|
|
|||||
Privacy and open government: conversations with EPIC and others about OpenIDA few days ago I proposed a way to offer more privacy to people visiting government web sites. This blog builds on that proposal, which was largely technical, by examining the policy and organizational issues that swirl around it. My ideas are informed by a discussion I had with Lillie Coney, Associate Director of the Electronic Privacy Information Center. The blog is also inspired by two comments on the earlier blog and brief email I exchanged with one commenter, which intertwine with Coney's in intriguing ways. As I said in the first blog, my proposal focused on a very narrow question driven by the Obama Administration's interest in revising a memorandum from 2000 concerning the use of cookies in web browsers. The proposal suggested a way to better approach anonymity, but didn't look at the related social and political issues:
This blog offers a number of points about those issues. The sections are:
Can the government be your friend?The kinds of government/public collaboration pursued by CIO Vivek Kundra and others in the Obama administration sees people doing much more than submitting ideas. The administration wants information sharing and an exchange of ideas that allow both sides to reveal vulnerabilities. But as one commenter pointed out on my previous blog, the government has a lot of power that should make us hesitate before sharing too much. Coney, whose work at EPIC includes a focus on domestic surveillance, pointed to an incident where the Las Vegas Review-Journal was served a subpoena requiring it identify readers who had posted online comments about an article involving a case with the Internal Revenue Service. (The newspaper is fighting the subpoena.) Some agencies have enough power to be scary. And some agency heads may take heavy-handed measures without even being malicious or vindictive--just out of a concern for security. So you may be living it up like Obama, Gates, and Crowley on one agency's web site, forming great relationships and having an extremely productive discussion, only to discover that your comments come back to bite you when you tussle with an entirely different agency. And of course, the data you give these sites lasts forever. Such promiscuous information sharing is supposedly outlawed by the 1974 Federal Privacy Act. This oft-cited law, along with the 1966 Freedom of Information Act, remain centerpieces in the armory of those protecting personal privacy in the U.S. However, the Federal Privacy Act creates many exceptions for agencies that want to opt out from its rules, and fails to cover private contractors. Coney says, "EPIC's goal is to develop fair information practices that are enforceable and transparent to protect users of government information." Having studied the privacy policies requested by different agencies, Coney finds them in two camps. Agencies whose mission is to reach and out and help people, such as the Department of Health and Human Services, favored as much privacy as possible--the same goal Kundra has expressed many times. On the other hand, law enforcement and other agencies concerned with protecting the public would like to log all accesses and try to attach personal information to all visits--even access to public information. That last policy puzzles me. If the government offers information freely, Carl Malamud or I or anybody can grab it and put it on another web site. There is no way to track who accesses free and open information. Tracking access in the hope of preventing criminal use is not only obnoxious but futile. In short, forming a partnership with government takes a bit more consideration than friending someone on Facebook. The new age of government participation we're hearing about, then, rests on some assurances to the public. Personal information should not be collected unless absolutely necessary, and should not be used for purposes unrelated to the reason for capturing it, especially by other government entities. We're all excited about the expanding collaboration between government and citizens, but the historic change intensifies the need to take a fresh look at laws and policies on a regular basis, just as the OMB has done in requesting comments on their cookie policy. Anonymity, pseudonymity, and participationPeople phone anonymous tips in to the police all the time. To allow the same kind of anonymity online would be just an invitation to spam. In fact, anyone with something to hide would make sure to flood the system with irresponsible accusations just to drown out the people who have legitimate crimes to report. (The FBI tip site asks you to identify yourself.) The proposal in my previous blog delivers pretty good pseudonymity, allowing someone to submit repeated comments with the assurance that they all come from the same person, but without surrendering personal information. One commenter on my blog asked whether we can really trust the government to protect pseudonymity. Well, of course they can always trace you if they want to. Even non-government actors can do that, as we've just seen from the recording industry's testimony at Joel Tenenbaum's trial. Privacy is a cat-and-mouse game in which both sides have escalating levels of attacks and parries.
Who should run an OpenID server?From this point on, I'll assume that OpenID will be used by federal agencies in some configuration, because that's the only technology with a widespread implementation that can provide the protections discussed in this blog. One of the central policy questions we have to deal with, then, is whom we should trust with our OpenID account. My proposal called on the federal government to run an OpenID server for all its agencies, mostly because I want the government to kick the habit of using commercial services for such essential information-age functions. (See my earlier blogs, Five projects for Open Source for America and themes from the Personal Democracy Forum conference.) Coney and I discussed several options for ensuring reliable servers. There's no reason not to allow multiple options. Running an OpenID server is pretty easy. If EPIC had a hankering to serve up privacy directly, this is its chance. The problem is whether visitors can trust any particular server 1) to stay up, 2) not to go out of business, 3) not to leak information, 4) not to abuse the information for private gain, and 5) not to cave in to government pressure and release information outside of the scope of the law. Here are a few options.
As usual, the policy, organizational, and social issues in deploying a technology are thornier than the technology itself. I still think the architecture I offered in my proposal to OMB provides a good basis for building any of the systems considered in this blog. Thought experiment: could federal agencies offer anonymous authentication for whistle-blowers?I'll end this blog by exploring an identity system that would allow an agency to authenticate a pseudonymous whistle-blower by verifying "Yes, this is a current employee" or "Yes, this is a former employee" without giving further information about that individual. I believe that any such authentication system would have to be based on a two-tier approach such as I laid out in my OpenID proposal. The system I lay out in this section is too complex, organizationally and technically, for the government to implement at this point, but it shows the tools available to privacy advocates.
In order to masquerade as an agency employee, someone would have to obtain both the employee's signed string and access to the employee's secret account on the OpenID server. This might be possible if the employee is lax in protecting the information (for instance, by putting it unencrypted on a cell phone and losing it). Other problems with this system include:
Technology confers power, and so does anonymity. Technical, legal, and policy experts are all needed to study the implications of the systems we have for participation, and the systems that are proposed to replace them. |
|||||
|
|||||
Comments: 2
Scott Burns [10 August 2009 08:11 PM]
Thank you for the thoughtful post on this important issue.
I'm the co-founder of a company (GovDelivery) that helps government agencies gather email address and other contact information from the public in order to provide outbound alerting services. We find that people are very trusting of the government and signup in large numbers as long as they understand what they are going to receive (given lots of choice) and aren't asked for unnecessary information.
The old thinking on ID systems in government was to create a master/massive "single sign-on" effort. I'm glad that OpenID exists and is now such an obvious and more practical solution to this age-old problem.
If the government thoughtfully plans and sets things in motion against this open standard, OpenID could be a real home run in the public sector. I know our company is ready to embrace it and that many of our clients and the citizens they serve would see it as a nice benefit.
Because we work with 13 of 15 federal agencies and many state and local governments, we could help put OpenID into broad use very quickly if the federal government put its support behind one or more of the approaches you outline.
I'm not an OpenID expert, but whatever approach is chosen, my only major concern is that users can easily bypass any onerous requirements for creating a detailed profile to make use of OpenID. If the amount of information required gets to great, I worry that what we call "impulse buys" (someone sees a health tip on the CDC website and quickly signs up for updates) could become so cumbersome that signup rates would plummet.
Your approach of thinking through the use cases and the pros and cons is a good one for ensuring that we don't take one step forward and two steps back.
-Scott Burns
www.twitter.com/smburns
www.govdelivery.com
SEO [16 November 2009 12:53 PM]
This is fantastic. Here’s to open government and the open web! I believe OpenID will continue to be the most convenient and trustworthy open identity standard on the Web. Open standards create a better Internet for everyone, and the U.S. government's adoption of OpenID is a huge endorsement of OpenID and a big step forward for open standards. From SEO Rider