news2mail.com

HomeComp › Society

comp.society.privacy

Privacy in the computing age (moderated).

comp.society.privacy was the moderated forum for privacy as a social question — data protection, workplace surveillance, anonymity — running alongside the rowdier alt.privacy.

Privacy organisations listed both groups side by side as standing resources; the Australian Privacy Foundation’s resource page still points at both addresses here.

Long-form reference · 8,417 words · about a 37-minute read

The group's own paperwork

Very little of what was said in comp.society.privacy is easy to find today. Almost everything about how the group was made, run and unmade is. The Internet Systems Consortium keeps the Usenet administrative record, and for this name it is close to complete: the request for discussion, the call for votes, the result with every ballot listed, and — eighteen years later — the paperwork that took the group away again. The companion archive of control messages for the name holds a hundred and nineteen messages. Nearly every specific date, address and figure about the group itself comes out of those two files, and where the record is silent this page says so.

The request for discussion went out on 14 February 1992, posted to news.announce.newgroups and crossposted to news.groups, alt.privacy, comp.org.eff.talk and alt.society.civil-liberty. Its author was Dennis G. Rears, who proposed himself as moderator. It was a second attempt: an earlier call for discussion had run some months before, and he summarised its outcome in a sentence that says a good deal about what Usenet argued over: “Most of the comments were favourable, the only disagreement was whether it should be named comp.privacy or comp.society.privacy.” He took the longer name. The same posting disposed, pre-emptively, of the question a reader of this directory is most likely to bring to it:

One question that was raised is what the relationship between CSP and alt.privacy. There is no relationship between the two groups.

The proposal then set out what the group was for. Its list of topics is the best surviving statement of the subject as it looked in February 1992, and it is worth reading as a period document rather than a charter: telecommunications, meaning caller identification, automatic number identification, the monitoring of cellular and cordless calls and the tracking of people's locations; cryptology, described as something that “enhances citizens rights to safeguard their information”; databases, under a heading observing that “Big Brother is here but it is not just the Govt”; high-technology surveillance devices; the spread of consumer video cameras and the forgeability of what they recorded, with the Rodney King footage named as the example; the admissibility in court of material produced by new technology; and a miscellany of national identifier numbers, bar-coded currency and “electronic toll devices mounted on Autos”.

It also drew a boundary that explains the group's position in the namespace. The proposal stated that the group “is not intended for the overall issue of privacy”, and gave as its counter-example a question about whether a rape victim's name should be published. This was to be privacy as a consequence of machinery, not privacy as a moral subject; a comp.* group rather than a soc.* or talk.* one. The reasoning offered for wanting the group at all was that privacy was already being discussed in many newsgroups, but each time only in so far as it touched that group's own topic.

On moderation the proposal was equally explicit, and unusually modest about what moderation would mean:

I am proposing that this group be moderated to keep a high signal to noise ratio. Moderation of a newgroup means different thing to different people. The moderation that I propose will filter out all administrative requests, test messages, non-tech/privacy items, and excessive flames. Nothing is censored.

The call for votes followed on 18 March 1992, under a subject line that misspelled the group's own name as somp.society.privacy — a detail preserved, like everything else, exactly as posted. It named the proponent as moderator, reproduced the charter, and set the ballot rules: votes by electronic mail only, to a single address at a United States Army host; invalid if posted to the network, sent by any other medium, made conditional, or cast by proxy; duplicates resolved in favour of the latest. Ballots had to arrive “before 05:00:00 GMT, 13 April 1992”. The passing condition, as the call stated it, was more yes votes than no votes and at least a hundred more yes than no.

The result was posted on 15 April 1992: the group passed 189 to 16, a margin of 173 where a hundred was required. The posting runs to two hundred and thirty lines because the votetaking convention of the day required the tally to be auditable, so every voter is listed by name or address, the sixteen who voted against first and the hundred and eighty-nine in favour after them.

Five days later, on 20 April 1992, David C. Lawrence, the moderator of news.announce.newgroups, sent the newgroup control message that actually created the group on the network. It carried the line every news administrator's software would file the name under:

comp.society.privacy    Effects of technology on privacy. (Moderated)

It also carried the addresses that made moderation work in practice — Group submission address: [email protected] and a moderator contact address on the same host — and, beneath a line reading “The charter, culled from the call for votes”, the charter itself:

This newsgroup is to provide a forum for discussion on the effect of technology on privacy. All to often technology is way ahead of the law and society as it presents us with new devices and applications. Technology can enhance and detract from privacy. This newsgroup will be gatewayed to an internet mailling list.

The typographical errors are the record's, and are reproduced here because this page quotes the charter rather than tidying it. That last sentence is the important one. It is not a description of a newsgroup. It is a description of a newsgroup attached to something else.

April 1992: the fortnight the group was accidentally unmoderated

Moderation on Usenet was a convention held up by a string. A moderated group's newgroup control message carried the word moderated after the name; servers that honoured the message recorded the flag; a posting to a group so flagged was mailed to the submission address instead of being injected into the network, and articles in that group propagated only if they carried an Approved header. There was no central register and no enforcement. The general mechanism is described on the directory's Usenet explainer and, for this hierarchy in particular, on the comp.* page. What the archive for this group preserves is what happened when the string slipped.

Six days after the group was created, three newgroup control messages for comp.society.privacy went out from a host at the University of Maine on 26 April 1992. They carried a Distribution header of umcs, which should have confined them to that campus. They did not stay there, and two of the three omitted the word moderated. On 27 April 1992 the moderator of news.announce.newgroups posted the correction, twice, to the same group and distribution:

This group was inadvertently changed to unmoderated by a leaked newgroup message from gandalf.umcs.maine.edu. It is properly a moderated newsgroup.

It happened again within weeks. A further newgroup message for the name, without the flag, appears in the archive on 13 May 1992, this time carrying a distribution of comp; a corrective message with the flag follows on 15 May, and on 10 June the same pair occurs again, an unflagged message from one site and a flagged one from another on the same day. The pattern recurs on a very different scale in 1998, when more than a hundred newgroup control messages for this one name went out between August and November, nearly all of them from the Big-8 group administration address, some flagged moderated and many not.

None of this was peculiar to the privacy group; it is simply what the control-message system looked like from inside. But it is worth stating on this page in particular, because the moderated form was the whole point of the group. The editorial arrangement that made the digest citable rested on a flag in a text message that any site could set, unset or contradict, and that in practice several did, by accident, in the group's first two months.

The digest before the newsgroup

The group did not begin as a group. Its ancestor was an Internet mailing list called telecom-priv, and the request for discussion gives that list's origin in a single sentence: it had been created about a year earlier — so, in 1991 — to discuss caller identification, “after the that topic was bounced from comp.dcom.telecom”. It was then, in the proponent's words, “expanded to include all issues of privacy dealing with telecom equipment”. Under the 1992 proposal the list “will be folded into this newsgroup”.

That is an unusually clean origin story for a Usenet group, and it is worth pausing on. The subject of this page exists because a telephony discussion — the sort of traffic this directory holds in alt.dcom.telecom and its moderated Big-8 counterpart — produced an argument its own forum would not carry. Caller identification was the argument. A separate list was made to hold it, the list broadened to the whole subject, and the broadened list acquired a newsgroup.

After the group existed, the list was renamed to match its new scope. The best contemporary description of the arrangement was published on 9 November 1992, in issue 2 of volume 14 of the RISKS Digest, under the heading “Privacy Digests”. Its author, Peter G. Neumann, was reminding RISKS readers of two publications that were “siphoning off some of the material that would otherwise appear in RISKS”:

The Computer PRIVACY Digest (CPD) (formerly the Telecom Privacy digest) is run by Dennis G. Rears. It is gatewayed to the USENET newsgroup comp.society.privacy. It is a relatively open (i.e., less tightly moderated) forum, and was established to provide a forum for discussion on the effect of technology on privacy.

The notice gave the working addresses: submissions to [email protected], administrative requests to [email protected]. The first is the same address the newgroup control message had published in April. The digest and the newsgroup were one object with two doors.

That double life is what a resource list is recording when it gives both an address and a group name. A reader whose site took a news feed subscribed to the newsgroup and saw each issue as an article. A reader without one — and in 1992 that was a very large fraction of the people who cared about the subject, including most of the lawyers, administrators and officials — subscribed by electronic mail and received the same material as a numbered bulletin. Neither reader saw anything the other did not.

The same RISKS notice named a second privacy periodical, the PRIVACY Forum Digest, run by Lauren Weinstein and described as “a rather selectively moderated digest, somewhat akin to RISKS”, spanning technological and non-technological privacy questions. Neumann's advice to a reader short of time was to take that one; a reader wanting “ongoing detailed discussions” should take the Computer Privacy Digest. There was much potential for overlap, he noted, but contributions tended not to appear in both. Late 1992, then, offered the interested reader three distinct instruments on one subject: two moderated digests of different temperature, and an unmoderated newsgroup.

The form: what a digest is, and what it is not

The shape the publication took was older than the network that carried it, and it had been written down two years before the group existed. RFC 1153, Digest Message Format, was published in April 1990 by F. Wancho of the White Sands Missile Range, and it opens with the history:

High traffic volume large mailing lists began to appear on the net in the mid-70s. The moderators of those lists developed a digest message format to enclose several messages into one composite message for redistribution to the mailing list addressees.

The stated motive is economy: bundling “reduces the mailer load in proportion to the number of messages contained within a digest message, and conserves network bandwidth by reducing the size of the headers of the enclosed messages”. But the moderator is in the memo's second sentence and never leaves it. Bundling implies somebody doing the bundling, and by the mid-1970s — several years before Usenet, which Tom Truscott and Jim Ellis conceived in 1979 — that person was already a recognised functionary of the network.

A printed schematic headed ARPANET LOGICAL MAP, MARCH 1977, showing host sites such as MIT, Stanford, UCLA, RAND and the Pentagon as labelled nodes joined by lines, with the computer models at each site boxed beside them.
The ARPANET logical map of March 1977, listing the host sites and the machine models installed at each. This is the network of the years RFC 1153 points back to when it says that the moderators of high-traffic mailing lists worked out the digest format in the mid-1970s — several years before Usenet, and fifteen before this group inherited the form. ARPANET · public domain · via Wikimedia Commons.

The memo is precise about the object it describes, and the precision is what made the form citable. The subject line carries the list name, the word Digest, a volume number and an issue number. The body must consist of a preamble, one or more enclosed messages, and a trailer. The preamble usually holds a table of contents drawn from the enclosed subject lines, and may carry administrative announcements. The preamble is separated from the rest by a line of seventy hyphens. Each enclosed message keeps only its Date, From, To, Cc, Subject, Message-ID and Keywords lines, rearranged into that order, with everything else discarded and Received lines discarded especially; the enclosed messages are separated from one another by lines of thirty hyphens. The trailer's first line must begin with the words End of, followed by the list name and the word Digest, usually with the volume and issue number after it, and the last line of the whole message is a rule of asterisks underlining it. The typical size, the memo notes, is fifteen thousand characters.

Software had grown around the convention from both ends. RFC 934, Proposed Standard for Message Encapsulation, published in January 1985 by Marshall T. Rose and Einar A. Stefferud, had set out a general encapsulation format so that a subscriber's mail program could take an issue apart and reply to one item inside it. RFC 1153 is careful to say that it does not supersede RFC 934: it documents a particular format that “existed well before RFC 934 was published and continues to be the format of choice for digest messages”. Between them the two memos let programs digestify and undigestify without agreement about anything else.

What neither memo touches is the part that mattered. RFC 1153 excludes it in one sentence:

Any editorial functions performed at the discretion of a digest moderator, such as discarding submissions, editing content to correct spelling and punctuation errors, inserting comments, and reformatting paragraphs to conform to width conventions are beyond the scope of this memo.

The standard specified the container and left the judgement to a person. That division is the whole difference between a digest and a discussion group, and it has two consequences a reader of the archive meets immediately. The unit of publication is the issue, not the contribution: nothing appears on posting, and a submission waits for whenever the editor next assembles one. And the record that results is a run of periodicals rather than a graph of threads, in which every contribution has a stable address consisting of a volume and an issue number. The general account of the digest form on Usenet, and of comp.risks as the hierarchy's longest-running example, belongs to the comp.* page; what is particular here is that this group's own charter promised the arrangement in its last line before the group existed.

Moderation, and the unmoderated group next door

For most of the 1990s there were, on the same network and at the same time, a moderated privacy digest and an unmoderated privacy newsgroup. That pairing is the structural fact about this page. The two forms make opposite bargains, and on a subject where the participants are by definition careful about exposure the difference is not academic. Submitting to the digest meant sending your text and your electronic address to one identified person at one named host, and waiting for an issue; the risk was concentrated in a single mailbox, and what you bought with it was delay and an editor. Posting to the open group meant immediate worldwide distribution of an article whose headers named the machine you sent it from, with no intermediary at all; the risk was spread everywhere at once, and what you bought with it was speed, and the absence of anyone whose own discretion you had to take on trust.

The proposal for this group insisted, as quoted above, that there was no relationship between the two. There was, of course, a relationship of the kind that does not need arranging: the same subject, the same years, largely the same reading public, and an overlap of contributors that anybody comparing the two archives will see. The unmoderated side of the line — including the crypto-wars traffic, the anonymous-remailer episode and the long argument about whether privacy is a matter for statutes or for mathematics — is told at alt.privacy, and is not retold here.

What the digest carried

Neumann's 1992 description — “relatively open (i.e., less tightly moderated)” — is the most useful characterisation of the editing that survives, and it matches the proposal's own account of the policy. The filter was for topicality and temperature, not for position: administrative requests, test messages, off-charter items and excessive flames out; argument in.

The issues surviving from the winter of 1992 wear the machinery on their faces — a numbered masthead, a submissions address, a note of where back issues were kept — and in that December the digest went out on most days, carrying about ten items an issue. Their contents are what the charter looks like in practice rather than in principle: a first-hand consumer report from a reader who had refused a supermarket's demand for an address before it would hand over a prize; a contested factual question about whether telephone companies kept records of local calls; a discussion of driving licences whose magnetic stripes carried the holder's Social Security number; and a correction addressed to the moderator. Nothing in that list is a set piece. It is the ordinary traffic of people who had noticed something and wanted to know whether they were right.

The editorial judgement is the reason the run can be used at all, and it is worth being exact about what it does and does not warrant. Privacy attracts two kinds of contribution simultaneously. One is professionally informed: lawyers, administrators of large record systems, telephone-company engineers, officials who know what their own institution does. The other is certainty that has outrun its evidence, because a subject about unseen observation rewards the suspicion that more is unseen than can be demonstrated. An unmoderated forum carries both in whatever proportion arrives at the server. A moderated digest carries what one editor judged to be on charter, dated and numbered as it went. That is a weaker claim than accuracy and a much stronger one than nothing, and it is the claim a researcher should make when citing an issue.

The moderatorship changes hands

In April 1992 the group's submission address was [email protected] and the moderator contact address was [email protected], Dennis G. Rears at Picatinny Arsenal, an installation of the United States Army in New Jersey. On 30 May 1997 a newgroup control message for the same name, issued by the group administration address at the Internet Systems Consortium and signed with PGP, gave a different pair of addresses:

Group submission address: [email protected]  /  Moderator contact address: [email protected] (L. P. Levine)

The contact line names a different person and a different institution, the University of Wisconsin–Milwaukee. The digest, in other words, had moved from a military mail host to a university one, and had changed editor. What the record does not contain is any account of when this happened, why, or whether there were intermediate hands: no vacancy notice, no handover posting, no announcement in news.announce.newgroups. There are two fixed points, 1992 and 1997, and five years of silence between them.

The 1997 message is worth a second look for a different reason. By then control messages for the Big Eight were being issued from a single administrative address and signed cryptographically, with a header pointing readers at the documentation for the signing scheme. Between the leaked, unsigned, contradictory newgroup messages of April 1992 and the signed one of May 1997 sits the network's decision to authenticate its own administrative traffic — a small, undramatic piece of applied cryptography that arrived on Usenet while the group was arguing about the large, dramatic kind.

The last thing the administrative record says about that university address is that it stopped accepting mail.

The law before the group

The statutes the digest argued about had a longer run-up than the digest did, and the vocabulary was already twenty years old when the group was voted into existence. The United States Fair Credit Reporting Act of 1970 had put rules on the files kept by consumer reporting agencies — the first American recognition in law that a private company's database about a person was a thing the person had standing to argue with. In 1972 a committee of the Department of Health, Education and Welfare, chaired by the computer scientist Willis Ware, took up automated personal data systems; its 1973 report, Records, Computers and the Rights of Citizens, set out the Code of Fair Information Practice that the field has been rearranging ever since, and it is the direct ancestor of both the American and the European instruments that followed.

The Privacy Act of 1974 — Public Law 93-579, signed on 31 December 1974 — put the code into federal law for federal agencies: notice of the systems of records an agency kept, a right for the subject to see and correct what was in them, and limits on disclosure. It is the statute against which almost every later American privacy argument has been measured, usually to observe how narrow it is: it binds government agencies and not the private sector, which is the whole reason the United States went on to legislate industry by industry for the next thirty years.

Internationally the same code went two ways at once. The Organisation for Economic Co-operation and Development issued guidelines on the protection of privacy and transborder flows of personal data in 1980, as a recommendation with no binding force. The Council of Europe went further: its Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data — Convention 108 — was opened for signature at Strasbourg on 28 January 1981 and entered into force on 1 October 1985, making it the first binding international treaty on data protection and the instrument on which the European Community's later directive was built.

The American courts, meanwhile, had drawn a line whose consequences the group would spend eighteen years watching. In Smith v. Maryland (1979) the Supreme Court held that a pen register recording the numbers dialled from a telephone was not a search under the Fourth Amendment, because those numbers had been handed over to the telephone company in the ordinary course of placing a call. It is the Court's first significant articulation of what is now called the third-party doctrine, and the distinction it draws — between what you say and the record that saying it leaves — is the distinction most of this group's traffic turns out to be about.

The statutes of the group's own decade

By the mid-1980s the American pattern was set: no general statute, and a new one for each category of record that produced a sufficiently embarrassing incident. The Electronic Communications Privacy Act of 1986 — Public Law 99-508, signed on 21 October 1986 — was the most consequential of them for anyone reading a newsgroup. It extended the 1968 wiretap statute from telephone calls to transmissions of electronic data by computer, added the stored-communications provisions that govern what is held on a service provider's disks, and added the pen-register provisions that govern the tracing of communications. Every later American argument about whether the police may read your electronic mail without a warrant is an argument about the shape of that 1986 Act, and it was already six years old when the group opened.

First page of a Congressional Research Service report, headed with the CRS logo and the title Privacy: An Overview of the Electronic Communications Privacy Act, by Charles Doyle, dated October 9, 2012.
Cover page of “Privacy: An Overview of the Electronic Communications Privacy Act”, a Congressional Research Service report by Charles Doyle dated 9 October 2012. The 1986 Act it summarises was six years old when this group opened and is still the statute behind most American arguments about police access to stored electronic mail. The report is a later summary of that law, and has no connection to the newsgroup. Congressional Research Service · public domain · via Wikimedia Commons.

The Video Privacy Protection Act followed in 1988, after a newspaper obtained and published the video-rental records of the Supreme Court nominee Robert Bork — the era's clearest demonstration that a legislature can move briskly on privacy when the records in question might be its own. The same year Congress went back to the 1974 Act to deal with the practice of matching one federal record system against another by computer: the Senate Committee on Governmental Affairs reported the bill, S. 496, on 15 September 1988, and what became the Computer Matching and Privacy Protection Act is codified as part of the Privacy Act rather than as a statute of its own.

Title page of a United States Senate committee report, 100th Congress 2d Session, Report 100-516, headed The Computer Matching and Privacy Protection Act of 1987, to accompany S. 496, with the Senate seal and the date September 15, 1988.
Title page of Senate Report 100-516, the Committee on Governmental Affairs report to accompany S. 496 — the Computer Matching and Privacy Protection Act of 1987 — ordered to be printed on 15 September 1988. Matching one federal record system against another by computer was squarely within this group's charter; the report is a congressional document and has no connection to the group. United States. Congress. Senate. Committee on Governmental Affairs · public domain · via Wikimedia Commons.

The Driver's Privacy Protection Act of 1994 arrived as Title XXX of that year's federal crime statute, signed on 13 September 1994, and governed what state motor-vehicle departments could disclose. Its legislative history is a reminder that these statutes were rarely abstract: the bill had been introduced in 1992 after opponents of abortion used public driving-licence databases to trace and harass clinic staff and patients. It is also the same class of record whose magnetic stripe was being argued over in the digest in December 1992, two years before the Act.

The rest of the decade filled in the categories. The Health Insurance Portability and Accountability Act was signed on 21 August 1996, but the privacy rule it authorised did not come into effect until 14 April 2003, so that for most of the group's life the United States had no comprehensive federal privacy rule for medical records at all. The Children's Online Privacy Protection Act was signed on 21 October 1998 and took effect on 21 April 2000, directed at the collection of personal information from children under thirteen. The financial-privacy provisions of the Gramm–Leach–Bliley Act arrived with the rest of that statute, which took effect on 12 November 1999.

Two things are worth noticing about that list. The first is that each Act is named for a kind of record — credit files, video rentals, driving licences, health plans, children's websites, bank customers — which is what a sectoral regime looks like from the outside. The second is that a European reader of the same period would have found the arrangement incomprehensible, and said so, at length, in this and every other privacy forum on the network.

Europe, and the instruments that kept being struck down

Europe legislated the whole subject at once. The Data Protection Directive, Directive 95/46/EC on the protection of individuals with regard to the processing of personal data and on the free movement of such data, was made on 24 October 1995, published in the Official Journal of 23 November 1995, and came into force on 13 December that year, with member states given until 24 October 1998 to transpose it. It applied to processing by anyone, public or private, and it carried the provision that has shaped the transatlantic argument ever since: personal data could be transferred out of the Community only to a country ensuring an adequate level of protection.

The electronic-communications sector got its own instrument. Directive 2002/58/EC on privacy and electronic communications was made on 12 July 2002, published in the Official Journal of 31 July 2002, with transposition due by 31 October 2003; it dealt with confidentiality, traffic data, unsolicited mail and the storing of information on a subscriber's own equipment. It was amended in 2009 by Directive 2009/136/EC, which changed that last provision from an opportunity to refuse into a requirement of prior consent. That amendment is the legal origin of the consent notice every European web user now dismisses several times a day, and the reader may judge for themselves whether the group's contributors, arguing in the 1990s about a silently-stored identifier, would have counted it a victory.

The Directive was replaced by the General Data Protection Regulation, Regulation (EU) 2016/679, adopted on 14 April 2016, dated 27 April 2016 and published in the Official Journal of 4 May 2016. It applied from 25 May 2018, on which date it repealed Directive 95/46/EC. Being a regulation rather than a directive, it took effect without national transposition, which is the technical fact behind its unusual reach.

The transfer question, though, has never stayed settled, and its history is the single clearest illustration of what the group used to argue about. The European Commission decided on 26 July 2000, by Decision 2000/520/EC, that the American safe-harbour privacy principles provided adequate protection. The Court of Justice of the European Union declared that decision invalid on 6 October 2015 in Case C-362/14, Maximillian Schrems v Data Protection Commissioner. A replacement, the EU–US Privacy Shield, was adopted as Commission Implementing Decision (EU) 2016/1250 of 12 July 2016; the Court declared that invalid too, on 16 July 2020, in Case C-311/18, the judgment universally called Schrems II. A third arrangement, the EU–US Data Privacy Framework, was adopted as Commission Implementing Decision (EU) 2023/1795 on 10 July 2023 and extended to the European Economic Area the following year.

Three adequacy arrangements in twenty-three years, two of them annulled by a court. The question underneath — whether an undertaking about what happens to a record after it crosses a border can be made to mean anything — is exactly the question the digest's European and American contributors put to each other in the 1990s, without resolving it. It has since been put to a court twice and answered twice, in the negative, and asked again.

Australia, and a note on the southern readership

Australia's arrangements are on this page because Australian readers keep arriving at it. The federal Privacy Act 1988 was the country's general statute, covering Commonwealth agencies. It was amended in 2000 to extend a set of National Privacy Principles to much of the private sector, with the substantive provisions commencing in December 2001 — putting Australia, on that point, some six years behind the European Directive and well ahead of the United States, which has still not passed a comparable general federal statute. The National Privacy Principles and the older Information Privacy Principles were then replaced on 12 March 2014 by a single set of Australian Privacy Principles, brought in by the Privacy Amendment (Enhancing Privacy Protection) Act 2012.

Why an Australian privacy organisation should have kept a link to a moderated Usenet digest on its resource page for years after the group was removed is a question about the referral culture of the early web rather than about this group, and it is answered on the alt.privacy page, which carries the same listing. The short version is that before web forums existed, a link to a newsgroup was a link to a living conversation rather than to a document, and there was very little else of the kind to point at.

Subjects that became ordinary

The most interesting thing about the group's subject list is how much of it stopped being alarming. In each case something specific and datable happened, and in none of them was it that the original worry turned out to be wrong.

Caller identification. The service that produced the group's parent mailing list was first tried commercially by BellSouth in a market trial at Orlando, Florida, in January 1984, and first deployed commercially by the same company in December 1988 at Memphis, Tennessee, spreading across its nine-state region over the following four years. The controversy of 1990 and 1991 — loud enough, as the record shows, to be thrown out of a telephony newsgroup — was about whether a caller was entitled to withhold the number. The settlement reached in the United States was per-call blocking, which providers are required by the Federal Communications Commission to offer. The end of the story is stranger than either side proposed: by rule of the same commission, telemarketers in the United States have been required to transmit caller identification since 29 January 2004. The disclosure the group's founding argument sought to make refusable is now, for one class of caller, compulsory.

Supermarket loyalty cards. The request for discussion's “Data Bases” heading of February 1992 was three years early. Tesco introduced its Clubcard in the United Kingdom on 13 February 1995, after trials the previous year, and the scheme worked by doing exactly what the digest's contributors had been describing in the abstract: it made an individual customer's purchases legible as a record. The card was not a surveillance instrument dressed as a discount; it was a discount that worked by being a record. Nothing about that has changed except that nobody now regards it as remarkable.

Cookies. The mechanism was devised at Netscape in June 1994 and shipped in Mosaic Netscape 0.9beta on 13 October 1994, accepted by default and without notice to the user. The public learned of it when the Financial Times published an article on 12 February 1996. In the same month the Internet Engineering Task Force working group that took the specification in hand identified third-party cookies as a considerable privacy threat, and the specification it produced, RFC 2109 of February 1997, said they should not be permitted at all or at least not enabled by default. Netscape and Internet Explorer declined to follow that recommendation; RFC 2965 superseded the memo in October 2000; the advertising industry built itself on the result. The regulatory answer arrived in Europe fifteen years after the mechanism did, in the 2009 amendment to the ePrivacy Directive described above. The group's own reaction to the news of 1996 belongs to the archive; the wider story is told on the alt.privacy page.

Closed-circuit television. Here what changed is chiefly the quality of the arithmetic. Britain was the country the group's contributors pointed at, and for years the figure in general circulation was 4.2 million cameras — a number derived from a 2002 study that extrapolated from the cameras counted on two streets in Wandsworth, and repeated as far as Home Office literature. A survey published in CCTV Image in 2011, extrapolating instead from a comprehensive count within one police force's jurisdiction, estimated 1.85 million cameras in private and local-government hands, about one per thirty-two people; the deputy chief constable of that force said plainly that the data undermined the more sensational estimates, including the widely repeated claim that the average Briton passes under three hundred cameras a day. The cameras are real, common and legally regulated. The numbers everyone was arguing with were not evidence.

Encryption. The group's charter listed cryptology as a technology that “enhances citizens rights to safeguard their information”, and in 1992 that was a claim about a right to use a controlled technology. The fight over control is not this page's story and is told on the alt.privacy page. What is this page's story is the ending, which is that encryption stopped being something anyone chooses. Let's Encrypt, a certificate authority announced on 18 November 2014, with the Electronic Frontier Foundation, the Mozilla Foundation, the University of Michigan, Akamai and Cisco among its founders, was set up to issue transport-layer certificates free and automatically; it entered public beta on 3 December 2015, left beta on 12 April 2016, and its certificates are now used by more than seven hundred million websites. A reader of the 1992 charter would have found the sentence about cryptology unremarkable and the fact that the ordinary web is encrypted by default, at no cost, without the user being consulted, quite hard to believe.

From records kept about you to records you generate

Two of the group's standing subjects did not become ordinary so much as change shape, and both are instances of the same shift: from records an institution deliberately keeps about a person to records that a person's use of a system generates as a by-product.

The first is monitoring at work, which reached the group already framed. The United States Congress's Office of Technology Assessment had published The Electronic Supervisor: New Technology, New Tensions in 1987, with chapters on the use of computers to monitor office work, on telephone call accounting, and on the law and policy of electronic work monitoring. Nothing in the group's eighteen years altered the principle that report set out; what changed was scope. The same measurement moved outward from clerical keystroke counts to electronic mail, then to web access, then to whatever else an employer's systems happened to record. The category the 1987 report named has never needed renaming.

The second is identity theft, which is the by-product problem in its purest form: the record is the person, for the institution's purposes, and anyone holding the record can be the person. The phrase itself is older than the network, dated by the Oxford English Dictionary to 1964, but the conduct became a distinct federal offence in the United States only with the Identity Theft and Assumption Deterrence Act of 1998 — Public Law 105-318, enacted on 30 October 1998 — which amended title 18 of the United States Code so that knowingly transferring, possessing or using another person's means of identification without lawful authority was a crime in itself, rather than merely a fraud against whichever institution had been deceived. The statutory recognition arrived thirty-four years after the phrase and six years after the group opened.

Behind both sits the doctrine of Smith v. Maryland. If the numbers you dial are not yours because you handed them to the telephone company in order to make the call, then the same reasoning is available for the sites you visit, the cells your telephone registers with, the doors your card opens and the searches you type. A great deal of what the digest carried, across eighteen years and several generations of equipment, is that line being tested on machinery its authors had not imagined. It is the most durable thing on the group's topic list, and it is the one item that has become more contested rather than less.

The neighbouring digests

The comp.society.* branch existed to treat computing as a social question rather than a technical one, and it was unusually full of edited publications rather than discussions. The checkgroups list of 1993 shows six names in it: the parent group comp.society, for the impact of technology on society; comp.society.folklore, for computer folklore and culture; comp.society.development, for computer technology in developing countries; comp.society.futures, for events in technology affecting future computing; comp.society.cu-digest, whose sole business was carrying the Computer Underground Digest; and this one. Four of the six, including this one, were flagged moderated. The branch's characteristic object was not a thread but an issue.

Its nearest relative of that kind sat outside the branch entirely. The RISKS Digest — formally the Forum on Risks to the Public in Computers and Related Systems, published from 1985 by the Association for Computing Machinery's Committee on Computers and Public Policy and edited throughout by Peter G. Neumann, who died in May 2026 — reached Usenet as comp.risks, a newsgroup that existed for no purpose except to carry it. Its publication record and its place in the hierarchy are described on the comp.* page. What matters here is the division of labour, which the 1992 notice quoted earlier states from the inside: RISKS would continue to carry the higher-level discussions in which risks to privacy were a concern, and referred readers who wanted the detail to the two privacy digests. Between them the three publications did the network's conscience work at a deliberate pace, one on what computers do to safety and reliability, the others on what they do to persons.

The branch went first. On 3 November 2003 a Moderator Vacancy Investigation was opened for comp.society, comp.society.folklore and comp.society.cu-digest together, on the ground that the groups were not functioning and might have been abandoned by their moderators. The result was posted on 21 June 2004: no moderators were located. comp.society was made unmoderated — the notice adds that “Unmoderation of comp.society should be considered to be an experiment” — and the other two were removed, with the dry finding that “Very little interest in comp.society.folklore was found, whereas no interest at all was detected for comp.society.cu-digest.”

How it ended

comp.society.privacy lasted another five and a half years, and then ended by the machinery that had made it. The sequence is documented from end to end and took a little under three months.

  • 29 October 2009 — a probe post to the group bounced. The Big-8 Management Board's routine check of whether moderated groups still worked had found that the submission address, forwarded through the moderators' relay, was being rejected at the University of Wisconsin–Milwaukee.
  • 28 November 2009 — a formal Moderator Vacancy Investigation was posted to news.announce.newgroups, news.groups.proposals and the group itself, “begun because moderated newsgroup comp.society.privacy is not functioning, and may have been abandoned by its moderator(s)”. The notice records that the Board treats a third option, converting a moderated group to unmoderated, as “likely to cause more harm than good”.
  • 13 December 2009 — first Request for Discussion to remove the group.
  • 27 December 2009 — second Request for Discussion, which does not survive in the archive as a separate document but is recorded in the change history printed at the foot of the later notices.
  • 9 January 2010 — Last Call for Comments, opening a five-day period for final comment.
  • 17 January 2010 — RESULT: the Board voted to remove the group, ten in favour, none against, none abstaining.
  • 19, 20 and 26 January and 19 February 2010 — four rmgroup control messages, PGP-signed from the group administration address, carrying the reason for removal in their bodies.

Every document in that sequence reprints the charter and the line “comp.society.privacy is a moderated newsgroup which passed its vote for creation by 189:16 as reported in news.announce.newgroups on 15 Apr 1992”. The removal paperwork is where the creation paperwork is most reliably preserved, which is a common and slightly melancholy property of Usenet's records.

The reason for removal was procedural. Nobody argued that the subject had been exhausted, and nothing in the record suggests anybody proposed a new moderator. The group was removed because mail sent to its submission address was refused, and a moderated group whose submission address does not accept mail is not a forum with a quiet period; it is a name that cannot be posted to at all.

The consequence is visible in the master files the Internet Systems Consortium distributes, from which any news server can build its group table. In the edition consulted while this page was written, carrying 45,003 names of which 677 begin with comp., comp.society.privacy does not appear. Neither does most of the branch: the only comp.society.* name still listed is comp.society.futures. comp.risks is there, described as before as carrying risks to the public from computers and users. So is alt.privacy, described as “Privacy issues in cyberspace”, together with alt.privacy.anon-server, alt.privacy.anon-server.stats, alt.privacy.clipper and alt.privacy.spyware — four of them named for controversies that finished long ago.

That is the moderated form's bargain, presented as a bill. The edited digest bought a citable record, an on-charter run and a readable archive, at the price of depending on one person continuing to read a mailbox; when the mailbox stopped answering, the name was withdrawn within three months. The unmoderated group beside it required nobody's continued attention, and survives in the master file today because there was never anything in it that could stop working.

The archive, and what a numbered issue is worth

A moderated digest with issue numbers leaves a different kind of record from an unmoderated group, and the difference is worth stating because it governs what this page can honestly claim.

In an open newsgroup the citable unit is a single article, identified by a message identifier that means nothing to a reader and that no contemporary source would have quoted. In a digest the citable unit is an issue, identified by a volume and a number that appear in the subject line, in the table of contents, and in the trailer, and that were designed — per RFC 1153 — to be readable by a person. That is the unglamorous reason an organisation compiling a resource list could point at the thing at all, and the reason a contributor could refer back to something published three months earlier without needing a search engine, which in 1992 did not exist for this material.

What survives falls into three parts, and they are in very different condition. The administrative record is the best of them: the proposal, the ballot, the result with every voter listed, the control messages and the removal documents, all public, all dated, and all mirrored by the Internet Systems Consortium. The newsgroup side of the publication survives in the public Usenet archives, which is where a modern reader will meet the traffic; the access details are in the box below this article and are not repeated here. The mailing-list side — the numbered run of the Computer Privacy Digest as its subscribers received it, with the mastheads and the back-issue notices — is the hardest of the three to locate, and this page deliberately points at no archive of it, because none was verified while the page was written.

That is a smaller loss than it sounds, because the two were gatewayed: the articles are the same articles. But it is a real one, because the digest's own apparatus — the editor's administrivia, the table of contents, the note of where back issues were kept — is precisely the part that does not survive gatewaying, and it is the part that would tell a historian how the publication was actually run.

What the record does not show

A page assembled mostly from administrative documents should be candid about the shape of the hole in the middle of it.

  • Readership. No figure of any kind is available or given. The 189 people who voted for the group in 1992 are the only enumerated population in the record, and a creation vote measures interest in a proposal, not subscribers.
  • Traffic. No article counts appear here. The article counters distributed alongside the master group list are placeholders identical for every entry, as the comp.* hierarchy page notes, and are not a measure of anything.
  • The handover. The record fixes the moderatorship at an Army host in 1992 and a university host in 1997 and says nothing whatever about the transition, or about whether anyone held the post between the two.
  • The ending. Why the digest stopped is not recorded. The bounce message of October 2009 is the only evidence, and a rejected address is consistent with several stories, none of which the archive tells.
  • Content. No thread titles, no subject lines, no post counts and no quotations from the group's own traffic are invented on this page. Where the traffic is described, it is described from the two documents that describe it: the 1992 proposal's topic list and the 1992 RISKS notice.

One thing the record does contain, and this page does not reproduce, is the name or electronic address of every person who voted in April 1992. The result posting lists all 205 of them, because the votetaking convention of the period required a result to be auditable. It is a small irony of the archive that the most complete personal-data set the group ever generated is the ballot that created it, and that it has been publicly retrievable ever since.

Scope and limits of this page

This is a page about a newsgroup, written from the newsgroup's own paperwork and from the documented history of the subject it covered. Where a fact here is specific — a date, an address, a vote, a line of a control message — it comes from the Internet Systems Consortium's mirror of news.announce.newgroups and the control archive, from the RISKS Digest issue of 9 November 1992, from RFC 934 and RFC 1153, from the master newsgroups file, or from the published text of the statutes and judgments named. Where it is general, it is general because the record is.

The people named here are named as the record names them: the two moderators by the names and addresses printed in the group's own control messages and in the 1992 RISKS notice, the moderator of news.announce.newgroups who created the group, the authors of the two RFCs, and the editor of the RISKS Digest. Nobody appears here who does not appear in a public document about this group or its form, and no personal detail is given beyond the institution and the published address at which each acted.

Three neighbouring accounts carry material deliberately left out here. The unmoderated side of this subject — the crypto wars as they were watched from a newsgroup, the anonymous-remailer episode, and the long argument about whether privacy is a problem for legislators or for mathematicians — is at alt.privacy. The comp.* hierarchy itself, the Big-8 procedure by which this group was created and removed, and the digest form's longest-running example are on the comp.* page. And the mechanics of moderation, control messages and the Approved header are on the directory's Usenet explainer.

Finally, a note on register. The group's business was an argument, conducted for eighteen years, about what technology was doing to people, and its contributors disagreed with each other sharply and in good faith. This page records what was argued and what the instruments say. It does not adjudicate, and where a question the group asked is still open — which is most of them — it is left open.

Reading comp.society.privacy today

  • Historical archive: Google Groups — comp.society.privacy (coverage varies by group and era).
  • Open in a newsreader: news:comp.society.privacy — the original site offered exactly this link, and it still works if your system has a newsreader registered for the news: scheme.
  • Live access: point an NNTP newsreader at a modern server — see accessing Usenet today.
  • The original news2mail e-mail subscription service ended in the mid-2000s and no longer operates.