<?xml version="1.0" encoding="utf-8"?>
<feed version="0.3" xmlns="http://purl.org/atom/ns#" xmlns:dc="http://purl.org/dc/elements/1.1/" xml:lang="en">
<title>Secondary Screening</title>
<link rel="alternate" type="text/html" href="http://secondaryscreening.net/" />
<modified>2006-04-28T01:25:29Z</modified>
<tagline>A Closer Look At Anti-Terrorism, Privacy and Data Mining</tagline>
<id>tag:secondaryscreening.net,2006://2</id>
<generator url="http://www.movabletype.org/" version="3.2">Movable Type</generator>
<copyright>Copyright (c) 2006, Ryan Singel</copyright>
<entry>
<title>Change of Address</title>
<link rel="alternate" type="text/html" href="http://www.secondaryscreening.net/static/archives/2006/04/change_of_addre.html" />
<modified>2006-04-28T01:25:29Z</modified>
<issued>2006-04-28T01:10:43Z</issued>
<id>tag:secondaryscreening.net,2006://2.297</id>
<created>2006-04-28T01:10:43Z</created>
<summary type="text/plain">Kevin Poulsen, my rocking editor at Wired News, made me an offer I couldn&apos;t refuse -- co-blogging with him over on the Wired News site. So now I&apos;m moving my prose stylings over to a Wired News blog called 27B...</summary>
<author>
<name>Ryan Singel</name>
<url>secondaryscreening.net</url>
<email>ryan@secondaryscreening.net</email>
</author>
<dc:subject>Miscellany</dc:subject>
<content type="text/html" mode="escaped" xml:lang="en" xml:base="http://secondaryscreening.net/">
<![CDATA[<p>Kevin Poulsen, my rocking editor at Wired News, made me an offer I couldn't refuse -- co-blogging with him over on the Wired News site.  </p>

<p>So now I'm moving my prose stylings over to a Wired News blog called <a href="http://blog.wired.com/27BStroke6/">27B Stroke 6</a>. I for one welcome my Lycos overlords.</p>

<p>Kevin describes the new site like this: "Investigative reporter Ryan Singel and senior editor Kevin Poulsen scare peace-loving people with phantoms of lost liberty, in a daily briefing on security, freedom and privacy in the wired world."</p>

<p>I love this little blog and will post here irregularly, but the new blog is gonna be even better more greater.</p>

<p>Sorry to mess with your bookmarks, but remember, we are all in this together.</p>

<p>For those who want to update their RSS readers, here's the <a href="http://blog.wired.com/27BStroke6/rss.xml">XML file</a> for 27B Stroke 6.<br />
<!-- technorati tags start --><p style="text-align:right;font-size:10px;">Technorati Tags: <a href="http://www.technorati.com/tag/27BStroke6" rel="tag">27BStroke6</a>, <a href="http://www.technorati.com/tag/27B Stroke 6" rel="tag">27B Stroke 6</a>, <a href="http://www.technorati.com/tag/Kevin Poulsen" rel="tag">Kevin Poulsen</a>, <a href="http://www.technorati.com/tag/Ryan Singel" rel="tag">Ryan Singel</a></p><!-- technorati tags end --></p>]]>

</content>
</entry>
<entry>
<title>Privatized Registered Traveler On Track</title>
<link rel="alternate" type="text/html" href="http://www.secondaryscreening.net/static/archives/2006/04/privatized_regi.html" />
<modified>2006-04-21T19:33:39Z</modified>
<issued>2006-04-21T19:19:20Z</issued>
<id>tag:secondaryscreening.net,2006://2.296</id>
<created>2006-04-21T19:19:20Z</created>
<summary type="text/plain">Passengers willing to undergo perpetual government background checks in exchange for the promise of shorter screening lines at the airport will be able to register as soon as late summer in a corporate-run Registered Traveler program set to debut in...</summary>
<author>
<name>Ryan Singel</name>
<url>secondaryscreening.net</url>
<email>ryan@secondaryscreening.net</email>
</author>
<dc:subject>Airline Security Measures</dc:subject>
<content type="text/html" mode="escaped" xml:lang="en" xml:base="http://secondaryscreening.net/">
<![CDATA[<p>Passengers willing to undergo perpetual government background checks in exchange for the promise of shorter screening lines at the airport will be able to register as soon as late summer in a corporate-run Registered Traveler program set to debut in ten to twenty airports.</p>

<p>The Transportation Security Administration announced the latest timetable and specifications Thursday.  While each airport could be run by a different company, which will have to pay for its own security lanes, screeners and registration process, a traveler registered with one company will be able to use the lanes at other airports.</p>

<p>But the <a href="http://www.tsa.gov/public/display?theme=44&content=09000519801cdf0d">press release</a> is vague on what the benefits for travelers will be:</p>

<blockquote>In order to enter the RT program, applicants must provide biographic information, which will be verified and authenticated to safeguard against the use of a false or stolen identity.  All applicants must undergo a TSA Security Threat Assessment that includes perpetual vetting.  When traveling, an RT participant must confirm his or her identity at an RT station using biometrics (fingerprints or iris).  RT participants will still be required to pass through the metal detector, have their carry-on and checked luggage screened, and will be subject to secondary screening by TSA if they trigger an alarm.  Consistent with TSA policies, an element of randomness will also be integrated into Registered Traveler to ensure unpredictability and disrupt potential efforts by terrorists to thwart the system.</blockquote>

<p>The release also alludes to benefits: "While the combination of benefits and security measures available at each participating airport may vary, all RT travelers should receive an expedited and more convenient checkpoint experience."  However if participants still have to have their luggage checked and could get secondary screening randomly, I don't see what the benefits are?  Shorter lines?  Snappier dressed security personnel?  Free Starbucks while waiting in line?  The feeling that while we are all in this together, some of us are more all in this than others?</p>]]>

</content>
</entry>
<entry>
<title>Software Bug Shuts Down Nation&apos;s Busiest Airport</title>
<link rel="alternate" type="text/html" href="http://www.secondaryscreening.net/static/archives/2006/04/software_bug_sh.html" />
<modified>2006-04-21T17:13:39Z</modified>
<issued>2006-04-21T16:58:35Z</issued>
<id>tag:secondaryscreening.net,2006://2.295</id>
<created>2006-04-21T16:58:35Z</created>
<summary type="text/plain">A software bug in the system designed to keep carry-on bag screeners alert shut down Atlanta&apos;s Hartsfield-Jackson International airport, the nation&apos;s busiest airport, on Wednesday, according to CNN. In order to break up the tedium of scanning bags full of...</summary>
<author>
<name>Ryan Singel</name>
<url>secondaryscreening.net</url>
<email>ryan@secondaryscreening.net</email>
</author>

<content type="text/html" mode="escaped" xml:lang="en" xml:base="http://secondaryscreening.net/">
<![CDATA[<p>A software bug in the system designed to keep carry-on bag screeners alert shut down Atlanta's Hartsfield-Jackson International airport, the nation's busiest airport, on Wednesday, according to CNN.</p>

<p>In order to break up the tedium of scanning bags full of books and cosmestics, the TSA uses software that randomly inserts images of bags with explosives and weapons.  A few seconds later, hopefully after the screener identifies the bag as a threat, the software is supposed to flash a message that the image is fake.</p>

<p>Only this time it didn't.</p>

<blockquote>While screening carry-on luggage, a TSA employee identified the image of a suspicious device but did not realize it was part of routine testing for security screeners because the software failed to indicate such a test was under way, [Transportation Security Administration Director Kip] Hawley said. 

<p>Authorities evacuated the security area for two hours while searching for the suspicious device, causing flight delays and forcing travelers who could not get through to the terminals to wait outside the airport.</blockquote></p>

<p><a href="http://www.cnn.com/2006/US/04/20/atlanta.airport/index.html">Link</a>.</p>

<p>Two thoughts.  One, I'm surprised this hasn't happened more often.  And two, systems, especially one as sprawling as the air transportation system, are fragile.  For over three years now, the TSA has been working to take the job of checking passengers' names against a terrorist watchlist out of the hands of individual airlines and centralize the checks in D.C.  What happens to airline travel if the government's planned computer system goes down?  Is that an acceptable risk?</p>]]>

</content>
</entry>
<entry>
<title>HostGator Rocks</title>
<link rel="alternate" type="text/html" href="http://www.secondaryscreening.net/static/archives/2006/04/hostgator_rocks.html" />
<modified>2006-04-21T00:54:27Z</modified>
<issued>2006-04-21T00:47:57Z</issued>
<id>tag:secondaryscreening.net,2006://2.294</id>
<created>2006-04-21T00:47:57Z</created>
<summary type="text/plain">My blog got smacked hard today with automated comment spam. I found the host of the responsible site and reported the abuse. I also dropped a note to the spammer, who lives in Mexico. He wrote me back saying his...</summary>
<author>
<name>Ryan Singel</name>
<url>secondaryscreening.net</url>
<email>ryan@secondaryscreening.net</email>
</author>
<dc:subject>Miscellany</dc:subject>
<content type="text/html" mode="escaped" xml:lang="en" xml:base="http://secondaryscreening.net/">
<![CDATA[<p>My blog got smacked hard today with automated comment spam.</p>

<p>I found the host of the responsible site and reported the abuse.</p>

<p>I also dropped a note to the spammer, who lives in Mexico.  He wrote me back saying his spam wasn't illegal and that my IP ban wouldn't work and that his ISP wouldn't disconnect him.</p>

<p><a href="http://hostgator.com/">HostGator</a> took his site down minutes later.</p>

<p>No hosting company wants to lose a customer, so I'm super impressed with these folks.</p>

<p>For those who don't run blogs, this may seem not to be a big deal, but blog spam is really tedious and really tough to shut down.  I highly appreciate any help I can get keeping these folks off my site.</p>]]>

</content>
</entry>
<entry>
<title>But some butter is more butter than other butter</title>
<link rel="alternate" type="text/html" href="http://www.secondaryscreening.net/static/archives/2006/04/but_some_butter.html" />
<modified>2006-04-19T17:32:47Z</modified>
<issued>2006-04-18T04:06:46Z</issued>
<id>tag:secondaryscreening.net,2006://2.293</id>
<created>2006-04-18T04:06:46Z</created>
<summary type="text/plain">This is Animal Farm situated in Orwell, Vermont. Their butter is better than normal capitalist butter: It also has a butter-fat content of 87 percent, significantly higher than other butters made in the United States and the equivalent of the...</summary>
<author>
<name>Ryan Singel</name>
<url>secondaryscreening.net</url>
<email>ryan@secondaryscreening.net</email>
</author>
<dc:subject>Miscellany</dc:subject>
<content type="text/html" mode="escaped" xml:lang="en" xml:base="http://secondaryscreening.net/">
<![CDATA[<p><a href="http://secondaryscreening.net/static/pics/frontimage.jpg" onclick="window.open('http://secondaryscreening.net/static/pics/frontimage.jpg','popup','width=300,height=246,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0');return false"><img src="http://secondaryscreening.net/static/pics/frontimage-tbn.jpg" height="246" width="300" align="right" border="5" hspace="5" vspace="5" alt="the animal farm" /></a>This is <a href="http://www.animalfarmvt.com/">Animal Farm</a> situated in Orwell, Vermont.</p>

<p>Their butter is better than normal capitalist butter:</p>

<p>It also has a butter-fat content of 87 percent, significantly higher than other butters made in the United States and the equivalent of the finest French butters. This makes Animal Farm butter superb for pastry-making - as well as for every other use.</p>

<p>(brazenly borrowed from <a href="http://www.emergentchaos.com/archives/2006/04/animal_farm.html">A. Shostack</a>)</p>]]>

</content>
</entry>
<entry>
<title>TSA Picks Privacy Player</title>
<link rel="alternate" type="text/html" href="http://www.secondaryscreening.net/static/archives/2006/04/tsa_picks_priva.html" />
<modified>2006-04-18T00:41:18Z</modified>
<issued>2006-04-17T22:41:08Z</issued>
<id>tag:secondaryscreening.net,2006://2.292</id>
<created>2006-04-17T22:41:08Z</created>
<summary type="text/plain">The Transportation Security Administration picked Peter Pietra as their top choice in this year&apos;s National Privacy League draft. Pietra will be playing QB (a position TSA bureaucrats call &quot;Director of Privacy Policy and Compliance&quot;) for the beleaguered TSA, which has...</summary>
<author>
<name>Ryan Singel</name>
<url>secondaryscreening.net</url>
<email>ryan@secondaryscreening.net</email>
</author>
<dc:subject>Airline Security Measures</dc:subject>
<content type="text/html" mode="escaped" xml:lang="en" xml:base="http://secondaryscreening.net/">
<![CDATA[<p>The Transportation Security Administration picked Peter Pietra as their top choice in this year's National Privacy League draft.  Pietra will be playing QB (a position TSA bureaucrats call "Director of Privacy Policy and Compliance") for the beleaguered TSA, which has struggled in the National Privacy League after repeated fumbles caused by poorly configured watch lists and unsanctioned use of personal information on American citizens.  </p>

<p>The TSA has also been unable to score any touchdowns with a computerized passenger-screening system known as CAPPS II or Secure Flight.  Congress and its investigative arm, the Government Accountability Office, have repeatedly forced the TSA to punt.</p>

<p>TSA hopes Pietra, who will be working with halfback/Privacy Officer Lisa Dean, will help the TSA overtake the FBI and NSA in the NPL's Federal Agency Conference, according to <a href="http://biz.yahoo.com/prnews/060417/dcm024.html?.v=41">today's announcement</a>.</p>

<p>"The devotion of increased resources and expertise to TSA privacy programs is expected to make the agency a leader in privacy efforts within DHS and the Federal government as a whole. With the anticipated launch of several programs, including TWIC, Registered Traveler and Secure Flight, it's critical the agency is poised to meet the workload and improve communication with stakeholders and the traveling public."</p>

<p>Pietra says he's just happy to get a shot at the bigs.</p>

<p>"We gotta play privacy impact assessments one day at a time. I'm just happy to be here. Hope I can help the agency," Pietra said. "I just want to give it my best shot, and the good Lord willing, things will work out."</p>]]>

</content>
</entry>
<entry>
<title>AT&amp;T Loses A Customer Over NSA Lawsuit</title>
<link rel="alternate" type="text/html" href="http://www.secondaryscreening.net/static/archives/2006/04/att_loses_a_cus.html" />
<modified>2006-04-15T00:06:52Z</modified>
<issued>2006-04-14T23:55:11Z</issued>
<id>tag:secondaryscreening.net,2006://2.291</id>
<created>2006-04-14T23:55:11Z</created>
<summary type="text/plain">AT&amp;T has lost at least one customer due to the class action lawsuit filed by the Electronic Frontier Foundation accusing the telecom giant of wiretapping the Internet on behalf of the National Security Agency (NSA). That customer? Judge Vaughn Walker,...</summary>
<author>
<name>Ryan Singel</name>
<url>secondaryscreening.net</url>
<email>ryan@secondaryscreening.net</email>
</author>
<dc:subject>Privacy</dc:subject>
<content type="text/html" mode="escaped" xml:lang="en" xml:base="http://secondaryscreening.net/">
<![CDATA[<p>AT&T has lost at least one customer due to the class action lawsuit filed by the Electronic Frontier Foundation accusing the telecom giant of wiretapping the Internet on behalf of the National Security Agency (NSA).</p>

<p>That customer? Judge Vaughn Walker, the San Francisco District Chief Judge who is assigned to the case.</p>

<p>In an order Walker released today, the judge told the parties that he was an AT&T phone customer when the case was assigned to him, so he switched telecom providers to avoid a conflict of interest.  Walker did not say what company he switched to, or if he got a better long distance rate.</p>

<p>Being a former AT&T customer also makes him a potential member of the class suing AT&T, so he foreswore any money he might be entitled to.</p>

<p>Walker is not recusing himself, however, and cited a number of cases supporting his position.  He also mentions that if he had to do so, so too would almost every judge in the district since it's highly likely that some member of every judge's family was an AT&T subscriber.  Walker is giving both AT&T and the EFF a week to file briefs agreeing or disagreeing (or in AT&T's case, to offer him free conference calling if he comes back into the fold).  After that, Walker says he will stat to rule on the flurry of motions filed this week.</p>

<p>Full recusal order <a href="http://www.eff.org/legal/cases/att/RecusalOrder.pdf">here</a>. (.pdf)</p>]]>

</content>
</entry>
<entry>
<title>Jetsons Video Phone?  Deaf Say Yes!</title>
<link rel="alternate" type="text/html" href="http://www.secondaryscreening.net/static/archives/2006/04/jetsons_video_p.html" />
<modified>2006-04-19T18:19:16Z</modified>
<issued>2006-04-13T17:47:24Z</issued>
<id>tag:secondaryscreening.net,2006://2.290</id>
<created>2006-04-13T17:47:24Z</created>
<summary type="text/plain">More than 40 years after the Jetsons promised us we would all have videophones, we&apos;ve arrived at a future where that&apos;s a reality -- whether through free internet chat applications, pricey standalone home units, or high-tech corporate video-conferencing rooms. Now...</summary>
<author>
<name>Ryan Singel</name>
<url>secondaryscreening.net</url>
<email>ryan@secondaryscreening.net</email>
</author>
<dc:subject>Miscellany</dc:subject>
<content type="text/html" mode="escaped" xml:lang="en" xml:base="http://secondaryscreening.net/">
<![CDATA[<p><a href="http://www.scarlet.nl/~ivo/photo_JANE3.JPEG"><img src="http://secondaryscreening.net/static/pics/photo_JANE3-tbn.jpg" height="250" width="341" border="2" hspace="2" vspace="2" align ="right" alt="Jane Jetson and a Video Phone" /></a>More than 40 years after the Jetsons promised us we would all have videophones, we've arrived at a future where that's a reality -- whether through free internet chat applications, pricey standalone home units, or high-tech corporate video-conferencing rooms.</p>

<p>Now that we have them, it's far from clear that the average phoner wants video for routine calls like ordering a pizza or checking in with mom and dad. But one community is certain of the videophone's benefits: the deaf.</p>

<blockquote>An FCC program for the deaf sounds like the modern equivalent of ringing Mabel the operator down at the phone exchange so she can patch through your call. Assuming, of course, that Mabel has signing skills.

<p>The system, called video relay services, or VRS, is proving a godsend to the deaf and hearing-impaired, allowing them to communicate using American Sign Language through a translator to a third party.</p>

<p>Increasing numbers of the hearing-impaired are now using various sorts of video phones with VRS to place calls to each other and to the hearing world.</p>

<p>VRS providers are paid approximately $6 a minute by the FCC from a tax levied on every U.S. phone bill. That makes VRS an expensive replacement for conventional TDD-based services, in which an operator relays between a deaf person typing on a computer terminal and a hearing person on the phone. Those calls cost the FCC about $1 a minute.</p>

<p>But the technology is a quantum leap for deaf people, according to Pat Nola, CEO of Sorenson Communications, the nation's largest VRS provider.</p>

<p>For the deaf, switching to the new service is like a hearing person going from Morse code to a telephone, says Nola.</blockquote></p>

<p>Full story <a href="http://www.wired.com/news/technology/0,70585-0.html">here</a>.</p>

<p>Josh, a reader, writes in to chide me for not including <a href="http://www.captionedtelephone.com">Captioned Telephone</a> as part of the story:</p>

<blockquote>From what I understand, the majority of the deaf and hard of hearing community can still speak.  This technology allows a normal telephone conversation to take place with the operator uses voice recognition to provide real-time captions of the phone call.  I know several people that use this and it seems much less cumbersome than a video conference system.</blockquote>

<p>That does sound interesting and I didn't include it in the story because I hadn't run it across it in my reporting.  Score another point for my readers being smarter than I am.<br />
</p>]]>

</content>
</entry>
<entry>
<title>AT&amp;T *69s EFF</title>
<link rel="alternate" type="text/html" href="http://www.secondaryscreening.net/static/archives/2006/04/att_69s_eff.html" />
<modified>2006-04-13T00:34:27Z</modified>
<issued>2006-04-13T00:28:14Z</issued>
<id>tag:secondaryscreening.net,2006://2.289</id>
<created>2006-04-13T00:28:14Z</created>
<summary type="text/plain">AT&amp;T has responded to the Electronic Frontier Foundation&apos;s move to have a judge stop the company from allegedly helping the NSA eavesdrop on its customers, and the telecom giant says it wants its secret documents back pronto. In papers filed...</summary>
<author>
<name>Ryan Singel</name>
<url>secondaryscreening.net</url>
<email>ryan@secondaryscreening.net</email>
</author>
<dc:subject>Privacy</dc:subject>
<content type="text/html" mode="escaped" xml:lang="en" xml:base="http://secondaryscreening.net/">
<![CDATA[<p>AT&T has responded to the Electronic Frontier Foundation's move to have a judge stop the company from allegedly helping the NSA eavesdrop on its customers, and the telecom giant says it wants its secret documents back pronto.</p>

<blockquote>In papers filed late Monday, AT&T argued that confidential technical documents provided by an ex-AT&T technician to the Electronic Frontier Foundation shouldn't be used as evidence in the case and should be returned.

<p>The documents, which the EFF filed under a temporary seal last Wednesday, purportedly detail how AT&T diverts internet traffic to the National Security Agency via a secret room in San Francisco and allege that such rooms exist in other AT&T switching centers.</p>

<p>The EFF filed the class-action lawsuit in U.S. District Court in Northern California in January, seeking damages from AT&T on behalf of AT&T customers for alleged violation of state and federal laws.</p>

<p>Mark Klein, a former technician who worked for AT&T for 22 years, provided three technical documents, totaling 140 pages, to the EFF and to The New York Times, which first reported last December that the Bush administration was eavesdropping on citizens' phone calls without obtaining warrants.</p>

<p>Klein issued a detailed public statement last week, saying he came forward because he believes the government's extrajudicial spying extended beyond wiretapping of phone calls between Americans and a party with suspected ties to terrorists, and included wholesale monitoring of the nation's internet communications.</blockquote></p>

<p>The rest of today's story is <a href="http://www.wired.com/news/technology/0,70650-0.html">here</a>.  Earlier stories on the lawsuit (<a href="http://www.secondaryscreening.net/static/archives/2006/04/exatt_employee.html">1</a> , <a href="http://www.secondaryscreening.net/static/archives/2006/04/exatt_employee.html">2</a>,<a href="http://www.wired.com/news/technology/0,70650-0.html">3</a>)<!-- technorati tags start --><p style="text-align:right;font-size:10px;">Technorati Tags: <a href="http://www.technorati.com/tag/narus" rel="tag">narus</a>, <a href="http://www.technorati.com/tag/nsa" rel="tag">nsa</a>, <a href="http://www.technorati.com/tag/eff" rel="tag">eff</a>, <a href="http://www.technorati.com/tag/at&t" rel="tag">at&t</a>, <a href="http://www.technorati.com/tag/mark klein" rel="tag">mark klein</a></p><!-- technorati tags end --></p>]]>

</content>
</entry>
<entry>
<title>Narus Not in the Know</title>
<link rel="alternate" type="text/html" href="http://www.secondaryscreening.net/static/archives/2006/04/narus_not_in_th.html" />
<modified>2006-04-12T20:48:38Z</modified>
<issued>2006-04-12T20:39:46Z</issued>
<id>tag:secondaryscreening.net,2006://2.288</id>
<created>2006-04-12T20:39:46Z</created>
<summary type="text/plain">Elise Ackerman at the San Jose Mercury News has some great follow-up reporting today on ex-AT&amp;T employee-cum-whistleblower Mark Klein&apos;s public statement last week, which included allegations that a secret NSA spying room wired into to AT&amp;T&apos;s internet switching station in...</summary>
<author>
<name>Ryan Singel</name>
<url>secondaryscreening.net</url>
<email>ryan@secondaryscreening.net</email>
</author>
<dc:subject>Data Mining</dc:subject>
<content type="text/html" mode="escaped" xml:lang="en" xml:base="http://secondaryscreening.net/">
<![CDATA[<p>Elise Ackerman at the <cite>San Jose Mercury News</cite> has some great follow-up reporting today on <a href="http://www.wired.com/news/technology/0,70619-0.html?tw=wn_index_1">ex-AT&T employee-cum-whistleblower Mark Klein</a>'s <a href="http://www.wired.com/news/technology/0,70621-0.html?tw=wn_index_1">public statement </a>last week, which included allegations that a secret NSA spying room wired into to AT&T's internet switching station in San Francisco was home to a <a href="http://www.secondaryscreening.net/static/archives/2006/04/spy_machine_cap.html">piece of data-mining equipment known as a Narus STA 6400</a>.</p>

<blockquote>The engineers at Narus weren't intending to create Big Brother's dream machine when they began writing software a decade ago to help phone companies send out more detailed bills.

<p>But as the Mountain View company's code became more and more sophisticated, customers began to discover new uses for software that was originally designed to monitor and analyze network traffic.</p>

<p>Now Narus finds itself at the center of a legal fight over domestic spying.</p>

<p>[...]</p>

<p>Narus executives confirm AT&T is a customer but say they do not know how the telecommunications giant uses its software. ``Once our customers buy our product, it's relatively opaque to us,'' said Steve Bannerman, vice president of marketing.</p>

<p>Narus CEO Greg Oslan said the company's software is designed to allow carriers to monitor all Internet traffic, including Web searches, e-mail content and attachments, and Internet phone calls.</blockquote></p>

<p>Full story <a href="http://www.mercurynews.com/mld/mercurynews/14323368.htm">here</a>.</p>]]>

</content>
</entry>
<entry>
<title>Barbie Says Privacy Is Hard</title>
<link rel="alternate" type="text/html" href="http://www.secondaryscreening.net/static/archives/2006/04/barbie_says_pri.html" />
<modified>2006-04-11T20:51:10Z</modified>
<issued>2006-04-11T19:57:10Z</issued>
<id>tag:secondaryscreening.net,2006://2.287</id>
<created>2006-04-11T19:57:10Z</created>
<summary type="text/plain">Daniel Solove has a post today about New York Attorney General Eliot Spitzer settling with Datran Media for $1.1 million for allegedly renting the Freepay/Gratis Internet/Freeipods.com email list while KNOWING that the email list was protected by a privacy policy....</summary>
<author>
<name>Ryan Singel</name>
<url>secondaryscreening.net</url>
<email>ryan@secondaryscreening.net</email>
</author>
<dc:subject>Privacy</dc:subject>
<content type="text/html" mode="escaped" xml:lang="en" xml:base="http://secondaryscreening.net/">
<![CDATA[<p>Daniel Solove has a <a href="http://www.concurringopinions.com/archives/2006/04/the_datran_medi_1.html#more">post</a> today about New York Attorney General Eliot Spitzer <a href="http://www.secondaryscreening.net/static/archives/2006/03/a_slimy_little.html">settling with Datran Media for $1.1 million</a> for allegedly renting the Freepay/Gratis Internet/Freeipods.com email list while KNOWING that the email list was protected by a privacy policy.  The settlement is causing some waves in the direct marketing community, which is now worried it will have to perform "due diligence" before renting lists.</p>

<p>Kirk Nahra's essay <a href="http://wrf.com/publication_newsletters.cfm?sp=newsletter&year=2006&ID=10&publication_id=12551&keyword=">essay</a> for <cite>Privacy in Focus</cite> is a prime example of that hand-wringing.  Nahra, a partner at the law firm of Wiley Rein & Fielding, described the settlement holding Datran responsible for checking the privacy policy of the database it wanted to deluge with emails as an "Alice-in-Wonderland result."</p>

<blockquote>The settlement appears to impose a new "due diligence" obligation on the vendor to understand and review the privacy policy of its principals and sub-vendors to make sure that the data supplier isn't doing something wrong in providing data.

<p>How far will this go? Does the vendor have to review underlying consents? Does the vendor have to engage in an audit of the list supplier's privacy practices? How does this new vendor-to-vendor due diligence obligation affect the already growing client-to-vendor oversight obligations?</p>

<p>Obviously, it is too soon to know the full implications of this case-including whether there are any real implications beyond this specific set of facts and companies. It is clear, however, that the Datran settlement adds a new and difficult dimension to vendor contracting, making it even more time consuming and burdensome to retain vendors for any activity that involves personal information. Is that really a result that protects people's privacy?</blockquote></p>

<p>Weirdly, Nahra mentions the <a href="http://www.secondaryscreening.net/static/archives/2006/03/lovely_day.html">follow-up lawsuit</a> against Gratis Internet, but it seems Nahra couldn't be bothered to read the filings, which might have answered some of his questions.</p>

<p>For instance, according to Spitzer's allegations, which rely heavily on documents and emails obtained during the investigation, Datran employee Susan Weiner asked Gratis Internet to change its privacy policy retroactively, after Datran entered into a contract with Gratis.  If true, and Datran's settlement indicates it was, is there any wonder Spitzer considered Datran negligent?</p>

<p>And really, so what if Spitzer sets a precedent that list buyers have to check the privacy policies of the databases they want to buy or rent? Really, how hard is it to check a privacy policy before you buy millions of pieces of intimate information on American citizens?  It's at most a couple of clicks. I do that before buying batteries online. </p>]]>

</content>
</entry>
<entry>
<title>Spy Machine Capabilities?</title>
<link rel="alternate" type="text/html" href="http://www.secondaryscreening.net/static/archives/2006/04/spy_machine_cap.html" />
<modified>2006-04-10T18:31:09Z</modified>
<issued>2006-04-10T18:17:41Z</issued>
<id>tag:secondaryscreening.net,2006://2.286</id>
<created>2006-04-10T18:17:41Z</created>
<summary type="text/plain">A blogger named bewert over at Daily Kos follows up on allegations made by ex-AT&amp;T employee Mark Klein that AT&amp;T installed equipment at an AT&amp;T Internet switching facility that feeds the NSA a copy of every Internet packet that flowing...</summary>
<author>
<name>Ryan Singel</name>
<url>secondaryscreening.net</url>
<email>ryan@secondaryscreening.net</email>
</author>
<dc:subject>Data Mining</dc:subject>
<content type="text/html" mode="escaped" xml:lang="en" xml:base="http://secondaryscreening.net/">
<![CDATA[<p>A blogger named bewert over at Daily Kos follows up on  allegations made by ex-AT&T employee Mark Klein that AT&T installed equipment at an AT&T Internet switching facility that feeds the NSA a copy of every Internet packet that flowing from or to AT&T customers or across AT&T's expansive Internet backbone network.  I covered <a href="http://www.secondaryscreening.net/static/archives/2006/04/exatt_employee.html">Klein's public statement for  Wired News on Friday</a> and his full statement can also be found <a href="http://www.wired.com/news/technology/0,70621-0.html?tw=wn_index_22">here</a>.</p>

<p>bewert looked into the machine alleging Narus STA 6400, <a href="http://www.dailykos.com/storyonly/2006/4/8/14724/28476">did a little math and parsing of some public statements</a> to find that the machine was capable of monitoring 39,000 DSL lines at any one time.</p>

<blockquote>Prior to 9/11 Narus worked on building carrier-grade tools to analyze IP network traffic for billing purposes, to prevent what they term "revenue leakage". Post-9/11 they have continued down that path while adding more semantic monitoring abilities for surveillance purposes. They even brought in former Deputy Director of the NSA William P. Crowell as an addition to their Board of Directors. [...]

<p>Remember that semantics is not just the data, but rather the meaning of the data. It looks at the data in a more comprehensive way than looking for keywords. Each NarusInsight machine does this at 2500 million bits per second, in real-time.[...]</p>

<p>These capabilities include playback of streaming media (i.e. VoIP), rendering of web pages, examination of e-mail and the ability to analyze the payload/attachments of e-mail or file transfer protocols. Narus partner products offer the ability to quickly analyze information collected by the Directed Analysis or Lawful Intercept modules. When Narus partners' powerful analytic tools are combined with the surgical targeting and real-time collection capabilities of Directed Analysis and Lawful Intercept modules, analysts or law enforcement agents are provided capabilities that have been unavailable thus far.[...]</blockquote></p>]]>

</content>
</entry>
<entry>
<title>Ex-AT&amp;T Employee on NSA Wiretap Room</title>
<link rel="alternate" type="text/html" href="http://www.secondaryscreening.net/static/archives/2006/04/exatt_employee.html" />
<modified>2006-04-07T20:01:45Z</modified>
<issued>2006-04-07T19:52:22Z</issued>
<id>tag:secondaryscreening.net,2006://2.285</id>
<created>2006-04-07T19:52:22Z</created>
<summary type="text/plain">An ex-At&amp;T employee has made public a summary of his statement he provided in support of a lawsuit against AT&amp;T, alleging that the telecom giant has built out secret wiretap rooms that funnel internet and phone call data to the...</summary>
<author>
<name>Ryan Singel</name>
<url>secondaryscreening.net</url>
<email>ryan@secondaryscreening.net</email>
</author>
<dc:subject>Data Mining</dc:subject>
<content type="text/html" mode="escaped" xml:lang="en" xml:base="http://secondaryscreening.net/">
<![CDATA[<p>An ex-At&T employee has made public a summary of his statement he provided in support of a lawsuit against AT&T, alleging that the telecom giant has built out secret wiretap rooms that funnel internet and phone call data to the National Security Agency.</p>

<blockquote>AT&T provided NSA eavesdroppers with full access to its customers' phone calls, and shunted its customers' internet traffic to data mining equipment installed in a secret room in its San Francisco switching center, according a former AT&T worker cooperating in the Electronic Frontier Foundation's lawsuit against the company.

<p>Mark Klein, a retired AT&T communications technician, submitted an affidavit in support of the EFF's lawsuit this week. That class action lawsuit, filed in federal court in San Francisco last January, alleges that AT&T violated federal and state laws by surreptiously allowing the government to monitor phone and internet communications of AT&T customers without warrants.</p>

<p>On Wednesday, the EFF asked the court to issue an injunction prohibiting AT&T from continuing the alleged wiretapping, and filed a number of documents under seal, including three AT&T documents that purportedly explain how the wiretapping system works.</p>

<p>According to a statement released by Klein's attorney, an NSA agent showed up at the San Francisco switching center in 2002 to interview a management-level technician for a special job. In January 2003, Klein observed a new room being built adjacent to the room housing AT&T's #4ESS switching equipment, which is responsible for routing long distance and international calls.</p>

<p>"I learned that the person whom the NSA interviewed for the secret job was the person working to install equipment in this room," Klein wrote. "The regular technician workforce was not allowed in the room."</p>

<p>Klein's job eventually included connecting internet circuits to a splitting cabinet that led to the secret room. During the course of that work, he learned from a co-worker that similar cabinets were being installed in other cities, including Seattle, San Jose, Los Angeles and San Diego.</p>

<p>"While doing my job, I learned that fiber optic cables from the secret room were tapping into the WorldNet (AT&T's internet service) circuits by splitting off a portion of the light signal," Klein said wrote.</p>

<p>The split circuits included traffic from peering links connecting to other internet backbone providers, meaning that AT&T's was also diverting traffic routed from its network to or from other domestic and international providers, according to Klein's statement.</p>

<p>The secret room also included data-mining equipment called a Narus STA 6400, "known to be used particularly by government intelligence agencies because of its ability to sift through large amounts of data looking for preprogrammed targets," according to Klein's statement.</blockquote></p>

<p>Full story <a href="http://www.wired.com/news/technology/0,70619-0.html?tw=wn_index_1">here</a>.  Justin Scheck of The Recorder had the story first, and has some <a href="http://legalpad.wordpress.com/2006/04/06/wiretap/">great info on the story and Klein's lawyer, Miles Ehrlich</a>, a former U.S. attorney, over at the CalLaw's blog, <a href="http://legalpad.wordpress.com/">Legal Pad</a>.</p>]]>

</content>
</entry>
<entry>
<title>Spitzer Fighting Spam With 1980&apos;s Technology</title>
<link rel="alternate" type="text/html" href="http://www.secondaryscreening.net/static/archives/2006/04/spitzer_fightin.html" />
<modified>2006-04-05T20:02:09Z</modified>
<issued>2006-04-05T19:40:00Z</issued>
<id>tag:secondaryscreening.net,2006://2.284</id>
<created>2006-04-05T19:40:00Z</created>
<summary type="text/plain">New York Attorney General Eliot Spitzer has been on a crusade against spammers and spyware companies, but it&apos;s a wonder anyone actually knows about it. I called yesterday asking to get on the press list and Spitzer&apos;s office told me...</summary>
<author>
<name>Ryan Singel</name>
<url>secondaryscreening.net</url>
<email>ryan@secondaryscreening.net</email>
</author>
<dc:subject>Miscellany</dc:subject>
<content type="text/html" mode="escaped" xml:lang="en" xml:base="http://secondaryscreening.net/">
<![CDATA[<p>New York Attorney General Eliot Spitzer has been on a crusade against <a href="http://www.secondaryscreening.net/static/archives/2006/03/lovely_day.html">spammers</a> and <a href="http://www.theregister.co.uk/2006/04/05/spitzer_blitzes_spyware/">spyware companies</a>, but it's a wonder anyone actually knows about it.  I called yesterday asking to get on the press list and Spitzer's office told me they only send out news releases via fax.</p>

<p>Fax?  I mean that's not even retro enough to be cool.  If they said, Citizen's Band radio or shortwave radio, or even better, telegrams, that would be cool.  But faxes?  That's 1980's uncool, like Alex P. Keaton uncool.  Since I don't feel like wasting toner and paper on routine press releases, I did some quick research on e-faxes and found one place that might not cost more than $30 a year for a phone number somewhere in Chicago that will forward PDFs to my inbox.</p>

<p>But that's just absurd -- I ain't wasting cash on an e-version of an outmoded technology. BUT, Spitzer's office does have a <a href="http://www.oag.state.ny.us/">web page</a> with <a href="http://www.oag.state.ny.us/press/agpress06.html">press releases</a> (although I don't know if the faxes come before or after the news is posted online).</p>

<p>So to help you intrepid reporters and bloggers out there who also think a faxed press release is just stinking stupid, I used <a href="http://feedtier.somee.com/?">FeedTier</a> to create an <a href="http://feedtier.somee.com/?http://www.oag.state.ny.us/press/agpress06.html">RSS feed of the press releases</a>, and then used <a href="http://www.rssfwd.com/">RSSFWD:</a> to create a press list from the RSS feed (subscribe <a href="http://www.rssfwd.com/rssfwd/preview?url=http%3A%2F%2Ffeedtier.somee.com%2F%3Fhttp%3A%2F%2Fwww.oag.state.ny.us%2Fpress%2Fagpress06.html">here</a>). Don't tell Spitzer though, he'd probably find some statute to sue me with.</p>]]>

</content>
</entry>
<entry>
<title>More On Justice and Privacy</title>
<link rel="alternate" type="text/html" href="http://www.secondaryscreening.net/static/archives/2006/04/more_on_justice.html" />
<modified>2006-04-05T18:33:28Z</modified>
<issued>2006-04-05T18:09:42Z</issued>
<id>tag:secondaryscreening.net,2006://2.283</id>
<created>2006-04-05T18:09:42Z</created>
<summary type="text/plain">The Justice Department&apos;s new chief privacy officer, Jane Horvath, has perhaps the most interesting job in D.C. Whether she will get to do it is another question altogether. I&apos;m fairly certain that Horvath has no power to subpoena documents (Homeland...</summary>
<author>
<name>Ryan Singel</name>
<url>secondaryscreening.net</url>
<email>ryan@secondaryscreening.net</email>
</author>
<dc:subject>Privacy</dc:subject>
<content type="text/html" mode="escaped" xml:lang="en" xml:base="http://secondaryscreening.net/">
<![CDATA[<p>The Justice Department's new chief privacy officer, <a href="http://www.washingtonpost.com/wp-dyn/content/article/2006/04/04/AR2006040401727.html">Jane Horvath</a>, has perhaps the most interesting job in D.C.  Whether she will get to do it is another question altogether.</p>

<p>I'm fairly certain that Horvath has no power to subpoena documents (Homeland Security's chief privacy officer doesn't) so any investigation she starts will rely on voluntary cooperation and whatever institutional leverage she has.  If AG Gonzales isn't on her side, then she won't get anywhere in investigations.</p>

<p>Of course, there's a great irony of being a privacy cop without subpoena power when your job is to oversee cops with the power and the inclination to write their own subpoenas (say a National Security Letter demanding an airline turn over its passenger database) and use that data however they wish, including using it to <a href="http://www.washingtonpost.com/wp-dyn/content/article/2005/11/05/AR2005110501366.html">build out a massive data-ming operation</a>.</p>

<p>Horvath might get a feel for the job and not alienate too many people internally by starting with a close look at the DOJ's use of private data aggregators (think privatized intelligence gathering operation) such as Axciom, Choicepoint and LexisNexis.  The GAO just released a <a href="http://www.gao.gov/new.items/d06421.pdf">study</a> (.pdf) which found that these information gatherers don't really follow Fair Information Practices and that federal agencies, including the DOJ, don't always follow them either.</p>

<blockquote>For example, the principles that the collection and use of personal information should be limited and its intended use specified are largely at odds with the nature of the information reseller business, which presupposes that personal information can be made available to multiple customers and for multiple purposes.[...] 

<p>Resellers generally limit the extent to which individuals can gain access to personal information held about themselves, as well as the extent to which inaccurate information contained in their databases can be corrected or deleted.</blockquote></p>

<p>For more see, Robert O'Harrow, Jr.'s <cite>Washington Post</cite> <a href="http://www.washingtonpost.com/wp-dyn/content/article/2006/04/04/AR2006040401727.html">story</a> and the GAO's <a href="http://www.gao.gov/new.items/d06421.pdf">testimony</a> (.pdf). to Congress yesterday.</p>

<p></p>

<p><br />
</p>]]>

</content>
</entry>

</feed>