Award Winning Blog

Showing posts with label privacy. Show all posts
Showing posts with label privacy. Show all posts

Tuesday, April 30, 2024

Thought Exercise on CPNI

             I recognize that many of my posts are technical, complex, and “inside baseball.”  However, the matter of wireless carrier disclosure of location information is really, really, important, and rather easy to understand.  

             For public safety, national security, emergency response, and a host of other issues, location data can save lives.  On the other hand, commercial exploitation of location data can kill people. 

             It does not take too much speculation to come up with scenarios where disclosure for compensation by commercial ventures can trigger catastrophe.  For every bail bond professional tracking of a client who failed to show up in court, there are scenarios where location information makes it far easier for stalking and worse.

             Here’s a thought exercise.  Can you come up with any scenario where a landline or wireless telephone company will reveal to you the name and address of a subscriber?  There are commercial ventures that can disclose home and business addresses associated with a telephone number.  But no telecommunications carrier has ever agreed to disclose either a fixed or mobile location of a subscriber upon a one off, anonymous request. Directory Assistance provided a telephone number if you identified a name and address.  The carriers even monetized unlisted numbers for subscribers who did not disclosure of such relatively benign information.

             What could entitle the wireless carriers to disclose such location data on a commercial, contractual basis?

             Is anyone else livid that their location data was commercialized and monetized for years?  Is anyone disgusted by assertions that the FCC has no legal basis to act?

How Much Did the U.S. Wireless Carriers “Earn” From “Location Information Aggregators”?

             The FCC lawfully fined U.S. facilities-based wireless carriers nearly $200 million for selling highly intrusive location data about subscribers without their “opt-in” consent.  See https://www.fcc.gov/document/fcc-fines-largest-wireless-carriers-sharing-location-data.

             In Section 222 of the Communications Act, Congress comprehensively specified how the carriers bore an affirmative duty of care not to disclose clearly defined Customer Proprietary Information (“CPNI”).  See https://www.law.cornell.edu/uscode/text/47/222. The Act explicitly required the FCC, and no other agency, to protect telecommunications consumers.

             The language in this section is quite unambiguous.  Congress surely answered the “major question” whether and how the FCC has jurisdiction to protect telecommunications service subscribers from the unconsented commercial exploitation of data about their immediate location.

             There is no basis for the carriers, or certain dissenting FCC Commissioners, to state that the Federal Trade Commission has exclusive jurisdiction over any and all consumer privacy issues.  See https://docs.fcc.gov/public/attachments/FCC-24-40A3.docx.  Wireless carriers need subscriber location information to route calls to consumers and to provide access to their networks.  Privacy surely can be invaded by unlawful disclosure, but the reason wireless carriers generate and process this information is a fundamental technological element in how they provide service to subscribers.

             There is no doubt that all the facilities-based carriers “monetized” this information, but we will never know how many millions they received, because the carriers would scream bloody murder that such information is “business confidential” and “proprietary.” I’ll bet the carriers received far more than the $200 million they have to forfeit.

             If you follow the logic for exonerating the wireless carriers, it is okay for the carriers to provide nearly instantaneous location information for compensation, because such disclosure does not constitute anything proprietary within the meaning of Section 222 of the Communications Act. The exonerators dug themselves an even deeper jurisprudential hole when they claim the FTC has exclusive jurisdiction to decide whether and how to sanction CPNI disclosures.

             Once upon a time both Democratic and Republican FCC Commissioners acted in a nonpartisan, unanimous manner to protect consumers. So did Congress when it enacted Section 222 and amended it on several occasions.

             Now we have apologists for truly egregious behavior by carriers who surely knew they were creating a lucrative, but illegal, new profit center.  It does not help that they mended their ways a few years ago.

Monday, September 6, 2021

What Rat You Out Smartphone Surveillance Do You Support?

At law school, I learned about the slippery slope of changing fact patterns that typically trigger a change in analysis and which side of a case I support. Sometimes the process is called a parade of horribles as the circumstances grow ever more problematic.  Such a continuum runs for wireless technologies essential for carriers to provide service, but also able to engage in unprecedented and largely unregulated surveillance, tracking, mining, and money making.

Readers of this blog understand that cellular radio carriers need to monitor continuously the location of every subscriber with their handsets on.  Such tracking provides the basis for knowing how to route an inbound call to a subscriber and when to provide service (what used to be called dialtone) to a subscriber seeking to make an outbound call. The slope becomes both slippery and increasingly horrible as tracking technologies offer new profit centers for carriers, smartphone manufacturers, platform intermediaries, content providers, social networks, data analytical firms, marketers, advertisers and more.  These stakeholders typically do not pay consumers for access to data about wireless subscribers’ locations, conversations, texts, messages, app uses, etc.

At best, the quid pro quo involves an exchange of something “free,” but not without cost to the consumer.  At worse, consumers receive nothing, may not even know about what takes place and may suffer from the intrusion of privacy, revealed preferences, and analysis that tilts a market transaction in favor of the firm having acquired and analyzed surveillance data.

I hope that readers neither accept the notion that broadband users have no reasonable expectation of privacy, nor do they have anything to fear about data mining.  The miners repeatedly emphasize how they take pains to anonymize the data they collect.  Yet, we should know by now how easy it is for data analytical firms and marketers to identify individuals and know more about us than what the data protection promises claim to safeguard.

It is quite easy for data mining to rat out someone, because they know where we are and how we use our smartphones.  The domestic terrorists/patriots (depending on your politics) should have known that an operational smartphone in their possession regularly records their location, the destination of their calls and texts, and what apps were used.  This is evidenceavailable to law enforcement authorities.  In most instances, the carrier and the manufacturer of the smartphone willingly cooperate with authorities, often without expecting a search warrant. The slippery slope starts in the reasonable law enforcement/national security zone, but quickly moves into territory most of us do not support. 

Just who is doing the rating out?

If you, like most, support the use of wireless metadata, call records, etc. for law enforcement, what do you think about congressional or state legislatures using these surveillance technologies for investigations?  This data can identify who aided and abetted the crimes committed by others on January 6, 2021.  Some people, not physically located at the Capitol, may have actively conspired to execute the carnage.  

What rat you out surveillance technologies violate a reasonable expectation of privacy, and the right to be left alone?  Appreciate the irony that while we might agonize about whether and how these concepts support or block congressional investigations, data miners typically have no constraints, because the terms of service grant a free reign.


Sunday, April 25, 2021

Side-by-Side Truth and Mistruth in the Wall Street Journal

             Even as the Wall Street Journal continues to provide important news reporting, its opinion pieces grow ever snarkier and more deceitful.  In the April 23, 2021 edition, readers will see varying degrees in the representation of the truth contained in two opinion pieces, each referring the American Civil Liberties Union.

             In an opinion authored by the Editorial Board,  the Journal notes that the ACLU, true to its longstanding mission, has joined conservative groups in opposing legislation in California requiring organizations qualifying as charities to disclose the identity of their contributors.  (See https://www.wsj.com/articles/donor-disclosure-arrives-at-the-supreme-court-11619217816).

           In this opinion, one could infer that the Journal authors see the ACLU as fair minded, still willing to take controversial and perhaps counterintuitive sides in litigation.

             In another opinion piece in the same online edition, (see https://www.wsj.com/articles/how-to-have-more-police-shootings-11619213893?mod=trending_now_opn_1), Holman W. Jenkins, Jr. appears to suggest that any arrested person risks death by resisting, even after police have subdued the arrestee.  Did Mr. Jenkins imply that any degree form of resisting arrest entitle police to punish the arrestee, seemingly with no constraint? 

             Mr. Jenkins also even parts company with his usually like-minded editorial writers at the Journal, at least insofar as his perception of the ACLU.  Unlike the Editorial Board opinion noting the ACLU remains an advocate, even for conservative-championed privacy and First Amendment freedom, Mr. Jenkins characterizes the current ACLU as “lately morphed into a pro-censorship promoter of progressive causes.”

             Has Mr. Jenkins concluded that he should continue to target and vilify the ACLU even when it shares his views?

Tuesday, April 5, 2011

Panadora Investigation

Marketplace Morning offers a few secs. of my thoughts on Pandora mobile apps investigation: http://lb.vg/BX67C.

Nice to receive a call at 6:45 am not involving a calamity.

Friday, April 2, 2010

Trust the Cloud?

By choice and necessity we increasingly use cloud computing to process and store information about us—from pictures to credit card numbers. The worst case scenarios of such reliance include identity theft and fraud. But there are lesser irritants, two of which affected me with no apparent reason or cause.

In the space of a few weeks my most frequent used car rental company “DNRed” me. They decided—or more likely a computer decided—that I was no longer credit worthy. So in one calculation I migrated from an “elite” frequent renter, to a deadbeat. After repeated calls to the company to identify who could correct the mistake, I was reinstated. But absolutely no one could explain how such a thing could have happened.

Cloud confusion event two occurred on a recent trip. A major German airline determined that my wife and I were blind. Okay I get the cosmic message in this, but a representative who unsuccessfully gave us back our sight noted that some human had to have inserted blindness into the record. The cloud would not relent: one each segment my wife and I were invited by name to “pre-board.” We may still be blind.

Trust but attempt to verify what the cloud knows about you.