443 karma · joined October 14, 2015
Bodil Lindquist v Åklagarkammaren (2003) Mrs. Lindquist (whose purposes were mostly charitable and religious) published on a private home page personal data about her colleagues, including telephone numbers and information about a coworker’s injured foot and medical leave. This case raised the question if a private home page accessible to only those who have the address is permitted under one of the exclusions (household activity). The European Court of Justice ruled that it is not.
Bodil Lindquist v Åklagarkammaren (2003) Mrs. Lindquist (whose purposes were mostly charitable and religious) published on a private home page personal data about her colleagues, including telephone numbers and information about a coworker’s injured foot and medical leave. This case raised the question if a private home page accessible to only those who have the address is permitted under one of the exclusions (household activity). The European Court of Justice ruled that it is not.
and they lost the case in 2014 (https://en.wikipedia.org/wiki/Google_Spain_v_AEPD_and_Mario_...), and 'interpreted it' as 'we'll just limit the results from Europe'. This was a landmark case, and they just keep losing them.
A real con artist can just fake someone's ID, for them it's pretty trivial.
The issue is less than 1% of convictions ever make it to the Internet, and those people currently will be stigmatized forever, unlike the other 99%, unless they have this mechanism. Google's plea was 'we will self police, but we won't tell you how. We will ignore court orders, because we choose to'. The court objected to that approach.
If you are convicted of new crimes, no matter how long ago, then your sentence may be significantly increased as a repeat offender.
Many large companies do business with Europe. Many of them are implementing GDPR-like controls and/or adopting Privacy Shield. Other US companies doing business with them must adhere to the new vendor controls these US-companies have adopted, or lose that business.
Across the world, (e.g. Singapore, Philippines and Japan) Privacy laws are being re-written to align parts of local law to GDPR.
The US has limited privacy laws generally (e.g. dat breach notification laws in CA and MA), but has adopted specific protections depending on industry (HIPAA for healthcare, GLBA for Banking). More like likely occur.
While mankind has not needed a right to be forgotten previously, it didn't have the omnipresent Google to deal with either. These are just the opening shots in the Privacy battle that will spread from GDPR.
Other search engines are affected too, but Google has a massive market share and has a long litigation history in Europe.
Then along comes a search engine and doubly punishes someone in what may be a disproportional way; e.g. it's highly unlikely you will come across the convictions of John Smith when you google him, but when you look up someone with a non-common name, it may be the very first search result; disproportionally disadvantaging them for jobs, business and even dating partners.
The issue in this case was Google wanted to be the sole arbiter of what they would remove and what they would leave in, with no oversight from anyone. This would have crippled the GDPR even before it began.
That said, it's early days for the right to be forgotten.
The duty of the prosecution is to prove their case in court. The fact that they have seized his computer(s) and carried out forensics already, means they are looking hard for a conviction. If they freak him out with this sort of circumstantial evidence, he will say something, and it's never a good thing.
https://www.youtube.com/watch?v=d-7o9xYp7eE
Legal precedent depends on jurisdiction and you haven't shared that. Connecting to Tor is a 'fact'. What value that fact has is up to the prosecution to prove. Relevancy is key. Best to wait and see what they alleged happened and then challenge just those set of facts.
If he says nothing, they have a lot to prove. In many places in the US, they will come in with multiple felonies then accept all sorts of plea bargains as it drags on and on and on, like a bad used sales car man.
How is the consumer (data subject) linked to the ID? aka how does a human prove ownership of the account (email address etc??) This is where your PD is.
The solution is pretty easy. You create a table where a user is mapped to an ID. Then you create the rest of the game just as normal, only using the ID.
You WILL need a privacy notice showing data subject rights and detailing what you are collecting and why, and other third parties that you share data with. Also how to contact you to enforce those rights. This should be on the website and wherever the game is (mobile app etc).
If there's a data request, you give them the mapping of their PD to your ID, and that's really it.
If they invoke their right to be forgotten, then you update that row of the table with something other than PD being mapped to the ID. Effectively, they are forgotten.
You can collect data once you tell them what data you are collecting and why, if you are relying on informed consent. They can either give it and play, or not give it and not play.
If it is recoverable, then it falls into the ominous term: Pseudonymous : https://www.wsgrdataadvisor.com/2015/09/personal-data-anonym...
If it's a) then that's either a 'hidden' toggle which does not meet GDPR needs. If it's a 'hidden' and do not process further, it is questionable (unless a right to be forgotten is invoked).
Also if it's a) then everything is discoverable by someone with legal authority, even years after you believe you have deleted it.
They have spent many millions in EU GDPR projects (such as the ability to download all records, which is in the news cycle right now).
Under the current legislation, they can be sued by each regulator in each country separately (this has happened to them multiple times). Under the GDPR, they will mostly be sued by just the Irish Data Protection Authority (other EU regulators will funnel issues to the Irish DPA first).
If they are not doing their job, (and you are not content with their reply), you then appeal to the Data Protection Authority (DPA, Privacy Regulator in the country). The DPA has full powers of subpoena (and a whole lot more), and are not to be trifled with.
"“With UMBRAGE and related projects the CIA cannot only increase its total number of attack types, but also misdirect attribution by leaving behind the ‘fingerprints’ of the groups that the attack techniques were stolen from,” Wikileaks said in a statement."
https://www.usatoday.com/story/news/2017/03/07/wikileaks-cia...
and for remote control:
"In April this year, WikiLeaks disclosed a brief information about Project Hive, revealing that the project is an advanced command-and-control server (malware control system) that communicates with malware to send commands to execute specific tasks on the targets and receive exfiltrated information from the target machines. Hive is a multi-user all-in-one system that can be used by multiple CIA operators to remotely control multiple malware implants used in different operations."
https://thehackernews.com/2017/11/cia-hive-malware-code.html
I believe that intelligence agencies are targeted all the time, and keeping machines clean is not that easy. Certain governments (like Singapore) adopted an air-gap approach, so the machines you use for work don't touch the internet.
But even then, it would be a lot easier to infect that persons's home machine.....Many of the people visiting Guccifers site were normal people, some were from intelligence agencies (proportionally probably a lot more than visit a normal site).
Assuming you had AWESOME undetectable malware, you'd have to infect the lot, get them to report in, and ferret out the interesting ones. Not exactly a weekend project, but if this was your passion in life, very achievable.
Spear phishing these guys is hard, watering hole may be easier.
For example: the Chinese government has been waging war against the Free Tibet movement for years: https://www.google.com.sg/search?q=chinese+malware+free+tibe...
There's a bunch of articles there. One technique is they put up a pro-Free Tibet site, and put malware on it. The visitors get infected and they have an insight into who is interested in that topic and their IP addresses for basic geo location, and maybe remote control of their machines.
If we pick a topic that's super interesting for government intelligence people (like the Guccifer blog site itself), and put some awesome non-detectable malware on there, you could potentially infect multiple intelligence officers from multiple countries.
When the bots phone home, they will report username, domain name, email addresses, visited URLs, security certificates (or basically anything you want). So you now have a rolodex of machines you can manipulate. Mossad did it...nope....North Korea....nope CIA...nope FBI etc etc
Now this is super hard to do in practice. But you only have to be lucky once.
https://www.cyberscoop.com/winter-olympics-hack-attribution-...
https://krebsonsecurity.com/2017/08/blowing-the-whistle-on-b...
https://blog.trendmicro.com/trendlabs-security-intelligence/...
https://blog.talosintelligence.com/2018/02/who-wasnt-respons...
and please note the careful wording: "Working off the IP address, U.S. investigators identified Guccifer 2.0 as a particular GRU officer working out of the agency’s headquarters on Grizodubovoy Street in Moscow. "
interpretation 1: The guy accessed the device from his GRU office
Interpretation 2: The IP belongs to a guy (maybe his residential connection), and he happens (from other sources) to work at the GRU office. Assuming the GRU device is relatively secure, is it possible that other devices on his home have malware on them? If the latter, all the devices would appear as coming from that same residential IP address.
I work in this field and false attribution happens all the time. Evidence is really easy to fake.
The last letter of the GDPR is Regulation. A regulation is very different than than a Directive (the pre-GDPR law is based on a directive). There is very little wiggle-room with a Regulation, even between countries. The ICO also works with other DPAs currently as part of Working Party 29, which ensures the DPAs are working in Sync.
So the ICO advice is worthy of close study, especially if your local DPA (assuming you have one) has not commented or given guidance on a certain matter.
If the DPO complies with all of it, they will breach the GDPR (e.g. Request 9b). Of course a data subject also has no right to know what security controls (request 8) you have in place, other than they are 'commercially reasonable'.
A regulator can require this information, but not a consumer (data subject). This could be the basis of a great interview test for selecting your DPO.