Stanford quantifies the privacy-stripping power of metadata
techcrunch.com
techcrunch.com
Someone from MIT also contributed to this study in the same vein http://www.nature.com/articles/srep01376 From the abstract, "[I]n a dataset where the location of an individual is specified hourly, and with a spatial resolution equal to that given by the carrier's antennas, four spatio-temporal points are enough to uniquely identify 95% of the individuals."
This quote from the Stanford News article is incorrect. The reason metadata is carved out is because there is Supreme Court precedent carving out metadata: https://en.wikipedia.org/wiki/Smith_v._Maryland. And that case has nothing to do with what can or cannot be inferred from metadata.[1] It distinguishes call data from call metadata because the latter is routinely recorded and used by phone companies for various purposes:
> First, we doubt that people in general entertain any actual expectation of privacy in the numbers they dial. All telephone users realize that they must "convey" phone numbers to the telephone company, since it is through telephone company switching equipment that their calls are completed. All subscribers realize, moreover, that the phone company has facilities for making permanent records of the numbers they dial, for they see a list of their long-distance (toll) calls on their monthly bills.
[1] Because that's totally irrelevant to the 4th amendment.
The quoted line of reasoning is absolutely disingenuous when considered in a modern and realistic setting.
What is being wilfully ignored is the change in quality of the information gleaned from the analysis of data as it is being done in bulk.
Nobody in 1979 could have foreseen the sort of information that can be extracted from the unimaginably large fire-hose of metadata we generate today.
It's a completely different thing if you had a list of who-called-who-when in 1979. How was this data kept? Well, for starters it probably wasn't centralized. Was it even digital? Probably, yes? Even if it was digital, the computers of that day could only handle trivial amounts of data. Factor in the ubiquity of phones and phone-usage today versus back then, to even consider the concept vaguely comparable is ridiculous.
It's the difference between getting records from the electricity company so that you know which parts of your house were illuminated when, versus getting "records" from all the individual CCD elements of various cameras installed in your house so that you know the same thing, which (tiny) parts of your house were illuminated when. That's the same thing right? It's just a tiny bit more fine-grained (/s).
Just because people might be okay with the former (say because you can see what lights are on from behind the curtains, on the street), doesn't mean they'd be fine with the latter.
The quality, and therefore the privacy-expectations, of the information extracted from the data changes as you blow up the number of records by some orders of magnitude. Almost nobody from 1979 could have imagined what that would mean. Almost nobody could even have fathomed the amount of computational power a desktop computer could throw at it. Hell, not even most people today can grasp that.
So there's "innocent" metadata that via some unfathomable process can be transmuted into some rather more detailed and revealing information. It's really quite hard to get a proper perspective on it (our brains aren't made for reasoning about graphs this size). I think it's more fair to call this process "magic", than otherwise. And in that case it really doesn't matter where it came from, say magic works, does it matter if the government knows all the details of your life from divining tea-leafs or divining phone metadata?
Now add to this, that thanks to having sufficiently-advanced our technology, it is also possible, using similar techniques of "magic", for the phone companies to keep records for billing purposes in a really clever (magic/encrypted) way to shield the data from those kinds of divination while still being able to do their billing. The only reasonable expectation I have is for these paradigm shifts to be applied on both sides, equally.
I'm not sure if a jury is a bad idea, when I first learned of it, I kinda liked the idea, but I'm worried about this kind of reasoning...
Is the decision made by one person that has these same fallacies? At least the risk is spread out some in the jury situation.
The UK uses juries in much the same way as the US does, as do many other countries whose legal systems derives from that of the UK (which are a fair number, because colonialism.)
I suppose if one of them were underage...
Their meeting up may have been consensual, but what happened while they were together might not have been. Also, the parent doesn't say both parties wanted to meet up. So, the meeting-up could have not been consensual. It could have been a stalking situation or maybe they just happened to run into each other by chance.
But their car-odometer didn't change, and their home-electricity usage dropped to zero that day.
Both of those observations are surely "evidence". Similarly, a digital signal still carries information, even though the zeroes are an "absence" of voltage.
Odometers increment on driven cars. The odometer did not increment. The car was driven. Unsatisfied.
People having sex are together. People who are together don't text each other. During a certain hour a person didn't text 68 contacts. At this certain hour, this certain person had sex with 68 people. Satisfiable.
Anyway, the whole charge is disgusting. Leave them alone dammit.
Moreover, this is kind of what juries do best: inferring what people did from other things they did or didn't do. While juries are subject to a lot of biases, I think humans have a good statistical model of the behaviors of other humans.
I can't say I agree with the use of circumstantial evidence, but that's how the court works. Additionally, many people do get off based on lack of clear evidence?
[1] https://plus.google.com/+TerenceTao27/posts/8vmpA9fgRMq?iem=...
https://en.wikipedia.org/wiki/Differential_privacy
When setting policy, it is better to have theoretical mathematical results rather than empirical effectiveness, since you can bet the technological frontier of privacy violation is a moving one. As with cryptography, you want solid foundations in unbreakable maths -- not 'we can't break this cipher with what we know today'. Probably, someone can.
"We kill people based on metadata” - General Michael Hayden
Probably would be safer to not publicize your every move publicly too, even if it'd only slow the process down a little
Friends and family are reporting on their friends and family without even understanding the implications of what they are doing.
It may seem benign at the moment, but given the nature of the turn-key totalitarian state, it's when that key gets turned and the cat starts getting walked back that this sort of information leakage from unexpected sources really becomes an issue.
> One of the government’s justifications for allowing law enforcement and national security agencies to access metadata without warrants is the underlying belief that it’s not sensitive information.
Is this true? I didn't think this was an actual part of the argument for using metadata, but that metadata wasn't covered under current laws, and was therefore easier to get.
I was working under the assumption that it was an unintentional oversight, not an intentional hole in legislation.
So they seem clear about the difference between content and meta, and that metadata will identify people.
They're less clear about the further de-anonymisation aspects of "just" metadata, and it's hard to know if that's because they don't know or don't care.
https://kieranhealy.org/blog/archives/2013/06/09/using-metad...
You can find a person's city of residence in 57% of the cases? That's pretty bad, I'd almost feel oddly relieved my data is saying so little, but I'm afraid the NSA would do a better job.
You can predict who is pregnant? And who owns a rifle? Alright now we are getting somewhere. The article didn't mention how many cases succeed here so I'm not sure if I should be impressed, since the rifle hotline or a licensing agency thing (I don't know how that works) would be pretty obvious.
If metadata has such power, why do they say that it is an "ineffective intelligence strategy"?