We are developing the social individualist meta-context for the future. From the very serious to the extremely frivolous... lets see what is on the mind of the Samizdata people.

Samizdata, derived from Samizdat /n. - a system of clandestine publication of banned literature in the USSR [Russ.,= self-publishing house]

Anti-RFID tags protect privacy

ZDNet.com reports that computer-security software maker RSA Security has developed a new technology for protecting information emitted by radio frequency identification tags.

The RFID cloaking system is intended to guard proprietary data located on chips used to carry product information. The RSA Blocker Tag technology uses a jamming system designed to confuse RFID readers and prevent those devices from tracking data on individuals or goods outside certain boundaries.

The blocker tags work by emitting radio frequencies designed to trick RFID readers into believing that they are being presented with unwanted data, or spam, causing the information collection devices to shun the incoming transmission. RSA claims that by placing an RFID-loaded product into a parcel bearing one of the blocker tags, the system would cause RFID readers to miss any information carried by the product in the bag, thereby protecting consumers.

The company also promised that its cloaking system would not interfere with the normal operation of RFID systems or allow hackers to use security technology to bypass theft control systems or launch denial-of-service attacks.

An expensive piece of research

This is a great piece. Since I have no idea whether it will remain internet-readable, and since I think it should for all eternity, here is all of it:

RFID Tags in New US Notes Explode When You Try to Microwave Them

Adapted from a letter sent to Henry Makow Ph.D.

Want to share an event with you, that we experienced this evening.. Dave had over $1000 dollars in his back pocket (in his wallet). New twenties were the lion share of the bills in his wallet. We walked into a truck stop/travel plaza and they have those new electronic monitors that are supposed to say if you are stealing something. But through every monitor, Dave set it off. He did not have anything to purchase in his hands or pockets. After numerous times of setting off these monitors, a person approached Dave with a ‘wand’ to swipe why he was setting off the monitors.

Believe it or not, it was his ‘wallet’. That is according to the minimum wage employees working at the truck stop! We then walked across the street to a store and purchased aluminum foil. We then wrapped our cash in foil and went thru the same monitors. No monitor went off.

We could have left it at that, but we have also paid attention to the European Union and the ‘rfid’ tracking devices placed in their money, and the blatant bragging of Walmart and many corporations of using ‘rfid’ electronics on every marketable item by the year 2005.

Dave and I have brainstormed the fact that most items can be ‘microwaved’ to fry the ‘rfid’ chip, thus elimination of tracking by our government.

So we chose to ‘microwave’ our cash, over $1000 in twenties in a stack, not spread out on a carasoul. Do you know what exploded on American money?? The right eye of Andrew Jackson on the new twenty, every bill was uniform in it’s burning… Isnt that interesting?

Now we have to take all of our bills to the bank and have them replaced, cause they are now ‘burnt’.

We will now be wrapping all of our larger bills in foil on a regular basis.

What we resent is the fact that the government or a corporation can track our ‘cash’. Credit purchases and check purchases have been tracked for years, but cash was not traceble until now …

Dave and Denise

Well said Dave and Denise, and well done. And dont you listen to all tho’s other people, your great at grammar and spelln and punctuationising. And thank you Dave Barry for the link to the story. Well, I think it must have been him, but I can find no mention of this story there. So how did I find out about this? (Update Wed 4: I remember now. All is explained here. So the link was via Dave Barry, but only via something else.)

Anyway, apologies if this has already been covered here. I’ve just realised that I haven’t checked. Also, I have no idea at all when this originally got written. It could have been years ago for all I know. I did a posting on Ubersportingpundit about a rugby player who was tackling people by sticking his hand up his opponents’ bottoms (true), and it turned out the story was about three years old. Imagine how embarrassed I was about that.

Needlestack

90% crud has an excellent post about government, security and privacy. He includes a quote by Bruce Schnier about central databases and data mining programmes from his article How we are fighting the war on terrorism/IDs and the illusion of security.

But any such system will create a third, and very dangerous, category: evildoers who don’t fit the profile. Oklahoma City bomber Timothy McVeigh, Washington-area sniper John Allen Muhammed and many of the Sept. 11 terrorists had no previous links to terrorism. The Unabomber taught mathematics at UC Berkeley. The Palestinians have demonstrated that they can recruit suicide bombers with no previous record of anti-Israeli activities. Even the Sept. 11 hijackers went out of their way to establish a normal-looking profile; frequent-flier numbers, a history of first-class travel and so on. Evildoers can also engage in identity theft, and steal the identity — and profile — of an honest person. Profiling can result in less security by giving certain people an easy way to skirt security.

There’s another, even more dangerous, failure mode for these systems: honest people who fit the evildoer profile. Because evildoers are so rare, almost everyone who fits the profile will turn out to be a false alarm. This not only wastes investigative resources that might be better spent elsewhere, but it causes grave harm to those innocents who fit the profile. Whether it’s something as simple as “driving while black” or “flying while Arab,” or something more complicated such as taking scuba lessons or protesting the Bush administration, profiling harms society because it causes us all to live in fear…not from the evildoers, but from the police.

The rest of the post is equally sound:

The problem with these data mining programs is that they don’t work. There simply isn’t enough data to build a good terrorist model. Let’s take two recent American terrorists: John Allen Muhammad and Timothy McVeigh. What did their records have in common before they acted? The only common data point between the two is that they both served in the military. If we had a system that could spot these two men, it would also falsely identify every single male who served in the US Military.

That of course assumes that the data is properly mined and analyzed. But let’s go back to the initial story, where we find out that the TSA sucks at analyzing data. Where does that leave us?

Some might say finding an evil-doer among regular people is akin to finding a needle in a haystack. I say that since there’s no way to tell the bad from the good it’s closer to finding a specific needle in a needlestack. Is that really worth giving up our privacy for an illusion of security?

Fighting for Right Not to Show ID

Wired writes about the case of a Nevada rancher who covets his privacy. Dudley Hiibel refused to hand over his identification to a police officer in 2000, an act which landed him in jail and his name on the U.S. Supreme Court’s docket.

At issue in the case, which will be heard March 22, is whether individuals stopped during an investigation of a possible crime must identify themselves to the police. Nevada state law says that individuals must do so if a police officer has reasonable suspicion that a crime has been or will be committed.

Hiibel’s attorneys argue that in such situations, known as Terry stops, individuals already have the right to not answer questions and that requiring individuals to show identification violates the Fourth and Fifth Amendments’ protections against unreasonable searches and self-incrimination.

The case runs as follows: Police responded to a report of an altercation between Hiibel and his daughter in Hiibel’s pickup parked on the side of the road. Hiibel was outside the pickup when deputies arrived and asked for his identification before asking about the alleged fight. A tape of the incident shows Hiibel refused 11 requests to produce identification, after which the deputy arrested him for impeding a police officer.

Police then arrested Hiibel’s daughter, Mimi, when she protested the arrest of her father. Both her charge of resisting arrest and the domestic violence charges against Hiibel were later dismissed. He was, however, found guilty of obstructing a police officer and fined $250, but the public defenders on the case appealed the conviction to a district court and the Nevada Supreme Court. Hiibel said:

I feel quite strongly I have a right to remain silent and I didn’t commit a crime. (The deputy) demanded my papers. I exerted my rights as a free American and I was cuffed and taken to jail.

Harriet Cummings, one of three Nevada public defenders working on the case, said that while the case might seem like “no big deal,” the legal issues at stake are huge.

This goes to the very nature of what our society is going to be like. We believe that exercising your right to remain silent should not be something that can cause you to be imprisoned.

If an officer acting under suspicion that a crime has been committed comes up to a person, starts asking questions and demands identification, and if the person, as Mr. Hiibel did, declines that demand, they can be hauled off to jail. And we think that is not something that should happen in a free society.

Solicitor General’s Office and the National Association of Police Organizations also filed briefs supporting the identification requirement, arguing that it was a necessary and not overly intrusive tool in fighting crime and terrorism. Here we have it, crime and terrorism wheeled out yet again…

Though the hearing is still weeks away, the case is already being widely debated in the blogosphere, thanks to the publicity efforts of privacy advocate Bill Scannell.

And on the topic of databases and governments – the Electronic Privacy Information Center’s brief ties the identification requirement to large-scale law enforcement databases, such as the FBI’s criminal database. The problem, according to EPIC staff attorney Marcia Hofmann, is not just that a police officer can use a driver’s license to pull up reams of data on a person from massive databases. It’s also that the encounter itself will be added to the system, Hofmann said.

Every little time something like this happens, the police question you and want to know who you are, it’s an incident that gets put into a database. And there will be a record of it thereafter, regardless of whether you did anything wrong.

Quite.

Roadblocks could slow RFID

CNetnews.com has an article about radio frequency identification that has become a hot concept, promising to streamline how businesses track and stock inventory, warning that companies may need to rethink their software infrastructures in order to make RFID work as advertised, say analysts and technology makers.

Early resistance to RFID adoption has come from civil liberties groups, which fear that the technology could lead to unprecedented surveillance of consumers. But industry watchers and technology vendors have identified a more mundane potential problem for RFID adopters. They warn that in the rush to launch RFID projects, businesses may be overlooking a crucial element necessary to allow the technology to work smoothly: Making sure back-end databases and business applications can handle the massive amounts of information generated by RFID-enabled systems. Kara Romanow, an analyst at AMR Research in Boston said:

Companies are going to have problems when they drop RFID on top of shaky infrastructures. In order to do RFID right, to see a true return, the first thing (a company) needs to do is finish a data synchronization initiative, and do it right.

Romanow believes that there are two popular scenarios among businesses working to develop RFID capabilities today: those doing just enough to keep demanding companies like Wal-Mart as a customer, and those with real long-term vision. According to the analyst, the first group will garner few returns other than short-term bragging rights to getting RFID up and running, while the second group will see true return on investment down the road.

RFID may give “Tag, you’re it!” a whole new meaning

Infoworld’s Ephraim Schwartz paints a picture:

Picture this: You’re sitting in the food court at your favorite mall with the family, munching on greasy kung pao chicken from Panda Express, followed by a warm, sweet Cinnabon, when a cordon of mall police surround your table, guns drawn, screaming at you to “Drop the bun and put your hands up!”

Reluctant as you are to give it up, you comply.

What went wrong? Your wife is wondering if you’ve been leading a secret life, but it’s nothing so exotic. Rather, the clerk at the Gap forgot to deactivate the RFID (radio frequency identification) tag in the sweater you just bought. When you passed an RFID reader, connected to the Wi-Fi enabled network, it sent a message to the security desk, and as you passed each RFID reader along the way, they tracked you down in the food court.

There is no doubt that RFID tags will be sewn into the lining of every item of clothing manufactured. Current RFID prices are about 16 cents each on orders of 10 million tags, with the price expected to reach a nickel a tag in a year or two.

By using RFID in clothing, not only will companies be able to discourage shoplifting, they’ll also be able to spot other frauds, such as counterfeit brand names or buyers who purchase an item at a discount outlet and then try to return it for the retail price at a regular store. Warranties can now also be easily tracked to date of purchase.

With those benefits to the supply chain, the question is, will the store really want to turn off the tag after the item is purchased, and how can you, as a consumer, tell? “What if you have some strange hobbies you’d like kept private?” Etterman asks.

It is certainly a small step from deploying RFID tags, which have a reach of only about three feet, to putting the readers in public places that already have hot spots. The combination is potent. Suddenly, the information in the tag can be transmitted over the Wi-Fi network and associated with all kinds of other data by all kinds of organizations, such as insurance companies. Or, you may be on the Most Wanted list at your local public library. Why shouldn’t they have a piece of you, too?

While these scenarios are not possible today, there is no technological barrier preventing them from becoming reality. Who can really say what’s next?

House of Fraser to Attach RFID Tags to Clothes

Logistics company Excel has announced an RFID trial with the UK retailer House of Fraser. RFID tags will be “attached directly to garments providing the scope to track shipment movements at item level”.

No comment is made as to whether the tags will be disabled and/or removed at point of sale.

Press release available here.

Cross-posted from the shiny new RFID Scanner

EU collects PNR as well!

In Euractiv, it is reported that the next Justice and Home Affairs Council on the 19th-20th February will pass a draft directive authorising the collection of Passenger Name Record (PNR) data from non-EU nationals by airlines flying to a Member State. The data will be transferred to agencies in charge of the EU’s external borders in order to aid the management of immigration.

Data will notably include the names, travel document used, nationality, date of birth plus point and time of departure and arrival. Airlines will face thousand euro fines if they have not transmitted data or if the data is incomplete or false.

The original Spanish proposal was watered down after the House of Lords, amongst other bodies, pointed out that this placed a huge burden upon air and sea carriers. The draft directive will fail if it has not passed by April 30th under the auspices of the Treaty of Amsterdam and the Irish Presidency has crafted a compromise whereby biometric data is excluded and the burden is limited to air carriers.

Statewatch had already raised the flag on this proposal to transform air and sea carriers into data collection and surveillance agencies for external border control agencies.

Airline passenger screening system faces delays

The General Accounting Office warned today that the Transportation Security Administration’s high-tech system to screen airline passengers for terrorist connections faces significant testing and deployment delays, which could affect the program’s ultimate success.
According to a report by the GAO, the TSA has not only fallen behind in testing the new Computer-Assisted Passenger PreScreening System (CAPPS II), but also has yet to fully identify all of the functions it would like the system to perform. In addition, the TSA has not yet completed work on at least seven key technical challenges that could stand in the way of the system’s final deployment.

These issues, if not resolved, pose major risks to the successful deployment and implementation of CAPPS II.

There are other significant issues facing U.S. airport security, according to a former top Israeli airport security official and the director of security at Virgin Atlantic Airlines. According to these officials, who spoke Tuesday during an online Terror and Technology conference sponsored by IDPartners LLC, the U.S. runs a major risk by focusing too much on information technology and other high-tech solutions to uncover terrorist plots against airports and airlines.

Rafi Ron, president of New Age Security Solutions and the former head of security at Ben Gurion Airport in Tel Aviv explains that the terrorist threat against airlines is a relatively new experience in the U.S.

There is a tendency to solve problems through the use of technological means. Focusing on technology sometimes makes you lose your overall perspective. That can lead to unbalanced planning, unbalanced investment and misuse of funds.

Rather than rely on IT systems for the bulk of security monitoring, Ron said airport authorities should use personnel training programs in behavior pattern recognition, which has been highly successful in Israel.

Behavior analysis can fill the gap of a purely technological approach. Technology is not yet good enough to provide us with a 100% solution.

Foes Assault Passenger Screening

Wired reports that privacy groups, business travelers and members of Congress asked the federal government this week to reconsider its plans to implement a passenger-profiling system because agencies have not adequately addressed privacy concerns or shown effectiveness in detecting potential terrorists.

House Minority Leader Nancy Pelosi (D-California), joined by 25 other Democrats, sent President Bush a letter Wednesday asking his administration to protect passenger privacy. The group also proposed that airlines should tell passengers exactly what information they pass along as travelers make reservations.

Before the Computer-Assisted Passenger Pre-Screening Program (CAPPS II) is implemented, we urge the adoption of a specific policy that makes clear the role of airlines in sharing consumer information with the federal government.

Members of Congress and the public have no real assurances that the system will not rely upon medical, religious, political or racial data.

CAPPS II will require passengers to give more personal information when buying airline tickets, information that will then be checked against mammoth commercial databases, watch lists and warrants to screen for suspected terrorists and people wanted for violent crimes.

An ideologically diverse group of public-interest groups – including Common Cause, the Electronic Frontier Foundation and the Free Congress Foundation -joined the letter-writing campaign, asking Congress for hearings.

Miaow

I rather think this may be the first posting about animal rights and their potential violation here on White Rose. (For some dumb reason I can’t make that link work, so go via the link below, where for some equally dumb reason the exact same link does seem to work.)

Anyway, this just in, via Dave Barry:

AKRON, Ohio – More stray cats could find their way home under a proposed plan to implant microchips that would electronically identify the cats’ owners.

Democrat Renee Greene introduced legislation Monday to implant microchips beneath the fur of 1,000 cats, giving the animals a permanent identification tag. A runaway cat’s owner would be identified by scanning the chip, which would be about the size of a grain of rice, then checking the scan against a voluntary registry maintained by the city.

Buying and installing the microchips would cost the city nearly $10,000. The City Council still must approve the legislation.

The legislation is an amendment to a cat law passed about 18 months ago that added cats to the city’s laws governing dogs and gave the city’s animal wardens the right to capture free-roaming cats, which can be killed if they aren’t claimed. The Summit County Animal Shelter, where stray cats are taken, already has the scanners that would be used on the microchips.

First they came for the cats …

Do you also get the feeling that humans will be next?

ID cards will only ruin the lives of the law abiding

Paul of Manchester United Ruined My Life has this to say about ID cards, and the claim that they might prevent horrors like the recent mass drowning of those unfortunate Chinese:

The recent tragic death of 19 Chinese cockle pickers demonstrates why ‘Mad Dog’ Blunket’s ID card scheme will fail to address his issues.

If you are willing to live in terrible conditions as reported here by icWales (40 to a house, no bedding, etc) and work for £1/day, do you seriously think that you could care less about a voluntary ID card?

It simply shows that if you are willing to break numerous laws, that the police can’t enforce anyway, then further legislation introducing ID cards, is a futile measure when it comes to stopping criminal activity. In fact the only people ID cards will significantly affect are the law abiding citizens of the UK who will not doubt adopt and follow the rules to the detriment of their own personal freedom.

UPDATE: Blunkett is saying more of the same (Thur 12th) again, so so is Paul of MURML again.