8-7-2010 Ohio:
COLUMBUS, Ohio — Neighbors routinely get a picture and a name when a sex offender moves next door. In a turnabout, an Ohio sex offender has received private information about his neighbors, including their Social Security numbers.
The material was shown to The Associated Press by convicted rapist Pearly Wilson, who was mistakenly given the information by a prosecutor. The data also contain the names, addresses and birth dates of nine of Wilson's one-time neighbors on Columbus' east side.
There was no indication Wilson misused anything in the files. Wilson, 80, says he came forward because he recognizes the irony of it falling into the hands of someone like him.
"Someone with a criminal mind could really use that information the wrong way," he said.
The case also offers a view into a massive and controversial database designed to track criminals with the help of a raft of background information, including data on people whose only connection to a criminal is a similar address.
Franklin County Prosecutor Ron O'Brien took responsibility for the error, which he believes to be isolated.
Wilson's former neighbors, meanwhile, are wondering why the government has data about them at all.
"They don't need to be running my personal information," said Don Hickman, 47, who still lives on the street where Wilson once worked as a live-in church groundskeeper. "I'm not a sex offender. I've done nothing wrong here."
Neighbor information is useful to police when serving warrants, making family connections and finding fugitives, said Shannon Crowther, who heads technology services for the Franklin County Sheriff's Office.
The information was released to Wilson last summer, as prosecutors were grappling with more than 7,000 lawsuits that sex offenders had filed against Ohio's first-in-the-nation implementation of the federal Adam Walsh Child Protection and Safety Act. The offenders' challenges contend the federal law's stricter classifications and longer reporting periods can't be applied retroactively.
Wilson spent 23 years behind bars for raping a woman in 1976. He went back for six months in 2005 for failing to report an address change to the state sex offender registry.
A voluminous litigator who acted as his own attorney, Wilson said he has an otherwise clean record. He waited almost a year to reveal what he had for fear it would jeopardize his ability to get off the registry. His obligation to stay on the registry expired in July.
O'Brien said Wilson had zealously sought records held in his county sex offender file. After Wilson threatened to take the issue to federal court, an assistant prosecutor turned over the documents.
"They feared he'd say, 'See, you're still hiding stuff,' so they released everything in the file, lock, stock and barrel, and didn't properly review it," O'Brien said. "They gave him things they shouldn't have."
According to the documents, the data on Wilson's neighbors was part of a background check on him run through Matrix, the Multi-State Anti-Terrorism Information Exchange. Wilson also received a copy of another confidential report created by Central Ohio Crime Stoppers, which contained no neighbor information.
Matrix drew the ire of privacy advocates after the U.S. Department of Justice adopted it shortly after the Sept. 11, 2001, terrorist attacks. Dubbed the largest database on the planet, it merges private and public data sources — including criminal histories, driver's license information, sex offender listings and real estate records — and sells the information to government agencies, private investigators and debt collectors, among others.
"Even if government organizations were collecting this data for legitimate purposes, we don't know what some of these documents are being used for," said James Hardiman, legal director for the Ohio branch of the American Civil Liberties Union, which led protests of Matrix. "There is this humongous database being kept of all kinds of information and the public has no idea it's being collected."
The federal government terminated funding to Matrix in 2005 amid privacy concerns, but two states — Ohio and Florida — continue to use the service, now known as dFACTS, without the interstate sharing.
Seisint Systems Inc., the Boca Raton, Fla.-based company that created Matrix, was purchased by LexisNexis in 2004. LexisNexis did not return a call seeking comment.
Social Security numbers are part of a state criminal database that feeds dFACTS, said Kim Kowalski, a spokeswoman for Ohio Attorney General Richard Cordray.
Kristen Anderson, director of the National Center for Missing and Exploited Children's case analysis division, defended the value of such information but said it is generally sanitized before release.
"From a law enforcement perspective, it's great that in this country there is so much information available about people," she said. "From a personal standpoint, there's just an awful lot out there about all of us, and with a little bit of digging you can get it, use it, post it online."
Some former neighbors said the Matrix report Wilson received was inaccurate or outdated.
Hickman's mother-in-law, Gloria Ward, said it listed an arrest for her daughter that would have had to occur when her daughter was 4.
Denise Sinkfield said she hadn't lived on the street for two years.
"I mean me and my husband, we've never bothered anybody," Sinkfield said. "So that's kind of weird, kind of scary." ..Source.. JULIE CARR SMYTH
August 7, 2010
In turnabout, Ohio ex-con gets data on neighbors
July 3, 2008
YouTube to Disclose Who Watches What, When
7-3-2008 National:
Dismissing privacy concerns, a federal judge overseeing a $1 billion copyright-infringement lawsuit against YouTube has ordered the popular online video-sharing service to disclose who watches which video clips and when.
U.S. District Judge Louis L. Stanton authorized full access to the YouTube logs after Viacom Inc. and other copyright holders argued that they needed the data to show whether their copyright-protected videos are more heavily watched than amateur clips.
The data would not be publicly released but disclosed only to the plaintiffs, and it would include less specific identifiers than a user's real name or e-mail address.
-A IP address is more specific than a e-mail address, who are they kidding.
Lawyers for Google Inc., which owns YouTube, said producing 12 terabytes of data -- equivalent to the text of roughly 12 million books -- would be expensive, time-consuming and a threat to users' privacy.
The database includes information on when each video gets played, which can be used to determine how often a clip is viewed. Attached to each entry is each viewer's unique login ID and the Internet Protocol, or IP, address for that viewer's computer.
Stanton ruled this week that the plaintiffs had a legitimate need for the information and that the privacy concerns are speculative.
Stanton rejected a request from the plaintiffs for Google to disclose the source code -- the technical secret sauce -- powering its market-leading search engine, saying there's no evidence Google manipulated its search algorithms to treat copyright-infringing videos differently.
The court has yet to rule on Google's requests to question comedians Jon Stewart and Stephen Colbert of Viacom's Comedy Central.
Viacom is seeking at least $1 billion in damages from Google, saying YouTube has built a business by using the Internet to "willfully infringe" copyrights on Viacom shows, which include Comedy Central's "The Daily Show with Jon Stewart" and Nickelodeon's "SpongeBob SquarePants" cartoon.
The lawsuit was combined with a similar case filed by a British soccer league and other parties.
Together, the plaintiffs are trying to prove that YouTube has known of copyright infringement and can do more to stop it, a finding that could dissolve the immunity protections that service providers have when they merely host content submitted by their users.
Though Google said giving the plaintiffs access to YouTube viewer data would threaten users' privacy, Stanton referred to Google's own blog entry in which the company argued that the IP address alone cannot identify a specific individual.
-This is misstating what Google describes, which first says, IP addresses are specific, but may be broader if more than one person uses a computer. Further, several individuals may also use the same e-mail address.
In a statement, Google said it was "disappointed the court granted Viacom's overreaching demand for viewing history. We are asking Viacom to respect users' privacy and allow us to anonymize the logs before producing them under the court's order."
Google did not say whether it would appeal the ruling or seek to narrow it.
Stanton's ruling made only passing reference to a 1988 federal law barring the disclosure of specific video materials that subscribers request or obtain.
Kurt Opsahl, a senior staff attorney with the Electronic Frontier Foundation, said Stanton should have considered that law along with constitutional free-speech rights, including a right to read or view materials anonymously.
He said a user's ID can sometimes include identifying information such as a first initial and last name.
Viacom said it isn't seeking any user's identity. The company said any data provided "will be used exclusively for the purpose of proving our case against YouTube and Google (and) will be handled subject to a court protective order and in a highly confidential manner."
This is not the first time Google has fought the disclosure of user information it had been stockpiling. While gathering evidence for a case involving online pornography, the U.S. Justice Department subpoenaed Google and other search engines for lists of search requests made by their users.
After Google resisted, a federal judge ruled that Google was obliged to turn over only a sample of Web addresses in its search index, not the actual search terms requested. ..News Source.. by Anick Jesdanun
Judge Orders YouTube to Give All User Histories to Viacom
7-3-2008 National:
Google will have to turn over every record of every video watched by YouTube users, including users' names and IP addresses, to Viacom, which is suing Google for allowing clips of its copyright videos to appear on YouTube, a judge ruled Wednesday.
Viacom wants the data to prove that infringing material is more popular than user-created videos, which could be used to increase Google's liability if it is found guilty of contributory infringement.
Viacom filed suit against Google in March 2007, seeking more than $1 billion in damages for allowing users to upload clips of Viacom's copyright material. Google argues that the law provides a safe harbor for online services so long as they comply with copyright takedown requests.
Although Google argued that turning over the data would invade its users' privacy, the judge's ruling (.pdf) described that argument as "speculative" and ordered Google to turn over the logs on a set of four tera-byte hard drives.
The judge also turned Google's own defense of its data retention policies -- that IP addresses of computers aren't personally revealing in and of themselves, against it to justify the log dump.
The Electronic Frontier Foundation has already reacted, calling the order a violation of the Video Privacy Protection act that "threatens to expose deeply private information."
The order also requires Google to turn over copies of all videos that it has taken down for any reason.
Viacom also requested YouTube's source code, the code for identifying repeat copyright infringement uploads, copies of all videos marked private, and Google's advertising database schema.
Those requests were denied in whole, except that Google will have to turn over data about how often each private video has been watched and by how many persons. ..News Source.. by Wired News
June 20, 2008
Alternatives Exist for Enhancing Protection of Personally Identifiable Information
6-20-2008 National:
Increasingly sophisticated ways of obtaining and using personally identifiable information have raised concerns about the adequacy of the legal framework for privacy protection. Although the Privacy Act, the E-Government Act, and related guidance from the Office of Management and Budget set minimum privacy requirements for agencies, they may not consistently protect personally identifiable information in all circumstances of its collection and use throughout the federal government and may not fully adhere to key privacy principles. Based on discussions with privacy experts, agency officials, and analysis of laws and related guidance, GAO identified issues in three major areas: CLICK for the rest of this GAO Report.
February 22, 2008
INFORMATION SECURITY
Protecting Personally Identifiable Information
What GAO Found:
Two primary laws (the Privacy Act of 1974 and the E-Government Act of 2002) give federal agencies responsibilities for protecting personal information, including ensuring its security. Additionally, the Federal Information Security Management Act of 2002 (FISMA) requires agencies to develop, document, and implement agencywide programs to provide security for their information and information systems (which include personally identifiable information and the systems on which it resides). The act also requires the National Institute of Standards and Technology (NIST) to develop technical guidance in specific areas, including minimum information security requirements for information and information systems. In the wake of recent incidents of security breaches involving personal data, OMB issued guidance in 2006 and 2007 reiterating agency responsibilities under these laws and technical guidance, drawing particular attention to the requirements associated with personally identifiable information. In this guidance, OMB directed, among other things, that agencies encrypt data on mobile computers or devices and follow NIST security guidelines regarding personally identifiable information that is accessed outside an agency’s physical perimeter. ..more.. by GAO Office
June 20, 2007
A User's Guide to the Stored Communications Act, and a Legislator's Guide to Amending It
Abstract:
Americans care deeply about their Internet privacy. But if they want to know how federal law protects the privacy of their stored Internet communications, they'll quickly learn that it's surprisingly difficult to figure out. The federal statute that protects the privacy of stored Internet communications is the Stored Communications Act (SCA), passed as part of the Electronic Communications Privacy Act of 1986 and codified at 18 U.S.C. section 2701-11. But courts, legislators, and even legal scholars have had a very hard time understanding the method behind the madness of the SCA. The statute is dense and confusing, and that confusion has made it difficult for legislators to legislate in the field, reporters to report about it, and scholars to write scholarship in this very important area.
This Article presents a user's guide to the SCA. It explains in relatively simple terms the structure and text of the Act so that legislators, courts, academics, and students can understand how it works - and in some cases, how it doesn't work. I hope to explain the basic nuts and bolts of the statute and show that the statute works reasonably effectively, although certainly not perfectly. My second goal is to show how Congress needs to amend the SCA. I recommend three ways that Congress should rethink the SCA to better protect the privacy of stored Internet communications, clarify its protections, and update the statute for the present. Specifically, I argue that Congress should raise the threshold the government must satisfy to compel the contents of certain Internet communications; that it should simplify the statute dramatically by eliminating the confusing categories of electronic communication service and remote computing service, and eliminating redundant text; and that it should restructure the remedies scheme for violations of the statute. ..more.. by ORIN S. KERR, George Washington University - Law School
