• The Everywhere Border. Digital Migration Control Infrastructure in the Americas

    The US is building a digital border infrastructure in neighbouring countries that expands and deepens surveillance, while hiding state violence. The implications of this new infrastructure will be long-lasting and need to be integrated into strategies of resistance of migrant justice movements worldwide.

    In 2021, José Eusebio Asegurado, a farmer in El Salvador, was arrested by the Salvadoran National Civil Police for ‘promoting human trafficking’. The basis for the arrest was a WhatsApp group chat (external link)
    that Asegurado and other migrants1 were using to coordinate a caravan, which had been infiltrated by a police agent. According to the screenshots used to incriminate him, Asegurado’s only participation in the chat was responding ‘OK’ to a migrant’s message that he would be at a meeting point at around 5 o’clock. Police arrested Asegurado at the meeting point, telling him he was ‘profiled’ as a caravan organiser.

    The same day, the Salvadoran police also charged Fátima Pérez, a cook, and Juan Rufino Ramírez, a private security guard, with promoting ‘human trafficking’ based on messages on a WhatsApp group they had created to coordinate a caravan. Screenshots in Ramírez’s case show him giving instructions to the 55-member group to meet at the bus station, and the prices of tickets to Guatemala. The police arrested Ramírez and Pérez the morning they were planning to leave.

    These three arrests took place in the span of four hours. The then-US ambassador in El Salvador, Katherine Dueholm, promptly congratulated (external link)
    the General Prosecutor’s office, stating: ‘I applaud the Salvadoran authorities who are taking action against those who want to deceive citizens with caravans and false promises. They promote only #UnViajeEnVano (external link)
    ’ – ’a journey in vain’.

    The arrests and Ambassador Dueholm’s praise reflect the critical role of covert surveillance and data-driven ‘smart’ technologies in US migration-control practices operating deep within countries outside the US. Over the past twenty years, the US (and other wealthy countries) have made strides to externalise border-control regimes well beyond their actual territory. This often involves effectively enrolling agencies in other countries in migrant surveillance, policing, and exclusion.

    The new digital infrastructure that enables border externalisation, however, is little understood. This digital infrastructure relies on both military-grade technology built by major weapons manufacturers and Silicon Valley innovation: inter-operable databases that share fingerprints seamlessly between police agencies across borders; biometric collection devices used by Mexican detention authorities to track migrants for US Customs and Border Protection (CBP); social media apps that serve as critical communications networks for migrants and surveillance tools for police; digital ID systems that enable access to essential services, but double as tracking devices.

    Infrastructure – digital or material – has real sticking power; that’s the point. Once a highway splits a community in half, a new permanence stifles the din of protest, and people move on. We use the term digital infrastructure to describe the establishment of a foundation that will be fundamental to how world powers will practise migration control; and, as it embeds itself, increasingly beyond challenge – a unified strategic intervention by powerful countries, with the US coveting the vanguard. While it may look like technological experimentation (like AI-powered robot dogs on the border) or one-off opportunistic data-grabs (like networks of international data-sharing agreements), the growth of digital border infrastructure is by design. This is enabled through joined-up digital technologies that settle into the kind of rigid, ‘motiveless’ permanence granted to other infrastructures, like submarine communications cables, protocols and servers that run the internet, an electrical grid or a superhighway.2

    The profound implications of new infrastructures persist long after their creation, as is the case for the digital infrastructure deployed to police migrants in the so-called US ‘backyard’. Its impacts are frequently rendered invisible. Governments promote border policing technologies as fundamentally safe, humane and non-violent (external link)
    while migrant advocates struggle to make visible the violence on the other side of this unseen ‘borderland circuitry’.3

    The implications range from digitally triggered violence and killings by local police in Central America to actions by the US, its allies and competitors in geopolitical contests over the control of global security. The US government and private industry have worked themselves into a largely covert entrepreneurial frenzy to own and control the migration policing interface of the future. Monitoring and control capabilities – a longstanding and routine part of US aid packages to fight organised crime – both expand domestic spying by partner governments for their own ends and serve US border externalization interests in controlling the movement of people and diverting them away from the US territorial border.

    This essay will focus primarily on how digital infrastructure serves US interests . What do we know about this strategy and how it is already affecting mobility and human rights in the region? What are its historical foundations? What challenges lie ahead? It is impossible to answer these questions simply by dissecting the cruelty or provenance of any single technology, system or actor. We first need to understand the transnational motivations driving these incremental, more observable, facts on the ground. We need, in other words, to make visible the invisible digital infrastructure.
    Digital infrastructure is key to border externalisation and a rise in unaccountable violence

    Understanding border externalisation through the lens of digital infrastructure captures the true scale of border practices envisaged by the US (and its competitors and allies) as well as their envisaged permanence within the future world order. Digital border infrastructure feeds on histories of domination, control and atrocities in the name of transnational ‘crime-fighting’ projects, setting the stage for tremendous social costs.

    First, as to scale, we are witnessing an escalation of US border imperialism and borderland violence4 – both in terms of geographical reach far into national territories and the further extension of ‘policeability’5 to an increasing number of individuals and groups through this digital infrastructure. This includes anyone an algorithm decides might be ‘dangerous’, those who might migrate, as well as humanitarian actors, migrant advocacy groups, and aid organisations. Scaling and the rapid growth it engenders is a quintessential property of digital technologies, regardless of their origin or application. The shifts to new targets under digital infrastructure are frictionless compared to earlier analogue-based border policing tactics. Asegurado, the farmer assisting migrants in El Salvador, was swept up in the US border externalisation dragnet with a simple ‘OK’ on a WhatsApp chat.

    Second, as to permanence, advocates of digital borders in national capitals, industry and development agencies embrace the term ‘digital public infrastructure’ as a brand, to bestow (unearned) trust, normalisation and the inevitability of contested digital tools such as biometric IDs and payment systems.6 Ceding the privilege of defining ‘digital infrastructure’ to actors with vested interests in current migration-control practices is reckless. Without a counternarrative that articulates their violent disposition, digital border externalisation tools – including widespread biometrics collection, real-time transaction data-collection in payment systems, and the confiscation of smartphones at the border – can easily be normalised as ‘digital public infrastructure’, rather than resisted.

    The scale and enduring impact of the rapidly hardening digital infrastructure that fuels border externalisation calls for urgent transnational organising. As writers and activists, we have come together to resist the use of digital infrastructure in US migration-control policy in Mexico, Central and South America, and the Caribbean. We have only traces and not the whole picture. Building on the work of others, we weave all this together to show how the fusion of state and digital power to construct digital border infrastructure is neither humane nor safe: rather, it is increasing unaccountable forms of violence.

    Convergence: Drugs war, border externalisation, digital infrastructure and the militarisation of US’ neighbouring regions

    Economic and political initiatives since the 1970s have driven relentlessly towards US investments in more militarised, criminalising, and digitised migration-control practices. Since 9/11, the US convergence of ‘national security’ with unauthorised migration has fueled an ever expanding border externalisation regime—currently there are 23 CBP offices and 48 ICE offices worldwide—and consequently has provided an especially lucrative market for digital surveillance corporations.7 Through programmes such as the Mérida Initiative and the Central American Regional Security Initiative, the US has tied aid to countries such as Mexico, El Salvador, Guatemala and Honduras to increased militarisation, policing, incarceration, and migration control.

    Yet migration patterns to the US from Mexico, Central America and the Caribbean cannot be divorced from the practices and policies that the US employed for over a century to dominate countries in these regions. Decades of US practices and policies have fuelled economic, political, and environmental instability – key factors that drive migration to the US. Over the past 20 years the number of people migrating from Central America has more than doubled (external link)
    , the largest increases coming from Guatemala, Honduras and Mexico. The US-backed ‘war on drugs’ in Mexico and Central America has dramatically increased violence and instability.8 In Mexico, the fight against organised crime has resulted in 350,000 deaths and more than 72,000 disappearances (external link)
    between 2006 and 2021. According to the World Bank, 60% of rural Central Americans live in poverty (external link)
    . While the largest contributors to the climate crisis are wealthy countries, these already impoverished populations suffer the most acute impacts of climate change. For decades, prolonged droughts together with natural catastrophic events such as hurricanes (external link)
    and floods (external link)
    have deeply affected Central America. The number of people facing food insecurity tripled between 2019 and 2021, affecting 6.4 million people (external link)
    . Asegurado, Pérez and Ramírez – like many others – are grasping for alternatives to this intolerable situation.

    Rather than acknowledge these underlying causes, the US response has been to extend its border ever further. General John Kelly, former Secretary of the US Department of Homeland Security (DHS), stated (external link)
    , ‘I believe the defense of the Southwest border starts 1,500 miles to the south’. Mexico has long been central to the US border-externalisation regime, and digital infrastructure plays an increasingly critical role. Tony Crowder, former director of CBP’s Air and Marine Operations, shared Kelly’s sentiment ‘We have taught the Mexicans how to fish…[but] even though we have all this surveillance capability, we don’t have enough, we need more’.9

    While part of a continuum of US efforts to enlist Mexico in support of its regional objectives, this ‘security and rule-of-law partnership (external link)
    ’ accelerated following 9/11. In 2007, the US shifted the focus of its drug war (external link)
    from Colombia to Mexico, Central America, and the Caribbean. Under this frame of securitisation, the drug war merged with the migrant-control regime. In 2008, the Mérida Initiative was launched – a bilateral partnership between the US and Mexico in the name of the US war on drugs. It initially provided financing for Mexico to purchase equipment for its military and police forces and for intelligence gathering. In 2013, Mérida was revamped to include four pillars (external link)
    , incorporating the creation of a ‘21st century US-Mexican border, while improving immigrant enforcement in Mexico and security along Mexico’s southern borders’. Effectively an extension of US policy, some $3.5 billion (external link)
    has helped shape Mexico’s migration-control agenda since 2008.

    In 2014, Programa Frontera Sur further securitised Mexico’s southern border by increasing the migration policing and deportation apparatus. Consequently, Mexico now has one of the world’s largest (external link)
    immigration detention systems. Between 2014 and 2017, Mexico deported more Central Americans (external link)
    than the US Border Patrol. Doris Meissner, the former commissioner of the Immigration and Naturalization Service (INS, the predecessor to ICE and CBP), underscored the importance of Mexican migration control, explaining in 2017 the need to look at both US and Mexican data to assess the effectiveness of US border enforcement (external link)
    .10

    Under these agreements, the US Department of Defense has provided training and sold millions in military equipment to Mexico, including an array of ‘smart border’ technologies provided by corporations (external link)
    such as Dev Technology, General Dynamics, Amazon Web Services, and NEC. The CBP and ICE have provided training on intelligence-gathering, info-sharing, and migration policing. A key element of US support to Mexico has been to develop an infrastructure to collect and share data – such as biometric and biographical information, and criminal history – in a manner that interfaces seamlessly with US databases.

    The digital infrastructure that tracks and catalogues migrants is central to US migration policy in Mexico. The US-backed Instituto Nacional de Migración (INM) strategy relies on this infrastructure (external link)
    as the primary means to control migration rather than sealing Mexico’s southern border with Guatemala. Biometric collection is essential to making migrants more legible to the state. In 2011, the US provided four biometric kiosks (external link)
    to Mexico’s southern border, and 117 additional biometric scanners (external link)
    the following year. Between 2018 and the first half of 2022, the Mexican government gathered and shared information on over 360,000 migrants in detention facilities.11 Information from CBP reveals that Mexican authorities shared information from 10,000 humanitarian visa (external link)
    applications with DHS. The release of approximately 1,800 unregistered migrants from a shelter in Piedras Negras was conditional on the registration of their data.12

    An ‘Information Sharing Environment’ that includes inter-operable data-sharing systems (external link)
    is central to achieving the objectives of the homeland security state. ‘Inter-operability’ enables seamless connectivity between police, immigration agencies, foreign governments, and more.13 Key forms of US-initiated digital infrastructure rely on widespread information-gathering and seamless sharing of data for surveillance across borders.

    This vast amount of data-collection and sharing has been fuelled by unleashing the power of the carceral state – including the centrality of the ‘criminal alien’, ‘gang member’ and ‘drug trafficker’ as threats to national security – at all geographic levels of the US migrant-control regime. For example, the Biometric Identification Transnational Migration Alert Program (BITMAP) allows DHS and its partner countries to know where and when an individual arrives in the Western Hemisphere (external link)
    and their travel patterns before they reach the southwest US border. BITMAP is currently deployed to 18 countries (external link)
    , including Mexico. DHS also has a Criminal History Information Sharing (CHIS) programme that allows for the global sharing of biographic, biometric, and descriptive information on individuals deported from the US (e.g. alleged immigration, employment, family, and criminal histories).

    The structural criminalisation of poverty in both countries is amplified with CHIS. According to the National Survey of Imprisoned Population in Mexico, conducted by the National Institute of Geography and Statistics (INEGI) in 2021, nearly 44% of the respondents declared having been imprisoned on the basis of false accusations or incriminations (external link)
    . Forty-two percent claimed they had been forced to plead guilty or to incriminate someone else. Nearly half of those who are jailed have not been convicted (external link)
    , and nearly half of all convictions are for theft of under US$100 (external link)
    . This is the kind of data that feeds CHIS.

    In another example, DHS is developing the Homeland Advanced Recognition Technology System (HART) (external link)
    to replace its current centralised biometric database, IDENT, through a contract with Peraton (external link)
    (a subsidiary of Veritas Capital, a private equity firm). Hosted by Amazon Web Services, HART will enable DHS to aggregate and compare biographical and biometric data on hundreds of millions of people across the globe. This includes so-called encounter data from police stops, facial recognition, DNA, iris scans, and voice prints – usually gathered without the individual’s knowledge or consent. The massive HART database draws from widespread biometrics collection in all realms – for example, the US DOS INL’s development of integrated DNA databases in Mexico and Central America in the name of combating trafficking or the proposed national biometric digital ID in Mexico (external link)
    . In this way, multiple state initiatives merge, and the power of the state to police, track and control migrants and all people under their watch grows exponentially.

    While the Mérida Initiative formally ended in 2019, its approach has been sustained by the Mexican government. In 2021, the Mexican government increased (external link)
    the military by 46% and the National Guard dedicated to stopping migrants by 300%. In July 2022, President López Obrador committed $1.5 billion in smart border infrastructure (external link)
    over the next two years.

    For US partner states, any technological and data-sharing channels that are financed and exported to them become assets – not just for monitoring migrants, but to advance multiple agendas of coercive power-building. This infrastructure can therefore end up fuelling violence and criminalisation, undermining the right to asylum, exacerbating inequality, and expanding the power of paramilitaries and the police (external link)
    , while privileging securitised neoliberal and corporate prerogatives.
    The geopolitical nature of digital infrastructure

    In their research on digital payment systems, Marieke de Goede and Carola Westermeier use the term ‘infrastructural geopolitics’ to stress the growing centrality of infrastructure to geopolitics and the ways in which US economic power is rooted in financial infrastructures (which, like migration control, are rapidly digitising).14

    The global financial messaging network SWIFT is an example of infrastructure that is invisible to most people and yet plays a major role, as the writers describe, in reinforcing power relations of the post-war global order in which it emerged. Seventy years after the Second World War and fifty years since SWIFT’s establishment, bank messaging routes flow through former colonial capitals and map onto a ‘core’ of Western countries, leaving large swaths of Latin America, Africa, and the Middle East in a permanent, but effectively invisible, economic periphery. Similarly, digital IDs, social media monitoring and infiltration, and data-sharing platforms are essentially component parts, nodes, or partially visible layers of deeper, longer-term geo-strategic digital infrastructure projects.

    Extension of borders through digital infrastructure serves US political and economic goals well beyond the policing of human mobility. Geopolitical contests for control over infrastructures play out across several domains. Military establishments covet ‘identity dominance (external link)
    ’, an objective that drove US forces to gather massive stores of biometric data in Afghanistan and Iraq as a weapon of war. US digital services giants like Amazon and Google mastered ‘platformisation’ by building e-commerce (digital advertising, search, social media, etc.) infrastructure to dominate the digital economy. Often, public and private-sector interests converge, including in the form of public–private partnerships (PPPs) to build infrastructure. In each case, the true contest among states and corporate giants centres on control over the interface, or the most essential, invisible, infrastructural methods of digital communication and control. As Michael Kwet explains (external link)
    , ‘Transnational “Big Tech” corporations based in the United States have amassed trillions of dollars and gained excessive powers to control everything, from business and labor to social media and entertainment in the Global South. Digital colonialism is now engulfing the world’. The US quest for domination through externalised migration policing infrastructure goes hand in hand with its geopolitical and corporate designs for economic power.

    These forms of infrastructural digital power pose unique challenges for documentation and ultimately for any form of systemic change. Challenges include blurred lines of responsibility, mission, and function; governments and corporate actors are seen or presented as passive conduits or intermediaries in digital public infrastructure; and infrastructures can easily appear to be ‘ahistorical’ and motiveless. In Mexico and Central America, migration control converges with ongoing US foreign policing operations (such as the war on drugs, and gang wars). We explore the several simultaneous effects of this complex merger: the turn to digital infrastructure; its relationship to violence and human suffering; and its foreclosure of accountability for these harms.
    Digital border infrastructure in your phone: Information and Communications Technology (ICT) policing techniques along migration routes

    Surveillance infrastructure is tangible in physical migration detention centres and in police arrests: mugshots, cheek swabs, confiscation of the detainee’s mobile phone. The deepening integration of daily life, telecommunications and computers open extensive avenues for more covert, opportunistic surveillance of private communications and activity by users who rely on social media, mobile communication and messaging apps. The surveillance of mobile phones and social media ranges from overt disclosure requirements for visa and benefits applications to government listing and tracking of protesters and other ‘undesirable’ actors. Migrant surveillance is immersed in these control schemes where surveillance technology serves as a silent tool for government violence and repression.

    This has had an impact on how migrants travel and keep safe, such as through safety in numbers. Travelling in caravans has therefore become both a survival and a protest strategy: sources of both physical and economic security (external link)
    and opposition (external link)
    to the economic policies that contributed to their displacement. Social media and messaging apps are key tools for the coordination of caravans and for migrants more broadly. Migrants use these tools to identify routes, look for shelter and food, communicate with their support networks, warn each other about risks (external link)
    , and coordinate travel. Governments as well as organised crime understand these dynamics and use these same tools to monitor and extort migrants.

    On 5 June 2019, Irineo Mujica, from Sin Fronteras – a civil society organisation (CSO) dedicated to the protection of human rights of migrants in Mexico and the US, and which has supported multiple migrant caravans – was arrested in Mexico, falsely charged with human trafficking (external link)
    . Mujica appeared in the CBP’s watchlist database published in 2019 (external link)
    that contained photos, names, professions, and other details of journalists, activists, and social media influencers both from Mexico and the US with links to the migrant caravan.

    A DHS Office of Inspector General (OIG) report (external link)
    on the database and other surveillance practices found that CBP established electronic alerts (lookouts) on journalists, attorneys, and advocates who were connected by social media to the migrant caravans. Those tagged by the lookouts were constantly flagged for secondary screening (external link)
    when entering the US, and interrogated about their work, organisation, family, education, and political leanings.

    The weaponisation of such information had grim effects on the Mexican side of the border. According to Sin Fronteras activist Alex Mensing (external link)
    , after the CBP shared information gathered through lookouts with the Mexican government, other members from his organisation who assisted migrant caravans in the same period saw an increase in border scrutiny and death threats (external link)
    . Organising and supporting migrants threatens lucrative operations that depend on the criminalisation of migration across the region. Civil society assistance makes migrants less prone to kidnapping and extortion, which therefore reduces the income for organised crime linked to these activities, and, as a domino effect, bribes to authorities also drop, pitting the collective interests of such groups against activists and those providing humanitarian assistance.

    Surveilling anyone who might pose a threat to the system has long been a generalised and systematic form of government control in Mexico. A leaked document from the NSO Group, the Israeli company that created Pegasus, revealed that 50,000 people were possible surveillance targets (external link)
    in Mexico. The list included opposition politicians, journalists investigating government corruption and extrajudicial killings, activists advocating the taxing of sugary drinks, judges, academics, and international experts who investigated the case of the enforced disappearance and extrajudicial killing of the 43 students, among others.

    In 2022, mobile phones from two journalists and an activist who investigated abuses committed by the Mexican army were found to be infected with the malware Pegasus (external link)
    . In 2020, the Mexican government sought to create a SIM card registry that would link to the card owner’s biometrics and other personal data. This would have intensified government digital surveillance via ICT infrastructure, and was opposed by civil society (external link)
    .

    CBP internal documents show (external link)
    that government agencies across the border continually share information about the location of migrants, their origin, and the number of people in each group, even before they start to migrate. In 2018, US DHS agents infiltrated a WhatsApp group (external link)
    of Honduran migrants travelling in a caravan of about 4,000. These policing practices are also being reproduced by the Mexican government.15

    Impact: Infrastructural violence and accountability deficits in globalised migration policing

    Roberto M., a young man in El Salvador, was shot and taken away by police shortly after being deported from the US. The rural police officers who shot Roberto also threatened an eyewitness at gunpoint, telling him that Roberto was a gang member and if he revealed what he’d seen, the same would happen to him. Police in El Salvador receive data on gang-member affiliation from the US, and share these lists (external link)
    with neighbourhood-level police where deportees plan to live. These databases have been found to be problematic and unreliable (external link)
    . Police departments confirmed (external link)
    that this information is used to target people (external link)
    : ‘We think that if a person wasn’t wanted in the United States, it must be because the deported person is bad’.

    Violence can increasingly be tied to digital border technologies, particularly in combination with one another and with physical and environmental realities that envelop them. Studies show the effects of integrated fixed-tower surveillance on migrant mortality rates in Arizona’s Altar Valley. Here, digital infrastructure merges with the ineffective yet longstanding US deterrence policy that purposefully makes migration routes more dangerous, on the theory that migrants would not risk the journey. The fusion of technology and policies that inflict deliberate harm produces these predictable results of increased migrant deaths (external link)
    .

    The story of Roberto M. and the witness to his post-deportation shooting and disappearance in El Salvador reflects another pattern of violence tied to information-sharing through digital infrastructures. The criminologist Ana Muñiz documents a ‘cycle of violent policing, migration, more violent policing, detention, deportation, violent policing, migration, and so on’, in which the labels themselves (‘criminal alien’ or ‘gang member’) become inescapable vectors of precarity.16 Such labels channel individuals into a ‘sort of statelessness’ as constant, quantifiable scapegoats that provide an easy diversion for state security forces and corporations that produce and perpetuate the ‘structural causes of violence’.17

    Digital infrastructure merges not with a physical terrain, but with pre-existing social and political factors that make violence a foregone conclusion. Today’s multipurpose digital infrastructure also permits the efficient incorporation of new undesirable criminalised categories, including ‘caravan organisers’ or ‘migration promoters’ – as in El Salvador’s attempt (external link)
    to reform its penal code, criminalising the ‘promotion of migration’ on social media.
    Challenges and way forward

    We are interested in developing deeper knowledge about the political origins of these infrastructures to challenge the violence of global migration control systems. This essay only sets out the field of engagement. Far more collective work is required to document and design models of resistance to meet such challenges.

    The diffuse and structural nature of power behind the seemingly ahistorical, and motiveless characteristics of digital infrastructures undermine classic approaches to accountability. Furthermore, the familiar national and international judicial avenues to hold perpetrators of these forms of indirect violence responsible – however imperfect or ineffective they may already be – are exceptionally ill-suited to the conditions at play in the migration policing context specifically, for several reasons.

    First, the technologies in use such as biometric databases, and the means of using civilian technologies like social media and other ICTs, are simply not designed to respect or be held to democratic scrutiny; they are military-grade and converted for use in quasi-militarised spaces, by institutions permeated with military ideology. Nearly a third of CBP personnel previously served in the US military. Biometric surveillance technologies advanced by leaps and bounds within US military operations before being integrated with ‘civilian’ border policing. Private-sector military contractors play an integral role in this transition.

    As journalist Annie Jacobsen documents, as part of the US military biometric data-collection in Afghanistan, Palantir Technologies served as a critical link between US intelligence operations to track and kill military targets and quasi-civilian policing operations like the piloting of rapid DNA samples from migrant families at the US border in 2019.18 Today, the biometric kits used in Afghanistan, some still storing biometric data collected on the battlefield, are for sale on eBay (external link)
    .

    Second, justice and oversight bodies are ill-equipped to serve their intended function in this ecosystem. Within criminal proceedings and investigations, the use of technologies that capture and record evidence of allegedly criminal activity or purport to biometrically match records are extremely difficult to challenge because of their scientific veneer and opaque data-collection and analysis methods, which leaves no practical room (external link)
    to impeach or exclude such evidence. The design of technologies that predetermine risk factors keyed to criminalised behaviour, including migration, contravenes the presumption of innocence. In the civil context, national-level justice mechanisms deny standing to non-nationals located outside the US who are victims of violations linked to digital surveillance.

    Finally, there are huge incentives for both state and corporate power to hide violence. The political positioning of ‘smart borders’ as more ‘humane’ conceals the state’s role in violence and insulates corporations from negative PR or constraints by participating in repugnant markets. Their task is made easy by rendering physical pain abstract rather than affecting real human beings,19 and features of the data economy like the way corporates have helped the movement towards running government functions like private digital platforms.

    Mitigation ‘risk assessment’ tools like data protection or human rights impact assessments provide cover (external link)
    , favouring the continuation of these business practices because firms undertake them voluntarily and face little or no consequences for a poor risk assessment. Unsurprisingly, these industry-led tools often fail to provide (external link)
    a means for real accountability; they reveal scant information that would be actionable if and when products do cause harm; and the burden of proving rights violations and finding an effective remedy (external link)
    after the fact is shouldered entirely by victims. The interests of powerful actors converge around a web of financial stakes in the system, leading to the aggressive harassment and potential silencing of activists as the case of Irineo Mujica and Sin Fronteras illustrates.

    We need tools and methods for transnational cooperation to document, gather and share information safely, and organise. Fusing new understandings about how digital power functions within existing resistance movements transnationally, holds potential for challenges to the digital infrastructure of border externalisation.

    We are in the initial stages of our collective effort to understand and expose this digital infrastructure. Through this analysis, we can begin to identify the interventions to start to tear it apart and break it down. Transnational organising against tech corporations offers opportunities for shared understanding and meaningful solidarity. This year, organisations in France and Kenya, with support from actors in other countries, sued biometrics giant IDEMIA (external link)
    for its failure to meet even minimum human rights standards of due diligence as it reaps billions in secret border security tech sales to low- and middle-income countries. This emerged from collaborative evidence-gathering and organising across borders.

    As the US military establishment recognised decades ago: whoever dominates the field of externalised borders defines ‘friend and foe’ everywhere.20 The faster the US establishes economic and political dominance over digital migration-control infrastructure, the greater its security in maintaining global digital power. Digital infrastructure serves multiple purposes at once, but the ultimate geopolitical function is raw, generalised power over global affairs. The tools examined here will ‘contain’ human life within spaces of catastrophic violence, by design. This specific effect betrays the most fundamental commitments of international human rights and humanitarian law in the face of unprecedented challenges to human survival across most of the world. But this pernicious effect is also ruthlessly beside the point.

    In reality, as facets of infrastructural power, the technologies that fix the ‘calculation of who must live and who must die’22 do not do so as an end in itself, but in the service of power and its reproduction in this digital age.23 In this way the complicity of state and corporate actors in the production of violence is cast in the starkest relief. This geopolitical analysis is our starting point for building resistance towards transformation.

    https://www.tni.org/en/article/the-everywhere-border
    #externalisation #migrations #frontières #réfugiés #USA #Etats-Unis #infrastructure #infrastructure_numérique #violence #violence_d'Etat #surveillance #caravane #whatsapp #criminalisation_de_la_migration #arrestation #technologie #technologie_intelligente #externalisation_des_contrôles_frontaliers #bases_de_données #interopérabilité #empreintes_digitales #coopération_policière #impérialisme #biométrie #Mérida_Initiative #Central_American_Regional_Security_Initiative #war_on_drugs #Amérique_centrale #Mexique #Programa_Frontera_Sur #rétention #détention_administrative #ICE #smart_borders #frontières_intelligentes #Dev_Technology #General_Dynamics #Amazon_Web_Services #complexe_militaro-industriel #NEC #Instituto_Nacional_de_Migración (#INM) #Guatemala #Biometric_Identification_Transnational_Migration_Alert_Program (#BITMAP) #Criminal_History_Information_Sharing (#CHIS) #criminalité #Homeland_Advanced_Recognition_Technology_System (#HART) #IDENT #Peraton #Veritas_Capital #reconnaissance_faciale #ADN #DOS_INL #infrastructural_geopolitics #géopolitique #SWIFT #multinationales #colonialisme_numérique #téléphones_portables #smartphones #criminalisation_de_la_solidarité #NSO_Group #border_deaths #décès #morts_aux_frontières #mourir_aux_frontières

  • Amazon Drops ‘Draconian’ Policy on Making Games After Work Hours - Bloomberg
    https://www.bloomberg.com/news/articles/2021-08-12/amazon-drops-company-policies-on-game-development-after-backlash

    Amazon.com Inc. withdrew a set of staff guidelines that claimed ownership rights to video games made by employees after work hours and dictated how they could distribute them, according to a company email reviewed by Bloomberg.

    Amazon abandonne ses prétentions sur les droits d’exploitation des jeux vidéo développés sur le temps libre de ses salariés, les forçant jusque là d’abreuver l’écosystème d’Amazon.

    #jeu_vidéo #jeux_vidéo #amazon #business #propriété_intellectuelle #droits_d'exploitation #boutique #ecommerce #aws #amazon_web_services

  • Les États-Unis mettent hors service une société israélienne de logiciels d’espionnage Moon of Alabama
    https://www.moonofalabama.org/2021/07/us-takes-down-israeli-spy-software-company.html#more
    https://lesakerfrancophone.fr/les-etats-unis-mettent-hors-service-une-societe-israelienne-de-lo

    Un certain nombre de journaux, dans le monde entier, parlent aujourd’hui https://www.theguardian.com/world/2021/jul/18/revealed-leak-uncovers-global-abuse-of-cyber-surveillance-weapon-nso-gr de la société de piratage israélienne NSO qui vend des logiciels d’espionnage [nommés Pegasus, NdT] à divers régimes. Ce logiciel est ensuite utilisé pour espionner les téléphones des ennemis du régime, des adversaires politiques ou des journalistes qui déplaisent. Tout cela était déjà bien connu, mais l’histoire a pris un nouvel essor puisque plusieurs centaines de personnes qui sont espionnées peuvent maintenant être nommées.

    La façon dont cela s’est produit est intéressante https://www.washingtonpost.com/gdpr-consent/?next_url=https%3a%2f%2fwww.washingtonpost.com%2finvestigations%2fin :

    Les téléphones sont apparus sur une liste de plus de 50 000 numéros concentrés dans des pays connus pour surveiller leurs citoyens et également connus pour avoir été clients de la société israélienne NSO Group, un leader mondial dans le secteur, en pleine expansion et largement non réglementé, des logiciels d’espionnage privés, selon l’enquête.

    La liste ne permet pas de savoir qui y a inscrit les numéros, ni pourquoi, et on ignore combien de téléphones ont été ciblés ou surveillés. Mais l’analyse technique de 37 smartphones montre que beaucoup d’entre eux présentent une corrélation étroite entre les horodatages associés à un numéro de la liste et le déclenchement de la surveillance, dans certains cas aussi brève que quelques secondes.

    Forbidden Stories, une organisation de journalisme à but non lucratif basée à Paris, et Amnesty International, une organisation de défense des droits de l’homme, ont eu accès à cette liste et l’ont partagée avec certains journaux, qui ont effectué des recherches et des analyses supplémentaires. Le Security Lab d’Amnesty International a effectué les analyses techniques des smartphones.

    Les chiffres figurant sur la liste ne sont pas attribués, mais les journalistes ont pu identifier plus de 1 000 personnes dans plus de 50 pays grâce à des recherches et des entretiens sur quatre continents.

    Qui aurait pu dresser une telle liste pour la donner à Amnesty et à Forbidden Stories ?

    NSO est l’une des sociétés israéliennes utilisées pour mettre sur le marché le travail de l’unité de renseignement militaire israélienne, 8200. Les « anciens » membres de 8200 sont employés par NSO pour produire des outils d’espionnage qui sont ensuite vendus à des gouvernements étrangers. Le prix de la licence est de 7 à 8 millions de dollars pour 50 téléphones à espionner. C’est une affaire louche mais lucrative pour cette société et pour l’État d’Israël.

    NSO nie les allégations selon lesquelles son logiciel est utilisé pour des objectifs malsains en racontant beaucoup de conneries https://www.nsogroup.com/Newses/following-the-publication-of-the-recent-article-by-forbidden-stories-we-wa :

    Le rapport de Forbidden Stories est rempli d’hypothèses erronées et de théories non corroborées qui soulèvent de sérieux doutes sur la fiabilité et les intérêts de leurs sources. Il semble que ces "sources non identifiées" aient fourni des informations qui n’ont aucune base factuelle et sont loin de la réalité.

    Après avoir vérifié leurs affirmations, nous démentons fermement les fausses allégations faites dans leur rapport. Leurs sources leur ont fourni des informations qui n’ont aucune base factuelle, comme le montre l’absence de documentation à l’appui de nombre de leurs affirmations. En fait, ces allégations sont tellement scandaleuses et éloignées de la réalité que NSO envisage de porter plainte pour diffamation.

    Les rapports affirment, par exemple, que le gouvernement indien du Premier ministre Narendra Modi a utilisé le logiciel de NSO pour espionner https://thewire.in/government/rahul-gandhi-pegasus-spyware-target-2019-polls le chef du parti d’opposition, Rahul Gandhi.

    Comment NSO pourrait-elle nier cette allégation ? Elle ne le peut pas.

    Plus loin dans la déclaration de NSO, la société se contredit https://www.nsogroup.com/Newses/following-the-publication-of-the-recent-article-by-forbidden-stories-we-wa sur ces questions :

    Comme NSO l’a déclaré précédemment, notre technologie n’a été associée en aucune façon au meurtre odieux de Jamal Khashoggi. Nous pouvons confirmer que notre technologie n’a pas été utilisée pour écouter, surveiller, suivre ou collecter des informations le concernant ou concernant les membres de sa famille mentionnés dans l’enquête. Nous avons déjà enquêté sur cette allégation, qui, une fois encore, est faite sans validation.

    Nous tenons à souligner que NSO vend ses technologies uniquement aux services de police et aux agences de renseignement de gouvernements contrôlés dans le seul but de sauver des vies en prévenant la criminalité et les actes terroristes. NSO n’exploite pas le système et n’a aucune visibilité sur les données.

    Comment NSO peut-elle nier que le gouvernement saoudien, l’un de ses clients reconnus, a utilisé son logiciel pour espionner Jamal Khashoggi, puis l’assassiner, en disant qu’il « n’exploite pas le système » et « n’a aucune visibilité sur les données » ?

    Vous ne pouvez pas prétendre à la fois a. recueillir des informations et b. n’avoir aucun moyen de les recueillir.

    Mais revenons à la vraie question :
    • Qui a la capacité de dresser une liste de 50 000 numéros de téléphone dont au moins 1 000 ont été espionnés avec le logiciel de NSO ?
    • Qui peut faire « fuiter » une telle liste à ONG et s’assurer que de nombreux médias « occidentaux » s’en emparent ?
    • Qui a intérêt à faire fermer NSO ou du moins à rendre ses activités plus difficiles ?

    La concurrence, je dirais. Et le seul véritable concurrent dans ce domaine est l’Agence nationale de sécurité [la NSA, NdT] étatsunienne.

    Les États-Unis utilisent souvent le « renseignement » comme une sorte de monnaie diplomatique pour maintenir les autres pays dans une situation de dépendance. Si les Saoudiens sont obligés de demander aux États-Unis d’espionner quelqu’un, il est beaucoup plus facile d’avoir de l’influence sur eux. Le NSO gêne cette activité. Il y a aussi le problème que ce logiciel d’espionnage de première classe que NSO vend à des clients un peu louches pourrait bien tomber entre les mains d’un adversaire des États-Unis.

    La « fuite » à Amnesty et Forbidden Stories est donc un moyen de conserver un certain contrôle monopolistique sur les régimes clients et sur les technologies d’espionnage. (Les Panama Papers étaient un type similaire de « fuite » parrainée par les États-Unis, mais dans le domaine financier).

    Edward Snowden, qui était autrefois un partisan convaincu de la NSA mais qui en a divulgué des documents parce qu’il voulait qu’elle respecte la loi, soutient cette campagne :

    Edward Snowden @Snowden - 16:28 UTC - 18 juil. 2021 https://twitter.com/Snowden/status/1416797153524174854

    Arrêtez ce que vous êtes en train de faire et lisez ceci. Cette fuite va être l’histoire de l’année : https://www.theguardian.com/world/2021/jul/18/revealed-leak-uncovers-global-abuse-of-cyber-surveillance-weapon-nso-gr

    Edward Snowden @Snowden - 15:23 UTC - 19 juil. 2021 https://twitter.com/Snowden/status/1417143168752095239

    Il y a certaines industries, certains secteurs, contre lesquels il n’y a aucune protection. Nous n’autorisons pas un marché commercial pour les armes nucléaires. Si vous voulez vous protéger, vous devez changer la donne, et la façon dont nous le faisons est de mettre fin à ce commerce.
    Guardian : Edward Snowden demande l’interdiction du commerce de logiciels espions dans le cadre des révélations sur Pegasus https://www.theguardian.com/news/2021/jul/19/edward-snowden-calls-spyware-trade-ban-pegasus-revelations

    Edward Snowden semble vouloir dire https://www.theguardian.com/news/2021/jul/19/edward-snowden-calls-spyware-trade-ban-pegasus-revelations que NSO, qui ne vend ses logiciels qu’aux gouvernements, devrait cesser de le faire mais que la NSA devrait continuer à utiliser cet instrument d’espionnage :

    Dans une interview accordée au Guardian, M. Snowden a déclaré que les conclusions du consortium illustraient la manière dont les logiciels malveillants commerciaux avaient permis aux régimes répressifs de placer beaucoup plus de personnes sous une surveillance invasive.

    L’opinion de Snowden à ce sujet est plutôt étrange :
    chinahand @chinahand - 17:28 UTC - 19 juil. 2021 https://twitter.com/chinahand/status/1417174487678656527

    Fascinant de voir comment M."La surveillance étatique américaine est la plus grande menace pour l’humanité" s’énerve sur le fait qu’un peu de surveillance étatique est apparemment externalisée à un entrepreneur privé par des acteurs étatiques de niveau moyen et bas.

    Edward Snowden @Snowden - 17:06 UTC - 19 juil. 2021 https://twitter.com/Snowden/status/1417168921472405504

    Lisez les articles sur les fonctionnaires de Biden, Trump et Obama qui ont accepté de l’argent du groupe NSO pour enterrer toute responsabilité, même après leur implication dans la mort et la détention de journalistes et de défenseurs des droits dans le monde entier !
    WaPo : Comment les assoiffés de pouvoir de Washington ont profité des ambitions de NSO en matière d’espionnage https://www.washingtonpost.com/gdpr-consent/?next_url=https%3a%2f%2fwww.washingtonpost.com%2ftechnology%2f2021%2

    Le tumulte créé dans les médias par les révélations concernant NSO a déjà eu l’effet escompté https://www.vice.com/en/article/xgx5bw/amazon-aws-shuts-down-nso-group-infrastructure :

    Amazon Web Services (AWS) a fermé l’infrastructure et les comptes liés au fournisseur israélien de logiciels de surveillance NSO Group, a déclaré Amazon dans un communiqué.

    Cette mesure intervient alors que des médias et des organisations militantes ont publié de nouvelles recherches sur les logiciels malveillants de NSO et les numéros de téléphone potentiellement sélectionnés pour être ciblés par les gouvernements clients de NSO.

    "Lorsque nous avons appris cette activité, nous avons agi rapidement pour fermer l’infrastructure et les comptes concernés", a déclaré, dans un courriel, un porte-parole d’AWS à Motherboard.
    Cela fait des années qu’AWS est au courant des activités de NSO. NSO a utilisé CloudFront, un réseau de diffusion de contenu appartenant à Amazon :

    L’infrastructure de CloudFront a été utilisée pour déployer les logiciels malveillants de NSO contre des cibles, notamment sur le téléphone d’un avocat français spécialisé dans les droits de l’homme, selon le rapport d’Amnesty. Le passage à CloudFront protège aussi quelque peu NSO contre des enquêteurs ou d’autres tiers qui tenteraient de découvrir l’infrastructure de l’entreprise.

    "L’utilisation de services en nuage protège NSO Group de certaines techniques de balayage d’Internet", ajoute le rapport d’Amnesty.

    Cette protection n’est plus valable. NSO aura bien du mal à remplacer un service aussi pratique.

    Israël s’en plaindra, mais il me semble que les États-Unis ont décidé de faire fermer NSO.

    Pour vous et moi, cela ne réduira que marginalement le risque d’être espionné.
    Moon of Alabama
    Traduit par Wayan, relu par Hervé, pour le Saker Francophone

    #nso #NSA #israel #Amnesty #police #agences_de_renseignement #Edward_Snowden #CloudFront #surveillance #pegasus #spyware #écoutes #smartphone #journalisme #hacking #sécuritaire #espionnage #géolocalisation #jamal_khashoggi #Forbidden_Stories #Amazon #Amazon_Web_Services #AWS
    #USA #CloudFront

    • La firme derrière Pegasus est liée au Luxembourg
      http://www.lessentiel.lu/fr/luxembourg/story/la-firme-derriere-pegasus-est-liee-au-luxembourg-15258218

      Jean Asselborn, ministre des Affaires étrangères, a confirmé l’existence au Luxembourg de deux bureaux de la firme israélienne NSO Group, qui a conçu le logiciel Pegasus, accusé d’avoir été utilisé par plusieurs États pour espionner les téléphones de journalistes et de dissidents.

      Selon le ministre, les bureaux luxembourgeois servent au back office, c’est-à-dire au contrôle des opérations financières de l’entreprise. Un communiqué de l’entreprise datant de 2019 précise que le siège social se trouve au Luxembourg. « NSO développe des technologies qui aident les services de renseignements et les agences étatiques à prévenir et enquêter sur le terrorisme et le crime », indique l’entreprise, dans sa présentation. Il serait même « un leader mondial » en la matière, générant « 250 millions de dollars de revenus en 2018 ». NSO affirme aussi s’être passé de clients à cause d’un non-respect des droits de l’homme.

      Un tour politique
      Mais la nature des activités au Grand-Duché reste floue. D’après Amnesty International, le logiciel Pegasus n’a pas été conçu au Grand-Duché. Aucune demande d’exportation de produit n’a d’ailleurs été formulée. « Je ne peux dire qu’une chose. S’il s’avère que le groupe NSO au Luxembourg a commis des violations des droits de l’homme, alors le Luxembourg doit réagir et réagira », a déclaré Asselborn. Ce dernier a envoyé une lettre aux dirigeants concernés pour rappeler les obligations en matière de droits de l’homme.

      Le sujet n’a pas encore été évoqué en commission des Affaires étrangères à la Chambre, expliquent des députés concernés. L’affaire a cependant vite pris un tour politique, avec d’abord une question parlementaire urgente du parti Pirates, sommant le gouvernement d’indiquer si des journalistes, politiciens ou militants au Luxembourg sont concernés par le scandale d’espionnage et quels sont les liens entre NSO et le Grand-Duché. Le parti déi Lénk demande aux autorités de réagir, bien au-delà du « Pacte national entreprises et droits de l’homme », avec une « loi opposable et munie des moyens financiers et personnels permettant d’intervenir pour mettre fin au mépris envers les droits humains ».

    • Hilarants ces politiques et ces journalistes choqués par leur surveillance !

      On n’a pas arrêté, ces dernières années, d’étendre toujours plus la surveillance du citoyen, depuis l’extension des caméras de surveillance partout sur le territoire jusqu’à la reconnaissance faciale qui ne cesse de progresser, y compris en France, jamais en retard d’une idée pour nous pister, nous surveiller, nous fliquer.

      Une surveillance active, intrusive, poussée, de plus en plus vicelarde, de certaines cibles aisément identifiées par ceux qui sont pouvoir, pour le profit personnel des politiciens et de leurs amis.

      Pour elles et eux, les drones qui seront sans nul doute utilisés pour mieux canaliser les mouvements de foule, les manifestations, pas de problème.
      Pour elles et eux, la loi européenne « ePrivacy » qui instaure de manière dérogatoire une surveillance automatisée de masse des échanges numériques sur internet en Europe, pas de problème.
      Le smartphone obligatoire, pas de problème.

      Ne parlons pas des données sur nos enfants, envoyées directement chez microsoft, education nationale, santé . . .
      Ne parlons pas non plus de toutes les informations possibles et imaginables que les gafam nous volent, de façon de plus en plus vicieuse.

      Pegasus, ePrivacy, pass sanitaire, la société qui se dessine ces dernières semaines devient véritablement cauchemardesque.
      Bon, d’après Edward Snowden la NSA n’aimait pas la concurrence pour ce qui est de nous espionner, et Julian Assange est toujours en prison, en Angleterre, sans aucun motif.

      Pour le reste, l’essentiel, c’est de monter à dessein les habitants de ce pays les uns contre les autres, et c’est une réussite.

  • Vaccination : le partenariat avec Doctolib contesté devant le Conseil d’Etat
    https://www.mediapart.fr/journal/france/260221/vaccination-le-partenariat-avec-doctolib-conteste-devant-le-conseil-d-etat

    Un collectif de professionnels de la santé reproche à Doctolib d’avoir confié l’hébergement des données des patients à Amazon Web Services, une société soumise au droit américain et aux programmes de surveillance permis par celui-ci.

    Un collectif a déposé, jeudi 25 février, une requête devant le Conseil d’État visant à obtenir l’annulation du partenariat passé entre le gouvernement et Doctolib pour la prise de rendez-vous dans le cadre de la campagne de vaccination contre le Covid-19.

    Ce référé-liberté, que Mediapart a pu consulter, a été signé par des professionnels de santé, le collectif InterHop, le professeur Didier Sicard, le Syndicat de la médecine générale, l’Union pour une médecine libre, le Syndicat national des jeunes médecins généralistes et la Fédération des médecins de France, ainsi que par des associations de patients, comme ActUp santé Sud-Ouest ou Marie Citrini, représentante des usagers de l’AP-HP.

    Ils reprochent à la société franco-allemande de mettre en danger les données personnelles des patients en confiant leur hébergement à Amazon Web Services (AWS), une société soumise au droit américain et donc aux programmes de surveillance permis par celui-ci.

    L’annonce de ce partenariat entre le gouvernement et Doctolib avait été faite le mardi 12 janvier par le ministre de la santé Olivier Véran lors d’une audition par la commission des affaires sociales de l’Assemblée nationale. Comme l’a indiqué celui-ci à l’époque, ce sont en fait trois prestataires qui ont été sélectionnés par le gouvernement : les sociétés Doctolib, Maiia et Keldoc. Ce choix a été opéré à la dernière minute, l’État n’ayant pas anticipé ce sujet lors de la construction en catastrophe de son système d’information pour le suivi de la vaccination.

    Cependant, comme le souligne la requête rédigée par Me Juliette Alibert, la plateforme du leader français du secteur est celle vers laquelle les candidats à la vaccination sont renvoyés afin de prendre un rendez-vous. Les requérants expliquent en effet avoir réalisé, le 25 janvier dernier, une « analyse du site Santé.fr », sur lequel les patients doivent se rendre pour prendre rendez-vous.

    Celle-ci révèle « que 861 centres de vaccination passent par la solution de prise de rendez-vous en ligne Doctolib, contre 39 et 97 pour les deux autres solutions (respectivement Maiia et Keldoc) », affirme la requête, soit un taux de redirection de « plus de 80 % ».

    Un chiffre correspondant à un décompte effectué par Mediapart mardi 2 février qui avait alors recensé 925 centres de vaccination utilisant Doctolib, sur un total de 1 133, soit une proportion de 81,6 %.

    En plus d’être en situation de quasi-monopole, Doctolib collecte une quantité importante de données sensibles. Le patient doit tout d’abord donner, lors de son inscription, son identité, sa date de naissance, son adresse mail et son téléphone. Il doit également indiquer le « motif de la consultation », c’est-à-dire la raison pour laquelle il fait partie des personnes prioritaires pour la vaccination.

    Le patient doit ainsi préciser s’il a plus de 75 ans, s’il est un professionnel ou s’il est atteint d’une des « pathologies à haut risque » ouvrant droit à un vaccin, comme les cancers, les maladies rénales ou certaines maladies rares.

    Le recours pointe que, de surcroît, Doctolib dispose déjà d’une importante quantité d’informations sur de nombreux patients, collectées à l’occasion de ses activités habituelles. Ainsi, il y a de fortes chances que des patients souhaitant se faire vacciner disposent déjà chez Doctolib d’un « historique » résumant leurs rendez-vous pris via la plateforme.

    « En croisant les données recueillies en lien avec la vaccination contre le Covid-19 avec l’historique des rendez-vous, il est possible de définir directement les pathologies dont souffre le patient et de renseigner son état de santé », s’inquiètent les requérants. Ils citent l’exemple d’un candidat à la vaccination dont l’historique révélerait de nombreux rendez-vous chez un néphrologue. « Il est dès lors très facile d’en déduire, en croisant les données, qu’il est prioritaire en raison d’une maladie rénale sévère, voire nécessitant d’être dialysé. »

    Mais leur principale critique porte sur les conditions d’hébergement des données de Doctolib. La société a en effet choisi d’avoir recours à la société américaine Amazon Web Services. Or, pointe la requête, cette solution emporte le risque de voir ces données visées par les programmes de surveillance permis par le droit américain, comme l’a d’ailleurs déjà reconnu le Conseil d’État en fin d’année 2020.

    En effet, au mois d’octobre dernier, un collectif avait déjà contesté devant le juge administratif le choix du gouvernement en matière d’hébergement de données de santé. À l’époque, il s’agissait de celles détenues par le Health Data Hub, la gigantesque plateforme devant centraliser, à terme, l’ensemble des données de santé des Français en confiant l’hébergement de celles-ci à la solution Azure de Microsoft.

    Ce recours se fondait sur un arrêt rendu le 16 juillet 2020 par la Cour de justice de l’Union européenne (CJUE) ayant annulé le « bouclier de protection des données », ou Privacy Shield, accord qui régissait les transferts de données personnelles entre les États-Unis et les pays de l’Union européenne.

    Or, dans cette décision, la CJUE ne se contentait pas d’évoquer le simple cas des transferts volontaires de données et s’inquiétait des cas de transferts imposés ou de consultations à distance par des agences américaines. Elle pointait les dangers de deux textes, le « Foreign Intelligence Surveillance Act » (Fisa) et l’« Executive Order ( EO) 12333 » régissant des programmes de surveillance américains, « qui instituent des programmes permettant l’accès des autorités publiques états-uniennes à des fins de sécurité nationale aux données personnelles transférées de l’UE vers les États-Unis, de façon particulièrement large et sans ciblage ». Parmi ces programmes figurent Prism et UpStream, dont l’ampleur avait été révélée par Edward Snowden en 2013 et qui ont été depuis maintenus.

    Interrogée sur cette question dans le cadre de la procédure contre le Health Data Hub, la Commission nationale de l’informatique et des libertés (Cnil) avait, le jeudi 8 octobre, transmis au Conseil d’État un mémoire dans lequel elle rejoignait l’analyse de la CJUE.

    « Même dans le cas où l’absence de transferts de données personnelles en dehors de l’UE à des fins de fourniture du service serait confirmée, affirmait la Cnil, la société Microsoft peut être soumise, sur le fondement du Fisa, voire peut-être de l’EO 12333, à des injonctions des services de renseignement l’obligeant à leur transférer des données stockées et traitées sur le territoire de l’Union européenne. »

    En conséquence, la commission appelait tout simplement l’État à cesser « dans un délai aussi bref que possible » de confier l’hébergement des données de santé des Français à Microsoft ou toute autre société soumise « au droit états-unien ».

    Ces inquiétudes semblaient avoir été entendues par le gouvernement. Dès le jour de la transmission du mémoire de la Cnil, à l’occasion d’une audition au Sénat, le secrétaire d’État au numérique Cédric O avait fait part de sa volonté de trouver une autre solution d’hébergement. « Nous travaillons avec Olivier Véran, après le coup de tonnerre de l’annulation du Privacy Shield, au transfert du Health Data Hub sur des plateformes françaises ou européennes », avait-il affirmé.

    Dans sa décision, rendue le vendredi 14 octobre, le Conseil d’État avait rejeté le recours de SantéNathon en raison de l’utilité du Health Data Hub dans le cadre de la lutte contre l’épidémie, mais tout en reconnaissant les risques de transferts pointés par la Cnil. Il appelait les autorités à concrétiser, « dans les délais les plus brefs possible », leurs engagements.

    Dans un courrier envoyé à la présidente de la Cnil Marie-Laure Denis, et révélé par Mediapart le 22 novembre 2020, Olivier Véran affirmait même souscrire « pleinement » aux craintes exprimées par la Cnil dans son mémoire et s’engageait à trouver une solution technique « dans un délai qui soit autant que possible compris entre 12 et 18 mois et qui, en tout état de cause, ne dépasse pas deux ans ».

    Lundi 22 février, c’est la Caisse nationale d’assurance-maladie (Cnam) qui dénonçait, dans un communiqué, le risque de confier les données de santé des Français à une entreprise américaine. « Les conditions juridiques nécessaires à la protection de ces données ne semblent pas réunies pour que l’ensemble de la base principale soit mise à disposition d’une entreprise non soumise exclusivement au droit européen […] indépendamment de garanties contractuelles qui auraient pu être apportées », écrivait-elle au sujet du Health Data Hub.

    « Il s’avère donc qu’ensemble, la CJUE, la Cnil, la Cnam […], le Conseil d’État et le gouvernement lui-même reconnaissent que l’état de la législation américaine ne permet pas une conciliation avec le droit à la protection des données tel que régi par le RGPD, que les données soient hébergées ou non dans l’Union européenne », résume la requête contre le partenariat de Doctolib.

    Pour les requérants, la société française, en recourant aux services d’Amazon, se place dans la même situation que le Health Data Hub avec Microsoft. « Par analogie […], les risques qui entourent l’entrepôt de données de santé hébergé par une société de droit américain sont identiques à ceux liés à une solution privée de prise de rendez-vous dont les données de santé sont hébergées par une société de droit américaine », affirment-ils.

    En conséquence, ils demandent au Conseil d’État d’ordonner « la suspension du partenariat avec Doctolib » et, « au ministère de la santé, d’avoir recours à d’autres solutions de gestion de la prise de rendez-vous ». La requête demande, subsidiairement, au juge administratif de solliciter la Cnil afin d’obtenir son analyse sur cette affaire. Si le référé-liberté est jugé recevable par le Conseil d’État, celui-ci devra normalement se prononcer dans les 48 heures.

    Contacté par Mediapart vendredi dans la journée, Doctolib explique n’avoir pas encore eu connaissance du recours et ne dispose « à date d’aucun élément sur ce sujet ». La société renvoie à sa page consacrée à la protection des données et souligne avoir « pris depuis 2013 des engagements forts pour protéger la vie privée et la sécurité des données de » ses utilisateurs.

    Concernant le recours aux services d’Amazon, Doctolib affirme avoir, depuis mai 2019, « publiquement recours à AWS comme partenaire pour l’hébergement sécurisé des données de santé ». La société souligne le fait que la société américaine héberge ses données « en France et en Allemagne ». Elle a par ailleurs été certifiée « hébergeur de données de santé » et « est à ce jour l’un des tout premiers hébergeurs du monde, notamment en matière de protection des données ».

    « Doctolib a par ailleurs mis en place un chiffrement systématique de l’ensemble des données hébergées chez AWS. Les clefs de chiffrement et déchiffrement sont quant à elles hébergées en France chez un hébergeur français », insiste la société.

    Enfin, concernant le partenariat passé avec le ministère de la santé, Doctolib renvoie vers celui-ci. « Nous pouvons simplement vous dire que nous sommes mobilisés jour et nuit pour aider les citoyens à accéder facilement à la vaccination et les centres de vaccination à gérer cette campagne », ajoute la société.

    Également contacté, le ministère de la santé n’avait, lui, pas encore réagi vendredi en fin d’après-midi.
    #Amazon #AmazonWebServices-AWS #Doctolib #données #CloudComputing #COVID-19 #santé #PrivacyShield (...)

    ##santé ##CJUE

  • Amazon Bares Its Computers - NYTimes.com
    Quentin Hardy - 15/11/13
    http://bits.blogs.nytimes.com/2013/11/15/amazon-bares-its-computers

    In a startling talk Thursday evening, a vice president who oversees the internal engineering of Amazon’s global computing system described how Amazon is building its own specialized computers, data storage systems, networking systems, even power substations and optical transmissions systems. In every case, he said, #Amazon_Web_Services [a system on which the company is thought to spend perhaps $1 billion annually] had developed ways to make its computers run cheaper and more efficiently than standard commercial products.

    Every significant component, including semiconductors and disk drives, is purchased directly, to keep the price down and to manage a chain of supply, assembly and installation that adds every day the equivalent of all the computing Amazon owned in 2004. “Every day. On the weekend, too,” Mr. Hamilton said.

    Où l’on apprend qu’#Amazon a son propre réseau de #fibre_optique, se montre assez #secret sur les technologies utilisées, ne participe pas aux discussions sur les #standards, tout en étant la seule entreprise de cette échelle à améliorer à ce point (en réduisant les coûts) son #infrastructure informatique (sur laquelle est assise son offre de #cloud#AWS donc).

    Avec Alpha House – Amazon se lance aussi dans la série télé
    http://seriestv.blog.lemonde.fr/2013/11/16/alpha-house-amazon-se-lance-dans-la-serie-tele #tv_shows

    Même si les choses ne sont pas dites aussi clairement, il apparaît évident que la démarche d’Amazon est de venir directement concurrencer #Netflix, en ne lui laissant pas le champ libre d’une création originale en marge des traditionnels circuits de la diffusion par les chaînes de télévision.