Friday, June 30, 2006

G'Buy to PayPal?

The Google empire have gone into the on-line payments business.

"Search giant Google has launched an online payments system which aims to compete with auction giant eBay. Dubbed Google Checkout, the system is designed to boost Google's main source of revenue - selling advertising. The service offers some free order processing to Google's millions of advertisers, but will initially be available only to stores in the US.
EBay unit Paypal is the market leader in online payments. EBay stock slipped ahead of Checkout's launch. "

Interestingly, the Beeb report downplays the idea that GBuy (as it is apparenly mostly already known) is intended to rival or destroy Paypal. Correspondents on Boing-Boing, NY Times and ZNet see it rather differently. "Google is charging merchants 20 cents plus 2 percent of the purchase price to process card transactions, less than most businesses pay for credit card processing. Banking industry executives say that credit card processors typically pay MasterCard and Visa a fee of 30 cents and 1.95 percent for every purchase, so Google will be subsidizing many transactions".

This could be good competition for PayPal - a good thing surely - and even the end of credit card domination of on-line payments - an interesting thing. Will Google, like PayPal, seek to be accredited in Europe as an Electronic Money Issuer, hence getting preferential treatment under the EMI Directive? It's only currently available in the US but one would think its case is even weaker than PP's (perhaps surprisingly successful) aplication - according to the Beeb again -

"The Google service will simply act as a transferring house, whereas Paypal has the facility for users to set up their own accounts to pay into - as well as offering credit card payments. "

To be an EMI requires stored value in essence - so it looks unlikely Google Checkout can qualify.

What does Google get out of it? More advertising is the main noted benefit; plus it supports their business opposition to Yahoo! and eBay/Paypal's recent tie up; but the NY Times also observes:

"Google may get several additional benefits from the checkout service. It will encourage more users to register and give it personal data, allowing Google to display advertising based on specific attributes of the viewer. More broadly, the data the company gets from transactions could help it improve the way it chooses which advertising to show to which users".

So we have interesting privacy implications too. Good thing Google does no evil, huh?

ps from John Battelle's SearchBlog, June 29 2006 -
The Oxford English Dictionary--last bastion of standardized English--includes "Google" as verb in the latest draft for its next edition. The pending definition, noted by Resource Shelf: intr. To use the Google search engine to find information on the Internet. trans. To search for information about (a person or thing) using the Google search engine.

WEIS and blog

The Security Lab people at Cambridge - including the esteemed Ross Anderson - have their own blog: full of interesting stories about computer security, including related legal issues.

I'm just back from WEIS, the Workshop on Economic Issues in Security run by that self same man : and boy, my mind is blown. I have things I now desperately want to write/research about selling zero day exploits, cyber insurance, and privacy seals , value of (actually less than zero) ; but I'm currently just too ill ! as I also came back with a bug and a high temperature.

But very shortly there will be a very long post about fascinating papers I've seen! In the meantime try Bruce Schneier's summary, with pointers to some of his highlight papers.

Also gratified by more abstracts that have arrived for GikII while I was away: it's looking goooood, kids!

Sunday, June 25, 2006

New Privacy Laws for the USA?

Two interestingly almost simultaneous calls for a uniform set of privacy laws for the US, applicable to private as well as public sectors, have emerged in the last few days.

OUT-Law.com reports : "Google, Microsoft, Intel, eBay, HP, Oracle and Sun are amongst the signatories to a statement calling for personal information to be protected across the US. Non-profit lobby group the Center for Democracy and Technology organised the companies into the Consumer Privacy Legislative Forum.

"The time has come for a serious process to consider comprehensive harmonized federal privacy legislation to create a simplified, uniform but flexible legal framework," said the CPL Forum's statement. "The legislation should provide protection for consumers from inappropriate collection and misuse of their personal information and also enable legitimate businesses to use information to promote economic and social value." "

Meanwhile Hillary Clinton has called for a Privacy Bill of Rights. Hilary,a likely Democratic candidate for 2008, stated that she wanted to to create a "privacy czar" within the White House to guard against recent problems like the theft of personal data from the
Department of Veterans Affairs'. She also wants legislation to let consumers know what information companies are keeping about them and how it is used, and create a tiered system of penalties for companies who are not careful with consumer data. "Clinton also waded into the debate over anti-terror eavesdropping. ..Clinton said any president should have the latest technology to track terrorists, but within laws that provide for oversight by judges."

And a San Francisco Chronicle report notes inter alia that technological invasion of privacy is not only accelerating but is also becoming more and more consumer friendly and "cool".

"Americans' rights to privacy will be tested even more in the next few years as biometric technology creeps increasingly into everyday arenas. For example, on the campus of UC San Diego, biometric experts are testing a soda machine that uses both fingerprint and face-recognition technology. The machine is in a lounge for grad students in UC San Diego's computer science building.
"The students are very excited about getting it working," Serge Belongie, a UC San Diego associate professor of computer science, says in a phone interview. "People think it's very cool. ... No one uses money. They have accounts. What would be fun is if (the machine) recognizes you and says, 'Would you like your usual?' "

As I have often suspected, the report indicates that although biometrics can be far more privacy threatening than ordinary methods of ID consumers favour them due to convenience factors:

"If UC San Diego students are reluctant to use the machine, their privacy concerns are outweighed by convenience -- a sentiment echoed in survey after survey on biometric technology. In March, Unisys Corp. released a report on public perception of "identity management" that said convenience and efficiency were the two biggest reasons consumers would use biometric technology. (The most preferred biometric methods are fingerprints and voice recognition, according to the survey. The least preferred, because of its perceived intrusiveness, is an iris or eye scan.) "

But not everyone is enthralled by the "brave new world in aisle 5":

"Pay By Touch admits it has encountered some resistance among shoppers it approached in supermarkets that already use the company's fingerprint service. But Morris, its president, says many of these customers are quickly won over by the convenience of Pay By Touch, which is free for consumers, and that the company keeps data points based on users' fingerprints, not actual fingerprints. So far, supermarkets in 40 states use the Pay By Touch system. .. The company insists it will never sell users' personal information or fingerprints to anyone else -- a pledge that's backed up in writing when users sign up with the company. But what if federal authorities, citing national security, insist on the finger scan and payment history of a Pay By Touch user? "

The times they are a changing. Last year, at a workshop I organised in Edinburgh, Peter Swire, effectively Bill (not HIlary's) privacy czar during that administration, was pessimistic that post 9/11 there was much scope for the private sector and governmental privacy legislation that the Clinton era might have favoured. Is the pendulum swinging again, in the light of recent personal data scandals, to the point where privacy is a vote-getter in the USA? Watch this space.

Saturday, June 24, 2006

Alan Moore vs the Copyright fairies

While we're considering pop culture and IT law (great stuff for a GikII paper here!) the IPKat reports that Alan Moore, father of the graphic novel is potentially running into trouble with his latest project,a graphic novel called Lost Girls which is "a meeting between Wendy (of Peter Pan), Alice (of Alice in Wonderland) and Dorothy of The Wizard of Oz) once they have grown up". It is also allegedly "erotic fiction at its finest". Hmm. As every IP lawyer knows of course, there is a specific exception in UK copyright law (s.300 of the CDPA )which grants perpetual copyright in J M Barrie's Peter Pan, which goes to the Great Ormond Street Hospital by virtue of a legacy to the hospital in Barrie's will. And the hospital are apparently deeply unhappy with being connected with this project and its possible paedophilic implications, and may seek to have publication banned in the UK and Europe.

The IPKat suggests that "the hospital [has after 2007] a right to royalties, not the full rights of a copyright owner. This would mean that the hospital could make money from the novel, but not that it could stop its distribution." Others suggest the whole idea of perpetual copyright, even as a pleasing anomaly given the storyline of Peter Pan , should be abolished. Alan Moore himself is no stranger to copyright fights: the tangled tale of Marvelman, Miracleman, Moore, DC, and Gaiman et al is too confusing to even begin to tell here. Moore, after various disputes, has also refused to allow film adapations of any of his works to which he still owns full copyright and has removed his name from adaptations he cannot control, even where they have been critically well received as with the recent V for Vendetta. He is a formidable adversary in respect of his work, and it will be interesting to see where this dispute goes next.

Dr Who and the Semantic Web

Tim Berners-Lee has been round the houses latel;y, proselytising not only for net neutrality (see earlier posts) but also for his baby, the Semantic Web. The Guardian has an informative and occasionally entertaining piece on his efforts.

"..the BBC, one of the organisations that led Britain on to the web, is keen to share some of its data. Tom Loosemore, head of strategic innovation, says the corporation will shortly place online the catalogue of its entire surviving programme library - not the 950,000 television and radio programmes themselves, but the names, transmission details, often production credits and in some cases who is interviewed..

"What is interesting is what the audience does with that data," [he says] although Loosemore imagines that Doctor Who fans will be early adopters. It will be available through an API (applications programming interface) at BBC Backstage (http://backstage.bbc.co.uk), which allows data to be re-used for non-commercial purposes - a model that the Ordnance Survey hopes to follow."

Friday, June 16, 2006

Internet libel : why, how and where

It's always good to see empirical research backing things you intuitively anyway :-) I've long asserted in my textbook Law and the Internet that email is particularly defamation-prone because of the odd nature of the medium, which combines the spontaneity of speech with the archiving capacity of text. Now we have actual scientific confirmation of the first point.

"In effect, e-mail cannot adequately convey emotion. A recent study by Profs. Justin Kruger of New York University and Nicholas Epley of the University of Chicago focused on how well sarcasm is detected in electronic messages. Their conclusion: Not only do e-mail senders overestimate their ability to communicate feelings, but e-mail recipients also overestimate their ability to correctly decode those feelings."

Two scientists in the area, Michael Morris and Jeff Lowenstein add "One reason for this, the business-school professors say, is that people are egocentric. They assume others experience stimuli the same way they do. Also, e-mail lacks body language, tone of voice, and other cues - making it difficult to interpret emotion.

"A typical e-mail has this feature of seeming like face-to-face communication," Professor Epley says. "It's informal and it's rapid, so you assume you're getting the same paralinguistic cues you get from spoken communication." "

Which raises an interesting point for various legal systems: if sarcasm or fair comment or "joke" (in rixa in Scots law) is a legal defense, is it to be measured by what the sender meant, the recipient understood, or what the "reasonable man" would have taken out of the communication? Probably the latter in most systems, given libel damages are measured by the damage to the reputation - but what if, as the study evidence seems to show , there is no objective "true" interpretation of email speech, only different subjective interpretations? Oh how postm0dern!

On the more legal front, another new English Internet libel case is Al Amoudi v Brisard and JCB Consulting International SARL [2006] EWHC 1062 (QB). (Via OUT-Law.com )

Ethiopian-born businessman Mohammed Hussein Al Amoudi, who normally lives in Saudi Arabia but spends around two-and-a-half months a year in England, sued Swiss resident Jean Charles Brisard and his Swiss company, JCB Consulting International SARL in the English courts. Brisard claims to be a world expert on terrorist financing. In two reports on JCB's site he made references to Al Amoudi. These suggested that Al Amoudi might be "a knowing participant in the economic, financial and/or terrorist networks of the terrorist Osama Bin Laden". Al Amoudi sued for defamation, seking summary judgment ie judgment without trial of the evidence. The key point on which this was rejected by the court was that Al Amoudi had not proved "substantial publication" in England and this could not be proved. (It was not argued at this stage whether the coments themselves were defamatory.)

Legally, in England, damage in libel cases is presumed, and therefore need not be proven, but, as a norm, circulation figures are provided to back claims of "substantial damage" in cases involving non-English defenders. In this case however, there was a dispute over how long the offending website had been available for, and it was thus submitted only that "publication over the Internet takes place if and only if the material is accessed and downloaded by a third party within the jurisdiction". Crucially, Mr Justice Gray held that "I am unable to accept that under English law a claimant in a libel action on an Internet publication is entitled to rely on a presumption of law that there has been substantial publication".[italics added]. Acordingly the case was denied summary judgment and the claimant must prove publication in the ordinary way if he wishes to proceed.

This is an interesting application of last year's major Internet libel case, Dow Jones v Jameel , [2005] EWCA Civ 75. In that case, only five people in England were shown to have "clicked through" a link on the defender's (DJ's)online Wall Street Journal website, which lead to an allegedly defamatory item. These 5 persons "clicking through", furthermore, included the solicitor of Mr Jameel (the person allegedly defamed)and two of his business associates. Thus, it was argued by the defendant, the court should dismiss the case, as damage to reputation in England that was more than nominal had not been proven.

Several very famous non-Internet libel cases were, however, cited by Jameel as precedents that " under English law there is a presumption of damage in libel cases, [thus] the plaintiffs did not have to adduce evidence of damage arising from the publication of the article in question": see eg Duke of Brunswick v Harmer (1849) 14 QB 185, Shevill v Presse Alliance [1996] AC 959 and Berezowsky v Michaels [2001] 1 WLR 1004. In other words, damage to reputation would be presumed. The Court of Appeal in Jameel upheld these precedents, and furthermore held on review of them that this presumption was still, in practice, irrebuttable. In conventional publication, it is extremely difficult to establish how many people have read a publication, so the presumption of damage makes sense or proof may become a bar to redress in very many cases. However with Internet hit counters, proof of publication in the jurisdiction (& numbers of readers) can become trivially easy. The court nonetheless thought there were good reasons why damage should still always be presumed, and furthermore that such a presumption did not "chill" freedom of expression under the Human Rights Act 1998 and/or Art 8 of the European Convention on Human Rights.

However this was not the end of the story. Jameel's case was still rejected as an "abuse of process". Since this was a non-EU, non-Brussels Convention case, an application to serve outside the jurisdiction of England was necessary, which raised the question of whether 'a real and substantial tort ha[d] been committed within the jurisdiction': Kroch v Rossell [1937] 1 All ER 725, Chadha v Dow Jones & Co Inc [1999] EMLR 724, and Civil Procedure Rules 6.20(8). Since the damage to Mr Jameel's reputation in England was apparently minimal, in the Court of Appeal's view, only "very modest damages" would have been available after what would have been a lengthy and expensive trial. So the case was thrown out as an abuse of process.

LJ Phillips MR noted that : "There have been two recent developments which have rendered the court more ready to entertain a submission that pursuit of a libel action is an abuse of process. The first is the introduction of the new Civil Procedure Rules. Pursuit of the overriding objective requires an approach by the court to litigation that is both more flexible and more pro-active. The second is the coming into effect of the Human Rights Act. ... Keeping a proper balance between the Article 10 right of freedom of expression and the protection of individual reputation must, so it seems to us, require the court to bring to a stop as an abuse of process defamation proceedings that are not serving the legitimate purpose of protecting the claimant's reputation, which includes compensating the claimant only if that reputation has been unlawfully damaged."

This case (which I must shamefacedly admit to having missed when it first came out) is a remarkable step forward, by a cleverly lateral route, from the much-criticised jurisdictional rules on forum non conveniens applied to date by the English courts in Internet-related cases like Berezovsky and Loutchansky v Times Newspapers & Ors Nos 2 to 5 [2002] QB 783. Jameel does not over-rule these cases (inded it could not, not being of House of Lords level). Nor does it impose a US style single publication rule, as Geoffrey Robertson QC has suggested in a number of cases, nor does it change the rules established in The Spiliada [1987] AC 470, as to when England is an appropriate forum (basically, nearly always:-)

But it does provide an alternative route by which to argue, sensibly, that the English courts should not be involved in cases where the circulation of the libelous item in England has been tiny, and the damages in England are therefore also likely to be minimal. This is a giant step forward for opposing the "chilling effect" of the threat of action in England in relation to texts on international websites which essentially have little or no connection to English readers. The Master of the Rolls is to be congratulated.

This author would however suggest that it's still not enough: Internet cases require a total revamp of the rules of forum non conveniens. Imagine if Berezovsky had been argued on post-Jameel rules, for example. That case concerned a tiny circulation of the libellous item in question in England, compared to an enormous circulation in the US - but still a circulation significant enough for more than nominal damages. I suspect the court would still have been forced to take it, even given the addition of the "abuse of process" concept - in other words we have still not budged from the idea that if England is an appropriate forum but obviously not THE most appropriate forum, it will still accept all comers. On the Internet this is clearly turning England into a "libel case magnet" as was asserted during Berezovsky. Given the weight of post-Spiliada authority any change will however require legislation: which will be , one suspects, a long time coming.

Wednesday, June 14, 2006

Who needs keyloggers? USB hacking for Dummies.

Steve Stasiukonis, VP and founder of Secure Network Technologies Inc, tells us how easy it is using social engineering to collect passwords and data from a large and apparently secure corporation , by means of leaving USB drives around and waitinmg for people to wonder "I wonder what's on it?", and click..

"We figured we would try something different by baiting the same employees that were on high alert. We gathered all the worthless vendor giveaway thumb drives collected over the years and imprinted them with our own special piece of software. I had one of my guys write a Trojan that, when run, would collect passwords, logins and machine-specific information from the user’s computer, and then email the findings back to us...

..The next hurdle we had was getting the USB drives in the hands of the credit union’s internal users. I made my way to the credit union at about 6 a.m. to make sure no employees saw us. I then proceeded to scatter the drives in the parking lot, smoking areas, and other areas employees frequented.

..After about three days, we figured we had collected enough data. When I started to review our findings, I was amazed at the results. Of the 20 USB drives we planted, 15 were found by employees, and all had been plugged into company computers. The data we obtained helped us to compromise additional systems, and the best part of the whole scheme was its convenience. We never broke a sweat. Everything that needed to happen did, and in a way it was completely transparent to the users, the network, and credit union management."

Glorious stuff. How should the law begin to help deal with this kind of thing? An obigation of security of systems, just as we currently have to provide a safe system of working under health and safety, seems the way to go, at least for any industry which handles the personal data of third parties. (of course, we theoretically have that already under DP law at least in Europe - but as usual, where's the enforcement mechanism?)

Monday, June 12, 2006

EBay Goes Ad-wards

"EBay is to launch keyword advertising - where internet users will be directed to specific auctions linked to words on the web page they are visiting.
Under the plan, site owners hosting the adverts for the online auctioneer will get a slice of the product sale price.

Called AdContext, EBay's new system may prove popular with blog site publishers who would be able to use it as an extra generator of revenue, analysts said.

The technique of contextual advertising is already used by Google and Yahoo. "

.. says the Beeb astutely adding that "EBay is one of the biggest advertisers on both Google and Yahoo and the plan could reduce its reliance on these sites, analysts said. "

Interesting , not just for its implications for eBay's business model and profits, (and indeed for the increasingly professionalised blog business model too), but also for what it might say about eBay's current EU and US immunity from liability for content originated by third parties. When eBay are actually facilitating the driving of traffic towards particuar auctions, by providing this particular advert model, with the specific intention of getting a cut of the final price (and driving that price up by greater traffic, one presumes) how neutral a third party intermediary really can they still be? (Also the contractual relationships must be fascinating.) I will shortly be writing up thoughts in this direction for the SCL's Journal of Computers and Law.

More Wiki than Geeky

Yochai's Benckler new Wealth of Networks, which is causing a veritable hail of interest, has, suprise, suprise a wiki.

And there are some very interesting links to commentary on the issue of wikis and the peer production method at Ray Corrigan's excellent blog.

This is a placeholder for my summer reading, natch; but it's also a chance for me to repeat my favourite IT law joke wot I thought up, as adapted freely from Sellar and Yeatman's fabulous 1066 And All That.

Students with a classical background , having finally managed to decipher their lecture notes,sometimes look up at their IT law profesors and say "Veni, vidi, vici!"* At which their law professors run away, thinking they have been (correctly) called Weeny, Weedy and Weaky, and this knew they had All been divided into Three Parts (like Gaul).
Only nowadays the ignorant non Latin loving profs think the students are just criticising their class Wiki!

Which is also a good place to plug my blue-skies cutting-edge and any other adjective you care to call it workshop on IT law and associated topics, GikII, to be held in Edinburgh on 5th September . Abstract deadline extended to June 30th, subsidy available for travel and accomodation and we already have papers on everything from digital property and virtual worlds governance to entropy in IT law and technophobia in Lord of the Rings!


* For Classicophobes, I came, I saw, I conquered! in Latin, as Julius Caesar is reported to have cried on conquering Britain (er, or somewhere else - see comment below..).

Wednesday, May 31, 2006

EU infrastructure security proposals

The EU has released a Communication on a strategy for a Secure Information Society – “Dialogue, partnership and empowerment” COM(2006) 251. This seems to be a serious atempt to advance the preservation of the Internet as critical infrastructure from the various current security threats - viruses, worms, DoS, hacking, spoofing et al. This was first advanced as an EC priority in Communication “i2010 – A European Information Society for growth and employment”( COM (2005) 229 final of 1.6.2005). The EU's press release announces that the Commission will report to Council and Parliament in the middle of 2007 on the activities launched, the initial findings and the state of play of individual initiatives, including those of ENISA (the European Network and Information Security Agency established in 2004, also as a result of the i2010 document) and those taken at Member State level and in the private sector. If appropriate, the Commission will then propose a Recommendation on network and information security (NIS).

The Communication identifies three key threats to Internet security.

"Firstly, attacks on information systems are increasingly motivated by profit rather than by the desire to create disruption for its own sake... [Secondly] The increasing deployment of mobile devices (including 3G mobile phones, portable
videogames, etc.) and mobile-based network services will pose new challenges, as IP based services develop rapidly. These could eventually prove to be a more common route for attacks than personal computers since the latter already deploy a significant level of security... [Thirdly} Another significant development is the advent of “ambient intelligence”, in which intelligentdevices supported by computing and networking technology will become ubiquitous (e.g. through RFID11, IPv6 and sensor networks). A totally interconnected and networked everyday life promises significant opportunities. However, it will also create additional security and privacy-related risks... The emergence of certain “monocultures” in software platforms and applications can greatly facilitate the growth and spread of security threats such as malware and viruses. Diversity, openness and interoperability are integral components of security and should be promoted."

What solutions does the Communication propose?

".. given the ubiquity of ICTs and information systems, network and information security is a challenge for everybody:
• Public administrations need to address the security of their systems, not just to protect
public sector information, but also to serve as an example of best practice for other players;
• Enterprises need to address NIS more as an asset and an element of competitive
advantage than as a “negative cost”;
• Individual users need to understand that their home systems are critical for the overall “security chain”.

In order to successfully tackle the problems described above, all stakeholders need reliable data on information security incidents and trends... one of the cornerstones in developing a culture of security is improving our knowledge of the problem... [And] Wherever possible, therefore, NIS should be presented as a virtue and an opportunity rather than as a liability and a cost. It needs to be viewed as an asset in building trust and consumer confidence, a competitive advantage for enterprises operating information systems, and a service quality issue for both public and private sector service providers."

PanGloss finds all this rather pleasing, as she has recently spent much time recommending , like the new EU instrument, a "holistic approach" to computer security, rather than one based, as at present, primarily on the ineffective tool of criminal law.

We are also promised a specific work programme which includes:

- two specific Communications on (i) spam, spyware and related threats; and (ii) cybercrime, including law enforcement authority co-operation.
- the scheduled review of the regulation of electronic communications due within 2006, to be expanded to include consideration of network and information security (NIS)
- the creation of a European multilingual info sharing and alert system (this to be a goal for ENISA)
- a "multi stakeholder dialogue" on economic, business and societal drivers towards NIS
- allocation of resources to NIS research under the 7th Framework programme

And in among the succeeding detail, is a para which sparks this writer's own little obsession - how far ISPs - and indeed software companies - should be held responsible for creating the new more secure Internet.

"3.3.2 The Commission also invites private sector stakeholders to take initiatives to:
• Develop an appropriate definition of responsibilities for software producers and
Internet service providers in relation to the provision of adequate and auditable levels of security. Here, support for standardised processes that would meet commonly agreed security standards and best practice rules is needed."

This is fascinating and much needed stuff. More comment when I have had time to look in more detail.

And the IT-Dino!

My correspondent Douglas Spencer points out that the tale of the cat who wasn't there (post below)is by no means the only recent domain name dispute to involve cute anthropomorphicised animals.

"I am reminded of a dispute between a purple dinosaur and a six-year-old boy [DRS1544]: HIT Entertainment PLC produce Barney, a stuffed purple dinosaur, together with a TV show and lots of valuable merchandise, and they disputed the registration of barney.co.uk by a certain Tim Loosemore, who had a son called Barney.

However, the giant media empire was dreadfully incompetent in assembling its case, and the boy's father is a major mover in organisations like Wired, FaxYourMP, and NTK.

The stuffed dinosaur lost. Visit Barney on the web".

Thanks, Doug!! sadly , the arbiter in this case, Andrew Lothian, declined to exposit further on the reality or otherwise of either fuzzy dinosaurs or six year olds.

the ITKat :-)

Discovered, with great delight via Discourse.net, a domain name arbitration around the well known trademark Morgan Stanley, in the US, where defendant's argument was, basically, that he was a cat.

"Respondent maintains that it is a cat, that is, a well-known carnivorous quadruped which has long been domesticated. However, it is equally well-known that the common cat, whose scientific name is Felis domesticus, cannot speak or read or write. Thus, a common cat could not have submitted the Response (or even have registered the disputed domain name). Therefore, either Respondent is a different species of cat, such as the one that stars in the motion picture "Cat From Outer Space," or Respondent's assertion regarding its being a cat is incorrect.

If Respondent is in fact a cat from outer space, then it should have so indicated in its reply, in order to avoid unnecessary perplexity by the Panel. Further, it should have explained why a cat from outer space would allow Mr. Woods to use the disputed domain name. In the absence of such an explanation, the Panel must conclude that, if Respondent is a cat from outer space, then it may have something to hide, and this is indicative of bad faith behavior.

On the other hand, if Respondent's assertion regarding its being a cat is incorrect, then Respondent has undoubtedly attempted to mislead this Panel and has provided incorrect WHOIS information. Such behavior is indicative of bad faith. See Video Direct Distribs. Inc. v. Video Direct, Inc., FA 94724 (Nat. Arb. Forum June 5, 2000) (finding that the respondent acted in bad faith by providing incorrect information to the registrar regarding the owner of the registered name). ...

The Panel finds that Respondent's assertions that it is a cat provide sufficient evidence to conclude that the Respondent registered and is using the disputed domain name in bad faith. And this despite the fact that the Panel, unlike Queen Victoria, is amused."

Thursday, May 25, 2006

Blogging for fun and profit, er, strife and ruin?

NY Times report incidents of people sacked or not hired for having work related blogs

"On the first day of his internship last year, Andrew McDonald created a Web site for himself. It never occurred to him that his bosses might not like his naming it after the company and writing in it about what went on in their office.
For Mr. McDonald, the Web log he created, "I'm a Comedy Central Intern," was merely a way to keep his friends apprised of his activities and to practice his humor writing. For Comedy Central, it was a corporate no-no — especially after it was mentioned on Gawker.com, the gossip Web site, attracting thousands of new readers.

"Not even a newborn puppy on a pink cloud is as cute as a secret work blog!" chirped Gawker, giddily providing the link to its audience."



Oops.

But no one's reading this, right?:-)

Wednesday, May 24, 2006

panGloss

As you may have noticed , BlogScript has now officially changed its name to PanGloss. I'm not changing the URL currently, but to give due warning, I may well migrate this blog elsewhere in the next few months.

Why the change? Well, Blogscript was never exactly a catchy name. It was supposed to be the "blog for SCRIPT"; and SCRIPT was the acronym I dreamt up, six or seven years back, for the loose conglomeration of IT and IP law scholars at Edinburgh Law School , who later became the AHRC Centre for Intellectual Property and Technology Law in 2002. SCRIPT stood for Scottish Centre for Research into IP and Technology (Law) - rather easier to remember than the current research-council imposed name, you must admit:-) The original idea was this blog would feature contributions from the postgraduate students at the AHRC Centre, with a bit of help from myself and Andres Guadamuz, my co-teacher. In the end though, as ever, you can take a student to water, but you can't make him/her drink :-) and so, predictably, I ended up writing the content exclusively myself, and to my surprise, like most bloggers, becoming mildly addicted to the process.

And now I'm leaving Edinburgh, it seems a good time to formalise this as MY blog, not a blog for a particular course or university; and thus to dump the clunky "SCRIPT blog" name in favour of something with a bit more juice to it.

So why panGloss? Well, blame Paul Maharg. A month or so back, at the very enjoyable BILETA 2006 conference in Malta, Paul gave a storming talk entitled " ‘Borne back ceaselessly into the past’: Glossa, hypertext and the future of legal education". Paul's argument was loosely that some very interesting similarities can be observed between legal education in the centuries before the invention of the printing press, and curent electronic publishing and social software practice. Paul pointed out that in the pre Caxton world, when original texts were rare and expensive - texts like the Bible, or in law, the Roman Institutes and Digests - the practice arose of annotating them in hand writing round the edges, often in different colours and styles. These commentaries - "glosses" - were then sometimes published themselves, arranged as marginalia around the original text, as studiable texts in their own right. These glosses then over years themselves became the subject of scholarly lectures, debate and analysis, with a dense web of mutual cross referencing arising. Such glosses contributed enormously to the development of law in most of Western Europe. The analogies to blogs and hyperlinking are both obvious and irresistably enticing, and the Scottish contingent at BILETA, raised in the mixed legal system tradition on stories of the medieval Glossators and Post-Glossators, were almost too excited to stay in their seats.

So the idea of a law blog as a modern "gloss" stuck in my mind. I once edited a hard copy fanzine called Gloss (gosh! how twentieth century!) so the new electronic Gloss had to be called something slightly more exciting. eGloss was too generic. iGloss was fun and a la mode, but sounded too much like an Apple product, or maybe a paint commercial. GLawss was clever but far too cutesy. panGloss , with its echoes of Voltaire and the best of all things in the best of all possible worlds seemed to strike a suitably optimistic and technophilic note. So panGloss it is. Be seeing you!

Law and the Semantic Web

WWW06 is on in Edinburgh right now. I'm not at it, for various reasons, but I am intrigued by the reports, because it's being run by my future home, Southampton University, in my current home, Edinburgh; and because we're getting the first inklings that there may be as many legal problems about Web 2.0 as we've already had with Web 1.0.

"Hugh Glaser of the University of Southampton ..describing the semantic web, an attempt to make the web more intelligent... [said] Privacy problems could occur,.. because the semantic web deliberately combines multiple sources of information about people and places."

This problem has already reportedly come up in real life with various Grid projects emanating from the E-Science Centre (also in Edinburgh). Large distributed databases are being mined for results by researchers asociated with the high-speed "Internet 2" that is the Grid, working from different institutions in different countries. In such circumstances, it is hard to identify and seperate data controllers, processors and subjects, let alone work out what legal system has jurisdiction, and hence what information privacy rules operate. It looks like the Semantic Web takes this trend one step further. I hope to be working on these kinds of problems with colleagues at Southampton very soon.

Monday, May 22, 2006

Americans wouldn't give a triple ex for that domain name..

The Beeb reports a challenge to the US blocking of the .xxx domain.

"ICM has filed Freedom of Information requests against the US Department of Commerce and Department of State to get uncensored copies of official documents that relate to the creation of the .xxx domain.

In its Freedom of Information filing, ICM said it expected the documents to "shed light on what role the United States government played in the Internet Corporation for Assigned Names and Numbers' (Icann) consideration of ICM's proposal to create and operate a new .xxx domain".

Members of the board voted against the ICM agreement based on inaccurate information about the written statements of various governments concerning .xxx
Icann voted on 10 May to reject ICM's plans following a year of delay over a final decision on the domain. "

Oooohhhh!!! (she says, insightfully).

As various other commentators have said, the US (and one assumes, religious right) opposition to .xxx seems mighty peculiar. Implementing the domain won't create more porn or make it easier to find - it'll just make it easier for ISPs and parents to filter it out. This is what they want, right? (My own feeling is that it's an unintersting squabble anyway, because you are hardly going to convince the Russians and Moldovans to put their porn sites in .xxxx if that DOES mean they'll be more easily filtered..).

How about a domain for .phish ? :-)

Sunday, May 21, 2006

Kitchens of Distinction

Sunday observations on opt in/opt out and junk email ..

Blogscript just finally bought a new cooker. This is something of a personal triumph, but why should you be interested?

Well the Sainsbury's website, whence from this appliance was purchased (at, I should say, a very competitive price) presents the following choice as the purchaser checks out:

Please indicate below whether you would like to receive these:
If you do not wish to receive information by post, tick yes/no box
If you do not wish to receive information by telephone, tick yes/no box
If you are happy to receive information by text email, tick yes/no box
If you are happy to receive information by text message, tick yes/no box

My instinct (and I'm betting that of several hundred thousand others) was to tick NO all the way down on automatic pilot. Then I noticed I actually had to say YES to third and fourth options to NOT get junk texts/emails.

Now Sainsburies are perhaps/probably acting in good faith here; having noticed that the PECD now requires affirmative consent of some kind re spam/texts.

But I still think it's bloody misleading , no??

About time we had a very small SI mandating a standard tick box for consumer opt in/opt out - as the NCC recommended several years back.

Thursday, May 18, 2006

Even Nova-er Terra Nova

New Scientist (inter alia) reports on what they call the "first ever virtual property" law suit:

"Marc Bragg, an attorney from Pennsylvania, US, filed the suit against the company behind Second Life, Linden Lab based in California, US. He accuses the company of deactivating his account after he discovered a loophole that enabled him to buy virtual land cheaply within the game.

The suit, filed in a local district court, seeks financial restitution for Bragg who claims he invested around $32,000 in the virtual land. "This is probably the first dispute of its kind," Bragg says in a statement posted online. "This suit challenges the legitimacy of a virtual intangible purchase of an asset."

Rather US centric, as there have been several other such suits reported already in Asian countries like Korea and China. But it looks like fun all the way - here's hoping neither side decides to settle!

Nul Points to the Royaume Uni..

Strangely little attention seems to have been paid to a rather significant written answer in the House of Commons, reported by that fine organ The Register.

"The government has given internet service providers until 2008 to block all access to websites containing illegal images of child abuse listed by the Internet Watch Foundation.

In a Parliamentary written answer on 15 May, Home Office Minister Vernon Coaker said progress had been made, but hinted that if the last paedophile services were not snuffed out of circulation soon the government might take steps itself to block people accessing them.

The industry-funded IWF had already seen a drastic drop in the number of illegal sites reported to be hosted in the UK, from 18 per cent in 1997 to 0.4 per cent in 2005.

All 3G mobile operators blocked access to paedophile sites over their networks, while all of the biggest internet service providers, representing 90 per cent of broadband domestic connections, were also willingly blocking access."

There is an awful lot of fudging going on here. Yes, the IWF has been staggeringly successful at removing child porn HOSTED in the UK. Those figures are true. This is not least because virtually all UK ISPs receive the IWF URL list of illegal child porn sites, and take action on it, since otherwise they would be liable to action as publishers on notice of illegal material under the EC E Commerce Directive.

But that doesn't mean there's any less kiddy porn out there. Au contraire, it just means it's hosted in other countries than the UK, where the laws are kinder or less well enforced: noteably the US, where hate speech, eg, still thrives under the protection of the First Amendment, and the outlaw lands of the former Soviet Union.

What the government are talking about here is enforcing, not takedown of child porn sites within the UK, which is indeed almost accomplished , but upstream censorship of all feeds coming into the UK so no one in the UK can access illegal porn from sites *outside* the UK. This access-filtering and blocking can be done very efficiently via the technology BT Internet have already implemented, known as Cleanfeed and which has already been rolled out by "agreement" (since many of those who sign up to BT wil know nothing of Cleanfeed and what it does) to those who signed up to get the Net via BT.

Now all this is OK so far, you are no doubt saying. If you want a child porn free feed so that eg your kids or partner can't get at it, then signing up with BT makes sense. Anyone else still has the ability to go to another UK ISP. And if it's illegal to possess child porn (which it is in almost every state in the world now) then why not command your ISPs to block it at source, so no customers can get at it?

Because - and this is to me a rather more immediate worry than the net neutrality debate - any filtering technology dependent on keywords or a URL list, that can efectively block all kid porn access, upstream, invisibly - and which is mandated to do so by the government and MUST be installed by every ISP - can very easily be extended to block any content AT ALL coming into the country that the government finds unlikeable. As also revealed by the parliamentary question,"The Home Office had admitted that it had considered blocking websites that "glorified terrorism" under the Terrorism Act (2006). It said it was not policy to require ISPs to block content, but added: "our legislation as drafted provides the flexibility to accomodate a change in Government policy should the need ever arise." (And there is some rumour that the govrnment had considered blocking "terrorist" material before this law ever came into force, and which thus may not have been illegal at all at the time.)

I'm no free speech nut, but that last sentence quoted sends chills down my spine. This is the technology that could turn us into China, tomorrow, and the nice bit is, most non-techy people would never even notice. Banned books get headlines, banned newspapers get marches in the streets : banned websites, or pictures, disguised behind the ubiquitous error messages of the Net, rarely get noticed. And while Google providing a censored service to its customers in China dominated the tech press in the US for weeks, here, the UK - the state, not a private company - proposing China style censorship tools as part of compulsory legislation for all ISPs, doesn't even seem to have made the BBC website. (And remember . we aren't China : they don't have to use these tools to close down sites abraod that are politically dubious. They could use them to block P2P downloading sites, or sites flogging warez, just as easily.)

Anyone else feel even a tad worried?

Vive La France!

One of the ideas I've toyed with a fair bit over the last year or so is whether there's an argument, for purposes as various as competition law, and public liability to implement human rights protection, to treat Google as a quasi-public body. Google earns about 80% of the search revenues of the word right now, has a clear stranglehold on the market and provides what almost everyone would now concede is an essential public service. Yet Google operate , quite reasonably, as a public corporation, accountable to no one but their share holders.

The situation would of cousre change if Google had a reasonable competitor - but both Yahoo! and MSN seem to have failed in that department. Now however the French have come to the rescue!! Or rather the EU, with an alleged "Google-killer" named Quaero, which as everyone with a Latin O Level knows means "I ask". According to the Beeb:

"European politicians seem worried about the supremacy of the Americans in cyberspace. French President Jacques Chirac has unveiled five grand Europrojects backed with public money to help counter the prevailing American technology influence.

Among them is something called Quaero, backed with some 250m euros of public funds. In most accounts of it, Quaero has been billed as an EU attempt to build a publicly funded Google killer. "

The whole project appears to be still under wraps with no details as yet. But even if it provides pinpoint search accuracy and makes drinks at the same time, will the English really choose to use a French search engine? -)