Showing posts with label three strikes and you're out. Show all posts
Showing posts with label three strikes and you're out. Show all posts

Tuesday, December 01, 2009

The Death of Public Wi fi: Grauniad

I decided to write up a user friendly version of the wi fi story for the Grauniad, as you can see here. Many thanks to Francis Davey, inter alia counsel for Theyworkforyou.com, who pointed out the difficulties of the word "agreement" in terms of defining a subscriber and an ISP in the Digital Economy Bill.

Saturday, November 28, 2009

ZDNet, Wi Fi and the Digital Economy Bill

ZDNet is reporting , rather relevantly to Current Times, that a pub owner running an open wi fi hotspot has been "fined £8,000" for infringing downloads by its customers. The information was provided by the Cloud, who provided the hot spot capability (and who also, incidentally, do the same for McDonalds, my example for wi fi liability of a few days back on this blog.)

"Graham Cove told ZDNet UK on Friday he believes the case to be the first of its kind in the UK. However, he would not identify the pub concerned, because its owner — a pubco that is a client of The Cloud's — had not yet given their permission for the case to be publicised."

ZDNet asked me to comment on the story which I was happy to do, but unfortunately one major error has crept through the phone call process. EDIT - corrected! Thank you! Story also now specifies it was a civil case.

So what about the pub story? It sounds very odd. Basically, we need more details here. First it doesn't sound on first glance like a case where criminal copyright would be applicable. So that probably isn't a "fine", but damages . Even more likely is that the case settled rather than going to final judgment (in which case, wouldn't it be a novel enough decision to have an opinion, and be up on BAILII? I can't see it there). In that case the £8000 is just an estimate of damages both parties were willing to settle for, and, it should be stressed, not a legal precedent.

As for the crucial responsibility angle, one wonders if the issue was mainly one of proof. After all, if a publican was alleged to be regularly downloading without permission, and the defense was that wi fi users were using his IP address ("it wasnae me" as we say in Glasgow), and the wi fi was open, then there was no attributed log of downloads, and thus no proof of this beyond that mere assertion. In strict law, even in a civil case where the standard of proof was the balance of probabilities, the onus of proof should be on the plaintiffs ie the rightsholders. But in a settlement situation, I can conceivably see that the publican might decide to give up and settle without hard proof to back up his case, and cut his losses and the chance of losing the case and paying both side's costs.

The important point is if that if this is a settlement, that doesn't at alll translate into a theory of secondary liability for downloaders suing your open network, still less a legal precedent. If anyone has further details, I'd love to hear them.

I may as well now go on and quote the rest of myself :) (a bit odd I know)

"However, she said the measures that would be brought in under the Digital Economy Bill — measures that could include disconnection of the account holder — would not apply because the business could be classified as a public communications service provider, which would make it exempt. According to the terms of the bill, only "subscribers" can be targeted with sanctions**.

[** note for legally minded Pangloss readers: this is because the DigiEc Bill cl 16defines "subscribers" as excluding "communications providers", which can be traced back via the Communications Act 2003 to include providers of electronic communications services or networks. The pub hotspot would fall into that class, probably :-) ]

According to legal advice sent to The Cloud by the law firm Faegre & Benson on 17 August, "Wi-Fi hotspots in public and enterprise environments providing access to the internet to members of the public, free or paid, are public communications services".

A public communications service provider must, under the terms of the Data Retention Regulations that came into force in the UK in April of this year, retain records for 12 months on communications that have taken place over their network. This data includes user IDs, the times and dates of access, and the online destinations that were being accessed. The content of the communications cannot be retained without the user's permission, due to data-protection laws.

However, there is a get-out clause in the Data Retention Regulations, in that no public communications service provider has to keep such records unless they are notified by the government that they are required to do so.

According to Edwards, this is because "only the big six ISPs have the facilities to comply, and because the government agreed [in its legislation] to repay some of the costs [of retaining [[and accessing - Pangloss adds]] such records]". She noted that this clause might itself be non-compliant with the EU data-retention laws that were transposed into UK law in April.

Edwards pointed out that, even if the sanctions proposed in the Digital Economy Bill come into force, "no-one will know who [the downloader] was, because the IP address that will show up [upon investigation] will be of the hotspot". She added that the rights holder seeking infringers of their copyright would probably not know that the IP address in question was not that of a subscriber.

It would then be up to the hotspot operator to point out that they were not the end user downloading copyrighted material. "But when would they get to say that? Maybe straightaway, maybe not until after disconnection — it's not currently clear," Edwards said."

Monday, November 23, 2009

Mandy and Me: some thoughts on the Digital Economy Bill

So, once more unto the breach, dear friends, once more, where the breach is of copyright of course. First a brief summary of the terrain.

Clauses 4-17 of the Digital Economy Bill introduce an “initial obligations” regime for ISPs, whereby subscribers accused of filesharing by rightsholders will be sent warnings of alleged copyright infringements, or “strikes”, by their ISPs; and a “technical measures” phase, to be green-lit only after evidence has been amassed that warnings do not work (but see below), which will allow sufficiently warned offenders who still seem not to have seen the error of their ways to be disconnected from the Internet. Traffic slowing and banning of access to certain sites eg the Pirate Bay, may also become available measures.

The Bill also, almost as an after thought, adds a “Henry VIII” clause, which allows the relevant Secretary of State (currently Lord Mandelson of Mordor sorry BIS) to make new copyright law in any area of Parts 1 and 7 of the Copyright, Design and Patents Act 1988 (CDPA), by statutory instrument (SI) not primary legislation, if justified by speed of technological developments (even ones that haven’t happened yet – see proposed new s 302A of the CDPA.) So essentially, new and important copyright laws (not exclusively to do with filesharing – DRM, fair dealing and user rights might all be affected) are to be made under the public radar, and without proper Parliamentary scrutiny. anytime, anywhere (hereafter, the “Martini clause”).

There has been a great deal of coverage of these matters – see eg here and here – so I will only point out a few matters of detail which have struck me as particularly worrying, on top of my, er, well-ventilated previous concerns about the principle of a regime of “three strikes” at all. Most of the press attention has focused on the posited disconnection regime, since of course the sanction is so far reaching. But the warnings regime, which if the Bill passes is likely to be of more immediate concern, is also staggeringly poorly drafted, and this is where my focus will lie.

Accusations and evidence

In the outline scheme we have, warnings are to be sent to subscribers solely on the say so of rightsholders. All a rightsholder need do, as presently laid out, is provide an IP address and time stamp of an alleged infringer to an ISP, and say that “ it appears to [them that ] a subscriber .. has infringed the owner’s copyright”. There is no requirement this belief be objectively reasonable. Nor is there any apparent sanction for malicious, or even simply careless or reckless allegations. Recent experience with the RIAA and BPI has shown that allegations made after IP address tracking at P2P sites often turn out to be wrong and that collecting IP addresses from P2P honeypots is a non-trivial exercise ; so the issue of liability for erroneous accusations is an important one. Libel, malicious falsehood and data protection laws may offer remedies for the falsely accused; but there is no mention of such in the Bill itself (so far), nor of any reasonable duty of care. In other words, all the power is given to rightsholders, and none of the responsibility.

“Allowing infringement”

The Bill also makes it clear that an infringement may be notified by a rightsholder if the subscriber “allowed another person to use the service and that other person has infringed”. What does “allowed” mean here? It seems clear it is intended to cover the case where an Internet service is used to download by any member of the household other than the subscriber eg by partners, children, flatmates and lodgers – but what of casual visitors, friends of children? Should such persons be routinely policed by the subscriber fearful of liability, their rooms and computers searched, guests interrogated about their laptops and smartphones? What of Art 8 ECHR guarantees of privacy (which, let us remember, apply to children as well as adults, especially in their own bedrooms)? This is however only the start. What of the school or university or business which gives access to the Internet to hundreds or thousands of people? These warnings will come to roost at their doors, or rather their IP addresses. Will we then see IBM, Oxford University and Standard Life (just say) subsequently banned from the Internet? Is it really feasible to expect such organisations to stamp out downloading among all their employees or attendees (especially given most already do their best to try) or to spend the resources on internally trying to attribute the warnings to individual employees etc?

The end of unsecured wi fi?

A connected issue Pangloss has raised before relates to wi fi. At present it is a subscriber’s choice whether to secure their wireless network or not. Despite the public panic about paedophile use etc, many still think leaving wi fi unsecured is a public service (see on this Daithi McSithigh’s excellent piece). Yet one can easily see that leaving a network unsecured will count as “allowing” another’s infringement (and note the mandatory requirement to notify alleged infringers about how to protect their wi fi in proposed new s 124(5)(f)). What we see therefore is constructive prohibition of unsecured wi fi by the back door, for both consumers, corporations and the public sector (think of the impact on digital inclusion?); a decision of huge significance, which itself deserves a major public debate.

Appeals

Appeals against allegations untested in court and based on evidence solely of one interested party, are vital. At the warnings stage, a single appeal is to be allowed, it seems, not to a full tribunal but merely to a “named person” who will be an arbiter of some type, independent of ISPs and rights holders, though not of OFCOM. Such an appeal is also vital to ensuring that this process meets the requirement of a “fair and impartial” hearing, under what was Amendment 138 to the now finalised Telecoms Package. But no grounds are named in the Bill for an appeal against an erroneous warning to be allowed (there are some in relation to the better drafted and seperate appeal against disconnection) , nor is it stated what disposal the “person” could make if an error was found to have been made. Strangely, there is not even any requirement for alleged infringers to be told of this right of appeal, even though they are required to be given an enormous number of other pieces of educational “information”. This is wholly unsatisfactory, especially in relation to Amendment 138.

Notification of warning

Finally on this part, note (see proposed s 124A (7)) that warnings are to be deemed “notified” if sent to “the electronic or postal address” held by the ISP. As someone who never uses or checks their nominal ISP-provided email address (mailto:something@virgin.net I guess) , I would strongly suggest this be altered to “and” rather than “or”. Of course this would cost substantially more to the rightsholders and ISPs, so possibly some midway solution should be found where an ISP is required to obtain a current used email address from its subscribers.

ISP liability?

ISPs hold an unfortunate piggy-in-the-middle position in all this, forced by the threat of a fine of up to £250,000 to co-operate with rightsholders, even though they gain nothing from the process but overheads and customer ill-will. I have said elsewhere that I do not think it is just or sensible to enrol ISPs as “copyright cops”, but if they are to be, they need strong protection from liability, ideally in the form of an indemnity from the rightsholders who actually plan to benefit from this whole stramash. ISPs face potential liability for sending out libellous allegations to subscribers, and again for disconnecting the wrong person on erroneous evidence, and in breach of contract, However currently all ISPs get by way of protection is the feather-light provision that an indemnity may – not must – be provided by the Code to be drafted (again, no further details now– see new s 124J(4)(b). If I were an ISP, I’d be going out now to price a shedload of legal liability insurance J - or to check out moving offshore.

The disconnection regime

Finally (gentle reader wipes brow), the present government has made a great deal of the assertion that the “disconnection” stage is a “nuclear deterrent” option – only to be implemented if all else has failed. One wonders why, three months before an election the current incumbents are likely to lose, it was not then simply left to the discretion of the next government whether to bring forward legislation, once the evidence was in. As it stands, the “disconnection” regime is supposed to be brought in, it has been widely reported, if a review by OFCOM shows (to some very vague timetable) that the “warnings and passing of ID details” approach is not working. However if you go and look, what s 124H(1)(b) actually says is that the Secretary of State may order that the “technical measures” stage may go ahead as appropriate in view of such a report OR “any other consideration”. In other words, you can forget evidence based policy making if times are tough, and donations from rightsholders are needed? Again Pangloss’s suggestion would be for that last sub-clause to go.

I could go on – for most of a PhD length thesis I suspect – but enough is enough. This legislation bears every hallmark of having been drafted in haste on the back of an envelope on a wet Tuesday. It’s so like The Thick Of It. Only without the jokes .

Ps if you are unhappy with any of the above, can I politely direct you towards http://petitions.number10.gov.uk/dontdisconnectus/ ?

Friday, November 20, 2009

Incredulity

.. is my new middle name.

The Digital Economy Bill will be released at 7.30am tomorrow and will, it seems, include not only the anticipated disconnection provisions, but also a clause to allow the Secretary of State to basically change copyright law at will in order to stop filesharing, without primary legislation and without proper public debate and democratic oversight.

Why is this?

It's reflecting the fact that technology is changing very fast," said Timms. "The existing [method] is quite cumbersome. We might need something else in the future."

So clearly every time things happen fast and the law might struggle to keep up with them, in future, well we should just junk ordinary democratic safeguards before anyone notices, and bow instead to the partisan interests who pay lobbyists the most to shout the loudest? I expect to see similar legislation introduced shortly so that SIs can be whipped out and shoved through to deal with every fast moving situation from Afghanistan to floods in Essex, banker bonuses in December and tone deaf twins winning X-Factor. Hey, democratic debate is for wimps. SOOOO last millennium.

The best thing one could say about this legislation is that it is so outrageous, it is hard to believe it could seriously have been included in the Queen's Speech if the current sadpack on the way out thought there was a real chance of getting it through before the election.
I could say a great deal more about this but I won't : Instead I'll quote in full the funniest thing on the Internet today by novelist Nick Harkaway.

"News I Made Up Which Would Arguably Be Less Bad Than The Actual News. (2)

The Business Secretary, Lord Mandelson, today announced the creation of a new post to deal with the nuanced and difficult issue of copyright in the digital era. The Batshit Tsar will have a mandate to seek out anyone, anywhere who does anything using a computer and set them on fire.

Candidates for the post include Lord Duckhouse of Cobbham, Baroness Fishwicket (formerly BPI President Martin Cleep) and Brian Dubblehand-Pryce, Witchfinder General to the Court of James I & VIth, although there is some doubt over the availability of Mr Dubblehand-Pryce, as he is believed to have been dead for four hundred years.

Civil liberties campaigners have expressed alarm at the plan to make an offense of ‘downloading copyright material’. It is unclear how anyone will be able to use the internet ever again without committing a crime. A Department of Health spokesman said this would have the positive effect of getting people out in the open air.

“The Internet is a middle class, elitist phenomenon which is ruining our atomised society with a sense of community and cooperation,” he said. “This will put a stop to that, and to the development of the nascent public sphere which has given us so much trouble recently.”

The much-debated ‘three strikes’ policy will require a massive monitoring operation, trawling through the logs of anyone who uses a high-bandwidth connection to get large amounts of data to see if they are doing anything wrong. This sort of ‘fishing expedition’ is generally considered inadmissible in court, but since there will be no court for this sort of crime, the government is confident the issue will not arise.

“If we don’t do this,” the spokesman said, “we’ll almost certainly have an outbreak of witches by Christmas. There will be rains of frogs and giant panthers in Surrey, and even my tinfoil hat will not protect me from the brainwaves of Satan which are transmitted down the tubes of the Internet by demonic monkeys. The public has to be protected.”

Lorrie Fingerhubble, of the British Association of Giant Nocturnal Lizards, welcomed the news.

“I think this is absolutely splendid,” Ms Fingerhubble said enthusiastically from her secret undersea base in Regent’s Park. “It’s ideal for the government to be able to make arbitrary, draconian changes to the law which won’t work, will cost money, and will criminalise everyone. It’s a traditional approach to law in the UK: we make a rule no one can hope to obey and then prosecute people when we want to but not otherwise, creating a sense of lurking guilt and suspicion at all times!”

Asked whether the law might conceivably be misused to stifle democratic debate or to spy on people, the government spokesman said:

“Antelopes.”

Thursday, November 19, 2009

here we go, here we go..

The Digital Economy Bill is nigh:

"Digital economy bill

Ensuring a world-class digital future following the Digital Britain White Paper , published on 16 June 2009, setting out the Government's ambition to secure the UK's position as one of the world's leading digital knowledge economies and take forward a new, more active industrial policy to maximise the benefits from the digital revolution by:

  • delivering a universally available broadband in the UK by 2012 through a public fund, including funds released from the digital television switchover help scheme;
  • giving the sectoral regulator, Ofcom, two new duties: first, to promote investment in infrastructure and content alongside its duties to promote competition; and second, to carry out a full assessment of the UK's communications infrastructure every two years; to ensure that the UK has a first class and resilient communications infrastructure;
  • establishing the necessary enabling powers for new commissioning bodies providing strong multi media news in the Nations, regionally and locally and update the Channel 4 Corporation's remit. This would help create the environment for continued investment in, and creation of, high quality and innovative content, including necessary changes in relation to public service broadcasting;
  • ensuring that all national broadcast radio stations are digital from the end of 2015, by making changes to the existing radio licensing regime to enable digital coverage to be extended, encourage investment by the commercial sector, alongside the BBC, in new digital content, and revise the existing regulatory and multiplex licences;
  • creating a robust legal and regulatory framework to combat illegal file sharing and other forms of online copyright infringement and give Ofcom a specific new responsibility to significantly reduce this practice, including two specific obligations on Internet Service Providers: the notification of unlawful activity and, for alleged serial-infringers, collation of data to allow rights holders to obtain court orders to force the release of personal details, enabling legal action to be taken against them;
  • implementing the recommendations of the Byron Review published in June 2008, to put age ratings of computer games on a statutory footing for ratings of 12 years and above. This will be achieved through the adoption of a new and strengthened system of classification for boxed video games with a strong UK based statutory layer of regulation, ensuring protection for children."
Well, hmm. .. see the emboldened section.. and no third obligation, to disconnect repeat offenders? I very much doubt it's been dropped - but it's interesting not to see it there..

Pangloss sees no full text of the Bill via Google - if it is out there, could somone point me at it?

Now we wait to see which happens first, the end if the world by Holywood apocalypse or the end of New Labour by election :-)

Tuesday, March 25, 2008

3 Strikes And You're Out talk from LSE conference

Ray Corrigan, one of the finest IT law bloggers on the block, has, incredibly helpfully, while I frolicked for the long Easter weekend, written up an account of my talk on the dubious legality of the posited "3 strikes and you're out" legislation which, if passed, would mandate disconnection of repeat filesharers in the UK from the Internet.

See http://b2fxxx.blogspot.com/2008/03/3-strikes-copyright.html (thanks Ray.)

There is also a third ground of possible illegality of any proposed "notice and disconnection" regime, , other than its transgression of due process and lack of propartionality with respect to human rights. I did not have time to get to this at the conference so Ray has not mentioned it - namely that in order to prevent an "it wasnae me" defense (as we say in Glasgow), legislation might also require the mandating of secured wi-fi for every user who maintains a wireless router. Without such a rule, every uploader could theoreticaly claim it was not them but a wi-fi piggy-backer who committed the "offence".

Currently, users are usually advised to make their wi-fi network secure, and most ISP T & Cs theoretically demand it, but many prominent security experts, notably including Bruce Schneier, deliberately keep their networks open (while maintaining high quality virus checking ware and firewalls for the security of their own data). they do son mainly on the grounds that the mobile Internet ought to be a public resource for those in transit or in public areas, like toilets or water fountains. Breach of a term imposing secure wi-fi only by an ISP may currently be a breach of contract which might conceivably lead the particular ISP in question to , legitimately, disconnect the user; but it would not, as "3 strikes" would, mean that user is then sent to Internet Coventry by every ISP in the country.

Cutting off the choice of providing public wi-fi to the user on pain of banishment from the Internet, raises obvious issues itself of infringement of freedom of expression and association. Avaiability of unsecured wi-fi in public areas, say, in parks or on streets or at emergencies, is also arguably , as Schneier and co believe, a public good. Given that, it should be asked whether a proper balance is being maintained if we legislate to ban an asset of general public interest, in order to protect the legitimate property interests of one narrow commercial sector. It also raises the question of whether a wi-fi operator might be a "mere conduit" under the E-Commerce Directive, Art 12, and if so whether, in effect, strict liability for other people's misdeeds can be imposed on such operators without infringing EC law.

This point is dealt with in my powerpoint which I believe will be soon up on the relevant website along with other slides from the day. Will add URL shortly.

I think the best point raised during the day which I had not really considered at all before, was how long a general ban or disconnection after notice would last. (I think this came from Michelle Childs, but I am not totally sure.) Does a foolish upload or two by a teenager in your house mean that dad and/or mum is banned from the Internet forever? Even when we talk of true criminal sanctions (and copyright is at root a civil matter), jail terms (bar "life means life" for murder) have to be of defined length. Do we want a world where ISPs are ordered by the content industry to patrol indefinite lifetime bans from the Internet? Would legislation include provisions for appeals after a certain time and has anyone thought through the due process ramifications? The more you think about it, the more damningly flawed the whole idea is.

In France, at least, the whole process is going to be under the supervision of an independent tribunal given directions by a judge. If we do end up going down this route in legislation, the French system should be the minimum starting point for transparency and due process. I hope instead however that the UK government and BERR will, after due consideration, decide this approach, with all its capacity for disproportionate human right infringement and errors in proof and process, is not a suitable way to police filesharing, when so many other routes exist.