Thursday, May 31, 2007

And More LJ..

Interesting climbdown.

I guess that one can be chalked up as another, albeit belated, victory for the users in web 2.0 culture - rather as with AACS and Digg.

It also makes it fairly plain that LJ's main worry was probably the appearance of locked communities to advertisers (where the visble content is mainly the "interests" - such as rape or paedophilia - rather than serious legal worries. Or perhaps that's too cynical.)

"We have always been strong supporters of free speech and at the same time we believe deeply that children deserve special protections as well as the victims of violence and hate. ... One could say that no matter what we did we would either be accused of opposing free speech or endangering children but I am sure we should and could have done this much better. "

I have a lot of sympathy:-)

Wednesday, May 30, 2007

Live Journal Attacked by Inocents (?)

A massive web 2.0-type censorship farrago has (yet again) engulfed Live Journal, probably the social blogging and networking site most popular with "fandom" - which includes the loose and vast collection of communities where people write slash fiction about under-age characters (as in Harry Potter and his cronies, for example.)

A rather shady outfit called Warriors for Innocence ("hunting pedophiles where they fester") appear to have either cajoled or threatened Live Journal (or its corporate owners, Six Apart) into taking down and/or deleting entries on a number of journals and communities whose "interests" keywords included terms like rape, teen, child and incest. In response , accusations are being made that some of these communities were for people who simply liked writing fan fiction and had absolutely no intention of encouraging or participating in sex with minors in "real life"; while other communities were actually doing positive good in that they were there to support incest survivors.

The usual web 2.0 battleground has now been thoroughly drawn up, with various calls for class actions for breach of contract against LJ, libel suits against WFI, claims WFI are actually an anti-LGBT group, and calls for symbolic one-day deletion of journals and user migration to other sites like GreatestJournal (which uses the same software as LJ and has been an alternative home in previous episodes of disenchantment with LJ, such as when default user icons showing breatfeeding and naked nipples (!) were banned).

The law as to LJ's possible liability seems at first clear, but has the odd wrinkle. First, no one seems very convinced that writing pedophilic literature (as opposed to taking, making, selling or distributing pictures of under age sex) is in fact any sort of criminal offence in any US state. Secondly, it is even less clear if publishing or facilitating the publication of such is a crime ("inducing pedophilia" anyone?). Thirdly, even if one assumes it is, would LJ be in any way criminally liable or would they be protected from liability? At first blush, this seems exactly the kind of situation the safe harbor of CDA was designed for. LJ , under the CDA, s 230 (c), as a service provider, should not be liable in respect of third party content.

However as every half awake blawger knows, the impact of s 230(c) on Web 2.0, user generated content sites has become steadily more blurry. As recently reported here, the social site Roommates.com was recently found liable by the Sixth Circuit for, in effect, publishing room listings placed by third parties which were in breach of anti-discrimination renting laws. Rommmates.com did not benefit from s 230 (c) because by providing a rigid template for entry of text, they had effectively become content providers, not just content platform provider.

It seems unlikely this would apply to LJ where almost all text is provided free form. On the other had, LJ does supply a "template" for journallers and communities to list their "interests" which are then used in searches. And it is these "interests" which are at the heart of LJ's current attempts at censorship. Could they have thought that Roommates.com left them at risk?

A rather more likely rumour is that LJ at first held firm, confident they were protected by the CDA, but panicked when WFI began going round their advertisers suggesting that LJ was not a nice place to hang out. This seems to have lead to a rather panicky surge of deletions of communities and journals. A more helpful approach would probably have been to have identified, before deletion or suspension, which communities were at least devoted to incest survivor support, and spared them the trouble of protest. Much of the furore also seems to surround accusations that LJ unilaterally changed its Terms of Service - yet it is completely clear that they reserved the right (sensibly) to do this at any time (clause 13, Revisions, of ToS).
Sparing "Fan" sites also seems a rather more difficult call: as Warren Ellis, the comics writer put it, "The outcome .. has been pure comedy, with comments that read very much like “I love spending all day reading about forced underage incestuous sex with squirrel fisting on top, but of course I’m not interested in that in real life — that’d make me a pervert!

Some "fan" writers have declared volubly that there is a vast difference between those who like to write fantasies of underage sex and those who'd ever wish to take part in them. PanGloss finds this a rather difficult call to expect a court, let alone a bunch of technohippies to make: surely every paedophile writer in the world would simply declare that oh no, they are merely a rampant Harry Potter slash fan?

Pangloss herself finds the degree of fan hysteria round this type of event a bit hard to stomach. LJ is a private site. It is not a state nor a common carrier nor a "public broadcaster" with positive obligations as to content, like the BBC in the UK. It is basically a business, one which rather oddly and sweetly does not seem to try to make maximum profits when it could (charge everyone, or show everyone ads.) The overwhelming majority of people using LJ still get their accounts and the extremely sophisticated functionality for free (and without advertising - ads are only given on consent, in return for which the user gets extra functionality, like being able to set up polls or have more user icons).

Yet in return for zero consideration, LJ seems to be expected by its clientele to take on a high dgree of risk in an uncertain area of law and to resist censorship at all costs. Yet in principle the situation is exactly as if Walmart had decided not to stock (say) Hello Kitty vibrators. Whether they are legal or not, it's Wallmart's store and Walmart's call. And if Walmart think those vibrators are a bit dodgy, either legally or in terms of alienating or annoying certain customers, then so be it. If they were stocking stuff they thought might or might not be legal, there isn't a lawyer in the world who wouldn't advise them to dump that stuff; and that's WALMART - who have millions of dollars and lawyers to fight prosecutions or civil suits.

An LJ or other web 2.0 site has the right to protect itself against the risk of being sued or prosecuted out of existence for taking on risk in an uncertain legal area. Would you rather have a world with LJ in it, albeit mildly policing the most extreme and likely to be dodgy of its boundaries, or a world with no LJ? Taking normal business steps to reduce legal risk is not the same as going over to the forces of censorship, fascism, illiberality and darkness.

It is interesting that many LJ users seem to feel LJ has a moral (not legal) duty to defend free speech over and above that of a normal business. PanGloss is not sure why. Isn't it good enough that they provide a global speech platform for free, and make efforts, it seems, not to "censor" (ie reduce legal risk) until someone with an agenda,like WFI, makes waves too big to ignore? In some ways , the web 2.0 social sites seem to have inherited the mantle of comforting and morally upright parent which we no longer expect of conventional nation states (?).



See also: Boing Boing

Useful links from LJ

Sample LJ Abuse team Letter

Wednesday, May 23, 2007

Blogzilla: Generation Y and privacy

Blogzilla has an interesting post on Generation Y and privacy.

I am in fact usually one of the doom sayers who argues that privacy norms and by extension, regulation, will have to change as the current Web 2.0 generation grows up. But perhaps I'm wrong? My very dear colleague Judith Rauhofer will be tackling the privacy "dark side" of Web 2.0 at my upcoming workshop in September (website coming soon.)

Tuesday, May 22, 2007

AllOfMP3.com declared fraudulent

Interesting story - the IFPI raid an agent of AllOfMP3.com, the infamous Russian-based illegal download service, in London.

"The individual was allegedly the UK-based European agent for allofmp3.com, facilitating the sale of digital downloads by advertising and selling vouchers through auction sites such as eBay and the website allofmp3vouchers.co.uk. That website has now been taken down from the internet. The vouchers contained a code that allowed UK and European consumers to access and download music illegally from the allofmp3.com website.

Charging £10 per voucher, the suspect was believed to be taking payment from European customers and transferring the cash into various offshore accounts operated by the site's Russian owners.

Metropolitan Police officers seized computer equipment and paperwork for further investigation. Early indications suggest the pirate operation may have generated criminal proceeds for the Russian website running into tens of thousands of pounds."

It is worth noting that the police executed the raid not under copyright law per se, but under Section 2 of the Fraud Act 2006 - legislation introduced into UK law in January 2007 specifically to combat online fraud. IPRED 2 was *not* involved. The 2006 Act makes it a criminal offense to dishonestly make a false representation for gain. A fales representation is one that is untrue or misleading and the person making it knows this. This is reportedly the first time the new fraud legislation has been used in a copyright-related case.

Interesting on two counts therefore. First, this is a good example of how even operating in a law haven like Rusia cannot necessarily save your business model in more lawful jurisdictions, when payment intermediaries are squeezed - Visa, Mastercard and even PayPal had ceased "laundering" payments to AllOfMP3.com from the UK making it almost unuseable by the average UK punter. (One wonders about Google Checkout?) . Similar strategies have been adopted successfully by the US to throttle online offshore gambling services offered to US nationals by countries like Antigua.

The legal liability of these payment intermediaries for providing funds access to AllOfMP3.com of course remains untested, as far as Pangloss knows. Would they be secondary infringers in UK copyright law, or "inducers" of copyright infringement in the US, a la Grokster? This must be the fear , but it would be nice to have had it judicially examined.

Secondly, the 2006 Fraud Act provisions were, it was thought, introduced to deal more effectively with "phishing", not copyright infringement - but it seems they have now been appropriated to that context. In Scotland where the 2006 Act does not operate, it is likely the existing common law of fraud would cover similar action. Is it fraud to take money in exchange for illegal services? One might argue that the punters were not being defrauded as they were getting exactly what they asked for , namely, downloads of music. Compare phishing where there is clear deception. The police/BPI argument would be that the punters are being deceived that what they are buying is legal in the UK. That, to Pangloss, seems in itself, rather deceptive:-)

Thursday, May 17, 2007

Web 2.0 sites beware!

Interesting decision from the States yesterday on immunity of hosts ("service providers") under CDA s 230 (c).

The Ninth Circuit Court of Appeals just determined that Roommates.com - a networking site for people looking for, housesharers, did not deserve immunity under Section 230 of the US Communications Decency Act for information that users of the site provide on questionnaires during registration.

The Register reports that "Section 230 of the CDA gives providers of an interactive computer service, such as a website, immunity from lawsuits relating to the publication of information on the site by a person other than the site's provider. Thus, information posted to a blog's comments or on an online forum won't put the site provider on the hook for damages if the publication of the content happens to break the law someplace.

Someone who, in whole or in part, creates or develops the published information, however, qualifies as a "content provider," and falls outside the bounds of the immunity. The Ninth Circuit panel determined that Roommates.com, by filtering the kind of information that visitors to the site would see, had developed the information provided, and could not claim immunity for the publication of the information...

The key quote from J Kozinski is "By categorizing, channeling and limiting the distribution of users’ profiles, Roommate provides an additional layer of information that it is “responsible” at least “in part” for creating or developing." [bold added]

In other words, Rommmates .com were, it seems, held to have "created" , in part though not in whole, the information that users themselves supplied via structured drop down menus; (eg "do you want to live with [options] straight men/gay men/straight women/gay women/anyone")but not information supplied by users themselves in freeform comments. That information was then held to have breached the anti-discrimination provisions of the Fair Housing Act.

This is rather reminiscent of the debate in the UK before the E Commerce Directive about whether sites were "editors" under the Defamation Act 1996 s 1 if they undertook any kind of filtering or editing of content - and the even earlier debate in the US about whether ISPs like Prodigy were putting themselves at risk of liability by undertaking similar editorial work to create "family-safe" content. Basically, if you are a user-generated content site, do you dare to mess with the content at all, even if the result is a better or more searchable/manageable/less offensive product for your users? Section 230 (c) was designed to put an end to such worries, as was in Europe, the ECD. From that perspective this is a very regressive step.

On the other hand, it has become increasingly clear that s 230(c) was too widely drawn in giving absolute immunity to ISPs/hosts in respect of criminal liability and non-copyright-related torts (cf the later DMCA, whose scheme is akin to the EU ECD in allowing limited immunity subject to notice and take down and other requirements) - and a series of cases have attempted to rein in that immunity by, eg, re-introducing distributor liability.

This case is a logical progression, but it is unfortunate. (A better solution would be legislative reform of s 230 (c) - but that ain't going to happen.) As the Register point out, what will the implications be for all the sites which "facilitate" or "edit" or "structure" or "filter" or even perhaps "tag" user-generated content - the MySpaces , Facebooks, and even the Googles? MySpace and Facebook both "structure" (some) information via menus and questions. So do many dating sites. What if some of this content is defamatory or obscene? In particular the word "categorized" is worrying. What might this do to the liability of new tagging sites like Digg and Delicio.us so valuable to the Internet at large?

In most these cases - especially the Diggs and Delicio.us es - I think the argument can be developed that they do not "thin down" or restrict or impose structure on the information generated by a third party content provider - which seems the nuance of the case - but merely add value to it separate from the actual text of the third party content. (What will AACS be thinking reading this, I wonder?) Similarly Google can argue that they do not themselves filter content but merely respond to user (ie third party) instruction. Nonetheless Google is usually made available with default on Safe Search, ie filtering out obscene content - so the position is not all that clear.

I await the appeal:-)

ps other views: Eric Goldman ; Eugene Volokh - neither happy.

Oysters Reopened

Anonymous (which is not a very helpful name for a correspondent) asked me "Just a quick question, why are you linking to a story that is over 12 months old saying 'look no further'?"

Well, in utter truth because I had Googled that story before I was referred to it by Andy, and caught the tag date "15 may 2007" and thought ah good, developments. Of course that was the date Google last spidered it not the actual date of the article which was very similar except one year earlier.. I blame 33 hours on a fery from Bilbao:-)

The ongoing story, as my anonymous corespondent pointed out, is that "TfL has already signed a deal with Barclaycard and Visa to launch a range of Oyster-branded credit and debit cards, which are also expected in the autumn."

However this isn't very exciting news. As already recorded here, Visa have already made it first into the contactless credit market in the EU with their payWave technology. The same article says that Mastercard and Amex are also on this route. A dual purpose Oyster card/credit card wil howeevr no doubt be a killer app (I'd get one myself).

But the real story for me here is the apparent death of the multipurpose stored value card. "Digital cash" of the 90s is dead ; long live contactless credit/debit (pace the nascent security problems no doubt about to emerge). I always had my doubts that in an era of bountiful credit, consumers could be persuaded to put cash up front in stored value AND carry an extra card around, whose loss, stored value and all, would (like cash) not be recoverable; this appears to have been the case. And the chances of Visa, Mastercard et al going bust are rather lower than with a pioneering digicash supplier. Interesting how the future is not always what we expect.

Wednesday, May 16, 2007

The Oyster is hard to Prise Open..

Re yesterday's query about when Oyster Card would finally roll out as a multi purpoe contactless small payments card.. look no further.

Interestingly, no mention of legal difficulties round becoming an EMI - only commercial problems with revenue sharing.

Tuesday, May 15, 2007

PayPal plays with the big boys

My colleague Technollama and I have long subscribed to the view that PayPal does not really fit the model of an Electronic Money Issuer under Euro law , despite the fact that the UK and other EU countries have agreed to accredit it as such. PayPal itself has now taken the interesting step of declaring that it plans to move to Luxembourg and become a proper bank, for apparently commercial rather than legal reasons. This certainly demonstrates the growing mainstream strength of the mobile payments market. But what does it mean for other emergent digital payment forms? Not all will have the cash reserves of PayPal, necessary to achieve accreditation under existing EU banking capitalisation and risk rules. The EMI Directive probably still needs revisited if innovation is really to get going in this market.

Interestingly, the market now supports credit cards used as a contactless payment card (Visa's new payWave); the mobile phone used as an easy billing mechanism for micro-payments (prevalent in many EU countries, though not yet the UK); niche RFID pre-paid payment cards (eg Oyster Card for London tube) and now a major "bank" which uses agency techniques and existing credit institutions, rather than a stored value card, to provide mobile credit. What has never actually taken off is real omni-purpose stored value debit cards - "digital cash" - as predicted throughout the early 2000s , and which the EMI Directive was specifically tailored to regulate.

I still wonder when (if ever?) we will see the long awaited roll out of OysterCard as a multipurpose small payments contactless stored value card mechanism? And what form of regulation it will then opt for?

Wednesday, May 02, 2007

OK v Hello!

OK v Hello! has finally been decided in the House of Lords (thanks to Loveandgarbage for the tip-off.) This is NOT, it should be stressed, about whether Michael Douglas and C. Zeta-Jones had their privacy invaded at their wedding (that one's been and gone in a shower of legal fees); it is about whether Hello! stole confidential information from OK, the information not being "about" OK, but about the aforesaid starlets and their so-called "private life".

According to the Beeb, "what the Law Lords were asked to decide was this: Did Hello magazine breach commercially confidential information in publishing unauthorised photos of the wedding of Michael Douglas and Catherine Zeta Jones?

And by a majority of three-to-two, yes, they did. So much , so duh. What we really wanted to know was: does this create a new property right, a right in your own image caught in photos, in videos, on tee shirts etc? And enforceable against the world, not just persons in a contractual relationship, or a relationship of confidence? Lord Hoffman says no: but it is clear the Max Cliffords of this world will waste no time in trying to turn it into one (especially given the tacit but acknowledge acceptance of such rights already in celebrity contracts and finacial planning affairs.)

I haven't had time to read it properly yet but am slightly heartened by one para that already caught my eye:

"118. It is first necessary to avoid being distracted by the concepts of privacy and personal information. In recent years, English law has adapted the action for breach of confidence to provide a remedy for the unauthorized disclosure of personal information: see Campbell v MGN Ltd [2004] 2 AC 457. This development has been mediated by the analogy of the right to privacy conferred by article 8 of the European Convention on Human Rights and has required a balancing of that right against the right to freedom of expression conferred by article 10. But this appeal is not concerned with the protection of privacy. Whatever may have been the position of the Douglases, who, as I mentioned, recovered damages for an invasion of their privacy, OK!'s claim is to protect commercially confidential information and nothing more. So your Lordships need not be concerned with Convention rights. OK! has no claim to privacy under article 8 nor can it make a claim which is parasitic upon the Douglases' right to privacy. The fact that the information happens to have been about the personal life of the Douglases is irrelevant. It could have been information about anything that a newspaper was willing to pay for. What matters is that the Douglases, by the way they arranged their wedding, were in a position to impose an obligation of confidence. They were in control of the information."

So we have not recognised , it appears, that X can sell their private life to Y, and Y can use privacy remedies to defend it. This is a good thing in my book. On the other hand, we have it seems in essence created a new form of intellectual property which can be defended against infringement by all comers, rather than merely against those who were in a contractual relationship. Celebrities and their lawyers and the crappy celebrity culture will all be very happy; and that can only be bad.

Intellectual prioperty rights are not awarded simply because it's a nice thing to so; they strike a balance between the need to incentivise creation and inovation, and the public interest in not allowing monopoly property rights over information.

Why should this balance be struck *at all* in relation to celebrity "image rights"? Do we want to incentivise the creation or more celebrities, or more celebrity activity? Would people not become celebrities even if the image right revenue stream was not available? As far as I'm concerned , the answers are no and yes. But what's done is done.

Thursday, April 26, 2007

Why oh why oh why

Blogger took my blog away again. Now I have it back (it's like a children's tale of woe) but my entries have vanished since Nov 06.

Watch this space. It may be dull, but at least it's there:)

Some announcements.

GikIII 2 : the Comeback is GO. See CFP at http://www.law.ed.ac.uk/ahrc/gikii/ . THIS IS GIKIII!!! September 19, London.

THis will follow a much more serious and Constructive workshop on "Law 2.0" - or possibly Law 3.7 - the jury is stil out on this one. Anyway , it is being sponsored by the SCL and the very kind Herbert Smith Solicitors, London, chaired by moi and will explore the legal aspects of WEb 2.0 - user generated content, mash ups, C2C business models, the Semantic Web, eScience, blogs and open source/open content. It should be very very interesting. September 17-18, London.

Also - Geeklawyer has organised a first UK meeting of law blawgers on 18th May in LOndon. See http://blog.geeklawyer.org/uk-legal-blogging-conference/. Pangloss hopes to go, if only for the curry in the evning - she probably doesn't deserve any better given her recent miserable show on blogging (though not as bad as Blogger would make out - grr.)

BILETA in Hertfordshire in April was as usual enormous fun. Full papers will be up soon so worth a visit. Pangloss is now on the BILETA Exec for the third time - this time on retirement I get a gold watch - or something. Guess when the first meeting of the Exec is? Yup, 18th May..

Similarly, Pangloss had already signed up to go the OxII day on global Internet filtering which judging by the sign up WikI will be attended bya cast of IT gliterati. Guess when it is? Yup, May 18.

Which will Pangloss go to? Write in with your suggestion (if this was Live Journal it would be a poll.)

Saturday, March 17, 2007

Law and Society Conference 2007

Paper at a conference I'm going to in Berlin in July. I'm quite intrigued actually, so there to the undoubted cynics out there :-P

The Gendering and Sex of Online Information
In Session: The Morality and Politics of Search Engines and User-Generated Content 1236

Author:*Ann Bartow (University of South Carolina)

Abstract: Drawing from feminist legal theory, research into computer intermediated discourse, and cultural studies, this paper looks at the impact of search engines and user generated Internet content on the construction of gender and sex in cyberspace. Ways in which the structures and norms of Internet searching and content generation may ultimately re-order specific areas of the law in will be addressed, as will the impact of anonymously or pseudonymously authored source material, and online activities colloquially termed "astroturfing" and "sockpuppeting," with an explicit focus on important issues of gender and sexuality.

Er, what is "astroturfing"????

I'm going as the speaker and rapporteur on a panel on privacy and security with my esteemed colleagues Andrea Matwyshwn, Jennifer Chandler, Jay Kesan and Hiram Juarbe. The conference looks remarkable - everything from gendering of Israeli legal culture to whether there are IP rights in tarot cards and yoga positions - I don't think I've ever been to such a jamboree. If any of my readers are also going, do let me know!! there wil be more posts on this nearer the time no doubt.

Monday, January 22, 2007

BILETA 2007

BILETA is the gathering of the tribes of IT law in the UK and Europe: the must-be-seen-at conference for the old lags (or lagettes) of the Internet law game. It's been going for over 20 years and is always enormous fun. This year's is on 16-17 April at the University of Hertfordshire.

I, (for my sins) am organising what was described as a "GikII-like" (or GikII-lite?) stream at this event -

"Stream 2 - Horizon scanning
Looking somewhat speculatively into the future, this stream asks the question, where technology will go from here and also what the legal response should be to these suggested changes. The legal reality of science fiction meets BILETA!
Email submission to: stream2@bileta2007.co.uk "

The abstract deadline (c 500 words) has just been extended to Friday 2 March 2007, so plenty of time to get your world-upturning contribution in. (Plenty of other streams too - see http://www.bileta2007.co.uk/papers/streams.html ). I'll be there (though not so much scanning the horizon as furrowing my brow in worry at it) with , hopefully, a paper on the empirical work on ISPs, notice and takedown, notice and disconnection and disclosure of IDs by ISPs I've been working on with the AHRC Centre at Edinburgh.

Friday, January 19, 2007

A Swedish-Trojan tale

According to the Beeb

"Internet fraudsters have stolen around 8m kronor ($1.1m; £576,000) from account holders at Swedish bank Nordea. The theft, described by Swedish media as the world's biggest online fraud, took place over three months. The criminals siphoned money from customer's accounts after obtaining login details using a malicious program that claimed to be anti-spam software.
Nordea said it had now refunded the lost money to all 250 customers affected by the scam.

"What is important is that none of our customers will have lost their money," said a bank spokesman. "

Really? At a conference last Tuesday organised very helpfully by ISPA , the UK ISP Association, to discuss the upcoming HL Inquiry into Personal Internet Security, the view was informally expressed that the banks are not really hurting on this one yet. If and when they do, we'll start to suddenly see a trend for these kind of losses to be absorbed by the customers. One wonders how the bank offsets their losses - what do their own insurance policies cover? Or are they just using up profits?

It is generally believed on the high street that any misuse of money in consumer bank accounts is the responsibility of the bank. In fact the real law is much less clear - especially in cases like phishing where the customer is arguably the one in breach of duty of care. Cases like this where Trojans are implanted as key loggers or other forms of spyware are a middle ground, being (again arguably) neither the fault of customer or bank; and misuse of credit cards, as in ID theft, falls clearly (after the latest clarification as to use overseas) into the consumer credit protection guarantees of the EC ie the responsibility of the card issuer.

I've yet to see a really clear piece of work in the UK dealing with these issues and not sponsored by an obviously involved party eg a bank or a law firm who wants bank work. It might be a good PhD for someone, since we apear to be in PhD application season..:-) Better than doing electronic signatures AGAIN for sure!

Wednesday, December 06, 2006

Curtains for DRM?

As I'm spending the evening wading through a PhD thesis on the dreadful wrongs of DRM, it seems mildly amusing to note in passing that where the shock troops of Creative Commons have failed, the market might just decide that DRM isn't a selling point anyway. The article makes the concise point (from the Wall St JOurnal) that pirate files get out via P2P or burned CDs anyway; so DRM doesn't stop illegal piracy, it just makes buying legal downloads more awkward - thereby alienating exactly the customers you most want to pander to.

Back to the battlefield..

More on Gower : ISP copyright cops are coming?

On the briefest of further scans, one item of particular interest to anyone who has been following the rather covert debate about how far ISPs can or should be enrolled to assist the state (or the BPI, etc) in cutting down on on line piracy.


Recommendation 39: Observe the industry agreement of protocols for sharing data between ISPs and rightsholders to remove and disbar users engaged in ‘piracy’. If this has not proved operationally successful by the end of 2007, Government should consider whether to legislate.

This is about whether ISPs should have to hand over logs of material downloaded automatially , or perhaps on request, to rightsholder groups so they can spot possible pirates. Should the user have a right to privacy or at least such a right prior to obtaining a court order or perhaps showing reasonable suspicion? Currently some ISPs are known to reveal anonymised logs of especially heavy downloades or uploaders, leaving it to the rightsholder then to come back and ask for disclosure on grounds permitted by the Data Protection Act. Some ISPs will only give away *any* details after court order, arguing that they may breach data protection rules otherwise and owe their clients confidentiality both by law and by contract. Others may feel that the public are entitled to presumption of innocence til proven guilty. Still others feel that they are merely ISPs , not mandated to act as judge and policemen in such cases where rightsholders might well ask for particular identified downloaders to be summarily disconnected.

Gower however signals a definite governmental backing both of voluntary disclosure by ISPs and of "notice and disconnection" (discussed before on this blog.)

ISPs "should assist rights holders by providing a procedure through which automatic action in courts will be avoided and would allow greater scrutiny on the actions of users. BCP [a model best common practice document] is an ideal way to proceed if an agreement can be brokered between the ISPs and the copyright owners and would respect safe harbour provisions for ISPs which were set up in good faith. If there is a failure to agree, the Government should look towards establishing an appropriate statutory protocol."

So there you go.

Incidentally I've changed my mind. The press may seize on 10 year sentences for downloaders, and Lessig and Cliff Richard may be (differently( excited about no term extensions; but my bet for Most Controversial Recomendation (possibly tieing with the already mentioned limited new introduction of private copying rights) is this one:

Recommendation 11: Propose that Directive 2001/29/EC be amended to allow for an
exception for creative, transformative or derivative works, within the parameters of the
Berne Three-Step Test.


Alrighty!! Who's going to be the first to create a sampled rap praising the Gower Report? maybe they can finance the implementation with the royalties from a few Snoopy Dog or Doggy Snop , records..

Ho hum! The view after Vista

David Utter, who left a nice comment re my rebutal of his article over at SecurityProNews, has also turned out some interesting security news items of his own, including evidence that although the majority of current malicious code may be defeated by the new security controls of Vista it can fairly swiftly be adapted to infect it by skilled operators. Indeed, three of the current top ten major viruses can already evade Vista's improved security.

Ah well! It's almost Xmas!!

Gower Report

No time right now but this is the summary of the recommendations for making copyright work in the digital age:

To ensure the correct balance in IP rights the review recommends:

ensuring the IP system only proscribes genuinely illegitimate activity. The Review recommends introducing a strictly limited 'private copying' exception to enable consumers to format-shift content they purchase for personal use. For example to legally transfer music from CD to their MP3 player;


enabling access to content for libraries and education establishments - to ensure that the UK's cultural heritage can be adequately stored for preservation and accessed for learning. The Review recommends clarifying exceptions to copyright to make them fit for the digital age;

and
recommending that the European Commission does not change the status quo and retains the 50 year term of copyright protection for sound recordings and related performers' rights.


On the other hand a stiff approach to IP crime, including sentences up to 10 years for music & film piracy.

Something for everyone then. In principle it mostly looks like damn sensible stuff. Lessig has already pulled out the most rallying-cry quote:

"Policy makers should adopt the principle that the term and scope of protection for IP rights should not be altered retrospectively."

Let the battle commence!

Tuesday, December 05, 2006

Ps - late egoboo:)

I was in New Scientist a few weeks back , rather curtailedly extolling my theories-in-progress of how a security commons might be created to reduce the insecurity currently caused by zombified home computers. As many of you know, zombies or "bot networks", computers emslaved by viruses unknown to their owners, are the leading cause of everything from spam, phishing and spyware to keylogging, ID theft, click-fraud and probably, dandruff. In particular almost all denial of service attacks are now carried out as distributed attacks via enslaved bot networks. By a"security commons", I meant joint action and joint responsibility by all p[artioes involved in a safer Internet: users, software writers, hosts and ISPs.

Illness intervened in my reporting (cof, cof) but here is the link for you my loyal readers :) Unfortunately New Scientist printed only the smallest part of what I told them over the phone (sigh) so it looked like I was suggesting that ISPs ONLY should be liable where a denial of service attack is carried out. Whereas in fact I continue to advocate that ISPs should take a positive role in (a) identifying zombified machines, not necessarily by deep packet inspection, as NS reported, but possibly only by external changes in patterns of traffic or congestion analysis (b) making available secured ISP services to consumers as well as businesses - as some companies like Nildram do already, thus protecting customers who don't know a firewall from a firelighter; and (c) where necessary, isolating identified zombies until they can be cleaned out.

ISPs would not necessarily be "held legally liable" if they failed to provide these services; they could be provided as competitive market price services, with users held liable if they did not avail themselves of them. Other methods such as compulsory "home computer user insurance" (like motor insurance) could be employed to reach the same reult.

Rather gratifyingly, there has already been a hostile response (always nice to know someone's listening.) David Utter suggests that if I had my way, ISPs might be held liable for hosting sites like Slashdot, which post links which often bring down sites by their sheer popularity. I was not in any way suggesting simple vicarious liability for ISPs hosting sites responsible for DOS attacks - for a start, the EU E Commerce Directive would currently probably forbid that. I have my own concerns about how the CMA amendments in the Police and Justice Act deal with inadvertent "slashdots" - given the late amendment to s 3 to allow recklessness as sufficient for "intention to impair the operation of a computer", it seems quite possible that innocent slashdotting is now prosecutable as denial of service in the UK. (Of course from a sysop point of view, whether a server goes down because of malice or carelessness is irrelevant - so maybe this was deliberate?) But it won't be the ISP that carries the can, even if this is true.

More interesting points are raised by a George Scriban on a blog called Global Nerdy

"Surely the ISPs of the world aren't the most responsible party in a DDoS attack? What of the companies who provide vulnerable operating systems? The customers who misuse, misconfigure, or undermaintain those systems, making them ideal zombie targets? ISVs whose software defects render systems vulnerable? And, of course, we have the criminals conspiring to commit these crimes themselves. There's enough blame to go around that it seems strange to focus the blunt instrument of government regulation on ISPs in particular."

But the whole point is that we're looking at here isn't moral retribution - ie, allocation of blame. What's the good of tinkering with the criminal law to punish DoSers when they're usually tidily hidden away in Moldova, Estonia or similar hi tech law enforcement havens? Or untraceable , because they've worked through a network of a million bots, enslaved via a Trojan virus sent by a third party? Or have their assets stashed in still another country?

Better to try to actually secure the Internet so it doesn't fall over, taking our hospitals and air traffic controllers with it - and worry about wreaking punishment on the guilty afterwards. The people the police forces (or civil courts, or insurance companies) of the US, EU and the rest of the developed world can usually get to are the users - you and me- and the ISPs. Regulation that would persuade the Microsofts of this world to produce less buggy software would also be good. Creating a safe Internet has to be done , right now, either by building it differently from scratch - which may have catastrophic effects for generativity, innovation and privacy and will take decades - or by regulating those three sets of people. Forget the Russian mafiosi, for every one you catch you will tie up the UK's entire National Hi Tech Crime Unit-as-was for months if not years . We need to move from blame to gain.

Oh, the anti-ci-pation..

Just a heads up that Tomorrow is Gower Day.

"The Report of the Gowers Review of Intellectual Property is due be published on Wednesday,6 December.
It will be available on the Treasury website from 08.00:
http://www.hm-treasury.gov.uk/independent_reviews/gowers_review_intellectual_property/gowersreview_index.cfm
We expect the Chancellor to refer to it during his pre-budget statement to the House of Commons, starting at 12.15."

Will private copying and sharing of mix tapes be legalised? Will term in sound recordings be left as it is? will Cliff Richard turn green and burst out of his leather trousers? only the Shadow knows!!

GikII ppts etc

I'm gratified to discover (though someone could have TOLD me, heh, Andres!!) that the powerpoints from the (she says nonchalantly) successful cutting edge blue skies cyberlaw workshop, GikII, are now available.

Talks are also underway towards turning GikII into a book on Geek Law and finding a home for GikII 2: This Time It's Personal. If you too want to be absorbed into the Geek Collective, contact Pangloss at the editorial address.