A UK-based cyberlaw blog by Lilian Edwards. Specialising in online privacy and security law, cybercrime, online intermediary law (including eBay and Google law), e-commerce, digital property, filesharing and whatever captures my eye:-) Based at The Law School of Strathclyde University . From January 2011, I will be Professor of E-Governance at Strathclyde University, and my email address will be lilian.edwards@strath.ac.uk .
Thursday, April 28, 2011
Still time for GikII Gothenberg!!
So don't waste your time watching the Royal Wedding, pretending to enjoy making the BBQ light, or pointelessly walking up a Munro when you could be doing something much more geeky instead! Instead send an abstract to lilian.edwards@strath.ac.uk or Mathias Klang (klangm@chalmers.se). We will notify successful applicants very shortly thereafter.
Full details and dates are here - note also that a limited number of places are also available to non speakers - with preference given to postgraduates and PhDs working actively in IT law related areas. You can notify us your details using the form here though note this does not confirm acceptance.
So come, come ye all or you risk missing: ppaers on variously the Twitter accounts of Abba, the legal personality of zombies, robot ethics and liability, law and virtual pornography, soft law in World of Warcraft, whistleblowing after Wikileaks, and the legal implications of time (or possibly the chronological implications of law).
Wednesday, April 27, 2011
Web blocking: the Internet is not for porn
More seriously, it seems worth reminding oneself of the cogent reasons by which Joe McNamee of EDrI persuaded the European Parliament earlier this month that state-mandated, self-regulatory,non-judicial, non transparent web blocking by ISPs was not the path to go down.
This is all the more important as, behind closed doors, Ed Vaizey, the UK Culture Minister, presses on regardless with plans for "voluntary" blocking by the big ISPs of both sites alleged to be complicit in copyright infringement, and even more worryingly, sites hosting "sexually explicit" material - material that in EU parlance may be harmful to, or just disliked by, some, but which is not in principle illegal for all to view or possess as is universally the case with child pornographic images.
If these matters are so important, one wnders, then why does the government not mandate them by the usual tool of legislation? Could it be that, having narowly escaped humiliation at the hands of the judicial review court in respects the Digital Economy Act (for now at least), they know that for an EU government to demand explicit blanket filtering of non-illegal material (which circulates with relative freedom in several EU member states) would almost certainly fall foul of art 10 and probably art 8 of the ECHR, as well as restraining freedom of services and trade across the EU?
At such moments, it never hurts, perhaps, to consult the old classics: The Internet is for Porn.. but not for long?
Wednesday, April 20, 2011
Judicial Review of Digital Economy Act fails: interim note
The expected, though still bad, news is that most the arguments put forward by BT and TalkTalk were rejected ie on incompatibility with the Technical Standards Directive, the Data Protection laws, the E-Commerce Directive and proportionality generally. The Act therefore stands.
However BT etc were partially successful in relation to sharing the costs of the filesharing system to be established - the cost sharing SI made under the Act proposed a 75:25 split between the copyright holders and the ISPs; it now seems ISPs wil not be required to pay 25% of the cosst of establishing the appeals body but will still have to pay in relation to "internal costs" ie sending letters and identifying filesharers.
A key point will be appeals. BT and Talk Talk are considering their positions on this. I would have strongly expected a reference to the European Court of Justice for clarification, but the judge has indicated he found the issues of law clear and therefore would not support such. My feeling is this point at least might well be appealed successfully - especially following the Advocate General's opinion in Scarlet v SABAM only a few days ago, where the reasoning is strongly against the legality of blanket filtering and monitoring to protect copyright, since invasion of personal data privacy is inevitable. Although this does not necessarily directly affect provisions of the DEA itself other than s 17 on web blocking orders (which may itself be heading for non-implementation hell if Ed Vaizey manages to convince ISPs, IWF-style, to block sites on a voluntary basis, without need for court orders, behind closed doors) the balance struck here between rights of privacy and rights of property will surely cast a doubt that the interpretation of EC law, especially the DPD and PECD , is quite as untroublingly easy as Mr Justice Parker has suggested.
If there are no such appeals, the Guardian suggests the first letters to filesharers could go out in the first half of 2012. Pangloss is not quite sure if this means letters warning alleged filesharers or letters indicating sanctions like suspension, traffic slowing, etc (technical measures) - but probably the former. Certainly it has already been announced that the final version of the Initial Obligations Code has been put back to at least summer 2011 from the original deadline of Xmas 2010. Given that the Initial Obligations stage has to run for at least a year before stage 2, Technical Measures can even be introduced - and that still needs the assent of both Houses of Parliment - we are still a very long way from the first potential disconnections.
In the meantime, streaming has already overtaken downloading, Spotify has managed to educate millions of Europeans, even without much assistance from US record labels, that legal streaming is a great idea, and hardened down and up-loaders have already become far too clever to ever be caught by the DEA's IP address collection methods, while the innocent may find themselves falsely accused (see Richard Clayton's excellent witness statement to the court) .
By that long away time (2013?) when the first disconnections might be justified, the DEA may be too antiquated for even the music industry to press for its continuation. In the meantime however a huge amount of money - £500m estimated - will have been spent to safeguard an industry worth £200m (also an estimate, of course) - and of course also to make it universally hated by its target customers.
The takeaway message on this also is that the judicial review court has only found that the DEA has not technically violated any EC laws. Only these arguments could be made because an Act that is otherwise passed under doctrines of parliamentary sovereignty, however bad it is , in principle, policy or execution, stands till repealed, because that is how we do law in this country. Nothing that happened today proves the DEA makes sense or is right - merely that one judge thinks it does not violate any supranational laws.
ps is there really no English translation of SABAM yet other than a Google translation? Pangloss cannot seem to locate..
Friday, March 18, 2011
The right to forget or the right to spin?
The right to forget is intriguing and seems to have caught the public attention of more than geeks and DP nerds. In boring Anglo-Saxon, it sounds much less exciting. The right to delete your personal data, wherever it is held - eg on Facebook - is what it's about. Put that way it doesn't sound that new. After all the DPD already gives you the right in art 14 to
" object at any time on compelling legitimate grounds relating to his particular situation to the processing of data relating to him, save where otherwise provided by national legislation. Where there is a justified objection, the processing instigated by the controller may no longer involve those data;"In the UK DPA 98, s 10, that gets translated as the right to stop processing where it is "causing or is likely to cause substantial damage or substantial distress to him or to another" and this is "unwarranted". As often the case, there is an argument that this is a rather limited expression lof the DPD, especially when case law is considered. There's also a connected right to demand your personal data is not processed for the purposes of direct marketing.
But this doesn't add up to an unqualified right to have data deleted nor to have this done for no reason at all, except it's your data. This is what the "right to forget"or "delete" movement is about.
Pangloss initially found the right to forget very appealing, but has got more conflicted as time has gone on. The trouble most often cited is that your personal data is very often also someone else's personal data. If I post a picture of both of us at a party on FB, do you have the right to delete it? What about my freedom of expression, my right to tell my own story? With pictures, you can imagine solutions - pixellate out the person objecting or crop it. Perhaps the compromise is that I have the right to post the photo but you have the right to untag yourself from it. (Though this will not suit some.)
But what about where I say "I was at Jack's last night and he was steaming drunk?" Does Jack have the right to delete this data, even if it's on my profile? This is where the Americans start indeed to get steamed up - since their culture and legal system has repeatedly preferred free speech to privacy rights.
Unsurprisingly this is one of the the scenarios Peter Fleischer, chief privacy officer of Google, had in mind when he described the right to forget last week as "foggy thinking ", claimed that "this raises difficult issues of conflict between freedom of expression and privacy" and more or less implied that this could be dealt with perfectly well by traditional laws of libel. In an ideal world this might be so: but we don't live in that world, but one where ordinary citizens as opposed to celebrities, almost never get to use laws like libel because they're simply far too costly and scarey.
Would Jack sue for libel in the above example? No, almost never. But he might ask FB to take it down (if he was aware it existed). This is another of Fleischer's worries - that intermediaries like ISPs and hosts would get inextricably and expensively involved in the "right to forget". Here his real agenda becomes fairly apparent - Google's success is entirely based on their right to remember as much as possible about us. We are back here in another version of the cookie and data retention wars, passim.
I am a fan of the Google chocolate factory, as anyone reading this blog will surely have gathered - but it is a mite disingenous to read Fleisher's (beautifully written) post without bearing in mind what seems to be Google's real worry, as cited at the bottom of his list, that search engines will find themselves called on to implement what people often want far more than a right to delete, namely a "right for their data not to be found" - ie, for it to be expunged from Google's web results.
Fleisher says correctly (and commendably under-statedly) that "This will surely generate legal challenges and counter-challenges before this debate is resolved. ". Imagine the reaction of Trip Advisor for example when 1000s of people who run hotels and restaurants try to have the site removed from Google rankings because it has personal data about them that they're not overly fond of..? More sympathetically, many readers of this blog will know decent people who have tried for years to get results removed from Google - unfair and illegitimate reviews, catty remarks from ex partners, professionals whose working life is blighted by abusive remarks by disgruntled ex clients. There should I think be clear remedies for them not dependent on the ad hoc discretion of the sitein question, depending on what mood it's in that day. On the other other hand, I don't want a world where politicians or demagogues can get their dodgy past involvements with fascism or the BNP or whatever quietly deleted or rendered unfindable on Google (this is a turf war which already goes on day in day out on the edits on Wikipedia).
A big problem (as with all DP issues) is the cross border, applicable law or jurisdiction aspects. Fleisher's column cites a rather sensationalist example - when a German court ordered references to a murder by a German citizen removed from a US based Wikipedia page because those convictions under German law were "spent". In fact rules about rehabilitation of offenders and spent convictions are common - certainly the UK has similar - and all that is unusual about this case is the attempt of the German courts to extend jurisdiction to publications hosted abroad. Indeed as some US states have "rights of publicity" protecting celebrity image and some don;t, one imagines they must already have evolved a degree of expertise in the international private law of privacy/publicity rights. (What if Elvis's image on tee shirts is protected in Tennessee but not in Virginia? can the Tennessee estate sue the Virginia t shirt factory that uses his image without paying?)
But certainly an EU right to forget will almost invariably engage us in the same kind of angst and threats of "data wars" over extraterritoriality that the Eighth DP Principle on export of personal data already has - not something to look forward to. It is noticeable that Reding fires off an early salvo on this when her spokesperson says , not for the first time, that companies "can't think they're exempt just because they have their servers in California or do their data processing in Bangalore. If they're targeting EU citizens, they will have to comply with the rules."
In reality , Pangloss suspects any right to forget that makes it through the next few years of horse trading will look much more limited and less existential than most of the ideas in the blogoverse - more like the right FB has already conceded, to delete rather than simply deactivate your profile, for example. Reding's speech itself seems to be in practice more about how FB sets its defaults than anything else: a default opt out from letting third parties tag your photos, rather than opt in, would seem a pretty limited and sensible demand.
Being more aspirational, Pangloss still has a soft spot for one interpretation of the "right to forget" which Fleischer rather derides as technically impossible - self expiring data. I'd love to hear from any techies who know more about this topic.
But the debate that has caught the public imagination goes wider than just DP law, and it is about whether we want to live in an online spin society.
There has been a certain amount of information coming out lately about how the Internet is not what it once was. Once we thought the Web was a conduit to unmediated news and opinions from real people, that it would enable direct democracy and change the world. But recent evidence has been that when it really matters - in matters of politics and revolutions and celebrities and ideology - a lot of what seems to be the "honest bloggers" or commenters or posters are actually paid spinners, employed and trained in the blogging and astro turfing schools of China and Russia and Iran and now, we hear this week, the US.
The right to forget can in some ways be used as the individual, non corporate, non state version of this. Rewriting history has been described by many people as Orwellian: we are at war with Eastasia, we have always been at war with Eastasia. That is chilling (in all senses of the word, including speech :-). The reality, as I already said, is likely to be consideringly less overwhelming (or effective). But this is still a debate we need to start having.
Tuesday, March 15, 2011
Online behavioural advertising: threat or menace?
The latter approach certainly seems to be taking centre stage. Today I hear on Twitter that Microsoft, still maker of the most popular browser in the world, have agreed to install a Do Not Track opt-out cookie into IE v 9; this follows Firefox doing something roughly similar, leaving only Chrome (Google) and Safari (Apple) of the major desktop browsers as outliers.
Will this self regulatory, "code" solution, which has been heavily advocated by the FTC in the US be successful? It is very relevant to us in Europe right now, where a similar system is being promoted by the ad industry, especially the IAB and EASA . They suggest an "awareness raising icon" or "big red button" ,which would be put on the sites of participating websites, and would then lead users who clicked on it to an opt-out registry by which means they could indicate "do not track me" to the ad networks. These are the networks which collect data via third party cookies and other techniques such as Flash cookies, and then distribute the ads to participant websites. (Slightly worryingly, Pangloss has heard of this development anecdotally via attendee accounts of meetings held with the EC Commission in December and March, but cannot seem to trace an official document on the Web about it. These accounts seem to indicate that the Commission is already heavily behind these initiatives, which is all the more reason for a proper public debate.)
In an ideal universe, such a user-choice driven system could be good. It might allow users (like Cybermatron) who want to to protect themselves from online data collection and profiling, to do that: and let those who are either quite happy about it all (the majority "don't cares"), or feel that web 2.0 businesses need a revenue stream to survive that targeted ads supply, and the genie is already out of the bottle re their personal data (moi, on a bad day); or who actually like targeted ads (these people must exist somewhere, though Pangloss has never met them); or who feel they can protect themselves from ads using filter products like AdAware or Firefox anti-ad plugins (the techy fringe, and distinctly not including my mum), to go on doing their thing.
But as usual it's a little more complicated than that (c Ben Goldacre, 2011). The WSJ note firstly:
It still isn't clear how effective the privacy protection tools in Microsoft's browser will be. The do-not-track feature automatically sends out a message to websites and others requesting that the user's data not be tracked.
But the system will only work if tracking companies agree to respect visitors' requests. So far, no companies have publicly agreed to participate in the system.
The price goes on to quote the IAB moaning that their members have no systems set up to respond to "Do Not Track" requests. This strikes me as getting into protesteth too much territory: if the advertising industry wants to avoid mandatory regulation with, perhaps, stiff fines, they wil get their act together on this pronto or face the worse alternative. One imagines similar fears are driving Microsoft and Forefox. It is interesting that Google who make Chrome and who benefit by far the most from the online advertising market appear to be dragging their feet.
So what are the problems? Pangloss has been trying to get her head around this, with a bit of help from Ms Matron and Alex Hanff's blog on PI.
First, that good old chestnut, consumer ignorance, inertia and techno-inability. Most consumers don't click on buttons to opt out from behavioural tracking, just like they don't go looking for privacy settings on Facebook. They have better things to do: like go looking for the goods and services they went online for in the first place, or on FB, looking to see what friends are having cool parties. There also seems to be some debate about just how big the "big red button" will be but that's really the least of the problem.
(Interestingly, Pangloss has spent some time lately helping her much maligned mother with computing matters and observed that she (my mum that is) just does not have the habit most readers here of younger generations will have acquired without noticing, of searching all around a webpage for cues. She would never even notice the big red button unless it was as big as a Comic Relief red nose. But I digress.)
And in fact US research bears this out already re the behavioural ads opt out button. Hanff states:"TrustE carried out an experiment to measure the effectiveness of the (US Do-Not_track) icon. Over 20 million people visited an experimental web page of which 0.6% of unique visitors interacted with the icon. TrustE shouted that this was a wonderful success, but I think the sane among us would argue the opposite is true."
If this is true, I'd certainly agree.
A secpnd, connected, problem is what is the effect of an opt out indication even if someone gets around to making one, by Do Not Track button or otherwise? You might well think it means that you have chosen for data collected about you not to be profiled and mined ie not to be tracked: but in fact the US experience so far may be just that the data collection and mining still goes on, but you don't get the targeted ads. This rather misses the point and I'm pretty sure everyone, including the NAI and IAB , knows this :-)
And a third problem is that given inertia, the problem is not really solved by the button, charming as it is, but by the underlying default set up of consumer browsers like IE, Firefox and Chrome. If the default is no tracking without saying "yes, please." (ie opt-in) then those who really want targeted ads can indeed opt-in, argues Cybermatron, and leave the rest of us alone. Less determined people like me say, well if no one ever clicks buttons if they don't have to, then no one will opt in to targeted ads bar a few maniacs, and web 2.0 will go bankrupt. I don't want that. Hmm. (It is also worth noting at this point that browsers are mostly written by companies whose fortunes are fairly heavily dependent on online advertising. Also hmm.)
Matron's solution is that web 2.0 can survive on serving ads, without using ad networks and behavioural tracking and data mining - good old fashioned second party cookie tracking, where one site uses what it learns about you to serve you more relevant ads. The likes of Amazon used to do quite nicely on this alone, using algorithms like "People like you who bought X also liked Y". Users can also fairly successfully block second party cookies themselves using most browsers, without having to rely on believing ad networks will implement do-not-track opt-out registers, not just save the data fot later and hide the ads.
But such evidence as there has been available to the public in recent years seems to point, unfortunately, to second party cookie tracking not being good enough for economic success. Google has massively the giant's share of the online ad delivery market because via its AdWords programmes, its near monopoly of search terms in many countries and its affiliates like YouTube and Android, it can collect far more targeting info about users than any other single site. The empirical evidence seems to be ; more targeted info means more click throughs means more money for the online industries in question.
One of the notable phenomena is that for companies like Amazon, advertising was a second string activity, really mainly marketing their own services. By contrast, the web 2.0 market, like Google, Facebook, last.fm etc etc, charge nothing so have to make money out of selling something, ie ads for other services and companies. This can only be achieved in any realistic way via third party cookies, ad networks and the like, goes a fairly obvious argument. Is it coincidence that third party advertising networks began to take over the market at almost the same time web 2.0 unpaid activity became the great success story of the Web? Seems unlikely but who knows?
Since the latter seems increasingly likely (see Paul Ohm's seminal work passim), I have suggested before that such anonymised data profiles should benefit from some if not all of the same protection as "personal data" under some rubric like "potentially personal data". Notably this might make data profiles even where not tagged by name subject to subject access requests, and deletion requests where damage or distress was shown (or even not at all if we get the much ballyhooed right to forget).
Finally, for us lawyers, I think the biggest challenge is to dig ourself out the regulatory hell we are in where the DPD and PECD (and the media, exceptionally unhelpfully) present us with a mish mash of consent, "explicit consent", prior consent, informed consent, opt-in and opt-out consent. To a very large extent these distinctions are now pretty meaningless in their purpose, ie, to provide protection to users in controlling the processing of their personal data without their knowledge and consent. Eg, "sensitive personal data" is supposed to be specially protected by a requirement of "explicit consent" in the DPD scheme, but a common lawyer would argue a site like Facebook gets exactly that - via the registration, login or "I accept the terms and conditions" box - without any real sense of any added protection.
Hanff (above)argues forcefully that the amended PECD, which is due to be implemented across the EU shortly, now requires prior opt-in, and thus an opt-out system of the "big red button" type, will be illegal. But sympathetic as I am to his outrage, this is not what the new law says.
Art 5(3)of the PECD now says that placing cookies is only allowed where "the user has given his or her consent, having been provided with clear and comprehensive information." In some EU countries such as notably the UK, consent can be given by implication. If the article said "explicit" consent then this would not be possible - but, contrary to some very bad BBC reporting, and according to BIS's version of the amended PECD, there is no use in amended art 5(3) of the word "explicit". (Nor by the way, is there in art 14 on locational data which remains unamended by the new changes. This seems exceptionally odd.)
Furthermore, under EU law generally, it seems that the settings of a browser which has not been altered to opt-out, very unfortunately, can probably be seen as giving that consent by implication, as this has what has been expressly put into the recitals of the amended PECD. Most browsers do by default accept second, and sometimes third, party cookies. In some browsers, such as the version Pangloss has of Firefox, this distinction is not made - cookies are accepted and users can choose to go in and delete them individually. In such an analysis, most browsers will be set to "give consent" and the "big red button" is merely providing users with an opportunity to withdraw the consent they have already given, and is perfectly legal.
This is not a good analysis for privacy or consumers. It is not what those who fought for the changes in art 5(3) probably thought they were getting. But it is a plausible interpretation. Of course, existing national laws and national implementations may alter its meaning "on the ground" ; and I suspect we will see substantial cross EU disharmony emerging as a result. None of which will in fact help the digital industries.
What do we need out of regulation rather than this fumbling about opt in and opt out? Nellie Kroes has some ideas:
First and foremost, we need effective transparency. This means that users should be provided with clear notice about any targeting activity that is taking place.That "middle way" solution, that involves real opt in consent but not endless pop up windows requesting consent, sounds a lot to me like mandating that browsers and manufacturers set browsers by default to reject cookies so users can demnonstarte real consent by changing that setting : the same strategy that I rejected above as impractical as the death of revenue to web 2.0. Maybe there is some more suble version of Reding's "middle way" I don't know about - I sincerely hope so. (Techy answers again very welcome!!)Secondly, we need consent, i.e. an appropriate form of affirmation on the part of the user that he or she accepts to be subject to targeting.
Third, we need a user-friendly solution, possibly based on browser (or another application) settings. Obviously we want to avoid solutions which would have a negative impact on the user experience. On that basis it would be prudent to avoid options such as recurring pop-up windows. On the other hand, it will not be sufficient to bury the necessary information deep in a website’s privacy policies. We need to find a middle way.[italics added]
On a related note, I would expect from you a clear condemnation of illegal practices which are unfortunately still taking place, such as ‘re-spawning’ of standard HTTP cookies against the explicit wishes of users.
Fourth and finally: effective enforcement. It is essential that any self-regulation system includes clear and simple complaint handling, reliable third-party compliance auditing and effective sanctioning mechanisms. If there is no way to detect breaches and enforce sanctions against those who break the rules, then self-regulation will not only be a fiction, it will be a failure. Besides, a system of reliable third party compliance auditing should be in place."
But if Ed Vaizey, can for example suggest, as he did this week, that all computers sold in the UK should be shipped with software set by default to filter out all "porn", (however he plans to define that, and good luck with that) then why can't a similar command be sent out re the relatively simple privacy settings of browsers? Pangloss suspects that in reality, neither will happen, especially given that computers and handsets alike are mostly assembled outside the EU. It looks like the cookie and OBA wars , both in and outside of Europe, still have a fair way to go..
Friday, March 04, 2011
A few more dates for diaries
The title is ""The medium is still the message:Angry Birds,the Met Opera & broadband bills"
Pangloss is really looking forward to that :)
Also for central-belt Scots - put April 14th 2011 evening in your diary, when Strathclyde Law School and the Franco-Scots Alliance will be co-hosting an event on the current state of anti filesharing legislation in the UK and France - myself and Nicolas Jondet (currently teaching IP law at Strathclyde, and local expert on HADOPI) representing these jurisdictions respectively. Venue TBD but Old College in Edinburgh likely. Given the current events around the Digital Economy Act - judicial review, Hargreaves Review - as well as in France this could be lively :)
GikII goes Gothenberg!
From Matthias Klang who is bravely taking the helm..
GikII VI, Göteborg, Sweden 2011
Freedom, openness & piracy?
26-28 June 2011
IT University
Göteborg, Sweden
Call for Papers
Is GikII a discussion of popular culture through the lens of law – or is it about technology law, spiced with popular culture? For five years and counting, GikII has been a vessel for the leading edge of debate about law, technology and culture, charting a course through the murky waters of our societal uses and abuses of technology.
For 2011, this ship full of seriously playful lawyers will enter for the first time the cold waters of the north (well, further north than Scotland) and enter that land of paradoxes: Sweden. Seen by outsiders as well-organised suicidal Bergman-watching conformists, but also the country that brought you Freedom of Information, ABBA, the Swedish chef, The Pirate Bay and (sort of…) Julian Assange. We offer fine weather, the summer solstice and a fair reception at the friendly harbour of Göteborg.
So come one, come all… Clean your screens, look into the harder discs of your virtual and real lives, and present your peers with your ideas on the meaning of our augmented lives. Confuse us with questions, dazzle us with legal arguments, and impress us with your GikIIness. If you have a paper on (for example) regulation of Technology & Futurama, soft law in World of Warcraft, censoring social media & Confucius, the creative role of piracy on latter day punk or plagiarism among the ancient Egyptians – We are the audience for you (for a taste of past presentations see the Programme section).
Application process
Please send an abstract not exceeding 500 words to Professor Lilian Edwards (Lilian.Edwards@strath.ac.uk) or Dr Mathias Klang (klang@ituniv.se). The deadline for submissions is 15 April 2011. We will try to have them approved and confirmed as soon as possible so that you can organise the necessary travel and accommodation.
Registration
As with previous years, GikII is free of charge, and therefore there are limited spaces available, so please make sure you submit your paper early. Priority is always given to speakers, but there are some limited spaces available for students and non-speakers. Registration is open through Eventbrite.
Friday, February 25, 2011
Wikileaks, online intermediaries and privatised censorship
Reminded of this as currently sitting at Georgia Tech U in Atlanta who kindly invited me to their Workshop on Free and Open Communication on the Internet. It becomes more and more apparent that although in Iran, China and Libya, the state may openly censor the Internet, in the developed world, censorship exists also, but is more often happening "under the wire" - in the form of voluntary removal or blocking of content by privately owned hosts or ISPs (eg You Tube, Amazon, BT) - either because of covert pressure from states or , more commonly perhaps, because there is no money or actual commercial risk in hosting upsetting content. This raises a key issue: what if any are the social responsibilities of private bodies to sacrifice their own profits to preserve human rights?
I don't think I'm particularly cynical here: I know thoughtful, clever, aware and socially conscious people working high up in inter alia Google, Microsoft , HP and various ISPs (and at the IWF). But I genuinely don't see why a not particularly evil private company would not choose to enforce its terms of service differentially eg not to lose important advertisers. These choices are hard enough for newspapers with traditional journalistic values : which are not part of the substratum of most ISPs and hosts.
Wendy Seltzer from the Berkman Centre points to the Global Net Initiative group of companies , and at this workshop we've heard of a great many promising Google initiatives (or co-initiatives): Chilling Effects; Transparency Report; and the fact that Blogger has good anti DDOS protection and thus hosts many activist blogs. But with no offense to Google (where some of my best friends, etc, etc), these acts of charity too have to be placed in the context of Google's own worldwide efforts to win public and regulatory support for its other battles - with Viacom, with the copyright industry, with Italy over privacy etc. When it becomes useful for Google's profit margin and existence to work against free speech rather than for it - what corporate social value will take precedence then?
Monday, January 10, 2011
Welcome to 2011!
Please note AGAIN my new email address is lilian.edwards@strath.ac.uk and my snail address should you conceivably need it is
School of Law
Faculty of Humanities and Social Sciences
Graham Hills Building, Level 7 (GH 7.13)
50 George Street
Glasgow G1 1QE
If any of you can remember the achingly long time ago before the festive season, the burst pipes (oh so don't ask) and the Snowpocalypse, you may remember we were a little exercised about Wikileaks. The nice people at Practical Law Company (PLC) asked me to write a briefing on what issues might be involved for the UK legal system, and you too can read it for free here. Basically I think the key issues are:
- were criminal offences committed of DDOS by UK residents? (almost certainly yes)
- is merely downloading a tool which can be used to help commit DDOS a crime? (yes, though proof of intent may be tricky)
- can IP addresses of attackers be captured & UK ISPs be asked to help identify such persons (yup)
- can ISPs in UK conceivably be asked to block Wikileaks sites or domain names? (A. probably not, unless by some back door means such as invoking copyright laws under s 97A of the CDPA, or by some hitherto latent common law power which would need at least a High Court application in England & Wales or Court of Session in Scotland, and still be pretty uncertain).
The last point, though it seems farfetched, is a topical one given the ill judged comments by Ed Vaizey just before Christmas suggesting that all online "adult sexual materials" sites should be blocked "at source" by UK ISPs , with only adults then allowed to opt back in. Beyond the obvious difficulties of definition of such sites, over blocking, under blocking, the herculean task of assembling such a list, most of which will be overseas, evasion, ULL-jumping, VPNs, proxy servers, the fact that kids are better than adults at hacking this, etc ad nauseam, the simple fact is that such blocking solutions don't work and don't scale on practical terms unless you're willing to devote the resources and the Stalinist control of a country like China to such a pursuit. Just look at Australia for the trouble it has caused there in a smaller country with far fewer ISPs and far more history of state censorship than here.
I'm all for thinking of the children, really (actually, to be honest, as a child's rights lawyer on the side I also wonder if anyone has paid attention to the emergent minor child's right to autonomy, see Gillick, see future possible ECHR applications..?) but right now this seems like an expensive, embarrassing, largely pointless red herring to go down. IF parents want to stop kids accessing porn, there are many good products out there to allow them to do it at home eg |Net Nanny and its ilk. The Daily Mail will like it though :-)
But more than ALL that, what worries me is the huge possibility for scope creep here. As I have noted often, often before, once you have one scheme for blocking huge amounts of URLS without transparency or accountability in place, what is the temptation to start adding other URLs to it you don't like? High , in my cynical opinion. (And whatever the government means by blocking sites "at source" this will have to involve an Internet Watch Foundation style blocklist - because every single adult site closed down by its host service in UK will simply shift to a host abroad in under 24 hours. Indeed the Telegraph story seems to clearly indicate an IWF type list would be used : "Ministers now want companies to use the same technology to stop children accessing adult images".)
Workshop on Free and Open Communication on theInternet (FOCI), to be held February 24-25, 2011 at Georgia Tech in Atlanta,Georgia (invited expert speaker)
BILETA, Manchester Metropolitan University, 11th-12th April
3rd Web Science Conference, Koblenz, Germany - June 15-17
GikII in Gothenberg, Sweden!! GikII goes Scandinavian hardcore:) , contact Matthias Klang for info - 27-28 June
SCL Policy Forum, London, Herbert Smiths, September 15-16th - I'm curating this one on a theme of the new shape of European regulation as the DPD, ECD and other major instruments head for reform.