Wednesday, May 12, 2004

The Washington Post, last week, had a good article on the electronic voting shenanigans in the US. There was nothing new in it but lots of useful links to related stories.

There are lots of very experienced election registrars genuinely supporting electronic voting and suggesting there has been too much focus on the tecnology and not enough on the overall election process, which has other built in safeguards, not least of which are vast numbers of dedicated election officials of impeccable integrity. Whilst I understand that point of view and the need to 'get the job done', whilst critics complain about 'hypothetical scenarios that have never happened', there have been significant failures with these machines. Officials who have not experienced such failures believe that they will not happen on their watch. But the security of the system is only as good as the weakest link and at the moment the weakest link is the technology, as has been repeatedly demonstrated.

Folk like Avi Rubin and David Gill really do understand the technology. With people of that calibre saying it neither implements security that is possible nor even implement security safeguards that are easy, we should be taking serious notice. Deploying technology in such a mission critical way fundamentally requires an understanding of that technology.

Whilst I have every sympathy with election officials, I have none at all for those like the Information Technology Association of America (ITAA - the trade association representing amongst others, surprise suprise, the electronic voting machine vendors) spouting complete nonsense like "Electronic voting systems work, and work well. Our recent survey shows that over two thirds of Americans believe that electronic voting is a secure, reliable way to conduct elections." This reminds me of the line from one of my favorite BBC TV shows of all time, Yes Prime Minister where Sir Humphrey Appleby is persuading the Prime Minister that he should invest in Trident: "It's the biggest and the best and the British people must have the best." Also the following sequence where Sir Humphrey and Bernard are discussing opinion polls:

Bernard: "He thinks..he thinks it's a vote winner."

Sir Humphrey (Sir H).: "Ah, that's more serious. What makes him think that?"

Bernard: "Well the party have had an opinion poll done. It seems all the voters are in favour of bringing back national service."

Sir H.: "Well have another opinion poll done showing the voters are against bringing back national service."

Bernard: "They can't be for it and against it."

Sir H. : "Oh of course they can, Bernard. Have you ever been surveyed?"

Bernard : "Yes. Well not me actually, my house. Oh I see what you mean."

Sir H.: "Well Bernard you know what happens. Nice young lady comes up to you. Obviously you want to create a good
impression. You don't want to look a fool, do you?"

Bernard: "No."

Sir H.: "No. So she starts asking you some questions. Mr. Wooley, are you worried about the number of young people without
jobs?"

B: "Yes"

Sir H.: "Are you worried about the rise in crime among teenagers?"

Bernard: "Yes"

Sir H. "Do you think there is a lack of discipline in our comprehensive schools?"

Bernard: "Yes"

Sir H.: "Do you think young people welcome some authority and leadership in their lives?"

Bernard: "Yes."

Sir H.: "Do you think they respond to a challenge?"

Bernard: "Yes."

Sir H: "Would you be in favour of re-introducing national service?"

Bernard: "Y… oh ..well I suppose I might be."

Sir H.: "Yes or no?"

Bernard: "Yes"

Sir H. : "Of course you would, Bernard. After all you've told you can't say no to that. So they don't mention the first five
questions and they publish the last one."

Bernard: "Is that really what they do?"

Sir H.: Well no not the reputable ones no but there aren't many of those. So alternatively the young lady can get the opposite
result."

Bernard: "How?"

Sir H.: "Mr Wooley, are you worried about the danger of war?"

Bernard: "Yes"

Sir H. : "Are you worried about the growth of armaments?"

Bernard: "Yes."

Sir H. : "Do you think there is a danger in giving young people guns and teaching them how to kill?"

Bernard: "Yes."

Sir H. : "Do you think it is wrong to force people to take up arms against their will?"

Bernard: "Yes."

Sir H.: "Would you oppose the re-introduction of national service?"

Bernard : "Yes."

Sir H. : "There you are you see, Bernard, the perfect balanced sample. So we just commission our own survey for the ministry
of defence. See to it Bernard."

The Boston Globe has picked up the story of the arrest of Japanese professor, Isamu Kaneko, over file sharing software Winny.

Tuesday, May 11, 2004

John Lettice is on the ID card case again at the Register, this time pointing out that Department for Homeland Security and a biometric company, Identix, which is is also supplying equipment for the UK Passport Service's ID card pilot, are on the receiving end of a lawsuit in the US. Two men are suing for slander and product liability as the Identix system helped to give them other people's criminal records.

One of the men actually got jailed for being a convicted felon carrying a gun, despite the fact that the crime on his record had been perpetrated by someone else who even had a completely different name, Kellogg as opposed to Benson.

How could that happen? Especially when UK Home Secretary, David Blunkett, seems to believe these seems are "impossible" to fool. It seems Benson had been fingerprinted for a traffic violation. Kellogg convicted of multiple crimes. But the admin number on their respective electronic fingerprint cards was accidentally duplicated. And when the records were entered on the criminal justice database, Benson got credited with Kellogg's crimes.

As Lettice concludes:

"For the rest of us, the real issue is how fallibility in software and human input can produce
extremely serious errors in systems which are intended to provide virtually infallible
identification. There is here no dispute that Benson's and Kellogg's biometric records are
entirely different (Benson has only nine fingertips, for starters), but the processes operated
in such a way that Benson's record got the convictions. These spread from Oregon to
California, and Benson's attorney claims that he is still recorded by the FBI as having
been arrested as a felon in possession of a firearm.

Organisations deploying such systems should of course be extremely concerned that they
are not subject to such errors. Aside from the impact on the victims, the creation of false
records will damage the integrity of the database they're used in initially, and the sharing of
this data will result in the corruption spreading into other systems. The further it gets, the
harder it will be to undo the damage. But the more sure the designers are that they've
ruled out problems like this, the harder it will be to have errors corrected. If it's
impossible, then the people complaining have got to be mad, right? The issue of how you
deal with the data is actually far more important than getting the technology to produce a
"unique" biometric."
Jonathan Wallace is fretting about president Bush again:

"Harry Truman understood that authority and responsibility are one, that they must lie in the same place. He put a sign on his desk that said, "The buck stops here." ...

...George Bush does not understand. It is impossible to determine where, if anywhere, in this administration the buck actually stops. The President too often seems to be the child of his vice president, Dick Cheney. The fact that they will be appearing together before the 9/11 Commission is not confidence inspiring. It is almost certainly planned this way so that Cheney can interrupt the president if he starts to blither...

...John later asks the president what his biggest mistake has been since September 11. "In the last campaign....you used to like to joke that it was trading Sammy Sosa."

And the President, God help us, replies:


Hmmm. I wish you'd given me this written question ahead of time so I could plan for it....I'm sure something will pop into my head here in the midst of this press conference with all the pressure of trying to come up with an answer, but it hadn't yet.
Which is why they won't send him before the experts on the 9/11 Commission without Dick Cheney there to interrupt and talk over him whenever necessary.

While we are all sweating it out, waiting for something to pop into the president's head, ask yourself the very serious question: where does the buck stop in this administration?"


Out-Law reports on the UK government's proposals for a national ID card: ID Card Database emerges from the shadows

This piece nicely reminds us that in its original consultation exercise on what David Blunkett was then calling an "entitlement card" the government said “it is most unlikely that entitlement information relating to specific services would be held on the central register” which, of course, is the complete opposite of what it says in the draft bill on the subject published last week.

Chris Pounder of Masons (who also publish Out-Law) says:

“The Government’s proposals, if enacted in their current form,
could amount to the lawful, secret, unrecorded access by the
police and security services to centralised details which could,
over time, list all the important public and private services used
by each card-holder during his or her life-time”.

“This raises very serious and new privacy concerns about the
central registry database, as the two Commissioners charged with
protecting privacy in the ID Card scheme could be in the dark
about the volume and nature of the access requests to the central
registry database by the security service and police."

A society where we can map anyone in detail but not monitor everyone in detail. Hmmm, now where have I heard that one before?
Ian Brown at FIPR has pointed me at a piece by Toby Young in the Times where he considers the downside of recording the minutiae of life, which is now (naturally) facilitated by technology.

THE first law of technology is: anything personal
invariably becomes public. So it will be with the
SenseCam, a miniature camera that can record a
person’s entire day and store it in a computerised
diary. Developed by Microsoft’s British engineers,
the SenseCam will allow us to keep our entire lives
on disk. What a treasure trove of memories!
Alternatively, what a catalogue of indiscretions for
others to peruse! "

"It is only a matter of time, probably after some
horrible and shocking event, before Parliament
sets up a Department of Personal Records
requiring citizens to download their weekly
behaviour on to a national database. Strictly in the
interests of national security, of course."

"There is a second law of technology: it goes wrong"

He should have added that the third law of technology is that we use it unthinkingly and carelessly leading to adverse emergent properties...

I had a bad day in the office yesterday, when I was supposed to be on study leave, sorting out some difficulties with the new electronic computer marked assignment for my Internet law course. (Difficulties created by a completely avoidable accumulation of minor errors which the system then made difficult to correct and leading to the perception of a right-and-left-hands communications breakdown).

Monday, May 10, 2004

Academics Patent P2P Spoofing That shoudl provide some fun.
More academics as criminals news from Slashdot. An assistant professor of computer science at the University of Tokyo has been arrested for encouraging copyright infringement. He created P2P software 'Winny' based on Freenet, which unfortunately for him it seems, became rather popular.

I wonder how much this arrest might be related to some sensitive Japanese police information getting distributed round the Net via Winny? Or whether this may have been a minor contributory factor in the decision to make the arrest? I'm sure most of us would be annoyed if sensitive information from our systems got p2p'd in a widespread fashion.

This might be an interesting case to watch, especially since the Japanese have a more relaxed attitude to copyright infringement, at least when it comes to comics. That's, no doubt, an unfair generalisation, as comics are a pretty specific area but then, as an old college friend of mine used to delight in pointing out, generalisations are generally wrong.
The UK chancellor is apparently going to spend £150 million this summer with a view to expanding evoting.

“E-voting is a key measure to tackle so-called disengagement among young people,” said a Whitehall source. “Given the rapidly increasing use of text messages it is crucial that this is properly developed as a method of voting.”

Let's get the Big Brother and Pop Idol fans on their mobiles and that will solve the electoral participation crisis.

Give me strength. I'm seriuosly tempted to change the title of my book to Technology is The Answer to Everything (And The Eegits who believe this).
Frank Field's latest contribution to the DRM debate - DRM is a folding chair.

"Here’s the real point – the folding chair really draws its effectiveness from the cultural norms that have built up around
it. An experienced Cambridge driver knows not to mess with a parking space that has a folding chair in it, even though she/he
has never experienced the consequences that I describe above. Speaking personally, I can’t name a single person who has
actually had this problem, but every Cambridge resident collectively knows that it would happen — even though a folding chair
is, practically speaking, a completely ineffective limit on the use of a parking space."

Friday, May 07, 2004

Frank Field on cynicism.

"DRM is part of a process to break us of the nasty habit of thinking culture is a common good. Like a speed bump, it’s not about making us stop; it’s about making us recognize that someone thinks what we’re doing is wrong. And then usingour own naïvité to get us to stop. "

Makes me feel better that I'm not necessarily being "cynical", in the OED sense of the word, just attributing self serving motives to politicians and lobbyists.
There's a fascinating exhange of views going on between Ernest Miller, Ed Felten, and Frank Field on the subject of DRM, the broadcast flag and the copyfight in general.

Ernest believes bright people pushing for drm and other expansions of intellectual property rights have got a hidden agenda because they basically can't be stupid enough to really believe drm is going to prevent copyright infringement. So they must have a hidden agenda.

Ed says the some of folk pushing this agenda that he has discussed the issues with are passionate about what they are doing, really do believe it will work and needs to work in order to balance all the interests involved.

Frank partly supports Ed in suggesting we should never underestimate the power of ideology.

"The fact that "the road to hell is paved with good intentions" derives from the fact that, in order to function in an increasingly complex world, everyone is forced to construct simplifying models of the way that the world works. When these models (a)
work and (b) are buttressed with rationalizing arguments, we get something more potent - an ideology.

The problem with ideologies is that, even though they work, they rely upon simplifications that will not obtain over time. These simplifications will eventually be the downfall of the ideology, but sometimes it takes a very long time before the failure of the ideology is recognized, meaning that a lot of bad (and potentially quite destructive) decisions get made in the interim...

Ernest is right; our opponents are not (all) stupid people. But they don't have nefarious ends. Rather, they're acting within the confines of the ideologies that they believe explain the way the world works. They aren't evil or stupid; they're just confused and frustrated. The old methods aren't working, even though they *know* their methods are "right." In fact, they're in exactly the same boat that we are. And we know we aren't evil.

Ideologies are hard to defeat, because they're invisible to those who hold them. To us, it's an ideology; to them, it's "the way the world works." Beating it will take time, being honest about what is happening and working really hard to devise a new way of looking at the world that we can collectively agree upon.

We can't afford to write them off as "evil." That's seductive, but dangerous because it simply isn't true. They're just doing what they think is right. We have to respect that as we work to show them that they're mistaken. "

Siva Vaidhyanathan makes some related commentsat the Lessig blog in telling the story of meeting someone who takes the view of "the other side". Some who thought Larry Lessig was "a kook". Siva now reckons elements on the two sides are beginning to understand each other because those pusshing for expanded protection of intellectual property rights are resorting to ad hominem attacks. Adn they are doing this because the Lessig's of the world are winning the argument. Interesting theory but as Seth Finkelstein says in commenting on Siva's post,

"Unfortunately, yes, I think you hang around too many people who actually read the books they criticize. You're a professor. Academics are *supposed* to be polite. Not that they always are. But there is a strong cultural belief there, as evident in what you?re writing, that ad-hominem arguments are "wrong". Again, it may be honored more in the breech than in the observance, it may be an ideal not always practiced, but it's part of the formal codes of conduct.

Hang out with lawyers and lobbyists and politicians more. To them, lying and smearing and ad-hominem attacks are *tactics*, debate *options*. Whether they use those approaches depends entirely on whether they think they can get away with it, that it'll work with the audience. It's a pure strategic calculation. They may decide they'll look bad if they lie. They may decide it's worth it. Situations vary. But the truth or intellectual strength of the argument bears a very tenuous relationship to the approaches employed.

I certainly don't see any change at all, in terms of Jack "Boston Strangler" Valenti style rhetoric.

And remember, a mosquito is slammed hard, but that doesn't mean it's powerful and influential.

So you can't derive "panic" from any of it. It may be that you just happened to run into a few people who think meanness is the way to go.

If the courts had been rebuffing the copyright extensions and the DMCA, then there might be panic. Otherwise, it's simply tactics."

James Heald of Foundation for a Free Information Infrastructure (FFII) tells me that the Irish presidency of the EU are bypassing all the EU parliament and other objections to software patents and doing an end run round a vastly watered down software patents directive proposal.

"The powerful COREPER committee of EU member states' Permanent
Representatives in Brussels has provisionally agreed on a new draft for
the controversial Software Patent directive, overruling concerns from
the German, Belgian, and Danish delegations, and the Slovakian
non-voting observers. (The new accession countries only become full
voting members in November).

The new draft rejects all of the European Parliament's limiting
amendments, and is described by FFII as "the most uncompromisingly
pro-patent text yet".

The Coreper text also goes further than the original European Commission
text of 2002. In 2002 the Commission had agreed, in difficult
negotiations between DG Internal Market (Bolkestein) and DG Information
Society (Liikanen) not to allow program claims. Now it seems that DG
Information Society has rolled over to the united pressure of Bolkestein
and the Council's patent administrators.

A leaked document from Bolkestein's DG Internal Market suggests that DG
Information Society no longer objects to program claims. This concession
by Liikanen is needed in order to rush the Council working group
proposal through the ministers' session as an "A item", i.e. a consensus
point which does not need any discussion by the ministers.

Technically, the decision by COREPER on Wednesday is only a "forecast"
of the final decision, to be confirmed at the Competitiveness Council of
Ministers on 17-18 May. Until that date, Member states can still change
their minds (and their votes).

If confirmed by ministers, the text will form the basis for the
Directive's second reading in Parliament, after the EU elections. EU
rules make it far more difficult for the Parliament to make changes at
second reading.

Support for the text at a political level in some states is still said
to be quite soft; and decisions brokered in Coreper do fall apart (last
year's discussions on the Community Patent, for example).

FFII is therefore urging supporters to make their voices heard *now*,
especially software SMEs who make up the majority of the IT industry (eg
over 80% of IT jobs in Germany). In particular supporters should try to
mobilise organisations of which they are members, urgently try to meet
or contact local MPs and MEPs, and also Commissioner Liikanen's office
at DG Information Society."

Whatever your take on software patents, this is another example of the Irish presidency's slick understanding of and ability to exploit EU processes. As to their motivation, my perspective is that it is no more complicated than Bertie Ahern and co. wishing to be percieved as an "effective" presidency, "effectivenes" in this context being measured by how many things you get done, regardless of what those things are.

Boy I really am being cynical in the past couple of days. I should go an lie in a dark room and think about that book I should have been working on this week [and would have been if it had not been for my study leave being perpetually interrupted by administrative trivia].
The ACLU, EFF, ALA, CDT and PK have jointly criticised the proposed Fraudulent Online Identity Sanctions Act:

"... we write to express our concern that this bill will penalize and potentially jail Americans who seek only to protect their privacy and right to anonymous free speech online...

... The WHOIS database requires that individual Internet users, when they register domain names, make their names, home addresses, home phone numbers, and home email addresses available to the world, with no privacy protections. Users covered by this requirement include human rights activists, corporate whistleblowers seeking to avoid retribution, and ordinary Americans seeking to avoid spam, stalking or identity theft. As long as WHOIS lacks safeguards to protect their privacy and security these users will feel compelled to place inaccurate data in the database for reasons that have nothing to do with the furtherance of illegal activity.

However, HR 3754 would... create a presumption that inaccurately registered WHOIS data represents evidence of malicious intent... would make violations of copyright or trademark in conjunction with an inaccurately resistered domain "wilful," carrying the highest penalties, even if the activity were otherwise innocent...

... Under current law, the author of an anonymous web log who innocently quotes a portion of a news article that a judge later considers to be too long to qualify for "fair use" would be an "innocent infringer" and subject to reduced statutory damages. Under HR 3754 the same "blogger" would face damages up to $150,000 and potential criminal liability...

...Domain name holders who submit inaccurate WHOIS data: 1) on the basis of bona fide concerns with privacy, or 2) to protect their legitimate rights to anonymous free speech, should not be branded criminals."
The conflict between the Korean mobile phone companies and the music industry over Mp3 playing phones is getting worse. The music indsutry are threatening to get an injunction banning sale of the very popular phones.
The European Commission has proposed a new recommendation of the EU parliament and Council of Ministers on the protection of minors and human dignity and the right of reply in the European audiovisual and information services industry.

Thursday, May 06, 2004

Finally for today, Larry Page's and Sregey Brin's letter to potential Google shareholders in their registration statement with the SEC makes fascinating reading.

"Google is not a conventional company. We do not intend to become one...

...Eric, Sergey and I intend to operate Google differently, applying the values it has developed as a private company to its future as a public company. Our mission and business description are available in the rest of the prospectus; we encourage you
to carefully read this information. We will optimize for the long term rather than trying to produce smooth earnings for each quarter. We will support selected high-risk, high-reward projects and manage our portfolio of projects. We will run the company collaboratively with Eric, our CEO, as a team of three. We are conscious of our duty as fiduciaries for our shareholders, and we will fulfill those responsibilities. We will
continue to attract creative, committed new employees, and we will welcome support from new shareholders. We will live up to our ?don?t be evil? principle by keeping user trust and not accepting payment for search results. We have a dual-class structure that is biased toward stability and independence and that requires investors to bet on the team, especially Sergey and me.

In this letter we have explained our thinking on why Google is better off going public. We have talked about our IPO auction method and our desire for stability and access for all investors. We have discussed our goal to have investors who determine a rational price and invest for the long term only if they can buy at that price. Finally, we have discussed our desire to create an ideal working environment that will ultimately drive the success of Google by retaining and attracting talented Googlers. "

You don't see many IPOs running on the principle "don't be evil."
The NYT yesterday reported the large Canadian telcos' concerns about their future in the era of Net telephony. It's the standard fare about VoIP but worth a read.
John Lettice at the Register has been thinking about the UK government's draft bill and consultation [which, just as a matter of interest, is unreadable from the old computer I happen to be using at the moment] exercise on the national identity card.

After lots of analysis including genuine puzzlement as to how Mr Blunkett, the Home Secretary, really believes he can convince people that the ID cards will cost them £4, when they actually pay £35, he concludes with a question,

"So do you want this? It's a system that won't achieve most of its objectives, and those it will achieve will be achieved via massive overdesign (secure passport system? Here, take this networked database and personal information register to go with it). You get a personal ID card you don't need. You pay vastly more than you need to for the ID documents you do need. It only addresses the immigration problem (most of the British public sees immigration as a problem) if you pretend to love it and use it all the time, in all sorts of areas where you don't need it and it's inappropriate. And you get the free centralised database of your personal information anyway, providing a locus for any number of government and private databases of your personal information. Don't worry you've nothing to hide - even from your bank, other banks, loan sharks and double glazing salespeople, right?

It costs £3.1bn for all this cool stuff. At least. Go and tell the Home Office how much you support it, you've got until the 20 July, and you'll find a link to the consultation document below. If you happen to agree with any of this article, paraphrase it, don't just copy it. If you do they'll just mark you down as a petition signer and disenfranchise you, like they did with the Stand objectors in the previous "consultation.""

Consultation document.



U.S. Releases 2004 Report on Intellectual Property Protection.

Ukraine cited as "priority foreign country"

U.S. Trade Representative (USTR) placed 33 trading partners on the "watch list" for IPR violations: Azerbaijan, Belarus, Bolivia, Bulgaria, Canada, Chile, Colombia, Costa Rica, Croatia, Dominican Republic, Ecuador, Guatemala, Hungary, Israel, Italy, Jamaica, Kazakhstan, Latvia, Lithuania, Malaysia, Mexico, Peru, Poland, Romania, Saudi Arabia, Slovak Republic, Tajikistan, Thailand, Turkmenistan, Uruguay, Uzbekistan, Venezuela and Vietnam.

Another 16 trading partners are on the "priority watch list," which entails greater
scrutiny. Eleven of these -- Argentina, Bahamas, Brazil, EU, India, Indonesia, Lebanon,
Philippines, Poland, Russia and Taiwan -- were on last year's priority list. The other five
-- Egypt, Korea, Kuwait, Pakistan and Turkey -- were moved this year from the watch
list to the priority list.

China and Paraguay get warned they're facing imminent trade sanctions for IP violations.
It seems that the start of trial of of the ten thousand (i.e. biometric national ID cards in the UK) was delayed by three months because the technology didn't work. Now it is going to for last three months rather than the planned six months.

David Blunkett has said that although the pilot scheme was late, "it is important to get it right rather than get it quickly?". I see. It does n't work. So delay the start. Then cut the time for the trial in half in case people notice there are lots of problems with it. And then claim you're trying to get it right. This is a joke. Right?

Ok, call me a cynic again. Hey, that's twice in one day.
My colleague, John Naughton, pointed me at this 10 minute interview, where an MIT student quizzed Jack Valenti. Jack genuinely didn't seem to know there were no DVDCCA licensed linux DVD players on the market.

"TT: But today, you still cannot on the market actually buy a licensed DVD player for Linux.

JV: I didn?t know that.

TT: So the question is, do you think people who go to Blockbuster, they rent a movie, they bring it
home, and they play it on Linux by circumventing the access control, are those people committing a
moral transgression?

JV: I do not believe that you have the right to override an encryption. Because if you have the right
to do it, everybody can do it. For whatever benign reason you have, somebody else has got one
even more benign. But once you let one person deal in a digital copy -- and I don?t have to tell you;
you know far better than I that, unlike in analog, the ten thousandth copy is as pure as the original --
it is a big problem. So once you let the barriers down for your perfectly sensible reason, you gotta
let it down for everybody.

I don?t want to get into the definition of morality. I never said anything was immoral in what I was
saying. I said it is wrong to take something that belongs to somebody else.

TT: Indeed, but are you doing that when you rent a movie from Blockbuster and you watch it at
home? ... I run Linux on my computer. There?s no product I can buy that?s licensed to watch
[DVDs]. If I go to Blockbuster and rent a movie and watch it, am I a bad person? Is that bad?

JV: No, you?re not a bad person. But you don?t have any right.

TT: But I rented the movie. Why should it be illegal?

JV: Well then, you have to get a machine that?s licensed to show it.

TT: Here?s one of these machines; it?s just not licensed.

[Winstein shows Valenti his six-line ?qrpff? DVD descrambler.]

TT: If you type that in, it?ll let you watch movies.

JV: You designed this?

TT: Yes.

JV: Un-fucking-believable.

TT: So the question is, if I just want to watch a movie--I rent it from Blockbuster--is that bad?

JV: No, that?s not bad. "

Valenti is going to be a hard act to follow when he leaves the MPAA.
Microsoft have launched their Janus drm software.
California have allegedly toughened their stance on electronic voting. The devil is in the detail and I remain unconvinved this is anything more than political posturing at the moment, especially since California Secretary of State is reportedly calling Diebold reprehensible and calling for a criminal investigation of the company. Ok call me a cynic.

Meanwhile at least one county in California is suing the secretary state for the right to use electronic voting in the presidential election.
The Dutch data protection authority, CBP, have stated, that the Dutch entertainment industry's anti-piracy group BREIN's sharing of information [on file sharing] with US counterparts is in breach of Dutch data protection and privacy laws. Following on from the Dutch supreme court's decision in the Kazaa case, that won't make the Netherlands any more popular with the industry.
Nice profile of Avi Rubin and his stance on the electronic voting controversy at the NYT.
From the Scotsman via historian Professor Steve Hindle, Blunkett's 'Id Card' Was Around in 16th Century. Wonderful.
I've spent another couple days this week away from my office at the OU, helping some colleagues agree the final structure and content of our new cybervandalism course, T187. The facilities at the conference centre, Harben House, run by Initial, were fine. What did really irritate me, though, was trying to access my weblog from their internet cafe and discovering it was censored by their filter software, which declared that my thoughts here might be unsuitable for children.

Do contact them about inappropriate filtering, if you feel so inclined. I've complained and been told my complaint would be reviewed by a human being. I wonder how many other filter software packages block these pages, presumably because the url and blog title contain the letters 'xxx'?
I spent a couple of days in Barcelona last week, one at the terrific Univeritat Oberta de Catalunya (UOC), the virtual university, where I met a group of like minded enthusiasts for the deployment of technology in education, who actually understood what can and cannot be done with technology in that context.

I shouldn't be surprised at this but it is such a rarity in the thick of all the nonsense that gets talked, written about and done in the name of computers in education that it was an absolutely delightful day. UOC have grown from about 300 to 30000 students in about ten years. They have also in that time been learning the same lessons, as an institution, that those of us in the Open University in the UK who have been deeply engaged in deploying multimedia computer and Internet facilitated education with large numbers of students over a similar period have learnt about the potential, current limitations and practicalities of technological tools in an educational context.

I only hope our wonderful hosts, Sylvia Gonzalez and Ferran Gimenez Prado, found it as useful as we did.

Saturday, May 01, 2004

The NYT are reporting that the FBI were given millions of passenger records by airlines in the says after the September 11th tragedies. Seems like a pretty sensible course of action for the FBI to request such records given the circumstances. They used subpoenas, so it was all above board. The only question, I guess, is regarding the boundaries of the request and the quantity of information handed over. Apparently at least one airline provided a year's worth of records.

Monday, April 26, 2004

The ID card draft bill is proposing to create quite a few new offenses, like disobeying an order from the Secretary of State. I hope one of the draftsmen have put that in as a joke to test how well this thing is going to get scrutinised? Think of it - in a democracy there could actually be an offense of refusing to follow the orders of a public servant. It also includes little incentives like a £2500 fine every time someone fails to turn up for an appointment for a biometrics scan (Section 6(4)). Jailtime for having someone else's card in your possession (don't offer to look after a friend's belongings whilst they respond to the call of nature then). All this draconian stuff is just an initial extreme pitch, so that Mr Blunkett can be seen to be making "reasonable concessions" when the actual law gets passed. Simon Davies of Privacy International is right - this whole shambles is a "disgrace to democracy."
A draft bill for a national ID card is online. There are lots of stories round about the ID card in the UK press today. Ministers are peddling the usual propaganda in favour and by and large journalists are lapping it up unquestioningly. Regarding the test progamme with ten thousand volunteers I have mixed feelings. I'm irritated with it because it's a waste of money and primarily a PR exercise. But at the same time I think it's a good idea because proponents and ordinary people, to whom the idea is intuitively and superficially attractive, will finally get to see how bad this 'state of the art', 'impossible to fool' biometric technology is in reality. The Australians did an ID card trial in the 90s and quietly abandoned the notion, having discovered how many problems it caused. Let's hope the UK version goes the same way
On the day that the UK government launch their controversial pilot national ID card scheme with ten thousand volunteers, Privacy International have released an interim report on a study of the connection between ID cards and preventing terrorism. Not surprisingly, "Mistaken Identity; Exploring the Relationship Between National Identity Cards & the Prevention of Terrorism" concludes that ID cards do not help to prevent terrorism.

Friday, April 23, 2004

NYT: Pentagon Ban on Pictures of Dead Troops Is Broken
EUpolitix has a succinct report on MEPs taking on the Commission and the US over the deal on the transfer of airline passenger data.

Thursday, April 22, 2004

Brad Templeton, chairman of the EFF, amongst other things, has produced a thoughtful analysis of the 'GMail Saga'.
The Bush administration is apparently proposing to give ally countries another 2 years to devop biometric passports. Secretary of State Colin Powell says

"Rushing a solution to meet the current deadline virtually guarantees that we will have systems that are not operable... Such a result may undercut international acceptance of this new technology as well as compound rather than ease our overall challenge."

The European Commission have issued a Communication on the Management of
Copyright and Related Rights
. In it they eulogise digital rights management (DRM) as the solution to all ills of the copyright variety, most specifically this time royalty collection agencies problems. What is it about biometric national ID cards, DRM, RFIDs, electronic voting machines, computers, technology in general that make them superficially attractive solutions to everything? The right technology appropriately deployed can be a terrific boon but why can't people understand that it is not usually a particularly good idea to start with a [technological] 'solution' and then go looking for a problem, just so you can use the 'solution'?
A Barcelona night club is allegedly implanting RFID chips in VIP customers so they don't need to worry about carrying a wallet about. No comment.

Tuesday, April 20, 2004

Despite the pending lawsuit against ClearPlay and others by the Directors Guild of America and the movie studios, it appears as though Walmart is going to be selling DVD players with ClearPlay filters built in. I wonder what the demand will be like and how that will affect the dynamics of the court case?
The United States Institute of Peace, which I admit I'd never prviously heard of, have issued a paper saying terrorists use the Internet too but for more routine activities than the hyped-up cyberterrorism feedstuff of the mainstream media. Terrorist organisations are said to have three major audiences:
Current and potential supporters
International public opinion
Enemy publics (i.e. citizens of states they are fighting)
and use the Net in 8 different (sometimes overlapping) ways:
Psychological warfare
Publicity and propaganda
Data mining
Fundraising
Recruitment and mobilisation
Networking
Sharing information
Planning and coordination

The report does imply that steganography is in widespread use by terrorist organisations but there is no direct evidence offered to that effect. The mainstream media has periodically salivated at the notion of religeous fundamentalist terrorists hiding messages in online porn but no evidence to that effect has been forthcoming. Being only 12 pages long the paper is just an overview I assume but it might be interesting to hear more details of the study.
Wonderful Ed Helms skit at Comedy Central about e-voting. Not to be missed. This kind of comedy does more to communicate the problems with electronic voting than all the ranting that I do on the subject.
Jay Rosen has a thoughtful analysis of the recent furore over inappropriate comments by a Democrat-supporting blogger. Another example of the scandalmongering of mainstream politics and media out-manoeuvering the democratising potential of the net.
The Berkman Center at Harvard have done an interesting study on Apple's iTunes service focussing on

Interaction between Copyright and Contract Law
Digital Rights Management
Digital First Sale Doctrine
Fair Use Doctrine

Worth a look.

Monday, April 19, 2004

There are two lovely essays in Bruce Schneier's latest Crypto-Gram, one on national identity cards and the second on the economic incentives to rig electronic voting machines. On national ID cards:

"But my primary objection isn't the totalitarian potential of national
IDs, nor the likelihood that they'll create a whole immense new class
of social and economic dislocations. Nor is it the opportunities they
will create for colossal boondoggles by government contractors. My
objection to the national ID card, at least for the purposes of this
essay, is much simpler.

It won't work. It won't make us more secure.

In fact, everything I've learned about security over the last 20 years
tells me that once it is put in place, a national ID card program will
actually make us less secure.

My argument may not be obvious, but it's not hard to follow,
either. It centers around the notion that security must be evaluated
not based on how it works, but on how it fails.

It doesn't really matter how well an ID card works when used by the
hundreds of millions of honest people that would carry it. What
matters is how the system might fail when used by someone intent on
subverting that system: how it fails naturally, how it can be made to
fail, and how failures might be exploited.

The first problem is the card itself. No matter how unforgeable we
make it, it will be forged. And even worse, people will get legitimate
cards in fraudulent names...

... the main problem with any ID system is that it requires the
existence of a database. In this case it would have to be an immense
database of private and sensitive information on every American -- one
widely and instantaneously accessible from airline check-in stations,
police cars, schools, and so on.

The security risks are enormous. Such a database would be a kludge of
existing databases; databases that are incompatible, full of erroneous
data, and unreliable. As computer scientists, we do not know how to
keep a database of this magnitude secure, whether from outside hackers
or the thousands of insiders authorized to access it.

And when the inevitable worms, viruses, or random failures happen and
the database goes down, what then? Is America supposed to shut down
until it's restored?

Proponents of national ID cards want us to assume all these problems,
and the tens of billions of dollars such a system would cost -- for
what? For the promise of being able to identify someone?"

Tim O'Reilly doesn't understand all the fuss about Google's Gmail and privacy.

Wednesday, April 07, 2004

Apparently the EU parliament's civil liberties committee has decided to delay the 'ill considered' proposal on biometric passports until the autumn.

Statewatch is also reporting on this "Commission’s EU biometric passport proposal exceeds the EC’s powers
- no powers conferred upon the EC by the EC Treaty, taken separately or together, confer upon the EC the power to adopt the proposed Regulation"

Tuesday, April 06, 2004

At least one online pundit agrees with me about media having a short attention span. This one sees a possible danger for bloggers and provides an interesting perspective on the hounding of a Democratic party activist blogger, Markos Moulitsas Zuniga, who writes the Daily Kos, for posting an inappropriate/tasteless comment on his blog.

Monday, April 05, 2004

Largely unnoticed about a month ago the EU launched PRIME, a four year project to

"Develop solutions to empower individuals to control their private sphere and manage their identities; "

and

"Trigger persuasive deployment of privacy-enhancing identity management solutions. "

-according to the website. Theoretically the EU Commission has been pushing PETs (privacy enhancing technologies) for some time and one of the principles is to minimise the amount of personal data collected. There are two fundamental problems:

1. The Blair/Blunkett and by extension the EU Council of Ministers simple solution to terrorism - collect as much personal data about the entire population of the world as possible, in the hope that you can kid people into believing you're actually tackling terrorism;

And

2. Though we all say, when asked, that we are concerned about our personal privacy, we do very little actively to protect it e.g. how many people think about the privacy implications of their supermarket store cards.

Ah well, at least somebody is working on it.
David Blunkett and Tony Blair are continuing to exploit the Madrid bombings unconscionably, by pushing forward the introduction of biometric national ID cards by 2008, as their "we must do something" response.

This capitalising on others' tragedy is politics at its lowest.

They are prepared to spend billions of pounds on a system which won't work and will, in the process undermine fundamental freedoms in the UK that people have fought and died for, just to extract some transcient and superficial "tough on terrorism" headlines from a media with a short attention span.

If Mr Blunkett does get to be prime minister off the back of this then we will deserve what we get, for letting him get away with propering from this poisonous snake oil he is currently selling. Liberty, price and eternal vigilance come to mind on the one hand and not just the media but a short attention span society and general apathy on the other. It's big, it costs a fortune and hey it involves new technology, so most of us will buy it. Especially because the real solutions, if there are any, are long term and too hard for us to deal with.

Friday, April 02, 2004

Mr Blair has decided to fast track David Blunkett's national ID card system to try and distract people from the immigration fiasco that has prompted Home Office (in charge of immigration) minister Beverly Hughes' resignation.

John Lettice at the Register has a nice dissection of this as a complete sham. His concluding paragraphs are absolutely damning:



" Now, here is the problem as best as can be established at the moment. The
size of the backlog of immigration cases (both asylum and general) has been a
major issue for the current government, and Hughes (who reported to David
Blunkett at the Home Office) was presiding over the acceleration of the
processing of applications. It appears that in at least some areas this
acceleration process resulted in the systematic rubber-stamping of
applications. Cases from Bulgaria and Rumania have been cited where forged
documents were approved, and where pro forma business plans were sold to
applicants fraudulently applying under a programme designed to bring in
self-sustaining business startups. Allegedly, the UK authorities were alerted to
these fraudulent applications and to their rubber stamping, and Hughes herself
had the matter drawn to her attention last year by one of her own ministers.

So friends, what do we have here? If we had ID cards, what would have been
happening? At the same time as Blunkett's Home Office has been thumping
the ID card tub on the basis of its efficacy against crime, terrorism and illegal
immigration, that very same Home Office has known as a matter of record
(this is not, we accept, the same as actually knowing or even noticing) that it's
been granting immigrant status to people who are not going to perform in
accordance with what it says on the tin they just bought. Granted they're a lot
more likely to be one-legged Bulgarian plumbers who don't know anything
about plumbing than terrorists, but still... Their application rubber-stamped,
under the future system they would then have been issued with ID cards, and
would have happily acquired a perfectly legitimate UK identity on the basis of
whatever it was they'd chosen to fill in. Moral: the Home Office might be best
advised to sort out the loopholes and system failures it already has before
introducing new ones to fix. "

Thursday, April 01, 2004

The European Parliament have rejected Commissioner Bolkestein's deal with the US to share airline passenger data for use in CAPPS II, because it breaches EU privacy laws. It was a close vote 229 to 202 but the resolution suggested they'd go to the European Court of Justice on the matter if necessary.
The copyright bills are coming out of Congress thick and fast. The latest is the "Piracy Deterrence and Education Act" (PDEA) according to Declan. More of the usual, this time pressurising the FBI to chase the copyright infringers. I guess it's a variation on the DOJ. It's also a variation on the Author, Consumer, and Computer Owner Protection and Security Act (ACCOPS) proposed last year which was suggesting 5 year prison terms and $250 000 fines for sharing a single file.

"One part of the PDEA that did not appear in earlier bills would require the FBI to "facilitate the sharing" of information among Internet providers, copyright holders and police. "

And so the procession rolls on.
James Grimmelmann has a wicked April fools joke over at Lawmeme about the RIAA suing Google. I wonder how far that one will spread.

A Canadian judge has put a spoke in the gathering momentum of the IFPI's campaign of lawsuits against individual file sharers. He has denied the Canadian Recording Industry Association (CRIA) request to identify individuals alleged to be involved in P2P file sharing. He even declared file sharing legal in Canada, including uploading. "The mere fact of placing a copy on a shared directory in a computer where that copy can be accessed via a P2P service does not amount to distribution," he wrote. "Before it constitutes distribution, there must be a positive act by the owner of the shared directory, such as sending out the copies or advertising that they are available for copying." Expect an appeal from the CRIA probably faster than you can blink.

Wednesday, March 31, 2004

Slashdot has links to a collection of stories about the IFPI lawsuits against individuals.
There is an absolutely fascinating paper, Privacy in a Noise Society, which I've just come across on the web, by Nicklas Lundblad of the St Anna Institute in Stokholm. He puts his finger on one of the key issues relating to privacy in an information society and that is that "...anyone but not everyone can be mapped in detail...We live in a society where it is possible to chart the lives of anyone, but not the lives of everyone." Information overload and cost effectively preclude the latter.

Essential reading.
Kim Zetter at Wired has written a longish article about the dangers of e-voting. Worth a look. Wired has an archive of stories on the e-voting issue, headed up "Machine politics" which I'd suggest is a good starting point for anyone with concerns about the use of computers in elections.

Zetter's article gives an idea of the timeline of when and key folk involved in the publicising of the problems, such as Rebecca Mercuri, Bev Harris, David Allen, Avi Rubin, Yoshi Kohno, Adam Stubblefield, David Dill, David Jefferson, Nebraska Sen. Chuck Hagel (Republican) and New Jersey Rep. Rush Holt (Democrat). It's largely told from Harris' perspective.
IFPI affiliated music industry associations in Denmark, Italy, Germany and Canada have launched lawsuits against hundreds of individuals. (FWIW it's about 120 in Denmark, 30 in Italy, 29 in Canada and 68 in Germany). Look out for comments from the usual suspects.

Aaron Swartz, in parallel, has launched a wiki for annotating and editing Larry Lessig's new book, Free Culture.

Monday, March 29, 2004

Ernest Miller over the weekend has concluded that the PIRATE Act will faciltate wiretapping for civil copyright infringement.

"...having thought about the proposed law a little more, I came to an interesting realization: you can get wiretaps for federal copyright infringement investigations...

...Under a regular civil suit for copyright infringement by means of file sharing, the copyright holder can only observe that the infringing files are available for download. They can't really tell how many people have downloaded them, if any. Furthermore, copyright holders have no way of going after people who are only downloading files and not uploading them. Wiretaps to the rescue. The RIAA may not be permitted to wiretap file sharers, but the government certainly can. The RIAA must be salivating at the prospect."
The entertainment industry's latest attempt to get their representatives in Congress to pass favorable laws has produced the proposed Protecting Intellectual Rights Against Theft and Expropriation Act (PIRATE Act). (What a name). The idea this time is to save the copyright holders the trouble and expense of having to sue for copyright infringement. The responsibility for that would now be with the Department for Justice (i.e. taxpayers). As Donna says, the industry reject compulsory licences because they don't want government interference in the private sector but it's ok for the government to interfere when it involves them picking up the industry's legal costs. This is a sad joke.

James Grimmelmann at Lawmeme has a wonderfully cutting perspective on US reaction the WTO's decision to declare the US in breach of international trade rules in relation to online gambling policies. I hope he won't mind me reproducing it in full here:

'Remember why those folks in Seattle were so mad at the WTO? Well, one of the big reasons was that local laws in developing countries (on issues such as environmental protection, labor standards, and cultural values) were at risk of being struck down as "barriers to trade." Trade is trade, said the U.S., and trade comes first, and countries just need to shut up and deal.

Well, oh how the tables have turned. A WTO panel ruled on Wednesday that the U.S. ban on online gambling is an illegal trade barrier. Outraged U.S. lawmakers have already promised to appeal. Surprise, surprise, the ideology that free trade trumps restrictive local values turns out to be much less appealing when the U.S. interests are aligned with "local values" instead of "free trade." '

An international coalition of civil liberties groups, led by Privacy International and the American Civil Liberties Union (ACLU) have signed an open letter to the International Civil Aviation Organization (ICAO) on the grave dangers of vast biometric-passenger-data sharing systems. Thanks to Ian Brown at FIPR for the following extract from Privacy International's media release:

The letter, spearheaded by Privacy International and the American Civil
Liberties Union (ACLU) raises concerns about little-known plans to
imminently create international standards that will require the use of
biometrics and RFID (radio frequency) technology in all future
passports. The measures, being decided this week at a meeting of the
ICAO in Cairo, will result in a distributed international identification
database on all passport holders.

The open letter has been signed by, among others, the Electronic
Frontier Foundation, Statewatch, the UK based Foundation for Information
Policy Research, the Association for Progressive Communications and the
US based Privacy Rights Clearinghouse.

The ICAO has agreed that the initial international biometric standard
for passports will be facial mapping. Adequate memory space in newly
issued passports will be reserved for additional biometrics such as
fingerprinting at the discretion of every government. The EU is already
calling for fingerprints to be included, along with an associated
European register of all biometrics. National authorities will store and
share these vast data reserves.

The measures, supported by the US and the EU, will ultimately create an
electronic ID system on hundreds of millions of travellers. Despite
serious implications for privacy and personal security, the process is
occurring without public engagement or debate. Rather than allowing this
important issue to be decided by parliaments, governments have delegated
the setting of standards to the ICAO, a UN-level organization that is
responsible for the standardization of travel documents, passenger data
systems and air travel requirements.

The legislative drivers for the ICAO system are already in pace. The
USA-PATRIOT Act, passed by the U.S. Congress after the events of
September 2001 included the requirement that the President certify a
biometric technology standard for use in identifying aliens seeking
admission into the U.S., within two years. The schedule for its
implementation was accelerated by another piece of legislation, the
little known Enhanced Border Security and Visa Entry Reform Act 2002.
Part of this second law included seeking international co-operation with
this standard. The incentive to international co-operation was made
clear:


"By October 26, 2004, in order for a country to remain eligible for
participation in the visa waiver program its government must certify
that it has a program to issue to its nationals machine-readable
passports that are tamper-resistant and which incorporate biometric and
authentication identifiers that satisfy the standards of the
International Civil Aviation Organization (ICAO)."


These laws gave momentum to the standards that were being considered at
the ICAO by requiring visa waiver countries (which include many EU
countries, Australia, Brunei, Iceland, Japan, Monaco, New Zealand,
Norway, Singapore, and Slovenia) to implement biometrics into their
Machine-Readable Travel Documents (MRTDs), i.e. passports.

Based on projections from current passport and travel statistics,
biometric details of more than a billion people will be electronically
stored by 2015. Some of the countries sampled for this estimate are:

United States 90 million
United Kingdom 54 million
Japan 64 million
Canada 24 million
Australia 13 million
Russian Federation 50 million
Ireland 4 million
Taiwan 17 million
China 60 million

The Privacy International open letter warns:

"We are increasingly concerned that the biometric travel document
initiative is part and parcel of a larger surveillance infrastructure
monitoring the movement of individuals globally that includes
Passenger-Name Record transfers, API systems and the creation of an
intergovernmental network of interoperable electronic data systems to
facilitate access to each country's law enforcement and intelligence
information."

Privacy International has warned of "unprecedented" security threats
that could arise from the plan because of potential access by terrorists
and organised crime. Furthermore, the biometric standard being adopted
is "fundamentally flawed" and will result in a substantial number of
passengers being falsely identified as potential terrorists or wrongly
accused of holding fraudulent passports.

Dr Gus Hosein, Senior Fellow with Privacy International, warned: "This
is a potentially perilous plan. The ICAO must go back to the drawing
board or hold itself responsible for creating the first truly global
biometric database".

"Governments may claim that they are under an international obligation
to create national databases of fingerprints and face scans but we will
soon see nations with appalling human rights records generating massive
databases, and then requiring our own fingerprints and face-scans as we
travel."

He continued: "In January 2004 when the U.S. began fingerprinting and
face-scanning foreign visitors and storing this data for over fifty
years under the US-VISIT program, many countries responded with alarm.
With the biometric passport, however, every country may have its own
surveillance system, accumulating fingerprints and face-scans and
keeping them for as long as they wish with no regard to privacy or civil
liberties."

Friday, March 26, 2004

Larry Lessig has persuaded his publishers, Penguin, to make his new book, Free Culture, available online under a creative commons licence, Cory Doctorow style.

It looks as though Microsoft may have pulled a fast one on the EU according to Dan Gillmor and Andrew Orlowski. Regardless of whether you love or hate the company, in some ways you've got to have a sneaking admiration for Microsoft or at least the smart people they employ. Even when they are apparently under the cosh they're always looking to outwit the authorities and usually do.

Wednesday, March 24, 2004

Interesting essay in Spiked by Brendan O'Neill: Creating the enemy. Extract:



Over the past 10 to 15 years, the politics of fear and caution have come to dominate Western societies. Where political life previously consisted of debates and disagreements about what kind of society we wanted to live in, today it tends to focus on issues of safety and perceived risks to our health, environment or 'way of life'. The exhaustion of the political traditions of Left and Right has had a profoundly disorientating impact across Western society, shattering the consensus upon which basic questions of politics and morality have been decided throughout recent history. Faith in what were traditionally considered 'Western' values or institutions, from democratic politics to medical science, from the church to the monarchy, has been steadily eroded. Gaining agreement on any issue, from genetic modification and abortion to the role of the family and the issue of recreational drugs, has become increasingly fraught and subject to abitrary considerations.

We live in an era of great uncertainty, in which political leaders stand isolated from the public and unsure of what they believe in, and individuals have a weakened sense of community, solidarity or identity. This is enough to put society in a constant state of powerlessness and vulnerability - even without terrorist attacks."

Tuesday, March 23, 2004

Mr Blunkett's ID card scheme is running on apace.

"Mr Harrison" [the head of the Home Office's identity card policy unit] "also outlined the latest Home Office thinking on on whether or not the one million Irish nationals living in Britain will have to carry UK identity cards...

Mr Harrison told a Law Society conference yesterday that
ministers had started with the assumption that information on
the pattern of everyday transactions involving each card would
not be kept on the central computer database.

But following representations from the information commissioner
they were now minded to keep information "about the audit of
transactions" to allow the authorities to investigate abuses of the
scheme...

The senior Home Office official also revealed the current thinking
on how to deal with the Irish problem. The 1949 Ireland Act
specifies that Irish citizens living in Britain enjoy total freedom of
movement between the two countries...

Mr Harrison said the plan now was to allow Irish nationals in
Britain to choose whether to be treated on an equivalent basis to
a British national or as an EU foreign national. He said there
would be a separate document which Irish nationals could obtain
which would not be a foreign national's resident's permit to
reflect their special status. "
Donna is getting some help with Copyfight. Elizabeth Rader, Aaron Swartz, Jason Schultz, Wendy Seltzer and Ernest Miller. They don't come much smarter than that lot. I wonder if it is something about people with names with 'z' in them, that raises the IQ (Ernest being the exception that proves the rule)?

Donna's first post to the new collective relates to the latest challenge coming out of Stanford's CIS to the Copyright Term Extension Act. With Golan v Ashcroft also coming out of that stable Lessig and co. seem determined, as James Grimmelmann so eloquently suggests, to salvage the phoenix from the Eldred case Supreme Court ashes. Better go update my link to copyfight now it has moved back to Corante.

Monday, March 22, 2004

The Guardian leader today shares my perpective on David Blunkett's intention to take advantage of the Madrid bombings to introduce ID cards. The illusion of security is the enemy of security.
UK Home Secretary, David Blunkett, is back to his hobby horse of trying to get his national ID card scheme implemented again and has Cabinet colleagues complaining about his sneaky tactics.
According to Mary Hodder and the smoking gun, Donald Trump has applied for a trademark on the phrase "You're Fired". Mary notes that "You're Outsourced" is still available.

Friday, March 19, 2004

A "True Name and Address" bill for all filesharers has been introduced in California. Ernest Miller is not impressed.

"The basic idea of the bill is to extend a "true name and address" statute to cover virtually all exchanges of copyrighted audiovisual information. That is, if you send someone a copy of a recording or audiovisual work electronically without also providing your true name and address, you could be fined $2,500 and spend a year in the clink...

We need to have a "true names" bill for politicians. By all rights, State Sen. Kevin Murray" [who is sponsoring the bill] "should start calling himself State Sen. Hollywood Sycophant."

I guess something similar could be said of Bill Lockyer, California's attorney general after his recent call to arms to fellow AGs about "dangerous" P2P software. 'Hollywood Ingratiator General' anyone?

As Ernest says,

"And what is this? Hollywood can't afford to sue people? We citizens of California have to expend precious tax dollars and limited law enforcement resources on copyright enforcement because Hollywood is too darn cheap? With massive statutory copyright damages available as a remedy, there is no excuse for Hollywood not to prosecute copyright infringers directly. Heck, it could even be a profit center."

Thursday, March 18, 2004

The Council of Europe's Convention on Cybercrime has been ratified today by Lithuania. "Following this fifth ratification, the Convention will enter into force on 1st July 2004 for Albania, Croatia, Estonia, Hungary and Lithuania. "

Kazaa duo's next call at Mercury news is a nice piece about Kazaa founders Niklas Zennstrom's and Janus Friis's new Net telephony service Skype. I vaguely recall seeing exactly this report somewhere last year but can't remember where at the moment.

The Eolas v Microsoft patent infringement case is testing the procedures in the US Patent Office, as well as the courts, as the patent is to be subjected to further review. Paul Festa says, "The next round in Microsoft's Web browser patent fight will unfold in an obscure bureaucratic proceeding that offers the company and its allies few, if any, chances to argue their side."

SNP MEP Neil MacCormick has offered a gentle critique of fellow MEPs Malcolm Harbour's (Conservative) and Arlene McCarthy's (Labour) support for the EU's intellectual property enforcement directive.

"There is no doubt that the EU should take action against counterfeiting and piracy...

...However, valid questions must be raised as to whether all the measures passed last week in the European Parliament are the correct ones - or whether some of them may bring unintended but serious consequences...

...Malcolm and Arlene argue that the EU directive has always been intended to tackle professional, commercial scale counterfeiting. Maybe so. It's just a pity that the final version which they voted for last week doesn't fully achieve that restriction...

...So, while it's true that a teenager doesn't have to fear his bank account being seized, it's not true to say that he can't have his CD collection seized...

...Another area of concern is the inclusion of patents in the scope of the directive. Patent law is much more complicated than other areas of IP law and much more open to abuse.

Legitimate companies who produce cheaper versions of medicines, for example, fear that the multinational drugs conglomerates will use this to stop the production of derivative medicines, so called 'generic medicines'...

...Perhaps the biggest disappointment in last week's European Parliament vote is that it was an opportunity lost. In an effort to rush through legislation before this June's elections we have ended up with a flawed directive.

Malcolm Harbour and Arlene McCarthy are right to say that the directive will be monitored and reviewed in due course. It's a great shame that so many people stand to suffer in the meantime in ways irrelevant to stamping out piracy and counterfeiting."

Wednesday, March 17, 2004

MacUser is reporting that "British government gets serious about open source" Which gives me an opportunity to mention a project launched yesterday by John Naughton and Quentin Stafford-Fraser called Ndiyo, (the Swahili word for 'yes') which has the small aim of changing the world. John likes a challenge.

It's all about bridging the digital divide (or more accurately, expanding the bubble of those included in the communications revolution) by using a new affordable hardware architecture and open source and free software.

In terms of architecture they're basically re-inventing the mainframe paradigm, the processing power of which can be shared by multiple users working from essentially dumb terminals. It's a slight variation on Larry Ellison's network computers from a few years back but workable on a local area basis. A clever, cheap, disposable, small box of tricks handles the local networking that let's the users at their terminals use the interact with the computer, which would be a PC equivalent. The box of tricks is currently proprietry technology, the patents on which are held by Newnham Research.

But Ndiyo are in the business of creating open standards to make a communications infrastructure equivalent to our plumbing or electrical network infrastructures, which everyone can have access to. They need companies like Newnham to manufacture the kit and break away from the Bill Gates enabled thinking trap about everyone needing a personal computer (running Microsoft software) but there is little stop another company to come up with their own version of networking box of tricks. In fact this piece of the infrastructure could be slimmed down to a single chip which could be mounted on the back of the monitor.

Given the vastly under-used processing power of most personal computers, or as Clay Shirky calls them "the dark matter of the internet", this kind of project is long overdue. It provides a huge potential to wire up inner cities, schools and public services at a tiny fraction of the cost of the equivalent in the WIntel universe. And that's just scratching the surface of what it could do in the affluent West.

Not many people know that about two thirds of the cost of an average PC is down to the licenses for Windows and Office software and the money goes straight to Microsoft. So using open source or free software provides an instant and vast cost saving.

I do have a slight worry about the reincarnation of the old monster, tyranno-sysadmin, who used to control computer users lives in relation to access to the sacred mainframe machines but that's a minor glitch in the scheme of things. There are also some technical obstacles ahead, as well as the issues of social protocol and questions of control over personal data, which brings me back again to the overall objective and the suitability of this new information architecture to the context, as well as, critically, they way the technology is deployed.

Nydiyo are committed to delivering three projects this year - a classroom in a box, an office in a box and an internet cafe in a box. Will John, Quentin and their small band of troops manage to change the world? Given an the ever increasing information feudalism we're seeing in the 'modern' world, I hope the answer is an emphatic Ndiyo.
Andrew Cringely recently asked "A Year Into the E-voting Crisis, Shouldn't We Have Noticed the Printer That's Already Built into Each Diebold Voting Machine?" Yet one of the spurious arguments against a verifiable paper audit trail is that is would cost too much to fit the printers to the e-voting machines.

Example:

"Meg Smothers of the League of Women Voters recently said that Georgia has 28,000 voting machines, and it would cost $15 million to retrofit them with printers to produce receipts. That comes to $535 per machine. "

I see. So we must employ computing in elections because computers are magic and they cost a lot, so they must be good. But we can't spend enough to make them actually work because it would cost too much. And it would cost too much because computers are pricey, so obviously if we want them to do anything extra (like print) that will cost a lot. And we are too stupid to realise that the computer will already do that extra thing we want it to do (i.e. print) - we just have to switch that part on. We are also too stupid to realise that because we don't even try to understand how computers work - because they are magic and we won't be able to. But we must have them for our elections because they are magic and using computers for anything will obviously make it better. That's alright then.

I wonder if any of these people ever heard of Josef Stalin? You know, the fellah that said "It is not the people who vote that count. It is the people who count the votes."

Monday, March 15, 2004

EU regulators have been meeting today to agree a draft ruling branding Microsoft a monopolist.
According to Xeni Jardin at Wired, the MPAA have drafted a letter for the California attorney general, Bill Lockyear, to circulate to fellow attorneys general, to encourage an all out legal assault on P2P file sharing software companies.

"The draft document, dated February 26, was obtained by Wired News on March 12. Distribution of a revised version to other attorneys general is said to coincide with the spring meeting in Washington, DC, March 15 to 17 of the National Association of
Attorneys General, of which Lockyer is president. The attorney general's office plans to release a final version publicly within the coming month, after obtaining additional signatories.

"We do not wish to make any comment at this time on any document that the office of the attorney general may or may not be developing," said Tom Dressler, spokesperson for Bill Lockyer in Sacramento. "But we remain concerned about the potential dangers posed to the public by peer-to-peer file-sharing technology."

However, the metadata associated with the Microsoft Word document indicates it was either drafted or reviewed by a senior vice president of the Motion Picture Association of America. According to this metadata (automatically generated by the Word application), the document's author or editor is "stevensonv." (The metadata of a document is viewable through the File menu under Properties.)

Sources tell Wired News that the draft letter's authorship is attributed to Vans Stevenson, the MPAA's senior vice president for state legislative affairs. MPAA representatives have issued similar criticisms of P2P technology in the past. Stevenson could not be reached for comment. "

Extract from the letter:

"As a P2P software developer and distributor, we believe you have the ability and responsibility to better educate consumers about these known risks, and to design your software in a manner that minimizes the risks. We view with grave concern reports that at least some P2P software developers may be adding features deliberately designed to hinder law enforcement in its prosecution of crimes using P2P software. Companies that engage in such conduct, and fail to meet the important responsibilities referenced above, harm the interests of consumers in our States.

It is widely recognized that P2P file-sharing software currently is used almost exclusively to disseminate pornography, and to illegally trade copyrighted music, movies, software and video games. File-sharing software also is increasingly
becoming a means to disseminate computer worms and viruses. Nevertheless, your company still does little to warn consumers about the legal and personal risks they face when they use your software to "share" copyrighted music, movies and computer software. A failure to prominently and adequately warn consumers, particularly when you advertise and sell paid versions of your software, could constitute, at the very least, a deceptive trade practice...

...Whether it is the widespread availability of pornography, including child pornography, the disclosure of sensitive personal information to millions of people, the exposure to pernicious computer worms and viruses, or the threat of legal liability for copyright infringement, P2P file-sharing software has proven costly and dangerous for many consumers...

Over the coming months, we will begin focusing more attention on the risks P2P software programs pose to consumers in our States. We hope this inquiry will encourage you to take proactive, concrete and meaningful steps to address the problems we have raised in this letter.... We take seriously our responsibility to protect consumers and ensure that the laws of our States are respected. In the future, we will not hesitate to take whatever actions we deem necessary to ensure that you fulfill your duties as a responsible corporate citizen.

The states of New York and Wisconsin have announced that they are withdrawing from the controversial MATRIX interstate database program. MATRIX is the state level version of the now scrapped Total Information Awareness program, which had the aim of sucking in vast swathes of personal data on everyone, thereby enabling the computer to automatically pinpoint the terrorists in our midst.

It sounds a superfically and intuitively attractive prospect, until you think about it. What if the computer or the operator gets it wrong? Like I said earlier. Law enforcement is difficult. And, as H.L. Mencken said, "For every human problem there is a solution which is simple, neat and wrong." We're right back to the old theme which I seem to come back to repeatedly, the widespread

"Boys-Own blind faith of computing ignoramuses, like certain decision makers, in the ability of computers to automatically and magically make things better, regardless of the overall objective or the suitability of the tools (computers) to the task or [critically] the way in which those tools are deployed, drives me nuts on a daily basis in my own day job. That it is happening in so important a context " as [choose your own context - in this case I choose 'law enforcement'] "is worrying in the extreme"
Ernest Miller is well worth reading on the problems law enforcement authorities have in surveilling the Net. The FBI are seeking to expand Carnivore. Miller's repsonse? They're onto a hiding to nothing because of the architecture of the Net.

"The amount of intervention in technology development necessary for the FBI and DOJ to accomplish what they want with regard to wiretapping is enormous. The costs will be both direct (money out of consumer's pockets) and indirect (loss of innovation). However, that is only half the picture. Unfortunately for the FBI, the costs to defeat the wiretapping are relatively small and will continue to decrease. We have here an asymmetric situation that will only grow more asymmetric as time goes on.

The problem is with the underlying architecture of the internet. Advances in technology along with the end-to-end/layers principle mean that it will always be cheaper to add encryption to the edges of the network than to increase the amount of surveillance at the center of the network. How much does it cost to write an encrypted VoIP app? Not much. How much does it cost to build the surveillance mechanism and conduct the surveillance across all possible ISPs? A heck of a lot more.

Ok. Now that the first encrypted VoIP app is compromised ... how much will it cost to build another encrypted layer on top of the first one? How much will it cost to conduct surveillance on this new layer? Hmmmm, if this progression continues, as we add additional layers of encryption and surveillance, the costs will increasingly diverge. Not a game you can win ultimately. In fact, it doesn't make much sense to even start. The FBI should be happy with what they've got...

...If I were the FBI, I wouldn't waste my time on a battle I ultimately couldn't win and instead would concentrate my efforts on the place where I could still achieve my goals - the ends. You want to know what someone is up to online? I would recommend, for example, key loggers, "real" spyware, and social engineering. It ain't gonna be easy, but you have a chance of winning in the long term. The sooner you quit a race you can't win, the faster you can enter a race where you have a chance."

He's got a point but it's one that takes longer than three seconds to grasp, so I don't see the politicos getting it any time soon. It's easy to spend lots of money and say we are spending lots of money fighting crime, and spin an illusion that such tactics work. It's hard to do the kinds of things Ernest is talking about and there are no simple tick box targets to wave in front of the media to illustrate success.

But law enforcement is hard.
Back to one of my hobby horses of recent times and a Wired report, Legislators Urge E-Voting Halt.

"State Sens. Don Perata (D-Oakland) and Ross Johnson (R-Irvine), the chairman and vice chairman of the Senate election committee, sent a letter to Secretary of State Kevin Shelley urging him to decertify all paperless touch-screen voting machines before the general election...

..."California has a lemon law that protects consumers if they buy a bad car," Johnson said at the press conference. "So far, e-voting in California is a lemon." He said Californians should demand no less oversight for voting machines."

Usually I hate soundbites. That one, I like.
The NYT reported on Friday that Microsoft has been encouraging big investment in SCO. There has been a fair degree of speculation about this ever since SCO launched their legal campaign against linux but the NYT have seen an email with specifics. Interesting, though hardly earth shattering.