Showing posts with label berr. Show all posts
Showing posts with label berr. Show all posts

Monday, January 19, 2009

BERR, the music industry and file sharing: also stupid porn law ideas

Sorry for long silence. A bit of a catch up here of some recent very important stories..

Ray Corrigan helpfully reminds me that the Department for Business Enterprise & Regulatory Reform has published the responses to their P2P filesharing consultation.

"None of the options highlighted in the consultation won widespread support. Rather there was a marked polarisation of views between the rights holder community and consumers and the ISPs over what action should be taken.

A number of key issues were identified by respondents including copyright protection, protections afforded under eCommerce legislation and the impact on the wider economy. Consumers (individuals and consumer organisations) in particular highlighted concerns over data protection and privacy. The role of technology was addressed by most respondents, however there were conflicting views as to whether it could offer all or part of any solution. For almost all the options, questions were raised as to their legality under the existing legal frameworks and again, views varied.

There was a degree of consensus that any solution must involve the provision of new legal sources of attractive content and the need for education on the importance of copyright in the wider economy.

A number of replies suggested alternative models to those options proposed. Copies of all non-confidential responses received have been placed on the BERR website."



Meanwhile documents leaked to the Financial Times apparently show that BERR is planning in the wake of this to introduce an "ISP tax scheme":

"Ministers intend to pass regulations on internet piracy requiring service providers to tell customers they suspect of illegally downloading films and music that they are breaking the law, says the draft report by Lord Carter.

It would also make them collect data on serious and repeated infringers of copyright law, which would then be made available to music companies or other rights-holders who can produce a court order for them to be handed over.

With the creation of a body called the Rights Agency to be paid for by a small levy from the internet service providers and rights-holding organisations, these measures would form the spine of a new code of conduct for the internet industry. The draft report says the code would be overseen by Ofcom, the broadcasting regulator, according to people who have read it.

The guiding philosophy of the report is that the internet and music industries have failed to sort out the problems of illegal downloading between them, and the government sees this as its preferred solution."



As others have commented, that last sentence is posibly accurate :-)

Until we get details it doesn't seem worth commenting much on this. First impression is that it is certainly preferable to either the compulsory filtering of allegedly copyright content out, or the "3 strikes and you're out" type scheme we have feared since March 2008. On the other hand the privacy implications of this scheme are still not good.

Why for heavens sake if we are going to start imposing taxes , can't we simply do the sane thing and install a tax/levy system on broadband use, which would pay for all music to be downloaded "free"? (A: because the music industry don't want it that way. Well, hello.)

According to Becky at ORG,

"The official government response to the consultation will be published as part of the interim Digital Britain report, which is expected at the end of this month."

In other news, DRM is dead. Well for music. I mean if iTunes has decided it isn't worth using, who the hell else is going to?

In still other news, turning from music IP to Net porn, Burnham talks Bollocks. Well, so no change there. I won't address this one in detail here either, because I just have in the (very heavily) revised version of my chapter on pornography, censorship and the Internet which will be appearing in the 3rd edition of Edwards and Waelde Law and the Internet, hopefully soon..

(This bit isn't so bad though. According to the Telegraph "
Mr Burnham also wants new industry-wide “take down times”. This means that if websites such as YouTube or Facebook are alerted to offensive or harmful content they will have to remove it within a specified time once it is brought to their attention." The vague definition of "expedient" in the E Commerce Directive Art 14 has long been unhelpful to both hosts and ISPs, so Pangloss approves of this as long as it is practicable.)

Here's a taster of my views , in the new section on the global rise in compulsory top-down invisible Internet content filtering..

"
Effectiveness. Web filtering can be easily avoided by those who really want to, and any government wishing to install it must consider the impact of this on effectiveness. Depending on how filtering is achieved, blocking can often be evaded by a proscribed site changing its URL, or merely its underlying IP address. Users in turn can simply use a foreign proxy server site to anonymise their surfing destinations[1]. Steps can be taken to inhibit avoidance, but they are likely to result in serious over-blocking – for example, the EFA paper on the Australian scheme notes that a serious web filtering system would also need to block the Google cache, the Way Back Machine[2], and numerous other Internet archive sites where content is mirrored. It can be argued that child porn web filtering systems merely inhibit the ignorant or lazy or those who stumble on illegal material by accident[3], and do not stop for a minute those who are ostensibly the real targets of the efforts involved – serious paedophiles who may go on to commit actual abuse.

A key anti-avoidance issue is whether filtering is only to be imposed on websites or on other types of digital content, such as Internet newsgroups[4], P2P filesharing systems, instant messaging (IM) and email, as well as mobile phone traffic. As we have discussed above, illegal content is now known to be more commonly swapped in encrypted P2P “darknets” than on the open Web, which begs the question, why bother to filter the Web at all? In response to such criticisms, the Australians have claimed they intend to extend their reach to cover material traded via the P2P protocol BitTorrent and the EC has instructed research into P2P content blocking[5]. Such research is still likely to prove useless in the face of modern evolving encrypted P2P systems. At present such systems (eg Tor and Freenet) are rarely used by the average EU or US citizen because they are user-unfriendly and slow – but in go-ahead Japan, the leading P2P systems, enabled by their fast next generation consumer broadband networks, are both encrypted and consumer-popular. It will not be long before such systems make the leap to Europe and the US as home broadband networks are upgraded here too. At that point only the most foolish pedophile would attempt to access child porn using the open Web.

A slightly easier target is mobile content. In Europe, many mobile operators already provide filtering software and filtered content for children, and UK operators since 2004 have voluntarily signed up to Ofcom-brokered codes of conduct requiring filtering of content to under 18s and labeling of over 18 content on their servers[6]. Reliably imposing these restrictions on children given cheap anonymous pay as you go phones, may however be a harder than foreseen task.

Resources. Even if we only look at filtering the Web, realistically, classifying the
ever-expanding billions of Internet pages manually as “illegal”, “inappropriate”
or whatever will cost billions of dollars and be an
ever moving target
[7].This has not however stopped the Culture Minister Andy
Burnham recently suggesting exactly this for the UK
[8].)

The IWF avoids this problem by being complaint-driven - which
means its list is,of course, very partial
[9] and thus of questionable success. In reality,
blocklists in commercial filters are
usually generated partly by automated and partly
by manual means, which as the ONI note, means they are
inevitably prone to both
over- and under-blocking.



[2] Interestingly, the Register has also reported that the IWF had added images on the Wayback Machine to its block list, which had lead to some ISPs banning the entire 85 million web page archive. Details were not given as to what images had been banned and ISPs involved gave 404 “page not found errors”. See “IWF confirms Wayback machine porn blacklisting” ,The Register, 14 January 2009.

[3] Mike Galvin of BT, one of the creators of the IWF “cleanfeed” system, admitted in an interview with the Guardian on 26 May 2005, that Cleanfeed “won’t stop the hardened pedophile” and went on to say that its main aim was to stop accidental access by users following links such as those in spam emails.

[4] Internet newsgroups have largely fallen out of common use but are still extensively used for porn trafficking: see January 2009 report of USA conviction of 7 paedophiles following the bust of a well organised network that used Internet newgroups to distribute illegal items to its members over a two year period. See “Child porn in the age of teenage “sexting” “, The Register, 16 January 2009.

[7] The EFA pages (supra n XX) estimate that even if a 1000 people were employed full time for a year , they would fail to categorise more than 0.1% of all the pages on the Web , and at the end of that year the list would be hopelessly out of date.

[8] See BBC report, 27 December 2008 , at http://news.bbc.co.uk/1/hi/uk/7800846.stm .

[9] Testing of the IWF Cleanfeed system for use in New Zealand found that their list contains probably only only about 10-15% of offending websites (statistic cited in EFA pages, op cit supra n XX)




Thursday, July 24, 2008

3 Strikes and You're Um Crawling to a Halt??

Pangloss hates to seem so one track minded on this, but well, things just keep happening. In this case, potentially pretty bad things.

After months of rumours, behind the scene talks, stealth tactics at the European Parliament (maybe), and denials that the UK and indeed, Carphone Warehouse would ever ever have anything to do with nasty French stuff like 3 strikes and you're out, today we have two somewhat interesting developments: a voluntary, and so far, rather worryingly vague, Memorandum of Understanding between the music industry, BERR and the 6 leading UK ISPs which between them account for 90% of UK traffic : BT, Tiscali, Virgin ("absolutely no possibility of disconnection"), Orange, BSkyB and oh suprise, Carphone Warehouse :)

Plus a consultation on what primary legislation should be brought in by BERR as a "backstop": the idea being presumably that if the other 10% of ISPs don't fall into line with the MoU - or if some of the above 6 pull out depending on how bad the PR fall out is and what the MoU actually compells them to do - they can then all be compelled still to "do something" about file sharing.

So what does the MoU say? Well basically for 3 months, the industry aided by the 6 ISPs involved are going to send out letters to suspected filesharers. Lots and lots of letters. 80,000 or so over 12 weeks. But hang on. If 67% of the UK have admitted to filesharing - even only once - that's 35 million letters that need sending out. Quite a bit of scaling up there to be done after the pilot. Eco-wise let's hope they're all emails:)

But letters is only stage 1 (after all the BPI could have sent them themselves, tho this way they do aparently get ISPs to pay for half of them.) Stage 2 is what do you do next, when presumably they compare them all on a big spreadsheet, and find that eg Mr A of Aberystwyth got 220 letters from 5 ISPs? What gets done to persuade Mr A to abandon his bad ways if the shock of 220 letters isn't enough?

Here the MoU gets vaguer. There will be discussion of "technical measures", for "repeat" or "the worst" offenders. This seems to involves three possible sanctions:
  • traffic management (slowing the offender's email til it's too slow to downlaod an MP3);
  • filtering out tagged-as-copyright traffic to that offender's IP address;
  • and possibly, maybe, not quite stated-as-such, disconnection??

Pangloss doesn't want to restate the (very tired and flat) wheel but this raises all the same problems I've gone though before plus more.

What will happen if the repeat offender is a child and the whole household loses access or has it slowed to unacceptable levels? "Traffic slowing" to an accountholder sounds better than disconnection, but I cannot see, having asked some tech experts, how it is substantially less damaging.

This is about music remember, not, so far, films. Supposed Little Johnny downloads several hundred tracks, and as a result the account to their home is restricted to a crawl. (It's likely to happen automatically after the account's bandwidth limit is reached.) If you can't manage to get a fast enough connection to download an MP3, or even 12 constituting an album, can Johnny still manage to download his course reading materials from the uni or school website?? can Mum run her small business? can Dad tele commute? can Sis run her small business on eBay? can ma and pa even manage to download programmes from iViewer, their legal right as a BBC license payer! It seems unlikely.

What if the infringer is really someone using your wi fi , or visiting your house, or a crook who's zombified your machine unbeknownst to you?

What if the music people have just got the IP address or look up to real life ID wrong? (well we should at least get to see the correct target hit rate - or the failure`rate - over the next three months.

What if you're making fair use of coyright materials eg review, journalism, education?

All these crucial points of evidence and standard of proof and exceptions remain right now (a) vague and (b) aparently to be determined and adjudicated by industry and ISPs - not courts, judges or even policemen.

The good news here is that the regulator Ofcom is to be involved in drafting codes with industry relating to "evidence .. repeat offenders..incorrect allegations... routes of appeal" (p 48).

Good. Very good even. But it will still be the music industry as prosecutor and judge and the ISP as cop and enforcer, with the onus on the consumer to challenge after the sanction has already been ordered: Pangloss still feels deeply unhappy about all this.

There is a better alternative though, and it's option A3 in the BERR consulation. (p 35).

"Rights holders would identify infringing IP addresses and pass evidence and
details to a 3rd party body, which would take responsibility for assessing the evidence that file-sharing of copyright material had taken place. If the evidence was judged sufficiently robust, the body would then direct the ISP to take appropriate action or do so itself. Such a body would also be able to hear appeals and complaints from
consumers and may also be responsible for developing and administering or overseeing
any required code of practice for ISPs and rights holders."

This is a win win solution. It could meet ECHR and UK standards of fairness, due process and transparency, while still cutting down on actual piracy (as is right and proper, we should not forget this).

It might also be seen as slow and expensive and the industry will not like it. But it doesn't have to be.

We already have a model , in the IP world, of a speedy cheap and effective, yet legally rigorous tribunal for on line wrong doing. It's the ICANN UDR dispute resolution procedure for dealing with cybersquatters - people who register domain names in apparent disregard of the rights of trademark holders. It works, it's seen 1000s of cases over a number of years and broadly industry - and the IP industry - has found it effective and satisfactory. In previous work for the EU, myself and my colleague Caroline Wilson held up the UDRP as a possible model for resolution of online consumer-related disputes. It can involve lawyers or technologists or even musicians so long as they are trained as arbiters who actually understand the relevant law, technology and business. It need not have the kind of time and cost constraints of the courts. Cases could mainly be conducted online, with electronic written pleadings, again already a tried and tested standard approach in the UDRP.

It could make the UK look like a world leader in dealing with the consumer piracy problem, as opposed to the freakshow of Europe.

What other alternatives does BERR suggest?
A1 suggests that ISPs be required to automatically reveal the personal identity of an alleged filesharer identified by IP address to music industry, on demand, with no need to go to court.

Currently ISPs refuse to do this because it would be breach of data protection law and also a breach of confidentiality to custoner without court order. It would, one imagines, be disastrous for ISP customer relations, but as US already has it in DMCA, it is likely to appeal to BERR as already working.

The problem is really how far this can be used to invade personal provacy and make groundless threats (as in so-called cyber-slapp libel litigation.) People are however extremely touchy about personal data revelation without consent right now, post HMRC. so Panlgoss suspects this one is likely to go down like a lead balloon.

A4, finally, (no there is no A2 - well not really) suggests that if we are all very very bad boys indeed, then ISps will be asked _ sorry ordered - to install filtering. THis would probably mean that the rightsholder would say "here is the list of tracks we hold cooyright in" and if Mr A in Aberystwth was detected downloading or uploading one of them, it would be filtered out (and he would no doubt get a letter too).

Secueity and technical experts say this is so unlikely to work correctly across all traffic, all users and all ISps, that it's like believing in fairies. How do you tell a Lily Allen track that's been illegally copied from a P2P site from one that's been legally downloaded as part of a BBC TV show from iViewer or one that's freely available on MySpaced as apromo? It's the same track.

It is also a blank ticket for unrestricted censorship with no public accountability or transparency. It's the kind of tactic which has been declared an unconstututional interference with the free expression rights of adults repeatedly in the US courts. Filtering might - just - be aceptable to stamp out child porn downloading - but not in the context of music where many people have quite legitimate rights to listen to much oif the material.

This is more than a hammer to crack a nut - it's an imaginary hammer cracking all the fruit in the world as well as the nut. (Yeh maybe the metaphors are getting out of hand.)

Think about it. If you like A3, do write to BERR (or do anyway) - the consultation closes on October 30.

Write to Michael Klym / Adrian Brazier
Communications & Content Industries
Department for Business, Enterprise & Regulatory Reform
UG28-30
1 Victoria Street
London SW1H 0ET
Tel: 020 7215 4165 / 1295 Fax: 020 7215 5442
Email: mike.klym@berr.gsi.gov.uk / adrian.brazier@berr.gsi.gov.uk