Wednesday, September 26, 2007

ILAWS launch, October 17 2007

The official press release!!

If anyone reading is in the area, or fancies coming out to quaint ol Hants do register as described below - or email me if you'd like a pesonalised invite :) There will be free drink!

Investigating the internet’s impact on business


The role of the internet in today's business world and the creation of new business models, in particular the impact of websites such as Facebook, are explored at the launch of the
University of Southampton’s Institute for Law and the Web at Southampton (ILAWS) Annual Lecture.

Professor Chris Reed, Chair of Electronic Commerce Law at Queen Mary College London, will give the inaugural lecture ‘Doing business online—how to avoid the legal pitfalls’ at the Turner Sims Concert Hall on Wednesday 17 October at 6pm.

The lecture marks the start of innovative new partnership between the University and Thomas Eggar LLP, a leading law firm in the South.

The School of Law at the University of Southampton founded ILAWS in 2006 to explore the legal issues and opportunities associated with the internet, the web and digital technology.

ILAWS is a unique interdisciplinary research centre that combines legal expertise in key areas such as information technology law, e-commerce, IT law and public policy, and intellectual property law. The Institute looks at the crucial current issues for commerce and government, alongside cutting-edge ‘future-gazing’ to discover what the legal issues of the future will be.

Quote

To register your place at this free event, please visit

www.thomaseggar.com/ilaws or

email simon.bomford@thomaseggar.com

For further information on the work of ILAWS please visit: www.soton.ac.uk/ilaws

Chieftain of the Pudding race

Via Thomas Otter

The strangest business model yet - get telephone calls for free if people can listen in and append ads.

"There's a new Skype competitor, dubbed ThePudding, on the Web. And ThePudding is completely free*. All you have to do is agree to let Pudding Media listen in on your calls. To compensate users for the breach of privacy, the company claims, "ThePudding uses breakthrough technology that makes your conversations fun and interesting." In other words, anyone using ThePudding will be served contextual ads based upon topics overheard in your conversation! "

Both Thomas and Pangloss agree that it may be legal, but wow, it's just damn weird. In some ways, it's just Gmail for phones - people already seem moderately happy with a model of free email storage in return for content of emials being scanned and ads appended.
But telephone conversations are so much more personal and intimate that, well, Pangloss would not sign up.

We seem to be approaching the furthest limits of the "it's ok if consent given" privacy model here - a model which already seems in the web 2.0 context to be entirely broken.

Monday, September 24, 2007

GikII 2 ppts: I'm in your legal system eating your brain

The GikII 2 presentation powerpoints are now all up and available and there is some fabulous stuff there.

It would be impossible and invidious for the chair to pick the best paper, but it is worth mentioning what was surely the best powerpoint - namely Daithi Mac Sithigh, Trinity College Dublin: “I’m in ur tube blocking ur internets: The Politics, Perception and Parody of Network Neutrality Legislation” which invents a whole new genre of "LawL Cats" (c. L Edwards, 2007) and manages to do an amazing job of explaining the magnificently difficult topic of Net Neutrality in Europe using cat macros.



Line of the day : "I baked you a constitution, but I ated it".

Jordan Hatcher's exegesis on “Drawing in Permanent Ink: A Look at Copyright Law and Tattoos”, has already been picked up by Boing-Boing .

I'd also recommend looking for sheer novelty and unexploredness around

- my colleague Caroline Wilson of Southampton's future gaze into 5-sense virtual worlds and how trademark law might deal with protecting smells, tastes and feelings;“Trade mark Law in an online future – coming to its senses?

- Thomas Otter's thoughtful consideration of how in the rush to Web 2.0 the issues of accessibility are. as usual , being left way behind - “Web 2.0 and Accessibility

- and Judith Rauhofer of UCLAN's fascinating linking of the risk-averse society of late modernity we now live in and the dangerous calculus that is emerging between security,

privacy and risk ; UCLAN, "Privacy is dead – get over it: Art. 8 and the dream of a risk-free society" .

Sunday, September 23, 2007

Dawkins v You Tube and the World

More trouble with You Tube and the DMCA.

Let's see if we can get this one straight.

Dawkinsites ("Rational Response Squad") post videos anti-creationism on You Tube.

Creationists get said Videos taken down by claiming NTD - that said vids contained their copyright material.

Dawkinsites plead fair use to no avail.

You Tube pull Dawkinsites YT account for making repeated complaints (says Wired).

Wow, I'm glad I'm not YT's Press agents ..

This is a good example though of why You Tube's much awaited Claim Your Copyright technology will NOT solve all problems relating to copyright and NTD - specificially where fair use, fair comment, freedom of expression etc are involced.

Whither the public domain and critical journalism in a world of fully water marked and automated copyright-material takedown?

Thursday, September 20, 2007

Web 3,0 arise

Via Rowena Rodrigues' e-identity blog - a very interesting piece bringing together some thoughts on web 2.0, the semantic Web , social software (not just social networking software) and a possible new approach for defining web 3.0 (or web thingy as Chris Reed has now famously christened it).

"For those of you who don't like terms like Web 2.0, and Web 3.0, I also want to mention that I agree --- we all want to avoid a rapid series of such labels or an arms-race of companies claiming to be > x.0. So I have a practical proposal: Let's use these terms to index decades since the Web began. This is objective -- we can all agree on when decades begin and end, and if we look at history each decade is characterized by various trends. I think this is reasonable proposal and actually useful (and also avoids endless new x.0's being announced every year). Web 1.0 was therefore the first decade of the Web: 1990 - 2000. Web 2.0 is the second decade, 2000 - 2010. Web 3.0 is the coming third decade, 2010 - 2020 and so on. Each of these decades is (or will be) characterized by particular technology movements, themes and trends."

A Manifesto for Inertia in a Web 2.0 World

After three days of running conferences, firstly the SCL/Herbert Smith sponsored "Law 2.0" event, and then the glorious GikII, I am currently too braindead to do much other than stare into space, vaguely respond to my stacked up email, and make virtual glub glub goldfish noises (coming soon, no doubt, to a Facebook app near you.)

Many thanks to all involved in speaking, participating, watching ,asking questions and administering ; you were all magnificent. More thoughts may follow.

In the meantime however, I have been deputised by the ever-wonderful Chris Reed of Queen Mary to publish the below on his behalf, as he has no blawg of his own. (During the course of a discussion on Tuesday, Chris opined that he does not blog, not as any normal person might have expected, because he is too busy, but because he thinks he can influence policy better by fully formed argument in articles and books, than by hasty scribbles on a blog. Probably right. I personally blog as I said, both to organise the legal information deluge to my own advantage (instant tagging, summary and first critical thoughts, to be come back to later) - and because it's a great way to get in touch with interesting people, have fun, and incidentally build a reputation :)

Take it away, Chris.

"A MANIFESTO FOR RADICAL INACTION

To: All those concerned with the regulation of Web 2.0 who know enough
to know that they know nothing.

1. When, as they will, politicians take up the cry of commentators that "This is awful. Something must be done!" we must resist them to our last breath. Laws about the internet made this way have consistently failed to achieve their aims and produced unintended, unfavourable consequences. It always ends in tears.

2. For the time being we must preserve the liberties of online intermediaries so that Web 2.0 can continue to evolve. One day we will understand what responsibilities they can fairly be asked to shoulder. Meanwhile we must muddle along, extending and adapting our current laws to new problems as best we can. If something really must be done, we should question and question again until satisfied that it will not do more harm than good.

3. So far as we are able, we must divert lawmakers into fixing problems that we at least vaguely understand. The most pressing of these are online privacy and intellectual property rights in the new Web 2.0 creations. Fortunately both these require years of international negotiation, which will give us time to identify the best solutions.

We owe it to the future to prevent the mistakes of the past. Aux armes
Netoyens!"

Comments, questions? :-)

EDIT: Rowena Rodrigues has created a neat back-of-a-credit-card version of Reed's Rules here.

"1. LEGISLATE NOT IN HASTE, NOR GET CARRIED AWAY BY THOSE THAT KNOW NOT WHAT TO DO (BUT LIKE TO PRETEND THEY DO!)

2. LET WEB 2.0 BLOSSOM

3. WHAT (LAW THERE) IS, MUST BE EXTENDED AND APPLIED.

4. AND WHILE WE FIGURE OUT THE BEST SOLUTION, IP AND PRIVACY MUST TAKE CENTRESTAGE!"


Ps other comments on legal blogging from the participants of the SCL Law 2.0 blogging debate :

- "Just say no."
- "Choose life."
- "I can't believe how obsessed you guys are with your Technorati ratings. I don't even know what mine is." - me
- "..Oh, you're about, maybe, no 40..?" (Technollama)
- "Since I started blogging my sex life has ended". (Anon , but see above.)
- "I don't know what you guys are complaining about, I got laid by blogging!" (GeekLawyer - naturellement).

Don't let this put you off , guys and gals..!

Wednesday, September 05, 2007

Facebook and privacy returns

Facebook are opening up their site to being Google-searchable. Hark! I hear a million privacy activists screaming.

But wait - they're actually doing it RIGHT.

a. They're only allowing name and profile pictures to appear in search results - not all the rest which tends to include highly personal material.

b. everyone appears to be getting prominent notice IN ADVANCE that they can opt out of their info being released onto Google

c. most impressively, if like me (and I imagine rather rarely) you'd already opted to "hide" on facebook, ie, not be searchable by name in their listing, you are automatically opted out of the Google release.

This appeared at the top of my FB profile this morning:

"Facebook now enables anyone to search for Facebook users who have public search listings from our Welcome page. In a few weeks we will allow users to make these public search listings visible to search engines like Google. Public Search Listings only include names and profile pictures.

Because you have restricted your search privacy settings your public search listing will not be shown. If you want friends who are not yet on Facebook to be able to search for you by name, you can change your settings on the Search Privacy page.

No privacy rules are changing; if you do choose to make this public search listing available, anyone who discovers your public search listing must sign up and login to contact you via Facebook. "

This strikes me as for once a good example of how privacy on line in web 2.0 ought to be handled - congrats to FB.

You could argue that a site like FB should not open itself to Google at all (in the interests of default privacy, etc etc) but the fact is that sites like Spock.com are already begining to scrape social networking sites like FB and make the data they contain searchable with no user opt-out or notice, and dubious supervision - so this at least pre-empts such attention, and gives the user some control.

It's also interesting that this is a case of the market dovetailing with privacy-enhancing code. FB WANT you to sign up for FB and go to their site to read that highly personal stuff - not read it on Google away from their adverts and apps (or on Spock.com).

LiveJournal, by comparison, an open source blogging site normally regarded as fairly privacy conscious, don't care (much) about ads (they make money from paid subs and are run by volunteers), so they also don't stop you allowing spiders to grab your whole blog. User choice prevails and as we all know by now, user choice when the default is no privacy, usually means disclosure by inertia. (You can opt out of spiders on LJ too, of course - but the option is distinctly not that obvious.)

Friday, August 17, 2007

My Brilliant Career :-P

Pangloss has been a bit lax in not indicating that the programme for GikII 2 is now up. It is very packed and should be very fun.

Similarly the provisional programme for the adjoining SCL/Herbert Smith Law 2.0 workshop is also up.

Both these events are now pretty much full, but if you are so inclined it may be possible to squeeze in.

We now return to our scheduled last 3 days of holiday:-)

AllOfMP3.com not Illegal- Official! (but do we care?)

This seems sufficiently remarkable to record without comment:

"A Russian court found the former boss of music download Web site www.allofmp3.com not guilty of breaching copyright on Wednesday in a case considered a crucial test of Russia's commitment to fighting piracy.

The allofmp3.com Web site angered Western music companies by undercutting the price of downloads in deals they said breached copyright law.

"The prosecution did not succeed in presenting persuasive evidence of his involvement in infringing copyright law," said judge Yekaterina Sharapova.

..

Kvasov [owner of AllOFMP3.com} always said he was within the law because the site paid part of its income to ROMS, a Russian organisation which collects and distributes fees for copyright holders.

The judge agreed with his defence.

"Everybody who uses soundtracks has to pay a certain amount of their income to the rights holders and this company has done that," she said. "MediaServices has paid a certain amount of money to ROMS."


Any Russian copyright experts out there care to comment?

And how far if at all does this affect the liability of those who download tracks in the UK from AllOfMP3.com's successor site www.mp3sparks.com in Russia? Rome II, which was recently finalised, indicates that in a transnational tort, the governing law is "the law of the country in which the damage occurs or is likely to occur , irrespective of the country in which the event giving rise to the damage occurred" (Art 4) .

Unfortunately this relatively clear provision is not the one that applies - instead Art 8 provides that the governing law in the case of non-Community-wide IP rights is instead " the law of the Member State in which the act of infringement is committed". Which is um, as clear as mud. The recitals however confirm that this is intended to mean the traditional IP IPL standard of the lex loci protectionis. "Traditionally in Private international law, disputes concerning national IP rights are governed by the lex loci protectionis. That is the law of the country where protection is sought. Where there is an infringement, this law coincides which the law of the country where the acts of infringement were committed." (stolen from the helpful IP-Kat.) Pangloss is still uncertain what that means that if a work in which UK copyright exists (eg a Kaiser chiefs song) is downloaded from a Russian server to a UK PC. One assumes it means that if the case is raised in UK courts, UK copyright law is applied hence there is still an unauthorised copy made and hence infringement.

So despite this court case, the answer "oh it's OK but it's legal in Russia!" appears to remain somewhere between a red herring and a red rag to a BPI bull :)

Wednesday, August 15, 2007

Summer Survey Time!

My colleague Jordan Hatcher asks me to pass the below on..

"**New survey on open content licences**

==Use of open content licences by cultural heritage organisations==

The Eduserv Foundation is funding a study into the use of Creative
Archive, Creative Commons and similar open content licences by
cultural heritage organisations in the United Kingdom. The study is
being led by legal consultant Jordan Hatcher of
opencontentlawyer.com. The survey is available here:

https://www.surveymonkey.com/s.aspx?sm=L3x_2b1lQJxqu7KdfK587AeA_3d_3d

This survey is open to UK-based cultural heritage organisations such
as museums, libraries, galleries, archives, film and video
organisations, broadcasters, and other organisations that conduct
cultural heritage activities.

The goal of this study is to provide information on the actual use of
Creative Archive, Creative Commons, and similar licences. This
information will be useful to decision makers and interested
professionals in the cultural heritage sector, and for local and
national government and the HE and FE sector. The study will be
conducted from now through to the middle of September and a report
will be made available in October.

If you are a member of a cultural heritage organisation, whether or
not you currently use Creative Commons or Creative Archive licences
(or even know what they are!), your participation is needed to make
this study a success.

Again, the survey is available at:
https://www.surveymonkey.com/s.aspx?sm=L3x_2b1lQJxqu7KdfK587AeA_3d_3d"

Saturday, August 11, 2007

HL Report on Personal Internet Security

Pangloss is on holiday at the Edinburgh festival and will be for a bit to come (feckless academics I hear you murmur) but is breaking radio silence to announce that the above much-awaited report is out.

Analysis to follow but right now you can see what my mate Ian says over on Blogzilla. As Ian notes, the Report's proposals seem to point along the lines that academics including myself have been suggesting for some while eg increased responsibilities to implement and encourage security on the Internet on inter alia banks, software writers and ISPs, with the aim of creating a shared "security commons". Encouraging stuff.

Monday, July 23, 2007

Life Is What Happens


Pangloss is one day back from a fantastic weekend in Leicester which had absolutely nothing to do with IT Law or even web 2.0 (yes this is possible, although you do have to swim to get there) and is packing again(or rather adding clothes to unpacked bag!) before she sets off at unearthly hour to the Berlin Law and Society Conference - where she is rapporteur to a multinational panel on privacy and security. If you are reading this and attending (and lord knows , it has 40 concurrent streams, so I expect to meet everyone I've ever known in academe..) then do say hi.

GikII 2 abstracts, meanwhile, are now closed: we have been (delightfully) imundated and I hope to get back to all who sent in submissions shortly after my return on 30 July. There may however be slight hiatus as I have 2 cats to transport to Cambridge and then Edinburgh..

Which all makes me think rather of the above :)

We are on at 8.15am Wed (back to Berlin) which was a time I thought I needed to know no more of post primary school:( Strong coffee will be required.
I am talking about privacy, security and convenience, the lesser spoken-of trio rather than dilemma; my colleagues are speaking on everything from Puerto Rican constitutional law and protection of privacy, to security defaults, to corporate data breaches. Should be fun.

There is also now a flyer for Pangloss's next venture at http://www.scl.org/event.asp?i=1582,which is the SCL workshop on Law 2.0 spoken of before, with limited low rate places for academics and students - hurry if you want to attend, as places are going fast!

Finally, a date for your diaries: ILAWS, the Institute for Law and the Web at Southampton, will be officially launched on October 10 2007 with a lecture by the ever entertaining Professor Chris Reed of QM College London, and following reception - do let me know if you are interested in coming and I'll put you on the list for more details nearer the time.

Real Comment, including German and French You Tube-style cases, and the ECJ ruling that ISPs cannot be required to filter out P2P traffic, follows soon!

Wednesday, July 18, 2007

Harry Potter and the Subtle Hand of Surveillance

My very smart colleague Judith Rauhofer of UCLAN has made the Telegraph web section today on the back of the upcoming Potterdamerung (the best coinage of the current media drench). What she's actually talking about is the paper she gave at last year's GikII (inter alia) and very good it was too. It is now published as "Defence against the Dark Arts: How the British Response to the Terrorist Threat Is Parodied in J K Rowling’s “Harry Potter and the Half Blood Prince” (2007) International Journal of Liability and Scientific Enquiry (inaugural issue).

I feel very proud:)

Tuesday, July 17, 2007

And yet more Facebook

Fascinating piece from Wired as counterpoint to previous post, via Andrew Ducker.

"For longtime users, the influx of grownups means that information once intended for a circle of fellow students is now available for anyone to see. That has introduced a new social conundrum: Deciding whose invites should be accepted -- and how much of your profile they should be able to see.

"You can't really unfriend your mom," says Hillary Woolley, a junior at the University of California at Davis. "So I've been upping my privacy settings."

Facebook lets users specify what data is displayed in searches, and users can customize a "limited" view for select friends. But it's time-consuming to set up customized views for individuals, so most people are simply walling off their profiles to non-friends. "

Combined with the post below, and similar incidents worldwide, I'm betting on FB moving from a default of "openness" - based on a core audience of high school kids who want to share as much as POSSIBLE with each other - to a default of "open only to Friends" - based on a norm of networking with chosen persons. At the very least, I expect to see the notion that everyone in your Network - where a Network is a town not a school/university - seeing everything you have by default , to disappear.

OR, alternately, a divesification of the sociual networking sites of choice (My Space for music, FB for real friends, Linked IN for business - tho no one in the UK seems to like Linked In?)OR, migration of the herd to a better FB with a better/easier privacy-friendly interface.

Is privacy finally a feature not a bug? Interesting times..

And more facebook..

So what does everyone think of this story?

http://technology.timesonline.co.uk/tol/news/tech_and_web/the_web/article2087306.ece

Leaving aside whether Oxford should or should not have conceivably antiquated rules forbidding students from celebrating (oh f'heavens sake!), who is most in the wrong here?

Should the girl who has been caught have checked to make sure her Facebook "privacy" settings actually stopped everyone seeing her pix of drunken devastation? One assumes, as my colleague Technollama has pointed out, that she did not necessarily reasonably have to know she was under surveillance - if she had joined the Oxford University network, then anyone else in that network (which I suspect, though do not know for sure, would embrace anyone who signed up with an ox.ac.uk email address, student or staff)would be able to see all her posts, contacts, photos, etcf etc - even if they were not known to her as a "Friend". To exclude that surveillance, she would have to have taken explicit privacy steps which anecdotally few people (particularly maths and philosopy graduates:) on Facebook seem aware.

Or to look at it another way; were her "reasonably expectations" of privacy met?

Should Facebook themselves have offered privacy to my-Friends-Only as the default, not leaving it up to the sense of people who think sparying each other with champagne and flour is the height of wit?

Should info gathered on Facebook in such circumstances be regarded as de jure "private" and therefore inadmissable as evidence (like evidence gathered in private houses when police break in without a warrant) - or is that as silly as saying that if the proctors had seen flour battles in the street they shouldn't have been able to use the evidence of their own eyes? Should evidence from facebook be not used, rather as insurnace companies have been asked not to use evidence of genetic testing? But what about a comparison to the case of people who are sacked from their jobs because they say daft things about their employers on their blogs? it seems difficult to disticnguish the two types of case.

If pictures existed on her site which showed the flour/champagne battles, is it so res ipsa loquitur that to talk of privacy and evidence and default settings is just silly and she should take her lumps?

Is Facebook a "private" or "public" space??

I think this is going to be my paper for the Berlin Law and Society Conference next week.It's meant to be on privacy and security but hell, I'm sure I can twists it round :)

Monday, July 02, 2007

GikII 2

In September 2006, Technollama and yours truly organised the first GikII workshop, a tremendously entertaining gathering of like-minded people willing to discuss the interface between geek culture and the law. The resulting workshop provided a look at the virtual personality of avatars; legal aspects of fandom, anime and even hentai; privacy in the novels of Harry Potter; technophobia as a drive for regulation; the ecological impact of computing; and more mentions to the three laws of robotics than you could ever expect in a legal workshop.

We are now officially announcing the venue for GikII 2 on September 19 2007 : University College London. Very many thanks to Ian Brown for arranging this. The workshop is free to speakers who have abstracts accepted, but a (very) limited number of non-speaker places are available at a nominal £30 GBP. There will be a conference dinner arranged at a nearby Italian restaurant which will again be free to speakers only and at reasonable costs to others. There is a very limited amount of money available to subsidise attendance - please contact me on l.edwards@soton.ac.uk for details - preference will be given to those with no home institutional funding, especially PhD students.

There is an online registration form here. Preference wil however be given to those whose abtrsacts are accepted. Because we're trying to be all Web 2.0, you can also join the group GikII on Facebook, which already has 24 members and rising!.

There is still time to get in abstracts but only just!!! The deadline is July 15 and as we already have a large number of submissions it is unlikely to be extended so get your marvellous ideas in NOW. 500 words max, to myself as above or to a.guadamuz@ed.ac.uk .

THIS IS GIKII!!

Thursday, June 28, 2007

SCL: Web 2.0 Conference

Aha! My mate Simon Deane-Johns, the CEO of Zopa the innovative P2P lending company, has come good on his stated intention to start a blog in the wake of the enthusiasm generated by the SCL conference (and not all of it about FaceBook and virtual detachable genitalia, either.)

His write up is here.

Nick Holme's of Binary Law has one here. I particularly like his reminder of the phrase of the conference: Tom Ilube's daughter describing her father's efforts to keep up on the social network scene as "so January".

Pangloss took lots of notes - and will try to transcribe some of them before it becomes Too Late.

Wednesday, June 27, 2007

Extreme porn bill

Busy day today; after this, no more spodding:)

The Extreme Pornography law has been published, tucked away in the Criminal Justice and Immigration Bill.

The key section is the definition of an "extreme" image, possession of which will be a crime, and which is as follows:
s 64(6) "An “extreme image” is an image of any of the following—

(a) an act which threatens or appears to threaten a person’s life,

(b) an act which results in or appears to result (or be likely to result) in
serious injury to a person’s anus, breasts or genitals,

(c) an act which involves or appears to involve sexual interference with a
human corpse,
(d) a person performing or appearing to perform an act of intercourse or
oral sex with an animal,

where (in each case) any such act, person or animal depicted in the image is or
appears to be real."

In an age where "torture porn" is not just the height of chic but appearing in a multiplex near you as I write (Hostel 2, anyone?) frankly I do not think this is unreasonable. (Classified films are in any case excluded from s 64 so no one is attempting to make possession of a Casino Royale DVD illegal because it involves images of murder and torture.) The usual suspects are however predictably upset.

Phew

For some reason (OK, to avoid writing about data protection, let's admit it) Pangloss has FINALLY after about a year, re-organised her blogroll, including many of the blogs of the great speakers I've met here and there over the last year, in particular at GikII last year.

If you think I've unjustly ignored your pride and joy, please comment and let me know! I'm not attempting to blogroll every blog in the universe, more the ones which reflect the British scene and especially those focusing on my own current obsessions: privacy, security, virtual worlds, Google and "law 2.0".

FaceBook Brought to Book?

My colleague Ian Brown of Blogzilla reports on an interesting post on why Facebook may be violating European privacy law.

The article reveals that creating an "exploit" in FaceBook - ie hacking the privacy of unsuspecting users - is trivially easy. All you have to do is use Advanced Search and you can search across controversial (and in European DP language, "sensitive") pieces of data such as Religion and Sexuality in apparently unlimited numbers of profiles. This is true even if the user has taken steps to protect the privacy of their data (see below). As Ian comments this is a security failure on FB's part, which should have been trivially easy to fix in their code.

Having just returned from the SCL Conference where it was revealed that over 3 million people in the UK are on Facebook (including apparently nearly every corporate lawyer in the UK.. and definitely at Allen and Overy :-) and it is growing in the UK at 6% per WEEK, this is serious, er, excrement.

Pangloss's own experimentation proves that in fact hacking FaceBook is even easier than this. Suppose you want to stalk person X who you know lives in London. All you have to do is set up an FB profile, join the London network - which requires NO validation, certainly not a University of London email address or the like - and suddenly you can see all their personal details - some of which (on brief inspection) are highly revealing , of social and sexual data that many people would not want public. Of course they may not have joined the London network - but very often it will be very easy to guess what network the stalkee is in.

Of course, will say FaceBook, you, the stalkee, can stop this. You can in fact change all your privacy defaults on FB so no one can see ANYTHING on your profile site unless they are people you have accepted as "Friends". (Pangloss has just gone and done this, with a vengeance.) Fair enough, except that the default privacy settings on FB are almost entirely in favour of disclosure and there is very little direction or instruction on the site to "change these defaults for heaven's sake, 300,000 people can see who you want to sleep with".

As the blogger above, Quiet Paranoia (great name) comments, "Users cannot be expected to know that the contents of their private profiles can be mined via [advanced] searches, and thus, very few do set the search permissions associated with their profile."

I agree. If an er um respected professor of privacy law can take some while to realise how exposed her data is on FaceBook, then it is unreasonable to expect children of 16 or 17 (FB is associated with high school students but the T & C say 13 up) to make these kind of difficult judgment calls, when what they are really concerned about is popularity and finding out about the good parties?

FB will say that they have provided opt-in to privacy, and anyone who does not avail themselves of the tools available is impliedly giving consent to processing of their data. They wil also point to their privacy policy which does not give the impression of overwhelming concern about the remarkably weak default privacy protection and indeed, security, offered by FaceBook.

"You post User Content (as defined in the Facebook Terms of Use) on the Site at your own risk. Although we allow you to set privacy options that limit access to your pages, please be aware that no security measures are perfect or impenetrable. We cannot control the actions of other Users with whom you may choose to share your pages and information. Therefore, we cannot and do not guarantee that User Content you post on the Site will not be viewed by unauthorized persons. We are not responsible for circumvention of any privacy settings or security measures contained on the Site. You understand and acknowledge that, even after removal, copies of User Content may remain viewable in cached and archived pages or if other Users have copied or stored your User Content."

Even Pangloss, who is no privacy fundamentalist, does not think this is good enough, particularly in relation to "sensitive personal data" where "explicit consent" to processing by third parties is required. (Is searching via key words "processing"? Almost certainly - see Art 2 of the Data Protection Directive which includes "retrieval" whether or not by automatic means. )

But FB will again say : Everyone who signs up to FB assents to the T & C. Does that mean they have given the requisite explicit consent to processing of sensitive data even by "unauthorised third parties"? Even if in pure contract law the T & C can be read this way, at this point both DP law and the Unfair Contract Terms Directive should surely both converge to make such a clause either void or unenforceable?

In comparison, another social networking site where Pangloss hangs out, Live Journal, has not only very sophisticated privacy controls, but also a culture of discussion and awareness that privacy and openness can be manipulated by the software. Of course privacy breaches do still occur (via "cut and paste fairies" for example) but they are pretty rare.

Do we need a legal solution? Is there a case for extension of DP law to cover the setting of defaults on social network sites? Should privacy not be the default, by law (perhaps with some exceptions to preserve functionality, such as name and network) and openness the opt-out, rather than the reverse? Maybe. Maybe all that is needed is an Industry Code of Practice combined with some upping of awareness of the issue. However with the number of people - especially young pre-employment proto-citizens - involved in web 2.0 sites rising by the minute, this really does seem an issue which is not merely knee jerk alarmism and should not be swept under the carpet. First year students may not care now about spilling their sexuality and contacts to the world: they may when they are older, wiser and looking for employment :)

Another suggestion might be the automatic expiry of social networking data after say six months unless the user chooses to opt in to keeping their data out there. Viktor Mayer-Schoenberger has made this kind of suggestion recently. In social networking sites where the whole business model is based around large databases of personal data, data is routinely retained apparently forever. Data retention is another area where the DPO authorities might want to have a bit of a look at whether the law needs tweaked.