Surveillance Capitalism

  • Surveillance capitalism is a term coined by Harvard Business School professor Shoshana Zuboff to describe the business model of using data collected from individuals to target advertising and influence behaviour. The concept of surveillance capitalism emerged in the late 20th and early 21st centuries with the rise of technology companies thatspecialize in gathering and analyzing personal data.
  • The history of surveillance capitalism can be traced back to the early days of the internet. In the 1990s, companies such as DoubleClick andOmniture began collecting data on internet users’ browsing habits inorder to target advertising. As the internet grew in popularity, these companies were able to gather an increasing amount of data on individuals, allowing them to more effectively target advertising and increase profits.
  • The advent of smart phones and mobile technology in the 2000s further expanded the reach of surveillance capitalism. With the widespread adoption of smart phones and mobile apps, companies were able to collect even more data on individuals, including location data and information about their physical activity. This data was used to target advertising and influence behaviour, leading to the rise of companies such as Google and Facebook, which have become dominant players in the digital advertising market.
  • The use of data collected from individuals to influence behaviour has also been used to influence political campaigns. In the 2016 USpresidential election, Cambridge Analytica, a data analytics firm, used data collected from Facebook users to influence voter behaviour. The firm used the data to target advertising and create psychological profiles of individuals, allowing them to more effectively influence voter behaviour.
  • The business model of surveillance capitalism has been widely criticised for its ethical implications. Critics argue that the collection and useof personal data without consent is a violation of individuals’ privacyand that the use of data to influence behaviour is manipulative and unethical. In recent years, there have been calls for greater regulationof the tech industry to address these concerns.
  • Surveillance capitalism has led to significant compliance overheads for companies that collect and use personal data. There are a number of laws and regulations that have been put in place to protect individuals’ privacy, such as the General Data Protection Regulation (GDPR) in theEuropean Union and the California Consumer Privacy Act (CCPA) inCalifornia, USA. These laws require companies to obtain consent from individuals before collecting and using their data, and to provide individuals with the right to access, correct, and delete their data.
  • Complying with these laws can be costly and time-consuming for companies. They may need to hire additional staff to handle data privacy compliance, and may also need to invest in new technology to manage andprotect personal data. In addition, companies are at risk of significant fines if they fail to comply with these laws.
  • In terms of who profits from surveillance capitalism, the primary beneficiaries are technology companies such as Google and Facebook,which have become dominant players in the digital advertising market.These companies collect and analyse large amounts of personal data,which they use to target advertising and influence behaviour. This allows them to generate significant profits from advertising revenue.
  • On the other hand, those who suffer the most negative impact from surveillance capitalism are individuals, whose personal data is collected and used without their consent. They are also at risk of theirprivacy being violated, and their personal data being misused. Additionally, the collection and use of personal data can lead to themanipulation of individuals’ behaviour and decision-making, which can have negative consequences for their lives and society at large.
  • Moreover, the business model of surveillance capitalism has also been criticized for creating a power imbalance between companies and individuals. Companies have access to vast amounts of personal data,which they can use to influence behaviour and make decisions that affect individuals’ lives. This can lead to a lack of privacy and autonomy for individuals, and can also lead to discrimination and bias indecision-making.
  • This is collectively an erosion of the demarcation between data, state surveillance, banking, and political leadership globally.
  • The term “surveillance state” refers to a state in which government agencies have the power to collect and analyze large amounts of personal data, often without the consent of individuals. The rise of surveillance capitalism has led to concerns about the potential for the creation of a surveillance state, as government agencies may use the data collected by companies for surveillance purposes.
  • There have been instances where government agencies have used data collected by companies for surveillance purposes. For example, in theUnited States, the National Security Agency (NSA) has been accused of using data collected by companies such as Google and Facebook for surveillance purposes. The agency’s PRISM program, which was revealed byEdward Snowden in 2013, was designed to collect and analyse data from internet companies in order to identify and track individuals. Europe isclear about it’sintentions to mandate their complete access to all encrypted personal communications in forthcoming legislation.
  • The use of data collected by companies for surveillance purposes canhave significant implications for individuals’ privacy and civil liberties. It can also lead to a lack of transparency and accountability, as government agencies may use the data without the knowledge or consent of individuals. In addition, the use of data for surveillance purposes can lead to discrimination and bias indecision-making, as well as a chilling effect on free speech and the exercise of other rights.
  • Akten has been talkingaboutthe phase transition from digital surveillance to pernicious corporateAI in terms of a modern ‘religion’ for many years.bayer2023artificialHe feels that despite public awareness of privacy invasion, there hasbeen no significant outcry or unanimous demand for privacy. Instead,most individuals seem to find comfort in the belief that a higher forceis watching and protecting the virtuous, while punishing wrongdoers. The concept of a ‘digital deity’ emerge from his thinking in this context,reflecting the role that religion and traditional gods have played in providing ethical frameworks, security, discipline, power, and other societal functions. More recently O’Gieblyn has been drawing the same conclusions,o2021god explicitly linking religiosity to the imperative to ‘create a godhead’ simply because it can be done, not pausing to discuss if it should be. Rosenberg calls this ‘a threat to EpistemicAgency’rosenbergmanipulationMore recently the Harari, author ofSapiensharari2014sapiens said ofAI: it“For thousands of years, prophets and poets and politicians have used language and storytelling in order to manipulate and to control people and to reshape society. Now AI is likely to be able to do it. And once it can… it doesn’t need to send killer robots to shoot us. It can get humans to pull the trigger. We need to act quickly before AI gets out ofour control. Drug companies cannot sell people new medicines without first subjecting these products to rigorous safety checks.” (AI will be discussed in detail in a later chapter).
  • Klein at the New York Times has been writing against thispointfor some time. His well articulated fear, is that the current model where three major Western companies, with similar highly competitive capitalist origins and values, should certainly not be in charge ofracing to monetise the most compelling and innately unknowable chat bot experience. As societies shift towards materialism and technological dependence, traditional gods lose their relevance, and the need for anew form of overseer arises. This digital deity, existing within therealm of technology and the cloud, perhaps represents an adaptation of primal human belief systems. This will be explored further in the AI/MLchapter later.
  • In conclusion, the rise of surveillance capitalism has led to concerns about the potential for the creation of a surveillance state, or worse,a new kind of omnipresent digital culturla authority. Corporations and government agencies may use the data collected by companies for surveillance purposes. This can have significant implications for individuals’ privacy and civil liberties. It’s important for laws and regulations to be in place to safeguard citizens’ rights and privacy inregards to the use of data by government agencies, and to hold them accountable for any misuse of data, and yet it seems the reality of the situation in ‘post Snowden’ seems far from that.
  • Surveillance Capitalism. As a quick round-up of this area, which is best researched elsewhere:
    • The global digital advertising market is expected to reach $335 billion by 2023.
    • In 2020, Google and Facebook accounted for 60% of the global digital advertising market.
    • The data brokerage industry, which includes companies that collect and sell personal data, is estimated to be worth $200 billion.
    • In 2020, Google and Facebook were reported to have data on over 4 billion active users.
    • As of 2021, the number of data breaches reported worldwide has grown from 4.1 billion in 2018 to 4.9 billion in 2020.
    • In 2013, it was revealed that the US National Security Agency (NSA) had been collecting the phone records of millions of Americans under its PRISM program.
    • In 2013, Edward Snowden leaked classified documents that revealed the scale of the NSA’s surveillance programs.
    • In the US, the Foreign Intelligence Surveillance Act (FISA) allows the government to conduct surveillance on non-US citizens outside the US without a warrant.
    • The UK’s Investigatory Powers Act 2016, also known as the “snooper’s charter,” gives government agencies wide-ranging powers to collect and analyze personal data.
    • In 2021, it was reported that the Chinese government has been collecting and analyzing the data of its citizens through a system of “social cred* scores, which are used to monitor and control individuals’ behaviour.
    • Surveillance capitalism refers to the business model of collecting and analyzing personal data for the purpose of targeted advertising and other forms of monetization.
    • A recent study by the Center for Digital Democracy found that the top 100 global digital media companies are projected to generate over $1 trillion in revenue by 2020, much of which is derived from surveillance-based advertising.
    • The number of surveillance cameras in use worldwide is estimated to be over 1 billion, with the majority located in China.
    • A 2018 study by Comparitech found that the average person in the UK is captured on CCTV cameras over 300 times per day.
    • According to a report by the American Civil Liberties Union (ACLU), the FBI has access to over 640 million photographs for facial recognition searches, including driver’s license and passport photos.
    • The U.S. government’s use of surveillance technologies, such as drones and mass data collection, has been a subject of ongoing controversy and debate.
    • Some experts warn that the increasing use of surveillance technologies by governments and private companies could lead to the erosion of privacy rights and the creation of a *surveillance state.”
    • In the USA senate hearing following the collapse of FTX Rep. Jesus Garcia described bitcoin and crypto as an industry that operates outside of the law and relies on hype, implying that the communities that have adopted bitcoin are ill-informed and vulnerable.
    • Bitcoin has been adopted by a variety of communities worldwide, particularly in countries such as Vietnam, the Philippines, Ukraine, India, Pakistan, Brazil, Thailand, Russia, and China.
    • There is an outsized level of adoption among Black Americans in the United States. This trend is not a result of targeted advertising by companies such as FTX, but rather a response to a legacy financial system that has limited individuals’ potential.
    • Marginalized early adopters of bitcoin still constitute a minority in their communities, but the worldwide adoption trend among these groups is on the rise.
    • The solutions that outsiders build in bitcoin will ultimately be the source of the technology’s promised revolution. Adoption in Africa and possibly India seems likely to be capable of driving this.
    • The paradigm shift will come from those who bring local, real-world focused use cases to their communities, separating bitcoin from the empty hype of speculation.
    • Marginalized communities will lead the industry’s recovery and redefine the purpose of bitcoin in the future.

Tech money in Civil Society

https://twitter.com/youranonnews/status/1816298460645068879

  • Big Tech firms donate substantial funds to charities, think tanks, academic research, and lobbying efforts to shape narratives and policy around tech regulation. Goldenfein Mann 2024
  • Tracking financial flows from Big Tech to DRCSOs is challenging due to limited transparency, but available data shows ongoing funding relationships.
  • Through class action cy pres settlements, Big Tech firms direct funds to DRCSOs that purport to represent class interests, but may actually advance the firms’ preferred policy narratives.
  • Funding from Big Tech raises questions about potential conflicts of interest for DRCSOs and whether they truly represent the public interest as opposed to aligning with industry agendas.
  • The authors argue Big Tech philanthropy allows economic power to translate into political and cultural capital, enabling the firms to continue profiting from problematic data practices while avoiding meaningful regulation.
  • Much of the following text is paraphrased from the work of Guy Turner of‘The Coin Bureau’, and Lawyer and academic Eden Moglen, and needs more work because of it’s critical importance to the book. Update Cycle
    • The adoption of printing by Europeans in the 15th century led to concerns around access to printed material. The right to read and the right to publish were central subjects in the struggle for freedom of thought for most of the last half millennium. The basic concern was forthe right to read in private and to think, speak, and act based on a free and uncensored will. The primary antagonist for freedom of thought at the beginning of this struggle was the universal Catholic Church, an institution aimed at controlling thought in the European world through weekly surveillance of individuals, censorship of all reading material,and the ability to predict and punish unorthodox thought. In early modern Europe, the tools available for thought control were limited, but they were effective. For hundreds of years, the struggle centred around the book as a mass-manufactured article in Western culture, and whether individuals could print, possess, traffic, read, or teach from books without the permission or control of an entity empowered to punish thought. By the end of the 17th century, censorship of written material in Europe began to break down in waves throughout the European world,and the book became an article of subversive commerce, undermining the control of thought.
  • Currently, a new phase in human history is beginning as we are building a single extraneous digital nervous system, that will connect every human mind. Within two generations, every single human being will be connected to this network, in which all thoughts, plans, dreams, and actions will flow as nervous impulses. The fate of freedom of thought and human freedom as a whole will depend upon the organization of thisnetwork. Our current generation is the last in which human brains will be formed without contact with this network, and from now on, every human brain will be formed from early life in direct connection to the network, with input from generative AI/ML systems. This possibly results in humanity becoming a super organism of a sort, where each of us is buta neuron in the brain. Unfortunately, this generation has been raised to be consumers of media, which is now consuming us.
  • Anonymous reading is being determined against. Efforts discussed throughout this graph to ensure privacy, from Zimmerman and the cypherpunks onward, have been met with resistance from government efforts to monitor and control information flow. The outcome of the organization of this network, and the freedom it allows, is currently being decided by this generation.
  • It is not solely the ease of surveillance, nor solely the permanence of data, that is concerning, it is the relentless nature of living after the “end of forgetting”. Today’s encrypted traffic, which is used with relative security, will eventually be decrypted as more data becomes available for crypto analysis. This means that security protocols will need to be constantly updated and redone. Furthermore, no information is ever truly lost, and every piece of information can be retained and eventually linked to other information. This is the rationale behind government officials who argue that a robust social graph of the UnitedStates is needed. The primary form of data collection that should be of most concern is media that is used to spy on us, such as books that watch us read them and search boxes that report our searches to unknown parties. There is a lot of discussion about data coming out ofMeta/Facebook, but the true threat is code going in. For the past 15years, enterprise computing has been adding a layer of analytics on topof data warehouses, which is known as business intelligence. This allows for the vast amount of data in a company’s possession to be analysed and used to answer questions the company did not know it had. The real threat of Facebook is the business intelligence layer on top of theFacebook data warehouse, which contains the behaviour of nearly a billion people. Intelligence agencies from around the world want toaccess this layer in order to find specific classes of people, such as potential agents, sources, and individuals that can be influenced or tortured. The goal is to run code within Facebook to extract this information, instead of obtaining data from Facebook, which would be dead data once extracted. Facebook wants to be a media company andcontrol the web, but the reality is the true value of Facebook is the information and behaviour of it’s users, and the ability to mine that data. Distributed internet protocols are important in the context of government overreach into digital society and people’s private livesbecause they provide a level of decentralization and resilience that canhelp protect against censorship and surveillance.
  • For example, if a government were to attempt to censor or block access to a centralized internet service, it could potentially do so with relative ease. However, if that same service were distributed across anetwork of nodes, it would be much more difficult for the government to effectively censor or block access to it.
  • Another advantage of distributed protocols is that they are typically more resilient to attacks or failures. If one node in the network goes offline or is compromised, the others can continue to operate, ensuring that the service remains available. This can be especially important in situations where the internet is being used for critical communication,such as during a natural disaster or political crisis.
  • In addition to their benefits for censorship resistance and resilience,distributed protocols can also help protect people’s privacy. Because they do not rely on centralized servers or infrastructure, they can bemore difficult for governments or other entities to monitor or track.This can be especially important in countries where government surveillance is prevalent or where individuals may be at risk of persecution for their online activities.
  • There are a number of distributed protocols that have been developed specifically to address issues of censorship and privacy, and these will be covered in more detail later.
  • It is important to note that distributed protocols are not a silver bullet for censorship or privacy concerns. They can be vulnerable to certain types of attacks, such as those that target the nodes of the network, and they may not always be practical for certain types of applications. However, they do provide an important tool for those seeking to protect their freedom of expression and privacy online. They offer a valuable tool for those seeking to protect their freedom of expression and privacy online, and they will likely continue to play a critical role in the future of the internet.
  • In recent years, several countries have proposed or passed bills that would result in unprecedented levels of online censorship. One such example is Canada’s Bill C-11, also known as the Online Streaming Act.This bill was first proposed in November 2020 as Bill C-10, but failed to pass due to its controversial provisions. It was reintroduced inFebruary 2021 as Bill C-11 and was approved by the Canadian House ofCommons, the first step in the process of becoming law. If passed, the bill would give the Canadian Radio, Television and TelecommunicationsCommission (CRTC) the power to decide what content Canadians can view onYouTube and other social media platforms. The CRTC would also have the power to dictate what content creators can produce, with a focus on promoting “Canadian content.” Additionally, the bill would require certain broadcasters to contribute to the Canada Media Fund, which is used to fund mainstream media in Canada. The bill is currently being considered by the Canadian Senate, which will vote on it in February. If passed, it will then be debated by the Canadian Parliament. Tech companies such as YouTube have reportedly failed to convince the Senate to exclude user-generated content from the bill, indicating a high likelihood of it becoming law. The potential impact on the internet andfree expression in Canada is significant, as the bill would give the government significant control over online content and restrict the ability of individuals to share their views and perspectives.
  • In a similar vein the forthcoming RESTRICT act in the USA gives hugepowers without oversight to a single branch of the US government.
    • The bill is called the “Restricting the Emergence of Security Threats that Risk Information and Communications Technology Act”
    • It was initially thought to be about banning TikTok due to its connections to the Chinese government and the data it collects on its users.
    • The RESTRICT Act has very little to do with banning TikTok and instead grants the US Secretary of Commerce significant powers to determine which entities are foreign adversaries and what technology poses a risk to national security.
    • The bill defines critical infrastructure broadly, which means it could apply to almost anything the government deems necessary. Lobbyists will be allowed to advise the Secretary of Commerce on which products and services should be labeled as foreign adversaries, potentially leading to monopolies.
    • Fines and jail time for interacting with foreign adversaries or posing a risk to national security could reach up to $1 million, 20 years in prison, and asset seizures.
    • The bill aims to crack down on VPNs (Virtual Private Networks), which provide privacy and access to foreign websites.
    • There is no oversight for the actions taken by the Secretary of Commerce under this act, and neither Congress nor the courts can request information on these decisions.
  • The European Union (EU) has separated its online censorship efforts into two separate bills: the Digital Markets Act and the Digital Services Act. These bills were introduced in December 2020 and are part of the EU’s Digital Services package, which aims to be completed by 2030. The Digital Services package is the second phase of the EU’s digital agenda, which is being enforced through regulation in the public sector and through ESG investing in the private sector. Both the Digital Markets Act and the Digital Services Act were passed in spring 2022 and went into force in autumn 2022, but will not be enforced until later this year and early next year, depending on the size of the relevant entity. The Digital Markets Act aims to increase the EU’s competitiveness in the tech space by imposing massive fines on “gatekeepers,” or companies that maintain monopolies by giving preference to their own products and services. This could open the door to innovation in cryptocurrency in the EU, but also requires gatekeepers to provide detailed data about the individuals and institutions using their products and services to theE U. The Digital Services Act, on the other hand, aims to regulate the content that is available online, including user-generated content. It does this by requiring companies to remove illegal content within one hour of it being reported and by imposing fines for non-compliance. The act also requires companies to implement measures to protect users from illegal content and from “other forms of harm,” which is defined broadly and could include a wide range of content. The EU is also in the process of passing the Artificial Intelligence Regulation Act, which will be discussed later this year and is reportedly the first of its kind. All five bills in the EU’s Digital Services package are regulations, meaning they will override the national laws of EU countries. The potential impact on the internet and free expression in the EU is significant, as the Digital Services Act would give the government significant control over online content and restrict the ability of individuals to share their views and perspectives.
  • In the United States, two significant documents related to online censorship are the Kids Online Safety Act and the Supreme Court caseGonzalez v. Google. The Kids Online Safety Act was introduced inFebruary 2021 and is expected to pass later this year due to bipartisan support. The act requires online services to collect Know Your Customer(KYC) information to ensure that they are not showing harmful content tominors. It also gives the Federal Trade Commission (FTC) the power to decide when children have been made unsafe online and allows parents tosue tech companies if their children have been harmed online. The act has received criticism from both sides of the political spectrum and entities outside of Congress, as it is seen as giving too much power tothe government to regulate online content and could lead to increased censorship by tech companies.
  • The Supreme Court case Gonzalez v. Google involves the question of whether Google’s algorithmic recommendations supported terrorism and contributed to the 2015 terrorist attacks in Paris. The case has been picked up by the Supreme Court after being passed up by various courts of appeal. It is being heard alongside another case, Twitter v. Tumne, involving the role of Twitter’s algorithms in a terrorist attack in Istanbul. There are two potential outcomes for the case. If the Supreme Court sides with Gonzalez, it could increase the liability of social media companies under Section 230 of the Communications Decency Act, which allows them to moderate content to a limited extent without violating the First Amendment. Alternatively, the Supreme Court could declare Section 230 unconstitutional, which would make online censorship illegal but also hinder the use of algorithms on the internet. The ideal outcome, in theory, would be for the Supreme Court to side with Google and for Congress to change Section 230. However, giving Congress the power to change the law could lead to increased censorship and the potential for abuse of power.
  • In the UK forthcoming legislation will see tech company leaders liablefor prison sentences if they fail in their duty to protect minors. This will doubtless lead to both stringent universal requirements for identity proof (KYC), and significantly muted and controlled content on the platforms.
  • Our research focuses on business to business use cases for distributed technologies, and will provide mechanisms for verifying who is communicating with whom, to avoid falling foul of these swinging global infringements on privacy.
  • It is the opinion of this book that information should befreeswartz2008guerilla

US Politics and Big Tech

    1. Secret lobbying campaign: Shortly after an assassination attempt on Trump, Elon Musk, David Sacks, and Tucker Carlson engaged in a “secret lobbying campaign” to secure Vance’s position as Trump’s VP pick. They called Trump directly to advocate for Vance 5.
    2. Silicon Valley connections: Vance has extensive ties to Silicon Valley elites, developed during his time as a venture capitalist. His connections include Peter Thiel, who introduced Vance to Trump in 2021, and David Sacks, who held a pro-Trump fundraiser that Vance helped organize 3.
    3. Financial support: Tech billionaires are throwing significant financial support behind the Trump-Vance ticket. Elon Musk reportedly plans to donate $45 million per month to a pro-Trump PAC, while other tech figures like Marc Andreessen and Ben Horowitz have pledged donations 4 5.
    4. Endorsements: Prominent tech investors, including Marc Andreessen and Ben Horowitz, have publicly endorsed Trump and Vance. They released a podcast explaining their rationale for backing the ticket 1.
    5. New super PAC: A new tech-aligned super PAC called America PAC was unveiled shortly after Vance’s nomination, with backing from crypto billionaires and venture capitalists. It has already raised over $8 million 1.
    6. Convention support: David Sacks, a venture capitalist and Vance supporter, spoke at the Republican National Convention and has been actively encouraging other tech figures to support Trump and Vance 3 4.
  • Big Tech Leaders Influencing Trump’s VP Choice
    • Silicon Valley Support
      • Prominent tech figures, including Elon Musk, have publicly endorsed the Trump-Vance ticket. Musk described the partnership as one that “resounds with victory.”
      • Wired article on Silicon Valley and Musk’s support for Vance.
    • Fundraising Dinner
      • A critical fundraising event in San Francisco attended by Trump and around 24 technology and cryptocurrency leaders significantly influenced Vance’s selection. The $300,000-per-person dinner, hosted by tech entrepreneur David Sacks, saw attendees overwhelmingly recommending Vance as Trump’s running mate.
      • New York Times article on the fundraising dinner’s impact.
    • Peter Thiel’s Influence
      • Vance’s connections to Silicon Valley, particularly his association with influential tech investor Peter Thiel, have been instrumental in his rise within the Republican Party. Thiel contributed $15 million to Vance’s 2022 Senate campaign.
      • New York Times on Thiel’s financial backing.
    • Financial Backing
      • Tech leaders are not only vocally supporting Vance but also providing substantial financial support. Elon Musk is reportedly planning to pledge $45 million a month to a pro-Trump political committee called America PAC.
      • The Winklevoss twins, known for their involvement in cryptocurrency, each donated $250,000 to America PAC.
    • Mixed Reactions
      • While many Silicon Valley conservatives are enthusiastic about Vance’s selection, not all GOP donors are pleased. Billionaire hedge fund manager Ken Griffin expressed a more reserved stance.
      • Business Insider on the mixed reactions from GOP donors.
    • Tech Industry Appeal
      • Vance’s background as a former venture capitalist and his connections to Silicon Valley are seen as potentially beneficial for the tech industry. Some investors believe a Trump-Vance administration could be favorable for startups and capitalism.

      • Wired article on the potential benefits for the tech industry.

        This influence from tech leaders on Trump’s VP choice highlights the growing intersection between Silicon Valley and national politics, with potential implications for future tech policies and regulations.

Intelligence Agencies and Tech Companies

Overview of Government Data Acquisition Practices

  • Surveillance Capitalism: This concept pertains to the commodification of personal data by private entities. The US government, among others, acquires this data for intelligence and enforcement purposes, circumventing traditional surveillance and legal protocols.
  • Data Brokers’ Role: Data brokers are pivotal, operating businesses that amass and trade personal data without interacting directly with consumers. Their databases encompass a wide array, from social media behaviour to precise geolocation details.

THe TrUTh iS OuT ThERe

  • This was Anthropic Claude responding to a research formatted query about ‘conspiracy theories’ found online.

image.png|600

  • “Open source response”
    • CIA/MI5 Hacking Smart Devices
      • Verdict: Partly True. The CIA and MI5 have been known to engage in surveillance activities involving internet-connected devices through programs like Weeping Angel. This program was designed to hack into Samsung smart TVs, but it’s important to note that the extent of this capability and its current status are classified.
    • CIA Infecting Car Control Systems
      • Verdict: Partly True. Vault 7 revealed a range of hacking tools developed by the CIA, including those capable of exploiting vulnerabilities in modern car systems. However, there’s no concrete evidence to suggest that the CIA has used these tools to remotely take control of cars.
    • Tech Companies Providing NSA with Zero-Day Vulnerabilities
      • Verdict: True. Documents leaked by Edward Snowden revealed that tech companies like Microsoft did provide advance warnings about zero-day vulnerabilities to the NSA before disclosing them to the public. This was part of a broader program aimed at improving national cybersecurity and giving government agencies an early warning system.
    • NSA Breaking Tor Networks
      • Verdict: Partly True. While the NSA has been involved in efforts to compromise Tor, there’s no conclusive evidence that they have successfully broken the network or can identify users with certainty. However, it is known that various intelligence agencies have attempted to exploit vulnerabilities in Tor.
    • NSA Intercepts Devices and Installs Malware Chips
      • Verdict: Partly True. The ANT/TAO Catalog, leaked by Edward Snowden in 2013, reveals the NSA’s capabilities for intercepting and altering electronic devices, including installing malware or backdoors before they are delivered to customers. However, this catalog primarily focuses on exploiting vulnerabilities in targeted surveillance operations rather than mass production of compromised devices.
    • American-Made Electronics Allow Access via Radio Frequencies
      • Verdict: Partly True. The Cottonmouth-I and SURLYSPAWN projects, as mentioned in the Snowden leaks, involve the use of radio frequency (RF) signals to remotely access devices. However, these were designed for specific targeted surveillance operations rather than mass surveillance. It’s true that many modern electronic devices emit RF signals or can be accessed through their wireless capabilities, but this does not inherently mean that all American-made electronics are compromised for remote access by the NSA or FBI without further context.
    • Backdoored Random Number Generators
      • Verdict: Partly True. The Dual Elliptic Curve Deterministic Random Bit Generator (Dual EC DRBG) algorithm, developed by NIST and NSA, has been criticized for its potential to contain a backdoor that could allow the NSA to break RSA encryption.
    • NSA Backdoors in CPUs
      • Verdict: Partly True. The claim refers to Intel ME (Management Engine) and AMD PSP (Platform Security Processor), which are both hardware-based security features integrated into modern CPUs. While these technologies can operate independently of the main system, there’s no conclusive evidence that they were implemented at the NSA’s request or are being used by the NSA specifically for mass surveillance. Their primary purpose is enterprise-level management and security rather than clandestine operations.
    • FBI Distributes Undetectable Malware
      • Verdict: Partly True. The claim likely refers to the FBI’s use of malware for law enforcement purposes, such as tracking suspects or gaining access to encrypted data. While the FBI has been known to use such tools, it’s not accurate to say that anti-virus software is legally not allowed to detect them. However, some of these tools may be designed to evade detection by common anti-virus programs.
    • Backdoored Random Number Generators
      • Verdict: Partly True. The Dual Elliptic Curve Deterministic Random Bit Generator (Dual EC DRBG) algorithm, developed by NIST and NSA, has been criticized for its potential to contain a backdoor that could allow the NSA to break RSA encryption. However, it’s important to note that while the algorithm’s vulnerabilities have been identified and it has been subsequently withdrawn from use, there’s no conclusive evidence that the NSA actively exploited this backdoor to break RSA encryption on a widespread scale.
  • Minimal Legal Barriers: The acquisition of commercial data by governments faces scant legal opposition, attributed to the classification of such data as “publicly available.” This status exempts it from the stringent privacy protections applicable to more confidential data.
  • Privacy and Civil Liberties Issues: The extensive gathering and utilisation of personal data by governmental entities elicit significant privacy alarms. Despite assurances of anonymisation, methods often exist to re-identify individuals, raising consent and privacy violation concerns.
  • **Data Sharing Agreements
    • Five Eyes Alliance**: International agreements like the Five Eyes (comprising Australia, Canada, New Zealand, the United Kingdom, and the United States) facilitate extensive data sharing for intelligence purposes. This raises the stakes for data privacy, with personal data potentially shared across borders without explicit consent from individuals.

The Influence of GDPR and the UK’s Data Protection Framework

  • General Data Protection Regulation (GDPR): The GDPR represents a robust data protection initiative, offering EU citizens significant control over their personal data. It mandates explicit consent for data processing and grants individuals the right to access and request the deletion of their data. However, its effectiveness is occasionally undermined by complex consent forms and the global nature of data flows which transcend its jurisdiction.
  • The UK Data Protection Act: Post-Brexit, the UK continues to uphold strong data protection standards, mirroring GDPR principles. However, future divergences may impact international data sharing, especially concerning agreements with entities in jurisdictions with differing privacy standards.

Technological Advancements and Their Dual-Edged Impact

  • Rise of AI in Data Analysis: AI’s evolution has transformed data analysis, enabling the extraction of nuanced insights from vast datasets. This capability enhances government surveillance potential, making it more efficient but also raising ethical concerns.
  • AI and Surveillance: The misuse of AI for surveillance by state actors is a growing concern. AI can automate the monitoring of individuals on an unprecedented scale, necessitating stringent oversight.
  • Data Encoded in AI Models: Information about individuals becoming encoded in the latent spaces of foundational AI models poses unique challenges. This data embedding can inadvertently leak personal information, complicating efforts to protect individual privacy.

Prospects for Reform and the Future Landscape

  • Judicial and Legislative Responses: Legal frameworks globally are under pressure to evolve in response to technological advancements. Judicial interventions may set new precedents, while legislative reforms, informed by GDPR and other standards, could offer more comprehensive protections.
  • Impact of AI Regulation: The regulation of AI technologies, to prevent their misuse for surveillance, becomes increasingly critical. Ensuring transparency and accountability in AI operations is paramount to safeguarding civil liberties.
  • International Cooperation: Addressing the global nature of data privacy requires international cooperation. Agreements on data protection standards and ethical AI use are essential to navigating the complex web of data surveillance, sharing, and protection.

Misc links

Government and Agency Involvement in AI

  • Former NSA Director Michael Hayden said:
"we kill people based on metadata"