19 February 2011

Photoshopped through the gate

What would we do without outlaw motorcycle gangs? Like communists (or 'fellow travellers') in the 1950s they're always available to spritz up a dull news story with a scary headline.

The front page of today's SMH thus features the headline "Bikies infiltrate defence bases' and goes on to reveal - hold your breath, lock away your kittens and children - that
GAPING holes in the security of Australia's defence bases are leaving them exposed to infiltration by organised criminals, bikie groups and terrorists.

Defence sources have revealed that since at least 2008 the military has failed to act on warnings of poor base security and ignored or stalled recommendations to fix deficiencies.
But wait, there is more -
In late 2009, senior US Navy officials raised concerns about security at Australian naval bases, querying whether American ships could dock safely.
Security protocols at US bases are of course exemplary. Are we talking a routine question ('Does your port have potable water? Are there nightclubs in the vicinity? Are the natives friendly? Is it safe to dock?') answered with a routine 'Yes'?

The SMH frets that -
Briefings and reports by defence and police officials during the past three years reveal that:
• A small number of serving defence personnel belong to outlaw bikie groups.

• A company tied to an alleged crime boss was given contracts to guard sensitive naval facilities in 2006.

• Plain-clothes undercover defence officials talked their way past security posts at half a dozen bases and on one occasion used a library ID card to enter a defence facility.

• Naval personnel smuggled guns into Australia from south-east Asia in 2008 by stashing them in the storage cavity of an Armidale-class patrol boat.
Given that membership of motorcycle groups is in fact not illegal in every part of Australia we might want to look behind the emo about "a small number of serving defence personnel belong to outlaw bikie groups". A small number of some 50,000 serving defence personnel are presumably members of the Liberal Party, stamp collectors clubs, gay saunas, pigeon racing clubs, Rotary and other entities. How small is "small" and what are the implications? Should all "serving defence personnel" be surveilled to determine their OMG associates? Mandatory blood, hair and urine testing to detect drug use?

The SMH apparently did not need to rely on Wikileaks in obtaining "A Defence Department document" that reveals "a review of the vulnerability of defence bases, ships and other assets called for a ground-up overhaul", shortly after the Chief of the Defence Force said he was confident "the security arrangements in place at our bases are effective".

Law enforcement agencies have supposedly documented concerns about organised crime penetrating defence facilities for over a decade. It is unclear whether that documentation reflects substantive concerns (particularly concerns that were not effectively addressed) or merely speculation and bureaucratic insurance.

The SMH states that -
In 2000, the Victoria Police drug squad created an intelligence file alleging that a group of navy personnel was importing cocaine through Garden Island naval base in Sydney.
Are we talking half the fleet or a few 'bad eggs' whose criminal behaviour has been detected and punished? Let us not dwell on independent claims that the Victoria Police has been "infiltrated" by drug dealers and OMGs or Office of Police Integrity reports indicating that information handling has been poor [PDF].
In 2006, two state police agencies discovered that Global Protective Services, a company subcontracted to guard HMAS Penguin and Garden Island naval base, was linked closely to the Finks outlaw motorcycle gang member and organised crime figure Yassar Bakir. GPS is now deregistered and not associated with any business with a similar name.

Queensland police suspected that the now-jailed Bakir was simultaneously using GPS - whose naval base contracts expired in mid-2006 - to run drugs down the east coast. In 2005, another company linked to Bakir, Global Protection Group, also not linked to any business operating now, had a contract to guard the Randwick barracks.

Defence sources said the department was not only failing adequately to vet civilian subcontractors but had failed to detect or act on links between at least two dozen serving personnel and bikie gangs.

Police sources have confirmed strong associations between some defence employees and the Hells Angels, Rebels, Bros and Gypsy Jokers gangs, whose members include organised crime figures.

A police report seen by the Herald says a small number of military personnel are members of hardcore, outlaw bikie groups and have been implicated in "weapons and drug trafficking".
Ideally the Defence Department or a parliamentary committee will place the claims in context.

Using library cards or Photoshopped ID is not unthinkable. In an unrelated matter Director of Public Prosecutions (Queensland) v. Bakir [2006] QCA 562 notes that Yassar Bakir was arrested in relation to possession of cannabis and possession of a Queensland Police Service identification badge.

CoE Cybercrime Convention

The Attorney-General and Minister for Home Affairs & Justice have released a 16 page public consultation paper regarding Australia's proposed accession to the Council of Europe Convention on Cybercrime, promoted as "the only binding international treaty on cybercrime" and as "a guide for nations developing comprehensive national legislation on cybercrime".

The Attorney-General stated that -
As cybercrime is a global issue, the Convention provides systems to facilitate international co-operation between signatory countries, as well as establishing procedures to make investigations more efficient.

While Australian law substantially complies with the obligations in the Convention, there is more we can do to ensure Australia is in the best position to address the range of cyber threats that confront us, both domestically and internationally.
The Convention broadly harmonises national law regarding cybercrime by requiring signatories to criminalise four types of offences, including -
• offences against the confidentiality, integrity and availability of computer data and systems, including illegal access to computer systems, illegal interception, data interference, systems interference and the misuse of devices;

• computer-related offences, including forgery and fraud;

• content-related offences, including child pornography; and

• offences related to the infringement of copyright and other related rights.
It also establishes procedures to facilitate investigations and cooperation between national law enforcement bodies, including -
• helping authorities from one country to collect data in another country;

• empowering authorities to request the disclosure of specific computer data;

• allowing authorities to collect or record traffic data in real-time;

• establishing a 24/7 network to provide immediate help to investigators; and

• facilitating the exchange of information.
Submissions are sought by 14 March 2011. Legislative amendments to give effect to the Convention are outlined in the exposure draft Extradition and Mutual Assistance in Criminal Matters Legislation Amendment Bill released for public comment on 31 January 2011. The deadline for comment on that draft is 14 March.

16 February 2011

Vodafone investigation

The Australian Privacy Commissioner has released his findings [PDF] following investigation into media reports that claimed billing and call records for up to four million Vodafone customers were available on a publically accessible website.

The Commissioner's report resembles the very frightful experience of being flogged with a very limp lettuce leaf and a jaundiced observer such as myself might doubt that Vodafone's executives are quivering sleepless in their beds with chagrin and horror at the findings.

The Commissioner indicates that his "investigation looked at Vodafone's compliance with the National Privacy Principles". Sound the trumpets -
In the course of my investigation I did not find any evidence that substantiated the claim that Vodafone customers' personal information was available on a publically accessible website. However, in my view, Vodafone did not have appropriate security measures in place to protect customer's personal information at the time. Consequently Vodafone was in breach of their obligations under the Privacy Act. I was particularly concerned by Vodafone's use of shared logins and passwords for staff and the broad range of detailed personal information available to them.
The absence of "appropriate security measures" and indications that staff in the Vodafone dealer network have been sharing access and - it seems - proving access/information to third parties does, I suggest, pose real concerns ... concerns that should and indeed can be addressed by the Commissioner, irrespective of whether a list of credit cards or other data has been parked on the web.

In response to the problem the Commissioner notes that -
As part of an undertaking given to the Privacy Commissioner, Vodafone agreed to review its IT security, and all appropriate staff including employees in retail stores and dealerships will be issued with individual login IDs and passwords.
All is well, it seems, as -
I am pleased that on being made aware of the allegations Vodafone acted promptly to put in additional security measures to limit access to the personal information it holds. While I welcome the steps that were taken I have also asked Vodafone to report back to me on the progress of the review and implementation of increased security measures
A more meaningful review would ask whether the "additional security measures" were effective and why, oh why, Vodafone's practice had been so inept that a problem had required investigation by the Commissioner.

I am unimpressed by the report's indication that -
In response to the investigation, Vodafone:

• advised the Privacy Commissioner it had implemented emergency technical measures and commenced an internal investigation on becoming aware of the allegation,

• advised that customer information was not, and had not, been publicly available on the internet or the Vodafone website,

• provided regular updates to the Privacy Commissioner about its internal investigation
In the tradition of Yes, Minister the Commissioner stated that "this case should serve as a reminder to all businesses using customer management systems to ensure that they have robust privacy protections built in". We might ask whether more than flailing with lettuce leaves and yet another reminder is necessary. Should there be meaningful penalties for bad practice? Should the Commissioner conduct an 'own motion' investigation of Vodafone's competitors (and, if unable to do so because of resource constraints, publicly indicate that bureaucratic incapacity has serious implications)?

The Commissioner stated that -
All businesses must take the privacy of their customers seriously. Systems should be up to date and secure and staff should only have access to the information that is necessary for their work. To comply with the Privacy Act and retain the trust and loyalty of their customers, I urge businesses to review their data security practices to prevent the likelihood of a privacy breach occurring which could have the potential to lead to identity theft or fraud.
That exhortation would be more meaningful if the Commissioner had chosen to move beyond the specific failure by Vodafone - and a narrow construction of media claims - and explore practice elsewhere in the telecommunications sector. Are Vodafone's competitors using the same model?

The report indicates that Vodafone customer data, contrary to media claims, was not placed on the web. That will reassure some observers.

The report however notes that -
Whether the steps taken by Vodafone to protect personal information are reasonable in the circumstances is a subjective test based on the particular risks within its business. In this regard, it is noted that Vodafone's business model includes licensed dealerships which can carry underlying data security risks and, consequently, such risks may warrant additional security safeguards being taken. For example, appropriate authentication of remote users will be an important network security measure. Further, while these dealerships are subject to contracts that include customer confidentiality obligations, the use of store loginIDs, rather than individual loginIDs, also adds to the underlying data security risk.

The use of shared loginIDs reduces the effectiveness of audit trails to assist in investigations and access control monitoring, which are important steps for organisations in protecting personal information. In practical terms, the use of shared logins means that anomalies may not be detected and if they are, they may not be able to be effectively investigated as the actions are not linked to an individual authorised user. The current investigation illustrates the impact that shared logins have in terms of providing an effective audit trail. Similarly, media reports about dealership employees 'Siebel farming' as part of customer retention activities illustrates the reduction in the effectiveness of audit trails where shared loginIDs are used.
But wait, as they say, there is more -
Vodafone's business functions require it to collect identity information from customers to comply with obligations to complete 100 point ID verification checks. This information is stored on Siebel and is available to all authorised users. This identity information includes, for example in the case of passports, the document number and expiry date. Identity theft can cause significant harm to individuals if a security breach occurs. Thus, while Vodafone staff and employees receive privacy training and their employment contracts include customer confidentiality requirements, having identity document information available to all staff and dealership employees raises additional privacy risks.

While Vodafone had a range of security safeguards in place to protect the personal information on its Siebel system at the time of the incident, the use of store logins and the wide availability of full identity information via Siebel caused an inherent data security risk in terms of how personal information was protected by Vodafone.
In an article published the day this post went online the SMH stated that -
But [the SMH] understands that information was in fact available to be accessed from the public internet – rather than an internal intranet – but that it required a username and password to gain access to customer details. It was that username and password, which this website understands was shared among authorised users, that allowed for the unauthorised access of a customers' personal information.

[Our] understanding was put to the Privacy Commissioner's spokeswoman, who confirmed that this was in fact the case. She said that the main point of the Privacy Commissioner's comments that details weren't available on the public internet was to ensure customers did not think that their details were easily accessible by anyone using the internet. [Random users, no. People who work in the dealer network or who had been provided with info/access by the dealers, yes]

An unauthorised user could access Vodafone's web portal but needed login credentials to see customer details.

In January, [we] published a report, which claimed that the personal details of millions of Vodafone customers - including their names, home addresses, driver's licence numbers and credit card details, had been available online.

A further report, published in late January, revealed Vodafone dealer CommsDirect had been misusing customer information and forwarding call records on to people outside the company. The revelations, which led to CommsDirect shutting down, also formed part of the Privacy Commissioner's investigation.
The Commissioner notes that -
The Privacy Act does not currently allow for sanctions to be imposed following an investigation initiated by the Privacy Commissioner. The Government has foreshadowed its support for recommendations made by the Australian Law Reform Commission to strengthen the enforcement regime available under the Privacy Act as part of the Government's program of privacy law reform.
Time I think for the Privacy Commissioner to -
• engage with industry in active development of a realistic, rather than excessively permissive, national standard for data protection in dealer environments

• work with industry to proactively prevent the sort of problems apparent at Vodafone (ie management indifference, poor prioritisation in IT investment, inadequate supervision of dealers and of the junior staff employed by dealers) rather than responding once the data goes walkies

• look at the vetting and supervision of employees within the dealer network (ie Vodafone's agents), given indications that there is substantial churn and low supervision of those personnel.

ACIP review of patentable subject matter

The Advisory Council on Intellectual Property (ACIP) has released a rather bland report on its review of patentable subject matter.

The 101 page report [PDF] by ACIP reflects concerns over several years about the sorts of things that can be patented. Under the Patents Act 1990 (Cth) the primary test in Australia of whether an invention is patentable subject matter is whether it is a 'manner of manufacture'. That test has been criticised as ambiguous and obscure, with the Australian Law Reform Commission's 2004 Genes and Ingenuity report on gene patenting for example noting the value of a flexible test for patentable subject matterbut finding that the test for the usefulness of an invention was unclear and accordingly recommending that the manner of manufacture test be reviewed.

The ACIP review recognised the overlap between 'manner of manufacture' and other criteria for patentability, thus encompassing 'patentable subject matter'. It included examination of the appropriateness and adequacy of the 'manner of manufacture' test as the threshold requirement for patentable subject matter under Australian law, and the historical requirement that an invention must not be 'generally inconvenient'.

ACIP released an Issues Paper in July 2008 as part of public consultation (with 38 public submissions from interest groups and academics such as Matthew Rimmer and Luigi Palombi) and conducted several public fora in March 2009 to discuss key issues. Its September 2009 options paper identified possible options for reforming the law, eliciting several written submissions in response to the options paper and resulting in a final report on the review of patentable subject matter. That report was provided to the Minister for Innovation, Industry, Science & Research in December last year.

The report's recommendations are cautious. They include -
• codifying the established principles of patentability – so that an invention must be an artificially created state of affairs in the field of economic endeavour

• maintaining the current exclusion from patentability of human beings and biological processes for their generation – but not introducing any further specific exclusions,

• introducing a general exclusion from patentability of inventions whose commercial exploitation would be wholly offensive to the Australian public,

• including a statement of objectives in the Patents Act to outline its purpose,

• changes to assist the Commissioner of Patents when applying the test for patentability.
The ACIP Chair in submitting the report states that -
In its wide consultations ACIP has listened to the concerns of the business community, interest groups and other stakeholders, and has sought a balanced approach to take account of their diverse views and interests.

A key recommendation is to introduce a general patentability exclusion in respect of subject matter the commercial exploitation of which would be wholly offensive. The proposed exclusion would provide a mechanism for dealing with contentious subject matter in extreme cases and remove the current uncertainty in relation to the doctrine of general inconvenience.
The Government will now develop a response to the report. That response may take some time, given current consideration of gene patenting by Parliamentary committees.

Geek chic

From Daniel Domscheit-Berg's Inside WikiLeaks: My Time with Julian Assange at the World’s Most Dangerous Website (Scribe, 2011) 144 -
In no time the Fosshotel apartment looked like an asylum for psychotic slobs. At the start the cleaning women had still been able to plow a path with their large black vacuum cleaners through our things, but soon they couldn't even get the tools of their trade through the door. For a few days these friendly Icelandic ladies battled to save apartment number 23. But after five days at the most they surrendered the terrain as lost. We agreed to an armistice and began swapping shopping bags full of trash for fresh towels and toilet paper.

None of us cooked or even bought anything sensible to eat. Half-empty bags of potato chips began to collect amid our dirty laundry. A pile of stinky dried fish that someone had bought but no one thought was edible lay rotting away on some surface. Things were getting worse by the hour. We should have patented the smell of old socks, pizza crusts, dried fish and sulfur as a means of torture.
Nice rendition of hacker cliches, sans Red Bull, black tshirts and sun-phobic kiddies.

15 February 2011

Comparative Incarceration Rates

Recent posts in this blog (eg here and here) have noted statistics on incarceration rates. A new Bulletin [PDF] from the NSW (BOCSAR) unpacks some statistics with questions about differences in imprisonment rates in NSW and Victoria.

BOCSAR's 'Why does NSW have a higher imprisonment rate than Victoria?' uses a descriptive analysis of national crime, court and prison data in commenting that -
The NSW imprisonment rate is about twice that of Victoria (204 per 100,000 population vs. 104 per 100,000 population). This fact is widely believed to indicate that sentencing policy and practice in NSW is much harsher than in Victoria. A higher imprisonment rate, however, does not necessarily indicate tougher sentencing. The difference between the two states in their imprisonment rates may, for example, arise from differences in the rate of arrest for serious crime, differences in their bail laws or differences in their parole policies.

The NSW court appearance rate is 26% higher than that in Victoria. The overall conviction rate in NSW is 85.7%, compared with 79.0% in Victoria. The overall percentage imprisoned is significantly higher in NSW (7.5%) than in Victoria (5.4%). The mean expected time to serve among prisoners dealt with by Victorian courts is slightly longer than the mean expected time to serve among prisoners dealt with by NSW courts. The NSW remand rate is approximately 2.5 times the Victorian remand rate.
BOCSAR attributes the higher NSW imprisonment rate to a higher rate of court appearance, a slightly higher conviction rate, a higher likelihood of imprisonment and a higher likelihood of remand in custody.

The bulletin's authors ask what explanation can be given for the higher court appearance rate in NSW, the higher proportion of defendants convicted, the higher proportion of convicted offenders imprisoned and the higher remand rate.

They suggest that -
The higher court appearance rate in NSW is likely to be due, at least in part, to higher rates of crime. In 2004, for example, (the last year in which comparable figures were published) the NSW recorded armed robbery rate was nearly 1.9 times that of Victoria. The higher rate of court appearance for drug offences is probably also at least partly a reflection of crime. NSW has a much higher rate of court appearance for importing illicit drugs. It also happens to be the port where the largest quantities of illicit drugs are seized. The much higher NSW court appearance rate for acts intended to cause injury is harder to explain. It would not be surprising if NSW, given its significantly larger Aboriginal population, had higher rates of assault. 21% of the NSW prison population is Indigenous, compared with 6% of the Victorian prison population. Assault is the most common offence for which Indigenous offenders in NSW are imprisoned. In 2004, (the last year in which comparable figures were published), NSW did have much higher recorded rates of assault. The Victorian police figures on assault, however, have been called into question by the Victorian Ombudsman. Survey figures, moreover, show no difference between NSW and Victoria in the prevalence of assault. The surveys conducted by the Australian Bureau of Statistics measure the prevalence rather than the incidence of assault. It is possible that NSW has a higher incidence of assault than Victoria. At this stage, however, it is impossible to say to what extent the higher NSW court appearance rate for acts intended to cause injury is attributable to higher assault rates, as opposed to differences in the way NSW and Victorian police and prosecutors respond to incidents of assault.

In other cases, the higher NSW court appearance rate is more likely to reflect differences between NSW and Victoria in policing or penal policy. NSW, for example, has double the number of people appearing in court for breaching apprehended violence orders (2,976 for NSW vs. 1,057 for Victoria). This difference is much too large to be plausibly attributed to a greater proclivity on the part of domestic violence offenders living in NSW to breach domestic violence orders. The more likely explanation is that the number of domestic violence orders issued in NSW is much higher than in Victoria and/or that police in NSW are more likely to take action in response to an alleged breach of an apprehended violence order. The same applies to the large difference between the two states in the rate of appearance in court for traffic/motor vehicle regulatory offences. Much of this difference stems from the fact that NSW has nearly four times as many people appearing in court for drink-driving offences. It is possible that NSW residents are nearly four times more likely to drink and drive than their Victorian counterparts but a more likely explanation for the high rate of drink-driving appearances is that levels of enforcement for drink-driving are higher in NSW than in Victoria.

There are several possible explanations for the higher proportion of defendants convicted in NSW. Juries in NSW may be more likely to convict defendants who plead not guilty than their Victorian counterparts. Likewise, NSW magistrates may be more likely to convict defendants who plead not guilty than Victorian magistrates. The proportion of defendants pleading guilty may be higher in NSW than in Victoria. Since the guilty plea rate varies from offence to offence, the difference in the percentage convicted may arise from differences in the offence profile of cases coming before the criminal courts. The higher percentage of convicted offenders given a prison sentence in NSW may also be due to several factors. It could, of course, reflect a greater proclivity on the part of NSW courts (regardless of offence and offender characteristics) to impose a custodial sanction. It is also possible, however, that NSW courts deal with a more serious population of offenders3 or that prosecutors in NSW are more likely to lay multiple charges.

Although this analysis has answered some questions, it raises many others. The NSW court appearance rate for acts intended to cause injury is more than double that of Victoria yet national survey data show little if any difference between NSW and Victoria in the prevalence of assaults. Is the difference in court appearance rates for this offence due to differences between NSW and Victoria in the incidence of assault or is it due to differences between the two states in the way they respond to assault? The percentage of convicted offenders sent to prison in NSW is 39%higher than in Victoria. Is the higher imprisonment rate attributable to differences between the two states in the profile of offenders coming before the court system or do NSW courts imprison offenders who, had they appeared in a Victorian court, would be given some kind of non-custodial sanction? NSW has a far higher remand rate than Victoria. Is this because NSW courts are less likely to grant bail at first instance, because police in NSW are more likely to take action in response to alleged breaches of bail or because NSW courts are more likely to revoke bail following evidence of a breach?

... The length of time spent in custody is only partly a function of the sentence imposed by the courts. For many offenders it is also shaped by the willingness of parole authorities to grant or revoke parole. Do NSW and Victoria differ in the willingness of parole authorities to grant or revoke parole? There is clearly a great deal more work to do before the differences between NSW and Victoria in their imprisonment rates are fully understood.

A comity of animals

From Rouse's translation of Nonnos' Dionysiaca, via Bowersock's NYRB blog post on the Lod Mosaic.
So she brought the baby into the light. The girl was bathed by the four Winds, which ride through all cities to fill the whole earth with the precepts of Beroe. Oceanos, first messenger of the laws for the newborn child, sent his flood for the childbed round the loins of the world, pouring his girdle of water in an everflowing belt. Time, his coeval, with his aged hands swaddled about the newborn girl's body the robes of Justice, prophet of things to come ; because he would put off the burden of age, like a snake throwing off the rope-like slough of his feeble old scales, and grow young again bathed in the waves of Law. The four Seasons struck up a tune together, when Aphrodite brought forth her wonderful daughter.

The beasts were wild with joy when they learnt of the Paphian's child safely born. The lion in playful sport pressed his mouth gently on the bull's neck, and uttered a friendly growl with pouting lips. The horse rattled off, scraping the ground with thuds of galloping feet, as he beat out a birthday tune. The spotted panther leaping on high with bounding feet capered towards the hare. The wolf let out a triumphal howl from a merry throat and kissed the sheep with jaws that tore not. The hound left his chase of the deer in the thickets, now that he felt a passion strange and sweet, and danced in tripping rivalry with the sportive boar. The bear lifted her forefeet and threw them round the heifer's neck, embracing her with a bond that did no hurt. The calf bending again and again in sport her rounded head, skipt up and licked the lioness's body, while her young lips made a half-completed moo. The serpent touched the friendly tusks of the elephant, and the trees uttered a voice.
Bowersock's post quotes the Dionysica as -
In late antiquity, the Greek epic poet of Dionysus, Nonnos of Panopolis, waxed eloquent in complex verse about the comity of the god’s animals:
The lion in playful sport pressed his mouth gently on the bull’s neck ... The spotted panther leaping on high with bounding feet capered toward the hare. The wolf let out a triumphal howl from a merry throat and kissed the sheep with jaws that tore not. The bear lifted her forefeet and threw them round the heifer’s neck, embracing her with a bond that did no hurt. The calf bending again and again in sport her rounded head, skipped up and licked the lioness’s body ... The serpent touched the friendly tusks of the elephant.