Showing posts with label wikileaks. Show all posts
Showing posts with label wikileaks. Show all posts

Friday, October 28, 2011

Wikileaks and intermediary ethics : the tunnel at the end of the light?

Pangloss is amused in a schadenfreude-ish way to see two developments this week she sort of predicted in big ongoing stories about Wikileaks and online copyright enforcement (Newzbin).

Back in February this year (and indeed, earlier), I commented that one of the most unsettling aspects of the Wikileaks affair was the power it had highlighted of intermediaries not part of the traditional media communities - hosts like Amazon Web Services , domain name providers like EveryDNS.com and payment intermediaries like PayPal, Mastercard et al - to close down possibly legitimate speech. (I noted also however that for these corporations to do so is currently entirely legal - raising a debate about the nature of corporate social responsibility and what ethical duties media and non-media organisations should have in the soon to arrive post hard-copy newspaper world).

Events since - Assange's extradition, Anonymous arrests, fights with the Guardian and unauthorised half -autobiographies, Anonymous taking up closing down child porn sites - have rather obscured the fact that in fact, Wikileaks may or may not have been winning the PR war for the hearts of the technoproletariat but they were losing to those self same intermediaries, who were, understandably and quietly, more interested in avoiding legal liability risks than defending access to knowledge.

So this week, Wikileaks announced they were suspending publication and concentrating only on fundraising as 95% of their assets have vanished or become inaccessible. The faceless intermediaries have it seems won after all.

Dan Gillmor is unhappy about this.

"Suppose you are the proprietor of an information service. Your customers buy what you sell using the major payment systems such as Visa, MasterCard, Western Union and PayPal. The information you provide is greatly upsetting to powerful people who would prefer to keep it a secret. You have been charged with no crime, much less convicted of one. But one day, you discover that all of these payment systems – quite obviously responding to pressure from the government but citing no actual legal authority – are refusing to accept money from your customers on your behalf.
This, sadly, is not a supposition. It is nearly the precise situation that WikiLeaks has encountered since late last year, stripping most of the revenue away and now, as reported this week, forcing the whistleblowing media operation to suspend all activity except fundraising in a struggle merely to survive.
If this was happening to any traditional media company, it would be a scandal, and the media in general would be screaming about the threat to free speech it represented. While the news media are covering the WikiLeaks situation, they are not offering serious support in ways that matter to an organisation with which they have much more in common than not."
I can't go as far as Gillmor, though, who suggests payment organisations like Paypal or Visa be treated like "common carrier"s ie akin to telcos and postal services , with a duty to accept and pass on payments to any customer who presents themselves in return for limitation of liability as to what messages they carry.
The analogy to the phone company is simply not right here (and is also, it should be noted, legally out of date, but let that pass): the phone company accepts relatively little economic as opposed to publication risk that is not compensated by immunity from publisher's liability. By dealing with all willy nilly, anyone might default on their bill, true, but it would probably be uneconomic to try to spot potential poor payers & discriminate anyway.
On the other hand, banks (say) run the risk of severe loss if they deal with payers or payees who are likely to be fraudsters or otherwise default - their risk is not just of liability for becoming connected to illegal activities. Constraining banks , PayPal etc to deal with all without any discretion would probably lead to them reducing the services they offered to reduce risk - eg reducing consumer offerings, excluding certain territories - to no one's benefit. It would also likely considerably benefit organized crime.
It is certainly time though for a debate on online intermediary corporate ethics as well as law in Europe - perhaps to accompany the potential draft review of the E-Commerce Directive this November , or the FCO's upcoming launch of yet another set of Internet Principles at the major Cyberlaw conference in London this week (featuring Ms Internet Freedom herself, Hillary Clinton!). I look forward to it.

oh and Ps as for Newzbin (no 2), read Francis Davey's great summary here . Executive summary : we now have a working system of court injunctions to secure web blocking of sites assisting in copyright infringement in the UK. Regardless of whether this is good or not, there is clearly now no need for s 16 of the DEA to stay on the statute books.
The main point is costs. These, as Francis says look boring to everyone but a lawyer - but in fact here they are where the action is. Newzbin was an unusually easy case for Fox and the rest of the plaintiffs to win on the matter of primary liability (see my earlier post) - which made it also relatively easy for the court to decide that yes, ISPs really ought to block it. Other case, involving sites which have significant non infringing use, will almost certainly not be as easy.
But if an ISP stands its ground and loses and then appeals, and still loses, as BT did, then the ISP now (it seems) pays. This is somehat different from the approach taken in Totalise v Motley Fool concerning whether an ISP should pay for its costs if opposing a Norwich Pharmacal order, and it is, in my view, the wrong decision. Why is it reasonable to demand the scrutiny of a court (para 53-4) but not to pursue an appeal if the ISP feels the instant court was wrong??
To date UK ISPs have resisted blocking on request (see Vaizey's talks in the summer on a secret council for voluntary ISP copyright blocking). Will they continue to demand a court order under the precedent Newzbin No 2 now sets? Or will they throw in the towel on the assumption the first court order will be a forgone conclusion and appeal too risky? I hope this latter is not what we see. Requests for blocking (see below) are so far getting fair bit of publicity at least in the geek press: but if they become more common such transparency will probably fade. (Anyone for hosting a Chilling Effects- type UK Block Requests Clearinghouse site?)

UPDATE 9/11/11 : Since writing this, plaintiff rightsholders have apparently demanded BT now block the Pirate Bay. Interestingly this is significantly different from Newzbin in that there is no existing finding of primary liability for copyright infringement. We are yet to see if BT will obtain a court order, though they say thay plan to before undertaking any blocking.
Most recently, Virgin and Talk Talk have also been asked to block Newzbin2. Again, it is not yet clear if they will see a court order though Virgin has gone further still & said they would like to see a quid pro quo for blocking of access to lawful content guarantees (Virgin of course have a notoriously long history of being stymied by rightsholders in their attempts to offer legal flatrate P2P.) Watch this space..

Monday, January 10, 2011

Welcome to 2011!

Happy new year, gentle readers, slightly belatedly, and for Pangloss it's all new indeed: new job, new title (Professor of E-Governance), new workplace (Strathclyde Law School) and new abode (back in Auld Reekie). All of this makes me very happy if in the short term, slightly, dishevelled, abandoned, hyper and well, fill in the adjective of your own choice :)

Please note AGAIN my new email address is lilian.edwards@strath.ac.uk and my snail address should you conceivably need it is

School of Law

Faculty of Humanities and Social Sciences

Graham Hills Building, Level 7 (GH 7.13)

50 George Street

Glasgow G1 1QE


If any of you can remember the achingly long time ago before the festive season, the burst pipes (oh so don't ask) and the Snowpocalypse, you may remember we were a little exercised about Wikileaks. The nice people at Practical Law Company (PLC) asked me to write a briefing on what issues might be involved for the UK legal system, and you too can read it for free here. Basically I think the key issues are:

- were criminal offences committed of DDOS by UK residents? (almost certainly yes)
- is merely downloading a tool which can be used to help commit DDOS a crime? (yes, though proof of intent may be tricky)
- can IP addresses of attackers be captured & UK ISPs be asked to help identify such persons (yup)
- can ISPs in UK conceivably be asked to block Wikileaks sites or domain names? (A. probably not, unless by some back door means such as invoking copyright laws under s 97A of the CDPA, or by some hitherto latent common law power which would need at least a High Court application in England & Wales or Court of Session in Scotland, and still be pretty uncertain).

The last point, though it seems farfetched, is a topical one given the ill judged comments by Ed Vaizey just before Christmas suggesting that all online "adult sexual materials" sites should be blocked "at source" by UK ISPs , with only adults then allowed to opt back in. Beyond the obvious difficulties of definition of such sites, over blocking, under blocking, the herculean task of assembling such a list, most of which will be overseas, evasion, ULL-jumping, VPNs, proxy servers, the fact that kids are better than adults at hacking this, etc ad nauseam, the simple fact is that such blocking solutions don't work and don't scale on practical terms unless you're willing to devote the resources and the Stalinist control of a country like China to such a pursuit. Just look at Australia for the trouble it has caused there in a smaller country with far fewer ISPs and far more history of state censorship than here.

I'm all for thinking of the children, really (actually, to be honest, as a child's rights lawyer on the side I also wonder if anyone has paid attention to the emergent minor child's right to autonomy, see Gillick, see future possible ECHR applications..?) but right now this seems like an expensive, embarrassing, largely pointless red herring to go down. IF parents want to stop kids accessing porn, there are many good products out there to allow them to do it at home eg |Net Nanny and its ilk. The Daily Mail will like it though :-)

But more than ALL that, what worries me is the huge possibility for scope creep here. As I have noted often, often before, once you have one scheme for blocking huge amounts of URLS without transparency or accountability in place, what is the temptation to start adding other URLs to it you don't like? High , in my cynical opinion. (And whatever the government means by blocking sites "at source" this will have to involve an Internet Watch Foundation style blocklist - because every single adult site closed down by its host service in UK will simply shift to a host abroad in under 24 hours. Indeed the Telegraph story seems to clearly indicate an IWF type list would be used : "Ministers now want companies to use the same technology to stop children accessing adult images".)

So on a brighter more positive start to the new year, here's a few events I plan to be at, be running , be speaking at, and so forth:

Workshop on Free and Open Communication on theInternet (FOCI), to be held February 24-25, 2011 at Georgia Tech in Atlanta,Georgia (invited expert speaker)

BILETA, Manchester Metropolitan University, 11th-12th April

3rd Web Science Conference, Koblenz, Germany - June 15-17

GikII in Gothenberg, Sweden!! GikII goes Scandinavian hardcore:) , contact Matthias Klang for info - 27-28 June

SCL Policy Forum, London, Herbert Smiths, September 15-16th - I'm curating this one on a theme of the new shape of European regulation as the DPD, ECD and other major instruments head for reform.

Sunday, December 12, 2010

Wikileaks drips on: some responses

Again like every self respecting blogger on the planet, I have written a short comment for the Grauniad on Wikileaks.

The main thrust of the point I was making is that settling a dispute of major public consequence by covert and non-legitimate bully boy tactics - covert pressure on hosts, payment services and DNS servers, plus DDOS attacks on Wikileaks hosts from the US-sympathising side - and anonymous DDOS attacks on sites like Amazon, Mastercard and Assange's alleged rape victims' lawyer's site from the Wikileaks-sympathising side - are BOTH the wrong thing to do. The point of a civilised society is suposed to be that disputes are settled by transparent legitimate and democratic, judicial or political processes. This has not been a particularly popular point with almost anybody, but it seems to me that it may indeed be naive (as some commenters have accused), but it is also, I stil think, both correct and needing saying, in the current frenzy around the First Great Infowar etc (it's 1996 all over again, yet again..).

One commenter asks not entirely unreasonably why it is justified for Amazon to take down content without going to court but "Vigilanteism" if the forces of Anonymous take down content extra judicially by DDOS attacks. The confusion here is in the word "justified". Amazon are justified, I argue, because since they host the content, they could be held legally liable for it (on a variety of grounds) if they do not take down having been given notice. That could lead to damages against them, injunctions blocking their site to customers (at their busiest time of the year) or even a prison sentence for their CEO . As a (liberal-sympathisng) friend in industry said to me, that last does tend to focus the mind. To state the bleeding obvious, Anonymous by contrast are not liable for the content they bring down.

But that meant I was saying Amazon were justified in a risk-management sense, and a legal sense, not an ethical sense. Was it Amazon's highest ethical duty to defend freedom of speech or to be responsible to their shareholders and their employees? That's a harder question. Many used to feel companies had no ethical duties at all, though that is gone in an era of corporate social responsibility (though this is still rarely if ever a legal obligation). Amazon's role is perhaps confused because they are best known as a consumer site selling books ie complicit with freedom of expression. Would we feel as aggrieved if Wikileaks had gone to a cloud host known only for B2B hosting? Perhaps, but what reason would there then be for expecting a host to behave like a newspaper?

What this leads us to as many, many commentators have pointed out is a renewed understanding that freedom of speech online is worryingly dependent on the good intentions of intermediaries whose core values and business model is not based on journalistic ethics, as was true for traditional news outlets in the offine age. This is hardly news: it has been making headines since at least 1996 when a Bavarian court convicted the CEO of Compuserve for distributing Usenet newsgroups to Europe, some of which happened to contain pornographic files. That incident among many others, lead to rules restricting the liability of hosts and intermediaries, in both the EU and US, which did quite well till round the early 2000s but are now struggling (not least because of pressure from both the copyright and the chld safety lobbies for less, not more, immunity). Not uncoincidentally, these rules are now being actively reviewed by among others, the EU, the OECD and WIPO. The really interesting question now will be what effect Wikileaks as a case study has on those debates.

Wednesday, December 01, 2010

Veni Vidi Wikileaks

Since every other blogger in the universe has discussed how the US is going to stop Wikileaks, perhaps it's time for Pangloss to enter the fray, with the not terribly unexpected news that Amazon (in its cloud hosting services capacity) have indeed decided to stop acting as new temporary host to Wikileaks which moved there following the devastating DDOS attacks on its own server (thanks to Simon Bradshaw for pointing me at this news).

This is interesting in all kinds of ways.

First, the initial move to Amazon was a clever one. In the old days, a concerted and continuing DDOS attack on a small site might have seen them off - nowadays there are plenty of commercial reasonably priced or free cloud hosts. So cloud computing can be seen as a bulwark for freedom of speech - vive les nuages!

Second, though of course, what strokes your back can also bite it, and here we have Amazon suddenly coming over shy. This appears to be entirely the sensible legal thing for them to do and anyone accusing them of bad behaviour should be accused right back of utter naivete. Amazon are now on notice from the government of hosting material which breached US national security and so would according to the US Espionage Act as quoted in the Guardian piece, fairly clearly have been at risk of guilt as a person who "knowingly receives and transmits protected national security information" if they had not taken down. (Though see a contrary view here.)

While Assange as an Australian not a US citizen, and a journalist (of sorts) might have had defences against the charges quoted also ( as canvassed in the Grauniad piece) Amazon, interestingly, would, it seems, not. They are American and by definition for other useful purposes (eg CDA s 230 (c) - see below and ye ancient Prodigy case) , not the sort of publisher who gets First Amendment protections. And Amazon has its CEO and its major assets in the US, also unlike Assange. I think that makes take down for Amazon a no-brainer. (And also interestingly, CDA s 230(c) which normally gives hosts complete immunity in matters of liability which might affect press freedom (such as defamation by parties hosted) does not apply to federal criminal liability.)

But as Simon B also pointed out, there are lots of other cloud suppliers , lots in Europe even. What if Wikileaks packs and moves again? Would any non US`host be committing a crime? That would depend on the local laws: but certainly it would be hard to see if the US Espionage Act could apply, or at any rate what effective sanctions could be taken against them if a US court ruled a foreign host service was guilty of a US crime.

Which leaves anyone wanting to stop access to Wikileaks, as Technollama already canvassed, the options of, basically, blocking and (illegal)DDOS (seperating the existence of the Wikileaks site from any action against Assange as an individual). Let's concentrate, as lawyers, on the former.

Could or would the UK block Wikileaks if the US`asked?

Well there is an infrastructure in place for exactly such. It is the IWF blacklist of URLs which almost all UK ISPs are instructed to block, without need for court order or warrant - and which is encrypted as it goes out, so no one in public (or in Parliament?) would need to know. This is one of the reasons I get so worked up about the current IWF when people are asking me if I won't think of the children.

There is also the possibility, as we saw just last week, of pressure being exerted not on ISPs but on the people who run domain name servers and the registrars that keep domain names valid. Andres G suggests that the US might exert pressure on ICANN to take down wikileaks.org for example. Wikileaks doesn't need a UK domain name to make itself known to the world, but interestingly only last week we also saw a suggestion from SOCA (not very well reported) that they should have powers effectively to force Nominet, the UK registry, to close down UK domain names being used for criminal purposes. Note though if you follow the link that that power could only be used if the doman was breaking a UK criminal law.

But there is a really simply non controversial way to allow UK courts the power to block Wikileaks. Or there may be soon.

Section 18 of the Digital Economy Act 2010 - remember that? - allows for regulations to be made for "the granting by a court of a blocking injunction in respect of a location on the internet which the court is satisfied has been, is being or is likely to be used for or in connection with an activity that infringes copyright."

Section 18, at present, needs a review and regulations to be made before it can come into force. This may in the new political climate perhaps never happen - who knows. But what if that had been seen to?

Wikileaks documents are almost all copyright of someone , like the US government, and are being used ie copied (bien sur) without permission. Hence almost certainly, a s18 fully realised could be used to block the Wikileaks site.Of course there is some possibility from the case of Ashcroft v Telegraph Group [2001] EWCA Civ 1142`that a public interest/freedom of expression defense to copyright infringement might be plead - but this is far less developed than it is in libel and even there it is not something people much want to rely on.

So there you go : copyright, the answer to everything, even Julian Assange :-)

Oh and PS - oddly enough the US legislature is currently considering a bill, COICA, which would also allow them to block the domain name of sites accused of encouraging copyright infringement. Handy, eh? (Though on this one point, the UK DEA s 18 is even less restrictive than COICA, which requires the site to be blocked to be "offering goods and services" in violation of copyright law - which is not even to a lawyer a description that sounds very much like Wikileaks.)

EDIT: Commenters have pointed out that official government documents in the US, unlike in the UK do not attract copyright. Howver the principle stands firm: embarrassing UK docs leaked by Wikileaks certainly would be prone to attack on copyright grounds, including DEA s 18, and it is quite possible some of the current Wikileaks documents could quote extensively from material copyright to individuals (and Wikileaks prior to the current batch of cables almost certainly contain copyright material).

Interestingly Amazon did in fact, subsequent to this piece, claim they removed Wikileaks from their service, not because of US pressure, but on grounds of breach of terms of service : see the Guardian 3 December 2010

"for example, our terms of service state that 'you represent and warrant that you own or otherwise control all of the rights to the content… that use of the content you supply does not violate this policy and will not cause injury to any person or entity.' It's clear that WikiLeaks doesn't own or otherwise control all the rights to this classified content. Further, it is not credible that the extraordinary volume of 250,000 classified documents that WikiLeaks is publishing could have been carefully redacted in such a way as to ensure that they weren't putting innocent people in jeopardy. Human rights organisations have in fact written to WikiLeaks asking them to exercise caution and not release the names or identities of human rights defenders who might be persecuted by their governments."

The copyright defense is alive and well :-)