14 May 2018

Nonhuman Animals

'Exonerating the Innocent: Habeas for Nonhuman Animals - Wrongful Convictions and the DNA Revolution: Twenty-Five Years of Freeing the Innocent' (University of Denver Legal Studies Research Paper No. 18-16) by Justin F. Marceau and Steve Wise comments
It is hard to conceive of a greater blemish on our justice system than the punishment of innocent persons. The idea of imprisoning or executing an innocent person almost defies the human capacity for empathy; it is nearly impossible to imagine oneself in such circumstances. Advances in science and the work of non-profits like the Innocence Project have made the exoneration of more than 300 people possible. And while the struggle to liberate unjustly incarcerated persons must continue, and should be accelerated, the cruelty of punishing innocents is not limited to the incarceration of human animals. It is time to consider the need to liberate at least some nonhuman animals from the most horrible confinement. These nonhuman animals are unquestionably innocent, their conditions of confinement, at least in some cases, are uniquely depraved; and their cognitive functioning, much less their ability to suffer, rivals that of humans. It is time to seriously consider habeas type remedies for nonhuman beings. 
We are cognizant that the call for nonhuman habeas may cause some to construe this project as one that dishonors or diminishes the efforts that have led to exonerations and the work that remains to be done in the context of human innocence. Nothing could be further from our purpose. One of us has been involved in death penalty defense and litigating claims of wrongful incarceration since graduating from law school, and the commitment to those issues remains unflappable. Indeed, we hope the salience of the cause of liberating humans will be reinforced by our efforts to cross the species barrier. It does no disservice to the cause of innocent humans to suggest that we pay closer attention to the suffering of nonhuman animals. Just as we look back in disgust at our forefathers who were less careful in their protection of human innocents, we predict that our grandchildren will judge us for the way we collectively treat nonhuman animals.
This Chapter proceeds in three parts. First, it analyzes the question of whether exoneration or innocence in the context of nonhuman confinements is illogical. Second, assuming it is a proper question at all, it examines why we would consider exonerating nonhuman animals, that is to say, what are the scientific and social reasons for contemplating relief for humans? Finally, the Chapter considers the practical viability of nonhuman habeas at least for a limited class of nonhuman animals subject to particularly harsh conditions. In so doing, the Chapter discusses the cutting-edge cases filed in recent years by the Nonhuman Rights Project (“NhRP”) seeking habeas review for chimpanzees.
'Meaning in the lives of humans and other animals' by Duncan Purves and Nicolas Delon in (2018) 175(2) Philosophical Studies 317–338 argues that
contemporary philosophical literature on meaning in life has important implications for the debate about our obligations to non-human animals. If animal lives can be meaningful, then practices including factory farming and animal research might be morally worse than ethicists have thought. We argue for two theses about meaning in life: (1) that the best account of meaningful lives must take intentional action to be necessary for meaning—an individual’s life has meaning if and only if the individual acts intentionally in ways that contribute to finally valuable states of affairs; and (2) that this first thesis does not entail that only human lives are meaningful. Because non-human animals can be intentional agents of a certain sort, our account yields the verdict that many animals’ lives can be meaningful. We conclude by considering the moral implications of these theses for common practices involving animals.
 The authors ask
Can animals1 have meaningful lives? This question has been largely omitted from discussions of meaning in contemporary analytic philosophy. It has also been largely ignored by the animal ethics literature. Perhaps the omission is a result of philosophers thinking that the question is misplaced or that it involves a category mistake. Yet, we will argue, the omission is important, because assessing the possibility of meaning in animal life is vital for understanding the full scope and content of our ethical obligations to animals. If meaning is a constituent of a good life, and some of our practices deprive animals’ lives of meaning, then this may be an overlooked way in which our practices harm them. 
In this paper we argue for two theses about the meaningfulness of animal life: (1) that the best account of meaningful lives requires acting intentionally in ways that contribute to final value; and (2) that this does not entail that the lives of animals are necessarily meaningless. A life can count as ‘meaningless’ either because it possesses zero meaning or because attributing meaning to a life of that sort would be a category mistake. To illustrate the difference, the number 2 is heatless, not because it is cold, but because it is not the sort of thing to which the concept HEAT applies. Analogously, a virus’s life is meaningless, not because it possesses zero meaning, but because the concept MEANING simply doesn’t apply. Our second thesis can be understood as a rejection of the claim that the lives of animals are meaningless in either of these senses. To the contrary, to the extent that animals can be intentional agents, our account of meaning yields nuanced verdicts concerning which animal lives are meaningful. It also accounts for the intuitively right range of cases involving humans. Section 2 discusses some prominent theories of meaning in the recent philosophical literature and their associated problems. In Sect. 2 we also propose and defend our intentional theory of meaning. In Sect. 3 we consider the implications of this theory for the possibility of meaning in the lives of animals. In Sect. 4 we discuss the ethical importance of the possibility of meaning in animal life.
In the US the Ninth Circuit in Naruto, a Crested Macaque, by and through his Next Friends, People for the Ethical Treatment of Animals, Inc., v. David John Slater; Blurb, Inc., a Delaware corporation; Wildlife Personalities, Ltd., a United Kingdom private limited company (No. 16-15469, D.C. No. 3:15-cv-04324- WHO) has affirmed the dismissal by the US Northern District of California court in the 'Monkey Selfie Case'.

The Court media statement indicates
the panel held that the animal had constitutional standing but lacked statutory standing to claim copyright infringement of photographs known as the “Monkey Selfies.” The panel held that the complaint included facts sufficient to establish Article III standing because it alleged that the monkey was the author and owner of the photographs and had suffered concrete and particularized economic harms. The panel concluded that the monkey’s Article III standing was not dependent on the sufficiency of People for the Ethical Treatment of Animals, Inc., as a guardian or “next friend.” 
The panel held that the monkey lacked statutory standing because the Copyright Act does not expressly authorize animals to file copyright infringement suits. The panel granted appellees’ request for an award of attorneys’ fees on appeal. 
Concurring in part, Judge N.R. Smith wrote that the appeal should be dismissed and the district court’s judgment  on the merits should be vacated because the federal courts lacked jurisdiction to hear the case. Disagreeing with the majority’s conclusion that next-friend standing is nonjurisdictional, Judge Smith wrote that PETA’s failure to meet the requirements for next-friend standing removed jurisdiction of the court.

AGSVA

The Australian National Audit Office report Mitigating Insider Threats through Personnel Security - consistent with past ANAO and Parlt Committee reports - identifies concerns regarding the national security vetting regime.

The audit report objective was to assessment of 'the effectiveness of the Australian Government’s personnel security arrangements for mitigating insider threats'.

ANAO states
 The Protective Security Policy Framework (PSPF) outlines a suite of requirements and recommendations to assist Australian Government entities to protect their people, information and assets. Personnel security, a component of the PSPF, aims to provide a level of assurance as to the eligibility and suitability of individuals accessing government resources, through measures such as conducting employment screening and security vetting, managing the ongoing suitability of personnel and taking appropriate actions when personnel leave. In 2014, the Attorney-General announced reforms to the PSPF to mitigate insider threats by requiring more active management of personnel risks and greater information sharing between entities. At the time of the audit, further PSPF reforms were being considered by the Government. 
The Australian Government Security Vetting Agency (AGSVA) was established within the Department of Defence (Defence) from October 2010 to centrally administer security vetting on behalf of most government entities (with the exception of five exempt intelligence and law enforcement entities). Centralised vetting was expected to result in: a single security clearance for each employee or contractor, recognised across government entities; a more efficient and cost-effective vetting service; and cost savings of $5.3 million per year. ANAO Audit Report No.45 of 2014–15 Central Administration of Security Vetting concluded that the performance of centralised vetting had been mixed and expectations of improved efficiency and cost-effectiveness had not been realised. ... 
The effectiveness of the Australian Government’s personnel security arrangements for mitigating insider threats is reduced by: AGSVA not implementing the Government’s policy direction to share information with client entities on identified personnel security risks; and all audited entities, including AGSVA, not complying with certain mandatory PSPF controls. 
AGSVA’s security vetting services do not effectively mitigate the Government’s exposure to insider threats. AGSVA collects and analyses information regarding personnel security risks, but does not communicate risk information to entities outside the Department of Defence or use clearance maintenance requirements to minimise risk. Since the previous ANAO audit, AGSVA’s average timeframe for completing Positive Vetting (PV) clearances has increased significantly. AGSVA has a program in place to remediate its PV timeframes, and it has established a comprehensive internal quality framework. AGSVA plans to realise many process improvements through procuring a new information and communications technology (ICT) system, which is expected to be fully operational in 2023. 
Selected entities’ compliance with PSPF personnel security requirements was mixed. While most entities had policies and procedures in place for personnel security, some entities were only partially compliant with the PSPF requirements to ensure personnel have appropriate clearances. None of the entities had fully implemented the PSPF requirements introduced in 2014 relating to managing ongoing suitability. In addition, entities did not always notify AGSVA when clearance holders leave the entity.
It goes on to note that
AGSVA’s clearances do not provide sufficient assurance to entities about personnel security risks. A significant proportion of vetting assessments in 2015–16 and 2016–17 resulted in potential security concerns being identified, but the majority (99.88 per cent) of vetting decisions were to grant a clearance without additional risk mitigation. On rare occasions AGSVA minimised risk by denying the requested clearance level and granting a lower level, or avoided risk by denying a clearance. In some cases identified concerns, which were accepted by AGSVA on behalf of sponsoring entities, should have been communicated to entities or managed through clearance maintenance requirements. 
AGSVA does not provide information about identified security concerns to sponsoring entities outside Defence due to a concern that disclosure would breach the Privacy Act 1988. The PSPF was revised in 2014 to require AGSVA to update its informed consent form to allow such disclosure to occur. Defence and AGD gave a commitment to Government in October 2016 that AGSVA would start sharing risk information in 2017–18. AGSVA updated its consent form in February 2017, but its revised form does not explicitly obtain informed consent to share information with entities. Consequently, AGSVA has not met the intent of the Government’s 2014 policy reform. 
AGSVA’s information systems do not meet its business needs, which has resulted in inefficient processes and data quality and integrity issues. Defence is in the scoping and approval stages of a project to develop a replacement ICT system, which is expected to be fully operational in 2023. The audit included additional work on information security, which is the subject of a report prepared under section 37(5) of the Auditor-General Act 1997.

13 May 2018

Australian Data Breach Regime and Equifax

The incisive 'The introduction of data breach notification legislation in Australia: A comparative view' by Angela Daly in (2018) 34(3) Computer Law and Security Review states
This article argues that Australia's recently-passed data breach notification legislation, the Privacy Amendment (Notifiable Data Breaches) Act 2017 (Cth), and its coming into force in 2018, makes an internationally important, yet imperfect, contribution to data breach notification law. Against the backdrop of data breach legislation in the United States and European Union, a comparative analysis is undertaken between these jurisdictions and the Australian scheme to elucidate this argument. Firstly, some context to data breach notification provisions is offered, which are designed to address some of the problems data breaches cause for data privacy and information security. There have been various prominent data breaches affecting Australians over the last few years, which have led to discussion of what can be done to deal with their negative effects. The international context of data breach notification legislation will be discussed, with a focus on the United States and European Union jurisdictions, which have already adopted similar laws. The background to the adoption of the Australia legislation will be examined, including the general context of data privacy and security protection in Australia. The reform itself will be then be considered, along with the extent to which this law is fit for purpose and some outstanding concerns about its application. While data breach notification requirements are likely to be a positive step for data security, further reform is probably necessary to ensure strong cybersecurity. However, such reform should be cognisant of the international trends towards the adoption of data security measures including data breach notification, but lack of alignment in standards, which may be burdensome for entities operating in the transnational data economy.
A perspective is provided in Breach of Trust: CFPB’s Complaint Database Shows Consumers Need Help After Equifax Breach from US Senators Elizabeth Warren, Brian Schatz and Robert Menendez regarding the September 2017 data breach at the global giant whose Australian arm absorbed the controversial Veda credit referencing business.

The report states
On September 7th, 2017, Equifax announced that it had allowed hackers to access the sensitive information of more than 143 million Americans in one of the largest security breaches of consumer data in history. In the wake of that breach, Equifax promised to make things right. Almost immediately, consumers used the Consumer Financial Protection Bureau’s (CFPB) consumer complaint hotline to register problems and concerns with the breach and Equifax’s response to it. This analysis contains the first comprehensive review of consumer complaints in the wake of the Equifax breach. It finds that, in the six months following the breach’s announcement, the CFPB received more than 20,000 complaints from consumers about the impact of the breach, problems with the Equifax response, or other issues with the company – nearly double the amount of complaints received regarding Equifax in the six months prior to the announcement. 
The number and nature of these complaints is particularly important because of public reports that cast doubt upon the CFPB’s investigation of Equifax and the agency’s commitment to assist consumers and address the fallout of the breach. In early February, reports indicated that the CFPB, under the new leadership of Office of Management and Budget (OMB) Director Mick Mulvaney, had declined to collaborate with other regulators in investigating Equifax and may have abandoned its own investigation. While the CFPB has confirmed that an inquiry is still open, reports suggest that the agency has slowed down or stalled the investigation into the Equifax breach and its impact on consumers. 
This report concludes that, based on the thousands of complaints received by the agency, the CFPB should act quickly and aggressively to hold Equifax accountable. Specific findings include:
• In six months between September 7, 2017, when Equifax announced the breach of sensitive consumer information, and March 7, 2018, consumers have filed more than 20,000 complaints regarding Equifax 
• The CFPB received more than 7,000 complaints of improper use of a credit report after the breach, the risks of which jumped after Equifax exposed credit card numbers, birth dates, social security numbers, and other personal information belonging to millions of Americans 
• The CFPB received more than 7,000 complaints of incorrect information on a credit report, a problem made significantly more prevalent by the increased risk of identity theft in the aftermath of the Equifax breach 
• The CFPB received more than 3,000 complaints about Equifax’s inadequate assistance in resolving problems after the breach, highlighting Equifax’s inability or unwillingness to assist consumers with their concerns 
• The CFPB received more than 1,500 complaints regarding Equifax’s credit monitoring services, fraud alerts, security freezes, and other identity theft protection products, demonstrating the company’s inadequate consumer support services in the wake of the breach
Consumers are facing myriad problems even six months after the breach, and continue to seek assistance from the CFPB. Specific complaints reported by consumers included:
• A consumer who had their “opportunity for employment...denied because of [their] Equifax credit report,” and despite apparently proving that fraud had led to the false accounts being placed on their file, was unable to get help after Equifax “re inserted” both accounts onto their report. 
• A consumer who, in the wake of the breach “was redirected to call 6 different phone numbers,” and when they were unable to get additional assistance from Equifax, their finances were “frozen for over a month,” causing them “extreme hardship.” 
• Consumers who were materially injured by Equifax’s negligent cybersecurity and reckless response to the breach. One consumer faced problems with their Equifax credit report that were “damaging [their] credit rating” when they were “in the process of buying a house.” 
• Another consumer who, after learning that their “information was part of the Equifax breach,” was unable to get Equifax to remove fraudulent accounts and inquiries from their report despite trying “multiple times,” even filing a police report over the false accounts listed on their report. 
• Another consumer who complained that Equifax had not contacted them to provide assistance with similar problems, specifically adding that “I have been a victim of identity theft and I have suffered from the credit breach.” 
Equifax continued to keep important information from the public, leaving consumers to fend for themselves. This report provides strong evidence that the CFPB must hold the company accountable and act decisively to protect the millions of consumers harmed by this breach. 
Introduction 
On September 7, 2017, Equifax announced that it had allowed hackers to access the sensitive information of more than 143 million Americans in one of the largest security breaches of consumer data in history. After failing to adopt strict cybersecurity measures to protect valuable consumer data, Equifax then mishandled the aftermath of the breach, failing to properly assist consumers, and in some cases, making the situation even worse. The company waited 40 days to alert consumers and regulators; initially asked that consumers waive their rights to file lawsuits just to receive free credit monitoring services; increased their profits through their partnership with LifeLock because of the ensuing rush for credit protection; and set up frustrating and ineffective call centers and other consumer support measures. 
Five months after the breach, reports indicated that Equifax was continuing to withhold information from the public about the extent of the breach. We still do not fully understand the scope of the harm to consumers or what measures Equifax is taking to avoid such catastrophic failures of cybersecurity and consumer support in the future. 
The Consumer Financial Protection Bureau was established by the Dodd-Frank Wall Street Reform and Consumer Protection Act in order to enforce federal consumer protection laws. The CFPB is responsible for protecting consumers from “unfair, deceptive, or abusive acts and practices.”3 The CFPB also has clear supervisory authority over large consumer reporting agencies, including Equifax. 
In his response to Senator’s Warren’s September 2017 letter to the CFPB, former Director Richard Cordray outlined the bureau’s authority over Equifax and efforts to investigate the breach and assist consumers. He described the CFPB’s “authority...to review the data security practices of financial institutions... to determine whether such practices violate Federal consumer financial laws...which include prohibitions on unfair, deceptive, or abusive acts and practices.” He added that the CFPB “is the only Federal agency that has any supervisory authority over the larger consumer reporting companies.” 
Director Cordray also noted that the “recent breach at Equifax poses an enormous threat to consumers,” and given that risk, informed Senator Warren that the bureau was “currently looking into the data breach and Equifax’s response.” More specifically, he claimed that the bureau was “working with our Federal and state partners to respond to the problems at Equifax,” including through efforts with other banking regulatory agencies. Director Cordray committed that the CFPB would “continue to examine and investigate consumer reporting companies,” adding that “a breach of this magnitude calls for a coordinated response.” 
Despite the severe threat to consumers and the authority and responsibility of the CFPB to investigate and respond to such threats, recent reports indicate that under the control of Office of Management and Budget Director Mick Mulvaney, the agency may have slowed down or stalled its investigation into the Equifax breach. The investigation has reportedly “sputtered since” Mr. Mulvaney took over at the CFPB, because he has “not ordered subpoenas against Equifax or sought sworn testimony from executives,” both of which are “routine steps when launching a full-scale probe.”  Furthermore, reports suggest that the CFPB “rebuffed bank regulators...when they offered to help with on-site exams of credit bureaus,” despite former Director Cordray making it clear that this cooperation was both necessary and welcome. 
In response to our inquiry, Mr. Mulvaney stated that “it is a matter of public record that the Bureau is looking into Equifax’s data breach and response,” and that any claims that there is no such investigation “are incorrect.” But Mr. Mulvaney did not specify whether the reporting about the sluggishness of his investigation is correct. Mr. Mulvaney also did not comment on whether the CFPB had stopped examining credit bureaus, or whether it had rejected offers of assistance from other bank regulators. 
Mr. Mulvaney has stated that the bureau “will be focusing on quantifiable and unavoidable harm to the consumer,” and that “quantitative analysis” would drive the work, stating, “there’s a lot more math in our future.”  Mr. Mulvaney also told his employees that “we will be prioritizing[,]” – and specifically cited – the number of complaints received on certain issues as a factor that would determine investigative priorities.  The CFPB’s consumer complaint database collects complaints from consumers around the country on a variety of issues, offering a quantitative look at the problems plaguing consumers. As Mr. Mulvaney noted, the database should serve as a guide for the bureau. 
This report does the math. It analyzes data and individual complaints from the CFPB’s consumer complaint database in order to determine the extent of the impact of the Equifax breach on consumers, the effectiveness of the CFPB response, and whether this data justified a CFPB investigation. Staff reviewed complaints that mention “Equifax” between September 7, 2017, the day the breach was announced, and March 7, 2018. Staff also read through individual complaints to understand the issues facing consumers. 
Findings 
The results of this staff review of CFPB complaints about Equifax reveal that consumers filed 21,921 complaints in the six months after Equifax announced the massive breach of consumer data – nearly double the amount of complaints related to Equifax in the six months preceding the announcement – and more complaints arrive every day. And while complaints regarding Equifax nearly doubled, consumer complaints filed regarding the company’s competitors, TransUnion and Experian, remained roughly the same or increased only slightly during the same period. 
From September 7, 2017 through March 7, 2018 – the six months after Equifax announced the breach – consumers filed 21,921 complaints regarding Equifax.  In the six months prior to the announcement, consumer filed only 11,973 complaints.

ASIO Questioning and Detention Powers

The report by the Parliamentary Joint Committee of Intelligence and Security on its review of the operation, effectiveness and implications of Division 3 of Part III (the questioning and detention powers) of the Australian Security Intelligence Organisation Act 1979 (Cth) considers
whether there is a need for an ASIO questioning power in the current security context, and the interaction of ASIO’s questioning and detention powers with other counter-terrorism powers that have more recently been introduced.
Those powers were discussed in ‘The Extraordinary Questioning and Detention Powers of the Australian Security Intelligence Organisation’ by Lisa Burton, Nicola McGarrity and George Williams in (2012) 36(2) Melbourne University Law Review noted here

Under
Division 3 of Part III of the Act allows ASIO, upon obtaining a warrant, to question a person under compulsion in order to obtain intelligence that is important in relation to a terrorism offence. With the Attorney-General’s consent, ASIO may request either a questioning warrant (QW) or a questioning and detention warrant (QDW) from an issuing authority (a judge acting in a personal capacity). Both warrant types require the person to appear before a prescribed authority for questioning in relation to the relevant terrorism offence/s. Under a QDW police officers take the person into custody and detain that person; under a QW the person is not initially apprehended or detained, instead appearing for questioning at a specified time. QDWs may be obtained where there are reasonable grounds for believing that, if the person is not immediately detained, the person may alert someone involved in a terrorism offence, may not appear for questioning, or may destroy or damage relevant records or things; and that relying on other methods of collecting that intelligence would be ineffective. 
The prescribed authority controls the questioning and detention process and may make a range of directions, including to detain the person or defer (or extend) questioning. Questioning may occur for up to eight hours, but this can be extended on request up to a maximum of 24 hours (or 48 hours if using an interpreter).7 Under a QDW, the person is detained until either the questioning has ceased, the above maximum questioning period is reached, or 168 hours (7 days) has passed from the time the person was brought before the prescribed authority, whichever is the earliest. 
During questioning, the person must provide any information, records or things requested. There is no privilege against self-incrimination—the person must answer the questions or produce the requested things even though it may incriminate them; however, any information provided cannot be used against the person in a criminal proceeding
The report notes
A range of safeguards apply. The [Inspector-GeneraI of Intelligence and Security] IGIS must be provided with a copy of any warrant requests, issued warrants, recordings made of questioning, and details of actions undertaken pursuant to a warrant. The IGIS may be present when a person is taken into custody under a QDW and during questioning under either warrant type.  The IGIS may raise concerns about any impropriety or illegality under the warrant and the prescribed authority must consider those concerns and may suspend questioning and other processes until the concerns are addressed. If the person wishes to make a complaint to the IGIS or the Ombudsman, then the person must be given facilities to enable them to make the complaint. 
The person may contact a lawyer. However, the person may be prevented from contacting a particular lawyer if the person is in detention and the prescribed authority is satisfied, on the basis of circumstances relating to that lawyer, that contacting that lawyer would mean:
a. a person involved in a terrorism offence may be alerted that the offence is being investigated; or 
b. a record or thing that the person may be requested to produce in accordance with the warrant may be destroyed, damaged or altered. 
A person’s contact with their lawyer can be monitored by ASIO. Reasonable opportunities must be provided for the lawyer to advise the person, and the lawyer may request permission to address the prescribed authority during breaks in questioning. The lawyer may not, however, intervene in the questioning or address the prescribed authority during questioning, except to clarify an ambiguous question. If the lawyer fails to comply with these restrictions, and is considered by the prescribed authority to be unduly disruptive of the questioning, the lawyer may be removed. If removed, the prescribed authority must permit the person to contact another lawyer. 
A range of criminal offences apply for non-compliance with the warrant, including for when the person fails to appear for questioning, makes a false statement, or fails to answer a question. Persons who commit these offences face a five year term of imprisonment. 
Secrecy offences also apply. During the life of a warrant, the person and their lawyer must not, on a strict liability basis, disclose the existence of the warrant, the fact of the questioning or detention or any operational information. In the two years following the expiry of the warrant, the person and lawyer also must not, on a strict liability basis, disclose any operational information obtained as a result of the questioning. The penalty for either offence is five years imprisonment
 The Committee makes four recommendations
R1 that the Australian Security Intelligence Organisation retains a compulsory questioning power under the Act. 
R2 that ASIO’s current detention powers, as set out in Division 3 of Part III of the Act, be repealed. 
R3 that the Government develop legislation for a reformed ASIO compulsory questioning framework, and refer this legislation to the Committee for inquiry and report. The Committee further recommends that proposed legislation be introduced by the end of 2018 and that the Committee be asked to report to the Parliament no sooner than three months following introduction. The Committee considers any proposed legislation should include an appropriate sunset clause. 
R4 that the Act be amended to extend the sunset date of 7 September 2018 by 12 months to allow sufficient time for legislation to be developed and reviewe

08 May 2018

National Security, Risk and Migration Vetting

'Extreme Vetting of Immigrants: Estimating Terrorism Vetting Failures', a Cato study by David J. Bier, comments
President Donald Trump has promised to implement “extreme vetting” of immigrants and foreign travelers, asserting that wide-spread vetting failures had allowed many ter- rorists to enter the United States. This policy analysis provides the first estimate of the number of ter- rorism vetting failures, both before and after the vetting enhancements implemented in response to the September 11, 2001, attacks. Vetting failures are rare and have become much rarer since 9/11.
A terrorism vetting failure occurs when a foreigner is granted entry to the United States who had terrorist associations or sympathies and who later committed a terrorism offense including support for terrorist groups abroad. This analysis defines vetting failure broadly to include individuals who had privately held extremist views before entry. Moreover, unless evidence exists to the contrary, it assumes that anyone who entered the United States legally either as an adult or older teenager, and who was charged with a terrorism offense within a decade of entry, entered as a result of a vetting failure, even without any evidence that he or she was radicalized prior to entry.
By this definition, only 13 people — 2 percent of the 531 individuals convicted of terrorism offenses or killed while committing an offense since 9/11 — entered due to a vetting failure in the post-9/11 security system. There were 52 vetting failures in the 15 years leading up to 9/11, four times as many as in the 15 years since the attacks. From 2002 to 2016, the vetting system failed and permitted the entry of 1 radicalized terrorist for every 29 million visa or status approvals. This rate was 84 percent lower than during the 15-year period leading up to the 9/11 attacks. Only 1 of the 13 post-9/11 vetting failures resulted in a deadly attack in the United States. Thus, the rate for deadly terrorists was 1 for every 379 million visa or status approvals from 2002 through 2016.
During this same period, the chance of an American being killed in an attack committed by a terrorist who entered as a result of a vetting failure was 1 in 328 million per year. The risk from vetting failures was 99.5 percent lower during this period than during the 15-year period from 1987 to 2001. The evidence indicates that the U.S. vetting system is already “extreme” enough to handle the challenge of foreign terrorist infiltration.

Homeopathy in Australian Pharmacies

The national Government has released its response to last year's Final Report of the Review of Pharmacy Remuneration and Regulation.

The response is of particular interest for disengagement regarding the sale and promotion of homeopathic products, which - as noted in a range of authoritative studies highlighted in this blog (eg here and here) - have no therapeutic efficacy apart from the placebo effect. It is disquieting that pharmacists continue to sell 'medications' in which it is impossible to detect a pharmacologically active agent. That practice, and the Commonwealth's response (an embodiment of regulatory capture), tells us something useful about health policy and about regulation, which we can contextualise through reference to the failures of ASIC, TGA, APRA and the OAIC evident in current reporting of for example the Hayne Royal Commission.

The response states
The Government responds to the Report in accordance with meeting its obligations under the Sixth Community Pharmacy Agreement (6CPA). The independent Review upholds a commitment made between the Australian Government and the Pharmacy Guild of Australia (the Guild), during negotiations of the 6CPA in 2015, to conduct a comprehensive review of pharmacy remuneration and regulation.
The Terms of Reference for the Review provided that it would make recommendations on the future remuneration, regulation including pharmacy location rules and other arrangements that apply to pharmacy and wholesalers for the dispensing of medicines and other services, including preparation of infusions or injections for chemotherapy, provided under the Pharmaceutical Benefits Scheme (PBS), to ensure consumers have reliable and affordable access to medicines.
In November 2015, the then Minister for Health, the Hon Sussan Ley MP, appointed Professor Stephen King to chair a panel of three eminent independent reviewers to undertake the Review. Other members appointed to the Review Panel were Ms Jo Watson and Mr Bill Scott. The Government acknowledges the comprehensive consultation, analysis and strategic thinking undertaken by the Review Panel in delivering the Report.
The Government notes that the Report has been informed by an extensive public consultation process and gratefully acknowledges the input of all individuals and organisations who contributed their knowledge, expertise and vision to the Review.
The Report notes that Australia’s pharmacy sector is evolving and adapting to change – it is in the midst of transition from a product supply focus to one which is more patient-centred and adaptive to an outcomes-based approach to the optimal use of medicines – and that this trend is also occurring internationally.
The Government notes that a number of recommendations of the Review complement work that has already been undertaken, or is in progress by Government and/or other organisations, agencies or jurisdictions to progress issues that support community pharmacy with this transition. Other recommendations of the Review will require further investigation by Government. The Government recognises the pivotal role of the community pharmacy sector in delivering medicines to Australian patients. The Government is committed to working closely with community pharmacies and other stakeholders to address the significant pressures being placed on the health system, including a growing burden of chronic disease, an ageing population, and growing demand for high-cost, high-tech services and breakthrough medicines.
xxx The 6CPA between the Government and the Guild provides approximately $18.9 billion to more than 5,700 community pharmacies for dispensing PBS medicines, providing pharmacy programs and services and for the Community Service Obligation (CSO) arrangements with pharmaceutical wholesalers.
The 6CPA, which operates until 30 June 2020, supports Australia’s National Medicines Policy and the sustainability of the PBS, contributes to the Government’s investment in new medicine listings (since coming into Government in September 2013, the Coalition has added around $8.2 billion worth of medicines to the PBS) and provides greater certainty of Government revenue to community pharmacies, in an environment of ongoing medicine price reductions associated with price disclosure.
In May 2017, the Government entered into a compact with the Guild to strengthen the PBS. As part of the 2017-18 Budget measure Improving Access to Medicines – support for community pharmacies, the Government is providing $825 million over three years from 2017–18 to support and improve Australians’ access to medicines.
This funding includes an additional $210 million over three years to community pharmacies and $15 million to pharmaceutical wholesalers in response to lower than forecast prescription volumes and in recognition of the impact of the package of price reduction policies outlined in the Budget measure. As part of the 2017-18 Budget measure, the Government is also providing $600 million in funding to community pharmacy for new and expanded community pharmacy programs delivered under the 6CPA. This funding will enable pharmacies to offer new or expanded services to consumers, including home visits by pharmacists, helping patients with their medication, and supporting Health Care Homes (HCH) with medicine management. The Government undertakes to work collaboratively with the Guild and other key stakeholders to maintain the community pharmacy model and to secure a viable community pharmacy sector that continues to meet the needs of consumers into the future.
The recommendations in the report cover
 2-1: PBS Pricing Variations. 
2-2: The $1 Discount. 
2-3: PBS Safety Net 
2-4: Pharmacy Atlas 
2-5: Consumer Medicines Information. 
2-6: Electronic Prescriptions . 
2-7: Electronic Medications Record 
2-8: Electronic Prescriptions — Consumer Choice 
3-1: Access to Medicines Programs for Indigenous Australians 
3-2: Pharmacy Ownership and Operation by an Aboriginal Health Service 
3-3: Patient Labelling of Medicines under Bulk Supply Arrangements 
3-4: Machine Dispensing 
4-1: Community Pharmacy — Minimum Services 
4-2: Complementary Medicines in Community Pharmacy 
4-3: Placement of Scheduled Medicines within a Community Pharmacy 
4-4: Sale of Homeopathic Products in PBS Approved Pharmacies 
5-1: Community Pharmacy Accounting Information (King  and Watson) and Alternative Recommendation 5-1 (Scott) 
5-2: Remuneration to be based on the Cost of Dispensing Services Associated with a Best Practice Pharmacy Model (King and Watson)  and Alternative Recommendation (Scott) 
5-3: Remuneration for Dispensing – Methodology (King and Watson) and Alternative Recommendation  (Scott) 
5-4: Remuneration Limits 
5-5: Remuneration for Other Services 
6-1: Reforms to Pharmacy Location Rules 
6-2: Pharmacy Location Rules — Concentration of Ownership 
6-3: Transparency in Government Programs . 
6-4: Rural Pharmacy Maintenance Allowance 
6-5: Harmonising Pharmacy Legislation 
6-6: Evaluation Mechanisms 
7-1: Community Service Obligation 
7-2: A Comprehensive Supply Chain Analysis 
7-3: Supporting Access to High-Cost Medicines 
7-4: Supporting Access to Highly Specialised Medicines 
7-5: Tightening the Listing of Generic Medicine 
8-1: Scope of Community Pharmacy Agreements — Dispensing 
8-2: Scope of Community Pharmacy Agreements — Wholesaling 
8-3: Scope of Community Pharmacy Agreements — Programs and Services 
8-4: Community Pharmacy Agreement Participants. 
9-1: Community Pharmacy Programs — Key Principles . 
9-2: Dose Administration Aids — Standards . 
9-3: Home Medicines Review — Removal of Caps 
9-4: Pharmacy Support for Residential Aged Care Facilities 
9-5: Support for Expanded Pharmacy Services Identified by Pharmacy Trial Program 
10-1: Chemotherapy Compounding — Uniform Minimum Standards 
10-2: Chemotherapy Compounding — Payments. 
10-3: Chemotherapy Compounding — Practice Models 
11-1: Managing Patient Medicine Risks on Discharge from Hospitals
In relation to Recommendation 4-4: 'Sale of Homeopathic Products in PBS Approved Pharmacies' the report noted
 Homeopathy and homeopathic products should not be sold in PBS-approved pharmacies. This requirement should be referenced and enforced through relevant policies, standards and guidelines issued by professional pharmacy bodies. 
The Government response is
The Government notes this recommendation. 
The Government notes the importance of the provision of information to consumers for all medicines and health related products available through community pharmacy. 
Professional standards have been designed for use by individual pharmacists to assess their own professional practice. They are intended to serve as guidance for desired standards of practice. However, it is the sole responsibility of the individual pharmacist to determine, in all circumstances, whether a higher standard is required. It is equally their  responsibility to meet that standard and ensure that consumers are provided with the best available information about the current evidence for, or lack-of efficacy in, offered treatments and therapies. 
As in relation to Recommendation 4-2, the Government has accepted the recommendations of the independent RMMDR reforming the regulation of complementary medicines in Australia.
The report's recommendation regarding 4-2 was
Community pharmacists are encouraged to:
a. display complementary medicines for sale in a separate area where customers can easily access a pharmacist for appropriate advice on their selection and use; and 
b. provide appropriate information to consumers on the extent of, or limitations to, the evidence of efficacy of complementary medicines. This could be achieved through the provision of appropriate signage within the pharmacy (in the area in which these products are sold), directing consumers to ‘ask the pharmacist for advice’ if required.
The Government has endorsed a regime where pharmacies - increasingly owned by chains - are free to sell what would be acerbically characterised as snake oil on the basis that a pharmacist is on the premises and thus available to answer any question about whether the pills, potion or salve will work.

Crypto

The US National Academies study Decrypting the Encryption Debate: A Framework for Decision Makers states
Encryption protects information stored on smartphones, laptops, and other devices—in some cases by default. Encrypted communications are provided by widely used computing devices and services — such as smart-phones, laptops, and messaging applications — that are used by hundreds of millions of users. Individuals, organizations, and governments rely on encryption to counter threats from a wide range of actors, including unsophisticated and sophisticated criminals, foreign intelligence agencies, and repressive governments. Encryption on its own does not solve the challenge of providing effective security for data and systems, but it is an important tool.
At the same time, encryption is relied on by criminals to avoid investigation and prosecution, including criminals who may unknowingly benefit from default settings as well as those who deliberately use encryption. Thus, encryption complicates law enforcement and intelligence investigations. When communications are encrypted “end to end,” intercepted messages cannot be understood. When a smartphone is locked and encrypted, the contents cannot be read if the phone is seized by investigators.
Yet even while the use of encryption is increasing, so is the amount of unencrypted stored data and communications and metadata. This is a result of the growth in the use of smartphones, social networks, text messaging, and other computing and electronic communications over the past decade. The result of the rise in both the amount of data and the use of encryption is that as the amount of data increases rapidly, there is both more data than ever of relevance to investigations and more data than ever that is inaccessible to investigators. With increasing use of encryption, often by default, law enforce- ment and some intelligence officials have increasingly called for a reliable and sufficiently rapid and scalable way to access plaintext—decrypted data and messages—so that they can protect the public and fulfill their public safety and national security missions. In particular, law enforce- ment officials point to
(1) the widespread and increasing use of encryp- tion by default in widely used products and services, 
(2) the myriad national security threats posed by terrorist groups and foreign rivals, (3) the increasing importance of digital evidence as human activity and crime have become increasingly digital, and 
(4) the limited effectiveness of alternative sources of digital evidence.
Critics have objected on a number of legal and practical grounds, arguing that regulations to ensure government access to plaintext likely would
(1) be ineffective, 
(2) pose unacceptable risks to cybersecurity, 
(3) pose unacceptable risks to privacy and civil liberties, 
(4) disadvantage U.S. providers of products and services, and 
(5) hamper innovation in encryption technologies.
In addition, critics argue that mandating means for ensuring government access to plaintext may be less necessary in light of the wider availability of data — and especially metadata —generally, and the alternative means currently available for government officials to obtain access to encrypted data.
There are a wide variety of legal and technical options available to governments that seek access to plaintext for law enforcement and intelligence investigations. These include the following:
• Take no legislative action to regulate the use of encryption, 
• Provide law enforcement with additional resources to access plaintext, 
• Enact legislation that requires that device vendors or service providers provide government access to plaintext without specifying the technical means of doing so, and 
• Enact legislation requiring a particular technical approach.
These are discussed in detail in Chapter 5.
Some computer scientists have reacted with concern to renewed proposals to regulate the use of encryption, citing the security risks. Several attempts have also been made in recent years to develop technical mecha- nisms to provide the government with exceptional access to encrypted data on locked devices and to encrypted communications that would minimize these risks. Three were presented to the Committee on Law Enforcement and Intelligence Access to Plaintext Information during its work (Box 5.1). The committee was not charged with reviewing specific proposals, but it did use these specific proposals to help develop and test its framework for evaluating suggested approaches.
The committee offers a framework (in the form of a set of questions) to ask about any path forward on encryption policy. The objective of this framework is not only to help policymakers determine whether a particular approach is optimal or desirable, but also to help ensure that any approach that policymakers might pursue is implemented in a way that maximizes its effectiveness while minimizing harmful side effects. The questions are as follows:
1. To what extent will the proposed approach be effective in permit- ting law enforcement and/or the intelligence community to access plain-text at or near the scale, timeliness, and reliability that proponents seek? 
2. To what extent will the proposed approach affect the security of the type of data or device to which access would be required, as well as cybersecurity more broadly? 
3. To what extent will the proposed approach affect the privacy, civil liberties, and human rights of targeted individuals and others? 
4. To what extent will the proposed approach affect commerce, economic competitiveness, and innovation? 
5. To what extent will financial costs be imposed by the proposed approach, and who will bear them? 
6. To what extent is the proposed approach consistent with existing law and other government priorities? 
7. To what extent will the international context affect the pro- posed approach, and what will be the impact of the proposed approach internationally? 
8. To what extent will the proposed approach be subject to effective ongoing evaluation and oversight?
In addressing these questions, policymakers will have to contend with incomplete data about the impact of encryption on investigations as well as incomplete data about the deliberate use of encryption by criminals. It is also difficult to quantify key factors such as the additional security risks of adding exceptional access to encryption systems. There are also a number of cases where one can only speculate about future behaviors that have bearing on the implications of government regulation of encryption. These include the fraction of criminals that would use noncompliant, unbreakable encryption if the government were to require vendors to provide exceptional access and the fraction of foreign customers that would eschew U.S. products if exceptional access were required.
Policymakers will also have to contend with the trade-offs associated with encryption and government access that underlie these questions. One of the fundamental trade-offs is that adding an exceptional access capability to encryption schemes necessarily weakens their security to some degree, while the absence of an exceptional access mechanism necessarily hampers government investigations to some degree. How much security is reduced and whether the resulting level of security remains acceptable depend on the specific technical and operational details of the exceptional access mechanism and on the requirements and perspectives of users. The impact on society when an investigation is hindered or thwarted will depend on the scope and scale of the associated crime or national security threat.
There are no easy answers to and many uncertainties in responding to these questions. However, developing and debating answers to these questions will help illuminate the underlying issues and trade-offs and help inform the debate over government access to plaintext.