Friday, February 26, 2010

Thursday, February 25, 2010

Annoyed now: Google & Italy

Lots of the blogosphere exploded in indignation yesterday at the revelation that an Italian court had found Google execs, including privacy chief Fleisher, criminally liable for publishing an amateur vid on You Tube which invaded the privacy of the special needs child depicted being bullied therein. Charges of criminal libel were however dismissed. Lawyers amongst us wondered if someone had forgotten to tell Italy about the safe harbours for hosting intermediaries of the E-Commerce Directive , arts 12-15 which apply throughout Europe. Richard Thomas, the UK's former Information Commissioner, despaired that this verdict was giving privacy a bad name. Americans, used to the total (and one might say, over-wide) immunity given online intermediaries in relation to publication torts by the Communications Decency Act were even more flabbergasted. Google, understandably slightly over egging it a tad, called it a serious threat to the very freedom of the Internet, well, at least in Italy. Peter Fleischer, awarded a six month suspended sentence, sounded about as genuinely outraged as a top corporate exec can sound on his blog, and threatened appeals, hellfire and a boycott of pasta.

Pangloss was surprised but also a little smug, as she'd covered this story as far back as May last year and in detail here. While we're waiting for an opinion to come from the Italian court (apparently required within 90 days, and is there an Italian translator out there please?) it is maybe worth refreshing the reader's memory for the only four ways I saw this case could go against Google, assuming Google did plead the ECD (bit of a no brainer that).

1. Italy may not have at all, or properly implemented the ECD. In which case Google has a claim for damages against Italy and the case may eventually to end up in the ECJ to hilarious embarrassment.

2. Italy may not think the ECD applied to Google/You Tube as a host, because of doubts about the "independence" of YT as an intermediary from its users . This argument has prevailed in some high profile French cases, but has largely been rubbished in most the rest of the EU. In particular the "YouTube complicit with users" argument may have some legs when we are talking about YT making money from ads next to popular copyright videos eg MTV clips, and thus, conceivably, being seen to profit from copyright infringement (cf current Viacom US litigation); but has absolutely none in the case of a video of this kind. Basically, YT provided a platform and got nothing out the deal except trouble.

3. Italy may not think the ECD applied to Google/You Tube as a host, because the ECD may only apply to commercial operators. This is almost entirely exploded as a theory, and will be when the Google Adwords case gets its full judgment from the ECJ next month. The Advocate-General's preliminary Opinion, as I noted in November, already plainly agrees that a search engine like Google which makes money indirectly from adverts while free to users can fall within the ECD. The UK courts have also so agreed.

4. The ECD safe harbour for hosts says basically that they are immune from liability for what they publish until they receive "notice" of illegal content. It does not say either that they have to pre-vet videos, nor that they have to read all the comments below a video. Pangloss suspects this, if anything, is the legal ambiguity in the case. Google says they took down as soon as the police gave them notice; Gooogle's opponents say "but the video was up for two months and people complained in comments". Should those "comments" have been regarded as notice then? In which case, did Google have a duty to pro-actively read them?

This is the bit that gets me annoyed. Google's success, as the Guardian's Charles Arthur explained cogently the other day, is built on automating everything. This doesn't mean that Google should be free of all responsibility for what goes on on its watch, but it does mean that exercising that responsibility should be practicable, or we lose Google and all its free chocolate factory offerings. Reviewing every comment under the millions of videos on YouTube - and in a multiplicity of languages - and in real or near real time - is impossible. It is a human task. It is not automatable. You can design algorithms to compare copyright works to "watermark" versions of the same - an approach Google is working on to cut down on YT piracy - but you cannot design a computer programme which can work out what videos - or text or images - are libellous or privacy-invasive. You just can't; well maybe not until artificial intelligence has finally gone Singularity, and possibly not even then - human judges find it hard enough a task.

The ECD was actively designed to set up that kind of practical responsibility for hosts. Receive notice of illegality; take down, or else become liable for it. It raises other issues about kneejerk censorship (we'll come back to that), but it is at least a good start. So when a freak case like this undermines the notice and take down system, it really is time to get our facts straight.

One way out here is to provide an easy way for the worried to flag a video as "inappropriate". That definitely would be notice, to which a takedown response could be automated. Malcolm Coles accuses Google's systems for alert of not working here, so I went and had a look. YT puts a "Flag" button below every video, fairly obviously, but it seems you can only use it if logged in. This means setting up a YT account; a process convoluted enough to put off a casual viewer, especially a one time viewer alerted by some one saying "look have you seen this, isn't it terrible?" This might explain why people left comments rather than gave "notice" on the YT site in the Italian case.

In which case, should Google be liable for failure to design robust systems of notice?? If so we're setting a very, very high bar for ECD immunity. Every host - which includes nearly every ISP and business in Europe with a website - would have to design obvious and accessible notice and take down buttons for the public, or fear legal liability. I can tell you from informal survey research I did myself a while back that most sites have far, far less information (if any) on how to give notice than YT. And in the UK, there is nothing in our law that requires this degree of specificity.

But there is another , more profound reason why automating takedown is not only impossible but undesirable. Google's complaints policy on privacy (for the UK) says:

"We don't act on all privacy complaints. The complaints we do act on usually involve videos, comments, or other text that contain your image or private information (such as social security number, government I.D., or credit card information). These days there's a good likelihood that you might get caught on camera if you're in a public place - whether it be a security camera or a tourist who inadvertently captures your image in their video. If you're complaining about a video that shows you in passing while you're in a public place, chances are we won't take action on your complaint unless you're clearly identified or identifiable in the video."

As a semi expert in the field, that reads to me like a true outline of the law. It may not be true of Italy. However it shows the dangers of accepting any claim of privacy invasion lightly, from anyone, without checking. Human checking that is - possiby even a human lawyer, if that isn't a contradiction in terms. Do we want to live in a world where anyone can censor any online content simply by claiming some kind of abuse of rights - privacy, libel, copyright - and demanding automatic take down? It would be an easier world for Google, to be sure - and an appealing world for those who want, understandably, videos of their children being abused or bullied online removed as as fast as possible - but bad news overall for the public interest in free speech and the public domain.

So how do we square this circle? If Google - and its competitors - can't primarily automate what they do, they cease to be able to function. Yet notice and take down is a process which if automated is inherently either impossible or undesirable. Is there a solution? I'm only a lawyer, not a computer scientist. I'm not sure. But if the Google Italy fracas is to do any good, it should inspire a debate , between science, business, law and the public about what that solution might be.

EDIT: ta to Charles Arthur at the Guardian for the nice link.

Wednesday, February 17, 2010

Filtering round up: French filtering, Ireland backs off, UK sidesteps?

Bit of a round up here on some interesting stories of last few weeks on aspects of filtering that I've been accumulating.

Increasingly, stories as to filtering out illegal content such as child porn; blocking infringing downloads of copyright material by deep packet inspection and disconnection; and filtering to fight the "war on terror" are converging. For all of these, the same issues come up again and again: privacy; proof, transparency and other aspects of due process; and scope creep. These 3 stories illustrate this well. For my own recent take on the issue of Net filtering, as I said before, see my Internet pornograohy chapter on SSRN, which suggests the need for a Free Speech Impact Assessment before non transparent stateNet filtering schemes are introduced, for whatever purpose.

Filtering of illegal content in France

Thanks to @clarinette on Twitter (whose real name I am not absolutely sure of!!) for pointing me to another important European move towards non transparent Internet filtering - this time in France. From La Quadrature de Net:

Paris, February 11th, 2010 - During the debate over the French security bill (LOPPSI), the government opposed all the amendments seeking to minimize the risks attached to filtering Internet sites. The refusal to make this measure experimental and temporary shows that the executive could not care less about its effectivity to tackle online child pornography or about its disastrous consequences. This measure will allow the French government to take control of the Internet, as the door is now open to the extension of Net filtering.

The refusal to enact Net filtering as an experimental measure is a proof of the ill-intended objective of the government. Making Net filtering a temporary measure would have shown that it is uneffective to fight child pornography.

As the recent move1 of the German government shows, only measures tackling the problem at its roots (by deleting the incriminated content from the servers; by attacking financial flows) and the reinforcement of the means of police investigators can combat child pornography.

Moreover, whereas the effectivity of the Net filtering provision cannot be proven, the French government refuses to take into account the fact that over-blocking - i.e the "collateral censorship" of perfectly lawful websites - is inevitable2. Net filtering can now be extended to other areas, as President Sarkozy promised to the pro-HADOPI ("Three-Strikes" law) industries3."

LQN are never exactly ones to mince their words:-) so the strong nature of this statement should perhas be taken with some care - but Pangloss intends to go investigate this story further.

Ireland, Eirecom, disconnection and DP

Meanwhile in a surprising twist, Eirecom have apparently pulled out of the negotiated settlement they reached in January 2009 to disconnect subscribers "repeatedly" using P2P for (alleged) illicit downloading. This was the result of the Irish court case brought against them by various parts of the music industry for hosting illegal downloads, and appeared to open up a route to "voluntary" notice and disconnection schemes on the part of the ISP industry; a worrying trend both for advocates of free speech, privacy, due process, ISP immunity and net neutrality.

Now however according to the Times:

As part of the agreement, Irma said it would use piracy-tracking software to trace IP addresses, which can identify the location of an internet user, and pass this information to Eircom. The company would then use the details to identify its customer, and take action.

But the office of the Data Protection Commissioner (DPC) has indicated that using customers’ IP addresses to cut off their internet connection as a punishment for illegal downloading does not constitute “fair use” of personal information. Irma and Eircom have asked the High Court to rule on whether these data-protection concerns mean the 2009 settlement cannot be enforced.

This is very, very interesting. A court case on this might settle a number of outstanding DP legal issues: whether IP addresses are "always" personal data (on which see also a recent EU study demonstarting the disharmny across Europe on this) and if not, when; what the scope of the exemmptions for preventing and investigating crime are; and what"fair" means in the whole context of the DP principles, purpose limitation and notice for processing.

Not only that but as the Times indicate, the human rights issues which have been repeatedly aired in debate around "three strikes" generally, would also come into play as well, as the straight DP law. Is use of a customer's personal data to cut them off from the Internet a proportionate response to a minor civil infringement? Does it breach a fundamantal right of freedom of expression or association? Does it breach due process? This could be the DP case of the decade. Pangloss is geekily excited. If anyone out there is involved in this case, do let me know.

UK cops don't terrorise the IWF?

Finally , as widely reported, the UK Home Office has introduced a website hotline for the public to report suspected terrorist or hate speech sites. Reports are then vetted by ACPO, the Association of Chief Police Officers, who it appears can then take action, not only by investigating in normal way, but also by asking the relevant host site to take down. The official press release notes : "If a website meets the threshold for illegal content, officers can exercise powers under section 3 of the Terrorism Act 2006 to take it down." Indeed on serving such a notice, the host only has 2 days to take down or loss immunity under the UK ECD Regs.

As TJ McIntyre also notes, this is a rather significant development, not just in itself but for sidestepping use of the Internet Watch Foundation (IWF). There have been persistent rumours since and before then-Home Sec Jacqui Smith's famous speech in Jan 2008, that theUK government was attempting to pressurise the IWF into adding reports of hate speech/terror to its block- or black-list; and that the IWF was as strongly resisting this, hate speech being a somewhat more ambiguous and controversial matter than adjudicating on child sexual imagery.

It seems then that the IWF has held fast and the Home Office have backed off and created their own scheme, which embraces only take down in the UK, not access blocking to sites abroad (?). Whether this is ideal remains to be seen. The IWF, at least until recently had the services of esteemed law prof Ian Walden as well as a lot of accumulated experience, and may have been a better informal legal tribunal, than a bunch of chief constables, to decide on the illegality of sites under terror legislation. Who knows. On the other hand , adding alleged terror URLs to an invisible, encrypted, non public blocklist defeats every concept of transparency and public debate regarding restrictions on freedom of political speech, and Pangloss is glad to see it avoided.

Pangloss's view remains that such difficult non-objective issues are best decided by the body long set up to deal with questions of hazy legal interpretation: namely, the courts. The definition of "terrorist" material for the urposes of s 3 of the 2006 Act is as follows (s 3(7)):

"(a) something that is likely to be understood, by any one or more of the persons to whom it has or may become available, as a direct or indirect encouragement or other inducement to the commission, preparation or instigation of acts of terrorism or Convention offences; or

(b) information which—

(i) is likely to be useful to any one or more of those persons in the commission or preparation of such acts; and

(ii) is in a form or context in which it is likely to be understood by any one or more of those persons as being wholly or mainly for the purpose of being so useful."

Well I hope that clears everything up :-) Still confused? Try s 3(8)).
"(8) The reference in subsection (7) to something that is likely to be understood as an indirect encouragement to the commission or preparation of acts of terrorism or Convention offences includes anything which is likely to be understood as—

(a) the glorification of the commission or preparation (whether in the past, in the future or generally) of such acts or such offences; and

(b) a suggestion that what is being glorified is being glorified as conduct that should be emulated in existing circumstances."

Er give me that last line again?

As with previous contested IWF rulings, the same questions come up again: what is the appeal from a take down notice under s 3 to the regular courts? What notice if any is given to the site owner and the public of therfact of and reasons for take down? What safeguards are there for freedom of speech? None of these are mentioned in ss 1-4 of the 2006 Act. Nor does there seem to be a general provision in the Act for Part 1 or the whole of the 2006 Act for appeals or review. Since the police are a public body however, one imagines that judicial review might be competent. EDIT However I am helpfully informed that ACPO is a company limited by giuarantee and regards itself as not a public body at least for the purpose of FOI requests. Clarity on this would be very desirable. And as noted above record keeping of take down for terror reasons seems to be poor due to voluntary compliance by ISPs.

Finally why introduce these powers if they are to be circumvented anyway? The Register reported on 12 November 2009 that so far no notices had been issued under s 3 anyway, because the UK ISPs involved had agreed to take down voluntarily, and no record has been kept of how many sites this involved. Furthermore if a site is taken down in the UK it won't be hard to resurrect it in a foreign country, where most extremist sites will be based anyway: El Reg reports that one site the police allegedly have their eye on, al-Fateh, a Hamas anti-Jewish kids site, is in fact hosted in Russia. One imagines this will continue to increase pressure on the IWF to expand the block list despite the latest moves.


Sunday, February 07, 2010

HL Committee on the Digital Economy Bill

Yes, that again:-)

As Twitter and ORG resders may know, I'm meaning to write some kind of interim summary of what the Committee stage in the House of Lords has "fixed" in the Digital Economy Bill with respect to the file-sharing and copyright provisions (A: not a lot) and what still needs urgently brought up at Report Stage and if necessary all the way to and through the Commons (A: an awful lot). This despite the best efforts of some exceptionally knowledgeable and persistent Lords, including though not limited to Lord Lucas, L. Howard of Rising, Lord Clement-Jones and the Earl of Errol.

However it seems my job has possibly been done for me - by the Lords' own Human Rights Joint Committee. Their executive summary makes very, very interesting reading and is worth quoting in full:

"
The Digital Economy Bill has been introduced to update the regulation of the communications sector. Due to time-constraints we focus on a single issue in the Bill: illegal file-sharing.

Copyright infringement reports

The Bill establishes a mechanism whereby holders of copyright will be able to issue a 'copyright infringement report' to an ISP where it appears that the ISP's service has been used by an account holder to infringe copyright. ISPs will be required to notify account holders when a copyright infringement report is received in connection with their account. The ISPs will also be required to maintain a list of account holders who have been the subject of such reports.

We consider that it is unlikely that these proposals alone will lead to a significant risk of a breach of individual internet users' right to respect for privacy, their right to freedom of expression or their right to respect for their property rights (Articles 8, 10, Article 1, Protocol 1 ECHR). However, we call on the Government to provide a further explanation of why they consider their proposals are proportionate.

Technical measures

The Bill provides for the Secretary of State to have the power to require ISPs to take "technical measures" in respect of account holders who have been the subject of copyright infringement reports. The scope of the measures will be defined in secondary legislation and could be wide-ranging.

We do not believe that such a skeletal approach to powers which engage human rights is appropriate. There is potential for these powers to be applied in a disproportionate manner which could lead to a breach of internet users' rights to respect for correspondence and freedom of expression. We set out a list of points that the Government should clarify in order to reduce the risk that these proposals could operate in a manner which may be incompatible with the Convention.

Right to a fair hearing

The Bill provides for provisions for appeals in codes. There is little detail about the right to appeal in the case of copyright infringement reports or decisions about the inclusion of certain individuals' information on copyright infringement lists. We consider that statutory provision for a right to appeal to an independent body against inclusion on any infringement list would be a human rights enhancing measure.

Without a clear picture of the criteria for the imposition of technical measures it is difficult to reach a final conclusion on the fairness of the process for the imposition of technical measures. This is a further argument against the skeletal nature of the technical measures clauses. We ask for further information about the quality of evidence to be provided and the standard of proof to be applied to be provided on the face of the Bill.

Reserve powers

Clause 17 of the Bill provides the Secretary of State with the power to amend the Copyright, Designs and Patents Act 1988 by secondary legislation. The broad nature of this power has been the subject of much criticism. In correspondence with us, the Secretary of State explained that the Government intended to introduce amendments to limit the power in Clause 17 and to introduce a 'super-affirmative' procedure. The Government amendments would limit the circumstances in which the Government could use their powers to amend the Act by secondary legislation and would provide a system for enhanced parliamentary scrutiny.

Despite the proposed amendments we are concerned that Clause 17 remains overly broad and that parliamentary scrutiny may remain inadequate. We call for a series of clarifications to address these concerns."

Delightful to see such plain and clear and unadulterated good sense. I particularly applaud the second section: "We do not believe that such a skeletal approach to powers which engage human rights is appropriate." Put that on your tee shirt and smoke it.

In the meantime, all kinds of odd and eddying currents are flowing around the whole filesharing mess, here and abroad. In Blighty, we're seeing more and more sectors of industry, like the hoteliers, coming to the realisation of how bad the DEB will be for them as providers of public wi fi to the public; in Europe, the Belgian SABANE case, which imposed an impossible to fulfil filtering obligation on a Belgian ISP in the interests of rightsholders, is going on appeal to the European Court of Justice, with strong backing in evidence from trusted computer industry experts ; and the first Ozzie case on intermediaries and file sharing since KaZaa has been heard, and as with Oink in the UK ,the music industry have done themselves no favours by bringing it (though this case, being civil, includes no room for accusations of perverse juries).

More on all of these to come, I suspect, but on the last, I direct you meanwhile to my colleague Technollama's very helpful comments on the Australian case. From Pangloss, it is bonne nuit.


Google and China: the fallout continues

Since I wrote my last post suggesting (rather speculatively) that Google's apparent willingness to pull out of China might be linked to US state fears of (and pressure concerning?) cyber espionage against data held by Google about US citizens instead of/as well as Chinese dissidents, the world has become very interested in the succeeding revelation by Google that they are now working with the NSA to improve their cyber defenses.

This raises all kinds of further questions: doesn't Google have as much expertise in computer security itself as the Spooks? Or as someone put it even more conspiratorially on Twitter: hadn't we always assumed Google was working with the spooks? In which case what drove a public admission of it now?

All fun stuff and clearly far beyond the ken of a mere academic lawyer. But t0day's Grauniad has an interesting quote:

"Google is unlikely to be turning to the NSA for technical advice. Why then is it calling in the spooks? One reason could be that the world's dominant internet company is now in the crossfire of early skirmishes of the next cold war.

This thought was reinforced by Financial Times columnist Gideon Rachman. He'd been to the International Institute for Strategic Studies for a briefing on its annual survey, Military Balance. "The thing I found most interesting," he said, "was the confirmation that cyber-security is the hot issue … John Chipman, the head of the IISS, says the institute is about to launch a study of cyber-security which raises all sorts of issues. What if a country's infrastructure could be destroyed as effectively by a cyber-attack as by an invasion of tanks? How do you defend against that? How do you identify the culprits? What does international law have to say – might we have to revise our definitions of what constitutes an act of war?"

"Chipman argues, plausibly, that we are now at an equivalent period to the early 1950s. Just as strategists had to devise whole new doctrines to cope with the nuclear age, so they will have to come up with new ideas to cope with the information age."

I've noted before that I find it difficult to see how current international law can define cyber attacks and especially cyber espionage as armed attacks justifying, eg, the doctrine of self defense. But I've also now been to several events where military lawyers seemed to be if not saying then at least moving toeards exactly that. It is clear we are entering the era of what is sometimes called "justificatory discourse" regarding cyber war, or PR in less elevated circles. (The irony of the fact this is playing out as the Iraq inquiry goes on is not lost on Pangloss. Nor that MI5 appears to be trying to get in on the action by revealing what bad stuff Chinese cyber spies have been doing inthe UK too.) The same thing, is, of course, happening in China too: one report from there notes that the average Chinese citizen is mostly apathetic to the loss of Google but Chinese news coverage has " focused not on Google but on what is perceived as US "information imperialism." "

And meanwhile, the ever excellent Ray Corrigan points out (I think - lots of interesting stuff packed in here) that cyberwar may be becoming the latest bogeyman, following hard on pedophiles and alQuaeda to justify incursions into our civil liberties. And that we are hardly ones to condemn China's Great Firewall, when we do an awful lot of net censorship ourselves. (See further, dare I say, my own chapter here, which is the basis of the paper on cyber filtering and free speech I'm giving in a few days.)

OT: Looking at B2fxx reminds me I have been derelict of duty not to mention my collague Chris Marsden's much awaited book on 'Net neutrality: towards a co-regulatory solution' is not only just published by Bloomsbury but also available for free download under a creative commons licence at http://www.bloomsburyacademic.com/pdf%20files/NetNeutrality.pdf . Lordy lordy such wondrous times we live in!!

Thursday, January 28, 2010

GikII 5!!!

Heads up GikII people; GikII 5 *will* be in Edinburgh June 28-29 2010. We have FINALLY managed to book a room!! More details soon. Already one paper offered on Gallifreyan legal procedure :-)

Google and China: Interesting Times?

So what do we think about the Google China affair then? For anyone who has been hiding under a rock on Pluto lately, Google announced on January 13th that it "may end its operations in China following a "sophisticated and targeted" cyber attack originating from the country." aimed apparently at gathering intelligence from Gmail accounts etc on human rights activits, dissidents and the like in China, and adding that in response they would no longer self censor their search database as they had since starting up in China in 2006. China, unsurprisingly, insisted that hacking was illegal in China and Google would have to toe the line and enforce local laws like other companies. Then perhaps slightly more surprisingly, the US government itself got involved in the form of a swinging speech by Hilary Clinton demanding that Beijing that should investigate the hack attacks on Google, and les directly, implying that China had a duty, like also-mentioned Tunisia, Uzbekistan, Vietnam and Egypt to stop restricting freedom of expression on the Internet. One commentator has compared this to Reagan demanding the pulling down of the Berlin Wall - only this time it was the Chinese Great Firewall. For China to back down wouldbe almost unprecedented; so at least China insider has said that in six months he expects there to be no Google.cn. Meanwhile information filters out that similar espionage hacks seem to have been mounted by Chinese hackers on other US companies in recent months , seeking economic espionage intelligence; two of the companies were major US oil companies.

The main response to this has been huzzah! In a world apparently dominated by bankers taking as many undeserved bonuses as they can sweep up, one can sense the eagernness of the world to believe that a big company can still want to do the right thing. Certainly even if Google's "Do no evil" motto has tarnished a little lately they do stand out as appearing in the world of corporate politics to give a damn about human rights. A Grauniad columnist wrote perhaps a little over excitedly yesterday:
"
we can now again unreservedly identify, politically as well as aesthetically, with Google. This is the spirit of liberal universalism. It says that there are some universal rights it is not the prerogative of any state or "civilisation" to curb; and that, as the Universal Declaration of Human Rights states, the right to information freedom is among them."
But is anything in life really this simple? As many have pointed out, China is a market where Google is not dominant, having only around 30% of the market. But pulling out of the world's largest emergent economy is still rather a bold step. Unless perhaps you consider the rather less publicised fact that Google only makes money by click through on ads; and reportedly, the Chinese don't yet bother to click through (Google don't reveal the turnover of their Chinese business as they do their US profits). Still it seems like either a very brave or a very foolhardy endeavour. (Bill Thompson comments that "Threatening to pull out of China is like threatening to spit on a whale".) (Unless you think it's all merely a very successful PR stunt.)

A braver woman than Pangloss might even sail into the world of conspiracy theories, and consider the Google response and the Clinton speech as part of a combined PR drive. China expert Orville Schell in this video recorded at Davos, notes that
"Google has become more like a nation than a company. By this he means that not only is Google closely connected to the Obama administration, but the company has a high resonance in the western world. Only a company like Google could take such a stance against China".
Why would the US want Google out of China, or at least, a very public fuss about the hack attacks on Gmail accounts by China? Well cybersecurity experts have long privately admitted that although rather more fuss has been publicly made about "cyberwar" denial of service attacks on critical infrastructure (as , famously, against Estonian and Georgian banks and media sites, etc), the foremost worry is actually about cyber espionage. Chinese keylogger code has been found before now on military computers; it is known that it is almost impossible to 100% protect against this. Google store invaluable information not just about Chinese dissidents but US citizens - and companies. If you were a Chinese espionage officer would you target the unprotected Gmail user or the more protected Google servers, or the very well protected servers carrying confidential military or corporate secrets?

For a cyber lawyer, the interest here is whether we are approaching the point where cyber espionage might begin to be characterised as "cyberwar". Just as with DDOS attacks, the current law is badly equippd, perhaps quite properly, to make this conceptual leap. I spoke on this in Estonia last summer, at the NATO backed CyberSecurity Centre. International treaties demand an "armed attack" by a "state" before rights of self defence or international humanitarian law can begin to apply. Is use of code to find out information an "armed attack"? Difficult to see (although there was some discussion of this back in the good ol' days of Star Wars defence.)

More significant still is the pained matter of attribution. No one can prove that attacks by Chinese hackers came from and with the authority of the Beijing government - and circumstantial evidence simply cannot be regarded as decisive here given the easy obfuscation of Internet traffic and addresses, and the flourishing private enterprise cyber black market. Much of the cybercrime in the world originates from networks of zombie machines run (apparently:-) by Russians with the machines scattered through every country from the UK to Brazil; this does not mean (necessarily) that Russia, the UK or Brazil is responsible as a state aggressor. The question of attribution will have to be far better discussed before we can go any further down this line. In the meantime however, it is interesting to note that there are reported American stirrings of interest in a cyberwar treaty to reduce cyber-attacks, as with munitions or poison gas weapons: such a treaty has long been resisted by the US, but now that position seems to be shifting - why?*

And meanwhile today brave little Twitter, hero of the Iran dissidents, announces they are sub contracting research to avoid being blocked by China. All in all very interesting times - in the Chinese sense?

*Well perhaps because as I discover the minute I finish writing this, 37% of US critical infrastructure firms think cyber attacks are growing and 2/5 expct a majot cyber security incient within the year - say McAfee at Davos.

Life, etc

Via my very lovely colleague Judith Rauhofer;

Quote of the week by Lord Clement-Jones:

" When a man is tired of the Digital Economy Bill, he is tired of life. I am sure this show will run for a long time."

And indeed, now the debates in HL Committee over the "three strikes" parts of the DEB have ended, watch this space for some thoughts on how the debates have gone, shortly. For now, interesting to note that legal process needs tweaking too: see the latest Which? report on the deluge of complaints against P2P ambulance chasing bully firm , ACS Law (creditably, much mentioned in the Lords debate.)

"
ACS:Law has sent thousands of letters to people claiming they have illegally downloaded material and offers them a chance to settle by paying around £500. 

Which? says it has been approached by some - including a 78 year-old accused of downloading pornography - who have no knowledge of the alleged offence.

ACS:Law said its methods were accurate.

The London-based firm said that it would send more letters soon."


In other news, I'd also like to comment on Google and China (interesting response here from the reliably interesting Bill Thompson, one of the few voices to be more realistic than triumphant here), connected cyberwar developments and public open data in the UK - to be continued!! (Oh and I'd really like to talk about whether full body airport scanning really constitutes distribution of child porn (eh?) as oposed to invading privacy (for sure). But chance would be a fine thing!

Also, the first review of Law and the Internet 3rd edn!! Thanks to Andrew Katz for preparing me, er, letting me know!!

Wednesday, January 20, 2010

ORG : Fight the Digital Economy Bill unconferences

Via ORG: a series of meet ups in Manchester, London, Edinburgh and Sheffield to learn more about how to effectively lobby your MP on digital rights matters, with current especial reference of course to the DEB, graduated response, disonnection etc.

This is a great and timely initiative and if you have any interest in learning how to actually participate in democracy and make your voice count, come along!! It's free!

I will be attending the Edinburgh one, and am happy to talk to people about what I've seen of the Lords debates on the amendments thus far - I'll also, time willing, be blogging in detail on this this week or next as we approach the end of the committee Lords stage. Hugh Hancock of Strange Co machinima fame will also be there and of course Jim Killock, director of ORG. (Will we have a Technollama, Andres??)

Details and sign up form here.

"The Open Rights Group wants to help you get your voice heard: by helping you to talk to your MP. Booking an appointment with your MP and saying what you think is easier than you might think.

At this event you will:

  • Gain the confidence to talk and write to your MP
  • Rehearse talking to your MP one on one
  • Find out what MPs will ask you
  • Learn how to write to your MP and get a response
  • Meet other people campaigning against disconnection without trial in the Digital Economy Bill

Talking to your MP is the most effective way to make sure Parliament knows how unpopular and bad disconnection without trial really would be.

In these short sessions, you can try out talking to your ‘MP’ or watch someone else having a go, and learn how to get your points across in a way that an MP will understand."

Friday, January 15, 2010

Quote of the debate so far

Lord Lucas, Jan 12th, Committee Stage day 2

"Lord Lucas: I agree with what the noble Lord, Lord Mitchell, has just said. We have to be careful about setting out to criminalise, as he says, a large proportion of our population, particularly when it involves putting them not in the hands of the criminal law with all the safeguards, care and rationality that involves, but in the hands of firms of solicitors who are out to make a

12 Jan 2010 : Column 423

buck from the process. None of these people are nice to deal with. Even where the majors have been involved in prosecutions-there are not many cases of that-they are relentless. It is not at all nice to be on the receiving end of one of their prosecutions. They can take a long time, cost a great deal of money and go on, with unspecified consequences, for a period of years. It is not like a parking fine or some simple, reasonable but reasonably painful financial consequence of wrong-doing. This is putting people into the civil justice system with civil levels of proof. We should be careful about doing that and the circumstances in which we do it."

The DEB amendments; 1 in a series..

You might wonder where I've been this time. Well, Pangloss is currently signed off work with a prolapsed disc. Yes it's Ok, it wsn't fun, but I'm getting better now, thanks. Anyway, one thing I plan to do for **fun** this week now I have time on my hands is sit down and have a look at the hundreds of DEB amendments. Yes I know; I'm that sad.

As a starter, it's important to remember not all the DEB is about disconnection of filesharers and neither are all the amendments.

One amendment Pangloss might draw attention to in particular has had quite a warm reception in parts of the press, odd perhaps given recent Google/Murdoch fracas (or not so odd?:). The Telegraph note

Lord Lucas, a Conservative peer, has tabled several amendments to the Digital Economy Bill

that would settle a number of copyright and electronic publishing arguments once and for all.

The one that’s been catching the headlines is immunity for search engines from prosecution under copyright laws as they go about their normal business of searching the web. Every provider of a publicly-accessible website shall be presumed to give a standing and non-exclusive licence to search engines to copy their content for the purposes of searching. A machine-readable file (robots.txt, for example) can be used to demonstrate that such a licence is not granted, should the owners of the website prefer not to be indexed.

Brilliant. Immediately all of the rows and back-and-forth between ill-advised newspapers and publishers is given a clear legal footing. It would be legal to be a search engine, and you can tell them to keep out if you wish. A few sentences saves millions of pounds of court costs and clears the headaches of everyone involved."


while the Guardian adds

" it would, for example, give Google legal immunity with which to index News Corp content, settling that thorny topic once and for all. But all would not be lost for publishers who want to retain control. Lucas's amendment does make provision…

The presumption (of having an automatic license) may be rebutted by explicit evidence that such a licence was not granted. Such explicit evidence shall be found only in the form of statements in a machine-readable file to be placed on the website and accessible to providers of search engine services.

In other words, Google would be free to copy everything - but a publisher blocking search spiders with a robots.txt file would be taken as withholding that right. An explicit "fair use" provision, which Google often cites against copyright-abuse claims, does not exist in UK law."

Interesting stuff?

NOTE: fun summary of this week's first debate at the Register

Oink site owner cleared of conspiracy to defraud

Well I guess we didn't see that coming.

"A man who ran a music-sharing website with almost 200,000 members has been found not guilty of conspiracy to defraud at Teesside Crown Court.

Alan Ellis, 26, was the first person in the UK to be prosecuted for illegal file-sharing...

Oink facilitated the download of 21 million music files...During the trial, which lasted seven days, Teesside Crown Court heard that users were required to make a donation to be able to invite friends to join the site.e jury was also told that Mr Ellis received $18,000 (£11,000) a month in donations from people using his website."

Well this is interesting. Is this the UK's own homegrown Pirate Bay case only coming out in reverse, or is it merely a blip from a perverse jury probably stuffed full of students and ne'er do wells? We may not find out for some time..

Some very strange elements here. Users had to make "donations" - yet they, who were looking for free music, donated £11,000 a month? How good was this site? An earlier Beeb story tells us "The court heard that membership to Oink was free, but by invitation only, and anyone wishing to propose a friend had to make a five dollar payment." Er that's an entry fee NOT a donation..

Te money was alleged to be used to buy a new server. You can buy a decent server for about £1000 or less these days..not £11K per month. The site was designed not to "defraud" but to allow the owner to practice his skills to bcome employable, he claimed. Yet "the website was developed from a free template, which had a torrent file-sharing facility included in it". In other words, it came as a kit. Not terribly skill enhancing? And this unemployed worker wannabe had $300,000 in his bank account when the police raided. All this rather points to the perverse jury theory.

Why did the CPS go for conspiracy to defraud anyway? Why not as in Sweden, a criminal copyright offence, since given the "donations" and profits, surely there is as much evidence of commercial trading in copyright infringement as with any normal geezer selling CDs off the back of a van? Did they decide not to take that approach because it was a torrent site not a hosting site? That would be my guess (although of course the Pirate Bay was a torrent site too) - it would be great if someone out there knows more.

Not a good week for the music industry altogether, as BIS back peddles on clause 17 of the DEB as well! Perhaps the most interesting sociological point here is to wonder why the jury came in with such a strange verdict. Has the music industry dug their own grave by making their enforcement tactics so alienating that juries will turn their back on overwhelming evidence of guilt? Hubris, ate??

Tuesday, January 05, 2010

The Google Toilet

This is getting a lot of pass-round in ye olde blogosphere. As with some of the vids I post here about filesharing, it makes some good points evocatively but I do not endorse the overall conclusion for one simple (or maybe not so simple) reason; even if you effectively feel you have to use Google (and there are rivals, especially in the non search categories of services) you can delete your Google cookies. But - another fun one to show students!

Monday, January 04, 2010

Tell it to the Marines: 2010, same news at 10

And so as it ended, it begins.. (obvious reference to Dr Who's regeneration deleted , sadly..)

The Beeb reports a pre emptive attempt by Bono to get headlines when as we all know this the time of year with No News.

""The immutable laws of bandwidth tell us we're just a few years away from being able to download an entire season of '24' in 24 seconds," he wrote.

"A decade's worth of music file-sharing and swiping has made clear that the people it hurts are the creators...the people this reverse Robin Hooding benefits are rich service providers, whose swollen profits perfectly mirror the lost receipts of the music business."


Um yeh. Would that be the same rich ISPs who are going to have to pay an estimated £500m to prop up the failure to innovate of an entirely other industry?

As to:
In a move that drew significant criticism, Bono went on to suggest that the feasibility of tracking down file-sharers had already been proven.

"We know from America's noble effort to stop child pornography, not to mention China's ignoble effort to suppress online dissent, that it's perfectly possible to track content," he said."

...I really feel any comment is redundant.


Oh and happy new year!!

Wednesday, December 09, 2009

Facebook Privacy:: Fact or theory?

Xmas comes early for privacy advocates?!

The Register reports

"Facebook has ordered its 350 million users to sort out their privacy settings right now, before it throws the switch on its revamped security system.

The social networker farmer in chief Mark Zuckerberg, told its users last week that, "We're adding something that many of you have asked for — the ability to control who sees each individual piece of content you create or upload." He also promised a simplified privacy page.

..In today's warning, coinciding with the actual launch of the tools, Facebook promised its new Publisher Privacy Control would allow users to set a privacy setting for each piece on content they create.

The firm is also removing its "regional networks", in favour of four basic control settings: friends, friends of friends, everyone and customised.

This will be allied with an "easy, intuitive and accessible" privacy settings page."


Well, hmm, let's see - but Blogzilla. looks like we may finally have to rewrite that FB paper!

Of course in other news today, Sophos, who discovered 2 years ago that most FB users would revel their most private details to cartoon frog, found that 2 years on, relicating the study in Australia, ... well, nothing had really changed.

"The survey found that 46% of users in a fictional 21 year old's age group accepted the offered friendship, while 41% of a fictional 56 year old's peers did.

On Facebook once someone has been accepted as your 'friend' they can see more information about you, but you can still choose to hide information from those friends or limit it to specific groups amongst your online friends....

"Both groups were very liberal with their email addresses and with their birthdays," said Sophos head of technology in Asia Pacific Paul Ducklin. "This is worrying because these details make an excellent starting point for scammers and social engineers.""

Ah well, you can't have everything!



Something Different for the Midweek: Google and Criminal Liability

Yesterday Pangloss was very happy to have a guest lecture for her Internet Law class given by Trevor Callaghan, Managing Product Counsel of Google UK. Trev gave a hilarious lecture on the law relating to search and copyright, which conbined legal insight, practical tips, and social responsibility with some Glasgow humour that would have put Armando Iannuci of The Thick Of It fame to shame (albeit with (slightly) less swearing). I enjoyed it, lots, and i think the students did too.

Anyway, this all reminded me that actually quite a few things are going on I should be talking about as well as (or perhaps even in combination with) the Digital Economy Bill. One of these, which has received suprisingly little press (even wonderful OUT-LAW hasn't mentioned it since February) , is that right now, four Google executives - including Privacy CEO Peter Fleischer- are on trial - yes, criminal trial - in Italy, in relation to a short phonecam video made by some school children of a bullying incident involving a child with learning disabilities, and then posted on Google Video.

In Italy, it appears that libel and , possibly, infringement of privacy laws, can be a matter of criminal as well as civil law. Google took down the video on notice within a day of receiving an official complaint from a consumer group, although the video had been online for about 2 months before that. Italian prosecutors investigated for two years but then decided to proceed.

For Pangloss this seems a not very difficult case that ought to be easily decided under the EC E-Commerce Directive safe harbours in Art 14 and 15, as often discused in this blog. If these aren't implemented into Italian law, then it would seem Italy must be in breach of EC law itself. Google was clearly a host here, and Art 14 provides that such sites are protected from criminal liability for the activity of users of the service, unless they receive actual notice, and fail to take down expediently. This is a case about criminal liability so there is no need even to move to the second branch of Art 14 (which is far more controversial) and discuss whether Google should have known - ie had constructive knowledge - of the activity or content. Injunctions would have been relevant, despite the safe harbours, but these are not the issue as Google already took down straightaway on notice.

So why on earth is this case coming to trial? Pangloss is perplexed. One possibility as noted above is that simply that Italy's domestic law is in breach of EC law (in which case Google should have a Francovich claim for damages against the Italian government, though that may not be much comfort to the men awaiting trial.) Another possibility, though rather an unlikely one, is that the Italian prosecutors have confused the activities of Google as a search engine, with Google as a host. The ECD does not give search engines , or hyperlinkers , a special immunity from liability as it does hosts and "mere conduits" : though a number of EC countries have in fact decidd to extend such an immunity, either under Art 12 or 14, or both. However in this case case it seems pretty clear Google was a host not a hyperlinker in terms of liability. So, what on earth quid iuris?

Another remote possibility is that the suggestion is that Google as a provider of free services does not gain the benefit of the Art 14 safe harbour. This uncertainty has been around for a long time, since only providers of "information society services"(ISSPs) get the benefit of Arts 12-15 and that definition is of an online service "normally provided for remuneration" (see recitals 17 and 18). Yet majority opinion has long felt that this particular point is no obstacle to the likes of Google (or Facebook, or Hotmail?) claiming safe harbours.

First, while renumeration might not come directly from users, it certainly does come in the form of the adverts Google place alongside its services. Second, search services are certainly something that would "normally" be paid for if they weren't, happily, often provided for free: they are of huge commercial value . Thirdly, it seems a strange policy in terms of public interest which would discriminate against services of great public value provided for free, in favour of those given purely for direct consideration.

There is no clear ECJ ruling on this yet but there is likely to be soon: in the upcoming Adwords conjoined referrals to the ECJ (Google France v Louis Vuitton, etc), the Advocate-General has already given a preliminary opinion in which he found:
"There is nothing in the wording of the definition of information society services to exclude its application to the provision of hyperlinks and search engines, that is to say, to Google’s search engine and AdWords. The element ‘normally provided for remuneration’ may raise some doubts as regards Google’s search engine, but, as has been pointed out, the search engine is provided free of charge in the expectation of remuneration under AdWords. (68) Since both services are also provided ‘at a distance, by electronic means and at the individual request of the recipient of services’, they fulfil all the requirements necessary to be regarded as information society services."(para 131)
And for what it is worth, a roughly similar finding was reached, albeit obiter and with an admission of some possibility of doubt , in the recent English libel case of Metropolitan v Designtechnica, where Eady J opined: "it would appear on balance that the provisions of the 2002 Regulations [defining an ISSP] are apt to cover those providing search engine services." (para 84)

So what does that leave? Well there is perhaps a clue in the New York Times account.

"Google and the prosecutors agree the video was uploaded Sept. 8 and removed Nov. 7, 2006. The prosecutors presented evidence showing that in early October, a month before the video’s removal, there were comments posted saying that it should be taken down. One of those messages read, “This is shameful! This should be taken down immediately.”

“It is reasonable to imagine that comments like this were followed by requests by these same people that the video be removed,” the prosecutors wrote in the document they presented to the judge."

So when are such shocked responses or "requests", "actual notice" as required by Art 14? Do comments on a video hosting site cut it, as opposed to an official request for takedown? To put it another way: does a hosting service have a duty to read comments about videos posted by, and probably of interest only to, their creators and viewers? Surely not.

Compare the situation to the original world Art 14 was designed to deal with, that of web 1.0. If Demon Internet hosted a basic site for (let's say) Anglers Magazine, and it contained a chatroom where libellous remarks were made about particular fly-fishers, would Demon be expected to monitor that chatroom for explicit or implied requests to take down those comments? Again, surely not. It would be up to the aggrieved angler to send his request for take down direct to Demon. The whole point of Art 14 was to reassure host providers they had no need to monitor the activities of those to whom they provided hosting services. Not only would this involve huge expenditure of effort and cost, but it might also be privacy invasive and chilling of free speech. Art 15 states this absolutely explicitly:

"Member States shall not impose a general obligation on providers, when providing the services covered by Articles 12, 13 and 14, to monitor the information which they transmit or store, nor a general obligation actively to seek facts or circumstances indicating illegal activity."

Still another way to put this is to ask , what are the minimum requirements for notice? This is a perennial problem. The US DMCA largely gets it right, with a statutory form which requires a complainant to give clear details including their own address and status as rightsholder, and provides sanctions for false accusations. The ECD, being a EC wide framework, is hopelessly vague. The UK's own regs help a little but not much - there is no DMCA type statutory notice but Reg 22 of our E Commerce Regulations does state that

"In determining whether a service provider has actual knowledge ... a court shall take into account all matters which appear to it in the particular circumstances to be relevant [including] whether a service provider has received a notice through a means of contact made available in accordance with regulation 6(1)(c)" - ie, their official contact email address .

This stuff should be simple law (compared at least to issues like eBay and Louis Vuitton, Google and AdWords) but even it is not. The ECD deperately needs revised to get a few simple things right and harmonised across Europe: what form should "actual notice" take; what does "expediently" mean; what is constructive notice; when, if ever, can an obligation to filter proactively be placed on ISSPs; what immunities should search engines (and hyperlinkers and aggregators) have. Pangloss loves this stuff but even she is tired of writing the same stuff over and over again. It is time to review the ECD.

PS and in the interest of public policy but with just a hint of minx-itude, I have helped draft a proposed amendment to the Digital Economy Bill for ORG which would aim to clarify some of these very matters, at least for the UK. See you in the House of Lords! :-)



Friday, December 04, 2009

Predictions 2010

The SCl Journal is as usual publishing pithy predictions for next year from the great, good and garrulous in IT Law (though they don't seem to have asked me this year - sob!

The best so far of course is from the wonderful Jeremy Phillips:

From Jeremy Phillips, IP Consultant, Olswang LLP

* 'Three strikes' proposals, even if enacted, will be shown to be feeble, cosmetic inconveniences. What's more, downloaders will assert they have a right to two free infringements.
* The Ministry responsible for IP/IT will change its name, its role and its Minister.
* The aggregated figure for victims of Data Protection Act data leak will exceed the population of the UK.
* The government will proclaim that innovation is ‘key’ to the country's well-being while further restricting its exploitation and taxing it to death.
* Some people will continue to believe in Santa Claus, a flat Earth and the Manchester Manifesto.

I particularly love the second point. One wonders if it's like the professor for DEfense against the dark Arts in each harry Potter novel - each government reshuffle, a new incumbent and name for the department required!

Less funy, but equally to point and often overlooked as we focus on three strikes, data breaches and e-commerce:

"From Jaron Lewis, Partner, Reynolds Porter Chamberlain LLP

2010 will be the year that our pre-internet libel laws are kicked into shape. Legislation is expected to prevent publishers being sued over archived web content. We will also see a consensus forming over the introduction of more streamlined - and cheaper - procedures for resolving libel disputes. Finally, our libel judges will continue to make clear that those providing the web infrastructure - such as ISPs and search engines - should not be liable for defamatory content, even when they are on notice of a complaint."

Having taught Internet libel law, substantive and jurisdictional for almost 20 years now, I really hope we are going to see real change here on the UK's antiquated libel magnet laws - Metropolitan v Google, which Pangloss really should have found time to blog properly, isalso an especially heartening and sensible decision. It is just a shame the current review of the single publication rule (still open till Dec 16th) is not looking at place as well as time.

Finally although not a prediction or even legal I must leave you with my favourite quote of the week for everyone out there who spends their life glued to a keyboard:

from Ben Goldacre on Twitter:"if anyone needs me i'm flying to america tonight so i can kill everyone involved in writing and marketing microsoft word."








Tuesday, December 01, 2009

The Death of Public Wi fi: Grauniad

I decided to write up a user friendly version of the wi fi story for the Grauniad, as you can see here. Many thanks to Francis Davey, inter alia counsel for Theyworkforyou.com, who pointed out the difficulties of the word "agreement" in terms of defining a subscriber and an ISP in the Digital Economy Bill.

Saturday, November 28, 2009

ZDNet, Wi Fi and the Digital Economy Bill

ZDNet is reporting , rather relevantly to Current Times, that a pub owner running an open wi fi hotspot has been "fined £8,000" for infringing downloads by its customers. The information was provided by the Cloud, who provided the hot spot capability (and who also, incidentally, do the same for McDonalds, my example for wi fi liability of a few days back on this blog.)

"Graham Cove told ZDNet UK on Friday he believes the case to be the first of its kind in the UK. However, he would not identify the pub concerned, because its owner — a pubco that is a client of The Cloud's — had not yet given their permission for the case to be publicised."

ZDNet asked me to comment on the story which I was happy to do, but unfortunately one major error has crept through the phone call process. EDIT - corrected! Thank you! Story also now specifies it was a civil case.

So what about the pub story? It sounds very odd. Basically, we need more details here. First it doesn't sound on first glance like a case where criminal copyright would be applicable. So that probably isn't a "fine", but damages . Even more likely is that the case settled rather than going to final judgment (in which case, wouldn't it be a novel enough decision to have an opinion, and be up on BAILII? I can't see it there). In that case the £8000 is just an estimate of damages both parties were willing to settle for, and, it should be stressed, not a legal precedent.

As for the crucial responsibility angle, one wonders if the issue was mainly one of proof. After all, if a publican was alleged to be regularly downloading without permission, and the defense was that wi fi users were using his IP address ("it wasnae me" as we say in Glasgow), and the wi fi was open, then there was no attributed log of downloads, and thus no proof of this beyond that mere assertion. In strict law, even in a civil case where the standard of proof was the balance of probabilities, the onus of proof should be on the plaintiffs ie the rightsholders. But in a settlement situation, I can conceivably see that the publican might decide to give up and settle without hard proof to back up his case, and cut his losses and the chance of losing the case and paying both side's costs.

The important point is if that if this is a settlement, that doesn't at alll translate into a theory of secondary liability for downloaders suing your open network, still less a legal precedent. If anyone has further details, I'd love to hear them.

I may as well now go on and quote the rest of myself :) (a bit odd I know)

"However, she said the measures that would be brought in under the Digital Economy Bill — measures that could include disconnection of the account holder — would not apply because the business could be classified as a public communications service provider, which would make it exempt. According to the terms of the bill, only "subscribers" can be targeted with sanctions**.

[** note for legally minded Pangloss readers: this is because the DigiEc Bill cl 16defines "subscribers" as excluding "communications providers", which can be traced back via the Communications Act 2003 to include providers of electronic communications services or networks. The pub hotspot would fall into that class, probably :-) ]

According to legal advice sent to The Cloud by the law firm Faegre & Benson on 17 August, "Wi-Fi hotspots in public and enterprise environments providing access to the internet to members of the public, free or paid, are public communications services".

A public communications service provider must, under the terms of the Data Retention Regulations that came into force in the UK in April of this year, retain records for 12 months on communications that have taken place over their network. This data includes user IDs, the times and dates of access, and the online destinations that were being accessed. The content of the communications cannot be retained without the user's permission, due to data-protection laws.

However, there is a get-out clause in the Data Retention Regulations, in that no public communications service provider has to keep such records unless they are notified by the government that they are required to do so.

According to Edwards, this is because "only the big six ISPs have the facilities to comply, and because the government agreed [in its legislation] to repay some of the costs [of retaining [[and accessing - Pangloss adds]] such records]". She noted that this clause might itself be non-compliant with the EU data-retention laws that were transposed into UK law in April.

Edwards pointed out that, even if the sanctions proposed in the Digital Economy Bill come into force, "no-one will know who [the downloader] was, because the IP address that will show up [upon investigation] will be of the hotspot". She added that the rights holder seeking infringers of their copyright would probably not know that the IP address in question was not that of a subscriber.

It would then be up to the hotspot operator to point out that they were not the end user downloading copyrighted material. "But when would they get to say that? Maybe straightaway, maybe not until after disconnection — it's not currently clear," Edwards said."

Downfall Meets Peer review