Tuesday, March 23, 2004

Mr Blunkett's ID card scheme is running on apace.

"Mr Harrison" [the head of the Home Office's identity card policy unit] "also outlined the latest Home Office thinking on on whether or not the one million Irish nationals living in Britain will have to carry UK identity cards...

Mr Harrison told a Law Society conference yesterday that
ministers had started with the assumption that information on
the pattern of everyday transactions involving each card would
not be kept on the central computer database.

But following representations from the information commissioner
they were now minded to keep information "about the audit of
transactions" to allow the authorities to investigate abuses of the
scheme...

The senior Home Office official also revealed the current thinking
on how to deal with the Irish problem. The 1949 Ireland Act
specifies that Irish citizens living in Britain enjoy total freedom of
movement between the two countries...

Mr Harrison said the plan now was to allow Irish nationals in
Britain to choose whether to be treated on an equivalent basis to
a British national or as an EU foreign national. He said there
would be a separate document which Irish nationals could obtain
which would not be a foreign national's resident's permit to
reflect their special status. "
Donna is getting some help with Copyfight. Elizabeth Rader, Aaron Swartz, Jason Schultz, Wendy Seltzer and Ernest Miller. They don't come much smarter than that lot. I wonder if it is something about people with names with 'z' in them, that raises the IQ (Ernest being the exception that proves the rule)?

Donna's first post to the new collective relates to the latest challenge coming out of Stanford's CIS to the Copyright Term Extension Act. With Golan v Ashcroft also coming out of that stable Lessig and co. seem determined, as James Grimmelmann so eloquently suggests, to salvage the phoenix from the Eldred case Supreme Court ashes. Better go update my link to copyfight now it has moved back to Corante.

Monday, March 22, 2004

The Guardian leader today shares my perpective on David Blunkett's intention to take advantage of the Madrid bombings to introduce ID cards. The illusion of security is the enemy of security.
UK Home Secretary, David Blunkett, is back to his hobby horse of trying to get his national ID card scheme implemented again and has Cabinet colleagues complaining about his sneaky tactics.
According to Mary Hodder and the smoking gun, Donald Trump has applied for a trademark on the phrase "You're Fired". Mary notes that "You're Outsourced" is still available.

Friday, March 19, 2004

A "True Name and Address" bill for all filesharers has been introduced in California. Ernest Miller is not impressed.

"The basic idea of the bill is to extend a "true name and address" statute to cover virtually all exchanges of copyrighted audiovisual information. That is, if you send someone a copy of a recording or audiovisual work electronically without also providing your true name and address, you could be fined $2,500 and spend a year in the clink...

We need to have a "true names" bill for politicians. By all rights, State Sen. Kevin Murray" [who is sponsoring the bill] "should start calling himself State Sen. Hollywood Sycophant."

I guess something similar could be said of Bill Lockyer, California's attorney general after his recent call to arms to fellow AGs about "dangerous" P2P software. 'Hollywood Ingratiator General' anyone?

As Ernest says,

"And what is this? Hollywood can't afford to sue people? We citizens of California have to expend precious tax dollars and limited law enforcement resources on copyright enforcement because Hollywood is too darn cheap? With massive statutory copyright damages available as a remedy, there is no excuse for Hollywood not to prosecute copyright infringers directly. Heck, it could even be a profit center."

Thursday, March 18, 2004

The Council of Europe's Convention on Cybercrime has been ratified today by Lithuania. "Following this fifth ratification, the Convention will enter into force on 1st July 2004 for Albania, Croatia, Estonia, Hungary and Lithuania. "

Kazaa duo's next call at Mercury news is a nice piece about Kazaa founders Niklas Zennstrom's and Janus Friis's new Net telephony service Skype. I vaguely recall seeing exactly this report somewhere last year but can't remember where at the moment.

The Eolas v Microsoft patent infringement case is testing the procedures in the US Patent Office, as well as the courts, as the patent is to be subjected to further review. Paul Festa says, "The next round in Microsoft's Web browser patent fight will unfold in an obscure bureaucratic proceeding that offers the company and its allies few, if any, chances to argue their side."

SNP MEP Neil MacCormick has offered a gentle critique of fellow MEPs Malcolm Harbour's (Conservative) and Arlene McCarthy's (Labour) support for the EU's intellectual property enforcement directive.

"There is no doubt that the EU should take action against counterfeiting and piracy...

...However, valid questions must be raised as to whether all the measures passed last week in the European Parliament are the correct ones - or whether some of them may bring unintended but serious consequences...

...Malcolm and Arlene argue that the EU directive has always been intended to tackle professional, commercial scale counterfeiting. Maybe so. It's just a pity that the final version which they voted for last week doesn't fully achieve that restriction...

...So, while it's true that a teenager doesn't have to fear his bank account being seized, it's not true to say that he can't have his CD collection seized...

...Another area of concern is the inclusion of patents in the scope of the directive. Patent law is much more complicated than other areas of IP law and much more open to abuse.

Legitimate companies who produce cheaper versions of medicines, for example, fear that the multinational drugs conglomerates will use this to stop the production of derivative medicines, so called 'generic medicines'...

...Perhaps the biggest disappointment in last week's European Parliament vote is that it was an opportunity lost. In an effort to rush through legislation before this June's elections we have ended up with a flawed directive.

Malcolm Harbour and Arlene McCarthy are right to say that the directive will be monitored and reviewed in due course. It's a great shame that so many people stand to suffer in the meantime in ways irrelevant to stamping out piracy and counterfeiting."

Wednesday, March 17, 2004

MacUser is reporting that "British government gets serious about open source" Which gives me an opportunity to mention a project launched yesterday by John Naughton and Quentin Stafford-Fraser called Ndiyo, (the Swahili word for 'yes') which has the small aim of changing the world. John likes a challenge.

It's all about bridging the digital divide (or more accurately, expanding the bubble of those included in the communications revolution) by using a new affordable hardware architecture and open source and free software.

In terms of architecture they're basically re-inventing the mainframe paradigm, the processing power of which can be shared by multiple users working from essentially dumb terminals. It's a slight variation on Larry Ellison's network computers from a few years back but workable on a local area basis. A clever, cheap, disposable, small box of tricks handles the local networking that let's the users at their terminals use the interact with the computer, which would be a PC equivalent. The box of tricks is currently proprietry technology, the patents on which are held by Newnham Research.

But Ndiyo are in the business of creating open standards to make a communications infrastructure equivalent to our plumbing or electrical network infrastructures, which everyone can have access to. They need companies like Newnham to manufacture the kit and break away from the Bill Gates enabled thinking trap about everyone needing a personal computer (running Microsoft software) but there is little stop another company to come up with their own version of networking box of tricks. In fact this piece of the infrastructure could be slimmed down to a single chip which could be mounted on the back of the monitor.

Given the vastly under-used processing power of most personal computers, or as Clay Shirky calls them "the dark matter of the internet", this kind of project is long overdue. It provides a huge potential to wire up inner cities, schools and public services at a tiny fraction of the cost of the equivalent in the WIntel universe. And that's just scratching the surface of what it could do in the affluent West.

Not many people know that about two thirds of the cost of an average PC is down to the licenses for Windows and Office software and the money goes straight to Microsoft. So using open source or free software provides an instant and vast cost saving.

I do have a slight worry about the reincarnation of the old monster, tyranno-sysadmin, who used to control computer users lives in relation to access to the sacred mainframe machines but that's a minor glitch in the scheme of things. There are also some technical obstacles ahead, as well as the issues of social protocol and questions of control over personal data, which brings me back again to the overall objective and the suitability of this new information architecture to the context, as well as, critically, they way the technology is deployed.

Nydiyo are committed to delivering three projects this year - a classroom in a box, an office in a box and an internet cafe in a box. Will John, Quentin and their small band of troops manage to change the world? Given an the ever increasing information feudalism we're seeing in the 'modern' world, I hope the answer is an emphatic Ndiyo.
Andrew Cringely recently asked "A Year Into the E-voting Crisis, Shouldn't We Have Noticed the Printer That's Already Built into Each Diebold Voting Machine?" Yet one of the spurious arguments against a verifiable paper audit trail is that is would cost too much to fit the printers to the e-voting machines.

Example:

"Meg Smothers of the League of Women Voters recently said that Georgia has 28,000 voting machines, and it would cost $15 million to retrofit them with printers to produce receipts. That comes to $535 per machine. "

I see. So we must employ computing in elections because computers are magic and they cost a lot, so they must be good. But we can't spend enough to make them actually work because it would cost too much. And it would cost too much because computers are pricey, so obviously if we want them to do anything extra (like print) that will cost a lot. And we are too stupid to realise that the computer will already do that extra thing we want it to do (i.e. print) - we just have to switch that part on. We are also too stupid to realise that because we don't even try to understand how computers work - because they are magic and we won't be able to. But we must have them for our elections because they are magic and using computers for anything will obviously make it better. That's alright then.

I wonder if any of these people ever heard of Josef Stalin? You know, the fellah that said "It is not the people who vote that count. It is the people who count the votes."

Monday, March 15, 2004

EU regulators have been meeting today to agree a draft ruling branding Microsoft a monopolist.
According to Xeni Jardin at Wired, the MPAA have drafted a letter for the California attorney general, Bill Lockyear, to circulate to fellow attorneys general, to encourage an all out legal assault on P2P file sharing software companies.

"The draft document, dated February 26, was obtained by Wired News on March 12. Distribution of a revised version to other attorneys general is said to coincide with the spring meeting in Washington, DC, March 15 to 17 of the National Association of
Attorneys General, of which Lockyer is president. The attorney general's office plans to release a final version publicly within the coming month, after obtaining additional signatories.

"We do not wish to make any comment at this time on any document that the office of the attorney general may or may not be developing," said Tom Dressler, spokesperson for Bill Lockyer in Sacramento. "But we remain concerned about the potential dangers posed to the public by peer-to-peer file-sharing technology."

However, the metadata associated with the Microsoft Word document indicates it was either drafted or reviewed by a senior vice president of the Motion Picture Association of America. According to this metadata (automatically generated by the Word application), the document's author or editor is "stevensonv." (The metadata of a document is viewable through the File menu under Properties.)

Sources tell Wired News that the draft letter's authorship is attributed to Vans Stevenson, the MPAA's senior vice president for state legislative affairs. MPAA representatives have issued similar criticisms of P2P technology in the past. Stevenson could not be reached for comment. "

Extract from the letter:

"As a P2P software developer and distributor, we believe you have the ability and responsibility to better educate consumers about these known risks, and to design your software in a manner that minimizes the risks. We view with grave concern reports that at least some P2P software developers may be adding features deliberately designed to hinder law enforcement in its prosecution of crimes using P2P software. Companies that engage in such conduct, and fail to meet the important responsibilities referenced above, harm the interests of consumers in our States.

It is widely recognized that P2P file-sharing software currently is used almost exclusively to disseminate pornography, and to illegally trade copyrighted music, movies, software and video games. File-sharing software also is increasingly
becoming a means to disseminate computer worms and viruses. Nevertheless, your company still does little to warn consumers about the legal and personal risks they face when they use your software to "share" copyrighted music, movies and computer software. A failure to prominently and adequately warn consumers, particularly when you advertise and sell paid versions of your software, could constitute, at the very least, a deceptive trade practice...

...Whether it is the widespread availability of pornography, including child pornography, the disclosure of sensitive personal information to millions of people, the exposure to pernicious computer worms and viruses, or the threat of legal liability for copyright infringement, P2P file-sharing software has proven costly and dangerous for many consumers...

Over the coming months, we will begin focusing more attention on the risks P2P software programs pose to consumers in our States. We hope this inquiry will encourage you to take proactive, concrete and meaningful steps to address the problems we have raised in this letter.... We take seriously our responsibility to protect consumers and ensure that the laws of our States are respected. In the future, we will not hesitate to take whatever actions we deem necessary to ensure that you fulfill your duties as a responsible corporate citizen.

The states of New York and Wisconsin have announced that they are withdrawing from the controversial MATRIX interstate database program. MATRIX is the state level version of the now scrapped Total Information Awareness program, which had the aim of sucking in vast swathes of personal data on everyone, thereby enabling the computer to automatically pinpoint the terrorists in our midst.

It sounds a superfically and intuitively attractive prospect, until you think about it. What if the computer or the operator gets it wrong? Like I said earlier. Law enforcement is difficult. And, as H.L. Mencken said, "For every human problem there is a solution which is simple, neat and wrong." We're right back to the old theme which I seem to come back to repeatedly, the widespread

"Boys-Own blind faith of computing ignoramuses, like certain decision makers, in the ability of computers to automatically and magically make things better, regardless of the overall objective or the suitability of the tools (computers) to the task or [critically] the way in which those tools are deployed, drives me nuts on a daily basis in my own day job. That it is happening in so important a context " as [choose your own context - in this case I choose 'law enforcement'] "is worrying in the extreme"
Ernest Miller is well worth reading on the problems law enforcement authorities have in surveilling the Net. The FBI are seeking to expand Carnivore. Miller's repsonse? They're onto a hiding to nothing because of the architecture of the Net.

"The amount of intervention in technology development necessary for the FBI and DOJ to accomplish what they want with regard to wiretapping is enormous. The costs will be both direct (money out of consumer's pockets) and indirect (loss of innovation). However, that is only half the picture. Unfortunately for the FBI, the costs to defeat the wiretapping are relatively small and will continue to decrease. We have here an asymmetric situation that will only grow more asymmetric as time goes on.

The problem is with the underlying architecture of the internet. Advances in technology along with the end-to-end/layers principle mean that it will always be cheaper to add encryption to the edges of the network than to increase the amount of surveillance at the center of the network. How much does it cost to write an encrypted VoIP app? Not much. How much does it cost to build the surveillance mechanism and conduct the surveillance across all possible ISPs? A heck of a lot more.

Ok. Now that the first encrypted VoIP app is compromised ... how much will it cost to build another encrypted layer on top of the first one? How much will it cost to conduct surveillance on this new layer? Hmmmm, if this progression continues, as we add additional layers of encryption and surveillance, the costs will increasingly diverge. Not a game you can win ultimately. In fact, it doesn't make much sense to even start. The FBI should be happy with what they've got...

...If I were the FBI, I wouldn't waste my time on a battle I ultimately couldn't win and instead would concentrate my efforts on the place where I could still achieve my goals - the ends. You want to know what someone is up to online? I would recommend, for example, key loggers, "real" spyware, and social engineering. It ain't gonna be easy, but you have a chance of winning in the long term. The sooner you quit a race you can't win, the faster you can enter a race where you have a chance."

He's got a point but it's one that takes longer than three seconds to grasp, so I don't see the politicos getting it any time soon. It's easy to spend lots of money and say we are spending lots of money fighting crime, and spin an illusion that such tactics work. It's hard to do the kinds of things Ernest is talking about and there are no simple tick box targets to wave in front of the media to illustrate success.

But law enforcement is hard.
Back to one of my hobby horses of recent times and a Wired report, Legislators Urge E-Voting Halt.

"State Sens. Don Perata (D-Oakland) and Ross Johnson (R-Irvine), the chairman and vice chairman of the Senate election committee, sent a letter to Secretary of State Kevin Shelley urging him to decertify all paperless touch-screen voting machines before the general election...

..."California has a lemon law that protects consumers if they buy a bad car," Johnson said at the press conference. "So far, e-voting in California is a lemon." He said Californians should demand no less oversight for voting machines."

Usually I hate soundbites. That one, I like.
The NYT reported on Friday that Microsoft has been encouraging big investment in SCO. There has been a fair degree of speculation about this ever since SCO launched their legal campaign against linux but the NYT have seen an email with specifics. Interesting, though hardly earth shattering.

Friday, March 12, 2004

There are a fair few reports around on the implementation of the IPR enforcement directive of which this EurActiv one is relatively typical. It is a sad irony that the Irish government should be instrumental in steering a pathway for this directive through Parliament, the Commission and the Council. Prior to their implementation last year of the copyright and related rights directive of 2001, the Irish government was one of the few which recognised an explicit right to bypass digital fences for fair dealing purposes. Section 374 of the Copyright and Related Rights Act 2000 allowed the circumvention of "rights protection measures" when the purpose was to access and use the protected work in ways otherwise permitted by copyright law.

Thursday, March 11, 2004

Excellent Greplaw interview with Seth Finkelstein.
On Tuesday, 9th March, the same say they were passing the intellectual property enforcement directive, the EU parliament

"...adopted a Resolution saying that the 1995 Data Protection Directive was not working because of lack of resources, powers of enforcement, and lack of political will by national governments and the European Commission. The Resolution condemned the handing over of passenger data on people flying to the USA because it is contrary to EU law and the 1995 Directive.

The Resolution was passed by 439 votes in favour, 39 against and 28 abstentions"

Tony Bunyan, Statewatch editor, comments:

"The European Parliament has decided, overwhelmingly, that data protection in the EU is not working. It has also decided that the transfer of personal data (PNR) on airline passengers to the USA - which has no data protection laws for non-US citizens - would "flagrantly breach" EU law.

At the end of this month the European Parliament will be asked to vote again on the question of whether or not the USA offers "adequate" protection of data for EU citizens flying there. National government will put a lot of pressure on MEPs to "toe the line" and accept the "deal" already agreed by the 15 EU governments.

All the evidence shows that people cannot rely on governments to protect their right to privacy, nor on the European Commission, for the future of democracy in Europe. Let us hope they can rely on the European Parliament"
There is a sharp and witty (but not for the easily-offended) analogous scenario to the SCO case drawn up by Simon Travaglia over at the Register, BOFH: Protecting bodily waste in the public domain. It captures some of the current excesses in the application of intellectual property law beautifully.

Wednesday, March 10, 2004

Victory for EFF Creates Problems for EFF's Filesharing Solution. Ernest Miller spot on as ever.

"Pennsylvania Federal judge has ordered the RIAA lawsuit charging 203 Comcast subscribers with copyright infringement be broken up into 203 separate lawsuits...

This is certainly a victory for the rights of those accused of copyright infringement, providing a high degree of protection to those who may have been falsely accused. It also greatly complicates the ability of copyright owners to prosecute wide spread infringement and places a greater burden on our court system. A reasonable tradeoff, but it also has other effects as well. For example, it also makes it almost impossible to enforce EFF's voluntary collective music licensing scheme on an individual basis...

In short, why would the majority of filesharers pay $5/month when they can get everything free from the minority of people who do pay? This latest victory, however, makes EFF's position virtually impossible to enforce on an individual basis..."
According to the NYT, the Bush administration have "set forth a new, more limited view of privacy rights as it tries to force hospitals and clinics to turn over records of hundreds and perhaps thousands of abortions."


Some possible good news on the IP front, though possibly not for Microsoft hating purists, is that the US Patent and Trademark office, having reviewed the patent they granted Eolas Technologies on browser technology, have apparently decided to invalidate the patent. This is the patent at the centre of the case where Eolas were awarded $520 million against Microsoft for patent infringement last summer. Judge James Zagel had recently, in February 2004, upheld the jury's original verdict.

This one is likely to run and run.
Robin Gross and Ross Anderson, organisations like FIPR and FFII, and many likeminded individuals will be greatly lamenting the European Parliament passing the intellectual property enforcement directive yesterday, Tuesday, 9 March, 2004. Looks like the CODE alliance, "an international coalition of civil liberties groups and consumer rights initiatives to protect consumer rights, innovation, and competition against the proposed European Union Directive on the Enforcement of Intellectual Property", has failed.

I understand that Pat Cox, the Irish head of the parliament, has said that the issue of the appearance of a potential conflict of interest involving the driving rapporteur, Jannelly Fourtou, whose husband, Jean-Rene Fourtou, is CEO of Vivendi Universal, would be raised in the Parliament Bureau. The question was raised during the voting session by MEP Neil MacCormick of the Scotish National Party.

The Competitiveness Council will rubber stamp the directive tomorrow and then 25 EU member states will be obliged to implement it into their national laws. CODE are unlikely to give up their campaign but it will have to be fought in relation to specific implementations in 25 jurisdictions now, rather than getting important checks and balances written into the directive itself. The specifics could mean the difference between having private security firms raiding homes in the middle of the night on the basis of very little evidence or requiring such raids only to be undertaken by official law enforcement authorities in response evidence 'beyond reasonable doubt' that someone is engaging in major intellectual property infringement. Even then I don't see why the directive could not have restricted this to commercial scale operations.

Parents of tech-savvy music loving teenagers would be particularly well advised to keep an eye on this. But it will be completely meaningless to most, even if it did get within touching distance of their awareness.

The gory detail of the directive is available at IP Justice.

Monday, March 08, 2004

Unlike many libertarians, Harvey Silvergate and Carl Takei don't see the PATRIOT act as the biggest threat to civil liberties in the US. They are more worried about what they believe to be the undermining of the little known legal writ of 'habeus corpus' (essentially a legal challenge to the detention of someone in either official custody or private hands).

"THIS IS NOT the first time the executive branch has tried to limit habeas corpus. In 1996, President Clinton signed into law the Anti-Terrorism and Effective Death Penalty Act. This law created a series of procedural hurdles making it more difficult for civilians charged with criminal offenses to use habeas to challenge the validity of an original trial on appeal...

The current curtailment of the writ is even more dangerous than President Lincoln?s wartime suspension of habeas. Lincoln, though he initially acted on his own, sought congressional authorization as soon as practicable, calling a special session to consider his wartime measures...

For civil libertarians, of course, the most egregious example of past habeas corpus violations remains the notorious internment of Japanese-Americans during World War II. The facts are well-known: the US government forced some 110,000 Americans of Japanese ancestry, two-thirds of whom were US citizens, out of their homes and into military internment camps for the duration of the war, allegedly because suspected saboteurs were hiding in Japanese-American communities. In a 1944 decision widely criticized as a nadir for American civil liberties and judicial review, the Supreme Court in Korematsu v. United States gave the internment program the imprimatur of constitutionality. In this extraordinary move, the judiciary deferred to a military measure that treated citizens like prisoners of war...

Yet in three important respects the Japanese internment cases did less damage to basic principles of democracy than today?s assault on habeas corpus threatens to do. First, in the WWII cases, the government felt compelled to concoct an elaborate lie to convince the court of its noble intentions, which suggests that it took seriously the need to persuade the court that detention was necessary. Today the government is not showing even that backhanded measure of deference to a co-equal branch of government, choosing instead to submit nothing more than two-to-three-page statements written by officials without firsthand knowledge and expecting courts to acquiesce without questioning the evidence or hearing anything from the other side. Second, in the WWII cases, detained citizens had the opportunity to consult lawyers and attempt to rebut falsehoods presented by the government. Finally, although the Japanese internment orders affected a much larger number of people than the "terror" detentions have done thus far, the WWII internment was limited by the finite duration of the war. In contrast, the present ill-defined "war on terrorism" and the attendant detentions have no foreseeable end."

There's an interesting interview with Gerald Santucci, "Head of the 'Trust & Security' Unit for the EC Directorate-General Information" Society at the European Biometrics Forum.
My experience as an Election Judge in Baltimore County by Avi Rubin

Wonderful.

Monday, March 01, 2004

Mark Fiore on electronic voting. Wonderful.
There's another interesting piece from Mr Schwartz at the NTY, this time on a report suggesting the entertainment industry's approach to fighting piracy is bad for business and the economy.

Larry Lessig has welcomed the report. Jane Ginsburg, renowned copyright expert at Columbia University, has welcomed some of the recommendations though criticises it as making misleading statements about copyright law.
The Bunner DVD DeCSS case has been decided by the California Appeal court having been referred back from the California Supreme Court last year. The Appeal Court overturned the injunction banning the posting of the code on the web, finding a first amendment violation; also that there was no evidence that CSS was a trade secret when Bunner posted the descrambler.
Tomorrow sees the biggest test of electronic voting machines when millions of voters will use them in ten states in the US. John Schwartz at the NYT gives a nice summary of the current situation.

Even voting on that scale fades a little compared to the proposed all electronic October election in India. Over half a billion people voting on more than a million machines supplied by just two companies. Scary.
The EU IPR enforcement directive is to get the fast track approval procedure according to the excellent EDRI-gram Newsletter - Number 2.4, 27 February 2004. Details on the problems with the directive can be found at the CODE campaign at IP Justice. Andreas Dietl, EDRI EU affairs director, says:

"The European Union's disputed Directive on the Enforcement of
Intellectual Property Rights is scheduled for a fast-track procedure that
may lead to it being adopted by the European Council in little more than
two weeks. At present, it is still under discussion in the Brussels
Parliament. The Rapporteur, French Conservative Janelly Fourtou, and the
Council both wish to pass this Directive in First Reading, before the
enlargement of the European Union. Trying to avoid delay by too much
discussion, they have each chosen the fastest procedure possible in their
respective institutions.

The final discussion about the report in the Parliament's Legal Affairs
Committee took place on Monday 23 February. The item was scheduled at the
very last minute, the Friday before, when most of the Members of
Parliament were already gone. With many MEPs still on their way to
Brussels on Monday, only 14 MEPs were present. The discussion only lasted
15 minutes after the Council and the Commission had ended their formal
introductions.

The longest speeches were given by Arlene McCarthy MEP (Social Democrat,
UK) and Malcolm Harbour MEP (Conservative, UK), who both claimed that this
Directive was not mainly about the Digital world, but about counterfeiting
of tangible goods. There is no proof for that in the text, however.

Technically, the debate was about the amendments that the Rapporteur had
laid down, together with McCarthy and with Toine Manders (Liberal,
Netherlands) and which reflect verbatim the Common Position of the
Council. This position had been fine-tuned, behind closed doors, in five
so-called trilogue meetings between the Parliament and the Council during
the previous weeks. The Legal Affairs Committee did not vote on the
amendments of Mrs. Fourtou: she chose to table them directly to the
Plenary.

MEPs may now lay down additional amendments until 4 March. The vote will
take place on 9 March in Strasbourg, preceded by a plenary debate the day
before. Already on 10 March, the outcome of the vote will be considered by
the Council's Committee of Permanent Representatives (COREPER). On 11
March, on the occasion of the meeting of the EU Competitiveness Council,
ministers may sign it off if it has been agreed by the Permanent
Representatives.

Though some of the concerns of civil society and internet providers have
been taken into account in the drafting of the Common Position, the text
remains problematic. The scope of the directive is extended to cover "any
infringement of intellectual property rights as provided for by Community
law and/or by the national law of the Member State concerned." At the same
time, the Commission's initial limitation to infringements which are
"committed for commercial purposes or cause significant harm to the right
holder" has been deleted.

The term "intellectual property rights" is not defined, creating the
possibility of a large range of abuses. Because the enforcement is not
limited to large-scale infringements, kids downloading songs from the
internet risk the same kind of treatment as large-scale counterfeiters of
trademark designer clothes.

EDRI-member organisation FIPR has prepared a set of amendments to deal
with the worst deficits in this Directive and is preparing, together with
a range of other organisations, a rally in Strasbourg to promote these
amendments and to encourage MEPs to vote against the Directive if some
minimum requirements are not fulfilled.

The European Commission's initial proposal for a Directive
http://europa.eu.int/smartapi/cgi/sga_doc?smartapi!celexplus!prod!CELEXnumdoc&numdoc=32001L0029&lg=EN

Amendments proposed by FIPR and EDR
http://www.ffii.org.uk/ip_enforce/andreas2.html

Campaign Info
http://www.ipjustice.org/CODE/ "

EDRI-gram also reports on the EU plan to introduce biometric passports I mentioned here recently.





I've done a fair bit of grumbling about the current state of the deployment of electronic voting machines but put it down to the cock-up rather than the conspiracy theory of life, since there has been no hard evidence of any electoral fraud (and lots of evidence of incompetence and cover up of that incompetence). Dr. Bob Fitrakis, senior editor of the Free Press, thinks there is a vast right wing conspiracy going on here.

It's all circumstantial neptoism and invisible-hand stuff with allegations, though no direct proof, of possible electoral manipulation but nevertheless an interesting read. If all the connections referred to are cosher then they could, at least, raise the appearance of impropriety. I really don't believe the Diebold folk and other electronic voting machine suppliers to date are avoiding the voter verifiable paper trail for any deep conspiratorial reasons, though. (I hope they are not anyway, in a world were powerful vested interests of all political persuasions are always angling for that extra edge). It's just that if you happen to have good market penetration with a less-than-perfect product, the short term marketing response to that knowledge leaking out is to try and cover it up.

Friday, February 27, 2004

Ernest Miller likes most of the EFF solution to the P2P file sharing problem.

"A Significant Problem: Using Any Software Won't Cut It

Why? Free riders. If people are permitted to freely share files on existing P2P systems, there goes any chance you have of limiting free riding.

Under EFF's proposed system, say I go ahead and get a license. For $5/month I can fileshare with impunity, that is, I can upload songs all day long. The free riders in this system will be the people downloading the songs from me. How do you enforce against downloaders? You can't, at least without draconian technical and legal enforcement mechanisms which I am sure the EFF would rightfully oppose.

What will happen under EFF's system is that a significant number of people will sign up for the system, say 10-20% of the filesharing population (if you are lucky). At this point, you stop getting subscriptions, because the free riders can get all the music they want for free, without fear of legal sanction. Sure, you might have some foolish people who both download and upload, but not many and all you'll do is turn them into legitimate uploaders for a small fee/fine. Suddenly, your $3 Billion/year is only $600 Million or $300 Million. Additionally many fee-paying subscribers will feel like suckers for paying"

He has a solution though - compulsory licenses.

"Compulsory licenses avoid this problem by forcing everyone to pay, regardless. This comes at the expense of heavily involving government, which should be a last ditch solution."
The UK government have published a discussion paper in response to the Newton Report which recommended that the Part 4 powers in the 2001 Anti-Terrorism Crime and Security Act, which allow indefinite detention of foreign terrorist suspects, should be replaced with new legislation. Lord Newton recommended new powers to apply to British as well as foreign nationals, to avoid having to opt out of a part of the European Convention on Human Rights. I doubt most people will be interested in purusing the full 123 pages but it would really be worthwhile for you to read the main principles and conclusions on pages 8 and 9 of the Newton report. The principles state that the report recognises that the individual has the right to liberty and privacy and that the authorities have a duty to take the necessary steps to protect society from terrorism. It explicitly recognises the need for special counter terrorism legislation but says it should be kept distinct from mainstream criminal law and limited to dealing with terrorism. And it implicitly criticises the David Blunkett approach of introducing emergency legislation supposedly to deal with terrorism but having the provisions so broadly drafted that they apply to petty crime. "The enactment of mainstream legislation using emergency procedures undermines the consensus for the use of such procedures in justifiable cases." Our Home Secretary won't have liked that. At the other end of the scale pure libertarians won't be overly enamoured with "the blanket ban on the use of intercepted communications as evidence in court should be lifted to make it possible to prosecute more terrorists (and other serious criminals) and the government should examine the scope for more intensive use of surveillance to prevent and disrupt terrorism."

All very topical this week in the light of the dropping of the prosecution of Katharine Gun and Claire Short's attempts to take revenge on Tony Blair with allegations of illicit spying on the UN.
According to the Independent, the general angst about electronic voting is spreading in Ireland.

Taoiseach Bertie Ahern is dismissive of concerns and determined that an auditable paper trail will not be built into the system.

"We are not going to go back to pushing pieces of paper around the place," he said, accusing a critic of wanting "to keep old ways, old things, the old nonsensical past".

I guess he means that "old nonsensical past" where the election system was transparent, had impeccable integrity, it was simple to vote (mark the ballot paper and stick it in the box) and had a clear audit trail so that any anomalies could be reviewed openly. But it was, of course, terrible that it might take a few days to get the final results.

The new system will provide instant results (yahoo! - I use the word in its original sense prior to the Internet age) and a windfall for voting machine manufacturers all for 40m Euros(£26m). But no transparency, no simplicity, no audit trail, no confidence, no integrity...

Governments get five years if they win the election. Is democracy not worth a few days to make sure the results of the election are accurate? In the words of Milton Friedman in the Eldred amicus brief, this one is a complete "no brainer" for me. This ubiquitous Boys-Own blind faith of computing ignoramuses, like certain decision makers, in the ability of computers to automatically and magically make things better, regardless of the overall objective or the suitability of the tools (computers) to the task or [critically] the way in which those tools are deployed, drives me nuts on a daily basis in my own day job. That it is happening in so important a context of the integrity of our democracies is worrying in the extreme. Mr Ahern should not knock paper. It is still the best available technology for voting (imho).

Thursday, February 26, 2004

Greplaw have done an interview with Jessica Litman. Lovely quote about Jessica thinking of herself as an older sister to Harry and I hadn't previously come across her Breakfast with Batman paper.
The Association of Chief Police Officers in the UK have accused the Information Commissioner of putting children at risk for ordering the "destruction of valuable criminal intelligence."

"In one case, in July 2003, the commissioner demanded that South Yorkshire police delete from a woman's record a juvenile conviction for actual bodily harm dating from 1979...

In September 2003 a similar request was made of West Yorkshire police over a man who wanted juvenile convictions that carried a three-month custodial sentence to be "weeded out" of his record.

In a case with echoes of Huntley, the commissioner asked an unnamed police force to delete intelligence relating to allegations that a man sexually assaulted young males in 1991 and 1998."

The notion that a juvenille conviction from 1979 (25 years ago) should be held against someone is a bit excessive. What about the juvenille conviction leading to a custodial sentence or someone with serious allegations stemming from 1998? It's difficult to say without more specifics of the individual cases. What's certain is that the police have a very difficult job but they do need to recognise that the Information Commissioner does too. Very often an organisation's interpretation of the Data Protection Act bears little relationship to the actual requirements of the act. There is a judgement call to be made on the merits of individual cases and the perception on where the dividing line should fall will vary depending on the values and objectives of the institution or the indivual. ACPO and the Information Commissioner, if the story is to be believed, have different perspectives on the boundaries.
There's a nice quote from Jonathan Zittrain in a New York Times article on the "Grey Album" (a re-mix of some Beatles tracks with some recent rap music) dispute:

"As a matter of pure legal doctrine, the Grey Tuesday protest is breaking the law, end of story. But copyright law was written with a particular form of industry in mind. The flourishing of information technology gives amateurs and home-recording artists powerful tools to build and share interesting, transformative, and socially valuable art drawn from pieces of popular culture. There's no place to plug such an important cultural sea change into the current legal regime."

Statewatch Editor Tony Bunyan is none too pleased at the EU plans to introduce biometric passports.

"For EU citizens getting a passport is quite straightforward, you fill in the form, get your picture taken in a photo booth and simply post both to the passport office. This simple process is about to change: to get a passport you will have to present yourself to an "enrolment centre" where a special picture will be taken of you and then you will have to have your fingerprints taken. These will then be held on a European database with personal data."

The political decision to introduce compulsory biometric identifiers, first on visas and residence permits and then on passports, was taken at two Informal meetings of Justice and Home Affairs Ministers (in February 2002 and then in March 2003). The Commission argued for a so-called "coherent approach" for "all travel documents, including the passports of EU citizens". These decisions were not reported at the time. It was the European Councils (the meeting of EU prime ministers) at Thessaloniki in June 2003 and later in Brussels on 12 December 2003 who formally endorsed the proposal. A secondary reason for bringing in biometrics on EU passports, the Commission argues, is that the USA is demanding them on passports too.

The legal basis for the proposal is highly dubious, see: Commission’s EU biometric passport proposal exceeds the EC’s powers, Statewatch legal analysis concludes that: "no powers conferred upon the EC by the EC Treaty, taken separately or together, confer upon the EC the power to adopt the proposed Regulation"

The ignorance in the making of these decisions about biometric identity as a surrogate for security continues to be staggering and it would be laughable if it wasn't so serious. I could mutter 'security is a trade off ' and 'biometrics may be unique (mostly) but they're not secret' and 'identity is no gaurantee of security' and 'statistically the bigger the biometric database the bigger the error rate' and 'false positives' and 'false negatives' and 'information overload' and 'well resourced clever human intelligence' and ''security is only as strong as the weakest link', but there's not much chance of getting heard by the 'war on terrorism' gang. And the sad thing is that I don't even know that much about security but even I can see the sense of people who really do know about it like Bruce Schneier. What kind of a world our our children going to grow up into?

Tuesday, February 24, 2004

321 Studios have lost their DMCA battle against the movie industry.

"Judge Susan Illston ruled Friday in San Francisco that software made by
Chesterfield, Mo.-based 321 Studios violates the 1998 Digital Millennium
Copyright Act, which prohibits the circumvention of anti-piracy measures such
as the Content Scramble System protecting movies on DVDs.

The judge ordered the company to cease making or distributing such software
within seven days of her order."

The company has said they will appeal.

Monday, February 23, 2004

Michael Froomkin recalled some advice from his grandmother recently in reflecting on the Bush administration's response to the atrocities of 9/11 and Siva Vaidhyanathan's confession of self-censorship when going through airport security at Newark.

Friday, February 13, 2004

I learn from The Filter that there's a nice summary of the controversy surrounding the Diebold electronic voting machines and leaked internal memos at the Berkman Center. Section "5.0 The Implications" seems to be repeated twice. Possibly for emphasis? Probably in error. I'm sure the Berkmanites will correct it pretty quickly.
I was telling some friends over lunch on Wednesday that I had just heard a BBC radio report on the problems with trying to play copy protected CDs in certain Vokswagen CD players. It seems that Andrew Orlowski at the Register heard the same report and has written about it: Copy-crippled CDs launch in UK, baffling Auntie Beeb.

Orlowski reports the conversation very accurately. What I can't get is how a hardened consumer-advocate journalist lets by openings like those provided by the BPI spokesman. He tells her the CD standards have been around for a long time and then says the CD manufacturers have recently "enhanced CDs" with new features (i.e. copy protection). And the effect of these new features is that the CD produces silence when played i.e. doesn't work. It's a bit like Raleigh saying 'we decided to take the wheels off our bikes to reduce bicycle thefts and improve our service to customers; and don't blame us that the bikes are no good for cycling, the government should have adapted the road transport infrastructure to take account of our changes.'

As to the notion that "The CD em player that he's got in his car is not actually, eh supposed initially to play audio CDs." Oh you mean that road was not meant for cycling my wheel-free-enhanced bike on? Even the BPI spokesman thinks "Now that might sound a bit strange" and the journalist still doesn't pounce.

You just could not make this stuff up.

All I can suggest to irritated, music loving, Volkswagen owners is to try to ensure not to have too many passengers when trying to play copy protected CDs. You might find yourself getting sued by the John Cage estate for infringing (public performance) their copyright in silence. Incidentally the real settlement figure was not the six figure sum the BBC report here but it was substantial and somewhere between four and six figures.

Thursday, February 12, 2004

The EFF have posted a recording of the oral arguments in the MGM v Grokster appeal hearing. MGM's lawyer took a bit of a battering from the judges. I don't know whether that gives any indicator as to the ultimate decision in the case but isn't it fantastic to able to get direct access to this kind of material.
The NYT have a profile of Bram Cohen who created BitTorrent, the file sharing software that speeds up the downloading process for large files (such as digital films) and has the movie industry so worried.

"Under older file-sharing systems like Napster and Kazaa, only a small subset of
users actually share files with the world. Most users simply download, or leech, in cyberspace parlance.

BitTorrent, however, uses what could be called a Golden Rule principle: the faster you upload, the faster you are allowed to download. BitTorrent cuts up files into many little pieces, and as soon as a user has a piece, they immediately start uploading that piece to other users. So almost all of the people who are sharing a given file are simultaneously uploading and downloading pieces of the same file (unless their downloading is complete).

The practical implication is that the BitTorrent system makes it easy to distribute very large files to large numbers of people while placing minimal bandwidth requirements on the original "seeder." That is because everyone who wants the file is sharing with one another, rather than downloading from a central source. A separate file-sharing network known as eDonkey uses a similar system."

Copyfighters are grappling with the implications of the Appeals Court decision earlier in the week on DMCA [alleged] copyright infringement notice and takedown procedures for ISPs. The case was Ellison v. Robertson et al.

Wednesday, February 11, 2004

Some light relief from the Onion on the Patriot Act.

Tuesday, February 10, 2004

Roger Clarke is getting exorcised about the Australian government's misrepresentation of the value of face recognition technologies.

"It's very likely that a project called SmartGate, conducted by the Australian Customs Service, will be trumpeted throughout the world as the good news that face-recognition technology has been waiting for.

This email contains an assessment of the extreme manipulation of data, truth and the media on which such 'good news' stories will be based...

The brazenness of Custom's manipulation of media and public opinion exceeds the standards normally expected of the Government.

(1) No data has been provided, despite assurances given in the past that data would be provided.

(2) The invited experts who were paraded by Customs are arguably about the world's two foremost designers of testing for biometric technologies.

But is appears that:

they did not *perform* the tests
they did not *design* the tests...

... The best quotation that Customs seem to have been able to extract from the two experts was that "the scheme's performance is remarkably good for an operational facial recognition system".

That seems quite positive, until you realise that the other attempts around the world have been abject failures, and pilot after pilot has been quietly abandoned.

In other words, the quotation can be readily interpreted as "it doesn't work very well, but it's better than the other disasters we've seen".

This is borne out by an answer by one of the experts to a reporter's question. He said: "In one test 100 company employees attempted to impersonate someone other than themselves and eight of them were falsely accepted by the system. That is a very
low rate of false accepts". At that"very low" level of false acceptances, every 747-load of people can include 25-30 terrorists..."

Roger is clearly not too happy and you can't blame him. Deployment of lousy expensive technology to create the illusion of improved security does nobody any favours. And whilst the over-stretched authorities are distracted dealing with processing those 25-30 innocents per planeload, the real terrorists have a clear run at their targets.

Roger has an informative general introduction to biometrics on the web.
The latest in the unintended consequences of intellectual property legislation is covered by The Register: "Seven years jail, $150,000 fine if you don't tell the world your email and home address" This is further example, though thankfully one not yet on the statute books, of the industrial regulation leading to a daft situation when applied at a personal level and in an unexpected/unexplored context.

The article winds off with an amusing exchange between a Harley-Davidson trademark manager and an IP lawyer included in Milton Mueller's wonderful book Ruling the Root. Mueller went on to say: "Under ICANN's contractual regime, the consumers and suppliers of domain name registration services are required to facilitate their own surveillance by intellectual property owners. If we apply the same logic to any other industry, it seems absurdly overreaching. Motorcycles can be used to break the law, but we do not require all vehicle manufacturers to create a publicly accessible, global database with complete and accurate information about all their customers... The linkage of resource administration to policy and regulation in the domain name regime has given intellectual property interests much more extensive rights of surveillance than they had before."

That's a pretty good rule of thumb when it comes to regulation of new communications or Internet techologies - apply the same logic in a different context and give it the absurdity test. James Boyle calls it the telephone rule. When ever he gets some hyped up journalist contacting him for 'the internet angle' on the latest sensational crime story, he asks them to substitute the word "telephone" for the word "internet" and see if they a can blame the telephone for whatever terrible crime has been perpetrated.
Frank Zappa as far back as 1983 was suggesting a different business model for the music inductry. He called it "A PROPOSAL FOR A SYSTEM TO REPLACE ORDINARY RECORD MERCHANDISING"

"We propose to acquire the rights to digitally duplicate and store THE BEST of
every record company's difficult-to-move Quality Catalog Items [Q.C.I.], store
them in a central processing location, and have them accessible by phone or
cable TV, directly patchable into the user's home taping appliances, with the
option of direct digital-to-digital transfer to F-1 (SONY consumer level digital tape
encoder), Beta Hi-Fi, or ordinary analog cassette (requiring the installation of a
rentable D-A converter in the phone itself . . . the main chip is about $12).

All accounting for royalty payments, billing to the customer, etc. would be
automatic, built into the initial software for the system.

The consumer has the option of subscribing to one or more Interest Categories,
charged at a monthly rate, without regard for the quantity of music he or she
decides to tape.

Providing material in such quantity at a reduced cost could actually diminish the
desire to duplicate and store it, since it would be available any time day or night. "

SO these ideas have been around for a while...

Friday, February 06, 2004

At the Mercury News: "California Secretary of State Kevin Shelley on Thursday announced measures to improve election security in the wake of a report describing how votes can be easily manipulated by hacking into an electronic voting system used across California."
Here's a novel way of alerting people to the privacy invading information trails we leave behind when using modern technology -

"Visitors to an art exhibit at the Pittsburgh Center for the Arts got more than their martinis when they ordered drinks at a bar inside the gallery's entrance. Instead of pretzels and peanuts, they were handed a receipt containing all the personal data found on their license. Some patrons also got receipts listing their phone number, income range, marital status, housing value and profession. For added effect, the receipt included a little map showing the location of their residence.

The magnetic strips and bar codes on the back of most state's driver's licenses contain more information than people think. The way the swipers use the information might surprise them as well: Some bars and restaurants scan driver's licenses to catch underage drinkers and fake IDs, but they're also using the information for marketing purposes.

Last year artists and producers Beatriz da Costa, Jamie Schulte and Brooke Singer built the Swipe exhibit in Pittsburgh to show what's on the cards we all carry. "
Erica Wass editor and contributing author "Addressing the World: National Identity and Internet Country Code Domains", (Rowman & Littlefield, October 2003) has a nice article on the .kid.us domain name space mandated last year by the US government.

"Ironically, it is the characteristics that make the .kids.us space remarkable that also create its uncertain future...

...the space is governed by two principal documents: a content policy and a governance policy. The content policy document defines the thirteen areas of content that are restricted from appearing in the space...Sites within .kids.us cannot link to sites outside of the .kids.us space; they also cannot incorporate interactive communications like chat rooms, instant messaging, discussion boards and e-mail...

...the majority of those who have registered sites have not yet made it through the content review processes. Despite having registered about 2,000 .kids.us domains, only seven have been activated...

The incentive to create a site within the .kids.us name space appears clear; it is a space directed toward children. It is a space created to enable children to be safe while surfing the Web. Many owners of sites directed toward children are now forced to reconcile this honorable goal with financial and theoretical concerns...

When Carol Myers, the owner of Stnicholas.kids.us, registered the domain, she already had developed a site at stnicholascenter.org and its .com variations. She says she wanted to be a part of the .kids.us space because she believes that parents should be careful about the media influences on their children. As a result, she paid $126 for each .kids.us name she registered, as well as the $250 per name content approval fee. She also bore the more hidden costs of hosting and design changes to fit the .kids.us regulations. "It is a big commitment, actually, to develop and maintain two sites," she says. The result, she says is that the kids.us site will be much more static than her main site. Myers worries that other non-profit sites, churches and other organizations that have a few excellent pages for children will not go through the hassle and expense of putting them on .kids.us...

Indeed, the restrictive linking and interactivity policies seem to turn a rich communications medium into just another example one-way communications. Why should children turn to the web, when they can access games on CD, video on TV, and text in various print media. While it is true that the ability to freely communicate can engender abuse, and, therefore, possible danger to children, it also enables a different type of learning and involvement. While such restrictive policies may provide protection for children, it also may insulate our children from the benefits of communicating online in a variety of ways with the rest of the world. "

Food for thought.
Today the EU is celebrating "Safer Internet Day."

"This event focuses on children's rights to a safer Internet as part of the European Commission's Safer Internet Programme. It showcases existing safer Internet projects, videos and awards developed with the backing of the programme. These programmes involve actors from the private, public and voluntary sectors. Safer Internet project members have contributed to several remarkable achievements. In October 2003 a worldwide child-porn ring was broken up following a tip from the Internet hotline association INHOPE. In November 2003 the new Internet Content Rating Association content filtering platform ICRAplus was launched. Events will be staged simultaneously in 12 European countries (Denmark, Germany, Greece, Iceland, Ireland, Italy, Luxembourg, Netherlands, Norway, Spain, Sweden, United Kingdom), as well as in Australia. These events involve public authorities, the Internet industry and hundreds of other organisations. "

According to the Washington Post, "The Pentagon has canceled plans to collect votes over the Internet from military personnel and civilians abroad for this fall's presidential election because of security concerns"

Apparently the system will still be used for a test but the votes will not be counted officially. The Pentagon have some very very smart people and it looks like they have won the argument on this. Good for them. As Avi Rubin said, "It's all the credit to them for inviting us onto the security panel when they anticipated we would say negative things about it, and then taking our advice that seriously. It's really incredible."

Wednesday, February 04, 2004

CNET have published a recent essay by Bruce Schneier, which they've called "Slouching towards big brother." More sensible thoughts.

"Security is a trade-off. It makes no sense to ask whether a particular security system is effective or not--otherwise you'd all be wearing bulletproof vests and staying immured in your home."

Tom Paine's tuppence worth of common sense on the problem of rewarding creators and producers at the centre of the knowledge economy?

"My prediction is that the balance will be found in new technologies that will be able to extract a small fee from each of a very large number of consumers all over the world who want to hear or see or otherwise make use of some creation. When added up, these fees will give innovators enough to compensate them for their efforts, while at the same time giving consumers access to all sorts of new creative products very cheaply. And all this without lawyers. "

I wish I could believe he was right about the lawyers.
Update: Out-Law are reporting on the Privacy International report mentioned earlier.

"EU accused of failing to protect air passengers' privacy"

It's a nice summary of how we got to the current situation between the US and the EU with the airlines caught in between.
Privacy International in cooperation with the Foundation for Information Policy Research, Statewatch and the European Digital Rights Initiative have just published a report on the air travel privacy issue. The report is called:"Transferring Privacy: The Transfer of Passenger Records and the Abdication of Privacy Protection" and is to be the first report in a series Privacy International call "Towards an International Infrastructure for Surveillance of Movement."

They accuse the European Commission of intending undermine the privacy rights of air travellers, systematic deception and subterfuge in relation to the promise to take a hardline on negotiations with the US over transfer of passenger data and covertly planning an EU surveillance system which "will be used not only for purposes of anti-terrorism, but also for immigration, law enforcement and customs" and a global air travel sureveillance system similar to the one being built by the US.

Privacy International are also calling for an investigation into these affairs by the European Parliament and for legal action against the Commission "to ensure that
this dangerous subterfuge does not occur in the future."

Pretty strong stuff.

Bruce Schneier is crystal clear as ever on "IDs and the illusion of security" over at sfgate.com.

"Everywhere, it seems, someone is checking IDs. The ostensible reason is that ID checks make us all safer, but that's just not so. In most cases, identification has very little to do with security...

...verifying that someone has a photo ID is a completely useless security measure. All the Sept. 11 terrorists had photo IDs. Some of the IDs were real. Some were fake...

...Harder-to-forge IDs only help marginally, because the problem is not making sure the ID is valid. This is the second myth of ID checks: that identification combined with profiling can be an indicator of intention.

Our goal is to somehow identify the few bad guys scattered in the sea of good guys. In an ideal world, what we would want is some kind of ID that denotes intention. We'd want all terrorists to carry a card that says "evildoer" and everyone else to carry a card that said "honest person who won't try to hijack or blow up anything." Then, security would be easy. We would just look at people's IDs and, if they were evildoers, we wouldn't let them on the airplane or into the building.

This is, of course, ridiculous, so we rely on identity as a substitute. In theory, if we know who you are, and if we have enough information about you, we can somehow predict whether you're likely to be an evildoer...

"Profiling has two very dangerous failure modes. The first one is obvious. Profiling's intent is to divide people into two categories: people who may be evildoers and need to be screened more carefully, and people who are less likely to be evildoers and can be screened less carefully.

But any such system will create a third, and very dangerous, category: evildoers who don't fit the profile...
...Profiling can result in less security by giving certain people an easy way to skirt security.

There's another, even more dangerous, failure mode for these systems: honest people who fit the evildoer profile. Because evildoers are so rare, almost everyone who fits the profile will turn out to be a false alarm...

...Security is a trade-off; we have to weigh the security we get against the price we pay for it. Better trade-offs are to spend money on intelligence and analysis, investigation and making ourselves less of a pariah on the world stage...

...Identification and profiling don't provide very good security, and they do so at an enormous cost. Dropping ID checks completely, and engaging in random screening where appropriate, is a far better security trade-off. "

Can't fault Schneier's analysis on security. And the UK government could learn from this - the latest inquiry will presumably ultimately blame the intelligence community for the war in Iraq. Then there will be a 'review' and re-organisation of the intelligence services and more laws mandating blanket collection of personal data, which already overstretched law enforcement and intelligence services will somehow extract relevant information from. They'd be better off listening to Schneier - Better trade-offs are to spend money on intelligence, analysis and investigation.
Technology companies including Intel, Nokia, Panasonic, Matsushita, and Samsung are due to launch a new wireless DRM specification via the trade group the Open Mobile Alliance (OMA). They are also creating a non-profit licensing agency, the Content Management License Administrator, (CMLA), to promote the scheme. Toshiba has backed out and though Microsoft is a member of the OLA, they are not part of the new licensing scheme.
There was some interesting discussion on blogs at a recent meeting of the All-Party Parliamentary Group for
e-Democracy. Especially clear contributions from Tom Watson and Tony Benn.

Watson, MP for West Bromwich East, said he's exploring the use of blogs:

to encourage participation and agenda setting;
as a tool for civic action;
as tools to promote accountability and transparency;
and as a political weapon.

He's found out about RFID tags through his blog and managed to galvanise his local Lidl supermarket to clean up the litter problems it was causing.

Tony Benn said ‘Anyone serious in politics has to take communication seriously’ and blogs gave the opportunity to deal with lies directly and quickly, ‘truth can get its boots on a lot faster!’

Monday, February 02, 2004

Diebold Systems are in the e-voting wars again. This time the systems in Maryland come in for some criticism from security experts commissioned to assess them.

The SCO website has been taken down by the MyDoom virus, according to the NYT.

The Lambert Report on University-Business collaboration on research and technology transfer was published just before Christmas. I didn't read it in detail at the time because it was accompanied by the usual PR and platitudes about how it would be a good idea if there was greater cooperation and how it was inherently a good idea etc.

It does have some interesting things to say about intellectual property in the context of university-business research collaboration, however. Things that were not included in the general pr accompanying the report when it was published.
http://www.hm-treasury.gov.uk/media//EA556/lambert_review_final_450.pdf

Section 4 covers the IP issues.

Whilst recommending that UK universities be more active about filing and exploiting patents and commercialising their IP, it suggests that IP is never going be a major direct revenue generator for universities. It cites the cases of MIT, Yale and Stanford in the US as institutions which started out with expectations of high earnings from market exploitation of their IP but which have now changed their objective for engaging in technology transfer to improving the "public good."

Some quotes from the report:

"A warning: the impact of technology transfer on the direction of research - whether it be towards short term applied or long term research - needs to be monitored carefully."

Cited barriers to commercialising university IP:
"copyright law is a big barrier to research collaboration between universities and the private sector...."

There were "too many lawyers involved, and too much time wasted" in trying to sort out IP ownership issues between industry and universities.

The FT apparently have an article on it today but their site was down when I tried to access it.

Amnesty International have criticised Microsoft and Cisco for selling technology to the Chinese authorities which is used to facilitate civil rights abuses, according to the Observer.
'[Microsoft] should be more concerned about human rights abuses and should be using its influence to lift restrictions on freedom of expression and get people out of prison. It is worrying that they don't seem to have raised these issues.'

But then again the free market is amoral and does not require companies to police the uses to which their products are put. Smith & Wesson are not held responsible every time one of their guns is used to kill a police officer or an innocent bystander.

I've been avoiding commenting on the Hutton Report. Lots of other folk are doing so in a much more enlightening way than I ever could. My Open University colleague, John Naughton is one.

Thursday, January 29, 2004

David Trimble has accused human rights groups of

"being complicit in the murder of innocent victims...

One of the great curses of this world is the human rights industry"

Amnesty's repsonse:

"The threat of terrorism must never be used as an excuse for abus ing people's human rights. David Trimble should remember that human rights organisations have condemned killings and other abuses by terrorist groups all over the world, while at the same time criticising governments who use the 'war on terror' as a pretext to abuse their citizens."
Disney have been in court again, this time with Roger Rabbit creator, Gary Wolf, who doesn't think he's getting his fair share of the reciepts from the commercialisation of his creation. It parallels the long running Slesinger case over the Winnie the Pooh takings. Looks like the Appeal Court sided with Wolf.

Meanwhile Google are heading to court in a trademark dispute with American Blind and Wallpaper Factory over selling keyword ads.
Thomas Goetz at Wired is predicting that the US businesses grounded in intellectual property will go the way of the erstwhile US shipping industry, if they don't stop focussing on extreme protectionism as the way to deal with new technology.

In the case of the shipping companies, he says:

"The US fleet was a classic victim of the efforts to save it. Rather than adapt to new economics, the American
industry suffocated under overregulation and protectionism. Now the job gets done - goods move efficiently from place to place - but it's a rogue's business, rife with ne'er-do-wells and pirates."

Larry Lessig, in the same issue of Wired, takes politicians to task for exploiting the general public's ignorance of economics in relation to developing versus developed world price discrimination on drugs.

There is no easy way out of this one. The economists' dream world is one of perfect price discrimination where everybody pays what the market will bear. Drug companies use their patent monopolies to generate revenues for profits and recover their R&D costs. They can't sell at high prices and huge profit margins in the developing world because the market will not bear it - people just can't afford it. So they sell the drugs at a premium in the developed world. With today's so called global markets, though, people in one area can justifiably ask the question as to why they should pay more than those in another area of the world. Economists will answer - because you can afford to. And that is a completely unsatisfactory to most of of us. But but but, we ask, why should I pay a premium when someone else can get them cheaper. I can just fly to Africa, buy a large batch and take them home with me and still have it work out cheaper - what the economists call arbitrage.

So when the free market absolutionists cry leave it to the market, the question I guess is, which free market? The producer-loaded one with perfect price discrimination or the customer loaded one with perfectly informed global consumer discrimination? A similar question goes to the anti-capitalist perspective - how can drug companies supply the need for medicines fairly across the globe and still generate respectable (or even optimum) revenues.

Information economics and intellectual property's place in it is a complex business. I don't have an answer and though there are models which help work out optimising theories, we live in an imperfect world.
Cory Doctorow has been getting passionate about the false choices of DRM, in response to a blog entry from Scoble at Microsoft:

"Well, says Scoble, all of the music that we buy from these legit services is going to have DRM use-restriction technology ("See, when you buy music from a service like Apple's iTunes or Napster (or MSN), it comes with DRM attached."). So the issue becomes "choosing between two competing lockin schemes."

And in that choice, says Scoble, Microsoft wins, because it has more licensees of its proprietary, lock-in format. That means that when you want to play your music in your car, it's more likely that you'll find a car-stereo manufacturer that has paid Microsoft to play Microsoft music than that you'll find one that has coughed up to Apple to play Apple music...

In this world where we have consumer choices to make, Scoble argues that our best buy is to pick the lock-in company that will have the largest number of licensees.

That's just about the worst choice you can make.

If I'm going to protect my investment in digital music, my best choice is clearly to invest in buying music in a format that anyone can make a player for. I should buy films, not kinetoscopes. I should buy VHS, not Betamax. I should buy analog tape, not DAT.

Because Scoble's right. If you buy Apple Music or if you buy Microsoft Music, you're screwed if you want to do something with that music that Apple or Microsoft doesn't like.

Copyright law has never said that the guy who makes the records gets to tell you what kind of record player you can use. If Scoble and his employer want to offer a product with "features" that their customers want, those features should reflect what their customers want: No Windows user rolled out of bed this morning and said, "I wish there was a way that I could get Microsoft to deliver me tools that allow me to do less with the music I buy...

No, the "customer" for Microsoft DRM is the guy who makes the records: the music industry; and not the gal who buys the records: you. That customer has already told Microsoft how it feels about its products: in the Broadcast Flag negotiation, the movie companies locked Microsoft DRM out of consideration for use in next-generation PVRs in favor of DRM that Sony (also a movie company, surprise, surprise) had a patent for.

Microsoft is selling out its customers to people who aren't even buying. Scoble points out that Microsoft licensed the hell out of its OS to hardware vendors, pioneering a new kind of open-ness. He's right. Microsoft set a good example that Apple has been too stupid to follow, and it's time for the company to do it again. When Microsoft shipped its first search-engine (which makes a copy of every page it searches), it violated the letter of copyright law. When Microsoft made its first proxy server (which makes a copy of every page it caches), it broke copyright law. When Microsoft shipped its first CD-ripping technology, it broke copyright law.

It broke copyright law because copyright law was broken. Copyright law changes all the time to reflect the new tools that companies like Microsoft invent. If Microsoft wants to deliver a compelling service to its customers, let it make general-purpose tools that have the side-effect of breaking Sony and Apple's DRM, giving its customers more choice in the players they use. Microsoft has shown its willingness to go head-to-head with antitrust people to defend its bottom line: next to them, the copyright courts and lawmakers are pantywaists, Microsoft could eat those guys for lunch...

But forget Microsoft, because Scoble's not talking about the best thing for Microsoft, he's talking about the best thing for you. The best way to protect your investment in music. Without a doubt, the best way to protect that investment is to only buy music that isn't in a lock-in format, and to break the locks on any music you do own, while you can..."

Wednesday, January 28, 2004

James Grimmelmann is back at Lawmeme and sharp as ever.

I hadn't seen the DVD he mentions, so it's interesting to hear such a high profile director encouraging creative re-use of his work.
There's an interesting interview with Michael Weiss, the ceo of StreamCast (Morpheus) in the eCommerce Times. He's not a fan of the music industry:

"Somehow, the RIAA has taken music's freewheeling image of rebellion and rock 'n' roll and turned it on its head. In their quest to control distribution, pricing and technological innovation, the major record labels and the RIAA have embarked on a journey filled with false accusations and half-truths. In an attempt to portray P2P file sharing as the root of all that is evil with society, the RIAA has resorted to lying to the American public and deceiving Congress.

There are solutions that can be worked out to ensure that artists and copyright holders get paid for their works, such as compulsory licensing. However, the RIAA appears to be more interested in compulsive litigation."

On the uses of P2P:

"There are so many great uses for distributed P2P technology, ranging from searching to content distribution to communications. One of the best uses is the enabling of free expression, free from the censorship of oppressive governments and the de facto censorship of news, information and political speech by the consolidation of media and news companies in the control of the entertainment and media conglomerates."

Last week they interviewed Sharman Networks (Kazaa) CTO, Phil Morle. He doesn't rate Morpheus:

"Morpheus ceased to be our main competitor, or indeed a trusted solution for users, a long time ago. eDonkey/Overnet is a strong competitor. They have cool technology and millions of users. I am consistently impressed with their releases that show a passion for P2P and what it can accomplish.

I am also surprised that Shareaza stays under the radar. Mike, who develops it, is a very ambitious young man, and I have to wonder when he sleeps. Shareaza is a well-made application that is a pleasure to use."

He doesn't like the music industry either:

"I have the benefit of many years thinking about P2P and its potential, and they have not got past the stage of fear. I am naturally disappointed that we are all wasting time and money on futile legal battles when everyone
could be growing their businesses and benefiting users today."

He seems to find the issue of privacy a problem because it interferes with the performance of the technology,
people don't have anything to hide and if they did we shouldn't facilitate it:

"Where I differ from some other file-sharing CTOs is that I don't believe users have anything to hide. Creating default "darknets" through technology defines the purpose of the network as illegal and encourages a certain kind of activity. This is not what we are here for because P2P is an enabling technology for all and not somewhere to hide. The modules found in Kazaa Lite that claim to bring privacy to the user can cause problems with other Internet applications, decrease the performance of the software and are ultimately possible to work around"

Interesting similarities and contrasts.

Tuesday, January 27, 2004

AP are reporting that "A federal judge has declared unconstitutional a portion of the USA Patriot Act that bars giving expert advice or assistance to groups designated foreign terrorist organizations."

Monday, January 26, 2004

Napster creator Shawn Fanning is working on a new venture, Sno-Cap to help record companies make money from p2p file sharing.
"Snocap's plan, which involves identifying music files being traded through file-swapping networks and then attaching a price tag to them, is resonating well with music industry executives. "
I like this story: Taking the Stuffing Out of Microsoft. It really does take intellectual property lawyers to create a legal battle between a software giant and a feather company.
The latest chapter in a long running dispute over the merchandising rights to Winnie the Pooh, closed in a Federal Appeals court on 15th January. The court blocked A.A. Milne's grandaughter's attempts to reclaim the rights from the Slesinger family.

Disney are backing Claire Milne because they are in dispute with the Slesingers over non payment of royalties. The case will continue as the court refused to rule on the substance of Milne's claims until the rights of Ernest Shepard's heirs could be sorted out. Shepard was the illustrator of the original stories.

Another children's character, Peter Pan, is the focal point of a transatlantic copyright dispute between Canadian author Emily Somma and the Great Ormond Street Hospital lawyers. It's a long story but briefly Ms Somma wrote and published a book in the US and Canada about Peter Pan growing up. Lawyers for the hospital's trustees want her to stop distributing the book, because under a 1988 copyright law the UK Parliament has granted the hospital a perpetual "right to a royalty" for "the public performance, commercial publication, broadcasting or inclusion in a cable programme service" of "the play 'Peter Pan' ... or of any adaptation of that work."

Peter Pan originally appeared in J.M.Barrie's book, The Little White Bird, published in 1902, the copyright of which has now expired. So Emily Somma believes she should be able to produce a derivative work. It seems she also offered to pay the hospital trustees a proportion of the royalties from the sales of her book.
Given that under US or Canadian law she would not be required to do this, it seems a pretty fair gesture.

It looks as though the lawyers are locked into an all or nothing mode which will just end up costing everybody. One of those cases that you would hope would never go to court.

The Stanford Cyberlaw Clinic maintains a faq on the case. Elizabeth Rader is acting as Ms Somma's lawyer.