Tuesday, April 9, 2013

Privacy or the Common Good? Creating Rules in the Face of Uncertain Risks and Rewards



Since we read Privacy in Atlantis, I’ve been thinking about the initial allocation of rights to information. In that article, the authors conclude pretty quickly that the rights to information about an individual ought to be initially allocated to that individual. But I think this conclusion deserves a more robust discussion.

At its core, this debate is really about risks and rewards offered by the use of  information related to individuals. There’s a pretty good argument that the rewards of access to information are so substantial that the default position ought to be to allocate information rights to the public unless there is a reason not to. Jane Yakowitz has written persuasively that data, at least de-identified data, is a common good and public access ought to be maintained in most situations. For example, Yakowitz notes that empirical research using public data was responsible for de-bunking racist theories that Caucasians are cognitively superior.

Economic theory tells us that the most efficient rule is the one that has the fewest exceptions because carving exceptions out the default rule is costly. So if we think that it is better to use data related to individuals as a public good most of the time then we should default to allocating information rights to the public. On the other hand, if we think that most of the time data related to individuals presents the risk of harm, we ought to allocate rights to individual information to the individuals themselves. So it seems that, rather intuitively, we should make the initial allocation of rights based on whether harms outweigh public goods.

My feeling is that we need not make this decision for all kinds of information at once. We don’t need to have a single unifying theory of privacy for all pots of information. Even though it might be economically efficient to have a single rule with minimal exceptions, it might not balance risks and rewards very well. A unified approach approach privileges theoretical consistency over reality, which seems a bit silly to me. So if I was running the world, I’d identify pots of information where the balance clearly goes in one direction. For example, health information and financial information are particularly sensitive and so the risks are high. For this reason, we ought to initially allocate rights to that information to the individual and robustly protect those rights. By contrast, information about individuals’ shopping or television viewing patterns has high economic value and presents relatively minimal risks so this information should be able to be freely used.

So the problem comes up at the margins—where the weighing of harms and benefits isn’t obviously tilted in one direction.

One problem with this analysis is that both the value of information in the public domain and the privacy risks that that unauthorized uses of information are unpredictable. Given this fact, maybe it’s not really a matter of deciding whether the risks or values are larger, but a question of how we want to handle uncertainty. In environmental regulation, there’s been a movement toward the application of the precautionary principle which dictates that when harms are uncertain, the best course of action is to assume the harms will materialize and protect against them. Some have suggested that the precautionary principle is a good model for privacy regulation. I’m inclined against the precautionary principle—at least when reflexively applied. It seems to me that a more careful and context specific analysis or probable risks and rewards, even while costly to conduct because of the inherent uncertainty involved, will produce a better balance of individual rights and common goods.

Monday, April 8, 2013

Do Digital Currency Investigations Differ Any from Paper Currency Investigations?



The New York Times reported yesterday on Bitcoin, which is a peer-to-peer currency that does not rely on a centralized bank or government treasury. This year the collective value of all Bitcoins passed one billion dollars. The Times notes that Bitcoin “comes in pretty handy for people who do not want their transactions monitored.” A significant criticism of Bitcoin is how it facilitates illegal activity. For example, it thwarts enforcement of money laundering laws. Much Bitcoin activity occurs at  the Silk Road, an online marketplace for illicit goods like narcotics and firearms.

What makes Bitcoin interesting from a privacy perspective is that all Bitcoin transactions are registered in a publically-available log. This ledger shows payments as made to Bitcoin “addresses”: strings of about 33 numbers and letters. Unless someone knows your Bitcoin address, people that inspect the public ledger have no idea who is conducting these transactions. In other words, the public keys do not constitute personally identifiable information.

But, Bitcoin isn’t so different from good old paper greenbacks. To track down a particular person using Bitcoin to commit crimes, law enforcement could contact the other participant in the transaction, and get that person to disclose what they know. After all, most of the goods bought with Bitcoin are physical property, and have to be shipped to a real world address at some point. Savvy criminal Bitcoin users can use anonymization programs or use decoy addresses (analogous to what savvy criminal cash users can do) to obfuscate their trail, but of course that takes time, effort, and expertise. And then there’s the cashout. Because (at this point) not all financial transactions can be conducted with digital currency, people will need to trade Bitcoin for government-backed money, which brings them back into a world of close government regulation.

The Fifth Amendment’s protection against self-incrimination might be one area of law that becomes more relevant with Bitcoin. In re Boucher, 2009 WL 424718 (D. Vt. Feb. 19, 2009), rejected a defendant’s Fifth Amendment claim against a grand jury subpoena which ordered him to turn over a password encrypting files that the government suspected harbored child pornography. Because at the time of his arrest the defendant had accessed his hard drive in front of the arresting officers, and the officers were able to see the file names (which strongly hinted that the files would contain child porn), the court ruled that providing access to the files "adds little or nothing to the sum total of the Government's information about the existence and location of files that may contain incriminating information,” thus defeating any Fifth Amendment claim. The same result was reached in United States v. Kirschner, 823 F. Supp. 2d 665 (E.D. Mich. 2010); see also United States v. Doe, 670 F.3d 1335 (11th Cir. 2012) (finding no Fifth Amendment violation here because unlike in Boucher the government did not know what was in the encrypted files it wanted passwords for). So if the government does not have a certain amount of evidence that illegal activity is going on, they can't likely subpoena someone to decrypt their Bitcoin account. Banks would probably be a lot more willing to disclose financial transactions than would other Bitcoin users (putting aside any statutory restrictions on banks). The government could probably try to ban Bitcoin outright, but I'll leave for another day how wise or effective that would be.

At this point, it is still relatively costly and time-intensive for the government to identify illegal activity with Bitcoin and then track down participants in this activity. Still, people enthusiastic about financial privacy should hesitate before uncritically plunging into the world of Bitcoin.

Sunday, April 7, 2013

Facebook Home - Giving Zuckerberg Even More Info

Facebook recently unveiled a new product - an app for the android operating system called "Facebook Home." Facebook's announcement is already raising privacy concerns, at least partially because Facebook is notoriously bad at appeasing the desires of the privacy-concerned. Facebook attempted to alleviate those concerns with a preemptive strike, and to an extent the current limits on the data collected by "Home" are a good sign.

Most Facebook users are aware that their information is being collected, and most facebook users don't care. Some may not realize the extent to which their information is collected and subsequently sold. It doesn't matter which camp an individual "Home" user falls into; the bottom line is that more information is going to be put into Facebook's hands. Perhaps for the users who choose "Home" this isn't a concern, but it does raise concerns about third party protection issues - i.e., how much more information about those who choose not to use "Home" is going to be collected? American users cannot prevent the Facebook app from collecting information regarding how often they are calling or messaging a "Home" user, and potentially what those messages contain. The entirety of Facebook's "Home" data collection intentions are not clear, but once they've establish a large installed base, the capability to collect insane amounts of data and sell it would be only a small "Data Use Policy" change away.

After all, Facebook has a history of letting its users down on the privacy front, specifically by making mandatory, short/minimal notice changes.

Try combining this with Google Glass, running Andriod, for bonus privacy erosion.

Are you too fat to work at CVS?

Rummaging around the internet, I found out that CVS is making waves by (kind of) requiring employees under their health plan to disclose their weight, body fat, glucose levels, and other health information.  Those who refuse to do so will be required to pay an extra $50 per month for the plan.  So basically you could call it "fat tax" (I always imagined that was coming down the pipe at some point).

CVS justifies this action on several levels.  First, it claims to not be viewing the information itself.  Second, it claims that this policy is no different than what many other companies do (which is actually true.  For example, Whole Foods offers an increased employee discount for being skinny, while other companies invade similar areas regarding health).  Finally, the company claims its goals are to help identify health problems to benefit both the company and the workers.

Privacy groups, obviously, are not thrilled.  Patient Privacy Rights founder Dr. Deborah Peel went so far as to call it "incredibly coercive and invasive" (see above links).  And naturally, there is concern as to whether or not such a rule infringes more on the privacy rights of the poor, as those who are less able to afford the $50 "tax" will be less likely to refuse the screening process.

I'm of two minds on this issue.  The free-market libertarian in me thinks that employers should be able to ask for information like this, as it IS certainly relevant when it comes to company costs (a heartless way to look at employee health, I know).  If you don't want to give it up, the option is available to either quit your job or pay the tax.  As Alonzo Harris told Hoyt in Training Day, it ain't like someone put a gun to your head.

And then, of course, there's the "it's none of your business" side of me, which tends to fly off the handle any time someone is forced against their will to disclose information that is sensitive in nature.  And in a very real way, this is certainly forcing the hand of some people.  As a law student who is a few dollars away from eating dirt, I can testify to the power of $50 a month.  In some cases, this isn't a real choice at all, but a requirement.

At the end of the day we're stuck with a balancing act between employers' rights and something that makes us feel very, very uncomfortable.  It (as in, employers prying into their employees private lives) started years ago with smoking.  Now it's moving onto weight.  Next year is it, "do you have kids?  Yes?  You'll have to pay an extra hundo a month to work here, then."

Saturday, April 6, 2013

Google Agrees to Educate Consumers About Privacy in Street View Settlement


Last month, Google agreed to a settlement with 38 state attorneys general in a case they brought over privacy violations committed by Google during the course of its Street View data collection. Google’s street mapping cars (apparently inadvertently) collected e-mail addresses, passwords, and other personal information from the unsecured home networks of unsuspecting computer users.

Google is paying a $7 million fine, to be divided among the states involved in the settlement. But more interestingly for our purposes, Google has also agreed to some privacy initiatives that are unlike those we’ve seen before in the context of FTC consent decrees (the FTC apparently ended its investigation of the Street View issue without imposing a fine). The settlement requires Google to conduct more robust privacy training for its employees and to create and promote a public service announcement instructing consumers on the importance of securing home Wi-Fi networks.


Consumer groups are (predictably) unimpressed by the idea of having Google educate its users about privacy. But on the other hand, maybe there's some wisdom in requiring (or encouraging) companies like Google and Facebook that collect large amounts of consumer data online to educate consumers about data privacy. Consumers clearly are willing to trust these companies with their personal information; perhaps they would also take notice if these companies encouraged users to take privacy more seriously. In order for the notice-and-choice model to be even reasonably effective at permitting consumers to balance their competing desires for privacy and services, consumers need to be well informed about the trade-offs and how to go about preserving the amount of privacy they want. To the extent that Google's privacy education campaign helps consumers get some of that information, it could be a positive development and a useful new tool for privacy regulators.

Friday, April 5, 2013

Right to Know CA Legislation



The EFF and ACLU of Northern California have helped California Assemblymember Bonnie Lowenthal introduce a new proposal called the Right to Know Act (AB 1291, PDF new window). The legislation is directed for customers wanting to know how much personal information is being disclosed to third parties from businesses that collect information for marketing purposes. Current CA law requires a response within thirty days of the names and addresses of the recipients of that information. This amendment would require the business to 1) provide to any customer, at no charge, a copy of that information, the names of contact information for all 3rd parties that the business shared the information for the last 12 months, and 2) provide information regarding the privacy policy and avoiding disclosure of personal information. Violation of these provisions would constitute an injury to the consumer. It does not create additional categories of privacy.

The EFF considers this a much needed update to the transparency law for the digital age, since the previous version was tailored for direct marketing. For example, the previous statute does not mention location data, which is increasingly valuable as smartphones proliferate. The EFF suggests that because Europeans have similar sorts of access, companies already have the “systems in place to facilitate user access.” It does not acknowledge that importing these systems to the US could incur costs, through software installation or greater demands on consumer service requiring detailed responses (though I can see the second part of the bill being satisfied by a boilerplate description). It also does not access whether requests for personal knowledge will be affected by the bills passing.

Although California is at the forefront of consumer privacy in the US, the bill has just been introduced so there is no knowledge of its probability of passing or existing in a diluted form. Data brokers have been notorious in refusing to name information sources, even to Congressional caucuses (here's an example letter: PDF new window); Senate investigations have been fruitless and their responses have been general, with even one organization (FICO) denying they even are a data broker. Whether they exercise their lobbying power to combat this bill remains to be seen.

Wednesday, April 3, 2013

The NCAA, Kevin Ware, and a T-Shirt

Everyone remembers Kevin Ware's unbelievably painful-looking broken leg right? If not, Google it. Be warned; it's awful. I'm intentionally not linking to the video since it seems that Ware prefers that it not be played over and over

Apparently, Ware's team rallied around him following his injury and won the game. That kind of excitement is what college sports are all about, right? The NCAA sure thinks so; it has decided to sell t-shirts commemorating the injury and Louisville's subsequent victory. The shirts will have Ware's number on the back and the words "Ri5e to the Occasion" on the front and will sell for $24.99. The Nation reports that Ware and his family will receive no compensation from t-shirt sales, which especially smarts because college athletes aren't entitled to worker's compensation meaning that the NCAA probably won't have to pay Ware's long-term rehab costs.

Maybe Ware should consider an appropriation claim to collect some of the proceeds from those t-shirts? Even though it sounds appealing, this may be a legal dead end. Ware's face and name aren't on the shirt, which might mean that Ware can't show that his "likeness" was appropriated (see White v. Samsung Electronics finding that a robot designed to look like Vanna White and used in an advertisement was not a likeness such that White could support an appropriation claim under California law).

Ware may have to wait for the resolution of a current case, O'Bannon v. NCAA, which seeks compensation from the NCAA for the advertising use of student-athletes' names and images. Stay tuned!