Indiscriminate surveillance at MIT – Logging of card access data at CSAIL
tech.mit.edu
tech.mit.edu
Further, this data is actually useful: if something happens, you know who the last people to open the door were. Further, as a grantee of privileged access, you know that. You know you can't just say it must have been one of the 200 others with the common key. So it's more invisible prevention than measurable solving.
This lets administrators be more permissive about delegating access while simultaneously increasing security. For example, I work in a couple of the concert halls on campus. Students have always held keys to interior doors, but University policy was that students could not have unsupervised access to exterior doors, probably for insurance reasons.
This meant that if the boss wanted to leave the hall operational while not present, student staff would have to prop doors open. If the hall was locked, he'd have to drive all the way out to campus even if he didn't need to be there for the event. Now that we have an audit-trail-producing card reader system, administration is fine with granting students card access to exterior doors. We are both more efficient (because we don't waste supervisor time) and more secure (because students can lock doors and reopen them when necessary.)
In the past, when students have gone missing, their last contact was not with humans but with the access control system. It provided better "last known location" data that improved investigations. It can validate alibis (demonstrating that you were at a building across campus) and provide evidence in discipline proceedings (the alleged rapist says he wasn't there that night, but his ID swiped into the dorm a few seconds behind the alleged victim, etc.)
Access control logs introduce truth into otherwise ambiguous situations. It matters less what you think, who you like more, or what you want to be true because there is a record you can check. Whether it's "should we keep the library open later?" or "when exactly did this kid go missing?"
You also almost never have to interact with the access control system unless you hold privileged access as part of a job, research assignment, etc. Students who live off campus and don't study at the libraries can go months without pulling out their IDs. It's not like you need to swipe your card to walk down a public street. But when you are accessing university services, it seems only reasonable that the university gets to know that you're doing so.
> Such claims must be put to the test. The NSA claimed that surveilling everyone in the US was vital for preventing terrorism. When it had to give details, it became clear that the supposed benefit did not exist.
And indeed, when RMS pressed the MIT police chief for actual evidence of the claimed benefits, he dodged the question.
"Gee, with this security system in place nothing has ever happened, so you need to prove that something bad would happen if we took it away."
The point here is that so far no evidence has been put forward to support all the hypothetical public safety benefits for which we're being asked to give up our privacy. That's troubling.
You get to communicate with your friends while keeping that fact secret from the government. That's in the Bill of Rights.
You do not get to enter a building that someone else owns while keeping that fact secret from the building owner. That's a crime.
[1] For this reason, your assertion that secretly entering a private building is a crime is not universally true.
You do not get to enter a building that someone else owns while keeping that fact secret from the building owner. That's a crime.
Nobody is saying that it should be "kept a secret". Only that it shouldn't be on record, especially electronically. You know, like people do everywhere buildings have regular keys.
That's a big "if", though, and in the article, Stallman points out that MIT isn't able to actually show that it's a realistic reason to encourage this sort of surveillance.
I feel like there's a middle ground here -- for example, card readers could store a hash of an on-card identifier, one that the security staff do not have access to in normal student records. In exceptional circumstances, you could de-blind the logs and see if a single person was in the building at a given time or not, but there wouldn't be surveillance and the logs would be useless in the typical case.
A card swipe doesn't show that you're there, though. As a student I'd lend people my card all the time, as would most people I knew.
I never once loaned or knew of someone loaning their student ID throughout my time at college.
However, a lot does depend on how the data is being used. My access pattern is very questionable. I swipe into my workplaces at weird times, sometimes to use the bathroom while coming back to the dorms from a party or something. I try my card on all kinds of doors just to see if they'll open. I've never been questioned about it.
I'm 99% certain that nobody is pulling the logs except in response to incidents.
Also yes, it eliminates the possibility of dragnet searching. This is by design. Dragnet searches go against the principles on which the United States was founded. If I am not personally suspected of a crime, my data must be sacrosanct or I have been demeaned as an individual. Innocent until proven guilty and unspied-upon until suspected personally.
If a municipality were to do this with all the private residences under their jurisdiction, sure, that'd be Orwellian, because then it really is your data. In this case it's MIT's data about MIT's facility that happens to have been triggered by you.
Were that system implemented (which it should never be, because I thought of it in 10 seconds for a hacker news comment and anything real would need to be much more thought out), the list of card IDs should exist only on paper, in a locked file cabinet, controlled by someone whose job it is specifically to safeguard the privacy of students. Maybe the existing roles that manage grade privacy.
IT is even worse. I'd hate for a creepy sysadmin intern I declined to go on a date with to know where I lived or if I was alone in an academic building at night.
Nobody denied this. But it's absolutely everyone's right to criticize her/him for it.
Employers can also paint the walls puke green and pipe in Muzak. They can hire the low bidder to make lunch out of pink slime. They can keep the offices at uncomfortable temperatures.
So, yes, they can also track you like tagged livestock. But they can also choose not to.
Again, because you seem to misunderstand this piece in many comments, this isn't about whether MIT can legally log. It's about whether they should. RMS is telling them they shouldn't not that they are legally constrained to not do so.
What a great EE/CS project ;)
http://www.bostonmagazine.com/2008/04/the-shaggy-god/
(the story about the access cards is right at the top)
>The most momentous product of Stallman’s genius, Linux, was the first operating system to feature software that was entirely free
Ugh!
Still, it does establish the fact that he uses some alternative means of getting in. Good for him.
Who owns the building? MIT or the personnel of CSAIL? If the building's owner wants a log of who came in and out of the building is that really something Mr Stallman has the power to object to?
My guess is that, in this case, nobody at a high level made a decision in the first place, but rather a mid-level organization like MIT security or facilities management instituted the policy. Since they probably are delegated responsibility over building-access systems, they can do that. But the building inhabitants can also try to complain about the way their departments' buildings are being managed. If you were to ask more specifically, "does facilities management or CSAIL own the building?", the answer is sort-of neither, and sort-of both: it's owned by the corporate parent of both of them.
What if MIT were logging who went to the bathroom?
There's clearly no fundamental difference in securing a different part of the building. Does Mr Stallman (or perhaps an employee of the building if he's just a third party) not have a basis to criticize MITs tracking of bathroom habits because he (or they) don't own the building?
In what way is door access different?
Stallman's thesis is "logs have no use". I'm sure the building's owners disagree. Let's think of a possible use-case:
"Someone stole a laptop from Room 214 over the weekend"
So are the logs useful now?Do you honestly think someone who wants to steal a computer will use their own access card?
Tailgating through doors is a lot harder when everybody knows that the doors log everything.
Indicating to MIT professors that they can't be trusted to use the bathroom responsibly is stupid because the consequences of "bathroom abuse" are very low - hell, who knows how many Nobel-prize-winning ideas were developed on the toilet. Further, they're not being paid to be present and take calls/help customers/make widgets. They're being paid to produce research findings. So even if they are spending all day in the bathrooms, as long as they're publishing, who cares?
Think about it like your house. I'll happily have keys made for extended family and close friends who are staying over. I know them, we will have an ongoing positive relationship, and I trust them. But what about the cleaning service? What about contractors? What about Airbnb guests? Given a checkbox, I'd definitely choose to log their entires. I probably wouldn't read the logs, but I'd feel better knowing they existed.
Before you say NSA, I'm collecting data on my house, not all the other houses on the block. I get to do that. There is no right to enter my house without letting met know about it.
This is MIT's house.
He's pedantic and often unlikable, but we're very lucky to have him.
http://www.annarbor.com/news/u-m-graduate-student-whose-plan...
It's kind of a weird story. A chemistry PhD student repeatedly climbing over walls to steal candy bars...