Various other sorts of actors surveil users through their clients as well. ComScore is
one of the biggest of several companies that collect data about Internet users for market research. It collects the entire Web browsing stream, including encrypted requests,
from the 2 million members of its worldwide ‘‘consumer panel.’’ ComScore connects
its online data with a variety of sources of off-line data, including supermarket purchases and automobile registrations. ComScore has admitted to using its collected
data to log in to its members’ online banking accounts to verify reported incomes. 38
ComScore recruits these panel members from a wide variety of countries, including
many from Europe and Asia, through a combination of sweepstakes, network performance improvement tools, claims of antimalware protection, and (according to
ComScore) a sincere desire by panel members to improve the efficiency of the
Internet. ComScore discloses to the panel members that the software is monitoring
their Web browsing activities, but it also keeps a strong separation between the
company itself and the operations that collect the data—currently OpinionSquare
and PermissionResearch—by not directly naming the tools or the organizations that
operate them anywhere on ComScore.com or even in its SEC annual report filing. And
it has had to recreate those operations at least once to evade detection by antispyware
tools. 39 ComScore sells access to these data, estimated by ComScore at 28 terabytes collected per month in 2007, as market research to many of the largest companies in the
world. The U.S. Privacy Act of 1974 prohibits the U.S. federal law enforcement and
other government agencies from importing data from ComScore (or LexisNexis or other private database) en masse, but the law does allow the agencies to perform queries
through ComScore or other private data sources about specific people. 40
Governments have various levels of access to data collected through anti-virus software market research, and malware. Some governments allegedly also use their own client software to collect data directly. Direct evidence of government client surveillance
is rare, but examples occasionally pop up. For instance, the U.S. Drug Enforcement
Agency (DEA) has been documented as installing a keylogger on a suspect’s machine
to capture the encryption keys necessary to read the suspect’s PGP-encrypted email. 41
And we know major anti-virus companies have complied with court orders to ignore
such U.S. government spyware. 42 There is strong evidence that the German police are
aggressively pursuing the use of client-side software to tap calls on Skype. 43 In Denmark, parliament approved a law that explicitly gives law enforcement agencies the
authority to install keylogging software on a suspect’s computer. 44 And, thanks to
researchers at the Citizen Lab, the world knows that a Chinese version of Skype was
logging sensitive messages to servers as mandated by the Chinese government. 45 The
software used by government agencies for surveillance in all these examples is functionally indistinguishable from client malware—the whole point of the software is to
collect data from the subject without knowledge or consent.
Client-side surveillance provides the most complete access to user data in comparison to network or server surveillance. Every bit of data sent, received, viewed, played,
The EU Data Retention Directive in an Era of Internet Surveillance
47
one of the biggest of several companies that collect data about Internet users for market research. It collects the entire Web browsing stream, including encrypted requests,
from the 2 million members of its worldwide ‘‘consumer panel.’’ ComScore connects
its online data with a variety of sources of off-line data, including supermarket purchases and automobile registrations. ComScore has admitted to using its collected
data to log in to its members’ online banking accounts to verify reported incomes. 38
ComScore recruits these panel members from a wide variety of countries, including
many from Europe and Asia, through a combination of sweepstakes, network performance improvement tools, claims of antimalware protection, and (according to
ComScore) a sincere desire by panel members to improve the efficiency of the
Internet. ComScore discloses to the panel members that the software is monitoring
their Web browsing activities, but it also keeps a strong separation between the
company itself and the operations that collect the data—currently OpinionSquare
and PermissionResearch—by not directly naming the tools or the organizations that
operate them anywhere on ComScore.com or even in its SEC annual report filing. And
it has had to recreate those operations at least once to evade detection by antispyware
tools. 39 ComScore sells access to these data, estimated by ComScore at 28 terabytes collected per month in 2007, as market research to many of the largest companies in the
world. The U.S. Privacy Act of 1974 prohibits the U.S. federal law enforcement and
other government agencies from importing data from ComScore (or LexisNexis or other private database) en masse, but the law does allow the agencies to perform queries
through ComScore or other private data sources about specific people. 40
Governments have various levels of access to data collected through anti-virus software market research, and malware. Some governments allegedly also use their own client software to collect data directly. Direct evidence of government client surveillance
is rare, but examples occasionally pop up. For instance, the U.S. Drug Enforcement
Agency (DEA) has been documented as installing a keylogger on a suspect’s machine
to capture the encryption keys necessary to read the suspect’s PGP-encrypted email. 41
And we know major anti-virus companies have complied with court orders to ignore
such U.S. government spyware. 42 There is strong evidence that the German police are
aggressively pursuing the use of client-side software to tap calls on Skype. 43 In Denmark, parliament approved a law that explicitly gives law enforcement agencies the
authority to install keylogging software on a suspect’s computer. 44 And, thanks to
researchers at the Citizen Lab, the world knows that a Chinese version of Skype was
logging sensitive messages to servers as mandated by the Chinese government. 45 The
software used by government agencies for surveillance in all these examples is functionally indistinguishable from client malware—the whole point of the software is to
collect data from the subject without knowledge or consent.
Client-side surveillance provides the most complete access to user data in comparison to network or server surveillance. Every bit of data sent, received, viewed, played,
The EU Data Retention Directive in an Era of Internet Surveillance
47
