Showing posts with label Internet Communications Surveillance. Show all posts
Showing posts with label Internet Communications Surveillance. Show all posts

Friday, 30 September 2016

HISTORICAL CELL SITE LOCATION INFORMATION AND TELCOS IN NIGERIA


According to Wikipedia.com, a telco i.e. telephone company, telephone service provider or telecommunications operator:
is a kind of communications service provider (CSP) (more precisely a telecommunications service provider or TSP) that provides telecommunications services such as telephony and data communications access…With the advent of mobile telephony, telephone companies now include wireless carriers, or mobile network operators. Most telephone companies now also function as internet service providers (ISPs), and the distinction between a telephone company and an ISP may disappear completely over time, as the current trend for supplier convergence in the industry continues.

Historical cell site location information or mobile/cell phone location data is a collection of past connections between a mobile phone and cell towers or telecommunications masts. A cell site is mobile phone base station or antenna where radio signals are sent and received. In  the United States case of State v. Earls, it was stated that “Cell or (mobile) phones register or identify themselves with nearby cell towers every seven seconds. Cell providers (like MTN, Glo, Etisalat and Airtel in Nigeria) collect data from those contacts, which allow carriers to locate cell phones on a real-time basis and to reconstruct a phone’s movement from recorded data.”

Most times when you call the call centre of your GSM network provider or telco in Nigeria such MTN, Glo, Etisalat or Airtel, to make a complaint or inquiry, the customer care representative will ask you what town or city and local government you are calling from. I am usually taken aback by this question because they (telcos) already know or at least can approximate my location so why bother to ask me.

Whenever a mobile telephone makes a call, the call is routed through a cell site located at a fixed geographic location. Mobile telephone companies keep records of which cell site processes a call, and through this information law enforcement agents can locate the position of the SIM card, and therefore infer the location of the telephone user. This was used by the Nigerian Police to obtain the location of Timothy Dung, an armed robbery suspect in the case of The State v. Timothy Dung. On page three of the judgement it was stated thus:
According to the PW2 on the 20/8/2010 a case of armed robbery was transferred from the ‘E’ Division Police Station to the State Criminal Investigation Department (CID). PW1 volunteered a statement before the police.
According to the PW2 they swung into action by applying their detective mechanism to arrest the person because the line snatched was still going. Police applied to court to obtain a court order to serve Airtel/Zain who was the service provider of the line (Zain) snatched from the PW1. Airtel/Zain complied with the court order and released the coordinate to the Police. The coordinate enabled the Police to set a security trapping system that showed them the exact direction and position where the accused (that) was using that particular line at that time was standing. The system gave the latitude and longitude on google earth. lt shows(sic) that the accused person who was with the stolen line was at Abuja and the call history of the line after the robbery was within Abuja town and a town in Plateau State.  However, about three' days back, the line was showing that it, was in Abuja. The Police went to Abuja and the system directed them to Federal Fire Service in Abuja town and they went there. When the PW2 and his team called the number/line, it rang and the accused received the call. The PW2 then arrested the accused and interviewed him.
The case of United States v. Allums, also shows that telcos know or can estimate the location of their subscribers or customers at any given time using historical cell site location information (CSLI) or cell site analysis. James Edward Allums on 30th November, 2007, robbed a bank in Salt Lake City, Utah, United States. A bank employee dropped a chair from the second floor balcony onto Allums’ head as he stood brandishing a knife at a teller on the first floor.  In anger Allums removed his ski mask to look up and curse at the chair-dropper and in the process glowered directly into the surveillance camera. Allums had a mobile phone on him on 30th November.

Prosecutors introduced evidence that cell site tracking records showed that Allums’ phone, and presumably Allums, was located in close proximity to the bank and to two other locations also robbed by Allums. Thus, Allums was convicted on three counts of armed robbery.

Apart from historical CSLI mobile phone location can also be determined through GPS and mobile phone triangulation. At this juncture it is appropriate to state how mobile phone communications work as captured or explained in Re: Application for Telephone Information Needed for a Criminal Investigation:
Cell (mobile) phones operate through the use of radio waves.  To facilitate cell phone use, cellular service providers maintain a network of radio base stations—also known as cell towers (popularly referred to in Nigeria as mast)—throughout their coverage areas.
Whenever a cell phone makes or receives a call, sends or receives a text message, or otherwise sends or receives data, the phone connects via radio waves to an antenna on the closest cell tower, generating cell site location information (CSLI).  The resulting CSLI includes the precise location of the cell tower and cell site serving the subject cell phone during each voice call, text message, or data connection.  If a cell phone moves away from the cell tower with which it started a call and closer to another cell tower, the phone connects seamlessly to that next tower.
CSLI may be generated in the absence of user interaction with the cell phone. For example, CSLI may still be generated during an incoming phone call that is not answered.  Additionally, most modern smartphones have applications that continually run in the background, sending and receiving data without a user having to interact with the cell phone.
Indeed, cell phones, when turned on and not in airplane mode, are always scanning their network’s cellular environment. In so doing, cell phones periodically identify themselves to the closest cell tower—i.e., the one with the strongest radio signal—as they move throughout their network’s coverage area.  This process, known as “registration” or “pinging,” facilitates the making and receiving of calls, the sending and receiving of text messages, and the sending and receiving of cell phone data. Pinging is automatic and occurs whenever the phone is on, without the user’s input or control. A cell phone that is switched on will ping the nearest tower every seven to nine minutes. (Emphasis mine)
From the above it is crystal clear that CSLI can be used to estimate the location of an individual by identifying the nearest cell tower or mast and sector used when a call is made. It therefore presents circumstantial evidence of a person’s location.  This ability to locate a cell phone presents obvious benefits to law enforcement and intelligence authorities  as seen in the two cases referred to above. CSLI also poses a significant threat to privacy. Thus in State v. Earls (supra) the court observed that:
Advances in technology offer great benefits to society in many areas. At the same time, they can pose significant risks to individual privacy rights. This case highlights both principles as we consider recent strides in cell-phone technology. New improvements not only expand our ability to communicate with one another and access the Internet, but the cell phones we carry can also serve as powerful tracking devices able to pinpoint our movements with remarkable precision and accuracy.

Tuesday, 28 June 2016

WILL THE DEATH OF PRIVACY GUARANTEE BETTER SECURITY OF LIVES AND PROPERTY FOR ALL OF US?


With every terrorist attack in the West legislators and law enforcement authorities call for laws (or amendment of extant laws) for increased surveillance of citizens. This they argue will enhance the capabilities of law enforcement authorities to prevent and where they occur, investigate terrorist attacks.

It has been reported here that: 
The federal government is taking another step it says would make the US homeland safer from terrorism. US border authorities are proposing that millions of tourists entering the country each year reveal their social media identities.
The proposal from US Customs and Border Protection, announced last week in the Federal Register, would add a line to the online or paper form that US-bound visitors must fill out if they don't have a visa and plan on staying for up to 90 days for vacation, business, or other affairs. The agency says travelers coming to the US under the Visa Waiver Program won't be forced to disclose their social media handles, but leaving it blank obviously could raise red flags.
Here's what will be asked: "Please enter information associated with your online presence—Provider/Platform—Social media identifier." 
It has also been reported that "Federal agents (in the US) are planting microphones to secretly record conversations."

Arstechnica also reported that:
Russia's lower house of parliament, the State Duma, has approved a series of new online surveillance measures as part of a wide-ranging anti-terrorism lawAs well as being able to demand access to encrypted services, the authorities will require Russia's telecom companies to store not just metadata, but the actual content of messages too, for a period of six months. Metadata alone must then be held for a total of three years, according to a summary of the new law on the Meduza site. Authorities will be able to access the stored content and metadata information on demand…the legislation still needs to be approved by Russia's upper house, the Federation Council, and signed by President Putin.”
Slowly and gradually our right to privacy is being be eroded. Nigerians may think this is only happening in the US but it is happening at home here in Nigeria too, for e.g. compelling mobile phone users to register their GSM lines and submit biometric data etc. before activation of the lines for use.


See also the Facebook post by one James S. Gbudu claiming to monitor the internet with the hope of riding it of fake social media accounts being used to abuse Nigerians!

It may not be out of place to conclude that the future for privacy looks bleak! I therefore foresee a situation whereby little by little the right to privacy(online and possibly offline) will be gradually eroded until there is no more right to privacy most especially in the name of fighting terrorism and other crimes. This erosion of privacy will be further aided by the coming Internet of Things (IoT).

The question then is; will the DEATH of privacy guarantee better security of lives and property for all of us?


Saturday, 19 March 2016

The Dangers of the Internet of Things (IoT)



Are you ready for a future where not just your smartphone,  desktop, laptop computer or tablet is connected to the Internet but also your cars, electronic appliances(home theatre, TV etc.), lights in household and commercial environments, alarm clocks, speaker systems, washing machines, microwaves, sandwich makers/toasters, blenders etc. are connected to the Internet? 

In the near future, you may no longer need to remember to turn the oven off when the cake is done or switch on lights when you enter a room. Your home will do it for you. These products are part of the Internet of Things (IoT), aimed at automating our lives by connecting mobile devices to appliances, lights, and just about everything.

The Internet of Things (IoT) refers to the ever-growing network of physical objects that feature an IP address for internet connectivity, and the communication that occurs between these objects and other Internet-enabled devices and systems. IoT extends internet connectivity beyond traditional devices like desktop and laptop computers, smartphones and tablets to a diverse range of devices and everyday things that utilize embedded technology to communicate and interact with the external environment, all via the Internet.

Simply put, IoT is a computing concept that describes a future where every day physical objects will be connected to the Internet and be able to identify themselves to other devices. Most of us think about being connected in terms of computers, tablets and smartphones. IoT describes a world where just about anything can be connected and communicate in an intelligent fashion. In other words, with the IoT, the physical world will become one big information system.

It describes a situation where everything in our surrounding environment is made capable of automatically communicating with each other without any inter-human or human-to-machine interaction. Apart from the fact that it is a path-breaking discovery, it can also prove to be extremely beneficial in facilitating our lives to manifolds.

Despite the enormous benefits, IoT might raise some privacy and security concerns. The risks inherent in our Internet-connected lives and IoT are brought into sharp focus by the movie: Ratter. Ratter is an acronym for a type of malware known as a Remote Access Trojan, an unwittingly downloaded program that provides a hacker with undetected access to a user’s Internet-enabled devices. The ratter can then manipulate programs and files, as well as operate camera and microphone functions, enabling video and audio access to the victim’s activities.

In the movie; Ratter, Emma is determined to make a fresh start as she moves from the Midwest of America to rent a spacious apartment in Brooklyn, New York and begin grad school, Emma never suspects that everything she does within view of her laptop, phone or webcam is being watched and recorded by an unknown stalker who has electronically hijacked her devices. Whether she’s prepping meals in her kitchen, settling into bed at night or showering with her laptop playing music in the background, Emma’s always-online lifestyle is fully revealed to the ratter.

At the same time, she begins receiving random blocked calls and text messages, which her friend Nicole dismisses as typical misdialed numbers and tech glitches. When her laptop starts acting up, Emma takes it to a repair shop but apparently there’s nothing amiss, although she does change her passwords as a precaution. An unexpected call from a blocked number turns out to be her jilted, bitter ex-boyfriend Alex, leading Emma to wonder if he’s the one who’s been anonymously harassing her.

She dismisses the thought however, since things are going so well with Michael, the new guy she’s been dating, until an online chat session becomes way too creepy and Emma breaks things off, concerned that even he might be targeting her. It’s all part of the ratter’s escalating plan to isolate her from friends and family, even as he becomes more aggressive, breaking into her apartment and observing her while she sleeps. As his threatening behavior escalates and Emma’s stress level spikes, her parents urge her to move to a new apartment, but with the ratter monitoring her every move, message and phone call, a change of location isn’t likely to provide much respite or increased security.

In a selfie-obsessed culture motivated by the urge to document everything and perhaps even achieve fleeting viral celebrity, the unpleasant possibilities articulated by the movie, Ratter, are alarmingly immediate and unnervingly reinforced by news accounts of hijacked webcams and hacked cellphones betraying unsuspecting users.



Monday, 29 February 2016

RICKY TARFA (SAN): THE RIGHT TO REMAIN SILENT AND PASSWORD-PROTECTED MOBILE PHONES



 On the 24th of February, 2016 a Senior Advocate of Nigeria, Mr. Rickey Tarfa withdrew an N5billion fundamental rights violation suit he filed against the Economic and Financial Crimes Commission (EFCC) and four other respondents. The senior lawyer had filed the suit, alleging violation of his right to privacy by the respondents

Mr. Tarfa in the suit sought a court declaration that his right to privacy was violated when the call records/log on his phone with mobile number 08034600000 was allegedly accessed without his authority and made available to Sahara Reporters and other online news media without any reasonable cause or a lawful court order.

He also urged the court to hold that it was unlawful for his iPhone 6 with mobile number 08034600000 to have been used in calling one Alhaji Ado in Kaduna on mobile number 08061272929 on February 9, 2016 while the said phone was with Magu and the EFCC without any reasonable cause or any court order.

Furthermore, Mr. Tarfa also urged the court to hold that it was unlawful for the EFCC to access his bank details, clients’ information, private and confidential information contained in his iPhone 6 with number 08034600000 and Samsung 6 phone with number 08077341616 without any reasonable cause or any court order.

The writer cannot tell if Mr. Tarfa’s mobile phones were password-protected but assuming he had pass-worded/locked his mobile phones (just like Syed Rizwan Farook, one of the two killers (who were later killed in a shootout with the police) in the December 2, 2015 San Bernardino, California mass shootings, who left behind a pass-worded/locked iPhone 5c whose data the FBI has not been able to get access to) and the EFCC were unable to access the mobile phones either through hacking or guessing his passwords, would it have been lawful for the EFCC to demand from Mr. Tarfa or compel him to provide the passwords to his mobile phones?

The Position of the Law in Nigeria
According to Section 35(2) 1999 Constitution as amended:
“Any  person  who  is  arrested  or  detained  shall  have  right  to  remain silent  or  avoid  answering  any  question  until  after  consultation  with  a legal practitioner or any other person of his own choice”

Section 36(11) further provides that “No person who is tried for a criminal offence shall be compelled to give evidence”. However, section 35(2) is more germane to the issue at hand so this discourse will be limited to the said section.

The import of the section 35(2) is that whenever a suspect is in police custody, his constitutional right to remain silent begins, and this right is to the effect that he cannot be forced or coerced to say a word unless he volunteers to do so as it is the duty of the prosecution to prove its case beyond reasonable doubt. The above position of the law has been upheld by the Supreme Court of Nigeria in the case of Sugh v. State (1988) NWLR (Pt. 77)475. See also Ajudua v. FRN (2014) LPELR-24126(CA) where it was held that an  accused  has the  right  to  remain  silent  as  he  cannot  be forced to make a statement during investigation.

The Position of the Law in the United States
In the United States the general position of the law regarding the right to remain silent or right against compelled self-incrimination is provided for in the Fifth Amendment to the United States Constitution which provides that “No person shall…be compelled in any criminal case to be a witness against himself.”

In the case of Securities and Exchange Commission (SEC) v. Bonan Huang et al (Case 2:15-cv-00269-MAK), the SEC were investigating the defendants who allegedly used insider information associated with their jobs to trade stocks. The SEC suspected the mobile devices were holding evidence of insider trading and demanded (via a motion filed in court) that the defendants turn over their passcodes. The defendants declined supplying their passcodes contending that the Fifth Amendment protected them.  The issue was therefore, whether the defendants could be forced to give up passcodes to devices that were provided by their employer, but secured by passcodes chosen by the employees themselves. The Federal District Court (the Supreme Court has never ruled on the constitutionality of the issue) in Eastern Pennsylvania ruled that the defendants cannot be compelled to give up the passcode to their cell phones as doing so would be equal to giving self-incriminating  testimony.

The Position of the Law in the United Kingdom
The privilege against compelled self-incrimination or the right to remain silent is deeply rooted in the common law. Goddard LJ in Blunt v Park Lane Hotel [1942] 2 KB 53 at 257 stated thus;
"No one is bound to answer any question if the answer thereto would, in the opinion of the judge, have a tendency to expose (him) to any criminal charge, penalty or forfeiture which the judge regards as reasonably likely to be preferred …" 

In Saunders v UK [1996] 23 EHRR 313 it was held that Article 6 of the European Convention of Human Rights guarantees the protection against self-incrimination.
"The right to silence and the right not to incriminate oneself, are generally recognised international standards which lie at the heart of the notion of a fair procedure under article 6….the right not to incriminate oneself, in particular, presupposes that the prosecution in the criminal case seek to prove their case against the accused without resort to evidence obtained through methods of coercion or oppression in defiance of the will of the accused. In this sense the right is closely linked to the presumption of innocence contained in article 6(2)".

However, the right is subject to numerous statutory exceptions which limit, amend, or abrogate the privilege in specified circumstances. Therefore, despite the privilege, individuals may sometimes be required to answer questions or provide information or documents which may incriminate them. For instance the Regulation of Investigatory Powers Act 2000 (RIPA), Part III, activated by ministerial order in October 2007, requires persons to supply decrypted information and/or keys/passwords to government representatives or law enforcement agents with a court order. Failure to disclose carries a maximum penalty of two years in jail. Thus, under the provisions of the RIPA Syed Hussain was convicted of failing to provide police with the password to the USB memory stick seized in a counter-terrorism operation. When Hussain was arrested in April 2012, police seized a USB memory stick from his home - but they discovered the information on the device was protected by sophisticated encryption technology. Hussain told detectives that he could not remember the password because he was suffering from stress – which meant they could not access its contents. Police called in experts from GCHQ, the government's secret eavesdropping and communications agency, but even they were unable to crack the device.

Oliver Drage, a 19-year old was arrested as part of an investigation into child sexual abuse images. His computer was seized by police who were unable to access some material on it thanks to a 50-character encryption password. Police formally requested the password from Drage, he refused to co-operate, an offence under the RIPA. He was accordingly sentenced to 16 weeks in a young offenders’ institution for refusing to give police the password to an encrypted file on his computer. See-

Conclusion
Considering the position or state of the law in Nigeria it may be safe to conclude that if Mr. Tarfa’s mobile phones were locked or pass-worded, the EFCC would have acted outside the law or illegally if they compelled Mr. Tarfa to disclose the passwords to his mobile phones which they seized. This is so as to the best of the writer’s knowledge there is no exception to the right to remain silent under Nigerian law; unlike the position in the UK, during interrogation in the custody of law enforcement agents.

However, as one writer observed:
“Realistically, the right to silence has a low value and not really exercised by most suspects. Only a suspect who knows the law and the right well would exercise the right as most people would not be able to withstand the mental pressures during the interrogation. False evidences, lies, isolation and many other psychological tactics are practiced to make the suspect confess the crime. As a result of this, many false confessions happen due to unbearable psychological pressures.”

It may therefore, not be out of place to suggest that it would take an extraordinarily strong-willed suspect undergoing interrogation during detention by any of the law enforcement agencies in Nigeria, especially the Nigerian Police who are notorious for torturing suspects in detention, to exercise his right to remain silent as guaranteed by section 35(2) of the 1999 Constitution as amended!

Thursday, 6 June 2013

Internet Communications Surveillance



It appears that governments all over the world are bent on spying on their citizens’ private internet or phone communications from the Middle East to Australia and to Nigeria. On Thursday June 6, 2013 the UK based newspaper; the Guardian released on their website a court order obtained by the National Security Agency (NSA) of U.S. directing Verizon - one of the largest phone companies in the US - to disclose to the NSA the metadata of all calls it processes, both domestic and international, in which at least one party is in the US. Such metadata includes telephone numbers, calling card numbers, the serial numbers of phones used and the time and duration of calls. It does not include the content of a call or the callers' addresses or financial information.


To some it might seem that collecting just metadata and not the contents of the call (what people say to each other when they are on the phone) is not harmful to privacy or freedom of expression and the press. However, such collection could be harmful as University of San Francisco law professor Susan Freiwald explained in a 1997 paper thus:

“For example, some information can be used to incriminate those who communicate with people involved in criminal enterprises. Further, some information can incriminate even without connecting the subject to other suspects. Several courts have held that an unusual volume of calls made immediately before, during, and after sporting events furnishes strong evidence that the caller is engaged in a gambling operation. Besides incriminating those who violate the law, communication attribute information yields evidence of those with whom one associates and the sources of one's information”



For more on what can be learned from people’s phone records and how these records can harm privacy and freedom of expression and the press read this article.


It seems that the Federal Government of Nigeria had similar intentions when as reported by Premium Times on April 25, 2013, it secretly and in open violation of lawful contracting procedures (See section 48(1) of the Fiscal Responsibility Act, 2007 which provides that the Federal Government shall ensure that its fiscal and financial affairs are conducted in a transparent manner and accordingly ensure full and timely disclosure and wide publication of all transactions and decisions involving public revenues and expenditures and their implications for its finances and Section 47 (3) (iii) of the Public Procurement Act 2007 which stipulates that single source contracts are to be awarded in emergency situations such as “natural disasters or a financial crisis”) awarded an Israeli firm, Elbit Systems, a $40million contract to help it spy on citizens’ computers and Internet communications under the guise of intelligence gathering and national security.

Fortunately, for the 47 million internet users in Nigeria (according to data from the Global Internet user, one of the Internet audit groups), the House of Representatives on Thursday, 30th May 2013 ordered the immediate suspension of the $40 million internet surveillance contract awarded to Elbit Systems, an Israeli Information Technology company by the Federal Government. The resolution of the House was that no further action should be taken on the contract until the outcome of the investigation of three committees of the House of Representatives. The committees, namely the committees on Human Rights, Information and Computer Technology as well as the Committee on National Security have three weeks to complete their investigations and make their findings known.

In as much the government may need to monitor internet and phone communications in the interest of national security or the fight against terrorism it must do so in a manner consistent with the 1999 Constitution of the Federal Republic of Nigeria which guarantees the right to privacy of Nigerians (section 37) and freedom of expression and the press (section 39) and the African Charter on Human and Peoples Rights which Nigeria has ratified. However, I do not think the Government necessarily needs to eavesdrop on or monitor our internet communications in order for it to stamp out the dreaded Boko Haram or other security challenges confronting Nigeria today. One should be able to have a private conversation online, just as one can have a private conversation in person. The situation in Nigeria is compounded by the non-existence of specific data privacy and lawful interception laws.

Frank La Rue (Special Rapporteur on the promotion and protection of the right to freedom of opinion and expression) in his report to the 23rd session of the Human Rights Council stated how restrictions on anonymous online communications or surveillance of internet communications of citizens affect the freedom of expression enshrined in section 39 of the Constitution thus:
"Anonymity of communications allows individuals to express themselves freely without fear of retribution or condemnation. Restrictions of anonymity in communication, for example, have an evident chilling effect on victims of all forms of violence and abuse, who may be reluctant to report for fear of double victimization. States should refrain from compelling the identification of users as a precondition for access to communications, including online services, cybercafés or mobile telephony...restrictions on anonymity facilitate State communications surveillance by simplifying the identification of individuals accessing or disseminating prohibited content, making such individuals more vulnerable to other forms of State surveillance. In this sense, restrictions on anonymity have a chilling effect, dissuading the free expression of information and ideas. They can also result in individuals’ de facto exclusion from vital social spheres, undermining their rights to expression and information, and exacerbating social inequalities."


In closing I wish to align myself with the suggestions/recommendations of Paradigm Initiative Nigeria (PIN’s) Policy Brief No. 1 entitled; Nigeria: Making A Case For Enduring Internet Freedom:

"The advised course of action for the government would be to work toward the passing of Data Privacy and Lawful Interception laws that:

1. Prescribe the fundamental privacy rights of citizens and define the legal frame work around surveillance.
2. Accord data privacy more priority than it currently has now. This is all the more urgent considering the numerous government and private institutions that hold sensitive citizen data. These include the National Identity Management Commission, Independent National Electoral Commission, Nigerian Communications Commission, Federal Inland Revenue Service, Nigerian Immigration Service, Federal Road Safety Corps, and banks.
3. Clearly outline provisions for interception in pursuit of a safer country without sacrificing the freedom of citizens or their constitutional right to communicate freely, including on the Internet.
4. Provide sufficient safeguards against abuse and opportunities for redress where infringement occurs."


I do sincerely hope that our legislators will take into cognizance the report of the special rapporteur Frank La Rue and especially the portion of the report quoted below when enacting the data privacy and lawful interception laws as recommend in this write up:

"The right to privacy is often understood as an essential requirement for the realization of the right to freedom of expression. Undue interference with individuals’ privacy can both directly and indirectly limit the free development and exchange of ideas. … An infringement upon one right can be both the cause and consequence of an infringement upon the other."