Friday, February 27, 2004

According to the Independent, the general angst about electronic voting is spreading in Ireland.

Taoiseach Bertie Ahern is dismissive of concerns and determined that an auditable paper trail will not be built into the system.

"We are not going to go back to pushing pieces of paper around the place," he said, accusing a critic of wanting "to keep old ways, old things, the old nonsensical past".

I guess he means that "old nonsensical past" where the election system was transparent, had impeccable integrity, it was simple to vote (mark the ballot paper and stick it in the box) and had a clear audit trail so that any anomalies could be reviewed openly. But it was, of course, terrible that it might take a few days to get the final results.

The new system will provide instant results (yahoo! - I use the word in its original sense prior to the Internet age) and a windfall for voting machine manufacturers all for 40m Euros(£26m). But no transparency, no simplicity, no audit trail, no confidence, no integrity...

Governments get five years if they win the election. Is democracy not worth a few days to make sure the results of the election are accurate? In the words of Milton Friedman in the Eldred amicus brief, this one is a complete "no brainer" for me. This ubiquitous Boys-Own blind faith of computing ignoramuses, like certain decision makers, in the ability of computers to automatically and magically make things better, regardless of the overall objective or the suitability of the tools (computers) to the task or [critically] the way in which those tools are deployed, drives me nuts on a daily basis in my own day job. That it is happening in so important a context of the integrity of our democracies is worrying in the extreme. Mr Ahern should not knock paper. It is still the best available technology for voting (imho).

Thursday, February 26, 2004

Greplaw have done an interview with Jessica Litman. Lovely quote about Jessica thinking of herself as an older sister to Harry and I hadn't previously come across her Breakfast with Batman paper.
The Association of Chief Police Officers in the UK have accused the Information Commissioner of putting children at risk for ordering the "destruction of valuable criminal intelligence."

"In one case, in July 2003, the commissioner demanded that South Yorkshire police delete from a woman's record a juvenile conviction for actual bodily harm dating from 1979...

In September 2003 a similar request was made of West Yorkshire police over a man who wanted juvenile convictions that carried a three-month custodial sentence to be "weeded out" of his record.

In a case with echoes of Huntley, the commissioner asked an unnamed police force to delete intelligence relating to allegations that a man sexually assaulted young males in 1991 and 1998."

The notion that a juvenille conviction from 1979 (25 years ago) should be held against someone is a bit excessive. What about the juvenille conviction leading to a custodial sentence or someone with serious allegations stemming from 1998? It's difficult to say without more specifics of the individual cases. What's certain is that the police have a very difficult job but they do need to recognise that the Information Commissioner does too. Very often an organisation's interpretation of the Data Protection Act bears little relationship to the actual requirements of the act. There is a judgement call to be made on the merits of individual cases and the perception on where the dividing line should fall will vary depending on the values and objectives of the institution or the indivual. ACPO and the Information Commissioner, if the story is to be believed, have different perspectives on the boundaries.
There's a nice quote from Jonathan Zittrain in a New York Times article on the "Grey Album" (a re-mix of some Beatles tracks with some recent rap music) dispute:

"As a matter of pure legal doctrine, the Grey Tuesday protest is breaking the law, end of story. But copyright law was written with a particular form of industry in mind. The flourishing of information technology gives amateurs and home-recording artists powerful tools to build and share interesting, transformative, and socially valuable art drawn from pieces of popular culture. There's no place to plug such an important cultural sea change into the current legal regime."

Statewatch Editor Tony Bunyan is none too pleased at the EU plans to introduce biometric passports.

"For EU citizens getting a passport is quite straightforward, you fill in the form, get your picture taken in a photo booth and simply post both to the passport office. This simple process is about to change: to get a passport you will have to present yourself to an "enrolment centre" where a special picture will be taken of you and then you will have to have your fingerprints taken. These will then be held on a European database with personal data."

The political decision to introduce compulsory biometric identifiers, first on visas and residence permits and then on passports, was taken at two Informal meetings of Justice and Home Affairs Ministers (in February 2002 and then in March 2003). The Commission argued for a so-called "coherent approach" for "all travel documents, including the passports of EU citizens". These decisions were not reported at the time. It was the European Councils (the meeting of EU prime ministers) at Thessaloniki in June 2003 and later in Brussels on 12 December 2003 who formally endorsed the proposal. A secondary reason for bringing in biometrics on EU passports, the Commission argues, is that the USA is demanding them on passports too.

The legal basis for the proposal is highly dubious, see: Commission’s EU biometric passport proposal exceeds the EC’s powers, Statewatch legal analysis concludes that: "no powers conferred upon the EC by the EC Treaty, taken separately or together, confer upon the EC the power to adopt the proposed Regulation"

The ignorance in the making of these decisions about biometric identity as a surrogate for security continues to be staggering and it would be laughable if it wasn't so serious. I could mutter 'security is a trade off ' and 'biometrics may be unique (mostly) but they're not secret' and 'identity is no gaurantee of security' and 'statistically the bigger the biometric database the bigger the error rate' and 'false positives' and 'false negatives' and 'information overload' and 'well resourced clever human intelligence' and ''security is only as strong as the weakest link', but there's not much chance of getting heard by the 'war on terrorism' gang. And the sad thing is that I don't even know that much about security but even I can see the sense of people who really do know about it like Bruce Schneier. What kind of a world our our children going to grow up into?

Tuesday, February 24, 2004

321 Studios have lost their DMCA battle against the movie industry.

"Judge Susan Illston ruled Friday in San Francisco that software made by
Chesterfield, Mo.-based 321 Studios violates the 1998 Digital Millennium
Copyright Act, which prohibits the circumvention of anti-piracy measures such
as the Content Scramble System protecting movies on DVDs.

The judge ordered the company to cease making or distributing such software
within seven days of her order."

The company has said they will appeal.

Monday, February 23, 2004

Michael Froomkin recalled some advice from his grandmother recently in reflecting on the Bush administration's response to the atrocities of 9/11 and Siva Vaidhyanathan's confession of self-censorship when going through airport security at Newark.

Friday, February 13, 2004

I learn from The Filter that there's a nice summary of the controversy surrounding the Diebold electronic voting machines and leaked internal memos at the Berkman Center. Section "5.0 The Implications" seems to be repeated twice. Possibly for emphasis? Probably in error. I'm sure the Berkmanites will correct it pretty quickly.
I was telling some friends over lunch on Wednesday that I had just heard a BBC radio report on the problems with trying to play copy protected CDs in certain Vokswagen CD players. It seems that Andrew Orlowski at the Register heard the same report and has written about it: Copy-crippled CDs launch in UK, baffling Auntie Beeb.

Orlowski reports the conversation very accurately. What I can't get is how a hardened consumer-advocate journalist lets by openings like those provided by the BPI spokesman. He tells her the CD standards have been around for a long time and then says the CD manufacturers have recently "enhanced CDs" with new features (i.e. copy protection). And the effect of these new features is that the CD produces silence when played i.e. doesn't work. It's a bit like Raleigh saying 'we decided to take the wheels off our bikes to reduce bicycle thefts and improve our service to customers; and don't blame us that the bikes are no good for cycling, the government should have adapted the road transport infrastructure to take account of our changes.'

As to the notion that "The CD em player that he's got in his car is not actually, eh supposed initially to play audio CDs." Oh you mean that road was not meant for cycling my wheel-free-enhanced bike on? Even the BPI spokesman thinks "Now that might sound a bit strange" and the journalist still doesn't pounce.

You just could not make this stuff up.

All I can suggest to irritated, music loving, Volkswagen owners is to try to ensure not to have too many passengers when trying to play copy protected CDs. You might find yourself getting sued by the John Cage estate for infringing (public performance) their copyright in silence. Incidentally the real settlement figure was not the six figure sum the BBC report here but it was substantial and somewhere between four and six figures.

Thursday, February 12, 2004

The EFF have posted a recording of the oral arguments in the MGM v Grokster appeal hearing. MGM's lawyer took a bit of a battering from the judges. I don't know whether that gives any indicator as to the ultimate decision in the case but isn't it fantastic to able to get direct access to this kind of material.
The NYT have a profile of Bram Cohen who created BitTorrent, the file sharing software that speeds up the downloading process for large files (such as digital films) and has the movie industry so worried.

"Under older file-sharing systems like Napster and Kazaa, only a small subset of
users actually share files with the world. Most users simply download, or leech, in cyberspace parlance.

BitTorrent, however, uses what could be called a Golden Rule principle: the faster you upload, the faster you are allowed to download. BitTorrent cuts up files into many little pieces, and as soon as a user has a piece, they immediately start uploading that piece to other users. So almost all of the people who are sharing a given file are simultaneously uploading and downloading pieces of the same file (unless their downloading is complete).

The practical implication is that the BitTorrent system makes it easy to distribute very large files to large numbers of people while placing minimal bandwidth requirements on the original "seeder." That is because everyone who wants the file is sharing with one another, rather than downloading from a central source. A separate file-sharing network known as eDonkey uses a similar system."

Copyfighters are grappling with the implications of the Appeals Court decision earlier in the week on DMCA [alleged] copyright infringement notice and takedown procedures for ISPs. The case was Ellison v. Robertson et al.

Wednesday, February 11, 2004

Some light relief from the Onion on the Patriot Act.

Tuesday, February 10, 2004

Roger Clarke is getting exorcised about the Australian government's misrepresentation of the value of face recognition technologies.

"It's very likely that a project called SmartGate, conducted by the Australian Customs Service, will be trumpeted throughout the world as the good news that face-recognition technology has been waiting for.

This email contains an assessment of the extreme manipulation of data, truth and the media on which such 'good news' stories will be based...

The brazenness of Custom's manipulation of media and public opinion exceeds the standards normally expected of the Government.

(1) No data has been provided, despite assurances given in the past that data would be provided.

(2) The invited experts who were paraded by Customs are arguably about the world's two foremost designers of testing for biometric technologies.

But is appears that:

they did not *perform* the tests
they did not *design* the tests...

... The best quotation that Customs seem to have been able to extract from the two experts was that "the scheme's performance is remarkably good for an operational facial recognition system".

That seems quite positive, until you realise that the other attempts around the world have been abject failures, and pilot after pilot has been quietly abandoned.

In other words, the quotation can be readily interpreted as "it doesn't work very well, but it's better than the other disasters we've seen".

This is borne out by an answer by one of the experts to a reporter's question. He said: "In one test 100 company employees attempted to impersonate someone other than themselves and eight of them were falsely accepted by the system. That is a very
low rate of false accepts". At that"very low" level of false acceptances, every 747-load of people can include 25-30 terrorists..."

Roger is clearly not too happy and you can't blame him. Deployment of lousy expensive technology to create the illusion of improved security does nobody any favours. And whilst the over-stretched authorities are distracted dealing with processing those 25-30 innocents per planeload, the real terrorists have a clear run at their targets.

Roger has an informative general introduction to biometrics on the web.
The latest in the unintended consequences of intellectual property legislation is covered by The Register: "Seven years jail, $150,000 fine if you don't tell the world your email and home address" This is further example, though thankfully one not yet on the statute books, of the industrial regulation leading to a daft situation when applied at a personal level and in an unexpected/unexplored context.

The article winds off with an amusing exchange between a Harley-Davidson trademark manager and an IP lawyer included in Milton Mueller's wonderful book Ruling the Root. Mueller went on to say: "Under ICANN's contractual regime, the consumers and suppliers of domain name registration services are required to facilitate their own surveillance by intellectual property owners. If we apply the same logic to any other industry, it seems absurdly overreaching. Motorcycles can be used to break the law, but we do not require all vehicle manufacturers to create a publicly accessible, global database with complete and accurate information about all their customers... The linkage of resource administration to policy and regulation in the domain name regime has given intellectual property interests much more extensive rights of surveillance than they had before."

That's a pretty good rule of thumb when it comes to regulation of new communications or Internet techologies - apply the same logic in a different context and give it the absurdity test. James Boyle calls it the telephone rule. When ever he gets some hyped up journalist contacting him for 'the internet angle' on the latest sensational crime story, he asks them to substitute the word "telephone" for the word "internet" and see if they a can blame the telephone for whatever terrible crime has been perpetrated.
Frank Zappa as far back as 1983 was suggesting a different business model for the music inductry. He called it "A PROPOSAL FOR A SYSTEM TO REPLACE ORDINARY RECORD MERCHANDISING"

"We propose to acquire the rights to digitally duplicate and store THE BEST of
every record company's difficult-to-move Quality Catalog Items [Q.C.I.], store
them in a central processing location, and have them accessible by phone or
cable TV, directly patchable into the user's home taping appliances, with the
option of direct digital-to-digital transfer to F-1 (SONY consumer level digital tape
encoder), Beta Hi-Fi, or ordinary analog cassette (requiring the installation of a
rentable D-A converter in the phone itself . . . the main chip is about $12).

All accounting for royalty payments, billing to the customer, etc. would be
automatic, built into the initial software for the system.

The consumer has the option of subscribing to one or more Interest Categories,
charged at a monthly rate, without regard for the quantity of music he or she
decides to tape.

Providing material in such quantity at a reduced cost could actually diminish the
desire to duplicate and store it, since it would be available any time day or night. "

SO these ideas have been around for a while...

Friday, February 06, 2004

At the Mercury News: "California Secretary of State Kevin Shelley on Thursday announced measures to improve election security in the wake of a report describing how votes can be easily manipulated by hacking into an electronic voting system used across California."
Here's a novel way of alerting people to the privacy invading information trails we leave behind when using modern technology -

"Visitors to an art exhibit at the Pittsburgh Center for the Arts got more than their martinis when they ordered drinks at a bar inside the gallery's entrance. Instead of pretzels and peanuts, they were handed a receipt containing all the personal data found on their license. Some patrons also got receipts listing their phone number, income range, marital status, housing value and profession. For added effect, the receipt included a little map showing the location of their residence.

The magnetic strips and bar codes on the back of most state's driver's licenses contain more information than people think. The way the swipers use the information might surprise them as well: Some bars and restaurants scan driver's licenses to catch underage drinkers and fake IDs, but they're also using the information for marketing purposes.

Last year artists and producers Beatriz da Costa, Jamie Schulte and Brooke Singer built the Swipe exhibit in Pittsburgh to show what's on the cards we all carry. "
Erica Wass editor and contributing author "Addressing the World: National Identity and Internet Country Code Domains", (Rowman & Littlefield, October 2003) has a nice article on the .kid.us domain name space mandated last year by the US government.

"Ironically, it is the characteristics that make the .kids.us space remarkable that also create its uncertain future...

...the space is governed by two principal documents: a content policy and a governance policy. The content policy document defines the thirteen areas of content that are restricted from appearing in the space...Sites within .kids.us cannot link to sites outside of the .kids.us space; they also cannot incorporate interactive communications like chat rooms, instant messaging, discussion boards and e-mail...

...the majority of those who have registered sites have not yet made it through the content review processes. Despite having registered about 2,000 .kids.us domains, only seven have been activated...

The incentive to create a site within the .kids.us name space appears clear; it is a space directed toward children. It is a space created to enable children to be safe while surfing the Web. Many owners of sites directed toward children are now forced to reconcile this honorable goal with financial and theoretical concerns...

When Carol Myers, the owner of Stnicholas.kids.us, registered the domain, she already had developed a site at stnicholascenter.org and its .com variations. She says she wanted to be a part of the .kids.us space because she believes that parents should be careful about the media influences on their children. As a result, she paid $126 for each .kids.us name she registered, as well as the $250 per name content approval fee. She also bore the more hidden costs of hosting and design changes to fit the .kids.us regulations. "It is a big commitment, actually, to develop and maintain two sites," she says. The result, she says is that the kids.us site will be much more static than her main site. Myers worries that other non-profit sites, churches and other organizations that have a few excellent pages for children will not go through the hassle and expense of putting them on .kids.us...

Indeed, the restrictive linking and interactivity policies seem to turn a rich communications medium into just another example one-way communications. Why should children turn to the web, when they can access games on CD, video on TV, and text in various print media. While it is true that the ability to freely communicate can engender abuse, and, therefore, possible danger to children, it also enables a different type of learning and involvement. While such restrictive policies may provide protection for children, it also may insulate our children from the benefits of communicating online in a variety of ways with the rest of the world. "

Food for thought.
Today the EU is celebrating "Safer Internet Day."

"This event focuses on children's rights to a safer Internet as part of the European Commission's Safer Internet Programme. It showcases existing safer Internet projects, videos and awards developed with the backing of the programme. These programmes involve actors from the private, public and voluntary sectors. Safer Internet project members have contributed to several remarkable achievements. In October 2003 a worldwide child-porn ring was broken up following a tip from the Internet hotline association INHOPE. In November 2003 the new Internet Content Rating Association content filtering platform ICRAplus was launched. Events will be staged simultaneously in 12 European countries (Denmark, Germany, Greece, Iceland, Ireland, Italy, Luxembourg, Netherlands, Norway, Spain, Sweden, United Kingdom), as well as in Australia. These events involve public authorities, the Internet industry and hundreds of other organisations. "

According to the Washington Post, "The Pentagon has canceled plans to collect votes over the Internet from military personnel and civilians abroad for this fall's presidential election because of security concerns"

Apparently the system will still be used for a test but the votes will not be counted officially. The Pentagon have some very very smart people and it looks like they have won the argument on this. Good for them. As Avi Rubin said, "It's all the credit to them for inviting us onto the security panel when they anticipated we would say negative things about it, and then taking our advice that seriously. It's really incredible."

Wednesday, February 04, 2004

CNET have published a recent essay by Bruce Schneier, which they've called "Slouching towards big brother." More sensible thoughts.

"Security is a trade-off. It makes no sense to ask whether a particular security system is effective or not--otherwise you'd all be wearing bulletproof vests and staying immured in your home."

Tom Paine's tuppence worth of common sense on the problem of rewarding creators and producers at the centre of the knowledge economy?

"My prediction is that the balance will be found in new technologies that will be able to extract a small fee from each of a very large number of consumers all over the world who want to hear or see or otherwise make use of some creation. When added up, these fees will give innovators enough to compensate them for their efforts, while at the same time giving consumers access to all sorts of new creative products very cheaply. And all this without lawyers. "

I wish I could believe he was right about the lawyers.
Update: Out-Law are reporting on the Privacy International report mentioned earlier.

"EU accused of failing to protect air passengers' privacy"

It's a nice summary of how we got to the current situation between the US and the EU with the airlines caught in between.
Privacy International in cooperation with the Foundation for Information Policy Research, Statewatch and the European Digital Rights Initiative have just published a report on the air travel privacy issue. The report is called:"Transferring Privacy: The Transfer of Passenger Records and the Abdication of Privacy Protection" and is to be the first report in a series Privacy International call "Towards an International Infrastructure for Surveillance of Movement."

They accuse the European Commission of intending undermine the privacy rights of air travellers, systematic deception and subterfuge in relation to the promise to take a hardline on negotiations with the US over transfer of passenger data and covertly planning an EU surveillance system which "will be used not only for purposes of anti-terrorism, but also for immigration, law enforcement and customs" and a global air travel sureveillance system similar to the one being built by the US.

Privacy International are also calling for an investigation into these affairs by the European Parliament and for legal action against the Commission "to ensure that
this dangerous subterfuge does not occur in the future."

Pretty strong stuff.

Bruce Schneier is crystal clear as ever on "IDs and the illusion of security" over at sfgate.com.

"Everywhere, it seems, someone is checking IDs. The ostensible reason is that ID checks make us all safer, but that's just not so. In most cases, identification has very little to do with security...

...verifying that someone has a photo ID is a completely useless security measure. All the Sept. 11 terrorists had photo IDs. Some of the IDs were real. Some were fake...

...Harder-to-forge IDs only help marginally, because the problem is not making sure the ID is valid. This is the second myth of ID checks: that identification combined with profiling can be an indicator of intention.

Our goal is to somehow identify the few bad guys scattered in the sea of good guys. In an ideal world, what we would want is some kind of ID that denotes intention. We'd want all terrorists to carry a card that says "evildoer" and everyone else to carry a card that said "honest person who won't try to hijack or blow up anything." Then, security would be easy. We would just look at people's IDs and, if they were evildoers, we wouldn't let them on the airplane or into the building.

This is, of course, ridiculous, so we rely on identity as a substitute. In theory, if we know who you are, and if we have enough information about you, we can somehow predict whether you're likely to be an evildoer...

"Profiling has two very dangerous failure modes. The first one is obvious. Profiling's intent is to divide people into two categories: people who may be evildoers and need to be screened more carefully, and people who are less likely to be evildoers and can be screened less carefully.

But any such system will create a third, and very dangerous, category: evildoers who don't fit the profile...
...Profiling can result in less security by giving certain people an easy way to skirt security.

There's another, even more dangerous, failure mode for these systems: honest people who fit the evildoer profile. Because evildoers are so rare, almost everyone who fits the profile will turn out to be a false alarm...

...Security is a trade-off; we have to weigh the security we get against the price we pay for it. Better trade-offs are to spend money on intelligence and analysis, investigation and making ourselves less of a pariah on the world stage...

...Identification and profiling don't provide very good security, and they do so at an enormous cost. Dropping ID checks completely, and engaging in random screening where appropriate, is a far better security trade-off. "

Can't fault Schneier's analysis on security. And the UK government could learn from this - the latest inquiry will presumably ultimately blame the intelligence community for the war in Iraq. Then there will be a 'review' and re-organisation of the intelligence services and more laws mandating blanket collection of personal data, which already overstretched law enforcement and intelligence services will somehow extract relevant information from. They'd be better off listening to Schneier - Better trade-offs are to spend money on intelligence, analysis and investigation.
Technology companies including Intel, Nokia, Panasonic, Matsushita, and Samsung are due to launch a new wireless DRM specification via the trade group the Open Mobile Alliance (OMA). They are also creating a non-profit licensing agency, the Content Management License Administrator, (CMLA), to promote the scheme. Toshiba has backed out and though Microsoft is a member of the OLA, they are not part of the new licensing scheme.
There was some interesting discussion on blogs at a recent meeting of the All-Party Parliamentary Group for
e-Democracy. Especially clear contributions from Tom Watson and Tony Benn.

Watson, MP for West Bromwich East, said he's exploring the use of blogs:

to encourage participation and agenda setting;
as a tool for civic action;
as tools to promote accountability and transparency;
and as a political weapon.

He's found out about RFID tags through his blog and managed to galvanise his local Lidl supermarket to clean up the litter problems it was causing.

Tony Benn said ‘Anyone serious in politics has to take communication seriously’ and blogs gave the opportunity to deal with lies directly and quickly, ‘truth can get its boots on a lot faster!’

Monday, February 02, 2004

Diebold Systems are in the e-voting wars again. This time the systems in Maryland come in for some criticism from security experts commissioned to assess them.

The SCO website has been taken down by the MyDoom virus, according to the NYT.

The Lambert Report on University-Business collaboration on research and technology transfer was published just before Christmas. I didn't read it in detail at the time because it was accompanied by the usual PR and platitudes about how it would be a good idea if there was greater cooperation and how it was inherently a good idea etc.

It does have some interesting things to say about intellectual property in the context of university-business research collaboration, however. Things that were not included in the general pr accompanying the report when it was published.
http://www.hm-treasury.gov.uk/media//EA556/lambert_review_final_450.pdf

Section 4 covers the IP issues.

Whilst recommending that UK universities be more active about filing and exploiting patents and commercialising their IP, it suggests that IP is never going be a major direct revenue generator for universities. It cites the cases of MIT, Yale and Stanford in the US as institutions which started out with expectations of high earnings from market exploitation of their IP but which have now changed their objective for engaging in technology transfer to improving the "public good."

Some quotes from the report:

"A warning: the impact of technology transfer on the direction of research - whether it be towards short term applied or long term research - needs to be monitored carefully."

Cited barriers to commercialising university IP:
"copyright law is a big barrier to research collaboration between universities and the private sector...."

There were "too many lawyers involved, and too much time wasted" in trying to sort out IP ownership issues between industry and universities.

The FT apparently have an article on it today but their site was down when I tried to access it.

Amnesty International have criticised Microsoft and Cisco for selling technology to the Chinese authorities which is used to facilitate civil rights abuses, according to the Observer.
'[Microsoft] should be more concerned about human rights abuses and should be using its influence to lift restrictions on freedom of expression and get people out of prison. It is worrying that they don't seem to have raised these issues.'

But then again the free market is amoral and does not require companies to police the uses to which their products are put. Smith & Wesson are not held responsible every time one of their guns is used to kill a police officer or an innocent bystander.

I've been avoiding commenting on the Hutton Report. Lots of other folk are doing so in a much more enlightening way than I ever could. My Open University colleague, John Naughton is one.

Thursday, January 29, 2004

David Trimble has accused human rights groups of

"being complicit in the murder of innocent victims...

One of the great curses of this world is the human rights industry"

Amnesty's repsonse:

"The threat of terrorism must never be used as an excuse for abus ing people's human rights. David Trimble should remember that human rights organisations have condemned killings and other abuses by terrorist groups all over the world, while at the same time criticising governments who use the 'war on terror' as a pretext to abuse their citizens."
Disney have been in court again, this time with Roger Rabbit creator, Gary Wolf, who doesn't think he's getting his fair share of the reciepts from the commercialisation of his creation. It parallels the long running Slesinger case over the Winnie the Pooh takings. Looks like the Appeal Court sided with Wolf.

Meanwhile Google are heading to court in a trademark dispute with American Blind and Wallpaper Factory over selling keyword ads.
Thomas Goetz at Wired is predicting that the US businesses grounded in intellectual property will go the way of the erstwhile US shipping industry, if they don't stop focussing on extreme protectionism as the way to deal with new technology.

In the case of the shipping companies, he says:

"The US fleet was a classic victim of the efforts to save it. Rather than adapt to new economics, the American
industry suffocated under overregulation and protectionism. Now the job gets done - goods move efficiently from place to place - but it's a rogue's business, rife with ne'er-do-wells and pirates."

Larry Lessig, in the same issue of Wired, takes politicians to task for exploiting the general public's ignorance of economics in relation to developing versus developed world price discrimination on drugs.

There is no easy way out of this one. The economists' dream world is one of perfect price discrimination where everybody pays what the market will bear. Drug companies use their patent monopolies to generate revenues for profits and recover their R&D costs. They can't sell at high prices and huge profit margins in the developing world because the market will not bear it - people just can't afford it. So they sell the drugs at a premium in the developed world. With today's so called global markets, though, people in one area can justifiably ask the question as to why they should pay more than those in another area of the world. Economists will answer - because you can afford to. And that is a completely unsatisfactory to most of of us. But but but, we ask, why should I pay a premium when someone else can get them cheaper. I can just fly to Africa, buy a large batch and take them home with me and still have it work out cheaper - what the economists call arbitrage.

So when the free market absolutionists cry leave it to the market, the question I guess is, which free market? The producer-loaded one with perfect price discrimination or the customer loaded one with perfectly informed global consumer discrimination? A similar question goes to the anti-capitalist perspective - how can drug companies supply the need for medicines fairly across the globe and still generate respectable (or even optimum) revenues.

Information economics and intellectual property's place in it is a complex business. I don't have an answer and though there are models which help work out optimising theories, we live in an imperfect world.
Cory Doctorow has been getting passionate about the false choices of DRM, in response to a blog entry from Scoble at Microsoft:

"Well, says Scoble, all of the music that we buy from these legit services is going to have DRM use-restriction technology ("See, when you buy music from a service like Apple's iTunes or Napster (or MSN), it comes with DRM attached."). So the issue becomes "choosing between two competing lockin schemes."

And in that choice, says Scoble, Microsoft wins, because it has more licensees of its proprietary, lock-in format. That means that when you want to play your music in your car, it's more likely that you'll find a car-stereo manufacturer that has paid Microsoft to play Microsoft music than that you'll find one that has coughed up to Apple to play Apple music...

In this world where we have consumer choices to make, Scoble argues that our best buy is to pick the lock-in company that will have the largest number of licensees.

That's just about the worst choice you can make.

If I'm going to protect my investment in digital music, my best choice is clearly to invest in buying music in a format that anyone can make a player for. I should buy films, not kinetoscopes. I should buy VHS, not Betamax. I should buy analog tape, not DAT.

Because Scoble's right. If you buy Apple Music or if you buy Microsoft Music, you're screwed if you want to do something with that music that Apple or Microsoft doesn't like.

Copyright law has never said that the guy who makes the records gets to tell you what kind of record player you can use. If Scoble and his employer want to offer a product with "features" that their customers want, those features should reflect what their customers want: No Windows user rolled out of bed this morning and said, "I wish there was a way that I could get Microsoft to deliver me tools that allow me to do less with the music I buy...

No, the "customer" for Microsoft DRM is the guy who makes the records: the music industry; and not the gal who buys the records: you. That customer has already told Microsoft how it feels about its products: in the Broadcast Flag negotiation, the movie companies locked Microsoft DRM out of consideration for use in next-generation PVRs in favor of DRM that Sony (also a movie company, surprise, surprise) had a patent for.

Microsoft is selling out its customers to people who aren't even buying. Scoble points out that Microsoft licensed the hell out of its OS to hardware vendors, pioneering a new kind of open-ness. He's right. Microsoft set a good example that Apple has been too stupid to follow, and it's time for the company to do it again. When Microsoft shipped its first search-engine (which makes a copy of every page it searches), it violated the letter of copyright law. When Microsoft made its first proxy server (which makes a copy of every page it caches), it broke copyright law. When Microsoft shipped its first CD-ripping technology, it broke copyright law.

It broke copyright law because copyright law was broken. Copyright law changes all the time to reflect the new tools that companies like Microsoft invent. If Microsoft wants to deliver a compelling service to its customers, let it make general-purpose tools that have the side-effect of breaking Sony and Apple's DRM, giving its customers more choice in the players they use. Microsoft has shown its willingness to go head-to-head with antitrust people to defend its bottom line: next to them, the copyright courts and lawmakers are pantywaists, Microsoft could eat those guys for lunch...

But forget Microsoft, because Scoble's not talking about the best thing for Microsoft, he's talking about the best thing for you. The best way to protect your investment in music. Without a doubt, the best way to protect that investment is to only buy music that isn't in a lock-in format, and to break the locks on any music you do own, while you can..."

Wednesday, January 28, 2004

James Grimmelmann is back at Lawmeme and sharp as ever.

I hadn't seen the DVD he mentions, so it's interesting to hear such a high profile director encouraging creative re-use of his work.
There's an interesting interview with Michael Weiss, the ceo of StreamCast (Morpheus) in the eCommerce Times. He's not a fan of the music industry:

"Somehow, the RIAA has taken music's freewheeling image of rebellion and rock 'n' roll and turned it on its head. In their quest to control distribution, pricing and technological innovation, the major record labels and the RIAA have embarked on a journey filled with false accusations and half-truths. In an attempt to portray P2P file sharing as the root of all that is evil with society, the RIAA has resorted to lying to the American public and deceiving Congress.

There are solutions that can be worked out to ensure that artists and copyright holders get paid for their works, such as compulsory licensing. However, the RIAA appears to be more interested in compulsive litigation."

On the uses of P2P:

"There are so many great uses for distributed P2P technology, ranging from searching to content distribution to communications. One of the best uses is the enabling of free expression, free from the censorship of oppressive governments and the de facto censorship of news, information and political speech by the consolidation of media and news companies in the control of the entertainment and media conglomerates."

Last week they interviewed Sharman Networks (Kazaa) CTO, Phil Morle. He doesn't rate Morpheus:

"Morpheus ceased to be our main competitor, or indeed a trusted solution for users, a long time ago. eDonkey/Overnet is a strong competitor. They have cool technology and millions of users. I am consistently impressed with their releases that show a passion for P2P and what it can accomplish.

I am also surprised that Shareaza stays under the radar. Mike, who develops it, is a very ambitious young man, and I have to wonder when he sleeps. Shareaza is a well-made application that is a pleasure to use."

He doesn't like the music industry either:

"I have the benefit of many years thinking about P2P and its potential, and they have not got past the stage of fear. I am naturally disappointed that we are all wasting time and money on futile legal battles when everyone
could be growing their businesses and benefiting users today."

He seems to find the issue of privacy a problem because it interferes with the performance of the technology,
people don't have anything to hide and if they did we shouldn't facilitate it:

"Where I differ from some other file-sharing CTOs is that I don't believe users have anything to hide. Creating default "darknets" through technology defines the purpose of the network as illegal and encourages a certain kind of activity. This is not what we are here for because P2P is an enabling technology for all and not somewhere to hide. The modules found in Kazaa Lite that claim to bring privacy to the user can cause problems with other Internet applications, decrease the performance of the software and are ultimately possible to work around"

Interesting similarities and contrasts.

Tuesday, January 27, 2004

AP are reporting that "A federal judge has declared unconstitutional a portion of the USA Patriot Act that bars giving expert advice or assistance to groups designated foreign terrorist organizations."

Monday, January 26, 2004

Napster creator Shawn Fanning is working on a new venture, Sno-Cap to help record companies make money from p2p file sharing.
"Snocap's plan, which involves identifying music files being traded through file-swapping networks and then attaching a price tag to them, is resonating well with music industry executives. "
I like this story: Taking the Stuffing Out of Microsoft. It really does take intellectual property lawyers to create a legal battle between a software giant and a feather company.
The latest chapter in a long running dispute over the merchandising rights to Winnie the Pooh, closed in a Federal Appeals court on 15th January. The court blocked A.A. Milne's grandaughter's attempts to reclaim the rights from the Slesinger family.

Disney are backing Claire Milne because they are in dispute with the Slesingers over non payment of royalties. The case will continue as the court refused to rule on the substance of Milne's claims until the rights of Ernest Shepard's heirs could be sorted out. Shepard was the illustrator of the original stories.

Another children's character, Peter Pan, is the focal point of a transatlantic copyright dispute between Canadian author Emily Somma and the Great Ormond Street Hospital lawyers. It's a long story but briefly Ms Somma wrote and published a book in the US and Canada about Peter Pan growing up. Lawyers for the hospital's trustees want her to stop distributing the book, because under a 1988 copyright law the UK Parliament has granted the hospital a perpetual "right to a royalty" for "the public performance, commercial publication, broadcasting or inclusion in a cable programme service" of "the play 'Peter Pan' ... or of any adaptation of that work."

Peter Pan originally appeared in J.M.Barrie's book, The Little White Bird, published in 1902, the copyright of which has now expired. So Emily Somma believes she should be able to produce a derivative work. It seems she also offered to pay the hospital trustees a proportion of the royalties from the sales of her book.
Given that under US or Canadian law she would not be required to do this, it seems a pretty fair gesture.

It looks as though the lawyers are locked into an all or nothing mode which will just end up costing everybody. One of those cases that you would hope would never go to court.

The Stanford Cyberlaw Clinic maintains a faq on the case. Elizabeth Rader is acting as Ms Somma's lawyer.

Friday, January 23, 2004

Lauren Gelman, Assistant Director of Stanford Law School's Center for Internet and Society, writing for Findlaw, believes that despite the laudable efforts of the Howard Dean campaign, we have yet to see a real Internet election.

She has it absolutely right on the potential of the net to revolutionise elections through decentralization. Sharing the pessimistic outlook of her colleague at Stanford, Larry Lessig, however, I wonder at the collective ability of liberal democratic electorates to raise ourselves above the usual level of cynical apathy, to the extent that would energise the many to many participative real democractic process she describes.

I think she is also a little optimistic about the best ideas/debates/creative inputs automatically rising to the top. As Tim O'Reilly has so wisely said in the past, with billions of conversations or creative works, we can't read them all - we still need aggregators, who can put the producers in contact with those interested in the products of their creative endeavours. So even with a sufficiently participative electoral process along the lines the Net could facilitate, I predict that there would be an evolution to a kind of halfway house (between total central control and decentralization) of electoral process information supernodes. The centralizing urges of politicians and media moguls would be likely to attempt to converge on a kind of Clear Channel Communications model of control of these supernodes. But on the positive side, I'm a believer in the cock-up rather than the conspiracy theory of history and don't see a future of total control - there will always be leakage and the power of networks of people (note I didn't say the Internet) to nurture that leakage is very strong.

Thursday, January 22, 2004

AOL are getting blamed for the increasing incidences of STDs in the US. Gives you a whole new perspective on computer viruses.

STDs are not the kind of infection worrying the security experts who assessed the proposed $22 million online system to allow Americans overseas to vote via the internet.

The experts said the system has numerous serious insecurities and should be abandoned, so naturally the politicos are going to go ahead with it. When you find yourself riding a dead horse the best advice is to dismount. This one is a lot more serious that putting lots of resources into trying to get a dead horse to move with living impairment enhancements, though. Why does this stuff have to be so difficult to communicate to people? I think I'm going try muttering "computers are not magic but they can be fantastic" repeatedly, to see if that has any affect.
The Electronic Privacy Information Center, EPIC, were not happy to find out that NorthWest Airlines, like JetBLue, had also been handling over passenger details for government related research on airline/airport/aviation security. They have complained formally to the Department of Transportation. They are also intending to sue NASA to find out what they did with the information supplied by the airline.

The Electronic Frontier Foundation, EFF, are calling for a congressional inquiry "into who has been seeking,
getting and giving passenger data to the government".

Meanwhile, E-Data, have settled a patent infringement suit with Microsoft over "downloading of information onto a tangible object." "We are quite pleased with this settlement, as it further reinforces the scope and validity of (our) patent in Europe," said E-Data hairman Bert Brodsky in a statement. "While the OD2 service is still in the nascent stage…the agreement sends an important essage to other companies infringing upon our intellectual property."

Looks like they may be planning to go after Apple's iTunes next.

Wednesday, January 21, 2004

Yet another example of the kind of idiotic "security measures" post 9/11 panic has triggered at airports is beautifully told at the Mommy blog.

"Luckily, this year we will all be traveling together on the same flight because we were able to find decent fares. Neither of us will have to brave it alone, like I did once last year, and will endeavor never to do again. I could not believe what they put me through. That rule about not holding a baby during a search--what is up with that?? Believe me, I am fully capable of holding my child far enough from my body to get that little wand where it needs to go, but there was just no negotiating a compromise. I had a purple, writhing, screaming baby, a toddler, and a preschooler with me, not to mention a double stroller clogging up the gate, and in the end I actually had to put the baby on the ground so that they could put me in the off-balance stance, search me, and invesitgate the wire in my bra.

By this time our 4 year old was a sniffling mess because we had forgotten to warn him that they would put his stuffed dinosaur through the x-ray machine. He actually threw himself onto the conveyor belt and crawled in after it, so I had to go in after him and then carry him through the sensor under my arm, wailing and wriggling like a marlin. I am normally polite and understanding, but this time I glared holes into the forehead of the woman who made my put my scared and screaming baby on the floor and asked her, "Do you have children? I do, and they were very secure children until a few minutes ago. They were very excited about this trip, and now I have six more hours to go, several of which will now be devoted to explaining why this is necessary, but not something to be afraid of." Total strangers came up to offer their sympathy and wonder at my composure. I wanted to shake that woman for putting her training so firmly in front of her line of sight that she couldn't see that it was scaring the children and pissing off the passengers. "

Monday, January 19, 2004

"The U.S. Supreme Court reversed an emergency stay on a case involving DVD descrambling Jan. 3. "

They said Matthew Pavlovich, who lives in Texas, cannot be sued in California, so he can now post the DeCSS (DVD descrambling code) up on the web again.
According to Larry Lessig,

"CBS is said to have refused to run MoveOn’s winning ad, citing its policy not to run commercials dealing “with controversial issues of public importance.” CBS will instead run ads from the White House Office of National Drug Control Policy — apparently an issue of public importance that is not controversial. Who would of thought an ad criticizing a $1 trillion deficit was more “controversial” than an ad about the war on drugs?

Here’s what the true libertarians have been saying for a long time — the biggest reason to worry about concentrated media in a world where media is regulated is exactly this."
Professor Susan Crawford is has been refreshing her cyberlaw syllabus and asked for ideas on what should be included.

Ernest Miller, amongst others, has replied.

Prof Crawford's syllabus for Spring 2004 is here.

Friday, January 16, 2004

ISP's without exception are not cooperating with the RIAA's new approach suspected file sharer identification, in the wake of the surprise decision in favour of Verizon just before Christmas. The RIAA are now asking the ISPs nicely to notify specific customers that they are RIAA suspects.

"Under the proposal, the RIAA would supply an identifying IP address of a suspected infringer to its ISP, which would then send a notice of infringement to the subscriber. "

An federal judge in the Microsoft v Eolas technologies case has upheld the huge patent infringement damages awarded against Microsoft by a jury in the summer of 2003.

"This motion rehearses a set of arguments that failed the first time around," Zagel wrote in his opinion. "While I am not entirely comfortable with the large size of the judgment, it is not my comfort that matters."
"San Francisco – Jan. 13, 2003 – TRUSTe, widely known for its global privacy
seal program, today announced four new additions to its board of directors,
including Joseph Alhadeff, vice president for global public policy for
Oracle Corporation; Hans Peter Brondmo, senior vice president of strategy
and corporate development for Digital Impact, Inc.; Peter Cullen, chief
privacy strategist for Microsoft, and Bennie Smith, chief privacy officer
for DoubleClick. Leveraging highly successful business and management track
records, the new board members will support TRUSTe as it provides guidance
and enforcement to its members and consumers on emerging privacy issues
such as wireless location-based services and spam"

Interesting.
According to Michael Cross in the Guardian, those of us opposed to the Home Secretary's national ID card scheme are 'nutters', 'ignorant' and 'inconsistent'. Doesn't that go a long way towards raising the quality of the debate?

Interesting contrast with an Economist article I pointed to before Christmas, saying

"Spurred by the misplaced enthusiasm of governments around the world, biometrics seem headed for dramatic growth in the next few years. But calm, public discussion of their benefits and drawbacks has been lamentably lacking. Such discussion is necessary both to prevent the waste of public money in the short term?for the most part, the private sector has been wiser in its adoption of biometrics?but also to regulate what will eventually have the potential to become a powerful mechanism for social control."

Whadaya know, the Guardian coming in to the right of the Economist.
McDonalds have been testing the use of biomentrics - fingerprint and handprint scanners - to monitor empoyees.

"At McDonald's, the scanners are connected to the payroll
department and save on paperwork, Christianson said. They also
free managers from record keeping and get them out working with
staff and the public, he added. "
The British Phonographic Industry director general, Andrew Yeates, has laid the ground for the roll out of RIAA-type individual lawsuits, on this side of the pond, for p2p file sharing:

"We want to increase awareness of the legal implications of file-sharing. If these are not working, there has to be a degree of enforcement".

He confirmed this position a the RSA's "Music And Technology: Policy Frameworks for the Future" which I attended yesterday. (More on that when I get a minute to myself).

Wednesday, January 14, 2004

I learn via "the importance of" that an Italian judge has declared Sony Playstation mod chips legal in a cleverly crafted opinion. From the judge:

"Ironically, [it is Sony who first] had supported strongly the thesis that a playstation is a true computer and not just a game console, when asked by the EU to pay for custom duties imposed over the consoles (while computers aren’t subjected to this tax)."

Ernest Miller's view:

"Ooops. Avoid those taxes, create an opening for the argument that the PlayStation is a computer (the use of which should be unrestricted)..."

Nice.
These are good - winners in the George Bush in 30 seconds ads competition. I hope they do the same for the eventual democratic candidate and for Tony Blair in the UK.

Tuesday, January 13, 2004

A judge has put a spoke in Lindow's chief Michael Robertson's attempts to help consumers claim their share of the $1.1 billion class action settlement against Microsoft in California.

"Lindows.com Inc.'s site, MSfreePC.com, promised to simplify the
process and provide instant gratification. Users, after answering a few
questions, were given Lindows' Linux operating system or other
open-source software instantly rather than having to wait six months
for paper claims to be processed.

Microsoft said MSfreePC violated the integrity of the claims process.
Lindows countered that Microsoft did not want to simplify the process
so that it could collect a bigger portion of any unclaimed money."

The judge sided with Microsoft.

Off the back of the IBM and Intel initiative I mentioned yesterday, it seems that Novell are to follow suit and offer legal protection (against SCO) to their linux customers.
Edward Hasbrouck, aka the practical nomad, has been delving into a privacy impact assessment for the US-VISIT scheme whereby visitors to the US get fingerprinted and photographed.

"The requirement for fingerprinting and photographing of visitors to the USA (except for short-term tourists from a few
countries, almost all of them inhabited mainly by white people) has gotten most of the attention paid to US-VISIT. But the real
privacy invasion feature of US-VISIT is buried deeply, and its significance evaded, in the Privacy Impact Assessment:
US-VISIT will be used to maintain a lifetime travel dossier for anyone who ever visits the USA, just as CAPPS-II will enable
the maintenance of lifetime travel dossiers on anyone who ever travels by air to, from, or within the USA...
In order to implement US-VISIT more quickly than would otherwise have been possible, it is being treated for Privacy Act
purposes as merely a "modification" of existing systems, rather than a new system. The US-VISIT data flow diagram on page 4
of the Privacy Impact Assessment includes a "modified database" labelled "biometric and biographic travel history", to be
included within the ADIS (Arrival Departure Information System).

These "travel histories" aren't mentioned anywhere in the so-called "assessment", which says of ADIS and other records only
that, "The policies of individual component systems, as stated in their SORNs [System of Records Notices under the Privacy
Act], govern the retention of personal information collected by US-VISIT." To find out anything about the policies governing
these records, one has to look at the most recent SORN for the ADIS system , which was published in the Federal Register on
12 December 2003.

Only there, deep in the acronym soup at 68 Federal Register 69412-69414, does one learn that these records may be
disclosed without restriction to any law enforcement agency in the USA or any other country (even if not actually relevant to
any specific investigation) and, even more significantly, that "Records will be retained for 100 years." Full stop."

A Belgian consumer group, Test-Aankoop, have decided to sue the music industry over copy-protected CDs that don't play in many CD players. EMI, Universal Music, Sony Music and BMG are the specific companies on the receiving end.

A former Treasury official in Australia is questioning the apparently "obvious" link between music downloading and reduced sales of CDs.

"If the healthy state of CD sales in the face of massive do-it-yourself competition surprises you, you are in good company. Midway through last year the Chicago University economist Stan Liebowitz was warning of annihilation. The recording industry loved him for it. He said large-scale unauthorised copying could soon make it obsolete.

Liebowitz has since had a change of heart. In a new study entitled Will MP3 Downloads Annihilate the Record Industry? he concedes that the evidence for annihilation has failed to materialise...

He concludes that the impact has not been large and says his best guess is that the worst of it is over, given that most homes that would want CD burners now have them."

The BBC have a similar report about CD sales in the UK. Apparently album sales were at a record high in 2003 up by 10 million units on the previous year. "Album sales in the UK rose by 7.6% in 2003 to a record high, fuelled by falling CD prices - in spite of piracy fears, according to an industry report. "

The editor-in-chief at Wired, Chris Anderson, has penned an open letter with some useful advice to Jack Valenti's forthcoming successor at the MPAA.

"You've still got a little time to figure this out, but a lot
less than your advisers are telling you...
Customers who feel they're getting their money's worth are less likely to turn into pirates...
You're at risk of alienating your customers like the music industry did...
the Napster for movies has been born. It's called BitTorrent...
So what should you do? Start by accepting that new technology means a new way of doing business...
And don't fight the technology. People want their digital media the way they want it: every way imaginable."

Monday, January 12, 2004

Net users and ISPs in France are not very happy with the proposed law to make ISPs responsible for filtering online material for illegal content.

Derek Slater is looking deeply into the potential conflict between intellectual property and free speech, off the back of the recent Pew report which suggested that the RIAAs tactics of suing individual file sharers was having a significant impact on the volume of P2P traffic.

Ernie Miller is puzzled at HP CEO Carly Fiorina's attack on digital piracy. "How strange the spectacle of a major computer manufacturer calling for an all out war on what computers enable"

Broadband is to be the FCC's top issue in 2004 according to this report at CNet. "Federal Communications Commission Chairman Michael Powell said that he doesn't yet support regulating broadband telephone service providers, but thinks instead that a national "forum" to guide the young industry is more appropriate." He re-iterated his feelings on VoIP, saying it should not be regulated like the existing phone companies and even called California's and Minnesota's attempts to do this "scary". Good for him. I didn't agree with Powell's call on media ownership but he's got it right on this one.

IBM and Intel and others are creating a $10 million dollar defense fund to pay the legal costs of companies getting sued by SCO.

The Gaurdian reports that "The residents of one Yorkshire town got so fed up with being passed over for broadband access that they set up Britain's first ISP cooperative."

28 entertainment companies have agreed, in court, not to sue ReplayTV owners for skipping ads.

The RIAA are sending troops out onto the streets to crack down on street vendors - "Though no guns were brandished, the bust from a distance looked
like classic LAPD, DEA or FBI work, right down to the black "raid"
vests the unit members wore. The fact that their yellow stenciled
lettering read "RIAA" instead of something from an official
law-enforcement agency was lost on 55-year-old parking-lot
attendant Ceasar Borrayo...
"They said they were police from the recording industry or something,
and next time they?d take me away in handcuffs," he said through an
interpreter. Borrayo says he has no way of knowing if the records,
with titles like Como Te Extra?o Vol. IV ? Musica de los 70?s y 80?s,
are illegal, but he thought better of arguing the point."

The Grocery Maufacturers of America have, none-too-cleverly, sent an email to a consumer group, CASPIAN, suggesting they are trying to dig up some dirt "about the
group's founder, Katherine Albrecht." Albrecht has spoken out strongly against RFID tags in the past.

Finally for today, check out lots of interesting stories at Instapundit.
A Very Belated Happy New Year.

Folks at The Independent are concerned about the UK government's new Civil Contingencies bill and a scared new world.

The RIAA had a bit of a setback just before Christmas in their pursuit of individual file sharers when an appeal court on the D.C. circuit rejected their subpoenas to Verizon to identify suspects. So theoretically ISP no longer have to hand over customer details to the RIAA. The appeal court was pretty blunt and said the text of section 512 (h) of the DMCA "does not authorize the issuance of a subpoena to an ISP acting as a mere conduit for the transmission of information sent by others." Donna has more.

Miriam Rainsford has an interesting commentary on Siva Vaidhyanathan's P2P essays at OpenDemocracy. She echoes, in this particular context, something John Naughton has been saying for some time: "we overestimate the short-term impacts of technology while underestimating long-term effects." I agree with Miriam also about the problematic use of emotive words but it does highlight a frustrating dilemma - in a world of short attention spans, before you can convince an audience of your perspective, you have to gain their attention. And using words like "anarchist" is a way to do that. If the language only leads to the usual polarised debate we see in the mainstream media then it gets us no further forward. However, if you can use it as a tool to alert sensible folk to the fact that there is a debate to be had and that it is a bit more complicated than the usual soundbites lead most people to believe, then there is some hope of progress. In the latter regard, I'd recommend both Siva's and Miriam's writings.

BTW folks I'm looking into switching my weblog to an OU server in the none-too-distant future, so look out for a url change for b2fxxx soon. We'd like to do some more active integration of blogs into some of our courses and it will make sense for my own blog to be in-house. It's time we started pushing some of the boundaries of what we can do with these kinds of technologies in an educational context again.

Tuesday, December 23, 2003

Merry Christmas to everyone. I'm off on a two week sabbatical for the festive season.
The Appeal Court in Norway has given Jon Johansen of DeCSS noteriety an early Chrismas present. There are a couple of factual errors in this BBC report in that Johansen did not actually create DeCSS and the MPAA did not bring the case against him, the Norwegian authorities did. But they get the aquittal right which I guess is the main thing. Trying to portray Johansen as a "serial hacker" is stretching things a bit but the MPAA are clearly disappointed at the outcome.

Friday, December 19, 2003

Creative Commons folk have had a party and a new animation to celebrate their first year in existence. (Warning the animation is pretty big, so unless you're on Broadband, it might be better to give it a skip, until they produce a smaller version).
The Dutch Supreme Court have just dismissed a case brought against the developers of Kazaa by the Dutch music copyright levy collection agency, BUMA. Kazaa creators cannot be held liable for the actions of their users.

It appears as though the Court's decision was procedural i.e. Kazaa won on a technicality. BUMA had wanted Kazaa changed in such a way that it would make copyright infringement using the program impossible but didn't file the correct legal documents in the correct way within the required deadlines. So the ruling is about procedures rather than directly about the liability of Kazaa for P2P file sharers actions. BUMA may try again.

Comment from the usual suspects imminent.

Thursday, December 18, 2003

I'm buried in exam marking and a pre-Christmas admin. mountain, so won't be posting much. Some things of note going on, not least of which is the Canadian Copyright Board's decision to stick a levy on MP3 players and suggest P2P downloading is legal (although uploading copyrighted files is not).

Friday, December 12, 2003

Susan Crawford is all for the RIAA litigationagainst individual copyright infringers but she is puzzled:

"If all bicycle manufacturers said all bicycle purchasers have to buy a particular form of bicycle, and that no bicycle can be loaned to a friend, we'd be upset -- and some black-market bicycle makers would show up with cheaper goods that consumers liked. What's so special about songs? Why do they get such special treatment? It must be true that all law is becoming intellectual property law -- it's like the growth of Chinatown. It's taking over... We're left with shards of rights, compliant devices, and expensive tunes...

So: I'm all for the lawsuits, that's fine, but you can't build a marketplace through litigation. Just as you can't demand that you come from a happy family, and make that true by fiat, you can't create loyalty to a product or a service by suing some of your customers. "
A Chisnese court in southwestern province of Sichuan has allegedly sentenced a man to eight years in jail for writing on the Web about corruption amongst Sichuan officials.
The re-trial of Jon Johansen, who originally posted DeCSS on the Net, has ended with the prosecuters calling for a suspended jail sentence. The Appeal court is due to issue it's verdict in about ten days. Nice Chrismas present for somebody?
Michael Robertson will be less than pleased that a Swedish court has at least temporarily sided with Microsoft in their trademark claims against Lindows.
Robert Cringely on "Why the Current Touch Screen Voting Fiasco Was Pretty Much Inevitable" A taste:

"Voting is nothing more than gathering and validating data on a huge scale, which these days is almost entirely the province of IT. And like many other really big IT projects, this touch screen voting thing came about as a knee-jerk reaction to some earlier problem, in this case the 2000 Florida election with its hanging chads and controversial outcome. Punch card voting was too unreliable, it was decided, so we needed something more complex and expensive because the response to any IT problem is to spend more money making things more complex...

In the case of this voting fiasco, there was a wonderful confluence of events. There was a vague product requirement coming from an agency that doesn't really understand technology (the U.S. Congress), foisting a system on other government agencies that may not have asked for it. There was a relatively small time frame for development and a lot of money. Finally, the government did not allow for even the notion of failure. By 2004, darn it, we'd all have touch screen voting."

Spot on.

Thursday, December 11, 2003

The Irish government have just published their proposed implementation of the EU directive on copyrights and related rights in the information society. Looks like a provision of existing Irish copyright law, Section 374 of the Copyright and Related Rights Act 2000, which explicitly allows the circumvention of "Rights protection measures" for fair dealing purposes is being replaced. So the construction of digital fences around existing access rights may now be premitted by law in Ireland. I have not reviewed the document in detail yet, so I'll need to have a proper look.

Monday, December 08, 2003

According to Groklaw, the judge in the SCO v IBM case has ordered SCO to disclose the specific code they claim IBM is infringing on. SCO had wanted IBM to turn over all their code so that SCO could pick through it to find infringements.
The Economist have a thoughtful article about the increasing market for biometrics, concluding,

"Spurred by the misplaced enthusiasm of governments around the world, biometrics seem headed for dramatic growth in the next few years. But calm, public discussion of their benefits and drawbacks has been lamentably lacking. Such discussion is necessary both to prevent the waste of public money in the short term—for the most part, the private sector has been wiser in its adoption of biometrics—but also to regulate what will eventually have the potential to become a powerful mechanism for social control."
I attended a really interesting seminar given by Oxford Balliol College Research Associate, Ms Tina Piper, last week on Tuesday December 2, 2003. Entitled 'The Unpatentability of Medical Diagnostic Methods: A Promise and Its Perils', it was one of the Oxford Intellectual Property Research Centre's Seminar Series. These are my notes on Ms Piper's fascinating talk.

Article 52.4 of the European Patent Convention excludes "medical methods" (of which "diagnostic methods" are a subset). This kind of exclusion is included in the patent law of 80 countries and the technical excuse for it tends to be that medical methods are not "capable of industrial application." This is a bit of a fudged construct but the law sometimes works like that.

The medical methods exclusion applies to the UK, Europe, Canada and New Zealand and there is a compromise on the exclusion in the US, which effectively gives medical practitioners immunity from being sued for patent infringement for using a patented technique. Medical methods are not excluded from patentability in Australia. "Diagnostic methods" are excluded in the UK and EU.

The US originally had an exclusion, then lost it and then partly regained it in the wake of the notorious Pallin v Singer case, when one eye surgeon sued another for patent infringement for performing a specific type of cataract operation. The Omnibus Appropriations act of 1996 made it possible for doctors to get patents on medical or surgical (but not "diagnostic") procedures but banned them from suing other doctors using the procedure in the course of their work. A congressional representative in 2002 introduced a bill called the Genomic Research and Diagnostic Accessibility Act but she has since been voted out of office and Ms Piper was unsure of the current status of her bill. This would have introduced patent infringement liability for diagnostic methods/tests.

The definitive UK case in the area for most of the 20th century was apparently a 1914 patent case (C and W's Application, Re (1914) 31 PRC 235, 36 Digest (Repl) 656, 104?). The UK Patent Act of 1977 suggested a definition for a diagnostic method - it must include all the steps in making a diagnosis (and it lists the steps). The Cygnus case challenged this definition saying the determining factors should be that the procedure is carried out by a skilled practitioner on or in the body i.e. it doesn't apply to samples taken from the body and tested in the laboratory.

There is supposed to be an overriding governing principle in this whole area, derived from the Baker Norton Pharmaceuticals case and guidelines from the European Patent Office, which states that:

Patents will not hamper doctors valuable life saving work.

Unfortunately in practice the principle is more represented in the breach than the observance. Ms Piper suggested there were a number of problems with the principle -

1. The exceptions from patentability of medical methods exist on paper but not in practice - judges and lawyers pretend the exception does not exist (In the Eli Lily case in 1976, the judge said that there was no logic to the idea of a medical methods exception and that it was based on ethics rather than logic).
2. There is little evidence of a principled approach in practice - drugs are patentable, diagnostics are not but the divide is artificial because diagnostics can take place in the lab rather than in the traditional face to face way. Skin tests applied to the body are not patentable yet the same test applied to a remote sample in a lab would be patentable.
3. There is little substantive protection of what are perceived to be healthcare goods - i.e. the exception covers very little in practice.
She then asked why should we care and provided some very succinct answers to her own question -

1. It is important to ask whether some technologies morally should or should not be patentable.

2. We are currently exporting our intellectual property laws to other countries through international treaties and trade agreements, so we should understand intimately the impact of these laws.

3. The state of the law may affect access to or cost of patented technologies and in the case of medical methods this is a public interest issue. An example is Myriad Genetics patent claim on the BRCA genes that can indicate a predisposition to develop breast cancer. Similarly in the case of the international outbreak of the SARS virus in 2003 there was a three way race to find and patent a causal gene sequence.

4. The state of the law will affect the type of technologies that will be affected, even if we only believe the inventive function of IP law. (If you add access to the knowledge base required to create those technologies there is a whole new dimension).

How did we get to where we are on medical methods patents? It turns out that it is all down to history.

In the mid 1800s medicine was a two tier profession. Wealthy upper class specialists and poor GPs. There was no standard training and anyone could set themselves up as a doctor. There were also lots of unsafe and useless medicines (like the carbolic smoke ball, the object an important contract law case Carlill v Carbolic Smoke Ball Company in 1893) and very little standardisation there either, in terms of treatment.

At that time 20% of all patents awarded were for medical treatments or medicines. The system was just a registration process, not the kind of examination and prior art process we have today. Anybody could register a patent and it was used as a marketing gimmick, a promotional badge supposedly giving the medicine the legitimate government stamp of approval.

Then the medical profession or elements therein decided to take control of the situation. How? They essentially created a parallel system to the patent system of the time, operating within a self-regulated medical profession. The self-regulation was effectively based on a set of ethical principles derived from the Hippocratic oath.

The profession:

1. Defined, facilitated and created a set of education standards that doctors who were to be registered had to meet. Basic training was standardised.
2. They encouraged collegiality and fraternity - in the spirit of the scientific method - medics shared their knowledge.
3. They got public support by creating a code of ethics which doctors were required to work to and opted out of the free market.
4. They gained state support and licensing and then self-regulation
5. They excluded regulations by other professions i.e. they booted out the lawyers

So they had created a parallel system to the patent system, (where lawyers and snake oil salesmen reigned), by replicating a number of functions of the patent system. Also medical inventions were evaluated on merit through peer review. (Now the peer review process has its own problems with hierarchy, convergence on the status quo, personality clashes etc. but we won't go into that as Ms Piper didn't). This new system meant that the incentive to invent was based on the acquisition of reputation. A fundamental aim was disclosure of new methods, products and processes - encouraged by the code of ethics and in the public interest, since it facilitated wider public access to effective treatments. There was also an indirect monetary effect in that the doctors with the best reputations were guaranteed a secure professional income.

Medicine was situated outside the market and until the 1920s and 1930s medics were completely against the patenting of medical methods because of this history. It was considered unclean for doctors to think about registering such patents - just not the done thing. In taking the profession outside the market, it also removed unseemly public legal disputes between doctors, such as the later (US) Pallin v Singer case, from the courts. Doctors don't like these kind of spats as they reflect badly on the whole profession. Even nowadays as we saw earlier Pallin v Singer led eventually to a change in US law. This was largely due to the general horror amongst powerful elements of the profession that a surgeon should be obliged to take three years of his life and run up $0.5 million in legal fees to defend his right to do his job using the best methods at his disposal.

One of the guiding principles was that patents should not hamper doctors pursuit of a decent income.

The original restrictions (late 1800s and early 1900s) imposed by this new medical profession governed regime required no patenting of substances, treatments or methods, though some patents on devices were allowed. And the rules were specifically enforced against doctors. The British Medical Association and the Medical Research Council enforced the rules.

There was some conflict and for example insulin and treatments for things like scarlet fever did get patented. The Association of British Medical Manufacturers also lobbied the BMA and MRC aggressively to open up the way to allow medical patents again. They justified their stance by saying that medical ethics insisted upon by the BMA et al were too strong and it was resulting in doctors being denied access to valuable rewards that would accrue from research. Doctors who wanted to take advantage of the patent system were being made to feel dirty about it.

The lobbying led to a series of developments in the law -
1. Dedication of medical patents to the MRC
2. Compulsory licensing, whereby patent holders were precluded from denying access to their innovations to but could derive some income from them
3. A medical methods exception to patents to avoid the Pallin v Singer type court case.

Effectively formal law was irrelevant to the reality of how medical patents were treated by the profession, the industry or the courts. When anyone wanted to change the law they formed a coalition and lobbied the BMA and the MRC. Ms Piper's (tongue-in-cheek) conclusion from all this was that, in reality, the lack of patents did not hinder doctors' access to a decent income.

What it did mean though was there was a lack of clarity and no logical conclusions as to what could be patentable in the area of medical methods.

What initial lessons is she drawing from her research to date?

1. Intellectual property law developed as the profession and the industry developed and evolved.
2. Intellectual property is about the interaction of legal and social norms. (We could add Lessig's architecture and market forces to that).
3. Intellectual property law can be and does get changed by well organised and resourced lobbyists.
4. When a law is widely ignored the whole legal system is undermined to a degree which can be dangerous.
5. We should recognise that the world has changed drastically and ask whether the appropriate balance in intellectual property has been maintained or whether it requires a re-alignment.

She finished with a question about how best to ensure access to medical methods and what role an exception for diagnostic or medical methods patents would play in that.

It seemed to me from the substance of Ms Piper's talk and her responses to the questions from the convened gathering afterwards, that she is very concerned about the public interest in all this. Basically, as in the US, well funded and organised self-interested groups can get together to change the law and the reality of medical methods patents but Jo Public does not get a seat at the table. (Interesting parallels here then with the situation in the US, where the relevant interest groups sit down, negotiate changes to the law, draft the new law and hand it to Congress for ratification. Jessica Litman, in Digital Copyright, describes this process with crystal clarity). Where indeed does the public interest get represented or, more importantly, factored in?

Perhaps it will be by making the general public more aware of the kind of work being done by the Tina Pipers of this world? Medical methods patents are a particularly stark illustration of the way in which intellectual property has serious impacts on ordinary people. We only have to look at the tragedy of AIDS in Africa and the lack of access to drugs with a track record of inhibiting the progress of the disease, to see this. If apathetic, disinterested Jo Public cannot be made to sit up and take notice of the life and death consequences of getting the balance right in intellectual property in this area, then it's never going to happen. My worry, however, is that it is just too emotive and attractive to the elements of the media interested in stoking up newspaper-selling public rows. The result is black and white sound bites from the extreme ends of the spectrum getting exposed and a complete lack of understanding of the real complexity of the issues we need to address to move forward.

Sunday, December 07, 2003

Anita Ramasastry on Why we should fear the Matrix.
Larry Lessig is worked up about SCO's CEO, Darl McBride, insulting the constitution by claiming it supports his case against IBM and Linux.
California is about to criminalise the act of sneaking a video camera into a cinema.
In the wake of Jon Johansen posting some software to help get round Apple iTunes digital rights management, some previously happy customers are feeling a bit put out. Not that Johansen has created the foundations of a workaround (though there are folk being less than polite about that) but rather that they feel conned into buying into DRM.

Can't really blame Apple, who made it pretty clear the files were protected, though they did deliberately fudge the issue of first sale.