to Google's scanning of emails - I have argued for a number of years that this is a breach of privacy and probably illegal - although trying to get a regulator to take action has been impossible.

2.  Even if we accept scanning of email content for the purpose of preventing spam, there were a number of key elements to my email which should have made it clear the email was not spam as listed below:

a.  The email was a reply to an email with my response inline.  The previous email I was responding too was indicated with ">" in the left margin next to each original line.  It should have been clear to any automated scanning system that this was a reply and therefore probably not unsolicited.

b.  The email requested both a delivery receipt and read receipt (I wanted to make sure the journalist received and read the email before their indicated deadline so I could phone them before that time if it was clear they hadn't).  Most spammers do not request delivery/read receipts as it uses up technical resources to process them as well as significantly increases their bandwidth usage - imagine if a spammer received two receipts for every single mail they sent to a list of millions.  So again any automated scanning system should have been configured to "understand" this.

c.  My email was signed with my PGP key.  Now granted this might not seem like an obvious reason not to mark something as spam, but have you ever received spam which is signed with a PGP key?  I certainly haven't.

d.  Neither my domain or my mail server's IP address are listed on any blacklist that I could find, so really it was unlikely that my server had suddenly started sending out bulk spam emails.

Google's filtering system for spam is completely arbitrary and quite simply doesn't work.  All four of the individual points above should have indicated to Google's systems that the email was probably not spam but for all four of those points to have existed together and yet the email was still marked as spam, illustrates a complete failure of Google's filters, which seem to be acting more as a form of censorship that anything else.

What makes this even more ironic, is the email content was all about an EU Regulation of which Google would be one of the corporations it impacts most - an email about privacy, scanned by a filter which goes against privacy and run by a company that has declared war on privacy because this single, fundamental right interferes with their illegitimate and unethical revenue model.

Tuesday, July 08, 2014

NSA - Intercepted Data and Who's Targeted

"In NSA-intercepted data, those not targeted far outnumber the foreigners who are" by Barton Gellman, Julie Tate, and Ashkan Soltani; Washington Post 7/5/2014

Excerpt

Ordinary Internet users, American and non-American alike, far outnumber legally targeted foreigners in the communications intercepted by the National Security Agency from U.S. digital networks, according to a four-month investigation by The Washington Post.

Nine of 10 account holders found in a large cache of intercepted conversations, which former NSA contractor Edward Snowden provided in full to The Post, were not the intended surveillance targets but were caught in a net the agency had cast for somebody else.

Many of them were Americans.  Nearly half of the surveillance files, a strikingly high proportion, contained names, e-mail addresses or other details that the NSA marked as belonging to U.S. citizens or residents.  NSA analysts masked, or “minimized,” more than 65,000 such references to protect Americans’ privacy, but The Post found nearly 900 additional e-mail addresses, unmasked in the files, that could be strongly linked to U.S. citizens or U.S. residents.

The surveillance files highlight a policy dilemma that has been aired only abstractly in public.  There are discoveries of considerable intelligence value in the intercepted messages — and collateral harm to privacy on a scale that the Obama administration has not been willing to address.

Among the most valuable contents — which The Post will not describe in detail, to avoid interfering with ongoing operations — are fresh revelations about a secret overseas nuclear project, double-dealing by an ostensible ally, a military calamity that befell an unfriendly power, and the identities of aggressive intruders into U.S. computer networks.

Months of tracking communications across more than 50 alias accounts, the files show, led directly to the 2011 capture in Abbottabad of Muhammad Tahir Shahzad, a Pakistan-based bomb builder, and Umar Patek, a suspect in a 2002 terrorist bombing on the Indonesian island of Bali.  At the request of CIA officials, The Post is withholding other examples that officials said would compromise ongoing operations.

Many other files, described as useless by the analysts but nonetheless retained, have a startlingly intimate, even voyeuristic quality.  They tell stories of love and heartbreak, illicit sexual liaisons, mental-health crises, political and religious conversions, financial anxieties and disappointed hopes.  The daily lives of more than 10,000 account holders who were not targeted are cataloged and recorded nevertheless.

In order to allow time for analysis and outside reporting, neither Snowden nor The Post has disclosed until now that he obtained and shared the content of intercepted communications.  The cache Snowden provided came from domestic NSA operations under the broad authority granted by Congress in 2008 with amendments to the Foreign Intelligence Surveillance Act.  FISA content is generally stored in closely controlled data repositories, and for more than a year, senior government officials have depicted it as beyond Snowden’s reach.

The Post reviewed roughly 160,000 intercepted e-mail and instant-message conversations, some of them hundreds of pages long, and 7,900 documents taken from more than 11,000 online accounts.

The material spans President Obama’s first term, from 2009 to 2012, a period of exponential growth for the NSA’s domestic collection.

Taken together, the files offer an unprecedented vantage point on the changes wrought by Section 702 of the FISA amendments, which enabled the NSA to make freer use of methods that for 30 years had required probable cause and a warrant from a judge.  One program, code-named PRISM, extracts content stored in user accounts at Yahoo, Microsoft, Facebook, Google and five other leading Internet companies.  Another, known inside the NSA as Upstream, intercepts data on the move as it crosses the U.S. junctions of global voice and data networks.

No government oversight body, including the Justice Department, the Foreign Intelligence Surveillance Court, intelligence committees in Congress or the president’s Privacy and Civil Liberties Oversight Board, has delved into a comparably large sample of what the NSA actually collects — not only from its targets but also from people who may cross a target’s path.

Among the latter are medical records sent from one family member to another, résumés from job hunters and academic transcripts of schoolchildren.  In one photo, a young girl in religious dress beams at a camera outside a mosque.

Scores of pictures show infants and toddlers in bathtubs, on swings, sprawled on their backs and kissed by their mothers.  In some photos, men show off their physiques.  In others, women model lingerie, leaning suggestively into a webcam or striking risque poses in shorts and bikini tops.

“None of the hits that were received were relevant,” two Navy cryptologic technicians write in one of many summaries of nonproductive surveillance.

Monday, June 16, 2014

INTERNET - Data Brokers vs Protecting Your Privacy

"Companies tracking our online footsteps should be more transparent, says FTC" PBS NewsHour 6/13/2014

Excerpt

JUDY WOODRUFF (NewsHour):  Now, how big data is being tracked for commercial purposes.

You may not know of or have heard much about companies known as data brokers, but a recent government report says these companies actually know a lot about you and the information you share online, billions of pieces of data, actually.

Jeffrey Brown has the story.

JEFFREY BROWN (NewsHour):  Are you a mobile mixer, an urban scrambler?  Do you know what those mean or that you yourself might be characterized as one or the other?

According to a new study by the Federal Trade Commission, large companies called data brokers use such labels as they track our online buying habits, what we do in our free time, religious affiliations, and much, much more, in an industry the FTC says suffers from a fundamental lack of transparency.

It found that one company’s database alone had information that included 1.4 billion consumer transactions and more than 700 billion aggregated pieces of data.  The FTC is calling on Congress to take new steps to protect consumers.

And its chairwoman, Edith Ramirez, joins us now to talk about it.

Monday, June 02, 2014

PRIVACY - Warning, Big Data Brokers

"FTC report warns consumers about big data brokers" PBS NewsHour 5/31/2014

Excerpt

HARI SREENIVASAN (NewsHour):  Earlier this week, the Federal Trade Commission issued a report that contained consumer protection recommendations concerning what’s referred to as “big data” – the companies that collect and sell billions of bits of information about all aspects of our online lives.  Information that includes purchases, income, political affiliations – even religion. As FTC Chairwoman Edith Ramirez put it:

“It’s time to bring transparency and accountability to bear on this industry on behalf of consumers, many of whom are unaware that data brokers even exist.”

For some insight, we turn to Amy Schatz who covers tech policy issues for Re/code.

So, what were the things that this report uncovered that might surprise consumers?

AMY SCHATZ, Re/code:  I think most of the things in the report would surprise consumers, although this isn’t necessarily a new issue – this has been going around for a couple of years – but most people don’t know that there are a bunch of data collectors out there who are collecting data about you.  Whether it’s who you voted for or your political beliefs.  Whether it’s your zip code or what you purchased at the store last week or what you’re lookeingat online.  There are these profiles that are being created online of most Americans now and that information is being traded and shared in a way that a lot of consumers might find a little troubling.

Monday, September 16, 2013

PRIVACY - The $Data Broker$

"Everything We Know About What Data Brokers Know About You" by Lois Beckett, ProPublica 9/13/2013

Sept. 13:  This story has been updated. It was originally published on March 7, 2013.

We’re continuing to learn new details about how the American government is collecting bulk records of citizens’ communications -- from demanding that a telephone company hand over the daily records of “all telephone calls in its systems,” to collecting an unknown number of emails, instant messages and Facebook messages.

It’s not clear how much information about ordinary people’s conversations the National Security Agency has gathered.  But we do know there’s a thriving public market for data on individual Americans -- especially data about the things we buy and might want to buy.

Consumer data companies scoop up large amounts of consumer information about people around the world and sell it, providing marketers details about whether you're pregnant or divorced or trying to lose weight, about how rich you are and what kinds of cars you drive.  But many people still don't know data brokers exist.

Regulators and some in Congress have been taking a closer look at this industry, and are beginning to push the companies to give consumers more information and control over what happens to their data.  The prominent data broker Acxiom recently launched aboutthedata.com, a site that allows you to review some of the information the company has connected to your name -- and, potentially, edit and update it as well.

Here's a look (originally published in March) at what we know about the consumer data industry.

How much do these companies know about individual people?

They start with the basics, like names, addresses and contact information, and add on demographics, like age, race, occupation and "education level," according to consumer data firm Acxiom's overview of its various categories.

But that's just the beginning:  The companies collect lists of people experiencing "life-event triggers" like getting married, buying a home, sending a kid to college — or even getting divorced.

Credit reporting giant Experian has a separate marketing services division, which sells lists of "names of expectant parents and families with newborns" that are "updated weekly."

The companies also collect data about your hobbies and many of the purchases you make.  Want to buy a list of people who read romance novels?  Epsilon can sell you that, as well as a list of people who donate to international aid charities.

A subsidiary of credit reporting company Equifax even collects detailed salary and paystub information for roughly 38 percent of employed Americans, as NBC News reported.  As part of handling employee verification requests, the company gets the information directly from employers.

Equifax said in a statement that the information is only sold to customers "who have been verified through a detailed credentialing process."  It added that if a mortgage company or other lender wants to access information about your salary, they must obtain your permission to do so.

Of course, data companies typically don't have all of this information on any one person.  As Acxiom notes in its overview, "No individual record ever contains all the possible data."  And some of the data these companies sell is really just a guess about your background or preferences, based on the characteristics of your neighborhood, or other people in a similar age or demographic group.

Where are they getting all this info?

The stores where you shop sell it to them.

Datalogix, for instance, which collects information from store loyalty cards, says it has information on more than $1 trillion in consumer spending "across 1400+ leading brands."  It doesn't say which ones. (Datalogix did not respond to our requests for comment.)

Data companies usually refuse to say exactly what companies sell them information, citing competitive reasons.  And retailers also don't make it easy for you to find out whether they're selling your information.

But thanks to California's "Shine the Light" law, researchers at U.C. Berkeley were able to get a small glimpse of how companies sell or share your data.  The study recruited volunteers to ask more than 80 companies how the volunteers' information was being shared.

Only two companies actually responded with details about how volunteers' information had been shared.  Upscale furniture store Restoration Hardware said that it had sent "your name, address and what you purchased" to seven other companies, including a data "cooperative" that allows retailers to pool data about customer transactions, and another company that later became part of Datalogix. (Restoration Hardware hasn't responded to our request for comment.)

Walt Disney also responded and described sharing even more information:  not just a person's name and address and what they purchased, but their age, occupation, and the number, age and gender of their children.  It listed companies that received data, among them companies owned by Disney, like ABC and ESPN, as well as others, including Honda, HarperCollins Publishing, Almay cosmetics, and yogurt company Dannon.

But Disney spokeswoman Zenia Mucha said that Disney's letter, sent in 2007, "wasn't clear" about how the data was actually shared with different companies on the list.  Outside companies like Honda only received personal information as part of a contest, sweepstakes, or other joint promotion that they had done with Disney, Mucha said.  The data was shared "for the fulfillment of that contest prize, not for their own marketing purposes."

Where else do data brokers get information about me?

Government records and other publicly available information, including some sources that may surprise you.  Your state Department of Motor Vehicles, for instance, may sell personal information — like your name, address, and the type of vehicles you own — to data companies, although only for certain permitted purposes, including identify verification.

Public voting records, which include information about your party registration and how often you vote, can also be bought and sold for commercial purposes in some states.

Are there limits to the kinds of data these companies can buy and sell?

Yes, certain kinds of sensitive data are protected — but much of your information can be bought and sold without any input from you.

Federal law protects the confidentiality of your medical records and your conversations with your doctor.  There are also strict rules regarding the sale of information used to determine your credit-worthiness, or your eligibility for employment, insurance and housing.  For instance, consumers have the right to view and correct their own credit reports, and potential employers have to ask for your consent before they buy a credit report about you.

Other than certain kinds of protected data — including medical records and data used for credit reports — consumers have no legal right to control or even monitor how information about them is bought and sold.  As the FTC notes, "There are no current laws requiring data brokers to maintain the privacy of consumer data unless they use that data for credit, employment, insurance, housing, or other similar purposes."

So they don't sell information about my health?

Actually, they do.

Data companies can capture information about your "interests" in certain health conditions based on what you buy — or what you search for online.  Datalogix has lists of people classified as "allergy sufferers" and "dieters."  Acxiom sells data on whether an individual has an "online search propensity" for a certain "ailment or prescription."

Consumer data is also beginning to be used to evaluate whether you're making healthy choices.

One health insurance company recently bought data on more than three million people's consumer purchases in order to flag health-related actions, like purchasing plus-sized clothing, the Wall Street Journal reported. (The company bought purchasing information for current plan members, not as part of screening people for potential coverage.)

Spokeswoman Michelle Douglas said that Blue Cross and Blue Shield of North Carolina would use the data to target free programming offers to their customers.

Douglas suggested that it might be more valuable for companies to use consumer data "to determine ways to help me improve my health" rather than "to buy my data to send me pre-paid credit card applications or catalogs full of stuff they want me to buy."

Do companies collect information about my social media profiles and what I do online?

Yes.

As we highlighted last year, some data companies record — and then resell — all kinds of information you post online, including your screen names, website addresses, interests, hometown and professional history, and how many friends or followers you have.

Acxiom said it collects information about which social media sites individual people use, and "whether they are a heavy or a light user," but that they do not collect information about "individual postings" or your "lists of friends."

More traditional consumer data can also be connected with information about what you do online.  Datalogix, the company that collects loyalty card data, has partnered with Facebook to track whether Facebook users who see ads for certain products actually end up buying them at local stores, as the Financial Times reported last year.

Is there a way to find out exactly what these data companies know about me? (Updated 9/5/2013)

Not really -- although that’s beginning to change.

You have the right to review and correct your credit report.  But with marketing data, there's often no way to know exactly what information is attached to your name — or whether it's accurate.

Most companies offer, at best, a partial picture.

In September, Acxiom debuted aboutthedata.com, which allows to you review and edit some of the company’s marketing data on you, by entering your name, address, birth date and the last four digits of your social security number.

The Federal Trade Commission’s Julie Brill tweeted that “more data brokers should follow” Acxiom’s example.  But the effort received mixed reviews from users, privacy advocates and government regulators, the New York Times reported.

Previously, Acxiom only let customers review a smaller slice of the information the company sells about them, including criminal history, as New York Times reporter Natasha Singer described last year.  When Singer requested and finally received her report in 2012, all it included was a record of her residential addresses.

Other companies also offer some access.  A spokeswoman for Epsilon said it allows consumers to review "high level information" about their data — like whether or not you’ve purchased "home furnishings" merchandise.  (Requests to review this information cost $5 and can only be made by postal mail.)

RapLeaf, a company that advertises that it has "real-time data" on 80 percent of U.S. email addresses, says it gives customers "total control over the data we have on you," and allows them to review and edit the categories it associates with them (like "estimated household income" and "Likely Political Contributor to Republicans").

How do I know when someone has purchased data about me?

Most of the time, you don't.

When you're checking out at a store and a cashier asks you for your Zip code, the store isn't just getting that single piece of information.  Acxiom and other data companies offer services that allow stores to use your Zip code and the name on your credit card to pinpoint your home address — without asking you for it directly.

Is there any way to stop the companies from collecting and sharing information about me?

Yes, but it would require a whole lot of work.

Many data brokers offer consumers the chance to "opt out" of being included in their databases, or at least from receiving advertising enabled by that company.  Rapleaf, for instance, has a "Permanent opt-out" that "deletes information associated with your email address from the Rapleaf database."

But to actually opt-out effectively, you need to know about all the different data brokers and where to find their opt-outs.  Most consumers, of course, don't have that information.

In their privacy report last year, the FTC suggested that data brokers should create a centralized website that would make it easier for consumers to learn about the existence of these companies and their rights regarding the data they collect.

How many people do these companies have information on?

Basically everyone in the U.S. and many beyond it.  Acxiom, recently profiled by the New York Times, says it has information on 500 million people worldwide, including "nearly every U.S. consumer."

After the 9/11 attacks, CNN reported, Acxiom was able to locate 11 of the 19 hijackers in its database.

How is all of this data actually used?

Mostly to sell you stuff.  Companies want to buy lists of people who might be interested in what they're selling — and also want to learn more about their current customers.

They also sell their information for other purposes, including identity verification, fraud prevention and background checks.

If new privacy laws are passed, will they include the right to see what data these companies have collected about me?

Unlikely.

In a report on privacy last year, the Federal Trade Commission recommended that Congress pass legislation "that would provide consumers with access to information about them held by a data broker."  President Barack Obama has also proposed a Consumer Privacy Bill of Rights that would give consumers the right to access and correct certain information about them.

But this probably won't include access to marketing data, which the Federal Trade Commission considers less sensitive than data used for credit reports or identity verification.

In terms of marketing data, "we think at the very least consumers should have access to the general categories of data the companies have about consumers," said Maneesha Mithal of the FTC's Division of Privacy and Identity Protection.

Data companies have also pushed back against the idea of opening up marketing profiles for individual consumers' inspection.

Even if there were errors in your marketing data profile, "the worst thing that could happen is that you get an advertising offer that isn't relevant to you," said Rachel Thomas, the vice president of government affairs at the Direct Marketing Association.

"The fraud and security risks that you run by opening up those files is higher than any potential harm that could happen to the consumer," Thomas said.