ChristopherSoghoian

Latest

  • Most of the government's anonymous tiplines aren't secure

    by 
    Timothy J. Seppala
    Timothy J. Seppala
    04.17.2015

    When it comes to whistleblowing, privacy is paramount -- just ask Edward Snowden. It's also why news from an American Civil Liberties Association report (PDF) about anonymous government tiplines not using HTTPS encryption is all the more alarming. In a letter to Tony Scott -- not the late filmmaker, the United States chief information officer -- the ACLU's Michael W. Macleod-Ball and Christopher Soghoian implore the government to fast-track efforts to swap the some 29 websites that are required by law to protect the anonymity of tipsters over to HTTPS. If that can't happen immediately (Scott has a two-year plan to encrypt all government websites) then the ACLU suggests allowing people to use the Tor browser for alerting the authorities about fraud or waste in the interim. Currently, the anonymity-minded browser is blocked by certain federal agency websites.

  • Sprint handed customer GPS data to law enforcement over 8 million times last year

    by 
    Joseph L. Flatley
    Joseph L. Flatley
    12.02.2009

    Privacy advocates and career criminals alike are in a lather over reports that between September 2008 and October 2009, Sprint Nextel ponied up customer location data to various law enforcement agencies more than 8 million times. Speaking at ISS World 2009 (a conference for law enforcement and telecom industry-types responsible for "lawful interception, electronic investigations and network Intelligence gathering"), Sprint Nextel's very own Paul Taylor, Manager of Electronic Surveillance, lamented on the sheer volume of requests the company's received in the past year for precise GPS data for Sprint customers. How did the company meet such high demand? Apparently, his team built a special "web interface" which "has just really caught on fire with law enforcement." We're glad that Sprint's plans to streamline the customer service experience don't stop short of those who serve and protect, but as the EFF points out, plenty of nagging questions remain, including: How many individual customers have been affected? Is Sprint demanding search warrants? How secure is this web interface? Check out an excerpt from Taylor's speech after the break.