The Security Lab people at Cambridge - including the esteemed Ross Anderson - have their own blog: full of interesting stories about computer security, including related legal issues.
I'm just back from WEIS, the Workshop on Economic Issues in Security run by that self same man : and boy, my mind is blown. I have things I now desperately want to write/research about selling zero day exploits, cyber insurance, and privacy seals , value of (actually less than zero) ; but I'm currently just too ill ! as I also came back with a bug and a high temperature.
But very shortly there will be a very long post about fascinating papers I've seen! In the meantime try Bruce Schneier's summary, with pointers to some of his highlight papers.
Also gratified by more abstracts that have arrived for GikII while I was away: it's looking goooood, kids!
A UK-based cyberlaw blog by Lilian Edwards. Specialising in online privacy and security law, cybercrime, online intermediary law (including eBay and Google law), e-commerce, digital property, filesharing and whatever captures my eye:-) Based at The Law School of Strathclyde University . From January 2011, I will be Professor of E-Governance at Strathclyde University, and my email address will be lilian.edwards@strath.ac.uk .
Friday, June 30, 2006
Sunday, June 25, 2006
New Privacy Laws for the USA?
Two interestingly almost simultaneous calls for a uniform set of privacy laws for the US, applicable to private as well as public sectors, have emerged in the last few days.
OUT-Law.com reports : "Google, Microsoft, Intel, eBay, HP, Oracle and Sun are amongst the signatories to a statement calling for personal information to be protected across the US. Non-profit lobby group the Center for Democracy and Technology organised the companies into the Consumer Privacy Legislative Forum.
"The time has come for a serious process to consider comprehensive harmonized federal privacy legislation to create a simplified, uniform but flexible legal framework," said the CPL Forum's statement. "The legislation should provide protection for consumers from inappropriate collection and misuse of their personal information and also enable legitimate businesses to use information to promote economic and social value." "
Meanwhile Hillary Clinton has called for a Privacy Bill of Rights. Hilary,a likely Democratic candidate for 2008, stated that she wanted to to create a "privacy czar" within the White House to guard against recent problems like the theft of personal data from the
Department of Veterans Affairs'. She also wants legislation to let consumers know what information companies are keeping about them and how it is used, and create a tiered system of penalties for companies who are not careful with consumer data. "Clinton also waded into the debate over anti-terror eavesdropping. ..Clinton said any president should have the latest technology to track terrorists, but within laws that provide for oversight by judges."
And a San Francisco Chronicle report notes inter alia that technological invasion of privacy is not only accelerating but is also becoming more and more consumer friendly and "cool".
"Americans' rights to privacy will be tested even more in the next few years as biometric technology creeps increasingly into everyday arenas. For example, on the campus of UC San Diego, biometric experts are testing a soda machine that uses both fingerprint and face-recognition technology. The machine is in a lounge for grad students in UC San Diego's computer science building.
"The students are very excited about getting it working," Serge Belongie, a UC San Diego associate professor of computer science, says in a phone interview. "People think it's very cool. ... No one uses money. They have accounts. What would be fun is if (the machine) recognizes you and says, 'Would you like your usual?' "
As I have often suspected, the report indicates that although biometrics can be far more privacy threatening than ordinary methods of ID consumers favour them due to convenience factors:
"If UC San Diego students are reluctant to use the machine, their privacy concerns are outweighed by convenience -- a sentiment echoed in survey after survey on biometric technology. In March, Unisys Corp. released a report on public perception of "identity management" that said convenience and efficiency were the two biggest reasons consumers would use biometric technology. (The most preferred biometric methods are fingerprints and voice recognition, according to the survey. The least preferred, because of its perceived intrusiveness, is an iris or eye scan.) "
But not everyone is enthralled by the "brave new world in aisle 5":
"Pay By Touch admits it has encountered some resistance among shoppers it approached in supermarkets that already use the company's fingerprint service. But Morris, its president, says many of these customers are quickly won over by the convenience of Pay By Touch, which is free for consumers, and that the company keeps data points based on users' fingerprints, not actual fingerprints. So far, supermarkets in 40 states use the Pay By Touch system. .. The company insists it will never sell users' personal information or fingerprints to anyone else -- a pledge that's backed up in writing when users sign up with the company. But what if federal authorities, citing national security, insist on the finger scan and payment history of a Pay By Touch user? "
The times they are a changing. Last year, at a workshop I organised in Edinburgh, Peter Swire, effectively Bill (not HIlary's) privacy czar during that administration, was pessimistic that post 9/11 there was much scope for the private sector and governmental privacy legislation that the Clinton era might have favoured. Is the pendulum swinging again, in the light of recent personal data scandals, to the point where privacy is a vote-getter in the USA? Watch this space.
OUT-Law.com reports : "Google, Microsoft, Intel, eBay, HP, Oracle and Sun are amongst the signatories to a statement calling for personal information to be protected across the US. Non-profit lobby group the Center for Democracy and Technology organised the companies into the Consumer Privacy Legislative Forum.
"The time has come for a serious process to consider comprehensive harmonized federal privacy legislation to create a simplified, uniform but flexible legal framework," said the CPL Forum's statement. "The legislation should provide protection for consumers from inappropriate collection and misuse of their personal information and also enable legitimate businesses to use information to promote economic and social value." "
Meanwhile Hillary Clinton has called for a Privacy Bill of Rights. Hilary,a likely Democratic candidate for 2008, stated that she wanted to to create a "privacy czar" within the White House to guard against recent problems like the theft of personal data from the
Department of Veterans Affairs'. She also wants legislation to let consumers know what information companies are keeping about them and how it is used, and create a tiered system of penalties for companies who are not careful with consumer data. "Clinton also waded into the debate over anti-terror eavesdropping. ..Clinton said any president should have the latest technology to track terrorists, but within laws that provide for oversight by judges."
And a San Francisco Chronicle report notes inter alia that technological invasion of privacy is not only accelerating but is also becoming more and more consumer friendly and "cool".
"Americans' rights to privacy will be tested even more in the next few years as biometric technology creeps increasingly into everyday arenas. For example, on the campus of UC San Diego, biometric experts are testing a soda machine that uses both fingerprint and face-recognition technology. The machine is in a lounge for grad students in UC San Diego's computer science building.
"The students are very excited about getting it working," Serge Belongie, a UC San Diego associate professor of computer science, says in a phone interview. "People think it's very cool. ... No one uses money. They have accounts. What would be fun is if (the machine) recognizes you and says, 'Would you like your usual?' "
As I have often suspected, the report indicates that although biometrics can be far more privacy threatening than ordinary methods of ID consumers favour them due to convenience factors:
"If UC San Diego students are reluctant to use the machine, their privacy concerns are outweighed by convenience -- a sentiment echoed in survey after survey on biometric technology. In March, Unisys Corp. released a report on public perception of "identity management" that said convenience and efficiency were the two biggest reasons consumers would use biometric technology. (The most preferred biometric methods are fingerprints and voice recognition, according to the survey. The least preferred, because of its perceived intrusiveness, is an iris or eye scan.) "
But not everyone is enthralled by the "brave new world in aisle 5":
"Pay By Touch admits it has encountered some resistance among shoppers it approached in supermarkets that already use the company's fingerprint service. But Morris, its president, says many of these customers are quickly won over by the convenience of Pay By Touch, which is free for consumers, and that the company keeps data points based on users' fingerprints, not actual fingerprints. So far, supermarkets in 40 states use the Pay By Touch system. .. The company insists it will never sell users' personal information or fingerprints to anyone else -- a pledge that's backed up in writing when users sign up with the company. But what if federal authorities, citing national security, insist on the finger scan and payment history of a Pay By Touch user? "
The times they are a changing. Last year, at a workshop I organised in Edinburgh, Peter Swire, effectively Bill (not HIlary's) privacy czar during that administration, was pessimistic that post 9/11 there was much scope for the private sector and governmental privacy legislation that the Clinton era might have favoured. Is the pendulum swinging again, in the light of recent personal data scandals, to the point where privacy is a vote-getter in the USA? Watch this space.
Saturday, June 24, 2006
Alan Moore vs the Copyright fairies
While we're considering pop culture and IT law (great stuff for a GikII paper here!) the IPKat reports that Alan Moore, father of the graphic novel is potentially running into trouble with his latest project,a graphic novel called Lost Girls which is "a meeting between Wendy (of Peter Pan), Alice (of Alice in Wonderland) and Dorothy of The Wizard of Oz) once they have grown up". It is also allegedly "erotic fiction at its finest". Hmm. As every IP lawyer knows of course, there is a specific exception in UK copyright law (s.300 of the CDPA )which grants perpetual copyright in J M Barrie's Peter Pan, which goes to the Great Ormond Street Hospital by virtue of a legacy to the hospital in Barrie's will. And the hospital are apparently deeply unhappy with being connected with this project and its possible paedophilic implications, and may seek to have publication banned in the UK and Europe.
The IPKat suggests that "the hospital [has after 2007] a right to royalties, not the full rights of a copyright owner. This would mean that the hospital could make money from the novel, but not that it could stop its distribution." Others suggest the whole idea of perpetual copyright, even as a pleasing anomaly given the storyline of Peter Pan , should be abolished. Alan Moore himself is no stranger to copyright fights: the tangled tale of Marvelman, Miracleman, Moore, DC, and Gaiman et al is too confusing to even begin to tell here. Moore, after various disputes, has also refused to allow film adapations of any of his works to which he still owns full copyright and has removed his name from adaptations he cannot control, even where they have been critically well received as with the recent V for Vendetta. He is a formidable adversary in respect of his work, and it will be interesting to see where this dispute goes next.
The IPKat suggests that "the hospital [has after 2007] a right to royalties, not the full rights of a copyright owner. This would mean that the hospital could make money from the novel, but not that it could stop its distribution." Others suggest the whole idea of perpetual copyright, even as a pleasing anomaly given the storyline of Peter Pan , should be abolished. Alan Moore himself is no stranger to copyright fights: the tangled tale of Marvelman, Miracleman, Moore, DC, and Gaiman et al is too confusing to even begin to tell here. Moore, after various disputes, has also refused to allow film adapations of any of his works to which he still owns full copyright and has removed his name from adaptations he cannot control, even where they have been critically well received as with the recent V for Vendetta. He is a formidable adversary in respect of his work, and it will be interesting to see where this dispute goes next.
Dr Who and the Semantic Web
Tim Berners-Lee has been round the houses latel;y, proselytising not only for net neutrality (see earlier posts) but also for his baby, the Semantic Web. The Guardian has an informative and occasionally entertaining piece on his efforts.
"..the BBC, one of the organisations that led Britain on to the web, is keen to share some of its data. Tom Loosemore, head of strategic innovation, says the corporation will shortly place online the catalogue of its entire surviving programme library - not the 950,000 television and radio programmes themselves, but the names, transmission details, often production credits and in some cases who is interviewed..
"What is interesting is what the audience does with that data," [he says] although Loosemore imagines that Doctor Who fans will be early adopters. It will be available through an API (applications programming interface) at BBC Backstage (http://backstage.bbc.co.uk), which allows data to be re-used for non-commercial purposes - a model that the Ordnance Survey hopes to follow."
"..the BBC, one of the organisations that led Britain on to the web, is keen to share some of its data. Tom Loosemore, head of strategic innovation, says the corporation will shortly place online the catalogue of its entire surviving programme library - not the 950,000 television and radio programmes themselves, but the names, transmission details, often production credits and in some cases who is interviewed..
"What is interesting is what the audience does with that data," [he says] although Loosemore imagines that Doctor Who fans will be early adopters. It will be available through an API (applications programming interface) at BBC Backstage (http://backstage.bbc.co.uk), which allows data to be re-used for non-commercial purposes - a model that the Ordnance Survey hopes to follow."
Friday, June 16, 2006
Internet libel : why, how and where
It's always good to see empirical research backing things you intuitively anyway :-) I've long asserted in my textbook Law and the Internet that email is particularly defamation-prone because of the odd nature of the medium, which combines the spontaneity of speech with the archiving capacity of text. Now we have actual scientific confirmation of the first point.
"In effect, e-mail cannot adequately convey emotion. A recent study by Profs. Justin Kruger of New York University and Nicholas Epley of the University of Chicago focused on how well sarcasm is detected in electronic messages. Their conclusion: Not only do e-mail senders overestimate their ability to communicate feelings, but e-mail recipients also overestimate their ability to correctly decode those feelings."
Two scientists in the area, Michael Morris and Jeff Lowenstein add "One reason for this, the business-school professors say, is that people are egocentric. They assume others experience stimuli the same way they do. Also, e-mail lacks body language, tone of voice, and other cues - making it difficult to interpret emotion.
"A typical e-mail has this feature of seeming like face-to-face communication," Professor Epley says. "It's informal and it's rapid, so you assume you're getting the same paralinguistic cues you get from spoken communication." "
Which raises an interesting point for various legal systems: if sarcasm or fair comment or "joke" (in rixa in Scots law) is a legal defense, is it to be measured by what the sender meant, the recipient understood, or what the "reasonable man" would have taken out of the communication? Probably the latter in most systems, given libel damages are measured by the damage to the reputation - but what if, as the study evidence seems to show , there is no objective "true" interpretation of email speech, only different subjective interpretations? Oh how postm0dern!
On the more legal front, another new English Internet libel case is Al Amoudi v Brisard and JCB Consulting International SARL [2006] EWHC 1062 (QB). (Via OUT-Law.com )
Ethiopian-born businessman Mohammed Hussein Al Amoudi, who normally lives in Saudi Arabia but spends around two-and-a-half months a year in England, sued Swiss resident Jean Charles Brisard and his Swiss company, JCB Consulting International SARL in the English courts. Brisard claims to be a world expert on terrorist financing. In two reports on JCB's site he made references to Al Amoudi. These suggested that Al Amoudi might be "a knowing participant in the economic, financial and/or terrorist networks of the terrorist Osama Bin Laden". Al Amoudi sued for defamation, seking summary judgment ie judgment without trial of the evidence. The key point on which this was rejected by the court was that Al Amoudi had not proved "substantial publication" in England and this could not be proved. (It was not argued at this stage whether the coments themselves were defamatory.)
Legally, in England, damage in libel cases is presumed, and therefore need not be proven, but, as a norm, circulation figures are provided to back claims of "substantial damage" in cases involving non-English defenders. In this case however, there was a dispute over how long the offending website had been available for, and it was thus submitted only that "publication over the Internet takes place if and only if the material is accessed and downloaded by a third party within the jurisdiction". Crucially, Mr Justice Gray held that "I am unable to accept that under English law a claimant in a libel action on an Internet publication is entitled to rely on a presumption of law that there has been substantial publication".[italics added]. Acordingly the case was denied summary judgment and the claimant must prove publication in the ordinary way if he wishes to proceed.
This is an interesting application of last year's major Internet libel case, Dow Jones v Jameel , [2005] EWCA Civ 75. In that case, only five people in England were shown to have "clicked through" a link on the defender's (DJ's)online Wall Street Journal website, which lead to an allegedly defamatory item. These 5 persons "clicking through", furthermore, included the solicitor of Mr Jameel (the person allegedly defamed)and two of his business associates. Thus, it was argued by the defendant, the court should dismiss the case, as damage to reputation in England that was more than nominal had not been proven.
Several very famous non-Internet libel cases were, however, cited by Jameel as precedents that " under English law there is a presumption of damage in libel cases, [thus] the plaintiffs did not have to adduce evidence of damage arising from the publication of the article in question": see eg Duke of Brunswick v Harmer (1849) 14 QB 185, Shevill v Presse Alliance [1996] AC 959 and Berezowsky v Michaels [2001] 1 WLR 1004. In other words, damage to reputation would be presumed. The Court of Appeal in Jameel upheld these precedents, and furthermore held on review of them that this presumption was still, in practice, irrebuttable. In conventional publication, it is extremely difficult to establish how many people have read a publication, so the presumption of damage makes sense or proof may become a bar to redress in very many cases. However with Internet hit counters, proof of publication in the jurisdiction (& numbers of readers) can become trivially easy. The court nonetheless thought there were good reasons why damage should still always be presumed, and furthermore that such a presumption did not "chill" freedom of expression under the Human Rights Act 1998 and/or Art 8 of the European Convention on Human Rights.
However this was not the end of the story. Jameel's case was still rejected as an "abuse of process". Since this was a non-EU, non-Brussels Convention case, an application to serve outside the jurisdiction of England was necessary, which raised the question of whether 'a real and substantial tort ha[d] been committed within the jurisdiction': Kroch v Rossell [1937] 1 All ER 725, Chadha v Dow Jones & Co Inc [1999] EMLR 724, and Civil Procedure Rules 6.20(8). Since the damage to Mr Jameel's reputation in England was apparently minimal, in the Court of Appeal's view, only "very modest damages" would have been available after what would have been a lengthy and expensive trial. So the case was thrown out as an abuse of process.
LJ Phillips MR noted that : "There have been two recent developments which have rendered the court more ready to entertain a submission that pursuit of a libel action is an abuse of process. The first is the introduction of the new Civil Procedure Rules. Pursuit of the overriding objective requires an approach by the court to litigation that is both more flexible and more pro-active. The second is the coming into effect of the Human Rights Act. ... Keeping a proper balance between the Article 10 right of freedom of expression and the protection of individual reputation must, so it seems to us, require the court to bring to a stop as an abuse of process defamation proceedings that are not serving the legitimate purpose of protecting the claimant's reputation, which includes compensating the claimant only if that reputation has been unlawfully damaged."
This case (which I must shamefacedly admit to having missed when it first came out) is a remarkable step forward, by a cleverly lateral route, from the much-criticised jurisdictional rules on forum non conveniens applied to date by the English courts in Internet-related cases like Berezovsky and Loutchansky v Times Newspapers & Ors Nos 2 to 5 [2002] QB 783. Jameel does not over-rule these cases (inded it could not, not being of House of Lords level). Nor does it impose a US style single publication rule, as Geoffrey Robertson QC has suggested in a number of cases, nor does it change the rules established in The Spiliada [1987] AC 470, as to when England is an appropriate forum (basically, nearly always:-)
But it does provide an alternative route by which to argue, sensibly, that the English courts should not be involved in cases where the circulation of the libelous item in England has been tiny, and the damages in England are therefore also likely to be minimal. This is a giant step forward for opposing the "chilling effect" of the threat of action in England in relation to texts on international websites which essentially have little or no connection to English readers. The Master of the Rolls is to be congratulated.
This author would however suggest that it's still not enough: Internet cases require a total revamp of the rules of forum non conveniens. Imagine if Berezovsky had been argued on post-Jameel rules, for example. That case concerned a tiny circulation of the libellous item in question in England, compared to an enormous circulation in the US - but still a circulation significant enough for more than nominal damages. I suspect the court would still have been forced to take it, even given the addition of the "abuse of process" concept - in other words we have still not budged from the idea that if England is an appropriate forum but obviously not THE most appropriate forum, it will still accept all comers. On the Internet this is clearly turning England into a "libel case magnet" as was asserted during Berezovsky. Given the weight of post-Spiliada authority any change will however require legislation: which will be , one suspects, a long time coming.
"In effect, e-mail cannot adequately convey emotion. A recent study by Profs. Justin Kruger of New York University and Nicholas Epley of the University of Chicago focused on how well sarcasm is detected in electronic messages. Their conclusion: Not only do e-mail senders overestimate their ability to communicate feelings, but e-mail recipients also overestimate their ability to correctly decode those feelings."
Two scientists in the area, Michael Morris and Jeff Lowenstein add "One reason for this, the business-school professors say, is that people are egocentric. They assume others experience stimuli the same way they do. Also, e-mail lacks body language, tone of voice, and other cues - making it difficult to interpret emotion.
"A typical e-mail has this feature of seeming like face-to-face communication," Professor Epley says. "It's informal and it's rapid, so you assume you're getting the same paralinguistic cues you get from spoken communication." "
Which raises an interesting point for various legal systems: if sarcasm or fair comment or "joke" (in rixa in Scots law) is a legal defense, is it to be measured by what the sender meant, the recipient understood, or what the "reasonable man" would have taken out of the communication? Probably the latter in most systems, given libel damages are measured by the damage to the reputation - but what if, as the study evidence seems to show , there is no objective "true" interpretation of email speech, only different subjective interpretations? Oh how postm0dern!
On the more legal front, another new English Internet libel case is Al Amoudi v Brisard and JCB Consulting International SARL [2006] EWHC 1062 (QB). (Via OUT-Law.com )
Ethiopian-born businessman Mohammed Hussein Al Amoudi, who normally lives in Saudi Arabia but spends around two-and-a-half months a year in England, sued Swiss resident Jean Charles Brisard and his Swiss company, JCB Consulting International SARL in the English courts. Brisard claims to be a world expert on terrorist financing. In two reports on JCB's site he made references to Al Amoudi. These suggested that Al Amoudi might be "a knowing participant in the economic, financial and/or terrorist networks of the terrorist Osama Bin Laden". Al Amoudi sued for defamation, seking summary judgment ie judgment without trial of the evidence. The key point on which this was rejected by the court was that Al Amoudi had not proved "substantial publication" in England and this could not be proved. (It was not argued at this stage whether the coments themselves were defamatory.)
Legally, in England, damage in libel cases is presumed, and therefore need not be proven, but, as a norm, circulation figures are provided to back claims of "substantial damage" in cases involving non-English defenders. In this case however, there was a dispute over how long the offending website had been available for, and it was thus submitted only that "publication over the Internet takes place if and only if the material is accessed and downloaded by a third party within the jurisdiction". Crucially, Mr Justice Gray held that "I am unable to accept that under English law a claimant in a libel action on an Internet publication is entitled to rely on a presumption of law that there has been substantial publication".[italics added]. Acordingly the case was denied summary judgment and the claimant must prove publication in the ordinary way if he wishes to proceed.
This is an interesting application of last year's major Internet libel case, Dow Jones v Jameel , [2005] EWCA Civ 75. In that case, only five people in England were shown to have "clicked through" a link on the defender's (DJ's)online Wall Street Journal website, which lead to an allegedly defamatory item. These 5 persons "clicking through", furthermore, included the solicitor of Mr Jameel (the person allegedly defamed)and two of his business associates. Thus, it was argued by the defendant, the court should dismiss the case, as damage to reputation in England that was more than nominal had not been proven.
Several very famous non-Internet libel cases were, however, cited by Jameel as precedents that " under English law there is a presumption of damage in libel cases, [thus] the plaintiffs did not have to adduce evidence of damage arising from the publication of the article in question": see eg Duke of Brunswick v Harmer (1849) 14 QB 185, Shevill v Presse Alliance [1996] AC 959 and Berezowsky v Michaels [2001] 1 WLR 1004. In other words, damage to reputation would be presumed. The Court of Appeal in Jameel upheld these precedents, and furthermore held on review of them that this presumption was still, in practice, irrebuttable. In conventional publication, it is extremely difficult to establish how many people have read a publication, so the presumption of damage makes sense or proof may become a bar to redress in very many cases. However with Internet hit counters, proof of publication in the jurisdiction (& numbers of readers) can become trivially easy. The court nonetheless thought there were good reasons why damage should still always be presumed, and furthermore that such a presumption did not "chill" freedom of expression under the Human Rights Act 1998 and/or Art 8 of the European Convention on Human Rights.
However this was not the end of the story. Jameel's case was still rejected as an "abuse of process". Since this was a non-EU, non-Brussels Convention case, an application to serve outside the jurisdiction of England was necessary, which raised the question of whether 'a real and substantial tort ha[d] been committed within the jurisdiction': Kroch v Rossell [1937] 1 All ER 725, Chadha v Dow Jones & Co Inc [1999] EMLR 724, and Civil Procedure Rules 6.20(8). Since the damage to Mr Jameel's reputation in England was apparently minimal, in the Court of Appeal's view, only "very modest damages" would have been available after what would have been a lengthy and expensive trial. So the case was thrown out as an abuse of process.
LJ Phillips MR noted that : "There have been two recent developments which have rendered the court more ready to entertain a submission that pursuit of a libel action is an abuse of process. The first is the introduction of the new Civil Procedure Rules. Pursuit of the overriding objective requires an approach by the court to litigation that is both more flexible and more pro-active. The second is the coming into effect of the Human Rights Act. ... Keeping a proper balance between the Article 10 right of freedom of expression and the protection of individual reputation must, so it seems to us, require the court to bring to a stop as an abuse of process defamation proceedings that are not serving the legitimate purpose of protecting the claimant's reputation, which includes compensating the claimant only if that reputation has been unlawfully damaged."
This case (which I must shamefacedly admit to having missed when it first came out) is a remarkable step forward, by a cleverly lateral route, from the much-criticised jurisdictional rules on forum non conveniens applied to date by the English courts in Internet-related cases like Berezovsky and Loutchansky v Times Newspapers & Ors Nos 2 to 5 [2002] QB 783. Jameel does not over-rule these cases (inded it could not, not being of House of Lords level). Nor does it impose a US style single publication rule, as Geoffrey Robertson QC has suggested in a number of cases, nor does it change the rules established in The Spiliada [1987] AC 470, as to when England is an appropriate forum (basically, nearly always:-)
But it does provide an alternative route by which to argue, sensibly, that the English courts should not be involved in cases where the circulation of the libelous item in England has been tiny, and the damages in England are therefore also likely to be minimal. This is a giant step forward for opposing the "chilling effect" of the threat of action in England in relation to texts on international websites which essentially have little or no connection to English readers. The Master of the Rolls is to be congratulated.
This author would however suggest that it's still not enough: Internet cases require a total revamp of the rules of forum non conveniens. Imagine if Berezovsky had been argued on post-Jameel rules, for example. That case concerned a tiny circulation of the libellous item in question in England, compared to an enormous circulation in the US - but still a circulation significant enough for more than nominal damages. I suspect the court would still have been forced to take it, even given the addition of the "abuse of process" concept - in other words we have still not budged from the idea that if England is an appropriate forum but obviously not THE most appropriate forum, it will still accept all comers. On the Internet this is clearly turning England into a "libel case magnet" as was asserted during Berezovsky. Given the weight of post-Spiliada authority any change will however require legislation: which will be , one suspects, a long time coming.
Wednesday, June 14, 2006
Who needs keyloggers? USB hacking for Dummies.
Steve Stasiukonis, VP and founder of Secure Network Technologies Inc, tells us how easy it is using social engineering to collect passwords and data from a large and apparently secure corporation , by means of leaving USB drives around and waitinmg for people to wonder "I wonder what's on it?", and click..
"We figured we would try something different by baiting the same employees that were on high alert. We gathered all the worthless vendor giveaway thumb drives collected over the years and imprinted them with our own special piece of software. I had one of my guys write a Trojan that, when run, would collect passwords, logins and machine-specific information from the user’s computer, and then email the findings back to us...
..The next hurdle we had was getting the USB drives in the hands of the credit union’s internal users. I made my way to the credit union at about 6 a.m. to make sure no employees saw us. I then proceeded to scatter the drives in the parking lot, smoking areas, and other areas employees frequented.
..After about three days, we figured we had collected enough data. When I started to review our findings, I was amazed at the results. Of the 20 USB drives we planted, 15 were found by employees, and all had been plugged into company computers. The data we obtained helped us to compromise additional systems, and the best part of the whole scheme was its convenience. We never broke a sweat. Everything that needed to happen did, and in a way it was completely transparent to the users, the network, and credit union management."
Glorious stuff. How should the law begin to help deal with this kind of thing? An obigation of security of systems, just as we currently have to provide a safe system of working under health and safety, seems the way to go, at least for any industry which handles the personal data of third parties. (of course, we theoretically have that already under DP law at least in Europe - but as usual, where's the enforcement mechanism?)
"We figured we would try something different by baiting the same employees that were on high alert. We gathered all the worthless vendor giveaway thumb drives collected over the years and imprinted them with our own special piece of software. I had one of my guys write a Trojan that, when run, would collect passwords, logins and machine-specific information from the user’s computer, and then email the findings back to us...
..The next hurdle we had was getting the USB drives in the hands of the credit union’s internal users. I made my way to the credit union at about 6 a.m. to make sure no employees saw us. I then proceeded to scatter the drives in the parking lot, smoking areas, and other areas employees frequented.
..After about three days, we figured we had collected enough data. When I started to review our findings, I was amazed at the results. Of the 20 USB drives we planted, 15 were found by employees, and all had been plugged into company computers. The data we obtained helped us to compromise additional systems, and the best part of the whole scheme was its convenience. We never broke a sweat. Everything that needed to happen did, and in a way it was completely transparent to the users, the network, and credit union management."
Glorious stuff. How should the law begin to help deal with this kind of thing? An obigation of security of systems, just as we currently have to provide a safe system of working under health and safety, seems the way to go, at least for any industry which handles the personal data of third parties. (of course, we theoretically have that already under DP law at least in Europe - but as usual, where's the enforcement mechanism?)
Monday, June 12, 2006
EBay Goes Ad-wards
"EBay is to launch keyword advertising - where internet users will be directed to specific auctions linked to words on the web page they are visiting.
Under the plan, site owners hosting the adverts for the online auctioneer will get a slice of the product sale price.
Called AdContext, EBay's new system may prove popular with blog site publishers who would be able to use it as an extra generator of revenue, analysts said.
The technique of contextual advertising is already used by Google and Yahoo. "
.. says the Beeb astutely adding that "EBay is one of the biggest advertisers on both Google and Yahoo and the plan could reduce its reliance on these sites, analysts said. "
Interesting , not just for its implications for eBay's business model and profits, (and indeed for the increasingly professionalised blog business model too), but also for what it might say about eBay's current EU and US immunity from liability for content originated by third parties. When eBay are actually facilitating the driving of traffic towards particuar auctions, by providing this particular advert model, with the specific intention of getting a cut of the final price (and driving that price up by greater traffic, one presumes) how neutral a third party intermediary really can they still be? (Also the contractual relationships must be fascinating.) I will shortly be writing up thoughts in this direction for the SCL's Journal of Computers and Law.
Under the plan, site owners hosting the adverts for the online auctioneer will get a slice of the product sale price.
Called AdContext, EBay's new system may prove popular with blog site publishers who would be able to use it as an extra generator of revenue, analysts said.
The technique of contextual advertising is already used by Google and Yahoo. "
.. says the Beeb astutely adding that "EBay is one of the biggest advertisers on both Google and Yahoo and the plan could reduce its reliance on these sites, analysts said. "
Interesting , not just for its implications for eBay's business model and profits, (and indeed for the increasingly professionalised blog business model too), but also for what it might say about eBay's current EU and US immunity from liability for content originated by third parties. When eBay are actually facilitating the driving of traffic towards particuar auctions, by providing this particular advert model, with the specific intention of getting a cut of the final price (and driving that price up by greater traffic, one presumes) how neutral a third party intermediary really can they still be? (Also the contractual relationships must be fascinating.) I will shortly be writing up thoughts in this direction for the SCL's Journal of Computers and Law.
More Wiki than Geeky
Yochai's Benckler new Wealth of Networks, which is causing a veritable hail of interest, has, suprise, suprise a wiki.
And there are some very interesting links to commentary on the issue of wikis and the peer production method at Ray Corrigan's excellent blog.
This is a placeholder for my summer reading, natch; but it's also a chance for me to repeat my favourite IT law joke wot I thought up, as adapted freely from Sellar and Yeatman's fabulous 1066 And All That.
Students with a classical background , having finally managed to decipher their lecture notes,sometimes look up at their IT law profesors and say "Veni, vidi, vici!"* At which their law professors run away, thinking they have been (correctly) called Weeny, Weedy and Weaky, and this knew they had All been divided into Three Parts (like Gaul).
Only nowadays the ignorant non Latin loving profs think the students are just criticising their class Wiki!
Which is also a good place to plug my blue-skies cutting-edge and any other adjective you care to call it workshop on IT law and associated topics, GikII, to be held in Edinburgh on 5th September . Abstract deadline extended to June 30th, subsidy available for travel and accomodation and we already have papers on everything from digital property and virtual worlds governance to entropy in IT law and technophobia in Lord of the Rings!
* For Classicophobes, I came, I saw, I conquered! in Latin, as Julius Caesar is reported to have cried on conquering Britain (er, or somewhere else - see comment below..).
And there are some very interesting links to commentary on the issue of wikis and the peer production method at Ray Corrigan's excellent blog.
This is a placeholder for my summer reading, natch; but it's also a chance for me to repeat my favourite IT law joke wot I thought up, as adapted freely from Sellar and Yeatman's fabulous 1066 And All That.
Students with a classical background , having finally managed to decipher their lecture notes,sometimes look up at their IT law profesors and say "Veni, vidi, vici!"* At which their law professors run away, thinking they have been (correctly) called Weeny, Weedy and Weaky, and this knew they had All been divided into Three Parts (like Gaul).
Only nowadays the ignorant non Latin loving profs think the students are just criticising their class Wiki!
Which is also a good place to plug my blue-skies cutting-edge and any other adjective you care to call it workshop on IT law and associated topics, GikII, to be held in Edinburgh on 5th September . Abstract deadline extended to June 30th, subsidy available for travel and accomodation and we already have papers on everything from digital property and virtual worlds governance to entropy in IT law and technophobia in Lord of the Rings!
* For Classicophobes, I came, I saw, I conquered! in Latin, as Julius Caesar is reported to have cried on conquering Britain (er, or somewhere else - see comment below..).
Wednesday, May 31, 2006
EU infrastructure security proposals
The EU has released a Communication on a strategy for a Secure Information Society – “Dialogue, partnership and empowerment” COM(2006) 251. This seems to be a serious atempt to advance the preservation of the Internet as critical infrastructure from the various current security threats - viruses, worms, DoS, hacking, spoofing et al. This was first advanced as an EC priority in Communication “i2010 – A European Information Society for growth and employment”( COM (2005) 229 final of 1.6.2005). The EU's press release announces that the Commission will report to Council and Parliament in the middle of 2007 on the activities launched, the initial findings and the state of play of individual initiatives, including those of ENISA (the European Network and Information Security Agency established in 2004, also as a result of the i2010 document) and those taken at Member State level and in the private sector. If appropriate, the Commission will then propose a Recommendation on network and information security (NIS).
The Communication identifies three key threats to Internet security.
"Firstly, attacks on information systems are increasingly motivated by profit rather than by the desire to create disruption for its own sake... [Secondly] The increasing deployment of mobile devices (including 3G mobile phones, portable
videogames, etc.) and mobile-based network services will pose new challenges, as IP based services develop rapidly. These could eventually prove to be a more common route for attacks than personal computers since the latter already deploy a significant level of security... [Thirdly} Another significant development is the advent of “ambient intelligence”, in which intelligentdevices supported by computing and networking technology will become ubiquitous (e.g. through RFID11, IPv6 and sensor networks). A totally interconnected and networked everyday life promises significant opportunities. However, it will also create additional security and privacy-related risks... The emergence of certain “monocultures” in software platforms and applications can greatly facilitate the growth and spread of security threats such as malware and viruses. Diversity, openness and interoperability are integral components of security and should be promoted."
What solutions does the Communication propose?
".. given the ubiquity of ICTs and information systems, network and information security is a challenge for everybody:
• Public administrations need to address the security of their systems, not just to protect
public sector information, but also to serve as an example of best practice for other players;
• Enterprises need to address NIS more as an asset and an element of competitive
advantage than as a “negative cost”;
• Individual users need to understand that their home systems are critical for the overall “security chain”.
In order to successfully tackle the problems described above, all stakeholders need reliable data on information security incidents and trends... one of the cornerstones in developing a culture of security is improving our knowledge of the problem... [And] Wherever possible, therefore, NIS should be presented as a virtue and an opportunity rather than as a liability and a cost. It needs to be viewed as an asset in building trust and consumer confidence, a competitive advantage for enterprises operating information systems, and a service quality issue for both public and private sector service providers."
PanGloss finds all this rather pleasing, as she has recently spent much time recommending , like the new EU instrument, a "holistic approach" to computer security, rather than one based, as at present, primarily on the ineffective tool of criminal law.
We are also promised a specific work programme which includes:
- two specific Communications on (i) spam, spyware and related threats; and (ii) cybercrime, including law enforcement authority co-operation.
- the scheduled review of the regulation of electronic communications due within 2006, to be expanded to include consideration of network and information security (NIS)
- the creation of a European multilingual info sharing and alert system (this to be a goal for ENISA)
- a "multi stakeholder dialogue" on economic, business and societal drivers towards NIS
- allocation of resources to NIS research under the 7th Framework programme
And in among the succeeding detail, is a para which sparks this writer's own little obsession - how far ISPs - and indeed software companies - should be held responsible for creating the new more secure Internet.
"3.3.2 The Commission also invites private sector stakeholders to take initiatives to:
• Develop an appropriate definition of responsibilities for software producers and
Internet service providers in relation to the provision of adequate and auditable levels of security. Here, support for standardised processes that would meet commonly agreed security standards and best practice rules is needed."
This is fascinating and much needed stuff. More comment when I have had time to look in more detail.
The Communication identifies three key threats to Internet security.
"Firstly, attacks on information systems are increasingly motivated by profit rather than by the desire to create disruption for its own sake... [Secondly] The increasing deployment of mobile devices (including 3G mobile phones, portable
videogames, etc.) and mobile-based network services will pose new challenges, as IP based services develop rapidly. These could eventually prove to be a more common route for attacks than personal computers since the latter already deploy a significant level of security... [Thirdly} Another significant development is the advent of “ambient intelligence”, in which intelligentdevices supported by computing and networking technology will become ubiquitous (e.g. through RFID11, IPv6 and sensor networks). A totally interconnected and networked everyday life promises significant opportunities. However, it will also create additional security and privacy-related risks... The emergence of certain “monocultures” in software platforms and applications can greatly facilitate the growth and spread of security threats such as malware and viruses. Diversity, openness and interoperability are integral components of security and should be promoted."
What solutions does the Communication propose?
".. given the ubiquity of ICTs and information systems, network and information security is a challenge for everybody:
• Public administrations need to address the security of their systems, not just to protect
public sector information, but also to serve as an example of best practice for other players;
• Enterprises need to address NIS more as an asset and an element of competitive
advantage than as a “negative cost”;
• Individual users need to understand that their home systems are critical for the overall “security chain”.
In order to successfully tackle the problems described above, all stakeholders need reliable data on information security incidents and trends... one of the cornerstones in developing a culture of security is improving our knowledge of the problem... [And] Wherever possible, therefore, NIS should be presented as a virtue and an opportunity rather than as a liability and a cost. It needs to be viewed as an asset in building trust and consumer confidence, a competitive advantage for enterprises operating information systems, and a service quality issue for both public and private sector service providers."
PanGloss finds all this rather pleasing, as she has recently spent much time recommending , like the new EU instrument, a "holistic approach" to computer security, rather than one based, as at present, primarily on the ineffective tool of criminal law.
We are also promised a specific work programme which includes:
- two specific Communications on (i) spam, spyware and related threats; and (ii) cybercrime, including law enforcement authority co-operation.
- the scheduled review of the regulation of electronic communications due within 2006, to be expanded to include consideration of network and information security (NIS)
- the creation of a European multilingual info sharing and alert system (this to be a goal for ENISA)
- a "multi stakeholder dialogue" on economic, business and societal drivers towards NIS
- allocation of resources to NIS research under the 7th Framework programme
And in among the succeeding detail, is a para which sparks this writer's own little obsession - how far ISPs - and indeed software companies - should be held responsible for creating the new more secure Internet.
"3.3.2 The Commission also invites private sector stakeholders to take initiatives to:
• Develop an appropriate definition of responsibilities for software producers and
Internet service providers in relation to the provision of adequate and auditable levels of security. Here, support for standardised processes that would meet commonly agreed security standards and best practice rules is needed."
This is fascinating and much needed stuff. More comment when I have had time to look in more detail.
And the IT-Dino!
My correspondent Douglas Spencer points out that the tale of the cat who wasn't there (post below)is by no means the only recent domain name dispute to involve cute anthropomorphicised animals.
"I am reminded of a dispute between a purple dinosaur and a six-year-old boy [DRS1544]: HIT Entertainment PLC produce Barney, a stuffed purple dinosaur, together with a TV show and lots of valuable merchandise, and they disputed the registration of barney.co.uk by a certain Tim Loosemore, who had a son called Barney.
However, the giant media empire was dreadfully incompetent in assembling its case, and the boy's father is a major mover in organisations like Wired, FaxYourMP, and NTK.
The stuffed dinosaur lost. Visit Barney on the web".
Thanks, Doug!! sadly , the arbiter in this case, Andrew Lothian, declined to exposit further on the reality or otherwise of either fuzzy dinosaurs or six year olds.
"I am reminded of a dispute between a purple dinosaur and a six-year-old boy [DRS1544]: HIT Entertainment PLC produce Barney, a stuffed purple dinosaur, together with a TV show and lots of valuable merchandise, and they disputed the registration of barney.co.uk by a certain Tim Loosemore, who had a son called Barney.
However, the giant media empire was dreadfully incompetent in assembling its case, and the boy's father is a major mover in organisations like Wired, FaxYourMP, and NTK.
The stuffed dinosaur lost. Visit Barney on the web".
Thanks, Doug!! sadly , the arbiter in this case, Andrew Lothian, declined to exposit further on the reality or otherwise of either fuzzy dinosaurs or six year olds.
the ITKat :-)
Discovered, with great delight via Discourse.net, a domain name arbitration around the well known trademark Morgan Stanley, in the US, where defendant's argument was, basically, that he was a cat.
"Respondent maintains that it is a cat, that is, a well-known carnivorous quadruped which has long been domesticated. However, it is equally well-known that the common cat, whose scientific name is Felis domesticus, cannot speak or read or write. Thus, a common cat could not have submitted the Response (or even have registered the disputed domain name). Therefore, either Respondent is a different species of cat, such as the one that stars in the motion picture "Cat From Outer Space," or Respondent's assertion regarding its being a cat is incorrect.
If Respondent is in fact a cat from outer space, then it should have so indicated in its reply, in order to avoid unnecessary perplexity by the Panel. Further, it should have explained why a cat from outer space would allow Mr. Woods to use the disputed domain name. In the absence of such an explanation, the Panel must conclude that, if Respondent is a cat from outer space, then it may have something to hide, and this is indicative of bad faith behavior.
On the other hand, if Respondent's assertion regarding its being a cat is incorrect, then Respondent has undoubtedly attempted to mislead this Panel and has provided incorrect WHOIS information. Such behavior is indicative of bad faith. See Video Direct Distribs. Inc. v. Video Direct, Inc., FA 94724 (Nat. Arb. Forum June 5, 2000) (finding that the respondent acted in bad faith by providing incorrect information to the registrar regarding the owner of the registered name). ...
The Panel finds that Respondent's assertions that it is a cat provide sufficient evidence to conclude that the Respondent registered and is using the disputed domain name in bad faith. And this despite the fact that the Panel, unlike Queen Victoria, is amused."
"Respondent maintains that it is a cat, that is, a well-known carnivorous quadruped which has long been domesticated. However, it is equally well-known that the common cat, whose scientific name is Felis domesticus, cannot speak or read or write. Thus, a common cat could not have submitted the Response (or even have registered the disputed domain name). Therefore, either Respondent is a different species of cat, such as the one that stars in the motion picture "Cat From Outer Space," or Respondent's assertion regarding its being a cat is incorrect.
If Respondent is in fact a cat from outer space, then it should have so indicated in its reply, in order to avoid unnecessary perplexity by the Panel. Further, it should have explained why a cat from outer space would allow Mr. Woods to use the disputed domain name. In the absence of such an explanation, the Panel must conclude that, if Respondent is a cat from outer space, then it may have something to hide, and this is indicative of bad faith behavior.
On the other hand, if Respondent's assertion regarding its being a cat is incorrect, then Respondent has undoubtedly attempted to mislead this Panel and has provided incorrect WHOIS information. Such behavior is indicative of bad faith. See Video Direct Distribs. Inc. v. Video Direct, Inc., FA 94724 (Nat. Arb. Forum June 5, 2000) (finding that the respondent acted in bad faith by providing incorrect information to the registrar regarding the owner of the registered name). ...
The Panel finds that Respondent's assertions that it is a cat provide sufficient evidence to conclude that the Respondent registered and is using the disputed domain name in bad faith. And this despite the fact that the Panel, unlike Queen Victoria, is amused."
Thursday, May 25, 2006
Blogging for fun and profit, er, strife and ruin?
NY Times report incidents of people sacked or not hired for having work related blogs
"On the first day of his internship last year, Andrew McDonald created a Web site for himself. It never occurred to him that his bosses might not like his naming it after the company and writing in it about what went on in their office.
For Mr. McDonald, the Web log he created, "I'm a Comedy Central Intern," was merely a way to keep his friends apprised of his activities and to practice his humor writing. For Comedy Central, it was a corporate no-no — especially after it was mentioned on Gawker.com, the gossip Web site, attracting thousands of new readers.
"Not even a newborn puppy on a pink cloud is as cute as a secret work blog!" chirped Gawker, giddily providing the link to its audience."
Oops.
But no one's reading this, right?:-)
"On the first day of his internship last year, Andrew McDonald created a Web site for himself. It never occurred to him that his bosses might not like his naming it after the company and writing in it about what went on in their office.
For Mr. McDonald, the Web log he created, "I'm a Comedy Central Intern," was merely a way to keep his friends apprised of his activities and to practice his humor writing. For Comedy Central, it was a corporate no-no — especially after it was mentioned on Gawker.com, the gossip Web site, attracting thousands of new readers.
"Not even a newborn puppy on a pink cloud is as cute as a secret work blog!" chirped Gawker, giddily providing the link to its audience."
Oops.
But no one's reading this, right?:-)
Wednesday, May 24, 2006
panGloss
As you may have noticed , BlogScript has now officially changed its name to PanGloss. I'm not changing the URL currently, but to give due warning, I may well migrate this blog elsewhere in the next few months.
Why the change? Well, Blogscript was never exactly a catchy name. It was supposed to be the "blog for SCRIPT"; and SCRIPT was the acronym I dreamt up, six or seven years back, for the loose conglomeration of IT and IP law scholars at Edinburgh Law School , who later became the AHRC Centre for Intellectual Property and Technology Law in 2002. SCRIPT stood for Scottish Centre for Research into IP and Technology (Law) - rather easier to remember than the current research-council imposed name, you must admit:-) The original idea was this blog would feature contributions from the postgraduate students at the AHRC Centre, with a bit of help from myself and Andres Guadamuz, my co-teacher. In the end though, as ever, you can take a student to water, but you can't make him/her drink :-) and so, predictably, I ended up writing the content exclusively myself, and to my surprise, like most bloggers, becoming mildly addicted to the process.
And now I'm leaving Edinburgh, it seems a good time to formalise this as MY blog, not a blog for a particular course or university; and thus to dump the clunky "SCRIPT blog" name in favour of something with a bit more juice to it.
So why panGloss? Well, blame Paul Maharg. A month or so back, at the very enjoyable BILETA 2006 conference in Malta, Paul gave a storming talk entitled " ‘Borne back ceaselessly into the past’: Glossa, hypertext and the future of legal education". Paul's argument was loosely that some very interesting similarities can be observed between legal education in the centuries before the invention of the printing press, and curent electronic publishing and social software practice. Paul pointed out that in the pre Caxton world, when original texts were rare and expensive - texts like the Bible, or in law, the Roman Institutes and Digests - the practice arose of annotating them in hand writing round the edges, often in different colours and styles. These commentaries - "glosses" - were then sometimes published themselves, arranged as marginalia around the original text, as studiable texts in their own right. These glosses then over years themselves became the subject of scholarly lectures, debate and analysis, with a dense web of mutual cross referencing arising. Such glosses contributed enormously to the development of law in most of Western Europe. The analogies to blogs and hyperlinking are both obvious and irresistably enticing, and the Scottish contingent at BILETA, raised in the mixed legal system tradition on stories of the medieval Glossators and Post-Glossators, were almost too excited to stay in their seats.
So the idea of a law blog as a modern "gloss" stuck in my mind. I once edited a hard copy fanzine called Gloss (gosh! how twentieth century!) so the new electronic Gloss had to be called something slightly more exciting. eGloss was too generic. iGloss was fun and a la mode, but sounded too much like an Apple product, or maybe a paint commercial. GLawss was clever but far too cutesy. panGloss , with its echoes of Voltaire and the best of all things in the best of all possible worlds seemed to strike a suitably optimistic and technophilic note. So panGloss it is. Be seeing you!
Why the change? Well, Blogscript was never exactly a catchy name. It was supposed to be the "blog for SCRIPT"; and SCRIPT was the acronym I dreamt up, six or seven years back, for the loose conglomeration of IT and IP law scholars at Edinburgh Law School , who later became the AHRC Centre for Intellectual Property and Technology Law in 2002. SCRIPT stood for Scottish Centre for Research into IP and Technology (Law) - rather easier to remember than the current research-council imposed name, you must admit:-) The original idea was this blog would feature contributions from the postgraduate students at the AHRC Centre, with a bit of help from myself and Andres Guadamuz, my co-teacher. In the end though, as ever, you can take a student to water, but you can't make him/her drink :-) and so, predictably, I ended up writing the content exclusively myself, and to my surprise, like most bloggers, becoming mildly addicted to the process.
And now I'm leaving Edinburgh, it seems a good time to formalise this as MY blog, not a blog for a particular course or university; and thus to dump the clunky "SCRIPT blog" name in favour of something with a bit more juice to it.
So why panGloss? Well, blame Paul Maharg. A month or so back, at the very enjoyable BILETA 2006 conference in Malta, Paul gave a storming talk entitled " ‘Borne back ceaselessly into the past’: Glossa, hypertext and the future of legal education". Paul's argument was loosely that some very interesting similarities can be observed between legal education in the centuries before the invention of the printing press, and curent electronic publishing and social software practice. Paul pointed out that in the pre Caxton world, when original texts were rare and expensive - texts like the Bible, or in law, the Roman Institutes and Digests - the practice arose of annotating them in hand writing round the edges, often in different colours and styles. These commentaries - "glosses" - were then sometimes published themselves, arranged as marginalia around the original text, as studiable texts in their own right. These glosses then over years themselves became the subject of scholarly lectures, debate and analysis, with a dense web of mutual cross referencing arising. Such glosses contributed enormously to the development of law in most of Western Europe. The analogies to blogs and hyperlinking are both obvious and irresistably enticing, and the Scottish contingent at BILETA, raised in the mixed legal system tradition on stories of the medieval Glossators and Post-Glossators, were almost too excited to stay in their seats.
So the idea of a law blog as a modern "gloss" stuck in my mind. I once edited a hard copy fanzine called Gloss (gosh! how twentieth century!) so the new electronic Gloss had to be called something slightly more exciting. eGloss was too generic. iGloss was fun and a la mode, but sounded too much like an Apple product, or maybe a paint commercial. GLawss was clever but far too cutesy. panGloss , with its echoes of Voltaire and the best of all things in the best of all possible worlds seemed to strike a suitably optimistic and technophilic note. So panGloss it is. Be seeing you!
Law and the Semantic Web
WWW06 is on in Edinburgh right now. I'm not at it, for various reasons, but I am intrigued by the reports, because it's being run by my future home, Southampton University, in my current home, Edinburgh; and because we're getting the first inklings that there may be as many legal problems about Web 2.0 as we've already had with Web 1.0.
"Hugh Glaser of the University of Southampton ..describing the semantic web, an attempt to make the web more intelligent... [said] Privacy problems could occur,.. because the semantic web deliberately combines multiple sources of information about people and places."
This problem has already reportedly come up in real life with various Grid projects emanating from the E-Science Centre (also in Edinburgh). Large distributed databases are being mined for results by researchers asociated with the high-speed "Internet 2" that is the Grid, working from different institutions in different countries. In such circumstances, it is hard to identify and seperate data controllers, processors and subjects, let alone work out what legal system has jurisdiction, and hence what information privacy rules operate. It looks like the Semantic Web takes this trend one step further. I hope to be working on these kinds of problems with colleagues at Southampton very soon.
"Hugh Glaser of the University of Southampton ..describing the semantic web, an attempt to make the web more intelligent... [said] Privacy problems could occur,.. because the semantic web deliberately combines multiple sources of information about people and places."
This problem has already reportedly come up in real life with various Grid projects emanating from the E-Science Centre (also in Edinburgh). Large distributed databases are being mined for results by researchers asociated with the high-speed "Internet 2" that is the Grid, working from different institutions in different countries. In such circumstances, it is hard to identify and seperate data controllers, processors and subjects, let alone work out what legal system has jurisdiction, and hence what information privacy rules operate. It looks like the Semantic Web takes this trend one step further. I hope to be working on these kinds of problems with colleagues at Southampton very soon.
Monday, May 22, 2006
Americans wouldn't give a triple ex for that domain name..
The Beeb reports a challenge to the US blocking of the .xxx domain.
"ICM has filed Freedom of Information requests against the US Department of Commerce and Department of State to get uncensored copies of official documents that relate to the creation of the .xxx domain.
In its Freedom of Information filing, ICM said it expected the documents to "shed light on what role the United States government played in the Internet Corporation for Assigned Names and Numbers' (Icann) consideration of ICM's proposal to create and operate a new .xxx domain".
Members of the board voted against the ICM agreement based on inaccurate information about the written statements of various governments concerning .xxx
Icann voted on 10 May to reject ICM's plans following a year of delay over a final decision on the domain. "
Oooohhhh!!! (she says, insightfully).
As various other commentators have said, the US (and one assumes, religious right) opposition to .xxx seems mighty peculiar. Implementing the domain won't create more porn or make it easier to find - it'll just make it easier for ISPs and parents to filter it out. This is what they want, right? (My own feeling is that it's an unintersting squabble anyway, because you are hardly going to convince the Russians and Moldovans to put their porn sites in .xxxx if that DOES mean they'll be more easily filtered..).
How about a domain for .phish ? :-)
"ICM has filed Freedom of Information requests against the US Department of Commerce and Department of State to get uncensored copies of official documents that relate to the creation of the .xxx domain.
In its Freedom of Information filing, ICM said it expected the documents to "shed light on what role the United States government played in the Internet Corporation for Assigned Names and Numbers' (Icann) consideration of ICM's proposal to create and operate a new .xxx domain".
Members of the board voted against the ICM agreement based on inaccurate information about the written statements of various governments concerning .xxx
Icann voted on 10 May to reject ICM's plans following a year of delay over a final decision on the domain. "
Oooohhhh!!! (she says, insightfully).
As various other commentators have said, the US (and one assumes, religious right) opposition to .xxx seems mighty peculiar. Implementing the domain won't create more porn or make it easier to find - it'll just make it easier for ISPs and parents to filter it out. This is what they want, right? (My own feeling is that it's an unintersting squabble anyway, because you are hardly going to convince the Russians and Moldovans to put their porn sites in .xxxx if that DOES mean they'll be more easily filtered..).
How about a domain for .phish ? :-)
Sunday, May 21, 2006
Kitchens of Distinction
Sunday observations on opt in/opt out and junk email ..
Blogscript just finally bought a new cooker. This is something of a personal triumph, but why should you be interested?
Well the Sainsbury's website, whence from this appliance was purchased (at, I should say, a very competitive price) presents the following choice as the purchaser checks out:
Please indicate below whether you would like to receive these:
If you do not wish to receive information by post, tick yes/no box
If you do not wish to receive information by telephone, tick yes/no box
If you are happy to receive information by text email, tick yes/no box
If you are happy to receive information by text message, tick yes/no box
My instinct (and I'm betting that of several hundred thousand others) was to tick NO all the way down on automatic pilot. Then I noticed I actually had to say YES to third and fourth options to NOT get junk texts/emails.
Now Sainsburies are perhaps/probably acting in good faith here; having noticed that the PECD now requires affirmative consent of some kind re spam/texts.
But I still think it's bloody misleading , no??
About time we had a very small SI mandating a standard tick box for consumer opt in/opt out - as the NCC recommended several years back.
Blogscript just finally bought a new cooker. This is something of a personal triumph, but why should you be interested?
Well the Sainsbury's website, whence from this appliance was purchased (at, I should say, a very competitive price) presents the following choice as the purchaser checks out:
Please indicate below whether you would like to receive these:
If you do not wish to receive information by post, tick yes/no box
If you do not wish to receive information by telephone, tick yes/no box
If you are happy to receive information by text email, tick yes/no box
If you are happy to receive information by text message, tick yes/no box
My instinct (and I'm betting that of several hundred thousand others) was to tick NO all the way down on automatic pilot. Then I noticed I actually had to say YES to third and fourth options to NOT get junk texts/emails.
Now Sainsburies are perhaps/probably acting in good faith here; having noticed that the PECD now requires affirmative consent of some kind re spam/texts.
But I still think it's bloody misleading , no??
About time we had a very small SI mandating a standard tick box for consumer opt in/opt out - as the NCC recommended several years back.
Thursday, May 18, 2006
Even Nova-er Terra Nova
New Scientist (inter alia) reports on what they call the "first ever virtual property" law suit:
"Marc Bragg, an attorney from Pennsylvania, US, filed the suit against the company behind Second Life, Linden Lab based in California, US. He accuses the company of deactivating his account after he discovered a loophole that enabled him to buy virtual land cheaply within the game.
The suit, filed in a local district court, seeks financial restitution for Bragg who claims he invested around $32,000 in the virtual land. "This is probably the first dispute of its kind," Bragg says in a statement posted online. "This suit challenges the legitimacy of a virtual intangible purchase of an asset."
Rather US centric, as there have been several other such suits reported already in Asian countries like Korea and China. But it looks like fun all the way - here's hoping neither side decides to settle!
"Marc Bragg, an attorney from Pennsylvania, US, filed the suit against the company behind Second Life, Linden Lab based in California, US. He accuses the company of deactivating his account after he discovered a loophole that enabled him to buy virtual land cheaply within the game.
The suit, filed in a local district court, seeks financial restitution for Bragg who claims he invested around $32,000 in the virtual land. "This is probably the first dispute of its kind," Bragg says in a statement posted online. "This suit challenges the legitimacy of a virtual intangible purchase of an asset."
Rather US centric, as there have been several other such suits reported already in Asian countries like Korea and China. But it looks like fun all the way - here's hoping neither side decides to settle!
Nul Points to the Royaume Uni..
Strangely little attention seems to have been paid to a rather significant written answer in the House of Commons, reported by that fine organ The Register.
"The government has given internet service providers until 2008 to block all access to websites containing illegal images of child abuse listed by the Internet Watch Foundation.
In a Parliamentary written answer on 15 May, Home Office Minister Vernon Coaker said progress had been made, but hinted that if the last paedophile services were not snuffed out of circulation soon the government might take steps itself to block people accessing them.
The industry-funded IWF had already seen a drastic drop in the number of illegal sites reported to be hosted in the UK, from 18 per cent in 1997 to 0.4 per cent in 2005.
All 3G mobile operators blocked access to paedophile sites over their networks, while all of the biggest internet service providers, representing 90 per cent of broadband domestic connections, were also willingly blocking access."
There is an awful lot of fudging going on here. Yes, the IWF has been staggeringly successful at removing child porn HOSTED in the UK. Those figures are true. This is not least because virtually all UK ISPs receive the IWF URL list of illegal child porn sites, and take action on it, since otherwise they would be liable to action as publishers on notice of illegal material under the EC E Commerce Directive.
But that doesn't mean there's any less kiddy porn out there. Au contraire, it just means it's hosted in other countries than the UK, where the laws are kinder or less well enforced: noteably the US, where hate speech, eg, still thrives under the protection of the First Amendment, and the outlaw lands of the former Soviet Union.
What the government are talking about here is enforcing, not takedown of child porn sites within the UK, which is indeed almost accomplished , but upstream censorship of all feeds coming into the UK so no one in the UK can access illegal porn from sites *outside* the UK. This access-filtering and blocking can be done very efficiently via the technology BT Internet have already implemented, known as Cleanfeed and which has already been rolled out by "agreement" (since many of those who sign up to BT wil know nothing of Cleanfeed and what it does) to those who signed up to get the Net via BT.
Now all this is OK so far, you are no doubt saying. If you want a child porn free feed so that eg your kids or partner can't get at it, then signing up with BT makes sense. Anyone else still has the ability to go to another UK ISP. And if it's illegal to possess child porn (which it is in almost every state in the world now) then why not command your ISPs to block it at source, so no customers can get at it?
Because - and this is to me a rather more immediate worry than the net neutrality debate - any filtering technology dependent on keywords or a URL list, that can efectively block all kid porn access, upstream, invisibly - and which is mandated to do so by the government and MUST be installed by every ISP - can very easily be extended to block any content AT ALL coming into the country that the government finds unlikeable. As also revealed by the parliamentary question,"The Home Office had admitted that it had considered blocking websites that "glorified terrorism" under the Terrorism Act (2006). It said it was not policy to require ISPs to block content, but added: "our legislation as drafted provides the flexibility to accomodate a change in Government policy should the need ever arise." (And there is some rumour that the govrnment had considered blocking "terrorist" material before this law ever came into force, and which thus may not have been illegal at all at the time.)
I'm no free speech nut, but that last sentence quoted sends chills down my spine. This is the technology that could turn us into China, tomorrow, and the nice bit is, most non-techy people would never even notice. Banned books get headlines, banned newspapers get marches in the streets : banned websites, or pictures, disguised behind the ubiquitous error messages of the Net, rarely get noticed. And while Google providing a censored service to its customers in China dominated the tech press in the US for weeks, here, the UK - the state, not a private company - proposing China style censorship tools as part of compulsory legislation for all ISPs, doesn't even seem to have made the BBC website. (And remember . we aren't China : they don't have to use these tools to close down sites abraod that are politically dubious. They could use them to block P2P downloading sites, or sites flogging warez, just as easily.)
Anyone else feel even a tad worried?
"The government has given internet service providers until 2008 to block all access to websites containing illegal images of child abuse listed by the Internet Watch Foundation.
In a Parliamentary written answer on 15 May, Home Office Minister Vernon Coaker said progress had been made, but hinted that if the last paedophile services were not snuffed out of circulation soon the government might take steps itself to block people accessing them.
The industry-funded IWF had already seen a drastic drop in the number of illegal sites reported to be hosted in the UK, from 18 per cent in 1997 to 0.4 per cent in 2005.
All 3G mobile operators blocked access to paedophile sites over their networks, while all of the biggest internet service providers, representing 90 per cent of broadband domestic connections, were also willingly blocking access."
There is an awful lot of fudging going on here. Yes, the IWF has been staggeringly successful at removing child porn HOSTED in the UK. Those figures are true. This is not least because virtually all UK ISPs receive the IWF URL list of illegal child porn sites, and take action on it, since otherwise they would be liable to action as publishers on notice of illegal material under the EC E Commerce Directive.
But that doesn't mean there's any less kiddy porn out there. Au contraire, it just means it's hosted in other countries than the UK, where the laws are kinder or less well enforced: noteably the US, where hate speech, eg, still thrives under the protection of the First Amendment, and the outlaw lands of the former Soviet Union.
What the government are talking about here is enforcing, not takedown of child porn sites within the UK, which is indeed almost accomplished , but upstream censorship of all feeds coming into the UK so no one in the UK can access illegal porn from sites *outside* the UK. This access-filtering and blocking can be done very efficiently via the technology BT Internet have already implemented, known as Cleanfeed and which has already been rolled out by "agreement" (since many of those who sign up to BT wil know nothing of Cleanfeed and what it does) to those who signed up to get the Net via BT.
Now all this is OK so far, you are no doubt saying. If you want a child porn free feed so that eg your kids or partner can't get at it, then signing up with BT makes sense. Anyone else still has the ability to go to another UK ISP. And if it's illegal to possess child porn (which it is in almost every state in the world now) then why not command your ISPs to block it at source, so no customers can get at it?
Because - and this is to me a rather more immediate worry than the net neutrality debate - any filtering technology dependent on keywords or a URL list, that can efectively block all kid porn access, upstream, invisibly - and which is mandated to do so by the government and MUST be installed by every ISP - can very easily be extended to block any content AT ALL coming into the country that the government finds unlikeable. As also revealed by the parliamentary question,"The Home Office had admitted that it had considered blocking websites that "glorified terrorism" under the Terrorism Act (2006). It said it was not policy to require ISPs to block content, but added: "our legislation as drafted provides the flexibility to accomodate a change in Government policy should the need ever arise." (And there is some rumour that the govrnment had considered blocking "terrorist" material before this law ever came into force, and which thus may not have been illegal at all at the time.)
I'm no free speech nut, but that last sentence quoted sends chills down my spine. This is the technology that could turn us into China, tomorrow, and the nice bit is, most non-techy people would never even notice. Banned books get headlines, banned newspapers get marches in the streets : banned websites, or pictures, disguised behind the ubiquitous error messages of the Net, rarely get noticed. And while Google providing a censored service to its customers in China dominated the tech press in the US for weeks, here, the UK - the state, not a private company - proposing China style censorship tools as part of compulsory legislation for all ISPs, doesn't even seem to have made the BBC website. (And remember . we aren't China : they don't have to use these tools to close down sites abraod that are politically dubious. They could use them to block P2P downloading sites, or sites flogging warez, just as easily.)
Anyone else feel even a tad worried?
Vive La France!
One of the ideas I've toyed with a fair bit over the last year or so is whether there's an argument, for purposes as various as competition law, and public liability to implement human rights protection, to treat Google as a quasi-public body. Google earns about 80% of the search revenues of the word right now, has a clear stranglehold on the market and provides what almost everyone would now concede is an essential public service. Yet Google operate , quite reasonably, as a public corporation, accountable to no one but their share holders.
The situation would of cousre change if Google had a reasonable competitor - but both Yahoo! and MSN seem to have failed in that department. Now however the French have come to the rescue!! Or rather the EU, with an alleged "Google-killer" named Quaero, which as everyone with a Latin O Level knows means "I ask". According to the Beeb:
"European politicians seem worried about the supremacy of the Americans in cyberspace. French President Jacques Chirac has unveiled five grand Europrojects backed with public money to help counter the prevailing American technology influence.
Among them is something called Quaero, backed with some 250m euros of public funds. In most accounts of it, Quaero has been billed as an EU attempt to build a publicly funded Google killer. "
The whole project appears to be still under wraps with no details as yet. But even if it provides pinpoint search accuracy and makes drinks at the same time, will the English really choose to use a French search engine? -)
The situation would of cousre change if Google had a reasonable competitor - but both Yahoo! and MSN seem to have failed in that department. Now however the French have come to the rescue!! Or rather the EU, with an alleged "Google-killer" named Quaero, which as everyone with a Latin O Level knows means "I ask". According to the Beeb:
"European politicians seem worried about the supremacy of the Americans in cyberspace. French President Jacques Chirac has unveiled five grand Europrojects backed with public money to help counter the prevailing American technology influence.
Among them is something called Quaero, backed with some 250m euros of public funds. In most accounts of it, Quaero has been billed as an EU attempt to build a publicly funded Google killer. "
The whole project appears to be still under wraps with no details as yet. But even if it provides pinpoint search accuracy and makes drinks at the same time, will the English really choose to use a French search engine? -)
Tim Berners Lee: Network Neutrality part 2
In an attempt to get my head round this, I went back to the one item everyone and their pet llama has blogged: the father of the Web, TBL himself, coming out behind network neutrality..
"When, seventeen years ago, I designed the Web, I did not have to ask anyone's permission. [3]. The new application rolled out over the existing Internet without modifying it. I tried then, and many people still work very hard still, to make the Web technology, in turn, a universal, neutral, platform. It must not discriminate against particular hardware, software, underlying network, language, culture, disability, or against particular types of data.
Anyone can build a new application on the Web, without asking me, or Vint Cerf, or their ISP, or their cable company, or their operating system provider, or their government, or their hardware vendor.
It is of the utmost importance that, if I connect to the Internet, and you connect to the Internet, that we can then run any Internet application we want, without discrimination as to who we are or what we are doing. We pay for connection to the Net as though it were a cloud which magically delivers our packets. We may pay for a higher or a lower quality of service. We may pay for a service which has the characteristics of being good for video, or quality audio. But we each pay to connect to the Net, but no one can pay for exclusive access to me. "
Which makes it clearer to me that network neutrality isn't just about a pie in the sky demand for "one rate to rule them all" . To a large extent, I don't care if YouTube has to pay more to get access to the net so x million people can download silly videos of anime characters dancing to copyright-infringed West End musical tunes. Yes I know about freedom of expresion, and plurality of voices, but really, the world wouldn't come to an end. If it was M$ that was one of the most popular targets on the net, and so was being asked to pay a higher rate to receive traffic, would people be up in arms? I somehow doubt it.
But if network non neutrality requires external content identification of packets - that's another story. That's censorship and potential centralised control and all the horrors of the end of the end to end Internet we're used to hearing about from Lessig and Zittrain et al.
But TBL himself still intuitively seems to have the idea that the market does play a role, albeit an unwanted one, in these things.
"When I was a child, I was impressed by the fact that the installation fee for a telephone was everywhere the same in the UK, whether you lived in a city or on a mountain, just as the same stamp would get a letter to either place. "
But it doesn't - as I said in my previous post, a second class postage stamp in the UK is now virtually a license for mail to arrive very late, or not at all; anyone who really wants mail to get there on time sends it first class. Which seems to me to be both a warning and an example: network neutrality in the sense discussed above may be vital, clearly, but if the telcos don't have the legal ability to implement what in other industries would be seen as sensible profit-making strategies, the srvice we all get may degrade. In the EC of course we'd say this was a case, if necessary, for essential/universal quality of service regulation - anyone know if the US has no equivalent?
EDIT : A nice simple video on the matter (via
"When, seventeen years ago, I designed the Web, I did not have to ask anyone's permission. [3]. The new application rolled out over the existing Internet without modifying it. I tried then, and many people still work very hard still, to make the Web technology, in turn, a universal, neutral, platform. It must not discriminate against particular hardware, software, underlying network, language, culture, disability, or against particular types of data.
Anyone can build a new application on the Web, without asking me, or Vint Cerf, or their ISP, or their cable company, or their operating system provider, or their government, or their hardware vendor.
It is of the utmost importance that, if I connect to the Internet, and you connect to the Internet, that we can then run any Internet application we want, without discrimination as to who we are or what we are doing. We pay for connection to the Net as though it were a cloud which magically delivers our packets. We may pay for a higher or a lower quality of service. We may pay for a service which has the characteristics of being good for video, or quality audio. But we each pay to connect to the Net, but no one can pay for exclusive access to me. "
Which makes it clearer to me that network neutrality isn't just about a pie in the sky demand for "one rate to rule them all" . To a large extent, I don't care if YouTube has to pay more to get access to the net so x million people can download silly videos of anime characters dancing to copyright-infringed West End musical tunes. Yes I know about freedom of expresion, and plurality of voices, but really, the world wouldn't come to an end. If it was M$ that was one of the most popular targets on the net, and so was being asked to pay a higher rate to receive traffic, would people be up in arms? I somehow doubt it.
But if network non neutrality requires external content identification of packets - that's another story. That's censorship and potential centralised control and all the horrors of the end of the end to end Internet we're used to hearing about from Lessig and Zittrain et al.
But TBL himself still intuitively seems to have the idea that the market does play a role, albeit an unwanted one, in these things.
"When I was a child, I was impressed by the fact that the installation fee for a telephone was everywhere the same in the UK, whether you lived in a city or on a mountain, just as the same stamp would get a letter to either place. "
But it doesn't - as I said in my previous post, a second class postage stamp in the UK is now virtually a license for mail to arrive very late, or not at all; anyone who really wants mail to get there on time sends it first class. Which seems to me to be both a warning and an example: network neutrality in the sense discussed above may be vital, clearly, but if the telcos don't have the legal ability to implement what in other industries would be seen as sensible profit-making strategies, the srvice we all get may degrade. In the EC of course we'd say this was a case, if necessary, for essential/universal quality of service regulation - anyone know if the US has no equivalent?
EDIT : A nice simple video on the matter (via
Lessig blog.) Reminds me that European universal service obligations do not at least as yet apply to VOIP, at least pre revision of TVF Directive ..
Wednesday, May 17, 2006
The Great Network Neutrality Debate
Boing Boing quotes Siva Vaidhyanathan, author of The Anarchist in the Library, on Net Neutrality -- audio and transcript now available:
There are a couple of different ways to look at this. There's the romantic way, right? The romantic way is that we want to have the Internet as the wild frontier for entrepreneurship, and that's a strong case. There's also the liberal free speech argument, which says we want the Internet to be a level playing field so a variety of voices can enter the public sphere. That's a fairly strong argument. But then you've got the economic argument, which is those of us who write checks every month to these companies, we want to be able to know that we are getting decent service for what we're paying. If my broadband company next week starts dialing down my Skype speed so Skype doesn't work as well for me, I might not even know it or notice it for a long time, until Skype starts frustrating me, and out of frustration, I'm just going to pick up my old phone and dial India the old-fashioned way and just pay for it because I know the call's going to go through. That's the sort of frustration and opacity we might start seeing on the Internet. So it is a service question, a competition question, an economic development question, a consumer question. And it really is dollars and cents.
Good straight talking but it makes me wonder if Siva realised he was also arguing for the opposition. I have had this lurking atavistic feeling throughout the network neutrality debate, that if Sony or AOL (say) want to pay for better service, then why shouldn't they be able to? People do the same in every other industry - cf business class air travel - including communications services like snail mail post.
The answer of course is more complex - that the Internet is an essential service and therefore must be subject to minimum service guarantees for everyone if it is to flourish. (yet the same could have been said of snail mail - and surely if I pay for first class mail this does indeed divert "bandwidth" from second class mail in exactly the same way? certainly judging by the standard of second class post in the UK right now :-) But it's good to see one of the "copyfighters" realising that economics will generally trump romantic rhetoric and (as with yesterday's post on privacy activists) the network neutrality samurai have got to be very aware of this in the debates.
I look forward to getting hold of Yochai Benkler's new book which will no doubt teach me the error of my ways:-)
There are a couple of different ways to look at this. There's the romantic way, right? The romantic way is that we want to have the Internet as the wild frontier for entrepreneurship, and that's a strong case. There's also the liberal free speech argument, which says we want the Internet to be a level playing field so a variety of voices can enter the public sphere. That's a fairly strong argument. But then you've got the economic argument, which is those of us who write checks every month to these companies, we want to be able to know that we are getting decent service for what we're paying. If my broadband company next week starts dialing down my Skype speed so Skype doesn't work as well for me, I might not even know it or notice it for a long time, until Skype starts frustrating me, and out of frustration, I'm just going to pick up my old phone and dial India the old-fashioned way and just pay for it because I know the call's going to go through. That's the sort of frustration and opacity we might start seeing on the Internet. So it is a service question, a competition question, an economic development question, a consumer question. And it really is dollars and cents.
Good straight talking but it makes me wonder if Siva realised he was also arguing for the opposition. I have had this lurking atavistic feeling throughout the network neutrality debate, that if Sony or AOL (say) want to pay for better service, then why shouldn't they be able to? People do the same in every other industry - cf business class air travel - including communications services like snail mail post.
The answer of course is more complex - that the Internet is an essential service and therefore must be subject to minimum service guarantees for everyone if it is to flourish. (yet the same could have been said of snail mail - and surely if I pay for first class mail this does indeed divert "bandwidth" from second class mail in exactly the same way? certainly judging by the standard of second class post in the UK right now :-) But it's good to see one of the "copyfighters" realising that economics will generally trump romantic rhetoric and (as with yesterday's post on privacy activists) the network neutrality samurai have got to be very aware of this in the debates.
I look forward to getting hold of Yochai Benkler's new book which will no doubt teach me the error of my ways:-)
Tuesday, May 16, 2006
I Told You So Pt 229.9 repeater
Bruce Schneier reports:
"While privacy remains a major concern for people around the world, a majority of consumers would share personal data if they knew the information was securely protected and if sharing it would make their lives easier, according to Unisys' Global Study on the Public's Perceptions about Identity Management. "
I do seem to have been saying this for some time..
Privacy activists can't simply shake their heads in horror. They need to understand this mindset - and when it is reasonable, and when it needs to be combatted, and when more facts are needed. Otherwise they are doomed to be fighting a losing battle.
"While privacy remains a major concern for people around the world, a majority of consumers would share personal data if they knew the information was securely protected and if sharing it would make their lives easier, according to Unisys' Global Study on the Public's Perceptions about Identity Management. "
I do seem to have been saying this for some time..
Privacy activists can't simply shake their heads in horror. They need to understand this mindset - and when it is reasonable, and when it needs to be combatted, and when more facts are needed. Otherwise they are doomed to be fighting a losing battle.
Monday, May 15, 2006
BlogScript gets a chair (Not the Flatpack Variety)
I've also mysteriously failed to note officially here what many of you already know: I am delighted to announce I will be taking up a Chair of Internet Law at Southampton from 1 September 2006; where I look forward very much to working with, inter alia, Caroline Wilson and Stephen Saxby. Plans there include a new LLM course in Law and Technology, a monograph on privacy law and a 3rd edition of Law and the Internet. In 2006/7 I will be helping teach the undergraduate IT Law course with Caroline and investigating the Semantic Web with Wendy Hall! This will also make me rather more accessible to London and Oxford events, which I'm throughly looking forward to..
GikII Workshop
I am running a one-day workshop at the World Computer Law Congress in Edinburgh in SEptember and have curiously failed to note it here - please note the call for papers has been extended to 30 June 2006. Attendance is FREE for everyone giving a paper, and some subsidy of travel and accomodation may be available on request. We've so far had some very interesting submissions on law, surveilance, popular culture, law and film, law and virtual worlds, law and online identity, law and computer games, law and entropy - it's looking good!
Young and international scholars, not necessarily from law, are especially encouraged.
GikII Workshop
Workshop Organiser: Lilian Edwards. Co-Director, AHRC Centre for Research into Intellectual Property and Technology; Chair of Law, University of Southampton (from September 06)
Tuesday 5th September 2006, VIth World Computer Congress, Law School, University of EdinburghWikipedia is the first encyclopaedia in the world where information is being amassed solely by the collaborative efforts of individuals working separately but together via on-line tools. Geeks are the people who contribute to this knowledge: fellow travellers on the digital omnibus, who delight in finding, publishing, inventing and sharing nuggets of joyful knowledge and innovation from the worlds of technology, science, popular culture, and technotrivia. LIIs are Legal Information Institutes: invaluable on-line temples of legal knowledge. The patriarch of the field is AustLII, but the concept has spread through the world bringing us BAILII, PacLII, CommonLII, and no doubt, many more bad puns to come.
GikII proposes to be the place where these worlds, institutions and players will come together for the first time at a major law and technology conference. We want to discuss whether geek law exists. If you have a paper burning for the oxygen of publicity on any aspect of law AND technology, science, geek culture, blogs, popular culture, wikis, science fiction or fantasy, computer games, digital culture, gender on-line, MMORPGS, virtual property or online human personae, then this is the workshop for you.
So if you long to find a venue where you can talk seriously about surveillance strategies in the novels of Harry Potter; why blawgs do well in the Technorati database; whether virtual worlds are the ideal try–out zones for law reform; whether characters in The Sims should be allowed the human right to private life ; the ethics of heroism post 9/11 as seen in the Spiderman movies; whether cyber-feminism still exists; and much, much more, then let us see your abstract.
Young and international scholars, not necessarily from law, are especially encouraged.
GikII Workshop
Workshop Organiser: Lilian Edwards. Co-Director, AHRC Centre for Research into Intellectual Property and Technology; Chair of Law, University of Southampton (from September 06)
Tuesday 5th September 2006, VIth World Computer Congress, Law School, University of EdinburghWikipedia is the first encyclopaedia in the world where information is being amassed solely by the collaborative efforts of individuals working separately but together via on-line tools. Geeks are the people who contribute to this knowledge: fellow travellers on the digital omnibus, who delight in finding, publishing, inventing and sharing nuggets of joyful knowledge and innovation from the worlds of technology, science, popular culture, and technotrivia. LIIs are Legal Information Institutes: invaluable on-line temples of legal knowledge. The patriarch of the field is AustLII, but the concept has spread through the world bringing us BAILII, PacLII, CommonLII, and no doubt, many more bad puns to come.
GikII proposes to be the place where these worlds, institutions and players will come together for the first time at a major law and technology conference. We want to discuss whether geek law exists. If you have a paper burning for the oxygen of publicity on any aspect of law AND technology, science, geek culture, blogs, popular culture, wikis, science fiction or fantasy, computer games, digital culture, gender on-line, MMORPGS, virtual property or online human personae, then this is the workshop for you.
So if you long to find a venue where you can talk seriously about surveillance strategies in the novels of Harry Potter; why blawgs do well in the Technorati database; whether virtual worlds are the ideal try–out zones for law reform; whether characters in The Sims should be allowed the human right to private life ; the ethics of heroism post 9/11 as seen in the Spiderman movies; whether cyber-feminism still exists; and much, much more, then let us see your abstract.
Court of Appeal Denial of Service Shock Horror
.. well maybe if you're a DoS geek like me:-)
The Court of Appeal has ruled that a judge was wrong to throw out the case of a UK teenager accused of crashing a mail server with millions of emails. David Lennon, who is now 18 and can therefore be named for the first time, is alleged to have used a mail bombing programme called Avalanche to send approximately five million emails to his former employers, in early 2004, crashing the company's email server.
The case against him, brought under the Computer Misuse Act (CMA) 1990, was dismissed last November by District Judge Kenneth Grant at Wimbledon Magistrates' Court. Judge Grant had said that Section 3 of the Act, which concerns unauthorised modification of data, had not been breached, as emails sent to a server configured to receive emails could not be classified as unauthorised.
But on Thursday, judges at the Royal Courts of Justice sent the case back to the Magistrates Court, saying Judge Grant "was not right to state there was no case to answer". Mr Justice Jack said the judge should consider "what answer Mr Lennon might have expected if he had asked D&G" before starting the mail bombing.
This last sentence is terribly interesting. Yes, it blows the "authorised" act defense out the water, therefore saving the bacon of the CMA amendments on DoS curently wending their way through Parliamant and cricised extensively here for NOT plugging this particular loophole.
But this time the hole which is plugged is far too wide (oh my we are in the land of mixed metaphors, aren't we?) This potentially means, IMHO, that every unwanted search engine spider that traverses a site; every price comparison engine which comes sniffing to collect info the site would rather not give away to its competitors, but has to leave public for its customers; every deep linker who plans to put a link in to enhance their own site's content, but thereby cut out the ads and branding on the home page of the content originator -- has suddenly now committed a criminal act.
Welcome to the UK. Trespass to websites , long controversial even in the US of A as a civil wrong, has just become a crime in the UK :-)
((Ps. BlogScript is writing a family law book. It will re appear in a shower of exciting commentary in about two weeks, with a change of name and even of image!! be there or be orthogonal!))
The Court of Appeal has ruled that a judge was wrong to throw out the case of a UK teenager accused of crashing a mail server with millions of emails. David Lennon, who is now 18 and can therefore be named for the first time, is alleged to have used a mail bombing programme called Avalanche to send approximately five million emails to his former employers, in early 2004, crashing the company's email server.
The case against him, brought under the Computer Misuse Act (CMA) 1990, was dismissed last November by District Judge Kenneth Grant at Wimbledon Magistrates' Court. Judge Grant had said that Section 3 of the Act, which concerns unauthorised modification of data, had not been breached, as emails sent to a server configured to receive emails could not be classified as unauthorised.
But on Thursday, judges at the Royal Courts of Justice sent the case back to the Magistrates Court, saying Judge Grant "was not right to state there was no case to answer". Mr Justice Jack said the judge should consider "what answer Mr Lennon might have expected if he had asked D&G" before starting the mail bombing.
This last sentence is terribly interesting. Yes, it blows the "authorised" act defense out the water, therefore saving the bacon of the CMA amendments on DoS curently wending their way through Parliamant and cricised extensively here for NOT plugging this particular loophole.
But this time the hole which is plugged is far too wide (oh my we are in the land of mixed metaphors, aren't we?) This potentially means, IMHO, that every unwanted search engine spider that traverses a site; every price comparison engine which comes sniffing to collect info the site would rather not give away to its competitors, but has to leave public for its customers; every deep linker who plans to put a link in to enhance their own site's content, but thereby cut out the ads and branding on the home page of the content originator -- has suddenly now committed a criminal act.
Welcome to the UK. Trespass to websites , long controversial even in the US of A as a civil wrong, has just become a crime in the UK :-)
((Ps. BlogScript is writing a family law book. It will re appear in a shower of exciting commentary in about two weeks, with a change of name and even of image!! be there or be orthogonal!))
Tuesday, April 18, 2006
Back on the ID cards trail.
This ain't gonna make me popular:-)
I've been thinking about the debate on ID cards at ****con and why it continues to dismay me. The reasons people cite against ID cards tend to fall into two camps: practical and principled.
Practical
1. The database project won't work; the error rate will be high, the information won't be successfully updated, the Chinese walls (if any) will be compromised etc.
2. The biometric data part of the project currently has too high a rate of false positive and false negatives for succesful identification, plus some people can't reliably provide biometric data.
3. Even if these problems could be solved, the project will go wildly over budget - like all public sector IT projects.
4. The public will have to pay for ID cards/passports at an unreasonable level compared to current cost of passports.
5.Even if access to the ID card database is restricted (as it should be for DP law purposes) to government agencies like health providers and welfare agencies, or police/crime investigation/intelligence etc , information will become available on the black market, and thence to everyone from private detectives to ID thieves.
To me these are issues of detail - of technology and management; which are difficult to critique in a non paranoid way right now as we know so little about the design of the underlying database or its costing. The time to argue these points is when we know how the database is to be designed, what the permissions for access to data will be and what the rules for dealing with erroneous data, false positive etc, will be.
On issues of non enforcement and data seep - the general mantra is that oh yeh, DP and confidentiality and ethics law exist that are meant to prevent these problems, but it won't work. In which case we might as well give up on ever having laws at all. I see the problem, believe me I do, but blanket cynicism is not a principled way to argue against ID cards, any more than blanket cynicism about enforcement of laws against car theft (equally viable) is a reason to abolish all laws on theft of cars, or all expenditure on enforcement of car theft laws.
On issues of cost - if in principle there is a case for ID cards , then the issues of cost have to be secondary. The cost is a matter for a principled debate in terms of how much we value the fight against terorism and other alleged evils (benefit fraud, asylum seeker entry) as against how much we value our personal data privacy. That debate just isn't happening in the UK right now.
"Practical" issues - of efficacy rather than principle - do not seem to me to be where the debate should be currently focussed. And at the moment, judging by yesterday's panel, for most people, it is.
What are the principled arguments against an ID card?
1. Putting all the data in one basket - a single linked database - creates a single point of failure. One decent hack or unprincipled employee or illegal agreement for a access by a government agency with a private actor, and huge amounts of personal data can be released - whereas if we only have, say, an NHS database, at least only health data can be so compromised.
2. Function creep. Create a single linked database of personal data and more uses will be found for it. We start off saying we'll only use it to assist in crime or terorism detenction , or, more benignly, to allow child care agencies to track children at risk wherever they go - but then we end up lending it to debt collectors, to commercial database marketing firms, to people who want to find out where pedophiles live, etc etc.
3. Compulsion. Till now no one in the UK has actually needed to acquire an ID card - no compulsion to get a driving license or a passport. Our Continental cousins, who live in liberal societies where ID cards (NOT ID databases) have been standard for decades find our objection to this one hard to parse: and indeed it is hard to claim , if you look at the empirical reality, that we are a freer society than, say, Belgium or Germany because they have ID cards and we don't.
4. Most of all, the principled issues are about the consequences of a linked ID database, not an ID card: this point itself is obscured in most of the on line/extralegal discussions.
I'm not particularly for a national ID card/database. I'm not particularly against it either. I can see advantages: I'd quite like to live in a world where I was exposed to less degree of risk at airports, at large public events. I can see disadvantages: I also don't want to run the risk of discovering Sony, or the DMA, or my ex boyfriend, or my employer, can find out everything there is to know about me. (But I have a feeling we pretty much live in that world already with or without an ID card.)
My own feeling is that we already have a system as good as we can devise of laws and practices for dealing with consent to the collection of, and subsequent protection of, personal data. It's called data protection law. I've critiqued the PRACTICE of DP law extensively myself but almost no one disagrees that the principles are sound. The problem currently is that there is a generic "get out of jail free" clause in DP law, in relation to personal data collected for the purposes of investigation of crime or security, as well as some other public sector functions. We need to consider how data protection could, albeit in part, and with more safeguards, be applied not wholy exempted in relation both to the police and security services, and to private sector parties exercising crime prevention roles (most CCTV cameras, eg, are operated by private actors, and they too benefit from this blanket fiat.)
The other problem is that DP law enforcement is wildly under resourced. One hypothetical argument about enforcement might be that in an ID database world, the state must finance the Information Comissioner as fully as it finances the police. (yeh right :-)
But most of all I'd like to see a debate on ID cards that isn't focused around "it'll never work" or "it'll cost too much" or "they can't make me do this" or "we all know it's a bunch of lies". That isn't a debate. That's a lynching. I'd like to see a debate that focuses round the real issues: how do we want to balance our needs for privacy and our needs for security? How, if at all, do we want to balance our privacy rights and the positive uses that can be made of a linked database, for both citizens and consumers? What are the safeguards that need to be built in, which once specified we can then pass to the database builders? And most of all what kind of privacy do most people really want - not the activists, not the No2ID card people, not the constitutional law academics, but everyone?
(Thanks for ideas included herein from my fellow panellists Dave Clements, Andrew Adams and Mike Scott.)
I've been thinking about the debate on ID cards at ****con and why it continues to dismay me. The reasons people cite against ID cards tend to fall into two camps: practical and principled.
Practical
1. The database project won't work; the error rate will be high, the information won't be successfully updated, the Chinese walls (if any) will be compromised etc.
2. The biometric data part of the project currently has too high a rate of false positive and false negatives for succesful identification, plus some people can't reliably provide biometric data.
3. Even if these problems could be solved, the project will go wildly over budget - like all public sector IT projects.
4. The public will have to pay for ID cards/passports at an unreasonable level compared to current cost of passports.
5.Even if access to the ID card database is restricted (as it should be for DP law purposes) to government agencies like health providers and welfare agencies, or police/crime investigation/intelligence etc , information will become available on the black market, and thence to everyone from private detectives to ID thieves.
To me these are issues of detail - of technology and management; which are difficult to critique in a non paranoid way right now as we know so little about the design of the underlying database or its costing. The time to argue these points is when we know how the database is to be designed, what the permissions for access to data will be and what the rules for dealing with erroneous data, false positive etc, will be.
On issues of non enforcement and data seep - the general mantra is that oh yeh, DP and confidentiality and ethics law exist that are meant to prevent these problems, but it won't work. In which case we might as well give up on ever having laws at all. I see the problem, believe me I do, but blanket cynicism is not a principled way to argue against ID cards, any more than blanket cynicism about enforcement of laws against car theft (equally viable) is a reason to abolish all laws on theft of cars, or all expenditure on enforcement of car theft laws.
On issues of cost - if in principle there is a case for ID cards , then the issues of cost have to be secondary. The cost is a matter for a principled debate in terms of how much we value the fight against terorism and other alleged evils (benefit fraud, asylum seeker entry) as against how much we value our personal data privacy. That debate just isn't happening in the UK right now.
"Practical" issues - of efficacy rather than principle - do not seem to me to be where the debate should be currently focussed. And at the moment, judging by yesterday's panel, for most people, it is.
What are the principled arguments against an ID card?
1. Putting all the data in one basket - a single linked database - creates a single point of failure. One decent hack or unprincipled employee or illegal agreement for a access by a government agency with a private actor, and huge amounts of personal data can be released - whereas if we only have, say, an NHS database, at least only health data can be so compromised.
2. Function creep. Create a single linked database of personal data and more uses will be found for it. We start off saying we'll only use it to assist in crime or terorism detenction , or, more benignly, to allow child care agencies to track children at risk wherever they go - but then we end up lending it to debt collectors, to commercial database marketing firms, to people who want to find out where pedophiles live, etc etc.
3. Compulsion. Till now no one in the UK has actually needed to acquire an ID card - no compulsion to get a driving license or a passport. Our Continental cousins, who live in liberal societies where ID cards (NOT ID databases) have been standard for decades find our objection to this one hard to parse: and indeed it is hard to claim , if you look at the empirical reality, that we are a freer society than, say, Belgium or Germany because they have ID cards and we don't.
4. Most of all, the principled issues are about the consequences of a linked ID database, not an ID card: this point itself is obscured in most of the on line/extralegal discussions.
I'm not particularly for a national ID card/database. I'm not particularly against it either. I can see advantages: I'd quite like to live in a world where I was exposed to less degree of risk at airports, at large public events. I can see disadvantages: I also don't want to run the risk of discovering Sony, or the DMA, or my ex boyfriend, or my employer, can find out everything there is to know about me. (But I have a feeling we pretty much live in that world already with or without an ID card.)
My own feeling is that we already have a system as good as we can devise of laws and practices for dealing with consent to the collection of, and subsequent protection of, personal data. It's called data protection law. I've critiqued the PRACTICE of DP law extensively myself but almost no one disagrees that the principles are sound. The problem currently is that there is a generic "get out of jail free" clause in DP law, in relation to personal data collected for the purposes of investigation of crime or security, as well as some other public sector functions. We need to consider how data protection could, albeit in part, and with more safeguards, be applied not wholy exempted in relation both to the police and security services, and to private sector parties exercising crime prevention roles (most CCTV cameras, eg, are operated by private actors, and they too benefit from this blanket fiat.)
The other problem is that DP law enforcement is wildly under resourced. One hypothetical argument about enforcement might be that in an ID database world, the state must finance the Information Comissioner as fully as it finances the police. (yeh right :-)
But most of all I'd like to see a debate on ID cards that isn't focused around "it'll never work" or "it'll cost too much" or "they can't make me do this" or "we all know it's a bunch of lies". That isn't a debate. That's a lynching. I'd like to see a debate that focuses round the real issues: how do we want to balance our needs for privacy and our needs for security? How, if at all, do we want to balance our privacy rights and the positive uses that can be made of a linked database, for both citizens and consumers? What are the safeguards that need to be built in, which once specified we can then pass to the database builders? And most of all what kind of privacy do most people really want - not the activists, not the No2ID card people, not the constitutional law academics, but everyone?
(Thanks for ideas included herein from my fellow panellists Dave Clements, Andrew Adams and Mike Scott.)
Not computer viruses this time ..!
My colleague Michael Bromby passes me an evocative example of why anonymity on the Internet is still sometimes a Really Good Idea.
Anonymous notification of STDs (with cool graphics, no less!)
Anonymous notification of STDs (with cool graphics, no less!)
Monday, April 17, 2006
Authentication algorithms, and more Oysters for Easter
Tired, like me, of deciphering skewed letters and numbers in order to persuade a site that you're not a spambot?
This new authentication system is based on recognition of fluffy animals - specifically picking 3 kittens out of a 3 X 3 block of cute animals. It's fun and it definitely picks out the human beings.. I don't THINK it's a late April fool and it somehow seems very appropriate for easter (though maybe that should have been bunnies..?)
Blogscript has been to another, non-law, conference which shall Not Be Named, where, as usual, she nonetheless spent a good part of her time talking about IT law, and participated in a rather good panel discussion about ID cards and ubiquitous surveillance. I discovered that in re the Oyster card discussion of a few weeks back, although not much publicised, you can apparently buy "anonymous" Oyster cards ie ones without identifying information either stored on, or accessible via, the card, for particular cash values. Furthermore, unlike normal travel tickets, these are officially freely transferable. This seems to overcome the traceability problem, rather as pay as you go phones do: but it raises a new legal issue - since these prepaid transferable Oyster cards are essentially stored value digital cash, are London Transport an electronic money issuer and subject to the regulations of the Electronic Money Directive? Answer - I think not, because those rules only apply to electronic money issuers where the stored value is accepted by multiple outlets (hence store loyalty cards are also excluded.) But if as reported a while back, London Transport do intend the Oyster cards to be picked up by private enterprise as a means of paying for low value items like sweets, papers or coffees, that might change..
For those who want to seriously confuse any potential investigators of Oyster card electronic tracks, eg anti terrorist squads, private detectives, it was also suggested that season ticket users could meet up and swap cards two or three times a day.. although one feels this might interfere with the average commuter's actual working day.. Interesting stuff!
This new authentication system is based on recognition of fluffy animals - specifically picking 3 kittens out of a 3 X 3 block of cute animals. It's fun and it definitely picks out the human beings.. I don't THINK it's a late April fool and it somehow seems very appropriate for easter (though maybe that should have been bunnies..?)
Blogscript has been to another, non-law, conference which shall Not Be Named, where, as usual, she nonetheless spent a good part of her time talking about IT law, and participated in a rather good panel discussion about ID cards and ubiquitous surveillance. I discovered that in re the Oyster card discussion of a few weeks back, although not much publicised, you can apparently buy "anonymous" Oyster cards ie ones without identifying information either stored on, or accessible via, the card, for particular cash values. Furthermore, unlike normal travel tickets, these are officially freely transferable. This seems to overcome the traceability problem, rather as pay as you go phones do: but it raises a new legal issue - since these prepaid transferable Oyster cards are essentially stored value digital cash, are London Transport an electronic money issuer and subject to the regulations of the Electronic Money Directive? Answer - I think not, because those rules only apply to electronic money issuers where the stored value is accepted by multiple outlets (hence store loyalty cards are also excluded.) But if as reported a while back, London Transport do intend the Oyster cards to be picked up by private enterprise as a means of paying for low value items like sweets, papers or coffees, that might change..
For those who want to seriously confuse any potential investigators of Oyster card electronic tracks, eg anti terrorist squads, private detectives, it was also suggested that season ticket users could meet up and swap cards two or three times a day.. although one feels this might interfere with the average commuter's actual working day.. Interesting stuff!
Friday, April 14, 2006
The IT Crowd Goes to Westminster
Am off again for the Easter weekend. But not before quoting this delightful exchange from a recent debate in Parliament on the new law (yes that one again!) making it (or intending to make it) illegal to design, use and sell hacking and DDOS tool kits.
"The hon. Member for Hornsey and Wood Green (Lynne Featherstone) was right to raise the issue that hacking tools are often used by computer technicians to rectify problems. I have been very stressed since Monday morning, when I switched on my desktop computer in Norman Shaw, North only to get an error message and find that I could not access my programmes, my e-mail or anything else. Fortunately, I have another computer. I phoned extension 2001 and eventually managed to speak to an intelligent life form, although it took a little while, as we know happens with extension 2001.
The Chairman: Order. The hon. Gentleman’s travails are deeply fascinating to the Committee, but we have to get back to the amendment under consideration.
Michael Fabricant: As ever, I accept your guidance, Mr. Conway. Mr. Graham Lugton, who I suspect is in my room this very moment, might be using that [diagnostic tool] software.
Stephen Pound (Ealing, North) (Lab): Wiping your history, I hope."
See http://www.publications.parliament.uk/pa/cm200506/cmstand/d/st060328/am/60328s03.htm .
"The hon. Member for Hornsey and Wood Green (Lynne Featherstone) was right to raise the issue that hacking tools are often used by computer technicians to rectify problems. I have been very stressed since Monday morning, when I switched on my desktop computer in Norman Shaw, North only to get an error message and find that I could not access my programmes, my e-mail or anything else. Fortunately, I have another computer. I phoned extension 2001 and eventually managed to speak to an intelligent life form, although it took a little while, as we know happens with extension 2001.
The Chairman: Order. The hon. Gentleman’s travails are deeply fascinating to the Committee, but we have to get back to the amendment under consideration.
Michael Fabricant: As ever, I accept your guidance, Mr. Conway. Mr. Graham Lugton, who I suspect is in my room this very moment, might be using that [diagnostic tool] software.
Stephen Pound (Ealing, North) (Lab): Wiping your history, I hope."
See http://www.publications.parliament.uk/pa/cm200506/cmstand/d/st060328/am/60328s03.htm .
Wednesday, April 12, 2006
Booby Job of the Week
This appeared shyly on an on line recruitment list I (used to) subscribe to..
Vacancy Title: Chief Executive
Location(s): London
Reference:
Department: Home Office
Salary: Not specified
Brief description: The National Identity Scheme is being delivered through a new Executive Agency (IPS) formed from the UK Passport Service and the Identity Cards Programme. IPS will work closely with other parts of the Government and private sector organisations to deliver the wide-ranging benefits expected of the scheme.
Working Arrangement(s): Full Time
Closing Date: 8 May 2006
More Information: http://www.careers.civilservice.gov.uk/index.asptxtOverRideDocID=19945
Any volunteers?-)
Vacancy Title: Chief Executive
Location(s): London
Reference:
Department: Home Office
Salary: Not specified
Brief description: The National Identity Scheme is being delivered through a new Executive Agency (IPS) formed from the UK Passport Service and the Identity Cards Programme. IPS will work closely with other parts of the Government and private sector organisations to deliver the wide-ranging benefits expected of the scheme.
Working Arrangement(s): Full Time
Closing Date: 8 May 2006
More Information: http://www.careers.civilservice.gov.uk/index.asptxtOverRideDocID=19945
Any volunteers?-)
Gadding About for Fun and Profit, oops, non-profit..
Having not yet opened my suitcase from last (highly stimulating and not at all sunny:-) jaunt to Malta, I have to admit that this conference upcoming in June is very tempting. And not only because it's being held in Rio:-)
"The aim of iCommons reaches far beyond the infrastructure that CC is building. The aim of the iSummit is to bring together a wide range of people in addition the CC crowd - including Wikipedians, Free Software sorts, the Free Culture kids, A2K heroes, Open Access advocates, and others -- to "to inspire and learn from one another and establish closer working relationships around a set of incubator projects." iCommons has a separate board from Creative Commons -- Joi Ito is its chair -- and its ultimate mission (in addition to this annual moveable feast of commons conversation) will be determined by the conversation that will continue in Rio." See further Lessig blog.
Having just come from the launch of Creative Commons Malta with that self same Lessig in attendance(at, uh, that conference mentioned in the previous item with the name that sounds like a skin disease), I was becoming a mite cynical about how much I actually still had to learn about CC and its international progeny. It's a lovely idea for a religion (as Ron Hubbard is once said to have declared in another context), but as far as actual law goes, it's just software licenses after all - would it go down as well with the great washed open source yoof if it was called Just Another Type of Licensing, rather than the much groovier Creative Commons? (I may yet write my paper on this for GikII, Martina...!)
But the move towards collaborative creation of, and open access to, knowledge in general - and the future of wikis and Wikipedia in particular - is something that I think is becoming of crucuial importance in the development of the Web and the nurturing of knowledge - including legal knowledge. So maybe I'll go after all.
And IT law conferences are like buses - no good ones for ages then three come along in one month. Having already decided I really don't have time for the The First International Conference on Legal, Security and Privacy Issues in IT, April 30- May 3, 2006, Hamburg, Germany, I now get an invite (at BILETA - no website I can find yet) to the even more enticing LEFIS Monitoring and Supervision Workshop in Rotterdam in - guess when - June!
Good thing my union is on strike so with any luck we won't be marking any poxy exams in June, huh?
**EDIT: In the interests of fairness and open access!, I should add details of yet another victim (for me) of the June pile up, namely IT and the Legal Learning Space,
The 9th bi-annual conference on Substantive Technology in the Law School, Oslo Thursday 29, Friday 30 June and Saturday 1 July 2006. In the past this conference (colloquially known as Subtech ) has been one of the higlights of the acdemic year, and this year it is to be run by the Oslo people and that colossus of the field , Jon Bing - I hate to face the reality that this year, I just can't prioritise over at least 2 of the 3 others listed above..
And it doesn't end there. July 10th-11th 2006 sees another goody, the Unlocking IP conference in UNSW, Sydney, Australia, courtesy of the ever energetic Graham Greenleaf and his team at AustLII. It's going to be a long hot summer for (well funded and time-rich) open source/creative commons mavens: if they don't change the world they should at least come home with a tan and knowing how to (a) light a barbie and (b)salsa..
"The aim of iCommons reaches far beyond the infrastructure that CC is building. The aim of the iSummit is to bring together a wide range of people in addition the CC crowd - including Wikipedians, Free Software sorts, the Free Culture kids, A2K heroes, Open Access advocates, and others -- to "to inspire and learn from one another and establish closer working relationships around a set of incubator projects." iCommons has a separate board from Creative Commons -- Joi Ito is its chair -- and its ultimate mission (in addition to this annual moveable feast of commons conversation) will be determined by the conversation that will continue in Rio." See further Lessig blog.
Having just come from the launch of Creative Commons Malta with that self same Lessig in attendance(at, uh, that conference mentioned in the previous item with the name that sounds like a skin disease), I was becoming a mite cynical about how much I actually still had to learn about CC and its international progeny. It's a lovely idea for a religion (as Ron Hubbard is once said to have declared in another context), but as far as actual law goes, it's just software licenses after all - would it go down as well with the great washed open source yoof if it was called Just Another Type of Licensing, rather than the much groovier Creative Commons? (I may yet write my paper on this for GikII, Martina...!)
But the move towards collaborative creation of, and open access to, knowledge in general - and the future of wikis and Wikipedia in particular - is something that I think is becoming of crucuial importance in the development of the Web and the nurturing of knowledge - including legal knowledge. So maybe I'll go after all.
And IT law conferences are like buses - no good ones for ages then three come along in one month. Having already decided I really don't have time for the The First International Conference on Legal, Security and Privacy Issues in IT, April 30- May 3, 2006, Hamburg, Germany, I now get an invite (at BILETA - no website I can find yet) to the even more enticing LEFIS Monitoring and Supervision Workshop in Rotterdam in - guess when - June!
Good thing my union is on strike so with any luck we won't be marking any poxy exams in June, huh?
**EDIT: In the interests of fairness and open access!, I should add details of yet another victim (for me) of the June pile up, namely IT and the Legal Learning Space,
The 9th bi-annual conference on Substantive Technology in the Law School, Oslo Thursday 29, Friday 30 June and Saturday 1 July 2006. In the past this conference (colloquially known as Subtech ) has been one of the higlights of the acdemic year, and this year it is to be run by the Oslo people and that colossus of the field , Jon Bing - I hate to face the reality that this year, I just can't prioritise over at least 2 of the 3 others listed above..
And it doesn't end there. July 10th-11th 2006 sees another goody, the Unlocking IP conference in UNSW, Sydney, Australia, courtesy of the ever energetic Graham Greenleaf and his team at AustLII. It's going to be a long hot summer for (well funded and time-rich) open source/creative commons mavens: if they don't change the world they should at least come home with a tan and knowing how to (a) light a barbie and (b)salsa..
Wikipedia vs Linux
Fascinating comparison of the numbers of users and active contributors to Linux and Wikipedia.
"Wikipedia can draw on half a billion potential contributors; only about 100,000 people can code Linux.
It's hard to overstate this difference."
So, yes, I'm back from BILETA in Malta (the annual reunion of the UK and increasingly, European/Asian IT Law, Internet law, and legal technology in education tribes.) Saw lots of interesting papers, some of which may even be written up when I've regained the energy, after twelve hours travelling on two hours sleep, to open my bag and find my conference abstract programme.
After last year's deluge of P2P and FOSS papers, this year, much talk of eBay, Flickr, Wikipedia, Jurispedia and Wikis as the new legal textbooks - looks like C2C and collaborative peer production models have hit the legal hive mind..
"Wikipedia can draw on half a billion potential contributors; only about 100,000 people can code Linux.
It's hard to overstate this difference."
So, yes, I'm back from BILETA in Malta (the annual reunion of the UK and increasingly, European/Asian IT Law, Internet law, and legal technology in education tribes.) Saw lots of interesting papers, some of which may even be written up when I've regained the energy, after twelve hours travelling on two hours sleep, to open my bag and find my conference abstract programme.
After last year's deluge of P2P and FOSS papers, this year, much talk of eBay, Flickr, Wikipedia, Jurispedia and Wikis as the new legal textbooks - looks like C2C and collaborative peer production models have hit the legal hive mind..
Monday, April 03, 2006
The DOS wars: Blogscript strikes back
Blogscript sadly fell beneath the waves of overwork at rather the wrong time to make a dent in the amendment process to the Police and Justice Bill revisions of the CMA 1990. Well, inspired by general waves of self congratulation from everyone form the APIG to the BCS, I feel inclined to remark in curmudgeonly way that I'm still not at all happy that the CMA amendments will do anything to water-tightly criminalise DOS in the UK. See my previous blog post at http://blogscript.blogspot.com/2006/01/denial-of-service-i-told-you-so-part.html .
If the latest version of the PJB is as at http://www.publications.parliament.uk/pa/cm200506/cmbills/119/06119.27-33.html, which I *think* it is, then it seems the amendments made have changed nothing useful (in cl 34 - cl 35 has been improved).
The crucial point is that in cl 34 it now reads:(I paraphrase)
S 3(1)CMA90 is amended to say
"A person is guilty of an offence if—
(a) he does any unauthorised act in relation to a computer;
AND (emphasis added)
(b) at the time when he does the act he has the requisite intent and
the requisite knowledge."
It doesn't help to define the intent required by s 3(1)(b) to include intent to impair* if s 3(1)(a) can't be established. You need both pre conditions for a conviction. And as things stand, post last year's DOS acquittal, someone who sends ordinary email or page requests etc to an open website is still not "unauthorised".
What is needed is to re-define or clarify "unauthorised". One easy way might be something like "The owner or operator of a website or server is rebuttably presumed not to give authorisation to the sending of data or traffic to that site where it is sent for the primary purpose of [insert the terms from s 3(2)]*".
I can't see any attempt to clarify "unauthorised" in the PJB. Worse still, we stil have s 3(4) declaring that "For the purposes of subsection (1)(b) above the requisite knowledge is knowledge that the act in question is unauthorised".
I sincerely hope I've missed something. Pah. Why do we expect MPs to draft legislation? We don't expect them to perform heart surgery or build bridges. Why is drafting law, a difficult and skilled task, treated as amateur hour?
* s 3(2) CMA 1990: " (a)to impair the operation of any computer,
(b) to prevent or hinder access to any program or data held in any
computer, or
(c) to impair the operation of any such program or the reliability of any such data,
whether permanently or temporarily."
If the latest version of the PJB is as at http://www.publications.parliament.uk/pa/cm200506/cmbills/119/06119.27-33.html, which I *think* it is, then it seems the amendments made have changed nothing useful (in cl 34 - cl 35 has been improved).
The crucial point is that in cl 34 it now reads:(I paraphrase)
S 3(1)CMA90 is amended to say
"A person is guilty of an offence if—
(a) he does any unauthorised act in relation to a computer;
AND (emphasis added)
(b) at the time when he does the act he has the requisite intent and
the requisite knowledge."
It doesn't help to define the intent required by s 3(1)(b) to include intent to impair* if s 3(1)(a) can't be established. You need both pre conditions for a conviction. And as things stand, post last year's DOS acquittal, someone who sends ordinary email or page requests etc to an open website is still not "unauthorised".
What is needed is to re-define or clarify "unauthorised". One easy way might be something like "The owner or operator of a website or server is rebuttably presumed not to give authorisation to the sending of data or traffic to that site where it is sent for the primary purpose of [insert the terms from s 3(2)]*".
I can't see any attempt to clarify "unauthorised" in the PJB. Worse still, we stil have s 3(4) declaring that "For the purposes of subsection (1)(b) above the requisite knowledge is knowledge that the act in question is unauthorised".
I sincerely hope I've missed something. Pah. Why do we expect MPs to draft legislation? We don't expect them to perform heart surgery or build bridges. Why is drafting law, a difficult and skilled task, treated as amateur hour?
* s 3(2) CMA 1990: " (a)to impair the operation of any computer,
(b) to prevent or hinder access to any program or data held in any
computer, or
(c) to impair the operation of any such program or the reliability of any such data,
whether permanently or temporarily."
Thursday, March 30, 2006
Predictiions that went flop..
Not all IT related by any means, but I particularly like these three:
«This antitrust thing will blow over.»
Bill Gates, founder of Microsoft.
«Remote shopping, while entirely feasible, will flop - because women like to get out of the house, like to handle merchandise, like to be able to change their minds.»
TIME, 1966, in one sentence writing off e-commerce long before anyone had ever heard of it.
«There is no reason anyone would want a computer in their home.»
Ken Olson, president, chairman and founder of Digital Equipment Corp. (DEC), maker of big business mainframe computers, arguing against the PC in 1977.
BlogScript knows it's been a bit thin lately: it's sorry, but it's had new job negotiations and end of term to deal with, is off to funeral, and then off to BILETA, the UK/EU national IT law conference, in Malta, where hopefully it will not only give a paper on eBay and update itself on the latest in Islamic data protection law (for real!) but also try out of every one of the four pools at the conference centre hotel :-) After that, mega content!!
«This antitrust thing will blow over.»
Bill Gates, founder of Microsoft.
«Remote shopping, while entirely feasible, will flop - because women like to get out of the house, like to handle merchandise, like to be able to change their minds.»
TIME, 1966, in one sentence writing off e-commerce long before anyone had ever heard of it.
«There is no reason anyone would want a computer in their home.»
Ken Olson, president, chairman and founder of Digital Equipment Corp. (DEC), maker of big business mainframe computers, arguing against the PC in 1977.
BlogScript knows it's been a bit thin lately: it's sorry, but it's had new job negotiations and end of term to deal with, is off to funeral, and then off to BILETA, the UK/EU national IT law conference, in Malta, where hopefully it will not only give a paper on eBay and update itself on the latest in Islamic data protection law (for real!) but also try out of every one of the four pools at the conference centre hotel :-) After that, mega content!!
Thursday, March 23, 2006
Cruel and Unusual Punishment
MMORPG reintroduces crucifixion.
I wittily suggested that if online personae do exist, and have human rights (as my PhD student is currently trying to claim) then they could certainly claim this was torture and so illegal under the ECHR. A passing computer gamer however noted "And so is getting shot in the face."
Point taken. There are some places law should not go :-)
I wittily suggested that if online personae do exist, and have human rights (as my PhD student is currently trying to claim) then they could certainly claim this was torture and so illegal under the ECHR. A passing computer gamer however noted "And so is getting shot in the face."
Point taken. There are some places law should not go :-)
Sunday, March 19, 2006
Read and wee(ip)
Great collection of IP overkill stories - fun for all the family!
Thanks for the tip to Andrew Ducker.
Thanks for the tip to Andrew Ducker.
Tuesday, March 14, 2006
Free wi fi = free beer, free speech or stolen beer?
Interesting discovery - an outfit called FON who are aiming to provide access to members ("Foneros") to free but secure wi fi wherever you go. They're backed by some heavyweight names like Esther Dyson and Dan Gilmore. Basically, individuals are encouraged to sign up to FON and buy a FON-equipped router, (for the reduced sum of 25 Euros/USD)which allows other FON users to use their bandwidth, via pre arranged usernames and passwords, wherever they go. FON undertake that the original user will always be left with a "reasonable amount of bandwidth" whatever that means :-) - and it does have the big advantage of meaning you can share a wi fi connection with pals without leaving it unsecured.
The big question, of course, is how legal is it? A while back as an anecdotal exercise I looked at a few UK ISP subscriber contracts and found that few, if any, had any direct prohibition on bandwidth sharing. Yet one imagines they wouldn't be too happy if this sort of wi fi sharing took off globally. The FON people themselves rather cleverly cover their backs with a term in the legal notice:
"In accordance with the Terms and Conditions of Use of FON Services, Foneros who enter the FON Community must have access to the Internet where they are permitted to share bandwidth with others and/or to download FON Software onto your router."
Of course there is no implication that they will check this so the legal risk falls on the users, which is of even less comfort to ISPs one imagine - always better to have a node to sue than a multiplicity of users. (Can we foresee the invention of the tort of inducement of wireless bandwidth theft a la Grokster??)
There's also a few cases lately in US and UK which hold that war-chalking - stealing bandwidth without the consent of the original bandwidth renter - is a crime. Yet this is IMHO not that either, since everyone involved in the FON network has consented to wi fi sharing.
So I conclude it's legal. Stick Skype or similar on your PDA (the new Orange SPV 3G phone will do this nicely, even though it is the size of a brick) and you need never pay a long distance phone bill again. Will this take off? I wonder. My own needs for wireless are most prominent (a) in hotels (b) in airports - and neither is somewhere where FON subscribers are likely to live and have a FON router set up. But then I'm quite hapy to pay my £15 a month for broadband from Telewest - maybe others are more canny/mean.
The big question, of course, is how legal is it? A while back as an anecdotal exercise I looked at a few UK ISP subscriber contracts and found that few, if any, had any direct prohibition on bandwidth sharing. Yet one imagines they wouldn't be too happy if this sort of wi fi sharing took off globally. The FON people themselves rather cleverly cover their backs with a term in the legal notice:
"In accordance with the Terms and Conditions of Use of FON Services, Foneros who enter the FON Community must have access to the Internet where they are permitted to share bandwidth with others and/or to download FON Software onto your router."
Of course there is no implication that they will check this so the legal risk falls on the users, which is of even less comfort to ISPs one imagine - always better to have a node to sue than a multiplicity of users. (Can we foresee the invention of the tort of inducement of wireless bandwidth theft a la Grokster??)
There's also a few cases lately in US and UK which hold that war-chalking - stealing bandwidth without the consent of the original bandwidth renter - is a crime. Yet this is IMHO not that either, since everyone involved in the FON network has consented to wi fi sharing.
So I conclude it's legal. Stick Skype or similar on your PDA (the new Orange SPV 3G phone will do this nicely, even though it is the size of a brick) and you need never pay a long distance phone bill again. Will this take off? I wonder. My own needs for wireless are most prominent (a) in hotels (b) in airports - and neither is somewhere where FON subscribers are likely to live and have a FON router set up. But then I'm quite hapy to pay my £15 a month for broadband from Telewest - maybe others are more canny/mean.
Tuesday, March 07, 2006
Click and dick?
The Harlow Star reports that a councillor who was sacked for downloading obscene pictures has failed in his attempts to have the monitoring employed by the council declared illegal. Judge Bradbury said the council was entitled to monitor its computers to avoid breaches of its code of conduct, which includes a prohibition on accessing pornography.
This is of a fair bit of interest legally, as very UK few reported decisions at courts (not EAT) level exist dealing with the legality of electronic employee surveillance, a matter which has been controversial ever since the Lawful Business Regulations and the Information Commissioner's Code on Employee Monitoring came out. But casual readers wil I suspect best remember this case for the councillor's excuse - he wasn't downloading porn, he was just checking out condom sizes as part of his role as the Liberal Democrat group's health spokesman conduting research into the European Union's recommended size for condoms.
Pull the other one, Matthew, it's got bells on it:-)
I am reminded of this delightful song - "Grab your dick and double click.."!
This is of a fair bit of interest legally, as very UK few reported decisions at courts (not EAT) level exist dealing with the legality of electronic employee surveillance, a matter which has been controversial ever since the Lawful Business Regulations and the Information Commissioner's Code on Employee Monitoring came out. But casual readers wil I suspect best remember this case for the councillor's excuse - he wasn't downloading porn, he was just checking out condom sizes as part of his role as the Liberal Democrat group's health spokesman conduting research into the European Union's recommended size for condoms.
Pull the other one, Matthew, it's got bells on it:-)
I am reminded of this delightful song - "Grab your dick and double click.."!
Is dongle still just a silly word?
.. or is two factor authentication the coming saviour for security in online banking?
Alliance and Leicester is set to roll out two-factor authentication to its internet banking customers.Two-factor authentication usually couples a password with some kind of device that generates a second passphrase. The isdea is that this makes it harder for fraudsters to steal both passwords and is therefore more secure than traditional methods of internet banking.
Bruce Schneier disagrees.
"The problem with passwords is that they're too easy to lose control of. People give them to other people. People write them down, and other people read them. ...
Two-factor authentication mitigates this problem. If your password includes a number that changes every minute, or a unique reply to a random challenge, then it's harder for someone else to intercept. You can't write down the ever-changing part. An intercepted password won't be good the next time it's needed. And a two-factor password is harder to guess. Sure, someone can always give his password and token to his secretary, but no solution is foolproof.
These tokens have been around for at least two decades, but it's only recently that they have gotten mass-market attention. AOL is rolling them out. Some banks are issuing them to customers, and even more are talking about doing it. It seems that corporations are finally waking up to the fact that passwords don't provide adequate security, and are hoping that two-factor authentication will fix their problems.
Unfortunately, the nature of attacks has changed over those two decades. Back then, the threats were all passive: eavesdropping and offline password guessing. Today, the threats are more active: phishing and Trojan horses."
So as Schneier says, imagine a customer is duped by a phishing email and website. He types in his password and he plugs in his dongle to generate a one time authentication code. As now, the site harvest both and logs in as him at the real site. How are we any further on? For a short while phishers may switch their attention to the old password-only sites as easier to crack, but that's just a blip till everyone has gone two-factor authenticated. the same problem arises if a Trojan is sitting on your hard disc harvesting everything you type in or send to a log in on a site.
back to the dongle board, folks..
Alliance and Leicester is set to roll out two-factor authentication to its internet banking customers.Two-factor authentication usually couples a password with some kind of device that generates a second passphrase. The isdea is that this makes it harder for fraudsters to steal both passwords and is therefore more secure than traditional methods of internet banking.
Bruce Schneier disagrees.
"The problem with passwords is that they're too easy to lose control of. People give them to other people. People write them down, and other people read them. ...
Two-factor authentication mitigates this problem. If your password includes a number that changes every minute, or a unique reply to a random challenge, then it's harder for someone else to intercept. You can't write down the ever-changing part. An intercepted password won't be good the next time it's needed. And a two-factor password is harder to guess. Sure, someone can always give his password and token to his secretary, but no solution is foolproof.
These tokens have been around for at least two decades, but it's only recently that they have gotten mass-market attention. AOL is rolling them out. Some banks are issuing them to customers, and even more are talking about doing it. It seems that corporations are finally waking up to the fact that passwords don't provide adequate security, and are hoping that two-factor authentication will fix their problems.
Unfortunately, the nature of attacks has changed over those two decades. Back then, the threats were all passive: eavesdropping and offline password guessing. Today, the threats are more active: phishing and Trojan horses."
So as Schneier says, imagine a customer is duped by a phishing email and website. He types in his password and he plugs in his dongle to generate a one time authentication code. As now, the site harvest both and logs in as him at the real site. How are we any further on? For a short while phishers may switch their attention to the old password-only sites as easier to crack, but that's just a blip till everyone has gone two-factor authenticated. the same problem arises if a Trojan is sitting on your hard disc harvesting everything you type in or send to a log in on a site.
back to the dongle board, folks..
Monday, March 06, 2006
EBay Makes Your Eyes Water
According to the Beeb, a prosecution brought against eBay.co.uk by the General Optical Council, for aiding and abetting in the illegal sale of contact lenses by persons other than registered opticians, under the Opticians Act 1989, has been dropped, after advice that EBay was protected by European law. One can only assume this refers to Art 14 of the EC Electronic Commerce Directive as implemented in the UK by the 2002 Regulations of the same name. Under this law, reg 19 states that:
"Where an information society service is provided which consists of the storage of information provided by a recipient of the service, the service provider (if he otherwise would) shall not be liable for damages or for any other pecuniary remedy or for any criminal sanction as a result of that storage where -
(a) the service provider -
(i) does not have actual knowledge of unlawful activity or information and, where a claim for damages is made, is not aware of facts or circumstances from which it would have been apparent to the service provider that the activity or information was unlawful; or
(ii) upon obtaining such knowledge or awareness, acts expeditiously to remove or to disable access to the information, and
(b) the recipient of the service was not acting under the authority or the control of the service provider.
EBay's involvement came from some 200 individuals selling contact lenses via its site listings, not from any direct commercial activities of its own. What the GOC seem to have accepted then is that, as EBay themselves put it, "as an "information society service provider", [EBay's] duty is simply to remove illegal sale notices from its site when it is made aware of them, rather than to comb through it for them". This interpretation is reinforced by Art 15 of the Electronic Commerce Directive which provides that EC states shall not impose positive obligations of monitoring on information society service providers.
As the Beeb report points out, this leaves the GOC, as a public regulator, in a highly unsatisfactory position. The GOC spokesman said: "We feel that it is an unreasonable burden for a regulator, with limited resources, to have to monitor the millions of listings on auction websites. In effect, we would have to notify the website of each individual instance of an illegal sale in order for it to be de-listed."
But did the GOC cave too soon? First, Art 15 was never transposed into UK law. Arguably this makes no difference as remedies can be obtained in respect of Directives even where not transposed into domestic law, but it is still rather odd.
Secondly, and rather controversially, could it be argued that the EBay sellers of contact lenses were acting "under the authority or the control of" EBay? EBay do contractually allow sellers to sell on its site, and take a cut of the profits for doing so. Is this not "authority"? As I have noted before, they are hardly in the same position as a traditional ISP handling myriads of communications in a hands off way. EBay furthermore do at least present something that looks rather like "control" in that they have various Acceptable Use policies relating to what can and cannot be sold on EBay. Contact lenses are specifically mentioned under the "prohibited" list. EBay do their best to make these warnings look advisory - "eBay is here to help, but you are ultimately responsible for making sure that buying an item or selling your item(s) is allowed on eBay and is not prohibited in the eyes of the law. Follow these steps to find out whether or not your item can be listed on eBay."
- but such words cannot detract from the fact that it seems a reasonable interpretation that eBay's various "prohibited" policies for buyers and sellers are incorporated by reference as part of the terms of the contract with eBay .
If eBay can be characterised as having either "authority or control" then the immunity provided by reg 19 in respect of criminal liability will fail to protect them.
Thirdly, nothing in the ECD or the UK regs stops a litigant seeking an injunction or interdict in relation to hosting liability. Reg 20 states: "Nothing in regulations 17, 18 and 19 shall ...(b) affect the rights of any party to apply to a court for relief to prevent or stop infringement of any rights." This language speaks of civil law rights, but could it be read also as allowing the GOC to take an injunction preventing eBay from selling contact lenses without a trained optician on staff? If so, the regulator's need for swift and single-targeted action can be met. Such an approach would not be out of step with the rest of the EU - in Germany, in two cases, the Supreme Court has allowed injunctions against on line auction sites in respect of illegal content they were hosting.
This case is significant for more than just the illegal sale of contact lenses. It is the first UK case, and one of the first EU cases, to decide in any shape or form whether eBay's habitual claim of immunity as a "neutral intermediary" will be unquestioningly accepted. As reported on this blog earlier, an action is also pending from Tiffany the diamond sellers in relation to rampant trademark infringement on eBay. If the GOC case is accepted in practice as any kind of precedent (it is not in strict law, being simply the abandonment of the case), it will be hard for any case on civil or criminal hosting liability to stand up against eBay.
Yet in a civil case such as a trademark infringement action, eBay can be held liable not just if it has actual notice, but also if it has constructive knowledge of the infringement. So in the upcoming TM case, I expect to see evidence that eBay must reasonably have known that its listings were full of counterfeit Tiffany goods, even if it was not compelled to actually monitor its site to see just how many counterfeit listings it had - simply from the NTD requests it received on an ongoing basis. The very advice eBay gives about prohibited listings could be seen as evidence that eBay knew quite well these sort of goods were habitually sold on its site. If that were to be proven - and it would not be hard, one feels - a defense of take down only on actual notice would be irrelevant.
Anyone know what lawyers advised the GOC?
"Where an information society service is provided which consists of the storage of information provided by a recipient of the service, the service provider (if he otherwise would) shall not be liable for damages or for any other pecuniary remedy or for any criminal sanction as a result of that storage where -
(a) the service provider -
(i) does not have actual knowledge of unlawful activity or information and, where a claim for damages is made, is not aware of facts or circumstances from which it would have been apparent to the service provider that the activity or information was unlawful; or
(ii) upon obtaining such knowledge or awareness, acts expeditiously to remove or to disable access to the information, and
(b) the recipient of the service was not acting under the authority or the control of the service provider.
EBay's involvement came from some 200 individuals selling contact lenses via its site listings, not from any direct commercial activities of its own. What the GOC seem to have accepted then is that, as EBay themselves put it, "as an "information society service provider", [EBay's] duty is simply to remove illegal sale notices from its site when it is made aware of them, rather than to comb through it for them". This interpretation is reinforced by Art 15 of the Electronic Commerce Directive which provides that EC states shall not impose positive obligations of monitoring on information society service providers.
As the Beeb report points out, this leaves the GOC, as a public regulator, in a highly unsatisfactory position. The GOC spokesman said: "We feel that it is an unreasonable burden for a regulator, with limited resources, to have to monitor the millions of listings on auction websites. In effect, we would have to notify the website of each individual instance of an illegal sale in order for it to be de-listed."
But did the GOC cave too soon? First, Art 15 was never transposed into UK law. Arguably this makes no difference as remedies can be obtained in respect of Directives even where not transposed into domestic law, but it is still rather odd.
Secondly, and rather controversially, could it be argued that the EBay sellers of contact lenses were acting "under the authority or the control of" EBay? EBay do contractually allow sellers to sell on its site, and take a cut of the profits for doing so. Is this not "authority"? As I have noted before, they are hardly in the same position as a traditional ISP handling myriads of communications in a hands off way. EBay furthermore do at least present something that looks rather like "control" in that they have various Acceptable Use policies relating to what can and cannot be sold on EBay. Contact lenses are specifically mentioned under the "prohibited" list. EBay do their best to make these warnings look advisory - "eBay is here to help, but you are ultimately responsible for making sure that buying an item or selling your item(s) is allowed on eBay and is not prohibited in the eyes of the law. Follow these steps to find out whether or not your item can be listed on eBay."
- but such words cannot detract from the fact that it seems a reasonable interpretation that eBay's various "prohibited" policies for buyers and sellers are incorporated by reference as part of the terms of the contract with eBay .
If eBay can be characterised as having either "authority or control" then the immunity provided by reg 19 in respect of criminal liability will fail to protect them.
Thirdly, nothing in the ECD or the UK regs stops a litigant seeking an injunction or interdict in relation to hosting liability. Reg 20 states: "Nothing in regulations 17, 18 and 19 shall ...(b) affect the rights of any party to apply to a court for relief to prevent or stop infringement of any rights." This language speaks of civil law rights, but could it be read also as allowing the GOC to take an injunction preventing eBay from selling contact lenses without a trained optician on staff? If so, the regulator's need for swift and single-targeted action can be met. Such an approach would not be out of step with the rest of the EU - in Germany, in two cases, the Supreme Court has allowed injunctions against on line auction sites in respect of illegal content they were hosting.
This case is significant for more than just the illegal sale of contact lenses. It is the first UK case, and one of the first EU cases, to decide in any shape or form whether eBay's habitual claim of immunity as a "neutral intermediary" will be unquestioningly accepted. As reported on this blog earlier, an action is also pending from Tiffany the diamond sellers in relation to rampant trademark infringement on eBay. If the GOC case is accepted in practice as any kind of precedent (it is not in strict law, being simply the abandonment of the case), it will be hard for any case on civil or criminal hosting liability to stand up against eBay.
Yet in a civil case such as a trademark infringement action, eBay can be held liable not just if it has actual notice, but also if it has constructive knowledge of the infringement. So in the upcoming TM case, I expect to see evidence that eBay must reasonably have known that its listings were full of counterfeit Tiffany goods, even if it was not compelled to actually monitor its site to see just how many counterfeit listings it had - simply from the NTD requests it received on an ongoing basis. The very advice eBay gives about prohibited listings could be seen as evidence that eBay knew quite well these sort of goods were habitually sold on its site. If that were to be proven - and it would not be hard, one feels - a defense of take down only on actual notice would be irrelevant.
Anyone know what lawyers advised the GOC?
Wednesday, March 01, 2006
EFF attack Yahoo!/AOL email postage stamp
EFF are co ordinating mass opposition to Yahoo!/AOL's email postage stamp scheme, as blogged by me a few days ago. And bloody right too.
"A pay-to-send system won't help the fight against spam - in fact, this plan assumes that spam will continue and that mass mailers will be willing to pay to have their emails bypass spam filters. And non-paying spammers will not reduce the amount of mail they throw at your filters simply because others pay to evade them.
Perversely, the new two-tiered system AOL proposes would actually reward AOL financially for failing to maintain its email service. The chief advantage of paying to send CertifiedEmail is that it can bypass AOL's spam filters. Non-paying customers are being asked to trust that after paid mail goes into effect, AOL will properly maintain its spam filters so only unwanted mail gets thrown away.
But the economic incentives point the other way: The moment AOL switches to a two-tiered Internet where giant emailers pay for preferential service, AOL will face a simple business choice: spend money to keep regular spam filters up-to-date, or make money by neglecting their spam filters and pushing more senders to pay for guaranteed delivery. Poor delivery of mail turns from being a problem that AOL has every incentive to fix to something that could actually make them money if the company ignores it. "
"A pay-to-send system won't help the fight against spam - in fact, this plan assumes that spam will continue and that mass mailers will be willing to pay to have their emails bypass spam filters. And non-paying spammers will not reduce the amount of mail they throw at your filters simply because others pay to evade them.
Perversely, the new two-tiered system AOL proposes would actually reward AOL financially for failing to maintain its email service. The chief advantage of paying to send CertifiedEmail is that it can bypass AOL's spam filters. Non-paying customers are being asked to trust that after paid mail goes into effect, AOL will properly maintain its spam filters so only unwanted mail gets thrown away.
But the economic incentives point the other way: The moment AOL switches to a two-tiered Internet where giant emailers pay for preferential service, AOL will face a simple business choice: spend money to keep regular spam filters up-to-date, or make money by neglecting their spam filters and pushing more senders to pay for guaranteed delivery. Poor delivery of mail turns from being a problem that AOL has every incentive to fix to something that could actually make them money if the company ignores it. "
Tuesday, February 28, 2006
Subscribe to:
Posts (Atom)