By John P. Mello Jr. TechNewsWorld
01/18/05 7:30 AM PT
"The DOJ has refused to answer the public's very simple question: 'Can the government see what I'm reading on the Web without having to show probable cause?' Yet the public's interest in an answer to that question, which implicates the most profound constitutional rights, is inestimable," the Electronic Frontier Foundation asserted.
A group that defends civil liberties on the Internet has filed a Freedom of Information Act (FOIA) request with the U.S. Department of Justice (DOJ) to determine if the government is secretly gathering information on the surfing habits of citizens.
In a copy of the FOIA obtained by TechNewsWorld, the San Francisco-based Electronic Frontier Foundation (EFF) said, "Although Internet users reasonably expect that their online reading habits are private, the DOJ will not confirm whether it collects or believes itself authorized to collect URLs using pen-trap devices."
"Pen registers" or "trap and trace devices" are technologies used by law enforcement agents to collect numbers dialed on a telephone or e-mail and IP addresses.
Individual Rights
"The DOJ has refused to answer the public's very simple question: 'Can the government see what I'm reading on the Web without having to show probable cause?' Yet the public's interest in an answer to that question, which implicates the most profound constitutional rights, is inestimable," the EFF FOIA asserted.
The Justice department is using pen-traps to garner information about what people are doing online, declared Alan Davidson, associate director for the Center For Democracy & Technology in Washington, D.C.
"The question is how much information are they getting when they use this tool," he told TechNewsWorld. "The reason that's important is that these pen-trap tools are used without the same judicial oversight you get with a wire tap."
With a wire tap, he explained, a judge is overseeing the whole process. "With a pen-trap, there's a much lower standard, and you can use it even when there's no probable cause to believe that a crime has been committed."
Limp Oversight
To obtain authorization for a pen register or trap and trace device, the government needs to obtain a "certification of relevance" from a court, noted EFF attorney and Bruce J. Ennis Fellow Kevin Bankston. "Rather than go to a judge and give facts leading to a finding of probable cause, which is required by the Constitution to get a search warrant, all the government has to do is certify -- sort of promise to the court without showing any
fact -- that it believes the information it is going to collect is relevant to the investigation."
Web addresses like URLs can contain much more information that a typical phone number, explained Jonathan Zittrain, director of the Harvard Law School's Berkman Center for Internet and Society in Cambridge, Massachusetts. "The idea behind a lower standard for phone number information is that it's merely 'envelope without contents,' showing the fact of the call -- something revealed already to the phone company -- rather than its contents," he told TechNewsWorld via e-mail .
"But URLs often contain contents rather than envelope," he continued. "For example, 'http://www.google.com/search?q=fbi>' is a visit to Google (Nasdaq: GOOG) -- but it's also the very act of searching for 'FBI' there. Too often the URL is the data, and the easy separation made for phone -- if ever it worked there -- doesn't cut it so well here."
How Far Can DOJ Go?
"If there's thought to be good reason not to allow warrantless searches of actual packet contents, then URLs too should be treated sensitively," he added.
Bankston explained that pen traps have been used legally in the analog world for some 30 years. When the Internet came along, courts began to expand the practice to e-mail addresses. That expansion was codified in the Patriot Act.
The problem, as the EFF sees it, is that the government refuses to reveal how far it thinks it can go under the Patriot Act in gathering information on the Internet.
"In a free society, the police should at least be able to tell the people what their interpretation of their powers is," Bankston argued. "Yet, the Justice department has refused in the year since the Patriot Act's passage how they read this new statute and whether they think it allows them to get URLs or not."
20 Days To Act
"If there is an FOIA request, we will review it and respond to it with any
records or documents that will be appropriate under the law," FBI spokesman
William Carter told TechNewsWorld.
Bankston said that the DOJ has 20 business days to address the FOIA. "That doesn't mean that they have to generate the documents by then, but they at least have to get back to us and start negotiating the release of documents," he explained.
Another Security Flaw Found in IE January 17, 2005
Symantec Corp. issued an advisory based on the publication of the latest Internet Explorer flaw. The company said that IE's download-detection function can be overridden by certain combinations of coding that includes an automatic download function and other HMTL coding tags.
Related Stories
China Starts Up World's Biggest Next-Gen Internet Network December 27, 2004
"We were a learner and a follower in the development of the first generation Internet, but we have caught up with the world's leaders in the next-generation Internet, become a first mover, and won respect and attention from the international community," IPv6 committee director Wu Jianping said.
Survey Shows Internet Top Media Choice September 24, 2004
"Consumers continue to move beyond purely functional uses of the Internet into more media-oriented activities, such as reading stories, looking at photos and watching video," Online Publishers Association President Michael Zimbalist said. "These results show how receptive people of all ages are to the Internet as a medium and not just a tool."
Symantec Updates Internet Security Suite August 18, 2004
Norton AntiVirus 2005's new Internet worm protection is designed to safeguard consumer and home office users from new types of fast-spreading blended Internet worms that attack computer users' systems through multiple entry points. Internet Worm Protection blocks inbound online ports to prevent the spread of threats like Sasser and Blaster that propagate through system vulnerabilities.
Mysterious New Threat Secretly Plagues Internet June 25, 2004
Although it is unclear precisely how the malicious code is infecting IIS servers, it is believed to be a so-called zero-day threat -- a virus or worm that is not prevented by most antivirus defense -- and might be similar to the Nimda worm, which infected users through Internet Explorer as well as through e-mail.
Related News Alerts
More by John P. Mello Jr.
McAfee Gives Enterprise Macs a Bodyguard November 02, 2009
When it comes to Mac use in an enterprise environment, running third-party security software isn't just a matter of using an abundance of caution. It may also be a matter of complying with governance mandates and regulations. McAfee's new Endpoint Protection for the Mac targets enterprise systems handling large amounts of sensitive data.
Adobe Elements Buffs Up for Mac October 26, 2009
For the almost-but-not-quite pro photog, Adobe Photoshop Elements offers a collection of tools that go beyond most free offerings but don't dish out the wallet-busting feature overload of full Photoshop. In the past, some Mac users have been annoyed with Adobe for having versions of Elements ready for Windows months before they were out on Mac. With version 8, both platforms get their chance at the same time.
GoToMyPC Gets Ready to Go to Your Mac October 19, 2009
GoToMyPC has been a popular remote access product in Citrix's portfolio, and previous versions have allowed any Net-connected computer to remotely control a PC. A new version, soon to come out of beta and into full release, can access Macs as well. With the growth of both telecommuting and Macs in the enterprise, Citrix felt the time was right.