Thursday, May 13, 2004

In the Guardian,

"Brian Hadfield, the managing director of Unisys UK, a
US-based technology company that has worked on national
identity schemes in South Africa and Malaysia, questions the
usefulness of an ID card in countering the terror threat."


San Bernardino County in California are reportedly planning to defy an order by the Secretary of State banning the use of specific electronic voting machines in the presidential election in November. The county uses Sequoia machines, though, so I didn't think the order affected them anyway.
Brendan O'Neill at Spiked has a conspiracy theory in his sights about the leaking of the torture photos from Abu Ghraib prison in Iraq.

The photos from Abu Ghraib may have only recently been published
but many in the American media have known of their existence for
months...

... Whether or not it was military figures in the Pentagon who leaked the
photos to the press, some of them have certainly used the ensuing
scandal to launch attacks against the civilian leadership in the
Department of Defence over the war in Iraq, specifically against
Donald Rumsfeld. One 'senior general at the Pentagon' told the
Washington Post: 'I do not believe we had a clearly defined war
strategy…. [Rumsfeld] refused to listen or adhere to military advice.'
A special forces officer said: 'Rumsfeld needs to go, as does Paul
Wolfowtiz [Rumsfeld's deputy].' (14)

In an unprecedented move, the Army Times, the US military
newspaper that gets distributed to American forces around the
world, published an editorial in the wake of the torture scandal calling
for Rumsfeld to resign, describing the torture scandal as 'a failure of
leadership from start to finish'. "
From James Heald of FFII:

"See stories on the FFII 'breaking news' wiki at
http://kwiki.ffii.org/SwpatcninoEn


* Luxembourg has called in the text. There /will/ now be a
round-the-table discussion of it by the ministers.

It will now /not/ be taken as one of the 'A items' nodded through
en-bloc at the start of the agenda.


* The leading German official has confirmed Germany still opposes the
proposed text.
http://kwiki.ffii.org/?DemoBerlin040513En


* Belgium and Slovenia are also likely to follow Germany on this.


* Poland: Richard Stallmann and others have made a big impact at a
lengthy session in the Polish parliament.

Previously Poland appears to have been keeping its head down.


* France: Le Monde has reminded the French president that he had
previously promised to opposed software patents, before the French
presidential election in 2002

http://www.weblmi.com/news_store/2004_05_12_Bataille_sur_les_bre_18/News_view



The issue is very much "in play".



===================================================================

In the UK and Ireland, our best chance I think is to try to convince the
powers that be that the proposed draft will simply not go through the
European Parliament, however much the Patent Office is pushing for it,
because it gives *nothing at all* in the three most important areas
where the Parliament expressed concern:

-- *nothing* to give explicit reassurance that ordinary discussion of
algorithms in the form of code fragments will not be silenced by program
claims. (article 5.2). A provision that such discussion should be
considered 'fair use' would at least offer an olive branch here.

-- *nothing* to prevent dominant patent owners locking out specific
competitors for interoperability by refusing patent licences, short of a
full-scale EU Competition commission investigation. (article 6a). (The
EP wanted to allow automatic unfettered use. As a compromise Denmark
has suggested creating new fast-track procedures to allow compulsory
RAND licensing -- but this is rejected in the Irish draft)

-- most importantly, *nothing* to clarify what should be considered
"technical". The EP wanted a reference to "control of the forces of
nature" as the acid test, and a statement that the mere processing of
data is not technical.(articles 2, 3a and 4). But all the EP's
amendments in this area are rejected.


Past UK case law also supports the idea that methods which merely
address generic data relate to "computer programs as such", and only
become technical if the data has a specific technological relevance
beyond this; thus the current Patent Office manual states:

"1.26.4 The reference in Merrill Lynch to Vicom involving an
increase in speed (see 1.26.2) does not mean that an increase in speed
of itself is enough. This point was considered in Options Clearing Corpn
Inc's Application (unreported) when the hearing officer concluded that
Vicom was allowable because it produced an advance, namely an increase
in speed, in a technical field, namely the technical field of image
enhancement, and not simply because of the advance itself".

This principle should be upheld; but the EPO is already granting patents
far beyond this.

The European Parliament proposed a specific amendment that a mere
increase in the speed of data processing should not of itself be
considered technical; but this amendment is also to be rejected.


If the Council makes no attempt to engage with the Parliament on any of
these concerns, it seems quite likely to lose the entire Directive."

Bertie and the boys (i.e. the Irish government), as they say in Ireland, may not have as smooth a ride on EU software patents as they expected.

Wednesday, May 12, 2004

Eolas strikes back; Microsoft prepares appeal
Story speaks for itself.
BIPlog reports on self destructing DVDs.

"What's the latest way to access expression in the film world? EZ-D, a DVD "purchase" with a timeclock that allows you to
watch the movie as many times as you want for 48 hours, then poof! -- the work disappears.

Question is, how happy are we about moving to a model where we buy things for two days at a time? Should we let the line
between ownership and not be so E-Zly blurred? Are imploding expressive goods a good idea?"
Clay Shirky thinks Groklaw may be the MVP in the SCO v IBM linux legal dispute.

"GrokLaw: MVP of the SCO Wars

Liz has convinced me that one of the most profound effects of weblogs is the communal workings of those who publish them,
and that they contribute significant new value to collaboration across disciplines and boundaries...

...By way of background, SCO, once a technology company,
has become a company devoted to a single legal strategy:

1. Assert rights to the Unix operating system
2. Assert infirnging contributions of Unix source code to Linux
3. Sue firms that sell or use Linux, especially deep-pocketed IBM
4. Profit!!!1! (or at least buyout by IBM, to save them the expense of the suit.)

Much of the matter is in dispute, and IANAL, but what is clear is this: a) many SCO employees contributed to the Linux kernel, back when SCO was a tech company (“oldSCO”), with the approval of their bosses, and b) the Groklaw is doing an astonishing, world-changing job of finding, documenting and publicizing these occurrences (alongside much other work on the case.)

Today’s entry reads:
Groklaw has reported before on contributions made to the Linux kernel by Christoph Hellwig while he was a Caldera employee. We have also offered some evidence of contributions by oldSCO employees as well. Alex Rosten decided to do
some more digging about the contributions of one kernel coder, Tigran Aivazian.

[…]

This paper is a group effort. Alex’s research was shared with others in the Groklaw community, who honed, edited, and added further research. Then the final draft was sent to Tigran himself, so he could correct and/or amplify, which he has done. Look at that second graf: “This paper is a group effort.” Everyone always says that about complex work, but this is different. This is the end of two-party law, where plaintiff and defendant duke it out in an arms race of $350/hr laywers and “Take that” counter-motions.

Instead, we have a third party, Groklaw, acting as a proxy for millions of Linux users, affecting the public perception of the case (and the outcome SCO wants has to do with its stock price, not redress in the courts.) Groklaw may also be affecting the case in the courts, by helping IBM with a distributed discovery effort that they, IBM, could never accomplish on their own, no matter how may lawyers they throw at it.

There are two ways to change the amount of leverage you have. The obvious one is to put more force on the lever, and this is what SCO thought they were doing — engaging IBM in a teeter-totter battle that would make it cheaper for IBM to simply buy SCO.

The other way to get more leverage is to move the fulcrum. Groklaw has moved the fulcrum of this battle considerably closer to SCO, making it easier for IBM to exert leverage, and harder for SCO to. I can’t predict how the current conflict will end, but the pattern Groklaw has established, of acting on behalf of the people who will be adversely affected by a two-party legal battle, has already been vindicated, even if SCO avoids bankruptcy."

How the Net can make a difference.
Straight from the Source: Perspectives from the African Open Source Movement. Highly recommended. If you can't manage the full 17 pages, at least read the summary. Extract -

"For a software developer working in Africa, Philip Mbogo's problem is as basic as it gets: "I don't have a computer," he said. "I have to go for unpaid work in order just to get on a computer." Internet access is also an expensive rarity, so he counts himself fortunate to work as an intern at an Internet service provider where he takes as much advantage of the bandwidth as he can. "Anything I can get I download. I even got [a Linux distribution called] Debian, which takes two days [to download]."

African software developers face many obstacles as they struggle to work in this field. But these "coders", as a group, form a community marked less by their frustration and isolation than by their perseverance and resolve. This theme dominated AfricaSource, a workshop held in Namibia in March 2004 and organised by the Tactical Technology Collective, AllAfrica Foundation and SchoolNet Namibia. The meeting in the small town of Okahandja of 40 software developers from 25 countries was for many the first chance to collaborate and compare notes.

Lack of access to the means and tools of production is the issue African programmers most commonly identify as the greatest barrier to success in their work. But at this event, coders got a chance to share the innovative ways they work around the problem. "We buy computer parts bit by bit. In the space of three or four months we have a computer," says Ayeni Samuel Olaoluwa, a web developer from Nigeria, who saves up to 50% this way. Another method he has devised is keeping his freelance clients' work on computers he uses as part of his day job. "I am able to hide stuff on the server, but when I leave the company I'm in trouble."

The prohibitive costs of bandwidth and hardware are an obstruction most programmers face, but it affects coders most seriously at the time they are preparing to enter the job market. Without the opportunity to earn salaries that would help them afford equipment of their own, ambitious market entrants eager for work face the prospect of successive, often unpaid, internships just to prove their skills.

This predicament is widespread across Africa, says Ghanaian Guido Sohne, "There are not enough projects available to work on to employ the available talent…. In most African countries IT is not part of the economic production process. It's actually more expensive to computerise your accounting system than to hire more people to do it manually." So when programmers do find jobs, a large percentage tend to find themselves ushered into system administration and technical roles, where they are overworked and their skills are underutilised."

I complain that my office desktop computer crashes half a doxen times a day. I at least have the access and can always revert to the laptop when the inevitable Micrsoft blue screen of death makes its regular appearance.
Ed Felten points to an op ed piece in CSO magazine by Simson Garfinkel that demonstrates, yet again, how careless we are in our use of computers.

"A FEW YEARS AGO, when
I was in Silicon Valley with
nothing to do, I stopped by
one of the valley's famed
stores that sell used and
"recycled" computers...

...But the real treasure trove that day wasn't on the store's display shelves; it was in the
warehouse. The cavernous space out back had several shelves stacked high with old hard
drives, each $5, "as is and untested," according to the sign...

...I bought 20 of them.

I took the drives home and started my own forensic analysis. Several of the drives had
source code from high-tech companies. One drive had a confidential memorandum
describing a biotech project; another had internal spreadsheets belonging to an
international shipping company.

Since then, I have repeatedly indulged my habit for procuring and then analyzing
secondhand hard drives. I bought recycled drives in Bellevue, Wash., that had internal
Microsoft e-mail (somebody who was working from home, apparently). Drives that I
found at an MIT swap meet had financial information on them from a Boston-area
investment firm. Last summer, I started buying drives en masse on eBay.

In all, I bought and analyzed the content of more than 150 drives with the help of Abhi
Shelat, another graduate student at MIT's Laboratory for Computer Science. We found
that between one-third and one-half of the drives still had significant amounts of
confidential data, even though many had been through a Format or FDisk operation. On
another third, someone had deleted the document files but left the applications behind. It
was a simple matter to undelete the data files and retrieve their secrets as well.

In fact, only 10 percent of the drives I purchased had been properly sanitized.

Much of the data we found was truly shocking. One of the drives once lived in an ATM. It
contained a year's worth of financial transactions—including account numbers and
withdrawal amounts—from a organization that had a legal requirement to not divulge such
information. Two other drives contained more than 5,000 credit card numbers—it looked
as if one had been inside a cash register. Another had e-mail and personal financial
records of a 45-year-old fellow in Georgia. The man is divorced, paying child support and
dating a woman he met in Savannah. And, oh yeah, he's really into pornography...

...Perhaps the saddest observation in our story is that erasing information from hard drives is
not difficult—with a little bit of Web searching, we found more than 50 programs that
purport to clean your hard drive so that the information on it cannot be recovered using
even the most advanced technical means...

...One key reason for today's poor disk sanitization practices is that it's very difficult to tell
the difference between a disk that has been properly sanitized and one that's simply been
reformatted...

...Another reason, we suspect, is that most people don't appreciate
the risk—the used-computer market is literally awash with
personal information from businesses and individuals, yet there
are relatively few cases of that information being used for
nefarious purposes."

ON the latter, it's only a matter of time. Garfinkel concludes:

"In the end, preventive technology is a better solution to the sanitization problem. If you use an encrypted file system, you can sanitize a disk simply by erasing the key. I'd like to see that sort of technology built in to hard drives. Or better, perhaps someday soon, all disk drives will come with a self-destruct feature—just like Star Trek's Enterprise did!"
Avi Rubin has had recent first hand experience of being on the receiving end of a false positive experience at an airport in California. The equipment detected non eixistent explosives in his belongings.

Prof Rubin also points to a slighly longer version of the hilarious clip from The Daily Show at Comedy Central on electronic voting.
I always seem to come away from reading Noam Chomsky's ideas with deep concerns about the world we live in and that which our children are inheriting. This essay in the aftermath of the September 11, 2001 tragedies, invokes just those feelings. The mere mention of Chomsky causes some people to foam at the mouth, but even when I can't accept his theses, reading them is enlightening if also anxiety and depression inducing!
Donna is pleased that the antidote to the DMCA is getting a hearing on Capitol Hill.

Fair Use Gets Fair Play on Capitol Hill

This Wednesday, May 12th, marks the first time since the DMCA was enacted in 1998 that Congress will hold hearings on
legislation to reform it.

The Digital Media Consumers' Rights Act, or DMCRA, has three important goals:

#1: Warning: You're About to Pay Full Price for a Hobbled CD

The DMCRA would require labels on copy-protected "CDs," letting us know that we can't actually use what we've purchased
except under limited circumstances. That's right -- you get advance warning that you're paying the same price for less
functionality.

#2: You Get to Reclaim Fair Uses of Digital Media That You Already Have in Analog Media

The DMC_R_A would put the Rights back in the DMCA. The bill amends the DMCA to allow you to circumvent copyright
controls on digital media for legitimate purposes -- for example, to make the fair uses that copyright law ordinarily and
traditionally allows.

Among other things, this would mean that:

a.) when most scholarly communication, publishing, instruction etc., takes place using digital media/online, our ability to share
knowledge and learn from one another won't be a distant and fast-fading memory;
b.) when researchers want to "tinker" to advance our scientific knowledge, they won't face a significant barrier -- like the
repeated threat of litigation; and
c.) when librarians seek to preserve our history in digital media, they won't have to wait three years at a time to beg the
Copyright Office for the narrowly defined technical ability to do so.

#3: These Will Be Real, Not Phantom/Illusory Fair Use Rights

The DMCRA would affirmatively allow the creation/distribution of devices that circumvent copyright controls, when the devices
have substantial non-infringing uses. That means inventors will be able to invent the next VCR or TiVo without asking
Hollywood's permission first. And if a researcher has created a circumvention tool for the purposes of researching/testing
web-filtering mechanisms, the researcher won't be limited to describing the controversial results. He or she could share the tool
with the scholarly community.
Cory Doctorow is lamenting, along with numerous others, the current state of play (or possibly more apt not-play) on the gadget side of Sony's business.
Waldon O'Dell, Diebold's CEO, today admits in the NYT that he made a "huge mistake" last year in declaring he wanted to deliver the election for George Bush. He's getting out of politics and planning to stay out as long as Diebold are in the voting machine business. Good for him.
The Washington Post, last week, had a good article on the electronic voting shenanigans in the US. There was nothing new in it but lots of useful links to related stories.

There are lots of very experienced election registrars genuinely supporting electronic voting and suggesting there has been too much focus on the tecnology and not enough on the overall election process, which has other built in safeguards, not least of which are vast numbers of dedicated election officials of impeccable integrity. Whilst I understand that point of view and the need to 'get the job done', whilst critics complain about 'hypothetical scenarios that have never happened', there have been significant failures with these machines. Officials who have not experienced such failures believe that they will not happen on their watch. But the security of the system is only as good as the weakest link and at the moment the weakest link is the technology, as has been repeatedly demonstrated.

Folk like Avi Rubin and David Gill really do understand the technology. With people of that calibre saying it neither implements security that is possible nor even implement security safeguards that are easy, we should be taking serious notice. Deploying technology in such a mission critical way fundamentally requires an understanding of that technology.

Whilst I have every sympathy with election officials, I have none at all for those like the Information Technology Association of America (ITAA - the trade association representing amongst others, surprise suprise, the electronic voting machine vendors) spouting complete nonsense like "Electronic voting systems work, and work well. Our recent survey shows that over two thirds of Americans believe that electronic voting is a secure, reliable way to conduct elections." This reminds me of the line from one of my favorite BBC TV shows of all time, Yes Prime Minister where Sir Humphrey Appleby is persuading the Prime Minister that he should invest in Trident: "It's the biggest and the best and the British people must have the best." Also the following sequence where Sir Humphrey and Bernard are discussing opinion polls:

Bernard: "He thinks..he thinks it's a vote winner."

Sir Humphrey (Sir H).: "Ah, that's more serious. What makes him think that?"

Bernard: "Well the party have had an opinion poll done. It seems all the voters are in favour of bringing back national service."

Sir H.: "Well have another opinion poll done showing the voters are against bringing back national service."

Bernard: "They can't be for it and against it."

Sir H. : "Oh of course they can, Bernard. Have you ever been surveyed?"

Bernard : "Yes. Well not me actually, my house. Oh I see what you mean."

Sir H.: "Well Bernard you know what happens. Nice young lady comes up to you. Obviously you want to create a good
impression. You don't want to look a fool, do you?"

Bernard: "No."

Sir H.: "No. So she starts asking you some questions. Mr. Wooley, are you worried about the number of young people without
jobs?"

B: "Yes"

Sir H.: "Are you worried about the rise in crime among teenagers?"

Bernard: "Yes"

Sir H. "Do you think there is a lack of discipline in our comprehensive schools?"

Bernard: "Yes"

Sir H.: "Do you think young people welcome some authority and leadership in their lives?"

Bernard: "Yes."

Sir H.: "Do you think they respond to a challenge?"

Bernard: "Yes."

Sir H: "Would you be in favour of re-introducing national service?"

Bernard: "Y… oh ..well I suppose I might be."

Sir H.: "Yes or no?"

Bernard: "Yes"

Sir H. : "Of course you would, Bernard. After all you've told you can't say no to that. So they don't mention the first five
questions and they publish the last one."

Bernard: "Is that really what they do?"

Sir H.: Well no not the reputable ones no but there aren't many of those. So alternatively the young lady can get the opposite
result."

Bernard: "How?"

Sir H.: "Mr Wooley, are you worried about the danger of war?"

Bernard: "Yes"

Sir H. : "Are you worried about the growth of armaments?"

Bernard: "Yes."

Sir H. : "Do you think there is a danger in giving young people guns and teaching them how to kill?"

Bernard: "Yes."

Sir H. : "Do you think it is wrong to force people to take up arms against their will?"

Bernard: "Yes."

Sir H.: "Would you oppose the re-introduction of national service?"

Bernard : "Yes."

Sir H. : "There you are you see, Bernard, the perfect balanced sample. So we just commission our own survey for the ministry
of defence. See to it Bernard."

The Boston Globe has picked up the story of the arrest of Japanese professor, Isamu Kaneko, over file sharing software Winny.

Tuesday, May 11, 2004

John Lettice is on the ID card case again at the Register, this time pointing out that Department for Homeland Security and a biometric company, Identix, which is is also supplying equipment for the UK Passport Service's ID card pilot, are on the receiving end of a lawsuit in the US. Two men are suing for slander and product liability as the Identix system helped to give them other people's criminal records.

One of the men actually got jailed for being a convicted felon carrying a gun, despite the fact that the crime on his record had been perpetrated by someone else who even had a completely different name, Kellogg as opposed to Benson.

How could that happen? Especially when UK Home Secretary, David Blunkett, seems to believe these seems are "impossible" to fool. It seems Benson had been fingerprinted for a traffic violation. Kellogg convicted of multiple crimes. But the admin number on their respective electronic fingerprint cards was accidentally duplicated. And when the records were entered on the criminal justice database, Benson got credited with Kellogg's crimes.

As Lettice concludes:

"For the rest of us, the real issue is how fallibility in software and human input can produce
extremely serious errors in systems which are intended to provide virtually infallible
identification. There is here no dispute that Benson's and Kellogg's biometric records are
entirely different (Benson has only nine fingertips, for starters), but the processes operated
in such a way that Benson's record got the convictions. These spread from Oregon to
California, and Benson's attorney claims that he is still recorded by the FBI as having
been arrested as a felon in possession of a firearm.

Organisations deploying such systems should of course be extremely concerned that they
are not subject to such errors. Aside from the impact on the victims, the creation of false
records will damage the integrity of the database they're used in initially, and the sharing of
this data will result in the corruption spreading into other systems. The further it gets, the
harder it will be to undo the damage. But the more sure the designers are that they've
ruled out problems like this, the harder it will be to have errors corrected. If it's
impossible, then the people complaining have got to be mad, right? The issue of how you
deal with the data is actually far more important than getting the technology to produce a
"unique" biometric."
Jonathan Wallace is fretting about president Bush again:

"Harry Truman understood that authority and responsibility are one, that they must lie in the same place. He put a sign on his desk that said, "The buck stops here." ...

...George Bush does not understand. It is impossible to determine where, if anywhere, in this administration the buck actually stops. The President too often seems to be the child of his vice president, Dick Cheney. The fact that they will be appearing together before the 9/11 Commission is not confidence inspiring. It is almost certainly planned this way so that Cheney can interrupt the president if he starts to blither...

...John later asks the president what his biggest mistake has been since September 11. "In the last campaign....you used to like to joke that it was trading Sammy Sosa."

And the President, God help us, replies:


Hmmm. I wish you'd given me this written question ahead of time so I could plan for it....I'm sure something will pop into my head here in the midst of this press conference with all the pressure of trying to come up with an answer, but it hadn't yet.
Which is why they won't send him before the experts on the 9/11 Commission without Dick Cheney there to interrupt and talk over him whenever necessary.

While we are all sweating it out, waiting for something to pop into the president's head, ask yourself the very serious question: where does the buck stop in this administration?"


Out-Law reports on the UK government's proposals for a national ID card: ID Card Database emerges from the shadows

This piece nicely reminds us that in its original consultation exercise on what David Blunkett was then calling an "entitlement card" the government said “it is most unlikely that entitlement information relating to specific services would be held on the central register” which, of course, is the complete opposite of what it says in the draft bill on the subject published last week.

Chris Pounder of Masons (who also publish Out-Law) says:

“The Government’s proposals, if enacted in their current form,
could amount to the lawful, secret, unrecorded access by the
police and security services to centralised details which could,
over time, list all the important public and private services used
by each card-holder during his or her life-time”.

“This raises very serious and new privacy concerns about the
central registry database, as the two Commissioners charged with
protecting privacy in the ID Card scheme could be in the dark
about the volume and nature of the access requests to the central
registry database by the security service and police."

A society where we can map anyone in detail but not monitor everyone in detail. Hmmm, now where have I heard that one before?
Ian Brown at FIPR has pointed me at a piece by Toby Young in the Times where he considers the downside of recording the minutiae of life, which is now (naturally) facilitated by technology.

THE first law of technology is: anything personal
invariably becomes public. So it will be with the
SenseCam, a miniature camera that can record a
person’s entire day and store it in a computerised
diary. Developed by Microsoft’s British engineers,
the SenseCam will allow us to keep our entire lives
on disk. What a treasure trove of memories!
Alternatively, what a catalogue of indiscretions for
others to peruse! "

"It is only a matter of time, probably after some
horrible and shocking event, before Parliament
sets up a Department of Personal Records
requiring citizens to download their weekly
behaviour on to a national database. Strictly in the
interests of national security, of course."

"There is a second law of technology: it goes wrong"

He should have added that the third law of technology is that we use it unthinkingly and carelessly leading to adverse emergent properties...

I had a bad day in the office yesterday, when I was supposed to be on study leave, sorting out some difficulties with the new electronic computer marked assignment for my Internet law course. (Difficulties created by a completely avoidable accumulation of minor errors which the system then made difficult to correct and leading to the perception of a right-and-left-hands communications breakdown).

Monday, May 10, 2004

Academics Patent P2P Spoofing That shoudl provide some fun.
More academics as criminals news from Slashdot. An assistant professor of computer science at the University of Tokyo has been arrested for encouraging copyright infringement. He created P2P software 'Winny' based on Freenet, which unfortunately for him it seems, became rather popular.

I wonder how much this arrest might be related to some sensitive Japanese police information getting distributed round the Net via Winny? Or whether this may have been a minor contributory factor in the decision to make the arrest? I'm sure most of us would be annoyed if sensitive information from our systems got p2p'd in a widespread fashion.

This might be an interesting case to watch, especially since the Japanese have a more relaxed attitude to copyright infringement, at least when it comes to comics. That's, no doubt, an unfair generalisation, as comics are a pretty specific area but then, as an old college friend of mine used to delight in pointing out, generalisations are generally wrong.
The UK chancellor is apparently going to spend £150 million this summer with a view to expanding evoting.

“E-voting is a key measure to tackle so-called disengagement among young people,” said a Whitehall source. “Given the rapidly increasing use of text messages it is crucial that this is properly developed as a method of voting.”

Let's get the Big Brother and Pop Idol fans on their mobiles and that will solve the electoral participation crisis.

Give me strength. I'm seriuosly tempted to change the title of my book to Technology is The Answer to Everything (And The Eegits who believe this).
Frank Field's latest contribution to the DRM debate - DRM is a folding chair.

"Here’s the real point – the folding chair really draws its effectiveness from the cultural norms that have built up around
it. An experienced Cambridge driver knows not to mess with a parking space that has a folding chair in it, even though she/he
has never experienced the consequences that I describe above. Speaking personally, I can’t name a single person who has
actually had this problem, but every Cambridge resident collectively knows that it would happen — even though a folding chair
is, practically speaking, a completely ineffective limit on the use of a parking space."

Friday, May 07, 2004

Frank Field on cynicism.

"DRM is part of a process to break us of the nasty habit of thinking culture is a common good. Like a speed bump, it’s not about making us stop; it’s about making us recognize that someone thinks what we’re doing is wrong. And then usingour own naïvité to get us to stop. "

Makes me feel better that I'm not necessarily being "cynical", in the OED sense of the word, just attributing self serving motives to politicians and lobbyists.
There's a fascinating exhange of views going on between Ernest Miller, Ed Felten, and Frank Field on the subject of DRM, the broadcast flag and the copyfight in general.

Ernest believes bright people pushing for drm and other expansions of intellectual property rights have got a hidden agenda because they basically can't be stupid enough to really believe drm is going to prevent copyright infringement. So they must have a hidden agenda.

Ed says the some of folk pushing this agenda that he has discussed the issues with are passionate about what they are doing, really do believe it will work and needs to work in order to balance all the interests involved.

Frank partly supports Ed in suggesting we should never underestimate the power of ideology.

"The fact that "the road to hell is paved with good intentions" derives from the fact that, in order to function in an increasingly complex world, everyone is forced to construct simplifying models of the way that the world works. When these models (a)
work and (b) are buttressed with rationalizing arguments, we get something more potent - an ideology.

The problem with ideologies is that, even though they work, they rely upon simplifications that will not obtain over time. These simplifications will eventually be the downfall of the ideology, but sometimes it takes a very long time before the failure of the ideology is recognized, meaning that a lot of bad (and potentially quite destructive) decisions get made in the interim...

Ernest is right; our opponents are not (all) stupid people. But they don't have nefarious ends. Rather, they're acting within the confines of the ideologies that they believe explain the way the world works. They aren't evil or stupid; they're just confused and frustrated. The old methods aren't working, even though they *know* their methods are "right." In fact, they're in exactly the same boat that we are. And we know we aren't evil.

Ideologies are hard to defeat, because they're invisible to those who hold them. To us, it's an ideology; to them, it's "the way the world works." Beating it will take time, being honest about what is happening and working really hard to devise a new way of looking at the world that we can collectively agree upon.

We can't afford to write them off as "evil." That's seductive, but dangerous because it simply isn't true. They're just doing what they think is right. We have to respect that as we work to show them that they're mistaken. "

Siva Vaidhyanathan makes some related commentsat the Lessig blog in telling the story of meeting someone who takes the view of "the other side". Some who thought Larry Lessig was "a kook". Siva now reckons elements on the two sides are beginning to understand each other because those pusshing for expanded protection of intellectual property rights are resorting to ad hominem attacks. Adn they are doing this because the Lessig's of the world are winning the argument. Interesting theory but as Seth Finkelstein says in commenting on Siva's post,

"Unfortunately, yes, I think you hang around too many people who actually read the books they criticize. You're a professor. Academics are *supposed* to be polite. Not that they always are. But there is a strong cultural belief there, as evident in what you?re writing, that ad-hominem arguments are "wrong". Again, it may be honored more in the breech than in the observance, it may be an ideal not always practiced, but it's part of the formal codes of conduct.

Hang out with lawyers and lobbyists and politicians more. To them, lying and smearing and ad-hominem attacks are *tactics*, debate *options*. Whether they use those approaches depends entirely on whether they think they can get away with it, that it'll work with the audience. It's a pure strategic calculation. They may decide they'll look bad if they lie. They may decide it's worth it. Situations vary. But the truth or intellectual strength of the argument bears a very tenuous relationship to the approaches employed.

I certainly don't see any change at all, in terms of Jack "Boston Strangler" Valenti style rhetoric.

And remember, a mosquito is slammed hard, but that doesn't mean it's powerful and influential.

So you can't derive "panic" from any of it. It may be that you just happened to run into a few people who think meanness is the way to go.

If the courts had been rebuffing the copyright extensions and the DMCA, then there might be panic. Otherwise, it's simply tactics."

James Heald of Foundation for a Free Information Infrastructure (FFII) tells me that the Irish presidency of the EU are bypassing all the EU parliament and other objections to software patents and doing an end run round a vastly watered down software patents directive proposal.

"The powerful COREPER committee of EU member states' Permanent
Representatives in Brussels has provisionally agreed on a new draft for
the controversial Software Patent directive, overruling concerns from
the German, Belgian, and Danish delegations, and the Slovakian
non-voting observers. (The new accession countries only become full
voting members in November).

The new draft rejects all of the European Parliament's limiting
amendments, and is described by FFII as "the most uncompromisingly
pro-patent text yet".

The Coreper text also goes further than the original European Commission
text of 2002. In 2002 the Commission had agreed, in difficult
negotiations between DG Internal Market (Bolkestein) and DG Information
Society (Liikanen) not to allow program claims. Now it seems that DG
Information Society has rolled over to the united pressure of Bolkestein
and the Council's patent administrators.

A leaked document from Bolkestein's DG Internal Market suggests that DG
Information Society no longer objects to program claims. This concession
by Liikanen is needed in order to rush the Council working group
proposal through the ministers' session as an "A item", i.e. a consensus
point which does not need any discussion by the ministers.

Technically, the decision by COREPER on Wednesday is only a "forecast"
of the final decision, to be confirmed at the Competitiveness Council of
Ministers on 17-18 May. Until that date, Member states can still change
their minds (and their votes).

If confirmed by ministers, the text will form the basis for the
Directive's second reading in Parliament, after the EU elections. EU
rules make it far more difficult for the Parliament to make changes at
second reading.

Support for the text at a political level in some states is still said
to be quite soft; and decisions brokered in Coreper do fall apart (last
year's discussions on the Community Patent, for example).

FFII is therefore urging supporters to make their voices heard *now*,
especially software SMEs who make up the majority of the IT industry (eg
over 80% of IT jobs in Germany). In particular supporters should try to
mobilise organisations of which they are members, urgently try to meet
or contact local MPs and MEPs, and also Commissioner Liikanen's office
at DG Information Society."

Whatever your take on software patents, this is another example of the Irish presidency's slick understanding of and ability to exploit EU processes. As to their motivation, my perspective is that it is no more complicated than Bertie Ahern and co. wishing to be percieved as an "effective" presidency, "effectivenes" in this context being measured by how many things you get done, regardless of what those things are.

Boy I really am being cynical in the past couple of days. I should go an lie in a dark room and think about that book I should have been working on this week [and would have been if it had not been for my study leave being perpetually interrupted by administrative trivia].
The ACLU, EFF, ALA, CDT and PK have jointly criticised the proposed Fraudulent Online Identity Sanctions Act:

"... we write to express our concern that this bill will penalize and potentially jail Americans who seek only to protect their privacy and right to anonymous free speech online...

... The WHOIS database requires that individual Internet users, when they register domain names, make their names, home addresses, home phone numbers, and home email addresses available to the world, with no privacy protections. Users covered by this requirement include human rights activists, corporate whistleblowers seeking to avoid retribution, and ordinary Americans seeking to avoid spam, stalking or identity theft. As long as WHOIS lacks safeguards to protect their privacy and security these users will feel compelled to place inaccurate data in the database for reasons that have nothing to do with the furtherance of illegal activity.

However, HR 3754 would... create a presumption that inaccurately registered WHOIS data represents evidence of malicious intent... would make violations of copyright or trademark in conjunction with an inaccurately resistered domain "wilful," carrying the highest penalties, even if the activity were otherwise innocent...

... Under current law, the author of an anonymous web log who innocently quotes a portion of a news article that a judge later considers to be too long to qualify for "fair use" would be an "innocent infringer" and subject to reduced statutory damages. Under HR 3754 the same "blogger" would face damages up to $150,000 and potential criminal liability...

...Domain name holders who submit inaccurate WHOIS data: 1) on the basis of bona fide concerns with privacy, or 2) to protect their legitimate rights to anonymous free speech, should not be branded criminals."
The conflict between the Korean mobile phone companies and the music industry over Mp3 playing phones is getting worse. The music indsutry are threatening to get an injunction banning sale of the very popular phones.
The European Commission has proposed a new recommendation of the EU parliament and Council of Ministers on the protection of minors and human dignity and the right of reply in the European audiovisual and information services industry.

Thursday, May 06, 2004

Finally for today, Larry Page's and Sregey Brin's letter to potential Google shareholders in their registration statement with the SEC makes fascinating reading.

"Google is not a conventional company. We do not intend to become one...

...Eric, Sergey and I intend to operate Google differently, applying the values it has developed as a private company to its future as a public company. Our mission and business description are available in the rest of the prospectus; we encourage you
to carefully read this information. We will optimize for the long term rather than trying to produce smooth earnings for each quarter. We will support selected high-risk, high-reward projects and manage our portfolio of projects. We will run the company collaboratively with Eric, our CEO, as a team of three. We are conscious of our duty as fiduciaries for our shareholders, and we will fulfill those responsibilities. We will
continue to attract creative, committed new employees, and we will welcome support from new shareholders. We will live up to our ?don?t be evil? principle by keeping user trust and not accepting payment for search results. We have a dual-class structure that is biased toward stability and independence and that requires investors to bet on the team, especially Sergey and me.

In this letter we have explained our thinking on why Google is better off going public. We have talked about our IPO auction method and our desire for stability and access for all investors. We have discussed our goal to have investors who determine a rational price and invest for the long term only if they can buy at that price. Finally, we have discussed our desire to create an ideal working environment that will ultimately drive the success of Google by retaining and attracting talented Googlers. "

You don't see many IPOs running on the principle "don't be evil."
The NYT yesterday reported the large Canadian telcos' concerns about their future in the era of Net telephony. It's the standard fare about VoIP but worth a read.
John Lettice at the Register has been thinking about the UK government's draft bill and consultation [which, just as a matter of interest, is unreadable from the old computer I happen to be using at the moment] exercise on the national identity card.

After lots of analysis including genuine puzzlement as to how Mr Blunkett, the Home Secretary, really believes he can convince people that the ID cards will cost them £4, when they actually pay £35, he concludes with a question,

"So do you want this? It's a system that won't achieve most of its objectives, and those it will achieve will be achieved via massive overdesign (secure passport system? Here, take this networked database and personal information register to go with it). You get a personal ID card you don't need. You pay vastly more than you need to for the ID documents you do need. It only addresses the immigration problem (most of the British public sees immigration as a problem) if you pretend to love it and use it all the time, in all sorts of areas where you don't need it and it's inappropriate. And you get the free centralised database of your personal information anyway, providing a locus for any number of government and private databases of your personal information. Don't worry you've nothing to hide - even from your bank, other banks, loan sharks and double glazing salespeople, right?

It costs £3.1bn for all this cool stuff. At least. Go and tell the Home Office how much you support it, you've got until the 20 July, and you'll find a link to the consultation document below. If you happen to agree with any of this article, paraphrase it, don't just copy it. If you do they'll just mark you down as a petition signer and disenfranchise you, like they did with the Stand objectors in the previous "consultation.""

Consultation document.



U.S. Releases 2004 Report on Intellectual Property Protection.

Ukraine cited as "priority foreign country"

U.S. Trade Representative (USTR) placed 33 trading partners on the "watch list" for IPR violations: Azerbaijan, Belarus, Bolivia, Bulgaria, Canada, Chile, Colombia, Costa Rica, Croatia, Dominican Republic, Ecuador, Guatemala, Hungary, Israel, Italy, Jamaica, Kazakhstan, Latvia, Lithuania, Malaysia, Mexico, Peru, Poland, Romania, Saudi Arabia, Slovak Republic, Tajikistan, Thailand, Turkmenistan, Uruguay, Uzbekistan, Venezuela and Vietnam.

Another 16 trading partners are on the "priority watch list," which entails greater
scrutiny. Eleven of these -- Argentina, Bahamas, Brazil, EU, India, Indonesia, Lebanon,
Philippines, Poland, Russia and Taiwan -- were on last year's priority list. The other five
-- Egypt, Korea, Kuwait, Pakistan and Turkey -- were moved this year from the watch
list to the priority list.

China and Paraguay get warned they're facing imminent trade sanctions for IP violations.
It seems that the start of trial of of the ten thousand (i.e. biometric national ID cards in the UK) was delayed by three months because the technology didn't work. Now it is going to for last three months rather than the planned six months.

David Blunkett has said that although the pilot scheme was late, "it is important to get it right rather than get it quickly?". I see. It does n't work. So delay the start. Then cut the time for the trial in half in case people notice there are lots of problems with it. And then claim you're trying to get it right. This is a joke. Right?

Ok, call me a cynic again. Hey, that's twice in one day.
My colleague, John Naughton, pointed me at this 10 minute interview, where an MIT student quizzed Jack Valenti. Jack genuinely didn't seem to know there were no DVDCCA licensed linux DVD players on the market.

"TT: But today, you still cannot on the market actually buy a licensed DVD player for Linux.

JV: I didn?t know that.

TT: So the question is, do you think people who go to Blockbuster, they rent a movie, they bring it
home, and they play it on Linux by circumventing the access control, are those people committing a
moral transgression?

JV: I do not believe that you have the right to override an encryption. Because if you have the right
to do it, everybody can do it. For whatever benign reason you have, somebody else has got one
even more benign. But once you let one person deal in a digital copy -- and I don?t have to tell you;
you know far better than I that, unlike in analog, the ten thousandth copy is as pure as the original --
it is a big problem. So once you let the barriers down for your perfectly sensible reason, you gotta
let it down for everybody.

I don?t want to get into the definition of morality. I never said anything was immoral in what I was
saying. I said it is wrong to take something that belongs to somebody else.

TT: Indeed, but are you doing that when you rent a movie from Blockbuster and you watch it at
home? ... I run Linux on my computer. There?s no product I can buy that?s licensed to watch
[DVDs]. If I go to Blockbuster and rent a movie and watch it, am I a bad person? Is that bad?

JV: No, you?re not a bad person. But you don?t have any right.

TT: But I rented the movie. Why should it be illegal?

JV: Well then, you have to get a machine that?s licensed to show it.

TT: Here?s one of these machines; it?s just not licensed.

[Winstein shows Valenti his six-line ?qrpff? DVD descrambler.]

TT: If you type that in, it?ll let you watch movies.

JV: You designed this?

TT: Yes.

JV: Un-fucking-believable.

TT: So the question is, if I just want to watch a movie--I rent it from Blockbuster--is that bad?

JV: No, that?s not bad. "

Valenti is going to be a hard act to follow when he leaves the MPAA.
Microsoft have launched their Janus drm software.
California have allegedly toughened their stance on electronic voting. The devil is in the detail and I remain unconvinved this is anything more than political posturing at the moment, especially since California Secretary of State is reportedly calling Diebold reprehensible and calling for a criminal investigation of the company. Ok call me a cynic.

Meanwhile at least one county in California is suing the secretary state for the right to use electronic voting in the presidential election.
The Dutch data protection authority, CBP, have stated, that the Dutch entertainment industry's anti-piracy group BREIN's sharing of information [on file sharing] with US counterparts is in breach of Dutch data protection and privacy laws. Following on from the Dutch supreme court's decision in the Kazaa case, that won't make the Netherlands any more popular with the industry.
Nice profile of Avi Rubin and his stance on the electronic voting controversy at the NYT.
From the Scotsman via historian Professor Steve Hindle, Blunkett's 'Id Card' Was Around in 16th Century. Wonderful.
I've spent another couple days this week away from my office at the OU, helping some colleagues agree the final structure and content of our new cybervandalism course, T187. The facilities at the conference centre, Harben House, run by Initial, were fine. What did really irritate me, though, was trying to access my weblog from their internet cafe and discovering it was censored by their filter software, which declared that my thoughts here might be unsuitable for children.

Do contact them about inappropriate filtering, if you feel so inclined. I've complained and been told my complaint would be reviewed by a human being. I wonder how many other filter software packages block these pages, presumably because the url and blog title contain the letters 'xxx'?
I spent a couple of days in Barcelona last week, one at the terrific Univeritat Oberta de Catalunya (UOC), the virtual university, where I met a group of like minded enthusiasts for the deployment of technology in education, who actually understood what can and cannot be done with technology in that context.

I shouldn't be surprised at this but it is such a rarity in the thick of all the nonsense that gets talked, written about and done in the name of computers in education that it was an absolutely delightful day. UOC have grown from about 300 to 30000 students in about ten years. They have also in that time been learning the same lessons, as an institution, that those of us in the Open University in the UK who have been deeply engaged in deploying multimedia computer and Internet facilitated education with large numbers of students over a similar period have learnt about the potential, current limitations and practicalities of technological tools in an educational context.

I only hope our wonderful hosts, Sylvia Gonzalez and Ferran Gimenez Prado, found it as useful as we did.

Saturday, May 01, 2004

The NYT are reporting that the FBI were given millions of passenger records by airlines in the says after the September 11th tragedies. Seems like a pretty sensible course of action for the FBI to request such records given the circumstances. They used subpoenas, so it was all above board. The only question, I guess, is regarding the boundaries of the request and the quantity of information handed over. Apparently at least one airline provided a year's worth of records.

Monday, April 26, 2004

The ID card draft bill is proposing to create quite a few new offenses, like disobeying an order from the Secretary of State. I hope one of the draftsmen have put that in as a joke to test how well this thing is going to get scrutinised? Think of it - in a democracy there could actually be an offense of refusing to follow the orders of a public servant. It also includes little incentives like a £2500 fine every time someone fails to turn up for an appointment for a biometrics scan (Section 6(4)). Jailtime for having someone else's card in your possession (don't offer to look after a friend's belongings whilst they respond to the call of nature then). All this draconian stuff is just an initial extreme pitch, so that Mr Blunkett can be seen to be making "reasonable concessions" when the actual law gets passed. Simon Davies of Privacy International is right - this whole shambles is a "disgrace to democracy."
A draft bill for a national ID card is online. There are lots of stories round about the ID card in the UK press today. Ministers are peddling the usual propaganda in favour and by and large journalists are lapping it up unquestioningly. Regarding the test progamme with ten thousand volunteers I have mixed feelings. I'm irritated with it because it's a waste of money and primarily a PR exercise. But at the same time I think it's a good idea because proponents and ordinary people, to whom the idea is intuitively and superficially attractive, will finally get to see how bad this 'state of the art', 'impossible to fool' biometric technology is in reality. The Australians did an ID card trial in the 90s and quietly abandoned the notion, having discovered how many problems it caused. Let's hope the UK version goes the same way
On the day that the UK government launch their controversial pilot national ID card scheme with ten thousand volunteers, Privacy International have released an interim report on a study of the connection between ID cards and preventing terrorism. Not surprisingly, "Mistaken Identity; Exploring the Relationship Between National Identity Cards & the Prevention of Terrorism" concludes that ID cards do not help to prevent terrorism.

Friday, April 23, 2004

NYT: Pentagon Ban on Pictures of Dead Troops Is Broken
EUpolitix has a succinct report on MEPs taking on the Commission and the US over the deal on the transfer of airline passenger data.

Thursday, April 22, 2004

Brad Templeton, chairman of the EFF, amongst other things, has produced a thoughtful analysis of the 'GMail Saga'.
The Bush administration is apparently proposing to give ally countries another 2 years to devop biometric passports. Secretary of State Colin Powell says

"Rushing a solution to meet the current deadline virtually guarantees that we will have systems that are not operable... Such a result may undercut international acceptance of this new technology as well as compound rather than ease our overall challenge."

The European Commission have issued a Communication on the Management of
Copyright and Related Rights
. In it they eulogise digital rights management (DRM) as the solution to all ills of the copyright variety, most specifically this time royalty collection agencies problems. What is it about biometric national ID cards, DRM, RFIDs, electronic voting machines, computers, technology in general that make them superficially attractive solutions to everything? The right technology appropriately deployed can be a terrific boon but why can't people understand that it is not usually a particularly good idea to start with a [technological] 'solution' and then go looking for a problem, just so you can use the 'solution'?
A Barcelona night club is allegedly implanting RFID chips in VIP customers so they don't need to worry about carrying a wallet about. No comment.

Tuesday, April 20, 2004

Despite the pending lawsuit against ClearPlay and others by the Directors Guild of America and the movie studios, it appears as though Walmart is going to be selling DVD players with ClearPlay filters built in. I wonder what the demand will be like and how that will affect the dynamics of the court case?
The United States Institute of Peace, which I admit I'd never prviously heard of, have issued a paper saying terrorists use the Internet too but for more routine activities than the hyped-up cyberterrorism feedstuff of the mainstream media. Terrorist organisations are said to have three major audiences:
Current and potential supporters
International public opinion
Enemy publics (i.e. citizens of states they are fighting)
and use the Net in 8 different (sometimes overlapping) ways:
Psychological warfare
Publicity and propaganda
Data mining
Fundraising
Recruitment and mobilisation
Networking
Sharing information
Planning and coordination

The report does imply that steganography is in widespread use by terrorist organisations but there is no direct evidence offered to that effect. The mainstream media has periodically salivated at the notion of religeous fundamentalist terrorists hiding messages in online porn but no evidence to that effect has been forthcoming. Being only 12 pages long the paper is just an overview I assume but it might be interesting to hear more details of the study.
Wonderful Ed Helms skit at Comedy Central about e-voting. Not to be missed. This kind of comedy does more to communicate the problems with electronic voting than all the ranting that I do on the subject.
Jay Rosen has a thoughtful analysis of the recent furore over inappropriate comments by a Democrat-supporting blogger. Another example of the scandalmongering of mainstream politics and media out-manoeuvering the democratising potential of the net.
The Berkman Center at Harvard have done an interesting study on Apple's iTunes service focussing on

Interaction between Copyright and Contract Law
Digital Rights Management
Digital First Sale Doctrine
Fair Use Doctrine

Worth a look.

Monday, April 19, 2004

There are two lovely essays in Bruce Schneier's latest Crypto-Gram, one on national identity cards and the second on the economic incentives to rig electronic voting machines. On national ID cards:

"But my primary objection isn't the totalitarian potential of national
IDs, nor the likelihood that they'll create a whole immense new class
of social and economic dislocations. Nor is it the opportunities they
will create for colossal boondoggles by government contractors. My
objection to the national ID card, at least for the purposes of this
essay, is much simpler.

It won't work. It won't make us more secure.

In fact, everything I've learned about security over the last 20 years
tells me that once it is put in place, a national ID card program will
actually make us less secure.

My argument may not be obvious, but it's not hard to follow,
either. It centers around the notion that security must be evaluated
not based on how it works, but on how it fails.

It doesn't really matter how well an ID card works when used by the
hundreds of millions of honest people that would carry it. What
matters is how the system might fail when used by someone intent on
subverting that system: how it fails naturally, how it can be made to
fail, and how failures might be exploited.

The first problem is the card itself. No matter how unforgeable we
make it, it will be forged. And even worse, people will get legitimate
cards in fraudulent names...

... the main problem with any ID system is that it requires the
existence of a database. In this case it would have to be an immense
database of private and sensitive information on every American -- one
widely and instantaneously accessible from airline check-in stations,
police cars, schools, and so on.

The security risks are enormous. Such a database would be a kludge of
existing databases; databases that are incompatible, full of erroneous
data, and unreliable. As computer scientists, we do not know how to
keep a database of this magnitude secure, whether from outside hackers
or the thousands of insiders authorized to access it.

And when the inevitable worms, viruses, or random failures happen and
the database goes down, what then? Is America supposed to shut down
until it's restored?

Proponents of national ID cards want us to assume all these problems,
and the tens of billions of dollars such a system would cost -- for
what? For the promise of being able to identify someone?"

Tim O'Reilly doesn't understand all the fuss about Google's Gmail and privacy.

Wednesday, April 07, 2004

Apparently the EU parliament's civil liberties committee has decided to delay the 'ill considered' proposal on biometric passports until the autumn.

Statewatch is also reporting on this "Commission’s EU biometric passport proposal exceeds the EC’s powers
- no powers conferred upon the EC by the EC Treaty, taken separately or together, confer upon the EC the power to adopt the proposed Regulation"

Tuesday, April 06, 2004

At least one online pundit agrees with me about media having a short attention span. This one sees a possible danger for bloggers and provides an interesting perspective on the hounding of a Democratic party activist blogger, Markos Moulitsas Zuniga, who writes the Daily Kos, for posting an inappropriate/tasteless comment on his blog.

Monday, April 05, 2004

Largely unnoticed about a month ago the EU launched PRIME, a four year project to

"Develop solutions to empower individuals to control their private sphere and manage their identities; "

and

"Trigger persuasive deployment of privacy-enhancing identity management solutions. "

-according to the website. Theoretically the EU Commission has been pushing PETs (privacy enhancing technologies) for some time and one of the principles is to minimise the amount of personal data collected. There are two fundamental problems:

1. The Blair/Blunkett and by extension the EU Council of Ministers simple solution to terrorism - collect as much personal data about the entire population of the world as possible, in the hope that you can kid people into believing you're actually tackling terrorism;

And

2. Though we all say, when asked, that we are concerned about our personal privacy, we do very little actively to protect it e.g. how many people think about the privacy implications of their supermarket store cards.

Ah well, at least somebody is working on it.
David Blunkett and Tony Blair are continuing to exploit the Madrid bombings unconscionably, by pushing forward the introduction of biometric national ID cards by 2008, as their "we must do something" response.

This capitalising on others' tragedy is politics at its lowest.

They are prepared to spend billions of pounds on a system which won't work and will, in the process undermine fundamental freedoms in the UK that people have fought and died for, just to extract some transcient and superficial "tough on terrorism" headlines from a media with a short attention span.

If Mr Blunkett does get to be prime minister off the back of this then we will deserve what we get, for letting him get away with propering from this poisonous snake oil he is currently selling. Liberty, price and eternal vigilance come to mind on the one hand and not just the media but a short attention span society and general apathy on the other. It's big, it costs a fortune and hey it involves new technology, so most of us will buy it. Especially because the real solutions, if there are any, are long term and too hard for us to deal with.

Friday, April 02, 2004

Mr Blair has decided to fast track David Blunkett's national ID card system to try and distract people from the immigration fiasco that has prompted Home Office (in charge of immigration) minister Beverly Hughes' resignation.

John Lettice at the Register has a nice dissection of this as a complete sham. His concluding paragraphs are absolutely damning:



" Now, here is the problem as best as can be established at the moment. The
size of the backlog of immigration cases (both asylum and general) has been a
major issue for the current government, and Hughes (who reported to David
Blunkett at the Home Office) was presiding over the acceleration of the
processing of applications. It appears that in at least some areas this
acceleration process resulted in the systematic rubber-stamping of
applications. Cases from Bulgaria and Rumania have been cited where forged
documents were approved, and where pro forma business plans were sold to
applicants fraudulently applying under a programme designed to bring in
self-sustaining business startups. Allegedly, the UK authorities were alerted to
these fraudulent applications and to their rubber stamping, and Hughes herself
had the matter drawn to her attention last year by one of her own ministers.

So friends, what do we have here? If we had ID cards, what would have been
happening? At the same time as Blunkett's Home Office has been thumping
the ID card tub on the basis of its efficacy against crime, terrorism and illegal
immigration, that very same Home Office has known as a matter of record
(this is not, we accept, the same as actually knowing or even noticing) that it's
been granting immigrant status to people who are not going to perform in
accordance with what it says on the tin they just bought. Granted they're a lot
more likely to be one-legged Bulgarian plumbers who don't know anything
about plumbing than terrorists, but still... Their application rubber-stamped,
under the future system they would then have been issued with ID cards, and
would have happily acquired a perfectly legitimate UK identity on the basis of
whatever it was they'd chosen to fill in. Moral: the Home Office might be best
advised to sort out the loopholes and system failures it already has before
introducing new ones to fix. "

Thursday, April 01, 2004

The European Parliament have rejected Commissioner Bolkestein's deal with the US to share airline passenger data for use in CAPPS II, because it breaches EU privacy laws. It was a close vote 229 to 202 but the resolution suggested they'd go to the European Court of Justice on the matter if necessary.
The copyright bills are coming out of Congress thick and fast. The latest is the "Piracy Deterrence and Education Act" (PDEA) according to Declan. More of the usual, this time pressurising the FBI to chase the copyright infringers. I guess it's a variation on the DOJ. It's also a variation on the Author, Consumer, and Computer Owner Protection and Security Act (ACCOPS) proposed last year which was suggesting 5 year prison terms and $250 000 fines for sharing a single file.

"One part of the PDEA that did not appear in earlier bills would require the FBI to "facilitate the sharing" of information among Internet providers, copyright holders and police. "

And so the procession rolls on.
James Grimmelmann has a wicked April fools joke over at Lawmeme about the RIAA suing Google. I wonder how far that one will spread.

A Canadian judge has put a spoke in the gathering momentum of the IFPI's campaign of lawsuits against individual file sharers. He has denied the Canadian Recording Industry Association (CRIA) request to identify individuals alleged to be involved in P2P file sharing. He even declared file sharing legal in Canada, including uploading. "The mere fact of placing a copy on a shared directory in a computer where that copy can be accessed via a P2P service does not amount to distribution," he wrote. "Before it constitutes distribution, there must be a positive act by the owner of the shared directory, such as sending out the copies or advertising that they are available for copying." Expect an appeal from the CRIA probably faster than you can blink.

Wednesday, March 31, 2004

Slashdot has links to a collection of stories about the IFPI lawsuits against individuals.
There is an absolutely fascinating paper, Privacy in a Noise Society, which I've just come across on the web, by Nicklas Lundblad of the St Anna Institute in Stokholm. He puts his finger on one of the key issues relating to privacy in an information society and that is that "...anyone but not everyone can be mapped in detail...We live in a society where it is possible to chart the lives of anyone, but not the lives of everyone." Information overload and cost effectively preclude the latter.

Essential reading.
Kim Zetter at Wired has written a longish article about the dangers of e-voting. Worth a look. Wired has an archive of stories on the e-voting issue, headed up "Machine politics" which I'd suggest is a good starting point for anyone with concerns about the use of computers in elections.

Zetter's article gives an idea of the timeline of when and key folk involved in the publicising of the problems, such as Rebecca Mercuri, Bev Harris, David Allen, Avi Rubin, Yoshi Kohno, Adam Stubblefield, David Dill, David Jefferson, Nebraska Sen. Chuck Hagel (Republican) and New Jersey Rep. Rush Holt (Democrat). It's largely told from Harris' perspective.
IFPI affiliated music industry associations in Denmark, Italy, Germany and Canada have launched lawsuits against hundreds of individuals. (FWIW it's about 120 in Denmark, 30 in Italy, 29 in Canada and 68 in Germany). Look out for comments from the usual suspects.

Aaron Swartz, in parallel, has launched a wiki for annotating and editing Larry Lessig's new book, Free Culture.

Monday, March 29, 2004

Ernest Miller over the weekend has concluded that the PIRATE Act will faciltate wiretapping for civil copyright infringement.

"...having thought about the proposed law a little more, I came to an interesting realization: you can get wiretaps for federal copyright infringement investigations...

...Under a regular civil suit for copyright infringement by means of file sharing, the copyright holder can only observe that the infringing files are available for download. They can't really tell how many people have downloaded them, if any. Furthermore, copyright holders have no way of going after people who are only downloading files and not uploading them. Wiretaps to the rescue. The RIAA may not be permitted to wiretap file sharers, but the government certainly can. The RIAA must be salivating at the prospect."
The entertainment industry's latest attempt to get their representatives in Congress to pass favorable laws has produced the proposed Protecting Intellectual Rights Against Theft and Expropriation Act (PIRATE Act). (What a name). The idea this time is to save the copyright holders the trouble and expense of having to sue for copyright infringement. The responsibility for that would now be with the Department for Justice (i.e. taxpayers). As Donna says, the industry reject compulsory licences because they don't want government interference in the private sector but it's ok for the government to interfere when it involves them picking up the industry's legal costs. This is a sad joke.

James Grimmelmann at Lawmeme has a wonderfully cutting perspective on US reaction the WTO's decision to declare the US in breach of international trade rules in relation to online gambling policies. I hope he won't mind me reproducing it in full here:

'Remember why those folks in Seattle were so mad at the WTO? Well, one of the big reasons was that local laws in developing countries (on issues such as environmental protection, labor standards, and cultural values) were at risk of being struck down as "barriers to trade." Trade is trade, said the U.S., and trade comes first, and countries just need to shut up and deal.

Well, oh how the tables have turned. A WTO panel ruled on Wednesday that the U.S. ban on online gambling is an illegal trade barrier. Outraged U.S. lawmakers have already promised to appeal. Surprise, surprise, the ideology that free trade trumps restrictive local values turns out to be much less appealing when the U.S. interests are aligned with "local values" instead of "free trade." '

An international coalition of civil liberties groups, led by Privacy International and the American Civil Liberties Union (ACLU) have signed an open letter to the International Civil Aviation Organization (ICAO) on the grave dangers of vast biometric-passenger-data sharing systems. Thanks to Ian Brown at FIPR for the following extract from Privacy International's media release:

The letter, spearheaded by Privacy International and the American Civil
Liberties Union (ACLU) raises concerns about little-known plans to
imminently create international standards that will require the use of
biometrics and RFID (radio frequency) technology in all future
passports. The measures, being decided this week at a meeting of the
ICAO in Cairo, will result in a distributed international identification
database on all passport holders.

The open letter has been signed by, among others, the Electronic
Frontier Foundation, Statewatch, the UK based Foundation for Information
Policy Research, the Association for Progressive Communications and the
US based Privacy Rights Clearinghouse.

The ICAO has agreed that the initial international biometric standard
for passports will be facial mapping. Adequate memory space in newly
issued passports will be reserved for additional biometrics such as
fingerprinting at the discretion of every government. The EU is already
calling for fingerprints to be included, along with an associated
European register of all biometrics. National authorities will store and
share these vast data reserves.

The measures, supported by the US and the EU, will ultimately create an
electronic ID system on hundreds of millions of travellers. Despite
serious implications for privacy and personal security, the process is
occurring without public engagement or debate. Rather than allowing this
important issue to be decided by parliaments, governments have delegated
the setting of standards to the ICAO, a UN-level organization that is
responsible for the standardization of travel documents, passenger data
systems and air travel requirements.

The legislative drivers for the ICAO system are already in pace. The
USA-PATRIOT Act, passed by the U.S. Congress after the events of
September 2001 included the requirement that the President certify a
biometric technology standard for use in identifying aliens seeking
admission into the U.S., within two years. The schedule for its
implementation was accelerated by another piece of legislation, the
little known Enhanced Border Security and Visa Entry Reform Act 2002.
Part of this second law included seeking international co-operation with
this standard. The incentive to international co-operation was made
clear:


"By October 26, 2004, in order for a country to remain eligible for
participation in the visa waiver program its government must certify
that it has a program to issue to its nationals machine-readable
passports that are tamper-resistant and which incorporate biometric and
authentication identifiers that satisfy the standards of the
International Civil Aviation Organization (ICAO)."


These laws gave momentum to the standards that were being considered at
the ICAO by requiring visa waiver countries (which include many EU
countries, Australia, Brunei, Iceland, Japan, Monaco, New Zealand,
Norway, Singapore, and Slovenia) to implement biometrics into their
Machine-Readable Travel Documents (MRTDs), i.e. passports.

Based on projections from current passport and travel statistics,
biometric details of more than a billion people will be electronically
stored by 2015. Some of the countries sampled for this estimate are:

United States 90 million
United Kingdom 54 million
Japan 64 million
Canada 24 million
Australia 13 million
Russian Federation 50 million
Ireland 4 million
Taiwan 17 million
China 60 million

The Privacy International open letter warns:

"We are increasingly concerned that the biometric travel document
initiative is part and parcel of a larger surveillance infrastructure
monitoring the movement of individuals globally that includes
Passenger-Name Record transfers, API systems and the creation of an
intergovernmental network of interoperable electronic data systems to
facilitate access to each country's law enforcement and intelligence
information."

Privacy International has warned of "unprecedented" security threats
that could arise from the plan because of potential access by terrorists
and organised crime. Furthermore, the biometric standard being adopted
is "fundamentally flawed" and will result in a substantial number of
passengers being falsely identified as potential terrorists or wrongly
accused of holding fraudulent passports.

Dr Gus Hosein, Senior Fellow with Privacy International, warned: "This
is a potentially perilous plan. The ICAO must go back to the drawing
board or hold itself responsible for creating the first truly global
biometric database".

"Governments may claim that they are under an international obligation
to create national databases of fingerprints and face scans but we will
soon see nations with appalling human rights records generating massive
databases, and then requiring our own fingerprints and face-scans as we
travel."

He continued: "In January 2004 when the U.S. began fingerprinting and
face-scanning foreign visitors and storing this data for over fifty
years under the US-VISIT program, many countries responded with alarm.
With the biometric passport, however, every country may have its own
surveillance system, accumulating fingerprints and face-scans and
keeping them for as long as they wish with no regard to privacy or civil
liberties."

Friday, March 26, 2004

Larry Lessig has persuaded his publishers, Penguin, to make his new book, Free Culture, available online under a creative commons licence, Cory Doctorow style.

It looks as though Microsoft may have pulled a fast one on the EU according to Dan Gillmor and Andrew Orlowski. Regardless of whether you love or hate the company, in some ways you've got to have a sneaking admiration for Microsoft or at least the smart people they employ. Even when they are apparently under the cosh they're always looking to outwit the authorities and usually do.

Wednesday, March 24, 2004

Interesting essay in Spiked by Brendan O'Neill: Creating the enemy. Extract:



Over the past 10 to 15 years, the politics of fear and caution have come to dominate Western societies. Where political life previously consisted of debates and disagreements about what kind of society we wanted to live in, today it tends to focus on issues of safety and perceived risks to our health, environment or 'way of life'. The exhaustion of the political traditions of Left and Right has had a profoundly disorientating impact across Western society, shattering the consensus upon which basic questions of politics and morality have been decided throughout recent history. Faith in what were traditionally considered 'Western' values or institutions, from democratic politics to medical science, from the church to the monarchy, has been steadily eroded. Gaining agreement on any issue, from genetic modification and abortion to the role of the family and the issue of recreational drugs, has become increasingly fraught and subject to abitrary considerations.

We live in an era of great uncertainty, in which political leaders stand isolated from the public and unsure of what they believe in, and individuals have a weakened sense of community, solidarity or identity. This is enough to put society in a constant state of powerlessness and vulnerability - even without terrorist attacks."