Employees pleaded with Facebook to stop letting politicians bend rules

One hundred cardboard cutouts of Facebook founder and CEO Mark Zuckerberg stand outside the US Capitol in Washington, DC, April 10, 2018.
Enlarge / One hundred cardboard cutouts of Facebook founder and CEO Mark Zuckerberg stand outside the US Capitol in Washington, DC, April 10, 2018.
Saul Loeb | Getty Images

Facebook’s senior executives interfered to allow US politicians and celebrities to post whatever they wanted on its social network despite pleas from employees to stop, leaked internal documents suggest.

Employees claim in the documents that while Facebook has long insisted that it is politically neutral, it allowed rightwing figures to break rules designed to curb misinformation and harmful content, after being stung by accusations of bias from conservatives.

In September 2020, just ahead of the US presidential election, the author of an internal memo wrote that “director-level employees” had “written internally that they would prefer to formally exclude political considerations from the decision-making process.”

The author called for the company’s leadership to create a “firewall” around its content moderation teams to stop this from happening and to make sure Facebook did not keep up or take down posts because of external political and media pressure.

In another internal note, dated December 2020, an employee claimed that Facebook’s public policy team blocked decisions to take down posts “when they see that they could harm powerful political actors.”

“In multiple cases the final judgment about whether a prominent post violates a certain written policy are made by senior executives, sometimes Mark Zuckerberg,” the author added, referring to Facebook’s chief executive. Parts of the note were previously reported by BuzzFeed.

In a further example from 2019, Zuckerberg was alleged to have been personally involved in a decision to allow a video that made the false claim that abortion is “never medically necessary.”

The post, which had been taken down by a moderator, was reinstated following complaints by Republican politicians, the document said.

The documents, part of a wider cache dubbed the Facebook Papers, were disclosed to US regulators and provided to Congress in redacted form by the legal counsel of whistleblower Frances Haugen. A consortium of news organisations, including the Financial Times, has obtained the redacted versions received by Congress.

Facebook declined to respond to queries about the outcome of any discussions about separating its content team from the policy and communications teams.

Joe Osborne, a Facebook spokesperson, said: “At the heart of these stories is a premise which is false. Yes, we’re a business and we make profit, but the idea that we do so at the expense of people’s safety or wellbeing misunderstands where our own commercial interests lie. The truth is we’ve invested $13bn and have over 40,000 people to do one job: keep people safe on Facebook.”

Staff told to aim for ‘“unimpeachable neutrality”

A former Facebook executive told the FT that Zuckerberg had long told staff to aim for what he called “unimpeachable neutrality.”

This was important particularly around US political groups, employees were told, because the company did not want to be accused of breaking campaign rules by giving a donation in kind.

But three other former employees said they had observed how Facebook applied its own rules in an inconsistent and haphazard way, with special treatment for celebrities.

One former integrity team employee said: “For the people running Facebook, it seems like they care much more about not appearing biased than actually not being biased. Often their efforts at the former make the latter worse.”

https://arstechnica.com/?p=1807122




Organizations Can Now Try Out End-to-End Encrypted Microsoft Teams Calls

Microsoft Teams end-to-end encryption (E2EE)

Microsoft this week announced that organizations can now enable their employees to make one-to-one calls on Teams that are protected by end-to-end encryption.

First announced at the tech giant’s Ignite event in March, end-to-end encryption (E2EE) for one-to-one Teams calls is now rolling out to public preview. Organizations can take advantage of the new capability, but IT admins and users will have to manually enable it.

When E2EE is used, conversations are encrypted in a way that prevents anyone, including Microsoft, from intercepting them. However, at this point, only the real-time media flow, which includes video and voice data, is encrypted end-to-end, and the users on both ends of the call will need to enable it.

E2EE is available for Teams on Windows, macOS, Android and iOS, and once it has been enabled for an account it can be used across all of a user’s devices. An end-to-end encryption indicator is displayed during a call so that the user knows their conversation is protected.

If users need to use Teams features that are not covered by end-to-end encryption — this includes recording, live caption and transcription, call transfer and merge, and group calls — they have to temporarily disable E2EE.

“In normal call flows, negotiation of the encryption key occurs over the call signaling channel. In an end-to-end encrypted call, the signaling flow is the same as a regular one-to-one Teams call. However, Teams uses DTLS to derive an encryption key based on per-call certificates generated on both client endpoints. Since DTLS derives the key based on client certificates, the key is opaque to Microsoft. Once both clients agree upon the key, the media begins to flow using this DTLS-negotiated encryption key over SRTP,” Microsoft explained.

It added, “To protect against a man-in-the-middle attack between the caller and callee, Teams derives a 20-digit security code from the SHA-256 thumbprints of the caller’s and callee’s endpoint call certificates. The caller and callee can validate the 20-digit security codes by reading them to each other to see if they match. If the codes don’t match, then the connection between the caller and callee has been intercepted by a man-in-the-middle attack. If the call has been compromised, users can terminate the call manually.”

Microsoft noted that even though E2EE is currently only available for one-to-one calls, other features such as group calls and chats are still protected by Microsoft 365 encryption. The company plans on adding E2EE to online meetings as well at some point in the future.

Microsoft has shared instructions on how end-to-end encryption can be enabled for Teams running on desktop and mobile devices.

Related: Zoom Introduces End-to-End Encrypted Phone Calls

Related: Facebook Adds End-to-End Encryption to Calls in Messenger

view counter

Eduard Kovacs (@EduardKovacs) is a contributing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Previous Columns by Eduard Kovacs:
Tags:

http://feedproxy.google.com/~r/securityweek/~3/BLr9ZV52f_Q/organizations-can-now-try-out-end-end-encrypted-microsoft-teams-calls




Snap’s Stock Drops as iPhone Privacy Controls Pinch Ad Sales

Snapchat’s corporate parent disclosed Thursday that its ad sales are being hurt by a privacy crackdown that rolled out on Apple’s iPhones earlier this year, raising investor fears that the app’s financial growth is going into a tailspin.

The revelation in Snap Inc.’s third-quarter earnings report sparked a sell-off in after-hours trading that could foreshadow one of the biggest one-day drops in the company’s stock since it went public in 2017.

Snap’s shares plunged by nearly 22% in Thursday’s extended trading. If that decrease is mirrored in Friday’s regular trading session, it will approach the stock’s previous one-day nadir in May 2018 when its price also plummeted by nearly 22%. A decline of that magnitude would wipe out nearly $30 billion in shareholder wealth.

The alarms set off by Snap’s disappointing performance could foreshadow troubles for other apps that may be having more problems tracking their users online activities because of an Apple update to the iPhone’s iOS software released in April.

The change blocks online tracking on iPhones unless a user grants explicit permission to do so, making it more difficult for companies that sell ads based on the information they collect about people’s interests and location.

In a statement, Snap CEO Evan Spiegel said the Santa Monica, California, company has had to recalibrate its operations to “navigate significant headwinds, including changes to the iOS platform that impact the way advertising is targeted.”

Facebook, an outspoken critic of Apple’s new privacy controls, had already told investors that its ad sales could suffer because of the change, but Snap’s results indicated the blow may be even bigger than Wall Street anticipated. Facebook’s shares shed more than 4% in Thursday’s extending trading. The social networking company is scheduled to release its latest quarterly results Monday.

Snap reported revenue of $1.07 billion for the July-September period, a 57% increase from the same time last year, but that was about $30 million below the projections of Wall Street analysts who steer investor expectations.

Perhaps even more troubling to investors, Snap predicted its revenue for the current quarter will range from $1.17 billion to $1.21 billion. Analysts had been forecasting revenue of $1.36 billion, according to FactSet.

Related: Apple Moving Forward on App Privacy, Despite Pushback

Related: Facebook Fails in Bid to Derail $15 Bn Privacy Suit

Related: Apple CEO Escalates Battle With Facebook Over Online Privacy

view counter

Previous Columns by Associated Press:
Tags:

http://feedproxy.google.com/~r/securityweek/~3/C2Xr0e_c5Lk/snaps-stock-drops-iphone-privacy-controls-pinch-ad-sales




Data Privacy Compliance Startup CYTRIO Launches With $3.5 Million in Funding

Data privacy compliance startup CYTRIO this week announced its launch with $3.5 million in seed funding from Dreamit Ventures, Food Retail Ventures and Rockwood Group, as well as angel investors.

CYTRIO was founded by Vijay Basani (chief executive officer), Pankaj Parekh (chief privacy officer), and Darshan Joshi (chief technology officer), who collectively have 50 years of experience in data, privacy and security. Basani previously founded WebManage Technologies (acquired by NetApp), AppIQ (acquired by HP), and Cygilant.

The company offers a solution that simplifies and automates data privacy management for mid-sized enterprises, arguing that “solutions designed for large companies are not suitable for mid-market organizations due to deployment complexity, long time-to-value, and a need for dedicated privacy teams.”

CYTRIO’s product is designed to automatically discover personal information across cloud and on-premises stores, orchestrate data subject access requests, and give customers control over their data.

“Today, we launch CYTRIO to enable mid-size companies to comply with numerous privacy regulations, while building customers’ trust that is essential to thrive in today’s digital economy,” said Basani.

“Our mission to deliver an easy-to-deploy SaaS privacy rights management solution will help mid-market enterprises swiftly and cost-effectively comply with data privacy regulations with minimal resources. We are leveling the playing field for mid-sized enterprises to compete and thrive in the data-driven digital economy, where consumers have control of their private, personal information (PI),” he added.

Related: Data Privacy Startup TripleBlind Raises $8.2 Million in Seed Funding

Related: Gravwell Emerges From Stealth With Data Fusion Platform for Security Teams

Related: Data Security Startup Code-X Emerges From Stealth With $5 Million in Funding

Related: Data Security Company Symmetry Systems Emerges From Stealth

view counter

Eduard Kovacs (@EduardKovacs) is a contributing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Previous Columns by Eduard Kovacs:
Tags:

http://feedproxy.google.com/~r/securityweek/~3/jDlz1iBOblo/data-privacy-compliance-startup-cytrio-launches-35-million-funding




OpenSSF Bags $10 Million Investment

The Linux Foundation has secured a new $10 million investment that will help  expand and support the Open Source Security Foundation (OpenSSF).

The funding will help OpenSSF focus on identifying and addressing security vulnerabilities in open source software, thus securing the software supply chain. The foundation is also working on the development of best practices, tooling, training, and vulnerability disclosure practices.

OpenSSF received financial help from tech giants such as Amazon, Cisco, Dell, Facebook, Google, Intel, Microsoft, and Oracle. Other organizations committed to helping the cross-industry collaboration include Aiven, Cybertrust Japan, Deepfence, DTCC, GitLab, Tencent, and Wind River, among others.

[ READ: Google Pledges $1 Million to Secure Open Source Program ]

“This pan-industry commitment is answering the call from the White House to raise the baseline for our collective cybersecurity wellbeing, as well as ‘paying it forward’ to open source communities to help them create secure software from which we all benefit,” Jim Zemlin, executive director at the Linux Foundation, said in a statement announcing the investment.

In addition to the funding, OpenSSF announced that open source luminary Brian Behlendorf will serve as its General Manager.

OpenSSF is home to projects such as Scorecards and Best Practices Badge, but is also involved in the development of security policies, a security framework for the software supply chain, training initiatives, vulnerability disclosures, security reviews, and research.

Related: Cisco, Sonatype and Others Join Open Source Security Foundation

Related: Google Pledges $1 Million to Secure Open Source Program

view counter

Ionut Arghire is an international correspondent for SecurityWeek.

Previous Columns by Ionut Arghire:
Tags:

http://feedproxy.google.com/~r/securityweek/~3/oJ_o2EonRV4/openssf-bags-10-million-investment




MS Patch Tuesday: 71 Vulns, One Exploited as Zero-Day

The Microsoft Patch Tuesday freight train for October rolled in with fixes for at least 71 security defects in Windows products and components and an urgent warning about a newly discovered zero-day cyberespionage campaign.

The Redmond, Wash. software maker confirmed in-the-wild exploitation of one of the patched bugs — CVE-2021-40449 — in an exploit chain discovered and reported by malware hunters at Kaspersky.

Kaspersky separately said the vulnerability was used in a Chinese-speaking cyber-espionage campaign targeting IT companies, diplomatic entities and military and defense contractors.   

Kaspersky researchers Boris Larin and Costin Raiu documented the findings in a blog post on “MysterySnail” and warned that a second information-disclosure vulnerability that was used by the attacker was not fixed. 

“We discovered that it was using a previously unknown vulnerability in the Win32k driver and exploitation relies heavily on a technique to leak the base addresses of kernel modules. We promptly reported these findings to Microsoft. The information disclosure portion of the exploit chain was identified as not bypassing a security boundary, and was therefore not fixed,” the Kaspersky researchers said.

[ READ: Microsoft Raises Alarm for New Windows Zero-Day Attacks ]

Kaspersky described the issue as a use-after-free vulnerability in the Win32k’s NtGdiResetDC function and said it was intercepted by anti-exploit technologies built into its security product lines..

Microsoft slapped an “important” rating on the flaw and warned that it introduced elevation of privilege risks on unpatched Windows systems.

In total, Redmond shipped patches for 71 documented security vulnerabilities in the flagship Windows OS, the Chromium-based Edge browser, Microsoft Exchange, Microsoft Office Services and SharePoint Server.

Two of the 71 documented vulnerabilities are rated “critical,” Microsoft’s highest severity rating.

Security professionals are urging Windows fleet administrators to pay attention to CVE-2021-26427, a remote code execution flaw in Exchange Server that was reported by the U.S. government’s National Security Agency (NSA).

[ READ: Apple Confirms iOS 15 Zero-Day Exploitation ]

The Microsoft patches come one day after Apple rushed out an urgent iOS mobile platform patch to address a software flaw being “actively exploited” in the wild.

The Cupertino, Calif. device maker confirmed the latest zero-day in an advisory and urged iOS and iPad users to upgrade to the newest iOS 15.0.2.

So far in 2021, there have been 73 documented in-the-wild zero day attacks, the majority hitting vulnerable code in products sold by Microsoft, Apple and Google.

Related: Microsoft Office Zero-Day Hit in Targeted Attacks 

Related: Apple Confirms New Zero-Day Attacks on Older iPhones

Related: Google: Sophisticated APT Group Burned 11 Zero-Days

Related: Apple Ships Urgent Patch for FORCEDENTRY Zero-Days

view counter

Ryan Naraine is Editor-at-Large at SecurityWeek and host of the popular Security Conversations podcast series. He is a journalist and cybersecurity strategist with more than 20 years experience covering IT security and technology trends.
Ryan has built security engagement programs at major global brands, including Intel Corp., Bishop Fox and Kaspersky GReAT. He is a co-founder of Threatpost and the global SAS conference series. Ryan’s career as a journalist includes bylines at major technology publications including Ziff Davis eWEEK, CBS Interactive’s ZDNet, PCMag and PC World.
Ryan is a director of the Security Tinkerers non-profit, and a regular speaker at security conferences around the world.
Follow Ryan on Twitter @ryanaraine.

Previous Columns by Ryan Naraine:
Tags:

http://feedproxy.google.com/~r/securityweek/~3/kIOT5bz8J_E/ms-patch-tuesday-71-vulns-one-exploited-zero-day




Garante Privacy: si alle smart city, ma seri rischi per i cittadini dalle applicazioni IA

Smart city e IA, i timori del Garante privacy

Le smart city sono il futuro delle nostre città. Un futuro tutto sommato vicino, prossimo al nostro tempo, in cui tutti noi, i cittadini, avremo modo di sfruttare i benefici di diverse tecnologie avanzate, tra cui l’intelligenza artificiale (IA).

Il Garante Privacy, partendo dai contenuti del nuovo studio dal titolo “Artificial Intelligence and Urban Development”, condotto dal Parlamento europeo, ha sottolineato nella sua comunicazione odierna la centralità di questo percorso di transizione tecnologica urbana per la crescita economica e il miglioramento della qualità della vita in città, evidenziandone, però, anche le criticità maggiori, se non quelli che a tutti gli effetti sono dei veri e propri rischi.

Rischi per i cittadini come singoli e comunità, ma anche per le organizzazioni e le Istituzioni che rendono vivo il tessuto urbano, con la possibilità di veder emergere nuove discriminazioni (su base etnica, sessuale, culturale e politica) e disuguaglianze (sociali, economiche, nell’accesso ai servizi e in termini di opportunità).

Proteggere i dati personali

Al centro delle preoccupazioni del Garante Privacy, che si vanno ad aggiungere a quelle espresse dagli europarlamentari, c’è ovviamente la tutela dei dati personali, il loro trattamento e la finalità per cui sono elaborati.

Come precisato dal commento del Garante: “L’intelligenza artificiale presenta tuttavia potenziali rischi collegati soprattutto alla capacità di raccogliere, elaborare e trasformare immense quantità di dati, sfruttando anche le sinergie con altre tecnologie (Big Data, cloud, Internet delle cose)”.

Sull’utilizzo dell’IA, in particolare, c’è anche il capitolo riconoscimenti facciale e suo utilizzo da parte delle Forze dell’ordine in ambito urbano, principalmente, con il parere negativo del Garante.

Principali rischi per la privacy

Rischi di varia natura, come detto, “che vanno dalle politiche di cybersecurity all’influenza di errori e “bias” (pregiudizi) basati sulla raccolta e l’elaborazione dei dati, che possono avere pesanti ripercussioni a livello individuale e collettivo”.

Ulteriore elemento di preoccupazione per il garante è il cosiddetto rischio “black-box”, legato all’opacità o addirittura totale impenetrabilità dei processi automatizzati, le implicazioni etiche connesse ai processi decisionali dell’AI che, a differenza di quelli umani, possono essere completamente avulsi da implicazioni morali, empatia, riferimento al contesto umano (lack-of-value).

Ulteriori punti di riflessione sono i rischi reputazionali, dovuti alla condivisione e diffusione incontrollata di dati personali, le disparità connesse alle differenti opportunità di accesso ai dati e l’eccessiva invasività del controllo tecnologico nelle vite quotidiane.

Le azioni da intraprendere

Tra le azioni da intraprendere per mitigare tali rischi e potenziare i vantaggi dell’IA, l’autorità propone:

  • un’attenta cooperazione tra le istituzioni;
  • lo sviluppo di politiche e pratiche focalizzate su una precisa regolazione dell’accesso ai dati e della loro condivisione;
  • un puntuale e tempestivo adeguamento dei quadri giuridici e regolamentari;
  • lo sviluppo di competenze e capacità adeguate (anche in chiave data protection) da parte dei soggetti chiamati a gestire lo sviluppo e la governance dei processi e delle tecnologie connessi alle città intelligenti.

https://www.key4biz.it/garante-privacy-si-alle-smart-city-ma-seri-rischi-per-i-cittadini-dalle-applicazioni-ia/376642/




Garante Privacy: smartphone, attenzione al microfono sempre acceso

Microfoni degli smartphone sempre accesi a carpire informazioni rivendute poi a società per fare proposte commerciali.

Un fenomeno sempre più diffuso, che sembrerebbe causato anche dalle app che scarichiamo sui nostri cellullari. Molte app, infatti, tra le autorizzazioni di accesso che richiedono al momento del download, inseriscono anche l’utilizzazione del microfono. Una volta che si accetta, senza pensarci troppo e senza informarsi sull’uso che verrà fatto dei propri dati, il gioco è fatto.

Su questo illecito uso di dati che si sta facendo alle spalle di persone ignare, già all’attenzione dei suoi uffici, il Garante per la privacy ha avviato un’indagine dopo che un servizio televisivo e diversi utenti hanno segnalato come basterebbe pronunciare alcune parole sui loro gusti, progetti, viaggi o semplici desideri per vedersi arrivare sul cellulare la pubblicità di un’auto, di un’agenzia turistica, di un prodotto cosmetico.

L’Autorità ha avviato un’istruttoria, in collaborazione con il Nucleo speciale privacy e frodi tecnologiche della Guardia di Finanza, che prevede l’esame di una serie di app tra le più scaricate e la verifica che l’informativa resa agli utenti sia chiara e trasparente e che sia stato correttamente acquisito il loro consenso.

            La nuova attività del Garante si affianca a quella già avviata sulla semplificazione delle informative, attraverso simboli ed immagini, affinché gli utenti e i consumatori siano messi in grado in maniera sintetica ed efficace di fare scelte libere e consapevoli.

https://www.key4biz.it/garante-privacy-smartphone-attenzione-al-microfono-sempre-acceso/375746/




Stalkerware: pcTattletale espone online le schermate rubate


L’azienda, che offre un software per spiare in remoto l’attività su smartphone, ha lasciato i contenuti disponibili per chiunque su Internet.

Non è solo un fenomeno lesivo della privacy di chi ne finisce vittima: spesso quello degli stalkerware è un problema più ampio, che rischia di esporre in maniera indiscriminata i dati sensibili di chi è sottoposto a questa subdola forma di “sorveglianza”.

Il caso di pcTattletale, azienda che ha avuto addirittura il coraggio di pubblicizzare i suoi prodotti su YouTube descrivendoli come uno strumento per “scoprire se il tuo partner ti tradisce”, è la migliore dimostrazione del livello di violazione della privacy a cui si può arrivare a causa degli stalkerware.

L’azienda non solo fornisce un software di spionaggio che viene promosso esplicitamente come uno strumento per controllare le attività di un congiunto, cosa che di per sé sarebbe sufficiente per censurarne il commercio. Come riporta il ricercatore di sicurezza Lukas Stefanko, il suo sistema di spionaggio espone informazioni personali a chiunque sul Web.

Nel dettaglio, il sistema messo a punto da pcTattletale, sfrutterebbe la creazione di filmati in cui vengono registrati gli screenshot del telefono Android sottoposto a sorveglianza, che poi vengono messi a disposizione dell’utente (lo stalker) sotto forma di semplici URL che puntano a un server AWS.

Peccato che l’indirizzo per il collegamento venga creato attraverso una formula fissa, che utilizza l’identificativo del telefono e un marcatore temporale, ma la cui visualizzazione non è subordinata ad alcuna forma di autenticazione.

Insomma, non solo pcTattletale fornisce un servizio presumibilmente illegale, ma non tutela in alcun modo i contenuti sottratti alle vittime di spionaggio, che sono potenzialmente visualizzabili da chiunque.

Peggio ancora: tutto il materiale rimarrebbe sui server anche dopo la cancellazione dell’account da parte dello stalker.

Un ennesimo caso che evidenzia il problema legato alla diffusione di questo tipo di applicazioni, la cui proliferazione è stata recentemente censurata negli Stati Uniti dalla Federal Trade Commission.

Condividi l’articolo



Articoli correlati

Altro in questa categoria


https://www.securityinfo.it/2021/09/28/stalkerware-pctattletale-espone-online-le-schermate-rubate/?utm_source=rss&utm_medium=rss&utm_campaign=stalkerware-pctattletale-espone-online-le-schermate-rubate




It’s not easy to control police use of tech—even with a law

It’s not easy to control police use of tech—even with a law
Roy Rochlin | Getty Images

In 2018, Oakland enacted an innovative law giving citizens a voice in police use of surveillance technology. The Electronic Frontier Foundation called it “the new gold standard in community control of police surveillance.” Since then, about 20 other cities have adopted similar laws.

Now, Brian Hofer, one of the architects of Oakland’s law, says it’s not working. Earlier this month, Hofer filed suit against the city and the police department, saying they had repeatedly violated the law.

“We ignored human nature,” Hofer says in an interview. “Police don’t like to be transparent. Surveillance technology use is by design secretive, and no self-interested party is going to voluntarily highlight anything negative about their own proposal.” A spokesperson for the Oakland Police Department says it doesn’t comment on ongoing legal matters.

Even in Oakland, however, the law has given critics of police surveillance a platform. Indeed, Hofer sued under a provision of the law that allows citizens to take the city to court. He hopes it leads to the appointment of an independent counsel to review the police department’s data and assessment of surveillance tech.

“Like any law, [the surveillance ordinance] needs to be enforced,” says Matt Cagle, a staff attorney for the Technology and Civil Liberties Program at the ACLU of Northern California. “Which is why it’s so great to see people in Oakland and San Francisco use it to take the police to court.”

A national review of the laws—dubbed CCOPS, for Community Control of Police Surveillance—suggests other small successes. In Nashville, opposition from a community group created by such a law stopped—at least temporarily—a proposal for the city to buy automated license plate readers.

The laws vary in their specifics. Some require regular meetings between police and community members, annual audits for effectiveness and potential bias, greater transparency of vendors and the cost to taxpayers of any new tech, and a period of public comment before purchasing new tech such as body cameras or ShotSpotter, which uses microphones to detect gunfire.

In a student white paper released earlier this year, the Samuelson Law, Technology & Public Policy Clinic at the Berkeley School of Law said many of the ordinances are weaker than Oakland’s. New York City and Grand Rapids don’t empower citizens to file suit, as Oakland does. In six jurisdictions, including Cambridge, Massachusetts, and Palo Alto, California, police are exempt from the rules. So while a library or school would have to allow for public comment for new surveillance tools, police are exempt from restrictions if they’re executing a warrant or responding to a crisis.

Most of the cities give police broad latitude to use surveillance tech during “exigent circumstances.” Students Tyler Takemoto and Ari Chivukula, authors of the white paper, say this can create loopholes in citizen oversight.

“We know that different local governments considered, for example, racial justice uprisings last summer to fall within that category of extenuating exigent circumstances,” Takemoto says.

Acknowledging that there’s no perfect combination of rules, the authors suggest such ordinances empower citizens to sue and create independent bodies to oversee police and provide support. “Maybe the most important thing is the outside advice… a local nonprofit or community group that’s going to stay engaged,” Chivukula says. “If you don’t have public engagement, then there’s no pressure.”

The movement in Oakland toward reining in police surveillance began in 2014, when groups including the ACLU and EFF protested a proposed “Domain Awareness Center,” a fusion center combining microphones, CCTV, and surveillance data.

First created for port security, the city was moving toward approving a citywide expansion. The advocacy groups successfully campaigned to cancel the expansion and create a temporary privacy committee that would write policies for the city’s use of technology. This became an early iteration of the CCOPS model.

“With an ongoing reporting obligation, we would for the first time ever have real data to determine efficacy, inform policy decisions like retention limits and third-party access, and identify any civil liberties impact,” Hofer says. At the time, he says, “we did naively believe that law enforcement would be truthful in the presentation of data and when discussing the pros and cons of potential uses.”

In the suit, however, Hofer alleges Oakland police have refused to provide the necessary use policies for technologies that were in place before the ordinance took effect, and have allowed federal officials to access surveillance data without written requests, among other things. According to the suit, the police agreed to audit the use of license plate readers for bias and effectiveness, but haven’t produced any audits since 2018.

In 2017, Nashville formed a Community Oversight Board that pushed for a referendum where residents voted in favor of adopting a local version of CCOPS. Then, last year, city councilmember Courtney Johnston introduced a bill enabling police to purchase and install license plate readers, citing a nationwide crime spike and an ongoing street racing problem.

Andrés Martínez, the chair of the oversight board, helped rally opposition, citing reports questioning the effectiveness of the technology. The proposal has been deferred several times.

“In reality, when you look at what license plate readers actually do, it’s minimal compared to the amount of data that they capture,” Martinez says. “I think that our money and attention would be better served in trying to find actual community-based solutions to our public safety issues.”

This story originally appeared on wired.com.

https://arstechnica.com/?p=1798346