9M logs of Brits' road journeys spill from number-plate camera dashboard
theregister.co.uk
theregister.co.uk
Who gets to decide what "harm" is or whether anyone suffered "detrimental effects"? Surveillance is so common and normalized they don't consider the act of collecting so much information itself as a "detrimental harm".
What if that harm only presented itself years down the line? Maybe a creepy stalker who can synthesize mulitple data sets to reconstruct a person's movements or possibly use it against them some way (scammers and fraudsters are increasingly using all these leaked datasets to create a more accurate profile of an individual for more sophisticated attacks/targeting. Your name/address/mobile number must not and can not be considered PII since it's already been leaked probably ten's of times by now).
That's an incredibly shortsighted comment to try and justify developing a system with not even the most basic of security considerations.
I honestly just wish those same people were jailed for 50 years as a result, we'd see a LOT more consideration in the future if they were held personally liable.
I'd consider myself privacy-conscious, however it is clear that this sort of open access further limits my "privacy." I wonder if privacy advocacy is more about aversion to certain power imbalances rather than privacy as an end itself for many folks.
Know your target number plate? Oh look, they go to such and such supermarket at around 8pm every Friday.
While having everything be open would probably reduce double standards along the "government and people with influence" vs "non-government and people without influence" lines I am not sure it would be a net positive, or at least not enough to prefer an open approach to dragnet systems over not having them in the first place.
I would be very worried about "tyranny of the majority" type situation where a (large and or powerful enough) local majority uses the system to the detriment of some local (small enough or powerless enough) minority either under color of law or with a blind eye and/or tacit approval from the local powers that be. With a large enough majority vs a small enough minority government's hands may effectively be tied when it comes to preventing abuse and intervention from next higher level up level of government is not always forthcoming. We've all seen the way online communities engage in witch hunts. If the past is any example I don't think we can trust municipalities in possession of dragnets to not do the same if the contents of those dragnets are open to the public.
I think we can all agree that gay bar patrons in rural Alabama and gun shop patrons in urban Massachusetts, to name a couple examples, might not do too well under an "all the location data the local government has out in the open" type of surveillance scheme.
But privacy itself is also a claim against your neighbor: not only is it illegal for them to blackmail you, it is impermissible to obtain the grounds for that blackmail.
I'm perhaps more afraid of my neighbor than I am the government. Rapists are more often people you know, and all that.
Urban areas have privacy by blending into the crowd. Rural areas have privacy by density, there simply aren't enough people to observe everything. Technology is making both those obsolete.
Private information "getting into the wrong hands" often seems to be an issue of misplaced confidence in the confidentiality of that information. In an era where "surveillance is democratized," how we think about the existence of "private information" might radically change. In your example, the words, actions, and ideas that would have generated controversy might not have ever been spoken or acted upon in the first place, or there would be such an apparent abundance that the "controversy" wouldn't hold ground. More of a fringe position here, but maybe certain ideas and actions wouldn't even be conceived of in a post-privacy world, as the result of the loss of an expectation that those ideas or actions could be kept confidential.
It certainly feels like the cat's out of the bag when it comes to mass surveillance. Facial recognition, for example, isn't going away, and there doesn't seem to be enough political / institutional momentum to counter the value that is provided to organizations by the data that one might view as an invasion of privacy. There doesn't seem to be a meaningful debate about maintaining personal privacy, so maybe the discussion should be who has access to these tools, systems, and institutions moving forward.
The former Chief Medical Officer of Scotland lost her job by visiting her second home during the lockdown.
Especially with this being a database of private data.
I imagine that depends. If your bank allows you access to another person's account by manipulating the URL, that presumably counts as a crime.
(Incidentally, this exact vulnerability has happened in the real world. https://news.ycombinator.com/item?id=2656837 , https://www.theregister.co.uk/2011/06/14/citigroup_website_h... )
"Manipulating the URL" -- "?id=1", "?id=2", "?id=3", in effect -- was enough to get Andrew Auernheimer (a.k.a. "weev") convicted and sentenced to ~3.5 years in prison [0].
Yes, his conviction was later vacated -- albeit due to a "technicality" ("improper venue"). Regardless, he still spent more than two years locked up for what really does seem like some completely exaggerated bullshit!
> "... [the Third Circuit judges] were skeptical of the original conviction, noting that no circumvention of passwords had occurred and that only publicly accessible information was obtained."
---
(Note: I've never met the guy, nor would I ever want to. Everything I've heard and read indicates that he's a pretty shitty human being -- and I suspect that didn't help him very much at trial. He almost certainly was deserving of some "bad karma" but that's not for the "justice system" to dish out.)
TL;DR: If you're in the U.S., you might want to think long and hard before taking that chance!
---
I would link some sources because you shouldn't trust just my vague memory, but it's incredibly difficult to find the right google search terms.
There has to be knowledge on the part of the offender that the access is unauthorised
So I guess it depends what the "offender" googled and what the link description said before they clicked it wrt open websites. And no doubt their explanation and demeanour when questioned etc.
https://www.cps.gov.uk/legal-guidance/cybercrime-prosecution...
Section 1
As I understand it, under GDPR data controllers have a responsibility to take reasonable measures to secure the data. I believe failure to do so is a criminal offense.
I suspect a much more interesting argument exactly is the issue with having this particular data - what laws are being broken by redistributing it (I don't have the answer). But that was not the point that you raised, hence my reply.
Anyone, not just the government can operate an ALPR system and record this data for whatever purpose they wish.
I'd be surprised though if it is really run by the council or just contracted out to some outsourcer. In which case they should be fined.
It might take a few years, but you can use this dataset in the future to understand who owned the vehicle at this time and reconstruct their movements.
Using collected information it's possible a computer can remember every journey you've ever taken; this car with this reg plate was here at this time at this place, and they did not have a valid tax/insurance at this time, or it could be useful during investigations
It seems analogous to an IP address in that sense, and the courts have ruled that IP addresses are personal information.
Putting aside ethical concerns , would there be any legal ramifications for capturing the presence of a car at a certain location and sharing it? The licence plate identifies the car, not the driver. (Similar schemes are in place for boats and airplanes of course)
Are you implying that the slightest doubt about the identity of the driver means that it is perfectly alright to collect the data? because if so that surely also applies to many other GDPR situations, where families share a single computer for instance.