Talk:Mosaic effect
Drating notes
[edit]Dissimilar/uniquely different from or to:
- https://en.wikipedia.org/wiki/Mosaic_theory_of_the_Fourth_Amendment
- https://en.wikipedia.org/w/index.php?title=Mosaic_theory_of_intelligence_gathering&oldid=1013033152
This is to see if there's a viable article around the more esoteric legal/security concept of combining enough / sufficient declassified or public-knowledge, or public-domain data, that the new aggregate whole of the collection of that data can instead elevant the concept to the point of being classified, simply on the basis of it's unification.
Although -- this may not be JUST a national security thing; this is a consideration in general intel/counter-intel, as well as in concepts like information technology, network security, likely corporate "security" and more.
May be in some ways similar to or related to the idea of an Information hazard, but in a legal sense.
Very short version
[edit]Data points by themselves are safe to consider in isolation, and were likely released properly per all relevant legal and organizational requirements. However, if you combine and look at those data points just right, you've now breached security--even up to the level of national security stuff.
Imagine if you could combine ALL the text from ALL the sources on a given 100 Wikipedia articles about government-related stuff. All that stuff, by itself, in isolation, is safe. Combine it all and maybe that aggregate data would be considered sensitive compartmented information requiring a sensitive compartmented information facility to even review it.
By arranging the mosaic of information just so, you've revealed secrets.
Term mosaic effect
[edit]Timeline...
- 1967 - (maybe) https://supreme.justia.com/cases/federal/us/390/39/
- 1981 - https://www.ojp.gov/pdffiles1/Digitization/92732NCJRS.pdf
- 1993 - https://www.tbs-sct.canada.ca/pol/doc-eng.aspx?id=25502§ion=html
- 1999 — https://www.federalregister.gov/documents/2000/12/21/00-32565/public-information-and-confidentiality-advance-notice-of-proposed-rulemaking-withdrawal-of-1994
- 2002 — https://www.energy.gov/data/procedures-public-release-data
- 2002 — https://www.justice.gov/information-quality
- 2004 — https://aspe.hhs.gov/sites/default/files/private/pdf/77196/rpt_Disclosure.pdf
- 2010 - https://richmurnane.blogspot.com/2011/01/mosaic-effect.html
- 2013 — https://obamawhitehouse.archives.gov/sites/default/files/omb/memoranda/2013/m-13-13.pdf
- 2014 — https://www.route-fifty.com/cybersecurity/2014/05/worried-about-security-beware-the-mosaic-effect/297335
- 2014 — https://www.nextgov.com/digital-government/2014/05/the-mosaic-effect-and-big-data/254461/
- 2014 — https://www.brookings.edu/wp-content/uploads/2014/11/20141201_health_data_transcript.pdf
- 2014 — https://aspe.hhs.gov/sites/default/files/private/pdf/77196/rpt_Disclosure.pdf
- 2017 — https://dtm.iom.int/sites/g/files/tmzbdl1461/files/07-11-2017%20Humanitarian%20Data%20Protection%20Draft%205.pdf
- 2019 — https://resources.data.gov/assets/documents/fds-data-ethics-framework.pdf
- 2019 - https://www2.census.gov/library/publications/decennial/2020/2020-census-disclosure-avoidance-handbook.pdf
- 2021 — https://www.washingtonpost.com/politics/2021/08/17/cybersecurity-202-sensitive-government-data-could-be-another-casualty-afghan-pullout/
- 2021 — https://blogs.icrc.org/law-and-policy/2021/02/09/mosaic-effect-revelation-risks/
- 2023 — https://www3.weforum.org/docs/WEF_Global_Risks_Report_2023.pdf
To review:
Corporate stuff
[edit]- https://ft.com/content/84621418-34a4-11e0-9ebc-00144feabdc0
- https://mitsloan.mit.edu/ideas-made-to-matter/supply-chain-transparency-explained
- https://online.wsj.com/article/SB10001424052748703864204576321013619678894.html
- https://online.wsj.com/articles/BL-DLB-33263
- https://online.wsj.com/articles/BL-DLB-33491
- https://rsaconference.com/library/blog/your-guide-to-osint-in-corporate-security
- https://sans.org/blog/what-is-open-source-intelligence/
- Need to find archive or alternative URL, found this mentioned in another piece: https://scholarship.wustl.edu/cgi/viewcontent.cgi?article=1850&context=law_journal_law_policy
- https://thetradinganalyst.com/mosaic-theory/
- https://tuckerellis.com/lingua-negoti-blog/is-the-mosaic-theory-as-a-defense-to-insider-trading-dead/
- https://www.proskauer.com/pub/proskauer-hedge-fund-trading-guide-2024-chapter-2-insider-trading-focus-on-subtle-and-complex-issues
- https://www.wired.com/2007/12/why-anonymous-data-sometimes-isnt
News & general bucket
[edit]- https://www3.weforum.org/docs/WEF_Global_Risks_Report_2023.pdf
- https://www.stanfordlawreview.org/wp-content/uploads/sites/3/2015/03/67_Stan_L_Rev_677_Schlabach.pdf
- https://digitalcommons.wcl.american.edu/cgi/viewcontent.cgi?article=1549&context=jgspl
- https://www.capitallawreview.org/api/v1/articles/89888-the-mosaic-theory-how-the-intersection-of-mass-surveillance-and-facial-recognition-is-provoking-an-orwellian-future.pdf
Non-US POV
[edit]- https://www.theguardian.com/uk-news/2023/nov/09/royal-security-cost-guardian-freedom-of-information-tribunal
- https://www.washingtonpost.com/politics/2021/08/17/cybersecurity-202-sensitive-government-data-could-be-another-casualty-afghan-pullout/
- https://iapp.org/news/a/beyond-gdpr-unauthorized-reidentification-and-the-mosaic-effect-in-the-eu-ai-act
- https://rkroundtable.org/2011/12/20/mosaic-theory-universal-surveillance-and-unlimited-recordkeeping/
finance/econ
[edit]Tranche 1 taken from Mosaic theory (investments)
- https://openscholarship.wustl.edu/cgi/viewcontent.cgi?article=1850&context=law_journal_law_policy
- https://scholarship.law.upenn.edu/faculty_scholarship/407/
- https://sites.law.berkeley.edu/thenetwork/2011/10/18/the-galleon-insider-trading-case-how-to-sentence-a-seemingly-victimless-crime/
- https://www.sec.gov/news/speech/spch444.htm
- https://www.sec.gov/Archives/edgar/data/1532747/000153274713000195/exp56_ubsinsidertrad061912.htm
- {{Cite journal|title=Regulation FD: An Alternative Approach to Addressing Information Asymmetry.|last=Fisch, Jill|journal=Faculty Scholarship at Penn Law|date=2013}}
- {{Cite web|title=UBS Global Asset Management Insider Trading Policies and Procedures|date=2012|website=SEC}}
- {{Cite web|title=The Galleon Insider Trading Case: How To Sentence a Seemingly Victimless Crime?|last=Hautekiet J.|date=2011|website=Berkeley University of California}}
- {{Cite web|title=Speech by SEC Staff: New Rules, Old Principles|last=Becker, D. M.|date=2000|website=SEC}}
- {{Cite web|title=Abandoning the 'Mosaic Theory' of Securities Analysis Constitutes Illegal insider Trading and What to do about it.|last=Davidowitz, A. S.|date=2019|website=6 Wash. U. J. L. & Pol’y281}}
- https://openscholarship.wustl.edu/cgi/viewcontent.cgi?article=1850&context=law_journal_law_policy
Tranche 2?
- https://www.economist.com/finance-and-economics/2011/04/14/the-mosaic-defence
- https://sevenpillarsinstitute.org/case-studies/raj-rajaratnam-and-insider-trading-2/
- https://www.hflawreport.com/2541831/implications-of-the-rajaratnam-verdict-for-the-mosaic-theory--the-knowing-possession-standard-of-insider-trading-and-criminal-wire-fraud-liability-in-the-absence-of-a-trade.thtml
- https://www.courthousenews.com/mosaic-defense-raj-is-not-the-first-to-use-it/
- https://archive.nytimes.com/dealbook.nytimes.com/2010/11/29/just-tidbits-or-material-facts-for-insider-trading/
- https://archive.nytimes.com/dealbook.nytimes.com/2011/04/11/why-is-insider-trading-wrong/
- https://www.researchgate.net/publication/332855906_Public_Disclosures_and_Information_Asymmetry_A_Theory_of_the_Mosaic
Classification by compilation
[edit]"Classification by compilation" is an older precursor term?
Legal and policy definition
[edit]- Classification by compilation (EO 13526, DOJ FOIA Guide)
Technical parallels
[edit]- Aggregation risk, inference attacks, re-identification, open-source fusion
Origins in intelligence policy
[edit]- Early case law (Halkin v. Helms, CIA v. Sims)
Post-9/11 expansion
[edit]- FOIA Exemption 1 jurisprudence
- David Pozen’s Yale Law Journal analysis
National security and government transparency
[edit]- FOIA exemptions, Glomar responses
- Executive training (DoD, ISOO, DOJ)
- Compilation doctrine under classification law
Personal privacy and data re-identification
[edit]- Latanya Sweeney’s k-anonymity research
- Netflix deanonymization case
- Wired and mainstream coverage
- Privacy law responses
Geospatial and location intelligence
[edit]- Strava heatmap incident
- OMB M-13-13 and the “mosaic effect” test
- Satellite imagery + public geodata risks
Financial markets and corporate compliance
[edit]- Analyst mosaic theory (Reg FD guidance)
- Insider trading enforcement cases (e.g., Galleon)
- Hedge fund legal guidance and critiques
Critical infrastructure and smart-city data
[edit]- Open utility shapefiles + imagery
- RSA and SANS OSINT examples
- CISA/HIFLD data disclaimers
Criticisms and limitation
[edit]- Over-classification
- Unfalsifiability concerns
- Transparency vs. security tensions
Policy and regulatory responses
[edit]- Open-data withdrawal cases (Data.gov, Afghan data)
- HHS and DoD data-minimization protocols
- Differential privacy, redaction frameworks
Impacted domains and industries etc
[edit]High level read from article draft, to see from other searching what is being overlooked as possible angles to cover.
- Advertising & behavioral targeting
- Artificial intelligence & machine learning
- Biometric identification systems
- Corporate competitive intelligence & analysis
- Criminal investigations & law enforcement
- Data privacy & anonymization law
- Finance & securities investment analysis
- Fraud detection & identity theft
- Government open-data initiatives
- Humanitarian aid & social-protection programs
- Intelligence & national-security operations
- Legal transparency (FOIA) & classification
- Medical & public-health analytics
- Oil & gas infrastructure monitoring
- Reproductive-health data investigations
- Sensor-based environmental data (e.g., NOAA)
Saving a point in time archive
[edit]Just to have a clear marker of unused as of today URLs; that may spillover to other related articles as useful sources. There may be more culling of URLs at this point than additions going in. TBD. -- Very Polite Person (talk) 17:36, 23 July 2025 (UTC)
Did you know nomination
[edit]- The following is an archived discussion of the DYK nomination of the article below. Please do not modify this page. Subsequent comments should be made on the appropriate discussion page (such as this nomination's talk page, the article's talk page or Wikipedia talk:Did you know), unless there is consensus to re-open the discussion at this page. No further edits should be made to this page.
The result was: promoted by Darth Stabro talk 17:28, 1 August 2025 (UTC)
- ... that the mosaic effect is the act of combining seemingly unrelated data to reveal sensitive or classified information that individual pieces of data would not disclose?
- Reviewed:
-- Very Polite Person (talk) 22:28, 28 July 2025 (UTC).
General: Article is new enough and long enough |
---|
Policy: Article is sourced, neutral, and free of copyright problems |
---|
|
Hook: Hook has been verified by provided inline citation |
---|
|
Image: Image is freely licensed, used in the article, and clear at 100px. |
---|
|
QPQ: Done. |
Overall: A truly fascinating and vital article. Great writing and mosaic-ing of disparate sources. No Swan So Fine (talk) 13:35, 1 August 2025 (UTC) No Swan So Fine (talk) 13:35, 1 August 2025 (UTC)