Showing posts with label lifehack. Show all posts
Showing posts with label lifehack. Show all posts

Monday, April 03, 2017

Side Effect: Snoopers Charter [Part 4]

It's been a wholly unsurprising journey to the Room of Truth with my CSP, only to be locked out of the final door.

After an online chat I finally got my request through to the legal department, only to be told that because it was a corporate account the DPA does not apply, and also; under Part 4 Section 93 of the IPA the CSP is not allowed to release the ICR data to me.

So I replied and re-iterated that the moment my SAR arrived identifying me, and linking me directly to the ICR data in question - also providing my authority as the account holders director - the DPA does apply as my name is linked to the internet usage [and that as my internet usage may contain specific records] and sensitive personal data.

Section 93 also refers to ensuring that the CSP puts adequate controls in place to retain the data in a secure manner. Nothing to do with disclosure. I can find no provision of the IPA which prevents the disclosure of ICR to the data subject(s) in question.

I'm the middle of designing and developing anti-spam security solution so frankly just don't have the time to focus on this at the moment. Whilst legal opinion appears to be that the IPA is not legal, I doubt the Prime Minister or Home Secretary are willing to have that "grown-up conversation". However ICO has enough of a fight ahead convincing the cabinet that it needs to keep parallel laws to keep trading with Europe.

Time to draw another spidergram and send the details to ICO - I can't imagine that the government regulator will do anything other than side with the government communications provider in this case.

I am Jack's total lack of surprise.

Tuesday, March 07, 2017

Side Effect: Snoopers Charter [Part 3]

Last month I was curious about the effects of recent legislation on my internet usage. Since then I've had some conversation tennis with support teams at my ISP but no traction or movement.

Up until this morning I'd suspected that nothing was being done - I'd send an email from an account I use tracking systems with, get a response back within a few hours telling me that email address wasn't authorised for the support ticket, then I'd send a reply from the original email address authorising the second email address with the ISP... and then getting nothing in reply.

Twice.

I know the emails were opened in India and read twice each time within a few hours of sending. All other responses or communications were simply being swallowed up into a black hole.

This morning I tried using the live chat on the ISPs website and got a far better response (even if it wasn't what I wanted to hear).

Despite repeated requests to get status or answer any outstanding queries I've had nothing. The live chat support person, Linda, was able to tell me that the original recipient of the request fobbed me off onto the wrong department then closed the support ticket. And it's been that way ever since the 19th of January. 

Not really surprised but I pushed Linda to forward the request onto either their legal or compliance team. A bit of confusion - it sounds like their usual section 7 requests are for case notes, not ICR data - easily clarified. Now although Linda refused to re-open the support ticket she did promise to forward the request onto legal after I explained that the ISPs legal team would have had to review & sign-off the Snoopers Charter implications. This would involve them understanding the request and its terms.

However we're now over the 40 day limit for a SAR and there is no response other than acknowledgements that the ISP have received the request - it's going to be interesting to see how they respond from this point. Recent legal updates have included a major setback to the Investigatory Powers Act at ECJ level and some inevitable challenges to it's implementation; especially relating to the requirement to implement 'back doors' in all CSP platforms. Note emphasis there on CSP platforms, not anti-virus software or encryption software.

Whether or not this will really affect peoples daily lives or not is another matter, but I'd be concerned that local councils, HMRC, the Dept. for Education and other similar level government departments will inevitably use this type of information for purposes other than 'detection of a crime'.

'Detection' will easily slip into 'Prevention', and then we're in the tin-foil hat territory akin to Minority Report. I don't have government-level actors trying to hack my devices but if there is a method of access available, criminals will find it - and that's enough of a cause for concern for me. Just a quick glance at how busy ICO are with government departments and you begin to understand the scale of the data-protection problem: Here's a list of decision notices - when this article went live they were all councils on the receiving end of complaints.

Click to see larger image

Monday, February 06, 2017

Side Effect: Snoopers Charter [Part 2]

Last month I sent a rather well-known international internet provider a subject access request (SAR) - since that post (which you can recap on here) I've had some rather less entertaining communiques with them.

I'm not going to name the ISP just yet for security reasons but suffice to say that the following are true:

  1. They ask that a cheque is sent in the post to them for £10 as part of the SAR process; yet do not accept cheques as a form of payment for any of their services
  2. They do not advertise the email details for any legal department inbox, nor do they extend their current online issue registration capabilities to include SAR or similar filings
  3. This is a company who sell themselves on high technological value (and do so on multiple continents) yet fail to provide a simple means for lodging a SAR - which is an individuals right under the law here in the UK [and EU]
After the last post I had received an assurance from the member of staff that she would contact the original member of staff to find out why it was [erroneously] passed to her department, and that she would call me back within 2 hours.

I've heard nothing since the 19th and 20th of January.

I've sent two follow-up emails to the ISP to which they have failed to reply within 48 hours - which is their SLA for business customers. I sent another further update request from an email address embedded within a tracking system.

This email got a response within 3 hours saying that the update request was "...not sent from the email address you used in your initial enquiry", and that "...for security reasons, we cannot provide an update unless you use the same email address that you originally used to contact us".

Actually I'm happy with that response as it's a verification of identity - the tracking system uses a completely separate domain and I'd be asking for the same verification from any of my customers too. So I sent back a message from the original email address used to the effect that yes - it was me, and that they should enact this second email address with the appropriate authorisation to deal with this issue.

That was the 2nd of February and there's been no further communication since.

So I repeated the latter part of the exercise and got the same response today - also read and responded to within 3 hours of being sent.

So what is clear is that the ISP are receiving the requests for update and essentially refusing to provide an update. As I've had adequate responses directly from the ISP staff they have received and acknowledged the request, and I've asked specifically how I can pay the £10 SAR fee without a cheque book.

As they're refusing to respond does that mean they're waiving it? Forgetting the fact that the fee was designed in the 1980's to cover the cost of postage of the potentially large printed documents to answer the SAR, I'm not sure how relevant that price is versus the cost of doing business - which the all businesses must acknowledge if they conform to the Data Protection Act.

I can show that each of the requests for information have been received, opened and read (all in India), yet have little to show in terms of meaningful response. I found another part of the same ISP - well it's a law firm that says it's part of this ISP and I'm going to send them a copy of these posts as well as the original request.

Expect another post in coming weeks as the time limit on the SAR (40 days) means the statutory limit expires on the 28th of February. At that point the ISP will be in breach of the DPA.

Thursday, January 19, 2017

Side Effect: Snoopers Charter [Part 1]

On the 6th of January 2017 the Investigatory Powers Bill came into effect. At this point all CSPs (ISPs such as TalkTalk, Vodafone and BT) must start collecting internet connection records - or ICRs.

I'm not going to get into the morality or the why's and wherefores but, according to the IPB these must contain the details of websites each internet connection connects to, but not the full URL or details of every page visited.

So how are they intending to collect that information? There's several ways to do that. Perhaps a form of DNS caching silo-ed to each household and business; perhaps packet inspection?

Whichever way this will be achieved the focus now shifts to the ICRs themselves - which of course are chunks of information stored about a person.

Wait... *sound of rustling paper* ...that means that under the Data Protection Act these ICRs come under the definition of personal data (section 1 I think states that but it is also referenced in schedule 2). But surely that would mean we could see what's being collected then? We each have the right to see all our data and meta-data to ensure that it is correct and being processed correctly.

Time for an exploration into some of these grey areas to see what will happen if I SAR my ISP for ICRs. The complication here is that I use a business account wired to my home address; but that isn't so much of a complication when you consider that when you inform someone that a Thing is personal data, you are associating your name with that Thing ... and therefore it becomes personal data (assuming it is about you). So... The ISP doesn't have an open email inbox although this makes sense - they'd just get spam.

Instead I have to log a request via the support system or send a *shudders* letter. My ISP also mandates that I should send them a cheque for £10 in the post before they'll deal with the SAR... but a) that's *shudders* basically a letter and b) I don't have a cheque book any more and and and and c) my ISP themselves don't accept cheques in payment for their services.

So I call cow poo on that one.

So this morning I logged the following support ticket - please feel free to take this and shape it to your own personal needs if you wish:

"Please pass this request to your legal department. It has been logged as a support request for tracking purposes.

This is a subject access (a section 7) request under the Data Protection Act.

As the internet services provided by this business account are also used for personal / home reasons, this SAR essentially ties the internet connection records (ICR) to my name, and therefore expands the scope of "personal data" to include the ICR themselves by association.

I am also the authorised person on the business account and am happy to be verified as such.

With that in mind, please provide copies of all data - in electronic format - and associated meta-data for the ICRs collected as required by the Investigatory Powers Bill - related to me.

As I do not have a cheque book it is impossible to follow your privacy guidelines about how to pay the £10 DPA-mandated fee, so ask that you contact me directly to provide alternative payment details."


Updates to follow (although bearing in mind the ISP involved, it won't be any time soon). I'm expecting some attempt to wiggle out of it either by admitting that they're not up-and-running with it yet, or that they try and claim a DPA exemption.

Update 1: Jan 19th, 2pm

Expected this sort of thing.
So the ISP has called a couple of times, the foreign call centre handler then immediately passed me through to their billings complaints department. After 10 mins of me telling them the reference number from their own email (and them claiming it wasn't a valid reference number), they agreed to speak to the call handler who had passed my call to them. They're now speaking to him and will call me back later.
I'm still a little surprised that this ISP (a large multinational) has live chat on the website, a ticketing system for non-standard queries and a web portal for account management still requires postal methods for a SAR. Seems an overly obstructive approach and making it almost dissuasive for most people.

The next few updates deserved a post of their own, check for new posts in coming days...

Friday, December 30, 2016

Yelpsters

There's been a lot of opinion expressed on both sides for this topic - most of the feedback is overwhelmingly negative but there's a substantial number of positions which are quite positive.

However looking at specific examples I've been able to witness first hand seem to weigh in on the former, although in reading up on this one there's been some comedic uses of the review sites - such as a bistro in the US offering a discount to customers providing negative reviews. There's an unknown amount of trade for former "SEO Consultants" who are now plying their trade to review site optimisation too, inferring that there's a sizeable economy surrounding these platforms.

Not only did it make a mockery of the review system on Yelp specifically but it highlights how abusive some of the platforms can appear. For example we got a local tradesman to fit the new carpets in our home and whilst talking to him he specifically asked us to read his reviews on Facebook, not Yelp.

Of course a comment like that is going to peak my natural curiosity so I dug a little deeper whilst the carpets were being laid, uncovering all sorts of fun & games (and stress) had trying to deal with the Yelp reviews. Having a quick look at his business Yelp page I can see what he means.

Of the 23 reviews that I could see at the time, 12 had been removed by Yelp as violating it's "terms of service", and 9 were "not recommended". This left two valid and "recommended" reviews - as far as Yelp itself were concerned - that were viable views on the business involved.

I couldn't understand the criteria match involved as the two remaining reviews were from Qype user accounts, and Qype hasn't existed as a platform since it was absorbed into Yelp in October 2013. To my mind more recent reviews over the previous twelve months are more likely to be representative of a business than something logged about a problem in three years previously.

For example, a restaurant can change hands and improve it's quality of service as a result; or a museum changes exhibits regularly providing differing levels of engagement over a longer period of time. TripAdvisor solves this problem by refusing any reviews over 12 months old - although they may still be visible their priority and importance in the overall business rating are lowered slightly too. On the face of it that makes more sense to me and allows business to atone for any past mistakes (as well as ensuring they don't rely on previously high ratings to boost their search rankings).

Yelp does not do this from any of the business reviews I've seen. It tries to hide the majority of reviews with a greyed link at the bottom of the page (enlarged in this image for ease of reference).
Suspect Carpety Reviews
The rest of the reviews - which are almost all positive from what I've read - are hidden in a "...reviews that are not currently recommended" moniker, and labelled essentially as irrelevant.
Yelp makes the following statement about this logic: 
Yelp statement on "Not recommended" reviews page

Now there's a few interesting sentences in there I'd like to focus on which don't seem to tie-in with a common-sensical approach. The first (highlighted yellow) seems to indicate that the reviews are assessed on quality and reliability combined with user activity. I don't understand how that's possible in Pete's case as there are a number of reviews in the last twelve months from people who have created a Yelp account purely to commend Pete's carpeting ability. 

But the two reviews which are being counted also indicate those users only ever made one review, and are from 2013 - neither those reviews or most of those on the "not recommended" page have any Yelp "friends" which may be the algorithm metric involved. Doesn't seem to tally. So the Qype user reviews giving Pete 5 stars are "not recommended", but the Qype reviewers panning Pete are on the front page.

Pete doesn't advertise on Yelp and rejected their sales teams suggestions that he buy a business account, shortly afterwards he says the problems really started. Customer reviews got moved away from the front page and his Yelp star rating shown alongside the search result dropped to a one star. Of course Yelp vehemently reject any suggestion that the two events are linked but Yelp only have a 2 star rating on their own website.

After Pete fitted the carpets I added my own review for his business on Yelp - creating a new account in the process. I also added a review for another business I'd used in the previous six months just to see if that was the deciding factor but, as if by magic, my review went from the front page to the "not recommended" page within 24 hours.

So going back to the Yelp statement the blue highlighted note about advertisers getting preferential treatment cannot really be proved or disproved without actually seeing the underlying algorithm first hand. However the majority of positive reviews for this specific business would nominally give Pete a  4.8 out of 5 (4 star service). The reviews de-listed because they "infringed the terms and conditions" would provide a small increase over that.

Should business owners like Pete care about Yelp? I'm not so sure - we did a lot of searching on other platforms such as Check-a-trade and social media; on both of those areas Pete scored highly based on recent customer reviews. Everyone gets to make up for past mistakes.

I also recently had an interesting conversation with another platform provider - Trustpilot.co.uk - who apply reviews of businesses and websites. I thought I'd try something related to my anti-spam activities and lodge appropriately negative (but entirely honest) reviews about two data trading businesses. The two businesses involved are AdView and UK Staff Search - both trading brands of Roxburghe / Dash Marketing who scrape job seeker details from jobs boards such as Jobsite.co.uk, pretend to operate in the US and then sell the personal data to various unsolicited marketing firms back in the UK.

The review went something like this:
Actually not as detailed or specific as it could be
The review omits details about how the company broke the law (DPA & PECR) but notes the basic facts.

Both business lodged a complaint about my reviews, and Trustpilot were of the opinion that despite AdView illegally acquiring my data and then spamming me I didn't qualify as a customer. Despite that being the very definition of an Adview customer they deemed my review in breach of their terms and conditions. And also despite AdView staff writing most of their reviews themselves. Perhaps if word of this post gets to them this review will also be removed by Trustpilot but I was completely unimpressed with their reasoning and position.

However the USS review stood and today someone marked it as "Helpful". That's the real purpose behind these platforms - finding good opinions and using them to choose the right product or service.

Overall I'm going to continue taking all reviews and opinion with a pinch of salt and actually talk to people to see if they know their trade. It's crazy but it might just work.

Saturday, August 23, 2014

Auto-Archiving IMAP in Outlook

It seems like I'm not alone in initially being surprised that IMAP accounts cannot be archived in Outlook.

After spending some time poking around forums, Q&A sites and product support pages it's as simple as IMAP and archiving are mutually exclusive. I thought I'd put a concept forward for anyone out there who needs both the convenience of externally hosted IMAP functionality as well as the maildrop & delivery capability provided by the POP3 system.

A typical example here for me is wanting to access the same email account across multiple devices, get alerts on incoming messages on those devices, and be able to reply should I need to.

I also want to be able to take an archive of older emails (receipts, legal conversations, audit items, records of business and conversations, etc) and store separately for a given period too.

So in order to get around this I use IMAP almost everywhere but then on one (perhaps two locations) I'll connect via POP3 over Outlook - use whatever email client you wish - and use the auto-archive facilities to create email archive files.
Application and Service Relationship

These files (PST) can then be added to an offsite backup. An IMAP account in Outlook will use an OST file to cache mail items and headers but if its deleted or lost your IMAP account is unaffected.
Archive and Artefact Relationships
 

Tuesday, August 19, 2014

Council Tax

How I'd imagined Birmingham Council Tax team to appear on Monday mornings
Have you ever had a situation where your council have incorrectly billed you and take an enormous amount of time to get back to  you - never mind resolve the situation?

Have you ever become frustrated with local government civil service ineptitude, broken record response, their lack of productivity and their incredible inefficiency?

Have you ever received threatening letters from the council, perhaps attempting to coerce you into overpaying something with the threat of a court appearance?

Well, I may have a couple of pointers to help you out.

In the first instance, obviously try and get the other party to engage in the issue and make reasonable attempt to move the situation along. For example, I tried phoning the council and was told I couldn't close the account and get a final bill until I provided the next tenants details. As I no way of knowing this and they wouldn't take the management agents details, I was told there was "nothing we can do" by the person on the other end of the phone.

Even though I told him that it simply wasn't my problem and followed it up in an email to confirm, they still tried bill me after I had vacated the property. I even explained that no other city I've lived in has ever tried such a ridiculous trick to save themselves investigating the deeds.

So ... what next?

Firstly, take the name at the bottom of the automated council tax letter you've just been unnecessarily sent - Usually its from someone nominally senior to make the letter more official, threatening court action if you don't comply. In my example it was stamped from Chris Gibbs, the Assistance Director of Revenues and Benefits.

You'll need the domain name they use as well - Do a web search for "[insert city name in here] council tax" and it should be amongst the top results - it'll usually be the same as the council tax website where you live. In my example its "birmingham.gov.uk".

Put that aside and try the usual routes of approach - I tend to avoid spending my own money on hold over the phone with various departments, who only tell me to fill out a form; and email directly. Don't expect rapid responses but it means you're getting everything in writing.

In this case it took a fortnight just to reply to an email.

Now when this inevitably fails - After hearing every excuse under the sun no to add single person occupancy discount, or close the account due to you moving out, etc, start forwarding snarky emails to the semi-important nominee you found on your letter.

Try the following:
  • firstname.surname@domain name
  • [letter of firstname].surname@domain name
  • [letter of firstname]surname@domain name
  • firstname_surname@domain name
  • ...and so on.
You'll end up with an email with a lot of recipients perhaps - try about five at a time. When one of the addresses does not return a failed recipient error email from the council email server you'll have found the right email address.

In my example it was as simple as chris.gibbs@birmingham.gov.uk - as you can see from the email I eventually got from his PA.

Now and then you may get the occasional attempt at derailment, or just plain mishaps with technology...such as your email vanishing in a puff of smoke. Example here. Apparently between replying to my email acknowledging receipt and then actually getting around to looking at it / forwarding it, the content had vanished. Electronic trickery. Clearly sorcery at work.

Finally, after five months end-to-end, malcontent with the situation and happy to demonstrate the level of ineffectualness to the courts; the council emailed me back. Very forthright and here it is.

I've waited a while to respond and ensured more people had access to the email address - Maybe it might help the council deal with queries faster - It certainly got past the evasive and disinclined lower ranks of the city council for me.

So all it took to add single person occupancy discount to the council tax bill and close the account in order to send me a final bill was my prompting, cajoling, returning legal threats in kind, involving the department deputy head for five months.

It took six minutes to pay in full electronically from my tablet.

Even now Chris' department are attempting to coerce me into paying council tax for a period after I moved out. Guess its time for another email...

Update 2015

After a few months of hearing nothing I got a bit suspicious - I'd created enough attention now that the issue would surely be resolved (only took a year). Unfortunately it had: The council had ignored my proof and raised a claim in the courts without notifying me. By the time I found out about it a collections agency contacted me. I'm not sure how legal that was because I would have been extremely happy to represent myself in the courts - after all, plenty of public evidence.

My advice here would be to email and call every week for an update to check that your council weren't trying to pull a fast one, I didn't and got caught out procedurally.

The net result was that I had to pay for the con-job letting agents portion of the bill as well as my own. I suppose it was more the principal of it than anything else as the money involved was negligible (only around £200) but local government defeated me by knowing how to take advantage of the system in order to absorb their own broken processes.

However, if you fall foul of a similar situation don't forget; don't waste your time with the 9-5 mob at BCC as they'll just have you chasing your own tail. Go straight to Chris Gibbs so you can get a response, and he can be reached at: chris.gibbs@birmingham.gov.uk - best of luck.