Feeds

The mobile phone as self-inflicted surveillance

And if you don't have one, what have you got to hide?

  • alert
  • submit to reddit

Top three mobile application threats

Mass surveillance of the rest of us is becoming even more pervasive. The UK started transposing the European directive on retaining data generated through electronic communications or public communications networks (European Directive 2006/24/EC) with the Data Retention (EC Directive) Regulations 2007. These came into force on 1st October 2007 and require service providers to retain fixed and mobile telephony traffic data of everyone's calls and SMS and MMS for one year and hand it over on request.

More than 650 public authorities can lawfully obtain communications data, including intelligence and law enforcement agencies, emergency services and other public authorities, such as the Financial Services Authority, local councils and the Home Office's UK Border Agency.

These regulations were superseded this week (on 6th April 2009), by the 2009 Regulations eventually completing the implementation of the European directive by adding the requirement to retain Internet access, email and Internet telephony traffic data as well.

What has to be retained in all cases is data necessary to trace and identify the source and destination of a communication and to identify the date, time and duration, and the communication's type. For mobile telephony and for Internet access, email and telephony, there's also a requirement to retain data necessary to identify users' communication equipment (or what purports to be their equipment) and the location of mobile communication equipment. The detail of exactly what needs to be retained has been regrouped in an easy to read list in a schedule to the Statutory Instrument (S.I.).

Earlier this year, Sir David Omand, a former Cabinet Office security and intelligence coordinator, gave a clear indication of what some in Whitehall have on their wish-list:

[A]pplication of modern data mining and processing techniques does involve examination of the innocent as well as the suspect to identify patterns of interest for further investigation.[...] Finding out other people's secrets is going to involve breaking everyday moral rules. So public trust in the essential reasonableness of UK police, security and intelligence agency activity will continue to be essential.

One extension to the traffic data retention guidelines that fits within this agenda is the building of a massive central silo for all UK communications data. Another is the e-Borders database (in pilot schemes, 0.0035 per cent of people screened were arrested); the location of your mobile phone had better match the country you declared you would be in.

Professor Steve Peers offers a glimmer of hope:

What is the relevance of [the European Court of Human Rights DNA database ruling] Marper to that? To what extent can it regulate or stop what is clearly an ongoing development?

Marper is very relevant if it rules out the sweeping collection of personal data regardless of the stigmatisation factor and regardless of the UK factor (the distinction between the UK and the rest of the Council of Europe countries). If we ignore these factors and say what is wrong here is purely sweeping collection of personal data, then this is a very significant judgement. Then it's profoundly important. It really stands in the way of what we're already doing across Europe, not just in the UK.

Of course the ruling may be interpreted to have no relevance outside its application to the retention of DNA and fingerprints. Then Sir David Omand's national security strategy may be further implemented and carrying a mobile phone - an electronic tag - could become a necessity, if you don't want people to think you have something to hide.

David Mery is a scribbler and technologist based in London. Two years ago he was one of 64 who asked the Metropolitan Police to have their DNA samples destroyed, and DNA profiles and associated records purged. His request was one of 18 that were deemed exceptional enough to be granted. His website is gizmonaut.net.

Combat fraud and increase customer satisfaction

More from The Register

next story
Lavabit loses contempt of court appeal over protecting Snowden, customers
Judges rule complaints about government power are too little, too late
Don't let no-hire pact suit witnesses call Steve Jobs a bullyboy, plead Apple and Google
'Irrelevant' character evidence should be excluded – lawyers
Record labels sue Pandora over vintage song royalties
Companies want payout on recordings made before 1972
EFF: Feds plan to put 52 MILLION FACES into recognition database
System would identify faces as part of biometrics collection
Edward Snowden on his Putin TV appearance: 'Why all the criticism?'
Denies Q&A cameo was meant to slam US, big-up Russia
Ex-Tony Blair adviser is new top boss at UK spy-hive GCHQ
Robert Hannigan to replace Sir Iain Lobban in the autumn
Judge halts spread of zombie Nortel patents to Texas in Google trial
Epic Rockstar patent war to be waged in California
US Supreme Court supremo rakes Aereo lawman in oral arguments
Antenna-array content streamers: 'Ruling against us could dissipate the cloud'
German space centre endures cyber attack
Chinese code retrieved but NSA hack not ruled out
prev story

Whitepapers

Mobile application security study
Download this report to see the alarming realities regarding the sheer number of applications vulnerable to attack, as well as the most common and easily addressable vulnerability errors.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Securing web applications made simple and scalable
In this whitepaper learn how automated security testing can provide a simple and scalable way to protect your web applications.
Combat fraud and increase customer satisfaction
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.