It’s been a long time coming, but last week saw the publication of RFC 6462, the Report from the Internet Privacy Workshop. The workshop, which was jointly hosted by the Internet Architecture Board (IAB) and others in December 2010, brought together experts from industry and the Internet standards community to better understand the role of privacy in Internet standardization work.
The workshop report provides a useful overview of fundamental privacy design challenges that appear again and again: the increasing ease of user/device/application fingerprinting, unforeseen information leakage, difficulties in distinguishing first parties from third parties, complications arising from system dependencies, and the lack of transparency and user awareness of privacy risks and tradeoffs. The report also identifies a number of barriers to successful deployment and analysis of privacy-minded protocols and systems, including the difficulty of using generic protocols and tools to defend against context-specific threats; the tension between privacy protection and usability; and the difficulty of navigating between business, legal, and individual incentives.
Coalition Urges Senate Not to Let Companies Waive Financial Regulations for AI
CDT joined AI Now Institute, American Civil Liberties Union, and several organizations dedicated to tech policy, consumer protection, and civil rights in a letter to Senate leadership and the Senate Banking, Housing, and Urban Affairs Committee opposing the “AI Innovation Labs” language in Sec. 10509 of the CLARITY Act.
British Public Oppose Secret Surveillance Powers and Want Strong Protections for Encrypted Communications
CDT released nationally representative polling data revealing that a the British public are broadly concerned about the security, privacy, and free speech consequences of allowing law enforcement to access encrypted communications.
Changing Course to Get It Right: The Advisory Committee Reviews Its AI Evidence Rule
CDT is keeping a close eye on Proposed Federal Rule of Evidence 707, which would govern when AI-generated information can be admitted as evidence in federal court — and many state courts where the federal rules are routinely adopted — without a human expert to explain it.