Internet i inne organizacje
Who's Looking Over Your Digital Shoulder? A Reader Privacy Quiz for Californians
Books are books whether we read them in a library or on a Kindle or iPad, but California laws are lagging when it comes to protecting reader privacy in the digital age. That's why EFF is a supporter of the Reader Privacy Act, a bill that has passed the California legislature and is awaiting Governor Brown's signature to become law.
Who's looking over Californians' digital shoulder and why does it matter? You can take our quiz to find out what's at risk -- and how Californians can protect their private reading records. Then tell Governor Brown to sign the Reader Privacy Act to ensure Californians don’t have to compromise their privacy when downloading electronic books, using online book services or even buying books from their local bookstore.
Who's on the Intelligence Oversight Board? Government Won't Say
San Francisco - The Electronic Frontier Foundation (EFF) filed suit today against the Office of the Director of National Intelligence (ODNI) demanding records of who is on the Intelligence Oversight Board (IOB) -- the presidentially appointed, civilian panel in charge of reviewing all misconduct reports for American intelligence agencies.
The IOB is supposed to alert the president and attorney general when it spots behavior that is unlawful or contrary to executive order. However, in his nearly three years in office, President Obama has not yet announced any appointments to the IOB. EFF's suit comes after the ODNI refused to respond to a Freedom of Information Act (FOIA) request for membership, vacancies, and other information about the IOB made earlier this year.
"The IOB has a critically important mission – civilian oversight of America's intelligence activities. The board exists to make sure government agencies are not overstepping their authority and abusing citizens' rights," said EFF Open Government Legal Fellow Mark Rumold. "History has shown that intelligence agencies overseeing their own behavior is like the fox guarding the henhouse. If the IOB is ineffective, impaired, or short-staffed, that's information Americans need to know."
EFF's ongoing FOIA litigation work has already uncovered widespread violations in intelligence investigations. Most recently, EFF revealed that the U.S. Army issued three National Security Letters (NSLs) for phone records, even though the law authorizes only the FBI to make these extraordinary requests for information. EFF also obtained documents detailing how the Army improperly attempted to investigate participants at a law school conference on Islamic law.
"We're trying to create a picture of the federal government's intelligence violations as Congress considers updates and changes to current surveillance law and oversight," said EFF Staff Attorney Jennifer Lynch. "Part of that picture is who is on the IOB. We're asking the government to follow the law and release the records on IOB membership."
For the full complaint in EFF v. ODNI:
https://www.eff.org/files/filenode/FOIA_IOB/ODNIIOBComplaint_92711.pdf
For more on the Defense Department intelligence violations:
https://www.eff.org/foia/intelligence-agencies-misconduct
Contacts:
Mark Rumold
Open Government Legal Fellow
Electronic Frontier Foundation
mark@eff.org
Jennifer Lynch
Staff Attorney
Electronic Frontier Foundation
jlynch@eff.org
Stop the Piecemeal: Obama Administration Should Fully Free Communications Tech Exports to Syria (& Companies Should Help)
EFF has long complained about export restrictions by the U.S. Departments of Treasury and Commerce that deny citizens access to vital communications tools. In the past, this has affected, among others, Zimbabwean activists trying to obtain hosting providers, Syrian businesspeople networking on LinkedIn, and ordinary Iranians trying to download web browsers.
The government has been responding, albeit in piecemeal fashion: in 2010, technology companies were granted a general license from the Department of Treasury’s Office of Foreign Assets Control (OFAC) to export communications tools that could “boost Internet-based communication” and the “free flow of information” Iranian, Sudanese, and Cuban citizens – but since then we’ve seen a wave of democracy activism reach Syria too, something EFF commented upon in July.
Syria Two-Step
Now we've seen some movement on Syria, but not enough. On August 18, amidst increasing regime violence toward opposition forces, the White House issued an Executive Order blocking a new range of transactions, including (Section 2(b)) “the exportation, re-exportation, sale, or supply, directly or indirectly, from the United States, or by a United States person, wherever located, of any services to Syria,” in light of the Syrian government’s escalating violence against civilians. This seemed like very bad news for Syrians who want to use communications tools to help with the protests.
Fortunately, recognizing the importance of communications tools and social networks to Syrian activists, the State Department’s Office of Foreign Assets Control (OFAC) quickly issued a general license allowing the export of “certain services incident to Internet-based communications.” The license specifically notes that transactions that are not otherwise exempt from certain earlier prohibitions, and that are related to the exchange of personal communications over the Internet, are permitted. Examples specifically laid out in the license include instant messaging, chat and email, social networking, photo- and video-sharing, web browsing, and blogging. The license also lays out what is not authorized for exportation, and while the language is a little unclear, it appears to allow export of technologies and services for all purposes other than those for commercial endeavors – so democracy activists should be in the clear.
But the story doesn’t end there. Restrictions from the Department of Commerce’s Bureau of Industry and Security (BIS) still appear to prevent communications tools and services from being exported to Syrians without a license. We think that because of these restrictions, Syrians still cannot access Google products Chrome and Earth, cannot download Java, among various other tools, and cannot use hosting services like Rackspace, SuperGreenHosting and others.
So the Treasury Department’s OFAC is out of the way, but the Commerce Department’s BIS restrictions remain, meaning that companies are still blocking certain communications tools from getting to Syrians. And until the government makes the bigger step of stopping the piecemeal nature of their relaxation of restrictions, we’ll have the same problems we’ve long complained about. These sorts of export restrictions are overbroad and contain elements which have no effect on the Syrian regime, while preventing Syrian citizens from accessing a wealth of tools that are available to their activist counterparts in neighboring countries and around the world. Furthermore, the penalties that result in violations of the regulations can be severe, so amidst confusing regulations, companies appear to be implementing broad restrictions on their services rather than run any risk. This happened recently when the open-source platform SourceForge blocked the IP addresses of users in five sanctioned countries.
What Needs to Happen
Two things ought to be done here, as soon as possible. First, and most importantly, the government -- the whole government -- should remove the license requirements and restrictions for communications technologies used by democracy activists. In the short term this should happen for Syria, in light of the ongoing struggle there. In the longer term, it’s time for the U.S. to stop this piecemeal approach and affirmatively allow unlicensed distribution of communications tools and services to people in all countries of the world.
Second, companies hesitant about allowing Syrians to use communications tools and services should take the simple steps necessary to seek a BIS license. While we don't think that such licenses should be required, the process is in fact quite simple, and frankly, the Syrians cannot wait. A company that wishes to export to Syria can file an online application with the Commerce Department’s Bureau of Industry and Security (BIS) for a license, which then should be resolved within 90 days. While registration is required before applying, any company that has ever gotten an export license before is likely already registered. Alternatively, companies may also request “interpretative guidance” as to whether or not they require a license from BIS, which takes only 30 days.
EFF Wants to Help
Given the situation on the ground in Syria, we need to focus there first. We reiterate our call for the Obama administration to affirmatively make clear throughout its various agencies that providing digital communications and information tools to citizens around the world, especially those under repressive governments, is not only legal, but encouraged. And in the meantime, we challenge those companies who are concerned about the BIS restrictions to take the simple steps necessary to apply for a license. In fact, we think this is so important that EFF would be willing to help a company that wants to take these steps but doesn’t have the resources to do it. Companies should contact EFF's Legal Director, Cindy@eff.org, if you'd like our help.
Don't Let Privacy Law Get Stuck in 1986: Demand a Digital Upgrade to the Electronic Communications Privacy Act
Sign now and we will add your name to this petition and also send a letter to your Representatives and Senators in time for the 25th anniversary of ECPA being signed into law:
Petiton language:
The government should be required to go to a judge and get a warrant before it can read our email, access private photographs and documents we store online, or track our location using our mobile phones. Please support legislation that would update the Electronic Communications Privacy Act of 1986 (ECPA) to require warrants for this sensitive information and to require the government to report publicly on the use of its surveillance powers.
ECPA was forward-looking when it was signed into law in October of 1986, considering that the World Wide Web hadn't even been invented yet. But now, ECPA has become outdated. The privacy standards that it applies to new technologies are unclear and weak. For example, the law doesn't specifically address cell phone location tracking at all, and it allows the government to seize most emails without ever having to go to a judge. Meanwhile, no one is perfectly sure how it applies to newer online services like social networks and search engines.
This gap between the law and the technology ultimately leaves us all at risk. Add your name now to sign the petition supporting ECPA reform, and feel free to add a personalized intro to the text below that will be sent to your legislators before the 25th anniversary of ECPA.


